<?xml version="1.0" encoding="UTF-8"?>

<modsCollection xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd">
<mods version="3.3">

<genre>conference paper</genre>

<titleInfo><title>The exact PRF security of truncation: Tight bounds for keyed sponges and truncated CBC</title></titleInfo>

  
  
<titleInfo type="alternative">
  
  <title>LNCS</title>
</titleInfo>

<note type="publicationStatus">published</note>


<note type="qualityControlled">yes</note>

<name type="personal">
  <namePart type="given">Peter</namePart>
  <namePart type="family">Gazi</namePart>
  <role><roleTerm type="text">author</roleTerm> </role><identifier type="local">3E0BFE38-F248-11E8-B48F-1D18A9856A87</identifier></name>
<name type="personal">
  <namePart type="given">Krzysztof Z</namePart>
  <namePart type="family">Pietrzak</namePart>
  <role><roleTerm type="text">author</roleTerm> </role><identifier type="local">3E04A7AA-F248-11E8-B48F-1D18A9856A87</identifier><description xsi:type="identifierDefinition" type="orcid">0000-0002-9139-1654</description></name>
<name type="personal">
  <namePart type="given">Stefano</namePart>
  <namePart type="family">Tessaro</namePart>
  <role><roleTerm type="text">author</roleTerm> </role></name>







<name type="corporate">
  <namePart></namePart>
  <identifier type="local">KrPi</identifier>
  <role>
    <roleTerm type="text">department</roleTerm>
  </role>
</name>



<name type="conference">
  <namePart>CRYPTO: International Cryptology Conference</namePart>
</name>



<name type="corporate">
  <namePart>Provable Security for Physical Cryptography</namePart>
  <role><roleTerm type="text">project</roleTerm></role>
</name>



<abstract lang="eng">This paper studies the concrete security of PRFs and MACs obtained by keying hash functions based on the sponge paradigm. One such hash function is KECCAK, selected as NIST’s new SHA-3 standard. In contrast to other approaches like HMAC, the exact security of keyed sponges is not well understood. Indeed, recent security analyses delivered concrete security bounds which are far from existing attacks. This paper aims to close this gap. We prove (nearly) exact bounds on the concrete PRF security of keyed sponges using a random permutation. These bounds are tight for the most relevant ranges of parameters, i.e., for messages of length (roughly) l ≤ min{2n/4, 2r} blocks, where n is the state size and r is the desired output length; and for l ≤ q queries (to the construction or the underlying permutation). Moreover, we also improve standard-model bounds. As an intermediate step of independent interest, we prove tight bounds on the PRF security of the truncated CBC-MAC construction, which operates as plain CBC-MAC, but only returns a prefix of the output.</abstract>

<relatedItem type="constituent">
  <location>
    <url displayLabel="IST-2016-673-v1+1_053.pdf">https://research-explorer.ista.ac.at/download/1671/4827/IST-2016-673-v1+1_053.pdf</url>
  </location>
  <physicalDescription><internetMediaType>application/pdf</internetMediaType></physicalDescription><accessCondition type="restrictionOnAccess">no</accessCondition>
</relatedItem>
<originInfo><publisher>Springer</publisher><dateIssued encoding="w3cdtf">2015</dateIssued><place><placeTerm type="text">Santa Barbara, CA, United States</placeTerm></place>
</originInfo>
<language><languageTerm authority="iso639-2b" type="code">eng</languageTerm>
</language>



<relatedItem type="host">
  <identifier type="ISI">000364183000018</identifier><identifier type="doi">10.1007/978-3-662-47989-6_18</identifier>
<part><detail type="volume"><number>9215</number></detail><extent unit="pages">368 - 387</extent>
</part>
</relatedItem>


<extension>
<bibliographicCitation>
<short>P. Gazi, K.Z. Pietrzak, S. Tessaro, in:, Springer, 2015, pp. 368–387.</short>
<mla>Gazi, Peter, et al. &lt;i&gt;The Exact PRF Security of Truncation: Tight Bounds for Keyed Sponges and Truncated CBC&lt;/i&gt;. Vol. 9215, Springer, 2015, pp. 368–87, doi:&lt;a href=&quot;https://doi.org/10.1007/978-3-662-47989-6_18&quot;&gt;10.1007/978-3-662-47989-6_18&lt;/a&gt;.</mla>
<chicago>Gazi, Peter, Krzysztof Z Pietrzak, and Stefano Tessaro. “The Exact PRF Security of Truncation: Tight Bounds for Keyed Sponges and Truncated CBC,” 9215:368–87. Springer, 2015. &lt;a href=&quot;https://doi.org/10.1007/978-3-662-47989-6_18&quot;&gt;https://doi.org/10.1007/978-3-662-47989-6_18&lt;/a&gt;.</chicago>
<ista>Gazi P, Pietrzak KZ, Tessaro S. 2015. The exact PRF security of truncation: Tight bounds for keyed sponges and truncated CBC. CRYPTO: International Cryptology Conference, LNCS, vol. 9215, 368–387.</ista>
<apa>Gazi, P., Pietrzak, K. Z., &amp;#38; Tessaro, S. (2015). The exact PRF security of truncation: Tight bounds for keyed sponges and truncated CBC (Vol. 9215, pp. 368–387). Presented at the CRYPTO: International Cryptology Conference, Santa Barbara, CA, United States: Springer. &lt;a href=&quot;https://doi.org/10.1007/978-3-662-47989-6_18&quot;&gt;https://doi.org/10.1007/978-3-662-47989-6_18&lt;/a&gt;</apa>
<ama>Gazi P, Pietrzak KZ, Tessaro S. The exact PRF security of truncation: Tight bounds for keyed sponges and truncated CBC. In: Vol 9215. Springer; 2015:368-387. doi:&lt;a href=&quot;https://doi.org/10.1007/978-3-662-47989-6_18&quot;&gt;10.1007/978-3-662-47989-6_18&lt;/a&gt;</ama>
<ieee>P. Gazi, K. Z. Pietrzak, and S. Tessaro, “The exact PRF security of truncation: Tight bounds for keyed sponges and truncated CBC,” presented at the CRYPTO: International Cryptology Conference, Santa Barbara, CA, United States, 2015, vol. 9215, pp. 368–387.</ieee>
</bibliographicCitation>
</extension>
<recordInfo><recordIdentifier>1671</recordIdentifier><recordCreationDate encoding="w3cdtf">2018-12-11T11:53:23Z</recordCreationDate><recordChangeDate encoding="w3cdtf">2025-09-23T13:50:18Z</recordChangeDate>
</recordInfo>
</mods>
</modsCollection>
