Lune

EUROCRYPT2022顶会

Post-Quantum Security of the Even-Mansour Cipher

Gorjan Alagic, Chen Bai, Jonathan Katz, Christian Majenz

2022年份
23被引次数
6顶会引用

摘要

The Even-Mansour cipher is a simple method for constructing a (keyed) pseudorandom permutation EE from a public random permutation P:{0,1}n→{0,1}nP:\{0,1\}^n \rightarrow \{0,1\}^n. It is secure against classical attacks, with optimal attacks requiring qEq_E queries to EE and qPq_P queries to PP such that qE⋅qP≈2nq_E \cdot q_P \approx 2^n. If the attacker is given quantum access to both EE and PP, however, the cipher is completely insecure, with attacks using qE,qP=O(n)q_E, q_P = O(n) queries known. In any plausible real-world setting, however, a quantum attacker would have only classical access to the keyed permutation EE implemented by honest parties, even while retaining quantum access to PP. Attacks in this setting with qE⋅qP2≈2nq_E \cdot q_P^2 \approx 2^n are known, showing that security degrades as compared to the purely classical case, but leaving open the question as to whether the Even-Mansour cipher can still be proven secure in this natural,"post-quantum"setting. We resolve this question, showing that any attack in that setting requires qE⋅qP2+qP⋅qE2≈2nq_E \cdot q^2_P + q_P \cdot q_E^2 \approx 2^n. Our results apply to both the two-key and single-key variants of Even-Mansour. Along the way, we establish several generalizations of results from prior work on quantum-query lower bounds that may be of independent interest.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

引用它的顶会 Paper6

问问它们各自怎么用它

它引用的顶会 Paper3

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖