arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.37276quant-phcs.CR

Shamir 秘密共享的量子泄漏鲁棒性

Quantum Leakage Resilience of Shamir Secret Sharing

Rishabh Batra, Fuyuki Kitagawa, Ryo Nishimaki, Takashi Yamakawa

首次发表
浏览论文内容

中文总结 AI 辅助

本文研究素数域上 Shamir 秘密共享的量子泄漏鲁棒性,证明在阈值率足够高时,即使存在局部量子泄漏或受限纠缠泄漏,方案仍安全,并给出线性数量设备共享纠缠时的安全性及经典泄漏攻击的负面结果。

中文摘要 AI 辅助

我们首次研究了未修改的、基于素数域的 Shamir 秘密共享的量子泄漏鲁棒性。在经典设置中,Shamir 秘密共享的一个被广泛研究的泄漏模型是每个份额的单比特局部泄漏。我们考虑其量子类比,其中对于每一方,一个局部泄漏信道以该方的份额为输入,并输出一个泄漏的量子比特。在没有预共享纠缠的情况下,我们证明当阈值率 $t/n=\tau$ 超过 $\tau_\star\approx0.73339$ 且差距为一个固定的正数时,区分优势为 $2^{-\Omega(n)}$。更一般地,我们允许任意固定最大大小的不相交纠缠块,其中不同块之间或与敌手之间没有纠缠,并且每个块至多发射固定数量的量子比特。当阈值率足够高(充分接近1)时,安全性成立。然后,我们允许一组指定的设备与敌手共享纠缠。我们证明,即使当线性数量的设备(对于小的 $\alpha>0$,为 $\alpha n$ 个)彼此之间以及与敌手共享纠缠时,只要阈值率足够大,安全性仍然成立。作为一个互补的负面结果,我们还表明,如果我们允许泄漏设备之间存在任意大的纠缠,即使是经典的单比特泄漏也会使 Shamir 方案不安全。由恰好 $t$ 个泄漏设备共享的 GHZ 态,即使与敌手没有任何纠缠,也会使经典的单比特泄漏变得不安全。在这种攻击中,每个参与设备仅发射一个经典比特,它们的联合奇偶性以恒定的优势区分任意一对选定的秘密。因此,对于高于 $\tau_\star$ 的固定阈值率,在保持安全性的前提下,可以彼此之间以及与敌手共享任意纠缠的设备的最大数量在常数因子意义下与 $n$ 成线性关系,尽管最优支持比例仍然是开放的。

英文摘要

We initiate the study of quantum leakage resilience of unmodified Shamir secret sharing over prime fields. A well-studied leakage model for Shamir's secret sharing classically is single-bit local leakage from each share. We consider its quantum analogue where, for each party, a local leakage channel takes as input the party's share and outputs a leaked qubit. Without preshared entanglement, we show that the distinguishing advantage is $2^{-Ω(n)}$ when the threshold rate $t/n=τ$ exceeds $τ_\star\approx0.73339$ by a fixed positive margin. More generally, we allow disjoint entangled blocks of any fixed maximum size where there is no entanglement between different blocks or with the adversary, and each block emits at most a fixed number of qubits. Security holds when the threshold rate is high enough (sufficiently close to one). We then allow a specified set of devices to share entanglement with the adversary. We show that security holds even when a linear number of devices ($αn$ for small $α>0$) share entanglement with each other and with the adversary for a large enough threshold rate. As a complementary negative result, we also show that even classical single-bit leakage makes Shamir scheme insecure if we allow arbitrarily large entanglement between the leakage devices. A GHZ state shared by exactly $t$ leakage devices makes even classical one-bit leakage insecure, without any entanglement with the adversary. In this attack, each participating device emits only one classical bit, and their joint parity distinguishes any chosen pair of secrets with a constant advantage. Thus, for fixed threshold rates above $τ_\star$, the maximum number of devices that may share arbitrary entanglement with one another and with the adversary while preserving security is linear in $n$ up to constant factors, although the optimal support fraction remains open.

发表机构

  • EPFL(洛桑联邦理工学院)
  • NTT Social Informatics Laboratories(NTT社会情报学实验室)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑