Abstract:Double-block-length hash functions are a classical approach for amplifying the concrete security of hash functions. This construction has been proven to achieve optimal quantum collision resistance under certain conditions. However, whether double-block-length constructions can still achieve optimal concrete security in the stronger and more applicable quantum security model of the collapsing property remains an open question. To conduct a further study on this issue, this study considers the collapsing property, which extends the notion of collision resistance in the quantum setting. This study focuses on the collapsing security of Nandi’s double-block-length construction based on a random oracle. This study proposes that when the permutations $ \pi $ within the construction is composed completely of a number of c-cycle permutations (i.e., for any $ {x}\in{{\{0, 1\}}}^{{m}} $, $ \pi^{{a}}{(x) =x} $ if and only if $ {a=c} $), the collapsing security of this construction is optimal. Constructing a permutation $ \pi $ composed solely of c-cycle permutations is straightforward. Optimal collapsing security implies that when the output size of the random oracle is n bits, the adversary can effectively distinguish between the two states, measuring the hash value of a quantum superposition of messages and measuring the message superposition itself, only after making at least $ \text{O(}{{2}}^{{2n/3}}\text{)} $ queries. The proposed optimal construction can also be extended by the Merkle-Damg?rd construction. The extended hash function retains the collapsing property. Therefore, this study provides a theoretical foundation for the design of collapsing hash functions in the future.