Paper 2026/382

Multi-Key Security in the Quantum World: Revisiting Tweakable Even-Mansour and FX

Rentaro Shiba, Nagoya University, Mitsubishi Electric (Japan)
Tetsu Iwata, Nagoya University
Abstract

In this paper, we prove the security of symmetric-key constructions in an adversary model called the Q1MK model, which combines the Q1 model, where the adversary makes classical online queries and quantum offline queries, and the multi-key (multi-user) setting. Specifically, under this model, we prove the security of two symmetric-key constructions: the tweakable Even-Mansour cipher (TEM) and the FX construction (FX), as starting points for understanding the post-quantum security of symmetric-key constructions in this adversary model. Our security proofs are based on the hybrid argument technique introduced by Alagic et al. at EUROCRYPT~2022. First, we prove that in order to break TEM in the Q1MK model, $\Omega(2^{\kappa/3})$ classical and quantum queries are needed, regardless of the number of target $\kappa$-bit keys. Then, before turning to the Q1MK security analysis of FX, we revisit the security proof of FX in the standard Q1 model proposed in version 20230317:200508 of ePrint~2022/1097 and tighten it. By the modified proof, we show that in order to break FX with $(\kappa + n)$-bit secret key in the Q1 model, $\Omega(2^{(\kappa+n)/3})$ classical and quantum queries are needed. We then apply this proof to the Q1MK setting, and we show that in order to break FX in the Q1MK model, $\Omega(2^{(\kappa + n - u)/3})$ classical and quantum queries are needed, when $2^u$ ($\le 2^{\kappa}$) independent keys are in use.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Published by the IACR in TOSC 2026
Keywords
multi-key securitymulti-user securitypost-quantum securityprovable securitytweakable Even-MansourFX
Contact author(s)
shiba rentaro k7 @ s mail nagoya-u ac jp
tetsu iwata @ nagoya-u jp
History
2026-06-16: revised
2026-02-24: received
See all versions
Short URL
https://ia.cr/2026/382
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/382,
      author = {Rentaro Shiba and Tetsu Iwata},
      title = {Multi-Key Security in the Quantum World: Revisiting Tweakable Even-Mansour and {FX}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/382},
      year = {2026},
      url = {https://eprint.iacr.org/2026/382}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.