An oblivious transfer protocol for quantum cryptography

July 1, 2008 By Miranda Marquit

“It's hard to beat the noise that you have with quantum information,” Barbara Terhal tells PhysOrg.com. “So our security protocol relies on the fact that storing quantum bits noiselessly is hard to do with current technology.”

Terhal is a scientist working at the IBM Watson Research Center in Yorktown Heights, New York. She collaborated with Stephanie Wehner and Christian Schaffner at CWI in Amsterdam on this project that is designed to provide a proof of principle for a form of cryptography known as oblivious transfer. Their work is published in Physical Review Letters: “Cryptography from Noisy Storage.”

Quantum cryptography, as first proposed by Charles Bennett and Gilles Brassard in 1984, Terhal explains, “is a protocol for two parties to generate a random bit string such that no third party knows the values of the bits. The random bit string can then be used as a key to send a secret message. The message is encrypted with the key by the sender and decrypted using the key by the receiver. This quantum technology has been realized now.”

Terhal and her co-workers propose to implement a different cryptographic protocol called oblivious transfer using quantum information. “We prove the security of our protocol under the assumption that one cannot yet store quantum information noiselessly,” Terhal says.

“In an oblivious transfer,” Terhal explains, “the sender Alice has two bits. The goal of the protocol is to transmit one of these bits to a receiver Bob, such that Bob determines which one he gets, but Alice does not know which one he gets. In addition, Bob is not allowed to learn anything about the other bit that Alice has.”

Terhal points out that oblivious transfer is used when one of the parties might be dishonest: “For example Bob can try to learn both bits. In the protocol Alice encodes two bits in quantum states. Because Bob cannot reliably store these qubits, he is forced to measure the qubits. The quantum encoding, similar as in the Bennett-Brassard scheme, ensures that he can learn – at most – one of the bits.” If he decides to store the qubits anyway, Terhal and her peers show that the noise involved in the storage will prevent Bob from learning the bits as well.

The main interest in oblivious transfer stems from the fact that the protocol can provide a basis for secure identification. Terhal offers a real-world application for oblivious transfer: “There are many scams that have to do with ATMs. You stick in your card, and you may give away your password. With a cryptographic scheme based on oblivious transfer, you won’t give your password away to a fraudulent ATM. The bank ATM needs to test that you know the password, and you need to test whether the bank knows your password, which it should if it is a proper ATM. With this protocol, the password isn’t explicitly exchanged, but it is established that both you and the bank know the password.”

The oblivious transfer protocol has not been made to work yet. However, Terhal and her colleagues think that their theory, using a model that assumes noisy storage, constitutes a proof of principle that could lead to oblivious transfer in practice. “It’s more of a theory right now,” Terhal admits. “It’s really a security proof that offers first principles that you can build something.”

“There are people working on better quantum memory and storage, in particular for photonic qubits which can be used in this protocol,” Terhal says, “but we wanted to create a protocol that is derived from current technology. We’re using the fact that quantum storage is noisy.”

Copyright 2007 PhysOrg.com.
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in whole or part without the express written permission of PhysOrg.com.


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 4.4 /5 (22 votes)

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • menkaur - Jul 01, 2008
    • Rank: 3.3 / 5 (3)
    come on... base a protocol on technology imperfection? are you insane ? )
  • Iztaru - Jul 02, 2008
    • Rank: 2.5 / 5 (2)
    are you insane ?


    Not really. Parents do that all the time when they put the candies taller than their kids can reach. The method will be render useless when they grow up, but in the mean time is a perfect and cheap solution for a problem. Otherwise, you would have to buy a safe or something similar.

    There cannot be a general purpose fit-all security mechanism. You have to consider the alternatives. And considering that noise in quantum storage is a real situation now, why not taking advantage of it?

July 1, 2008 all stories

Comments: 2

4.4 /5 (22 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories




  • hide
  • Relevant PhysicsForums posts

  • Speed of light : missing energy
    created 3 hours ago
  • Can light produce darkness and can noise procude quiteness 4
    created 5 hours ago
  • Magnetic Oscillation Equations
    created 11 hours ago
  • US Physics Test Eligibility
    created 12 hours ago
  • More from Physics Forums - General Physics

Other News

Quick restart of Big Bang machine stuns scientists (AP)

Quick restart of Big Bang machine stuns scientists

Physics / General Physics

created 3 hours ago | popularity 4.4 / 5 (11) | comments 2

(AP) -- Scientists moved Saturday to prepare the world's largest atom smasher for exploring the depths of matter after successfully restarting the $10 billion machine following more than a year of repairs.


A view of a superconducting solenoid magnet at the European Organization for Nuclear Research (CERN) near Geneva

CERN atom-smasher restarts after 14-month hiatus: official

Physics / General Physics

created 23 hours ago | popularity 4.6 / 5 (22) | comments 0

The world's biggest atom-smasher, shut down after its inauguration in September 2008 amid technical faults, restarted on Friday, a spokesman for the European Organisation for Nuclear Research said.


Tapering a Free-Electron Laser to Extract More Juice

Tapering a Free-Electron Laser to Extract More Juice

Physics / General Physics

created 23 hours ago | popularity 4 / 5 (1) | comments 0

(PhysOrg.com) -- Researchers from the NSLS and Science Applications International Corporation (SAIC) have demonstrated a technique that could be used to significantly improve the quantity and quality of light ...


nuclear power plant

Doubts raised on nuclear industry viability

Physics / General Physics

created Nov 19, 2009 | popularity 3.2 / 5 (17) | comments 18

(PhysOrg.com) -- The investment in nuclear power has been growing around the world over the last few years, being viewed as a means for countries to control their energy security, avoid the price fluctuations ...


Researchers Find Innate Correlations Among Different Power Law Phenomena

Researchers Find Innate Correlations Among Different Power Law Phenomena

Physics / General Physics

created Nov 17, 2009 | popularity 4.3 / 5 (15) | comments 12

(PhysOrg.com) -- Studying the patterns that emerge in natural and social phenomena is a popular area of research, although usually individual phenomena are studied separately from each other. In a recent study, ...