Cryptanalysis of the Legendre Pseudorandom Function over Extension Fields
Daksh Pandey

TL;DR
This paper conducts the first comprehensive cryptanalysis of the Legendre PRF over extension fields, revealing vulnerabilities under passive and active attack models and emphasizing the need for higher-degree variants for security.
Contribution
It introduces novel attack techniques on the Legendre PRF over extension fields and establishes security boundaries, highlighting the importance of higher-degree keys.
Findings
Classical collision attacks are neutralized by a no-carry fracture but can be bypassed using Differential Signature bucketing.
Adversaries can recover the secret key in polynomial time under passive and active models using structural attacks.
Higher-degree key variants are necessary for exponential security against structural reductions in extension fields.
Abstract
The Legendre Pseudorandom Function (PRF) is a highly efficient cryptographic primitive built upon the Legendre symbol, valued for its low multiplicative complexity in Multi-Party Computation (MPC) and Zero-Knowledge Proof (ZKP) protocols. While its security over prime fields is well-documented, recent interest has shifted toward instantiations over extension fields . This paper presents the first comprehensive cryptanalysis of the single-degree Legendre PRF operating over . First, we analyze polynomial input encoding under a standard passive threat model (sequential additive counter queries). We demonstrate that while the absence of polynomial carry-overs causes an asynchronous "no-carry fracture" that neutralizes classical sliding-window collision attacks, the fracture itself is deterministically periodic. By introducing a novel…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
