You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The argument that Note Privacy (OOB) is near-perfect relies on \psi being chosen independently at random. Since \psi is the output of PRF^expand_rseed, Note Privacy (OOB) must assume PRF^expand_rseed is a PRF. This should be clarified in the table.
(PRF^expand_rseed is called KDF^\psi in the book).
The text was updated successfully, but these errors were encountered:
defuse
changed the title
[Book] Note privacy (OOB) actually depends on PRFness of PRF^expand
[Book] Note Privacy (OOB) actually depends on PRFness of PRF^expand
Aug 4, 2021
I think only WeakPRF is needed. Also, the derivation of ψ using PRFexpand is part of note encryption/decryption, and not strictly speaking required by the rest of the protocol.
https://zcash.github.io/orchard/design/nullifiers.html
The argument that Note Privacy (OOB) is near-perfect relies on \psi being chosen independently at random. Since \psi is the output of PRF^expand_rseed, Note Privacy (OOB) must assume PRF^expand_rseed is a PRF. This should be clarified in the table.
(PRF^expand_rseed is called KDF^\psi in the book).
The text was updated successfully, but these errors were encountered: