[Paper Review] Quantum McEliece public-key encryption scheme
This paper proposes a quantum McEliece public-key encryption (QPKE) scheme for encrypting quantum messages using classical keys, based on the hardness of NP-complete problems in coding theory. It introduces a double-encryption technique to enhance security, proving the improved scheme is more secure than the original but less secure than the quantum one-time pad, while maintaining efficiency and avoiding unnecessary quantum error correction functionality.
This paper investigates a quantum version of McEliece public-key encryption (PKE) scheme, and analyzes its security. As is well known, the security of classical McEliece PKE is not stronger than the onewayness of related classical one-way function. We prove the security of quantum McEliece PKE ranks between them. Moreover, we propose the double-encryption technique to improve its security, and the security of the improved scheme is proved to be between the original scheme and the quantum one-time pad.
Motivation & Objective
- To design a quantum public-key encryption scheme capable of securely encrypting quantum messages using classical keys.
- To analyze the security of the original quantum McEliece PKE scheme proposed in Ref. [8], which is based on classical error-correcting codes.
- To improve the security of the original scheme using a double-encryption technique that introduces additional randomness during encryption.
- To demonstrate that the improved scheme maintains practicality while offering stronger resistance to known attacks than the original.
- To clarify misconceptions about the original scheme’s vulnerability to classical attacks when used for classical message encryption.
Proposed method
- The scheme uses a classical McEliece-like structure: a public key derived from a Goppa code via scrambling with invertible and permutation matrices.
- Quantum messages are encrypted by applying a unitary transformation based on the public key, using a random vector to mask the message.
- The double-encryption technique applies two independent random masks in sequence, increasing the entropy of the ciphertext and thwarting chosen-plaintext attacks.
- Security is analyzed in terms of computational indistinguishability, with bounds derived from the hardness of decoding random linear codes (an NP-complete problem).
- The scheme avoids quantum error correction functionality, simplifying encoding/decoding while preserving security for quantum message encryption.
- Theoretical analysis shows that repeated use of double-encryption reduces security, as the advantage of randomness diminishes over multiple encryptions.
Experimental results
Research questions
- RQ1Is the original quantum McEliece PKE scheme secure against quantum adversaries, and how does its security compare to classical McEliece?
- RQ2Can the security of the quantum McEliece PKE be enhanced without introducing quantum error correction, which is not required for encryption?
- RQ3What is the impact of multiple encryptions on the security of the double-encryption variant?
- RQ4Why do classical attacks like Korzhik-Turkin and message-resend attacks fail against the quantum McEliece PKE?
- RQ5How does the security of the double-encryption scheme compare to the quantum one-time pad and the original scheme?
Key findings
- The original quantum McEliece PKE is at least as secure as its classical counterpart, with security bounded by the one-wayness of the underlying classical one-way function.
- The double-encryption scheme improves security beyond the original scheme, but its security degrades with repeated use due to reduced randomness advantage.
- The improved scheme is proven to be more secure than the original but less secure than the quantum one-time pad, establishing a security hierarchy.
- Classical attacks such as Korzhik-Turkin, message-resend, and related-message attacks fail against the quantum McEliece PKE due to the non-reusability of quantum states and the structure of the encryption process.
- The scheme is more efficient and simpler than Fujita’s quantum McEliece variant because it omits quantum error correction, which is unnecessary for public-key encryption.
- The scheme can be used to encrypt classical messages as a 'quantum envelope' with enhanced security compared to classical McEliece, due to the incompatibility of classical attacks with quantum states.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.