{"id":"271f3ab9-61f5-49e6-90df-221377183c0e","arxiv_id":"2510.08079","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":8.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A modular watermarking-based compiler yields the first classical-lessor quantum key leasing schemes for PRFs and signatures, plus an encryption scheme with VRA security, all under LWE.","lead":"Secure key leasing lets a quantum key be lent out and later revoked with a verifiable proof of deletion. This paper shows a fully classical owner can do this for encryption, pseudorandom functions, and digital signatures, and gives the first such schemes for the latter two from the LWE assumption.","discovery_kind":"new_method","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Central construction hinges on the unverified LWE realization of special dual-mode SFE (Def. 4.1); if its non-standard coherent-state, unique-state, and decomposable-state properties fail, all three SKL schemes collapse.","rationale":"The reader identified the same fragile point. I agree: the special dual-mode SFE is the linchpin. The good news is that the rest of the proof structure is modular and the hybrid arguments are fairly explicit; there is independent support in the form of the detailed reductions to NTCF cut-and-choose, and the construction is parameter-free. The concern is not an internal contradiction in the security proofs but a missing verification of the most non-standard building block. The DS/SIS issue is secondary but worth an erratum: the abstract's blanket 'under LWE' should either be qualified or accompanied by a reduction. Because the key concern is with the deferred Appendix A proof, the verdict should remain CONDITIONAL: accept if Appendix A verifies; otherwise require revision.","tokens_in":65321,"tokens_out":14570,"duration_ms":129257,"concrete_test":"Independently verify Appendix A's construction: work out the receiver algorithm of the PVW08-based dual-mode OT and check (a) for all (crs, x, msg^(1)) in the hiding mode there is a unique st, and (b) the coherent Rec1 can be implemented as an isometry storing st and measuring msg^(1) with the randomness register returned to |0>. Concretely, compute the collision probability over LWE randomness of two distinct st for the same (x, msg^(1)); if collisions are non-negligible, Unique state fails. If this check does not go through, re-derive the deletion-verification equation in Theorem 6.1 with a non-unique state and see whether DelVrfy still accepts honest deletions with overwhelming probability.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The compiler's key-generation step (Section 6.1, IntKeyGen) requires SFE.Rec1 to be applied coherently to a superposition of NTCF preimages, producing a state with no residual randomness, and later requires the state st to be uniquely determined by and recoverable/decomposable from (crs, x, msg^(1)) via StaRcv. These are non-standard properties for an SFE/OT. A standard LWE dual-mode OT (e.g., PVW08) has a receiver state (the LWE secret) that is not obviously uniquely determined by (x, msg^(1)), and its coherent application risks entanglement with sampling randomness. The paper defers the proof to Appendix A, which is not present in the supplied text; Theorem 4.2 is asserted without a visible derivation. Since every construction (PKE, PRF, DS) and every security reduction (Theorems 6.2, 7.2, 8.2) imports this SFE, failure of any one of these properties invalidates the main claim. A secondary inconsistency: the DS scheme also relies on SIS-based coherently-signable constrained signatures (Lemma 2.9), so the abstract's 'under LWE' is not justified for DS unless a separate LWE-to-SIS route is supplied.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes a modular framework for constructing secure key leasing (SKL) with a fully classical lessor. The key idea is to compile any parallel-extractable watermarkable cryptographic functionality (PKE, UPF/PRF, or digital signature) into a classical-lessor SKL scheme using two lattice-based tools: noisy trapdoor claw-free functions (NTCF) and a non-standard 'special dual-mode secure function evaluation' (SFE), together with a cut-and-choose adaptive hardcore bit lemma. The authors claim PKE-SKL, PRF-SKL, and DS-SKL, all satisfying VRA security, under LWE. The PKE construction is given with a detailed hybrid proof; the PRF and DS constructions are presented in the body, and the LWE realization of the special SFE is deferred to Appendix A. A non-interactive key-generation variant of PKE-SKL is also given.","tokens_in":65686,"tokens_out":11599,"duration_ms":104792,"significance":"If the claims are correct, this is a substantial contribution: it unifies several ad hoc SKL constructions, gives the first classical-lessor PRF-SKL and DS-SKL schemes, achieves VRA security, and obtains non-interactive key generation for PKE-SKL. The modular watermarking-based compiler is elegant and the explicit use of parallel mark extractability is a genuine technical simplification over prior preimage-extraction arguments. The paper also credits and cleanly reuses known building blocks (NTCF, TEPRF, constrained signatures), and the PKE-SKL security proof is detailed. The main caveats are that the central SFE tool is non-standard and its LWE realization is not verifiable from the submitted text, and that the DS scheme actually rests on SIS rather than a pure LWE assumption.","major_comments":[{"comment":"Definition 4.1 is the linchpin of the entire framework. The compiler (Section 6.1, IntKeyGen) requires SFE.Rec1 to be applied coherently to an NTCF superposition with no residual entanglement with the receiver's randomness, and later requires the unique-state and state-recoverability properties in the hiding mode. These are not standard properties of dual-mode OT/SFE and cannot be taken for granted. The only support is Theorem 4.2, whose proof is deferred to Appendix A. In the reviewed manuscript, Appendix A is listed in the table of contents but is not included in the supplied text, so the construction and proof of these properties cannot be checked. Since every scheme (PKE-SKL, PRF-SKL, DS-SKL) and every security proof (Theorems 6.2, 7.2, 8.2) imports this SFE, this is a load-bearing omission. Please provide the full appendix, or an explicit construction and proof in the main text.","section":"Section 4, Definition 4.1 and Theorem 4.2"},{"comment":"The abstract states that all three schemes are proven under LWE. However, the DS-SKL construction uses watermarkable digital signatures whose construction (Section 3.3) relies on coherently-signable constrained signatures. Lemma 2.9, cited from [KMY25], assumes SIS with a subexponential modulus-to-target-norm-bound ratio. No LWE-to-SIS implication is stated or proved. Thus, as written, the DS result is at best under SIS (together with LWE for the NTCF/SFE), not under LWE alone. The same applies to Table 3. This is a load-bearing overclaim and should be corrected in the abstract, introduction, and theorem statements.","section":"Abstract and Section 3.3 / Lemma 2.9"},{"comment":"As typeset, the cut-and-choose experiment in Lemma 2.12 sends the adversary the trapdoors {td_i}_{i∈S} for the injective-mode positions S in Step 5, while Step 6 asks for preimages x_i for exactly those positions. With the trapdoors in hand, the adversary can trivially run Invert(pp_i,td_i,y_i) and win with probability 1, making the stated lemma false. Moreover, the reduction in Lemma 6.4 needs the trapdoors for the two-to-one positions S̄ in order to form the deletion verification key dvk. I suspect this is a typesetting/OCR inconsistency and the intended set is {td_i}_{i∈S̄}, but as written the lemma is internally inconsistent. Please fix the notation and check all subsequent applications.","section":"Lemma 2.12 and Lemma 6.4"}],"minor_comments":[{"comment":"The algorithm tuple is written as '(IntKeyGen,Enc,Dec,Dec,Del,DelVrfy)' with 'Dec' appearing twice. This should be cleaned up to distinguish the lessor's decryption algorithm from the lessee's quantum decryption algorithm.","section":"Definition 5.1"},{"comment":"The proof uses 'Exppar-pre' and 'Exppar-ow' inconsistently when referring to the parallel one-way inversion game. This is a naming typo but should be harmonized for readability.","section":"Section 3.1, Theorem 3.1 proof"},{"comment":"In the reduction's Step 4, the text refers to 'WPKE.dk_i(x_i)' and 'WPKE.msk_i' in a WUPF context; these should be WUPF.key_i(x_i) and WUPF.msk_i. The proof is understandable, but the notation is confusing.","section":"Section 7.2, Lemma 7.3"},{"comment":"The special SFE is introduced as 'SFE=SFE.(Rec1,Send,Rec2)' but Definition 4.1 includes CRSGen as a fourth algorithm. The ingredient list should include CRSGen to avoid ambiguity.","section":"Section 6.1, ingredient list"}],"recommendation":"major_revision","confidential_remarks":"This is a promising paper whose modular approach and claimed results are significant. The decision hinges on the availability and correctness of the deferred Appendix A construction of the special dual-mode SFE, and on correcting the SIS versus LWE attribution in the DS claim. If the appendix is complete and the notation in Lemma 2.12 is fixed, the paper may become acceptable."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"First, the punchline: if Theorem 4.2's special SFE holds, this is a genuinely useful paper—the first PRF and digital-signature SKL schemes with a classical lessor, plus a PKE-SKL that gets VRA security and non-interactive key generation. The modular compiler (parallel-extractable watermarking + NTCF + dual-mode SFE) is a real conceptual step beyond the ad hoc CGJL25 construction. The PKE proof in the main body is detailed and the hybrid structure is legible; the watermarkable UPF and DS constructions with equivocality to handle evaluation/signing oracles are shown in the text, not hand-waved. Credit where due.\n\nThe soft spots are two, in different sizes.\n\nFirst, the special SFE (Def 4.1) is load-bearing: efficient state superposition and decomposable state recoverability are not standard SFE/OT properties. The paper asserts Theorem 4.2 and defers the proof to Appendix A, which is not present in the version I read. The claimed extension of the PVW08 dual-mode OT is plausible, but 'coherent Rec1 without residual entanglement' and 'state uniquely determined and decomposable' are exactly where such constructions tend to break. This is not a demonstrated flaw, but it is a real verification gap. A referee needs to see that appendix before accepting the main claim.\n\nSecond, and visible in the text itself: the abstract and the comparison table say the DS scheme is 'under LWE,' but the watermarkable DS is built from watermarkable UPF (from OWFs) plus coherently-signable constrained signatures from SIS (Lemma 2.9). The paper even says the WDS construction 'can be constructed from SIS.' No LWE-to-SIS bridge is provided. So the DS claim is overstated; either the theorem statement and abstract need to be corrected to 'SIS,' or an LWE-to-SIS route needs to be supplied. This is minor in the sense that it doesn't invalidate the DS construction, but it does misstate the assumption.\n\nOn the reader's 'fragile premise' worry: I don't think the SFE concern is a reason to desk-reject—deferred appendices are the norm. But it is exactly the kind of thing a serious referee should pin down. If Appendix A delivers the stated properties, the central argument holds up.\n\nThis paper is for lattice/crypto theorists working on quantum revocation. It deserves serious peer review. I'd send it to a strong referee, with instructions to check the SFE appendix and the DS assumption typo.","headline":"Strong modular SKL paper with real firsts, but the DS 'under LWE' claim overreaches and the load-bearing SFE construction is deferred to a missing appendix.","tokens_in":66161,"tokens_out":3229,"would_cite":true,"duration_ms":29683,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"A classical lessor can lease, use, and verifiably revoke quantum keys for public-key encryption, pseudorandom functions, and digital signatures, all under the learning-with-errors assumption.","keywords":["secure key leasing","classical lessor","quantum key revocation","VRA security","noisy trapdoor claw-free functions","dual-mode secure function evaluation","watermarking","LWE assumption"],"falsifier":"Exhibit an explicit LWE instantiation of the special dual-mode SFE and show either that state recoverability fails for some adversarially chosen first message, or that the coherent version of Rec1 leaves entanglement with the randomness; either would break the deletion-verification step. Alternatively, construct a quantum adversary that passes deletion verification and then decrypts the PKE-SKL challenge ciphertext with non-negligible probability while LWE remains hard.","tokens_in":65249,"feed_emoji":"🔐","tokens_out":3438,"duration_ms":34563,"temperature":0.7,"pith_summary":"The paper claims a modular framework for secure key leasing in which the lessor is entirely classical: both the leasing and the revocation of a quantum secret key happen over classical communication. It shows that any post-quantum IND-CPA public-key encryption scheme can be upgraded to a PKE-SKL scheme, and it constructs the first classical-lessor PRF-SKL and DS-SKL schemes. All three schemes are proven secure against verification-key revealing attacks (VRA security) under the LWE assumption. The central step is to make the lessee prepare the unclonable BB84-style quantum key from purely classical data, then verify deletion through the cut-and-choose adaptive hardcore bit property of NTCF functions and the parallel extractability of watermarking.","feed_headline":"Classical lessor now leases revocable quantum keys for PKE, PRF, and signatures","feed_subtitle":"One modular compiler upgrades any watermarkable primitive to a key-leasing scheme, all proven under LWE.","key_machinery":"The load-bearing object is a special dual-mode secure function evaluation (SFE) with five simultaneous properties: mode indistinguishability, statistical security against malicious senders in the hiding mode, state recoverability in the hiding mode, extractability in the extraction mode, and an efficient state superposition property with decomposable states. The decomposability identity c_i·(st0⊕st1) = d*_i·(a0⊕a1) is what lets the verifier convert a deletion certificate into a hardcore-bit relation, while the watermarking parallel-extraction property converts a successful decryptor into the computational-basis preimages. These two together contradict the cut-and-choose adaptive hardcore bit","core_discovery":"The paper's central claim is a compiler that transforms any cryptographic primitive equipped with parallel-extractable watermarking into a classical-lessor SKL scheme, provided the primitive's functionality is preserved under parallel composition. The compiler uses a cut-and-choose split: some positions use injective-mode NTCF functions so the quantum key contains a single preimage, while others use two-to-one mode so the key contains a superposition of two preimages; a special dual-mode SFE lets the lessee build the quantum key from a claw state. Deletion verification works because a valid deletion certificate in the Hadamard basis, combined with preimages extracted from a successful decryp","pith_inferences":["The compiler suggests a general recipe for classical-client quantum delegation: if a functionality has a watermarkable key and parallel composition, it can be leased and revoked with a classical lessor, so analogous schemes for ABE, FHE, or functional encryption may follow once watermarkable variants exist.","The special dual-mode SFE properties, especially efficient state superposition and decomposable states, could be reused to build classical-client blind state preparation with negligible security, bypassing the inverse-polynomial barrier of generic RSP protocols.","The cut-and-choose structure might be adaptable to collusion-resistant leasing: if parallel mark extraction can tolerate multiple copies per position, the same framework may yield schemes that support an a-priori bounded number of leased keys.","The reliance on LWE is partly structural (NTCF and special SFE) and partly for the watermarkable signatures; replacing the signature watermarking with a post-quantum OWF-based construction would still require SIS for the coherently-signable constrained signatures, so a fully OWF-based DS variant seems unlikely."],"forward_implications":["Any post-quantum IND-CPA PKE can be made revocable with a fully classical lessor under LWE, without changing the underlying encryption scheme.","The first classical-lessor PRF-SKL and DS-SKL schemes exist; for signatures, both signing key and signature size stay polynomial and independent of the number of issued signatures.","PKE-SKL achieves non-interactive quantum key generation with a classical lessor, a property not achieved by prior classical-lessor constructions.","VRA security holds for all three schemes, meaning the deletion verification key can be leaked after a valid deletion certificate without breaking revocation.","The framework is generic: any primitive with parallel-extractable watermarking that is closed under parallel composition can be upgraded to classical-lessor SKL via the same compiler."],"fun_headline_variants":["Quantum keys, classical lessor: revocable for PKE, PRF, and signatures","Unified classical-lessor key leasing: PKE, PRF, and signatures under LWE","First classical-lessor key leasing for PRFs and signatures, plus PKE","Classical lessor, quantum revocation: unified for PKE, PRF, and signatures"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"Everything rests on the LWE-based construction of the special dual-mode SFE satisfying all five required properties simultaneously, most crucially that the receiver's state decomposes bitwise and can be prepared in superposition without residual entanglement with the randomness; if this one construction fails any property, the entire compiler collapses.","fun_headline_variants_meta":{"raw":{"variants":["Quantum keys, classical lessor: revocable for PKE, PRF, and signatures","Unified classical-lessor key leasing: PKE, PRF, and signatures under LWE","First classical-lessor key leasing for PRFs and signatures, plus PKE","Classical lessor, quantum revocation: unified for PKE, PRF, and signatures"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000968,"raw_usage":{"total_tokens":3943,"prompt_tokens":720,"completion_tokens":3223,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":464,"completion_tokens_details":{"reasoning_tokens":3129}},"tokens_in":464,"tokens_out":3223,"duration_ms":20865,"temperature":1.0,"reasoning_tokens":3129,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-04T10:48:37.322284+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Exhibit an explicit LWE instantiation of the special dual-mode SFE and show either that state recoverability fails for some adversarially chosen first message, or that the coherent version of Rec1 leaves entanglement with the randomness; either would break the deletion-verification step. Alternatively, construct a quantum adversary that passes deletion verification and then decrypts the PKE-SKL challenge ciphertext with non-negligible probability while LWE remains hard.","supporting_citations":[],"review_version":1}