Sep 16, 2024
n
(security parameter).l
bits.Big L
bits.f_k
producing Big L
bit outputs from l
bit inputs.f(x) = K XOR x
, it fails as a PRF since outputs for different inputs are related, allowing a distinguisher to identify the function.n
, it acts as a PRP.n
and produces an output of size t * Big L
bits.