Skip to main content
QUICK REVIEW

[论文解读] On Quantum Obfuscation

Gorjan Alagic, Bill Fefferman|arXiv (Cornell University)|Feb 4, 2016
Cryptography and Data Security参考文献 28被引用 11
一句话总结

本文首次对量子混淆展开严谨研究,为经典与量子功能定义了多种变体,如黑盒混淆、不可区分性混淆及最优混淆。研究证明,当攻击者可访问多个输出时,量子黑盒混淆是不可能的;统计不可区分性混淆在复杂性理论层面会坍塌,但留下了信息论层面黑盒混淆至单一不可克隆量子态的可能性。

ABSTRACT

Encryption of data is fundamental to secure communication in the modern world. Beyond encryption of data lies obfuscation, i.e., encryption of functionality. It is well-known that the most powerful means of obfuscating classical programs, so-called ``black-box obfuscation',' is provably impossible [Barak et al '12]. However, several recent results have yielded candidate schemes that satisfy a definition weaker than black-box, and yet still have numerous applications. In this work, we initialize the rigorous study of obfuscating programs via quantum-mechanical means. We define notions of quantum obfuscation which encompass several natural variants. The input to the obfuscator can describe classical or quantum functionality, and the output can be a circuit description or a quantum state. The obfuscator can also satisfy one of a number of obfuscation conditions: black-box, information-theoretic black-box, indistinguishability, and best possible; the last two conditions come in three variants: perfect, statistical, and computational. We discuss many applications, including CPA-secure quantum encryption, quantum fully-homomorphic encryption, and public-key quantum money. We then prove several impossibility results, extending a number of foundational papers on classical obfuscation to the quantum setting. We prove that quantum black-box obfuscation is impossible in a setting where adversaries can possess more than one output of the obfuscator. In particular, generic transformation of quantum circuits into black-box-obfuscated quantum circuits is impossible. We also show that statistical indistinguishability obfuscation is impossible, up to an unlikely complexity-theoretic collapse. Our proofs involve a new tool: chosen-ciphertext-secure encryption of quantum data, which was recently shown to be possible assuming quantum-secure one-way functions exist [Alagic et al '16].

研究动机与目标

  • 将量子混淆形式化并严谨分析,作为密码学原原子,将经典混淆概念扩展至量子领域。
  • 探究量子力学是否能实现经典不可行的更强混淆形式,尤其在经典密码学已知不可能性结果的背景下。
  • 探索构造保留功能性的量子混淆器的可行性,即使在面对量子攻击者时也能隐藏敏感实现细节。
  • 利用复杂性理论与信息论工具,识别在量子环境中哪些混淆定义是可能或不可能的。
  • 建立量子混淆与其他密码学原原子(如量子全同态加密与量子货币)之间的联系。

提出的方法

  • 提出量子混淆的正式框架,区分输出量子线路或量子态的混淆器,以及不同混淆条件(黑盒、不可区分性、最优)。
  • 定义量子安全伪随机性与量子态的对称密钥加密,构建量子混淆的基础工具。
  • 应用选定密文安全的量子加密(最近证明在量子安全单向函数下可行)作为不可能性证明中的关键技术工具。
  • 证明当攻击者可获取混淆器的多个输出(即使在同一输入上)时,量子黑盒混淆是不可能的。
  • 证明统计不可区分性混淆在存在量子安全单向函数的假设下,会坍塌至复杂性理论的坍塌。
  • 利用CPTP线路与量子态族的结构,形式化混淆条件并分析其影响。

实验结果

研究问题

  • RQ1量子力学手段能否实现经典或量子程序的黑盒混淆,特别是在输出不可克隆的情况下?
  • RQ2统计不可区分性混淆在量子环境中是否可能?若可能,其复杂性理论后果是什么?
  • RQ3量子混淆能否促成新型密码学原原子,如量子全同态加密或公钥量子货币?
  • RQ4当攻击者可访问多个混淆实例或利用量子态结构时,量子混淆的局限性是什么?
  • RQ5是否存在即使计算型混淆不可行,也具有信息论安全性的量子混淆方案?

主要发现

  • 在攻击者可获取混淆器多个输出(即使在同一输入上)的设置下,量子黑盒混淆是不可能的。
  • 在存在量子安全单向函数的假设下,统计不可区分性混淆在量子环境中不可能实现,因其会导致多项式层次坍塌。
  • 计算不可区分性混淆在量子环境中仍是一个可行候选,尽管未提供显式构造。
  • 本研究证明,在存在量子计算不可区分性混淆器的假设下,QMA的量子见证加密是可行的。
  • 结果留下了信息论安全黑盒混淆至单一不可克隆量子态的可能性,暗示混淆领域可能存在量子优势。
  • 量子混淆可能显著强于经典混淆,特别是当不可克隆量子态可作为混淆程序时。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。