Security of quantum key distribution

Security of quantum key distribution
复制标题

量子密钥分发的安全性

DOI:
10.1142/s0219749908003256
复制
发表时间:
2008-02-01
影响因子:
1.2
通讯作者:
Renner, Renato
Renner, Renato
中科院分区:
物理与天体物理4区
文献类型:
--
作者:
Renner, Renato

文献摘要

被引文献

相似文献

量子信息论是物理学的一个领域,从信息论的角度研究量子力学的基本问题和应用问题。然而,底层技术通常仅限于满足特定独立条件的系统的分析。例如,假设一个实验可以独立重复多次,或者一个大型物理系统由许多实际上独立的部分组成。不幸的是,这样的假设并不总是合理的。对于实际应用尤其如此——例如在量子密码学中,系统的某些部分可能具有任意且未知的行为。我们提出了一种方法,使我们能够研究上述独立条件不一定成立的一般物理系统。它基于各种信息理论概念的扩展。例如,我们引入了新的不确定性度量,称为平滑最小熵和最大熵,它们是冯·诺依曼熵的推广。此外,我们开发了德菲内蒂表示定理的量子版本,如下所述。考虑一个由 n 个部分组成的物理系统。例如,这些可能是 n 次物理实验的结果。此外,我们假设该 n 分系统的联合状态可以扩展到 (n + k) 分状态,该状态在其各部分的排列下是对称的(对于某些 k ≫ 1)。 Thede Finetti 表示定理表明,原始 n 分状态在某种意义上接近于乘积状态的混合。因此,独立性(近似地)遵循对称条件。在许多自然情况下很容易满足这种对称条件。例如,它适用于从任意 (n + k) 部分系统中随机选择的 n 部分的联合状态。 作为这些技术的应用,我们证明了量子密钥分发 (QKD) 的安全性,即通过量子信道通信进行密钥协商。特别是,我们表明,为了分析 QKD 协议,通常考虑所谓的集体攻击就足够了,其中对手仅限于对通过量子通道发送的每个粒子分别应用相同的操作。该证明是通用的,因此适用于已知协议,例如 BB84 和 B92(其中获得了对密钥速率和量子通道最大容忍噪声水平的更好限制)以及连续变量方案(其中尚不知道完整的安全证明)。此外,安全性遵守所谓的通用可组合定义。这意味着 QKD 协议生成的密钥可以安全地用于任何应用程序,例如一次性密码加密——值得注意的是,大多数标准定义并非如此。
Quantum Information Theoryis an area of physics which studies both fundamental and applied issues in quantum mechanics from an information-theoretical viewpoint. The underlying techniques are, however, often restricted to the analysis of systems which satisfy a certainindependence condition. For example, it is assumed that an experiment can be repeated independently many times or that a large physical system consists of many virtually independent parts. Unfortunately, such assumptions are not always justified. This is particularly the case for practical applications — e.g. in quantum cryptography — where parts of a system might have an arbitrary and unknown behavior.We propose an approach which allows us to study general physical systems for which the above mentioned independence condition does not necessarily hold. It is based on an extension of various information-theoretical notions. For example, we introduce new uncertainty measures, calledsmooth min- and max-entropy, which are generalizations of the von Neumann entropy. Furthermore, we develop a quantum version of de Finetti's representation theorem, as described below.Consider a physical system consisting of n parts. These might, for instance, be the outcomes of n runs of a physical experiment. Moreover, we assume that the joint state of this n-partite system can be extended to an (n + k)-partite state which is symmetric under permutations of its parts (for some k ≫ 1). Thede Finetti representation theoremthen says that the original n-partite state is, in a certain sense, close to a mixture of product states. Independence thus follows (approximatively) from a symmetry condition. This symmetry condition can easily be met in many natural situations. For example, it holds for the joint state of n parts, which are chosen at random from an arbitrary (n + k)-partite system.As an application of these techniques, we prove the security ofquantum key distribution (QKD), i.e. secret key agreement by communication over a quantum channel. In particular, we show that, in order to analyze QKD protocols, it is generally sufficient to consider so-calledcollective attacks, where the adversary is restricted to applying the same operation to each particle sent over the quantum channel separately. The proof is generic and thus applies to known protocols such asBB84andB92(where better bounds on the secret-key rate and on the the maximum tolerated noise level of the quantum channel are obtained) as well as tocontinuous variableschemes (where no full security proof has been known). Furthermore, the security holds with respect to a strong so-calleduniversally composabledefinition. This implies that the keys generated by a QKD protocol can safely be used in any application, e.g. forone-time padencryption — which, remarkably, is not the case for most standard definitions.