Table of Contents
Fetching ...

Tight Quantum Time-Space Tradeoffs for Permutation Inversion

Akshima, Tyler Besselman, Kai-Min Chung, Siyao Guo, Tzu-Yi Yang

TL;DR

This work establishes tight quantum time-space tradeoffs for permutation inversion, showing that any quantum preprocessing scheme requiring S qubits of advice and running in time T must satisfy ST + T^2 = Ω(N). By reducing preprocessing to a bit-fixing model and applying representation theory of the symmetric group, the authors bound offline information gain and the Grover-type speedup achievable after the challenge. The key technical contribution is an average-bound lemma proved via a spectral analysis of a symmetry-respecting operator M, decomposed into irreducible representations labeled by Young diagrams. The result confirms that Grover’s search and Hellman-style classical methods cannot be combined to beat the established bound, providing an optimal security bound against quantum preprocessing for permutation inversion. The approach extends Rosmanis’ representation-theoretic framework to the bit-fixing setting and clarifies why permutation-specific techniques are necessary beyond compressed-oracle methods used for random functions.

Abstract

In permutation inversion, we are given a permutation $π: [N] \rightarrow [N]$, and want to prepare some advice of size $S$, such that we can efficiently invert any image in time $T$. This is a fundamental cryptographic problem with profound connections to communication complexity and circuit lower bounds. In the classical setting, a tight $ST = \tildeΘ(N)$ bound has been established since the seminal work of Hellman (1980) and Yao (1990). In the quantum setting, a lower bound of $ST^2 = \tildeΩ(N)$ is proved by Nayebi, Aaronson, Belovs, and Trevisan (2015) against classical advice, and by Hhan, Xagawa and Yamakawa (2019) against quantum advice. It left open an intriguing possibility that Grover's search can be sped up to time $\tilde{O}(\sqrt{N / S})$. In this work, we prove an $ST + T^2 = Ω(N)$ lower bound for permutation inversion with even quantum advice. This bound matches the best known attacks and shows that Grover's search and the classical Hellman's algorithm cannot be further sped up. Our proof combines recent techniques by Liu (2023) and by Rosmanis (2022). Specifically, we first reduce the permutation inversion problem against quantum advice to a variant by Liu's technique, then we analyze this variant via representation theory inspired by Rosmanis (2022).

Tight Quantum Time-Space Tradeoffs for Permutation Inversion

TL;DR

This work establishes tight quantum time-space tradeoffs for permutation inversion, showing that any quantum preprocessing scheme requiring S qubits of advice and running in time T must satisfy ST + T^2 = Ω(N). By reducing preprocessing to a bit-fixing model and applying representation theory of the symmetric group, the authors bound offline information gain and the Grover-type speedup achievable after the challenge. The key technical contribution is an average-bound lemma proved via a spectral analysis of a symmetry-respecting operator M, decomposed into irreducible representations labeled by Young diagrams. The result confirms that Grover’s search and Hellman-style classical methods cannot be combined to beat the established bound, providing an optimal security bound against quantum preprocessing for permutation inversion. The approach extends Rosmanis’ representation-theoretic framework to the bit-fixing setting and clarifies why permutation-specific techniques are necessary beyond compressed-oracle methods used for random functions.

Abstract

In permutation inversion, we are given a permutation , and want to prepare some advice of size , such that we can efficiently invert any image in time . This is a fundamental cryptographic problem with profound connections to communication complexity and circuit lower bounds. In the classical setting, a tight bound has been established since the seminal work of Hellman (1980) and Yao (1990). In the quantum setting, a lower bound of is proved by Nayebi, Aaronson, Belovs, and Trevisan (2015) against classical advice, and by Hhan, Xagawa and Yamakawa (2019) against quantum advice. It left open an intriguing possibility that Grover's search can be sped up to time . In this work, we prove an lower bound for permutation inversion with even quantum advice. This bound matches the best known attacks and shows that Grover's search and the classical Hellman's algorithm cannot be further sped up. Our proof combines recent techniques by Liu (2023) and by Rosmanis (2022). Specifically, we first reduce the permutation inversion problem against quantum advice to a variant by Liu's technique, then we analyze this variant via representation theory inspired by Rosmanis (2022).
Paper Structure (37 sections, 19 theorems, 116 equations, 5 figures)

This paper contains 37 sections, 19 theorems, 116 equations, 5 figures.

Key Result

Theorem 1

Let $\mathcal{A} = (\mathcal{A}_1, \mathcal{A}_2)$ be an Auxiliary-Input algorithm for permutation inversion problem consisting of two stages: Then, the success probability satisfies where $\pi \leftarrow S_N$ and $y \leftarrow [N]$ are sampled uniformly.

Figures (5)

  • Figure 1: The red dashed line indicates the point at which the algorithm $\mathcal{A}$ receives the challenge $y$. The left part depicts the offline phase, and the right part depicts the online phase.
  • Figure 2: Example of $\theta$, $\overline{\theta}$, and $\overline{\theta}_{*}$ (left to right) for $N = 12$, $k = 5$.
  • Figure 3: The Young diagrams (top) and corresponding partitions (bottom) of size $4$.
  • Figure 4: Hook lengths for $\lambda=(5,3,2)$. The dimension is $d_{\lambda}=\tfrac{10!}{7\cdot 6\cdot 4\cdot 4\cdot 3\cdot 2\cdot 2}=300$.
  • Figure 5: Restriction of the $S_{10}$-representation $\lambda=(6,3,1)$ to $S_9$. The fixed point $y\in[10]$ is unspecified.

Theorems & Definitions (37)

  • Theorem 1
  • Lemma 1: Auxiliary-Input to Bit-Fixing
  • Lemma 2
  • Theorem 1
  • Definition 1: Bit-Fixing Model
  • Lemma 2: Auxiliary-Input to Bit-Fixing
  • Lemma 2
  • Lemma 3
  • Lemma 4
  • Lemma 5
  • ...and 27 more