🤖 AI Summary
This study addresses the security degradation of one-time memory (OTM) protocols caused by the failure of the NISQ assumption in the fault-tolerant quantum computing era. To overcome this limitation, this work proposes the Classically Accessible Random Oracle Model (CAROM). Methodologically, an efficiently simulation-secure OTM protocol is constructed based on BB84 state encoding and a quadratic communication complexity design. Furthermore, it is proven that strong one-time programs can be realized under the condition permitting only classical queries. By transcending NISQ constraints, this research achieves an exponential reduction in simulation advantage and establishes both the feasibility and security of OTM protocols within the new model, thereby providing solid theoretical foundations for early fault-tolerant quantum computers.
📝 Abstract
Quantum information enables many cryptographic primitives that are impossible in the classical world. A line of works has developed cryptographic protocol under the assumption that quantum adversaries are restricted to noisy intermediate-scale quantum (NISQ) computing power, enabling strong one-time functionalities. But the advent of early fault-tolerant quantum computers eras will allow deeper logical quantum circuits, calling into questions the applicability of these NISQ-based assumptions. In this work, we adapt the classically accessible random oracle model (CAROM) as in [BDF+11] and [AK22], in which adversaries are only allowed to classically query the random oracle. The restriction is well motivated for NISQ quantum adversaries and may remain plausible in the presence of early fault-tolerant quantum computers. Then, we show that an efficient simulation-secure one-time memory (OTM) is possible under CAROM. Our protocol uses only BB84 states and has quadratic communication: for a $\lambda$-bit message and integer-valued parameters $n=n(\lambda)$ and $\ell=\ell(\lambda)$, the construction uses $n\ell$ qubits and $(n+2)\lambda$ classical bits, and for any quantum adversary with at most $2^{\ell/2-1}-1$ classical queries to the random oracle, its simulation advantage is at most $(n+3)\left(\frac{3}{4}\right)^n.$ Hence exponentially small simulation advantage in $n$.