Lune

CRYPTO2026顶会

Lower Bounds on Black-Box Constructions of Pseudorandom Functions

Bar Alon, Itai Dinur, Muthuramakrishnan Venkitasubramaniam

2026年份

摘要

In their seminal work, Goldreich, Goldwasser, and Micali [CRYPTO 1984] constructed a pseudorandom function (PRF) using a black-box access to a pseudorandom generator (PRG). When combined with Levin's domain extension technique, the GGM construction invokes the PRG ω(log⁡n)\omega(\log n) times, where nn denotes the input length to the PRG. To this day, no black-box construction achieving fewer calls is known. Recently, Beimel, Malkin, and Mazor [CRYPTO 2024] showed that for a certain family of constructions, which they termed tree constructions, the GGM construction is optimal. However, the basic challenge of whether a PRF can be built with just one invocation of the PRG still remains open. In this work, we consider fully black-box constructions of PRFs from PRGs, where both the construction and the reduction are required to be black-box, and the number of interactions the reduction makes with the adversary is independent of the number of oracle calls the adversary makes to its underlying function within each interaction. Our main result shows that no such construction can have o(n/log⁡n)o(n/\log n) and o(in/log⁡in)o(\mathsf{in}/\log\mathsf{in}) non-adaptive calls to the PRG, where in\mathsf{in} is the input length of the PRF. This impossibility holds even for weak PRFs with one-bit output, where the adversary is restricted to making i.i.d. uniformly random queries. In addition, we prove a lower bound for weak PRFs with sufficiently long outputs that holds even when the construction is allowed to make adaptive queries to the PRG.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext a1ba76d0-e5f2-4996-83e7-21ffe53b6bbe

它引用的顶会 Paper1

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖