arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Shamir秘密共享的改进局部泄漏弹性与最坏情况最优多项式交集

Improved Local Leakage Resilience of Shamir Secret Sharing and Worst-Case Optimal Polynomial Intersection

Yihang Sun, Mary Wootters

arXiv 2610.12357首次发表:更新:

发表机构

Stanford University(斯坦福大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究利用Sun等2026年提出的关联,改进了Shamir秘密共享的局部泄漏弹性(突破二分之一壁垒)与最坏情况最优多项式交集的量子算法及存在性结果,还给出了OPI的量子-经典困难性无条件分离。

AI 中文摘要

我们研究两个问题:Shamir秘密共享的局部泄漏弹性(Local Leakage Resilience, LLR),以及最坏情况最优多项式交集(Optimal Polynomial Intersection, OPI)。两个问题均涉及素数阶有限域$\boldsymbol{\text{F}}_p$上次数小于$k$的多项式$Q(X)$。在Shamir秘密共享的LLR问题中,给定从不同非零求值点$\boldsymbol{\text{F}}_p$中选取的$\boldsymbol{\text{F}}_p$个点$\boldsymbol{\text{F}}_p$对应的$Q(\boldsymbol{\text{F}}_p), \boldsymbol{\text{F}}_p, Q(\boldsymbol{\text{F}}_p)$中每个点泄漏的少量比特,我们需要确定能从中获取多少关于$Q(0)$的信息。在OPI问题中,给定输入列表$\boldsymbol{\text{F}}_p, \boldsymbol{\text{F}}_p, \boldsymbol{\text{F}}_p \boldsymbol{\text{F}}_p$,我们需要找到一个次数小于$k$的多项式$Q(X)$,使得$Q(\boldsymbol{\text{F}}_p)$尽可能多地属于$S_i$。利用Sun和Wootters(2026)提出的这两个问题之间的最新关联,我们改进了两个问题的现有最优结果。对于LLR,我们证明存在某个常数$\boldsymbol{\text{F}}_p > 0$,只要$R := k/n \boldsymbol{\text{F}}_p 1/2 - \boldsymbol{\text{F}}_p$,Shamir秘密共享就是1比特局部泄漏弹性的(即只能获取关于$Q(0)$的可忽略量信息)。这是首个突破LLR所谓“二分之一壁垒”的结果,优于此前已知的最佳结果(Kasser, 2025)要求$R \boldsymbol{\text{F}}_p 0.668$。对于OPI,我们提出一种量子算法,对于任意固定的$\boldsymbol{\text{F}}_p > 0$,该算法能找到一个多项式$Q(X)$,使其在期望上与至少$\boldsymbol{\text{SCL}}_\rho(R) - \boldsymbol{\text{F}}_p$比例的列表一致,其中$\boldsymbol{\text{SCL}}_\rho$是Jordan等人(2025)提出的半圆律。这改进了Jo(2026)和Horinaga、Yamakawa(2026)的现有算法(及存在性)结果,我们还给出了进一步改进的存在性结果。此外,我们将Yamakawa和Zhandry(2024)的困难性结果调整为适用于OPI(而非其折叠版本);在大域上,这给出了相对于成员查询的OPI量子与经典困难性之间的无条件分离。

英文摘要

We study two problems: Local Leakage Resilience (LLR) for Shamir secret sharing, and worst-case Optimal Polynomial Intersection (OPI). Both problems concern polynomials $Q(X)$ of degree less than $k$, over a prime-order finite field $\mathbb{F}_p$. In LLR for Shamir secret sharing, one asks how much one can learn about $Q(0)$ given a few bits leaked from each of $Q(α_1), \ldots, Q(α_n)$, for distinct non-zero evaluation points $α_i \in \mathbb{F}_p$. In OPI, one is given input list $S_1, \ldots, S_n \subset \mathbb{F}_p$, and wants to find a polynomial $Q(X)$ of degree less than $k$ so that $Q(α_i) \in S_i$ for as many $i$ as possible. Leveraging recent connection between these two problems due to (Sun, Wootters 2026), we improve the state-of-the-art for both problems. For LLR, we show that there is some constant $δ> 0$ so that, as long as $R := k/n \geq 1/2 - δ$, Shamir secret-sharing is one-bit locally leakage resilient (meaning that one can learn only a negligible amount about $Q(0)$). This is the first result to break the so-called "one-half barrier" for LLR, and improves over the previous best known result, requiring $R \geq 0.668$ (Kasser, 2025). For OPI, we give a quantum algorithm that finds a polynomial $Q(X)$ that agrees with at least a $\mathsf{SCL}_ρ(R)-\varepsilon$ fraction of the lists in expectation, for every fixed $\varepsilon>0$, where $\mathsf{SCL}_ρ$ is the \emph{semicircle law} of (Jordan et al., 2025). This improves previous algorithmic (and existential) results of (Jo, 2026) and (Horinaga, Yamakawa, 2026). We also give further improved existential results. We also adapt the hardness result of (Yamakawa, Zhandry, 2024) to apply to OPI (rather than a folded version); over large fields, this gives an unconditional separation between the quantum and classical hardness of OPI relative to a membership oracle.

Comments70 pages, 3 figures

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑