English

Post-Quantum Security of the Even-Mansour Cipher

Quantum Physics 2021-12-15 v1

Abstract

The Even-Mansour cipher is a simple method for constructing a (keyed) pseudorandom permutation EE from a public random permutation~P:{0,1}n{0,1}nP:\{0,1\}^n \rightarrow \{0,1\}^n. It is secure against classical attacks, with optimal attacks requiring qEq_E queries to EE and qPq_P queries to PP such that qEqP2nq_E \cdot q_P \approx 2^n. If the attacker is given \emph{quantum} access to both EE and PP, however, the cipher is completely insecure, with attacks using qE,qP=O(n)q_E, q_P = O(n) queries known. In any plausible real-world setting, however, a quantum attacker would have only \emph{classical} access to the keyed permutation~EE implemented by honest parties, even while retaining quantum access to~PP. Attacks in this setting with qEqP22nq_E \cdot q_P^2 \approx 2^n are known, showing that security degrades as compared to the purely classical case, but leaving open the question as to whether the Even-Mansour cipher can still be proven secure in this natural, "post-quantum" setting. We resolve this question, showing that any attack in that setting requires qEqP2+qPqE22nq_E \cdot q^2_P + q_P \cdot q_E^2 \approx 2^n. Our results apply to both the two-key and single-key variants of Even-Mansour. Along the way, we establish several generalizations of results from prior work on quantum-query lower bounds that may be of independent interest.

Keywords

Cite

@article{arxiv.2112.07530,
  title  = {Post-Quantum Security of the Even-Mansour Cipher},
  author = {Gorjan Alagic and Chen Bai and Jonathan Katz and Christian Majenz},
  journal= {arXiv preprint arXiv:2112.07530},
  year   = {2021}
}

Comments

19+4 pages

R2 v1 2026-06-24T08:17:04.462Z