2010Physical Review AOpen access

Fundamental quantitative security in quantum key generation

Horace P. Yuen

Open full text 29 citations

Abstract

We analyze the fundamental security significance of the quantitative criteria on the final generated key $K$ in quantum key generation including the quantum criterion $d$, the attacker's mutual information on $K$, and the statistical distance between her distribution on $K$ and the uniform distribution. For operational significance a criterion has to produce a guarantee on the attacker's probability of correctly estimating some portions of $K$ from her measurement, in particular her maximum probability of identifying the whole $K$. We distinguish between the raw security of $K$ when the attacker just gets at $K$ before it is used in a cryptographic context and its composition security when the attacker may gain further information during its actual use to help get at $K$. We compare both of these securities of $K$ to those obtainable from conventional key expansion with a symmetric key cipher. It is pointed out that a common belief in the superior security of a quantum generated $K$ is based on an incorrect interpretation of $d$ which cannot be true, and the security significance of $d$ is uncertain. Generally, the quantum key distribution key $K$ has no composition security guarantee and its raw security guarantee from concrete protocols is worse than that of conventional ciphers. Furthermore, for both raw and composition security there is an exponential catch-up problem that would make it difficult to quantitatively improve the security of $K$ in a realistic protocol. Some possible ways to deal with the situation are suggested.

Open-access reader

About this research paper

What this paper is about

We analyze the fundamental security significance of the quantitative criteria on the final generated key $K$ in quantum key generation including the quantum criterion $d$, the attacker's mutual information on $K$, and the statistical distance between her distribution on $K$ and the uniform distribution. For operational significance a criterion has to produce a guarantee on the attacker's probability of correctly estimating some portions of $K$ from her measurement, in particular her maximum probability of identifying the whole $K$. We distinguish between the raw security of $K$ when the attacker just gets at $K$ before it is used in a cryptographic context and its composition security when the attacker may gain further information during its actual use to help get at $K$. We compare both of these securities of $K$ to those obtainable from conventional key expansion with a symmetric key cipher. It is pointed out that a common belief in the superior security of a quantum generated $K$ is based on an incorrect interpretation of $d$ which cannot be true, and the security significance of $d$ is uncertain. Generally, the quantum key distribution key $K$ has no composition security guarantee and its raw security guarantee from concrete protocols is worse than that of conventional ciphers. Furthermore, for both raw and composition security there is an exponential catch-up problem that would make it difficult to quantitatively improve the security of $K$ in a realistic protocol. Some possible ways to deal with the situation are suggested.

Why it matters

OpenAlex reports 29 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

We analyze the fundamental security significance of the quantitative criteria on the final generated key $K$ in quantum key generation including the quantum criterion $d$, the attacker's mutual information on $K$, and the statistical distance between her distribution on $K$ and the uniform distribution. For operational significance a criterion has to produce a guarantee on the attacker's probability of correctly estimating some portions of $K$ from her measurement, in particular her maximum probability of identifying the whole $K$. We distinguish between the raw security of $K$ when the attacker just gets at $K$ before it is used in a cryptographic context and its composition security when the attacker may gain further information during its actual use to help get at $K$. We compare both of these securities of $K$ to those obtainable from conventional key expansion with a symmetric key cipher. It is pointed out that a common belief in the superior security of a quantum generated $K$ is based on an incorrect interpretation of $d$ which cannot be true, and the security significance of $d$ is uncertain. Generally, the quantum key distribution key $K$ has no composition security guarantee and its raw security guarantee from concrete protocols is worse than that of conventional ciphers. Furthermore, for both raw and composition security there is an exponential catch-up problem that would make it difficult to quantitatively improve the security of $K$ in a realistic protocol. Some possible ways to deal with the situation are suggested.

Key concepts: Quantum key distribution, Computer science, Key (lock), Cryptography, Key generation, Cipher, Context (archaeology), Computer security

Related papers

Back to paper searchBrowse research topicsOriginal source
Fundamental quantitative security in quantum key generation — Research Paper | ScholarLens