freenode
Security & Cryptography

SDitH and MQOM proofs flagged over ideal-cipher assumptions

A NIST PQC comment urges more conservative modeling of AES and Rijndael after related-key concerns.

Demi Marie Obenour has posted an official comment on NIST’s post-quantum cryptography forum questioning the security proofs for the Round 3 additional signature candidates SDitH and MQOM.

Both schemes rely on the ideal cipher model. Obenour argues that model is a poor fit for the ciphers actually chosen. AES-192 and AES-256 are known to be vulnerable to related-key attacks, and treating Rijndael-256 as free of such weaknesses is not a conservative stance, she wrote. The remark is explicitly precautionary and not tied to a concrete break.

She recommends tightening the proofs and possibly the designs so they rest on weaker assumptions about the underlying cipher, or spelling out exactly how AES or Rijndael is used. As an alternative construction detail, she suggests Rijndael-192 may be preferable to Rijndael-256 with a padded key and truncated output. Another path would be switching to a different symmetric primitive better matched to the ideal-cipher setting.

The comment lands while NIST is still evaluating additional signature schemes for eventual standardization, so modeling assumptions that affect concrete parameter choices remain material.