论文标题
最佳世界世界多党量子计算,可公开可识别的堕胎
Best-of-Both-Worlds Multiparty Quantum Computation with Publicly Verifiable Identifiable Abort
论文作者
论文摘要
Alon等。 (Crypto 2021)引入了一种多阶量子计算方案,该协议具有可识别的流产(MPQC-SWIA)。但是,他们的协议仅允许在MPQC政党内部了解恶意玩家的身份。当两组人不同意并且需要像陪审团这样的第三方来验证恶意政党是谁时,这变得有问题。鉴于量子状态可能仅在一个副本中存在,因此此问题在量子设置中具有更高的意义。因此,我们强调了具有公开可识别的堕胎(PVIA)的协议的必要性,使只有经典计算能力的外部观察者能够在失败的情况下就恶意政党的身份达成一致。然而,由于无关定理,使用PVIA实现MPQC构成了重大挑战,Mahadev(Stoc 2018)和Chung等人提出的先前作品。 (Eurocrypt 2022)用于量子计算的经典验证。 在本文中,我们获得了第一个MPQC-PVIA协议,假设量词后传输和经典的广播渠道。我们构造的核心组成部分是一种称为可审计量子身份验证(AQA)的新身份验证原始验证,它以压倒性的概率识别恶意发件人。此外,我们还提供了第一个MPQC协议,其中包括Best-Worlds(BOBW)的安全性,该协议可以保证以诚实的多数席位的输出交付,即使大多数人不诚实,也仍然会在中止堕胎。我们最好的世界MPQC方案也满足流产后的PVIA。
Alon et al. (CRYPTO 2021) introduced a multiparty quantum computation protocol that is secure with identifiable abort (MPQC-SWIA). However, their protocol allows only inside MPQC parties to know the identity of malicious players. This becomes problematic when two groups of people disagree and need a third party, like a jury, to verify who the malicious party is. This issue takes on heightened significance in the quantum setting, given that quantum states may exist in only a single copy. Thus, we emphasize the necessity of a protocol with publicly verifiable identifiable abort (PVIA), enabling outside observers with only classical computational power to agree on the identity of the malicious party in case of an abort. However, achieving MPQC with PVIA poses significant challenges due to the no-cloning theorem, and previous works proposed by Mahadev (STOC 2018) and Chung et al. (Eurocrypt 2022) for classical verification of quantum computation fall short. In this paper, we obtain the first MPQC-PVIA protocol assuming post-quantum oblivious transfer and a classical broadcast channel. The core component of our construction is a new authentication primitive called auditable quantum authentication (AQA) that identifies the malicious sender with overwhelming probability. Additionally, we provide the first MPQC protocol with best-of-both-worlds (BoBW) security, which guarantees output delivery with an honest majority and remains secure with abort even if the majority is dishonest. Our best-of-both-worlds MPQC protocol also satisfies PVIA upon abort.