Skip to main content
QUICK REVIEW

[论文解读] Classically Verifiable (Dual-Mode) NIZK for QMA with Preprocessing.

Tomoyuki Morimae, Takashi Yamakawa|arXiv (Cornell University)|Feb 18, 2021
Cryptography and Data Security参考文献 39被引用 4
一句话总结

本论文首次提出了适用于QMA的、具有双模特性的可经典验证非交互式零知识证明(CV-NIZK),在一种模式下实现信息论安全性,在另一种模式下实现信息论零知识。该工作在预处理模型中构建了三个方案:一个在秘密参数模型下实现信息论安全与信息论零知识的CV-NIP/NIZK;以及一个基于学习误差问题(LWE)的量子困难性假设的计算性CV-NIZK,解决了Coladangelo等人(CRYPTO '20)提出的一个开放问题。

ABSTRACT

We propose three constructions of classically verifiable non-interactive proofs (CV-NIP) and non-interactive zero-knowledge proofs and arguments (CV-NIZK) for QMA in various preprocessing models. - We construct an information theoretically sound CV-NIP for QMA in the secret parameter model where a trusted party generates a quantum proving key and classical verification key and gives them to the corresponding parties while keeping it secret from the other party. Alternatively, we can think of the protocol as one in a model where the verifier sends an instance-independent quantum message to the prover as preprocessing. - We construct a CV-NIZK for QMA in the secret parameter model. It is information theoretically sound and zero-knowledge. - Assuming the quantum hardness of the leaning with errors problem, we construct a CV-NIZK for QMA in a model where a trusted party generates a CRS and the verifier sends an instance-independent quantum message to the prover as preprocessing. This model is the same as one considered in the recent work by Coladangelo, Vidick, and Zhang (CRYPTO '20). Our construction has the so-called dual-mode property, which means that there are two computationally indistinguishable modes of generating CRS, and we have information theoretical soundness in one mode and information theoretical zero-knowledge property in the other. This answers an open problem left by Coladangelo et al, which is to achieve either of soundness or zero-knowledge information theoretically. To the best of our knowledge, ours is the first dual-mode NIZK for QMA in any kind of model.

研究动机与目标

  • 在预处理模型中构造适用于QMA的可经典验证非交互式证明(CV-NIP)与NIZK。
  • 通过在双模NIZK系统中实现信息论安全性或信息论零知识,解决Coladangelo、Vidick与Zhang(CRYPTO '20)提出的一个开放问题。
  • 在存在可信方生成公共参考字符串(CRS)的模型中,提供QMA的CV-NIZK构造,其中验证者在预处理阶段发送与实例无关的量子消息。
  • 在CRS生成的两种不同模式中,分别实现信息论安全性与信息论零知识,且两种模式在计算上不可区分。
  • 在保持经典验证能力的同时,确保方案在学习误差问题的量子困难性假设下依然安全。

提出的方法

  • 在秘密参数模型中设计适用于QMA的CV-NIP,其中可信方生成量子证明密钥与经典验证密钥,并将证明密钥保密。
  • 在相同的秘密参数模型中构建CV-NIZK,实现信息论安全性与信息论零知识。
  • 引入双模构造,使得两种CRS生成模式在计算上不可区分:一种提供信息论安全性,另一种提供信息论零知识。
  • 利用学习误差问题(LWE)的量子困难性,确保在基于CRS的模型中具备计算安全性。
  • 采用预处理模型,其中验证者向证明者发送与实例无关的量子消息,从而在最终协议中实现高效验证。
  • 通过仅使用经典计算即可实现经典验证,即使证明本身涉及量子态。

实验结果

研究问题

  • RQ1能否在双模环境下构造出兼具信息论安全性与信息论零知识的QMA可经典验证NIZK?
  • RQ2是否可能在一种模式下实现信息论安全性,另一种模式下实现信息论零知识,且两种CRS生成模式在计算上不可区分?
  • RQ3能否在验证者发送与实例无关的量子消息的预处理模型中,构造出QMA的CV-NIZK?
  • RQ4如何利用学习误差问题的量子困难性,来构建一个在CRS模型中安全且可经典验证的QMA NIZK?
  • RQ5所提出的构造是否解决了在双模NIZK系统中实现QMA的任一信息论安全性或信息论零知识的开放问题?

主要发现

  • 本论文在秘密参数模型中首次构造出兼具信息论安全与信息论零知识的CV-NIZK。
  • 提出了一种双模CV-NIZK,其中一种模式确保信息论安全性,另一种模式确保信息论零知识,且两种模式在计算上不可区分。
  • 该构造实现了在预处理模型中对量子证明的经典验证,其中验证者向证明者发送与实例无关的量子消息。
  • 在学习误差问题的量子困难性假设下,论文在CRS模型中提供了带有预处理的CV-NIZK,其模型与Coladangelo等人(CRYPTO '20)一致。
  • 本工作解决了Coladangelo、Vidick与Zhang留下的开放问题,实现了在双模NIZK系统中对QMA的信息论安全性或信息论零知识。
  • 据我们所知,这是首个在任何模型中实现的QMA双模NIZK,标志着在具有经典验证能力的量子交互式证明系统方面取得了重大进展。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。