具有认证删除的半量子密码学
Semi-Quantum Cryptography with Certified Deletion
- MIT(麻省理工学院)
- NTT Research(NTT研究所)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本工作提出一个通用编译器,在LWE后量子假设下,通过纯经典通信实现公开可验证的认证删除,支持多种加密原语,并允许经典客户端审计和检索数据。
AI中文摘要:
认证删除允许客户端将加密数据以量子态上传至服务器,随后请求服务器删除其数据并检测服务器是否遵守。如果验证通过,则即使解密密钥日后泄露,服务器上的数据仍将保持隐藏。在公开可验证的认证删除中,验证密钥被公开,以便任何人可以检查删除合规性。在本工作中,我们给出一个通用的编译器,用于公开可验证的认证删除,该编译器允许客户端在普通模型中基于LWE的后量子困难性假设,通过纯经典通信初始上传*量子*密文。我们的方法可应用于广泛的密码原语,包括承诺方案以及公钥、基于属性、基于身份和全同态加密。此外,我们的构造允许客户端以经典方式管理加密数据,而不仅仅是验证其删除。经典客户端可以通过无入侵证明对密文进行非破坏性审计,以检查其是否已泄露给第三方。经典客户端还可以在同时验证其从服务器删除数据的同时检索数据。因此,他们不必在检索数据和保护数据免受未来密钥泄露之间做出选择。作为我们的核心技术贡献,我们给出一个经典通信协议和模拟技术,该技术允许调整基于纯化的安全性论证,以适用于通过经典交互制备的BB84态。它使得所需的纯化在混合实验中可用,尽管在真实执行中经典转录唯一地确定了所制备的状态。
英文摘要:
Certified deletion allows a client to upload encrypted data to a server as a quantum state, then later request that the server delete their data and detect whether the server complies. If verification passes, then the data on the server will remain hidden even if the decryption key is later leaked. In publicly verifiable certified deletion, the verification key is published so that anyone may check for deletion compliance. In this work, we give a general compiler to publicly verifiable certified deletion that allows the client to initially upload the *quantum* ciphertext using purely *classical* communication, assuming the post-quantum hardness of LWE in the plain model. Our approach can be applied to a wide variety of primitives, including commitments and public-key, attribute-based, identity-based, and fully-homomorphic encryption. Moreover, our constructions allow the client to classically manage the encrypted data beyond just verifying its deletion. The classical client may non-destructively audit the ciphertext via a Proof of No Intrusion to check whether it has been leaked to a third party. The classical client may also retrieve the data while simultaneously verifying its deletion from the server. Thus, they do not have to choose between retrieving the data and protecting it against future key leakage. As our core technical contribution, we give a classical-communication protocol and simulation technique that allows adapting purification-based security arguments for BB84-style states which are prepared through classical interaction. It makes the required purification available in a hybrid experiment, despite the classical transcript uniquely determining the prepared state in a real execution.