

























Avijit Dutta, Institute for Advancing Intelligence, TCG CREST, AcSIR
Tetsu Iwata, Nagoya University
Ashwin Jha, Ruhr University Bochum
Kazuhiko Minematsu, NEC Corporation
Mridul Nandi, Indian Statistical Institute, Kolkata
Yu Sasaki, NTT Social Informatics Laboratories
Meltem Sönmez Turan, National Institute of Standards and Technology
Stefano Tessaro, University of Washington
We consider FB-PRF, one of the key derivation functions defined in NIST SP 800-108 constructed from a pseudorandom function in a feedback mode. The standard allows some flexibility in the specification, and we show that one specific instance of FB-PRF allows an efficient distinguishing attack.
BibTeX
@misc{cryptoeprint:2025/1586,
author = {Ritam Bhaumik and Avijit Dutta and Tetsu Iwata and Ashwin Jha and Kazuhiko Minematsu and Mridul Nandi and Yu Sasaki and Meltem Sönmez Turan and Stefano Tessaro},
title = {A Note on Feedback-{PRF} Mode of {KDF} from {NIST} {SP} 800-108},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/1586},
year = {2025},
url = {https://eprint.iacr.org/2025/1586}
}
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。