## CryptoDB

### Paper: On the Concrete Security of Goldreich’s Pseudorandom Generator

Authors: Geoffroy Couteau Aurélien Dupin Pierrick Méaux Mélissa Rossi Yann Rotella DOI: 10.1007/978-3-030-03329-3_4 Search ePrint Search Google Slides ASIACRYPT 2018 Local pseudorandom generators allow to expand a short random string into a long pseudo-random string, such that each output bit depends on a constant number d of input bits. Due to its extreme efficiency features, this intriguing primitive enjoys a wide variety of applications in cryptography and complexity. In the polynomial regime, where the seed is of size n and the output of size $n^{\textsf {s}}$ for $\textsf {s}> 1$ , the only known solution, commonly known as Goldreich’s PRG, proceeds by applying a simple d-ary predicate to public random size-d subsets of the bits of the seed.While the security of Goldreich’s PRG has been thoroughly investigated, with a variety of results deriving provable security guarantees against class of attacks in some parameter regimes and necessary criteria to be satisfied by the underlying predicate, little is known about its concrete security and efficiency. Motivated by its numerous theoretical applications and the hope of getting practical instantiations for some of them, we initiate a study of the concrete security of Goldreich’s PRG, and evaluate its resistance to cryptanalytic attacks. Along the way, we develop a new guess-and-determine-style attack, and identify new criteria which refine existing criteria and capture the security guarantees of candidate local PRGs in a more fine-grained way.
##### BibTeX
@inproceedings{asiacrypt-2018-29160,
title={On the Concrete Security of Goldreich’s Pseudorandom Generator},
booktitle={Advances in Cryptology – ASIACRYPT 2018},
series={Lecture Notes in Computer Science},
publisher={Springer},
volume={11273},
pages={96-124},
doi={10.1007/978-3-030-03329-3_4},
author={Geoffroy Couteau and Aurélien Dupin and Pierrick Méaux and Mélissa Rossi and Yann Rotella},
year=2018
}