Skip to main content
QUICK REVIEW

[Paper Review] Authentication of Quantum Messages

Howard Barnum, Claude Crépeau|University of North Texas Digital Library (University of North Texas)|May 20, 2002
Quantum Information and Cryptography3 citations
TL;DR

This paper introduces a non-interactive quantum authentication scheme that enables a sender and receiver to securely transmit quantum messages using a classical private key. By leveraging a novel purity-testing protocol based on quantum error-correcting codes, the scheme achieves unconditional security with exponentially small failure probability in the security parameter, requiring only $2m + O(s)$ classical key bits to authenticate $m$ qubits, and proves that quantum message authentication inherently requires encryption, making digital signing of quantum states impossible.

ABSTRACT

Authentication is a well-studied area of classical cryptography: a sender S and a receiver R sharing a classical private key want to exchange a classical message with the guarantee that the message has not been modified by any third party with control of the communication line. In this paper we define and investigate the authentication of messages composed of quantum states. Assuming S and R have access to an insecure quantum channel and share a private, classical random key, we provide a non-interactive scheme that enables S both to encrypt and to authenticate (with unconditional security) an m qubit message by encoding it into m+s qubits, where the failure probability decreases exponentially in the security parameter s. The classical private key is 2m+O(s) bits. To achieve this, we give a highly efficient protocol for testing the purity of shared EPR pairs. We also show that any scheme to authenticate quantum messages must also encrypt them. (In contrast, one can authenticate a classical message while leaving it publicly readable.) This has two important consequences: On one hand, it allows us to give a lower bound of 2m key bits for authenticating m qubits, which makes our protocol asymptotically optimal. On the other hand, we use it to show that digitally signing quantum states is impossible, even with only computational security.

Motivation & Objective

  • To formalize the concept of authentication for quantum messages, distinguishing it from classical message authentication due to the no-cloning theorem and state disturbance under measurement.
  • To design an efficient, non-interactive protocol that authenticates and encrypts $m$-qubit quantum messages using only a classical private key.
  • To establish a lower bound on the key size required for quantum message authentication, showing $2m$ bits are necessary for security.
  • To prove that digital signing of quantum states is impossible, even with computational security, due to the fundamental link between authentication and encryption in the quantum setting.

Proposed method

  • Define quantum message authentication in terms of fidelity preservation and indistinguishability of the authenticated state from the original, even under adversarial interference.
  • Construct a purity-testing protocol using families of quantum error-correcting codes with a covering property: any Pauli error is detected by most codes in the family.
  • Use projective geometry to build an explicit family of codes that support an efficient purity-testing protocol requiring only $O(s)$ classical communication.
  • Apply a quantum-to-classical reduction technique (Lo-Chau) to prove security of the purity-testing protocol against adversarial eavesdropping.
  • Integrate the purity-testing protocol into a full authentication scheme where the sender encodes the $m$-qubit message into $m+s$ qubits using the classical key and the purity test.
  • Prove that any authentication scheme must also encrypt the message, due to the fact that measuring a quantum state disturbs it, unlike classical messages.

Experimental results

Research questions

  • RQ1Can quantum message authentication be achieved without interaction between sender and receiver, using only a classical private key?
  • RQ2What is the minimal key size required to unconditionally authenticate $m$ qubits, and is this bound tight?
  • RQ3Why is quantum message authentication fundamentally different from classical message authentication, especially regarding the necessity of encryption?
  • RQ4Is it possible to digitally sign a quantum state, even with computational security, given the constraints of quantum mechanics?
  • RQ5Can a purity-testing protocol be constructed that efficiently verifies the integrity of shared EPR pairs without attempting error correction?

Key findings

  • The proposed authentication scheme achieves exponentially small failure probability in the security parameter $s$, ensuring high fidelity between the original and received quantum state.
  • The scheme requires a classical key of size $2m + O(s)$ bits to authenticate $m$ qubits, and this key size is asymptotically optimal.
  • A purity-testing protocol based on quantum error-correcting codes with a covering property enables efficient verification of EPR pair integrity with only $O(s)$ classical communication.
  • The paper proves that any scheme authenticating quantum messages must also encrypt them, due to the disturbance caused by measuring quantum states, which does not occur in classical settings.
  • It is impossible to digitally sign quantum states, even with computational security, because any such scheme would imply a way to distinguish quantum states with high fidelity, violating quantum indistinguishability principles.
  • The lower bound of $2m$ key bits for $m$-qubit authentication is established by showing that partial key leakage allows information extraction via superdense coding, implying the key must contain at least $2m(1 - \text{poly}(\epsilon))$ bits.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.