Paper 2024/1478

Mind the Bad Norms: Revisiting Compressed Oracle-based Quantum Indistinguishability Proofs

Ritam Bhaumik, TII, Abu Dhabi, UAE
Benoît Cogliati, Thales DIS France SAS, Meudon, France
Jordan Ethan, CISPA Helmholtz Center for Information Security, Saarbrücken, Germany
Ashwin Jha, Ruhr-Universität Bochum, Bochum, Germany

In this work, we revisit the Hosoyamada-Iwata (HI) proof for the quantum CPA security of the 4-round Luby-Rackoff construction and identify a gap that appears to undermine the security proof. We emphasize that this is not an attack, and the construction may still achieve the claimed security level. However, this gap raises concerns about the feasibility of establishing a formal security proof for the 4-round Luby-Rackoff construction. In fact, the issue persists even if the number of rounds is increased arbitrarily. On a positive note, we restore the security of the 4-round Luby-Rackoff construction in the non-adaptive setting, achieving security up to $2^{n/6}$ superposition queries. Furthermore, we establish the quantum CPA security of the 4-round MistyR and 5-round MistyL constructions, up to $2^{n/5}$ and $2^{n/7}$ superposition queries, respectively, where $n$ denotes the size of the underlying permutation.

