Return
Breaking and Fixing MacaKey
DOI:10.46586/tosc.v2026.i1.76-94.png)
Abstract
En 中文
The sponge construction underpins many modern symmetric primitives,enabling efficient hashing and authenticated encryption. While full-state absorptionis known to be secure in keyed sponges, the security of full-state squeezing hasremained unclear. Recently, Lefevre and Marhuenda-Beltr & aacute;n introducedMacaKey,which applies ideas from the summation-truncation hybrid technique of constructingPRFs to the full-state sponge. The authors claimed thatMacaKeyis provably secureup to the birthday bound in capacity, even when the adversary is allowed to requestvariable-length outputs. In this work, we revisit this claim and show thatMacaKeyis insecure as a PRF. We demonstrate a simple four-query distinguishing attackthat violates its claimed bound, exploiting the exposure of the full internal stateand the resulting loss of secrecy in the capacity portion during squeezing. We thenpropose a simple modification that restores security with negligible overhead. Themodified construction,KeyMacaKey, re-randomizes the internal state after absorptionby incorporating a keyed finalization step without requiring an extra permutation call.Further, we show thatKeyMacaKeyachieves the stronger security of birthday-boundin the full state size than what was claimed forMacaKey.
Keywords:
permutation-based cryptography
VIL-VOL PRF
beyond-birthday-bound security
full-state sponge
Journal
I
IF:
2.2
Papers:
21
Citations:
1.1K

