On the indifferentiability of the sponge construction

  • Authors:
  • Guido Bertoni;Joan Daemen;Michaël Peeters;Gilles Van Assche

  • Affiliations:
  • STMicroelectronics;STMicroelectronics;NXP Semiconductors;STMicroelectronics

  • Venue:
  • EUROCRYPT'08 Proceedings of the theory and applications of cryptographic techniques 27th annual international conference on Advances in cryptology
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we prove that the sponge construction introduced in [4] is indifferentiable from a random oracle when being used with a random transformation or a random permutation and discuss its implications. To our knowledge, this is the first time indifferentiability has been shown for a construction calling a random permutation (instead of an ideal compression function or ideal block cipher) and for a construction generating outputs of any length (instead of a fixed length).