[Paper Review] Trevisan's extractor in the presence of quantum side information
This paper establishes that Trevisan's extractor construction remains secure even when an adversary holds quantum side information, proving its robustness in quantum-secure settings. The authors leverage the modularity of Trevisan's framework to construct quantum-proof extractors with poly-logarithmic seed length and near-optimal entropy loss, enabling applications in quantum cryptography and randomness recycling under realistic side-information models.
Randomness extraction involves the processing of purely classical information and is therefore usually studied in the framework of classical probability theory. However, such a classical treatment is generally too restrictive for applications, where side information about the values taken by classical random variables may be represented by the state of a quantum system. This is particularly relevant in the context of cryptography, where an adversary may make use of quantum devices. Here, we show that the well known construction paradigm for extractors proposed by Trevisan is sound in the presence of quantum side information. We exploit the modularity of this paradigm to give several concrete extractor constructions, which, e.g, extract all the conditional (smooth) min-entropy of the source using a seed of length poly-logarithmic in the input, or only require the seed to be weakly random.
Motivation & Objective
- To establish the security of Trevisan’s extractor construction in the presence of quantum side information, which is critical for quantum-secure cryptography.
- To extend classical extractor theory to the quantum setting by proving that conditional min-entropy remains a valid measure of extractable randomness when side information is quantum.
- To construct practical quantum-proof extractors with small seed length and low entropy loss, suitable for applications like privacy amplification and randomness recycling.
- To analyze whether modifications of Trevisan’s extractor (e.g., using multivariate codes or weak seeds) remain secure under quantum side information.
- To identify open problems in constructing practical, quantum-proof two-source extractors and efficient implementations.
Proposed method
- Adapts Trevisan’s extractor framework—based on a two-stage process: a design-based seed generation and a 1-bit extractor applied to each subset of the input.
- Uses a weak $(t,r)$-design to generate $m$ subsets of the seed, ensuring sufficient randomness expansion while preserving security under quantum side information.
- Applies a 1-bit extractor $C$ with error $rac{ ho^2}{9m^2}$ to each subset, ensuring the final output is statistically close to uniform conditioned on quantum side information.
- Employs the smooth conditional min-entropy $H_{ ext{min}}^{ ext{ε}}(X|E)$ as the security metric, proving that extractors satisfying $H_{ ext{min}}(X|E) o ext{uniform output}$ are secure against quantum adversaries.
- Combines the extractor with a weak random seed of length $d = O(rac{1}{eta^2 u} \ olimits \log n)$, where $\nu$ controls the entropy loss and $\beta$ controls error, achieving $d = O(\log n)$ for constant $\beta, \nu$.
- Uses a composition technique to achieve near-optimal entropy loss, with output length $m = n^{\alpha - \gamma} - o(1)$, matching the conditional min-entropy up to sub-polynomial factors.
Experimental results
Research questions
- RQ1Can Trevisan’s extractor construction remain secure when the side information is quantum rather than classical?
- RQ2What is the minimal seed length required for a quantum-proof extractor that extracts all the conditional min-entropy from a source?
- RQ3Can modifications of Trevisan’s extractor—such as those using multivariate codes or weak seeds—be proven secure in the presence of quantum side information?
- RQ4How does the entropy loss of a quantum-proof extractor compare to its classical counterpart, and can it be minimized?
- RQ5Are there practical implementations of quantum-proof extractors that maintain low running time and small seed size?
Key findings
- Trevisan’s extractor framework is proven secure against quantum side information, extending its applicability to quantum-cryptographic protocols.
- A quantum-proof $(n^\gamma m + 8\log m + 8\log 1/\varepsilon + O(1), \varepsilon)$-strong extractor is constructed with seed length $d = O(\frac{1}{\beta^2 \gamma} \log n)$ and seed min-entropy $s = (1 - \frac{\frac{1}{2} - \beta}{c})d$, achieving $d = O(\log n)$ for constant $\beta, \gamma$.
- The extractor achieves output length $m = n^{\alpha - \gamma} - o(1) = H_{\min}(X|E)^{1 - \frac{\gamma}{\alpha}} - o(1)$, extracting nearly all the conditional min-entropy.
- A construction with seed length $d = O(\log^3 n)$ and seed entropy $s = d - O(\sqrt[3]{d})$ is shown to extract all the min-entropy of the source, with entropy loss linear in $d$.
- The paper demonstrates that modifications of Trevisan’s extractor using $1$-bit extractors and designs remain quantum-proof, extending results to constructions like those of Raz et al. and Lu.
- The work leaves open the question of whether advanced constructions using multivariate codes (e.g., [TZS06, SU05]) or sub-polynomial entropy sources remain quantum-proof, suggesting a direction for future research.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.