arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.03824quant-ph

量子随机预言机模型(QROM)中完美完备多轮密钥协商的不可能性

Impossibility of Perfectly Complete Many-Round Key Agreement in the QROM

Longcheng Li, Qian Li, Xingjian Li, Qipeng Liu

中文总结 AI 辅助

本文在QROM中证明,无法以黑箱方式从量子安全OWF构造完美完备多轮QKA协议,窃听者可通过$O((q_A+q_B)^5)$次经典查询恢复共享密钥,该界限与多参数无关,且优于此前仅适用于两轮或依赖猜想的结果。

中文摘要 AI 辅助

本文证明,在量子随机预言机模型(QROM)中,无法以黑箱方式从量子安全的单向函数(OWF)构造完美完备的量子密钥协商协议(QKA)。具体而言,考虑任意满足以下条件的协议:Alice和Bob仅交换经典消息,分别对布尔值随机预言机进行至多$q_{\text{A}}$和$q_{\text{B}}$次量子查询,且能以确定性方式协商出共享密钥。本文表明,存在一名窃听者,在获取经典消息后,可使用$O((q_{\text{A}}+q_{\text{B}})^5)$次经典预言机查询以确定性方式恢复共享密钥。该界限与轮数、传输记录长度、密钥长度及预言机域大小无关。此前的结果仅适用于两轮密钥协商(Li等人,CRYPTO 26),或依赖未证明的猜想(Austrin等人,CRYPTO 22)。GPT-5.6 Sol Ultra在一次对话中发现了该证明并起草了本文的初稿,作者对本文的正确性、撰写及讨论负全部责任。

英文摘要

This paper proves that it is impossible to construct perfectly complete quantum key agreement protocols (QKA) from quantumly secure one-way functions (OWFs) in a black-box manner. Specifically, consider any protocol in which Alice and Bob exchange only classical messages, make at most $q_{\mathsf{A}}$ and $q_{\mathsf{B}}$ quantum queries, respectively, to a Boolean-valued random oracle, and agree on a shared key with certainty. This paper shows that there exists an eavesdropper, given the classical messages, that can recover the shared key with certainty using $O((q_{\mathsf{A}}+q_{\mathsf{B}})^5)$ classical oracle queries. The bound is independent of the number of rounds, transcript length, key length, and oracle-domain size. Previous results only applies to two-round key agreement (Li et al. CRYPTO 26) or relies on unproven conjectures (Austrin et al. CRYPTO 22). GPT-5.6 Sol Ultra found this proof in a one-shot conversation and drafted a preliminary version of this paper. The authors are fully responsible for the correctness, writing and discussions of this paper.

补充信息

↑