量子性の証明にゼロ知識性を加える方法
Zero-Knowledge Proofs of Quantumness
この論文をやさしく読む
ひとことで言うと
量子計算を行ったと示す証明で、検証者が量子側から余計な情報を引き出さない条件を定義した。
何に役立つ?
量子性の証明手順を安全に設計・評価する理論的な指針になる。要旨は具体的な実機での検証を報告していない。
この研究の面白いところ
検証者側にも古典的なゼロ知識証明を要求し、既存の二つの方式を変換できると示した。
どこまで分かった?
変換できるのは要旨で挙げた既存方式の一部であり、量子性証明の全方式が自動的に安全になるとは述べていない。
v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。
アブストラクトの日本語訳
量子コンピューターの進展とともに、計算が量子的であることの証明が注目されている。しかし現在の方式では、古典的な検証者が悪意を持つと、量子的な証明者を利用できる危険がある。検証者が相互作用で不正な戦略を使い、利用する方式に由来する難しい問題の一部を解いてしまう可能性がある。これは、検証者が有用な情報を取り出すことを防ぐ形式化が欠けているためである。著者らは、この問題に対して量子性のゼロ知識証明を形式化する。直感的には、古典的検証者が量子的証明者とのやり取りで得る情報は、同じ検証者と相互作用する模擬的な古典的証明者を用いて再現できる情報を超えてはならない。この性質により、悪意のある検証者が量子的な優位性を利用することを防げる。著者らは、古典的なゼロ知識証明を使えば、既存の量子性証明方式の一部をゼロ知識型へ変換できると見いだす。証明者側ではなく検証者側にゼロ知識証明を要求する方が一般性が高いと考えられ、悪意のある検証者の振る舞いを、規則に従うが情報を得ようとする振る舞いへ制限する。このため両者は、量子性の証明での役割に加え、古典的なゼロ知識証明では逆の役割も担う。具体的には、Shorの素因数分解に基づく方式と、Brakerskiらが2018年に示したLearning With Errorsに基づく方式で、検証者側へ抽出可能な非対話型ゼロ知識論証を要求することで変換できる。量子性のゼロ知識証明は、量子性証明の安全性を強めた概念と見なせる。
v1の要旨から自動生成。本文の精読・人による確認は未実施。
- 初稿
- 2026-09-20(UTC)
- 最新改訂
- 2026-09-20 · v1
- 査読・掲載
- 掲載先の記載あり
著者による掲載先の記載:IACR Communications in Cryptology, vol. 1, no. 4, 2025。出版社での独立確認は未実施です。
更新履歴
- v1 2026-09-20 この版を読む
取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。
原文の要旨
With the rapid development of quantum computers, proofs of quantumness have recently become an interesting research direction. However, in current schemes for proofs of quantumness, quantum provers face the risk of being maliciously exploited by classical verifiers. Through malicious strategies in interaction with quantum provers, classical verifiers could solve some instances of hard problems that arise from the specific scheme in use. This is due to the lack of formalization that prevents malicious verifiers from extracting useful information in proofs of quantumness. To address this issue, we formalize zero-knowledge proofs of quantumness. Intuitively, the zero-knowledge property necessitates that the information gained by the classical verifier from interactions with the quantum prover should not surpass what can be simulated using a simulated classical prover interacting with the same verifier. As a result, the new zero-knowledge notion can prevent a malicious verifier from exploiting quantum advantage. We find that the classical zero-knowledge proof is sufficient to compile some existing proofs of quantumness schemes into zero-knowledge proofs of quantumness schemes. It appears to be more general to require zero-knowledge proof on the verifier side instead of the prover side. This helps to regulate the verifier's behavior from malicious to be honest-but-curious. As a result, both parties will play not only one role in the proofs of quantumness but also the dual role in the classical zero-knowledge proof. Specifically, Shor's factoring-based scheme and the learning with errors-based scheme in [Brakerski et al., FOCS, 2018] can be transformed into zero-knowledge proofs of quantumness by requiring an extractable non-interactive zero-knowledge argument on the verifier side. Zero-knowledge proofs of quantumness can thus be viewed as an enhanced security notion for proofs of quantumness.
著者のコメント
19 pages, 8 figures. Published in IACR Communications in Cryptology
arXiv ID: 2609.23455 / 要約の誤りについて