[Paper Review] Lower Bounds for Quantum Oblivious Transfer
This paper establishes fundamental lower bounds on cheating probabilities in quantum 1-out-of-2 oblivious transfer (OT) protocols, proving that no protocol can achieve cheating probabilities below 1/2 for either party. It introduces a two-message OT protocol with cheating probabilities bounded at 3/4 and extends Kitaev’s semidefinite programming framework to derive optimal bounds for general primitives with forcing security.
Oblivious transfer is a fundamental primitive in cryptography. While perfect information theoretic security is impossible, quantum oblivious transfer protocols can limit the dishonest players' cheating. Finding the optimal security parameters in such protocols is an important open question. In this paper we show that every 1-out-of-2 oblivious transfer protocol allows a dishonest party to cheat with probability bounded below by a constant strictly larger than 1/2. Alice's cheating is defined as her probability of guessing Bob's index, and Bob's cheating is defined as his probability of guessing both input bits of Alice. In our proof, we relate these cheating probabilities to the cheating probabilities of a coin flipping protocol and conclude by using Kitaev's coin flipping lower bound. Then, we present an oblivious transfer protocol with two messages and cheating probabilities at most 3/4. Last, we extend Kitaev's semidefinite programming formulation to more general primitives, where the security is against a dishonest player trying to force the outcome of the other player, and prove optimal lower and upper bounds for them.
Motivation & Objective
- To determine the optimal cheating probabilities in quantum oblivious transfer protocols under information-theoretic security.
- To close the gap between known upper bounds and lower bounds for quantum OT, particularly for 1-out-of-2 OT.
- To extend Kitaev’s semidefinite programming formulation to general primitives where one party can force the outcome of the other.
- To establish tight lower and upper bounds for forcing bias in quantum OT and related primitives.
Proposed method
- Formulates quantum oblivious transfer as a semidefinite program (SDP), adapting Kitaev’s framework for quantum coin flipping.
- Relates cheating probabilities in OT to those in quantum bit commitment, leveraging known lower bounds from prior work.
- Constructs a two-message OT protocol using quantum coin flipping subroutines to achieve bounded cheating probabilities.
- Derives a general lower bound on the product of cheating probabilities using SDP duality and honest outcome probabilities.
- Uses weak coin flipping protocols with cheating probability approaching $1/ ho$ to achieve near-optimal forcing bias.
- Proves that the forcing bias in $n race k$-fOT is bounded below by $\sqrt{2}^k$, and constructs a protocol achieving this bound asymptotically.
Experimental results
Research questions
- RQ1What is the minimum cheating probability achievable by a dishonest party in a quantum 1-out-of-2 oblivious transfer protocol?
- RQ2Can the lower bound on cheating probability in quantum OT be derived from known lower bounds in quantum bit commitment?
- RQ3What is the optimal trade-off between cheating probabilities for Alice and Bob in quantum OT, and can it be achieved?
- RQ4Can Kitaev’s semidefinite programming formulation be generalized to capture forcing security in broader classes of quantum primitives?
- RQ5Is there a protocol for $n race k$-fOT that achieves the theoretical lower bound on forcing bias?
Key findings
- Every 1-out-of-2 quantum oblivious transfer protocol allows a dishonest party to cheat with probability strictly greater than $1/2$, establishing a fundamental lower bound.
- A two-message quantum OT protocol is constructed with cheating probabilities at most $3/4$ for both parties, matching the best-known upper bound.
- The forcing bias in $n race k$-fOT is bounded below by $\sqrt{2}^k$, and this bound is tight up to a $1+\gamma$ factor.
- An optimal protocol for $2 race 1$-fOT is presented where both parties have honest outcome probability $1/4$, and cheating probability is bounded by $\frac{1}{\sqrt{8}}(1+\gamma)$ for any $\gamma > 0$.
- The protocol uses classical messages and quantum weak coin flipping subroutines, achieving near-optimal performance with polynomial-time quantum subroutines.
- The SDP formulation generalizes to arbitrary primitives with forcing security, enabling derivation of optimal lower and upper bounds.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.