发表机构
UC San Diego; Tsinghua University; Purdue University(加州大学圣地亚哥分校; 清华大学; 普渡大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文证明基于Haar随机态和反射预言机的量子货币在用户钞票数低于状态层析规模时具有最优查询安全性,即现有钞票无法加速伪造,并给出了紧下界及匹配攻击。
AI 中文摘要
量子密码学利用不可克隆性来实现一系列经典上不可能实现的密码学应用,例如受量子力学保护以防伪造的数字货币。安全性要求任何高效用户都不能在其已拥有的钞票之外再产生一张额外的有效钞票。然而,现有的安全性界限随着用户可获得的钞票数量增加而减弱。在本文中,我们研究了一种量子货币的构造,只要用户可获得的钞票数量保持在状态层析所需的规模以下,其渐近查询安全性就不会恶化。特别地,我们证明了基于$n$量子比特Haar随机态和反射预言机的构造实现了最优查询安全性:除非用户持有$\u03a9(2^n)$张钞票,否则其现有钞票无法在渐近意义上加速伪造——其最佳可能攻击与没有任何钞票时相同。为了建立这一结果,我们开发了一个基于压缩预言机技术的框架,用于定义和分析诸如Haar态克隆等量子任务的进展度量。此外,我们证明了生成$r$个额外副本的紧下界,给出了匹配的攻击,并将我们的结果应用于量子复制保护。
英文摘要
Quantum cryptography leverages unclonability to enable a wide range of cryptographic applications that are impossible classically, such as digital currency protected against counterfeiting by quantum mechanics. Security requires that no efficient user can produce even one additional valid banknote beyond those already in their possession. However, existing security bounds weaken as the number of banknotes available to a user increases. In this paper, we study a construction of quantum money whose asymptotic query security does not deteriorate as long as the number of banknotes available to a user remains below the scale required for state tomography. In particular, we show that the construction based on an $n$-qubit Haar-random state and a reflection oracle achieves optimal query security: unless a user holds $Ω(2^n)$ banknotes, their existing banknotes cannot asymptotically speed up counterfeiting --- their best possible attack is the same as if they do not have any banknotes. To establish this result, we develop a framework based on the compressed-oracle technique for defining and analyzing progress measures for quantum tasks such as Haar state cloning. Furthermore, we prove a tight lower bound for generating $r$ additional copies, give a matching attack, and apply our results to quantum copy-protection.
Comments36 pages