On Oct 31, 2005, at 1:10 PM, D. J. Bernstein wrote:
OK, clearly I'm in way over my head, but isn't that what the discussion about the Leftover Hash Lemma was about? Doesn't that lemma guarantee that UH(R,SV) is delta-uniform when R is chosen independently of SV? And if the output of UH is delta-uniform, then isn't the PRF secure under standard assumptions? I know this falls far short of a real proof, but, as I said, I'm in over my head here. -John |
_______________________________________________ Cfrg mailing list Cfrg at ietf.org https://www1.ietf.org/mailman/listinfo/cfrg