Searcharxiv⌕ Search

arXiv subjects

Toyohiro Tsurumaru

Publications and source records attributed to Toyohiro Tsurumaru.

At least 19 recordsLinked to original sources

Estimating the spectral radius of Bell-type operator via finite dimensional approximation of orthogonal projections

We establish a new decomposition formula for two orthogonal projections P and Q on a separable Hilbert space V. This formula yields an orthogonal direct sum decomposition of V into invariant subspaces under P and Q, each of which is either at most two dimensional or infinite dimensional. On every infinite dimensional component, the pair (P,Q) admits a matrix representation that we call the "one-shifted form". This representation diagonalizes both P and Q into blocks of size at most two, and moreover, both projections can be explicitly approximated by orthogonal projections on finite dimensional subspaces. This approximation scheme offers a way to derive infinite dimensional results from their finite dimensional counterparts and is also useful in numerical computations. This decomposition provides a useful framework for analyzing a wide range of problems involving two orthogonal projections in infinite dimensions. In particular, several spectral problems for operators generated by P and Q (including polynomials in P and Q) can be reduced to the case where the pair admits a one-shifted form. More concretely, we can estimate the spectral radius of [P,Q], which is equivalent to estimating the spectral radius of the Bell-CHSH operator, a quantity of fundamental importance in quantum mechanics. We provide an upper bound and a lower bound for the spectral radius of [P,Q], which become exact when the matrix representations of P and Q are in "constant-angle one-shifted form".

math.RT↗

Security loophole in error verification in quantum key distribution

The security of quantum key distribution (QKD) is evaluated based on the secrecy of Alice's key and the correctness of the keys held by Alice and Bob. A practical method for ensuring correctness is known as error verification, in which Alice and Bob reveal a portion of their reconciled keys and check whether the revealed information matches. In this paper, we point out that when error verification is performed in a QKD protocol, the definition of secrecy must be revised accordingly. We illustrate the necessity of this revision with a counterexample, showing that neglecting it can lead to an incorrect security claim. In particular, we observe that in the case of security proof method based on phase error correction, which is one of the mainstream approaches and also known as Koashi's approach, no explicit method has been established to properly incorporate the revised secrecy definition. To resolve this issue, we present a way to translate the phase error correction-based approach into another mainstream approach, called the leftover hashing lemma-based approach, also known as Renner's approach, where a solution has already been formulated. As a consequence, security proofs under the phase error correction-based approach automatically remain valid without any change in the secret key length, even if they implicitly consider error verification without revising the secrecy definition.

quant-ph↗

Tight scaling of key rate for differential-phase-shift quantum key distribution

The performance of quantum key distribution (QKD) protocols is evaluated based on the ease of implementation and key generation rate. Among major protocols, the differential-phase-shift (DPS) protocol has the advantage of simple implementation using a train of coherent pulses and a passive detection unit. Unfortunately, however, its key rate is known to be at least proportional to $η^2$ with respect to channel transmission $η\to0$. If one can only prove the rate proportional to $η^2$ and cannot improve the analysis beyond that, then the DPS protocol will be deemed inferior to other major protocols, such as the decoy BB84 protocol. In this paper, we consider a type of DPS protocol in which the phase of each emitted block comprising $n$ pulses is randomized and significantly improve the analysis of its key rate. Specifically, we reveal that the key rate is proportional to $η^{1+\frac{1}{n-2}}$ and this rate is tight. This implies that the DPS protocol can achieve a key rate proportional to $η$ for a large number of $n$, which is the same scaling as the decoy BB84 protocol. Our result suggests that the DPS protocol can achieve a combination of both advantages of ease of implementation and a high key generation rate.

quant-ph↗

Indistinguishability between quantum randomness and pseudo-randomness under efficiently calculable randomness measures

We present a no-go theorem for the distinguishability between quantum random numbers (i.e., random numbers generated quantum mechanically) and pseudo-random numbers (i.e., random numbers generated algorithmically). The theorem states that one cannot distinguish these two types of random numbers if the quantum random numbers are efficiently classically simulatable and the randomness measure used for the distinction is efficiently computable. We derive this theorem by using the properties of cryptographic pseudo-random number generators, which are believed to exist in the field of cryptography. Our theorem is found to be consistent with the analyses on the actual data of quantum random numbers generated by the IBM Quantum and also those obtained in the Innsbruck experiment for the Bell test, where the degrees of randomness of these two set of quantum random numbers turn out to be essentially indistinguishable from those of the corresponding pseudo-random numbers. Previous observations on the algorithmic randomness of quantum random numbers are also discussed and reinterpreted in terms of our theorems and data analyses.

quant-ph↗

Information-theoretically secure equality-testing protocol with dispute resolution

There are often situations where two remote users each have data, and wish to (i) verify the equality of their data, and (ii) whenever a discrepancy is found afterwards, determine which of the two modified his data. The most common example is where they want to authenticate messages they exchange. Another possible example is where they have a huge database and its mirror in remote places, and whenever a discrepancy is found between their data, they can determine which of the two users is to blame. Of course, if one is allowed to use computational assumptions, this function can be realized readily, e.g., by using digital signatures. However, if one needs information-theoretic security, there is no known method that realizes this function efficiently, i.e., with secret key, communication, and trusted third parties all being sufficiently small. In order to realize this function efficiently with information-theoretic security, we here define the ``equality-testing protocol with dispute resolution'' as a new framework. The most significant difference between our protocol and the previous methods with similar functions is that we allow the intervention of a trusted third party when checking the equality of the data. In this new framework, we also present an explicit protocol that is information-theoretically secure and efficient.

cs.IT↗

Advantage of the key relay protocol over secure network coding

The key relay protocol (KRP) plays an important role in improving the performance and the security of quantum key distribution (QKD) networks. On the other hand, there is also an existing research field called secure network coding (SNC), which has similar goal and structure. We here analyze differences and similarities between the KRP and SNC rigorously. We found, rather surprisingly, that there is a definite gap in security between the KRP and SNC; that is, certain KRPs achieve better security than any SNC schemes on the same graph. We also found that this gap can be closed if we generalize the notion of SNC by adding free public channels; that is, KRPs are equivalent to SNC schemes augmented with free public channels.

cs.IT↗

Long-term secure distributed storage using quantum key distribution network with third-party verification

The quantum key distribution network with Vernam's One Time Pad encryption and secret sharing are powerful security tools to realize an information theoretically secure distributed storage system. In our previous work, a single-password-authenticated secret sharing scheme based on the QKD network and Shamir's secret sharing was experimentally demonstrated; it confirmed ITS data transmission, storage, authentication, and integrity. To achieve data integrity, an ITS message authentication code tag is employed and a data owner of the secret sharing performs both the MAC tag generation and verification. However, for a scenario in which the data owner and end users are different entities, the above approach may not work since the data owner can cheat the end users. In this paper, we resolve this problem by proposing an ITS integrity protection scheme employing a third-party verification with time-stamp.

quant-ph↗

Equivalence of three classical algorithms with quantum side information: Privacy amplification, error correction, and data compression

Privacy amplification (PA) is an indispensable component in classical and quantum cryptography. Error correction (EC) and data compression (DC) algorithms are also indispensable in classical and quantum information theory. We here study these three algorithms (PA, EC, and DC) in the presence of quantum side information, and show that they all become equivalent in the one-shot scenario. As an application of this equivalence, we take previously known security bounds of PA, and translate them into coding theorems for EC and DC which have not been obtained previously. Further, we apply these results to simplify and improve our previous result that the two prevalent approaches to the security proof of quantum key distribution (QKD) are equivalent. We also propose a new method to simplify the security proof of QKD.

quant-ph↗

Leftover hashing from quantum error correction: Unifying the two approaches to the security proof of quantum key distribution

We show that the Mayers-Shor-Preskill approach and Renner's approach to proving the security of quantum key distribution (QKD) are essentially the same. We begin our analysis by considering a special case of QKD called privacy amplification (PA). PA itself is an important building block of cryptography, both classical and quantum. The standard theoretical tool used for its security proof is called the leftover hashing lemma (LHL). We present a direct connection between the LHL and the coding theorem of a certain quantum error correction code. Then we apply this result to proving the equivalence between the two approaches to proving the security of QKD.

quant-ph↗

Secure random number generation from parity symmetric radiations

The random number generators (RNGs) are an indispensable tool in cryptography. Of various types of RNG method, those using radiations from nuclear decays (radioactive RNG) has a relatively long history but their security has never been discussed rigorously in the literature. In this paper we propose a new method of the radioactive RNG that admits a simple and rigorous proof of security. The security proof is made possible here by exploiting the parity (space inversion) symmetry arising in the device, which has previously been unfocused but is generically available for a nuclide which decays by parity-conserving interactions.

quant-ph↗

Multi-partite squash operation and its application to device-independent quantum key distribution

The squash operation, or the squashing model, is a useful mathematical tool for proving the security of quantum key distribution systems using practical (i.e., non-ideal) detectors. At the present, however, this method can only be applied to a limited class of detectors, such as the threshold detector of the Bennett-Brassard 1984 type. In this paper we generalize this method to include multi-partite measurements, such that it can be applied to a wider class of detectors. We demonstrate the effectiveness of this generalization by applying it to the device-independent security proof of the Ekert 1991 protocol, and by improving the associated key generation rate. For proving this result we use two physical assumptions, namely, that quantum mechanics is valid, and that Alice's and Bob's detectors are memoryless.

quant-ph↗

More Efficient Privacy Amplification with Less Random Seeds via Dual Universal Hash Function

We explicitly construct random hash functions for privacy amplification (extractors) that require smaller random seed lengths than the previous literature, and still allow efficient implementations with complexity $O(n\log n)$ for input length $n$. The key idea is the concept of dual universal$_2$ hash function introduced recently. We also use a new method for constructing extractors by concatenating $δ$-almost dual universal$_2$ hash functions with other extractors. Besides minimizing seed lengths, we also introduce methods that allow one to use non-uniform random seeds for extractors. These methods can be applied to a wide class of extractors, including dual universal$_2$ hash function, as well as to conventional universal$_2$ hash functions.

quant-ph↗

Dual universality of hash functions and its applications to quantum cryptography

In this paper, we introduce the concept of dual universality of hash functions and present its applications to quantum cryptography. We begin by establishing the one-to-one correspondence between a linear function family {\cal F} and a code family {\cal C}, and thereby defining \varepsilon-almost dual universal_2 hash functions, as a generalization of the conventional universal_2 hash functions. Then we show that this generalized (and thus broader) class of hash functions is in fact sufficient for the security of quantum cryptography. This result can be explained in two different formalisms. First, by noting its relation to the δ-biased family introduced by Dodis and Smith, we demonstrate that Renner's two-universal hashing lemma is generalized to our class of hash functions. Next, we prove that the proof technique by Shor and Preskill can be applied to quantum key distribution (QKD) systems that use our generalized class of hash functions for privacy amplification. While Shor-Preskill formalism requires an implementer of a QKD system to explicitly construct a linear code of the Calderbank-Shor-Steane type, this result removes the existing difficulty of the construction a linear code of CSS code by replacing it by the combination of an ordinary classical error correcting code and our proposed hash function. We also show that a similar result applies to the quantum wire-tap channel. Finally we compare our results in the two formalisms and show that, in typical QKD scenarios, the Shor-Preskill--type argument gives better security bounds in terms of the trace distance and Holevo information, than the method based on the δ-biased family.

quant-ph↗

Concise and Tight Security Analysis of the Bennett-Brassard 1984 Protocol with Finite Key Lengths

We present a tight security analysis of the Bennett-Brassard 1984 protocol taking into account the finite size effect of key distillation, and achieving unconditional security. We begin by presenting a concise analysis utilizing the normal approximation of the hypergeometric function. Then next we show that a similarly tight bound can also be obtained by a rigorous argument without relying on any approximation. In particular, for the convenience of experimentalists who wish to evaluate the security of their QKD systems, we also give explicit procedures of our key distillation, and also show how to calculate the secret key rate and the security parameter from a given set of experimental parameters. Besides the exact values of key rates and security parameters, we also present how to obtain their rough estimates using the normal approximation.

quant-ph↗

Squash Operator and Symmetry

This paper begins with a simple proof of the existence of squash operators compatible with the Bennett-Brassard 1984 (BB84) protocol which suits single-mode as well as multi-mode threshold detectors. The proof shows that, when a given detector is symmetric under cyclic group C_4, and a certain observable associated with it has rank two as a matrix, then there always exists a corresponding squash operator. Next, we go on to investigate whether the above restriction of "rank two" can be eliminated; i.e., is cyclic symmetry alone sufficient to guarantee the existence of a squash operator? The motivation behind this question is that, if this were true, it would imply that one could realize a device-independent and unconditionally secure quantum key distribution protocol. However, the answer turns out to be negative, and moreover, one can instead prove a no-go theorem that any symmetry is, by itself, insufficient to guarantee the existence of a squash operator.

quant-ph↗

Security proof for QKD systems with threshold detectors

In this paper, we rigorously prove the intuition that in security proofs for BB84 one may regard an incoming signal to Bob as a qubit state. From this result, it follows that all security proofs for BB84 based on a virtual qubit entanglement distillation protocol, which was originally proposed by Lo and Chau [H.-K. Lo and H. F. Chau, Science 283, 2050 (1999)], and Shor and Preskill [P. W. Shor and J. Preskill, Phys. Rev. Lett. 85, 441 (2000)], are all valid even if Bob's actual apparatus cannot distill a qubit state explicitly. As a consequence, especially, the well-known result that a higher bit error rate of 20% can be tolerated for BB84 protocol by using two-way classical communications is still valid even when Bob uses threshold detectors. Using the same technique, we also prove the security of the Bennett-Brassard-Mermin 1992 (BBM92) protocol where Alice and Bob both use threshold detectors.

quant-ph↗

Exact minimum and maximum of yield with a finite number of decoy light intensities

In this paper, for the decoy state method using a finite number of decoy light intensities, we present an improved upper and lower bounds for the asymptotic yield y_n for n-photon states. In particular if all the light intensities are less than or equal to one, they are not only a lower or upper bound, but in fact are the exact minimum or maximum.

quant-ph↗

Sequential Attack with Intensity Modulation on the Differential-Phase-Shift Quantum Key Distribution Protocol

In this paper, we discuss the security of the differential-phase-shift quantum key distribution (DPSQKD) protocol by introducing an improved version of the so-called sequential attack, which was originally discussed by Waks et al. Our attack differs from the original form of the sequential attack in that the attacker Eve modulates not only the phases but also the amplitude in the superposition of the single-photon states which she sends to the receiver. Concentrating especially on the "discretized gaussian" intensity modulation, we show that our attack is more effective than the individual attack, which had been the best attack up to present. As a result of this, the recent experiment with communication distance of 100km reported by Diamanti et al. turns out to be insecure. Moreover it can be shown that in a practical experimental setup which is commonly used today, the communication distance achievable by the DPSQKD protocol is less than 95km.

quant-ph↗