Towards Quantum Security of Hirose Compression Function and Romulus-H
摘要
Double-block-length (DBL) hash is a classical and effective approach to amplify concrete security of hash functions. However, it remains open if popular DBL constructions achieve non-trivial security in the quantum world. Towards bridging this gap, we consider the NIST LWC finalist Romulus-H hash function, which is constructed by injecting the Hirose DBL compression function into a Merkle-Damgård variant. Concretely, we consider Random Oracle (RO)-based variants of Hirose construction and Romulus-H. When the output size of the random oracle is n-bit, we prove that this RO-based Hirose variant is: (i) collapsing up to \(2^{n/2}\) quantum random oracle queries, and (ii) preimage resistance up to \(2^n\) quantum random oracle queries. Our proven bounds are easily extended to the RO-based Romulus-H as well.