Tight QROM security constant

Derive a tight quantum-random-oracle-model security constant for the transcript-bound hybrid combiner’s strongest-link security bound.

Background

The paper proves the strongest-link IND-CCA bound for the transcript-bound combiner in the classical random-oracle model. It gives only a qualitative argument for lifting the guarantee to the quantum random-oracle model, with the expected square-root degradation associated with Grover-style search.

The authors explicitly identify the derivation of a tight QROM constant as unresolved, so the precise quantitative security loss for the construction against quantum oracle queries remains to be established.

References

A tight QROM constant for the explicit bound is left to future work.

— Transcript-Bound Combiners for Downgrade-Resilient Hybrid Post-Quantum Key Establishment: Definition, Proof, and Embedded-Device Cost  (2609.21273 - Gupta et al., 18 Sep 2026) in Theorem 1 discussion, Section 5 (Security Analysis); also listed in the claim taxonomy in Section 6.1

Future work includes deriving a tight QROM constant for the transcript-bound combiner, extending the model to multi-session settings with session-state reveal, applying the principle to three-or-more component combiners for post-quantum agility, replacing the analytic energy model with power-instrumented single-board measurements, and integrating the combiner into a complete EDHOC extension evaluated against the existing cipher-suite negotiation.