arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

在QROM中实现非完全密钥协商的不可能性研究

Towards the Impossibility of Imperfectly Complete Key Agreement in the QROM

Fuyuki Kitagawa, Ryo Nishimaki, Agi Villanyi, Takashi Yamakawa

arXiv 2608.17610首次发表:更新:

发表机构

NTT Social Informatics Laboratories; Massachusetts Institute of Technology(NTT社会信息学实验室; 麻省理工学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究在QROM中构造受限场景下量子密钥协商的无条件攻击,排除了特定条件下非完全正确量子公钥加密的存在性,推进了非完全密钥协商不可能性的研究。

AI 中文摘要

我们在量子计算、经典通信(QCCC)密钥协商的非完全不可能性研究方面取得进展,通过在以下受限场景中构造首个针对量子密钥协商的无条件攻击。在两消息场景中,假设Alice在第一轮仅对预言机进行经典查询,且她发给Bob的消息是经典的,除此之外双方均可执行任意量子计算、进行量子查询,并在第二轮发送量子态。我们的攻击与分析基于Austrin等人(CRYPTO 2022)的重查询学习技术,以及Katz和Sela(arXiv 2401.14319)的重编程技术。在轮独立场景中,我们证明Barak和Mahmoody(CRYPTO 2009;J. Cryptology 2017)的攻击可扩展至多轮,前提是Alice和Bob共享经典通信,且除最后一轮外仅进行经典查询。在两种场景中,攻击者计算能力无界,当每个诚实方的查询上限最多为poly(λ)且有效协商概率为逆多项式时,攻击者进行poly(λ)次查询即可恢复密钥。因此,我们在QROM中排除了针对长度为λ的多项式级经典消息的非完全正确量子公钥加密,前提是密钥生成具有经典预言机访问权限,即便加密、解密及密文均为量子的。特别地,当经典OSP发送方仅进行经典随机预言机查询时,1比特情况适用于Bartusek和Khurana(CRYPTO 2025)从两轮OSP得到的非完全正确PKE。

英文摘要

We make progress towards the impossibility of quantum-computation, classical-communication (QCCC) key agreement by giving the first unconditional polynomial-query attacks that tolerate imperfect completeness in the following settings. First, we give a quantum attack on protocols with arbitrarily many rounds in which both parties' oracle queries and communication are classical before the final round, while local computation may be quantum throughout, and the final round may involve quantum oracle queries and one quantum message. Second, we give a classical attack on constant-round QCCC protocols in which Alice has classical oracle access and Bob may make quantum queries throughout. In both settings, the attacker is computationally unbounded and makes $poly(λ)$ queries to recover the key with nonnegligible probability whenever each party's total honest query bound is at most $poly(λ)$ and the valid agreement probability is inverse-polynomial. As consequences, we rule out query-bounded IND-CPA security for quantum public-key encryption with classical public and secret keys and classical messages of polynomially bounded length in the QROM in either of two settings: (i) key generation has classical oracle access, while encryption, decryption, and the ciphertext may be quantum; or (ii) encryption has classical oracle access and ciphertexts are classical, while key generation and decryption may have quantum oracle access. Both results assume negligible correctness error and polynomial honest query complexity. Combining the constant-round attack with the constructions of Bartusek and Khurana (CRYPTO 2025), we also rule out constant-round oblivious state preparation with polynomial honest query complexity and negligible correctness error in the QROM against computationally unbounded quantum receivers making polynomially many oracle queries.

Comments75 pages, 2 figures, 2 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑