In this talk I will give a brief introduction about the security of various symmetric-key constructions against quantum attackers in two models: Q1 model and Q2 model. I’ll talk about the difference between those two models, why Q1 model is more realistic and some recent results about the post-quantum security of block ciphers in the Q1 model.
Reference: G. Alagic, C. Bai, J. Katz, C. Majenz, Post-Quantum Security of the Even-Mansour Cipher https://eprint.iacr.org/2021/1601.