发表机构
The Chinese University of Hong Kong, Shenzhen; International Quantum Academy; Nagoya University; Southern University of Science and Technology; Quantum Science Center of Guangdong-Hong Kong-Macao Greater Bay Area(香港中文大学(深圳); 国际量子科学院; 名古屋大学; 南方科技大学; 粤港澳大湾区量子科学中心)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出基于二次稳定子公钥态的信息论认证协议,证明在单签名暴露模型下,安全性等价于部分预测博弈,并揭示密钥重用率存在尖锐阈值,从而保证抗固定目标伪造的安全性。
AI 中文摘要
我们提出了一种基于信息论的认证协议,该协议利用有限供应的、定义在奇素数域上的二次稳定子公钥态。一个计算能力无界的对手观察到一条有效的经典签名,并可能联合处理$N$个公钥副本,而验证过程则使用一个额外的独立副本。我们证明,在暴露签名条件下,安全问题可归结为对$r=n-\ell$个剩余量子比特上的均匀稳定子系综的部分预测博弈,其中部分查询沿$d=\mathrm{rank}(Y-Y')$个方向进行,这里$n$是量子比特数,$\ell$是消息空间维度,$Y$和$Y'$分别表示诚实签名和目标伪造的消息。令人惊讶的是,尽管目标仅需要部分信息,但当$d/r\to\beta\in(0,1]$时,所需副本率并没有一阶降低。最优平均固定目标伪造概率在$N/r\to\alpha<1$时趋于零,在$\alpha>1$时趋于一,揭示了在$\alpha=1$处的尖锐阈值。因此,我们的结果保证了在单签名暴露模型下针对固定目标伪造的安全性。
英文摘要
We propose an information-theoretic authentication protocol based on a finite supply of long quadratic-stabilizer public-key states over an odd-prime field, where the effective key length after one signature exposure is the residual dimension $r=n-\ell$. A computationally unbounded adversary observes one valid classical signature and may jointly process $N$ public-key copies, while verification uses one additional independent copy. We show that, conditioned on the exposed signature, the security problem reduces to a partial-prediction game for a uniform stabilizer ensemble on these $r$ residual qudits, with a partial query along $d=\operatorname{rank}(Y-Y')$ directions, where $Y$ and $Y'$ denote the honestly signed and target-forged messages, respectively. Surprisingly, although the target requires only partial information, there is no first-order reduction in the required copy rate when $d/r\toβ\in(0,1]$. The optimal average forgery probability for the specified target tends to zero for $N/r\toα<1$ and to one for $α>1$, revealing a sharp threshold at $α=1$. Thus, long stabilizer public keys resist finite-copy forgery attacks under a single-signature-exposure model whenever the adversarial copy rate remains below one.
CommentsRevised the title, abstract, introduction, and related discussion to clarify the distinction from and division of roles with the paper arXiv:2609.13923. The technical results are unchanged