[論文レビュー] On Quantum Obfuscation
本稿は、古典的および量子的機能性の両方に対して、ブラックボックス、区別不能性、最良の可能性の obfuscation などの複数のバリエーションを定義することで、量子 obfuscation の厳密な研究を開始する。攻撃者が複数の出力をアクセスできる状況では、量子ブラックボックス obfuscation が不可能であることを証明し、統計的区別不能性 obfuscation は計算複雑性論的に崩壊するが、情報理論的ブラックボックス obfuscation が単一の複製不能な量子状態に可能である可能性が残っている。
Encryption of data is fundamental to secure communication in the modern world. Beyond encryption of data lies obfuscation, i.e., encryption of functionality. It is well-known that the most powerful means of obfuscating classical programs, so-called ``black-box obfuscation',' is provably impossible [Barak et al '12]. However, several recent results have yielded candidate schemes that satisfy a definition weaker than black-box, and yet still have numerous applications. In this work, we initialize the rigorous study of obfuscating programs via quantum-mechanical means. We define notions of quantum obfuscation which encompass several natural variants. The input to the obfuscator can describe classical or quantum functionality, and the output can be a circuit description or a quantum state. The obfuscator can also satisfy one of a number of obfuscation conditions: black-box, information-theoretic black-box, indistinguishability, and best possible; the last two conditions come in three variants: perfect, statistical, and computational. We discuss many applications, including CPA-secure quantum encryption, quantum fully-homomorphic encryption, and public-key quantum money. We then prove several impossibility results, extending a number of foundational papers on classical obfuscation to the quantum setting. We prove that quantum black-box obfuscation is impossible in a setting where adversaries can possess more than one output of the obfuscator. In particular, generic transformation of quantum circuits into black-box-obfuscated quantum circuits is impossible. We also show that statistical indistinguishability obfuscation is impossible, up to an unlikely complexity-theoretic collapse. Our proofs involve a new tool: chosen-ciphertext-secure encryption of quantum data, which was recently shown to be possible assuming quantum-secure one-way functions exist [Alagic et al '16].
研究の動機と目的
- 量子 obfuscation を暗号的プリミティブとして形式化し、厳密に分析すること。古典的 obfuscation の概念を量子ドメインに拡張すること。
- 量子力学的性質が、古典的に可能でないより強力な obfuscation 形式を可能にするかどうかを調査すること。特に、古典暗号理論における既知の不可能性結果を踏まえて検討すること。
- 量子攻撃者に対しても機能を保持しながら、機密な実装詳細を隠ぺいすることができる量子 obfuscator の構築可能性を検討すること。
- 複雑性理論的および情報理論的ツールを用いて、量子設定下でどの obfuscation 定義が可能または不可能であるかを同定すること。
- 量子 obfuscation と他の暗号的プリミティブ(例:量子完全同型暗号化、量子マネー)との関係を確立すること。
提案手法
- 量子 obfuscation の形式的フレームワークを導入し、出力が量子回路または量子状態である obfuscator を区別し、ブラックボックス、区別不能性、最良の可能性といった異なる obfuscation 条件を定義する。
- 量子状態用の量子セキュアな擬似乱数生成および対称鍵暗号化を定義し、量子 obfuscation の基盤的ツールを構築する。
- 最近、量子セキュアな一方向関数の下で可能であることが示された、選択暗号文攻撃耐性のある量子暗号化を、不可能性証明の主要技術的ツールとして応用する。
- 攻撃者が同一の入力に対して obfuscator の複数の出力を入手できる状況では、量子ブラックボックス obfuscation が不可能であることを証明する。
- 量子セキュアな一方向関数が存在すると仮定すると、統計的区別不能性 obfuscation は多項式階層の崩壊に帰着され、したがって不可能であることを示す。
- CPTP 回路および量子状態の集合の構造を用いて、obfuscation 条件を形式化し、その意味・影響を分析する。
実験結果
リサーチクエスチョン
- RQ1量子力学的手段を用いて、古典的または量子的プログラムのブラックボックス obfuscation を達成できるか。特に、出力が複製不能である場合にどうか。
- RQ2量子設定下で統計的区別不能性 obfuscation は可能か。もし可能であれば、その計算複雑性論的結果は何か。
- RQ3量子 obfuscation が、量子完全同型暗号化や公開鍵型量子マネーといった新しい暗号的プリミティブの実現を可能にするか。
- RQ4攻撃者が複数の obfuscated インスタンスにアクセスできる、または量子状態の構造を悪用できる場合、量子 obfuscation の限界は何か。
- RQ5計算的 obfuscation が不可能であっても、情報理論的に安全な量子 obfuscation スキームは存在するか。
主な発見
- 攻撃者が同一の入力に対して obfuscator の複数の出力を入手できる状況では、量子ブラックボックス obfuscation は不可能である。
- 量子セキュアな一方向関数が存在すると仮定すると、統計的区別不能性 obfuscation は、多項式階層の崩壊に起因して量子設定下で不可能である。
- 計算的区別不能性 obfuscation は、明示的な構成が提示されていないものの、量子設定下でも有効な候補のまま残っている。
- 量子計算的区別不能性 obfuscator の存在を仮定すると、QMA 用の量子ワーニング暗号化が可能であることが確立された。
- 情報理論的に安全なブラックボックス obfuscation が、単一の複製不能な量子状態に可能である可能性が残っており、obfuscation における量子優位性の可能性を示唆している。
- 量子 obfuscation は、複製不能な量子状態が obfuscated プログラムとして機能できる場合、古典的 obfuscation よりもはるかに強力である可能性がある。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。