The prefix-free PRF (pseudorandom function) security of a cascade function based on a compression function f against a q-query distinguisher is reduced to a q-query PRF security of f with a tightness gap \(\ell q\) where \(\ell \) represents the length of the longest query among all q queries. In this paper, we have shown a new reduction which is also applicable to multiuser setup and improves the tightness gap for both adaptive and non-adaptive distinguishers. As an immediate application of our result, we have shown multiuser security of NMAC, HMAC  and many other known MACs in the standard model. Moreover, the tightness gap is improved in comparison with known single-user analysis. We also have shown a similar tightness gap for the single-keyed version of NMAC. As a result, the constants ipad and opad used in HMAC and relying upon the PRB (pseudorandom bit) assumption on the underlying compression function become redundant.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Improving Tightness Gap of GGM Construction and Its Applications

  • Mridul Nandi

摘要

The prefix-free PRF (pseudorandom function) security of a cascade function based on a compression function f against a q-query distinguisher is reduced to a q-query PRF security of f with a tightness gap \(\ell q\) where \(\ell \) represents the length of the longest query among all q queries. In this paper, we have shown a new reduction which is also applicable to multiuser setup and improves the tightness gap for both adaptive and non-adaptive distinguishers. As an immediate application of our result, we have shown multiuser security of NMAC, HMAC  and many other known MACs in the standard model. Moreover, the tightness gap is improved in comparison with known single-user analysis. We also have shown a similar tightness gap for the single-keyed version of NMAC. As a result, the constants ipad and opad used in HMAC and relying upon the PRB (pseudorandom bit) assumption on the underlying compression function become redundant.