Skip to main content
QUICK REVIEW

[論文レビュー] Classically Verifiable (Dual-Mode) NIZK for QMA with Preprocessing.

Tomoyuki Morimae, Takashi Yamakawa|arXiv (Cornell University)|Feb 18, 2021
Cryptography and Data Security参考文献 39被引用数 4
ひとこと要約

本論文は、QMAにおける情報理論的音声性と情報理論的ゼロ知識の両方を別々のモードで達成する、二モード性を持つクラス的に検証可能な非インタラクティブゼロ知識証明(CV-NIZK)の最初の提示である。1つのモードでは情報理論的音声性を、もう1つのモードでは情報理論的ゼロ知識を達成する。事前処理モデルにおいて3つの方式を構築した。1つは秘密パラメータモデルにおける情報理論的音声性および情報理論的ゼロ知識を備えたCV-NIP/NIZKであり、もう1つは学習誤差問題(LWE)の量子ハードネスに基づく計算的CV-NIZKであり、Coladangeloら(CRYPTO '20)が提起した未解決問題を解決する。

ABSTRACT

We propose three constructions of classically verifiable non-interactive proofs (CV-NIP) and non-interactive zero-knowledge proofs and arguments (CV-NIZK) for QMA in various preprocessing models. - We construct an information theoretically sound CV-NIP for QMA in the secret parameter model where a trusted party generates a quantum proving key and classical verification key and gives them to the corresponding parties while keeping it secret from the other party. Alternatively, we can think of the protocol as one in a model where the verifier sends an instance-independent quantum message to the prover as preprocessing. - We construct a CV-NIZK for QMA in the secret parameter model. It is information theoretically sound and zero-knowledge. - Assuming the quantum hardness of the leaning with errors problem, we construct a CV-NIZK for QMA in a model where a trusted party generates a CRS and the verifier sends an instance-independent quantum message to the prover as preprocessing. This model is the same as one considered in the recent work by Coladangelo, Vidick, and Zhang (CRYPTO '20). Our construction has the so-called dual-mode property, which means that there are two computationally indistinguishable modes of generating CRS, and we have information theoretical soundness in one mode and information theoretical zero-knowledge property in the other. This answers an open problem left by Coladangelo et al, which is to achieve either of soundness or zero-knowledge information theoretically. To the best of our knowledge, ours is the first dual-mode NIZK for QMA in any kind of model.

研究の動機と目的

  • 事前処理モデルにおけるQMAのためのクラス的に検証可能な非インタラクティブ証明(CV-NIP)およびNIZKの構築。
  • Coladangelo, Vidick, and Zhang(CRYPTO '20)が提起した未解決問題を解決すること:二モードNIZKシステムにおいて、情報理論的音声性または情報理論的ゼロ知識を達成すること。
  • 信頼できる参加者が共通参照文字列(CRS)を生成するモデルにおいて、QMAのためのCV-NIZKの構築。このモデルでは検証者がインスタンスに依存しない量子メッセージを送信する。
  • CRS生成の2つの異なるモードにおいて、情報理論的音声性と情報理論的ゼロ知識を別々に達成し、それらのモードが計算的に区別不能であるようにすること。
  • 学習誤差問題(LWE)の量子ハードネスを保証しながら、古典的検証を維持する形で、セキュリティを確保すること。

提案手法

  • 信頼できる参加者が量子証明鍵と古典的検証鍵を生成し、証明鍵を秘密に保つ秘密パラメータモデルにおいて、QMAのためのCV-NIPを設計する。
  • 同じ秘密パラメータモデルにおいて、情報理論的音声性と情報理論的ゼロ知識の両方を達成するQMAのためのCV-NIZKを構築する。
  • 2つのCRS生成モードが計算的に区別不能である二モード構成を導入する。1つのモードでは情報理論的音声性を、もう1つのモードでは情報理論的ゼロ知識を提供する。
  • 学習誤差問題(LWE)の量子ハードネスを活用して、CRSベースのモデルにおける計算的セキュリティを確保する。
  • 検証者がインスタンスに依存しない量子メッセージを証明者に送信する事前処理モデルを用い、最終プロトコルにおける効率的な検証を可能にする。
  • 証明が量子状態を含んでも、検証者が古典的計算のみを用いて証明を検証できるようにすること。

実験結果

リサーチクエスチョン

  • RQ1QMAのためのクラス的に検証可能なNIZKを、二モード設定において情報理論的音声性とゼロ知識を同時に達成できるか?
  • RQ2情報理論的音声性を1つのモードで、情報理論的ゼロ知識をもう1つのモードで達成し、それらのCRS生成モードが計算的に区別不能であるようにすることは可能か?
  • RQ3検証者がインスタンスに依存しない量子メッセージを送信する事前処理モデルにおいて、QMAのためのCV-NIZKを構築できるか?
  • RQ4学習誤差問題(LWE)の量子ハードネスを活用して、CRSモデルにおける安全で、クラス的に検証可能なNIZKをQMAのための構築できるか?
  • RQ5提案された構成は、QMAのための二モードNIZKシステムにおいて、情報理論的音声性またはゼロ知識を達成するという、未解決問題を解決するか?

主な発見

  • 本論文は、秘密パラメータモデルにおけるQMAのための情報理論的音声性およびゼロ知識を備えた、最初のCV-NIZKを構築した。
  • 1つのモードでは情報理論的音声性、もう1つのモードでは情報理論的ゼロ知識を達成する二モードCV-NIZKを提示した。2つのモードは計算的に区別不能である。
  • 検証者がインスタンスに依存しない量子メッセージを送信する事前処理モデルにおいて、量子証明の古典的検証を実現した。
  • 学習誤差問題(LWE)の量子ハードネスの下で、事前処理付きのCRSモデルにおけるQMAのためのCV-NIZKを提供した。これはColadangeloら(CRYPTO '20)のモデルと一致する。
  • Coladangelo, Vidick, and Zhangが残した未解決問題を解決し、QMAのための二モードNIZKシステムにおいて情報理論的音声性またはゼロ知識を達成した。
  • 我々の知る限り、これはあらゆるモデルにおいてQMAのための最初の二モードNIZKであり、古典的検証を伴う量子インタラクティブ証明系における顕著な前進を示している。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。