gafter> Phil's exact system was presented and broken in the cryptographic gafter> literature. See the paper "How To Construct Pseudorandom Permutations gafter> from Pseudorandom Functions", Siam J. Comput., Vol 17, No. 2, April gafter> 1988. gafter> gafter> The paper shows that Phil's system is insecure, but that using two gafter> rounds of his system (with different keys) results in a secure system.