(Multi-key) quantum analysis of Masked Even–Mansour with applications to offset public permutation and elephant
摘要
Masked Even–Mansour (MEM) is a tweakable construction proposed at EUROCRYPT 2016 for usage in authenticated encryption schemes. This paper investigates the quantum security of MEM, highlighting the threat of quantum computing in applications, i.e., multi-user networks. In the single-key scenario, an attack on MEM using only known-plaintext classical queries is developed by exploiting the randomness inherent in tweaks. In the multi-key scenario, we explore general attacks and emphasize that it is costly to recover all keys if correlations between users cannot be established. To solve it, we draw on the giant component theorem and propose the first known-plaintext attack on MEM. The trade-offs between data per user (D), offline time (T), and the number of users (W) are