Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Book] Note Privacy (OOB) actually depends on PRFness of PRF^expand #172

Open
defuse opened this issue Aug 4, 2021 · 1 comment
Open
Labels
documentation Improvements or additions to documentation

Comments

@defuse
Copy link
Contributor

defuse commented Aug 4, 2021

https://zcash.github.io/orchard/design/nullifiers.html

The argument that Note Privacy (OOB) is near-perfect relies on \psi being chosen independently at random. Since \psi is the output of PRF^expand_rseed, Note Privacy (OOB) must assume PRF^expand_rseed is a PRF. This should be clarified in the table.

(PRF^expand_rseed is called KDF^\psi in the book).

@defuse defuse added the documentation Improvements or additions to documentation label Aug 4, 2021
@defuse defuse changed the title [Book] Note privacy (OOB) actually depends on PRFness of PRF^expand [Book] Note Privacy (OOB) actually depends on PRFness of PRF^expand Aug 4, 2021
@daira
Copy link
Contributor

daira commented Aug 5, 2021

I think only WeakPRF is needed. Also, the derivation of ψ using PRFexpand is part of note encryption/decryption, and not strictly speaking required by the rest of the protocol.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation
Projects
None yet
Development

No branches or pull requests

2 participants