发表机构
IBM India, IBM CIO(印度IBM,首席信息官办公室)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文证明群环单位求逆的难度由矩阵块维度而非交换性决定,并给出多项式时间算法及量子电路,在二面体群下可破解相关公钥方案。
AI 中文摘要
若干公钥方案的安全性基于“求群环中一个单位的逆是困难的”这一信念。最近的一项结果表明,当群是阿贝尔群时,这一信念在量子计算机上是错误的。为了恢复安全性,设计者转向非阿贝尔群,尤其是二面体群,认为二面体隐藏子群问题(HSP)的难度会保护该方案。本文表明,单位求逆是一个不同的问题,不需要求解HSP。相反,它可以通过一种基变换来解决,该变换将群环分解为小的矩阵块。我们证明,当存在高效的广义傅里叶变换、群环是半单的且最大矩阵块具有多项式大小时,单位求逆在经典和量子计算上都是多项式时间的。二面体群环满足这些条件,因为其不可约表示的维数至多为2,并且存在高效的傅里叶变换。我们给出了块求逆步骤的显式可逆量子电路,并在寄存器级模拟器中进行了验证。我们还确定了该方法失效的确切结构边界,并在一个新的、明确陈述的安全假设下,在幸存区域提出一个候选构造。建设性结果由可复现的软件工件和实验支持。
英文摘要
Several public-key schemes base their security on the belief that inverting a unit of a group ring is hard. A recent result showed that this belief is false on a quantum computer when the group is abelian. To restore security, designers moved to non-abelian groups, especially dihedral groups, believing that the hardness of the dihedral hidden subgroup problem (HSP) would protect the scheme. This paper shows that unit inversion is a different problem and does not require an HSP solver. Instead, it can be solved by a change of basis that splits the group ring into small matrix blocks. We prove that unit inversion is polynomial-time, classically and quantumly, when an efficient generalized Fourier transform exists, the group ring is semisimple, and the largest matrix block has polynomial size. Dihedral group rings satisfy these conditions because their irreducible representations have dimension at most 2 and an efficient Fourier transform exists. We give an explicit reversible quantum circuit for the block-inversion step and validate it in a register-level simulator. We also identify the exact structural boundary where the method stops and propose a candidate construction in the surviving regime under a new, clearly stated security assumption. The constructive results are supported by reproducible software artifacts and experiments.
Comments29 pages, 7 tables, 5 figures