A Robust and Sponge-Like PRNG with Improved Efficiency
نویسنده
چکیده
Ever since Keccak won the SHA3 competition, sponge-basedconstructions are being suggested for many different applications, in-cluding pseudo-random number generators (PRNGs). Sponges are verydesirable, being well studied, increasingly efficient to implement and sim-plistic in their design. The initial construction of a sponge-based PRNG(Bertoni et al. CHES 2010) based its security on the well known spongeindifferentiability proof in the random permutation model and providedno forward security. Since then, another improved sponge-based PRNG has been put forwardby Gaži and Tessaro (Eurocrypt 2016) who point out the necessity for apublic seed to prevent an adversarial sampler from gaining non-negligibleadvantage. The authors further update the security model of Dodis etal. (CCS 2013) to accommodate a public random permutation, modelledin the ideal cipher model, and how this affects the notions of security. In this paper we introduce Reverie, an improved and practical, sponge-like pseudo-random number generator together with a formal securityanalysis in the PRNG with input security model of Dodis et al. with themodifications of the Gaži and Tessaro paper. We prove that Reverie is robust when used with a public random per-mutation; robustness is the strongest notion of security in the chosensecurity model. Robustness is proved by establishing two weaker notionsof security, preserving and recovering security, which together, can beshown to imply the robustness result. The proofs utilise the H-coefficienttechnique that has found recent popularity in this area; providing a veryuseful tool for proving the generator meets the necessary security notions.
منابع مشابه
Provably Robust Sponge-Based PRNGs and KDFs
We study the problem of devising provably secure PRNGs with input based on the sponge paradigm. Such constructions are very appealing, as efficient software/hardware implementations of SHA-3 can easily be translated into a PRNG in a nearly black-box way. The only existing sponge-based construction, proposed by Bertoni et al. (CHES 2010), fails to achieve the security notion of robustness recent...
متن کاملOptimization of conditions for gene delivery system based on PEI
Objective(s): PEI based nanoparticle (NP) due to dual capabilities of proton sponge and DNA binding is known as powerful tool for nucleic acid delivery to cells. However, serious cytotoxicity and complicated conditions, which govern NPs properties and its interactions with cells practically, hindered achievement to high transfection efficiency. Here, we have tried to optimize the properties of ...
متن کاملOn Random Numbers And The Performance Of Genetic Algorithms
Pseudo random number generators (PRNGs) are the basic input to the stochastic selection, recombination, and mutation operations of genetic algorithms (GAs). Although it does not seem like a crucial decision, recent studies suggest that the choice of PRNG can affect the performance of GAs. The objective of this paper is to study the effect of PRNGs on a simple GA, and to identify the components ...
متن کاملEvaluating the efficiency of a baffled-filter system with sponge media on removal of turbidity, microbial agents, and total organic carbon from water
Background and Objective: Access to safe water is critical for protecting human health. Turbidity is one of the main physical parameters that affect the quality of water from both health and aesthetical points of view. Therefore, waters should be treated based on the standards set for turbidity before consumption. This study was performed to determine the performance of a bench-scale baffled fi...
متن کاملRobust efficiency in data envelopment analysis with VRS technology
One of the fundamental problems in the classic DEA is lack of ability to distinguish unit's performance scores that is considered as a disadvantage. Recently, Parkan et al. [9] tried to address this problem. They proposed to assess each unit both optimistic and pessimistic views are taken into account. In contrast to traditional evaluation, one index is considered for each unit based on the l...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- IACR Cryptology ePrint Archive
دوره 2016 شماره
صفحات -
تاریخ انتشار 2016