发表机构
University of Toronto; The University of Hong Kong(多伦多大学; 香港大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出一种基于NISQ设备的单服务器SPIR协议,利用BB84态单向传输和分块排列实现信息论安全,在容忍噪声信道下以约千比特分块达到数据库隐私$10^{-6}$,并扩展到诱骗态。
AI 中文摘要
对称私密信息检索(SPIR)允许查询者仅获取一个特定的比特,同时不向数据库所有者泄露关于该比特索引的任何信息。对于拥有不受限制量子能力的双方而言,在单服务器情况下这是不可能的。我们证明,当服务器和用户仅持有没有长期量子存储的含噪声中等规模量子(NISQ)设备,并在每个量子比特到达时进行测量,而窃听者仍然拥有全能力时,该问题在信息论安全意义下变得可行;这是有界量子存储模型和噪声量子存储模型中存储限制的一种更严格形式。服务器单向发送BB84态;用户对其进行无歧义区分,从而知道比特的一个随机子集。在联合随机排列成分块后,用户宣布一个私下选择的块中的确定位置,服务器对每个块中的这些位置进行哈希并取随机奇偶校验;排列使得一组位置适配两个块的概率呈指数级降低。我们证明了针对窃听者的保密性、通过宣布集合的显式大小规则实现的数据库隐私性,以及针对准备规定BB84态并如实宣布的服务器(在单光子情形下精确成立,并在容忍噪声信道上存在小的多光子项)的用户隐私性。对BB84设备的唯一增加是一个带有一个辅助模式的无源线性光学测量。对于一个$10^{4}$比特的数据库和$10^{-6}$的数据库隐私性,在容忍噪声信道上,对于应用规定测量的用户,约一千个量子比特的分块就足够了;认证任意无记忆用户并承诺排列需要更大的辅助传输,我们用量子有限密钥对其进行了量化。数据库隐私性可扩展到诱骗态弱相干脉冲,模拟表明该界限几乎是紧的。
英文摘要
Symmetric private information retrieval (SPIR) lets an inquirer obtain one specific bit only, without leaking any information about its index to the database owner. With a single server, this is impossible for parties with unrestricted quantum power. We show that it becomes possible, with information-theoretic security, when the server and the user hold only noisy intermediate-scale quantum (NISQ) devices without long-term quantum memory and measure each qubit on arrival, while the eavesdropper remains all-powerful; this is a stricter form of the memory restriction of the bounded- and noisy-quantum-storage models. The server sends BB84 states one way; the user discriminates them unambiguously and so knows a random subset of the bits. After a joint random permutation into blocks, the user announces the conclusive locations of one privately chosen block, and the server hashes and takes a random parity of these locations in every block; the permutation makes it exponentially unlikely that one set of locations fits two blocks. We prove secrecy against the eavesdropper, database privacy through an explicit size rule for the announced set, and user privacy against a server who prepares the prescribed BB84 states and announces truthfully, exactly for single photons and up to a small multi-photon term over a tolerated noise channel. The only addition to BB84 equipment is a passive linear-optical measurement with one ancillary mode. For a $10^{4}$-bit database and database privacy $10^{-6}$, blocks of about a thousand qubits suffice over a tolerated noise channel for a user who applies the prescribed measurement; certifying an arbitrary memoryless user and committing to the permutation need larger auxiliary transmissions, which we quantify with finite keys. Database privacy extends to decoy-state weak coherent pulses, and simulations show that the bound is nearly tight.
Comments40 pages, 7 figures