{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T01:39:40Z","timestamp":1760060380108,"version":"build-2065373602"},"reference-count":27,"publisher":"MDPI AG","issue":"9","license":[{"start":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T00:00:00Z","timestamp":1755907200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Open Fund of Advanced Cryptography and System Security Key Laboratory of Sichuan Province","award":["SKLACSS-202315","U23B2002","62272238","61902195","KYCX24_1233"],"award-info":[{"award-number":["SKLACSS-202315","U23B2002","62272238","61902195","KYCX24_1233"]}]},{"name":"National Natural Science Foundation of China","award":["SKLACSS-202315","U23B2002","62272238","61902195","KYCX24_1233"],"award-info":[{"award-number":["SKLACSS-202315","U23B2002","62272238","61902195","KYCX24_1233"]}]},{"name":"Postgraduate Innovation Training Program of Jiangsu Province","award":["SKLACSS-202315","U23B2002","62272238","61902195","KYCX24_1233"],"award-info":[{"award-number":["SKLACSS-202315","U23B2002","62272238","61902195","KYCX24_1233"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>COPA is a notable authenticated online cipher and was one of the winning proposals for the CAESAR competition. Current works describe how to break the existentially unforgeable under quantum chosen message attack (EUF-qCMA) of COPA. However, these works do not demonstrate the confidentiality of COPA in the quantum setting. This paper fills this gap, considers the indistinguishable under quantum chosen-plaintext attack (IND-qCPA) security for privacy, and presents the first IND-qCPA security analysis of COPA. In addition, in order to effectively avoid the problems of quantum existential forgery attack and quantum distinguishing attack, we introduce an intermediate state doubling-point technology into COPA, restrict the associated data non-emptiness, and present an enhanced variant, called COPA-ISDP, to support the IND-qCPA and EUF-qCMA security. Our work is of great significance, as it provides a simple and effective post-quantum secure design idea to resist Simon\u2019s attack.<\/jats:p>","DOI":"10.3390\/e27090890","type":"journal-article","created":{"date-parts":[[2025,8,25]],"date-time":"2025-08-25T00:10:36Z","timestamp":1756080636000},"page":"890","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Post-Quantum Security of COPA"],"prefix":"10.3390","volume":"27","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0647-0375","authenticated-orcid":false,"given":"Ping","family":"Zhang","sequence":"first","affiliation":[{"name":"School of Computer Science, Nanjing University of Posts and Telecommunications, Nanjing 210023, China"},{"name":"Advanced Cryptography and System Security Key Laboratory of Sichuan Province, Chengdu 610225, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yutao","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Computer Science, Nanjing University of Posts and Telecommunications, Nanjing 210023, China"},{"name":"Advanced Cryptography and System Security Key Laboratory of Sichuan Province, Chengdu 610225, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,8,23]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"1484","DOI":"10.1137\/S0097539795293172","article-title":"Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer","volume":"26","author":"Shor","year":"1997","journal-title":"SIAM J. Comput."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1474","DOI":"10.1137\/S0097539796298637","article-title":"On the Power of Quantum Computation","volume":"26","author":"Simon","year":"1997","journal-title":"SIAM J. Comput."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1161","DOI":"10.1007\/s10623-018-0510-5","article-title":"Using Bernstein-Vazirani algorithm to attack block ciphers","volume":"87","author":"Xie","year":"2019","journal-title":"Des. Codes Cryptogr."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"104605","DOI":"10.1016\/j.ic.2020.104605","article-title":"Revisiting Deutsch-Jozsa algorithm","volume":"275","author":"Qiu","year":"2020","journal-title":"Inf. Comput."},{"key":"ref_5","first-page":"161","article-title":"Grover Meets Simon\u2014Quantumly Attacking the FX-construction","volume":"Volume 10625","author":"Takagi","year":"2017","journal-title":"Proceedings of the Advances in Cryptology\u2014ASIACRYPT 2017\u201423rd International Conference on the Theory and Applications of Cryptology and Information Security"},{"key":"ref_6","first-page":"421","article-title":"Attacks on Beyond-Birthday-Bound MACs in the Quantum Setting","volume":"Volume 12841","author":"Cheon","year":"2021","journal-title":"Proceedings of the Post-Quantum Cryptography\u201412th International Workshop, PQCrypto 2021"},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"170","DOI":"10.1137\/S0097539703436345","article-title":"A Subexponential-Time Quantum Algorithm for the Dihedral Hidden Subgroup Problem","volume":"35","author":"Kuperberg","year":"2005","journal-title":"SIAM J. Comput."},{"key":"ref_8","first-page":"552","article-title":"Quantum Attacks Without Superposition Queries: The Offline Simon\u2019s Algorithm","volume":"Volume 11921","author":"Galbraith","year":"2019","journal-title":"Proceedings of the Advances in Cryptology\u2014ASIACRYPT 2019\u201425th International Conference on the Theory and Application of Cryptology and Information Security"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"102501:1","DOI":"10.1007\/s11432-017-9468-y","article-title":"Quantum key-recovery attack on Feistel structures","volume":"61","author":"Dong","year":"2018","journal-title":"Sci. China Inf. Sci."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"1179","DOI":"10.1007\/s10623-020-00741-y","article-title":"Quantum attacks on some feistel block ciphers","volume":"88","author":"Dong","year":"2020","journal-title":"Des. Codes Cryptogr."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"117","DOI":"10.1007\/s11128-021-03027-x","article-title":"Applications of Simon\u2019s algorithm in quantum attacks on Feistel variants","volume":"20","author":"Cui","year":"2021","journal-title":"Quantum Inf. Process."},{"key":"ref_12","first-page":"433","article-title":"Quantum Attacks Against Type-1 Generalized Feistel Ciphers and Applications to CAST-256","volume":"Volume 11898","author":"Hao","year":"2019","journal-title":"Proceedings of the Progress in Cryptology\u2014INDOCRYPT 2019\u201420th International Conference on Cryptology in India"},{"key":"ref_13","unstructured":"Alagic, G., Bai, C., Katz, J., and Majenz, C. (June, January 30). Post-quantum security of the Even-Mansour cipher. Proceedings of the Annual International Conference on the Theory and Applications of Cryptographic Techniques, Trondheim, Norway."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Alagic, G., Bai, C., Katz, J., Majenz, C., and Struck, P. (2024, January 26\u201330). Post-quantum Security of Tweakable Even-Mansour, and Applications. Proceedings of the Annual International Conference on the Theory and Applications of Cryptographic Techniques, Zurich, Switzerland.","DOI":"10.1007\/978-3-031-58716-0_11"},{"key":"ref_15","unstructured":"Bai, C., Esmaili, M., and Mantri, A. (2025). Quantum Security Analysis of the Key-Alternating Ciphers. IACR Cryptology ePrint Archive, 945."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"337","DOI":"10.46586\/tosc.v2021.i1.337-377","article-title":"Provably Quantum-Secure Tweakable Block Ciphers","volume":"2021","author":"Hosoyamada","year":"2021","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"207","DOI":"10.1007\/978-3-662-53008-5_8","article-title":"Breaking Symmetric Cryptosystems Using Quantum Period Finding","volume":"Volume 9815","author":"Robshaw","year":"2016","journal-title":"Proceedings of the Advances in Cryptology\u2014CRYPTO 2016\u201436th Annual International Cryptology Conference"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Bhaumik, R., Bonnetain, X., Chailloux, A., Leurent, G., Naya-Plasencia, M., Schrottenloher, A., and Seurin, Y. (2021, January 6\u201310). QCB: Efficient quantum-secure authenticated encryption. Proceedings of the Advances in Cryptology\u2013ASIACRYPT 2021: 27th International Conference on the Theory and Application of Cryptology and Information Security, Singapore. Proceedings, Part I 27.","DOI":"10.1007\/978-3-030-92062-3_23"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"379","DOI":"10.46586\/tosc.v2022.i2.379-414","article-title":"On the quantum security of OCB","volume":"2022","author":"Maram","year":"2022","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"ref_20","first-page":"195","article-title":"Quantum IND-CPA Security Notions for AEAD","volume":"Volume 15578","author":"Niederhagen","year":"2025","journal-title":"Proceedings of the Post-Quantum Cryptography\u201416th International Workshop, PQCrypto 2025"},{"key":"ref_21","unstructured":"Hosoyamada, A. (2025). Post-Quantum Security of Keyed Sponge-Based Constructions through a Modular Approach. IACR Cryptology ePrint Archive, 1059."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"79","DOI":"10.1007\/978-3-031-37679-5_4","article-title":"On the Post-quantum Security of Classical Authenticated Encryption Schemes","volume":"Volume 14064","author":"Mrabet","year":"2023","journal-title":"Proceedings of the Progress in Cryptology\u2014AFRICACRYPT 2023\u201414th International Conference on Cryptology in Africa"},{"key":"ref_23","first-page":"44","article-title":"Post-Quantum Security of the CBC, CFB, OFB, CTR, and XTS Modes of Operation","volume":"Volume 9606","author":"Takagi","year":"2016","journal-title":"Proceedings of the Post-Quantum Cryptography\u20147th International Workshop, PQCrypto 2016"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1007\/s11128-022-03774-5","article-title":"Quantum attacks against BBB secure PRFs or MACs built from public random permutations","volume":"22","author":"Nan","year":"2023","journal-title":"Quantum Inf. Process."},{"key":"ref_25","first-page":"424","article-title":"Parallelizable and Authenticated Online Ciphers","volume":"Volume 8269","author":"Sako","year":"2013","journal-title":"Proceedings of the Advances in Cryptology\u2014ASIACRYPT 2013\u201419th International Conference on the Theory and Application of Cryptology and Information Security"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"131","DOI":"10.1007\/s11128-021-03036-w","article-title":"Quantum forgery attacks on COPA, AES-COPA and marble authenticated encryption algorithms","volume":"20","author":"Xu","year":"2021","journal-title":"Quantum Inf. Process."},{"key":"ref_27","first-page":"557","article-title":"A note on the quantum collision and set equality problems","volume":"15","author":"Zhandry","year":"2015","journal-title":"Quantum Inf. Comput."}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/27\/9\/890\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T18:34:33Z","timestamp":1760034873000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/27\/9\/890"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,23]]},"references-count":27,"journal-issue":{"issue":"9","published-online":{"date-parts":[[2025,9]]}},"alternative-id":["e27090890"],"URL":"https:\/\/doi.org\/10.3390\/e27090890","relation":{},"ISSN":["1099-4300"],"issn-type":[{"type":"electronic","value":"1099-4300"}],"subject":[],"published":{"date-parts":[[2025,8,23]]}}}