Simple Extremely Lossy Functions from Small-Exponent Hashing

📅 2026-10-05
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the reliance of existing Extremely Lossy Function (ELF) constructions on the elliptic curve Decisional Diffie-Hellman (DDH) assumption and complex bootstrapping procedures. We propose an Extremely Lossy Trapdoor Hash (ELTDH) based on the small-exponent discrete logarithm and Decisional Composite Residuosity (DCR) assumptions, achieving the first one-step construction without bootstrapping and eliminating restrictions to fixed-size adversaries. By leveraging cryptographic techniques over the multiplicative group modulo N squared, our approach simplifies the construction process while broadening the diversity of underlying hardness assumptions. The resulting ELF variant is simpler and more efficient than existing schemes, significantly enhancing both theoretical generality and practical deployment feasibility.
📝 Abstract
Extremely Lossy Functions (ELFs) are a standard model primitive that captures many useful properties of random oracles (Zhandry, Crypto 2016). While there are many variations of ELFs with additional properties, every construction (excluding obfuscation) has followed essentially the same template of bootstrapping from a sequence of ELFs secure only against fixed-size adversaries, and every construction was based on only the exponential hardness of DDH (or $k$-Lin), an assumption that is only reasonable over elliptic curves. We introduce and construct Extremely Lossy Trapdoor Hashing (ELTDH), a stronger notion that implies all known variations of ELFs. Our construction achieves ELTDH in one go, without bootstrapping from schemes secure for only fixed-size adversaries, which makes it simpler and more efficient than existing ELFs. We assume exponential security of the small-exponent discrete logarithm, together with polynomial security of decisional composite residuosity (DCR). Exponential security is only required in the size of the secret exponent, not the size of the group, so the assumption plausibly holds for multiplication modulo $N^2$ (and for many other cryptographic groups), despite the subexponential-time discrete logarithm attacks from index calculus. Our results diversify the assumptions underlying ELFs, while also giving a simpler construction.
Problem

Research questions and friction points this paper is trying to address.

Extremely Lossy Functions
Trapdoor Hashing
Cryptographic Assumptions
Bootstrapping
Innovation

Methods, ideas, or system contributions that make the work stand out.

Extremely Lossy Trapdoor Hashing
Small-Exponent Discrete Logarithm
Decisional Composite Residuosity
Bootstrapping-free Construction
Extremely Lossy Functions