Imperfect 1-Out-of-2 Quantum Oblivious Transfer: Bounds, a Protocol, and its Experimental Implementation

Imperfect 1-Out-of-2 Quantum Oblivious Transfer: Bounds, a Protocol, and its Experimental Implementation
复制标题

DOI:
10.1103/prxquantum.2.010335
复制
发表时间:
2021-03-01
期刊:
影响因子:
9.7
通讯作者:
Andersson, Erika
Andersson, Erika
中科院分区:
物理与天体物理1区
文献类型:
--
作者:
Amiri, Ryan;Starek, Robert;Andersson, Erika

文献摘要

被引文献

相似文献

不经意传输是现代密码学中的一个重要原语。应用包括安全多方计算、不经意采样、电子投票和签名。信息理论上安全的完美二选一不经意传输是不可能实现的。不完美的变体,其中两个参与者的欺骗能力仍然有限,使用量子手段是可能的,同时保持经典的不可能。确切地说,什么样的安全参数是可以达到的仍然是未知的。我们引入了一个研究半随机量子不经意传输的理论框架,证明了它在欺骗概率上与规则的不经意传输等价。然后,我们用它来推导出作弊的界限。我们还提出了一个协议,具有较低的欺骗概率比以前的计划,连同它的光学实现。我们表明,一个下界的2/3的最小可实现的作弊概率可以直接推导出半随机协议使用不同的方法和定义的作弊比以前使用的。如果协议输出的状态是纯的和对称的,则下限从2/3增加到大约0.749。我们提出的不经意传输方案使用明确的状态消除测量,可以实现与标准量子密码相同的技术要求。特别是,它不需要诚实的参与者准备或测量纠缠态。欺骗概率分别为3/4和约0.729的发送方和接收方,这是低于现有的协议。使用光子测试床,我们已经实现了诚实的各方,以及最佳的作弊策略的协议。由于接收方和发送方的欺骗概率的不对称性,该协议可以与“平凡”协议相结合,以实现发送方和接收方的平均欺骗概率约为0.74的较低的整体协议。这表明,有趣的是,最终输出状态是纯的和对称的协议在平均欺骗概率方面不是最优的。
Oblivious transfer is an important primitive in modern cryptography. Applications include secure multiparty computation, oblivious sampling, e-voting, and signatures. Information-theoretically secure perfect 1-out-of 2 oblivious transfer is impossible to achieve. Imperfect variants, where both participants' ability to cheat is still limited, are possible using quantum means while remaining classically impossible. Precisely what security parameters are attainable remains unknown. We introduce a theoretical framework for studying semirandom quantum oblivious transfer, which is shown to be equivalent to regular oblivious transfer in terms of cheating probabilities. We then use it to derive bounds on cheating. We also present a protocol with lower cheating probabilities than previous schemes, together with its optical realization. We show that a lower bound of 2/3 on the minimum achievable cheating probability can be directly derived for semirandom protocols using a different method and definition of cheating than used previously. The lower bound increases from 2/3 to approximately 0.749 if the states output by the protocol are pure and symmetric. The oblivious transfer scheme we present uses unambiguous state elimination measurements and can be implemented with the same technological requirements as standard quantum cryptography. In particular, it does not require honest participants to prepare or measure entangled states. The cheating probabilities are 3/4 and approximately 0.729 for sender and receiver, respectively, which is lower than in existing protocols. Using a photonic testbed, we have implemented the protocol with honest parties, as well as optimal cheating strategies. Because of the asymmetry of the receiver's and sender's cheating probabilities, the protocol can be combined with a "trivial" protocol to achieve an overall protocol with lower average cheating probabilities of approximately 0.74 for both sender and receiver. This demonstrates that, interestingly, protocols where the final output states are pure and symmetric are not optimal in terms of average cheating probability.