ExplorerComputer ScienceCybersecurity
Research PaperResearchia:202608.17017

Lower Bounds on Black-Box Constructions of Pseudorandom Functions

Bar Alon

Abstract

In their seminal work, Goldreich, Goldwasser, and Micali [CRYPTO 1984] constructed a pseudorandom function (PRF) using a black-box access to a pseudorandom generator (PRG). When combined with Levin's domain extension technique, the GGM construction invokes the PRG $ω(\log n)$ times, where $n$ denotes the input length to the PRG. To this day, no black-box construction achieving fewer calls is known. Recently, Beimel, Malkin, and Mazor [CRYPTO 2024] showed that for a certain family of constructi...

Submitted: August 17, 2026Subjects: Cybersecurity; Computer Science

Description / Details

In their seminal work, Goldreich, Goldwasser, and Micali [CRYPTO 1984] constructed a pseudorandom function (PRF) using a black-box access to a pseudorandom generator (PRG). When combined with Levin's domain extension technique, the GGM construction invokes the PRG ω(logn)ω(\log n) times, where nn denotes the input length to the PRG. To this day, no black-box construction achieving fewer calls is known. Recently, Beimel, Malkin, and Mazor [CRYPTO 2024] showed that for a certain family of constructions, which they termed \emph{tree constructions}, the GGM construction is optimal. However, the basic challenge of whether a PRF can be built with just \emph{one invocation} of the PRG still remains open. In this work, we consider fully black-box constructions of PRFs from PRGs, where both the construction and the reduction are required to be black-box, and the number of interactions the reduction makes with the adversary is independent of the number of oracle calls the adversary makes to its underlying function within each interaction. Our main result shows that no such construction can have o(n/logn)o(n/\log n) and o(in/login)o(\mathsf{in}/\log\mathsf{in}) \emph{non-adaptive} calls to the PRG, where in\mathsf{in} is the input length of the PRF. This impossibility holds even for weak PRFs with one-bit output, where the adversary is restricted to making i.i.d. uniformly random queries. In addition, we prove a lower bound for weak PRFs with sufficiently long outputs that holds even when the construction is allowed to make adaptive queries to the PRG.


Source: arXiv:2608.14501v1 - http://arxiv.org/abs/2608.14501v1 PDF: https://arxiv.org/pdf/2608.14501v1 Original Link: http://arxiv.org/abs/2608.14501v1

Please sign in to join the discussion.

No comments yet. Be the first to share your thoughts!

Access Paper
View Source PDF
Submission Info
Date:
Aug 17, 2026
Topic:
Computer Science
Area:
Cybersecurity
Comments:
0
Bookmark