DDH ⇒ PRF (Naor–Reingold)

DDH implies a PRF, by the Naor–Reingold construction.

Construction

Migrated verbatim from PRF § Other results:

PRF from DDH: the Naor-Reingold construction maps to and is secure under DDH — NR97

Notes

The same reduction is stated from the other end at DDH § Known Results.