Tight Quantum Time-Space Tradeoffs for Function Inversion
Kai-Min Chung, Siyao Guo, Qipeng Liu, Luowen Qian
Abstract
In function inversion, we are given a function ๐ : [๐ ] โฆ โ [๐ ], and want to prepare some advice of size ๐, such that we can efficiently invert any image in time ๐ . This is a well studied problem with profound connections to cryptography, data structures, communication complexity, and circuit lower bounds. Investigation of this problem in the quantum setting was initiated by Nayebi, Aaronson, Belovs, and Trevisan (2015), who proved a lower bound of ๐๐ 2 = ฮฉ(๐ ) for random permutations against classical advice, leaving open an intriguing possibility that Grover's search can be sped up to time ร( โ๏ธ ๐/๐). Recent works by Hhan, Xagawa, and Yamakawa (2019), and Chung, Liao, and Qian (2019) extended the argument for random functions and quantum advice, but the lower bound remains ๐๐ 2 = ฮฉ(๐ ).
In this work, we prove that even with quantum advice, ๐๐ + ๐ 2 = ฮฉ(๐ ) is required for an algorithm to invert random functions. This demonstrates that Grover's search is optimal for ๐ = ร( โ ๐ ), ruling out any substantial speed-up for Grover's search even with quantum advice. Further improvements to our bounds would imply new classical circuit lower bounds, as shown by Corrigan-Gibbs and Kogan (2019).
To prove this result, we develop a general framework for establishing quantum time-space lower bounds. We further demonstrate the power of our framework by proving the following results.
โข Yao's box problem: We prove a tight quantum time-space lower bound for classical advice.
For quantum advice, we prove a first time-space lower bound using shadow tomography. These results resolve two open problems posted by Nayebi et al (2015).
โข Salted cryptography: We show that "salting generically provably defeats preprocessing," a result shown by Coretti, Dodis, Guo, and Steinberger (2018), also holds in the quantum setting. In particular, we prove quantum time-space lower bounds for a wide class of salted cryptographic primitives in the quantum random oracle model. This yields the first quantum time-space lower bound for salted collision-finding, which in turn implies that ๐ฏ๐ถ๐ฏ๐ฏ ๐ช ฬธ โ ๐ฅ๐ก๐ฐ๐ฏ ๐ช /๐๐๐๐ ๐ relative to a random oracle ๐ช.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers16
- Quantum Cryptography in AlgorithmicaWilliam Kretschmer, Luowen Qian, Makrand Sinha, Avishay TalSTOC 2023 ยท 47 citations
- Verifiable Quantum Advantage without StructureTakashi Yamakawa, Mark ZhandryFOCS 2022 ยท 35 citations
- Efficient NIZKs and Signatures from Commit-and-Open Protocols in the QROMJelle Don, Serge Fehr, Christian Majenz, Christian SchaffnerCRYPTO 2022 ยท 15 citations
- A One-Query Lower Bound for Unitary Synthesis and Breaking Quantum CryptographyAlex Lombardi, Fermi Ma, John WrightSTOC 2024 ยท 14 citations
- Unconditionally Secure Quantum Commitments with PreprocessingLuowen QianCRYPTO 2024 ยท 9 citations
Builds on1
Related papers
- Tight Quantum Time-Space Tradeoffs for Permutation InversionAkshima, Tyler Besselman, Kai-Min Chung, Siyao Guo et al.EUROCRYPT 2026
- Non-uniformity and Quantum Advice in the Quantum Random Oracle ModelQipeng LiuEUROCRYPT 2023 ยท 7 citations
- Revisiting Time-Space Tradeoffs for Function InversionAlexander Golovnev, Siyao Guo, Spencer Peters, Noah Stephens-DavidowitzCRYPTO 2023 ยท 5 citations
- The Query-Complexity of Preprocessing AttacksAshrujit Ghoshal, Stefano TessaroCRYPTO 2023 ยท 7 citations
- Non-adaptive Cryptanalytic Time-Space Lower Bounds via a Shearer-Like Inequality for PermutationsItai Dinur, Nathan Keller, Avichai MarmorSTOC 2026
