---
格式版本: 2
标题: "Towards the Impossibility of Imperfectly Complete Key Agreement in the QROM"
原文链接: "https://arxiv.org/abs/2608.17610"
发布日期: "2026-08-18"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Tue, 18 Aug 2026 10:19:27 UTC (35 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-20T14:43:00+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-20T14:38:42+08:00"
入库时间: "2026-08-20T06:43:00.473Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=Oracle&searchtype=all"
匹配关键词:
  []
相关厂家:
  - "Oracle"
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 0
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "该资料为量子物理方向arXiv论文，讨论密钥协商与量子计算，与超节点/AI Rack/机柜级AI基础设施等主题完全无关，属于明显无关内容。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-20T14:46:06+08:00"
AI主题相关性: 0
AI来源权威性: 0
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 0
AI摘要: "该研究在量子计算、经典通信密钥协商的不可能性问题上取得进展，构造了两种受限设置下的首类无条件攻击，攻击者能恢复密钥。其结论排除了量子随机预言机模型中一类不完全正确的量子公钥加密方案。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:21:57.600Z"
采集批次: "2026年8月20日14点19分32秒"
采集批次ID: "20260820-141932-079"
去重键: "https://arxiv.org/abs/2608.17610"
---

## Quantum Physics

## Title:Towards the Impossibility of Imperfectly Complete Key Agreement in the QROM

Authors:[Fuyuki Kitagawa](https://arxiv.org/search/quant-ph?searchtype=author&query=Kitagawa,+F), [Ryo Nishimaki](https://arxiv.org/search/quant-ph?searchtype=author&query=Nishimaki,+R), [Agi Villanyi](https://arxiv.org/search/quant-ph?searchtype=author&query=Villanyi,+A), [Takashi Yamakawa](https://arxiv.org/search/quant-ph?searchtype=author&query=Yamakawa,+T)

[View PDF](https://arxiv.org/pdf/2608.17610) [HTML (experimental)](https://arxiv.org/html/2608.17610v1)

> Abstract:We make progress towards the impossibility of imperfectly complete quantum-computation, classical-communication (QCCC) key agreement by constructing the first unconditional attacks on quantum key agreement in the following restricted settings. In the two-message setting, we assume that Alice makes only classical queries to the oracle in the first round and that her message to Bob is classical, but otherwise both parties may perform arbitrary quantum computation, make quantum queries, and send a quantum state in the second round. Our attack and analysis are based on the heavy-query learning techniques from Austrin et al. (CRYPTO 2022) and the reprogramming techniques of Katz and Sela (arXiv [2401.14319](https://arxiv.org/abs/2401.14319)). In the round-independent setting, we show that the attack of Barak and Mahmoody (CRYPTO 2009; J. Cryptology 2017) can be extended to multiple rounds when Alice and Bob share classical communication and make only classical queries in all but the final round. In both settings, the attacker is computationally unbounded and makes $poly(\lambda)$ queries to recover the key whenever each honest query bound is at most $poly(\lambda)$ and the valid agreement probability is inverse-polynomial. As a consequence, we rule out imperfectly correct quantum public-key encryption for classical messages whose length is bounded by a polynomial in $\lambda$ in the QROM when key generation has classical oracle access, even if encryption, decryption, and the ciphertext are quantum. In particular, the one-bit case applies to the imperfectly correct PKE obtained from two-round OSP by Bartusek and Khurana (CRYPTO 2025) whenever the classical OSP sender makes only classical random-oracle queries.

| Comments: |  |
| --- | --- |
| Subjects: | Quantum Physics (quant-ph); Cryptography and Security (cs.CR) |
| Cite as: | [arXiv:2608.17610](https://arxiv.org/abs/2608.17610) \[quant-ph\] |
|  | (or [arXiv:2608.17610v1](https://arxiv.org/abs/2608.17610v1) \[quant-ph\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.17610](https://doi.org/10.48550/arXiv.2608.17610) |

## Submission history

From: Agi Villanyi \[[view email](https://arxiv.org/show-email/83dca51b/2608.17610)\]  
**\[v1\]** Tue, 18 Aug 2026 10:19:27 UTC (35 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.17610) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
