Paper 2025/1586

A Note on Feedback-PRF Mode of KDF from NIST SP 800-108

Ritam Bhaumik, Technology Innovation Institute
Avijit Dutta, Institute for Advancing Intelligence, TCG CREST, AcSIR
Tetsu Iwata, Nagoya University
Ashwin Jha, Ruhr University Bochum
Kazuhiko Minematsu, NEC Corporation
Mridul Nandi, Indian Statistical Institute, Kolkata
Yu Sasaki, NTT Social Informatics Laboratories
Meltem Sönmez Turan, National Institute of Standards and Technology
Stefano Tessaro, University of Washington
Abstract

We consider FB-PRF, one of the key derivation functions defined in NIST SP 800-108 constructed from a pseudorandom function in a feedback mode. The standard allows some flexibility in the specification, and we show that one specific instance of FB-PRF allows an efficient distinguishing attack.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
Key derivation functionNIST SP 800-108Feedback modePseudorandomness
Contact author(s)
bhaumik ritam @ gmail com
avirocks dutta13 @ gmail com
tetsu iwata @ nagoya-u jp
ashwin jha @ ruhr-uni-bochum de
k-minematsu @ nec com
mridul nandi @ gmail com
yusk sasaki @ ntt com
meltem turan @ nist gov
tessaro @ cs washington edu
History
2025-09-05: approved
2025-09-03: received
See all versions
Short URL
https://ia.cr/2025/1586
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1586,
      author = {Ritam Bhaumik and Avijit Dutta and Tetsu Iwata and Ashwin Jha and Kazuhiko Minematsu and Mridul Nandi and Yu Sasaki and Meltem Sönmez Turan and Stefano Tessaro},
      title = {A Note on Feedback-{PRF} Mode of {KDF} from {NIST} {SP} 800-108},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1586},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1586}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.