Impossibility of Perfectly Complete Many-Round Key Agreement in the QROM
Longcheng Li, Qian Li, Xingjian Li, Qipeng Liu
Abstract
This paper proves that it is impossible to construct perfectly complete quantum key agreement protocols (QKA) from quantumly secure one-way functions (OWFs) in a black-box manner. Specifically, consider any protocol in which Alice and Bob exchange only classical messages, make at most qA and qB quantum queries, respectively, to a Boolean-valued random oracle, and agree on a shared key with certainty. This paper shows that there exists an eavesdropper, given the classical messages, that can recover the shared key with certainty using O((qA+qB)5) classical oracle queries. The bound is independent of the number of rounds, transcript length, key length, and oracle-domain size. Previous results only applies to two-round key agreement (Li et al. CRYPTO 26) or relies on unproven conjectures (Austrin et al. CRYPTO 22). GPT-5.6 Sol Ultra found this proof in a one-shot conversation and drafted a preliminary version of this paper. The authors are fully responsible for the correctness, writing and discussions of this paper.
Create a lesson
Related papers
Continuous variable distributed quantum sensing in integrated photonics
Bethany Puzio, Oliver M. Green, Joel F. Tasker et al.
Securing quantum error correction against misleading advice from AI agents
A. Barış Özgüler
Exact logical error rates for magic state cultivation
Kwok Ho Wan, Ainhoa Zapirain
Hamiltonian engineering via pulses: beyond group averaging
Ivan Beschastnyi, Lucah Patel, David Tinoco
Logarithmic-depth quantum simulation of boson sampling
Changhun Oh
Entanglement swapping across a five-node relay in a multiplexed quantum-classical network
Andrew R. Cameron, Jordan M. Thomas, Alexandru Macridin et al.