arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.25195quant-ph

将量子不可区分混淆(qIO)与可证伪假设分离

Separating Quantum Indistinguishability Obfuscation from Falsifiable Assumptions

Mohammed Barhoush, Tomoyuki Morimae, Ramis Movassagh

AI总结:

该研究通过受限量子黑盒归约,证明针对QMA的WE无法基于可证伪密码学假设,进而分离零-qIO与可证伪假设,为构造qIO设置了障碍。

AI中文摘要:

量子不可区分混淆(qIO)旨在使量子电路在保留其功能的同时变得不可理解,它是高级应用的基础原语,例如针对QMA的见证加密(WE)、针对QMA的非交互零知识论证以及针对BQP的属性基加密。尽管qIO至关重要,但从标准假设出发构造qIO仍是一个重大开放性问题。在这项工作中,我们通过一类受限的量子黑盒归约证明,针对QMA的WE的安全性无法基于任何可证伪密码学假设。由于针对零量子电路的qIO隐含着针对QMA的WE,这也将零-qIO与可证伪假设分离开来。由于几乎所有标准密码学假设都是可证伪的,我们的结果为基于标准密码学假设构造qIO设置了障碍。我们排除的归约是受限的:归约必须以经典方式、非自适应地查询敌手,使用相同的安全参数,且仅针对诚实生成的密文进行查询。此外,我们的不可能性结果仅适用于具有经典密文的WE,因此并不排除其混淆器输出为量子态的qIO。排除更一般的归约以及更一般形式的WE和qIO仍是开放性问题。我们的不可能性结果依赖于QMA-QCIP[2]间隙问题的存在,这是一个平均情况假设,假定存在一种无法通过两条经典通信消息验证的QMA语言。

英文摘要:

Quantum indistinguishability obfuscation (qIO) aims to make a quantum circuit unintelligible while preserving its functionality. It serves as a foundational primitive for advanced applications, such as witness encryption (WE) for QMA, non-interactive zero-knowledge arguments for QMA, and attribute-based encryption for BQP. Despite its importance, constructing qIO from standard assumptions remains a major open problem. In this work, we prove that the security of WE for QMA cannot be based on any falsifiable cryptographic assumption via a restricted class of quantum black-box reductions. Because qIO for null quantum circuits implies WE for QMA, this also separates null-qIO from falsifiable assumptions. Since almost all standard cryptographic assumptions are falsifiable, our result presents a barrier to basing qIO on standard cryptographic assumptions. The reductions we rule out are restricted: the reduction must query the adversary classically, non-adaptively, at the same security parameter, and only on honestly generated ciphertexts. Moreover, our impossibility applies only to WE with classical ciphertexts, and therefore does not rule out qIO with obfuscators whose output is a quantum state. Ruling out more general reductions, as well as more general forms of WE and qIO, remains open. Our impossibility relies on the existence of a QMA-QCIP[2] gap problem, an average-case assumption postulating a QMA language that cannot be verified with two messages of classical communication.

补充信息

↑