发表机构
Cornell University(康奈尔大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究证明若量子随机预言机中存在通用的类Fiat-Shamir编译器,则QMA=BQP,从而为量子协议无法直接编译为NIZK提供了正式证据。
AI 中文摘要
量子密码学中一个重要的开放问题是构造针对QMA的公开可验证NIZK。经典上,可以通过Fiat-Shamir变换将针对NP的诚实验证者ZK(HVZK)Σ-协议编译为随机预言机模型(有时在标准模型中)中的NIZK。Broadbent和Grilo引入了Σ-协议的量子类比(他们称之为Ξ-协议),其中证明者的第一条消息是量子的,并表明针对QMA的HVZK Ξ-协议存在。然而,如何将这些协议编译为(Q)ROM中的NIZK尚不清楚,因为Fiat-Shamir变换似乎与量子消息不兼容。在这项工作中,我们给出了正式证据表明情况确实如此:我们证明,如果QROM中存在通用的“类Fiat-Shamir”编译器用于量子协议(具有小的完备性和可靠性误差),则QMA = BQP。
英文摘要
An important open question in quantum cryptography is the construction of publicly-verifiable NIZKs for QMA. Classically, one can construct NIZKs for NP in the random oracle model (and sometimes in the standard model) by compiling an honest-verifier ZK (HVZK) $Σ$-protocol for NP using the Fiat-Shamir transformation. Broadbent and Grilo introduced a quantum analog of a $Σ$-protocol (which they call a $Ξ$-protocol) in which the prover's first message is quantum, and show that HVZK $Ξ$-protocols exist for QMA. However, it is not clear how to compile such protocols into NIZKs in the (Q)ROM, because the Fiat-Shamir transformation seems to be incompatible with quantum messages. In this work we give formal evidence that this is indeed the case: we show that if generic "Fiat-Shamir-like" compilers for quantum protocols exist in the QROM (with small completeness and soundness error) then QMA = BQP.