SearcharxivSearch

arXiv subjects

Horace P. Yuen

Publications and source records attributed to Horace P. Yuen.

At least 19 recordsLinked to original sources

Can Quantum Key Distribution Be Secure

The importance of quantum key distribution as a cryptographic method depends upon its purported strong security guarantee. The following gives reasons on why such strong security guarantee has not been validly established and why good QKD security is difficult to obtain.

quant-ph

Some Physics And System Issues In The Security Analysis Of Quantum Key Distribution Protocols

In this paper we review a number of issues on the security of quantum key distribution (QKD) protocols that bear directly on the relevant physics or mathematical representation of the QKD cryptosystem. It is shown that the cryptosystem representation itself may miss out many possible attacks which are not accounted for in the security analysis and proofs. Hence the final security claims drawn from such analysis are not reliable, apart from foundational issues about the security criteria that are discussed elsewhere. The cases of continuous-variable QKD and multi-photon sources are elaborated upon.

quant-ph

On the Foundations of Quantum Key Distribution - Reply to Renner and Beyond

In a recent note (arXiv:1209.2423) Renner claims that the criticisms of Hirota and Yuen on the security foundation of quantum key distribution arose from a logical mistake. In this paper it is shown that Renner misrepresents the claims of Yuen and also Hirota while adopting one main theorem of Yuen in lieu of his own previous error. This leads to his incoherent position which ignores quantitative security criterion levels that undermine the current security claims, a main point of the Yuen and Hirota criticisms. This security criterion issue has never been properly addressed in the literature and is here fully discussed, as are several common misconceptions on QKD security. Other foundational issues are touched upon to bring out further the present precarious state of quantum key distribution security proofs.

quant-ph

Essential lack of security proof in quantum key distribution

All the currently available unconditional security proofs on quantum key distribution, in particular for the BB84 protocol and its variants including continuous-variable ones, are invalid or incomplete at many points. In this paper we discuss some of the main known problems, particularly those on operational security guarantee and error correction. Most basic are the points that there is no security parameter in such protocols and it is not the case the generated key is perfect with probability $\geq 1-ε$ under the trace distance criterion $d\leqε$, which is widely claimed in the technical and popular literature. The many serious security consequences of this error about the QKD generated key would be explained, including practical ramification on achievable security levels. It will be shown how the error correction problem alone may already defy rigorous quantitative analysis. Various other problems would be touched upon. It is pointed out that rigorous security guarantee of much more efficient quantum cryptosystems may be obtained by abandoning the disturbance-information tradeoff principle and utilizing instead the known KCQ (keyed communication in quantum noise) principle in conjunction with a new DBM (decoy bits method) principle that will be detailed elsewhere.

quant-ph

Problems of Existing Unconditional Security Proofs in Quantum Key Distribution

It is repeatedly and persistently claimed in the literature that a specific trace criterion $d$ would guarantee universal composition security in quantum cryptography. Currently that is the sole basis of unconditional security claim in quantum key distribution. In this paper, it is shown that just security against known-plaintext attacks when the generated key is used in direct encryption is not provided by $d$. The problem is directly connected with several general problems in the existing unconditional security proofs in quantum key distribution. A number of issues will be clarified concerning the nature of true security, privacy amplification, key generation rate and the mathematical approach needed for their determination in concrete protocols.

quant-ph

Fundamental Security Issues in Continuous Variable Quantum Key Distribution

Several fundamental issues in establishing security in continuous variable quantum key distribution are discussed, in particular on reverse reconciliation and security under heterodyne attack. It appears difficult to derive quantum advantage in a concrete realistic protocol due to source and loss uncertainties, apart from the problem of bounding Eve's information after reconciliation. The necessity of proving robust security for QKD protocols is indicated.

quant-ph

Fundamental Insecurity of Multi-Photon Sources Under Photon-Number Splitting Attacks in Quantum Key Distribution

A simple photon-number splitting attack is described which works on any lossy quantum key distribution system with a multi-photon source independently of the mean source photon number, and with no induced error rate. In particular, it cannot be detected by decoy states. The quantitative loss of security is similar when the user employs photon-number resolving detectors or threshold detectors. Numerical values indicate that existing implementations of concrete QKD systems are fundamentally insecure against this attack because a large portion of leaked sifted key bits is not accounted for. The possibility of other damaging photon-number splitting attacks is discussed. Some morals will be drawn.

quant-ph

Unconditional Security In Quantum Key Distribution

It has been widely claimed and believed that many protocols in quantum key distribution, especially the single-photon BB84 protocol, have been proved unconditionally secure at least in principle, for both asymptotic and finite protocols with realistic bit lengths. In this paper it is pointed out that the only known quantitative justification for such claims is based on incorrect assertions. The precise security requirements are described in terms of the attacker's sequence and bit error probabilities in estimating the key. The extent to which such requirements can be met from a proper trace distance criterion is established. The results show that the quantitative security levels obtainable in concrete protocols with ideal devices do not rule out drastic breach of security unless privacy amplification is more properly applied.

quant-ph

Problems of Security Proofs and Fundamental Limit on Key Generation Rate in Quantum Key Distribution

It is pointed out that treatments of the error correcting code in current quantum key distribution protocols of the BB84 type are not correct under joint attack, and the general interpretation of the trace distance security criterion is also incorrect. With correct interpretation of the criterion as well as a correct treatment of the error correcting code and privacy amplification code, it is shown that even for an ideal system under just collective attack, the maximum tolerable quantum bit error rate is about 1.5% and a net key cannot actually be generated with practical error correcting codes even at such low rates, contrary to claims in the literature.

quant-ph

Security Significance of the Trace Distance Criterion in Quantum Key Distribution

The security significance of the trace distance security criterion $d$ is analyzed in terms of operational probabilities of an attacker's success in identifying different subsets of the generated key, both during the key generation process and when the key is used in one-time pad data encryption under known-plaintext attacks. The difference between Eve's sequence error rate and bit error rate is brought out. It is shown with counter-examples that the strong security claim maintained in the literature is incorrect. Other than the whole key error rates that can be quantified at the levels d^{1/3} and d^{1/4} which are much worse than $d$ itself, the attacker's success probabilities in estimating various subsets of the key and in known-plaintext attacks are yet to be quantified from $d$ if possible. It is demonstrated in realistic numerical examples of concrete protocols that drastic breach of security cannot yet be ruled out.

quant-ph

Effect of Transmission Loss on The Fundamental Security of Quantum Key Distribution

It is shown that the effect of transmission loss has often not been properly taken into account in the security proofs on quantum key distribution. A class of general attacks to be called probabilistic re-sends attack is described that has not been accounted for, which is a generalization of the well-known unique state determination attack. In the case of the four-state single-photon BB84 protocol, it is shown in detail how such attacks are not accounted for in the known security proofs against the simplest individual attacks.

quant-ph

Classicalization of Nonclassical Quantum States in Loss and Noise -- Some No-Go Theorems

The general problem of performance advantage obtainable by the use of nonclassical transmitted states over classical ones is considered. Attention is focused on the situation where system loss is significant and additive Gaussian noise may be present at the receiver. Under the assumption that the total received state is classical, rigorous output density operator representations and their trace distance bounds are developed for classical and nonclassical transmitted states. For applications with high loss in all modes, a practical No-Go theorem is enunciated that rules out the possibility of significant advantage of nonclassical over classical states. The recent work on quantum illumination is discussed as an example of our no-go approach.

quant-ph

Universality and The Criterion 'd' in Quantum Key Generation

The common security criterion d in quantum key distribution is taken to solve the universal composability problem in quantum key distribution as well as providing good general quantitative security guarantee. In this paper it is shown that these are a result of an invalid interpretation of d. The general security significance of d is analyzed in detail. The related issues of universality and attacker's side information are discussed.

quant-ph

Key Generation: Foundations and a New Quantum Approach

The fundamental security and efficiency considerations for fresh key generation will be described. It is shown that the attacker's optimal probability of finding the generated key is an indispensable measure of security and that this probability limits the possibility of privacy amplification and the amount of fresh key that can be generated. A new approach to quantum cryptography to be called KCQ, keyed communication in quantum noise, is developed on the basis of quantum detection and communication theory for classical information transmission. KCQ key generation schemes with coherent states of considerable energy will be described. The possibility of fresh key generation is demonstrated for binary and N-ary detection systems under heterodyne attacks. The security issues of these schemes will be discussed and compared with BB84. The emphasis throughout is on concrete finite bit-length protocols.

quant-ph

Comment on "Exposed-Key Weakness of Alpha-Eta" [Phys. Lett. A 370 (2007) 131]

We show that the insecurity claim of the AlphaEta cryptosystem made by C. Ahn and K. Birnbaum in Phys. Lett. A 370 (2007) 131-135 under heterodyne attack is based on invalid extrapolations of Shannon's random cipher analysis and on an invalid statistical independence assumption. We show, both for standard ciphers and AlphaEta, that expressions of the kind given by Ahn and Birnbaum can at best be interpreted as security lower bounds.

quant-ph

Impossibility Proofs and Quantum Bit Commitment

The nature and scope of various impossibility proofs as they relate to real-world situations are discussed. In particular, it is shown in words without technical symbols how secure quantum bit commitment protocols may be obtained with testing that exploits the multiple possibilities of cheating entanglement formation.

quant-ph