Skip to main content
QUICK REVIEW

[Paper Review] Quantum authentication with key recycling

Christopher Portmann|arXiv (Cornell University)|Oct 11, 2016
Quantum Information and Cryptography4 citations
TL;DR

This paper presents a composable security proof for quantum authentication protocols with full key recycling, demonstrating that all secret key bits can be recycled upon successful message authentication and partial recycling upon tampering detection. The protocol leverages quantum error-detecting codes and unitary operations to construct a secure quantum channel from an insecure channel and a shared secret key, achieving optimal key recycling with bounded security error.

ABSTRACT

We show that a family of quantum authentication protocols introduced in [Barnum et al., FOCS 2002] can be used to construct a secure quantum channel and additionally recycle all of the secret key if the message is successfully authenticated, and recycle part of the key if tampering is detected. We give a full security proof that constructs the secure channel given only insecure noisy channels and a shared secret key. We also prove that the number of recycled key bits is optimal for this family of protocols, i.e., there exists an adversarial strategy to obtain all non-recycled bits. Previous works recycled less key and only gave partial security proofs, since they did not consider all possible distinguishers (environments) that may be used to distinguish the real setting from the ideal secure quantum channel and secret key resource.

Motivation & Objective

  • To provide a complete composable security proof for quantum authentication protocols with key recycling, addressing gaps in prior work.
  • To demonstrate that all secret key bits can be recycled when a message is successfully authenticated.
  • To prove that partial key recycling occurs when tampering is detected, ensuring optimal key reuse.
  • To close the security gap in prior works by considering all possible distinguishers, including impersonation attacks.
  • To establish that the number of recycled key bits is optimal, with an adversary strategy that can recover all non-recycled bits.

Proposed method

  • Uses a family of quantum authentication protocols from Barnum et al. (2002) with unitary encoding and quantum error-detecting codes.
  • Employs a two-stage protocol: encrypt-then-encode and its reverse, with key recycling based on syndrome measurement.
  • Introduces a simulator that prepares EPR pairs and uses random unitaries to emulate the real protocol's behavior under different distinguisher orders.
  • Applies trace distance analysis to bound the distinguishability between real and ideal systems, with error terms derived from code detection properties.
  • Considers both substitution and impersonation attacks by modeling distinguishers that can input forged ciphers before or after messages.
  • Uses weak purity testing codes and proves security via trace distance bounds involving the code's detection capability and key space size.

Experimental results

Research questions

  • RQ1Can quantum authentication protocols with key recycling be proven secure under all possible distinguishers, including impersonation attacks?
  • RQ2Is the number of recycled key bits optimal for the given protocol family?
  • RQ3Does the security proof remain composable when the protocol is used in an arbitrary environment?
  • RQ4Can full key recycling be achieved upon successful authentication, and partial recycling upon tampering?
  • RQ5What is the exact error bound for the composed protocol, and how does it scale with protocol parameters?

Key findings

  • The protocol achieves full key recycling upon successful authentication and partial recycling upon tampering detection.
  • The security error is bounded by εq-auth = max{ε, 2−n}, where ε is the channel error and n is the number of qubits in the code.
  • The number of recycled key bits is optimal: an adversary can recover all non-recycled bits, proving no protocol in this family can recycle more.
  • The composable security proof accounts for all distinguishers, including impersonation attacks, which previous works overlooked.
  • The proof establishes that the encrypt-then-encode and its reverse protocol variants securely construct the ideal secure quantum channel Sm♭ from an insecure channel and a secret key.
  • The trace distance between real and ideal systems is bounded by the sum of code detection failure probability and 2−n, ensuring composable security.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.