{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,9]],"date-time":"2026-01-09T14:36:17Z","timestamp":1767969377269,"version":"3.49.0"},"publisher-location":"Cham","reference-count":44,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031159787","type":"print"},{"value":"9783031159794","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-15979-4_6","type":"book-chapter","created":{"date-parts":[[2022,10,12]],"date-time":"2022-10-12T16:25:31Z","timestamp":1665591931000},"page":"165-194","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":19,"title":["On\u00a0the\u00a0Impossibility\u00a0of\u00a0Key\u00a0Agreements\u00a0from Quantum Random Oracles"],"prefix":"10.1007","author":[{"given":"Per","family":"Austrin","sequence":"first","affiliation":[]},{"given":"Hao","family":"Chung","sequence":"additional","affiliation":[]},{"given":"Kai-Min","family":"Chung","sequence":"additional","affiliation":[]},{"given":"Shiuan","family":"Fu","sequence":"additional","affiliation":[]},{"given":"Yao-Ting","family":"Lin","sequence":"additional","affiliation":[]},{"given":"Mohammad","family":"Mahmoody","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2022,10,13]]},"reference":[{"key":"6_CR1","unstructured":"Aaronson, S., Ambainis, A.: The need for structure in quantum speedups. arXiv preprint arXiv:0911.0996 (2009)"},{"issue":"2063","key":"6_CR2","first-page":"3473","volume":"461","author":"S Aaronson","year":"2005","unstructured":"Aaronson, S.: Quantum computing, postselection, and probabilistic polynomial-time. Proc. R. Soc. A Math. Phys. Eng. Sci. 461(2063), 3473\u20133482 (2005)","journal-title":"Proc. R. Soc. A Math. Phys. Eng. Sci."},{"key":"6_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"435","DOI":"10.1007\/978-3-030-77870-5_16","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2021","author":"A Agarwal","year":"2021","unstructured":"Agarwal, A., Bartusek, J., Goyal, V., Khurana, D., Malavolta, G.: Post-quantum multi-party computation. In: Canteaut, A., Standaert, F.-X. (eds.) EUROCRYPT 2021. LNCS, vol. 12696, pp. 435\u2013464. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-77870-5_16"},{"key":"6_CR4","doi-asserted-by":"crossref","unstructured":"Austrin, P., Chung, H., Chung, K.-M., Fu, S., Lin, Y.-T., Mahmoody, M.: On the impossibility of key agreements from quantum random oracles. Cryptology ePrint Archive, Paper 2022\/218 (2022). https:\/\/eprint.iacr.org\/2022\/218","DOI":"10.1007\/978-3-031-15979-4_6"},{"key":"6_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"153","DOI":"10.1007\/978-3-030-64381-2_6","volume-title":"Theory of Cryptography","author":"G Alagic","year":"2020","unstructured":"Alagic, G., Childs, A.M., Grilo, A.B., Hung, S.-H.: Non-interactive classical verification of quantum computation. In: Pass, R., Pietrzak, K. (eds.) TCC 2020. LNCS, vol. 12552, pp. 153\u2013180. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64381-2_6"},{"key":"6_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"346","DOI":"10.1007\/978-3-030-84242-0_13","volume-title":"Advances in Cryptology \u2013 CRYPTO 2021","author":"P Ananth","year":"2021","unstructured":"Ananth, P., Chung, K.-M., Placa, R.L.L.: On the concurrent composition of quantum zero-knowledge. In: Malkin, T., Peikert, C. (eds.) CRYPTO 2021. LNCS, vol. 12825, pp. 346\u2013374. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-84242-0_13"},{"key":"6_CR7","series-title":"Information Security and Cryptography","doi-asserted-by":"publisher","first-page":"45","DOI":"10.1007\/978-3-319-57048-8_2","volume-title":"Tutorials on the Foundations of Cryptography","author":"B Barak","year":"2017","unstructured":"Barak, B.: The complexity of public-key cryptography. In: Tutorials on the Foundations of Cryptography. ISC, pp. 45\u201377. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-57048-8_2"},{"key":"6_CR8","unstructured":"Bartusek, J.: Secure quantum computation with classical communication. Cryptology ePrint Archive, Report 2021\/964 (2021). https:\/\/ia.cr\/2021\/964"},{"key":"6_CR9","unstructured":"Bennett, C.H., Brassard, G.: Quantum cryptography: public key distribution and coin tossing. In: Proceedings of IEEE International Conference on Computers, Systems, and Signal Processing, pp. 175\u2013179 (1984)"},{"key":"6_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"55","DOI":"10.1007\/978-3-540-78524-8_4","volume-title":"Theory of Cryptography","author":"E Biham","year":"2008","unstructured":"Biham, E., Goren, Y.J., Ishai, Y.: Basing weak public-key cryptography on strong one-way functions. In: Canetti, R. (ed.) TCC 2008. LNCS, vol. 4948, pp. 55\u201372. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-78524-8_4"},{"issue":"2","key":"6_CR11","doi-asserted-by":"publisher","first-page":"510","DOI":"10.1006\/inco.2000.2885","volume":"163","author":"M Bellare","year":"2000","unstructured":"Bellare, M., Goldreich, O., Petrank, E.: Uniform generation of NP-witnesses using an NP-oracle. Inf. Comput. 163(2), 510\u2013526 (2000)","journal-title":"Inf. Comput."},{"key":"6_CR12","unstructured":"Brassard, G., Hoyer, P., Kalach, K., Kaplan, M., Laplante, S., Salvail, L.: Key establishment \u00e0 la merkle in a quantum world (2015)"},{"key":"6_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1007\/978-3-030-90459-3_3","volume-title":"Theory of Cryptography","author":"N Bitansky","year":"2021","unstructured":"Bitansky, N., Kellner, M., Shmueli, O.: Post-quantum resettably-sound zero knowledge. In: Nissim, K., Waters, B. (eds.) TCC 2021. LNCS, vol. 13042, pp. 62\u201389. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-90459-3_3"},{"key":"6_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"559","DOI":"10.1007\/978-3-642-19571-6_34","volume-title":"Theory of Cryptography","author":"Z Brakerski","year":"2011","unstructured":"Brakerski, Z., Katz, J., Segev, G., Yerukhimovich, A.: Limits on the power of zero-knowledge proofs in cryptographic constructions. In: Ishai, Y. (ed.) TCC 2011. LNCS, vol. 6597, pp. 559\u2013578. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-19571-6_34"},{"key":"6_CR15","unstructured":"Brakerski, Z., Koppula, V., Vazirani, U., Vidick, T.: Simpler proofs of quantumness. arXiv preprint arXiv:2005.04826 (2020)"},{"issue":"3","key":"6_CR16","doi-asserted-by":"publisher","first-page":"699","DOI":"10.1007\/s00145-016-9233-9","volume":"30","author":"B Barak","year":"2017","unstructured":"Barak, B., Mahmoody, M.: Merkle\u2019s key agreement protocol is optimal: an $${O}(n^2)$$ attack on any key agreement from random oracles. J. Cryptol. 30(3), 699\u2013734 (2017)","journal-title":"J. Cryptol."},{"key":"6_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"374","DOI":"10.1007\/978-3-642-03356-8_22","volume-title":"Advances in Cryptology - CRYPTO 2009","author":"B Barak","year":"2009","unstructured":"Barak, B., Mahmoody-Ghidary, M.: Merkle puzzles are optimal \u2014 an O(n2)-query attack on any key exchange from a random oracle. In: Halevi, S. (ed.) CRYPTO 2009. LNCS, vol. 5677, pp. 374\u2013390. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-03356-8_22"},{"key":"6_CR18","doi-asserted-by":"crossref","unstructured":"Brassard, G., Salvail, L.: Quantum Merkle puzzles. In: International Conference on Quantum, Nano and Micro Technologies (ICQNM), pp. 76\u201379. IEEE Computer Society (2008)","DOI":"10.1109\/ICQNM.2008.16"},{"key":"6_CR19","doi-asserted-by":"crossref","unstructured":"Bitansky, N., Shmueli, O.: Post-quantum zero knowledge in constant rounds. In: Proceedings of the 52nd Annual ACM SIGACT Symposium on Theory of Computing, pp. 269\u2013279 (2020)","DOI":"10.1145\/3357713.3384324"},{"key":"6_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1007\/978-3-030-64381-2_7","volume-title":"Theory of Cryptography","author":"N-H Chia","year":"2020","unstructured":"Chia, N.-H., Chung, K.-M., Yamakawa, T.: Classical verification of quantum computations with efficient verifier. In: Pass, R., Pietrzak, K. (eds.) TCC 2020. LNCS, vol. 12552, pp. 181\u2013206. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64381-2_7"},{"key":"6_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"598","DOI":"10.1007\/978-3-030-77886-6_21","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2021","author":"K-M Chung","year":"2021","unstructured":"Chung, K.-M., Fehr, S., Huang, Y.-H., Liao, T.-N.: On the compressed-oracle technique, and post-quantum security of proofs of sequential work. In: Canteaut, A., Standaert, F.-X. (eds.) EUROCRYPT 2021. LNCS, vol. 12697, pp. 598\u2013629. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-77886-6_21"},{"key":"6_CR22","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1016\/j.tcs.2020.11.013","volume":"855","author":"S Cao","year":"2021","unstructured":"Cao, S., Xue, R.: Being a permutation is also orthogonal to one-wayness in quantum world: impossibilities of quantum one-way permutations from one-wayness primitives. Theor. Comput. Sci. 855, 16\u201342 (2021)","journal-title":"Theor. Comput. Sci."},{"key":"6_CR23","doi-asserted-by":"crossref","unstructured":"Dinur, I., Friedgut, E., Kindler, G., O\u2019Donnell, R.: On the Fourier tails of bounded functions over the discrete cube. In: Proceedings of the Thirty-Eighth Annual ACM Symposium on Theory of Computing, pp. 437\u2013446 (2006)","DOI":"10.1145\/1132516.1132580"},{"issue":"6","key":"6_CR24","doi-asserted-by":"publisher","first-page":"644","DOI":"10.1109\/TIT.1976.1055638","volume":"22","author":"W Diffie","year":"1976","unstructured":"Diffie, W., Hellman, M.E.: New directions in cryptography. IEEE Trans. Inf. Theory 22(6), 644\u2013654 (1976)","journal-title":"IEEE Trans. Inf. Theory"},{"key":"6_CR25","doi-asserted-by":"crossref","unstructured":"Gertner, Y., Kannan, S., Malkin, T., Reingold, O., Viswanathan, M.: The relationship between public key encryption and oblivious transfer. In: Proceedings 41st Annual Symposium on Foundations of Computer Science, pp. 325\u2013335. IEEE (2000)","DOI":"10.1109\/SFCS.2000.892121"},{"key":"6_CR26","doi-asserted-by":"crossref","unstructured":"Grover, L.K.: A fast quantum mechanical algorithm for database search. In: Proceedings of the Twenty-Eighth Annual ACM Symposium on Theory of Computing, pp. 212\u2013219 (1996)","DOI":"10.1145\/237814.237866"},{"key":"6_CR27","doi-asserted-by":"crossref","unstructured":"Haitner, I., Hoch, J.J., Reingold, O., Segev, G.: Finding collisions in interactive protocols - a tight lower bound on the round complexity of statistically-hiding commitments. In: Proceedings of the 48th Annual IEEE Symposium on Foundations of Computer Science (FOCS 2007), Providence, RI, USA, 20\u201323 October 2007, pp. 669\u2013679 (2007)","DOI":"10.1109\/FOCS.2007.7"},{"key":"6_CR28","unstructured":"Haitner, I., Mazor, N., Oshman, R., Reingold, O., Yehudayoff, A.: On the communication complexity of key-agreement protocols. arXiv preprint arXiv:2105.01958 (2021)"},{"key":"6_CR29","doi-asserted-by":"crossref","unstructured":"Haitner, I., Mazor, N., Silbak, J., Tsfadia, E.: On the complexity of two-party differential privacy (2021)","DOI":"10.1145\/3519935.3519982"},{"key":"6_CR30","doi-asserted-by":"crossref","unstructured":"Holenstein, T.: Key agreement from weak bit agreement. In: Proceedings of the Thirty-Seventh Annual ACM Symposium on Theory of Computing, pp. 664\u2013673 (2005)","DOI":"10.1145\/1060590.1060689"},{"issue":"2","key":"6_CR31","doi-asserted-by":"publisher","first-page":"283","DOI":"10.1007\/s00145-014-9194-9","volume":"29","author":"I Haitner","year":"2016","unstructured":"Haitner, I., Omri, E., Zarosim, H.: Limits on the usefulness of random oracles. J. Cryptol. 29(2), 283\u2013335 (2016)","journal-title":"J. Cryptol."},{"key":"6_CR32","unstructured":"Hosoyamada, A., Yamakawa, T.: Finding collisions in a quantum world: quantum black-box separation of collision-resistance and one-wayness. Cryptology ePrint Archive, Report 2018\/1066 (2018). http:\/\/ia.cr\/2018\/1066"},{"key":"6_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-030-64837-4_1","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2020","author":"A Hosoyamada","year":"2020","unstructured":"Hosoyamada, A., Yamakawa, T.: Finding collisions in a quantum world: quantum black-box separation of collision-resistance and one-wayness. In: Moriai, S., Wang, H. (eds.) ASIACRYPT 2020. LNCS, vol. 12491, pp. 3\u201332. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-64837-4_1"},{"key":"6_CR34","doi-asserted-by":"crossref","unstructured":"Impagliazzo, R., Rudich, S.: Limits on the provable consequences of one-way permutations. In: Proceedings of the 21st Annual ACM Symposium on Theory of Computing (STOC), pp. 44\u201361. ACM Press (1989)","DOI":"10.1145\/73007.73012"},{"key":"6_CR35","doi-asserted-by":"crossref","unstructured":"Kahn, J., Saks, M., Smyth, C.: A dual version of Reimer\u2019s inequality and a proof of Rudich\u2019s conjecture. In: Proceedings 15th Annual IEEE Conference on Computational Complexity, pp. 98\u2013103. IEEE (2000)","DOI":"10.1109\/CCC.2000.856739"},{"key":"6_CR36","doi-asserted-by":"crossref","unstructured":"Mahadev, U.: Classical verification of quantum computations. In: 2018 IEEE 59th Annual Symposium on Foundations of Computer Science (FOCS), pp. 259\u2013267. IEEE (2018)","DOI":"10.1109\/FOCS.2018.00033"},{"key":"6_CR37","unstructured":"Merkle, R.: C.s. 244 project proposal (1974). Facsimile http:\/\/www.merkle.com\/1974"},{"key":"6_CR38","doi-asserted-by":"crossref","unstructured":"Mahmoody, M., Maji, H.K., Prabhakaran, M.: Limits of random oracles in secure computation. In: Proceedings of the 5th Conference on Innovations in Theoretical Computer Science, pp. 23\u201334 (2014)","DOI":"10.1145\/2554797.2554801"},{"key":"6_CR39","doi-asserted-by":"crossref","unstructured":"O\u2019Donnell, R., Saks, M., Schramm, O., Servedio, R.A.: Every decision tree has an influential variable. In: 46th Annual IEEE Symposium on Foundations of Computer Science (FOCS 2005), pp. 31\u201339. IEEE (2005)","DOI":"10.1109\/SFCS.2005.34"},{"issue":"2","key":"6_CR40","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1145\/359340.359342","volume":"21","author":"RL Rivest","year":"1978","unstructured":"Rivest, R.L., Shamir, A., Adleman, L.M.: A method for obtaining digital signatures and public-key cryptosystems. Commun. ACM 21(2), 120\u2013126 (1978)","journal-title":"Commun. ACM"},{"key":"6_CR41","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-540-24638-1_1","volume-title":"Theory of Cryptography","author":"O Reingold","year":"2004","unstructured":"Reingold, O., Trevisan, L., Vadhan, S.: Notions of reducibility between cryptographic primitives. In: Naor, M. (ed.) TCC 2004. LNCS, vol. 2951, pp. 1\u201320. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-24638-1_1"},{"key":"6_CR42","unstructured":"Rudich, S.: Limits on the provable consequences of one-way functions. Ph.D. thesis, University of California (1988)"},{"key":"6_CR43","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"239","DOI":"10.1007\/978-3-030-26951-7_9","volume-title":"Advances in Cryptology \u2013 CRYPTO 2019","author":"M Zhandry","year":"2019","unstructured":"Zhandry, M.: How to record quantum queries, and applications to quantum indifferentiability. In: Boldyreva, A., Micciancio, D. (eds.) CRYPTO 2019. LNCS, vol. 11693, pp. 239\u2013268. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-26951-7_9"},{"key":"6_CR44","doi-asserted-by":"crossref","unstructured":"Zhang, J.: Succinct blind quantum computation using a random oracle. In: STOC 2021: 53rd Annual ACM SIGACT Symposium on Theory of Computing, Virtual Event, Italy, 21\u201325 June 2021, pp. 1370\u20131383 (2021)","DOI":"10.1145\/3406325.3451082"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 CRYPTO 2022"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-15979-4_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T22:03:17Z","timestamp":1760220197000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-15979-4_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031159787","9783031159794"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-15979-4_6","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"13 October 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CRYPTO","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Cryptology Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Santa Barbara, CA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15 August 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 August 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"42","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crypto2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crypto.iacr.org\/2022\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}