Witness Complexity of Short Descriptions: A Cryptographic Perspective
Abstract
In cryptographic practice, where protocols impose strict time bounds, implementations demand predictable resource usage, and real-world systems require immediate verification for security and usability, a short key or certificate is useful only if it can be expanded or verified within a bounded time; otherwise a compact representation that requires superpolynomial work to expand offers no operational guarantee within a bounded-time protocol. This paper formalises that gap by introducing \emph{witness complexity} , the minimum running time over near-shortest descriptions of a string on a universal Turing machine. differs from Shannon entropy and Kolmogorov complexity : low can coexist with high . We prove invariance up to polynomial factors; a conditional separation (assuming ). An unconditional lower bound from incomputability of ; a biconditional characterisation of via the class-relative variant ; and polynomial-time tractability for structured families. Part II develops companion measures and shows an unconditional gap between grammar size and derivation cost, positioning as a metric for the usability of keys and certificates.
Keywords
Cite
@article{arxiv.2606.31370,
title = {Witness Complexity of Short Descriptions: A Cryptographic Perspective},
author = {Fabio F. G. Buono},
journal= {arXiv preprint arXiv:2606.31370},
year = {2026}
}