Revisiting the Indifferentiability of the Sum of Permutations
Aldo Gunsing, Ritam Bhaumik, Ashwin Jha, Bart Mennink, Yaobin Shen
Abstract
The sum of two n-bit pseudorandom permutations is known to behave like a pseudorandom function with n bits of security. A recent line of research has investigated the security of two public n-bit permutations and its degree of indifferentiability. Mandal et al. (INDOCRYPT 2010) proved 2n/3-bit security, Mennink and Preneel (ACNS 2015) pointed out a non-trivial flaw in their analysis and re-proved (2n/3-log 2 (n))-bit security. Bhattacharya and Nandi (EUROCRYPT 2018) eventually improved the result to n-bit security. Recently, Gunsing at CRYPTO 2022 already observed that a proof technique used in this line of research only holds for sequential indifferentiability. We revisit the line of research in detail, and observe that the strongest bound of n-bit security has two other serious issues in the reasoning, the first one is actually the same non-trivial flaw that was present in the work of Mandal et al., while the second one discards biases in the randomness influenced by the distinguisher. More concretely, we introduce two attacks that show limited potential of different approaches. We (i) show that the latter issue that discards biases only holds up to 2 3n/4 queries, and (ii) perform a differentiability attack against their simulator in 2 5n/6 queries. On the upside, we revive the result of Mennink and Preneel and show (2n/3log 2 (n))-bit regular indifferentiability security of the sum of public permutations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1ed70f42-4dab-4631-9731-985e3cfe585eCited by top-tier papers1
Ask how each one uses itBuilds on1
Related papers
- How to Build a Short-Input Random Oracle from Public Random PermutationsRitam Bhaumik, Nilanjan Datta, Avijit Dutta, Ashwin Jha et al.EUROCRYPT 2026
- Combining Outputs of a Random Permutation: New Constructions and Tight Security Bounds by Fourier AnalysisItai DinurEUROCRYPT 2025 · 1 citation
- Mind the Composition: Birthday Bound Attacks on EWCDMD and SoKAC21Mridul NandiEUROCRYPT 2020 · 14 citations
- Separate Your Domains: NIST PQC KEMs, Oracle Cloning and Read-Only IndifferentiabilityMihir Bellare, Hannah Davis, Felix GüntherEUROCRYPT 2020 · 35 citations
- Impossibility of Indifferentiable Iterated Blockciphers from 3 or Less Primitive CallsChun Guo, Lei Wang, Dongdai LinEUROCRYPT 2023 · 5 citations
