发表机构
University of Maryland; Technical University of Denmark(马里兰大学; 丹麦技术大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文重新审视压缩置换预言机,将可靠性界限从O(N^{1/12})改进为紧致的Ω(N^{1/2}),并应用于SHA3海绵构造和SHA1/SHA2的Davies-Meyer函数,得到紧致的碰撞与原像下界。
AI 中文摘要
压缩置换预言机已被用于分析许多先前技术无法处理的密码构造的量子安全性。然而,这些分析从根本上受到该方法较弱可靠性的限制:该技术仅被证明对N个元素上的置换在最多O(N^{1/12})次查询内是可靠的。我们重新审视了这一分析,将可靠性界限改进为紧致的Ω(N^{1/2})。除了更紧致外,我们的证明在概念上更简单、更直接,并且在理想密码模型下给出相同的界限。主要技术思想是从朴素纯化上的一个简单POVM构造压缩等距,这一技术可能具有更广泛的应用。作为直接应用,我们的结果为支撑SHA3的海绵哈希构造以及SHA1和SHA2中使用的Davies-Meyer压缩函数提供了紧致的、具体的碰撞和原像下界。更广泛地说,改进的可靠性定理为在随机置换或理想密码作为底层原语的环境中分析量子安全性提供了一个通用工具。
英文摘要
The compressed permutation oracle has been used to analyze the quantum security of a number of cryptographic constructions which resisted prior techniques. However, these analyses were fundamentally limited by the poor soundness of the method: the technique was proven sound only up to $O(N^{1/12})$ queries to permutations on $N$ elements. We revisit this analysis, improving the soundness bound to a tight $Ω(N^{1/2})$. In addition to being tighter, our proof is conceptually simpler and more direct, and gives the same bound in the ideal cipher model. The main technical idea is to construct the compression isometry from a simple POVM on the naive purification, a technique which may find wider applications. As immediate applications, our results yield tight, concrete collision and pre-image lower bounds for the sponge hash construction underlying SHA3 and the Davies--Meyer compression function used in SHA1 and SHA2. More broadly, the improved soundness theorem provides a general-purpose tool for analyzing quantum security in settings where random permutations or ideal ciphers serve as the underlying primitive.