Questions tagged [indifferentiability]
4 questions
4
votes
1 answer
Visibility of oracle queries in the Indifferentiability model
I have a construction $C$ which internally uses idealized primitive $\mathcal{P}$ (a random permutation) where the goal is that $C$ is indifferentiable from a random oracle $\mathcal{F}$. That is, $C$ implements the API of $\mathcal{F}$. Via the…
PeterRindal
- 83
- 6
3
votes
1 answer
Indifferentiability of Sponge Construction
In the case of sponge construction, it is shown to be differentiable from a RO. In the paper by Bertoni et al., what is meant by the node being saturated. How does it become saturated and the condition which leads to error in the simulator was not…
Crypto_Research
- 719
- 3
- 10
1
vote
0 answers
(In)Differentiability of Feistel Network?
An $n$-round Feistel network is a key-ed permutation defined by
$$
{\sf Fstl}^{(m)}_{k_1,\dots,k_m}(L,R) := {\sf Fstl}^{(m-1)}_{k_1,\dots,k_{m-1}}\big(
R, L\oplus F_{k_m}(R)
\big)\;,
$$
with the convention that ${\sf Fstl}^{(0)}:={\sf Id}$.
It…
Yu-Hsuan Huang
- 212
- 9
1
vote
1 answer
Reset Indifferentiability need and it's implications
What is reset indifferentiability? Why practical hash functions cannot satisfy reset indifferentiability. What are the implication of reset indifferentiability.
Crypto_Research
- 719
- 3
- 10