International Association for Cryptologic Research

International Association
for Cryptologic Research

CryptoDB

Authentication of Quantum Messages

Authors:
Howard Barnum
Claude Crépeau
Daniel Gottesman
Adam Smith
Alain Tapp
Download:
URL: http://eprint.iacr.org/2002/082
Search ePrint
Search Google
Abstract: Authentication is a well-studied area of classical cryptography: a sender A and a receiver B sharing a classical private key want to exchange a classical message with the guarantee that the message has not been modified or replaced by a dishonest party with control of the communication line. In this paper we study the authentication of messages composed of quantum states. We give a formal definition of authentication in the quantum setting. Assuming A and B have access to an insecure quantum channel and share a private, classical random key, we provide a non-interactive scheme that both enables A to encrypt and authenticate (with unconditional security) an m qubit message by encoding it into m+s qubits, where the probability decreases exponentially in the security parameter s. The scheme requires a private key of size 2m+O(s). To achieve this, we give a highly efficient protocol for testing the purity of shared EPR pairs. It has long been known that learning information about a general quantum state will necessarily disturb it. We refine this result to show that such a disturbance can be done with few side effects, allowing it to circumvent cryptographic protections. Consequently, any scheme to authenticate quantum messages must also encrypt them. In contrast, no such constraint exists classically: authentication and encryption are independent tasks, and one can authenticate a message while leaving it publicly readable. This reasoning has two important consequences: On one hand, it allows us to give a lower bound of 2m key bits for authenticating m qubits, which makes our protocol asymptotically optimal. On the other hand, we use it to show that digitally signing quantum states is impossible, even with only computational security.
BibTeX
@misc{eprint-2002-11605,
  title={Authentication of Quantum Messages},
  booktitle={IACR Eprint archive},
  keywords={foundations / quantum cryptography, authentication codes, digital signatures},
  url={http://eprint.iacr.org/2002/082},
  note={ asmith@theory.lcs.mit.edu 11863 received 25 Jun 2002},
  author={Howard Barnum and Claude Crépeau and Daniel Gottesman and Adam Smith and Alain Tapp},
  year=2002
}