arXiv論文メモ
新着一覧
quant-ph / cs.CR · 査読状況未確認

信頼できない量子装置で漏えいに耐える秘密選択通信を構成

Robust and leakage-resilient device-independent oblivious transfer in MiniQCryp

Zhili Chen, Rahul Jain, YaoNan Zhang

この論文をやさしく読む

ひとことで言うと

量子装置の内部を信頼しなくても、相手の選択を隠す通信やビットの事前確約を安全に行うための、条件付きの理論構成です。

何に役立つ?

信頼できない量子装置を使う暗号の、安全性と故障・漏えいへの耐性を設計する基礎になります。

この研究の面白いところ

装置の故障と実験室間の量子情報漏えいを二つの条件に分け、同じプロトコルの骨格で扱っています。装置実行を変えずに安全性証明の抽出を行う点も述べられています。

どこまで分かった?

耐量子一方向関数の仮定、分離や測定の条件、漏えい量と故障率の制限があります。安全性は中止を許し、構成全体では静的侵害を対象とします。実機での速度や耐故障実験の報告ではありません。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

耐量子一方向関数を仮定し、デバイス独立(DI)な紛失通信(OT)とビットコミットメントを構成する。正直な当事者は、信頼できる古典計算だけを用いて、信頼できない量子装置を操作する。装置は任意の量子もつれを共有してよく、独立同分布でない挙動も許す。安全性は、量子多項式時間の攻撃者に対するシミュレーションに基づくもので、効率的なシミュレーターを伴い、逐次合成が可能である。 一つのプロトコル骨格が、二つの条件領域で両方式を実現する。実験室が分離され、正直な受信者の装置が座標ごとに局所的な測定を行う場合には、正直な装置の故障が一定割合で生じても耐える。実験室間に適応的に漏れる量子ビット数が多重対数個で、任意の共同測定を許す場合には、多重対数の逆数の割合の故障に耐える。基本的なDI呼び出しごとに、多重対数個の装置座標からなる新しい分離バッチを用い、構成されたOTプロトコルの装置使用総量は多項式となる。 コミットメントは双方の当事者に対する効率的なシミュレーターを持ち、中止を許すDIコイントスを実現する。OTは安全な計算に対して完全なので、この構成は、当事者数を固定した場合の効率的に計算可能な任意の古典的機能について、中止を許すDIプロトコルを与える。全員ではない任意の部分集合が静的に侵害される場合にも安全である。 コミットメントの抽出器は、古典的な開示内容の切り替えによって公開パリティ関係を変えるが、装置の実行、したがって漏えいは変えない。コミット・証明機能、互いに重ならない監査、アフィン整合性検査により、認証された相関を理想的なOTへ結び付ける。送信者の安全性は、選択器を考慮したMagic Squareゲームの並列反復上界に基づき、これをKunduとTanの2ラウンド閾値定理から導く。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-10-01(UTC)
最新改訂
2026-10-01 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Assuming post-quantum one-way functions, we construct device-independent (DI) oblivious transfer (OT) and bit commitment: honest parties use only trusted classical computation to operate untrusted quantum devices, which may share arbitrary entanglement and behave non-IID. Security is simulation-based against quantum polynomial-time adversaries and composes sequentially with efficient simulators. One protocol skeleton serves both, in two regimes. With isolated laboratories and coordinate-local measurements in the honest receiver's device, it tolerates a constant rate of honest-device faults. With polylogarithmically many qubits of adaptive leakage between the laboratories and arbitrary joint measurements, it tolerates an inverse-polylogarithmic rate. Each elementary DI call uses a fresh, isolated batch of polylogarithmically many device coordinates, and total device use in the compiled OT protocol is polynomial. The commitment has efficient simulators against both parties and yields DI coin tossing with abort. Because OT is complete for secure computation, the construction yields a DI protocol, with abort, for every efficiently computable classical functionality on a fixed number of parties, secure against static corruption of any proper subset of them. The commitment's extractor changes a public parity relation through classical equivocation and leaves the device execution, hence its leakage, unchanged. A commit-and-prove functionality, disjoint audits, and an affine consistency check link the certified correlations to ideal OT. Sender security rests on a selector-aware parallel-repetition bound for the Magic Square game, which we derive from the two-round threshold theorem of Kundu and Tan.

arXiv ID: 2610.01421 / 要約の誤りについて