An oblivious transfer protocol for quantum cryptography

July 1, 2008 By Miranda Marquit

“It's hard to beat the noise that you have with quantum information,” Barbara Terhal tells PhysOrg.com. “So our security protocol relies on the fact that storing quantum bits noiselessly is hard to do with current technology.”

Terhal is a scientist working at the IBM Watson Research Center in Yorktown Heights, New York. She collaborated with Stephanie Wehner and Christian Schaffner at CWI in Amsterdam on this project that is designed to provide a proof of principle for a form of cryptography known as oblivious transfer. Their work is published in Physical Review Letters: “Cryptography from Noisy Storage.”

Quantum cryptography, as first proposed by Charles Bennett and Gilles Brassard in 1984, Terhal explains, “is a protocol for two parties to generate a random bit string such that no third party knows the values of the bits. The random bit string can then be used as a key to send a secret message. The message is encrypted with the key by the sender and decrypted using the key by the receiver. This quantum technology has been realized now.”

Terhal and her co-workers propose to implement a different cryptographic protocol called oblivious transfer using quantum information. “We prove the security of our protocol under the assumption that one cannot yet store quantum information noiselessly,” Terhal says.

“In an oblivious transfer,” Terhal explains, “the sender Alice has two bits. The goal of the protocol is to transmit one of these bits to a receiver Bob, such that Bob determines which one he gets, but Alice does not know which one he gets. In addition, Bob is not allowed to learn anything about the other bit that Alice has.”

Terhal points out that oblivious transfer is used when one of the parties might be dishonest: “For example Bob can try to learn both bits. In the protocol Alice encodes two bits in quantum states. Because Bob cannot reliably store these qubits, he is forced to measure the qubits. The quantum encoding, similar as in the Bennett-Brassard scheme, ensures that he can learn – at most – one of the bits.” If he decides to store the qubits anyway, Terhal and her peers show that the noise involved in the storage will prevent Bob from learning the bits as well.

The main interest in oblivious transfer stems from the fact that the protocol can provide a basis for secure identification. Terhal offers a real-world application for oblivious transfer: “There are many scams that have to do with ATMs. You stick in your card, and you may give away your password. With a cryptographic scheme based on oblivious transfer, you won’t give your password away to a fraudulent ATM. The bank ATM needs to test that you know the password, and you need to test whether the bank knows your password, which it should if it is a proper ATM. With this protocol, the password isn’t explicitly exchanged, but it is established that both you and the bank know the password.”

The oblivious transfer protocol has not been made to work yet. However, Terhal and her colleagues think that their theory, using a model that assumes noisy storage, constitutes a proof of principle that could lead to oblivious transfer in practice. “It’s more of a theory right now,” Terhal admits. “It’s really a security proof that offers first principles that you can build something.”

“There are people working on better quantum memory and storage, in particular for photonic qubits which can be used in this protocol,” Terhal says, “but we wanted to create a protocol that is derived from current technology. We’re using the fact that quantum storage is noisy.”

Copyright 2007 PhysOrg.com.
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in whole or part without the express written permission of PhysOrg.com.


   
Rate this story - 4.4 /5 (22 votes)

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • menkaur - Jul 01, 2008
    • Rank: 3.3 / 5 (3)
    come on... base a protocol on technology imperfection? are you insane ? )
  • Iztaru - Jul 02, 2008
    • Rank: 2.5 / 5 (2)
    are you insane ?


    Not really. Parents do that all the time when they put the candies taller than their kids can reach. The method will be render useless when they grow up, but in the mean time is a perfect and cheap solution for a problem. Otherwise, you would have to buy a safe or something similar.

    There cannot be a general purpose fit-all security mechanism. You have to consider the alternatives. And considering that noise in quantum storage is a real situation now, why not taking advantage of it?

July 1, 2008 all stories

Comments: 2

4.4 /5 (22 votes)

  • hide
  • Related Stories




  • hide
  • Relevant PhysicsForums posts

  • Pressure created by clamping base and cover
    created 36 minutes ago
  • How to find static friction
    created 6 hours ago
  • Calculating decible increases
    created 13 hours ago
  • Coefficients of friction
    created 13 hours ago
  • More from Physics Forums - General Physics

Other News

Extra large carbon

Extra large carbon

Physics / General Physics

created 13 hours ago | popularity 4.7 / 5 (12) | comments 7 | with audio podcast

An exotic form of carbon has been found to have an extra large nucleus, dwarfing even the nuclei of much heavier elements like copper and zinc, in experiments performed in a particle accelerator in Japan. ...


Scientist explore future of high-energy physics

Scientist explore future of high-energy physics

Physics / General Physics

created 19 hours ago | popularity 4.9 / 5 (12) | comments 8 | with audio podcast

In a 1954 speech to the American Physical Society, the University of Chicago's Enrico Fermi fancifully envisioned a particle accelerator that encircled the globe. Such would be the ultimate theoretical outcome, ...


Leaf veins inspire a new model for distribution networks (w/ Video)

Physics / General Physics

created 16 hours ago | popularity 5 / 5 (3) | comments 0 | with audio podcast

(PhysOrg.com) -- Following the straight and narrow may be good moral advice, but it’s not a great design principle for a distribution network. In new research, a team of biophysicists describe a complex netting of interconnected ...


New magnetic tuning method enhances data storage

New magnetic tuning method enhances data storage

Physics / General Physics

created 20 hours ago | popularity 4.2 / 5 (5) | comments 0 | with audio podcast

Researchers in Chicago and London have developed a method for controlling the properties of magnets that could be used to improve the storage capacity of next-generation computer hard drives.


High-performance microring resonator developed by INRS researchers

Physics / Optics & Photonics

created 12 hours ago | popularity 1.5 / 5 (2) | comments 0

A new, more efficient low-cost microring resonator for high speed telecommunications systems has been developed and tested by Professor Roberto Morandotti's INRS team in collaboration with Canadian, American, and Australian ...