Lune

EUROCRYPT2023顶会

Finding Many Collisions via Reusable Quantum Walks - Application to Lattice Sieving

Xavier Bonnetain, André Chailloux, André Schrottenloher, Yixin Shen

2023年份
22被引次数
4顶会引用

摘要

Given a random function ff with domain [2n][2^n] and codomain [2m][2^m], with m≥nm \geq n, a collision of ff is a pair of distinct inputs with the same image. Collision finding is an ubiquitous problem in cryptanalysis, and it has been well studied using both classical and quantum algorithms. Indeed, the quantum query complexity of the problem is well known to be Θ(2m/3)\Theta(2^{m/3}), and matching algorithms are known for any value of mm. The situation becomes different when one is looking for multiple collision pairs. Here, for 2k2^k collisions, a query lower bound of Θ(2(2k+m)/3)\Theta(2^{(2k+m)/3}) was shown by Liu and Zhandry (EUROCRYPT 2019). A matching algorithm is known, but only for relatively small values of mm, when many collisions exist. In this paper, we improve the algorithms for this problem and, in particular, extend the range of admissible parameters where the lower bound is met. Our new method relies on a chained quantum walk algorithm, which might be of independent interest. It allows to extract multiple solutions of an MNRS-style quantum walk, without having to recompute it entirely: after finding and outputting a solution, the current state is reused as the initial state of another walk. As an application, we improve the quantum sieving algorithms for the shortest vector problem (SVP), with a complexity of 20.2563d+o(d)2^{0.2563d + o(d)} instead of the previous 20.2570d+o(d)2^{0.2570d + o(d)}.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext eab415d2-4e2f-4546-82e9-5b4d8161d6fe

引用它的顶会 Paper4

问问它们各自怎么用它

它引用的顶会 Paper1

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖