Abstract
The FX construction FXk,k′[E](x) = Ek (x ⊕ k′) ⊕ k′ transforms a block cipher E: {0, 1}κ ×{0, 1}n → {0, 1}n with κ-bit keys into a block cipher with (κ+n)-bit keys. It ensuresκ+n bits 2 security in the classical setting andκ+n bits security in the quantum Q1 setting. Alagic et al. proposed 3 a so-called tweakable FX construction, which is defined as (Formula Presented). It constructs a tweakable block cipher from a (classical) block cipher and two auxiliary functions f1 and f2 . Alagic proved min{n/2, (κ + n)/3} bits quantum Q1 security for this construction. Interestingly, Sibleyras proposed another model of tweakable FX construction, which is defined as (Formula Presented). In Sibleyras’s construction, the block cipher E is invoked with a tweak-dependent key g(kg, t). In the classical setting, Sibleyras’s construction was proved to ensure (κ + n)/2 bits security, and a natural question is whether it enjoys (κ + n)/3 bits quantum Q1 security. This study answers this question positively. By adapting a number of distributions in the proofs of Alagic et al. and Guo et al., it is proved that Sibleyras’s tweakable FX construction yields a tweakable block cipher with (κ + n)/3 bits quantum Q1 security. The gap between security bounds of Sibleyras’s and Alagic’s constructions indicates that minor modifications to cryptographic constructions may incur significant influences.
| Translated title of the contribution | Quantum Q1 Security of Sibleyras’s Tweakable FX Construction |
|---|---|
| Original language | Chinese (Traditional) |
| Pages (from-to) | 1247-1264 |
| Number of pages | 18 |
| Journal | Journal of Cryptologic Research |
| Volume | 12 |
| Issue number | 6 |
| DOIs | |
| State | Published - 2025 |
| Externally published | Yes |
Fingerprint
Dive into the research topics of 'Quantum Q1 Security of Sibleyras’s Tweakable FX Construction'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver