• Aucun résultat trouvé

Weak approximate unitary designs and applications to quantum encryption

N/A
N/A
Protected

Academic year: 2022

Partager "Weak approximate unitary designs and applications to quantum encryption"

Copied!
36
0
0

Texte intégral

(1)

Weak approximate unitary designs and applications to quantum encryption

Joint work with Christian Majenz (QuSoft & CWI) arXiv:1911.06742

Cécilia Lancien

Institut de Mathématiques de Toulouse & CNRS

QUASAR group meeting – November 12 2020

(2)

Outline

1 Background and motivations

2 Main technical results

3 Application to quantum cryptography

(3)

Haar and

t

-design unitaries

RandomHaar unitariesplay an important role in many aspects of theoretical quantum information (e.g. quantum source and channel coding, quantum encryption, typical properties of quantum states and channels etc.)

Problem:Implementing Haar unitaries, even approximately, is infeasible (requires an amount of randomness and a number of gates which is exponential in the number of qubits they act on).

Unitary t-design: measure on the unitary group that reproduces the Haar measure up to thet-th moment.

−→At-design unitary can replace a Haar unitary in situations where it is applied at mostttimes. Goal:Find “economical” such measures (e.g. with finite, as small as possible, support).

Often even just approximate versions of unitaryt-designs are sufficient. Question:What is the “right” metrics to quantify approximation?

−→The answer depends on the application... Notation

L(d)set of linear operators onCd,U(d)subset of unitary ones,D(d)subset of quantum states.

L

(d)set of linear maps onL(d),

C

(d)subset of quantum channels.

(4)

Haar and

t

-design unitaries

RandomHaar unitariesplay an important role in many aspects of theoretical quantum information (e.g. quantum source and channel coding, quantum encryption, typical properties of quantum states and channels etc.)

Problem:Implementing Haar unitaries, even approximately, is infeasible (requires an amount of randomness and a number of gates which is exponential in the number of qubits they act on).

Unitary t-design: measure on the unitary group that reproduces the Haar measure up to thet-th moment.

−→At-design unitary can replace a Haar unitary in situations where it is applied at mostttimes.

Goal:Find “economical” such measures (e.g. with finite, as small as possible, support).

Often even just approximate versions of unitaryt-designs are sufficient. Question:What is the “right” metrics to quantify approximation?

−→The answer depends on the application... Notation

L(d)set of linear operators onCd,U(d)subset of unitary ones,D(d)subset of quantum states.

L

(d)set of linear maps onL(d),

C

(d)subset of quantum channels.

(5)

Haar and

t

-design unitaries

RandomHaar unitariesplay an important role in many aspects of theoretical quantum information (e.g. quantum source and channel coding, quantum encryption, typical properties of quantum states and channels etc.)

Problem:Implementing Haar unitaries, even approximately, is infeasible (requires an amount of randomness and a number of gates which is exponential in the number of qubits they act on).

Unitary t-design: measure on the unitary group that reproduces the Haar measure up to thet-th moment.

−→At-design unitary can replace a Haar unitary in situations where it is applied at mostttimes.

Goal:Find “economical” such measures (e.g. with finite, as small as possible, support).

Often even just approximate versions of unitaryt-designs are sufficient.

Question:What is the “right” metrics to quantify approximation?

−→The answer depends on the application...

Notation

L(d)set of linear operators onCd,U(d)subset of unitary ones,D(d)subset of quantum states.

L

(d)set of linear maps onL(d),

C

(d)subset of quantum channels.

(6)

Haar and

t

-design unitaries

RandomHaar unitariesplay an important role in many aspects of theoretical quantum information (e.g. quantum source and channel coding, quantum encryption, typical properties of quantum states and channels etc.)

Problem:Implementing Haar unitaries, even approximately, is infeasible (requires an amount of randomness and a number of gates which is exponential in the number of qubits they act on).

Unitary t-design: measure on the unitary group that reproduces the Haar measure up to thet-th moment.

−→At-design unitary can replace a Haar unitary in situations where it is applied at mostttimes.

Goal:Find “economical” such measures (e.g. with finite, as small as possible, support).

Often even just approximate versions of unitaryt-designs are sufficient.

Question:What is the “right” metrics to quantify approximation?

−→The answer depends on the application...

Notation

L(d)set of linear operators onCd,U(d)subset of unitary ones,D(d)subset of quantum states.

L

(d)set of linear maps onL(d),

C

(d)subset of quantum channels.

(7)

Exact and approximate unitary designs

Definition (Unitaryt-design)

Given a measureµonU(d), define its associatedUt-twirl channel Tµ(t)as Tµ(t):X∈L(dt)7→

Z

UU(d)

UtXU∗⊗tdµ(U)∈L(dt).

SettingT(t):=THaar(t) ,µis called at-designifTµ(t)=T(t).

µis an approximatet-design ifTµ(t)≈T(t).

Natural measure of approximation: in 1→1 norm, i.e. sup

kXk161

T

(t)

µ (X)−T(t)(X) 16ε. Note:It is a quite weak notion of approximation. Sometimes, stronger results are needed (e.g. approximation ofT(t)innorm, i.e. ofidd⊗T(t)in 1→1 norm).

Goal:Find an “economical” measureµonU(d)which is an approximatet-design, in this sense (e.g. a discrete measureµ={(pi,Ui)}ni=1withn“small” and theUi’s “easy” to construct).

(8)

Exact and approximate unitary designs

Definition (Unitaryt-design)

Given a measureµonU(d), define its associatedUt-twirl channel Tµ(t)as Tµ(t):X∈L(dt)7→

Z

UU(d)

UtXU∗⊗tdµ(U)∈L(dt).

SettingT(t):=THaar(t) ,µis called at-designifTµ(t)=T(t). µis an approximatet-design ifTµ(t)≈T(t).

Natural measure of approximation: in 1→1 norm, i.e. sup

kXk161

T

(t)

µ (X)−T(t)(X) 16ε. Note:It is a quite weak notion of approximation. Sometimes, stronger results are needed (e.g. approximation ofT(t)innorm, i.e. ofidd⊗T(t)in 1→1 norm).

Goal:Find an “economical” measureµonU(d)which is an approximatet-design, in this sense (e.g. a discrete measureµ={(pi,Ui)}ni=1withn“small” and theUi’s “easy” to construct).

(9)

Exact and approximate unitary designs

Definition (Unitaryt-design)

Given a measureµonU(d), define its associatedUt-twirl channel Tµ(t)as Tµ(t):X∈L(dt)7→

Z

UU(d)

UtXU∗⊗tdµ(U)∈L(dt).

SettingT(t):=THaar(t) ,µis called at-designifTµ(t)=T(t). µis an approximatet-design ifTµ(t)≈T(t).

Natural measure of approximation: in 1→1 norm, i.e. sup

kXk161

T

(t)

µ (X)−T(t)(X) 16ε. Note:It is a quite weak notion of approximation. Sometimes, stronger results are needed (e.g. approximation ofT(t)innorm, i.e. ofidd⊗T(t)in 1→1 norm).

Goal:Find an “economical” measureµonU(d)which is an approximatet-design, in this sense (e.g. a discrete measureµ={(pi,Ui)}ni=1withn“small” and theUi’s “easy” to construct).

(10)

Ut

-twirl channel and representation theory

(Cd)tcarries representations of the groupsStandU(d), whose actions are given by:

∀σ∈St,σ.|φ1i ⊗ · · · ⊗ |φti=|φσ1(1)i ⊗ · · · ⊗ |φσ1(t)iand∀U∈U(d),U.|φi=Ut|φi. Lemma (Schur-Weyl duality)

The actions ofStandU(d)on(Cd)tcommute:(Cd)tdecomposes into a direct sum of irreducible representations (irreps) of the product groupSt×U(d), which are tensor products of irreps ofStandU(d). What is more, this decomposition is multiplicity free, and is given by

(Cd)t∼= M

λ`(t,d)

Vλ⊗[λ],withVλirrep ofU(d)and[λ]irrep ofSt.

Consequence:SinceT(t)is covariant with respect to the action ofU(d), T(t)(X)=∼

λ`(t,d) 1Vλ

dim(Vλ)⊗TrVλ(PλX), withPλprojector ontoVλ⊗[λ]. Examples:

T(1)(X) = Z

UU(d)

UXUdU=Tr(1X)1 d. T(2)(X) =

Z

UU(d)

U2XU∗⊗2dU=Tr 1+F

2 X

1+F d(d+1)+Tr

1−F

2 X

1−F d(d−1).

(11)

Ut

-twirl channel and representation theory

(Cd)tcarries representations of the groupsStandU(d), whose actions are given by:

∀σ∈St,σ.|φ1i ⊗ · · · ⊗ |φti=|φσ1(1)i ⊗ · · · ⊗ |φσ1(t)iand∀U∈U(d),U.|φi=Ut|φi. Lemma (Schur-Weyl duality)

The actions ofStandU(d)on(Cd)tcommute:(Cd)tdecomposes into a direct sum of irreducible representations (irreps) of the product groupSt×U(d), which are tensor products of irreps ofStandU(d). What is more, this decomposition is multiplicity free, and is given by

(Cd)t∼= M

λ`(t,d)

Vλ⊗[λ],withVλirrep ofU(d)and[λ]irrep ofSt.

Consequence:SinceT(t)is covariant with respect to the action ofU(d), T(t)(X)∼=

λ`(t,d) 1Vλ

dim(Vλ)⊗TrVλ(PλX), withPλprojector ontoVλ⊗[λ]. Examples:

T(1)(X) = Z

UU(d)

UXUdU=Tr(1X)1 d. T(2)(X) =

Z

UU(d)

U2XU∗⊗2dU=Tr 1+F

2 X

1+F d(d+1)+Tr

1−F

2 X

1−F d(d−1).

(12)

Outline

1 Background and motivations

2 Main technical results

3 Application to quantum cryptography

(13)

Previously known result: Approximating

T(1)

with few Kraus operators

Theorem(Hayden/Leung/Shor/Winter, Aubrun)

LetU1, . . . ,Unbe sampled independently from the Haar measure onU(d). Define the random channelTn(1):X∈L(d)7→1

n

n

i=1

UiXUi.

For any fixed 0<ε<1, ifn>Cd2, then with probability at least 1−ecd

∀ρ∈D(d), T

(1)

n (ρ)−T(1)(ρ) 16ε.

Pros/Cons:Optimal result theoretically, but sampling from the Haar measure is hard in practice.

Theorem(Aubrun)

Letµbe a 1-design onU(d)andU1, . . . ,Unbe sampled independently fromµ. Define the random channelTµ,(1n):X∈L(d)7→1

n

n

i=1

UiXUi.

For any fixed 0<ε<1, ifn>Cd(logd)62, then with probability at least (say) 1/2

∀ρ∈D(d), T

(1)

µ,n(ρ)−T(1)(ρ) 16ε.

Pros/Cons:Extra(logd)6factor and only (arbitrary) constant probability, but there are explicit 1-designs from which it is easy to sub-sample (→partial derandomization).

(14)

Previously known result: Approximating

T(1)

with few Kraus operators

Theorem(Hayden/Leung/Shor/Winter, Aubrun)

LetU1, . . . ,Unbe sampled independently from the Haar measure onU(d). Define the random channelTn(1):X∈L(d)7→1

n

n

i=1

UiXUi.

For any fixed 0<ε<1, ifn>Cd2, then with probability at least 1−ecd

∀ρ∈D(d), T

(1)

n (ρ)−T(1)(ρ) 16ε.

Pros/Cons:Optimal result theoretically, but sampling from the Haar measure is hard in practice.

Theorem(Aubrun)

Letµbe a 1-design onU(d)andU1, . . . ,Unbe sampled independently fromµ. Define the random channelTµ,(1n):X∈L(d)7→1

n

n

i=1

UiXUi.

For any fixed 0<ε<1, ifn>Cd(logd)62, then with probability at least (say) 1/2

∀ρ∈D(d), T

(1)

µ,n(ρ)−T(1)(ρ) 16ε.

Pros/Cons:Extra(logd)6factor and only (arbitrary) constant probability, but there are explicit 1-designs from which it is easy to sub-sample (→partial derandomization).

(15)

Main result: Approximating

T(t)

with few Kraus operators

Theorem (ApproximatingT(t))

Letµbe at-design onU(d)andU1, . . . ,Unbe sampled independently fromµ. Define the random channelTµ,(tn):X∈L(dt)7→1

n

n

i=1

UitXUi∗⊗t.

For any fixed 0<ε<1, ifn>C(td)t(tlogd)62, then with probability at least 1/2

∀ρ∈D(dt), T

(t)

µ,n(ρ)−T(t)(ρ) 16ε.

Remarks:

The result is optimal (up to apoly(t,logd)factor): it is impossible to approximateT(t)in 1→1 norm with less than orderdtKraus operators(Lancien/Winter).

In fact, stronger result:Tµ,(tn)approximatesT(t)in 1→∞norm up to errorε/dt.

The result still holds if unitaries are sampled from an approximatet-design (errors add up). Interest: There are quite efficient constructions of approximatet-designs (in a strong sense). For instance: a random circuit onnqubits withpoly(t,n)independent 2-qubit Haar gates (Brandão/Harrow/Horodecki, Harrow/Mehraban, etc).

(16)

Main result: Approximating

T(t)

with few Kraus operators

Theorem (ApproximatingT(t))

Letµbe at-design onU(d)andU1, . . . ,Unbe sampled independently fromµ. Define the random channelTµ,(tn):X∈L(dt)7→1

n

n

i=1

UitXUi∗⊗t.

For any fixed 0<ε<1, ifn>C(td)t(tlogd)62, then with probability at least 1/2

∀ρ∈D(dt), T

(t)

µ,n(ρ)−T(t)(ρ) 16ε.

Remarks:

The result is optimal (up to apoly(t,logd)factor): it is impossible to approximateT(t)in 1→1 norm with less than orderdtKraus operators(Lancien/Winter).

In fact, stronger result:Tµ,(tn)approximatesT(t)in 1→∞norm up to errorε/dt.

The result still holds if unitaries are sampled from an approximatet-design (errors add up).

Interest: There are quite efficient constructions of approximatet-designs (in a strong sense).

For instance: a random circuit onnqubits withpoly(t,n)independent 2-qubit Haar gates (Brandão/Harrow/Horodecki, Harrow/Mehraban, etc).

(17)

Technical tools in the proof

Fact:All outputs of the channelT(t)are very mixed. Concretely: sup

ρ∈D(dt)

T

(t)(ρ) 6

2t d

t

.

Proof:By Schur-Weyl duality, sup

ρ∈D(dt)

T

(t)(ρ)

= min 1

λ`(t,d)dim(Vλ). The result then follows from Weyl’s dimension formula:dim(Vλ) =

16i<j6d

λi−λj+j−i j−i .

Lemma(Aubrun)

LetUˆ1, . . . ,Uˆn∈U(d)and letε1, . . . ,εnbe independent Bernoulli random variables. Then,

Eε sup

ρ∈D(dt)

n

i=1

εiUˆt

i ρUˆ∗⊗t

i

!

6C(tlogd)5/2(logn)1/2 sup

ρ∈D(dt)

n

i=1

i tρUˆ∗⊗t

i

1/2

.

Proof:Consists in estimating the average of the supremum of an empirical process through covering numbers (thanks to Dudley’s inequality and a duality argument for entropy numbers).

(18)

Technical tools in the proof

Fact:All outputs of the channelT(t)are very mixed. Concretely: sup

ρ∈D(dt)

T

(t)(ρ) 6

2t d

t

.

Proof:By Schur-Weyl duality, sup

ρ∈D(dt)

T

(t)(ρ)

= min 1

λ`(t,d)dim(Vλ). The result then follows from Weyl’s dimension formula:dim(Vλ) =

16i<j6d

λi−λj+j−i j−i . Lemma(Aubrun)

LetUˆ1, . . . ,Uˆn∈U(d)and letε1, . . . ,εnbe independent Bernoulli random variables. Then,

Eε sup

ρ∈D(dt)

n

i=1

εiUˆt

i ρUˆ∗⊗t

i

!

6C(tlogd)5/2(logn)1/2 sup

ρ∈D(dt)

n

i=1

itρUˆ∗⊗t

i

1/2

.

Proof:Consists in estimating the average of the supremum of an empirical process through covering numbers (thanks to Dudley’s inequality and a duality argument for entropy numbers).

(19)

Outline of the proof

SetM:= sup

ρ∈D(dt)

1 n

n

i=1

UitρU∗⊗i t−T(t)(ρ)

.

We want to show that, forn>C(td)t(tlogd)62,M6ε/dtwith probability at least 1/2.

Note thatT(t)(ρ) =EV 1 n

n

i=1

VitρVi∗⊗t

!

, for theVi’s independent copies of theUi’s.

So by a symmetrization trick,EUM62EU sup

ρ∈D(dt)

1 n

n

i=1

εiUitρUi∗⊗t

! .

Hence by Aubrun’s lemma,EM6√2C

n(tlogd)5/2(logn)1/2E

 sup

ρ∈D(dt)

1 n

n

i=1

UitρUi∗⊗t

1/2

.

Now by the fact about the 1→∞norm ofT(t), sup

ρ∈D(dt)

1 n

n

i=1

UitρUi∗⊗t

6M+ 2t

d t

.

Putting everything together,EM64C

2

n (tlogd)5logn+√2C

n(tlogd)5/2(logn)1/2 2t

d t/2

. And the latter quantity is smaller thanε/dtas soon asnis larger thanC0(td)t(tlogd)62. If this is so, then by Markov’s inequalityP

M6 2ε

dt

>1EM 2ε/dt > 1

2.

(20)

Other result: Approximating the Haar

U

U-twirl channel

¯

Given a measureµonU(d), define theU⊗U-twirl channel T¯ µ(1,1)as Tµ(1,1):X∈L(d2)7→

Z

UU(d)

U⊗UXU¯ U¯dµ(U)∈L(d2).

SetT(1,1):=THaar(1,1). Note that, ifµis a 2-design onU(d), thenTµ(1,1)=T(1,1). Indeed:Tµ(1,1)(X) =Tµ(2)(XΓ)Γ, whereYΓis the partial transposition ofY.

Theorem (ApproximatingT(1,1))

Letµbe a 2-design onU(d)andU1, . . . ,Unbe sampled independently fromµ. Define the random channelTµ,(1n,1):X∈L(d2)7→ 1

n

n

i=1

UiU¯iXU

iU¯

i. For any 0<ε<1, ifn>Cd2(logd)62, then with probability at least 1/2

∀ρ∈D(d2), T

(1,1)

µ,n −T(1,1)(ρ) 16ε. Proof idea:Distinguish between:

The maximally entangled state, whereT(1,1)andTµ,(1n,1)both act as the identity.

Its orthogonal complement, where the 1→∞norm ofT(1,1)is small (equal to 1/(d2−1)), so that the same argument as forT(t)can be applied.

(21)

Other result: Approximating the Haar

U

U-twirl channel

¯

Given a measureµonU(d), define theU⊗U-twirl channel T¯ µ(1,1)as Tµ(1,1):X∈L(d2)7→

Z

UU(d)

U⊗UXU¯ U¯dµ(U)∈L(d2).

SetT(1,1):=THaar(1,1). Note that, ifµis a 2-design onU(d), thenTµ(1,1)=T(1,1). Indeed:Tµ(1,1)(X) =Tµ(2)(XΓ)Γ, whereYΓis the partial transposition ofY.

Theorem (ApproximatingT(1,1))

Letµbe a 2-design onU(d)andU1, . . . ,Unbe sampled independently fromµ. Define the random channelTµ,(1n,1):X∈L(d2)7→ 1

n

n

i=1

UiU¯iXU

iU¯

i. For any 0<ε<1, ifn>Cd2(logd)62, then with probability at least 1/2

∀ρ∈D(d2), T

(1,1)

µ,n −T(1,1)(ρ) 16ε.

Proof idea:Distinguish between:

The maximally entangled state, whereT(1,1)andTµ,(1n,1)both act as the identity.

Its orthogonal complement, where the 1→∞norm ofT(1,1)is small (equal to 1/(d2−1)), so that the same argument as forT(t)can be applied.

(22)

Other result: Approximating the Haar twirl super-channel

Given a measureµonU(d), define thetwirl super-channelΘµas Θµ:

M

L

(d)7→

X∈L(d)7→

Z

UU(d)

U

M

(UXU)Udµ(U)L(d)

L

(d).

SetΘ := ΘHaar. Note that, ifµis a 2-design onU(d), thenΘµ= Θ.

Indeed:id⊗Θµ(

M

)(|ψihψ|) =Tµ(1,1)(id⊗

M

(|ψihψ|)), with|ψithe maximally entangled state.

Theorem (ApproximatingΘ)

Letµbe a 2-design onU(d)andU1, . . . ,Unbe sampled independently fromµ. Define the random super-channelΘµ,n:

M

L

(d)7→ XL(d)7→1

n

n

i=1

Ui

M

(UiXUi)Ui

! . For any fixed 0<ε<1, ifn>Cd2(logd)62, then with probability at least 1/2

N

C

(d),ρ∈D(d2),

id⊗Θµ,n(

N

)(ρ)idΘ(

N

)(ρ)16ε. Proof idea:Derived from approximation results forT(1)andT(1,1).

(23)

Other result: Approximating the Haar twirl super-channel

Given a measureµonU(d), define thetwirl super-channelΘµas Θµ:

M

L

(d)7→

X∈L(d)7→

Z

UU(d)

U

M

(UXU)Udµ(U)L(d)

L

(d).

SetΘ := ΘHaar. Note that, ifµis a 2-design onU(d), thenΘµ= Θ.

Indeed:id⊗Θµ(

M

)(|ψihψ|) =Tµ(1,1)(id⊗

M

(|ψihψ|)), with|ψithe maximally entangled state.

Theorem (ApproximatingΘ)

Letµbe a 2-design onU(d)andU1, . . . ,Unbe sampled independently fromµ. Define the random super-channelΘµ,n:

M

L

(d)7→ XL(d)7→1

n

n

i=1

Ui

M

(UiXUi)Ui

! . For any fixed 0<ε<1, ifn>Cd2(logd)62, then with probability at least 1/2

N

C

(d),∀ρ∈D(d2),

id⊗Θµ,n(

N

)(ρ)−id⊗Θ(

N

)(ρ)16ε.

Proof idea:Derived from approximation results forT(1)andT(1,1).

(24)

Outline

1 Background and motivations

2 Main technical results

3 Application to quantum cryptography

(25)

One-time-secure quantum encryption

A quantum encryption scheme is given by families of channels{

E

i:L(d)→L(d0)}ni=1 (encoders) and{

D

i:L(d0)→L(d)}ni=1(decoders) satisfying

D

i

E

i=idfor all 16i6n.

The parameterslogn,logdandlogd0are thekey,messageandciphertextlength, respectively.

Given a stateσ, define the channel

N

σas

N

σ:X7→Tr(X)σ. Definition (Indistinguishabilty)

A quantum encryption scheme hasε-indistinguishable ciphertexts against adversaries without side information, if there existsσ∈D(d0)such that

1 n

n

i=1

E

i

N

σ

11

6ε.

Definition (Non-malleability)

A quantum encryption scheme isε-non-malleable against adversaries without side information, if there existsσ∈D(d0)such that, for all

N

C

(d0), there exists 06p61 such that

1 n

n

i=1

D

i

N

E

i−(pid+ (1−p)

N

σ)

6ε.

(26)

One-time-secure quantum encryption

A quantum encryption scheme is given by families of channels{

E

i:L(d)→L(d0)}ni=1 (encoders) and{

D

i:L(d0)→L(d)}ni=1(decoders) satisfying

D

i

E

i=idfor all 16i6n.

The parameterslogn,logdandlogd0are thekey,messageandciphertextlength, respectively.

Given a stateσ, define the channel

N

σas

N

σ:X7→Tr(X)σ. Definition (Indistinguishabilty)

A quantum encryption scheme hasε-indistinguishable ciphertexts against adversaries without side information, if there existsσ∈D(d0)such that

1 n

n

i=1

E

i

N

σ

11

6ε.

Definition (Non-malleability)

A quantum encryption scheme isε-non-malleable against adversaries without side information, if there existsσ∈D(d0)such that, for all

N

C

(d0), there exists 06p61 such that

1 n

n

i=1

D

i

N

E

i−(pid+ (1−p)

N

σ)

6ε.

(27)

One-time-secure quantum encryption scheme with small key

A family of unitaries{Ui}ni=1defines a quantum encryption scheme (with same message and cyphertext length) via:

E

i:X7→UiXUiand

D

i=

E

ifor all 16i6n.

Fact:SettingTE:X7→1nn

i=1

E

i(X)andΘE,D:

M

7→n1n

i=1

D

i

M

E

i, we have: ε-indistinguishable⇒

TE−T(1)

1162ε,

TE−T(1)

116ε⇒ε-indistinguishable. ε-non-malleable⇒

ΘE,D−Θ

62ε,

ΘE,D−Θ

6ε⇒ε-non-malleable.

−→Proving security of a unitary encryption scheme(

E

,

D

)boils down to proving that its associated channelTEand super-channelΘE,Dare approximate twirls.

Theorem

Fix 0<ε<1. Letµbe a 2-design onU(d)andU1, . . . ,Unbe sampled independently fromµ. Ifn>Cd2(logd)62, then with probability at least 1/2, the quantum encryption scheme defined by the family of unitaries{Ui}ni=1hasε/√

d-indistinguishable ciphertexts and isε-non-malleable against adversaries without side information.

−→Unitary encryption scheme for a message oflogdbits using 2logd+O(log logd)bits of key, which is secure against adversaries without side information.

(28)

One-time-secure quantum encryption scheme with small key

A family of unitaries{Ui}ni=1defines a quantum encryption scheme (with same message and cyphertext length) via:

E

i:X7→UiXUiand

D

i=

E

ifor all 16i6n.

Fact:SettingTE:X7→1nn

i=1

E

i(X)andΘE,D:

M

7→n1n

i=1

D

i

M

E

i, we have:

ε-indistinguishable⇒

TE−T(1)

1162ε,

TE−T(1)

116ε⇒ε-indistinguishable.

ε-non-malleable⇒

ΘE,D−Θ

62ε,

ΘE,D−Θ

6ε⇒ε-non-malleable.

−→Proving security of a unitary encryption scheme(

E

,

D

)boils down to proving that its associated channelTE and super-channelΘE,Dare approximate twirls.

Theorem

Fix 0<ε<1. Letµbe a 2-design onU(d)andU1, . . . ,Unbe sampled independently fromµ. Ifn>Cd2(logd)62, then with probability at least 1/2, the quantum encryption scheme defined by the family of unitaries{Ui}ni=1hasε/√

d-indistinguishable ciphertexts and isε-non-malleable against adversaries without side information.

−→Unitary encryption scheme for a message oflogdbits using 2logd+O(log logd)bits of key, which is secure against adversaries without side information.

(29)

One-time-secure quantum encryption scheme with small key

A family of unitaries{Ui}ni=1defines a quantum encryption scheme (with same message and cyphertext length) via:

E

i:X7→UiXUiand

D

i=

E

ifor all 16i6n.

Fact:SettingTE:X7→1nn

i=1

E

i(X)andΘE,D:

M

7→n1n

i=1

D

i

M

E

i, we have:

ε-indistinguishable⇒

TE−T(1)

1162ε,

TE−T(1)

116ε⇒ε-indistinguishable.

ε-non-malleable⇒

ΘE,D−Θ

62ε,

ΘE,D−Θ

6ε⇒ε-non-malleable.

−→Proving security of a unitary encryption scheme(

E

,

D

)boils down to proving that its associated channelTE and super-channelΘE,Dare approximate twirls.

Theorem

Fix 0<ε<1. Letµbe a 2-design onU(d)andU1, . . . ,Unbe sampled independently fromµ. Ifn>Cd2(logd)62, then with probability at least 1/2, the quantum encryption scheme defined by the family of unitaries{Ui}ni=1hasε/√

d-indistinguishable ciphertexts and isε-non-malleable against adversaries without side information.

−→Unitary encryption scheme for a message oflogdbits using 2logd+O(log logd)bits of key, which is secure against adversaries without side information.

(30)

Generalization to adversaries with limited side information

If the adversary has at mostlogkbits of side information:

Indistinguishability⇔

idk⊗TE−idk⊗T(1)

11small.

Non-malleability⇔

idk⊗ΘE,D−idk⊗Θ

small.

Fact:kidk⊗Sk116kkSk11andkidk⊗Σk6k2kΣk. Corrolary

Fix 0<ε<1. Letµbe a 2-design onU(d)andU1, . . . ,Unbe sampled independently fromµ. Ifn>Cd2(logd)6k42, then with probability at least 1/2, the quantum encryption scheme defined by the family of unitaries{Ui}ni=1hasε/k√

d-indistinguishable ciphertexts and is ε-non-malleable against adversaries withk-bounded side information.

−→Unitary encryption scheme for a message oflogdbits using 2logd+4logk+O(log logd) bits of key, which is secure against adversaries withk-bounded side information.

This is interesting only fork√

d, since security against adversaries with full side information (i.e.logdbits) is possible with 4logd+O(log logd)bits of key(Ambainis/Bouda/Winter).

(31)

Generalization to adversaries with limited side information

If the adversary has at mostlogkbits of side information:

Indistinguishability⇔

idk⊗TE−idk⊗T(1)

11small.

Non-malleability⇔

idk⊗ΘE,D−idk⊗Θ

small.

Fact:kidk⊗Sk116kkSk11andkidk⊗Σk6k2kΣk.

Corrolary

Fix 0<ε<1. Letµbe a 2-design onU(d)andU1, . . . ,Unbe sampled independently fromµ. Ifn>Cd2(logd)6k42, then with probability at least 1/2, the quantum encryption scheme defined by the family of unitaries{Ui}ni=1hasε/k√

d-indistinguishable ciphertexts and is ε-non-malleable against adversaries withk-bounded side information.

−→Unitary encryption scheme for a message oflogdbits using 2logd+4logk+O(log logd) bits of key, which is secure against adversaries withk-bounded side information.

This is interesting only fork√

d, since security against adversaries with full side information (i.e.logdbits) is possible with 4logd+O(log logd)bits of key(Ambainis/Bouda/Winter).

(32)

Generalization to adversaries with limited side information

If the adversary has at mostlogkbits of side information:

Indistinguishability⇔

idk⊗TE−idk⊗T(1)

11small.

Non-malleability⇔

idk⊗ΘE,D−idk⊗Θ

small.

Fact:kidk⊗Sk116kkSk11andkidk⊗Σk6k2kΣk. Corrolary

Fix 0<ε<1. Letµbe a 2-design onU(d)andU1, . . . ,Unbe sampled independently fromµ. Ifn>Cd2(logd)6k42, then with probability at least 1/2, the quantum encryption scheme defined by the family of unitaries{Ui}ni=1hasε/k√

d-indistinguishable ciphertexts and is ε-non-malleable against adversaries withk-bounded side information.

−→Unitary encryption scheme for a message oflogdbits using 2logd+4logk+O(log logd) bits of key, which is secure against adversaries withk-bounded side information.

This is interesting only fork√

d, since security against adversaries with full side information (i.e.logdbits) is possible with 4logd+O(log logd)bits of key(Ambainis/Bouda/Winter).

(33)

Final comments

Our approach to construct “economical” approximate unitary designs: sub-sampling few operators from a known (approximate) unitary design.

Problem:How to efficiently construct the latter in the first place? (i.e. equivalently: how to efficiently construct more specifiable approximate unitary designs?)

−→Analyze known such constructions with respect to our, weaker, notion of approximation.

More general question:Is it possible to approximate a quantum channel by one with few Kraus operators, under the constraint that those must be of a specific form? (here: unitaries with a tensor product structure)

Other potential applications:data hiding and data locking(Hayden/Leung/Shor/Winter).

(34)

Final comments

Our approach to construct “economical” approximate unitary designs: sub-sampling few operators from a known (approximate) unitary design.

Problem:How to efficiently construct the latter in the first place? (i.e. equivalently: how to efficiently construct more specifiable approximate unitary designs?)

−→Analyze known such constructions with respect to our, weaker, notion of approximation.

More general question:Is it possible to approximate a quantum channel by one with few Kraus operators, under the constraint that those must be of a specific form? (here: unitaries with a tensor product structure)

Other potential applications:data hiding and data locking(Hayden/Leung/Shor/Winter).

(35)

Final comments

Our approach to construct “economical” approximate unitary designs: sub-sampling few operators from a known (approximate) unitary design.

Problem:How to efficiently construct the latter in the first place? (i.e. equivalently: how to efficiently construct more specifiable approximate unitary designs?)

−→Analyze known such constructions with respect to our, weaker, notion of approximation.

More general question:Is it possible to approximate a quantum channel by one with few Kraus operators, under the constraint that those must be of a specific form? (here: unitaries with a tensor product structure)

Other potential applications:data hiding and data locking(Hayden/Leung/Shor/Winter).

(36)

References

A. Ambainis, J. Bouda, A. Winter.Non-malleable encryption of quantum information.

2009.

G. Aubrun.On almost randomizing channels with a short Kraus decomposition. 2009.

F.G.S.L. Brandão, A.W. Harrow, M. Horodecki.Local random quantum circuits are approximate polynomial-designs. 2016.

A.W. Harrow, S. Mehraban.Approximate unitaryt-designs by short random quantum circuits using nearest-neighbor and long-range gates. 2018.

P. Hayden, D. Leung, P.W. Shor, A. Winter.Randomizing quantum states: constructions and applications. 2004.

C. Lancien, A. Winter.Approximating quantum channels by completely positive maps with small Kraus rank. 2017.

Références

Documents relatifs

The physical basis for our device-independent security proof is the fact that measurements on entangled particles can provide Alice and Bob with nonlocal correlations,

Contributions due to the Coulomb interaction to the second order in a R ∗ are exactly discarded by contributions due to the pseudo- potential, the presence of the infinite

The paper is organized as follows: 1-2 contain preliminaries on the soft and hard liberation operations, in 3-4 we discuss the quantum reflection groups, in 5-6 we discuss the

En effet à partir des contributions du chapitre 5 dénommé « la détermination du statut et du niveau de vulnérabilité d’un individu à travers les Réseaux Bayésiens dans

The production of entropy solely vanishes for reversible transfor- mations, which corresponds to quasi-static (infinitely slow) processes. The second law has crucial

The probabilistic nature of the continuous limit found by Attal and Pautrat is not due to the passage to the limit, it is already built-in the Hamiltonian dynamics of repeated

In this work, we theoretically studied the static properties of small molecular systems, their field-free photodissociation and radiative association dynamics, the control of

–  Quantum Mechanics as an theory of information –  Advances in classical Computer Science. –  Practical Quantum Cryptography –  Advances in