论最简单的量子安全分组密码
On The Simplest Quantum-Secure Block Cipher
浏览论文内容
中文总结 AI 辅助
本研究证明两轮Even-Mansour密码在量子查询下信息论安全,并指出单轮构造不安全,该构造为最简单的量子安全分组密码。
中文摘要 AI 辅助
伪随机置换在理论和应用密码学中无处不在。即使在 adversaries 进行量子查询的情况下也能提供安全性的 PRP 越来越受到关注,并应用于从构造伪随机酉算子到将 SZK 与 BQP 分离等场景。构造经典安全 PRP 的一个成功框架是密钥交替 Even-Mansour 方法,该方法将公开置换的应用与轮密钥的添加交错进行。单轮构造在理想置换模型(IPM)中已经是经典安全的,增加轮数可提供更好的具体安全性。然而,在量子查询环境下,该框架的现状目前尚不清楚。基于 Simon 算法的一个简单量子查询攻击可以破解单轮密码。对于两轮或更多轮,安全性仅对必须提前准备所有查询的非自适应 adversaries 已知。在本工作中,我们证明了两轮 Even-Mansour 密码在 IPM 中对于 adversaries 对所有可用预言机进行多项式多次自适应前向和逆向量子查询是信息论安全的。我们的证明使用了压缩置换预言机和一个专门构造的等距算子,将理想实验和真实实验联系起来。我们还表明,该构造是最小的,因为本质上任何通过单次调用公开置换构造的密码在量子环境下都是不安全的。
英文摘要
Pseudorandom permutations are ubiquitous in theoretical and applied cryptography. PRPs that offer security even against adversaries making quantum queries are of increasing interest, and used in applications ranging from constructing pseudorandom unitaries to separating SZK from BQP. A successful framework for constructing classically-secure PRPs is the key-alternating Even-Mansour approach, which interleaves applications of public permutations with additions of round keys. The single-round construction is already classically secure in the ideal permutation model (IPM), with added rounds offering improved concrete security. However, in the quantum-query setting, the status of this framework is presently unclear. A simple quantum-query attack based on Simon's algorithm breaks the one-round cipher. For two or more rounds, security is only known against non-adaptive adversaries who must prepare all queries in advance. In this work, we show that the two-round Even-Mansour cipher is information theoretically secure in the IPM against adversaries making polynomially-many adaptive forward and inverse quantum queries to all available oracles. Our proof uses compressed permutation oracles and a specially crafted isometry relating the ideal and real experiments. We also show that this construction is minimal, in the sense that essentially any cipher constructed via a single call to a public permutation is quantumly insecure.
发表机构
- University of Maryland(马里兰大学)
- National Institute of Standards and Technology(美国国家标准与技术研究院)
- Technical University of Denmark(丹麦技术大学)
机构由 AI 辅助整理,请以论文原文为准。