{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T07:56:26Z","timestamp":1781078186167,"version":"3.54.1"},"publisher-location":"Cham","reference-count":37,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031223174","type":"print"},{"value":"9783031223181","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-22318-1_3","type":"book-chapter","created":{"date-parts":[[2022,12,21]],"date-time":"2022-12-21T03:04:30Z","timestamp":1671591870000},"page":"52-79","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["The Parallel Reversible Pebbling Game: Analyzing the\u00a0Post-quantum Security of\u00a0iMHFs"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5542-4674","authenticated-orcid":false,"given":"Jeremiah","family":"Blocki","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3638-163X","authenticated-orcid":false,"given":"Blake","family":"Holman","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4475-5686","authenticated-orcid":false,"given":"Seunghoon","family":"Lee","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,12,21]]},"reference":[{"key":"3_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"241","DOI":"10.1007\/978-3-662-53008-5_9","volume-title":"Advances in Cryptology \u2013 CRYPTO 2016","author":"J Alwen","year":"2016","unstructured":"Alwen, J., Blocki, J.: Efficiently computing data-independent memory-hard functions. In: Robshaw, M., Katz, J. (eds.) CRYPTO 2016. Part II. LNCS, vol. 9815, pp. 241\u2013271. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53008-5_9"},{"key":"3_CR2","doi-asserted-by":"crossref","unstructured":"Alwen, J., Blocki, J.: Towards practical attacks on argon2i and balloon hashing. In: 2017 IEEE European Symposium on Security and Privacy (EuroS &P), pp. 142\u2013157. IEEE (2017)","DOI":"10.1109\/EuroSP.2017.47"},{"key":"3_CR3","doi-asserted-by":"crossref","unstructured":"Alwen, J., Blocki, J., Harsha, B.: Practical graphs for optimal side-channel resistant memory-hard functions. In: Thuraisingham, B.M., Evans, D., Malkin, T., Xu, D. (eds.) ACM CCS 2017, pp. 1001\u20131017. ACM Press, October\/November 2017","DOI":"10.1145\/3133956.3134031"},{"key":"3_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-319-56617-7_1","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2017","author":"J Alwen","year":"2017","unstructured":"Alwen, J., Blocki, J., Pietrzak, K.: Depth-robust graphs and their cumulative memory complexity. In: Coron, J.-S., Nielsen, J.B. (eds.) EUROCRYPT 2017. Part III. LNCS, vol. 10212, pp. 3\u201332. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-56617-7_1"},{"key":"3_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1007\/978-3-319-78375-8_4","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2018","author":"J Alwen","year":"2018","unstructured":"Alwen, J., Blocki, J., Pietrzak, K.: Sustained space complexity. In: Nielsen, J.B., Rijmen, V. (eds.) EUROCRYPT 2018, Part II. LNCS, vol. 10821, pp. 99\u2013130. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-78375-8_4"},{"key":"3_CR6","doi-asserted-by":"crossref","unstructured":"Alwen, J., Serbinenko, V.: High parallel complexity graphs and memory-hard functions. In: Servedio, R.A., Rubinfeld, R. (eds.) 47th ACM STOC, pp. 595\u2013603. ACM Press, June 2015","DOI":"10.1145\/2746539.2746622"},{"key":"3_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"493","DOI":"10.1007\/978-3-319-70500-2_17","volume-title":"Theory of Cryptography","author":"J Alwen","year":"2017","unstructured":"Alwen, J., Tackmann, B.: Moderately hard functions: definition, instantiations, and applications. In: Kalai, Y., Reyzin, L. (eds.) TCC 2017. Part I. LNCS, vol. 10677, pp. 493\u2013526. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70500-2_17"},{"issue":"5","key":"3_CR8","doi-asserted-by":"publisher","first-page":"1510","DOI":"10.1137\/S0097539796300933","volume":"26","author":"CH Bennett","year":"1997","unstructured":"Bennett, C.H., Bernstein, E., Brassard, G., Vazirani, U.V.: Strengths and weaknesses of quantum computing. SIAM J. Comput. 26(5), 1510\u20131523 (1997)","journal-title":"SIAM J. Comput."},{"key":"3_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"220","DOI":"10.1007\/978-3-662-53887-6_8","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2016","author":"D Boneh","year":"2016","unstructured":"Boneh, D., Corrigan-Gibbs, H., Schechter, S.: Balloon hashing: a memory-hard function providing provable protection against sequential attacks. In: Cheon, J.H., Takagi, T. (eds.) ASIACRYPT 2016. Part I. LNCS, vol. 10031, pp. 220\u2013248. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53887-6_8"},{"key":"3_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1007\/978-3-642-25385-0_3","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2011","author":"D Boneh","year":"2011","unstructured":"Boneh, D., Dagdelen, \u00d6., Fischlin, M., Lehmann, A., Schaffner, C., Zhandry, M.: Random oracles in a quantum world. In: Lee, D.H., Wang, X. (eds.) ASIACRYPT 2011. LNCS, vol. 7073, pp. 41\u201369. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-25385-0_3"},{"key":"3_CR11","unstructured":"Biryukov, A., Dinu, D., Khovratovich, D., Josefsson, S.: The memory-hard argon2 password hash and proof-of-work function. In: Internet-Draft draft-irtf-cfrg-argon2-00, Internet Engineering Task Force (2016)"},{"issue":"4","key":"3_CR12","doi-asserted-by":"publisher","first-page":"766","DOI":"10.1137\/0218053","volume":"18","author":"CH Bennett","year":"1989","unstructured":"Bennett, C.H.: Time\/space trade-offs for reversible computation. SIAM J. Comput. 18(4), 766\u2013776 (1989)","journal-title":"SIAM J. Comput."},{"key":"3_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"573","DOI":"10.1007\/978-3-030-26951-7_20","volume-title":"Advances in Cryptology \u2013 CRYPTO 2019","author":"J Blocki","year":"2019","unstructured":"Blocki, J., Harsha, B., Kang, S., Lee, S., Xing, L., Zhou, S.: Data-independent memory hard functions: new attacks and stronger constructions. In: Boldyreva, A., Micciancio, D. (eds.) CRYPTO 2019. Part II. LNCS, vol. 11693, pp. 573\u2013607. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-26951-7_20"},{"key":"3_CR14","doi-asserted-by":"crossref","unstructured":"Blocki, J., Harsha, B., Zhou, S.: On the economics of offline password cracking. In: 2018 IEEE Symposium on Security and Privacy, pp. 853\u2013871. IEEE Computer Society Press, May 2018","DOI":"10.1109\/SP.2018.00009"},{"key":"3_CR15","unstructured":"Blocki, J., Lee, S., Zhou, S.: On the security of proofs of sequential work in a post-quantum world. In: Tessaro, S. (ed.) 2nd Conference on Information-Theoretic Cryptography (ITC 2021). Leibniz International Proceedings in Informatics (LIPIcs), vol. 199, pp. 22:1\u201322:27, Dagstuhl, Germany. Schloss Dagstuhl - Leibniz-Zentrum f\u00fcr Informatik (2021)"},{"key":"3_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"445","DOI":"10.1007\/978-3-319-70500-2_15","volume-title":"Theory of Cryptography","author":"J Blocki","year":"2017","unstructured":"Blocki, J., Zhou, S.: On the depth-robustness and cumulative pebbling cost of Argon2i. In: Kalai, Y., Reyzin, L. (eds.) TCC 2017. Part I. LNCS, vol. 10677, pp. 445\u2013465. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70500-2_15"},{"key":"3_CR17","doi-asserted-by":"crossref","unstructured":"Cobham, A.: The recognition problem for the set of perfect squares. In: 7th Annual Symposium on Switching and Automata Theory (swat 1966), pp. 78\u201387 (1966)","DOI":"10.1109\/SWAT.1966.30"},{"key":"3_CR18","doi-asserted-by":"crossref","unstructured":"Cook, S.A.: An observation on time-storage trade off. In: Proceedings of the Fifth Annual ACM Symposium on Theory of Computing, STOC 1973, pp. 29\u201333. Association for Computing Machinery, New York (1973)","DOI":"10.1145\/800125.804032"},{"key":"3_CR19","doi-asserted-by":"publisher","first-page":"2000","DOI":"10.1002\/1521-3978(200009)48:9\/11<771::AID-PROP771>3.0.CO;2-E","volume":"48","author":"DP Divincenzo","year":"2000","unstructured":"Divincenzo, D.P.: The physical implementation of quantum computation. Fortschr. Phys. 48, 2000 (2000)","journal-title":"Fortschr. Phys."},{"issue":"3","key":"3_CR20","doi-asserted-by":"publisher","first-page":"365","DOI":"10.1016\/0898-1221(75)90037-1","volume":"1","author":"P Erd\u00f6s","year":"1975","unstructured":"Erd\u00f6s, P., Graham, R.L., Szemer\u00e9di, E.: On sparse graphs with dense long paths. Comput. Math. Appl. 1(3), 365\u2013369 (1975)","journal-title":"Comput. Math. Appl."},{"key":"3_CR21","doi-asserted-by":"crossref","unstructured":"Fefferman, B., Remscrim, Z.: Eliminating intermediate measurements in space-bounded quantum computation. In Proceedings of the 53rd Annual ACM SIGACT Symposium on Theory of Computing, STOC 2021, pp. 1343\u20131356. Association for Computing Machinery, New York (2021)","DOI":"10.1145\/3406325.3451051"},{"key":"3_CR22","doi-asserted-by":"crossref","unstructured":"Grassi, P., et al.: Digital identity guidelines: authentication and lifecycle management, 2017-06-22 (2017)","DOI":"10.6028\/NIST.SP.800-63b"},{"key":"3_CR23","doi-asserted-by":"crossref","unstructured":"Grover, L.K.: A fast quantum mechanical algorithm for database search. In: 28th ACM STOC, pp. 212\u2013219. ACM Press, May 1996","DOI":"10.1145\/237814.237866"},{"issue":"2","key":"3_CR24","doi-asserted-by":"publisher","first-page":"332","DOI":"10.1145\/322003.322015","volume":"24","author":"J Hopcroft","year":"1977","unstructured":"Hopcroft, J., Paul, W., Valiant, L.: On time versus space. J. ACM 24(2), 332\u2013337 (1977)","journal-title":"J. ACM"},{"key":"3_CR25","doi-asserted-by":"crossref","unstructured":"Kaliski, B.: PKCS #5: Password-Based Cryptography Specification Version 2.0. RFC 2898, RSA Laboratories, September 2000","DOI":"10.17487\/rfc2898"},{"key":"3_CR26","doi-asserted-by":"crossref","unstructured":"Pati, A.K., Braunstein, S.: Impossibility of deleting an unknown quantum state. Nature 404, 164\u2013165 (2000)","DOI":"10.1038\/404130b0"},{"key":"3_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"292","DOI":"10.1007\/3-540-45627-9_26","volume-title":"SOFSEM 2001: Theory and Practice of Informatics","author":"R Kr\u00e1l\u2019ovi\u010d","year":"2001","unstructured":"Kr\u00e1l\u2019ovi\u010d, R.: Time and space complexity of reversible pebbling. In: Pacholski, L., Ru\u017ei\u010dka, P. (eds.) SOFSEM 2001. LNCS, vol. 2234, pp. 292\u2013303. Springer, Heidelberg (2001). https:\/\/doi.org\/10.1007\/3-540-45627-9_26"},{"key":"3_CR28","unstructured":"Kornerup, N., Sadun, J., Soloveichik, D.: The spooky pebble game (2021)"},{"key":"3_CR29","doi-asserted-by":"crossref","unstructured":"Li, M., Vit\u00e1nyi, P.: Reversibility and adiabatic computation: trading time and space for energy. Proc. Roy. Soc. Lond. Ser. A: Math. Phys. Eng. Sci. 452(1947), 769\u2013789 (1996)","DOI":"10.1098\/rspa.1996.0039"},{"key":"3_CR30","doi-asserted-by":"crossref","unstructured":"Meuli, G., Soeken, M., Roetteler, M., Bjorner, N., De Micheli, G.: Reversible pebbling game for quantum memory management. In: 2019 Design, Automation Test in Europe Conference Exhibition (DATE), pp. 288\u2013291 (2019)","DOI":"10.23919\/DATE.2019.8715092"},{"key":"3_CR31","doi-asserted-by":"crossref","unstructured":"Nielsen, M.A., Chuang, I.: Quantum computation and quantum information (2002)","DOI":"10.1119\/1.1463744"},{"key":"3_CR32","doi-asserted-by":"crossref","unstructured":"Paul, W.J., A 2.5 n-lower bound on the combinational complexity of Boolean functions. In: Proceedings of the Seventh Annual ACM Symposium on Theory of Computing, STOC 1975, pp. 27\u201336. Association for Computing Machinery, New York (1975)","DOI":"10.1145\/800116.803750"},{"key":"3_CR33","unstructured":"Paterson, M.S., Hewitt, C.E.: Comparative Schematology, pp. 119\u2013127. Association for Computing Machinery, New York (1970)"},{"key":"3_CR34","unstructured":"Provos, N., Mazi\u00e8res, D.: A future-adaptive password scheme. In: Proceedings of the Annual Conference on USENIX Annual Technical Conference, ATEC 1999, p. 32. USENIX Association, USA (1999)"},{"key":"3_CR35","doi-asserted-by":"crossref","unstructured":"Paul, W.J., Tarjan, R.E., Celoni, J.R.: Space bounds for a game on graphs. In: Proceedings of the Eighth Annual ACM Symposium on Theory of Computing, STOC 1976, pp. 149\u2013160. Association for Computing Machinery, New York (1976)","DOI":"10.1145\/800113.803643"},{"issue":"3","key":"3_CR36","doi-asserted-by":"publisher","first-page":"423","DOI":"10.1145\/321958.321962","volume":"23","author":"N Pippenger","year":"1976","unstructured":"Pippenger, N., Valiant, L.G.: Shifting graphs and their applications. J. ACM 23(3), 423\u2013432 (1976)","journal-title":"J. ACM"},{"issue":"1","key":"3_CR37","doi-asserted-by":"publisher","first-page":"106","DOI":"10.1016\/0022-0000(81)90007-6","volume":"23","author":"M Tompa","year":"1981","unstructured":"Tompa, M.: Corrigendum: time-space tradeoffs for computing functions, using connectivity properties of their circuits. J. Comput. Syst. Sci. 23(1), 106 (1981)","journal-title":"J. Comput. Syst. Sci."}],"container-title":["Lecture Notes in Computer Science","Theory of Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-22318-1_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,21]],"date-time":"2025-12-21T01:01:54Z","timestamp":1766278914000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-22318-1_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031223174","9783031223181"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-22318-1_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"21 December 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"TCC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Theory of Cryptography Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Chicago, IL","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7 November 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 November 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"tcc2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/tcc.iacr.org\/2022\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"139","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"60","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"43% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.1","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"9.9","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}