Quantum security of subset cover problems
Samuel Bouaziz--Ermann, Alex B. Grilo, Damien Vergnaud

TL;DR
This paper analyzes the quantum query complexity of subset cover problems, which underpin the security of hash-based signature schemes, providing tight bounds and new algorithms for these cryptographic problems.
Contribution
It establishes tight quantum query complexity bounds for the restricted subset cover problem and general $(r,k)$-subset cover problem, advancing understanding of their cryptographic security.
Findings
Quantum algorithms match lower bounds for restricted subset cover.
Security bounds for hash-based signature schemes are clarified.
New quantum algorithms for subset cover problems are proposed.
Abstract
The subset cover problem for hash functions, which can be seen as an extension of the collision problem, was introduced in 2002 by Reyzin and Reyzin to analyse the security of their hash-function based signature scheme HORS. The security of many hash-based signature schemes relies on this problem or a variant of this problem (e.g. HORS, SPHINCS, SPHINCS+, ). Recently, Yuan, Tibouchi and Abe (2022) introduced a variant to the subset cover problem, called restricted subset cover, and proposed a quantum algorithm for this problem. In this work, we prove that any quantum algorithm needs to make queries to the underlying hash functions with codomain size to solve the restricted subset cover problem, which essentially matches the query complexity of the algorithm proposed by…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
