Security of Key-Alternating Ciphers: Quantum Lower Bounds and Quantum Walk Attacks
Chen Bai, Mehdi Esmaili, Atul Mantri

TL;DR
This paper investigates the quantum security of key-alternating ciphers, establishing lower bounds and a quantum key-recovery attack, revealing the impact of quantum adversaries on multi-round cipher security.
Contribution
It provides the first non-trivial quantum key-recovery algorithm for multi-round KACs and proves quantum lower bounds, advancing understanding of quantum attacks on symmetric ciphers.
Findings
Quantum lower bounds for t-round KACs in Q1 and Q2 models
A quantum key-recovery algorithm with improved query complexity
Collapse of the exponential Q1-Q2 gap for t ≥ 2 in non-adaptive setting
Abstract
We study the quantum security of key-alternating ciphers (KAC), a natural multi-round generalization of the Even--Mansour construction. KAC abstracts the round structure of practical block ciphers as public permutations interleaved with key XORs. The -round KAC or EM setting already highlights the power of quantum superposition access: EM is secure against classical and Q1 adversaries (quantum access to the public permutation), but insecure in the Q2 model. The security of multi-round KACs remain largely unexplored; in particular, whether the quantum-classical separation extends beyond a single round had remained open. 1) Quantum Lower Bounds. We prove security of the -round KAC against a non-adaptive adversary in both the Q1 and Q2 models. In the Q1 model, any distinguiser requires oracle queries to distinguish the cipher from a random permutation,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsQuantum Computing Algorithms and Architecture · Cryptographic Implementations and Security · Chaos-based Image/Signal Encryption
