In a recent seminal work, Bitansky and Shmueli (STOC '20) gave the first construction of a constant round zero-knowledge argument for NP secure against quantum attacks. However, their construction has several drawbacks compared to the classical counterparts. Specifically, their construction only achieves computational soundness, requires strong assumptions of quantum hardness of learning with errors (QLWE assumption) and the existence of quantum fully homomorphic encryption (QFHE), and relies on non-black-box simulation. In this paper, we resolve these issues at the cost of weakening the notion of zero-knowledge to what is called $\epsilon$-zero-knowledge. Concretely, we construct the following protocols: - We construct a constant round interactive proof for NP that satisfies statistical soundness and black-box $\epsilon$-zero-knowledge against quantum attacks assuming the existence of collapsing hash functions, which is a quantum counterpart of collision-resistant hash functions. Interestingly, this construction is just an adapted version of the classical protocol by Goldreich and Kahan (JoC '96) though the proof of $\epsilon$-zero-knowledge property against quantum adversaries requires novel ideas. - We construct a constant round interactive argument for NP that satisfies computational soundness and black-box $\epsilon$-zero-knowledge against quantum attacks only assuming the existence of post-quantum one-way functions. At the heart of our results is a new quantum rewinding technique that enables a simulator to extract a committed message of a malicious verifier while simulating verifier's internal state in an appropriate sense.
翻译:在一项近期开创性工作中,Bitansky 和 Shmueli(STOC '20)首次构建了针对NP问题的恒定轮次零知识论证,该论证可抵御量子攻击。然而,与经典方法相比,其构造存在若干缺陷:仅实现计算可靠性,需依赖学习误差量子困难性(QLWE假设)和量子全同态加密(QFHE)的强假设,并采用非黑盒模拟。本文通过将零知识概念弱化为所谓的$\epsilon$-零知识,解决了上述问题。具体而言,我们构造了以下协议: - 在假设存在塌缩哈希函数(经典抗碰撞哈希函数的量子对应物)的条件下,构建了针对NP的恒定轮次交互式证明,该证明满足统计可靠性和抗量子攻击的黑盒$\epsilon$-零知识。值得注意的是,该构造仅为Goldreich 和 Kahan(JoC '96)经典协议的改编版本,但针对量子敌手的$\epsilon$-零知识属性证明需引入新思路。 - 在仅假设存在后量子单向函数的条件下,构建了针对NP的恒定轮次交互式论证,该论证满足计算可靠性和抗量子攻击的黑盒$\epsilon$-零知识。我们结果的核心是一种新型量子重绕技术,该技术使模拟器能在适当意义上模拟恶意验证者内部状态的同时,提取其承诺信息。