Paper 2025/1148

On the Composition of Single-Keyed Tweakable Even-Mansour for Achieving BBB Security

Avik Chakraborti, Indian Statistical Institute, NTT Secure Platform Laboratories
Mridul Nandi, Indian Statistical Institute
Suprita Talnikar, Indian Statistical Institute
Kan Yasuda, NTT Secure Platform Laboratories
Abstract

Observing the growing popularity of random permutation (RP)-based designs (e.g, Sponge), Bart Mennink in CRYPTO 2019 has initiated an interesting research in the direction of RP-based pseudorandom functions (PRFs). Both are claimed to achieve beyond-the-birthday-bound (BBB) security of $2n/3$ bits ($n$ being the input block size in bits) but require two instances of RPs and can handle only one-block inputs. In this work, we extend research in this direction by providing two new BBB-secure constructions by composing the tweakable Even-Mansour appropriately. Our first construction requires only one instance of an RP and requires only one key. Our second construction extends the first to a nonce-based Message Authentication Code (MAC) using a universal hash to deal with multi-block inputs. We show that the hash key can be derived from the original key when the underlying hash is the Polyhash. We provide matching attacks for both constructions to demonstrate the tightness of the proven security bounds.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Published by the IACR in TOSC 2020
DOI
10.13154/TOSC.V2020.I2.1-39
Keywords
PDMMACDavis-MeyerPRFMACpermutationbeyond the birthday bound security
Contact author(s)
avikchkrbrti @ gmail com
mridul nandi @ gmail com
suprita45 @ gmail com
yasuda kan @ lab ntt co jp
History
2025-06-21: revised
2025-06-18: received
See all versions
Short URL
https://ia.cr/2025/1148
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1148,
      author = {Avik Chakraborti and Mridul Nandi and Suprita Talnikar and Kan Yasuda},
      title = {On the Composition of Single-Keyed Tweakable Even-Mansour for Achieving {BBB} Security},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1148},
      year = {2025},
      doi = {10.13154/TOSC.V2020.I2.1-39},
      url = {https://eprint.iacr.org/2025/1148}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.