Quantum Key Recovery Attacks On Prøst‐COPA and Prøst‐OTR Using Simon's Algorithm

Wenjie Liu, Yuan‐Yuan Zhang · Advanced Quantum Technologies · 2024

Abstract Due to its innovative and performance advantages, Prøst‐COPA and Prøst‐OTR have attracted widespread attention. For the Prøst‐COPA without associated data and with associated data, the corresponding quantum key recovery attacks are proposed using Simon's algorithm, respectively. In the first scenario, the messages are used to calculate the Message Authentication Code (MAC) and construct a period function to recover the secret parameter . Then, utilizing ciphertext, a periodic function is constructed with a periodic value equal to the key value. MAC is calculated from messages and the associated data in the second scenario. Considering the impact of the associated data on the periodicity of the function, the messages are treated as a constant and further construct two periodic functions to recover the secret parameter and the key. For Prøst‐OTR, by constructing two periodic functions using two tags with different numbers of message blocks, the secret parameter can be recovered, and then the key can be recovered using Simon's algorithm. Compared to the classical attacks, the quantum‐based methods only require quantum queries (where is the message block size), resulting in an exponential speed acceleration and the success probability of the method is close to 1. These methods also show a lower query complexity than the state‐of‐the‐art quantum methods.

Read the paper · More papers on PaperTik