发表机构
NTT Research; Carnegie Mellon University(NTT研究所; 卡内基梅隆大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究强化了相关挑战安全定义,证明其隐含先前SDE概念,构造了满足条件的相关UPO,首次实现了点函数等的plain模型复制保护,解决了相关开放问题。
AI 中文摘要
复制保护将一种功能编码为可重复使用的量子态,该量子态无法被拆分为两个同时保持可用性的状态(即“免费搭车者”敌手)。先前的plain-model(plain模型)结果仅处理独立采样的挑战;而与不可克隆比特、点函数复制保护相关的更自然的相同挑战概念仍未解决。我们强化了这些定义,并证明了新的更强概念在plain模型下的安全性。对于单解密器加密(SDE),我们定义了相关挑战安全性,证明其隐含所有先前的SDE概念(包括相同挑战安全性),并证明Kitagawa和Yamakawa(TCC'25)的构造在假设存在iO(不可区分混淆)和单向函数的情况下可实现该安全性。我们还几乎完全刻画了先前SDE概念之间的关系。对于一般功能,我们定义了相关挑战不可克隆可打孔混淆(UPO),允许挑战点、打孔比特以及拆分前后的辅助信息之间存在任意相关性,且仅要求每个点单独满足条件均匀比特和λ^c平均条件最小熵(因此,这些点可以是相同的)。在假设存在后量子iO和量子困难的LWE(学习误差)的情况下,我们为输入长度至少为λ^c的多项式大小密钥电路构造了相关UPO,回答了Ananth、Behera、Huang、Kitagawa、Yamakawa(EUROCRYPT'26)以及Cakan-Goyal(EUROCRYPT'26)提出的开放问题。我们还获得了针对点函数、k点函数和计算-比较程序的首个plain模型复制保护,以及针对一般可打孔功能的相同挑战复制保护。
英文摘要
A main application of quantum information in cryptography is copy-protection, where we encode a functionality (such as a decryption key or software) into a reusable quantum state so that it cannot be split into two adversaries (called freeloaders) that both remain useful. Previous works have only shown security for independently sampled challenges for the two adversaries. A competing natural security notion is identical-challenge security where the adversaries receive the same challenge. This notion has many real-life applications and connections to other fundamental primitives such as unclonable bits (i.e. unclonable encryption) and unclonable lockboxes (i.e. copy-protection of point functions). Despite its importance and numerous attempts, achieving identical-challenge security in the plain model has remained open. We first make progress on the definitional foundations of copy-protection by introducing natural copy-protection security definitions that imply the previous ones (including identical-challenge security) and better capture the security intuitions and real-life use cases; and we also characterize the relationship between the previous definitions. Then, we show how to achieve in the plain model our new stronger definitions for copy-protection of general classes of functionalities. In particular, we resolve the long-standing open questions of copy-protection of point functions, copy-protection of compute-and-compare programs, and identical-challenge secure copy-protection of decryption keys and all puncturable functionalities. Our technical core is a new decisional monogamy-of-entanglement result for coset states, which both allows us to achieve our new results, and also significantly simplifies and unifies unclonable cryptography proofs. We believe this will have further applications and may be of independent interest.