[Paper Review] Quantum Public-Key Encryption with Information Theoretic Security
This paper proposes a novel quantum public-key encryption scheme with information-theoretic security based on quantum state indistinguishability under chosen-plaintext attack (CPA). It introduces a new public-key structure using GHZ-like entangled states derived from classical functions, achieving security independent of computational assumptions by ensuring any distinguisher's advantage is bounded by inverse polynomial, even against unbounded quantum adversaries.
We propose a definition for the information theoretic security of a quantum public-key encryption scheme, and present bit-oriented and two-bit-oriented encryption schemes satisfying our security definition via the introduction of a new public-key algorithm structure. We extend the scheme to a multi-bitoriented one, and conjecture that it is also information theoretically secure, depending directly on the structure of our new algorithm.
Motivation & Objective
- To define information-theoretic security for quantum public-key encryption beyond computational assumptions.
- To address the vulnerability of classical public-key schemes in the post-quantum era.
- To design a quantum public-key encryption scheme that remains secure even against adversaries with unbounded quantum computational power.
- To extend existing quantum encryption schemes with stronger security guarantees based on quantum state indistinguishability.
- To provide a foundation for practical, information-theoretically secure quantum key exchange protocols.
Proposed method
- Introduces a new public-key structure using a classical function F: Ωₙ → Ωₙ as private key and a quantum state ρₖ,ᵢ⁰ as public key.
- Constructs two n-qubit quantum states ρₖ,ᵢ⁰ and ρₖ,ᵢ¹ using Hamming-weight-dependent superpositions and controlled phase flips.
- Employs permutation operators Pₖ to transform states into GHZ-like entangled states, enabling efficient state preparation.
- Uses Z-gate application on qubits to generate the complementary state ρₖ,ᵢ¹ from ρₖ,ᵢ⁰ when Wₕ(k) is odd.
- Defines ciphertext indistinguishability via a quantum circuit family {Cₙ}, requiring that no distinguisher can tell apart E(x) and E(y) with advantage better than 1/p(n).
- Designs a bit-oriented encryption scheme where the plaintext bit b determines whether ρₖ,ᵢ⁰ or ρₖ,ᵢ¹ is transmitted, with security based on the indistinguishability of these states.
Experimental results
Research questions
- RQ1Can a quantum public-key encryption scheme achieve information-theoretic security under CPA without relying on computational hardness assumptions?
- RQ2How can quantum state indistinguishability be formalized in the context of public-key encryption to ensure security against unbounded quantum adversaries?
- RQ3What structural properties of quantum states and classical functions enable information-theoretic security in quantum public-key systems?
- RQ4Can the proposed scheme be extended to multi-bit encryption while preserving information-theoretic security?
- RQ5What is the relationship between the Hamming weight of the key and the security of the resulting quantum states?
Key findings
- The proposed quantum public-key encryption scheme satisfies the definition of information-theoretic security under CPA, as any quantum distinguisher's advantage is bounded by 1/p(n) for any positive polynomial p(n).
- The scheme uses a novel public-key structure based on a classical function F and a quantum state ρₖ,ᵢ⁰, where k = F(s), ensuring that the public key reveals no information about the private key s.
- The encryption process leverages GHZ-like entangled states generated via permutation and phase operations, enabling efficient state preparation and transformation.
- The scheme achieves indistinguishability of ciphertexts for different plaintext bits by encoding them into orthogonal superpositions ρₖ,ᵢ⁰ and ρₖ,ᵢ¹, which are operationally indistinguishable without knowledge of k and i.
- The authors conjecture that the multi-bit extension of the scheme is also information-theoretically secure, based on the structural properties of the underlying algorithm.
- The security definition is stronger than prior work, as it removes the restriction to polynomial-size quantum circuits, making it applicable to unbounded quantum adversaries.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.