Paper 2019/1466

A Note on the Instantiability of the Quantum Random Oracle

Edward Eaton and Fang Song


In a highly influential paper from fifteen years ago, Canetti, Goldreich, and Halevi showed a fundamental separation between the Random Oracle Model (ROM) and the Standard Model. They constructed a signature scheme which can be shown to be secure in the ROM, but is insecure when instantiated with any hash function (and thus insecure in the standard model). In 2011, Boneh et al. defined the notion of the Quantum Random Oracle Model (QROM), where queries to the random oracle may be made in quantum superposition. Because the QROM generalizes the ROM, a proof of security in the QROM is stronger than one in the ROM. This leaves open the possibility that security in the QROM could imply security in the standard model. In this work, we show that this is not the case, and that security in the QROM cannot imply standard model security. We do this by showing that the original schemes that show a separation between the standard model and the ROM are also secure in the QROM. We consider two schemes that establish such a separation, one with length-restricted messages, and one without, and show both to be secure in the QROM. Our results give further understanding to the landscape of proofs in the ROM versus the QROM or standard model, and point towards the QROM and ROM being much closer to each other than either is to standard model security.

Available format(s)
Publication info
Preprint. MINOR revision.
Quantum Random OraclesTheory of CryptographyStandard ModelProvability
Contact author(s)
eeaton @ uwaterloo ca
fang song @ tamu edu
2019-12-23: received
Short URL
Creative Commons Attribution


      author = {Edward Eaton and Fang Song},
      title = {A Note on the Instantiability of the Quantum Random Oracle},
      howpublished = {Cryptology ePrint Archive, Paper 2019/1466},
      year = {2019},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.