Paper 2025/383
$\mathsf{♯Pencil}$: A Domain-Extended Committing BBB PRF for Strengthening GCM
Abstract
We consider the problem of constructing efficient committing pseudorandom functions with Beyond-Birthday-Bound (BBB) security from blockciphers. More specifically, we are interested in expanding pseudorandom functions (PRF) whose domain is roughly twice that of the underlying blockcipher. The main motivation behind our work is to construct an AES-based key derivation function (KDF) that can be combined with GCM in order to improve its security bound, accommodate larger nonces that can be generated randomly without risking collisions, and make it a committing AEAD scheme. NIST has recently announced a pre-draft call for comments to standardise AEAD schemes that can encrypt larger amounts of data and admit larger nonces. The call lists two approaches. The first is to define an analogue of GCM using a 256-bit blockcipher, and the second is based on a recent proposal by Gueron, to extend GCM with a key derivation function (KDF) called $\mathsf{DNDK}$ to increase its security. The latter has clear benefits in terms of backwards compatibility and is likely to be the preferred interim solution. Moreover, $\mathsf{DNDK}$-$\mathsf{GCM}$ is already deployed in production at Meta. $\mathsf{DNDK}$ is essentially a BBB-secure expanding weak pseudorandom function with a domain size of 192 bits realised from AES. We here propose an alternative AES-based KDF called $\mathsf{♯Pencil}$ with comparable efficiency but stronger provable security guarantees. Specifically, $\mathsf{♯Pencil}$ is a full PRF, whereas $\mathsf{DNDK}$ is only a weak PRF, which allows us to prove the $\mathsf{♯Pencil}$-$\mathsf{GCM}$ composition secure as an AEAD scheme. Our most technically challenging result is to show that $\mathsf{♯Pencil}$ is committing, whereas $\mathsf{DNDK}$ claims this property without proof. Finally, in contrast to $\mathsf{DNDK}$ and other alternatives, $\mathsf{♯Pencil}$ can be safely used with arbitrary (non-random) nonces and remains committing even when the nonce is not included as part of the ciphertext.
Note: [04/04/25] Fixed some typos and added a missing condition for the expansion matrix U. [09/06/26] Complete overhaul to extended version of the paper published in CRYPTO 2026, with new co-author (Chandranan Dhar) and major changes throughout the paper. [18/06/26] Added acknowledgements.
Metadata
- Available format(s)
-
PDF
- Category
- Secret-key cryptography
- Publication info
- A major revision of an IACR publication in CRYPTO 2026
- Keywords
- BBB PRFDNDK-GCMNonce DoublingKeystream GenerationPencil
- Contact author(s)
-
bhaumik ritam @ gmail com
jeanpaul degabriele @ tii ae
chandranandhar @ gmail com - History
- 2026-06-18: last of 3 revisions
- 2025-02-28: received
- See all versions
- Short URL
- https://ia.cr/2025/383
- License
-
CC BY-NC-SA
BibTeX
@misc{cryptoeprint:2025/383,
author = {Ritam Bhaumik and Jean Paul Degabriele and Chandranan Dhar},
title = {$\mathsf{♯Pencil}$: A Domain-Extended Committing {BBB} {PRF} for Strengthening {GCM}},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/383},
year = {2025},
url = {https://eprint.iacr.org/2025/383}
}