发表机构
Department of Computer Science, Virginia Tech(弗吉尼亚理工大学计算机科学系)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
通过构造经典预言机,证明存在EFI对但无单向谜题,利用通信复杂性归约和随机矩阵理论,显示量子优势缺失。
AI 中文摘要
EFI对(Brakerski、Canetti和Qian,ITCS 2023)和单向谜题(Khurana和Tomer,STOC 2024)是量子密码学最小假设的主要候选者。前者是可高效制备的量子态,统计上相距甚远但在计算上不可区分;后者是经典谜题,易于采样但难以求解。单向谜题蕴含EFI对,而逆命题是否成立仍是开放问题。我们构造了一个单一的经典预言机,相对于该预言机,即使验证者无界,单向谜题也不存在,而一个EFI对却能抵御所有在经典上查询预言机并携带关于预言机的建议、最后进行一次叠加查询的区分器。该预言机回答关于量子采样器输出概率的所有问题,从而消除了谜题,并隐藏了一个Haar随机的半维子空间。为了证明安全性,我们将其归约到通信复杂性。一个其子空间知识以经典查询答案形式到达的敌手,可以在一个两方协议中被模拟,以对抗持有该子空间的一方,因此无论预言机计算什么,其表现都不优于Vector-in-Subspace的最佳经典协议(Klartag和Regev,STOC 2011)。该论证不涵盖叠加查询,我们转而使用随机矩阵理论中的工具对其进行界定。同样的攻击给出了经典消息协议中任何量子方的经典模拟,且无需预先共享纠缠,因此相对于该预言机,也不存在量子性的证明。因此,量子多项式时间在具有经典输入和输出的任何任务上都不提供优势,而这两个量子态仍然不可区分。我们提出了关于消除叠加查询限制的猜想。
英文摘要
EFI pairs (Brakerski, Canetti, and Qian, ITCS 2023) and one-way puzzles (Khurana and Tomer, STOC 2024) are the leading candidates for the minimal assumption of quantum cryptography. The first are efficiently preparable quantum states, statistically far yet computationally indistinguishable; the second are classical puzzles, easy to sample and hard to solve. One-way puzzles imply EFI pairs, and whether the converse holds is open. We construct a single classical oracle relative to which one-way puzzles do not exist, even with an unbounded verifier, while an EFI pair survives every distinguisher that queries the oracle classically throughout and holds advice about it, making its one superposition query at the end. The oracle answers every question about the output probabilities of quantum samplers, which removes the puzzles, and hides a Haar-random half-dimensional subspace. To prove security we reduce it to communication complexity. An adversary whose knowledge of the subspace arrives as classical query answers can be simulated inside a two-party protocol against the party holding it, so it does no better than the best classical protocol for Vector-in-Subspace (Klartag and Regev, STOC 2011), whatever the oracle computes. That argument does not cover the superposition query, which we bound instead using tools from random matrix theory. The same attack gives a classical simulation of any quantum party in a classical-message protocol with no entanglement shared in advance, so relative to the oracle there is no proof of quantumness either. Quantum polynomial time therefore offers no advantage on any task with classical inputs and outputs, while the two quantum states stay indistinguishable. We state conjectures on removing the restriction on superposition queries.