The Sponge Is Quantum Indifferentiable
Gorjan Alagic, Joseph Carolan, Christian Majenz, Saliha Tokat
Abstract
The sponge is a cryptographic construction that turns a public permutation into a hash function. When the Keccak permutation is used, the resulting design constitutes the Secure Hash Algorithm 3 (SHA-3), standardized by the National Institute of Standards and Technology (NIST). SHA-3 is a core component of most post-quantum public-key cryptography schemes slated for worldwide adoption. While one can consider many security properties for the sponge, the ultimate one is indifferentiability from a random oracle, or simply indifferentiability. The sponge was proved indifferentiable against classical adversaries by Bertoni et al. in 2008. Despite significant efforts in the years since, little is known about sponge security against quantum adversaries, even for simple properties like preimage or collision resistance beyond a single round. This is primarily due to the lack of a satisfactory quantum analog of the lazy sampling technique for permutations. In this work, we develop a specialized technique that overcomes this barrier in the case of the sponge. We prove that the sponge is in fact indifferentiable from a random oracle against quantum adversaries. Our result establishes that the domain extension technique behind SHA-3 is secure in the post-quantum setting. Our indifferentiability bound for the sponge is a loose, but we also give bounds on preimage and collision resistance that are tighter.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b6626ede-7bbe-474d-9576-874d38f26dfaBuilds on8
- Post-Quantum Security of the Even-Mansour CipherGorjan Alagic, Chen Bai, Jonathan Katz, Christian MajenzEUROCRYPT 2022 · 23 citations
- Efficient NIZKs and Signatures from Commit-and-Open Protocols in the QROMJelle Don, Serge Fehr, Christian Majenz, Christian SchaffnerCRYPTO 2022 · 15 citations
- Tight Preimage Resistance of the Sponge ConstructionCharlotte Lefevre, Bart MenninkCRYPTO 2022 · 15 citations
- Post-quantum Security of Tweakable Even-Mansour, and ApplicationsGorjan Alagic, Chen Bai, Jonathan Katz, Christian Majenz et al.EUROCRYPT 2024 · 10 citations
- Quantum One-Wayness of the Single-Round Sponge with Invertible PermutationsJoseph Carolan, Alexander PorembaCRYPTO 2024 · 4 citations
Related papers
- Time-Space Tradeoffs for Sponge Hashing: Attacks and Limitations for Short CollisionsCody Freitag, Ashrujit Ghoshal, Ilan KomargodskiCRYPTO 2022 · 9 citations
- Permutation-Based Hashing with Stronger (Second) Preimage ResistanceSiwei Sun, Shun Li, Zhiyu Zhang, Charlotte Lefevre et al.CRYPTO 2026
- Permutation-Based Hash from Non-Idealized Assumptions: Adding Feed-Forward to SpongeChun Guo, Kai Hu, Shuntian Jiang, Yanhong Fan et al.CRYPTO 2026
- The Impossibility of Post-quantum Public Indifferentiability for Merkle-DamgårdAkinori HosoyamadaCRYPTO 2026
- Preimage Attacks on up to 5 Rounds of SHA-3 Using Internal DifferentialsZhongyi Zhang, Chengan Hou, Meicheng LiuEUROCRYPT 2025 · 1 citation
