The Impossibility of Post-quantum Public Indifferentiability for Merkle-Damgård
Akinori Hosoyamada
Abstract
The Merkle-Damgård construction (in its strengthened form as used in SHA-256 and SHA-512, the untruncated members of SHA-2) is not classically indifferentiable from a Variable-Input-Length (VIL) random oracle because of the length-extension attack. Nevertheless, Dodis, Ristenpart, and Shrimpton showed that Merkle-Damgård is publicly indifferentiable, a weaker notion that still justifies replacing a VIL random oracle by Merkle-Damgård in many security proofs when all inputs to a random oracle are public (e.g., Fiat-Shamir and full-domain-hash signatures).
In this paper, we show that this replacement fails in the post-quantum setting: (Strengthened) Merkle-Damgård is not publicly indifferentiable from a VIL random oracle against quantum distinguishers with superposition access to the underlying primitive (while construction queries remain classical), even if the compression function is ideally random. We first formalize post-quantum public indifferentiability so that the corresponding composition theorem extends to the quantum random oracle model. We also introduce a post-quantum version of sequential indifferentiability, an even weaker notion. We then prove that (strengthened) Merkle-Damgård satisfies neither notion by showing that an explicit quantum distinguisher achieves non-negligible advantage against any efficient simulator, using Zhandry's compressed-oracle technique. We thus obtain an explicit, conjecture-free separation between an indifferentiability-style notion in the classical setting and its post-quantum analogue.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get b82e3271-62ae-4465-bb5a-637e0ef90703Related papers
- Separate Your Domains: NIST PQC KEMs, Oracle Cloning and Read-Only IndifferentiabilityMihir Bellare, Hannah Davis, Felix GüntherEUROCRYPT 2020 · 35 citations
- The Sponge Is Quantum IndifferentiableGorjan Alagic, Joseph Carolan, Christian Majenz, Saliha TokatFOCS 2025 · 6 citations
- Classical vs Quantum Random OraclesTakashi Yamakawa, Mark ZhandryEUROCRYPT 2021 · 43 citations
- Random Oracle Combiners: Merkle-Damgård StyleYevgeniy Dodis, Eli Goldin, Peter HallEUROCRYPT 2025
- Efficient NIZKs and Signatures from Commit-and-Open Protocols in the QROMJelle Don, Serge Fehr, Christian Majenz, Christian SchaffnerCRYPTO 2022 · 15 citations
