arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.34413quant-phcs.CR

排列异或的量子安全性:基于傅里叶分析

Quantum Security of XOR of Permutations via Fourier Analysis

  • DGIST(大邱科学技术院)
  • KAIST(韩国科学技术院)

机构由 AI 辅助整理,请以论文原文为准。

Wonseok Choi, Minki Hhan, Junyoung Jang

AI总结:

通过傅里叶分析证明排列异或(XoP)在量子攻击下超越生日界的安全性,给出优势上界并推测其紧性。

AI中文摘要:

两个或多个独立随机排列的异或(XoP)是由排列构造的典型伪随机函数,其安全性超越了生日界。XoP构造的经典安全性已得到充分研究,但其对以叠加态查询XoP的量子攻击的安全性一直悬而未决。我们证明,对于任意q次量子算法,在$q\ll 2^n$条件下,$r\ge 2$个在$\{0,1\}^n$上的随机排列的异或与随机函数不可区分,其优势为\\[O\left(\min\left\{\frac{q^3}{2^{rn}},\frac{q^{1.5}}{2^{(r-0.5)n}},\frac{1}{2^{(r-1.5)n}}\right\}\right)\\]。特别地,XoP在整个查询范围内保持安全,远超量子碰撞发现攻击导致的$2^{n/3}$界限。这是首个从排列构造实现超越生日界安全性的量子版本的构造。我们还提出了若干启发式攻击,表明在$q\le 2^{n/2}$和$\approx 2^n$范围内我们的界限是紧的。我们使用了多项式方法的傅里叶分析变体:任意q次量子算法的优势由至多$2q$次的傅里叶分量或构造的$2q$个输入输出数据控制。大多数分量的范数有良好界限,证明了$2^{-(r-3/2)n}$的界限。低次分量的范数对于$q^3/2^{rn}$和$q^{1.5}/2^{(r-0.5)n}$的界限而言过大。我们将这些低次分量重新解释为其他问题的优势(之和)。例如,2次和4次项被解释为针对带有和不带有植入碰撞的随机函数的优势,进而使用Zhandry的小范围分布来界定。在此过程中,我们证明了小范围不可区分性的一个新界限,讽刺的是该界限适用于大范围,这具有独立意义。

英文摘要:

The XOR of two or more independent random permutations (XoP) is the prototypical pseudorandom function built from permutations achieving security beyond the birthday bound. The classical security of the XoP construction is well established, but its security against quantum attacks that query XoP in superposition has remained widely open. We prove that the XOR of $r\ge 2$ random permutations over $\{0,1\}^n$ is indistinguishable from a random function by any $q$-query quantum algorithm with advantage \[O\left(\min\left\{\frac{q^3}{2^{rn}},\frac{q^{1.5}}{2^{(r-0.5)n}},\frac{1}{2^{(r-1.5)n}}\right\}\right)\] for all $q\ll 2^n$. In particular, XoP remains secure throughout the entire query range, far beyond the $2^{n/3}$ bound due to quantum collision finding attacks. This is the first construction from permutations that achieves the quantum version of the beyond birthday bound security. We also present several heuristic attacks suggesting the tightness of our bounds in ranges $q\le 2^{n/2}$ and $\approx 2^n$. We use a Fourier-analytic variant of the polynomial method: the advantage of any $q$-query quantum algorithm is controlled by the Fourier components of degree at most $2q$, or by $2q$ input-output data of the construction. The norms of most components are bounded well, proving the bound $2^{-(r-3/2)n}$. The norm of low-degree components turn out to be too large for the bounds $q^3/2^{rn}$ and $q^{1.5}/2^{(r-0.5)n}$. We reinterpret these low-degree components as (sums of) advantages of the other problems. For example, the degree-2 and degree-4 terms are interpreted as the advantages against random functions with and without \emph{planted collisions}, which in turn are bounded using Zhandry's small-range distributions. Along the way, we prove a new bound for the small-range indistinguishability for (ironically) large ranges, which is of independent interest.

↑