Although it is well known that all basic private-key cryptographic primitives can be built from one-way functions, finding weak assumptions from which practical implementations of such primitives exist remains a challenging task. Towards this goal, this paper introduces the notion of a constant-query weak PRF , a function with a secret key which is computationally indistinguishable from a truly random function when evaluated at a constant number s of known random inputs, where s can be as small as two.
We provide iterated constructions of (arbitrary-input-length) PRFs from constant-query weak PRFs that even improve the efficiency of previous constructions based on the stronger assumption of a weak PRF (where polynomially many evaluations are allowed).
One of our constructions directly provides a new mode of operation using a constant-query weak PRF for IND-CPA symmetric encryption which is essentially as efficient as conventional PRF-based counter-mode encryption. Furthermore, our constructions yield efficient modes of operation for keying hash functions (such as MD5 and SHA-1) to obtain iterated PRFs (and hence MACs) which rely solely on the assumption that the underlying compression function is a constant-query weak PRF, which is the weakest assumption ever considered in this context.
尽管众所周知,所有基本的私钥加密原语都可以通过单向功能来构建,但发现这些原始词实际实现的假设较弱仍然是一项艰巨的任务。为了实现这一目标,本文介绍了常数弱PRF的概念,该函数具有秘密键,当以恒定的已知随机输入的常数s评估时,与真正随机的函数在计算上无法区分,其中s可以像小一样小作为两个。
我们提供了(任意输入长度)PRF的迭代构建体,这些构建体来自恒定弱PRF,甚至基于更强的弱PRF假设(在多个方面允许许多评估)基于更强的假设(在多个评估中)提高了先前构建体的效率。
我们的构造中的一种直接使用恒定的弱PRF用于IND-CPA对称加密,提供了一种新的操作模式,该加密本质上与常规的基于PRF的反模式加密效率同样有效。此外,我们的构造产生有效的操作模式,用于键入哈希功能(例如MD5和SHA-1),以获得迭代的PRF(以及MAC),这些PRF(以及MACS)仅依赖于以下假设:基础压缩函数是常数弱弱PRF,这是在这种情况下考虑的最弱的假设。