Non-interactive XOR quantum oblivious transfer: optimal protocols and their experimental implementations
arXiv:2209.11300 · doi:10.1103/PRXQuantum.4.020320
Abstract
Oblivious transfer (OT) is an important cryptographic primitive. Any multi-party computation can be realised with OT as building block. XOR oblivious transfer (XOT) is a variant where the sender Alice has two bits, and a receiver Bob obtains either the first bit, the second bit, or their XOR. Bob should not learn anything more than this, and Alice should not learn what Bob has learnt. Perfect quantum OT with information-theoretic security is known to be impossible. We determine the smallest possible cheating probabilities for unrestricted dishonest parties in non-interactive quantum XOT protocols using symmetric pure states, and present an optimal protocol, which outperforms classical protocols. We also "reverse" this protocol, so that Bob becomes sender of a quantum state and Alice the receiver who measures it, while still implementing oblivious transfer from Alice to Bob. Cheating probabilities for both parties stay the same as for the unreversed protocol. We optically implemented both the unreversed and the reversed protocols, and cheating strategies, noting that the reversed protocol is easier to implement.
23 pages, 6 figures; v2: added Subsection IV.A and other minor additions
References in corpus (2)
Cited by in corpus (6)
- Quantum cryptography beyond key distribution: theory and experiment
- Error-tolerant oblivious transfer in the noisy-storage model
- Efficient source-independent quantum conference key agreement
- Quantum Rabin oblivious transfer using two pure states
- Quantum Universally Composable Oblivious Linear Evaluation
- Incomplete quantum oblivious transfer with perfect one-sided security