Paper 2026/1556
Breaking the Beyond-Birthday-Bound Security of $\sharp\textsf{Pencil}$
Abstract
$\sharp\textsf{Pencil}$ is a domain-extended pseudorandom function by Bhaumik et al, accepted at CRYPTO 2026, claiming that it achieves close to $n$-bit security beyond the birthday bound. It is used as the key-derivation layer of the $\sharp\textsf{Pencil}$-CAU authenticated-encryption mode. We show that $\sharp\textsf{Pencil}$ has a birthday-bound collision attack: its front end $\textsf{Sharp}$ compresses the second half $N_2$ of the input through the $(n-8)$-bit value \[ J(N_2) = \operatorname{msb}_{n-8}\bigl({\mathsf{E}}_{K_1}(N_2 || \texttt{0x00})\bigr), \] after which the entire computation is a deterministic function of $(N_1,J)$. Thus, for any fixed $N_1$, distinct values $N_2,N_2'$ satisfying $J(N_2)=J(N_2')$ produce identical $\sharp\textsf{Pencil}$ outputs. Such collisions occur with probability $1-e^{-1}$ after $2^{(n-7)/2}$ queries, $2^{60.5}$ when $n=128$. This yields a PRF distinguisher with constant advantage, contradicting the security bound of Theorem 4. Since $2^{60.5}$ falls below the birthday bound $2^{n/2}$ that the construction was designed to pass, the beyond birthday-bound property does not hold. Given the derived key $K_1$, an explicit collision can be constructed in approximately $10^3$ inverse-cipher evaluations in expectation. The same collision breaks $\sharp\textsf{Pencil}$-CAU, as two nonce-respecting queries can reuse the key and the nonce of the inner GCM instance, yielding the difference of the two plaintexts. The first version of the paper does not have the defect: it left $J$ untruncated, which makes the map injective and invalidates the collisions above. Reverting to it is the remedy we suggest.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Preprint.
- Keywords
- Pseudo Random FunctionsCryptanalysisBirthday attack
- Contact author(s)
-
la @ leanear io
cd @ leanear io - History
- 2026-08-11: last of 2 revisions
- 2026-07-29: received
- See all versions
- Short URL
- https://ia.cr/2026/1556
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1556,
author = {Léonard Assouline and Cécile Delerablée},
title = {Breaking the Beyond-Birthday-Bound Security of $\sharp\textsf{Pencil}$},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1556},
year = {2026},
url = {https://eprint.iacr.org/2026/1556}
}