Perfectly Complete Quantum Key Agreement from One-Way Functions
Whether perfectly complete quantum key agreement can be built from quantumly secure one-way functions in a black-box way. It cannot: for any protocol where Alice and Bob exchange only classical messages, make at most $q_A$ and $q_B$ quantum queries to a Boolean random oracle and agree on a key with certainty, an eavesdropper given the classical messages recovers the key with certainty in $O((q_A + q_B)^5)$ classic…