How to Stretch Random Functions: The Security of Protected Counter Sums
Daniel J. Bernstein
SVM HeaderParse 0.1
SVM HeaderParse 0.2
. Let f be an unpredictable random function taking (b + c)-bit inputs to b-bit outputs. This paper presents an unpredictable random function f 0 taking variable-length inputs to b-bit outputs. This construction has several advantages over chaining, which was proven unpredictable by Bellare, Kilian, and Rogaway, and cascading, which was proven unpredictable by Bellare, Canetti, and Krawczyk. The highlight here is a very simple proof of security. 1.