发表机构
Telecom Paris, Institut Polytechnique de Paris; Beijing University of Posts and Telecommunications; Beijing Institute of Technology(巴黎理工学院电信学院; 北京邮电大学; 北京理工大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文形式化量子性的零知识证明,防止恶意经典验证者利用量子优势,通过验证者端可提取非交互式零知识论证,将现有方案转化为增强安全概念。
AI 中文摘要
随着量子计算机的快速发展,量子性证明最近成为一个有趣的研究方向。然而,在当前的量子性证明方案中,量子证明者面临被经典验证者恶意利用的风险。通过与量子证明者的交互中的恶意策略,经典验证者可以解决特定方案中出现的某些困难问题的实例。这是由于缺乏形式化机制来防止恶意验证者在量子性证明中提取有用信息。为了解决这个问题,我们形式化了量子性的零知识证明。直观地说,零知识性质要求经典验证者从与量子证明者的交互中获得的信息不应超过使用模拟的经典证明者与同一验证者交互所能模拟的信息。因此,新的零知识概念可以防止恶意验证者利用量子优势。我们发现,经典的零知识证明足以将一些现有的量子性证明方案编译成量子性的零知识证明方案。在验证者端而非证明者端要求零知识证明似乎更为普遍。这有助于将验证者的行为从恶意规范为诚实但好奇。因此,双方在量子性证明中不仅扮演一个角色,而且在经典零知识证明中扮演双重角色。具体来说,[Brakerski等人,FOCS,2018]中基于Shor因式分解的方案和基于带误差学习的方案可以通过在验证者端要求可提取的非交互式零知识论证来转化为量子性的零知识证明。因此,量子性的零知识证明可以被视为量子性证明的增强安全概念。
英文摘要
With the rapid development of quantum computers, proofs of quantumness have recently become an interesting research direction. However, in current schemes for proofs of quantumness, quantum provers face the risk of being maliciously exploited by classical verifiers. Through malicious strategies in interaction with quantum provers, classical verifiers could solve some instances of hard problems that arise from the specific scheme in use. This is due to the lack of formalization that prevents malicious verifiers from extracting useful information in proofs of quantumness. To address this issue, we formalize zero-knowledge proofs of quantumness. Intuitively, the zero-knowledge property necessitates that the information gained by the classical verifier from interactions with the quantum prover should not surpass what can be simulated using a simulated classical prover interacting with the same verifier. As a result, the new zero-knowledge notion can prevent a malicious verifier from exploiting quantum advantage. We find that the classical zero-knowledge proof is sufficient to compile some existing proofs of quantumness schemes into zero-knowledge proofs of quantumness schemes. It appears to be more general to require zero-knowledge proof on the verifier side instead of the prover side. This helps to regulate the verifier's behavior from malicious to be honest-but-curious. As a result, both parties will play not only one role in the proofs of quantumness but also the dual role in the classical zero-knowledge proof. Specifically, Shor's factoring-based scheme and the learning with errors-based scheme in [Brakerski et al., FOCS, 2018] can be transformed into zero-knowledge proofs of quantumness by requiring an extractable non-interactive zero-knowledge argument on the verifier side. Zero-knowledge proofs of quantumness can thus be viewed as an enhanced security notion for proofs of quantumness.
Comments19 pages, 8 figures. Published in IACR Communications in Cryptology
Journal refIACR Communications in Cryptology, vol. 1, no. 4, 2025