arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

伪随机函数的黑盒构造的下界

Lower Bounds on Black-Box Constructions of Pseudorandom Functions

Bar Alon, Itai Dinur, Muthuramakrishnan Venkitasubramaniam

arXiv 2608.14501首次发表:更新:

AI 中文总结

该研究针对从伪随机生成器(PRG)到伪随机函数(PRF)的全黑盒构造,证明了其对PRG的非适应性调用次数的下界,且该结果适用于弱PRF,部分情况还涵盖适应性调用场景。

AI 中文摘要

在Goldreich、Goldwasser和Micali的开创性工作[CRYPTO 1984]中,他们通过对伪随机生成器(PRG)的黑盒访问构造了伪随机函数(PRF)。结合Levin的域扩展技术,GGM构造会调用PRG ω(log n)次,其中n表示PRG的输入长度。迄今为止,尚未发现调用次数更少的黑盒构造。最近,Beimel、Malkin和Mazor[CRYPTO 2024]表明,对于他们称为“树构造”的某类构造,GGM构造是最优的。然而,仅用一次PRG调用能否构建PRF这一基本问题仍未解决。在本研究中,我们考虑从PRG到PRF的全黑盒构造,其中构造和归约均需为黑盒,且归约与敌手的交互次数独立于敌手在每次交互中对其底层函数的预言调用次数。我们的主要结果表明,此类构造对PRG的非适应性调用次数不能达到o(n/log n)和o(in/log in),其中in是PRF的输入长度。该不可能性结果甚至适用于输出为1比特的弱PRF,此时敌手被限制为进行独立同分布的均匀随机查询。此外,我们证明了输出足够长的弱PRF的下界,该下界即使在允许构造对PRG进行适应性调用时依然成立。

英文摘要

In their seminal work, Goldreich, Goldwasser, and Micali [CRYPTO 1984] constructed a pseudorandom function (PRF) using a black-box access to a pseudorandom generator (PRG). When combined with Levin's domain extension technique, the GGM construction invokes the PRG $ω(\log n)$ times, where $n$ denotes the input length to the PRG. To this day, no black-box construction achieving fewer calls is known. Recently, Beimel, Malkin, and Mazor [CRYPTO 2024] showed that for a certain family of constructions, which they termed \emph{tree constructions}, the GGM construction is optimal. However, the basic challenge of whether a PRF can be built with just \emph{one invocation} of the PRG still remains open. In this work, we consider fully black-box constructions of PRFs from PRGs, where both the construction and the reduction are required to be black-box, and the number of interactions the reduction makes with the adversary is independent of the number of oracle calls the adversary makes to its underlying function within each interaction. Our main result shows that no such construction can have $o(n/\log n)$ and $o(\mathsf{in}/\log\mathsf{in})$ \emph{non-adaptive} calls to the PRG, where $\mathsf{in}$ is the input length of the PRF. This impossibility holds even for weak PRFs with one-bit output, where the adversary is restricted to making i.i.d. uniformly random queries. In addition, we prove a lower bound for weak PRFs with sufficiently long outputs that holds even when the construction is allowed to make adaptive queries to the PRG.

CommentsPublished at CRYPTO 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑