发表机构
UT Austin; Columbia University; UC Berkeley; NTT Research(德克萨斯大学奥斯汀分校; 哥伦比亚大学; 加州大学伯克利分校; NTT研究所)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究提出一种无需可信随机种子、在量子随机预言机模型下无条件安全且速率最优的量子随机性认证协议,并构建条件最小熵证明以支持随机信标应用。
AI 中文摘要
认证随机比特的生成是量子计算机近期应用的一个新兴方向。诸如随机信标和CRS生成等潜在应用需要近乎均匀的随机性,其速率(最小熵与比特长度之比)约为1。然而,现有的认证随机性协议要么生成速率为o(1)的弱随机字符串,要么需要可信的随机种子。我们展示了如何在不要求验证者提供任何可信随机性的情况下,以最优速率约1来认证随机性。我们的协议在量子随机预言机模型(QROM)中是无条件安全的。这改进了Coladangelo等人的结果,他们在QROM中无条件地认证了弱随机字符串,并回答了Aaronson和Hung提出的问题。我们还定义并构建了一个条件最小熵的证明,即使在对抗性选择的转录条件下,也能认证最优的最小熵。我们展示了该原语在随机信标中的应用,其中每个脉冲应在所有先前消息的条件下具有高最小熵。
英文摘要
The generation of certified random bits is an emerging near-term application of quantum computers. Potential applications, such as randomness beacons and CRS generation, require nearly uniform randomness, whose rate (the ratio of min-entropy to bitlength) is ~ 1. However, existing protocols for certified randomness either produce weakly random strings with rate o(1), or they require a trusted random seed. We show how to certify randomness with the optimal rate ~ 1 without requiring any trusted randomness from the verifier. Our protocol is secure unconditionally in the quantum random oracle model (QROM). This improves the result of Coladangelo et al., who certified weakly random strings unconditionally in the QROM, and answers a question posed by Aaronson and Hung. We also define and construct a proof of conditional min-entropy, which certifies optimal min-entropy even conditioned on an adversarially chosen transcript. We show an application of this primitive to randomness beacons, where each pulse should have high min-entropy conditioned on all previous messages.