After formally defining constrained VRFs, we derive instantiations from the multilinear-maps-based constrained PRFs by Boneh and Waters, yielding a VRF with constrained keys for any set that can be decided by a polynomial-size circuit. Our VRFs have the same function values as the Boneh-Waters PRFs and are proved secure under the same hardness assumption, showing that verifiability comes at no cost. Constrained (functional) VRFs were stated as an open problem by Boyle et al.
Category / Keywords: public-key cryptography / Verifiable random functions, constrained pseudorandom functions Original Publication (with major differences): SCN 2014, Springer LNCS 8642 Date: received 9 Jul 2014 Contact author: georg fuchsbauer at ist ac at Available format(s): PDF | BibTeX Citation Version: 20140709:151902 (All versions of this report) Short URL: ia.cr/2014/537 Discussion forum: Show discussion | Start new discussion