Paper 2025/1148
On the Composition of Single-Keyed Tweakable Even-Mansour for Achieving BBB Security
Abstract
Observing the growing popularity of random permutation (RP)-based designs (e.g, Sponge), Bart Mennink in CRYPTO 2019 has initiated an interesting research in the direction of RP-based pseudorandom functions (PRFs). Both are claimed to achieve beyond-the-birthday-bound (BBB) security of $2n/3$ bits ($n$ being the input block size in bits) but require two instances of RPs and can handle only one-block inputs. In this work, we extend research in this direction by providing two new BBB-secure constructions by composing the tweakable Even-Mansour appropriately. Our first construction requires only one instance of an RP and requires only one key. Our second construction extends the first to a nonce-based Message Authentication Code (MAC) using a universal hash to deal with multi-block inputs. We show that the hash key can be derived from the original key when the underlying hash is the Polyhash. We provide matching attacks for both constructions to demonstrate the tightness of the proven security bounds.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- Published by the IACR in TOSC 2020
- DOI
- 10.13154/TOSC.V2020.I2.1-39
- Keywords
- PDMMACDavis-MeyerPRFMACpermutationbeyond the birthday bound security
- Contact author(s)
-
avikchkrbrti @ gmail com
mridul nandi @ gmail com
suprita45 @ gmail com
yasuda kan @ lab ntt co jp - History
- 2025-06-21: revised
- 2025-06-18: received
- See all versions
- Short URL
- https://ia.cr/2025/1148
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1148,
author = {Avik Chakraborti and Mridul Nandi and Suprita Talnikar and Kan Yasuda},
title = {On the Composition of Single-Keyed Tweakable Even-Mansour for Achieving {BBB} Security},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1148},
year = {2025},
doi = {10.13154/TOSC.V2020.I2.1-39},
url = {https://eprint.iacr.org/2025/1148}
}