Security of a storage device against a tampering adversary has been a well-studied topic in classical cryptography. Such models give black-box access to an adversary, and the aim is to protect the stored message or abort the protocol if there is any tampering. In this work, we extend the scope of the theory of tamper detection codes against an adversary with quantum capabilities. We consider encoding and decoding schemes that are used to encode a $k$-qubit quantum message $\vert m\rangle$ to obtain an $n$-qubit quantum codeword $\vert {\psi_m} \rangle$. A quantum codeword $\vert {\psi_m} \rangle$ can be adversarially tampered via a unitary $U$ from some known tampering unitary family $\mathcal{U}_{\mathsf{Adv}}$ (acting on $\mathbb{C}^{2^n}$). Firstly, we initiate the general study of \emph{quantum tamper detection codes}, which detect if there is any tampering caused by the action of a unitary operator. In case there was no tampering, we would like to output the original message. We show that quantum tamper detection codes exist for any family of unitary operators $\mathcal{U}_{\mathsf{Adv}}$, such that $\vert\mathcal{U}_{\mathsf{Adv}} \vert < 2^{2^{\alpha n}}$ for some constant $\alpha \in (0,1/6)$; provided that unitary operators are not too close to the identity operator. Quantum tamper detection codes that we construct can be considered to be quantum variants of \emph{classical tamper detection codes} studied by Jafargholi and Wichs~['15], which are also known to exist under similar restrictions. Additionally, we show that when the message set $\mathcal{M}$ is classical, such a construction can be realized as a \emph{non-malleable code} against any $\mathcal{U}_{\mathsf{Adv}}$ of size up to $2^{2^{\alpha n}}$.
翻译:存储设备对抗篡改敌手的安全性一直是经典密码学中深入研究的课题。此类模型赋予敌手黑盒访问权限,其目标是保护存储消息,或在发生任何篡改时中止协议。在本工作中,我们将篡改检测码理论的范围扩展至具备量子能力的敌手。考虑用于编码$k$量子比特量子消息$\vert m\rangle$以得到$n$量子比特量子码字$\vert {\psi_m} \rangle$的编码与解码方案。量子码字$\vert {\psi_m} \rangle$可能通过某个酉算子$U$(作用于$\mathbb{C}^{2^n}$)受到来自已知篡改酉算子族$\mathcal{U}_{\mathsf{Adv}}$的敌手篡改。首先,我们开创性地研究了\emph{量子篡改检测码}的一般理论,该检测码能够检测是否因酉算子作用而引发任何篡改。若未发生篡改,我们期望输出原始消息。我们证明:对于任意酉算子族$\mathcal{U}_{\mathsf{Adv}}$,若存在常数$\alpha \in (0,1/6)$使得$\vert\mathcal{U}_{\mathsf{Adv}} \vert < 2^{2^{\alpha n}}$,且酉算子与恒等算子不充分接近,则量子篡改检测码存在。我们所构造的量子篡改检测码可视为Jafargholi与Wichs~['15]研究的\emph{经典篡改检测码}的量子变体,后者亦已知在类似限制下存在。此外,我们证明当消息集$\mathcal{M}$为经典时,此类构造可实现为针对任意规模至多$2^{2^{\alpha n}}$的$\mathcal{U}_{\mathsf{Adv}}$的\emph{非恶意编码}。