On the Construction of Trapdoor Claw-Free Functions with Certifiable Key
A cs.CR paper defines certifiable keys for trapdoor claw-free functions and compiles quantumness proofs into zero-knowledge.
An arXiv cs.CR paper gives a family-agnostic way to certify honestly generated keys for noisy trapdoor claw-free functions. It defines a certifiable key relation, with trapdoor-recoverable witnesses, and certified key generation offering completeness, extractable certificate soundness, and key privacy. Zero-knowledge arguments of knowledge instantiate the relation, and a compiler turns any TCF-based proof of quantumness into a zero-knowledge proof. For protocols based on injective invariance, an accepting certificate itself distinguishes the family and leaks the bit those protocols must hide.
- Defines certifiable key relations and certified key generation for noisy TCFs.
- Instantiates certificates with zero-knowledge arguments of knowledge.
- Compiles any TCF proof of quantumness into a zero-knowledge proof.
- Shows injective-invariance certificates can leak the hidden distinguishing bit.
Full article156 words · extracted from arxiv.org · click to collapse
Trapdoor claw-free functions (TCFs) underpin much of classical-quantum cryptographic interaction, yet every TCF-based protocol states its guarantees relative to an honestly generated key. We give a family-agnostic abstraction of key certification for (noisy) TCF constructions, built on two notions: a certifiable key relation, an NP relation capturing a family's honest keys with witnesses recoverable from the trapdoor; and certified key generation, which emits with each key a certificate of membership satisfying completeness, certificate soundness with extractability, and key privacy. We instantiate certifiable key relations for different constructions, each met generically by a zero-knowledge argument of knowledge for the relation. As our main application, a generic compiler turns any TCF-based proof of quantumness into a zero-knowledge one, with each security property following from its counterpart in the certification scheme. Finally, we delimit the primitive's reach: for protocols resting on injective invariance, an accepting certificate is itself a family distinguisher, leaking exactly the bit such protocols must hide.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.25819