Security when providing membership oracles for exponentially many subspaces
Establish the collision-resistance of the hash function H in the OSS construction when membership oracles are provided for the exponentially many subspaces S_{y,m}^⊥ associated with arbitrary orders of bit corrections (i.e., for all m in {0,1}^ℓ), or otherwise develop an analysis proving security under this richer oracle access.
Sponsor
References
One option would be to give out exponentially-many subspaces, corresponding to arbitrary orders of the bits, but we do not know how to analyze this or prove its security.
— Unclonable Cryptography in Linear Quantum Memory
(2511.04633 - Shmueli et al., 6 Nov 2025) in Overview of techniques, Parallel Signing