On the Indifferentiability of the Sponge Construction
- Cite this paper as:
- Bertoni G., Daemen J., Peeters M., Van Assche G. (2008) On the Indifferentiability of the Sponge Construction. In: Smart N. (eds) Advances in Cryptology – EUROCRYPT 2008. EUROCRYPT 2008. Lecture Notes in Computer Science, vol 4965. Springer, Berlin, Heidelberg
In this paper we prove that the sponge construction introduced in  is indifferentiable from a random oracle when being used with a random transformation or a random permutation and discuss its implications. To our knowledge, this is the first time indifferentiability has been shown for a construction calling a random permutation (instead of an ideal compression function or ideal block cipher) and for a construction generating outputs of any length (instead of a fixed length).