arXiv is now an independent nonprofit! Learn more
License: arXiv.org perpetual non-exclusive license
arXiv:1410.0556v1 [quant-ph] 02 Oct 2014

Practical sharing of quantum secrets over untrusted channels

Anne Marin Affiliation: CNRS LTCI, Département Informatique et Réseaux, Telecom ParisTech, 23 avenue d’Italie, CS 51327, 75214 Paris CEDEX 13, France    Damian Markham Affiliation: CNRS LTCI, Département Informatique et Réseaux, Telecom ParisTech, 23 avenue d’Italie, CS 51327, 75214 Paris CEDEX 13, France
Abstract

In this work we address the issue of sharing a quantum secret over untrusted channels between the dealer and players. Existing methods require entanglement over a number of systems which scales with the security parameter, quickly becoming impractical. We present protocols (interactive and a non-interactive) where single copy encodings are sufficient. Our protocols work for all quantum secret sharing schemes and access structures, and are implementable with current experimental set ups. For a single authorised player, our protocols act as quantum authentication protocols.

I Introduction

In secret sharing a dealer wishes to distribute a secret to a network of players such that only authorised sets of players can access the secret, and unauthorised sets of players cannot. After the initial protocols for sharing classical secrets Shamir79; Blakley79, ones for sharing quantum secrets were later developed HBB99; CGL99, and have found uses including secure multiparty computation BCG06. However, these protocols rely on trusted channels between the dealer and the players. In practice, channels may be corrupted either by unavoidable noise, or malicious attacks.

One way to resolve this situation would be to use the quantum authentication protocol BCGST02. However this protocol is highly impractical in that it uses error correcting codes and which would require encoding each qubit sent from the dealer into a highly entangled state (or perform entangling measurements, which would allow the generation of large entangled states), the size of which scale with the security parameter. This difficulty, on a par with the coherences needed for quantum computing, renders this approach infeasible in the near future.

In this work we present a protocol which is universal (it works for all quantum secret sharing protocols and access structures) and is implementable with current experimental setups, for example by using graph states. This is possible because our protocol uses only single copy encodings. As in the authentication scheme BCGST02, our protocol uses an initial shared secret key between the dealer and receivers. We begin by introducing an interactive protocol, which will serve as a basis for the non-interactive protocol which follows. We then give an example of an explicit graph state implementation for sharing a secret between five players such that any three can access the secret and fewer cannot. We finish with a discussion on possible variants of the protocol including the possibility of abort, and the merits of graph state implementations MS08; KFMS10; MM13; MMP13.

II Protocols

In quantum secret sharing, a secret |ψ=α|0+β|1|\psi\rangle=\alpha|0\rangle+\beta|1\rangle is encoded by the dealer dd into some logical basis |ψLP=α|0LP+β|1LP|\psi_{L}\rangle_{P}=\alpha|0_{L}\rangle_{P}+\beta|1_{L}\rangle_{P} on |P||P| systems, and distributed to the players PP. A set of players BPB\subset P are authorised if they can access the secret. This is equivalent to there existing a pair of logical operators XLX_{L}, ZLZ_{L} which are nontrivial only over the systems BB, and act over the logical basis in the appropriate way XL|iL=|i1LX_{L}|i_{L}\rangle=|i\oplus 1_{L}\rangle, ZL|iL=(1)i|iLZ_{L}|i_{L}\rangle=(-1)^{i}|i_{L}\rangle (where \oplus symbolises sum modulo two) MM13. These are used by BB to access the secret. A set of players BPB\subset P are unauthorised if they can get no information at all about the quantum secret state. The choice of the logical basis determines the authorised and unauthorised sets. All our protocols are built on the existence of these schemes (which exist for all access structures CGL99), and we will use this notation in our protocols.

For our first protocol, we use a general entangled based picture of secret sharing MM13. In this picture the dealer and the players share an entangled EPR state

|ΦdP=|0d|0LP+|1d|1LP2,\displaystyle|\Phi\rangle_{dP}=\frac{|0\rangle_{d}|0_{L}\rangle_{P}+|1\rangle_{d}|1_{L}\rangle_{P}}{\sqrt{2}}, (1)

which is then used to teleport the secret to the players. The interactive protocol presented below essentially verifies that the dealer and a give set of authorised players BB share this state (or the associated reduced state), in which case the teleportation will be successful. More explicitly, the dealer generates many (SS) copies of the entangled EPR state (1) and uses all but one to test the state (steps 3. and 4 in the protocol below), and one to teleport (step 5.). By randomly choosing when to test and when to use the state for teleportation any malicious actions cannot help but be detected. We will see after that this can be translated to a non-interactive protocol by replacing communication by a shared random key.

Interactive Protocol

  1. 1.

    Dealer dd generates SS EPR states, |ΦdPS|\Phi\rangle_{dP}^{\otimes S}, and sends the shares of each one to PP.

  2. 2.

    After PP received all their parts, dd chooses r[1,S]r\in[1,...S] at random and sends rr to PP.

  3. 3.

    For EPR pairs iri\neq r, dd chooses ti[0,1]t_{i}\in[0,1] and measures XdX_{d} if ti=0t_{i}=0 or measures ZdZ_{d} if ti=1t_{i}=1, and denotes the result yiy_{i}, and sends tit_{i} and yiy_{i} to PP.

  4. 4.

    For EPR pairs iri\neq r, accessing set BB measure XL,BX_{L,B} if ti=0t_{i}=0 or measures ZL,BZ_{L,B} if ti=1t_{i}=1. Denoting result by yiy_{i}^{\prime} if yi=yiy_{i}=y_{i}^{\prime} ACCEPT, if yiyiy_{i}\neq y_{i}^{\prime} REJECT.

  5. 5.

    For i=ri=r, dd uses EPR pair rr to teleport the secret state onto the logical basis, denoting the bell basis measurements xx, and sends xx to all PP. Upon receiving xx, BB decodes using XL,BX_{L,B} and ZL,BZ_{L,B}.

This protocol is effectively a quantum authentication protocol from the dealer to authorised set BB. In BCGST02 a framework for quantum authentication is laid out, along with definitions of completeness, soundness and security, which we will adopt here. A general quantum authentication scheme for sending messages from AA to BB is described by a randomly chosen classical key k𝒦k\in\mathcal{K} that is shared by AA and BB, and associated encoding operations AkA_{k} and BkB_{k} respectively. At the end of the protocol BB has a system which encodes the message, and a classical register which encodes the decision whether to accept or reject in orthogonal states |ACC|ACC\rangle and |REJ|REJ\rangle. A quantum authentication scheme is ϵ\epsilon-secure if for all states |ψ|\psi\rangle it satisfies the two conditions.

  • Completeness. For all keys k𝒦k\in\mathcal{K}

    Bk(Ak(|ψψ|))=|ψψ||ACCACC|.B_{k}(A_{k}(|\psi\rangle\langle\psi|))=|\psi\rangle\langle\psi|\otimes|ACC\rangle\langle ACC|. (2)
  • Soundness. For all (possibly malicious) channels OO, describing the expected state on Bob’s side after the protocol as ρB=1|𝒦|k𝒦Bk(O(Ak(|ψψ|)))\rho_{B}=\frac{1}{|\mathcal{K}|}\sum_{k\in\mathcal{K}}B_{k}(O(A_{k}(|\psi\rangle\langle\psi|))), and denoting the two projections Pfail|ψ:=(I|ψψ|)|ACCACC|P_{fail}^{|\psi\rangle}:=(I-|\psi\rangle\langle\psi|)\otimes|ACC\rangle\langle ACC|, then

    Tr(Pfail|ψρB)ϵ.Tr\left(P_{fail}^{|\psi\rangle}\rho_{B}\right)\leq\epsilon. (3)

We say that our protocols are ϵ\epsilon-secure if all authorised sets BB can authenticate the secret with ϵ\epsilon-security, and unauthorised sets of players get no information. The latter is guarenteed by the use of the original secret sharing logical operators in our protocol, as is the completeness, we will prove the soundness now.

The left hand side of equation (3) is equal to the probability of accepting multiplied by the fidelity to BB’s resulting state (averaged over keys) to the space orthogonal to the ideal state |ψ|\psi\rangle. That is, it represents a failing in the protocol, so we want to make it arbitrarily small (with some security parameter SS). In order to prove soundness, we will bound this by considering statements about the entangled states themselves, before the teleportation.

We first introduce the operator ΠdB:=1/4(IdIB+XdXL,B+ZdXdZL,BXL,B+ZdZL,B)\Pi_{dB}:=1/4(I_{d}\otimes I_{B}+X_{d}\otimes X_{L,B}+Z_{d}X_{d}\otimes Z_{L,B}X_{L,B}+Z_{d}\otimes Z_{L,B}), which is a projector onto a space where all states are maximally entangled between dd and BB. More specifically every state in this subspace can be expressed in the form |0d|0L(i)B+|1d|1L(i)B2\frac{|0\rangle_{d}|0_{L(i)}\rangle_{B}+|1\rangle_{d}|1_{L(i)}\rangle_{B}}{\sqrt{2}}, where {|0L(i)B,|1L(i)B}\{|0_{L(i)}\rangle_{B},|1_{L(i)}\rangle_{B}\} are some basis of BB such that ii represents a possible logical bases, XL,B|jL(i)B=|j1L(i)BX_{L,B}|j_{L(i)}\rangle_{B}=|{j\oplus 1}_{L(i)}\rangle_{B}, ZL,B|jL(i)B=(1)j|jL(i)BZ_{L,B}|j_{L(i)}\rangle_{B}=(-1)^{j}|j_{L(i)}\rangle_{B} and we will use many such bases in (4) such that jL(i)|kL(m)B=δj,kδi,m\langle j_{L(i)}|k_{L(m)}\rangle_{B}=\delta_{j,k}\delta_{i,m}.

Consider the state ρdBr\rho_{dB}^{r} which is used to teleport in protocol step 5 (conditioned on accepting on all other pairs, see (6)). Any such state can be purified to |ΨdBE|\Psi\rangle_{dBE}, which can be expanded

|ΨdBE\displaystyle|\Psi\rangle_{dBE} =\displaystyle= (ΠdBIE+(IdBΠAB)IE))|ΨdBE\displaystyle(\Pi_{dB}\otimes I_{E}+(I_{dB}-\Pi_{AB})\otimes I_{E}))|\Psi\rangle_{dBE} (4)
=\displaystyle= F(iαi(|0d|0L(i)B+|1d|1L(i)B)|ψiE)\displaystyle\sqrt{F}\left(\sum_{i}\alpha_{i}(|0\rangle_{d}|0_{L(i)}\rangle_{B}+|1\rangle_{d}|1_{L(i)}\rangle_{B})|\psi_{i}\rangle_{E}\right)
+1F|ξdBE,\displaystyle+\sqrt{1-F}|\xi\rangle_{dBE},

where F=Tr(ΠdBρdBr)F=Tr(\Pi_{dB}\rho_{dB}^{r}). If this state is then used to teleport a state |ψ|\psi\rangle from dd to BB, followed by BB doing a logical decoding to ancilla system BB^{\prime} (for example BB performs a logical swap onto BB^{\prime}) the state recovered ρB\rho_{B^{\prime}} has fidelity f:=ψ|ρB|ψf:=\langle\psi|\rho_{B^{\prime}}|\psi\rangle with the original state satisfying fFf\geq F. Furthermore,

Tr(Pfail|ψρB)\displaystyle Tr\left(P_{fail}^{|\psi\rangle}\rho_{B}\right) =Tr(((I|ψψ|)|ACCACC|)ρB)\displaystyle=Tr\left(((I-|\psi\rangle\langle\psi|)\otimes|ACC\rangle\langle ACC|)\rho_{B}\right)
Tr(ΠdB|ACCACC|ρdBAR),\displaystyle\leq Tr\left(\Pi_{dB}^{\perp}\otimes|ACC\rangle\langle ACC|\rho_{dB_{AR}}\right), (5)

where ΠdB\Pi_{dB}^{\perp} is the projector onto the space orthogonal to ΠdB\Pi_{dB} and ρdBAR=1/Sr=1SpACCrρdBr|ACCACC|+pREJrρdBr,REJ|REJREJ|\rho_{dB_{AR}}=1/S\sum_{r=1}^{S}p_{ACC}^{r}\rho_{dB}^{r}\otimes|ACC\rangle\langle ACC|+p_{REJ}^{r}\rho_{dB}^{r,REJ}\otimes|REJ\rangle\langle REJ|, pACCrp_{ACC}^{r} and pREJrp_{REJ}^{r} are the probability of accepting and rejecting respectively when using rr, and ρdBr,REJ\rho_{dB}^{r,REJ} is the state conditioned on rejecting.

Denoting the POVM element associated to accepting the test step 4 for pair ii as MACCi=1/2(IdiIBi+XdiXL,Bi2+IdiIBi+ZdiZL,Bi2)M_{ACC_{i}}=1/2\left(\frac{I_{d_{i}}\otimes I_{B_{i}}+X_{d_{i}}\otimes X_{L,B_{i}}}{2}+\frac{I_{d_{i}}\otimes I_{B_{i}}+Z_{d_{i}}\otimes Z_{L,B_{i}}}{2}\right), we have MACCi(IdiIBi+Πdi,Bi)2M_{ACC_{i}}\leq\ \frac{\left(I_{d_{i}}\otimes I_{B_{i}}+\Pi_{d_{i},B_{i}}\right)}{2}. Then, if we call the total state shared over all copies of the dealer and the players BB, ρd1,B1,dS,BS\rho_{d_{1},B_{1},...d_{S},B_{S}}, it follows that

ρdBr=1pACCrTrrc(irMACCiρd1,B1,dS,BS),\rho_{dB}^{r}=\frac{1}{p_{ACC}^{r}}Tr_{r^{c}}\left(\bigotimes_{i\neq r}M_{ACC_{i}}\rho_{d_{1},B_{1},...d_{S},B_{S}}\right), (6)

where TrrcTr_{r^{c}} indicates trace over all systems but rr. Putting this together we have,

Tr(ΠdBρdB)\displaystyle Tr\left(\Pi_{dB}^{\perp}\rho_{dB}\right) =1Sr=1STr(Πdr,BrirMACCiρd1,B1,dS,BS)\displaystyle=\frac{1}{S}\sum_{r=1}^{S}Tr\left(\Pi_{d_{r},B_{r}}^{\perp}\otimes_{i\neq r}M_{ACC_{i}}\rho_{d_{1},B_{1},...d_{S},B_{S}}\right)
Tr(Qρd1,B1,dS,BS),\displaystyle\leq Tr\left(Q\rho_{d_{1},B_{1},...d_{S},B_{S}}\right), (7)

where Q=r=1SΠdr,Brir(IdiIBi+Πdi,Bi)2Q=\sum_{r=1}^{S}\Pi_{d_{r},B_{r}}^{\perp}\otimes_{i\neq r}\frac{\left(I_{d_{i}}\otimes I_{B_{i}}+\Pi_{d_{i},B_{i}}\right)}{2}. It can easily be seen that QQ has maximum eigenvalues of 1/S1/S, reached by projection Πdj,BjijΠdi,Bi\Pi_{d_{j},B_{j}}^{\perp}\otimes_{i\neq j}\Pi_{d_{i},B_{i}} for any jj. With this, we arrive at the following theorem.

Theorem 1.

The interactive protocol defined above is ϵ\epsilon-secure, with scaling ϵ=1/S\epsilon=1/S.

Note here that the scaling of the protocol is inverse linear, as compared to exponential in BCGST02. This can be understood as the cost of making the protocol practical. To get the exponential scaling in BCGST02 they require entangled measurements or encodings over SS systems (which quickly becomes infeasible), whereas our protocol requires SS copies of the single round encodings, which adds no difficulty in standard optical implementations, and is implementable with current technology.

The protocol above suffers from two main issues. Firstly, interaction is needed between the dealer and the players. Although this could be allowed in principle, it is more interesting if limited or no interaction is needed. Second, largely due to the interaction, memory is required by the dealer and players BB between steps 1 and 5. The dealer must keep their part of the EPR pairs until the players have recieved their shares, and BB must keep their shares until rr is announced by the dealer and further until dd announces their result xx for the teleportation. These problems can be overcome by replacing communication and the entanglement between the dealer and players with shared random keys, as was done in BCGST02, but with an extra twist - they should be shared using a classical secret sharing protocol, so that the access structure is maintained. In this way, the protocol below requires no interaction after the initial sharing of a random key and the dealer’s use of the channel, and similarly no memory is required by BB or dd and no entanglement is needed between dd and PP (it is of the ‘prepare and measure’ type). To encode the randomly chosen rr, we define string q=(q1,qS)q=(q_{1},...q_{S}) such that qi=0q_{i}=0 if iri\neq r, qi=1q_{i}=1 if i=ri=r, where rr is randomly chosen in [1,..S][1,..S].

Non-interactive Protocol

  1. 1.

    dd and PP share random strings q,t,y,xq,t,y,x via a classical secret sharing scheme over P (i.e. dd knows each string, but it is shared via a classical secret sharing scheme with the relevant access structure over PP so that only authorised sets can access it, and only when they collaborate to do so, and unauthorised sets get no information at all).

  2. 2.

    Going through round by round i=1Si=1...S. If qi=0q_{i}=0 the dealer proceeds to step 3, if qi=1q_{i}=1 the dealer proceeds to step 4.

  3. 3.

    For qi=0q_{i}=0

    1. (a)

      Dealer prepares and distributes state HLtiZLyi|0LP+|1LP2H_{L}^{t_{i}}Z_{L}^{y_{i}}\frac{|0_{L}\rangle_{P}+|1_{L}\rangle_{P}}{\sqrt{2}}.

    2. (b)

      After receiving the state from the dealer, authorised set BB collaborate to find qiq_{i} (which is 00), tit_{i}, and yiy_{i}.

    3. (c)

      Authorised set BB measures XL,BX_{L,B} if ti=0t_{i}=0 or measures ZL,BZ_{L,B} if ti=1t_{i}=1 . The result is denoted yiy_{i}^{\prime}.
      If yiyiy_{i}\neq y_{i}^{\prime} REJECT. If yi=yiy_{i}=y_{i}^{\prime} ACCEPT.

    4. (d)

      If i=Si=S, END, otherwise return to step 2.

  4. 4.

    For qi=1q_{i}=1

    1. (a)

      dd encodes and distrubutes the state XLx0ZLx1|ψLPX_{L}^{x_{0}}Z_{L}^{x_{1}}|\psi_{L}\rangle_{P}.

    2. (b)

      After recieving the state from the dealer, authorised set BB collaborate to find qiq_{i} (which is 11), tit_{i}, yiy_{i} and xx.

    3. (c)

      BB decodes using XL,B,ZL,BX_{L,B},Z_{L,B}.

    4. (d)

      If i=Si=S, END, otherwise return to step 2

Replacing the communication by shared random strings in this way does not effect the security BCGST02; SP00, and we have the following theorem.

Theorem 2.

The non- interactive protocol defined above is ϵ\epsilon-secure, with ϵ=1/S\epsilon=1/S.

III Example

In recent years graph states have emerged as a useful framework in which to do secret sharing MS08; KFMS10; MMP13; MM13. As an example, we now illustrate how secret sharing over untrusted channels works for the case of five players, such that any set of three or more players can access the secret and any fewer have none (the so called (3,5)(3,5) threshold secret sharing scheme of MS08). To begin, we introduce some notation. A graph state |G1,,n|G\rangle_{1,...,n} is a state on nn qubits which is associated to graph GG through graph state stabiliser operators Ki:=XijN(i)ZjK_{i}:=X_{i}\otimes_{j\in N(i)}Z_{j} where ii is associated to a vertex in the graph and N(i)N(i) are the set of its neighbours, and the eigenequations Ki|G1,n=|G1,nK_{i}|G\rangle_{1,...n}=|G\rangle_{1,...n} i\forall i.

In our example the logical states are given by |0LP=|GPP|0_{L}\rangle_{P}=|G_{P}\rangle_{P} for the graph GPG_{P} in Fig. 1a), and |1LP=Z1Z2Z3Z4Z5|GPP|1_{L}\rangle_{P}=Z_{1}Z_{2}Z_{3}Z_{4}Z_{5}|G_{P}\rangle_{P} with P={1,2,3,4,5}P=\{1,2,3,4,5\}. The entangled state used in the interactive protocol step 1 is

|ΦdP=|0d|0LP+|1d|1LP2.\displaystyle|\Phi\rangle_{dP}=\frac{|0\rangle_{d}|0_{L}\rangle_{P}+|1\rangle_{d}|1_{L}\rangle_{P}}{\sqrt{2}}. (8)

It is not difficult to see that this is itself a graph state associated to the graph in Fig. 1b), |ΦdP=|GdPdP|\Phi\rangle_{dP}=|G_{dP}\rangle_{dP}.

The choice of logical operators depends on the set BPB\subset P who are trying to access the secret. Notice that during the protocol the dealers’ action does not require knowledge of BB - this is essential to secret sharing, so that the players can decide for themselves who access the secret.

If players B={1,2,3}B=\{1,2,3\} wish to act as the authorised set, they can use logical operators XL=X1Z2X3X_{L}=X_{1}Z_{2}X_{3} and ZL=Z1X2Z3Z_{L}=Z_{1}X_{2}Z_{3}. The logical operators measured in the test step of the protocol (step 4 for the interactive and step 3 for the non-interactive) are graph state stabilisers of the graph GdBG_{dB} given in Fig. 1c), XdXL,B=KdK1K3X_{d}\otimes X_{L,B}=K_{d}K_{1}K_{3}, ZdZL,B=K2Z_{d}\otimes Z_{L,B}=K_{2}. This is no coincidence, and is a general feature of graph state protocols, which gives a simple decomposition of states into the graph state basis as the natural expansion for (4). To decode the secret after teleportation, players 11 and 33 measure in the Bell basis, and the secret is passed onto the qubit of player 22. This is the same decoding procedure for the standard secret sharing protocol MS08.

If players B={1,3,4}B=\{1,3,4\} wish to act as the authorised set, they can use logical operators XL=Z1X3X4X_{L}=Z_{1}X_{3}X_{4} and ZL=X1X3X4Z_{L}=X_{1}X_{3}X_{4}. The logical operators measured in the test step of the protocol (4 for the interactive and 3 for the non-interactive) are graph state stabilisers of the graph GdBG_{dB} given in Fig. 1d), XdXL,B=KdK3K4X_{d}\otimes X_{L,B}=K_{d}K_{3}K_{4}, ZdZL,B=K1K3K4Z_{d}\otimes Z_{L,B}=K_{1}K_{3}K_{4}. In this case, to decode the secret after teleportation, players 33 and 44 measure in the Bell basis, and the secret is passed onto the qubit of player 11.

Logical operators can similarly be defined for all sets of three players, and it is easy to see that any two players cannot access the secret by themselves MS08.

a) 2211554433        b) dd2211554433       

c)dd223311        d)dd114433

Figure 1: Graphs for sharing a secret amongst five players such that any majority can access the secret MS08.a) Graph GPG_{P} associated to logical encoding. b) Graph GdPG_{dP} for the entangled state between dd and PP used in step 1 of the protocol. c) Graph GdBG_{dB} associated to the test for players B={1,2,3}B=\{1,2,3\}. d) Graph GdBG_{dB} associated to the test for players B={1,3,4}B=\{1,3,4\}.

IV Conclusions

Several variations of these protocols are also possible. In particular, if the quantum secret is precious, the dealer may not want to send the information when the channel is not trusted - i.e. when it fails the test part of the protocols above. To address this one can adapt the protocol to allow for the players to announce abort when they fail the test. It is possible to show an adapted theorem for security, which is only slightly modified. We present the protocol and the theorem in the appendix A. One subtle issue with how this may be used however, is that the protocol is now interactive (albeit limited to when the players announce abort). When the accessing set BB announce abort they declare themselves, which may be an issue in some uses of secret sharing as a primitive (one may try to develop ways to overcome this for example using an anonymous announcement of abort). Another alternative protocol with abort can be found if, instead of randomly choosing in a fixed number (SS) of rounds, at each round we randomly choose to test or use the channel. This allows for slightly different security statements, as used in PCW12 for entanglement verification. We consider this simplified unbounded aborting protocol in appendix A.

Using graph state schemes as in the example shown here has several advantages. Firstly they are a common framework for many quantum information processing tasks, including measurement based quantum computation and error correction. This allows these protocols to naturally fit into more general and elaborate network scenarios integrating several of these tasks. Furthermore, this relationship allows us to understand the connection between different protocols. The measurements used for the test part of our protocol are exactly those used for the CQCQ protocols to establish secure key between the dealer and authorised players MM13. This relationship is general - whenever complementary bases are used to establish a secure key, successful key generation implies the channel works CW05; MM13.

Secondly graph states are very well suited to implementation. Many schemes exist for the generation and manipulation of graph states in different technologies including linear optics Browne05, continuous variables Rigas12; Ukai11 and ion traps Wunderlich09; Lanyon13. Optical implementations of graph states are ideal for the secret sharing protocols presented here, and experiments in this direction are well advanced, indeed optics has been used to implement sophisticated quantum information processing tasks including measurement based quantum computing WRR05, blind quantum computation BKBFW12, and error correction BHT14. These experiments contain all the key steps needed for our protocols.

All of the results here easily extend to the qudit case, including use for qudit graph state secret sharing KFMS10; MM13, which allows our scheme to be used to cover all access structures. One simply extends the states and operators to their natural qudit versions. This is done explicitly in the appendix B. Furthermore, the proofs also follow through for secret sharing protocols using mixed state encodings, as well as the hybrid protocols of BCT09,JMP11 where classical secret sharing is used in addition to allow for access structures otherwise forbidden, in this case however authenticated classical channels between the dealer and the players must also be secure.

Acknowledgements. We thank Anthony Leverrier, Eleni Diamanti and André Chailloux for many useful discussions and helpful comments. This work was supported by the Ville de Paris Emergences program, project CiQWii.

References

  • (1) A. Shamir, Commun. ACM 22, 612 (1979).
  • (2) G. R. Blakley, Proceedings of the National Computer Conference 48, 313-317 (1979).
  • (3) M. Hillery, V. Bužek and A. Berthiaume, Phys. Rev. A 59, 1829 (1999).
  • (4) R. Cleve, D. Gottesman, H.K. Lo, Phys. Rev. Lett. 83, 648 (1999).
  • (5) M. Ben-Or, C. Crépeau, D. Gottesman, A. Hassidim, A. Smith, In 47th Annual IEEE Symposium on Foundations of Computer Science, FOCS’06, 249-260. (2006).
  • (6) Howard Barnum, Claude Crépeau, Daniel Gottesman, Adam Smith and Alain Tapp, Proc. 43rd Annual IEEE Symposium on the Foundations of Computer Science (FOCS ’02), pp. 449-458. IEEE Press, (2002).
  • (7) D. Markham and B. C. Sanders, Phys. Rev. A, 78(4) 042309 (2008).
  • (8) A. Keet, B. Fortescue, D. Markham and B. C. Sanders, Phys. Rev. A 82, 062315 (2010).
  • (9) A. Marin and D. Markham, Phys. Rev. A 88, 042332 (2013).
  • (10) A. Marin, D. Markham and S. Perdrix, TQC’13, LIPICS, Vol 22, pp 308–324 (2013).
  • (11) P. W. Shor and J. Preskill, Phys. Rev. Lett. 85, 441 (2000).
  • (12) A. Pappa, A. Chailloux, S. Wehner, E. Diamanti and I.Kerenidis, Phys. Rev. Lett. 108(26), 260502 (2012).
  • (13) M. Christandl and A. Winter, IEEE Trans Inf Theory, vol 51, no.9, pp 3159-3165 (2005).
  • (14) Daniel E. Browne and Terry Rudolph, Physical Review Letters 95, 010501 (2005).
  • (15) I. Rigas, C. Gabriel, S. Berg-Johansen, A. Aiello, P. van Loock, U. L. Andersen, Ch. Marquardt and G. Leuchs, Quant-ph/1210.5188.
  • (16) Ryuji Ukai, Noriaki Iwata, Yuji Shimokawa, Seiji C. Armstrong, Alberto Politi, Jun-ichi Yoshikawa, Peter van Loock and Akira Furusawa, Phys. Rev. Lett 106, 240504 (2011).
  • (17) P. Walther, K. J. Resch, T. Rudolph, E. Schenck, H. Weinfurter, V. Vedral, M. Aspelmeyer and A. Zeilinger, Nature 434, 169 (2005).
  • (18) S. Barz, E. Kashefi, A. Broadbent, J. F. Fitzsimons, A. Zeilinger and P. Walther, Science 335, 303 (2012).
  • (19) B. A. Bell, D. A. Herrera-Martí, M. S. Tame, D. Markham, W. J. Wadsworth, J. G. Rarity Nature Communications 5, 3658 (2014)
  • (20) A. Broadbent, P. R. Chouha and A. Tapp, Proceedings of the Third International Conference on Quantum, Nano and Micro Technologies (ICQNM 2009), 59-62 (2009).
  • (21) J. Javelle, M. Mhalla and S. Perdrix, Preprint at http://arxiv.org/abs/1109.1487 (2011).
  • (22) Harald Wunderlich, Christof Wunderlich, Kilian Singer, Ferdinand Schmidt-Kaler, Physical Review A 79, 052324 (2009).
  • (23) B. P. Lanyon, P. Jurcevic, M. Zwerger, C. Hempel, E. A. Martinez, W. D�r, H. J. Briegel, R. Blatt and C. F. Roos, Measurement-based quantum computation with trapped ions. Physical Review Letters 111, 210501 (2013)
  • (24) L.Sheridan and V.Scarani, Phys. Rev. A 82, 030301(R) (2010).

Appendix A Aborting protocols

We first present an adaptation of the non-interactive protocol to include abort.

Protocol with Abort

  1. 1.

    dd and PP share random strings q,t,y,xq,t,y,x via a classical secret sharing scheme over P.

  2. 2.

    Going through round by round i=1Si=1...S. Authorised set BB collaborate to find qiq_{i}. If qi=0q_{i}=0 all proceed to step 3, if qi=1q_{i}=1 all proceed to step 4.

  3. 3.

    For qi=0q_{i}=0

    1. (a)

      Dealer prepares and distributes state HLtiZLyi|0LP+|1LP2H_{L}^{t_{i}}Z_{L}^{y_{i}}\frac{|0_{L}\rangle_{P}+|1_{L}\rangle_{P}}{\sqrt{2}}.

    2. (b)

      For authorised set BB, if ti=0t_{i}=0, BB measures ZLZ_{L}, if ti=1t_{i}=1, BB measures XLX_{L}. The result is denoted yiy_{i}^{\prime}.
      If yiyiy_{i}\neq y_{i}^{\prime} BB announces ABORT, all abort.

    3. (c)

      If yi=yiy_{i}=y_{i}^{\prime} ACCEPT, and return to step 2.

  4. 4.

    For qi=1q_{i}=1

    1. (a)

      dd encodes and distributes the state XLx0ZLx1|ψLPX_{L}^{x_{0}}Z_{L}^{x_{1}}|\psi_{L}\rangle_{P}.

    2. (b)

      BB decode.

    3. (c)

      END

Theorem 3.

The aborting protocol defined above is ϵ\epsilon-secure, with ϵ<2/S\epsilon<2/S.

The proof follows the same argumentation as before, but in this case the testing stops at round rr. This gives a different QQ operator (applied as in equation (II)),

Q=1Sr=1SΠdr,Bri<r(IdiIBi+Πdi,Bi)2i>r(IdiIBi).Q=\frac{1}{S}\sum_{r=1}^{S}\Pi_{d_{r},B_{r}}^{\perp}\bigotimes_{i<r}\frac{\left(I_{d_{i}}\otimes I_{B_{i}}+\Pi_{d_{i},B_{i}}\right)}{2}\bigotimes_{i>r}(I_{d_{i}}\otimes I_{B_{i}}). (9)

To find the greatest eigenvalue we can decompose into the {Πdi,Bi,Πdi,Bi}\{\Pi_{d_{i},B_{i}},\Pi_{d_{i},B_{i}}^{\perp}\} basis. Then we have a sum with all strings of products, where each string xx, in which Πdi,Bi\Pi_{d_{i},B_{i}} appears |x||x| times, occurs with weight 1/Sa=0|x|11/2a1/S\sum_{a=0}^{|x|-1}1/2^{a}. Thus, the greatest eigenvalue of QQ is 1/Sa=0S11/2a=22SS<2/S1/S\sum_{a=0}^{S-1}1/2^{a}=\frac{2-2^{-S}}{S}<2/S, given by the string Πd1,B1Πd2,B2ΠdS,BS\Pi_{d_{1},B_{1}}^{\perp}\otimes\Pi_{d_{2},B_{2}}^{\perp}\otimes...\Pi_{d_{S},B_{S}}^{\perp}. In this case we see that the optimal cheat (in terms of maximising the failure of the protocol) is given by the dishonest parties preparing many copies of states all outside the ideal space.

We also present an aborting protocol where the randomness (over whether to test the channel or use it) is inserted each round.

Aborting protocol, indefinite length

  1. 1.

    Dealer dd generates EPR state |ΦdP|\Phi\rangle_{dP} and sends the shares to PP.

  2. 2.

    After PP received all their parts, dd chooses r[0,S1]r\in[0,...S-1] at random and sends rr to PP. If r0r\neq 0, continue to step 3, otherwise move to step 4.

  3. 3.

    TEST

    1. (a)

      dd chooses t{0,1}t\in\{0,1\}. If t=0t=0, dd measures ZdZ_{d}, if t=1t=1 dd measures XdX_{d}. The result is denoted yy. dd sends tt and yy to PP.

    2. (b)

      If t=0t=0, BB measures ZL,BZ_{L,B}, if t=1t=1, BB measures XL,BX_{L,B}. The result is denoted yy^{\prime}. If yiyiy_{i}\neq y_{i}^{\prime} BB announces ABORT, all abort.

    3. (c)

      If yi=yiy_{i}=y_{i}^{\prime} ACCEPT, and return to step 1.

  4. 4.

    USE CHANNEL

    1. (a)

      dd uses EPR pair to teleport the secret state onto the logical basis, denoting the bell basis measurements xx, and sends xx to all PP. Upon receiving xx, BB decodes.

This protocol is similar to the use of the verification of GHZ states in PCW12, and we can present a similar security statement as there. Let CfC_{f} be the event that the state is teleported, and that the fidelity of any teleported state ρ\rho and the sent state |ψ|\psi\rangle is bounded by ψ|ρ|ψf\langle\psi|\rho|\psi\rangle\leq f, then we have the following theorem.

Theorem 4.

For all f, the probability of event CfC_{f} is bounded

OPENP(Cf))2S(1f).P(C_{f}))\leq\frac{2}{S(1-f)}. (10)

To prove this, call CfNC_{f}^{N} the event that at round N+1N+1 the state is used (which means that all previous rounds have returned accept) and that the fidelity of all states sent satisfies ψ|ρ|ψf\langle\psi|\rho|\psi\rangle\leq f. The probability of this event is given by the probability of using the N+1N+1th round state, times the probability of having tested the previous rounds times the probability of passing all the previous rounds.

P(CfN)=1S(11S)Ni=1NpiP(C_{f}^{N})=\frac{1}{S}\left(1-\frac{1}{S}\right)^{N}\prod_{i=1}^{N}p_{i} (11)

where pip_{i} is the probability that round ii is accepted. This is given by

pi\displaystyle p_{i} =Tr(ρdi,BiMACCi)\displaystyle=Tr(\rho_{d_{i},B_{i}}M_{ACC_{i}})
1+Tr(ρdi,BiΠdi,Bi)2\displaystyle\leq\frac{1+Tr(\rho_{d_{i},B_{i}}\Pi_{d_{i},B_{i}})}{2}
1+f2.\displaystyle\leq\frac{1+f}{2}. (12)

The probability of event CfC_{f} is then given by taking the limit of the sum over NN, which is bounded by taking the integral.

P(CF)\displaystyle P(C_{F}) 1S0(11S)N(1+f2)N\displaystyle\leq\frac{1}{S}\sum_{0}^{\infty}\left(1-\frac{1}{S}\right)^{N}\left(\frac{1+f}{2}\right)^{N}
1SN=0(1(1f2))N𝑑N\displaystyle\leq\frac{1}{S}\int_{N=0}^{\infty}\left(1-\left(\frac{1-f}{2}\right)\right)^{N}dN
=1S1log(1(1f2))\displaystyle=\frac{1}{S}\frac{-1}{\log\left(1-\left(\frac{1-f}{2}\right)\right)}
2S(1f).\displaystyle\leq\frac{2}{S(1-f)}. (13)

Appendix B Qudit protocols

The qudit versions work in the same way, by simply replacing states and operators by their generalised high dimensional versions. For simplicity we consider prime dimension qq (this is sufficient for allowing for all access structures BCGST02). Paulis and the computational basis are replaced by their qudit extensions, XX, ZZ, X|i=|i1X|i\rangle=|i\oplus 1\rangle (where now \oplus denotes sum modulo qq) and Z|i=ωi|iZ|i\rangle=\omega^{i}|i\rangle, ω=ei2π/q\omega=e^{i2\pi/q} (analogously for all the possible sets of logical operators and basis states), and the EPR state by its qudit version

|ΦdP=1qi=0q1|id|iLP.|\Phi\rangle_{dP}=\frac{1}{\sqrt{q}}\sum_{i=0}^{q-1}|i\rangle_{d}|i_{L}\rangle_{P}. (14)

We similarly define the projection operator on dd and subset of players BPB\subset P,

ΠdB=tFq2Zdt1Xdt2ZL,Bt1XL,Bt2,\Pi_{dB}=\sum_{t\in F_{q}^{2}}Z_{d}^{t^{1}}X_{d}^{t^{2}}\otimes Z_{L,B}^{t^{1}}X_{L,B}^{t^{2}}, (15)

where t={t1,t2}t=\{t^{1},t^{2}\}, tiFqt^{i}\in F_{q}. This again defines a space of maximally entangled states between the dealer and players BB.

For simplicity we present a qudit protocol which includes all the measurements in this projection. This is not necessary for our results, indeed for the qubit case we had fewer and similar results follow using fewer measurements as in the qubit version - it is mostly a matter of taste if one chooses the full set or fewer (similar to the situation for qudit versions of QKD Sheridan10). We adopt it here for its simpler presentation. It allows for analagous statement of Theorems 1, 2 following the same logic as for the qubit version.

Interactive Protocol (qudit)

  1. 1.

    Dealer dd generates SS qudit EPR states, |ΦdPS|\Phi\rangle_{dP}^{\otimes S}, and sends the shares of each one to PP.

  2. 2.

    After PP received all their parts, dd chooses r[1,S]r\in[1,...S] at random and sends rr to PP.

  3. 3.

    For qudit EPR pairs iri\neq r, dd chooses tiFq2t_{i}\in F_{q}^{2}, and measures Zdti1Xdti2Z_{d}^{t^{1}_{i}}X_{d}^{t^{2}_{i}} , and denotes the result yiy_{i}, and sends tit_{i} and yiy_{i} to PP.

  4. 4.

    For qudit EPR pairs iri\neq r, accessing set BB measure ZL,Bti1XL,Bti2Z_{L,B}^{t^{1}_{i}}X_{L,B}^{t^{2}_{i}} . Denoting result by yiy_{i}^{\prime} if yi=yiy_{i}=y_{i}^{\prime} ACCEPT, if yiyiy_{i}\neq y_{i}^{\prime} REJECT.

  5. 5.

    For i=ri=r, dd uses qudit EPR pair rr to teleport the secret state onto the logical basis, denoting the qudit bell basis measurements xx, and sends xx to all PP. Upon receiving xx, BB decodes.

Theorem 5.

Any state ρdB\rho_{dB} with fidelity F=Tr(ΠdBρdB)F=Tr(\Pi_{dB}\rho_{dB}) to projector ΠdB\Pi_{dB} accepts at step 4 of the qudit interactive protocol with probability Pr=1+F2\displaystyle Pr=\frac{1+F}{2} .

Theorem 6.

The interactive qudit protocol defined above is ϵ\epsilon-secure, with ϵ=1/S\epsilon=1/S.

The non-interactive version follows similarly, as does the Theorem. The state |Ψt,yP|\Psi^{t,y}\rangle_{P} denotes the eigenstate of the operator ZLti1XLti2Z_{L}^{t^{1}_{i}}X_{L}^{t^{2}_{i}} with eigenvalue ωy\omega^{y}.

Non-interactive Protocol (qudit)

  1. 1.

    dd and PP share random strings r,t,y,xr,t,y,x via a classical secret sharing scheme over P (i.e. dd knows the string, but it is shared via a classical secret sharing scheme with the relevant access structure over PP so that only authorised sets can access it, and only when they collaborate to do so, and unauthorised sets get no information at all).

  2. 2.

    Going through round by round i=1Si=1...S. If qi=0q_{i}=0 the dealer proceeds to step 3, if qi=1q_{i}=1 the dealer proceeds to step 4.

  3. 3.

    For qi=0q_{i}=0

    1. (a)

      Dealer prepares and distributes state |Ψt,yP|\Psi^{t,y}\rangle_{P}.

    2. (b)

      After receiving the state from the dealer, authorised set BB collaborate to find qiq_{i} (which is 00), tit_{i} and yiy_{i}.

    3. (c)

      Authorised set BB measures ZL,Bti1XL,Bti2Z_{L,B}^{t^{1}_{i}}X_{L,B}^{t^{2}_{i}} . The result is denoted yiy_{i}^{\prime}.
      If yiyiy_{i}\neq y_{i}^{\prime} REJECT. If yi=yiy_{i}=y_{i}^{\prime} ACCEPT.

    4. (d)

      If i=Si=S, END, otherwise return to step 2.

  4. 4.

    For qi=1q_{i}=1

    1. (a)

      dd encodes and distrubutes the state XLx0ZLx1|ψLPX_{L}^{x_{0}}Z_{L}^{x_{1}}|\psi_{L}\rangle_{P}.

    2. (b)

      After recieving the state from the dealer, authorised set BB collaborate to find qiq_{i}, which is 11.

    3. (c)

      BB decodes.

    4. (d)

      If i=Si=S, END, otherwise return to step 2

Theorem 7.

The non-interactive qudit protocol defined above is ϵ\epsilon-secure, with ϵ=1/S\epsilon=1/S.

The aborting protocol follows similarly.