Source-linked AI summary
Cryptanalysis of the Hillery-Buzek-Berthiaume quantum secret-sharing protocol
Su-Juan Qin, Fei Gao, Qiao-Yan Wen, Fu-Chen Zhu
TL;DR
Participant attacks are a central security threat in quantum secret sharing, and the paper addresses incomplete analysis of such attacks in the HBB protocol. It develops a mixed-state discrimination method, derives necessary and sufficient conditions, and constructs an explicit attack showing that original HBB is insecure.
Problem
Security analysis of QSS is difficult because multiple participants may be dishonest, and prior analyses did not cover all individual attacks systematically.
Method
The paper analyzes a dishonest participant who couples an ancilla to transmitted qubits and uses mixed-state discrimination after basis announcements.
Results
The derived necessary and sufficient conditions allow a dishonest participant to obtain all information without introducing errors, showing that original HBB is insecure.
Takeaways & Limitations
The method supports systematic security analysis, makes attack construction easy when loopholes exist, and can be modified for similar QSS protocols.
Abstract
from arXiv · showhide
The participant attack is the most serious threat for quantum secret-sharing protocols. We present a method to analyze the security of quantum secret-sharing protocols against this kind of attack taking the scheme of Hillery, Buzek, and Berthiaume (HBB) [Phys. Rev. A 59 1829 (1999)] as an example. By distinguishing between two mixed states, we derive the necessary and sufficient conditions under which a dishonest participant can attain all the information without introducing any error, which shows that the HBB protocol is insecure against dishonest participants. It is easy to verify that the attack scheme of Karlsson, Koashi, and Imoto [Phys. Rev. A 59, 162 (1999)] is a special example of our results. To demonstrate our results further, we construct an explicit attack scheme according to the necessary and sufficient conditions. Our work completes the security analysis of the HBB protocol, and the method presented may be useful for the analysis of other similar protocols.
I. INTRODUCTION
The paper develops a systematic method for analyzing participant attacks in QSS, using the HBB scheme as an example. It derives necessary and sufficient attack conditions and explains how these conditions support explicit attack construction.
- QSS security analysis is difficult because multiple participants may be dishonest, and relatively few security results existed.
- The paper gives a complete and systematic analysis of the original HBB protocol against participant attacks.
- The derived necessary and sufficient conditions characterize successful attacks that obtain the whole secret without introducing errors.
- The conditions allow many attack schemes to be found easily, including the eavesdropping strategy previously reported in Ref..
- The paper organizes the analysis around the HBB protocol, general participant attack strategies, an explicit attack, and concluding security discussion.
II. THE HBB PROTOCOL
The HBB protocol shares a secret using GHZ triplets distributed among Alice, Bob, and Charlie. Random basis announcements and sampled error checking determine which outcomes become secret-key data.
- Table I lists the correlations between Alice’s and Bob’s measurement results and Charlie’s results.Alice’s results are listed in the first column and Bob’s in the first row.
- Alice prepares GHZ triplets, keeps particle A, and sends particles B and C to Bob and Charlie.The state is (1/2)(|000⟩+|111⟩)ABC.
- Alice, Bob, and Charlie randomly measure in the x or y basis and then publicly announce their measurement bases.Bob and Charlie announce first; Alice subsequently reveals all three bases.
- When the number of x-basis choices is odd, the outcomes are useful because Bob and Charlie can deduce Alice’s outcome cooperatively.
- Alice checks a randomly selected large subset by publicly comparing outcomes and retains the remaining outcomes when the error rate is below a threshold.
III. THE ATTACK ON THE HBB PROTOCOL
The attack model treats Charlie as a dishonest participant who exploits delayed basis information. He couples an ancilla to the transmitted qubits, forwards one qubit, stores the others, and measures after the announcements.
- Charlie is chosen as the dishonest participant and seeks Alice’s secret without causing errors in the eavesdropping check.
- Charlie interacts an initially prepared ancilla with qubits B and C using a unitary operation.The ancilla dimensionality is unrestricted in the attack model.
- After the interaction, Charlie sends qubit B to Bob while retaining qubit C and the ancilla.
- Charlie delays measurement until Alice announces the measurement bases, then selects his measurement strategy using that information.
A. The conditions to escape detection
The paper derives conditions under which Charlie can distinguish the relevant state sets perfectly and therefore evade detection. These conditions establish a successful participant attack on the original HBB protocol.
- The conditions to escape detection: Charlie must completely discriminate between two state sets determined by Alice’s and Bob’s x-basis outcomes.Perfect discrimination occurs if and only if the subspaces spanned by the two sets are orthogonal.
- The conditions to escape detection: The required discrimination imposes four orthogonality constraints among Charlie’s conditional states.The constraints are the four scalar products listed for the x-basis case.
- The conditions to escape detection: The analysis obtains corresponding constraints for the other measurement-basis cases before collecting the final necessary and sufficient conditions.
- The conditions to escape detection: The resulting conditions include a01* a11⟨ε01|ε11⟩ = 0, a10* a11⟨ε10|ε11⟩ = 0, |a00| = |a11|, and |a01| = |a10|.
- The conditions to escape detection: Charlie can evade Alice’s and Bob’s detection when his operations satisfy the derived conditions.
B. The maximum information the attacker can attain
The attacker’s information is bounded by distinguishing two mixed states arising from Alice’s possible results, using minimum-error discrimination and optimizing the resulting mutual information. Under the derived conditions, the ancilla states are mutually orthogonal with equal amplitudes, enabling a dishonest participant to obtain the secret without detection.
- Mixed-state discrimination: Charlie* distinguishes two mixed states corresponding to Alice’s possible results, which occur with equal prior probability.The analysis chooses ambiguous minimum-error discrimination because its attainable failure probability is lower than that of unambiguous discrimination for two mixed states.
- Information optimization: The mutual information I_AC is expressed through the minimum-error probability P_E and maximized subject to the attack constraints.The paper uses a Lagrange multiplier method for this constrained optimization.
- Security implication: The derived necessary and sufficient conditions show that the original HBB protocol is insecure against a dishonest participant.The known attack using two additional qubits is identified as a special case of the general result.
IV. AN EXAMPLE OF SUCCESSFUL ATTACK
The paper constructs an explicit participant attack in which Charlie* uses an ancilla and basis-dependent operations to avoid detection while recovering Alice’s secret.
- Attack setup: Charlie* initializes an ancilla, intercepts qubits B and C, applies operations, forwards B, and delays measurements until the measurement bases are announced.The attack exploits Alice’s and Bob’s delayed basis information.
- Basis-dependent operations: For each measurement-basis combination, Charlie* selects corresponding operations and measurement procedures to distinguish the relevant states.Tables II and the case analysis specify the basis-dependent choices for the four cases.
- State discrimination: The four post-interaction states are orthogonal in every case, allowing Charlie* to distinguish them perfectly.Because the states are orthogonal, the attack can separate the alternatives needed for both detection avoidance and secret recovery.
- Avoiding detection: The detection circuit converts the relevant states so Charlie* can announce results consistently with the detection protocol.For case (i), the circuit uses U = V = W = H, followed by computational-basis measurements and announcements determined by outcomes.
- Recovering the secret: Measurement outcomes 01 or 10 identify Alice’s x− secret, whereas 00 or 11 identify x+.Charlie* uses the information-qubit circuit to measure qubit C in Alice’s basis and qubit E in the computational basis.
V. CONCLUSION AND DISCUSSION
The paper concludes that participant attacks are the central security threat in QSS and that the HBB protocol is insecure in its original form. Its systematic method derives attack conditions and can support analysis and design of related QSS protocols.
- Participant attacks are identified as the most serious threat to QSS security because dishonest participants may seek the secret independently.
- The proposed method derives necessary and sufficient conditions for a dishonest participant to obtain all information without introducing errors.
- Applying the method to the original HBB protocol shows that it is insecure against dishonest participants.
- The method provides a complete treatment of individual participant attacks allowed by physical laws, improving on the previously incomplete or nonsystematic analyses.
- The method can help construct attack strategies when security loopholes exist and establish security when the attack conditions cannot be reached.
APPENDIX A: CONSTRAINTS ON CHARLIE*’S PROBES
The appendix imposes orthogonality constraints on Charlie*’s probe states so that his announcements remain consistent with Alice’s and Bob’s measurement results. Across measurement-basis cases, Charlie* must distinguish result sets associated with different announcements without causing detection errors.
- Charlie*’s operations must satisfy conditions ensuring that no errors occur in the detection procedure across the remaining measurement cases.
- x, y, y basis case: For Alice, Bob, and Charlie* using x, y, y, Charlie* must distinguish two probe-state sets corresponding to different announcement choices.
- x, y, y basis case: The x, y, y case requires orthogonality between each probe state in one announcement set and each state in the other set.
- y, x, y basis case: For Alice, Bob, and Charlie* using y, x, y, results y+x+ or y−x− imply Charlie* should announce y−, while other results imply y+.
- y, y, x basis case: In the y, y, x case, the corresponding probe states must obey four pairwise orthogonality relations.
- y, y, x basis case: For Alice, Bob, and Charlie* using y, y, x, results y+y+ or y−y− imply an x− announcement, while other results imply x+.