<?xml version="1.0" encoding="UTF-8"?>

<modsCollection xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd">
<mods version="3.3">

<genre>conference paper</genre>

<titleInfo><title>(Verifiable) delay functions from Lucas sequences</title></titleInfo>

  
  
<titleInfo type="alternative">
  
  <title>LNCS</title>
</titleInfo>



<note type="qualityControlled">yes</note>

<name type="personal">
  <namePart type="given">Charlotte</namePart>
  <namePart type="family">Hoffmann</namePart>
  <role><roleTerm type="text">author</roleTerm> </role><identifier type="local">0f78d746-dc7d-11ea-9b2f-83f92091afe7</identifier><description xsi:type="identifierDefinition" type="orcid">0000-0003-2027-5549</description></name>
<name type="personal">
  <namePart type="given">Pavel</namePart>
  <namePart type="family">Hubáček</namePart>
  <role><roleTerm type="text">author</roleTerm> </role></name>
<name type="personal">
  <namePart type="given">Chethan</namePart>
  <namePart type="family">Kamath</namePart>
  <role><roleTerm type="text">author</roleTerm> </role></name>
<name type="personal">
  <namePart type="given">Tomáš</namePart>
  <namePart type="family">Krňák</namePart>
  <role><roleTerm type="text">author</roleTerm> </role></name>







<name type="corporate">
  <namePart></namePart>
  <identifier type="local">KrPi</identifier>
  <role>
    <roleTerm type="text">department</roleTerm>
  </role>
</name>



<name type="conference">
  <namePart>TCC: Theory of Cryptography</namePart>
</name>






<abstract lang="eng">Lucas sequences are constant-recursive integer sequences with a long history of applications in cryptography, both in the design of cryptographic schemes and cryptanalysis. In this work, we study the sequential hardness of computing Lucas sequences over an RSA modulus.
First, we show that modular Lucas sequences are at least as sequentially hard as the classical delay function given by iterated modular squaring proposed by Rivest, Shamir, and Wagner (MIT Tech. Rep. 1996) in the context of time-lock puzzles. Moreover, there is no obvious reduction in the other direction, which suggests that the assumption of sequential hardness of modular Lucas sequences is strictly weaker than that of iterated modular squaring. In other words, the sequential hardness of modular Lucas sequences might hold even in the case of an algorithmic improvement violating the sequential hardness of iterated modular squaring.
Second, we demonstrate the feasibility of constructing practically-efficient verifiable delay functions based on the sequential hardness of modular Lucas sequences. Our construction builds on the work of Pietrzak (ITCS 2019) by leveraging the intrinsic connection between the problem of computing modular Lucas sequences and exponentiation in an appropriate extension field.</abstract>

<originInfo><publisher>Springer Nature</publisher><dateIssued encoding="w3cdtf">2023</dateIssued><place><placeTerm type="text">Taipei, Taiwan</placeTerm></place>
</originInfo>
<language><languageTerm authority="iso639-2b" type="code">eng</languageTerm>
</language>



<relatedItem type="host"><titleInfo><title>21st International Conference on Theory of Cryptography</title></titleInfo>
  <identifier type="issn">0302-9743</identifier>
  <identifier type="eIssn">1611-3349</identifier>
  <identifier type="isbn">9783031486234</identifier>
  <identifier type="ISI">001160733700013</identifier><identifier type="doi">10.1007/978-3-031-48624-1_13</identifier>
<part><detail type="volume"><number>14372</number></detail><extent unit="pages">336-362</extent>
</part>
</relatedItem>


<extension>
<bibliographicCitation>
<short>C. Hoffmann, P. Hubáček, C. Kamath, T. Krňák, in:, 21st International Conference on Theory of Cryptography, Springer Nature, 2023, pp. 336–362.</short>
<ama>Hoffmann C, Hubáček P, Kamath C, Krňák T. (Verifiable) delay functions from Lucas sequences. In: &lt;i&gt;21st International Conference on Theory of Cryptography&lt;/i&gt;. Vol 14372. Springer Nature; 2023:336-362. doi:&lt;a href=&quot;https://doi.org/10.1007/978-3-031-48624-1_13&quot;&gt;10.1007/978-3-031-48624-1_13&lt;/a&gt;</ama>
<mla>Hoffmann, Charlotte, et al. “(Verifiable) Delay Functions from Lucas Sequences.” &lt;i&gt;21st International Conference on Theory of Cryptography&lt;/i&gt;, vol. 14372, Springer Nature, 2023, pp. 336–62, doi:&lt;a href=&quot;https://doi.org/10.1007/978-3-031-48624-1_13&quot;&gt;10.1007/978-3-031-48624-1_13&lt;/a&gt;.</mla>
<chicago>Hoffmann, Charlotte, Pavel Hubáček, Chethan Kamath, and Tomáš Krňák. “(Verifiable) Delay Functions from Lucas Sequences.” In &lt;i&gt;21st International Conference on Theory of Cryptography&lt;/i&gt;, 14372:336–62. Springer Nature, 2023. &lt;a href=&quot;https://doi.org/10.1007/978-3-031-48624-1_13&quot;&gt;https://doi.org/10.1007/978-3-031-48624-1_13&lt;/a&gt;.</chicago>
<ieee>C. Hoffmann, P. Hubáček, C. Kamath, and T. Krňák, “(Verifiable) delay functions from Lucas sequences,” in &lt;i&gt;21st International Conference on Theory of Cryptography&lt;/i&gt;, Taipei, Taiwan, 2023, vol. 14372, pp. 336–362.</ieee>
<apa>Hoffmann, C., Hubáček, P., Kamath, C., &amp;#38; Krňák, T. (2023). (Verifiable) delay functions from Lucas sequences. In &lt;i&gt;21st International Conference on Theory of Cryptography&lt;/i&gt; (Vol. 14372, pp. 336–362). Taipei, Taiwan: Springer Nature. &lt;a href=&quot;https://doi.org/10.1007/978-3-031-48624-1_13&quot;&gt;https://doi.org/10.1007/978-3-031-48624-1_13&lt;/a&gt;</apa>
<ista>Hoffmann C, Hubáček P, Kamath C, Krňák T. 2023. (Verifiable) delay functions from Lucas sequences. 21st International Conference on Theory of Cryptography. TCC: Theory of Cryptography, LNCS, vol. 14372, 336–362.</ista>
</bibliographicCitation>
</extension>
<recordInfo><recordIdentifier>14693</recordIdentifier><recordCreationDate encoding="w3cdtf">2023-12-17T23:00:54Z</recordCreationDate><recordChangeDate encoding="w3cdtf">2025-09-09T14:01:23Z</recordChangeDate>
</recordInfo>
</mods>
</modsCollection>
