A game of one reduction

The Distinguisher's
Table

Proving that PRG security implies EAV security — by playing the reduction, one round at a time.

▸  Press start  ◂

Music begins when you start · ♪ in the top bar mutes it

Briefing

You are the distinguisher

The challenger deals you a string w from one of two sources, and will not say which. Either w = G(k) for a hidden seed, or w is uniformly random. Tell them apart and you have broken G — which nobody has ever done.

You cannot read w. It is noise either way. What you can do is hire Ā, an eavesdropper who breaks Enc(k,m) = G(k) ⊕ m with advantage ε — and turn Ā's talent into an answer about w.

Assembly · Part I of IV

What the challenger hands you

Table I

The Braggart

D · you
Ā · under contract
the challenger
the challenger waits
BREAK
◂ uniformevidencepseudorandom ▸
hands dealt 0 · matched 0 · rate odds 1 : 1
Round 1

BP
Observed rate · the two hypotheses
The call

Which source is dealing?

Result

Hover the plot to read a point.
◆  The theorem  ◆

An adversary you cannot use is an adversary that cannot hurt you.