Paper 2026/2092

Indifferentiability of the Sum of Two Permutations: Tight 3n/4 Security for the Uniform Simulator and a New Simulator for 4n/5 Security

Sunyeop Kim
Abstract

We study the regular indifferentiability of the sum of two n-bit permutations. Previous work proved 2n/3-bit security and gave a 5n/6-bit attack against the uniform simulator. We prove 3n/4-bit se curity for the simulator and give a matching attack. Our proof bounds the KL divergence between response distributions by tracking the bias in unrevealed construction values through their conditional distribution, which was not analysed in detail in previous work. To exceed this thresh old, we introduce the Gyroscope simulator, which adjusts inverse-query acceptance probabilities to compensate for the bias left by earlier re sponses. The Gyroscope simulator achieves 4n/5-bit security.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
Indifferentiabilitysum of permutationssimulatordistinguishing attacks
Contact author(s)
sunyeopkim @ korea ac kr
History
2026-09-22: revised
2026-09-18: received
See all versions
Short URL
https://ia.cr/2026/2092
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/2092,
      author = {Sunyeop Kim},
      title = {Indifferentiability of the Sum of Two Permutations: Tight 3n/4 Security for the Uniform Simulator and a New Simulator for 4n/5 Security},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2092},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2092}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.