{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,14]],"date-time":"2026-02-14T05:52:59Z","timestamp":1771048379168,"version":"3.50.1"},"reference-count":18,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2025,11,24]],"date-time":"2025-11-24T00:00:00Z","timestamp":1763942400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Key Laboratory of Security Communication Foundation","award":["6142103042409"],"award-info":[{"award-number":["6142103042409"]}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"crossref","award":["3282025001"],"award-info":[{"award-number":["3282025001"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>We investigate the quantum security of nonce-based encryption under the indistinguishability against quantum chosen-plaintext attacks (IND-qCPA). While classical results establish that IV-based modes such as CBC, CFB, OFB, and CTR achieve IND-qCPA security, we demonstrate that simply replacing the random IV with a nonce undermines both classical and quantum security. To address this, we propose a general transformation from R-IND-qCPA security to N-IND-qCPA security and introduce enhanced variants, namely, CBC2, CFB2, OFB2, and CTR2, that are provably secure in the nonce-based quantum setting. We further show that nonce-based stream cipher encryption inherently satisfies N-IND-qCPA security. These results provide a systematic framework for upgrading IV-based constructions to secure nonce-based counterparts, thereby strengthening practical symmetric encryption against quantum adversaries.<\/jats:p>","DOI":"10.3390\/e27121194","type":"journal-article","created":{"date-parts":[[2025,11,25]],"date-time":"2025-11-25T08:50:20Z","timestamp":1764060620000},"page":"1194","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Quantum Security of Nonce-Based Encryption"],"prefix":"10.3390","volume":"27","author":[{"given":"Shuping","family":"Mao","sequence":"first","affiliation":[{"name":"Beijing Electronic Science & Technology Institute, Beijing 100070, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peng","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cryptology, University of Chinese Academy of Sciences, Beijing 100049, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yan","family":"Jia","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Cyberspace Security Defense, Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100085, China"},{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing 100049, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gang","family":"Liu","sequence":"additional","affiliation":[{"name":"National Key Laboratory of Security Communication, Chengdu 610041, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bing","family":"Liu","sequence":"additional","affiliation":[{"name":"Beijing Electronic Science & Technology Institute, Beijing 100070, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,11,24]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Grover, L.K. (1996, January 22\u201324). A Fast Quantum Mechanical Algorithm for Database Search. Proceedings of the Twenty-Eighth Annual ACM Symposium on the Theory of Computing, Philadelphia, PA, USA.","DOI":"10.1145\/237814.237866"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1474","DOI":"10.1137\/S0097539796298637","article-title":"On the Power of Quantum Computation","volume":"26","author":"Simon","year":"1997","journal-title":"SIAM J. Comput."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Kuwakado, H., and Morii, M. (2010, January 12\u201318). Quantum distinguisher between the 3-round Feistel cipher and the random permutation. Proceedings of the IEEE International Symposium on Information Theory, ISIT, Austin, TX, USA.","DOI":"10.1109\/ISIT.2010.5513654"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Mao, S., Guo, T., Wang, P., and Hu, L. (2022, January 28\u201330). Quantum Attacks on Lai-Massey Structure. Proceedings of the Post-Quantum Cryptography, PQCrypto 2022, Virtual.","DOI":"10.1007\/978-3-031-17234-2_11"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Ito, G., Hosoyamada, A., Matsumoto, R., Sasaki, Y., and Iwata, T. (2019, January 4\u20138). Quantum Chosen-Ciphertext Attacks Against Feistel Ciphers. Proceedings of the Topics in Cryptology\u2014CT-RSA 2019\u2014The Cryptographers\u2019 Track at the RSA Conference 2019, San Francisco, CA, USA.","DOI":"10.1007\/978-3-030-12612-4_20"},{"key":"ref_6","first-page":"561","article-title":"Study on block cipher structures against simon\u2019s quantum algorithm","volume":"6","author":"Luo","year":"2019","journal-title":"J. Cryptologic Res."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Kaplan, M., Leurent, G., Leverrier, A., and Naya-Plasencia, M. (2016, January 14\u201318). Breaking Symmetric Cryptosystems Using Quantum Period Finding. Proceedings of the Advances in Cryptology\u2014CRYPTO 2016, Santa Barbara, CA, USA.","DOI":"10.1007\/978-3-662-53008-5_8"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Bhaumik, R., Bonnetain, X., Chailloux, A., Leurent, G., Naya-Plasencia, M., Schrottenloher, A., and Seurin, Y. (2021, January 6\u201310). QCB: Efficient Quantum-Secure Authenticated Encryption. Proceedings of the Advances in Cryptology\u2014ASIACRYPT 2021, Singapore.","DOI":"10.1007\/978-3-030-92062-3_23"},{"key":"ref_9","first-page":"422","article-title":"Quantum Linearization Attacks","volume":"Volume 13090","author":"Tibouchi","year":"2021","journal-title":"Proceedings of the Advances in Cryptology\u2014ASIACRYPT 2021\u201427th International Conference on the Theory and Application of Cryptology and Information Security, Singapore, 6\u201310 December 2021, Proceedings, Part I"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"379","DOI":"10.46586\/tosc.v2022.i2.379-414","article-title":"On the Quantum Security of OCB","volume":"2022","author":"Maram","year":"2022","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Boneh, D., and Zhandry, M. (2013, January 18\u201322). Secure Signatures and Chosen Ciphertext Security in a Quantum Computing World. Proceedings of the Advances in Cryptology\u2014CRYPTO 2013, Santa Barbara, CA, USA.","DOI":"10.1007\/978-3-642-40084-1_21"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Anand, M.V., Targhi, E.E., Tabia, G.N., and Unruh, D. (2016, January 24\u201326). Post-Quantum Security of the CBC, CFB, OFB, CTR, and XTS Modes of Operation. Proceedings of the Post-Quantum Cryptography, PQCrypto 2016, Fukuoka, Japan.","DOI":"10.1007\/978-3-319-29360-8_4"},{"key":"ref_13","unstructured":"Lang, N., Leuther, J., and Lucks, S. (2025, October 03). Generic Composition: From Classical to Quantum Security. Cryptology ePrint Archive, Paper 2025\/387. Available online: https:\/\/eprint.iacr.org\/2025\/387."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"194711","DOI":"10.1109\/ACCESS.2024.3520364","article-title":"A Survey on the Quantum Security of Block Cipher-Based Cryptography","volume":"12","author":"Bootsma","year":"2024","journal-title":"IEEE Access"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"4453","DOI":"10.1007\/s10623-024-01506-7","article-title":"A quantum-secure partial parallel MAC QPCBC","volume":"92","author":"Mao","year":"2024","journal-title":"Des. Codes Cryptogr."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"2807","DOI":"10.1109\/JIOT.2024.3481033","article-title":"Lightweight Yet Nonce-Misuse Secure Authenticated Encryption for Very Short Inputs","volume":"12","author":"Adomnicai","year":"2025","journal-title":"IEEE Internet Things J."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"57834","DOI":"10.1109\/ACCESS.2025.3554602","article-title":"A Review of Block Ciphers and Its Post-Quantum Considerations","volume":"13","author":"Chethana","year":"2025","journal-title":"IEEE Access"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Rogaway, P. (2004, January 14\u201316). Nonce-Based Symmetric Encryption. Proceedings of the Fast Software Encryption, FSE 2004, Graz, Austria.","DOI":"10.1007\/978-3-540-25937-4_22"}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/27\/12\/1194\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,26]],"date-time":"2025-11-26T05:25:26Z","timestamp":1764134726000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/27\/12\/1194"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,24]]},"references-count":18,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["e27121194"],"URL":"https:\/\/doi.org\/10.3390\/e27121194","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,24]]}}}