发表机构
The Stein Faculty of Computer and Information Science, Ben-Gurion University of the Negev; Department of Computer Science, Columbia University(内盖夫本-古里安大学斯坦计算机与信息科学学院; 哥伦比亚大学计算机科学系)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文在标准模型中基于一次性签名构造了可对话量子火,实现无密钥不可电报性和可对话性,并给出其首批密码学应用,展示了单向与双向经典通信在传输量子火上的本质差异。
AI 中文摘要
量子火由量子态组成,这些量子态可以被高效地功能性克隆,但无法通过单向经典通信传输。此前所有具有已证明不可电报性的量子火构造都相对于预言机而言,而我们的构造基于一次性签名,处于标准模型中。我们的构造实现了我们引入的两个进一步概念:(a) 无密钥不可电报性,这是不可电报性的强化;(b) 可对话性,意味着火焰虽然无法通过单向经典通信电报传输,但可以通过经典交互传输。因此,单向和双向经典通信在传输这种量子火的能力上存在质的差异。我们利用量子火的这两个新特性及其可克隆性,给出了量子火的首批密码学应用之一。无密钥不可电报性迫使有效火焰序列号分布具有高最小熵,而可对话性和可克隆性允许相应的火焰仅使用经典通信即可被克隆和转移。我们提出了可对话量子火构造的两种变体。第一种基于一次性签名(可由亚指数iO、亚指数安全单向函数和LWE实例化),支持多项式多个火焰,且序列号分布的最小熵为超对数。第二种在更强的指数级不可伪造一次性签名假设下(可相对于经典预言机实例化),支持指数多个火焰,且最小熵为线性。
英文摘要
Quantum fire consists of quantum states that can be efficiently functionally cloned but cannot be transmitted using one-way classical communication. Whereas all previous quantum-fire constructions with proven untelegraphability are relative to an oracle, ours, based on one-shot signatures, is in the standard model. Our construction achieves two further notions that we introduce: (a) keyless untelegraphability, a strengthening of untelegraphability; and (b) conversability, meaning that a flame, though not telegraphable via one-way classical communication, can be transmitted via classical interaction. Hence one-way and two-way classical communication differ qualitatively in their power to transmit this quantum fire. We use these two novel properties of quantum fire, along with its clonability, to give one of the first cryptographic applications of quantum fire. Keyless untelegraphability forces the distribution of serial numbers of valid flames to have high min-entropy, while conversability and clonability allow the corresponding flame to be cloned and transferred using only classical communication. We present two variants of our conversable quantum-fire construction. The first, based on one-shot signatures (instantiable from subexponential iO, subexponentially secure one-way functions, and LWE), supports polynomially many flames, and super-logarithmic min-entropy of the serial-number distribution. The second, under the stronger assumption of exponentially unforgeable one-shot signatures (instantiable relative to a classical oracle), supports exponentially many flames, and linear min-entropy.
Comments40 pages, 9 figures