Enhancing Provable Security and Efficiency of Permutation-Based DRBGs
Woohyuk Chung, Seongha Hwang, Hwigyeom Kim, Jooyoung Lee
Abstract
We revisit the security analysis of the permutation-based deterministic random bit generator (DRBG) discussed by Coretti et al. at CRYPTO 2019. Specifically, we prove that their construction, based on the sponge construction, and hence called Sponge-DRBG in this paper, is secure up to queries in the seedless robustness model, where is the required min-entropy and is the sponge capacity. This significantly improves the provable security bound from the existing to the birthday bound. We also show that our bound is tight by giving matching attacks.
As the Multi-Extraction game-based reduction proposed by Chung et al. at Asiacrypt 2024 is not applicable to Sponge-DRBG in a straightforward manner, we further refine and generalize the proof technique so that it can be applied to a broader class of DRBGs to improve their provable security.
We also propose a new permutation-based DRBG, dubbed POSDRBG, with almost the optimal output rate , outperforming the output rate of Sponge-DRBG, where is the output size of the underlying permutation and . We prove that POSDRBG is tightly secure up to queries. Thus, to the best of our knowledge, POSDRBG is the first permutation-based DRBG that achieves the optimal output rate of 1, while maintaining the same level of provable security as Sponge-DRBG in the seedless robustness model.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get fa5b218f-eb36-4a82-a692-5d9cc13037f9Related papers
- Permutation-Based Hashing with Stronger (Second) Preimage ResistanceSiwei Sun, Shun Li, Zhiyu Zhang, Charlotte Lefevre et al.CRYPTO 2026
- How to Build a Short-Input Random Oracle from Public Random PermutationsRitam Bhaumik, Nilanjan Datta, Avijit Dutta, Ashwin Jha et al.EUROCRYPT 2026
- Security Analysis of NIST CTR-DRBGViet Tung Hoang, Yaobin ShenCRYPTO 2020 · 14 citations
- Revisiting the Indifferentiability of the Sum of PermutationsAldo Gunsing, Ritam Bhaumik, Ashwin Jha, Bart Mennink et al.CRYPTO 2023 · 10 citations
- Upper Bound on Information-Theoretic Security of Permutation-Based Pseudorandom FunctionsChun Guo, Jian Guo, Xinnian Li, Wenjie NanEUROCRYPT 2026
