[Paper Review] Classical Encryption and Authentication under Quantum Attacks
This paper re-proves a key result by Boneh and Zhandry showing that uniformly random functions—and thus quantum-secure pseudorandom functions—can serve as message authentication codes (MACs) secure against adversaries with superposition oracle access. The proof uses the quantum polynomial method, demonstrating that forging q+1 valid input-output pairs after q superposition queries is impossible with non-negligible probability, even under quantum attacks.
Post-quantum cryptography studies the security of classical, i.e. non-quantum cryptographic protocols against quantum attacks. Until recently, the considered adversaries were assumed to use quantum computers and behave like classical adversaries otherwise. A more conservative approach is to assume that also the communication between the honest parties and the adversary is (partly) quantum. We discuss several options to define secure encryption and authentication against these stronger adversaries who can carry out 'superposition attacks'. We re-prove a recent result of Boneh and Zhandry, stating that a uniformly random function (and hence also a quantum-secure pseudorandom function) can serve as a message-authentication code which is secure, even if the adversary can evaluate this function in superposition.
Motivation & Objective
- To investigate the security of classical cryptographic schemes, particularly MACs, under stronger quantum attack models where communication between honest parties and adversaries can be quantum.
- To explore whether traditional security definitions for encryption and authentication remain valid when adversaries can perform superposition queries and entangle with honest parties.
- To provide a new, self-contained proof of Boneh and Zhandry's result on quantum-secure MACs using the quantum polynomial method.
- To propose and analyze an alternative security model that includes non-entangled quantum communication, assessing its feasibility and potential strength compared to existing models.
Proposed method
- Re-proves the theorem of Boneh and Zhandry using the quantum polynomial method, a technique from quantum query complexity.
- Models the MAC forging game as a quantum query problem where an adversary makes q superposition queries to an oracle function.
- Applies a generalization of Farhi et al.'s theorem on function identification via quantum queries to bound the adversary's success probability in outputting q+1 valid pairs.
- Uses the fact that a uniformly random function (or pseudorandom function) cannot be distinguished from a random function by an adversary making polynomially many superposition queries.
- Analyzes the success probability of an adversary in forging a MAC as being bounded by q/|Y|, where |Y| is the size of the output space, which is negligible when |Y| is large.
- Establishes that quantum-secure pseudorandom functions (PRFs) imply quantum-secure MACs under the EUF-qCMA security model.
Experimental results
Research questions
- RQ1Can classical MACs built from pseudorandom functions remain secure when the adversary has superposition access to the underlying function?
- RQ2Is the security of a MAC under superposition attacks equivalent to classical security, or does it require stronger assumptions?
- RQ3Can a new security model that includes non-entangled quantum communication between honest parties and adversaries yield stronger or more realistic security guarantees?
- RQ4What is the relationship between the quantum polynomial method and the security of cryptographic primitives under quantum superposition attacks?
- RQ5Are there feasible constructions of encryption schemes secure under the proposed quantum communication model, and how do they compare to Boneh and Zhandry’s model?
Key findings
- A uniformly random function can serve as a quantum-secure MAC, even when the adversary has superposition oracle access, because forging q+1 input-output pairs after q queries is impossible with non-negligible probability.
- The success probability of an adversary forging a MAC with q superposition queries is bounded by q/|Y|, which is negligible when |Y| is exponentially large in the security parameter.
- Quantum-secure pseudorandom functions (PRFs) imply quantum-secure MACs under the EUF-qCMA model, as they are indistinguishable from random functions under superposition queries.
- The proof technique generalizes Farhi et al.'s result on function identification, extending it to non-Boolean functions and the goal of generating multiple input-output pairs.
- The construction of quantum-secure MACs from PRFs is feasible and secure, supporting the use of classical schemes in a post-quantum world with quantum-interactive adversaries.
- The paper suggests that classical constructions like the Luby-Rackoff block cipher may be quantum-secure, though this remains an open question requiring further research.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.