{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,27]],"date-time":"2026-07-27T09:02:04Z","timestamp":1785142924128,"version":"3.55.0"},"reference-count":26,"publisher":"Springer Science and Business Media LLC","issue":"7","license":[{"start":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T00:00:00Z","timestamp":1781481600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T00:00:00Z","timestamp":1781481600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Quantum Inf Process"],"DOI":"10.1007\/s11128-026-05245-7","type":"journal-article","created":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T04:32:20Z","timestamp":1781497940000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Quantum meet-in-the-middle attacks on key-length extension constructions"],"prefix":"10.1007","volume":"25","author":[{"given":"Min","family":"Liang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ruihao","family":"Gao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiali","family":"Wu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,15]]},"reference":[{"key":"5245_CR1","doi-asserted-by":"crossref","unstructured":"Dinur, I., Dunkelman, O., Keller, N., Shamir, A.: Efficient dissection of composite problems, with applications to cryptanalysis, knapsacks, and combinatorial search problems. In: Advances in Cryptology - CRYPTO 2012. LNCS, vol. 7417, pp. 719\u2013740. (2012)","DOI":"10.1007\/978-3-642-32009-5_42"},{"key":"5245_CR2","doi-asserted-by":"crossref","unstructured":"Ga\u017ei, P.: Plain versus Randomized Cascading-Based Key-Length Extension for Block Ciphers. In: Canetti, R., Garay, J.A. (eds.) Advances in Cryptology - CRYPTO 2013, Part I. LNCS, vol. 8042, pp. 551\u2013570. (2013)","DOI":"10.1007\/978-3-642-40041-4_30"},{"key":"5245_CR3","doi-asserted-by":"crossref","unstructured":"Lee, J.: Towards Key-Length Extension with Optimal Security: Cascade Encryption and Xor-cascade Encryption, In: T. Johansson and P. Nguyen (Eds.), EUROCRYPT 2013, LNCS 7881, pp. 405-425 (2013)","DOI":"10.1007\/978-3-642-38348-9_25"},{"key":"5245_CR4","doi-asserted-by":"crossref","unstructured":"Ga\u017ei, P., Lee, J., Seurin, Y., Steinberger, J., Tessaro, S.: Relaxing Full-Codebook Security: A Refined Analysis of Key-Length Extension Schemes, In: G. Leander (Ed.), FSE 2015, LNCS 9054, pp. 319-341 (2015)","DOI":"10.1007\/978-3-662-48116-5_16"},{"issue":"7","key":"5245_CR5","doi-asserted-by":"publisher","first-page":"465","DOI":"10.1145\/358699.358718","volume":"24","author":"RC Merkle","year":"1981","unstructured":"Merkle, R.C., Hellman, M.E.: On the security of multiple encryption. Commun. ACM 24(7), 465\u2013467 (1981)","journal-title":"Commun. ACM"},{"issue":"1","key":"5245_CR6","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1007\/s001450010015","volume":"14","author":"J Kilian","year":"2001","unstructured":"Kilian, J., Rogaway, P.: How to protect DES against exhaustive key search (an analysis of DESX). J. Cryptol. 14(1), 17\u201335 (2001)","journal-title":"J. Cryptol."},{"key":"5245_CR7","doi-asserted-by":"crossref","unstructured":"Bonnetain, X., Schrottenloher, A., Sibleyras, F.: Beyond quadratic speedups in quantum attacks on symmetric schemes. In: O. Dunkelman and S. Dziembowski (Eds.). EUROCRYPT 2022, LNCS 13277, pp. 315-344 (2022)","DOI":"10.1007\/978-3-031-07082-2_12"},{"key":"5245_CR8","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"161","DOI":"10.1007\/978-3-319-70697-9_6","volume-title":"ASIACRYPT 2017","author":"G Leander","year":"2017","unstructured":"Leander, G., May, A.: Grover meets simon - quantumly attacking the FX-construction. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017. LNCS, vol. 10625, pp. 161\u2013178. Springer, Cham (2017)"},{"key":"5245_CR9","doi-asserted-by":"crossref","unstructured":"Bonnetain, X., Hosoyamada, A., Naya-Plasencia, M., Sasaki, Y., Schrottenloher, A.: Quantum attacks without superposition queries: the offline Simon\u2019s algorithm. In: Galbraith, S.D., Moriai, S. (eds.) ASIACRYPT 2019, Part I. LNCS 11921, pp. 552\u2013583. Springer, Cham (2019)","DOI":"10.1007\/978-3-030-34578-5_20"},{"key":"5245_CR10","doi-asserted-by":"crossref","unstructured":"Zhandry, M.: How to construct quantum random functions. In: Proceedings of 2012 IEEE 53rd Annual Symposium on Foundations of Computer Science, pp. 679\u2013687. IEEE (2012)","DOI":"10.1109\/FOCS.2012.37"},{"issue":"6","key":"5245_CR11","first-page":"925","volume":"8","author":"M Liang","year":"2021","unstructured":"Liang, M., Luo, Y.Y., Liu, F.M.: A survey on quantum-secure symmetric cryptography. J. Cryptol. Res. 8(6), 925\u2013947 (2021)","journal-title":"J. Cryptol. Res."},{"key":"5245_CR12","doi-asserted-by":"publisher","first-page":"697","DOI":"10.1007\/s00145-015-9207-3","volume":"29","author":"I Dinur","year":"2016","unstructured":"Dinur, I., Dunkelman, O., Keller, N., Shamir, A.: Key recovery attacks on iterated even-mansour encryption schemes. J. Cryptol. 29, 697\u2013728 (2016)","journal-title":"J. Cryptol."},{"key":"5245_CR13","first-page":"74","volume":"10","author":"W Diffie","year":"1977","unstructured":"Diffie, W., Hellman, M.: Exhaustive cryptanalysis of the NBS data encryption standard. SIAM J. Comput. 10, 74\u201384 (1977)","journal-title":"SIAM J. Comput."},{"key":"5245_CR14","doi-asserted-by":"crossref","unstructured":"Jaeger, J., Song, F., Tessaro, S.: Quantum Key-Length Extension. In: K. Nissim and B. Waters (Eds.). TCC 2021, LNCS 13042, pp. 209-239 (2021)","DOI":"10.1007\/978-3-030-90459-3_8"},{"key":"5245_CR15","doi-asserted-by":"publisher","first-page":"321","DOI":"10.1007\/s11434-009-0532-5","volume":"55","author":"PC Zhong","year":"2010","unstructured":"Zhong, P.C., Bao, W.S.: Quantum mechanical meet-in-the-middle search algorithm for Triple-DES. Chin. Sci. Bull. 55, 321\u2013325 (2010)","journal-title":"Chin. Sci. Bull."},{"key":"5245_CR16","unstructured":"Kaplan, M.: Quantum attacks against iterated block ciphers, (2014). arXiv:1410.1434 arXiv preprint"},{"key":"5245_CR17","first-page":"1","volume":"11","author":"C Guo","year":"2024","unstructured":"Guo, C., Huang, A.J., Yu, Y.: Quantum Q1 security proof for the FX key-length extension construction. J. Cryptol. Res. 11, 1\u201313 (2024)","journal-title":"J. Cryptol. Res."},{"key":"5245_CR18","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1007\/978-3-642-29011-4_6","volume-title":"EUROCRYPT 2012","author":"P Ga\u017ei","year":"2012","unstructured":"Ga\u017ei, P., Tessaro, S.: Efficient and optimally secure key-length extension for block ciphers via randomized cascading. In: Pointcheval, D., Johansson, T. (eds.) EUROCRYPT 2012. LNCS, vol. 7237, pp. 63\u201380. Springer, Heidelberg (2012)"},{"key":"5245_CR19","doi-asserted-by":"crossref","unstructured":"Grover, L.K.: A fast quantum mechanics algorithm for database search. In: Proceeding of the 28th ACM Symposium on Theory of Computation, pp. 212\u2013219. ACM Press, New York (1996)","DOI":"10.1145\/237814.237866"},{"key":"5245_CR20","doi-asserted-by":"publisher","first-page":"2746","DOI":"10.1103\/PhysRevA.60.2746","volume":"60","author":"C Zalka","year":"1999","unstructured":"Zalka, C.: Grover\u2019s quantum searching algorithm is optimal. Phys. Rev. A 60, 2746 (1999)","journal-title":"Phys. Rev. A"},{"key":"5245_CR21","doi-asserted-by":"crossref","unstructured":"Zhang, S.: Promised and distributed quantum search. In: Proceedings of the Eleventh Annual International Conference on Computing and Combinatorics (COCOON \u201905). LNCS, vol. 3595, pp. 430\u2013439. (2005)","DOI":"10.1007\/11533719_44"},{"key":"5245_CR22","doi-asserted-by":"crossref","unstructured":"Tani, S.: An improved claw finding algorithm using quantum walk. In: L. Ku\u010dera and A. Ku\u010dera (Eds.). MFCS 2007, LNCS 4708, pp. 536-547 (2007)","DOI":"10.1007\/978-3-540-74456-6_48"},{"key":"5245_CR23","doi-asserted-by":"crossref","unstructured":"Jaques, S., Schanck, J. M.: Quantum Cryptanalysis in the RAM model: Claw-finding attacks on SIKE. In: A. Boldyreva and D. Micciancio (Eds.). CRYPTO 2019, LNCS 11692, pp. 32-61 (2019)","DOI":"10.1007\/978-3-030-26948-7_2"},{"key":"5245_CR24","doi-asserted-by":"crossref","unstructured":"Canteaut, A., Naya-Plasencia, M., Vayssiere, B.: Sieve-in-the-Middle: Improved MITM Attacks. In: R. Canetti and J.A. Garay (Eds.). CRYPTO 2013, Part I, LNCS 8042, pp. 222-240 (2013)","DOI":"10.1007\/978-3-642-40041-4_13"},{"key":"5245_CR25","doi-asserted-by":"crossref","unstructured":"Beyne, T., Chen, Y.L.: Provably Secure Reflection Ciphers. In: Dodis, Y., Shrimpton, T. (eds.) Advances in Cryptology- CRYPTO 2022. LNCS, vol. 13510, pp. 234\u2013263. (2022)","DOI":"10.1007\/978-3-031-15985-5_9"},{"key":"5245_CR26","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s00145-013-9164-7","volume":"28","author":"O Dunkelman","year":"2015","unstructured":"Dunkelman, O., Keller, N., Shamir, A.: Slidex attacks on the even-mansour encryption scheme. J. Cryptol. 28, 1\u201328 (2015)","journal-title":"J. Cryptol."}],"container-title":["Quantum Information Processing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11128-026-05245-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11128-026-05245-7","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11128-026-05245-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,27]],"date-time":"2026-07-27T08:11:26Z","timestamp":1785139886000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11128-026-05245-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,15]]},"references-count":26,"journal-issue":{"issue":"7","published-online":{"date-parts":[[2026,7]]}},"alternative-id":["5245"],"URL":"https:\/\/doi.org\/10.1007\/s11128-026-05245-7","relation":{},"ISSN":["1573-1332"],"issn-type":[{"value":"1573-1332","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,15]]},"assertion":[{"value":"31 May 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 June 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"15 June 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":1,"name":"Ethics","label":"Conflict of interest","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable.","order":2,"name":"Ethics","label":"Ethics approval and consent to participate","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable.","order":3,"name":"Ethics","label":"Consent for publication","group":{"name":"EthicsHeading","label":"Declarations"}}],"article-number":"219"}}