Papers
Topics
Authors
Recent
Search
2000 character limit reached

What is the Random Oracle Model?

Updated 4 October 2026
  • The Random Oracle Model (ROM) is a publicly accessible, random function where distinct inputs yield independent outputs, and repeated queries return consistent responses;two alternative versions include the Quantum Random Oracle Model (QROM) for quantum queries and the Quantum Haar Random Oracle Model (QHROM).
  • The ROM is crucial for proving black-box key agreements. Simplifying the process increases query complexity investments up to a factor of order two exits due to the combinatorial properties that have been characterized. Additionally, the ROM has significant application in instantiating cryptographic constructions like digital signatures. Security in the ROM does not immediately transfer to arbitrary hash functions.
  • In cryptographic implementations targeted to be resistant against adversaries, the ROM yields limits on the query complexity of key agreement protocols and identifies optimal structures for secure hash function properties.

The Random Oracle Model (ROM) is an idealized cryptographic model in which a publicly accessible function is sampled at random and then fixed. For distinct inputs, its outputs are independent; repeated queries to the same input return the same value. Algorithms and adversaries access the function only through oracle queries rather than through an explicit description. In its classical form, the ROM abstracts black-box access to a symmetric primitive such as a hash function. Its quantum variants distinguish between classical random functions queried in superposition (the QROM), Haar-random unitaries and their inverses (the QHROM), and restricted interfaces such as the classically accessible random-oracle model (CAROM). The model supports security proofs, impossibility results, query-complexity lower bounds, and idealized constructions, but security in the ROM does not automatically transfer to an arbitrary concrete hash function.

1. Definition and formal structure

A random oracle is a random function whose values at distinct inputs are independent. A general formulation is

H:{0,1}∗→{0,1}∗.H:\{0,1\}^*\to\{0,1\}^*.

The output distribution need not be uniform or length-preserving; independence across distinct inputs is the essential property. For a finite partial function FF, the probability that HH is consistent with FF is

Pr⁡H[F]=∏(x,y)∈FPr⁡[H(x)=y].\Pr_H[F] =\prod_{(x,y)\in F}\Pr[H(x)=y].

Consequently, an answer at a previously unqueried input is fresh independent randomness, while a repeated query returns the value already associated with that input. A simulator commonly implements this behavior by lazy sampling: it assigns a fresh value to a new input, stores the pair, and returns the stored value on subsequent queries.

The oracle is public. Honest parties, adversaries, and reductions may query the same function. In information-theoretic analyses, the relevant resource is often the number of oracle queries rather than ordinary running time. An adversary may be computationally unbounded between queries, so a query bound can express a stronger restriction than polynomial-time computation.

The ROM is frequently parameterized by a security parameter. For each parameter nn, one may sample a finite random function HnH_n uniformly from a set Hashn\mathrm{Hash}_n. Security in the ROM averages over the choice of HnH_n, as well as the randomness of the scheme and adversary. Security relative to a fixed instantiation HH instead holds the function sequence fixed and averages only over algorithmic randomness.

The distinction between these two statements is fundamental. A ROM proof establishes an average property over random functions; it does not, by itself, identify a practical efficiently computable function preserving that property. Algorithmic-randomness work shows that, under effective security conditions, a scheme-specific computable instantiation can exist, while also emphasizing that the resulting function need not be polynomial-time computable or practically usable (Tadaki et al., 2013).

2. Query complexity and black-box impossibility

The ROM is particularly important for black-box key agreement. Alice and Bob share the public oracle but possess no pre-shared secret. Their hidden correlation must therefore arise from oracle information that they both learn while Eve does not.

For a two-party protocol, the honest parties use private randomness, exchange a public transcript, query the oracle, and output keys. If Alice and Bob make at most FF0 and FF1 oracle queries and agree with probability at least FF2, then a deterministic eavesdropper can make at most

FF3

queries and predict Bob’s output with probability at least FF4, for every FF5. In the symmetric case FF6, this is FF7, or FF8 for constant FF9. The result applies to arbitrary interactive protocols; the number of communication rounds is not the parameter controlling the attack (0801.3669).

The attack maintains the public transcript, learned oracle-answer pairs, and a conditional distribution of possible honest views. It repeatedly queries heavy oracle points: points having sufficiently high conditional probability of appearing in Alice’s or Bob’s possible query sets. A bipartite compatibility graph represents possible Alice and Bob views, with an edge precisely when their unknown query sets are disjoint. Once sufficiently heavy shared dependencies have been exposed, this graph is dense, and the conditional views are close to independent. Eve can then sample a possible Alice view and use its key as a prediction of Bob’s key.

The result improves the earlier approximately HH0-query attack of Impagliazzo and Rudich and establishes that Merkle’s quadratic gap is optimal up to constants. The one-round setting admits an independent theorem for random permutation oracles: if Alice and Bob make at most HH1 and HH2 queries, Eve can break the protocol with HH3 queries and constant probability. The proof repeatedly simulates Bob, thereby finding common queries, and then reconstructs Alice’s later behavior (0801.4714).

Merkle’s construction supplies the matching lower bound. Alice and Bob query random points in a domain of size HH4, exchange the corresponding oracle values, and use a common preimage as the key. Each honest party makes HH5 queries, while Eve must search a domain of size HH6. Thus the achievable asymptotic separation is

HH7

The communication cost of this gap is also constrained. For uniform-query protocols, obtaining secrecy against HH8-query adversaries requires HH9 communication. More quantitatively,

FF0

For two-message non-adaptive protocols with arbitrary query distributions,

FF1

which becomes FF2 when FF3 (Haitner et al., 2021).

3. Heavy queries, intersections, and weakened models

The key combinatorial resource in ROM key agreement is the intersection of the honest query sets. If FF4 and FF5 are Alice’s and Bob’s query sets, then

FF6

contains oracle points whose answers may be shared by both parties. Eve’s strategy is to identify those points without querying every possible honest execution.

The heavy-query analysis distinguishes ordinary conditional views from views conditioned on Eve not having missed an intersection query. This conditioning creates dependence between Alice’s and Bob’s views, and treating them as independent is invalid. The compatibility-graph method explicitly represents this dependence and proves approximate product structure after heavy queries have been exposed.

This methodology also appears in communication lower bounds. In a two-round non-adaptive protocol, Eve queries points whose probability conditioned on the transcript exceeds a threshold FF7. Since the honest parties make at most FF8 queries, each set of heavy points has size at most FF9. Choosing Pr⁡H[F]=∏(x,y)∈FPr⁡[H(x)=y].\Pr_H[F] =\prod_{(x,y)\in F}\Pr[H(x)=y].0 keeps Eve within a Pr⁡H[F]=∏(x,y)∈FPr⁡[H(x)=y].\Pr_H[F] =\prod_{(x,y)\in F}\Pr[H(x)=y].1-query budget. If the transcript contains insufficient information about the unqueried intersection, Eve can sample a plausible honest view and approximate the shared key.

The standard ROM can be refined by exposing selected weaknesses of the ideal function. Weakened random-oracle models (WROMs) retain the random oracle and add an auxiliary oracle that provides collisions, second preimages, first preimages, or prefix-sensitive variants. The collision-tractable ROM, second-preimage-tractable ROM, and first-preimage-tractable ROM expose these corresponding capabilities. Prefix-sensitive variants include common chosen-prefix collision, chosen-prefix collision, chosen-prefix second-preimage, and chosen-prefix first-preimage models (Tezuka et al., 2021).

These models isolate which hash-function property a proof actually requires. RSA-FDH, RSASSA-PKCS-v1.5, and the simplified DSA construction transfer signatures across hash collisions and are therefore vulnerable when collision or prefix-collision oracles are available. RSA-PFDH uses signer-selected randomness and can remain secure against some chosen-prefix collision capabilities, but it is vulnerable to a chosen-prefix second-preimage oracle invoked after the signer’s randomness is known. RSA-FDHPr⁡H[F]=∏(x,y)∈FPr⁡[H(x)=y].\Pr_H[F] =\prod_{(x,y)\in F}\Pr[H(x)=y].2 is presented as a transformation robust against the considered prefix-sensitive models.

4. Applications and constructions

The ROM has been used to analyze signatures, encryption, key agreement, memory-hard functions, and quantum protocols.

Fiat–Shamir-style signatures commonly model the challenge hash as a random oracle. A lattice-based ring-signature construction uses

Pr⁡H[F]=∏(x,y)∈FPr⁡[H(x)=y].\Pr_H[F] =\prod_{(x,y)\in F}\Pr[H(x)=y].3

where Pr⁡H[F]=∏(x,y)∈FPr⁡[H(x)=y].\Pr_H[F] =\prod_{(x,y)\in F}\Pr[H(x)=y].4 is a set of short challenge vectors. The proof programs Pr⁡H[F]=∏(x,y)∈FPr⁡[H(x)=y].\Pr_H[F] =\prod_{(x,y)\in F}\Pr[H(x)=y].5 at selected inputs, uses rejection sampling to make the secret-dependent response statistically close to a Gaussian sample, and applies forking to obtain an SIS solution from two valid transcripts (Wang et al., 2014). Such proofs remain ROM proofs; replacing Pr⁡H[F]=∏(x,y)∈FPr⁡[H(x)=y].\Pr_H[F] =\prod_{(x,y)\in F}\Pr[H(x)=y].6 by a concrete hash function requires a separate justification.

The ROM also supports generic memory-hardness analyses. EGSample is a data-dependent memory-hard function analyzed in the Parallel Random Oracle Model (PROM). Its guarantee is that a successful evaluator either sustains

Pr⁡H[F]=∏(x,y)∈FPr⁡[H(x)=y].\Pr_H[F] =\prod_{(x,y)\in F}\Pr[H(x)=y].7

bits of memory for Pr⁡H[F]=∏(x,y)∈FPr⁡[H(x)=y].\Pr_H[F] =\prod_{(x,y)\in F}\Pr[H(x)=y].8 oracle rounds or incurs cumulative memory cost

Pr⁡H[F]=∏(x,y)∈FPr⁡[H(x)=y].\Pr_H[F] =\prod_{(x,y)\in F}\Pr[H(x)=y].9

for every constant nn0, with high probability under the stated parameter conditions. The construction combines fractional depth robustness, ancestral robustness, Grates, DRSample graphs, and indegree reduction. Its dynamic-pebbling analysis gives the stronger-looking alternative nn1, but the direct PROM theorem is needed because an ex-post-facto graph can reveal dependencies unavailable to an online evaluator (Blocki et al., 9 Aug 2025).

In the quantum setting, the ROM is divided according to oracle access. The QROM retains a classical random function but permits quantum queries through

nn2

A quantum query can therefore act on a superposition of inputs. Classical ROM security does not imply QROM security: a collision-finding protocol can be classically secure against bounded birthday attacks but quantumly insecure because collision search requires only nn3 oracle evaluations in the relevant construction. History-free reductions provide one class of classical proofs that can transfer to the QROM (Boneh et al., 2010).

QROM techniques also support online extraction. The compressed-oracle method stores a quantum representation of the oracle’s query history. A commutator bound between the compressed-oracle query operation and an extraction measurement is

nn4

This permits straightline, on-the-fly extraction when a quantum adversary outputs a value related to an oracle response. Applications include commit-and-open protocols and the textbook Fujisaki–Okamoto transformation (Don et al., 2021).

Other QROM applications include non-interactive delegation of quantum computation using reversible garbled circuits and quantum KDM security (Zhang, 2018), succinct blind quantum computation with a classical online client (Zhang, 2020), and certified randomness without computational assumptions beyond the ideal oracle. The latter uses biased-oracle reprogramming, query-norm bounds, and list recovery to certify nn5 min-entropy against adversaries making nn6 adaptive quantum queries for nn7 (Coladangelo et al., 31 Aug 2026).

5. Quantum oracle variants

The QROM is not the only quantum extension. A random function may remain classical while the interface becomes quantum, or the oracle itself may be a random quantum operation.

In the QROM, adversaries query a classical random function coherently. The central technical issues are the recording barrier, quantum reprogramming, and the impossibility of treating queries as a classical transcript. In CAROM, by contrast, adversaries may perform arbitrary quantum computation and maintain arbitrary quantum memory, but every random-oracle input is classical and every response is classical. This restriction supports an information-theoretic one-time memory construction based on BB84 states. For a message length nn8, the construction uses nn9 qubits and HnH_n0 classical bits, with simulation advantage at most

HnH_n1

when the adversary makes at most HnH_n2 classical oracle queries (Chen et al., 26 Sep 2026).

The quantum Haar random oracle model (QHROM) replaces the random function by a shared Haar-random unitary HnH_n3. Depending on the model, parties may access HnH_n4, HnH_n5, HnH_n6, and HnH_n7. Path-recording formalisms provide a quantum analogue of lazy sampling by recording input-output relations in purifying registers.

In the inverseless QHROM, two sequential calls suffice for an unbounded-query pseudorandom unitary:

HnH_n8

One-call constructions cannot provide unbounded-query security, although one-call bounded-query constructions and one-call multi-copy pseudorandom states exist (Ananth et al., 2024). In the full QHROM, including inverse access, strong pseudorandom unitaries are constructed using

HnH_n9

with three Hashn\mathrm{Hash}_n0-bit key blocks and two sequential calls to Hashn\mathrm{Hash}_n1. The outer masks prevent inverse-query cancellations and are essential for strong security (Ananth et al., 29 Sep 2025).

The QHROM also supports reusable unclonable encryption with arbitrary polynomial-length messages, even when all parties access Hashn\mathrm{Hash}_n2. A unitary reprogramming lemma shows that a polynomial-query adversary cannot distinguish a Haar unitary from a product of independent Haar unitaries on a sufficiently small hidden subspace. This yields reusable unclonable encryption relative to the Haar oracle and a relativized setting in which reusable unclonable encryption exists while one-way functions do not (Bartusek et al., 12 Mar 2026).

Quantum time-lock puzzles provide another separation from the classical ROM. Classical puzzles are copyable and can be searched in parallel; a quantum puzzle can be a single-copy state built from hidden-basis BB84 states. The resulting construction uses one oracle round for generation, at most Hashn\mathrm{Hash}_n3 sequential oracle rounds for solving, and is secure against polynomial-width adversaries of depth Hashn\mathrm{Hash}_n4 (Ananth et al., 30 Sep 2026).

6. Instantiation, indifferentiability, and limitations

A central limitation of the ROM is that an ideal random function is not an efficiently computable hash function. Replacing it by SHA-2, SHA-3, AES, or another concrete primitive is generally heuristic unless a reduction establishes that the construction is secure for the relevant property of the concrete primitive.

The secure-instantiation problem can be studied through algorithmic randomness. For a fixed ROM-secure signature scheme, the set of oracle sequences that cause infinitely many effective attacks forms an effective measure-zero set. Every Martin-Löf-random oracle preserves the relevant security, and under effective ROM security there exists a computable, scheme-specific oracle preserving security. This does not imply that the oracle is efficiently computable, compact, universal across schemes, or suitable as a practical hash function (Tadaki et al., 2013).

Indifferentiability provides a stronger framework for comparing ideal models. Ordinary indistinguishability of a construction from a random oracle is insufficient when an adversary also queries the underlying primitive. The construction must remain indistinguishable together with a simulator for that underlying interface. In this framework, a fourteen-round Feistel network with independent public random functions is indifferentiable from a random permutation. The result establishes an information-theoretic, black-box relationship between the ROM and the ideal cipher model, while leaving open whether fewer than fourteen rounds suffice and emphasizing that a flawed six-round proof does not establish impossibility (Holenstein et al., 2010).

Several recurring misconceptions should therefore be avoided:

  • ROM security is not standard-model security: a proof in the ideal model does not establish security for every concrete hash function.
  • The ROM and QROM are not interchangeable: coherent quantum queries can invalidate classical reductions.
  • A random permutation is not automatically a random function: permutation outputs are correlated, and proofs must account for this structure.
  • Query complexity is not ordinary time: many ROM impossibility results permit unbounded computation between oracle queries.
  • More rounds do not necessarily improve ROM key-agreement security: the quadratic attack applies to arbitrary interactive structure in the general theorem.
  • Quantum access is part of the security model: classical-access security, QROM security, CAROM security, and QHROM security make different claims.
  • Oracle-relative results do not imply concrete realizations: instantiation requires an additional computational, statistical, or heuristic argument.

The ROM remains useful precisely because it separates black-box information-theoretic behavior from assumptions about the internal structure of concrete primitives. Its strongest results are therefore often negative or conditional: quadratic limits on key agreement, explicit identification of necessary hash properties, precise distinctions between classical and quantum access, and idealized constructions whose validity depends on the oracle interface being modeled.

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Random Oracle Model.