针对有界对手的无密钥保密性
Keyless secrecy against bounded adversaries
- University of Ottawa(渥太华大学)
- École polytechnique, Institut Polytechnique de Paris(巴黎综合理工学院,巴黎理工学院)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
我们提出一种无密钥编码原语,在对手在线计算有界时同时保证接收方不被欺骗和消息保密,并构造了高效量子方案,解决了相关开放问题。
AI中文摘要:
我们引入一种无密钥编码/密码学原语,它同时要求两个保证:接收方永远不会被欺骗而接受除所发送消息之外的任何消息,并且除非接收方弃权(不执行),否则对手对消息一无所知。发送方和接收方都不持有秘密密钥,也不假设任何计算困难性。唯一的限制是对手的在线计算:如果到固定截止时间没有收到任何内容,接收方将弃权(不执行),因此对手必须在此之前转发某些内容,并且在该时间窗口内她的映射由规模(或深度)至多$p$的电路计算;在此之前和之后,她是无界的。对于每个多项式$p$,我们构造了这样一个高效的量子方案,将$k$比特消息编码为$n = O(k)$个量子比特,电路规模为$\mathrm{poly}(n,p)$。没有任何经典方案能在任何参数选择下实现这种类型的永久安全性。我们的技术还解决了针对以基数而非电路规模限制的家族的通用篡改检测的开放问题。我们解决了Broadbent、Kapshikar和Rochette关于放宽篡改检测的问题。作为推论,我们获得了第一个针对全局量子篡改的高效非延展性码,无需分裂态限制,而文献中当前的构造要求将码字分裂为不通信的份额。
英文摘要:
We introduce a keyless coding/cryptographic primitive that asks for two guarantees at once: the receiver is never fooled into accepting a message other than the one sent, and the adversary learns nothing about the message unless the receiver aborts. Neither the sender nor the receiver holds a secret key, and no computational hardness is assumed. The only restriction is on the adversary's online computation: the receiver aborts if nothing arrives by a fixed deadline, so the adversary must forward something before it, and her map in that window is computed by a circuit of size (or depth) at most $p$; before and after, she is unbounded. For every polynomial $p$ we construct such an efficient quantum scheme, encoding $k$-bit messages into $n = O(k)$ qubits with circuits of size $\mathrm{poly}(n,p)$. No classical scheme achieves this type of everlasting security, at any choice of parameters. Our techniques also resolve open questions about universal tamper detection against families restricted in cardinality rather than in circuit size. We settle a question of Broadbent, Kapshikar and Rochette on relaxed tamper detection. As a corollary, we obtain the first efficient non-malleable code secure against global quantum tampering, with no split-state restriction, whereas the current constructions in the literature require the codeword to be split into non-communicating shares.