On The Simplest Quantum-Secure Block Cipher

📅 2026-09-30
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the open problem regarding the security of the two-round Even-Mansour (EM) cipher under quantum adaptive queries. Working within the ideal permutation model, this work proposes a compressed permutation oracle technique alongside a tailored isometry mapping method to rigorously bridge the security reduction between ideal and real experimental settings. The primary contribution is the first information-theoretic proof that the two-round EM cipher remains secure against polynomially bounded quantum adaptive queries, thereby establishing it as the minimal structural boundary for quantum resistance. By filling a critical theoretical gap concerning the minimal construction of quantum-secure block ciphers, these findings provide an essential theoretical foundation for the design of post-quantum symmetric-key cryptography.
📝 Abstract
Pseudorandom permutations are ubiquitous in theoretical and applied cryptography. PRPs that offer security even against adversaries making quantum queries are of increasing interest, and used in applications ranging from constructing pseudorandom unitaries to separating SZK from BQP. A successful framework for constructing classically-secure PRPs is the key-alternating Even-Mansour approach, which interleaves applications of public permutations with additions of round keys. The single-round construction is already classically secure in the ideal permutation model (IPM), with added rounds offering improved concrete security. However, in the quantum-query setting, the status of this framework is presently unclear. A simple quantum-query attack based on Simon's algorithm breaks the one-round cipher. For two or more rounds, security is only known against non-adaptive adversaries who must prepare all queries in advance. In this work, we show that the two-round Even-Mansour cipher is information theoretically secure in the IPM against adversaries making polynomially-many adaptive forward and inverse quantum queries to all available oracles. Our proof uses compressed permutation oracles and a specially crafted isometry relating the ideal and real experiments. We also show that this construction is minimal, in the sense that essentially any cipher constructed via a single call to a public permutation is quantumly insecure.
Problem

Research questions and friction points this paper is trying to address.

quantum-secure block cipher
pseudorandom permutations
Even-Mansour cipher
quantum queries
ideal permutation model
Innovation

Methods, ideas, or system contributions that make the work stand out.

Quantum-Secure Block Cipher
Even-Mansour Cipher
Pseudorandom Permutations
Compressed Permutation Oracles
Adaptive Quantum Queries
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
G
Gorjan Alagic
University of Maryland
J
Joseph Carolan
University of Maryland
Christian Majenz
Christian Majenz
Associate Professor, Technical University of Denmark
post-quantum cryptographyquantum cryptographyquantum information theory
S
Saliha Tokat
Technical University of Denmark