Constructions of PRF (Pseudo Random Function)The Goldreich-Goldwasser-Micali Construction with bad PRGSSecurity of KDF1 and KDF2 (hash based KDF's)Implementing a pseudo random function in practiceCryptanalysis of Marvin32 compared to SipHashPseudo Random FunctionWhy is this function pseudo random (PRF)?Decentralized consent over a random numberExistence of PRF $implies$ existence of PRGDoes a distinguisher for an PRF based on a hash make the hash function insecure?Can we convert a pseudorandom function (PRF) to an Oblivious PRF (OPRF) through an Oblivious Transfer (OT) protocol?

Was there a Viking Exchange as well as a Columbian one?

What happens to Mjolnir (Thor's hammer) at the end of Endgame?

can anyone help me with this awful query plan?

Read line from file and process something

Extension of 2-adic valuation to the real numbers

How did Captain America manage to do this?

Does a large simulator bay have standard public address announcements?

Can't get 5V 3A DC constant

Does tea made with boiling water cool faster than tea made with boiled (but still hot) water?

Function pointer with named arguments?

How can I get this effect? Please see the attached image

Can an Area of Effect spell cast outside a Prismatic Wall extend inside it?

What are the steps to solving this definite integral?

Like totally amazing interchangeable sister outfits II: The Revenge

Rivers without rain

Retract an already submitted recommendation letter (written for an undergrad student)

How does Captain America channel this power?

Contradiction proof for inequality of P and NP?

Why does Mind Blank stop the Feeblemind spell?

How to limit Drive Letters Windows assigns to new removable USB drives

"The cow" OR "a cow" OR "cows" in this context

"Whatever a Russian does, they end up making the Kalashnikov gun"? Are there any similar proverbs in English?

Checks user level and limit the data before saving it to mongoDB

a sore throat vs a strep throat vs strep throat



Constructions of PRF (Pseudo Random Function)


The Goldreich-Goldwasser-Micali Construction with bad PRGSSecurity of KDF1 and KDF2 (hash based KDF's)Implementing a pseudo random function in practiceCryptanalysis of Marvin32 compared to SipHashPseudo Random FunctionWhy is this function pseudo random (PRF)?Decentralized consent over a random numberExistence of PRF $implies$ existence of PRGDoes a distinguisher for an PRF based on a hash make the hash function insecure?Can we convert a pseudorandom function (PRF) to an Oblivious PRF (OPRF) through an Oblivious Transfer (OT) protocol?













2












$begingroup$


I was taught only GGM based PRF construction in class. It's very inefficient. I am just curious about various PRF constructions from standard assumptions. Please provide a few PRF constructions from various assumptions.










share|improve this question









$endgroup$











  • $begingroup$
    Well, one standard assumption is that the SHA-256 compression function is a PRF, from which we can conclude that HMAC-SHA256 is a PRF (and a reasonably efficient one at that), but maybe you meant to restrict the domain of ‘standard assumptions’?
    $endgroup$
    – Squeamish Ossifrage
    3 hours ago
















2












$begingroup$


I was taught only GGM based PRF construction in class. It's very inefficient. I am just curious about various PRF constructions from standard assumptions. Please provide a few PRF constructions from various assumptions.










share|improve this question









$endgroup$











  • $begingroup$
    Well, one standard assumption is that the SHA-256 compression function is a PRF, from which we can conclude that HMAC-SHA256 is a PRF (and a reasonably efficient one at that), but maybe you meant to restrict the domain of ‘standard assumptions’?
    $endgroup$
    – Squeamish Ossifrage
    3 hours ago














2












2








2





$begingroup$


I was taught only GGM based PRF construction in class. It's very inefficient. I am just curious about various PRF constructions from standard assumptions. Please provide a few PRF constructions from various assumptions.










share|improve this question









$endgroup$




I was taught only GGM based PRF construction in class. It's very inefficient. I am just curious about various PRF constructions from standard assumptions. Please provide a few PRF constructions from various assumptions.







pseudo-random-generator pseudo-random-function






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked 4 hours ago









satyasatya

441317




441317











  • $begingroup$
    Well, one standard assumption is that the SHA-256 compression function is a PRF, from which we can conclude that HMAC-SHA256 is a PRF (and a reasonably efficient one at that), but maybe you meant to restrict the domain of ‘standard assumptions’?
    $endgroup$
    – Squeamish Ossifrage
    3 hours ago

















  • $begingroup$
    Well, one standard assumption is that the SHA-256 compression function is a PRF, from which we can conclude that HMAC-SHA256 is a PRF (and a reasonably efficient one at that), but maybe you meant to restrict the domain of ‘standard assumptions’?
    $endgroup$
    – Squeamish Ossifrage
    3 hours ago
















$begingroup$
Well, one standard assumption is that the SHA-256 compression function is a PRF, from which we can conclude that HMAC-SHA256 is a PRF (and a reasonably efficient one at that), but maybe you meant to restrict the domain of ‘standard assumptions’?
$endgroup$
– Squeamish Ossifrage
3 hours ago





$begingroup$
Well, one standard assumption is that the SHA-256 compression function is a PRF, from which we can conclude that HMAC-SHA256 is a PRF (and a reasonably efficient one at that), but maybe you meant to restrict the domain of ‘standard assumptions’?
$endgroup$
– Squeamish Ossifrage
3 hours ago











1 Answer
1






active

oldest

votes


















4












$begingroup$

The most common efficient PRFs from specific assumptions are:



The Naor-Reingold PRF, which is based on the decision Diffie-Hellman assumption (DDH), and



The BPR PRF, which is based on the learning with error assumption (LWE).



Perhaps slightly less well-known is the NRR PRF, which is based on the hardness of factoring.






share|improve this answer









$endgroup$













    Your Answer








    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "281"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: false,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: null,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    noCode: true, onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fcrypto.stackexchange.com%2fquestions%2f70083%2fconstructions-of-prf-pseudo-random-function%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    1 Answer
    1






    active

    oldest

    votes








    1 Answer
    1






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    4












    $begingroup$

    The most common efficient PRFs from specific assumptions are:



    The Naor-Reingold PRF, which is based on the decision Diffie-Hellman assumption (DDH), and



    The BPR PRF, which is based on the learning with error assumption (LWE).



    Perhaps slightly less well-known is the NRR PRF, which is based on the hardness of factoring.






    share|improve this answer









    $endgroup$

















      4












      $begingroup$

      The most common efficient PRFs from specific assumptions are:



      The Naor-Reingold PRF, which is based on the decision Diffie-Hellman assumption (DDH), and



      The BPR PRF, which is based on the learning with error assumption (LWE).



      Perhaps slightly less well-known is the NRR PRF, which is based on the hardness of factoring.






      share|improve this answer









      $endgroup$















        4












        4








        4





        $begingroup$

        The most common efficient PRFs from specific assumptions are:



        The Naor-Reingold PRF, which is based on the decision Diffie-Hellman assumption (DDH), and



        The BPR PRF, which is based on the learning with error assumption (LWE).



        Perhaps slightly less well-known is the NRR PRF, which is based on the hardness of factoring.






        share|improve this answer









        $endgroup$



        The most common efficient PRFs from specific assumptions are:



        The Naor-Reingold PRF, which is based on the decision Diffie-Hellman assumption (DDH), and



        The BPR PRF, which is based on the learning with error assumption (LWE).



        Perhaps slightly less well-known is the NRR PRF, which is based on the hardness of factoring.







        share|improve this answer












        share|improve this answer



        share|improve this answer










        answered 3 hours ago









        Geoffroy CouteauGeoffroy Couteau

        9,29011834




        9,29011834



























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Cryptography Stack Exchange!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid …


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            Use MathJax to format equations. MathJax reference.


            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fcrypto.stackexchange.com%2fquestions%2f70083%2fconstructions-of-prf-pseudo-random-function%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            Which organization defines CJK Unified Ideographs? The Next CEO of Stack OverflowCharacters which have several different shapesHow useful are the kanji in reading Chinese?Can Chinese readers scan large amounts of text faster/more accurately than their alphabet-using counterparts?丼: why is “well” also “bowl of food”?What Does Unicode 8.0 Mean For Chinese?How are blanks indicated for placeholders in Chinese (like ???)Is there a dictionary of standard character variants?How to display CJK Extension F?How is it decided as to which character is used on the tech terminology?How does 子 come to mean 'midnight'?

            Shenzhen Football Club Índice Elenco atual | Títulos | Referências Ligações externas | Menu de navegaçãoGooglenotíciaslivrosacadêmicoeditar«"Elenco"»Site oficialexpandindo-oeee

            When We Were Young (canção de Adele) Índice Antecedentes e lançamento | Faixas e formatos | Performances e covers | Desempenho nas tabelas musicais | Créditos | Histórico de lançamento | Referências Menu de navegação«Best albums of 2015»«Adele - When We Were Young (Radio Date: 22-01-2016)»«When We Were Young - Single by Adele»«Adele: Inside Her Private Life and Triumphant Return»«adele interview: world exclusive first interview in three years»«Tobias Jesso Jr: since Adele tweeted his song, he's even bigger than his dad»«Adele interviews Tobias Jesso Jr: 'I think that a couple of the ideas we had could be rap songs'»«Adele on Her Return: 'I Was So Frightened That No One Cared'»«Tobias Jesso Jr. on working with Adele: 'I was as nervous as shit'»«How Ariel Rechtshaid Pushed Adele To Her Limit»«Adele Previews 'When We Were Young' on '60 Minutes' Teaser, Tops Trending 140»«Adele Performs New '25' Ballad, "When We Were Young" Live: Watch»«Which '25' Song Should Be Adele's Next Single?»«Adele's 'When We Were Young' Confirmed As Second Single From '25'»«Adele's new single artwork for 'When We Were Young' is perfectly adorable»«Adele at the BBC review: honest, funny and spectacular – Celebrity News News»«'Saturday Night Live': Adele Sings 'Hello' and 'When We Were Young'»«'Adele: Live in New York City' NBC Special – Set List Revealed!»«Adele Closes Out the 2016 Brit Awards With 'When We Were Young'»«What Is The Adele Live Tour Set List? There's No Way She'd Leave Out These 8 Songs»«See Demi Lovato's Soaring Cover of Adele's 'When We Were Young'»«'The Voice': 5 Best Moments From Week 1 Blind Auditions»«Adele – When We Were Young (Media Control Charts)»«Adele – When We Were Young (Entertainment Monitoring Africa)»«Adele – When We Were Young (ARIA Charts)»«Adele – When We Were Young (Ö3 Austria Top 40)»«Adele – When We Were Young (Ultratop 50)»«Adele – When We Were Young (Ultratop 40)»«Adele – When We Were Young (Canadian Hot 100)»«Adele – When We Were Young (Tracklisten)»«Adele – When We Were Young (The Official Charts Company)»«Adele – Hello (IFPI Slovenská Republika)»«Adele – When We Were Young (Productores de Música de España)»«Adele – When We Were Young (Billboard Hot 100)»«Adele – When We Were Young (Pop Songs)»«Adele – When We Were Young (Adult Pop Songs)»«Adele – When We Were Young (Hot Adult Contemporary Charts)»«Adele – When We Were Young (Hot Dance Club Songs)»«Adele – When We Were Young (Rock Airplay)»«Adele – When We Were Young (IFPI Finlândia)»«Adele – When We Were Young (Syndicat National de l'Éditon Phonographique)»«Adele – When We Were Young (Magyar Hanglemezkiadók Szövetsége)»«Adele – When We Were Young (Irish Recorded Music Association)»«Adele – When We Were Young (Mexico Airplay)»«Adele – When We Were Young (VG-lista)»«Adele – When We Were Young (NZ Top 40 Singles)»«Adele – When We Were Young (MegaCharts)»«Adele – When We Were Young (Związek Producentów Audio Video)»«Adele – When We Were Young (Portugal Digital Songs)»«Adele – When We Were Young (UK Indie Singles Chart)»«Adele – When We Were Young (UK Singles Chart)»«Adele – When We Were Young (Sverigetopplistan)»«Adele – When We Were Young (Schweizer Hitparade)»«Adele – When We Were Young (Portugal Digital Songs)»«Music Canada – Gold/Platinum – When We Were Young»«NZ Top 40 Singles Chart»«Certified Awards»e