SearcharxivSearch

arXiv subjects

Erika Andersson

Publications and source records attributed to Erika Andersson.

At least 19 recordsLinked to original sources

Quantum protocols for Rabin oblivious transfer

Rabin oblivious transfer is the cryptographic task where Alice wishes to receive a bit from Bob but it may get lost with probability 1/2. In this work, we provide protocol designs which yield quantum protocols with improved security. Moreover, we provide a constant lower bound on any quantum protocol for Rabin oblivious transfer. To quantify the security of this task with asymmetric cheating definitions, we introduce the notion of cheating advantage which may be of independent interest in the study of other asymmetric cryptographic primitives.

quant-ph

Optimal Discrimination of Mixed Symmetric Multi-mode Coherent States

We find the optimal measurement for distinguishing between symmetric multi-mode phase-randomized coherent states. A motivation for this is that phase-randomized coherent states can be used for quantum communication, including quantum cryptography. The so-called square-root measurement is optimal for pure symmetric states, but is not always optimal for mixed symmetric states. When phase-randomizing a multi-mode coherent state, the state becomes a mixture of pure multi-mode states with different total photon numbers. We find that the optimal measurement for distinguishing between any set of phase-randomised coherent states can be realised by first counting the total number of photons, and then distinguishing between the resulting pure states in the corresponding photon-number subspace. If the multi-mode coherent states we started from are symmetric, then the optimal measurement in each subspace is a square-root measurement. The overall optimal measurement in the cases we consider is also a square-root measurement. In some cases, we are able to present a simple linear optical circuit that realizes the overall optimal measurement.

quant-ph

Quantum Rabin oblivious transfer using two pure states

Oblivious transfer between two untrusting parties is an important primitive in cryptography. There are different variants of oblivious transfer. In Rabin oblivious transfer, the sender Alice holds a bit, and the receiver Bob either obtains the bit, or obtains no information with probability $p_?$. Alice should not know whether or not Bob obtained the bit. We examine a quantum Rabin oblivious transfer (OT) protocol that uses two pure states. Investigating different cheating scenarios for the sender and for the receiver, we determine optimal cheating probabilities in each case. Comparing the quantum Rabin oblivious transfer protocol to classical Rabin oblivious transfer protocols, we show that the quantum protocol outperforms classical protocols, which do not use a third party, for some values of $p_?$. We find that quantum Rabin OT protocols that use mixed states can outperform quantum Rabin OT protocols that use pure states for some values of $p_?$.

quant-ph

Incomplete quantum oblivious transfer with perfect one-sided security

Oblivious transfer is a fundamental cryptographic primitive which is useful for secure multiparty computation. There are several variants of oblivious transfer. We consider 1 out of 2 oblivious transfer, where a sender sends two bits of information to a receiver. The receiver only receives one of the two bits, while the sender does not know which bit the receiver has received. Perfect quantum oblivious transfer with information theoretic security is known to be impossible. We aim to find the lowest possible cheating probabilities. Bounds on cheating probabilities have been investigated for complete protocols, where if both parties follow the protocol, the bit value obtained by the receiver matches the sender bit value. We instead investigate incomplete protocols, where the receiver obtains an incorrect bit value with probability pf. We present optimal non interactive protocols where Alice bit values are encoded in four symmetric pure quantum states, and where she cannot cheat better than with a random guess. We find the protocols such that for a given pf, Bob cheating probability pr is as low as possible, and vice versa. Furthermore, we show that non-interactive quantum protocols can outperform non-interactive classical protocols, and give a lower bound on Bob cheating probability in interactive quantum protocols. Importantly for optical implementations, our protocols do not require entanglement nor quantum memory.

quant-ph

Cheating in quantum Rabin oblivious transfer using delayed measurements

Oblivious transfer has been the interest of study as it can be used as a building block for multiparty computation. There are many forms of oblivious transfer; we explore a variant known as Rabin oblivious transfer. Here the sender Alice has one bit, and the receiver Bob obtains this bit with a certain probability. The sender does not know whether the receiver obtained the bit or not. For a previously suggested protocol, we show a possible attack using a delayed measurement. This allows a cheating party to pass tests carried out by the other party, while gaining more information than if they would have been honest. We show how this attack allows perfect cheating, unless the protocol is modified, and suggest changes which lower the cheating probability for the examined cheating strategies.

quant-ph

Error-tolerant oblivious transfer in the noisy-storage model

The noisy-storage model of quantum cryptography allows for information-theoretically secure two-party computation based on the assumption that a cheating user has at most access to an imperfect, noisy quantum memory, whereas the honest users do not need a quantum memory at all. In general, the more noisy the quantum memory of the cheating user, the more secure the implementation of oblivious transfer, which is a primitive that allows universal secure two-party and multi-party computation. For experimental implementations of oblivious transfer, one has to consider that also the devices held by the honest users are lossy and noisy, and error correction needs to be applied to correct these trusted errors. The latter are expected to reduce the security of the protocol, since a cheating user may hide themselves in the trusted noise. Here we leverage entropic uncertainty relations to derive tight bounds on the security of oblivious transfer with a trusted and untrusted noise. In particular, we discuss noisy storage and bounded storage, with independent and correlated noise.

quant-ph

Non-interactive XOR quantum oblivious transfer: optimal protocols and their experimental implementations

Oblivious transfer (OT) is an important cryptographic primitive. Any multi-party computation can be realised with OT as building block. XOR oblivious transfer (XOT) is a variant where the sender Alice has two bits, and a receiver Bob obtains either the first bit, the second bit, or their XOR. Bob should not learn anything more than this, and Alice should not learn what Bob has learnt. Perfect quantum OT with information-theoretic security is known to be impossible. We determine the smallest possible cheating probabilities for unrestricted dishonest parties in non-interactive quantum XOT protocols using symmetric pure states, and present an optimal protocol, which outperforms classical protocols. We also "reverse" this protocol, so that Bob becomes sender of a quantum state and Alice the receiver who measures it, while still implementing oblivious transfer from Alice to Bob. Cheating probabilities for both parties stay the same as for the unreversed protocol. We optically implemented both the unreversed and the reversed protocols, and cheating strategies, noting that the reversed protocol is easier to implement.

quant-ph

Experimental demonstration of optimal unambiguous two-out-of-four quantum state elimination

A core principle of quantum theory is that non-orthogonal quantum states cannot be perfectly distinguished with single-shot measurements. However, it is possible to exclude a subset of non-orthogonal states without error in certain circumstances. Here we implement a quantum state elimination measurement which unambiguously rules out two of four pure, non-orthogonal quantum states -- ideally without error and with unit success probability. This is a generalised quantum measurement with six outcomes, where each outcome corresponds to excluding a pair of states. Our experimental realisation uses single photons, with information encoded in a four-dimensional state using optical path and polarisation degrees of freedom. The prepared state is incorrectly ruled out up to $3.3(2)\%$ of the time.

quant-ph

Unconditionally secure digital signatures implemented in an 8-user quantum network

The ability to know and verifiably demonstrate the origins of messages can often be as important as encrypting the message itself. Here we present an experimental demonstration of an unconditionally secure digital signature (USS) protocol implemented for the first time, to the best of our knowledge, on a fully connected quantum network without trusted nodes. Our USS protocol is secure against forging, repudiation and messages are transferrable. We show the feasibility of unconditionally secure signatures using only bi-partite entangled states distributed throughout the network and experimentally evaluate the performance of the protocol in real world scenarios with varying message lengths.

quant-ph

Imperfect 1-out-of-2 quantum oblivious transfer: bounds, a protocol, and its experimental implementation

Oblivious transfer is an important primitive in modern cryptography. Applications include secure multiparty computation, oblivious sampling, e-voting, and signatures. Information-theoretically secure perfect 1-out-of 2 oblivious transfer is impossible to achieve. Imperfect variants, where both participants' ability to cheat is still limited, are possible using quantum means while remaining classically impossible. Precisely what security parameters are attainable remains unknown. We introduce a theoretical framework for studying semirandom quantum oblivious transfer, which is shown to be equivalent to regular oblivious transfer in terms of cheating probabilities. We then use it to derive bounds on cheating. We also present a protocol with lower cheating probabilities than previous schemes, together with its optical realization. We show that a lower bound of 2/3 on the minimum achievable cheating probability can be directly derived for semirandom protocols using a different method and definition of cheating than used previously. The lower bound increases from 2/3 to approximately 0.749 if the states output by the protocol are pure and symmetric. The oblivious transfer scheme we present uses unambiguous state elimination measurements and can be implemented with the same technological requirements as standard quantum cryptography. The cheating probabilities are 3/4 and approximately 0.729 for sender and receiver respectively, which is lower than in existing protocols. Using a photonic test-bed, we have implemented the protocol with honest parties, as well as optimal cheating strategies.

quant-ph

A group-theoretic approach to elimination measurements of qubit sequences

Most measurements are designed to tell you which of several alternatives have occurred, but it is also possible to make measurements that eliminate possibilities and tell you an alternative that did not occur. Measurements of this type have proven useful in quantum foundations and in quantum cryptography. Here we show how group theory can be used to design such measurements. After some general considerations, we focus on the case of measurements on two-qubit states that eliminate one state. We then move on to construct measurements that eliminate two three-qubit states and four four-qubit states. A condition that constrains the construction of elimination measurements is then presented. Finally, in an appendix, we briefly consider the case of elimination measurements with failure probabilities and an elimination measurement on $n$-qubit states.

quant-ph

Unambiguous quantum state elimination for qubit sequences

Quantum state elimination measurements tell us what states a quantum system does not have. This is different from state discrimination, where one tries to determine what the state of a quantum system is, rather than what it is not. Apart from being of fundamental interest, quantum state elimination may find uses in quantum communication and quantum cryptography. We consider unambiguous quantum state elimination for two or more qubits, where each qubit can be in one of two possible states. Optimal measurements for eliminating one and two states out of four two-qubit states are given. We also prove that if we want to maximise the average number of eliminated overall N-qubit states, then individual measurements on each qubit are optimal.

quant-ph

Truly noiseless probabilistic amplification

Most of the schemes for "noiseless" amplification of coherent states, which have recently been attracting theoretical and experimental interest, share a common trait: the amplification is not truly noiseless, or perfect, for non-zero success probability. While this must hold true for all phase-independent amplification schemes, in this work we point out that truly noiseless amplification is indeed possible, provided that the states which we wish to amplify come from a finite set. Perfect amplification with unlimited average gain is then possible with finite success probability, for example using techniques for unambiguously distinguishing between quantum states. Such realizations require only linear optics, no single-photon sources, nor any photon counting. We also investigate the optimal success probability of perfect amplification of a symmetric set of coherent states. There are two regimes: low-amplitude amplification, where the target amplitude is below one, and general amplification. For the low-amplitude regime, analytic results for the optimal amplification success probabilities can be obtained. In this case a natural bound imposed by the ratio of success probabilities of optimal unambiguous discrimination of the source and amplified states can always be reached. We also show that for general amplification this bound cannot always be satisfied.

quant-ph

Implementation vulnerabilities in general quantum cryptography

Quantum cryptography is information-theoretically secure owing to its solid basis in quantum mechanics. However, generally, initial implementations with practical imperfections might open loopholes, allowing an eavesdropper to compromise the security of a quantum cryptographic system. This has been shown to happen for quantum key distribution (QKD). Here we apply experience from implementation security of QKD to several other quantum cryptographic primitives. We survey quantum digital signatures, quantum secret sharing, source-independent quantum random number generation, quantum secure direct communication, and blind quantum computing. We propose how the eavesdropper could in principle exploit the loopholes to violate assumptions in these protocols, breaking their security properties. Applicable countermeasures are also discussed. It is important to consider potential implementation security issues early in protocol design, to shorten the path to future applications.

quant-ph

Optimal simultaneous measurements of incompatible observables of a single photon

Joint or simultaneous measurements of non-commuting quantum observables are possible at the cost of increased unsharpness or measurement uncertainty. Many different criteria exist for defining what an "optimal" joint measurement is, with corresponding different tradeoff relations for the measurements. Understanding the limitations of such measurements is of fundamental interest and relevant for quantum technology. Here, we experimentally test a tradeoff relation for the sharpness of qubit measurements, a relation which refers directly to the form of the measurement operators, rather than to errors in estimates. We perform the first optical implementation of the simplest possible optimal joint measurement, requiring less quantum resources than have previously often been employed. Using a heralded single-photon source, we demonstrate quantum-limited performance of the scheme on single quanta.

quant-ph

Ancilla-driven quantum computation for qudits and continuous variables

Although qubits are the leading candidate for the basic elements in a quantum computer, there are also a range of reasons to consider using higher dimensional qudits or quantum continuous variables (QCVs). In this paper we use a general `quantum variable' formalism to propose a method of quantum computation in which ancillas are used to mediate gates on a well-isolated `quantum memory' register and which may be applied to the setting of qubits, qudits (for $d>2$) or QCVs. More specifically, we present a model in which universal quantum computation may be implemented on a register using only: repeated applications of a single fixed two-body ancilla-register interaction gate, ancillas prepared in a single state, and local measurements of these ancillas. In order to maintain determinism in the computation, adaptive measurements via a classical-feedforward of measurement outcomes are used, with the method similar to that in measurement-based quantum computation (MBQC). We show that our model has the same hybrid quantum-classical processing advantages as MBQC, including the power to implement any Clifford circuit in essentially one layer of quantum computation. In some physical settings, high-quality measurements of the ancillas may be highly challenging or not possible, and hence we also present a globally unitary model which replaces the need for measurements of the ancillas with the requirement for ancillas to be prepared in states from a fixed orthonormal basis. Finally, we discuss settings in which these models may be of practical interest.

quant-ph

Measurement-Device-Independent Quantum Digital Signatures

Digital signatures play an important role in software distribution, modern communication and financial transactions, where it is important to detect forgery and tampering. Signatures are a cryptographic technique for validating the authenticity and integrity of messages, software, or digital documents. The security of currently used classical schemes relies on computational assumptions. Quantum digital signatures (QDS), on the other hand, provide information-theoretic security based on the laws of quantum physics. Recent work on QDS shows that such schemes do not require trusted quantum channels and are unconditionally secure against general coherent attacks. However, in practical QDS, just as in quantum key distribution (QKD), the detectors can be subjected to side-channel attacks, which can make the actual implementations insecure. Motivated by the idea of measurement-device-independent quantum key distribution (MDI-QKD), we present a measurement-device-independent QDS (MDI-QDS) scheme, which is secure against all detector side-channel attacks. Based on the rapid development of practical MDI-QKD, our MDI-QDS protocol could also be experimentally implemented, since it requires a similar experimental setup.

quant-ph

Experimental measurement-device-independent quantum digital signatures over a metropolitan network

Quantum digital signatures (QDS) provide a means for signing electronic communications with informationtheoretic security. However, all previous demonstrations of quantum digital signatures assume trusted measurement devices. This renders them vulnerable against detector side-channel attacks, just like quantum key distribution. Here, we exploit a measurement-device-independent (MDI) quantum network, over a 200-square-kilometer metropolitan area, to perform a field test of a three-party measurement-device-independent quantum digital signature (MDI-QDS) scheme that is secure against any detector side-channel attack. In so doing, we are able to successfully sign a binary message with a security level of about 1E-7. Remarkably, our work demonstrates the feasibility of MDI-QDS for practical applications.

quant-ph