arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.29493quant-ph

量子悲观之地

Quantum Pessiland

Boyang Chen, Tomoyuki Morimae, Takashi Yamakawa

首次发表
浏览论文内容

中文总结 AI 辅助

本文证明存在量子预言机与经典预言机,对应量子悲观之地,其中NP平均困难却无量子/经典密码学,且无采样量子优势,还为开放问题给出部分否定答案。

中文摘要 AI 辅助

悲观之地(Pessiland)是这样一个世界:NP问题平均情形下困难,但不存在单向函数(OWFs)[Impagliazzo 1995]。由于几乎所有经典密码原语都隐含单向函数的存在[Impagliazzo和Luby 1989],悲观之地中几乎没有经典密码学。另一方面,即使不存在单向函数,量子密码学仍可存在[Kretschmer 2021;Morimae和Yamakawa 2022;Ananth、Qian和Yuen 2022]。那么是否存在量子版本的悲观之地,其中NP问题平均情形下困难,但即使量子密码学也不存在?本文证明,这样一个糟糕的世界——量子悲观之地(Quantum Pessiland)是存在的:存在一个量子预言机,相对于该预言机,UP∩coUP问题在带有量子建议的量子多项式时间算法面前平均情形下困难,但辅助输入EFI对不存在。我们还证明,存在一个经典预言机,相对于该预言机,UP∩coUP问题在带有量子建议的量子多项式时间算法面前平均情形下困难,但经典安全的辅助输入单向谜题(OWPuzzs)不存在。几乎所有量子密码原语都隐含EFI对或OWPuzzs的存在,因此这些结果意味着,相对于这些预言机,几乎没有量子密码学。我们进一步证明,相对于该经典预言机,SampBQP = SampBPP,因此量子悲观之地中不存在基于采样的量子优势。最后,由于我们得到的UP∩coUP平均情形下困难性隐含P^#P⊈this http URL,我们的结果还意味着,仅从P^#P⊈this http URL构造OWPuzzs需要非相对化证明技术,这对[Khurana和Tomer 2025]提出的开放问题给出了部分否定答案。

英文摘要

Pessiland is a world where NP is hard on average but one-way functions (OWFs) do not exist [Impagliazzo 1995]. Because almost all classical cryptographic primitives imply OWFs [Impagliazzo and Luby 1989], there is almost no classical cryptography in Pessiland. On the other hand, quantum cryptography can exist even when OWFs do not [Kretschmer 2021; Morimae and Yamakawa 2022; Ananth, Qian and Yuen 2022]. Is there a quantum analogue of Pessiland where NP is hard on average but even quantum cryptography does not exist? In this paper, we show that such a miserable world, Quantum Pessiland, exists: there is a quantum oracle relative to which $UP\cap coUP$ is hard on average against quantum polynomial-time algorithms with quantum advice, yet auxiliary-input EFI pairs do not exist. We also show that there is a classical oracle relative to which $UP\cap coUP$ is hard on average against quantum polynomial-time algorithms with quantum advice, yet classically-secure auxiliary-input one-way puzzles (OWPuzzs) do not exist. Almost all quantum cryptographic primitives imply EFI pairs or OWPuzzs, and therefore these results mean that there is almost no quantum cryptography relative to these oracles. We further show that relative to the classical oracle, SampBQP = SampBPP, and therefore there is no sampling-based quantum advantage in Quantum Pessiland. Finally, because our average-case hardness of $UP\cap coUP$ implies $P^{\#P}\not\subseteq i.o.BQP/qpoly$, our result also implies that a non-relativizing proof technique is necessary to construct OWPuzzs solely from $P^{\#P}\not\subseteq i.o.BQP/qpoly$, which gives a partial negative answer to the open problem of [Khurana and Tomer 2025].

发表机构

  • Tsinghua University(清华大学)
  • Kyoto University(京都大学)
  • NTT Social Informatics Laboratories(NTT社会信息学实验室)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑