[论文解读] Code-routing: a new attack on position verification
本文提出了一种名为代码路由(code-routing)的新颖作弊策略,用于位置验证协议,该策略利用有限域上的量子秘密共享和跨度程序。通过将量子系统编码到基于跨度程序导出的指示函数的秘密共享方案中,该攻击对属于复杂度类 $\text{Mod}_p\text{L}$ 的函数实现了 $O(SP_p(f))$ 个贝尔态(EPR pairs),显著扩展了以往仅限于 $\text{L}$ 类函数的脆弱函数范围。
The cryptographic task of position verification attempts to verify one party's location in spacetime by exploiting constraints on quantum information and relativistic causality. A popular verification scheme known as $f$-routing involves requiring the prover to redirect a quantum system based on the value of a Boolean function $f$. Cheating strategies for the $f$-routing scheme require the prover use pre-shared entanglement, and security of the scheme rests on assumptions about how much entanglement a prover can manipulate. Here, we give a new cheating strategy in which the quantum system is encoded into a secret-sharing scheme, and the authorization structure of the secret-sharing scheme is exploited to direct the system appropriately. This strategy completes the $f$-routing task using $O(SP_p(f))$ EPR pairs, where $SP_p(f)$ is the minimal size of a span program over the field $\mathbb{Z}_p$ computing $f$. This shows we can efficiently attack $f$-routing schemes whenever $f$ is in the complexity class $ ext{Mod}_p ext{L}$, after allowing for local pre-processing. The best earlier construction achieved the class L, which is believed to be strictly inside of $ ext{Mod}_p ext{L}$. We also show that the size of a quantum secret sharing scheme with indicator function $f_I$ upper bounds entanglement cost of $f$-routing on the function $f_I$.
研究动机与目标
- 开发一种针对位置验证中 $f$-路由协议的新颖作弊策略,以绕过纠缠资源成本的假设。
- 将易受高效攻击的函数类从先前已知的 $\text{L}$ 类扩展至 $\text{Mod}_p\text{L}$ 类。
- 证明具有指示函数 $f_I$ 的量子秘密共享方案可对 $f_I$ 的 $f$-路由实现纠缠资源成本的上界。
- 形式化建立 $\mathbb{Z}_p$ 上跨度程序复杂度与 $f$-路由中作弊纠缠成本之间的联系。
提出的方法
- 该攻击将量子系统编码到一个秘密共享方案中,其访问结构源自 $\mathbb{Z}_p$ 上的跨度程序。
- 使用函数 $f'$ 定义为 $f'(z,b) = f(z) \wedge b$,该函数被分解为 $f_{I} \circ g$,其中 $g$ 对输入位进行复制和取反。
- 通过原始函数 $f$ 的跨度程序构造出一个单调跨度程序,从而确保 $f_I$ 同时具有单调性和不可克隆性。
- 该攻击的纠缠资源成本由 $O(SP_p(f))$ 个贝尔态(EPR pairs)上界控制,其中 $SP_p(f)$ 是 $\mathbb{Z}_p$ 上最小跨度程序的大小。
- 该构造确保作弊策略仅通过局部操作和单轮通信即可在目标时空区域外完成 $f$-路由任务。
- 该方法利用跨度程序与秘密共享之间的对偶性,将计算复杂度映射到纠缠资源成本。
实验结果
研究问题
- RQ1能否利用量子秘密共享构造出一种 $f$-路由的作弊策略,使纠缠资源成本低于先前的界限?
- RQ2该代码路由方法可高效攻击的函数复杂度类是什么?
- RQ3在 $\mathbb{Z}_p$ 上的跨度程序大小与 $f$-路由中作弊的纠缠资源成本之间有何关系?
- RQ4该构造能否推广至 $\text{L}$ 类之外的函数,如 $\text{Mod}_p\text{L}$ 类函数?
- RQ5最小跨度程序大小与 $f$-路由作弊的最小贝尔态资源成本之间是否存在直接对应关系?
主要发现
- 代码路由攻击对 $f$-路由实现了 $O(SP_p(f))$ 个贝尔态(EPR pairs)的资源成本,其中 $SP_p(f)$ 是 $\mathbb{Z}_p$ 上最小跨度程序的大小。
- 该攻击成功破坏了所有属于复杂度类 $\text{Mod}_p\text{L}$ 的函数 $f$ 的 $f$-路由方案,显著扩展了此前仅限于 $\text{L}$ 类函数的脆弱范围。
- 该构造表明,任何在 $\mathbb{Z}_p$ 上具有跨度程序的函数 $f$,均可通过使用指示函数 $f_I$ 的秘密共享实现高效攻击。
- 对 $f$-路由的纠缠资源成本由具有指示函数 $f_I$ 的量子秘密共享方案的大小所上界控制,从而建立了秘密共享与位置验证安全性之间的直接联系。
- 该方法构建了一个大小为 $m \cdot SP_p(f) + 1$ 的 $f_I$ 单调跨度程序,其中 $m$ 为输入位数,确保该方案有效且具备不可克隆性。
- 本文提供了一个具体示例:$f(x,y) = x \oplus y$,表明该攻击通过一个 5 行的跨度程序仅使用 5 个贝尔态,展示了其可行性。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。