[Paper Review] Two-Source Extractors Secure Against Quantum Adversaries
This paper presents the first two-source extractor secure against quantum adversaries, including those sharing entanglement. It proves that the Chor-Goldreich inner-product extractor and its multi-bit variant by Dodis et al. remain secure under quantum bounded storage and entanglement, achieving parameters matching the classical case with tight bounds on error and min-entropy requirements.
We initiate the study of multi-source extractors in the quantum world. In this setting, our goal is to extract random bits from two independent weak random sources, on which two quantum adversaries store a bounded amount of information. Our main result is a two-source extractor secure against quantum adversaries, with parameters closely matching the classical case and tight in several instances. Moreover, the extractor is secure even if the adversaries share entanglement. The construction is the Chor-Goldreich [CG88] two-source inner product extractor and its multi-bit variant by Dodis et al. [DEOR04]. Previously, research in this area focused on the construction of seeded extractors secure against quantum adversaries; the multi-source setting poses new challenges, among which is the presence of entanglement that could potentially break the independence of the sources.
Motivation & Objective
- To investigate whether multi-source extractors remain secure when faced with quantum adversaries storing quantum information.
- To determine if entanglement between adversaries can break the security of two-source extractors.
- To establish explicit bounds on min-entropy and error for two-source extractors to remain secure against quantum knowledge.
- To bridge the gap between classical multi-source extractors and their quantum-secure counterparts, especially in the presence of entanglement.
Proposed method
- Adapts the Chor-Goldreich two-source inner-product extractor and its multi-bit variant by Dodis et al. to the quantum setting.
- Uses the Pretty Good Measurement (粗略翻译:近似最优测量) framework to model quantum adversaries' knowledge and measurement strategies.
- Applies the XOR-Lemma to reduce multi-bit extractor security to the one-bit strong extractor case.
- Composes the resulting quantum-secure two-source extractor with a seeded extractor against quantum knowledge to amplify output length.
- Employs trace distance bounds and quantum information-theoretic tools to quantify security against quantum adversaries with bounded storage.
- Leverages known results on quantum-secure seeded extractors (e.g., from [DPVR09]) to achieve full output length with minimal seed overhead.
Experimental results
Research questions
- RQ1Can two-source extractors remain secure when adversaries store quantum information and share entanglement?
- RQ2Do standard classical two-source extractors, such as the inner-product extractor, remain secure against quantum bounded-storage adversaries?
- RQ3What are the tightest achievable min-entropy and error parameters for a two-source extractor to be secure against quantum adversaries?
- RQ4How does entanglement between adversaries affect the independence and security of multi-source extractors in the quantum setting?
- RQ5Can the security of multi-bit two-source extractors be reduced to the one-bit case under quantum knowledge?
Key findings
- The Chor-Goldreich inner-product extractor is secure against quantum adversaries with bounded storage, even when adversaries share entanglement.
- For a two-source extractor with min-entropies $k_1$ and $k_2$, security is achieved when $k_1 + k_2 \gtrapprox n + 6\log \varepsilon^{-1}$, matching classical parameters up to logarithmic factors.
- The extractor is a $(k_1, k_2, \varepsilon)$ X-strong (Y-strong) extractor against quantum knowledge when $k_1 + k_2 \geq n - 2 + 6\log \varepsilon^{-1}$ for the one-bit case.
- For the multi-bit case, the extractor $E_D$ is secure when $k_1 + k_2 \geq 6m + n - 2 + 6\log \varepsilon^{-1}$, producing $m$ bits of nearly uniform output.
- By composing with a quantum-secure seeded extractor of length $d = O(\log^3(n/\varepsilon))$, the final construction achieves $m = \frac{1}{6}(k_1 + k_2 - n - 6\log \varepsilon^{-1}) + k_1 - 8\log k_1 - 8\log \varepsilon^{-1} - O(1)$ output bits.
- The security proof establishes that trace distance between the extractor output and uniform is bounded by $\sqrt{\varepsilon}$, ensuring robustness against quantum knowledge.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.