Method for spacetime-constrained oblivious transfer
View Patent ↗A method for performing spacetime-constrained oblivious transfer between various laboratories of a first party A and various laboratories of a second party B. The method includes providing the spacetime-constrained oblivious transfer to satisfy various conditions. The method further includes encoding, by the laboratories of the first party A, various messages in a quantum state selected from various non-orthogonal quantum states. The method further includes transmitting, by the laboratories of the first party A, the quantum state to a first laboratory of the second party B. The method further includes applying, by the first laboratory of the second party B, a quantum measurement on the quantum state to obtain a classical measurement outcome. The method further includes transmitting, by the first laboratory of the second party B, the classical measurement outcome to the laboratories of the second party B.
1. A method for performing spacetime-constrained oblivious transfer between a plurality of laboratories of a first party A and a plurality of laboratories of a second party B, comprising:
providing the spacetime-constrained oblivious transfer to satisfy a first condition by a first spacetime region R j and a second spacetime region R k that there does not exist any causal curve in spacetime that connects any spacetime point of the first spacetime region R j to any spacetime point of the second spacetime region R k ;
encoding, by the plurality of laboratories of the first party A, a first plurality of messages r i in a quantum state selected from a plurality of non-orthogonal quantum states;
transmitting, by the plurality of laboratories of the first party A, the quantum state to a first laboratory L B of the second party B;
applying, by the first laboratory L B of the second party B, a quantum measurement on the quantum state to obtain a classical measurement outcome;
transmitting, by the first laboratory L B of the second party B, the classical measurement outcome to a plurality of laboratories of the second party B,
wherein communication among different laboratories of the second party B is only classical, and
wherein communication over distant laboratories of the plurality of laboratories of the first party A and the plurality of laboratories of the second party B is only classical; and
providing the spacetime-constrained oblivious transfer to satisfy a second condition selected from a group consisting of:
(2.1) a plurality of laboratories of the second party B receive, in the causal past of at least one spacetime point of the first spacetime region R j , a second plurality of messages comprising information about the quantum state from a plurality of laboratories of the first party A, and the classical measurement outcome obtained by the first laboratory L B of the second party B;
a plurality of laboratories of the second party B use the classical measurement outcome received from the first laboratory L B of the second party B and the messages received from the plurality of laboratories of the first party A to decode, in a plurality of spacetime regions comprising the first spacetime region R j , a first message from the first plurality of messages r i encoded by the plurality of laboratories of the first party A; and
no laboratory among the plurality of laboratories of the second party B can decode, in the second spacetime region R k , a second message from the first plurality of messages r i encoded by the plurality of laboratories of the first party A; and
(2.2) no laboratory among the plurality of laboratories of the second party B receive, in the causal past of any spacetime point of the first spacetime region R j , any message comprising information about the quantum state from the plurality of laboratories of the first party A; and
no laboratory among the plurality of laboratories of the second party B can decode, in the first spacetime region R j , any message from the first plurality of messages r i encoded by the plurality of laboratories of the first party A.
2. The method of claim 1 , wherein communication among the distant laboratories is implemented via internet channels.
3. The method of claim 1 , wherein the plurality of laboratories of the first party A cannot determine which message from the first plurality of messages r i is obtained by the plurality of laboratories of the second party B, and wherein this condition may be provided with unconditional security.
4. The method of claim 1 , wherein the condition (2.1) is satisfied with unconditional security.
5. The method of claim 1 , wherein,
for some integer m≥2, the first plurality of messages r i encoded in the quantum state by the plurality of laboratories of the first party A are m messages r 0 , r 1 , . . . , r m-1 ;
the transmitted quantum state belong to a set of non-orthogonal quantum states
{
❘
"\[LeftBracketingBar]"
Ψ
r
s
〉
❘
"\[RightBracketingBar]"
r
∈
Ω
o
u
t
c
ome
,
s
∈
Ω
b
a
s
i
s
}
labelled by classical messages r∈Ω outcome and s∈Ω basis , wherein r∈Ω outcome are strings of m messages given by r=(r 0 , r 1 , . . . , r m-1 ), and wherein Ω outcome is the set of possible values of r and Ω basis is the set of possible values of s;
the applied quantum measurement is a measurement M c that belongs to a set of measurements {M i } i∈I m , wherein c∈I m ≡{0, 1, . . . , m−1};
the set of quantum states
{
❘
"\[LeftBracketingBar]"
Ψ
r
s
〉
❘
"\[RightBracketingBar]"
r
∈
Ω
o
u
t
c
ome
,
s
∈
Ω
b
a
s
i
s
}
,
the probability distributions for r∈Ω outcome and for s∈Ω basis , and the set of measurements {M i } i∈I m satisfy the following properties:
by applying the quantum measurement M c on the quantum state |Ψ r s , and knowing the measurement outcome, knowing the measurement M c that is implemented, and knowing the message s, it is possible to decode the message r c , or a message r′ c that is very close to r c according to a predetermined threshold, with a probability equal to unity, or close to unity, for r∈Ω outcome , s∈Ω basis and c∈I m ;
for any pair of different numbers i, j from the set I m , for any quantum operation O independent of s and independent of r acting on the quantum state |Ψ r s that produces at least two quantum systems B 0 and B 1 , and for any sets of quantum measurements
{
M
~
0
s
}
s
∈
Ω
basis
and
{
M
~
0
s
}
s
∈
Ω
basis
,
the probability to obtain respective outcomes r′ i and r′ j that are respectively close to r′ i and r′ j according to a predetermined threshold, by respectively applying {tilde over (M)} 0 s on B 0 and {tilde over (M)} 1 s on B 1 , is smaller than unity, which may be negligible, and which may decrease exponentially with some security parameter, which may comprise the number n of bits of the messages r i if the messages r i are strings of bits, for i∈I m .
6. The method of claim 1 , wherein the first plurality of messages r i encoded by the plurality of laboratories of the first party A in the quantum state that is transmitted to the first laboratory L B of the second party B, and the second plurality of messages transmitted by the plurality of laboratories of the first party A to the plurality of laboratories of the second party B, are used by the plurality of laboratories of the first party A to encode a third plurality of messages x a .
7. The method of claim 1 , wherein the first and second spacetime regions R j and R k are different elements from a set of M different spacetime regions R 0 , R 1 , . . . , R M-1 specified by the plurality of laboratories of parties A and B, for some integer M≥2, satisfying the property that there does not exist any causal curve in spacetime that connects any spacetime point of R a to any spacetime point of R a′ , for any pair of different numbers a and a′ from the set I M ≡{0, 1, . . . , M−1}.
8. The method of claim 1 , wherein,
for some integer m≥2, the first plurality of messages r i encoded in the quantum state by the plurality of laboratories of the first party A are m messages r 0 , r 1 , . . . , r m-1 ;
the transmitted quantum state belong to a set of non-orthogonal quantum states
{
❘
"\[LeftBracketingBar]"
Ψ
r
s
〉
❘
"\[RightBracketingBar]"
r
∈
Ω
o
u
t
c
ome
,
s
∈
Ω
b
a
s
i
s
}
labelled by classical messages r∈Ω outcome and s∈Ω basis , wherein r∈Ω outcome are strings of m messages given by r=(r 0 , r 1 , . . . , r m-1 ), and wherein Ω outcome is the set of possible values of r and Ω basis is the set of possible values of s;
the applied quantum measurement is a measurement M c that belongs to a set of measurements {M i } i∈I m , wherein c∈I m ≡{0, 1, . . . , m−1};
the condition (2.1) further comprises the condition:
(2.1.1) a laboratory L j A of the first party A transmits the value of s within a third spacetime region Q j , wherein the third spacetime region Q j satisfies a first property that it lies within the causal past of at least one spacetime point of the first spacetime region R j , and a second property that it is not in the causal past of any spacetime point of the second spacetime region R k ;
a laboratory L j B of the second party B receives, within the causal past of at least one spacetime point of the first spacetime region R j , the value of s from the laboratory L j A of the first party A and the classical measurement outcome obtained by the first laboratory L B of the second party B;
the laboratory L j B of the second party B knows, in the causal past of at least one spacetime point of the first spacetime region R j , the label c of the quantum measurement M c implemented by the first laboratory L B of the second party B;
the laboratory L j B of the second party B uses the classical measurement outcome, the value of s, and the label c of the implemented measurement M c , to decode a message r′ c that is equal to the message r c , or close to r c according to a predetermined threshold, with a probability that is equal to unity, or close to unity, in the first spacetime region R j , or in the causal past of at least one spacetime point of the first spacetime region R j ;
no laboratory among the plurality of laboratories of the second party B can decode, in the second spacetime region R k , a message r′ i that is equal to the message r i , or close to r i according to a predetermined threshold, with a probability that is equal to unity, or close to unity, for any i∈I m with i≠c; and
the condition (2.2) further comprises the condition:
(2.2.1) no laboratory among the plurality of laboratories of the second party B receives, in the causal past of any spacetime point of the first spacetime region R j , any message including information about the value of s from a plurality of laboratories of the first party A; and
no laboratory among the plurality of laboratories of the second party B can decode, in the first spacetime region R j , any message from the first plurality of messages r 0 , r 1 , . . . , r m-1 encoded by the plurality of laboratories of the first party A.
9. The method of claim 1 , wherein,
for an integer m≥2, the first plurality of messages r i encoded in the quantum state by the plurality of laboratories of the first party A are m messages r 0 , r 1 , . . . , r m-1 ;
the transmitted quantum state belong to a set of non-orthogonal quantum states
{
❘
"\[LeftBracketingBar]"
Ψ
r
s
〉
❘
"\[RightBracketingBar]"
r
∈
Ω
o
u
t
c
ome
,
s
∈
Ω
b
a
s
i
s
}
labelled by classical messages r∈Ω outcome and s∈Ω basis , wherein r∈Ω outcome are strings of m messages given by r=(r 0 , r 1 , . . . , r m-1 ), and wherein Ω outcome is the set of possible values of r and Ω basis is the set of possible values of s;
the set of quantum states
{
❘
"\[LeftBracketingBar]"
Ψ
r
s
〉
❘
"\[RightBracketingBar]"
r
∈
Ω
o
u
t
c
ome
,
s
∈
Ω
b
a
s
i
s
}
and the probability distributions for r∈Ω outcome and s∈Ω basis satisfy a plurality of conditions selected from a group consisting of:
the quantum states |Ψ r s cannot be effectively cloned without knowing s,
the quantum states |Ψ r s and |Ψ r s′ are not orthogonal for any pair of different messages s and s′ from the set Ω basis , and for a plurality of messages r∈Ω outcome ,
the message r is generated from the set Ω outcome with a probability distribution that is random, or very close to be random, and
the value of s is generated from the set Ω basis with a probability distribution that is random, or very close to be random.
10. The method of claim 1 , wherein the spacetime-constrained oblivious transfer satisfies a plurality of conditions selected from a group consisting of:
the plurality of laboratories of the first party A and the plurality of laboratories of the second party B are secure,
messages communicated among the plurality of laboratories of the second party B are communicated through communication channels that comprise a plurality of classical communication channels, which may be secure and authenticated, and
messages communicated among the plurality of laboratories of the first party A are communicated through communication channels comprising a plurality of classical communication channels, which may be secure and authenticated.
11. The method of claim 1 , wherein a plurality of laboratories of the first party A and a plurality of laboratories of the second party B align spacetime reference frames.
12. The method of claim 1 , wherein if in the transmission of the quantum state from the plurality of laboratories of the first party A to the first laboratory L B of the second party B, signals are sent from a plurality of laboratories of the second party B to a plurality of laboratories of the second party A then the signals do not leak more than a predetermined amount of information about the quantum measurement that is implemented on the transmitted quantum state.
13. The method of claim 1 , wherein the spacetime-constrained oblivious transfer satisfies a plurality of conditions selected from a group consisting of:
the transmitted quantum state is the tensor product of qubit states;
the transmitted quantum state is the tensor product of qubit states that are selected from the set of BB84 states;
the transmitted quantum state is encoded in a plurality of photons;
the transmitted quantum state is encoded in polarization degrees of freedom of photons;
the transmission of the quantum state to the first laboratory L B of the second party B includes a step comprising the exchange of weak coherent states with small average photon number between a plurality of laboratories of the first party A and the first laboratory L B of the second party B; and
the transmission of the quantum state to the first laboratory L B of the second party B includes a step comprising the communication of classical messages from the first laboratory L B of the second party B to a plurality of laboratories of the first party A indicating a quantum system to which the quantum state is transmitted.
14. The method of claim 1 , wherein the first plurality of messages encoded by the plurality of laboratories of the first party A in the quantum state that is transmitted to the first laboratory L B of the second party B, and the second plurality of messages transmitted by the plurality of laboratories of the first party A to the plurality of laboratories of the second party B, are used by the plurality of laboratories of the first party A to encode information about the trajectory of a plurality of moving objects.
15. The method of claim 9 , wherein
for some integer m≥2, the plurality of messages r i encoded in the quantum state by the plurality of laboratories of the first party A are m messages r 0 , r 1 , . . . , r m-1 ;
the transmitted quantum state belong to a set of non-orthogonal quantum states
{
❘
"\[LeftBracketingBar]"
Ψ
r
s
〉
❘
"\[RightBracketingBar]"
r
∈
Ω
o
u
t
c
ome
,
s
∈
Ω
b
a
s
i
s
}
labelled by classical messages r∈Ω outcome and s∈Ω basis , wherein r∈Ω outcome are strings of m messages given by r=(r 0 , r 1 , . . . , r m-1 ), and wherein Ω outcome is the set of possible values of r and Ω basis is the set of possible values of s;
for i∈I m ={0, 1, . . . , m−1}, the messages r i are of the form r i =(r i 1 , r i 2 , . . . , r i n )∈Ω n , i.e. with r i j ∈Ω, for j∈[n], wherein Ω is a set of l≥2 different elements, and wherein [n]={1, 2, . . . , n};
the messages s∈Ω basis are of the form s=(s 1 , s 2 , . . . , s n )∈Λ n , i.e. with s i ∈Λ, wherein s j =(s 0 j , s 1 j , . . . , s m-1 j ), for j∈[n], wherein Λ={(a 0 , a 1 , . . . , a m-1 )|a i ∈I m and a i ≠a i , if i≠i′, for i, i′∈I m }, i.e. the set Λ is in one-to-one correspondence with the set of permutations of m distinct elements;
the quantum state |Ψ r s is transmitted to a quantum system with Hilbert space A at the first laboratory L B of the second party B, wherein the Hilbert space A is of the form
A
=
⊗
i
∈
I
m
,
j
∈
[
n
]
A
i
j
,
with the dimension of the Hilbert space A i j being equal to 1, for all i∈I m and for all j∈[n];
the transmitted quantum state is of the form
❘
Ψ
r
s
〉
A
=
⊗
i
∈
I
m
,
j
∈
[
n
]
❘
α
r
i
j
i
〉
A
s
i
j
j
,
with the set of quantum states i ={|α r i } r∈Ω being an orthonormal basis of an l-dimensional Hilbert space, for i∈I m ; and
it holds that λ<1, wherein
λ
=
max
i
≠
i
′
❘
"\[LeftBracketingBar]"
〈
α
r
i
❘
a
r
′
i
′
〉
❘
"\[RightBracketingBar]"
2
,
and wherein the maximum is taken over all r, r′∈Ω and over all i, i′∈I m with i≠i′.