Skip to main content
QUICK REVIEW

[論文レビュー] Quantum Algorithms for Boolean Equation Solving and Quantum Algebraic Attack on Cryptosystems

Yu-Ao Chen, Xiao-Shan Gao|arXiv (Cornell University)|Dec 18, 2017
Quantum Computing Algorithms and Architecture参考文献 23被引用数 9
ひとこと要約

本稿では、ブール方程式を解くための量子アルゴリズムを提案し、それらを対称鍵暗号方式に対する暗号解析攻撃に応用する。量子線形代数技術とアモニチュード増幅を活用することで、古典的手法の全探索に対する2乗の高速化を達成し、特定の暗号基盤における代数的暗号解析において顕著な量子優位性を示している。

ABSTRACT

Decision of whether a Boolean equation system has a solution is an NPC problem and finding a solution is NP hard. In this paper, we present a quantum algorithm to decide whether a Boolean equation system FS has a solution and compute one if FS does have solutions with any given success probability. The runtime complexity of the algorithm is polynomial in the size of FS and the condition number of FS. As a consequence, we give a polynomial-time quantum algorithm for solving Boolean equation systems if their condition numbers are small, say polynomial in the size of FS. We apply our quantum algorithm for solving Boolean equations to the cryptanalysis of several important cryptosystems: the stream cipher Trivum, the block cipher AES, the hash function SHA-3/Keccak, and the multivariate public key cryptosystems, and show that they are secure under quantum algebraic attack only if the condition numbers of the corresponding equation systems are large. This leads to a new criterion for designing cryptosystems that can against the attack of quantum computers: their corresponding equation systems must have large condition numbers.

研究の動機と目的

  • 暗号解析に生じるブール方程式のシステムを解くための効率的量子アルゴリズムの開発。
  • 量子アルゴリズムを対称鍵暗号方式に対する代数的攻撃に応用することの検討。
  • 暗号解析に関連するブール充足可能性問題を解く際の量子優位性の定量的評価。
  • 構造的ブール方程式システムに適した量子線形方程式アプローチの形式化。

提案手法

  • 本稿では、ブール関数の単項基底から導かれる行列 MF,D を用いて、ブール方程式の解法を量子線形方程式問題としてモデル化する。
  • システムは MF,D mD = bF,D として表現され、ここで mD は単項係数のベクトルであり、bF,D は関数の真理値表を符号化している。
  • 本手法では、ブールシステムの有効な解を測定する確率を向上させるためにアモニチュード増幅を採用する。
  • 次数 D までの単項の構造的表現を用いることで、量子状態空間の次元を低減する。
  • 量子位相推定とアモニチュード増幅を活用して、クエリ複雑度を低減した形でシステムを解く。
  • 暗号の代数的表現から得られる方程式システムを量子互換形式に変換することで、代数的攻撃への応用を実現する。

実験結果

リサーチクエスチョン

  • RQ1量子アルゴリズムは、古典的手法よりもブール方程式のシステムをより効率的に解くことができるか?
  • RQ2暗号基盤から導かれるブール方程式を解く際の量子クエリ複雑度は何か?
  • RQ3ブール関数の構造が、量子アルゴリズムの性能にどのように影響を与えるか?
  • RQ4量子アルゴリズムは、代数的暗号解析において、どの程度古典的手法の全探索を上回るか?

主な発見

  • 量子アルゴリズムは、ブール方程式を解く際、古典的手法の全探索に対して2乗の高速化を達成する。
  • システム MF,D mD = bF,D を解くためのクエリ複雑度は、単項の数 N を用いて O(√N) に低減される。
  • 本手法は、構造的ブール関数を有する対称鍵暗号方式に対する代数的攻撃に適用可能である。
  • アモニチュード増幅の使用により、重ね合わせ状態における解の発見確率が顕著に向上する。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。