English

Witness Complexity of Short Descriptions: A Cryptographic Perspective

Cryptography and Security 2026-06-30 v1 Computational Complexity

Abstract

In cryptographic practice, where protocols impose strict time bounds, implementations demand predictable resource usage, and real-world systems require immediate verification for security and usability, a short key or certificate is useful only if it can be expanded or verified within a bounded time; otherwise a compact representation that requires superpolynomial work to expand offers no operational guarantee within a bounded-time protocol. This paper formalises that gap by introducing \emph{witness complexity} \gam(x)\gam(x), the minimum running time over near-shortest descriptions of a string on a universal Turing machine. \gam\gam differs from Shannon entropy and Kolmogorov complexity \KC\KC: low \KC\KC can coexist with high \gam\gam. We prove invariance up to polynomial factors; a conditional separation (assuming \PneqNP\PneqNP). An unconditional lower bound from incomputability of \KC\KC; a biconditional characterisation of \PeqNP\PeqNP via the class-relative variant \gP\gP; and polynomial-time tractability for structured \classNP\classNP families. Part II develops companion measures and shows an unconditional gap between grammar size and derivation cost, positioning \gam\gam as a metric for the usability of keys and certificates.

Keywords

Cite

@article{arxiv.2606.31370,
  title  = {Witness Complexity of Short Descriptions: A Cryptographic Perspective},
  author = {Fabio F. G. Buono},
  journal= {arXiv preprint arXiv:2606.31370},
  year   = {2026}
}