14
1

A Note on Output Length of One-Way State Generators and EFIs

Abstract

We study the output length of one-way state generators (OWSGs), their weaker variants, and EFIs. - Standard OWSGs. Recently, Cavalar et al. (arXiv:2312.08363) give OWSGs with mm-qubit outputs for any m=ω(logλ)m=\omega(\log \lambda), where λ\lambda is the security parameter, and conjecture that there do not exist OWSGs with O(loglogλ)O(\log \log \lambda)-qubit outputs. We prove their conjecture in a stronger manner by showing that there do not exist OWSGs with O(logλ)O(\log \lambda)-qubit outputs. This means that their construction is optimal in terms of output length. - Inverse-polynomial-advantage OWSGs. Let ϵ\epsilon-OWSGs be a parameterized variant of OWSGs where a quantum polynomial-time adversary's advantage is at most ϵ\epsilon. For any constant cNc\in \mathbb{N}, we construct λc\lambda^{-c}-OWSGs with ((c+1)logλ+O(1))((c+1)\log \lambda+O(1))-qubit outputs assuming the existence of OWFs. We show that this is almost tight by proving that there do not exist λc\lambda^{-c}-OWSGs with at most (clogλ2)(c\log \lambda-2)-qubit outputs. - Constant-advantage OWSGs. For any constant ϵ>0\epsilon>0, we construct ϵ\epsilon-OWSGs with O(loglogλ)O(\log \log \lambda)-qubit outputs assuming the existence of subexponentially secure OWFs. We show that this is almost tight by proving that there do not exist O(1)O(1)-OWSGs with ((loglogλ)/2+O(1))((\log \log \lambda)/2+O(1))-qubit outputs. - Weak OWSGs. We refer to (11/poly(λ))(1-1/\mathsf{poly}(\lambda))-OWSGs as weak OWSGs. We construct weak OWSGs with mm-qubit outputs for any m=ω(1)m=\omega(1) assuming the existence of exponentially secure OWFs with linear expansion. We show that this is tight by proving that there do not exist weak OWSGs with O(1)O(1)-qubit outputs. - EFIs. We show that there do not exist O(logλ)O(\log \lambda)-qubit EFIs. We show that this is tight by proving that there exist ω(logλ)\omega(\log \lambda)-qubit EFIs assuming the existence of exponentially secure PRGs.

View on arXiv
Comments on this paper