发表机构
Centre for Quantum Technologies, Singapore; Department of Computer Science, National University of Singapore; MajuLab, UMI 3654, Singapore(新加坡量子技术中心; 新加坡国立大学计算机系; 新加坡UMI 3654 MajuLab)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
基于后量子单向函数,构造了鲁棒且抗泄漏的设备无关不经意传输与比特承诺协议,容忍设备故障和泄漏,实现安全计算。
AI 中文摘要
假设存在后量子单向函数,我们构造了设备无关(DI)的不经意传输(OT)和比特承诺:诚实方仅使用可信的经典计算来操作不可信的量子设备,这些设备可能共享任意纠缠并以非独立同分布方式行为。安全性是基于模拟的,针对量子多项式时间对手,并且能够与高效模拟器顺序组合。一个协议骨架同时服务于两者,在两种体制下工作。在诚实接收方设备的隔离实验室和坐标局部测量下,它容忍恒定比例的诚实设备故障。在实验室之间具有多对数数量级的自适应泄漏量子比特以及任意联合测量下,它容忍逆多对数比例。每次基本DI调用使用一批新的、隔离的多对数数量级设备坐标,编译后的OT协议中总设备使用量是多项式的。承诺对双方都有高效的模拟器,并产生带中止的DI抛币。由于OT对于安全计算是完备的,该构造为固定数量方上的每个高效可计算经典功能产生带中止的DI协议,对任何适当子集的静态腐化都是安全的。承诺的提取器通过经典含糊改变公共奇偶关系,并保持设备执行及其泄漏不变。一个承诺并证明功能、不相交审计和仿射一致性检查将认证相关性连接到理想OT。发送方安全性依赖于Magic Square游戏的选择器感知并行重复界,我们由Kundu和Tan的两轮阈值定理推导得出。
英文摘要
Assuming post-quantum one-way functions, we construct device-independent (DI) oblivious transfer (OT) and bit commitment: honest parties use only trusted classical computation to operate untrusted quantum devices, which may share arbitrary entanglement and behave non-IID. Security is simulation-based against quantum polynomial-time adversaries and composes sequentially with efficient simulators. One protocol skeleton serves both, in two regimes. With isolated laboratories and coordinate-local measurements in the honest receiver's device, it tolerates a constant rate of honest-device faults. With polylogarithmically many qubits of adaptive leakage between the laboratories and arbitrary joint measurements, it tolerates an inverse-polylogarithmic rate. Each elementary DI call uses a fresh, isolated batch of polylogarithmically many device coordinates, and total device use in the compiled OT protocol is polynomial. The commitment has efficient simulators against both parties and yields DI coin tossing with abort. Because OT is complete for secure computation, the construction yields a DI protocol, with abort, for every efficiently computable classical functionality on a fixed number of parties, secure against static corruption of any proper subset of them. The commitment's extractor changes a public parity relation through classical equivocation and leaves the device execution, hence its leakage, unchanged. A commit-and-prove functionality, disjoint audits, and an affine consistency check link the certified correlations to ideal OT. Sender security rests on a selector-aware parallel-repetition bound for the Magic Square game, which we derive from the two-round threshold theorem of Kundu and Tan.