{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T17:12:40Z","timestamp":1778087560734,"version":"3.51.4"},"publisher-location":"Cham","reference-count":56,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032253163","type":"print"},{"value":"9783032253170","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-25317-0_4","type":"book-chapter","created":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T16:28:46Z","timestamp":1778084926000},"page":"97-127","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Combining Oblivious Pseudorandom Functions"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-4126-3098","authenticated-orcid":false,"given":"Sebastian","family":"Faller","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0597-8297","authenticated-orcid":false,"given":"Marc","family":"Fischlin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-0499-8594","authenticated-orcid":false,"given":"Julius","family":"Hardt","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2875-6198","authenticated-orcid":false,"given":"Julia","family":"Hesse","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,7]]},"reference":[{"key":"4_CR1","doi-asserted-by":"publisher","unstructured":"Alamati, N., De Feo, L., Montgomery, H., Patranabis, S.: Cryptographic group actions and applications. In: Moriai, S., Wang, H. (eds.) ASIACRYPT\u00a02020, Part\u00a0II. LNCS, vol. 12492, pp. 411\u2013439. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_14","DOI":"10.1007\/978-3-030-64834-3_14"},{"key":"4_CR2","doi-asserted-by":"publisher","unstructured":"Albrecht, M.R., Davidson, A., Deo, A., Gardham, D.: Crypto dark matter on the torus - oblivious PRFs from shallow PRFs and TFHE. In: Joye, M., Leander, G. (eds.) EUROCRYPT\u00a02024, Part\u00a0VI. LNCS, vol. 14656, pp. 447\u2013476. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-58751-1_16","DOI":"10.1007\/978-3-031-58751-1_16"},{"key":"4_CR3","doi-asserted-by":"publisher","unstructured":"Albrecht, M.R., Davidson, A., Deo, A., Smart, N.P.: Round-optimal verifiable oblivious pseudorandom functions from ideal lattices. In: Garay, J. (ed.) PKC\u00a02021, Part\u00a0II. LNCS, vol. 12711, pp. 261\u2013289. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-75248-4_10","DOI":"10.1007\/978-3-030-75248-4_10"},{"key":"4_CR4","doi-asserted-by":"publisher","unstructured":"Albrecht, M.R., G\u00fcr, K.D.: Verifiable oblivious pseudorandom functions from lattices: practical-ish and thresholdisable. In: Chung, K.M., Sasaki, Y. (eds.) ASIACRYPT\u00a02024, Part\u00a0IV. LNCS, vol. 15487, pp. 205\u2013237. Springer, Singapore (2024). https:\/\/doi.org\/10.1007\/978-981-96-0894-2_7","DOI":"10.1007\/978-981-96-0894-2_7"},{"key":"4_CR5","doi-asserted-by":"publisher","unstructured":"Basso, A.: A post-quantum round-optimal oblivious PRF from isogenies. In: Carlet, C., Mandal, K., Rijmen, V. (eds.) SAC 2023. LNCS, vol. 14201, pp. 147\u2013168. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-53368-6_8","DOI":"10.1007\/978-3-031-53368-6_8"},{"key":"4_CR6","doi-asserted-by":"publisher","unstructured":"Basso, A., et al.: Supersingular curves you can trust. In: Hazay, C., Stam, M. (eds.) EUROCRYPT\u00a02023, Part\u00a0II. LNCS, vol. 14005, pp. 405\u2013437. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30617-4_14","DOI":"10.1007\/978-3-031-30617-4_14"},{"key":"4_CR7","doi-asserted-by":"publisher","unstructured":"Basso, A., Kutas, P., Merz, S.P., Petit, C., Sanso, A.: Cryptanalysis of an oblivious PRF from supersingular isogenies. In: Tibouchi, M., Wang, H. (eds.) ASIACRYPT\u00a02021, Part\u00a0I. LNCS, vol. 13090, pp. 160\u2013184. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-92062-3_6","DOI":"10.1007\/978-3-030-92062-3_6"},{"key":"4_CR8","doi-asserted-by":"publisher","unstructured":"Baum, C., et al.: Publicly verifiable zero-knowledge and post-quantum signatures from VOLE-in-the-head. In: Handschuh, H., Lysyanskaya, A. (eds.) CRYPTO\u00a02023, Part\u00a0V. LNCS, vol. 14085, pp. 581\u2013615. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-38554-4_19","DOI":"10.1007\/978-3-031-38554-4_19"},{"key":"4_CR9","doi-asserted-by":"crossref","unstructured":"Beullens, W., Dodgson, L., Faller, S., Hesse, J.: The 2Hash OPRF framework and efficient post-quantum instantiations. Cryptology ePrint Archive, Report 2024\/450 (2024). https:\/\/eprint.iacr.org\/2024\/450","DOI":"10.1007\/978-3-031-91101-9_12"},{"key":"4_CR10","doi-asserted-by":"publisher","unstructured":"Beullens, W., Dodgson, L., Faller, S.H., Hesse, J.: The 2Hash OPRF framework and efficient post-quantum instantiations. In: Fehr, S., Fouque, P.A. (eds.) EUROCRYPT\u00a02025, Part\u00a0VIII. LNCS, vol. 15608, pp. 332\u2013362. Springer, Cham (2025). https:\/\/doi.org\/10.1007\/978-3-031-91101-9_12","DOI":"10.1007\/978-3-031-91101-9_12"},{"key":"4_CR11","unstructured":"Beullens, W., Faller, S.: GitHub - 2HashFramework\/LegendreOPRF (2025). https:\/\/github.com\/2HashFramework\/LegendreOPRF. Accessed 29 Sept 2025"},{"key":"4_CR12","doi-asserted-by":"publisher","unstructured":"Boneh, D., Ishai, Y., Passel\u00e8gue, A., Sahai, A., Wu, D.J.: Exploring crypto dark matter: new simple PRF candidates and their applications. In: Beimel, A., Dziembowski, S. (eds.) TCC\u00a02018, Part\u00a0II. LNCS, vol. 11240, pp. 699\u2013729. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03810-6_25","DOI":"10.1007\/978-3-030-03810-6_25"},{"key":"4_CR13","doi-asserted-by":"publisher","unstructured":"Boneh, D., Kogan, D., Woo, K.: Oblivious pseudorandom functions from isogenies. In: Moriai, S., Wang, H. (eds.) ASIACRYPT\u00a02020, Part\u00a0II. LNCS, vol. 12492, pp. 520\u2013550. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64834-3_18","DOI":"10.1007\/978-3-030-64834-3_18"},{"key":"4_CR14","unstructured":"Booher, J., et al.: Failing to hash into supersingular isogeny graphs. Cryptology ePrint Archive, Report 2022\/518 (2022). https:\/\/eprint.iacr.org\/2022\/518"},{"key":"4_CR15","doi-asserted-by":"publisher","unstructured":"Canetti, R.: Universally composable security: a new paradigm for cryptographic protocols. In: 42nd FOCS, pp. 136\u2013145. IEEE Computer Society Press (2001). https:\/\/doi.org\/10.1109\/SFCS.2001.959888","DOI":"10.1109\/SFCS.2001.959888"},{"key":"4_CR16","doi-asserted-by":"publisher","unstructured":"Canetti, R., Sarkar, P., Wang, X.: Efficient and round-optimal oblivious transfer and commitment with adaptive security. In: Moriai, S., Wang, H. (eds.) ASIACRYPT\u00a02020, Part\u00a0III. LNCS, vol. 12493, pp. 277\u2013308. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64840-4_10","DOI":"10.1007\/978-3-030-64840-4_10"},{"key":"4_CR17","doi-asserted-by":"publisher","unstructured":"Casacuberta, S., Hesse, J., Lehmann, A.: SoK: oblivious pseudorandom functions. In: 2022 IEEE European Symposium on Security and Privacy, pp. 625\u2013646. IEEE Computer Society Press (2022). https:\/\/doi.org\/10.1109\/EuroSP53844.2022.00045","DOI":"10.1109\/EuroSP53844.2022.00045"},{"key":"4_CR18","doi-asserted-by":"publisher","unstructured":"Castryck, W., Decru, T.: An efficient key recovery attack on SIDH. In: Hazay, C., Stam, M. (eds.) EUROCRYPT\u00a02023, Part\u00a0V. LNCS, vol. 14008, pp. 423\u2013447. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_15","DOI":"10.1007\/978-3-031-30589-4_15"},{"key":"4_CR19","unstructured":"Cloudflare: Privacy Pass (2025). https:\/\/developers.cloudflare.com\/waf\/tools\/privacy-pass\/"},{"key":"4_CR20","unstructured":"Connell, G., Fang, V., Schmidt, R., Dauterman, E., Popa, R.A.: Secret key recovery in a global-scale end-to-end encryption system. In: 18th USENIX Symposium on Operating Systems Design and Implementation (OSDI 2024) (2024)"},{"key":"4_CR21","doi-asserted-by":"publisher","unstructured":"Damg\u00e5rd, I.: On the randomness of Legendre and Jacobi sequences. In: Goldwasser, S. (ed.) CRYPTO\u201988. LNCS, vol.\u00a0403, pp. 163\u2013172. Springer, New York (1990). https:\/\/doi.org\/10.1007\/0-387-34799-2_13","DOI":"10.1007\/0-387-34799-2_13"},{"key":"4_CR22","doi-asserted-by":"publisher","unstructured":"Davies, G.T., et al.: Security analysis of the WhatsApp end-to-end encrypted backup protocol. In: Handschuh, H., Lysyanskaya, A. (eds.) CRYPTO\u00a02023, Part\u00a0IV. LNCS, vol. 14084, pp. 330\u2013361. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-38551-3_11","DOI":"10.1007\/978-3-031-38551-3_11"},{"key":"4_CR23","unstructured":"Doussot, G., Lacharit\u00e9, M.S., Schorn, E.: End-to-End Encrypted Backups Security Assessment (2021). https:\/\/research.nccgroup.com\/wp-content\/uploads\/2021\/10\/NCC_Group_WhatsApp_E001000M_Report_2021-10-27_v1.2.pdf"},{"key":"4_CR24","unstructured":"Esgin, M.F., Steinfeld, R., Tairi, E., Xu, J.: LeOPaRd: towards practical post-quantum oblivious PRFs via interactive lattice problems. Cryptology ePrint Archive, Report 2024\/1615 (2024). https:\/\/eprint.iacr.org\/2024\/1615"},{"key":"4_CR25","unstructured":"Faller, S., Fischlin, M., Hardt, J., Hesse, J.: Combining oblivious pseudorandom functions. Cryptology ePrint Archive, Report 2025\/1084 (2025). https:\/\/eprint.iacr.org\/2025\/1084"},{"key":"4_CR26","doi-asserted-by":"publisher","unstructured":"Freedman, M.J., Ishai, Y., Pinkas, B., Reingold, O.: Keyword search and oblivious pseudorandom functions. In: Kilian, J. (ed.) TCC\u00a02005. LNCS, vol.\u00a03378, pp. 303\u2013324. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/978-3-540-30576-7_17","DOI":"10.1007\/978-3-540-30576-7_17"},{"key":"4_CR27","doi-asserted-by":"publisher","unstructured":"Gertner, Y., Kannan, S., Malkin, T., Reingold, O., Viswanathan, M.: The relationship between public key encryption and oblivious transfer. In: 41st FOCS, pp. 325\u2013335. IEEE Computer Society Press (2000). https:\/\/doi.org\/10.1109\/SFCS.2000.892121","DOI":"10.1109\/SFCS.2000.892121"},{"key":"4_CR28","doi-asserted-by":"publisher","unstructured":"Grassi, L., Rechberger, C., Rotaru, D., Scholl, P., Smart, N.P.: MPC-friendly symmetric key primitives. In: Weippl, E.R., Katzenbeisser, S., Kruegel, C., Myers, A.C., Halevi, S. (eds.) ACM CCS 2016, pp. 430\u2013443. ACM Press (2016). https:\/\/doi.org\/10.1145\/2976749.2978332","DOI":"10.1145\/2976749.2978332"},{"key":"4_CR29","doi-asserted-by":"publisher","unstructured":"Harnik, D., Kilian, J., Naor, M., Reingold, O., Rosen, A.: On robust combiners for oblivious transfer and other primitives. In: Cramer, R. (ed.) EUROCRYPT\u00a02005. LNCS, vol.\u00a03494, pp. 96\u2013113. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11426639_6","DOI":"10.1007\/11426639_6"},{"issue":"3","key":"4_CR30","doi-asserted-by":"publisher","first-page":"422","DOI":"10.1007\/s00145-008-9034-x","volume":"23","author":"C Hazay","year":"2008","unstructured":"Hazay, C., Lindell, Y.: Efficient protocols for set intersection and pattern matching with security against malicious and covert adversaries. J. Cryptol. 23(3), 422\u2013456 (2008). https:\/\/doi.org\/10.1007\/s00145-008-9034-x","journal-title":"J. Cryptol."},{"key":"4_CR31","doi-asserted-by":"publisher","unstructured":"Heimberger, L., Hennerbichler, T., Meisingseth, F., Ramacher, S., Rechberger, C.: OPRFs from isogenies: designs and analysis. In: Zhou, J., Quek, T.Q.S., Gao, D., C\u00e1rdenas, A.A. (eds.) ASIACCS 2024. ACM Press (2024). https:\/\/doi.org\/10.1145\/3634737.3645010","DOI":"10.1145\/3634737.3645010"},{"key":"4_CR32","unstructured":"Herzberg, A.: Folklore, practice and theory of robust combiners. Cryptology ePrint Archive, Report 2002\/135 (2002). https:\/\/eprint.iacr.org\/2002\/135"},{"key":"4_CR33","doi-asserted-by":"publisher","unstructured":"Hesse, J., Rosenberg, M.: PAKE combiners and efficient post-quantum instantiations. In: Fehr, S., Fouque, P.A. (eds.) EUROCRYPT\u00a02025, Part\u00a0II. LNCS, vol. 15602, pp. 395\u2013420. Springer, Cham (2025). https:\/\/doi.org\/10.1007\/978-3-031-91124-8_14","DOI":"10.1007\/978-3-031-91124-8_14"},{"key":"4_CR34","doi-asserted-by":"publisher","unstructured":"Impagliazzo, R., Rudich, S.: Limits on the provable consequences of one-way permutations. In: 21st ACM STOC, pp. 44\u201361. ACM Press (1989). https:\/\/doi.org\/10.1145\/73007.73012","DOI":"10.1145\/73007.73012"},{"key":"4_CR35","doi-asserted-by":"publisher","unstructured":"Jarecki, S., Kiayias, A., Krawczyk, H.: Round-optimal password-protected secret sharing and T-PAKE in the password-only model. In: Sarkar, P., Iwata, T. (eds.) ASIACRYPT\u00a02014, Part\u00a0II. LNCS, vol.\u00a08874, pp. 233\u2013253. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-45608-8_13","DOI":"10.1007\/978-3-662-45608-8_13"},{"key":"4_CR36","doi-asserted-by":"publisher","unstructured":"Jarecki, S., Kiayias, A., Krawczyk, H., Xu, J.: Highly-efficient and composable password-protected secret sharing (or: How to protect your Bitcoin wallet online). In: 2016 IEEE European Symposium on Security and Privacy, pp. 276\u2013291. IEEE Computer Society Press (2016). https:\/\/doi.org\/10.1109\/EuroSP.2016.30","DOI":"10.1109\/EuroSP.2016.30"},{"key":"4_CR37","doi-asserted-by":"publisher","unstructured":"Jarecki, S., Krawczyk, H., Xu, J.: OPAQUE: an asymmetric PAKE protocol secure against pre-computation attacks. In: Nielsen, J.B., Rijmen, V. (eds.) EUROCRYPT\u00a02018, Part\u00a0III. LNCS, vol. 10822, pp. 456\u2013486. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-78372-7_15","DOI":"10.1007\/978-3-319-78372-7_15"},{"key":"4_CR38","doi-asserted-by":"crossref","unstructured":"Jarecki, S., Krawczyk, H., Xu, J.: OPAQUE: an asymmetric PAKE protocol secure against pre-computation attacks. Cryptology ePrint Archive, Report 2018\/163 (2018). https:\/\/eprint.iacr.org\/2018\/163","DOI":"10.1007\/978-3-319-78372-7_15"},{"key":"4_CR39","doi-asserted-by":"publisher","unstructured":"Jarecki, S., Krawczyk, H., Xu, J.: On the (in)security of the Diffie-Hellman oblivious PRF with multiplicative blinding. In: Garay, J. (ed.) PKC\u00a02021, Part\u00a0II. LNCS, vol. 12711, pp. 380\u2013409. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-75248-4_14","DOI":"10.1007\/978-3-030-75248-4_14"},{"key":"4_CR40","doi-asserted-by":"publisher","unstructured":"Lai, Y.F., Galbraith, S.D., Delpech de Saint Guilhem, C.: Compact, efficient and UC-secure isogeny-based oblivious transfer. In: Canteaut, A., Standaert, F.X. (eds.) EUROCRYPT\u00a02021, Part\u00a0I. LNCS, vol. 12696, pp. 213\u2013241. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-77870-5_8","DOI":"10.1007\/978-3-030-77870-5_8"},{"key":"4_CR41","unstructured":"Lauter, K., Kannepalli, S., Laine, K., Cruz\u00a0Moreno, R.: Password monitor: safeguarding passwords in Microsoft Edge (2021). https:\/\/www.microsoft.com\/en-us\/research\/blog\/password-monitor-safeguarding-passwords-in-microsoft-edge\/"},{"key":"4_CR42","doi-asserted-by":"publisher","unstructured":"Lyu, Y., Liu, S.: Hybrid password authentication key exchange in the UC framework. In: Fehr, S., Fouque, P.A. (eds.) EUROCRYPT\u00a02025, Part\u00a0II. LNCS, vol. 15602, pp. 421\u2013450. Springer, Cham (2025). https:\/\/doi.org\/10.1007\/978-3-031-91124-8_15","DOI":"10.1007\/978-3-031-91124-8_15"},{"key":"4_CR43","doi-asserted-by":"publisher","unstructured":"Maino, L., Martindale, C., Panny, L., Pope, G., Wesolowski, B.: A direct key recovery attack on SIDH. In: Hazay, C., Stam, M. (eds.) EUROCRYPT\u00a02023, Part\u00a0V. LNCS, vol. 14008, pp. 448\u2013471. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_16","DOI":"10.1007\/978-3-031-30589-4_16"},{"key":"4_CR44","doi-asserted-by":"publisher","unstructured":"Masny, D., Rindal, P.: Endemic oblivious transfer. In: Cavallaro, L., Kinder, J., Wang, X., Katz, J. (eds.) ACM CCS 2019, pp. 309\u2013326. ACM Press (2019). https:\/\/doi.org\/10.1145\/3319535.3354210","DOI":"10.1145\/3319535.3354210"},{"key":"4_CR45","doi-asserted-by":"publisher","unstructured":"Meier, R., Przydatek, B.: On robust combiners for private information retrieval and other primitives. In: Dwork, C. (ed.) CRYPTO\u00a02006. LNCS, vol.\u00a04117, pp. 555\u2013569. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11818175_33","DOI":"10.1007\/11818175_33"},{"key":"4_CR46","doi-asserted-by":"publisher","unstructured":"Meier, R., Przydatek, B., Wullschleger, J.: Robuster combiners for oblivious transfer. In: Vadhan, S.P. (ed.) TCC\u00a02007. LNCS, vol.\u00a04392, pp. 404\u2013418. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-70936-7_22","DOI":"10.1007\/978-3-540-70936-7_22"},{"key":"4_CR47","doi-asserted-by":"publisher","unstructured":"Peikert, C., Vaikuntanathan, V., Waters, B.: A framework for efficient and composable oblivious transfer. In: Wagner, D. (ed.) CRYPTO\u00a02008. LNCS, vol.\u00a05157, pp. 554\u2013571. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-85174-5_31","DOI":"10.1007\/978-3-540-85174-5_31"},{"key":"4_CR48","doi-asserted-by":"publisher","unstructured":"Reingold, O., Trevisan, L., Vadhan, S.P.: Notions of reducibility between cryptographic primitives. In: Naor, M. (ed.) TCC\u00a02004. LNCS, vol.\u00a02951, pp. 1\u201320. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-24638-1_1","DOI":"10.1007\/978-3-540-24638-1_1"},{"key":"4_CR49","doi-asserted-by":"publisher","unstructured":"Robert, D.: Breaking SIDH in polynomial time. In: Hazay, C., Stam, M. (eds.) EUROCRYPT\u00a02023, Part\u00a0V. LNCS, vol. 14008, pp. 472\u2013503. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-30589-4_17","DOI":"10.1007\/978-3-031-30589-4_17"},{"key":"4_CR50","doi-asserted-by":"publisher","unstructured":"Roy, L.: SoftSpokenOT: quieter OT extension from small-field silent VOLE in the minicrypt model. In: Dodis, Y., Shrimpton, T. (eds.) CRYPTO\u00a02022, Part\u00a0I. LNCS, vol. 13507, pp. 657\u2013687. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-15802-5_23","DOI":"10.1007\/978-3-031-15802-5_23"},{"key":"4_CR51","doi-asserted-by":"crossref","unstructured":"Seres, I.A., Horv\u00e1th, M., Burcsi, P.: The legendre pseudorandom function as a multivariate quadratic cryptosystem: security and applications. Appl. Algebra Eng. Commun. Comput. 1\u201331 (2023)","DOI":"10.1007\/s00200-023-00599-2"},{"key":"4_CR52","unstructured":"Sommer, C.: Robust Combiners for Cryptographic Primitives. Master\u2019s thesis, ETH Z\u00fcrich (2006). http:\/\/www.sommer.jp\/combiner.pdf"},{"key":"4_CR53","unstructured":"WhatsApp: Security of End-to-End Encrypted Backups (2021). https:\/\/www.whatsapp.com\/security\/WhatsApp_Security_Encrypted_Backups_Whitepaper.pdf"},{"key":"4_CR54","doi-asserted-by":"publisher","unstructured":"Yang, K., Sarkar, P., Weng, C., Wang, X.: QuickSilver: efficient and affordable zero-knowledge proofs for circuits and polynomials over any field. In: Vigna, G., Shi, E. (eds.) ACM CCS 2021, pp. 2986\u20133001. ACM Press (2021). https:\/\/doi.org\/10.1145\/3460120.3484556","DOI":"10.1145\/3460120.3484556"},{"key":"4_CR55","doi-asserted-by":"crossref","unstructured":"Yang, Y.: GitHub - gconeice\/PR-OPRF: Gold OPRF in the paper: \u201cGold OPRF: Post-quantum oblivious power-residue PRF\u201d (2025). https:\/\/github.com\/gconeice\/PR-OPRF. Accessed 29 Sept 2025","DOI":"10.1109\/SP61157.2025.00116"},{"key":"4_CR56","doi-asserted-by":"publisher","unstructured":"Yang, Y., Benhamouda, F., Halevi, S., Krawczyk, H., Rabin, T.: Gold OPRF: post-quantum oblivious power-residue PRF. In: Blanton, M., Enck, W., Nita-Rotaru, C. (eds.) 2025 IEEE Symposium on Security and Privacy, pp. 259\u2013278. IEEE Computer Society Press (2025). https:\/\/doi.org\/10.1109\/SP61157.2025.00116","DOI":"10.1109\/SP61157.2025.00116"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2026"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-25317-0_4","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T16:28:57Z","timestamp":1778084937000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-25317-0_4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032253163","9783032253170"],"references-count":56,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-25317-0_4","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"7 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that\u00a0are relevant to the content of this article.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Rome","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 May 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 May 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"45","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt.iacr.org\/2026\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}