SearcharxivSearch

arXiv subjects

Dominic Mayers

Publications and source records attributed to Dominic Mayers.

16 recordsLinked to original sources

Unconditionally Secure Quantum Coin Tossing

In coin tossing two remote participants want to share a uniformly distributed random bit. At the least in the quantum version, each participant test whether or not the other has attempted to create a bias on this bit. It is requested that, for b = 0,1, the probability that Alice gets bit b and pass the test is smaller than 1/2 whatever she does, and similarly for Bob. If the bound 1/2 holds perfectly against any of the two participants, the task realised is called an exact coin tossing. If the bound is actually $1/2 + ξ$ where the bias $ξ$ vanishes when a security parameter m defined by the protocol increases, the task realised is a (non exact) coin tossing. It is found here that exact coin tossing is impossible. At the same time, an unconditionally secure quantum protocol that realises a (non exact) coin tossing is proposed. The protocol executes m biased quantum coin tossing procedures at the same time. It executes the first round in each of these m procedures sequentially, then the second rounds are executed, and so on until the end of the n procedures. Each procedure requires 4n particles where $n \in O(\lg m)$. The final bit x is the parity of the m random bits. The information about each of these m bits is announced a little bit at a time which implies that the principle used against bit commitment does not apply. The bias on x is smaller than $1/m$. The result is discussed in the light of the impossibility result for exact coin tossing.

quant-ph

The Universal Composable Security of Quantum Message Authentication with Key Recyling

Barnum, Crepeau, Gottesman, Tapp, and Smith (quant-ph/0205128) proposed methods for authentication of quantum messages. The first method is an interactive protocol (TQA') based on teleportation. The second method is a noninteractive protocol (QA) in which the sender first encrypts the message using a protocol QEnc and then encodes the quantum ciphertext with an error correcting code chosen secretly from a set (a purity test code (PTC)). Encryption was shown to be necessary for authentication. We augment the protocol QA with an extra step which recycles the entire encryption key provided QA accepts the message. We analyze the resulting integrated protocol for quantum authentication and key generation, which we call QA+KG. Our main result is a proof that QA+KG is universal composably (UC) secure in the Ben-Or-Mayers model (quant-ph/0409062). More specifically, this implies the UC-security of (a) QA, (b) recycling of the encryption key in QA, and (c) key-recycling of the encryption scheme QEnc by appending PTC. For an m-qubit message, encryption requires 2m bits of key; but PTC can be performed using only O(log m) + O(log e) bits of key for probability of failure e. Thus, we reduce the key required for both QA and QEnc, from linear to logarithmic net consumption, at the expense of one bit of back communication which can happen any time after the conclusion of QA and before reusing the key. UC-security of QA also extends security to settings not obvious from quant-ph/0205128. Our security proof structure is inspired by and similar to that of quant-ph/0205128, reducing the security of QA to that of TQA'. In the process, we define UC-secure entanglement, and prove the UC-security of the entanglement generating protocol given in quant-ph/0205128, which could be of independent interest.

quant-ph

Self-Testing of Quantum Circuits

We prove that a quantum circuit together with measurement apparatuses and EPR sources can be fully verified without any reference to some other trusted set of quantum devices. Our main assumption is that the physical system we are working with consists of several identifiable sub-systems, on which we can apply some given gates locally. To achieve our goal we define the notions of simulation and equivalence. The concept of simulation refers to producing the correct probabilities when measuring physical systems. To enable the efficient testing of the composition of quantum operations, we introduce the notion of equivalence. Unlike simulation, which refers to measured quantities (i.e., probabilities of outcomes), equivalence relates mathematical objects like states, subspaces or gates. Using these two concepts, we prove that if a system satisfies some simulation conditions, then it is equivalent to the one it is purposed to implement. In addition, with our formalism, we can show that these statements are robust, and the degree of robustness can be made explicit (unlike the robustness results of [DMMS00]). In particular, we also prove the robustness of the EPR Test [MY98]. Finally, we design a test for any quantum circuit whose complexity is linear in the number of gates and qubits, and polynomial in the required precision.

quant-ph

General Security Definition and Composability for Quantum & Classical Protocols

We generalize the universally composable definition of Canetti to the Quantum World. The basic idea is the same as in the classical world. The main contribution is that we unfold the result in a new model which is well adapted to quantum protocols. We also simplify some aspects of the classical case. In particular, the case of protocols with an arbitrary number of layers of sub-protocols is naturally covered in the proposed model.

quant-ph

Unconditional security in Quantum Cryptography

Basic techniques to prove the unconditional security of quantum cryptography are described. They are applied to a quantum key distribution protocol proposed by Bennett and Brassard in 1984. The proof considers a practical variation on the protocol in which the channel is noisy and photons may be lost during the transmission. The initial coding into the channel must be perfect (i.e., exactly as described in the protocol). No restriction is imposed on the detector used at the receiving side of the channel, except that whether or not the received system is detected must be independent of the basis used to measure this system.

quant-ph

Self testing quantum apparatus

We study a configuration of devices that includes (1) a source of some unknown bipartite quantum state that is claimed to be the Bell state $Φ^+$ and (2) two commuting but otherwise unknown measurement apparatus, one on each side, that are each claimed to execute an orthogonal measurement at an angle $θ\in \{0, π/8, π/4\}$ that is chosen by the user. We show that, if the nine distinct probability distributions that are generated by the self checking configuration, one for each pair of angles, are consistent with the specifications, the source and the two measurement apparatus are guaranteed to be identical modulo some isomorphism to the claimed specifications. We discuss the connection with quantum cryptography.

quant-ph

Superselection rules and quantum protocols

We show that superselection rules do not enhance the information-theoretic security of quantum cryptographic protocols. Our analysis employs two quite different methods. The first method uses the concept of a reference system -- in a world subject to a superselection rule, unrestricted operations can be simulated by parties who share access to a reference system with suitable properties. By this method, we prove that if an n-party protocol is secure in a world subject to a superselection rule, then the security is maintained even if the superselection rule is relaxed. However, the proof applies only to a limited class of superselection rules, those in which the superselection sectors are labeled by unitary irreducible representations of a compact symmetry group. The second method uses the concept of the format of a message sent between parties -- by verifying the format, the recipient of a message can check whether the message could have been sent by a party who performed charge-conserving operations. By this method, we prove that protocols subject to general superselection rules (including those pertaining to nonabelian anyons in two dimensions) are no more secure than protocols in the unrestricted world. However, the proof applies only to two-party protocols. Our results show in particular that, if no assumptions are made about the computational power of the cheater, then secure quantum bit commitment and strong quantum coin flipping with arbitrarily small bias are impossible in a world subject to superselection rules.

quant-ph

Superselection Rules in Quantum Cryptography

It is believed that superselection rules in quantum mechanics can restrict the possible operation on a qbit. If this was true, the model used by Mayers for the impossibility of bit commitment and by Kitaev for the impossibility of coin flipping would be inadequate. We explain why this is not the case. We show that a charge superselection rule implies no restriction on the operations that can be executed on any individual qbit.

quant-ph

Unconditional Security of Practical Quantum Key Distribution

We present a complete protocol for BB84 quantum key distribution for a realistic setting (noise, loss, multi-photon signals of the source) that covers many of todays experimental implementations. The security of this protocol is shown against an eavesdropper having unrestricted power to manipulate the signals coherently on their path from sender to receiver. The protocol and the security proof take into account the effects concerning the finite size of the generated key.

quant-ph

Quantum Cryptography with Imperfect Apparatus

Quantum key distribution, first proposed by Bennett and Brassard, provides a possible key distribution scheme whose security depends only on the quantum laws of physics. So far the protocol has been proved secure even under channel noise and detector faults of the receiver, but is vulnerable if the photon source used is imperfect. In this paper we propose and give a concrete design for a new concept, {\it self-checking source}, which requires the manufacturer of the photon source to provide certain tests; these tests are designed such that, if passed, the source is guaranteed to be adequate for the security of the quantum key distribution protocol, even though the testing devices may not be built to the original specification. The main mathematical result is a structural theorem which states that, for any state in a Hilbert space, if certain EPR-type equations are satisfied, the state must be essentially the orthogonal sum of EPR pairs.

quant-ph

Defeating classical bit commitments with a quantum computer

It has been recently shown by Mayers that no bit commitment scheme is secure if the participants have unlimited computational power and technology. However it was noticed that a secure protocol could be obtained by forcing the cheater to perform a measurement. Similar situations had been encountered previously in the design of Quantum Oblivious Transfer. The question is whether a classical bit commitment could be used for this specific purpose. We demonstrate that, surprisingly, classical unconditionally concealing bit commitments do not help.

quant-ph

A brief review on the impossibility of quantum bit commitment

The desire to obtain an unconditionally secure bit commitment protocol in quantum cryptography was expressed for the first time thirteen years ago. Bit commitment is sufficient in quantum cryptography to realize a variety of applications with unconditional security. In 1993, a quantum bit commitment protocol was proposed together with a security proof. However, a basic flaw in the protocol was discovered by Mayers in 1995 and subsequently by Lo and Chau. Later the result was generalized by Mayers who showed that unconditionally secure bit commitment is impossible. A brief review on quantum bit commitment which focuses on the general impossibility theorem and on recent attempts to bypass this result is provided.

quant-ph

Unconditionally secure quantum bit commitment is impossible

The claim of quantum cryptography has always been that it can provide protocols that are unconditionally secure, that is, for which the security does not depend on any restriction on the time, space or technology available to the cheaters. We show that this claim does not hold for any quantum bit commitment protocol. Since many cryptographic tasks use bit commitment as a basic primitive, this result implies a severe setback for quantum cryptography. The model used encompasses all reasonable implementations of quantum bit commitment protocols in which the participants have not met before, including those that make use of the theory of special relativity.

quant-ph

The Trouble with Quantum Bit Commitment

In a recent paper, Lo and Chau explain how to break a family of quantum bit commitment schemes, and they claim that their attack applies to the 1993 protocol of Brassard, Crépeau, Jozsa and Langlois (BCJL). The intuition behind their attack is correct, and indeed they expose a weakness common to all proposals of a certain kind, but the BCJL protocol does not fall in this category. Nevertheless, it is true that the BCJL protocol is insecure, but the required attack and proof are more subtle. Here we provide the first complete proof that the BCJL protocol is insecure.

quant-ph

Quantum Key Distribution and String Oblivious Transfer in Noisy Channels

We prove the unconditional security of a quantum key distribution (QKD) protocol on a noisy channel against the most general attack allowed by quantum physics. We use the fact that in a previous paper we have reduced the proof of the unconditionally security of this QKD protocol to a proof that a corresponding Quantum String Oblivious Transfer (String-QOT) protocol would be unconditionally secure against Bob if implemented on top of an unconditionally secure bit commitment scheme. We prove a lemma that extends a security proof given by Yao for a (one bit) QOT protocol to this String-QOT protocol. This result and the reduction mentioned above implies the unconditional security of our QKD protocol despite our previous proof that unconditionally secure bit commitment schemes are impossible.

quant-ph