Paper 2017/500

Algebraic XOR-RKA-Secure Pseudorandom Functions from Post-Zeroizing Multilinear Maps

Michel Abdalla, Fabrice Benhamouda, and Alain Passelègue


Due to the vast number of successful related-key attacks against existing block-ciphers, related-key security has become a common design goal for such primitives. In these attacks, the adversary is not only capable of seeing the output of a function on inputs of its choice, but also on related keys. At Crypto 2010, Bellare and Cash proposed the first construction of a pseudorandom function that could provably withstand such attacks based on standard assumptions. Their construction, as well as several others that appeared more recently, have in common the fact that they only consider linear or polynomial functions of the secret key over complex groups. In reality, however, most related-key attacks have a simpler form, such as the XOR of the key with a known value. To address this problem, we propose the first construction of RKA secure pseudorandom function for XOR relations. Our construction relies on multilinear maps and, hence, can only be seen as a feasibility result. Nevertheless, we remark that it can be instantiated under two of the existing multilinear-map candidates since it does not reveal any encodings of zero. To achieve this goal, we rely on several techniques that were used in the context of program obfuscation, but we also introduce new ones to address challenges that are specific to the related-key-security setting.

Available format(s)
Publication info
Pseudorandom functionsrelated-key securitymultilinear mapspost-zeroizing constructions
Contact author(s)
alapasse @ gmail com
2017-06-01: received
Short URL
Creative Commons Attribution


      author = {Michel Abdalla and Fabrice Benhamouda and Alain Passelègue},
      title = {Algebraic XOR-RKA-Secure Pseudorandom Functions from Post-Zeroizing Multilinear Maps},
      howpublished = {Cryptology ePrint Archive, Paper 2017/500},
      year = {2017},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.