Reflection ciphers

Christina Boura, Anne Canteaut, Lars Ramkilde Knudsen, Gregor Leander

Research output: Contribution to journalJournal articleResearchpeer-review

271 Downloads (Pure)


This paper investigates ciphers where the set of encryption functions is identical to the set of decryption functions, which we call reflection ciphers. Equivalently, there exists a permutation P, named the coupling permutation, such that decryption under k corresponds to encryption under P(k). We study the necessary properties for this coupling permutation.
Special care has to be taken of some related-key distinguishers since, in the context of reflection ciphers, they may provide attacks in the single-key setting.We then derive some criteria for constructing secure reflection ciphers and analyze the security properties of different families of coupling permutations. Finally, we concentrate on the case of reflection block ciphers and, as an illustration, we provide concrete examples of key schedules corresponding to several coupling permutations, which lead to new variants of the block cipher PRINCE.
Original languageEnglish
JournalDesigns, Codes and Cryptography
Pages (from-to)3-25
Publication statusPublished - 2017


  • Reflection ciphers
  • Involutions
  • Related-key distinguishers

Fingerprint Dive into the research topics of 'Reflection ciphers'. Together they form a unique fingerprint.

Cite this