This paper studies the limitations of the generic approaches to solving cryptographic problems in classical and quantum settings in various models. - In the classical generic group model (GGM), we find simple alternative proofs for the lower bounds of variants of the discrete logarithm (DL) problem: the multiple-instance DL and one-more DL problems (and their mixture). We also re-prove the unknown-order GGM lower bounds, such as the order finding, root extraction, and repeated squaring. - In the quantum generic group model (QGGM), we study the complexity of variants of the discrete logarithm. We prove the logarithm DL lower bound in the QGGM even for the composite order setting. We also prove an asymptotically tight lower bound for the multiple-instance DL problem. Both results resolve the open problems suggested in a recent work by Hhan, Yamakawa, and Yun. - In the quantum generic ring model we newly suggested, we give the logarithmic lower bound for the order-finding algorithms, an important step for Shor's algorithm. We also give a logarithmic lower bound for a certain generic factoring algorithm outputting relatively small integers, which includes a modified version of Regev's algorithm. - Finally, we prove a lower bound for the basic index calculus method for solving the DL problem in a new idealized group model regarding smooth numbers. The quantum lower bounds in both models allow certain (different) types of classical preprocessing. All of the proofs are significantly simpler than the previous proofs and are through a single tool, the so-called compression lemma, along with linear algebra tools. Our use of this lemma may be of independent interest.
翻译:摘要:本文研究了在经典与量子环境下,多种模型中采用通用方法解决密码学问题的局限性。 - 在经典通用群模型(GGM)中,我们为离散对数(DL)问题的变体(多实例DL与多一次DL问题及其混合形式)的下界找到了简单替代证明。我们还重新证明了未知阶GGM的下界,例如阶求解、根提取和重复平方问题。 - 在量子通用群模型(QGGM)中,我们研究了离散对数变体的复杂度。即使在复合阶设定下,我们仍证明了QGGM中对数阶DL下界,并给出了多实例DL问题的渐近紧下界。这两个结果解决了Hhan、Yamakawa和Yun近期工作中提出的开放问题。 - 在我们新提出的量子通用环模型中,我们给出了阶求解算法的对数下界(这是Shor算法的重要步骤),并针对输出相对较小整数的特定通用因式分解算法(包含Regev算法的改进版本)给出了对数下界。 - 最后,针对涉及光滑数的全新理想化群模型,我们证明了基于基本索引计算法求解DL问题的下界。两个量子模型中的下界允许不同类别的经典预处理。所有证明均显著简化,且均通过单一工具(即压缩引理)结合线性代数方法完成。我们对该引理的应用可能具有独立价值。