• No results found

In this section we consider quantum protocols in which the participants enforce recipient symmetry by exchanging a selection of their measurement outcomes. For simplicity, we again restrict to the three-party scenario. An example of an exchange procedure is described in Step 6 of the distribution stage of Protocol 1 (see Section 2.4). The aim of the exchange procedure is to leave Bob and Charlie with outcomes that have the same expected error rate with whatever signature Alice can later declare. For this to happen, Bob and Charlie must exchange their measurement

outcomes in secret so that Alice cannot selectively introduce errors for one party and not the other.

The end result of the exchange process is that, regardless of what Alice sends, Bob and Charlie have the same expected error rates with Alice’s future signature declaration. Therefore, it is natural to ask: is it sensible for protocols to require an honest Alice to send the same states to Bob and Charlie?

Same-state vs different-state protocols

The exchange process ensures that security against repudiation and non-transferability are guaranteed regardless of whether Alice sends the same or different states to each recipient. On the other hand, having Alice send the same states to recipients helps dishonest forgers by weakening the partial information recovery property – a dishon- est Bob is provided with a perfect copy of the states sent to Charlie. For protocols involving larger numbers of participants the situation is even worse, since dishonest coalitions would have access to many copies of the states sent to honest participants, thereby allowing them to make accurate estimates of exactly what Alice sent.

As such, same-state quantum protocols place highly restrictive limitations on the number of participants allowed in any quantum USS scheme. Instead, it seems more efficient and secure to specify exchange-type protocols in which Alice sends different states to Bob and Charlie, similarly to the classical USS scheme P2 [1].

Basis reconciliation

In this subsection we consider Protocol 1 from Section 2.4 and consider how it could be improved. Based on the discussion in the previous subsection, we immediately make the modification that an honest Alice is not required to send the same states to Bob and Charlie. Instead, each state that is sent to Bob or Charlie is chosen independently and uniformly at random from the set {|0i , |1i , |+i , |−i}.

We further examine whether it is more efficient for recipients to perform the unambiguous state elimination (USE) measurements used in Protocol 1, or whether it is beneficial to include a BB84-style processing stage where the sender and receiver announce their basis choices and only results in matching bases are kept. Based on the discussion in the remainder of this subsection, we will conclude that for a number of reasons it is better to use the latter.

For non-repudiation and transferability, it is the exchange process that ensures security. Without a basis reconciliation step Alice does not know which basis each recipient chose to measure in. Whenever an element of her signature is expressed

in a different basis to the chosen measurement basis, this signature element will not cause an error, regardless of who made the measurement. Effectively, this means Alice’s signature contains redundant information that does not provide additional security against these threats. Shorter signatures are desirable because they are ap- pended to the message transmitted, and so carry a communication cost. Performing basis reconciliation allows for a shorter signature lengths and does not compromise security.

For forging, since Alice sends different states to Bob and Charlie, a dishonest Bob’s information comes entirely from eavesdropping on the Alice-Charlie channel. Without basis reconciliation, each signature element is taken from the set SU SE =

{0, 1, +, −}. When Bob is trying to forge, for each signature element he is trying to choose one of the 3 members of SU SE that do not cause a mismatch with Charlie’s

recorded outcome. Recall that Charlie performs an USE measurement to exclude a single element of SU SE, and a mismatch occurs if Bob declares the excluded element.

With basis reconciliation, each signature element is taken from the set SBR = {0, 1},

and Bob is trying to choose one of the two members of SBR that will not cause a

mismatch with Charlie’s recorded outcome. Therefore, a naïve argument suggests that Bob’s task is easier without basis reconciliation, since 3 out of the 4 elements of SU SE will not cause a mismatch.

However, this naïve argument may not be correct, since the basis declaration step reveals additional information which Bob may be able to use to help him to forge a message. Nevertheless, as in QKD, it can be shown that so long as the Alice-Charlie quantum channel error rate is reasonably small, the basis declaration does not reveal much information to Bob. For signatures of equal length, the forger’s task is indeed harder with basis reconciliation than without. Intuitively, this can be understood as follows. Without basis reconciliation, Bob has more freedom in choosing his forging strategy. Whenever an element of Bob’s dishonest signature is specified in a different basis to Charlie’s measurement, Charlie will never find a mismatch on that element. In this way, allowing the potential of mismatched bases helps the forger to reduce his overall error rate. Therefore, although the basis declaration reveals some small amount of information to the forger, this is offset by forcing the forger to declare elements in the same basis as measured by the verifier Charlie.

A final benefit to including the basis reconciliation step is that it allows us to leverage existing results in QKD and apply them to quantum USS schemes. As we shall see in Chapter 6, the theoretical tools developed to analyse QKD protocols are powerful, and allow for significant improvements in both the security analysis and

experimental implementations of quantum USS schemes.