Finding many Collisions via Reusable Quantum Walks
Xavier Bonnetain, Andr\'e Chailloux, Andr\'e Schrottenloher, Yixin, Shen

TL;DR
This paper introduces a new chained quantum walk algorithm that efficiently finds multiple collisions in cryptographic functions and improves quantum algorithms for the shortest vector problem.
Contribution
It develops a novel chained quantum walk method for multiple collision finding, extending the parameter range where quantum lower bounds are tight, and applies it to enhance SVP algorithms.
Findings
Improved quantum algorithms for multiple collision detection.
Extended parameter range for collision lower bounds.
Enhanced quantum sieving algorithm for SVP with lower complexity.
Abstract
Given a random function with domain and codomain , with , a collision of is a pair of distinct inputs with the same image. Collision finding is an ubiquitous problem in cryptanalysis, and it has been well studied using both classical and quantum algorithms. Indeed, the quantum query complexity of the problem is well known to be , and matching algorithms are known for any value of . The situation becomes different when one is looking for multiple collision pairs. Here, for collisions, a query lower bound of was shown by Liu and Zhandry (EUROCRYPT~2019). A matching algorithm is known, but only for relatively small values of , when many collisions exist. In this paper, we improve the algorithms for this problem and, in particular, extend the range of admissible parameters where the lower bound is met. Our…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsQuantum Computing Algorithms and Architecture · Advanced biosensing and bioanalysis techniques · Quantum-Dot Cellular Automata
