S‐box is one of the most important components of modern cipher. For efficient implementation and to avoid a purely algebraic construction, utilizing special cipher structure and small‐size random permutation to design S‐boxes seems to be an attractive approach. In this paper, we focus on the structure‐recovery problem on three kinds of S‐boxes, that is, specify the inner transformations from the look‐up table, which allows a much more efficient hardware implementation. For a given n‐bit bijection, with introducing equivalent structures, we decompose it into three‐layer Feistel/MISTY/Lai–Massey within time complexity O(2n/2) and 2 − n/2 part of the full codebook. Copyright © 2017 John Wiley & Sons, Ltd.