Skip to main content
QUICK REVIEW

[Paper Review] Improving the Security of Quantum Protocols via Commit-and-Open

Ivan Damgaard, Serge Fehr|ArXiv.org|Feb 23, 2009
Quantum Information and Cryptography3 references22 citations
TL;DR

This paper introduces a general compiler that enhances the security of two-party quantum protocols—such as quantum identification and oblivious transfer—by transforming protocols secure against 'almost honest' adversaries into ones secure against arbitrary computationally bounded quantum adversaries. The method uses a computational commitment scheme with quantum-secure extraction properties, preserving security in the bounded-quantum-storage model (BQSM) and ensuring that breaking the protocol requires both large quantum memory and significant computational power.

ABSTRACT

We consider two-party quantum protocols starting with a transmission of some random BB84 qubits followed by classical messages. We show a general "compiler" improving the security of such protocols: if the original protocol is secure against an "almost honest" adversary, then the compiled protocol is secure against an arbitrary computationally bounded (quantum) adversary. The compilation preserves the number of qubits sent and the number of rounds up to a constant factor. The compiler also preserves security in the bounded-quantum-storage model (BQSM), so if the original protocol was BQSM-secure, the compiled protocol can only be broken by an adversary who has large quantum memory and large computing power. This is in contrast to known BQSM-secure protocols, where security breaks down completely if the adversary has larger quantum memory than expected. We show how our technique can be applied to quantum identification and oblivious transfer protocols.

Motivation & Objective

  • To address the vulnerability of quantum protocols to adversaries who delay measuring transmitted qubits, thereby gaining excessive information beyond intended access.
  • To develop a general method that upgrades protocols secure against 'almost honest' Bob into ones secure against any computationally bounded quantum adversary.
  • To preserve unconditional security against dishonest Alice while improving security against dishonest Bob without increasing qubit or round complexity significantly.
  • To ensure that protocols remain secure in the bounded-quantum-storage model (BQSM), even if the adversary exceeds the assumed quantum storage limit, by requiring both large quantum memory and high computational power to break.
  • To enable practical deployment of quantum protocols by combining computational assumptions with BQSM security, offering hybrid security not achievable by classical protocols alone.

Proposed method

  • The compiler transforms a two-party quantum protocol that is secure against 'almost honest' Bob into one secure against any computationally bounded quantum adversary.
  • It relies on a classical commitment scheme with quantum-secure extraction properties, inspired by Regev's cryptosystem, to bind Bob’s behavior during the protocol.
  • A common reference string is used to simplify and improve efficiency of the commitment scheme, enabling constant-round compilation.
  • The protocol preserves the number of qubits and rounds up to a constant factor, maintaining efficiency and practicality.
  • The compiler integrates techniques from [DFSS07] to extend security to man-in-the-middle attacks by using an extractor MAC for authenticated classical communication.
  • Privacy amplification and error-correcting codes are used to ensure that extracted information remains close to uniform and independent of any adversary's knowledge.

Experimental results

Research questions

  • RQ1Can a general compiler be designed to upgrade the security of quantum protocols from 'almost honest' adversaries to any computationally bounded quantum adversary?
  • RQ2How can security in the bounded-quantum-storage model (BQSM) be preserved or enhanced when the adversary exceeds the assumed quantum storage limit?
  • RQ3Can computational assumptions be used to achieve hybrid security—requiring both large quantum memory and high computational power—without sacrificing unconditional security against dishonest Alice?
  • RQ4To what extent can the compiler be applied to existing protocols like quantum identification and oblivious transfer while maintaining efficiency and round complexity?
  • RQ5Can the protocol be secured against man-in-the-middle attacks by combining commitment schemes with extractor MACs, and does this allow key reusability?

Key findings

  • The compiled protocol achieves computational security against any computationally bounded quantum adversary, even when the original protocol only secured against 'almost honest' Bob.
  • Security in the bounded-quantum-storage model (BQSM) is preserved: the protocol remains secure only if the adversary has both large quantum memory and high computational power.
  • The protocol maintains unconditional security against dishonest Alice, ensuring that no information is leaked beyond what is intended.
  • The number of transmitted qubits and rounds is preserved up to a constant factor, making the compiler efficient and practical.
  • The use of an extractor MAC enables key reusability in classical authentication, allowing long-term security against man-in-the-middle attacks.
  • For quantum identification, the compiled protocol is secure against impersonation and man-in-the-middle attacks, with security requiring both large quantum memory and computational effort.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.