Papers
Topics
Authors
Recent
Search
2000 character limit reached

Lower Bounds on Black-Box Constructions of Pseudorandom Functions

Published 14 Aug 2026 in cs.CR | (2608.14501v1)

Abstract: In their seminal work, Goldreich, Goldwasser, and Micali [CRYPTO 1984] constructed a pseudorandom function (PRF) using a black-box access to a pseudorandom generator (PRG). When combined with Levin's domain extension technique, the GGM construction invokes the PRG ω(log⁡n)ω(\log n) times, where nn denotes the input length to the PRG. To this day, no black-box construction achieving fewer calls is known. Recently, Beimel, Malkin, and Mazor [CRYPTO 2024] showed that for a certain family of constructions, which they termed \emph{tree constructions}, the GGM construction is optimal. However, the basic challenge of whether a PRF can be built with just \emph{one invocation} of the PRG still remains open. In this work, we consider fully black-box constructions of PRFs from PRGs, where both the construction and the reduction are required to be black-box, and the number of interactions the reduction makes with the adversary is independent of the number of oracle calls the adversary makes to its underlying function within each interaction. Our main result shows that no such construction can have o(n/log⁡n)o(n/\log n) and o(in/log⁡in)o(\mathsf{in}/\log\mathsf{in}) \emph{non-adaptive} calls to the PRG, where in\mathsf{in} is the input length of the PRF. This impossibility holds even for weak PRFs with one-bit output, where the adversary is restricted to making i.i.d. uniformly random queries. In addition, we prove a lower bound for weak PRFs with sufficiently long outputs that holds even when the construction is allowed to make adaptive queries to the PRG.

Summary

  • The paper proves that non-adaptive, fully black-box constructions of weak PRFs from PRGs require at least Ω(n/log n) calls when reductions are query-bounded, ruling out constant-call designs for input lengths growing faster than log n.
  • The authors use meta-reductions, seed-collision analysis, concentration bounds, and randomized thresholds to simulate ideal adversaries efficiently and separate constructions making too few PRG queries.
  • A separate entropy-based result rules out adaptive constructions using fewer than out/(r + ω(log n)) calls for long-output weak PRFs, narrowing the gap with GGM while leaving unrestricted reductions, standard PRFs, and exact optimality open.

Context and motivation

The GGM construction of pseudorandom functions from pseudorandom generators [GGM86] remains the canonical black-box reduction between these two primitives. Combined with Levin's domain extension trick, it requires ω(log⁡n)\omega(\log n) invocations of an nn-bit PRG per evaluation, where nn is the PRG seed length. Whether this call complexity is optimal has been open since the construction was introduced: prior to this work, Beimel, Malkin, and Mazor [BMM24] had established optimality only for the restricted class of "tree constructions," and no previous result ruled out a single-call construction. The paper under review, by Alon, Dinur, and Venkitasubramaniam (arXiv (2608.14501)), makes substantial progress on this question by proving the first lower bounds that apply beyond tree constructions.

The paper works in the fully black-box model of Reingold–Trevisan–Vadhan [RTV04]: both the construction FF and the security reduction RR treat the underlying primitive as an oracle. Following the meta-reduction paradigm of Boneh–Venkatesan [BV98], the authors construct inefficient "ideal" adversaries and simulate them efficiently via "real" adversaries that exploit the transcript of the reduction's interaction with the PRG oracle.

Main result: non-adaptive constructions

The central theorem states that there is no fully black-box construction of a weak PRF with input length in\mathit{in} from an arbitrary-stretch PRG using cc non-adaptive calls, whenever c=o(n/log⁡n)c = o(n/\log n) and c=o(in/log⁡in)c = o(\mathit{in}/\log \mathit{in}), provided the reduction is query-bounded. A reduction is (d,α)(d,\alpha)-query-bounded if its number of calls to any distinguishing adversary with advantage at least nn0 is bounded by nn1. Notably:

  • The impossibility holds even for weak PRFs, where the adversary makes only i.i.d. uniform queries, and even for one-bit output PRFs.
  • As a corollary, constant-call constructions are ruled out entirely for query-bounded reductions when nn2 — in particular, resolving the single-call case for this class of reductions.
  • The bounds are incomparable in strength to GGM's nn3 calls: GGM uses fewer calls asymptotically but is a tree construction; the new result covers all non-tree constructions as well, at the cost of the query-bounded restriction on the reduction.

Proof technique for the main result

A naive random-oracle-based separation fails here for an instructive reason: constructions such as nn4 are information-theoretically secure against polynomial-query adversaries when nn5 is instantiated by a random function, so no efficient oracle-aided distinguisher can break them. The authors instead use meta-reductions.

An ideal adversary queries nn6 on all inputs and checks whether some key is consistent with a large fraction of the oracle's answers on nn7 fixed inputs. A real adversary must emulate this without querying nn8, using only the reduction's own PRG query-answer pairs. Two technical obstacles arise: (i) outputs of the PRF may be dependent across inputs when seeds collide, breaking concentration arguments; (ii) the reduction can implant the challenge string nn9 into one answer, perturbing the ideal score by 1 while leaving the real score nearly unchanged.

Both issues are resolved by identifying, per key, either a set of frequent seeds (whose PRG values are replaced by fixed values maximizing the score, removing entropy contributions) or a large set of inputs with mutually disjoint seeds (via a greedy independent-set argument on a collision graph). On disjoint-seed sets, the relevant indicators become independent, so Hoeffding's inequality shows the real score tracks the expected ideal score within nn0 except with probability nn1, where nn2. A uniformly random threshold nn3 smooths residual discrepancies between the two scores.

Parameter choices require nn4, which is at most nn5 precisely because nn6; similarly, the reduction's total PRG query count nn7 stays below nn8 because nn9. Instantiating the PRG as a random function then contradicts the fact that a random function is a PRG against FF0-query adversaries (proved via lazy sampling).

The query-bounded restriction

The proof requires that the number FF1 of reduction-to-adversary interactions be fixed independently of the adversary's query count FF2: since the statistical distance per interaction is only inverse-polynomial (not negligible), one needs FF3 small relative to the precision achievable with large FF4. Under the standard fully black-box definition, a reduction could adaptively increase its number of interactions based on the adversary's behavior, creating a circular dependence between FF5 and FF6. The authors argue that all reductions in the literature — including GGM, Goldreich–Levin, and Waters' IBE — are query-bounded, and note that if one could achieve negligible statistical distance between the two adversaries, the restriction would disappear. Extending the lower bound to all black-box reductions remains open.

Lower bound for long outputs with adaptive calls

The second result removes both the non-adaptivity and the query-boundedness assumptions, at the cost of restricting the output length. Specifically, there is no fully black-box construction of a weak PRF with output length FF7 from an FF8-bit stretch PRG using at most FF9 calls. The proof is an entropy argument: consider a PRG that applies genuine randomness only to the first RR0 bits of the seed (its existence relative to a suitable oracle follows from a lemma of BMM24). Then RR1 evaluations of the PRF carry at most RR2 bits of entropy, versus RR3 for a random function; taking RR4 yields a distinguishing gap of RR5 via a union bound over keys and intermediate strings.

Comparing to GGM: composing GGM (with Levin's trick) with the Goldreich–Levin hardcore-bit construction yields an RR6-bit output PRF from a 1-bit stretch PRG using RR7 calls, whereas the lower bound requires RR8 calls. Thus GGM is optimal up to a factor of RR9 in this regime.

Limitations and open questions

Several restrictions qualify the results and should be stated plainly. First, the main theorem applies only to non-adaptive constructions; adaptive constructions are covered only in the long-output regime. Second, the main theorem requires query-bounded reductions, a strictly smaller class than all fully black-box reductions, though the authors contend it captures every reduction known. Third, both results concern weak PRFs; extending to standard PRFs is not addressed. Fourth, the gap between the upper bound (in\mathit{in}0 calls for GGM-type constructions) and the lower bound (in\mathit{in}1 calls impossible) leaves the exact optimum unresolved, and the single-call question for general reductions remains open. Finally, the statistical-distance argument inherently produces only inverse-polynomial closeness between the real and ideal adversaries; whether this can be improved to negligible distance — which would eliminate the query-bounded assumption — is left unanswered.

Conclusion

This work substantially broadens the known impossibility landscape for black-box PRF constructions from PRGs, moving beyond tree constructions to rule out all non-adaptive constructions with in\mathit{in}2 calls under a natural and widely satisfied restriction on reductions, and ruling out sub-in\mathit{in}3-call constructions even adaptively for long-output PRFs. The combination of meta-reduction techniques with combinatorial seed-collision analysis appears likely to be useful for further separations, though closing the remaining gaps — adaptivity, unrestricted reductions, and the exact call-complexity threshold — remains open.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Tweets

Sign up for free to view the 1 tweet with 0 likes about this paper.