发表机构
Princeton(普林斯顿大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文在随机预言机模型中证明了破解量子密码学的时间-空间下界接近最优,显示量子密码学在抵御预处理攻击方面优于经典密码学,并简化推广了现有方法。
AI 中文摘要
我们在随机预言机模型中证明了破解量子密码学的时间-空间下界接近最优。具体而言,我们证明一个进行$T$次查询、拥有$S$量子比特非均匀建议的攻击者,从$n$量子比特二进制相位态$|\psi_k\rangle \propto \sum_{x} R(k,x) |x\rangle$中恢复随机密钥$k$的概率至多为$O(\frac{T^2 + \sqrt{ST}}{N})$,其中$N=2^n$。相比之下,后量子单向函数的最佳已知界为$O(\frac{T^2 + ST}{N})$,且在$S = N$时存在平凡攻击。这表明量子密码学相对于经典密码学具有新的优势:$n$量子比特的通信足以抵御空间高达$N^2$而非$N$的预处理攻击。我们的方法很简单:将最优预处理攻击表示为随机矩阵的算子范数,并通过迹矩方法在随机预言机上对该值的期望进行界定。这些迹矩可以利用压缩预言机[Zhandry, Crypto 2019]进行自然解释,我们随后对其进行分析。这可以看作是对Liu [Eurocrypt 2023]证明破解后量子密码学时间-空间权衡方法的简化和推广。我们还证明了以下结果:(1) 我们收紧了Liu对QROM中后量子PRG的分析,实现了$O(\frac{T^2}N + \sqrt{\frac{ST}N})$的区分优势界。(2) 对于酉合成,我们将Lombardi-Ma-Wright [STOC 2024]的单查询下界扩展到能够进行一次任意函数查询以及多项式次(自适应)随机预言机查询(在函数查询之前或之后)的攻击者。这也从压缩预言机的角度解释了原始的LMW24结果。(3) 最后,我们证明了针对空间$S$区分器的随机二进制相位态伪随机性的紧致$O(\frac{\sqrt{S}}N)$界。
英文摘要
We prove near-optimal lower bounds for preprocessing attacks on quantum cryptography in the random oracle model. Specifically, we show that a $T$-query adversary with $S$ qubits of non-uniform advice can recover a random key $k$ from the $n$-qubit binary phase state $|ψ_k\rangle \propto \sum_{x} R(k,x) |x\rangle$ with probability at most $O(\frac{T^2 + \sqrt{ST}}{N})$ for $N=2^n$. In contrast, the best known bound for post-quantum one-way functions is $O(\frac{T^2 + ST}{N})$, with a trivial attack at $S = N$. This demonstrates a new advantage of quantum cryptography over classical cryptography: $n$ qubits of communication suffice for security against preprocessing attacks with space up to $N^2$ rather than $N$. Our methodology is simple: express the optimal preprocessing attack as the operator norm of a random matrix, and bound this value in expectation over the random oracle via the trace-moment method. These trace moments have a natural interpretation using compressed oracles [Zhandry, Crypto 2019], which we then analyze. This can be viewed as a simplification and generalization of the approach of Liu [Eurocrypt 2023] for proving the security of post-quantum cryptography against preprocessing attacks. We also prove the following results: (1) We tighten Liu's analysis of post-quantum PRGs in QROM, achieving a distinguishing advantage bound of $O(\frac{T^2}N + \sqrt{\frac{ST}N})$. (2) For unitary synthesis, we extend the one-query lower bound of Lombardi-Ma-Wright [STOC 2024] to hold against adversaries that can make one arbitrary function query along with polynomially many (adaptive) queries to the random oracle, either before or after the function query. This also interprets the original LMW24 result in terms of compressed oracles. (3) Finally, we prove a tight $O(\frac{\sqrt{S}}N)$ bound for the pseudorandomness of random binary phase states against space $S$ distinguishers.