Skip to main content
QUICK REVIEW

[论文解读] Generalised entropy accumulation

Tony Metger, Omar Fawzi|arXiv (Cornell University)|Mar 9, 2022
Physical Unclonable Functions (PUFs) and Hardware Security被引用 5
一句话总结

本文提出了一种广义熵累积定理(广义EAT),将原始熵累积定理(EAT)扩展至更广泛的量子侧信息模型,允许动态更新的侧信息。通过放宽原始EAT所需的马尔可夫条件,广义EAT使得在量子密码学中能够实现更紧致且更广泛适用的安全性证明,包括首次对一般对手下盲随机性扩展协议的安全性证明。

ABSTRACT

Consider a sequential process in which each step outputs a system $A_i$ and updates a side information register $E$. We prove that if this process satisfies a natural "non-signalling" condition between past outputs and future side information, the min-entropy of the outputs $A_1, \dots, A_n$ conditioned on the side information $E$ at the end of the process can be bounded from below by a sum of von Neumann entropies associated with the individual steps. This is a generalisation of the entropy accumulation theorem (EAT), which deals with a more restrictive model of side information: there, past side information cannot be updated in subsequent rounds, and newly generated side information has to satisfy a Markov condition. Due to its more general model of side-information, our generalised EAT can be applied more easily and to a broader range of cryptographic protocols. As examples, we give the first multi-round security proof for blind randomness expansion and a simplified analysis of the E91 QKD protocol. The proof of our generalised EAT relies on a new variant of Uhlmann's theorem and new chain rules for the Renyi divergence and entropy, which might be of independent interest.

研究动机与目标

  • 开发一种更通用的框架,用于在侧信息可在各轮之间更新的量子协议中界定最小熵。
  • 克服原始熵累积定理(EAT)的局限性,该定理对侧信息施加了严格的马尔可夫条件。
  • 实现对不完全信任的设备无关量子密码学协议(如盲随机性扩展)的安全性证明。
  • 提供一种适用于更广泛量子密码学协议的工具,包括对E91型量子密钥分发协议的改进安全性证明。
  • 确立非信号条件作为序列熵累积中马尔可夫条件的自然替代方案。

提出的方法

  • 广义EAT将序列量子过程建模为每轮输出系统 $A_i$ 并更新侧信息寄存器 $E$,其中过去输出与未来侧信息之间满足非信号条件。
  • 证明了在最终侧信息 $E_n$ 条件下,完整输出序列 $A_1^n$ 的平滑最小熵下界由各轮的冯·诺依曼熵 $H(A_i|E_i)$ 之和给出。
  • 非信号条件取代了原始EAT中的马尔可夫条件,使得侧信息可在各轮之间被更新和重用。
  • 该方法使用Rényi散度和谱压紧技术,推导出条件Rényi熵的强化链式法则。
  • 通过熵不确定关系构造了最小收益函数,从而在E91和盲随机性扩展等协议中推导出最小熵的下界。
  • 该框架支持对经典和量子侧信息进行条件化处理,包括将 $X^n$ 等系统加入侧信息寄存器以满足非信号条件。

实验结果

研究问题

  • RQ1熵累积定理能否被推广,以允许在序列量子协议中对动态更新的侧信息进行处理?
  • RQ2在仍能实现紧致最小熵下界的前提下,如何放宽原始EAT中的马尔可夫条件?
  • RQ3广义EAT能否应用于不完全信任的设备无关协议(如盲随机性扩展)?
  • RQ4非信号条件在替代熵累积中马尔可夫侧信息结构方面起到何种作用?
  • RQ5广义EAT能否为E91等量子密钥分发协议提供改进的安全性证明?

主要发现

  • 广义EAT在非信号条件下,建立了平滑最小熵 $H_{\textnormal{min}}^{\bar{ε}}(A^n|E_n)$ 的下界,其表达为各轮冯·诺依曼熵 $H(A_i|E_i)$ 之和。
  • 该定理首次实现了对一般对手下盲随机性扩展协议的安全性证明,该协议此前不在原始EAT的适用范围内。
  • 广义EAT避免了为满足马尔可夫条件而添加辅助系统(如 $\bar{A}_i$)的需要,从而减少了安全性界中的熵惩罚项。
  • 该方法允许侧信息在各轮之间被更新,包括量子系统 $Q_i^n\bar{Q}_i^n$ 和经典数据 $X_i$,这些均可被整合进侧信息寄存器 $E_i$。
  • 该框架支持使用基于熵不确定关系构造的最小收益函数,从而在E91 QKD等协议中实现具体的最小熵下界。
  • 通过去除对侧信息的独立同分布或马尔可夫性假设,广义EAT实现了更紧致且更灵活的安全性边界。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。