Lattice-based cryptography has emerged as one of the most prominent candidates for post-quantum cryptography, projected to be secure against the imminent threat of large-scale fault-tolerant quantum computers. The Shortest Vector Problem (SVP) is to find the shortest non-zero vector in a given lattice. It is fundamental to lattice-based cryptography and believed to be hard even for quantum computers. We study a natural generalization of the SVP known as the $K$-Densest Sub-lattice Problem ($K$-DSP): to find the densest $K$-dimensional sub-lattice of a given lattice. We formulate $K$-DSP as finding the first excited state of a Z-basis Hamiltonian, making $K$-DSP amenable to investigation via an array of quantum algorithms, including Grover search, quantum Gibbs sampling, adiabatic, and Variational Quantum Algorithms. The complexity of the algorithms depends on the basis through which the input lattice is presented. We present a classical polynomial-time algorithm that takes an arbitrary input basis and preprocesses it into inputs suited to quantum algorithms. With preprocessing, we prove that $O(KN^2)$ qubits suffice for solving $K$-DSP for $N$ dimensional input lattices. We empirically demonstrate the performance of a Quantum Approximate Optimization Algorithm $K$-DSP solver for low dimensions, highlighting the influence of a good preprocessed input basis. We then discuss the hardness of $K$-DSP in relation to the SVP, to see if there is reason to build post-quantum cryptography on $K$-DSP. We devise a quantum algorithm that solves $K$-DSP with run-time exponent $(5KN\log{N})/2$. Therefore, for fixed $K$, $K$-DSP is no more than polynomially harder than the SVP.
翻译:格密码学已成为后量子密码学中最突出的候选方案之一,预计能抵御大规模容错量子计算机迫在眉睫的威胁。最短向量问题(SVP)是在给定格中寻找最短非零向量,它是格密码学的基础,即便对于量子计算机也被认为难以求解。我们研究SVP的一种自然推广——$K$维最密子格问题($K$-DSP):在给定格中寻找最密的$K$维子格。我们将$K$-DSP表述为Z基哈密顿量第一激发态的求解问题,从而使其可通过多种量子算法(包括Grover搜索、量子吉布斯采样、绝热量子算法和变分量子算法)进行研究。算法的复杂度取决于输入格所采用的基。我们提出一种经典多项式时间算法,可将任意输入基预处理为适合量子算法的输入。经预处理后,我们证明对于$N$维输入格,解决$K$-DSP仅需$O(KN^2)$个量子比特。我们通过低维量子近似优化算法$K$-DSP求解器实验验证了性能,凸显了良好预处理输入基的重要性。随后我们讨论$K$-DSP与SVP的难度关系,探究是否有理由基于$K$-DSP构建后量子密码学。我们设计了一种量子算法,其求解$K$-DSP的运行时间指数为$(5KN\log{N})/2$。因此,对于固定$K$,$K$-DSP的难度不超过SVP的多项式倍数。