Security of practical private randomness generation

Security of practical private randomness generation
复制标题

DOI:
10.1103/physreva.87.012336
复制
发表时间:
2013-01-30
期刊:
影响因子:
2.9
通讯作者:
Massar, Serge
Massar, Serge
中科院分区:
物理与天体物理2区
文献类型:
--
作者:
Pironio, Stefano;Massar, Serge

文献摘要

被引文献

相似文献

纠缠量子系统的测量必然会产生本质上不可预测的结果,如果他们违反贝尔不等式。该属性可以用于以设备无关的方式生成经认证的随机性,即,而无需对用于生成随机数的量子设备的内部工作进行详细假设。此外,这些数字也是私有的;即,它们不仅对用户而且对可能拥有设备的完美描述的任何对手都是随机的。由于该过程需要一个小的初始随机种子来对量子设备的行为进行采样并从设备的原始输出中提取均匀的随机性,因此通常会谈到与设备无关的随机性扩展。本文的目的是双重的。首先,我们指出,在大多数真实的实际情况下,其中设备独立性的概念被用作防止量子设备的无意缺陷或故障的保护,足以表明所生成的串相对于仅持有经典边信息的对手是随机的;即,不需要针对量子边信息来证明随机性。此外,初始随机种子不需要相对于对手是私有的,只要它是以独立于被测系统的方式生成的。然而,这些设备将生成对手无法预测的加密安全的随机性,因此,如果可以访问免费的公共随机性,就可以谈论私人随机性生成。根据这些标准量化生成的随机性的理论工具已经在S。Pironio等人[Nature(伦敦)464,1021(2010)],但最终结果表述不当。本文的第二个目的是纠正这种不准确的提法,因此奠定了一个精确的理论框架,实际设备无关的随机性产生。DOI:10.1103/PhysRevA.87.012336
Measurements on entangled quantum systems necessarily yield outcomes that are intrinsically unpredictable if they violate a Bell inequality. This property can be used to generate certified randomness in a device-independent way, i.e., without making detailed assumptions about the internal working of the quantum devices used to generate the random numbers. Furthermore these numbers are also private; i.e., they appear random not only to the user but also to any adversary that might possess a perfect description of the devices. Since this process requires a small initial random seed to sample the behavior of the quantum devices and to extract uniform randomness from the raw outputs of the devices, one usually speaks of device-independent randomness expansion. The purpose of this paper is twofold. First, we point out that in most real, practical situations, where the concept of device independence is used as a protection against unintentional flaws or failures of the quantum apparatuses, it is sufficient to show that the generated string is random with respect to an adversary that holds only classical side information; i.e., proving randomness against quantum side information is not necessary. Furthermore, the initial random seed does not need to be private with respect to the adversary, provided that it is generated in a way that is independent from the measured systems. The devices, however, will generate cryptographically secure randomness that cannot be predicted by the adversary, and thus one can, given access to free public randomness, talk about private randomness generation. The theoretical tools to quantify the generated randomness according to these criteria were already introduced in S. Pironio et al. [Nature ( London) 464, 1021 ( 2010)], but the final results were improperly formulated. The second aim of this paper is to correct this inaccurate formulation and therefore lay out a precise theoretical framework for practical device-independent randomness generation. DOI: 10.1103/PhysRevA.87.012336