Skip to main content
QUICK REVIEW

[论文解读] Privacy Amplification Against Active Quantum Adversaries

Gil Cohen, Thomas Vidick|arXiv (Cornell University)|Aug 22, 2016
Cryptography and Data Security参考文献 26被引用 3
一句话总结

本文首次提出了在面对主动量子攻击者时仍保持安全的隐私放大协议,通过证明Dodis-Wichs两轮协议在其非可修改提取器组件为量子安全时的安全性。本文引入了量子安全的非可修改提取器,并表明Chattopadhyay等人近期构造的一种变体满足该性质,从而实现了对量子侧信息的无条件安全。

ABSTRACT

Privacy amplification is the task by which two cooperating parties transform a shared weak secret, about which an eavesdropper may have side information, into a uniformly random string uncorrelated from the eavesdropper. Privacy amplification against passive adversaries, where it is assumed that the communication is over a public but authenticated channel, can be achieved in the presence of classical as well as quantum side information by a single-message protocol based on strong extractors. In 2009 Dodis and Wichs devised a two-message protocol to achieve privacy amplification against active adversaries, where the public communication channel is no longer assumed to be authenticated, through the use of a strengthening of strong extractors called non-malleable extractors which they introduced. Dodis and Wichs only analyzed the case of classical side information. We consider the task of privacy amplification against active adversaries with quantum side information. Our main result is showing that the Dodis-Wichs protocol remains secure in this scenario provided its main building block, the non-malleable extractor, satisfies a notion of quantum-proof non-malleability which we introduce. We show that an adaptation of a recent construction of non-malleable extractors due to Chattopadhyay et al. is quantum proof, thereby providing the first protocol for privacy amplification that is secure against active quantum adversaries. Our protocol is quantitatively comparable to the near-optimal protocols known in the classical setting.

研究动机与目标

  • 填补在窃听者拥有量子侧信息时,针对主动攻击者仍保持安全的隐私放大协议的空白。
  • 将原始设计用于经典侧信息的Dodis-Wichs两轮协议扩展至量子设置。
  • 引入并形式化量子安全非可修改提取器的概念,作为量子攻击者模型下安全性的必要构建模块。
  • 证明Chattopadhyay等人近期提出的非可修改提取器构造满足新引入的量子安全非可修改性,从而实现该设置下的首个安全协议。
  • 实现一个效率与近似最优经典协议相当的协议,确保实际可行性。

提出的方法

  • 通过确保其核心组件——非可修改提取器为量子安全,将Dodis与Wichs针对主动攻击者的两轮协议适配至量子设置。
  • 引入量子安全非可修改提取器的概念,其必须在攻击者持有量子侧信息时仍保持安全。
  • 证明Chattopadhyay等人近期提出的非可修改提取器构造满足量子安全非可修改性条件。
  • 利用非可修改提取器在量子攻击下的安全性,建立隐私放大协议的整体安全性。
  • 利用强提取器及其向非可修改提取器的强化性质,确保对主动篡改和量子侧信息的鲁棒性。
  • 使用信息论技术分析协议的安全性,证明输出字符串在攻击者的量子系统下仍保持均匀随机且不相关。

实验结果

研究问题

  • RQ1Dodis-Wichs两轮隐私放大协议能否在攻击者拥有量子侧信息时仍保持安全?
  • RQ2非可修改提取器需满足何种额外性质,才能确保在量子攻击者存在时的安全性?
  • RQ3是否存在已知的非可修改提取器构造,满足新引入的量子安全非可修改性概念?
  • RQ4能否构建一个效率与经典近似最优协议相当的量子安全隐私放大协议?
  • RQ5在主动量子设置中,仍能实现信息论安全的攻击者能力最小假设是什么?

主要发现

  • 当所用非可修改提取器为量子安全时,Dodis-Wichs两轮协议对主动攻击者仍保持安全。
  • 正式定义了量子安全非可修改提取器的概念,并证明其足以在量子攻击者模型下实现安全。
  • 对Chattopadhyay等人非可修改提取器构造的一种变体被证明为量子安全,提供了具体的实例化。
  • 由此产生的协议实现了对主动量子攻击者的无条件安全,是该设置下的首个此类协议。
  • 协议的效率在定量上与近似最优经典协议相当,表明其具有强大的实际可行性。
  • 安全证明依赖于信息论技术,即使攻击者控制公共信道并持有量子侧信息,该证明依然成立。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。