Pith. sign in

REVIEW 2 cited by

The Universal Composable Security of Quantum Message Authentication with Key Recyling

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1610.09434 v1 pith:5AKWGYRI submitted 2016-10-29 quant-ph

classification quant-ph
keywords protocolencryptionquant-phauthenticationmessagequantumsecurityqenc
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Barnum, Crepeau, Gottesman, Tapp, and Smith (quant-ph/0205128) proposed methods for authentication of quantum messages. The first method is an interactive protocol (TQA') based on teleportation. The second method is a noninteractive protocol (QA) in which the sender first encrypts the message using a protocol QEnc and then encodes the quantum ciphertext with an error correcting code chosen secretly from a set (a purity test code (PTC)). Encryption was shown to be necessary for authentication. We augment the protocol QA with an extra step which recycles the entire encryption key provided QA accepts the message. We analyze the resulting integrated protocol for quantum authentication and key generation, which we call QA+KG. Our main result is a proof that QA+KG is universal composably (UC) secure in the Ben-Or-Mayers model (quant-ph/0409062). More specifically, this implies the UC-security of (a) QA, (b) recycling of the encryption key in QA, and (c) key-recycling of the encryption scheme QEnc by appending PTC. For an m-qubit message, encryption requires 2m bits of key; but PTC can be performed using only O(log m) + O(log e) bits of key for probability of failure e. Thus, we reduce the key required for both QA and QEnc, from linear to logarithmic net consumption, at the expense of one bit of back communication which can happen any time after the conclusion of QA and before reusing the key. UC-security of QA also extends security to settings not obvious from quant-ph/0205128. Our security proof structure is inspired by and similar to that of quant-ph/0205128, reducing the security of QA to that of TQA'. In the process, we define UC-secure entanglement, and prove the UC-security of the entanglement generating protocol given in quant-ph/0205128, which could be of independent interest.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Authentication of Continuous-Variable Quantum Messages

    quant-ph 2025-06 conditional novelty 6.0 of 10

    A trap-based quantum message authentication protocol for continuous-variable states is shown to be eta-secure with eta=(n/(n+2z))^(t+1).

  2. Design and analysis of a set of discrete variable protocols for secure quantum communication

    quant-ph 2025-08 conditional novelty 5.0 of 10

    A doctoral thesis presenting QIA protocols from QSDC structures, two weak-coherent-pulse QKD protocols, a controller-assisted QKA protocol, and a game-theoretic QBER bound for DL04 QSDC.

Pith tools