The existence of one-way functions is one of the most fundamental assumptions in classical cryptography. In the quantum world, on the other hand, there are evidences that some cryptographic primitives can exist even if one-way functions do not exist. We therefore have the following important open problem in quantum cryptography: What is the most fundamental element in quantum cryptography? In this direction, Brakerski, Canetti, and Qian recently defined a notion called EFI pairs, which are pairs of efficiently generatable states that are statistically distinguishable but computationally indistinguishable, and showed its equivalence with some cryptographic primitives including commitments, oblivious transfer, and general multi-party computations. However, their work focuses on decision-type primitives and does not cover search-type primitives like quantum money and digital signatures. In this paper, we study properties of one-way state generators (OWSGs), which are a quantum analogue of one-way functions. We first revisit the definition of OWSGs and generalize it by allowing mixed output states. Then we show the following results. (1) We define a weaker version of OWSGs, weak OWSGs, and show that they are equivalent to OWSGs. (2) Quantum digital signatures are equivalent to OWSGs. (3) Private-key quantum money schemes (with pure money states) imply OWSGs. (4) Quantum pseudo one-time pad schemes imply both OWSGs and EFI pairs. (5) We introduce an incomparable variant of OWSGs, which we call secretly-verifiable and statistically-invertible OWSGs, and show that they are equivalent to EFI pairs.
翻译:单向函数的存在是经典密码学中最基本的假设之一。然而,在量子世界中,有证据表明某些密码原语即使不存在单向函数也能存在。因此,量子密码学中有一个重要的开放问题:量子密码学中最基本的要素是什么?针对这一问题,Brakerski、Canetti和Qian最近定义了一个名为EFI对的概念——即统计上可区分但计算上不可区分的可高效生成态对,并证明了它与承诺、茫然传输和通用多方计算等若干密码原语的等价性。然而,他们的工作集中于判定型原语,并未涵盖搜索型原语(如量子货币和数字签名)。本文研究了单向状态生成器(OWSGs)的性质,它是单向函数的量子类比。我们首先重新审视OWSGs的定义,并通过允许混合输出态来推广该定义。随后我们证明以下结果:(1)定义了一种较弱的OWSGs版本——弱OWSGs,并证明其与OWSGs等价;(2)量子数字签名与OWSGs等价;(3)私钥量子货币方案(使用纯货币态)蕴含OWSGs;(4)量子伪一次一密方案同时蕴含OWSGs和EFI对;(5)引入一种与OWSGs不可比较的变体,称为秘密可验证且统计可逆的OWSGs,并证明其与EFI对等价。