ebook img

Eavesdropping of two-way coherent-state quantum cryptography via Gaussian quantum cloning machines PDF

0.11 MB·English
Save to my drive
Quick download
Download
Most books are stored in the elastic cloud where traffic is expensive. For this reason, we have a limit on daily download.

Preview Eavesdropping of two-way coherent-state quantum cryptography via Gaussian quantum cloning machines

Eavesdropping of two-way coherent-state quantum cryptography via Gaussian quantum cloning machines Stefano Pirandola,1 Stefano Mancini,2 Seth Lloyd,1,3 and Samuel L. Braunstein4 1M.I.T. - Research Laboratory of Electronics, Cambridge MA 02139, USA 2Dipartimento di Fisica, Universit`a di Camerino, I-62032 Camerino, Italy 3M.I.T. - Department of Mechanical Engineering, Cambridge MA 02139, USA 4Computer Science, University of York, York YO10 5DD, United Kingdom (Dated: January 22, 2009) WeconsideroneofthequantumkeydistributionprotocolsrecentlyintroducedinRef.[Pirandola et al., Nature Physics 4, 726 (2008)]. This protocol consists in a two-way quantum communication betweenAliceandBob,whereAliceencodessecret information viaarandomphase-spacedisplace- 9 ment of a coherent state. In particular, we study its security against a specific class of individual 0 attacks which are based on combinations of Gaussian quantumcloning machines. 0 2 n INTRODUCTION the output variable Y is a Gaussian variable with zero a mean and variance Σ2 + σ2. According to Shannon’s J 2 Recently [1, 2], we have shown how two-way quantum theory [8], the classical correlations between the input 2 communication can profitably be exploited to enhance and output variables lead to a mutual information the security of continuous variable quantum key distri- 1 ] bution[3,4,5,6]. Inparticular,wehaveinvestigatedthe I(X,Y)= log(1+γ) , (2) h 2 p securityoftwo-wayprotocolsinthepresenceofcollective - Gaussianattackswhicharemodelled bycombinationsof whereγ Σ2/σ2 is the signalto noiseratio(SNR). This t ≡ n entangling cloners [5]. Even though this situation is the formula gives the maximal number of bits per Gaussian a most important one from the point view of the practical value that can be sent through a Gaussian channel with u implementation, the effect of other kind of Gaussian at- a given SNR (on averageand asymptotically). q [ tacks (i.e., not referable to entangling cloners) must also In quantum information theory, an example of addi- be analyzed. In this paper, we study the security of the tiveGaussianchannelis providedbythe Gaussianquan- 1 two-way coherent-state protocol of Ref. [1] against in- tumcloningmachine(GQCM)[9]. Consideracontinuous v 8 dividual attacks where an eavesdropper (Eve) combines variable (CV) system, like a bosonic mode, which is de- 6 two different Gaussian quantum cloning machines (also scribedby a pair of conjugate quadraturesxˆ and pˆ, with 5 called Gaussian cloners). In particular, we are able to [xˆ,pˆ]=i, acting on a Hilbert space . Then, consider a 3 show the robustness of the two-way protocol when the coherent state ϕ with amplitude ϕH= (x+ip)/√2. A . | i 1 firstcloneris fixedtobe symmetric inthe outputclones. 1 2 GQCM is a completely-positive trace-preserving 0 This symmetryconditionenablesusto derivethe results lin→ear map 9 quite easily but clearly restricts our security analysis to :0 a preliminary stage. For this reason, the optimal per- M :|ϕihϕ|→ρ12 ∈D(H⊗2) , (3) v formance of Gaussian cloners against two-way quantum i such that the single clone states, ρ =tr (ρ ) and ρ = X cryptography is still unknown at the present stage. 1 2 12 2 tr (ρ ),aregivenbyaGaussianphase-spacemodulation 1 12 r a of the input state ϕ ϕ, i.e., | ih | ADDITIVE GAUSSIAN CHANNELS AND GAUSSIAN CLONERS ρk = dµΩσk2(µ)Dˆ(µ)|ϕihϕ|Dˆ†(µ), k=1,2, (4) Z Consider a stochastic variable X with values x R where ∈ distributed according to a Gaussian probability 2 1 µ GΣ2(x)= √21πΣ2 exp −2xΣ22 , (1) Ωσk2(µ)≡ πσk2 exp"−|σk2| # , (5) (cid:20) (cid:21) and with variance Σ2. This variable is taken as input of a classicalchannelthatoutputsanotherstochasticvariable Dˆ(µ)=exp(µaˆ† µ∗aˆ) . (6) Y with values y R. In particular, the classical channel − ∈ is called additive Gaussian channel if, for every input In Eq. (5), the quantities σ2 are the error variances in- k x, the conditional output y x is Gaussianly distributed ducedbythecloningprocessonboththexandpquadra- | around x with some variance σ2 [7]. As a consequence, tures of the k-th clone. Notice that here we consider a 2 GQCM which clones symmetrically in the quadratures encodesthe signalamplitude α, maskedby the ref- (in general, one can have a Gaussian cloner which is erence amplitude β chosen by Bob. asymmetricbothintheclonesandthequadratures,with four different noise variances σ2 , σ2 , σ2 and σ2 .) The state is finally sent back to Bob, who tries to guess 1,x 1,p 2,x 2,p the two Alice’s numbers x and p by a joint measure- The previousvariancesdo notdepend onthe input state A A (universal GQCM) and satisfy the relation mentofconjugateobservables[10]. This is accomplished by a heterodyne detection [11] of the state, which will σ2σ2 1/4 , (7) give an outcome ζ α+β. After the subtraction of the 1 2 ≥ known value β, Bo≈b achieves an estimate α′ of Alice’s imposed by the uncertainty principle. In particular, the complex amplitude α, i.e., x′ x and p′ p . previous GQCM is said to be optimal if σ2σ2 = 1/4. In In the case of a noiselessAch≈annAel betwAee≈n AAlice and 1 2 termsofShannon’stheory,eachofthetworealvariables, Bob,theonlynoiseinalltheprocessisintroducedbythe x and p, is subject to an additive Gaussianchannel with heterodyne detection. This measurement can be seen as noise equal to σ2 during the cloning process from the a further Gaussian additive channel at Bob’s site, which k input state to the output k-th clone. gives a Gaussian noise equal to 1 for each quadrature. Thus, according to Shannon’s formula, we have TWO-WAY COHERENT-STATE PROTOCOL I =I(x ,x′ )+I(p ,p′ )=log(1+γ ) , (9) AB A A A A AB with γ =Σ2/1. The protocol is sketched in Fig.1 and consists of two AB Let us now consider a noisy channel adding Gaussian configurations, ON and OFF, that can be selected by noisewithvariancesσ2 (intheforwardpath)andσ′2 (in Alice with probabilities 1 c and c respectively. − thebackwardpath)foreachquadrature. Then,thetotal noise ofthe channelis σ2 =σ2+σ′2 andthe totalnoise ch Bob Eve Alice whichBobtests,afterdetection,isequaltoσ2 =σ2 +1, B ch giving a SNR γ = Σ2/σ2. In the OFF configuration, b M 1 Alice and Bob eAsBtimate theBnoise in the channel by per- 1- c c forming two heterodyne detections. After receiving the 2 referencestate,Alicesimplyheterodynesitwithoutcome - b ' Dˆ(a) β′ and then reconstructs a coherentstate ϑ . This state J + | i is sent to Bob, who gets the outcome ζ ϑ after detec- 2’ ≈ tion. In this way,Alice and Bob collect the pairs β,β′ 1’ M’ and ϑ,ζ from which they can estimate the two{noise}s { } z σ2 and σ′2 of the channel via public communications. Notice that here we are using the ON configuration to encode the key and the OFF configuration to check the FIG.1: Two-waycoherent-stateprotocolinboththeONand noise of the channel. This means that we are implicitly OFF configurations. assuming that Eve’s attack is disjoint between the two paths of the quantum communication (i.e., Eve is using LetBobprepareareference coherentstate β β ,with | ih | two distinct one-mode GQCMs). More generally, in or- amplitudeβ randomlychoseninthecomplexplane(e.g., der to exclude joint attacks between the two paths, the according to a Gaussian distribution with a large vari- ONandOFFconfigurationsmustbeusedsymmetrically ance). Such a state is sent to Alice on the forward use for encoding and checking [1]. of the quantum channel. In the ON configuration, Alice encodesasignal onthisreferencestateviaaphase-space displacementDˆ(α) whose amplitude α (xA+ipA)/√2 EAVESDROPPING VIA GAUSSIAN CLONERS ischosenintheC-planeaccordingtoar≡andomGaussian distribution ΩΣ2(α) with large variance Σ2. Notice that In the previoustwo-wayquantumcommunication, the choices of the reference β and the signal α are two inde- (i) The signal amplitude α symmetrically encodes two pendentprocesses. As aconsequence,Evehasto extract signal quadratures, x and p , i.e., two indepen- A A information on both the reference β and the total dis- dent and real random variables distributed ac- placement α+β in order to access Alice’s encoding α cording to Gaussian distributions GΣ2(xA) and (this is true until the attack is disjoint). Let us consider GΣ2(pA). twodifferentattacks,oneontheforwarduseofthechan- (ii) The output state nel and the other one in the backwarduse, by using two optimal GQCMs which we call M and M′, respectively Dˆ(α)β β Dˆ†(α)= α+β α+β , (8) (see Fig. 1). | ih | | ih | 3 Since the reference β and the signalα are chosenwith longercontainthereferenceβ. Here,theactionoftheBS large variances, such machines must be universal, and isverysimilartothesum(mod2)performedoverabinary sincetheinformationissymmetricallyencodedinthetwo key(k)andthecorrespondingencryptedmessage(k m), ⊕ quadratures,weconsiderequalcloningnoisesinxandp. operation that reveals the message in the classical case For these reasons,Eve’s GQCMs are exactly of the kind (k m k = m). On the other hand, the other port + ⊕ ⊕ specified by Eq. (4) with σ2σ2 =1/4. After cloning,Eve still contains a mixing between α and β and, therefore, 1 2 must extract the information about α from her clones. does not provide further information about the signal. Shecandirectlyheterodynetheclones. Alernatively,she Tracing out this port, we have cansendtheclonestoabeam-splitter(BS),withsuitable reflectionand transmissioncoefficients r and t, and then ρ− = d2λ Ω1/4ω2(λ) (α+λ)/√2 − (α+λ)/√2 . | i h | heterodynes the output ports. Z (15) InordertostudytheeavesdroppingdepictedinFig.1, Heterodyningsuchastate,Evecanestimatethevalueof it is not sufficient to consider the reduced states ρ of k α up to a Gaussian noise with variance the two single clonesat the output ofM, but we have to computeexplicitlythewholebipartitestateρ12 ofmodes σE2 =2+(4ω2)−1 , (16) 1 and 2. In fact, mode 1 is sent to Alice (who displaces for each quadrature. For Bob, instead, we have a total it) and then cloned by M′ into the output modes 1′ and noise 2′. The secondmode 2′ then interfereswiththe previous mode2onthebeam-splitter. Forthis reason,wehaveto σB2 =1+σc2h , (17) keep all the correlations between the various modes till equaltothesumoftheheterodynenoise(1)andthetotal theinterferenceprocess. Onecanprovethatthebipartite channel noise state ρ at the output of the optimal GQCM M is a 12 Gaussian state with correlation matrix (CM) equal to σc2h =1/2+ω2 . (18) 1 (1+2σ2)I I According to Shannon, Bob (B) and Eve (E) will share V = 2 I (1+1/2σ2)I , (10) with Alice (A) a mutual information equal to IAX = (cid:18) (cid:19) log(1+γ ) with γ Σ2/σ2 for X = B,E. Since AX AX ≡ X whereI isthe 2 2identity matrix. The CMofEq.(10) [13] × has positive partial transpose for every σ2 0, and, therefore,ρ12isalwaysaseparablestate[12]. T≥hismeans IAB ≥IAE ⇐⇒γAB ≥γAE ⇐⇒σB2 ≤σE2 , (19) thatEvecannotexploitstrategiesbasedontheentangle- we can easily compute a security threshold for this kind ment between her clones and the ones of Alice and Bob. of attack, which is equal to In the particular case of symmetric cloning (σ2 = 1/2), σ˜2 =(3+√5)/4 1.3 . (20) we can write the useful decomposition ch ≃ Such a threshold must be compared with the security ρ = d2µ Ω (µ) threshold (0.5) which characterizes one-way coherent- 12 1/2 × Z state protocols [5, 6] against individual GQCM attacks. β+µ β+µ β+µ β+µ . (11) 1 2 | i h |⊗| i h | Then, let us consider the case where the first cloner M CONCLUSION is optimal and symmetric (σ2 = σ2 = 1/2), while the 1 2 second cloner M′ is optimal but asymmetric, with σ2 1′ ≡ In this paper we have considered one of the two-way ω2 and σ2 = 1/4ω2. In this case, at the output modes 2′ protocols introduced in [1]. Then, we have explicitly + and of the BS, we have the bipartite state − studied its security in the presence of particular kind of individual attacks which are based on combinations ρ = d2µ Ω (µ) χ(µ) (12) +− 1/2 of one-mode Gaussian cloners. Our analysis indicates Z thatthe superadditivebehaviorofthe securitythreshold where should also hold against this kind of Gaussian attacks. χ(µ) d2λ Ω1/4ω2(λ) However, our analysis is far to be complete since we ≡ × have considered only particular combinations of cloners Z θ +λr θ +λr θ +λt θ +λt , (13) and we have also excluded the possibility of a two-mode + + + − − − | i h |⊗| i h | cloner (acting coherently on both the paths of the quan- and tum communication). Furthermore, the analysis covers the case of direct reconciliation only. Despite these re- θ (µ+β)(t+r)+αr, θ (µ+β)(t r)+αt . (14) + − ≡ ≡ − strictions, the present work represents the first step in IfwenowtakeabalancedBS(i.e.,t=r =1/√2)wehave the security analysis of two-way protocols against more θ α/√2 and, therefore, the output port does no exotic kind of Gaussian interactions. − ≡ − 4 ACKNOWLEDGEMENTS Cerf, and P. Grangier, “Quantum key distribution using Gaussian-modulated coherent states,” Nature 421, 238 (2003); F. Grosshans, and Ph. Grangier, “Continuous TheresearchofS.PirandolawassupportedbyaMarie variable quantum cryptography using coherent states,” Curie Fellowship of the European Community. S. Lloyd Phys. Rev.Lett. 88, 057902 (2002). was supported by the W.M. Keck center for extreme [6] C. Weedbrook et al., “Quantum cryptography without quantum information theory (xQIT). switching,” Phys. Rev. Lett. 93, 170504 (2004); A. M. Lance et al., “No-switching quantum key distribution using broadband modulated coherent light,” Phys. Rev. Lett. 95, 180503 (2005). [7] More properly, this channel is called additive Gaussian [1] S.Pirandola,S.Mancini,S.Lloyd,andS.L.Braunstein, noise channel. For the general theory of these channels “Continuous variable quantum cryptography using two- see, e.g., T. M. Cover and J. A. Thomas, “Elements of way quantum communication,” Nature Physics 4, 726 Information Theory” (Wiley, 2006). (2008). [8] C. E. Shannon, “A Mathematical Theory of Communi- [2] S.Pirandola,S.Mancini,S.Lloyd,andS.L.Braunstein, cation,” Bell Syst. Tech.J. 27, 623 (1948). “Security of two-way quantum cryptography against [9] N. J. Cerf, A. Ipe, and X. Rottenberg, “Cloning of con- asymmetric attacks,” Proc. SPIE, Vol. 7092, 709215 tinuous quantum variables,” Phys. Rev. Lett. 85, 1754 (2008). Seealso arXiv:0807.1937. (2000). [3] T. C. Ralph, “Continuous variable quantum cryptog- [10] E. Arthurs and J. L. Kelly, “On the simultaneous mea- raphy,” Phys. Rev. A 61, 010303(R) (2000); T. C. surement of a pair of conjugate observables,” Bell Syst. Ralph, “Security of continuous-variable quantum cryp- Tech. J. 44, 725 (1965). tography,”Phys.Rev.A62,062306 (2000); M.D.Reid, [11] H.P. Yuen and J.H. Shapiro, “Optical communication “Quantum cryptography with a predetermined key us- with two-photon coherent states - part III: Quantum ingcontinuous-variableEinstein-Podolsky-Rosencorrela- measurements realizable with photoemessive detectors,” tions,” Phys.Rev.A 62, 062308 (2000). IEEE Trans. Inf. Theory IT-26, 78-92 (1980). [4] D. Gottesman, and J. Preskill, “Secure quantum key [12] R. Simon, “Peres–Horodecki separability criterion for distribution using squeezed states,” Phys. Rev. A 63, continuous variable systems,” Phys. Rev. Lett. 84, 2726 022309 (2001); S. Iblisdir, G. Van Assche, and N. J. (2000). Cerf, “Security of quantum key distribution with coher- [13] I. Csisz´ar and J. K¨orner, “Broadcast channels with con- ent states and homodyne detection,” Phys. Rev. Lett. fidentialmessages,”IEEETrans.Inf.TheoryIT-24,339 93, 170502 (2004). (1978). [5] F.Grosshans,G.VanAssche,J.Wenger,R.Brouri,N.J.

See more

The list of books you might like

Most books are stored in the elastic cloud where traffic is expensive. For this reason, we have a limit on daily download.