Quantum security of sponges paper @PQCrypto18

Our paper on the quantum security of the sponge construction will be presented at PQCrypto 2018. We prove collision resistance and collapsing for the sponge construction under the assumption that the internal block function is a random one-way permutation or a random function. Sadly, this does not cover SHA3 as the block function in SHA3 is an invertible permutation. However, we are already working on new results to cover this case.