arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

保护量子计算机免受不可信用户攻击

Protecting Quantum Computers against Untrusted Users

Shiv Akshar Yadavalli, Joel Rajakumar, Alexander Schuckert, Michael J. Gullans

arXiv 2610.06812首次发表:更新:

发表机构

Joint Center for Quantum Information and Computer Science, University of Maryland and NIST; Electrical & Computer Engineering Department, The University of California, Los Angeles; DIENS, École Normale Supérieure, PSL University, CNRS, INRIA; QuEra Computing Inc.; QuEra Computing UK Ltd.(马里兰大学与美国国家标准与技术研究院联合量子信息与计算中心; 加州大学洛杉矶分校电气与计算机工程系; 巴黎高等师范学院、PSL大学、法国国家科学研究中心、法国国家信息与自动化研究所联合信息系; QuEra计算公司; QuEra计算英国有限公司)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

提出受限计算模型1/2BQP_1,通过随机输入和单比特输出限制量子计算机的密码分析能力,同时保留科学应用,并论证其安全性基于因子分解的经典困难性和有理重构的电路下界。

AI 中文摘要

公开可访问的容错量子计算机必须在限制密码分析能力的同时保持科学实用性。我们提出了受限计算模型1/2BQP_1:量子服务器提供随机计算基输入,仅在执行后揭示,并指定一个输出比特。该接口允许任意电路和系统规模。我们推测,进行多项式多次自适应请求的经典客户端无法高效分解RSA模数。该模型包含了著名的一洁净量子比特模型DQC1,保留了其在无限温度多时间关联、超时序相关器和适当归一化配分函数中的应用。我们提出了一个基于测试量子自旋动力学经典预测的候选方案,用于区分1/2BQP_1与DQC1。我们分两步论证安全性。首先,我们证明单比特读出使标准因子分解算法的量子阶段可经典模拟,即使其准备和后处理在围绕单次算术预言机调用的广泛族内重新设计。这涵盖了Shor、Ekera-Hastad、Kitaev和Regev因子分解构造的量子阶段。其次,我们考察了相干实现有理重构以释放因子比特的变通方法。随机输入阻碍了这一直接攻击:已知技术可适应对数深度经典电路,但有理重构几十年来一直抵抗这种并行化。因此,我们表明我们协议的安全性不仅建立在因子分解的经典困难性上,还建立在有理重构的推测电路下界上。

英文摘要

Publicly accessible fault-tolerant quantum computers must preserve scientific utility while limiting cryptanalytic power. We propose the restricted model of computation, 1/2BQP_1: a quantum server provides random computational-basis inputs, revealed only after execution, and one designated output bit. This interface permits arbitrary circuits and system sizes. We conjecture that a classical client making polynomially many adaptive requests cannot efficiently factor RSA moduli. The model subsumes the well-known one-clean-qubit model DQC1, retaining its applications to infinite-temperature multi-time correlations, out-of-time-order correlators, and suitably normalized partition functions. We propose a candidate for separating 1/2BQP_1 from DQC1 based on testing classical predictions of quantum spin dynamics. We argue security in two steps. First, we show that one-bit readout makes the quantum stages of standard factoring algorithms classically simulable, even when their preparation and postprocessing are redesigned within a broad family around a single arithmetic-oracle call. This covers the quantum stages of Shor, Ekera-Hastad, Kitaev, and Regev factoring constructions. Second, we examine the workaround of coherently implementing rational reconstruction to release a factor bit. Random inputs obstruct this straightforward attack: known techniques accommodate logarithmic-depth classical circuits, but rational reconstruction has resisted such parallelization for decades. Therefore, we show that security of our protocol is built on not only classical hardness for factoring, but also conjectured circuit lowerbounds for rational reconstruction.

Comments10 pages, 5 pages of Appendix, 2 Figures, and 1 Table. Comments welcome!

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑