Pith. sign in

REVIEW

A classical one-way function to confound quantum adversaries

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv quant-ph/0701115 v2 pith:63D5XIKJ submitted 2007-01-17 quant-ph

A classical one-way function to confound quantum adversaries

classification quant-ph
keywords problemquantumfunctionhiddensubgroupclassicalhardinverting
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved
0 comments
read the original abstract

The promise of quantum computation and its consequences for complexity-theoretic cryptography motivates an immediate search for cryptosystems which can be implemented with current technology, but which remain secure even in the presence of quantum computers. Inspired by recent negative results pertaining to the nonabelian hidden subgroup problem, we present here a classical algebraic function $f_V(M)$ of a matrix $M$ which we believe is a one-way function secure against quantum attacks. Specifically, inverting $f_V$ reduces naturally to solving a hidden subgroup problem over the general linear group (which is at least as hard as the hidden subgroup problem over the symmetric group). We also demonstrate a reduction from Graph Isomorphism to the problem of inverting $f_V$; unlike Graph Isomorphism, however, the function $f_V$ is random self-reducible and therefore uniformly hard. These results suggest that, unlike Shor's algorithm for the discrete logarithm--which is, so far, the only successful quantum attack on a classical one-way function--quantum attacks based on the hidden subgroup problem are unlikely to work. We also show that reconstructing any entry of $M$, or the trace of $M$, with nonnegligible advantage is essentially as hard as inverting $f_V$. Finally, $f_V$ can be efficiently computed and the number of output bits is less than $1+\epsilon$ times the number of input bits for any $\epsilon > 0$.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.