发表机构
Technology Innovation Institute (TII); Max Planck Institute for Security and Privacy (MPI-SP)(技术创新研究所; 马克斯·普朗克安全与隐私研究所)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出一个通用的不可区分性提升定理,证明若基础预言机量子不可区分,则其密钥化预言机也量子不可区分(优势损失O(q^2)),并应用于构造压缩理想密码和加倍量子安全强伪随机置换的消息长度。
AI 中文摘要
密码学安全证明通常涉及敌手与一个更大的、密钥化的预言机交互,该预言机由(可能指数级)许多个较小的基础预言机的独立实例组成。然而,证明两个这样的密钥化预言机之间的量子不可区分性可能很棘手,因为敌手的一次查询可能涉及覆盖所有基础预言机实例的叠加态。在本文中,我们建立了一个通用形式的不可区分性提升定理:如果两个基础预言机在量子查询下是不可区分的,那么它们对应的密钥化预言机也是不可区分的,其区分优势最多有O(q^2)的乘法损失,其中q是敌手发起的查询次数。我们的提升定理适用于统计和计算两种设置,也适用于有状态的预言机。它也是最优的,因为它与针对某种(人为构造的)预言机选择的明显Grover搜索攻击相匹配。作为一个直接应用,我们将Carolan的压缩排列预言机扩展为一个可高效实现的压缩理想密码,并用它来证明Davies-Meyer压缩函数在量子理想密码模型中的原像抗性。得益于我们的提升定理,我们压缩理想密码的可靠性归结为Carolan预言机的可靠性,并且对后者的任何进一步改进将自动转移到前者。作为我们的第二个应用,我们给出一个模块化构造,将任何量子安全强伪随机置换的消息长度加倍。在此过程中,我们证明了一个现有的两轮可调整Feistel构造在量子双向查询下与随机置换不可区分。这是通过一个专门的多项式方法论证完成的,该论证可能具有独立的意义。
英文摘要
Cryptographic security proofs often involve an adversary interacting with a larger, keyed oracle that consists of (potentially exponentially) many independent instances of a smaller, base oracle. However, showing quantum indistinguishability between two such keyed oracles can be tricky, since a single query made by an adversary may involve a superposition that covers all instances of the base oracles simultaneously. In this paper, we establish a generic indistinguishability lifting theorem of the following form: if the two base oracles are indistinguishable under quantum queries, then their corresponding keyed oracles are too, up to an O(q^2) multiplicative loss in distinguishing advantage, where q is the number of queries made by the adversary. Our lifting theorem applies to both statistical and computational settings, and to oracles that are stateful as well. It is also optimal in that it matches the obvious Grover search attack for a certain (contrived) choice of oracles. As an immediate application, we extend Carolan's compressed permutation oracle to an efficiently implementable compressed ideal cipher, and use it to prove preimage resistance of the Davies-Meyer compression function in the quantum ideal cipher model. Thanks to our lifting theorem, the soundness of our compressed ideal cipher reduces to that of Carolan's oracle, and any further improvement on the latter would automatically carry over to the former. As our second application, we give a modular construction that doubles the message length of any quantum-secure strong pseudorandom permutation. Along the way, we show that an existing two-round tweakable Feistel construction is indistinguishable from a random permutation under quantum bidirectional queries. This is done via a dedicated polynomial-method argument, which may be of independent interest.