arXiv · 2608.03824
Impossibility of Perfectly Complete Many-Round Key Agreement in the QROM
Abstract
This paper proves that it is impossible to construct perfectly complete quantum key agreement protocols (QKA) from quantumly secure one-way functions (OWFs) in a black-box manner. Specifically, consider any protocol in which Alice and Bob exchange only classical messages, make at most $q_{\mathsf{A}}$ and $q_{\mathsf{B}}$ quantum queries, respectively, to a Boolean-valued random oracle, and agree on a shared key with certainty. This paper shows that there exists an eavesdropper, given the classical messages, that can recover the shared key with certainty using $O((q_{\mathsf{A}}+q_{\mathsf{B}})^5)$ classical oracle queries. The bound is independent of the number of rounds, transcript length, key length, and oracle-domain size. Previous results only applies to two-round key agreement (Li et al. CRYPTO 26) or relies on unproven conjectures (Austrin et al. CRYPTO 22). GPT-5.6 Sol Ultra found this proof in a one-shot conversation and drafted a preliminary version of this paper. The authors are fully responsible for the correctness, writing and discussions of this paper.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Longcheng Li, Qian Li, Xingjian Li, Qipeng Liu. 2026-08-04. Impossibility of Perfectly Complete Many-Round Key Agreement in the QROM. https://arxiv.org/abs/2608.03824
Cite the original work for its findings. Save a collection to share your selection of sources.