<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName>Iranian Society of Cryptology</PublisherName>
				<JournalTitle>The ISC International Journal of Information Security</JournalTitle>
				<Issn>2008-2045</Issn>
				<Volume>15</Volume>
				<Issue>1</Issue>
				<PubDate PubStatus="epublish">
					<Year>2023</Year>
					<Month>01</Month>
					<Day>01</Day>
				</PubDate>
			</Journal>
<ArticleTitle>Quantum Cryptanalysis of Symmetric Primitives by Improving Relaxed Variants of Simon’s Algorithm</ArticleTitle>
<VernacularTitle></VernacularTitle>
			<FirstPage>83</FirstPage>
			<LastPage>95</LastPage>
			<ELocationID EIdType="pii">154316</ELocationID>
			
<ELocationID EIdType="doi">10.22042/isecure.2022.321346.739</ELocationID>
			
			<Language>EN</Language>
<AuthorList>
<Author>
					<FirstName>Ali</FirstName>
					<LastName>Khosravi</LastName>
<Affiliation>Sharif University of Technology, Department of Electrical Engineering, Tehran, Iran</Affiliation>

</Author>
<Author>
					<FirstName>Taraneh</FirstName>
					<LastName>Eghlidos</LastName>
<Affiliation>Electronics Research Institute, Sharif University of Technology, Tehran, Iran.</Affiliation>
<Identifier Source="ORCID">0000-0002-3182-0277</Identifier>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
			<History>
				<PubDate PubStatus="received">
					<Year>2021</Year>
					<Month>12</Month>
					<Day>24</Day>
				</PubDate>
			</History>
		<Abstract>The main goal of Simon’s Algorithm is to find the period of periodic functions. However, if the target function does not satisfy Simon&#039;s promise completely or if the number of superposition queries of the adversary is limited, Simon&#039;s algorithm cannot compute the actual period, unambiguously. These problems may lead to the failure of period-finding-based (PFB) quantum attacks. We focus in this paper on relaxing Simon&#039;s algorithm so that quantum adversaries can still carry out the mentioned attacks without any assumptions on the target function. To that end, we use two different methods, which are suitable for some of PFB quantum attacks. In the first method, as a complement to Kaplan&#039;s suggestion, we show that using Simon&#039;s algorithm one can find proper partial periods of Boolean vector functions, so that the probability of their establishment, independent of the target function, is directly related to the number of the attacker&#039;s quantum queries. Next, we examine how one can use partial period instead of the actual one. The advantage of this method is twofold: It enables the attackers to perform the quantum PFB distinguishers, with smaller number of quantum queries than those of the previous relaxation method. On the other hand, it generalizes the previous forgery attacks on modes of operation for message authentication codes. In the second method, we use Grover&#039;s algorithm, as a complement to Simon&#039;s algorithm in quantum key recovery attacks. This ensures that the time complexity of the mentioned attacks is less than that of a quantum brute-force attack.</Abstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">Modes of Operation</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Quantum Cryptanalysis</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Quantum Distinguishers</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Quantum Key Recovery Attack</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Quantum Related Key Attack</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Quantum Slide Attack</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Symmetric Cipher</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://www.isecure-journal.com/article_154316_add947ef6d495a9cf63dde8273b1f10f.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
