Post-Quantum Security of the Even-Mansour Cipher
Gorjan Alagic, Chen Bai, Jonathan Katz, Christian Majenz
Abstract
The Even-Mansour cipher is a simple method for constructing a (keyed) pseudorandom permutation from a public random permutation . It is secure against classical attacks, with optimal attacks requiring queries to and queries to such that . If the attacker is given quantum access to both and , however, the cipher is completely insecure, with attacks using queries known. In any plausible real-world setting, however, a quantum attacker would have only classical access to the keyed permutation implemented by honest parties, even while retaining quantum access to . Attacks in this setting with are known, showing that security degrades as compared to the purely classical case, but leaving open the question as to whether the Even-Mansour cipher can still be proven secure in this natural,"post-quantum"setting. We resolve this question, showing that any attack in that setting requires . Our results apply to both the two-key and single-key variants of Even-Mansour. Along the way, we establish several generalizations of results from prior work on quantum-query lower bounds that may be of independent interest.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0a2f0e9c-90af-48ec-9c5f-2e911770f682Cited by top-tier papers6
- Quantum Linear Key-Recovery Attacks Using the QFTAndré SchrottenloherCRYPTO 2023 · 12 citations
- The Sponge Is Quantum IndifferentiableGorjan Alagic, Joseph Carolan, Christian Majenz, Saliha TokatFOCS 2025 · 6 citations
- Quantum One-Wayness of the Single-Round Sponge with Invertible PermutationsJoseph Carolan, Alexander PorembaCRYPTO 2024 · 4 citations
- Quantum Lifting for Invertible Permutations and Ideal CiphersAlexandru Cojocaru, Minki Hhan, Qipeng Liu, Takashi Yamakawa et al.CRYPTO 2025 · 2 citations
- The NISQ Complexity of Collision FindingYassine Hamoudi, Qipeng Liu, Makrand SinhaEUROCRYPT 2024 · 2 citations
Builds on3
- Measure-Rewind-Measure: Tighter Quantum Random Oracle Model Proofs for One-Way to Hiding and CCA SecurityVeronika Kuchta, Amin Sakzad, Damien Stehlé, Ron Steinfeld et al.EUROCRYPT 2020 · 60 citations
- Online-Extractability in the Quantum Random-Oracle ModelJelle Don, Serge Fehr, Christian Majenz, Christian SchaffnerEUROCRYPT 2022 · 57 citations
- Quantum-Access-Secure Message Authentication via Blind-UnforgeabilityGorjan Alagic, Christian Majenz, Alexander Russell, Fang SongEUROCRYPT 2020 · 55 citations
Related papers
- Post-quantum Security of Tweakable Even-Mansour, and ApplicationsGorjan Alagic, Chen Bai, Jonathan Katz, Christian Majenz et al.EUROCRYPT 2024 · 10 citations
- On the Impossibility of Key Agreements from Quantum Random OraclesPer Austrin, Hao Chung, Kai-Min Chung, Shiuan Fu et al.CRYPTO 2022 · 20 citations
- Cryptomania v.s. Minicrypt in a Quantum WorldLongcheng Li, Qian Li, Xingjian Li, Qipeng LiuCRYPTO 2026
- Quantum Public-Key Encryption with Tamper-Resilient Public Keys from One-Way FunctionsFuyuki Kitagawa, Tomoyuki Morimae, Ryo Nishimaki, Takashi YamakawaCRYPTO 2024 · 13 citations
- Beyond Quadratic Speedups in Quantum Attacks on Symmetric SchemesXavier Bonnetain, André Schrottenloher, Ferdinand SibleyrasEUROCRYPT 2022 · 32 citations
