路径寻找、轨道态制备与不变量子货币的安全性
Path-Finding, Orbit State Preparation, and the Security of Invariant Quantum Money
浏览论文内容
中文总结 AI 辅助
本文研究不变量子货币的安全性,指出路径寻找假设在无群结构时不足,提出可证伪的态制备假设,并证明其与转移假设结合等价于安全性,且黑盒归约无法推导转移假设。
中文摘要 AI 辅助
基于纽结的量子货币及其推广到不变货币的安全性,依赖于路径寻找(即在两个等价对象之间展示一系列移动序列)是困难的这一假设。目前尚无从该假设本身出发证明安全性的已知结果。现有证明增加了路径知识假设,该假设断言任何生成两个具有相同不变量的对象的有效算法都隐式地知道它们之间的一条路径。没有攻击能否定这样的假设,并且它是否由安全性推导而来尚不可知。我们探讨路径寻找何时是正确的假设。当每个等价类是一个可高效计算且可叠加的群作用的轨道,且每个移动都作为群元素作用时(如图的情形),路径寻找的平均情况困难性对于安全性是必要的。对于纽结,没有这样的群已知,而路径寻找器仅将伪造问题归约为同等困难的态制备问题。无论有无路径寻找器,伪造者都必须制备一个验证接受的态,我们将该任务的困难性作为假设。对于验证行走在多项式时间内混合的方案,制备假设指出:给定一枚新铸造钞票的序列号以及从中测量出的一个对象,没有高效算法能制备这样的态。该假设是可证伪的,并且等价于针对先测量其钞票的伪造者的安全性。转移假设(安全性蕴含它)指出,先测量最多使伪造者付出多项式因子代价。两者结合等价于安全性,因此每个安全性证明必须建立制备假设。若制备假设成立,则没有完全黑盒归约(仅以给定序列号调用伪造者)能从制备假设推导出转移假设。
英文摘要
The security of quantum money from knots, and of its generalization to invariant money, is based on the assumption that path-finding, exhibiting a sequence of moves between two equivalent objects, is hard. No proof of security from that assumption alone is known. The existing proofs add knowledge-of-path assumptions, which assert that any efficient algorithm producing two objects with the same invariant implicitly knows a path between them. No attack can refute such an assumption, and it is not known to follow from security. We ask when path-finding is the right assumption. When each equivalence class is the orbit of an efficiently computable action of a group that can be superposed over, and every move acts as a group element, as for graphs, average-case hardness of path-finding is necessary for security. For knots no such group is known, and a path-finder only reduces forgery to an equally hard state-preparation problem. With or without a path-finder, a forger must prepare a state that verification accepts, and we take the hardness of that task as the assumption. For schemes whose verification walk mixes in polynomial time, the preparation assumption states that no efficient algorithm, given the serial number of a freshly minted banknote and one object measured from it, prepares such a state. It is falsifiable, and it is equivalent to security against forgers that measure their banknote first. The transfer assumption, which security implies, states that measuring first costs a forger at most a polynomial factor. Together the two are equivalent to security, so every proof of security must establish the preparation assumption. If the preparation assumption holds, no fully black-box reduction that calls the forger only at the serial number it is given can derive the transfer assumption from the preparation assumption.
发表机构
- The University of Sydney(悉尼大学)
机构由 AI 辅助整理,请以论文原文为准。