Constructions of PRF (Pseudo Random Function)The Goldreich-Goldwasser-Micali Construction with bad PRGSSecurity of KDF1 and KDF2 (hash based KDF's)Implementing a pseudo random function in practiceCryptanalysis of Marvin32 compared to SipHashPseudo Random FunctionWhy is this function pseudo random (PRF)?Decentralized consent over a random numberExistence of PRF $implies$ existence of PRGDoes a distinguisher for an PRF based on a hash make the hash function insecure?Can we convert a pseudorandom function (PRF) to an Oblivious PRF (OPRF) through an Oblivious Transfer (OT) protocol?
Alignment of various blocks in tikz
Two field separators (colon and space) in awk
Implications of cigar-shaped bodies having rings?
Can an Area of Effect spell cast outside a Prismatic Wall extend inside it?
Elements that can bond to themselves?
Discriminated by senior researcher because of my ethnicity
How can I print the prosodic symbols in LaTeX?
Can I criticise the more senior developers around me for not writing clean code?
Dynamic SOQL query relationship with field visibility for Users
Re-entry to Germany after vacation using blue card
How do I deal with a coworker that keeps asking to make small superficial changes to a report, and it is seriously triggering my anxiety?
Initiative: Do I lose my attack/action if my target moves or dies before my turn in combat?
Could the terminal length of components like resistors be reduced?
Was there a Viking Exchange as well as a Columbian one?
What happens to Mjolnir (Thor's hammer) at the end of Endgame?
Like totally amazing interchangeable sister outfits II: The Revenge
How to write a column outside the braces in a matrix?
How to denote matrix elements succinctly?
Can SQL Server create collisions in system generated constraint names?
Why didn't the Space Shuttle bounce back into space as many times as possible so as to lose a lot of kinetic energy up there?
Can't get 5V 3A DC constant
What term is being referred to with "reflected-sound-of-underground-spirits"?
Does a large simulator bay have standard public address announcements?
Pulling the rope with one hand is as heavy as with two hands?
Constructions of PRF (Pseudo Random Function)
The Goldreich-Goldwasser-Micali Construction with bad PRGSSecurity of KDF1 and KDF2 (hash based KDF's)Implementing a pseudo random function in practiceCryptanalysis of Marvin32 compared to SipHashPseudo Random FunctionWhy is this function pseudo random (PRF)?Decentralized consent over a random numberExistence of PRF $implies$ existence of PRGDoes a distinguisher for an PRF based on a hash make the hash function insecure?Can we convert a pseudorandom function (PRF) to an Oblivious PRF (OPRF) through an Oblivious Transfer (OT) protocol?
$begingroup$
I was taught only GGM based PRF construction in class. It's very inefficient. I am just curious about various PRF constructions from standard assumptions. Please provide a few PRF constructions from various assumptions.
pseudo-random-generator pseudo-random-function
$endgroup$
add a comment |
$begingroup$
I was taught only GGM based PRF construction in class. It's very inefficient. I am just curious about various PRF constructions from standard assumptions. Please provide a few PRF constructions from various assumptions.
pseudo-random-generator pseudo-random-function
$endgroup$
$begingroup$
Well, one standard assumption is that the SHA-256 compression function is a PRF, from which we can conclude that HMAC-SHA256 is a PRF (and a reasonably efficient one at that), but maybe you meant to restrict the domain of ‘standard assumptions’?
$endgroup$
– Squeamish Ossifrage
4 hours ago
add a comment |
$begingroup$
I was taught only GGM based PRF construction in class. It's very inefficient. I am just curious about various PRF constructions from standard assumptions. Please provide a few PRF constructions from various assumptions.
pseudo-random-generator pseudo-random-function
$endgroup$
I was taught only GGM based PRF construction in class. It's very inefficient. I am just curious about various PRF constructions from standard assumptions. Please provide a few PRF constructions from various assumptions.
pseudo-random-generator pseudo-random-function
pseudo-random-generator pseudo-random-function
asked 5 hours ago
satyasatya
441317
441317
$begingroup$
Well, one standard assumption is that the SHA-256 compression function is a PRF, from which we can conclude that HMAC-SHA256 is a PRF (and a reasonably efficient one at that), but maybe you meant to restrict the domain of ‘standard assumptions’?
$endgroup$
– Squeamish Ossifrage
4 hours ago
add a comment |
$begingroup$
Well, one standard assumption is that the SHA-256 compression function is a PRF, from which we can conclude that HMAC-SHA256 is a PRF (and a reasonably efficient one at that), but maybe you meant to restrict the domain of ‘standard assumptions’?
$endgroup$
– Squeamish Ossifrage
4 hours ago
$begingroup$
Well, one standard assumption is that the SHA-256 compression function is a PRF, from which we can conclude that HMAC-SHA256 is a PRF (and a reasonably efficient one at that), but maybe you meant to restrict the domain of ‘standard assumptions’?
$endgroup$
– Squeamish Ossifrage
4 hours ago
$begingroup$
Well, one standard assumption is that the SHA-256 compression function is a PRF, from which we can conclude that HMAC-SHA256 is a PRF (and a reasonably efficient one at that), but maybe you meant to restrict the domain of ‘standard assumptions’?
$endgroup$
– Squeamish Ossifrage
4 hours ago
add a comment |
1 Answer
1
active
oldest
votes
$begingroup$
The most common efficient PRFs from specific assumptions are:
The Naor-Reingold PRF, which is based on the decision Diffie-Hellman assumption (DDH), and
The BPR PRF, which is based on the learning with error assumption (LWE).
Perhaps slightly less well-known is the NRR PRF, which is based on the hardness of factoring.
$endgroup$
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "281"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: false,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
noCode: true, onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fcrypto.stackexchange.com%2fquestions%2f70083%2fconstructions-of-prf-pseudo-random-function%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
$begingroup$
The most common efficient PRFs from specific assumptions are:
The Naor-Reingold PRF, which is based on the decision Diffie-Hellman assumption (DDH), and
The BPR PRF, which is based on the learning with error assumption (LWE).
Perhaps slightly less well-known is the NRR PRF, which is based on the hardness of factoring.
$endgroup$
add a comment |
$begingroup$
The most common efficient PRFs from specific assumptions are:
The Naor-Reingold PRF, which is based on the decision Diffie-Hellman assumption (DDH), and
The BPR PRF, which is based on the learning with error assumption (LWE).
Perhaps slightly less well-known is the NRR PRF, which is based on the hardness of factoring.
$endgroup$
add a comment |
$begingroup$
The most common efficient PRFs from specific assumptions are:
The Naor-Reingold PRF, which is based on the decision Diffie-Hellman assumption (DDH), and
The BPR PRF, which is based on the learning with error assumption (LWE).
Perhaps slightly less well-known is the NRR PRF, which is based on the hardness of factoring.
$endgroup$
The most common efficient PRFs from specific assumptions are:
The Naor-Reingold PRF, which is based on the decision Diffie-Hellman assumption (DDH), and
The BPR PRF, which is based on the learning with error assumption (LWE).
Perhaps slightly less well-known is the NRR PRF, which is based on the hardness of factoring.
answered 4 hours ago
Geoffroy CouteauGeoffroy Couteau
9,29011834
9,29011834
add a comment |
add a comment |
Thanks for contributing an answer to Cryptography Stack Exchange!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
Use MathJax to format equations. MathJax reference.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fcrypto.stackexchange.com%2fquestions%2f70083%2fconstructions-of-prf-pseudo-random-function%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
$begingroup$
Well, one standard assumption is that the SHA-256 compression function is a PRF, from which we can conclude that HMAC-SHA256 is a PRF (and a reasonably efficient one at that), but maybe you meant to restrict the domain of ‘standard assumptions’?
$endgroup$
– Squeamish Ossifrage
4 hours ago