Skip to main content
QUICK REVIEW

[论文解读] A Unified Framework For Quantum Unforgeability

Mina Doosti, Mahshid Delavar|arXiv (Cornell University)|Mar 25, 2021
Cryptography and Data Security参考文献 35被引用 5
一句话总结

本文提出了一种统一的、参数化的基于量子博弈的框架,用于在量子敌手存在的情况下定义和分析不可伪造性,该框架涵盖了先前的古典和量子不可伪造性概念。证明了在存在性不可伪造性下,只有与先前查询消息正交的消息才能被视为有效伪造,且表明在一般叠加查询攻击下,确定性构造会失败,而伪随机函数(PRFs)可实现对完整量子敌手的选定不可伪造性。

ABSTRACT

In this paper, we continue the line of work initiated by Boneh and Zhandry at CRYPTO 2013 and EUROCRYPT 2013 in which they formally define the notion of unforgeability against quantum adversaries specifically, for classical message authentication codes and classical digital signatures schemes. We develop a general and parameterised quantum game-based security model unifying unforgeability for both classical and quantum constructions allowing us for the first time to present a complete quantum cryptanalysis framework for unforgeability. In particular, we prove how our definitions subsume previous ones while considering more fine-grained adversarial models, capturing the full spectrum of superposition attacks. The subtlety here resides in the characterisation of a forgery. We show that the strongest level of unforgeability, namely existential unforgeability, can only be achieved if only orthogonal to previously queried messages are considered to be forgeries. In particular, we present a non-trivial attack if any overlap between the forged message and previously queried ones is allowed. We further show that deterministic constructions can only achieve the weaker notion of unforgeability, that is selective unforgeability, against such restricted adversaries, but that selective unforgeability breaks if general quantum adversaries (capable of general superposition attacks) are considered. On the other hand, we show that PRF is sufficient for constructing a selective unforgeable classical primitive against full quantum adversaries. Moreover, we show similar positive results relying on Pseudorandom Unitaries (PRU) for quantum primitives. These results demonstrate the generality of our framework that could be applicable to other primitives beyond the cases analysed in this paper.

研究动机与目标

  • 在量子敌手模型下,统一并推广古典和量子密码原原子的不可伪造性概念。
  • 形式化一个细粒度的安全模型,以捕捉量子安全中所有叠加攻击的完整谱系。
  • 确定在量子环境下,存在性不可伪造性和选定不可伪造性可实现的条件。
  • 确立在一般量子敌手下,特别是叠加查询场景中,确定性构造的局限性。
  • 证明伪随机函数(PRFs)足以用于构建对完整量子敌手具有选定不可伪造性的经典原原子。

提出的方法

  • 提出一种参数化的基于量子博弈的安全模型,将不可伪造性定义推广至古典和量子原原子。
  • 引入一种基于与先前查询消息正交性的新伪造概念,表明这是实现存在性不可伪造性的必要条件。
  • 使用量子区分者博弈,证明在一般叠加查询下,确定性构造无法实现存在性不可伪造性。
  • 采用量子随机酉和哈尓测度模拟,构建基于矛盾的证明,以证明某些不可伪造性级别不可能实现。
  • 将该框架应用于证明PRFs和酉-通用(UU)方案在经典和量子环境中均可实现通用不可伪造性(qGUU)。
  • 建立不可伪造性级别的层次结构,包括1-qGEU、μ-qGEU、1-qGSU、μ-qGSU和qGUU,并映射其在不同原原子类型中的可行性。

实验结果

研究问题

  • RQ1能否通过单一统一框架,在量子敌手存在下捕捉古典和量子密码原原子的不可伪造性?
  • RQ2在量子环境下,特别是在叠加查询下,实现存在性不可伪造性的必要条件是什么?
  • RQ3为何确定性构造在一般量子敌手下无法实现选定或存在性不可伪造性?
  • RQ4伪随机函数(PRFs)能否用于构建在完整量子敌手下仍保持安全的经典原原子?
  • RQ5不同不可伪造性级别(如qGUU、1-qGSU)之间的关系是什么?哪些原原子能够实现这些级别?

主要发现

  • 在量子环境下,存在性不可伪造性要求伪造物与所有先前查询的消息正交,这一条件既是必要也是具有限制性的。
  • 确定性古典消息认证码(MAC)方案如HMAC和NMAC在一般叠加攻击下无法实现存在性或选定不可伪造性,除非在平凡情况μ=1。
  • 基于PRFs的随机化构造可克服此限制,并实现对完整量子敌手的选定不可伪造性。
  • 量子伪随机酉(PRUs)和酉-通用(UU)方案在较弱的qGUU不可伪造性级别下被证明是安全的,该级别对古典和量子原原子均可实现。
  • 该框架证明了1-qGSU安全意味着qGUU安全,且PRFs足以在经典原原子中实现qGUU安全。
  • 表3总结了不可能性结果:确定性古典和量子原原子无法实现μ≠1级别的qGEU或qGSU,而随机化构造可实现qGUU。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。