{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,18]],"date-time":"2025-03-18T04:14:16Z","timestamp":1742271256057,"version":"3.40.1"},"reference-count":37,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2024,12,18]],"date-time":"2024-12-18T00:00:00Z","timestamp":1734480000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,12,18]],"date-time":"2024-12-18T00:00:00Z","timestamp":1734480000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["No.62172337","No.61902073"],"award-info":[{"award-number":["No.62172337","No.61902073"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Key Project of Gansu Natural Science Foundation","award":["No.23JRRA685"],"award-info":[{"award-number":["No.23JRRA685"]}]},{"name":"The Funds for Innovative Fundamental Research Group Project of Gansu Province","award":["No.23JRRA684"],"award-info":[{"award-number":["No.23JRRA684"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Des. Codes Cryptogr."],"published-print":{"date-parts":[[2025,3]]},"DOI":"10.1007\/s10623-024-01538-z","type":"journal-article","created":{"date-parts":[[2024,12,18]],"date-time":"2024-12-18T16:21:41Z","timestamp":1734538901000},"page":"737-768","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Quantum security of Trojan message attacks on Merkle\u2013Damg\u00e5rd hash construction"],"prefix":"10.1007","volume":"93","author":[{"given":"Ying","family":"Xu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaoni","family":"Du","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jian","family":"Zou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,12,18]]},"reference":[{"key":"1538_CR1","doi-asserted-by":"crossref","unstructured":"Shor P.W.: Algorithms for quantum computation: discrete logarithms and factoring. In: Proceedings 35th Annual Symposium on Foundations of Computer Science, pp. 124\u2013134. IEEE (1994). https:\/\/ieeexplore.ieee.org\/abstract\/document\/365700.","DOI":"10.1109\/SFCS.1994.365700"},{"key":"1538_CR2","unstructured":"Standards N.I., Technology: post-quantum cryptography standardization. https:\/\/csrc.nist.gov\/projects\/post-quantum-cryptography\/post-quantum-cryptography-standardization."},{"key":"1538_CR3","doi-asserted-by":"crossref","unstructured":"Kuwakado H., Morii M.: Quantum distinguisher between the 3-round feistel cipher and the random permutation. In: 2010 IEEE International Symposium on Information Theory, pp. 2682\u20132685. IEEE (2010). https:\/\/ieeexplore.ieee.org\/abstract\/document\/5513654.","DOI":"10.1109\/ISIT.2010.5513654"},{"key":"1538_CR4","unstructured":"Kuwakado H., Morii M.: Security on the quantum-type Even-Mansour cipher. In: 2012 International Symposium on Information Theory and its Applications, pp. 312\u2013316. IEEE (2012). https:\/\/ieeexplore.ieee.org\/abstract\/document\/6400943."},{"key":"1538_CR5","doi-asserted-by":"publisher","unstructured":"Kaplan M., Leurent G., Leverrier A., Naya-Plasencia M.: Breaking symmetric cryptosystems using quantum period finding. In: Advances in Cryptology\u2014CRYPTO 2016: 36th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 14\u201318, 2016, Proceedings, Part II 36, pp. 207\u2013237. Springer, Berlin (2016). https:\/\/doi.org\/10.1007\/978-3-662-53008-5_8.","DOI":"10.1007\/978-3-662-53008-5_8"},{"key":"1538_CR6","doi-asserted-by":"publisher","unstructured":"Leander G., May A.: Grover meets Simon\u2014quantumly attacking the FX-construction. In: Advances in Cryptology\u2014ASIACRYPT 2017: 23rd International Conference on the Theory and Applications of Cryptology and Information Security, Hong Kong, China, December 3\u20137, 2017, Proceedings, Part II 23, pp. 161\u2013178. Springer, Berlin (2017). https:\/\/doi.org\/10.1007\/978-3-319-70697-9_6.","DOI":"10.1007\/978-3-319-70697-9_6"},{"key":"1538_CR7","doi-asserted-by":"publisher","unstructured":"Bonnetain X., Naya-Plasencia M.: Hidden shift quantum cryptanalysis and implications. In: Advances in Cryptology\u2014ASIACRYPT 2018: 24th International Conference on the Theory and Application of Cryptology and Information Security, Brisbane, QLD, Australia, December 2\u20136, 2018, Proceedings, Part I 24, pp. 560\u2013592. Springer, Berlin (2018). https:\/\/doi.org\/10.1007\/978-3-030-03326-2_19.","DOI":"10.1007\/978-3-030-03326-2_19"},{"key":"1538_CR8","doi-asserted-by":"publisher","unstructured":"Bonnetain X., Leurent G., Naya-Plasencia M., Schrottenloher A.: Quantum linearization attacks. In: Advances in Cryptology\u2014ASIACRYPT 2021: 27th International Conference on the Theory and Application of Cryptology and Information Security, Singapore, December 6\u201310, 2021, Proceedings, Part I 27, pp. 422\u2013452. Springer, Berlin (2021). https:\/\/doi.org\/10.1007\/978-3-030-92062-3_15.","DOI":"10.1007\/978-3-030-92062-3_15"},{"key":"1538_CR9","doi-asserted-by":"publisher","unstructured":"Bonnetain X., Naya-Plasencia M., Schrottenloher A.: On quantum slide attacks. In: International Conference on Selected Areas in Cryptography, pp. 492\u2013519. Springer, Berlin (2019). https:\/\/doi.org\/10.1007\/978-3-030-38471-5_20.","DOI":"10.1007\/978-3-030-38471-5_20"},{"key":"1538_CR10","doi-asserted-by":"publisher","unstructured":"Ito G., Hosoyamada A., Matsumoto R., Sasaki Y., Iwata T.: Quantum chosen-ciphertext attacks against feistel ciphers. In: Topics in Cryptology\u2014CT-RSA 2019: The Cryptographers\u2019 Track at the RSA Conference 2019, San Francisco, CA, USA, March 4\u20138, 2019, Proceedings, pp. 391\u2013411. Springer, Berlin (2019). https:\/\/doi.org\/10.1007\/978-3-030-12612-4_20.","DOI":"10.1007\/978-3-030-12612-4_20"},{"key":"1538_CR11","doi-asserted-by":"publisher","unstructured":"Dong X., Dong B., Wang X.: Quantum attacks on some Feistel block ciphers. Des Codes Cryptogr. 88(6), 1179\u20131203 (2020). https:\/\/doi.org\/10.1007\/s10623-020-00741-y.","DOI":"10.1007\/s10623-020-00741-y"},{"issue":"5","key":"1538_CR12","doi-asserted-by":"publisher","first-page":"1474","DOI":"10.1137\/S0097539796298637","volume":"26","author":"DR Simon","year":"1997","unstructured":"Simon D.R.: On the power of quantum computation. SIAM J. Comput. 26(5), 1474\u20131483 (1997).","journal-title":"SIAM J. Comput."},{"key":"1538_CR13","doi-asserted-by":"crossref","unstructured":"Grover L.K.: A fast quantum mechanical algorithm for database search. In: Proceedings of the Twenty-eighth Annual ACM Symposium on Theory of Computing, pp. 212\u2013219 (1996). https:\/\/arxiv.org\/abs\/quant-ph\/9605043.","DOI":"10.1145\/237814.237866"},{"key":"1538_CR14","doi-asserted-by":"publisher","unstructured":"Merkle R.C.: A certified digital signature. In: Conference on the Theory and Application of Cryptology, pp. 218\u2013238. Springer, Berlin (1989). https:\/\/doi.org\/10.1007\/0-387-34805-0_21.","DOI":"10.1007\/0-387-34805-0_21"},{"key":"1538_CR15","doi-asserted-by":"publisher","unstructured":"Merkle R.C.: One way hash functions and des. In: Conference on the Theory and Application of Cryptology, pp. 428\u2013446. Springer, Berlin (1989). https:\/\/doi.org\/10.1007\/0-387-34805-0_40.","DOI":"10.1007\/0-387-34805-0_40"},{"key":"1538_CR16","doi-asserted-by":"publisher","unstructured":"Damg\u00e5rd I.B.: A design principle for hash functions. In: Conference on the Theory and Application of Cryptology, pp. 416\u2013427. Springer, Berlin (1989). https:\/\/doi.org\/10.1007\/0-387-34805-0_39.","DOI":"10.1007\/0-387-34805-0_39"},{"key":"1538_CR17","doi-asserted-by":"publisher","unstructured":"Joux A.: Multicollisions in iterated hash functions. application to cascaded constructions. In: Annual International Cryptology Conference, pp. 306\u2013316. Springer, Berlin (2004). https:\/\/doi.org\/10.1007\/978-3-540-28628-8_19.","DOI":"10.1007\/978-3-540-28628-8_19"},{"key":"1538_CR18","doi-asserted-by":"publisher","unstructured":"Kelsey J., Schneier B.: Second preimages on n-bit hash functions for much less than $$2^n$$ work. In: Advances in Cryptology\u2014EUROCRYPT 2005: 24th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Aarhus, Denmark, May 22-26, 2005. Proceedings 24, pp. 474\u2013490. Springer, Berlin (2005). https:\/\/doi.org\/10.1007\/11426639_28.","DOI":"10.1007\/11426639_28"},{"key":"1538_CR19","doi-asserted-by":"publisher","unstructured":"Andreeva E., Bouillaguet C., Fouque P.A., Hoch J.J., Kelsey J., Shamir A., Zimmer S.: Second preimage attacks on dithered hash functions. In: Advances in Cryptology\u2013EUROCRYPT 2008: 27th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Istanbul, Turkey, April 13\u201317, 2008. Proceedings 27, pp. 270\u2013288. Springer, Berlin (2008). https:\/\/doi.org\/10.1007\/978-3-540-78967-3_16.","DOI":"10.1007\/978-3-540-78967-3_16"},{"key":"1538_CR20","doi-asserted-by":"publisher","unstructured":"Kelsey J., Kohno T.: Herding hash functions and the nostradamus attack. In: Annual International Conference on the Theory and Applications of Cryptographic Techniques, pp. 183\u2013200. Springer, Berlin (2006). https:\/\/doi.org\/10.1007\/11761679_12.","DOI":"10.1007\/11761679_12"},{"key":"1538_CR21","doi-asserted-by":"publisher","first-page":"657","DOI":"10.1007\/s00145-015-9206-4","volume":"29","author":"E Andreeva","year":"2016","unstructured":"Andreeva E., Bouillaguet C., Dunkelman O., Fouque P.-A., Hoch J., Kelsey J., Shamir A., Zimmer S.: New second-preimage attacks on hash functions. J. Cryptol. 29, 657\u2013696 (2016). https:\/\/doi.org\/10.1007\/s00145-015-9206-4.","journal-title":"J. Cryptol."},{"key":"1538_CR22","doi-asserted-by":"publisher","unstructured":"Andreeva E., Bouillaguet C., Dunkelman O., Kelsey J.: Herding, second preimage and trojan message attacks beyond Merkle\u2013Damg\u00e5rd. In: Selected Areas in Cryptography: 16th Annual International Workshop, SAC 2009, Calgary, Alberta, Canada, August 13\u201314, 2009, Revised Selected Papers 16, pp. 393\u2013414. Springer, Berlin (2009). https:\/\/doi.org\/10.1007\/978-3-642-05445-7_25.","DOI":"10.1007\/978-3-642-05445-7_25"},{"key":"1538_CR23","doi-asserted-by":"publisher","unstructured":"Kortelainen T., Kortelainen J.: On diamond structures and trojan message attacks. In: International Conference on the Theory and Application of Cryptology and Information Security, pp. 524\u2013539. Springer, Berlin (2013). https:\/\/doi.org\/10.1007\/978-3-642-42045-0_27.","DOI":"10.1007\/978-3-642-42045-0_27"},{"key":"1538_CR24","unstructured":"Chen S., Jin C.: Trojan message attack on the concatenated hash functions. J. Commun. 37(8), 45\u201350 (2016)."},{"key":"1538_CR25","doi-asserted-by":"publisher","unstructured":"Benedikt B.J., Fischlin M., Huppert M.: Nostradamus goes quantum. In: International Conference on the Theory and Application of Cryptology and Information Security, pp. 583\u2013613. Springer, Berlin (2022). https:\/\/doi.org\/10.1007\/978-3-031-22969-5_20.","DOI":"10.1007\/978-3-031-22969-5_20"},{"issue":"5","key":"1538_CR26","doi-asserted-by":"publisher","DOI":"10.1103\/PhysRevA.78.052310","volume":"78","author":"V Giovannetti","year":"2008","unstructured":"Giovannetti V., Lloyd S., Maccone L.: Architectures for a quantum random access memory. Phys. Rev. A 78(5), 052310 (2008). https:\/\/doi.org\/10.1103\/PhysRevA.78.052310.","journal-title":"Phys. Rev. A"},{"issue":"16","key":"1538_CR27","doi-asserted-by":"publisher","DOI":"10.1103\/PhysRevLett.100.160501","volume":"100","author":"V Giovannetti","year":"2008","unstructured":"Giovannetti V., Lloyd S., Maccone L.: Quantum random access memory. Phys. Rev. Lett. 100(16), 160501 (2008). https:\/\/doi.org\/10.1103\/PhysRevLett.100.160501.","journal-title":"Phys. Rev. Lett."},{"key":"1538_CR28","doi-asserted-by":"crossref","unstructured":"Bao Z., Guo J., Li S., Pham P.: Evaluating the security of Merkle\u2013Damg\u00e5rd hash functions and combiners in quantum settings. In: International Conference on Network and System Security, pp. 687\u2013711. Springer, Berlin (2022).","DOI":"10.1007\/978-3-031-23020-2_39"},{"key":"1538_CR29","doi-asserted-by":"publisher","unstructured":"Dong X., Li S., Pham P., Zhang G.: Quantum attacks on hash constructions with low quantum random access memory. In: International Conference on the Theory and Application of Cryptology and Information Security, pp. 3\u201333. Springer, Berlin (2023). https:\/\/doi.org\/10.1007\/978-981-99-8727-6_1.","DOI":"10.1007\/978-981-99-8727-6_1"},{"issue":"1","key":"1538_CR30","doi-asserted-by":"publisher","first-page":"210","DOI":"10.1137\/S0097539705447311","volume":"37","author":"A Ambainis","year":"2007","unstructured":"Ambainis A.: Quantum walk algorithm for element distinctness. SIAM J. Comput. 37(1), 210\u2013239 (2007). https:\/\/doi.org\/10.1137\/S0097539705447311.","journal-title":"SIAM J. Comput."},{"key":"1538_CR31","doi-asserted-by":"publisher","unstructured":"Brassard G., H\u00f8yer P., Tapp A.: Quantum cryptanalysis of hash and claw-free functions. In: LATIN\u201998: Theoretical Informatics: Third Latin American Symposium Campinas, Brazil, April 20\u201324, 1998 Proceedings 3, pp. 163\u2013169. Springer, Berlin (1998). https:\/\/doi.org\/10.1007\/BFb0054319.","DOI":"10.1007\/BFb0054319"},{"key":"1538_CR32","doi-asserted-by":"publisher","unstructured":"Chailloux A., Naya-Plasencia M., Schrottenloher A.: An efficient quantum collision search algorithm and implications on symmetric cryptography. In: Advances in Cryptology\u2014ASIACRYPT 2017: 23rd International Conference on the Theory and Applications of Cryptology and Information Security, Hong Kong, China, December 3\u20137, 2017, Proceedings, Part II 23, pp. 211\u2013240. Springer, Berlin (2017). https:\/\/doi.org\/10.1007\/978-3-319-70697-9_8.","DOI":"10.1007\/978-3-319-70697-9_8"},{"key":"1538_CR33","doi-asserted-by":"publisher","first-page":"53","DOI":"10.48550\/arXiv.quant-ph\/0005055","volume":"305","author":"G Brassard","year":"2002","unstructured":"Brassard G., Hoyer P., Mosca M., Tapp A.: Quantum amplitude amplification and estimation. Contemp. Math. 305, 53\u201374 (2002). https:\/\/doi.org\/10.48550\/arXiv.quant-ph\/0005055.","journal-title":"Contemp. Math."},{"key":"1538_CR34","unstructured":"Zhandry M.: A note on the quantum collision and set equality problems. arXiv preprint arXiv:1312.1027 (2013)."},{"key":"1538_CR35","doi-asserted-by":"publisher","unstructured":"Jaques S., Schrottenloher A.: Low-gate quantum golden collision finding. In: Selected Areas in Cryptography: 27th International Conference, Halifax, NS, Canada (Virtual Event), October 21\u201323, 2020, Revised Selected Papers 27, pp. 329\u2013359. Springer, Berlin (2021). https:\/\/doi.org\/10.1007\/978-3-030-81652-0_13.","DOI":"10.1007\/978-3-030-81652-0_13"},{"key":"1538_CR36","doi-asserted-by":"crossref","unstructured":"Zhandry M.: How to Construct Quantum Random Functions. Cryptology ePrint Archive, Paper 2012\/182 (2012). https:\/\/eprint.iacr.org\/2012\/182.","DOI":"10.1109\/FOCS.2012.37"},{"key":"1538_CR37","doi-asserted-by":"publisher","first-page":"171","DOI":"10.1007\/s10623-010-9481-x","volume":"64","author":"SR Blackburn","year":"2012","unstructured":"Blackburn S.R., Stinson D.R., Upadhyay J.: On the complexity of the herding attack and some related attacks on hash functions. Des. Codes Cryptogr. 64, 171\u2013193 (2012). https:\/\/doi.org\/10.1007\/s10623-010-9481-x.","journal-title":"Des. Codes Cryptogr."}],"container-title":["Designs, Codes and Cryptography"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10623-024-01538-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10623-024-01538-z\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10623-024-01538-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,17]],"date-time":"2025-03-17T16:40:49Z","timestamp":1742229649000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10623-024-01538-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,18]]},"references-count":37,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2025,3]]}},"alternative-id":["1538"],"URL":"https:\/\/doi.org\/10.1007\/s10623-024-01538-z","relation":{},"ISSN":["0925-1022","1573-7586"],"issn-type":[{"type":"print","value":"0925-1022"},{"type":"electronic","value":"1573-7586"}],"subject":[],"published":{"date-parts":[[2024,12,18]]},"assertion":[{"value":"17 July 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"19 September 2024","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 November 2024","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 December 2024","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"There are some additional declarations needed to be mentioned: all authors disclosed no relevant relationships.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}