发表机构
Technische Universität Berlin; Freie Universität Berlin(柏林工业大学; 柏林自由大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出一种有限大小方法,精确评估乘积分布建议下量子-经典猜测矩分离的加速指数,应用于冷启动泄漏等场景,指数可达3.97,优于先前熵基估计。
AI 中文摘要
Grover算法为黑盒搜索提供了最优的二次查询优势。然而,在密码分析中,搜索通常伴随着对候选者的额外概率性建议,且常具有乘积形式,例如来自独立密钥坐标的侧信道泄漏。经典情况下,按似然顺序进行猜测在期望上是最优的。在量子设置中,Montanaro展示了如何实现最优期望查询复杂度,在每次非均匀建议分布上(至多常数开销因子)都优于普通Grover算法。迄今为止所缺失的是一种有限大小的方法,用于评估给定建议分布所引发的量子-经典猜测矩分离。我们针对乘积分布建议提供了这样一种方法,从而细化了Bashiri等人先前基于熵的估计。我们将经典和量子猜测矩归结为一维惊奇分布的函数,该分布通过卷积每个坐标的惊奇定律获得,用于乘积建议。当惊奇值位于公共算术网格上(可公度情形)时,对数矩以及由此产生的加速指数可以作为有限和进行评估而无离散化误差;指数倾斜使此计算数值稳定。对于一般乘积建议,我们将惊奇值离散化到公共网格上,并推导出由此产生的分箱误差的后验界。我们将该框架应用于种子和分组密码密钥的冷启动泄漏、模板攻击后验,以及校准到针对ML-KEM和ML-DSA的Keccak侧信道攻击所报告残差秩的合成i.i.d.伯努利后验。在几种偏斜建议设置中,所得指数显著超过2,在这些合成模型中达到高达3.97,并包括先前基于熵的界未能建立高于2的指数的情形。
英文摘要
Grover's algorithm gives an optimal quadratic query advantage for black-box search. In cryptanalysis, however, the search often comes with additional probabilistic advice over the candidates, frequently of product form, e.g. from side-channel leakage on independent key coordinates. Classically, guessing in likelihood order is optimal in expectation. In the quantum setting, Montanaro showed how to achieve an optimal expected query complexity, beating plain Grover on every non-uniform advice distribution (up to a constant overhead factor). What has been missing so far is a finite-size method for evaluating the quantum-classical guessing-moment separation induced by a given advice distribution. We provide such a method for product-distribution advice, thereby sharpening the previous entropy-based estimate of Bashiri et al. We reduce the classical and quantum guessing moments to functionals of the one-dimensional surprisal distribution, obtained for product advice by convolving the per-coordinate surprisal laws. When the surprisals lie on a common arithmetic grid (the commensurate case), the logarithmic moments and hence the speedup exponent can be evaluated as finite sums without discretization error; exponential tilting makes this computation numerically stable. For general product advice, we discretize the surprisals onto a common grid and derive an a-posteriori bound on the resulting binning error. We apply the framework to cold-boot leakage on seeds and block-cipher keys, to template-attack posteriors, and to synthetic i.i.d. Bernoulli posteriors calibrated to residual ranks reported for Keccak side-channel attacks on ML-KEM and ML-DSA. The resulting exponents substantially exceed 2 in several skewed-advice settings, reaching up to 3.97 in these synthetic models, and include cases where the previous entropy-based bound did not establish an exponent above 2.
Comments19 pages, 2 tables, accepted at PQQS '26