Paper 2025/1586
A Note on Feedback-PRF Mode of KDF from NIST SP 800-108
Abstract
We consider FB-PRF, one of the key derivation functions defined in NIST SP 800-108 constructed from a pseudorandom function in a feedback mode. The standard allows some flexibility in the specification, and we show that one specific instance of FB-PRF allows an efficient distinguishing attack.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- Preprint.
- Keywords
- Key derivation functionNIST SP 800-108Feedback modePseudorandomness
- Contact author(s)
-
bhaumik ritam @ gmail com
avirocks dutta13 @ gmail com
tetsu iwata @ nagoya-u jp
ashwin jha @ ruhr-uni-bochum de
k-minematsu @ nec com
mridul nandi @ gmail com
yusk sasaki @ ntt com
meltem turan @ nist gov
tessaro @ cs washington edu - History
- 2025-09-05: approved
- 2025-09-03: received
- See all versions
- Short URL
- https://ia.cr/2025/1586
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/1586,
author = {Ritam Bhaumik and Avijit Dutta and Tetsu Iwata and Ashwin Jha and Kazuhiko Minematsu and Mridul Nandi and Yu Sasaki and Meltem Sönmez Turan and Stefano Tessaro},
title = {A Note on Feedback-{PRF} Mode of {KDF} from {NIST} {SP} 800-108},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1586},
year = {2025},
url = {https://eprint.iacr.org/2025/1586}
}