Double-block-length (DBL) hash is a classical and effective approach to amplify concrete security of hash functions. However, it remains open if popular DBL constructions achieve non-trivial security in the quantum world. Towards bridging this gap, we consider the NIST LWC finalist Romulus-H hash function, which is constructed by injecting the Hirose DBL compression function into a Merkle-Damgård variant. Concretely, we consider Random Oracle (RO)-based variants of Hirose construction and Romulus-H. When the output size of the random oracle is n-bit, we prove that this RO-based Hirose variant is: (i) collapsing up to \(2^{n/2}\) quantum random oracle queries, and (ii) preimage resistance up to \(2^n\) quantum random oracle queries. Our proven bounds are easily extended to the RO-based Romulus-H as well.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Towards Quantum Security of Hirose Compression Function and Romulus-H

  • Shaoxuan Zhang,
  • Chun Guo,
  • Meiqin Wang

摘要

Double-block-length (DBL) hash is a classical and effective approach to amplify concrete security of hash functions. However, it remains open if popular DBL constructions achieve non-trivial security in the quantum world. Towards bridging this gap, we consider the NIST LWC finalist Romulus-H hash function, which is constructed by injecting the Hirose DBL compression function into a Merkle-Damgård variant. Concretely, we consider Random Oracle (RO)-based variants of Hirose construction and Romulus-H. When the output size of the random oracle is n-bit, we prove that this RO-based Hirose variant is: (i) collapsing up to \(2^{n/2}\) quantum random oracle queries, and (ii) preimage resistance up to \(2^n\) quantum random oracle queries. Our proven bounds are easily extended to the RO-based Romulus-H as well.