arXiv論文メモ
新着一覧
quant-ph · 査読状況未確認

一方向関数を避ける量子暗号構成への限界

How Not to Build Microcrypt

Aditya Gulati (UCSB), Dakshita Khurana (UIUC and NTT Research), Kabir Tomer (UIUC)

この論文をやさしく読む

ひとことで言うと

一方向関数に依存しない量子暗号を目指した既存の複数の構成でも、実は一方向関数やNP困難性が導かれることを示した理論研究です。

何に役立つ?

新しい擬似乱数量子状態やユニタリ変換の構成を提案するとき、仮定が本当に一方向関数から独立か検討する材料になります。具体的な暗号製品の安全性を評価した研究ではありません。

この研究の面白いところ

NPの助けを借りたシャドウトモグラフィーと学習アルゴリズムを作り、これを既存のPRS・PRU構成の不可能性に関する結果へ結び付けています。

どこまで分かった?

結論は要旨でいう計算可能な純粋状態や分析対象の構成方式についてのものです。すべてのPRS・PRU構成が一方向関数を含意するとは述べていません。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

量子暗号の重要な課題は、量子計算可能な一方向関数を使わずに、量子的一方向性と擬似乱数性を構成することである。これはこれまで難しく、一方向関数から直接作られていない候補は少数しかない。さらに、それらの候補が意図せず一方向関数を導いてしまう条件を分析する手法も不足していた。本研究は、量子状態の効率的なNP補助付きシャドウトモグラフィーを導入する。計算可能な純粋状態の集合は、この方法で学習できることを証明する。ここで状態が計算可能とは、効率的な状態準備回路の記述が与えられたとき、計算基底の任意の項の振幅と位相を古典計算で効率よく求められることをいう。また、ユニタリ変換への多項式個の問い合わせを与えられた場合に、NPを利用してそれを学習する新しいアルゴリズムも示す。 これらの結果に基づき、擬似乱数状態(PRS)と擬似乱数ユニタリ(PRU)の既存の多くの構成方式について、一方向関数を避ける目的で提案されたハミルトニアン位相状態なども含め、実際には一方向関数の存在、またはNP困難性を含意することを示す。著者らは、これらの不可能性に関する結果が、複雑性クラスNPの外にあると考えられる仮定からPRSやPRUを構成する今後の研究に役立つことを期待している。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-24(UTC)
最新改訂
2026-09-24 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

A key challenge in quantum cryptography is to build quantum one-wayness and pseudorandomness without the use of (quantum computable) one-way functions. So far, this has turned out to be a difficult task, with only a few proposed candidates that are not directly built from one-way functions. Even within these few proposed candidates, we have lacked the techniques to analyze when proposed constructions may inadvertently yield one-way functions. In this work, we introduce efficient NP-aided shadow tomography of quantum states. We prove that collections of {\em computable} pure states can be learned via efficient NP-aided shadow tomography, where we say that a state is computable if the amplitude and phase on any computational basis term can be classically efficiently computed given the description of an efficient preparation circuit for the state. We also give new algorithms for NP-aided learning of unitaries given polynomially many queries to the unitary. By building on this, we show that many existing architectures for PRS and PRU, including some that were explicitly introduced for the purposes of avoiding one-way functions (e.g., Hamiltonian Phase States, Bostanci et. al., TQC 2025), actually do imply the existence of one-way functions or imply \(\NP\) hardness. We hope that these no-go results will inform future investigations into building PRS and PRUs from assumptions that are plausibly outside the complexity class NP.

arXiv ID: 2609.30253 / 要約の誤りについて