ROM ⇒ Merkle puzzles
Statement
In the random oracle model, Merkle’s puzzles is a key-agreement protocol in which the honest parties make oracle queries, while any eavesdropper recovering the key with constant probability makes queries — Mer78.
Notes
- The quadratic gap is optimal: every random-oracle key agreement whose honest parties make queries falls to an eavesdropper making queries — BM09 (No reduction from ROM to KE).