[Paper Review] Quantum trapdoor functions from classical one-way functions
This paper introduces quantum trapdoor functions (QTFs), a novel cryptographic primitive that enables public-key encryption with a pure quantum public key, constructed from quantum-secure one-way functions. The construction leverages pseudorandom states from one-way functions and proves security via a reduction to an information-theoretic state-discrimination task with Haar-random states, demonstrating that quantum public keys can be secure even when an adversary obtains polynomially many copies.
We formalize and study the notion of a quantum trapdoor function. This is an efficiently computable unitary that takes as input a "public" quantum state and a classical string $x$, and outputs a quantum state. This map is such that (i) it is hard to invert, in the sense that it is hard to recover $x$ given the output state (and many copies of the public state), and (ii) there is a classical trapdoor that allows efficient inversion. We show that a quantum trapdoor function can be constructed from any quantum-secure one-way function. A direct consequence of this result is that, assuming just the existence of quantum-secure one-way functions, there exists a public-key encryption scheme with a (pure) quantum public key.
Motivation & Objective
- To formalize the concept of a quantum trapdoor function (QTF), a unitary map that is hard to invert without a classical trapdoor but efficiently invertible with it.
- To show that quantum trapdoor functions can be constructed from quantum-secure one-way functions, bridging a gap between classical one-way functions and quantum public-key cryptography.
- To demonstrate that such QTFs imply public-key encryption schemes where the public key is a pure quantum state, even when the adversary has polynomially many copies of it.
- To explore the implications for two-message key-exchange protocols in the quantum setting, under a model of authenticated quantum communication that allows copying of quantum messages.
Proposed method
- The construction uses pseudorandom states (PRS) from one-way functions, as established by Ji, Liu, and Song (2018) and later proven secure by Brakerski and Shmueli (2019).
- The evaluation key $\ket{\text{eval}}$ is a pseudorandom quantum state generated from a classical seed, and the trapdoor allows efficient generation of this state and inversion of the function.
- Security is proven by reducing an adversary that inverts the QTF to one that solves a state-discrimination task involving Haar-random states, leveraging the pseudorandomness of the state generation.
- The public-key encryption scheme is constructed analogously to classical trapdoor functions: the public key is $\ket{\text{eval}}$, and encryption involves computing $f(x)$ and a hardcore bit of $x$, with the message XORed with the hardcore bit.
- The two-message key-exchange protocol uses the quantum public key as the first message and a quantum-encrypted random string as the second, with security relying on the CPA-security of the underlying quantum public-key encryption.
- The model assumes a quantum authenticated channel that allows the adversary to obtain polynomially many copies of the quantum message, which captures scenarios where the public key is widely distributed.
Experimental results
Research questions
- RQ1Can a trapdoor function be constructed from a one-way function in the quantum setting, where the public key is a quantum state?
- RQ2Is it possible to achieve public-key encryption with a pure quantum public key based solely on the existence of quantum-secure one-way functions?
- RQ3What is the correct model of authenticated quantum communication that supports secure two-message key exchange in the quantum setting?
- RQ4How does the security of quantum public-key encryption differ from classical public-key encryption when the adversary has access to multiple copies of the public key?
Key findings
- Quantum trapdoor functions can be constructed from any quantum-secure one-way function, establishing a new cryptographic primitive in the quantum setting.
- The construction relies on the pseudorandom state (PRS) framework, where the evaluation key is a pseudorandom quantum state generated from a classical seed.
- Security is proven by reducing the inversion problem to a state-discrimination task with Haar-random states, which is information-theoretically hard.
- A public-key encryption scheme with a pure quantum public key exists under the same assumption, even when the adversary has polynomially many copies of the public key.
- A two-message key-exchange protocol is realized using the quantum public-key encryption scheme, assuming a quantum authenticated channel that allows the adversary to collect multiple copies of the quantum message.
- The result shows that quantum public keys are conceptually viable as public information, even though they are not practically efficient, and highlights a fundamental difference between classical and quantum public information.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.