Skip to main content
QUICK REVIEW

[论文解读] The Quantum Cut-and-Choose Technique and Quantum Two-Party Computation

Elham Kashefi, Luka Music|arXiv (Cornell University)|Mar 10, 2017
Cryptography and Data Security参考文献 25被引用 8
一句话总结

本文提出了量子计算剪裁-选择(QC-CC)技术,以实现对量子隐蔽敌手的安全两方量子计算,利用测量型量子计算中的经典控制与量子资源分离。该技术实现安全性的条件为单向离线量子通信、仅服务器需要量子能力,且仅使用最少的密码学原原子,通过Watous与Unruh的量子重播技术在安全证明中构造模拟器。

ABSTRACT

The application and analysis of the Cut-and-Choose technique in protocols secure against quantum adversaries is not a straightforward transposition of the classical case, among other reasons due to the difficulty to use rewinding in the quantum realm. We introduce a Quantum Computation Cut-and-Choose (QC-CC) technique which is a generalisation of the classical Cut-and-Choose in order to build quantum protocols secure against quantum covert adversaries. Such adversaries can deviate arbitrarily provided that their deviation is not detected. As an application of the QC-CC we give a protocol for securely performing two-party quantum computation with classical input/output. As basis we use secure delegated quantum computing (Broadbent et al 2009), and in particular the garbled quantum computation of (Kashefi et al 2016) that is secure against only a weak specious adversaries, defined in (Dupuis et al 2010). A unique property of these protocols is the separation between classical and quantum communications and the asymmetry between client and server, which enables us to sidestep the quantum rewinding issues. This opens the prospect of using the QC-CC to other quantum protocols with this separation. In our proof of security we adapt and use (at different parts) two quantum rewinding techniques, namely Watrous' oblivious q-rewinding (Watrous 2009) and Unruh's special q-rewinding (Unruh 2012). Our protocol achieves the same functionality as in previous works (e.g. Dupuis et al 2012), however using the QC-CC technique on the protocol from (Kashefi et al 2016) leads to the following key improvements: (i) only one-way offline quantum communication is necessary , (ii) only one party (server) needs to have involved quantum technological abilities, (iii) only minimal extra cryptographic primitives are required, namely one oblivious transfer for each input bit and quantum-safe commitments.

研究动机与目标

  • 为解决经典剪裁-选择技术在量子协议中难以适用的问题,因标准重播技术在量子测量塌缩下失效。
  • 设计一种安全的两方量子计算协议,支持经典输入输出,可抵御低检测概率的量子隐蔽敌手。
  • 通过仅让一方(服务器)具备量子能力,最小化量子技术需求,使客户端仅执行经典计算与单量子比特制备任务。
  • 通过仅使用每输入比特一个无条件安全的不经意传输和量子安全承诺,减少对复杂经典密码学原原子的依赖。
  • 在单一协议中集成并应用量子重播技术——特别是Watous与Unruh的方法——以构建安全证明中的模拟器。

提出的方法

  • 利用测量型量子计算中经典控制与量子资源的分离(如量子门 teleportation)特性,实现客户端-服务器模型的委托量子计算。
  • 通过在量子混淆电路协议中随机选择检查图或评估图,应用QC-CC技术,确保偏差行为以高概率被检测。
  • 使用Watous的无条件量子重播技术,模拟敌手在抛硬币阶段的行为,确保模拟器可偏置评估图的选择。
  • 在不经意传输与承诺阶段的模拟中采用Unruh的特殊量子重播技术,实现真实世界与理想世界之间的不可区分性。
  • 构建一个模拟器,通过承诺虚假图、利用重播技术偏置抛硬币过程,并在解承诺密钥后才解密输出,以模拟真实协议。
  • 依赖量子安全承诺和每输入比特一次的不经意传输,以在量子攻击下维持安全性。

实验结果

研究问题

  • RQ1能否将经典剪裁-选择技术推广至量子环境,以保护两方量子计算免受量子隐蔽敌手的攻击?
  • RQ2当标准量子重播技术不适用时,如何在量子环境下证明安全性?可适配哪些量子重播技术?
  • RQ3量子计算模型在多大程度上可被分解为经典控制与量子资源,以降低量子硬件需求?
  • RQ4能否设计一种仅需单向离线量子通信和最少经典密码学原原子的两方量子协议?
  • RQ5是否可能仅让一方具备量子能力,而另一方保持经典计算能力,从而实现对量子隐蔽敌手的安全性?

主要发现

  • QC-CC技术成功将经典剪裁-选择推广至量子领域,实现了在量子隐蔽敌手模型下的安全两方量子计算。
  • 该协议仅需单向离线量子通信,与以往双向协议相比,显著降低了量子通信开销。
  • 仅服务器需要量子能力;客户端可离线准备单量子比特,从而实现实用的委托计算模型。
  • 安全性仅依赖每输入比特一个不经意传输和量子安全承诺,极大减少了对复杂经典原原子的依赖。
  • 该协议在模拟器的不同阶段同时使用Watous与Unruh的量子重播技术,是首次在单一协议中实现双重量子重播的应用。
  • 模拟器在抛硬币阶段的每次重播成功概率为$\frac{1}{s}$,期望重播次数为$\tilde{O}(ns)$,确保模拟误差可忽略。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。