Skip to main content
QUICK REVIEW

[Paper Review] Quantum oblivious transfer and bit commitment protocols based on two non-orthogonal states coding

Li Yang|arXiv (Cornell University)|Jun 25, 2013
Quantum Information and Cryptography2 references3 citations
TL;DR

This paper proposes quantum oblivious transfer (R-OT and OT₁²) and bit commitment protocols based on non-orthogonal quantum states, using two non-orthogonal states with a fixed angle (π/4) to enable secure information transfer. Although the protocols are unconditionally secure against individual attacks, they are not secure against entanglement-based attacks as per the no-go theorem, but are physically secure due to practical limitations in quantum memory and matrix size.

ABSTRACT

Oblivious transfer protocols (R-OT and OT$_{1}^{2}$) are presented based on non-orthogonal states transmission, and the bit commitment protocols on the top of OT$_{1}^{2}$ are constructed. Although these OT protocols are all unconditional secure, the bit commitment protocols based on OT protocols are not secure against attack similar to that presented by no-go theorem.

Motivation & Objective

  • To design quantum oblivious transfer protocols based on non-orthogonal quantum states for unconditional security in key distribution.
  • To construct bit commitment protocols using the OT₁² protocol as a foundation, aiming for practical security despite theoretical limitations.
  • To analyze the physical feasibility of quantum bit commitment under realistic constraints such as finite quantum memory and matrix size.
  • To demonstrate that protocols can be physically secure even if not unconditionally secure under the no-go theorem.
  • To explore the trade-off between theoretical security and practical implementability in quantum cryptography.

Proposed method

  • Uses two non-orthogonal quantum states |Ψ₀⟩ and |Ψ₁⟩ with ⟨Ψ₀|Ψ₁⟩ = cos(π/4) = √2/2 to encode bits, enabling distinguishability with optimal probability 1 - √2/2.
  • Employs a measurement basis choice strategy: Bob randomly selects between B₀ = {|Ψ₀⟩, |Ψ₀⟩⊥} and B₁ = {|Ψ₁⟩, |Ψ₁⟩⊥}, accepting only when measuring |Ψₓ⟩⊥ to infer rₓ⊕1.
  • Constructs OT₁² via Crépeau’s framework using R-OT, where Bob selects k conclusive bits from his results and commits to a random basis choice (X,Y) to enable Alice to encrypt messages.
  • Applies XOR-based encryption: c₀ = b₀ ⊕ s₀, c₁ = b₁ ⊕ s₁, where s₀ and s₁ are XORs of selected bit strings, enabling Bob to recover only one message.
  • Proposes a bit commitment protocol using Bell states |Φ⁻⟩, where Alice modifies qubits via Ry(−π/2) rotation based on her bit string, and Bob verifies via projective measurement.
  • Introduces a simplified protocol using single-qubit states with angle encoding, where Alice rotates states by π/4 based on her bits, and Bob verifies using random basis measurements.

Experimental results

Research questions

  • RQ1Can oblivious transfer be securely implemented using only two non-orthogonal quantum states, without requiring entanglement?
  • RQ2To what extent can bit commitment protocols be made physically secure despite the no-go theorem forbidding unconditional security?
  • RQ3What is the impact of practical limitations—such as finite quantum memory and matrix size—on the feasibility of entanglement-based attacks?
  • RQ4How does the choice of measurement basis and state encoding affect the success probability and security of quantum oblivious transfer?
  • RQ5Can a bit commitment protocol be constructed that is secure in practice even if not unconditionally secure in theory?

Key findings

  • The R-OT protocol achieves a conclusive bit success probability of 1/4 per qubit using a simple measurement basis strategy, with honest Bob obtaining approximately n/4 conclusive bits.
  • The OT₁² protocol is unconditionally secure when the probability of honest Bob obtaining more than k conclusive bits (p₁) approaches 1 exponentially, and malicious Bob obtaining 2k or more bits (p₂) approaches 0 exponentially, as n → ∞.
  • The bit commitment protocol based on Bell states |Φ⁻⟩ is not unconditionally secure due to entanglement-based attacks, but becomes physically secure due to the infeasibility of storing or manipulating large-scale unitary matrices (e.g., 2²⁰⁰ × 2²⁰⁰ for 2k=200).
  • The simplified protocol using single-qubit states with angle encoding avoids quantum memory requirements if Bob measures during the commit phase, but remains vulnerable to qubit omission attacks unless detectors are perfect.
  • The physical security of the protocols stems from the astronomical size of required unitary transformations (e.g., 2²⁰⁰ matrix entries) and limited quantum memory lifetime, making attacks infeasible in practice.
  • Even though the protocols do not satisfy the full conditions of unconditional security under the no-go theorem, they are physically secure due to practical constraints on quantum operations and storage.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.