Insecurity of quantum secure computations

Insecurity of quantum secure computations
复制标题

DOI:
10.1103/physreva.56.1154
复制
发表时间:
1997-08-01
期刊:
影响因子:
2.9
通讯作者:
Lo, HK
Lo, HK
中科院分区:
物理与天体物理2区
文献类型:
--
作者:
Lo, HK

文献摘要

被引文献

相似文献

人们普遍认为,量子力学可以在公共决策过程中保护私人信息,例如,所谓的两方安全计算。如果是这样的话,量子智能卡,存储机密信息,只有一个适当的阅读器,可以防止伪造的出纳机从客户的输入学习PIN(个人身份证号码)。尽管这种乐观主义受到了最近令人惊讶的发现所谓量子比特承诺的不安全性的挑战,但量子双方计算本身的安全性仍然没有得到解决。在这里,我直接回答了这个问题,证明了所有单边的两方计算(只允许双方中的一方学习结果)必然是不安全的。作为我的结果的推论,量子单向不经意密码识别和所谓的量子二选一不经意传输是不可能的。我还构造了一类不能在任何双边两方计算中安全计算的函数。尽管如此,量子密码学在密钥分发中仍然很有用,并且仍然可以在Wiesner提出的“量子货币”中提供部分安全性。
It had been widely claimed that quantum mechanics can protect private information during public decision in, for example, the so-called two-party secure computation. If this were the case, quantum smart-cards, storing confidential information accessible only to a proper reader, could prevent fake teller machines from learning the PIN (personal identification number) from the customers' input. Although such optimism has been challenged by the recent surprising discovery of the insecurity of the so-called quantum bit commitment, the security of quantum two-party computation itself remains unaddressed. Here I answer this question directly by showing that all one-sided two-party computations (which allow only one of the two parties to learn the result) are necessarily insecure. As corollaries to my results, quantum one-way oblivious password identification and the so-called quantum one-out-of-two oblivious transfer are impossible. I also construct a class of functions that cannot be computed securely in any two-sided two-party computation. Nevertheless, quantum cryptography remains useful in key distribution and can still provide partial security in ''quantum money'' proposed by Wiesner.