Cryptology City

Cryptology City
Home

❯

Reductions

❯

ROM ⇒ Merkle puzzles

Oct 04, 2026

ROM ⇒ Merkle puzzles

Random oracle model · Mer78

Statement

In the random oracle model, Merkle’s puzzles is a key-agreement protocol in which the honest parties make O(n) oracle queries, while any eavesdropper recovering the key with constant probability makes Ω(n2) queries — Mer78.

Notes

  • The quadratic gap is optimal: every random-oracle key agreement whose honest parties make n queries falls to an eavesdropper making O(n2) queries — BM09 (No reduction from ROM to KE).

Graph View

  • ROM ⇒ Merkle puzzles
  • Statement
  • Notes

Backlinks

  • No reduction from ROM to KE
  • Random Oracle Model
  • Merkle puzzles

Created with Quartz v4.5.2 © 2026

  • GitHub
  • Bluesky