Paper 2026/1556

Breaking the Beyond-Birthday-Bound Security of $\sharp\textsf{Pencil}$

Léonard Assouline, Leanear
Cécile Delerablée, Leanear
Abstract

$\sharp\textsf{Pencil}$ is a domain-extended pseudorandom function by Bhaumik et al, accepted at CRYPTO 2026, claiming that it achieves close to $n$-bit security beyond the birthday bound. It is used as the key-derivation layer of the $\sharp\textsf{Pencil}$-CAU authenticated-encryption mode. We show that $\sharp\textsf{Pencil}$ has a birthday-bound collision attack: its front end $\textsf{Sharp}$ compresses the second half $N_2$ of the input through the $(n-8)$-bit value \[ J(N_2) = \operatorname{msb}_{n-8}\bigl({\mathsf{E}}_{K_1}(N_2 || \texttt{0x00})\bigr), \] after which the entire computation is a deterministic function of $(N_1,J)$. Thus, for any fixed $N_1$, distinct values $N_2,N_2'$ satisfying $J(N_2)=J(N_2')$ produce identical $\sharp\textsf{Pencil}$ outputs. Such collisions occur with probability $1-e^{-1}$ after $2^{(n-7)/2}$ queries, $2^{60.5}$ when $n=128$. This yields a PRF distinguisher with constant advantage, contradicting the security bound of Theorem 4. Since $2^{60.5}$ falls below the birthday bound $2^{n/2}$ that the construction was designed to pass, the beyond birthday-bound property does not hold. Given the derived key $K_1$, an explicit collision can be constructed in approximately $10^3$ inverse-cipher evaluations in expectation. The same collision breaks $\sharp\textsf{Pencil}$-CAU, as two nonce-respecting queries can reuse the key and the nonce of the inner GCM instance, yielding the difference of the two plaintexts. The first version of the paper does not have the defect: it left $J$ untruncated, which makes the map injective and invalidates the collisions above. Reverting to it is the remedy we suggest.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Preprint.
Keywords
Pseudo Random FunctionsCryptanalysisBirthday attack
Contact author(s)
la @ leanear io
cd @ leanear io
History
2026-08-11: last of 2 revisions
2026-07-29: received
See all versions
Short URL
https://ia.cr/2026/1556
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1556,
      author = {Léonard Assouline and Cécile Delerablée},
      title = {Breaking the Beyond-Birthday-Bound Security of $\sharp\textsf{Pencil}$},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1556},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1556}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.