When Messages Are Keys: Is HMAC a Dual-PRF?
Matilda Backendal, Mihir Bellare, Felix Günther, Matteo Scarlata
摘要
In Internet security protocols including TLS 1.3, KEMTLS, MLS and Noise, HMAC is being assumed to be a dual-PRF, meaning a PRF not only when keyed conventionally (through its first input), but also when "swapped" and keyed (unconventionally) through its second (message) input. We give the first in-depth analysis of the dual-PRF assumption on HMAC.
For the swap case, we note that security does not hold in general, but completely characterize when it does; we show that HMAC is swap-PRF secure if and only if keys are restricted to sets satisfying a condition called feasibility, that we give, and that holds in applications. The sufficiency is shown by proof and the necessity by attacks. For the conventional PRF case, we fill a gap in the literature by proving PRF security of HMAC for keys of arbitrary length.
Our proofs are in the standard model, make assumptions only on the compression function underlying the hash function, and give good bounds in the multi-user setting. The positive results are strengthened through achieving a new notion of variable key-length PRF security that guarantees security even if different users use keys of different lengths, as happens in practice.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Obfuscated Key ExchangeFelix Günther, Douglas Stebila, Shannon VeitchCCS 2024 · 被引用 1 次
- Shadowfax: Hybrid Security and Deniability for AKEMsPhillip Gajland, Vincent Hwang, Jonas JanneckUSENIX Security 2026
- The SecureDrop Protocol: End-to-End Encrypted Whistleblowing for AllGiulio Berra, Felix Linker, Luca Maier, Cory Francis Myers 等CCS 2026
- iSeal: Encrypted Fingerprinting for Reliable LLM Ownership VerificationZixun Xiong, Gaoyi Wu, Qingyang Yu, Mingyu Derek Ma 等AAAI 2026
它引用的顶会 Paper6
- Post-Quantum TLS Without Handshake SignaturesPeter Schwabe, Douglas Stebila, Thom WiggersCCS 2020 · 被引用 162 次
- Post-quantum WireGuardAndreas Hülsing, Kai-Chun Ning, Peter Schwabe, Florian Weber 等S&P 2021 · 被引用 73 次
- Efficient Schemes for Committing Authenticated EncryptionMihir Bellare, Viet Tung HoangEUROCRYPT 2022 · 被引用 54 次
- The Multi-user Security of GCM, Revisited: Tight Bounds for Nonce RandomizationViet Tung Hoang, Stefano Tessaro, Aishwarya ThiruvengadamCCS 2018 · 被引用 39 次
- Security Analysis of the MLS Key DerivationChris Brzuska, Eric Cornelissen, Konrad KohbrokS&P 2022 · 被引用 26 次
相关 Paper
- On the Concrete Security of TLS 1.3 PSK ModeHannah Davis, Denis Diemert, Felix Günther, Tibor JagerEUROCRYPT 2022 · 被引用 19 次
- Verified Models and Reference Implementations for the TLS 1.3 Standard CandidateKarthikeyan Bhargavan, Bruno Blanchet, Nadim KobeissiS&P 2017 · 被引用 233 次
- Key Derivation Functions Without a Grain of SaltMatilda Backendal, Sebastian Clermont, Marc Fischlin, Felix GüntherEUROCRYPT 2025 · 被引用 5 次
- Stealth Key Exchange and Confined Access to the Record Protocol Data in TLS 1.3Marc FischlinCCS 2023 · 被引用 7 次
- Quantifying the Security Cost of Migrating Protocols to PracticeChristopher Patton, Thomas ShrimptonCRYPTO 2020 · 被引用 2 次
