Skip to main content
QUICK REVIEW

[论文解读] Unconditionally Secure Quantum Coin Tossing

Dominic Mayers, Louis Salvail|arXiv (Cornell University)|Apr 22, 1999
Quantum Computing Algorithms and Architecture参考文献 9被引用 17
一句话总结

本文提出了一种无条件安全的量子硬币 tossing 协议,通过在轮次中并行执行 m 个有偏的量子硬币 tossing 协议,实现小于 1/m 的偏差,每个协议使用 4n 个粒子,其中 n ∈ O(lg m)。最终的位是 m 个结果的异或,该协议通过逐步揭示信息,避免了对位承诺的已知攻击,证明了精确硬币 tossing 在理论上不可能实现,同时在安全参数 m 增大时实现了偏差递减的近乎完美安全性。

ABSTRACT

In coin tossing two remote participants want to share a uniformly distributed random bit. At the least in the quantum version, each participant test whether or not the other has attempted to create a bias on this bit. It is requested that, for b = 0,1, the probability that Alice gets bit b and pass the test is smaller than 1/2 whatever she does, and similarly for Bob. If the bound 1/2 holds perfectly against any of the two participants, the task realised is called an exact coin tossing. If the bound is actually $1/2 + ξ$ where the bias $ξ$ vanishes when a security parameter m defined by the protocol increases, the task realised is a (non exact) coin tossing. It is found here that exact coin tossing is impossible. At the same time, an unconditionally secure quantum protocol that realises a (non exact) coin tossing is proposed. The protocol executes m biased quantum coin tossing procedures at the same time. It executes the first round in each of these m procedures sequentially, then the second rounds are executed, and so on until the end of the n procedures. Each procedure requires 4n particles where $n \in O(\lg m)$. The final bit x is the parity of the m random bits. The information about each of these m bits is announced a little bit at a time which implies that the principle used against bit commitment does not apply. The bias on x is smaller than $1/m$. The result is discussed in the light of the impossibility result for exact coin tossing.

研究动机与目标

  • 探究无条件安全的精确量子硬币 tossing 是否可能实现。
  • 解决在量子环境下无法实现精确硬币 tossing 的根本限制。
  • 设计一种协议,实现近乎完美的安全性,且偏差随安全参数 m 增大而减小。
  • 通过避免位承诺不可能性原理的适用性,克服现有协议的局限性。
  • 提供一种具有可证明安全性且偏差随 m 增大而减小的实用量子硬币 tossing 方案。

提出的方法

  • 协议在轮次中顺序执行 m 个有偏量子硬币 tossing 实例的并行运行。
  • 每个独立的硬币 tossing 程序使用 4n 个粒子,其中 n 属于 O(lg m),确保资源规模随 m 对数增长。
  • 逐步揭示关于 m 个位的信息,防止位承诺协议被破坏的原理生效。
  • 最终结果 x 计算为 m 个协议生成的独立随机位的异或。
  • 协议确保即使拥有无限量子计算能力的参与者,也无法将最终结果偏差超过 1/m。
  • 通过组合多轮并行执行,协议实现了偏差随 m 增大而减小的特性。

实验结果

研究问题

  • RQ1在原则上,能否实现无条件安全的精确量子硬币 tossing?
  • RQ2在无条件安全条件下,量子硬币 tossing 的偏差是否存在根本限制?
  • RQ3如何设计一种量子硬币 tossing 协议,以避免适用于位承诺的不可能性结果?
  • RQ4能否构造一种协议,使得偏差随安全参数 m 的函数而减小?
  • RQ5在量子硬币 tossing 中,实现偏差小于 1/m 所需的资源要求是什么?

主要发现

  • 在无条件安全下,精确量子硬币 tossing 不可能实现,论文已证明此结论。
  • 所提出的协议实现了小于 1/m 的偏差,且随着安全参数 m 增大而减小。
  • 该协议使用 m 个并行执行的量子硬币 tossing 程序,每轮在轮次中运行,每个程序使用 4n 个粒子,其中 n ∈ O(lg m)。
  • 最终结果为 m 个独立生成位的异或,确保偏差通过大数定律被降低。
  • 逐步揭示信息可防止位承诺不可能性原理的应用,从而实现安全性。
  • 该协议提供了一种实用的、无条件安全的量子硬币 tossing 方案,其偏差可证明随 m 增大而减小。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。