Almost tight bound on the query complexity of generalized Simon's problem.

Zekun Ye, Yunqi Huang, Yuyi Wang, Lvzhou Li · arXiv (Cornell University) · 2019

Simon's problem played an important role in the history of quantum algorithms, as it inspired Shor to discover the celebrated quantum algorithm solving integer factorization in polynomial time. Besides, the quantum algorithm for Simon's problem has been recently applied to break symmetric cryptosystems. Generalized Simon's problem, denoted by $\mathsf{GSP}(n,k)$, is a natural extension of Simon's problem: Given a function $f:\{0,1\}^n \to \{0,1\}^m$ and the promise that there exists a subgroup $S \le \mathbb{Z}_2^n$ of rank $k<n$ such that for any $x, y \in \{0,1\}^n, f(x) = f(y)$ iff $x \oplus y \in S$, the goal is to find $S$. Here we consider the query complexity of the problem, that is, the minimum number of queries to $f$ required to find $S$. It is not difficult to design a quantum algorithm for solving the above problem exactly with query complexity of $O(n-k)$. However, so far it is not clear what is the classical deterministic query complexity of the problem, and revealing this complexity is necessary for clarifying the computational power gap between quantum and classical computing on the problem. Also, the methods developed in this process may be helpful for other problems. In this paper, we obtain an upper bound $O\left(\max\{k, \sqrt{k \cdot 2^{n-k}}\}\right)$ on the classical deterministic query complexity of $\mathsf{GSP}(n,k)$, by constructing a subtle classical algorithm based on group theory and the divide-and-conquer method. Moreover, we prove that any classical deterministic algorithm for $\mathsf{GSP}(n,k)$ has to query at least $\Omega\left(\max\{k, \sqrt{k \cdot 2^{n-k}}\}\right)$ values of $f$, by the double counting method and the adversary method. Therefore, we have a full characterization on the classical deterministic query complexity of generalized Simon's problem.

Read the paper · More papers on PaperTik