Papers
Topics
Authors
Recent
Search
2000 character limit reached

Cryptanalysis of the Legendre Pseudorandom Function over Extension Fields

Published 6 Apr 2026 in cs.CR and math.NT | (2604.04833v2)

Abstract: The Legendre Pseudorandom Function (PRF) is a highly efficient cryptographic primitive built upon the Legendre symbol, valued for its low multiplicative complexity in Multi-Party Computation (MPC) and Zero-Knowledge Proof (ZKP) protocols. While its security over prime fields F<em>p\mathbb{F}<em>p is well-documented, recent interest has shifted toward instantiations over extension fields F</em>p<sup>r\mathbb{F}</em>{p<sup>r}. This paper presents the first comprehensive cryptanalysis of the single-degree Legendre PRF operating over F<em>p<sup>r\mathbb{F}<em>{p<sup>r}. First, we analyze polynomial input encoding under a standard passive threat model (sequential additive counter queries). We demonstrate that while the absence of polynomial carry-overs causes an asynchronous "no-carry fracture" that neutralizes classical sliding-window collision attacks, the fracture itself is deterministically periodic. By introducing a novel "Differential Signature" bucketing technique, we prove that an adversary can systematically group fractured sequences by their structural shapes to bypass this defense, recovering the secret key in O(U⋅p<sup>r/M)\mathcal{O}(U \cdot p<sup>r/M) operations, where UU is the unicity distance. Second, we evaluate the PRF under an active Chosen-Query threat model. We demonstrate that an adversary can circumvent the additive fracture by evaluating the PRF along a geometric sequence generated by a primitive polynomial. This structure invokes strict multiplicative homomorphism over F<sup>∗</sup></em>p<sup>r\mathbb{F}<sup>*</sup></em>{p<sup>r}, permitting a direct generalization of state-of-the-art table collision attacks to extract the key in O(p<sup>r/M)\mathcal{O}(p<sup>r/M) operations. Finally, we establish the cryptographic boundaries of these attacks, formally proving the necessity of higher-degree key variants (d≥2d \ge 2) to achieve exponential security against structural reduction in extension fields.

Authors (1)

Summary

  • The paper shows that efficient cryptanalytic reductions can fully compromise the d=1 Legendre PRF in extension fields via both passive differential and active multiplicative attacks.
  • It reveals that polynomial input encoding creates predictable differential signatures, which allow for key recovery in polynomial time under certain conditions.
  • The study concludes that using higher-degree PRF variants (d ≥ 2) is essential to prevent algebraic attacks in MPC and ZKP implementations.

Cryptanalysis of the Single-Degree Legendre PRF Over Extension Fields

Overview

This work provides a thorough cryptanalytic assessment of the Legendre Pseudorandom Function (PRF) instantiated over extension fields Fpr\mathbb{F}_{p^r}, focusing on the d=1d=1 case. While previous analyses largely addressed prime fields Fp\mathbb{F}_p, this paper formalizes the impact of polynomial input encoding and examines both passive and active attack models. The results demonstrate efficient cryptanalytic reductions that fully compromise the d=1d=1 Legendre PRF in extension fields and delineate necessary adjustments for security in MPC and ZKP deployments.

Mathematical Construction and Security Model

The Legendre PRF, initially defined on Fp\mathbb{F}_p, exploits the properties of the Legendre symbol for computational efficiency in cryptographic protocols. For extension fields Fpr\mathbb{F}_{p^r}, elements are polynomials, and queries are encoded via base-pp representations mapped polynomially. Crucially, addition in Fp[x]\mathbb{F}_p[x] is coefficient-wise and lacks carry-over, yielding notable structural consequences for PRF inputs in sequence.

For the PRF LK(x)=(x+Kp)L_K(x) = (\frac{x + K}{p}), generalization to Fpr\mathbb{F}_{p^r} involves the multiplicative quadratic character with Euler’s criterion, where statistical properties are governed by Weil bounds. The mapping of integer counters to polynomial field elements and the requirement for d=1d=10 (number of queries) are formalized, ensuring the absence of trivial periodicity in the PRF output.

Passive Cryptanalysis: Differential Signatures

The transition from integer to polynomial input encoding interrupts standard arithmetic progressions needed for classical table collision attacks. The paper demonstrates that, in d=1d=11, the differential between sequential PRF inputs fractures into a small set of d=1d=12 patterns dictated by d=1d=13-adic carry, which is fully characterized:

d=1d=14

for carry depth d=1d=15 determined by the d=1d=16-adic representation of the input.

Despite the breakdown of contiguous differentials, the absence of carries is itself highly regular. The paper introduces the concept of "Differential Signatures," enabling the adversary to cluster segments of the keystream according to their signature shapes. This removes the need for a constant difference, allowing passive recovery of the secret key in expected time d=1d=17, where d=1d=18 is the unicity distance. This attack bypasses the designed “no-carry” protection of the encoding and exposes the key in polynomial time.

Active Cryptanalysis: Geometric (Multiplicative) Attack

With active oracle access, the attacker queries the PRF on multiplicative (geometric) sequences d=1d=19 in Fp\mathbb{F}_p0 rather than additive sequences. The PRF structure on such sequences enables a reduction to a discrete logarithm shift:

Fp\mathbb{F}_p1

with Fp\mathbb{F}_p2 determined by the discrete log Fp\mathbb{F}_p3. This strictly multiplicative property allows the extension of known table collision attacks from the literature to the polynomial case.

A hash table collates windows of the keystream; upon collision with the reference sequence (or its bitwise complement), the discrete log relation yields Fp\mathbb{F}_p4 directly. The attack complexity is reduced to Fp\mathbb{F}_p5, matching the optimal lower bound for exhaustive search given Fp\mathbb{F}_p6 queries and thus completely breaks the security of the Fp\mathbb{F}_p7 PRF over extension fields in active settings.

Implications for Higher-Degree PRF Variants

A significant conclusion is the absolute necessity of employing higher-degree (Fp\mathbb{F}_p8) versions of the Legendre PRF over extension fields. For Fp\mathbb{F}_p9, the algebraic dependencies preclude the factorization techniques exploited in the d=1d=10 case. Specifically, for quadratic or higher-degree polynomials, the attacker cannot algebraically isolate the secret key by sequence shifting or factorization, neutralizing the geometric sequence attack.

The paper notes that while some meet-in-the-middle and algebraic reduction strategies might apply, the complexity scales as d=1d=11 at best, restoring exponential security for practical parameter choices at d=1d=12. Therefore, cryptographic deployments in MPC and ZKP must enforce d=1d=13 (and preferably higher) when instantiating the Legendre PRF in extension fields.

Theoretical and Practical Impact

This research decisively clarifies that the structural protections conferred by polynomial input encoding (such as eliminating carries in sequence generation) are insufficient for cryptographic resilience if only the single-degree variant is used. Both theoretical and implementational security boundaries are addressed. In practice, protocols relying on the Legendre PRF over d=1d=14 must revisit their construction parameters, as widespread use in privacy and MPC settings would be directly undermined by the attacks described.

The analytical framework and open-source implementations provided will inform both further cryptanalytic research and the design of next-generation PRFs for algebraic cryptography.

Conclusion

The paper conclusively demonstrates that the d=1d=15 Legendre PRF construction over extension fields is vulnerable to both passive and active attacks due to deterministic structural properties inherent in polynomial encoding and field multiplication. The only mathematically sound defense is deploying PRF variants with d=1d=16, a finding that has direct and immediate consequences for real-world cryptosystems utilizing the Legendre PRF in advanced field settings. This work forms a new baseline for the evaluation of algebraic PRFs in extension fields and motivates further cryptanalytic and theoretical inquiries into higher-degree variants.

Reference: "Cryptanalysis of the Legendre Pseudorandom Function over Extension Fields" (2604.04833)

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.

Tweets

Sign up for free to view the 3 tweets with 1 like about this paper.