Lune

CRYPTO2025顶会

Enhancing Provable Security and Efficiency of Permutation-Based DRBGs

Woohyuk Chung, Seongha Hwang, Hwigyeom Kim, Jooyoung Lee

2025年份

摘要

We revisit the security analysis of the permutation-based deterministic random bit generator (DRBG) discussed by Coretti et al. at CRYPTO 2019. Specifically, we prove that their construction, based on the sponge construction, and hence called Sponge-DRBG in this paper, is secure up to O(min⁡{2c2,2λ2})O\left(\min \left\{2^{\frac{c}{2}}, 2^{\frac{\lambda}{2}}\right\}\right) queries in the seedless robustness model, where λ\lambda is the required min-entropy and cc is the sponge capacity. This significantly improves the provable security bound from the existing O(min⁡{2c3,2λ2})O\left(\min \left\{2^{\frac{c}{3}}, 2^{\frac{\lambda}{2}}\right\}\right) to the birthday bound. We also show that our bound is tight by giving matching attacks.

As the Multi-Extraction game-based reduction proposed by Chung et al. at Asiacrypt 2024 is not applicable to Sponge-DRBG in a straightforward manner, we further refine and generalize the proof technique so that it can be applied to a broader class of DRBGs to improve their provable security.

We also propose a new permutation-based DRBG, dubbed POSDRBG, with almost the optimal output rate 11, outperforming the output rate rn\frac{r}{n} of Sponge-DRBG, where nn is the output size of the underlying permutation and r=n−cr=n-c. We prove that POSDRBG is tightly secure up to O(min⁡{2c2,2λ2})O\left(\min \left\{2^{\frac{c}{2}}, 2^{\frac{\lambda}{2}}\right\}\right) queries. Thus, to the best of our knowledge, POSDRBG is the first permutation-based DRBG that achieves the optimal output rate of 1, while maintaining the same level of provable security as Sponge-DRBG in the seedless robustness model.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖