<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article  PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article"><front><journal-meta><journal-id journal-id-type="publisher-id">JQIS</journal-id><journal-title-group><journal-title>Journal of Quantum Information Science</journal-title></journal-title-group><issn pub-type="epub">2162-5751</issn><publisher><publisher-name>Scientific Research Publishing</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.4236/jqis.2022.123006</article-id><article-id pub-id-type="publisher-id">JQIS-119508</article-id><article-categories><subj-group subj-group-type="heading"><subject>Articles</subject></subj-group><subj-group subj-group-type="Discipline-v2"><subject>Physics&amp;Mathematics</subject></subj-group></article-categories><title-group><article-title>
 
 
  A Quantum Mechanical Proof of Insecurity of the Theoretical QKD Protocols
 
</article-title></title-group><contrib-group><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Jianzhong</surname><given-names>Zhao</given-names></name><xref ref-type="aff" rid="aff1"><sub>1</sub></xref></contrib></contrib-group><aff id="aff1"><label>1</label><addr-line>Geophysics Department, Yunnan University, Kunming, China</addr-line></aff><pub-date pub-type="epub"><day>28</day><month>07</month><year>2022</year></pub-date><volume>12</volume><issue>03</issue><fpage>53</fpage><lpage>63</lpage><history><date date-type="received"><day>30,</day>	<month>June</month>	<year>2022</year></date><date date-type="rev-recd"><day>27,</day>	<month>August</month>	<year>2022</year>	</date><date date-type="accepted"><day>30,</day>	<month>August</month>	<year>2022</year></date></history><permissions><copyright-statement>&#169; Copyright  2014 by authors and Scientific Research Publishing Inc. </copyright-statement><copyright-year>2014</copyright-year><license><license-p>This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/</license-p></license></permissions><abstract><p>
 
 
  Cryptography is crucial to communication security. In 1984, a well-known QKD (quantum key distribution) protocol, BB84, was published by Bennett and Brassard. The BB84 Protocol was followed by the QKD protocols published by Ekert (1991) (E91) and Bennett (1992) (B92). Some authors proved security of the theoretical QKD protocols in different theoretical frameworks by defining security of QKD protocols differently. My argument is that the previous proofs of security are neither unique nor exhaustive for each theoretical QKD protocol, which means that proof of security of the theoretical QKD protocols has not been completed or achieved. The non-uniqueness and the non-exhaustiveness of the proofs will lead to more proofs. However, a coming “proof” of security of the theoretical QKD protocols is possible to be a disproof. The research by quantum mechanics in this paper disproves security of the theoretical QKD protocols, by establishing the theoretical framework of quantum mechanical proof, defining security of QKD protocols, establishing the quantum state of the final key of the theoretical protocols from their information leakages, and applying Grover’s fast quantum mechanical algorithm for database search to the quantum state of the final key to result in the Insecurity Theorem. This result is opposite to those of the previous proofs where the theoretical QKD protocols were secure. It is impossible for Alice and Bob to protect their communications from information leakage by stopping or canceling the protocols. The theoretical QKD keys are conventional and basically insecure. Disproof of security of the theoretical QKD protocols is logical.
 
</p></abstract><kwd-group><kwd>Quantum Mechanics</kwd><kwd> Quantum Cryptography</kwd><kwd> Quantum Computation</kwd><kwd> Security</kwd><kwd> Proof</kwd></kwd-group></article-meta></front><body><sec id="s1"><title>1. Introduction</title><p>Cryptography is crucial to communication security. In 1984, a well-known QKD (quantum key distribution) protocol, BB84, was published by Bennett and Brassard [<xref ref-type="bibr" rid="scirp.119508-ref1">1</xref>]. The BB84 Protocol was followed by the QKD protocols published by Ekert in 1991 (E91) and Bennett in 1992 (B92) [<xref ref-type="bibr" rid="scirp.119508-ref2">2</xref>] [<xref ref-type="bibr" rid="scirp.119508-ref3">3</xref>].</p><p>Some authors (E. Biham, M. Boyer, P.O. Boykin, T. Mor and V. Roychowdhury; P. W. Shor and J. Preskill; D. Mayers; D. Gottesman and H.-K. Lo; H.-K. Lo, H. F. Chau and M. Ardehali; R. Renner, N. Gisin and B. Kraus; M. Boyer, R. Liss and T. Mor; H.-Y. Su) proved security of BB84 [<xref ref-type="bibr" rid="scirp.119508-ref4">4</xref>] - [<xref ref-type="bibr" rid="scirp.119508-ref13">13</xref>], others (Q. Zhang and C.-j. Tang; K. Tamaki, M. Koashi and N. Imoto; K. Tamaki and N. L&#252;tkenhaus; K.Tamaki, N. L&#252;tkenhaus, M. Koashi and J. Batuwantudawe; M. Lucamarini, G. D. Giuseppe and K. Tamaki) proved security of B92 [<xref ref-type="bibr" rid="scirp.119508-ref14">14</xref>] - [<xref ref-type="bibr" rid="scirp.119508-ref19">19</xref>], in different theoretical frameworks by defining security of QKD protocols differently.</p><p>My argument is that the authors understand security of QKD with different perspectives, and the previous proofs of security are neither unique nor exhaustive for each theoretical QKD protocol, which means that proof of security of the theoretical QKD protocols has not been completed or achieved. On the other hand, it is possible, from the non-uniqueness and non-exhaustiveness of proofs of security of QKD, that the theoretical QKD protocols will be proved insecure in an updated theoretical framework with an updated definition of security. For insecurity, one proof is enough.</p><p>Quantum mechanics is applied to variant research fields. For example, Stanisław Olszewski examines the time intervals characteristic for the quantum emission process, partly on the basis of the Ehrenfest treatment of the adiabatic invariants and partly with the aid of a study of the mechanical properties of electrons entering the simple quantum systems [<xref ref-type="bibr" rid="scirp.119508-ref20">20</xref>]. Shiro Ishikawa proposes the understanding of Wittgenstein’s picture theory in the framework of quantum language (or, “measurement theory”, “the linguistic Copenhagen interpretation of quantum mechanics”, “the quantum mechanical worldview”) [<xref ref-type="bibr" rid="scirp.119508-ref21">21</xref>].</p><p>Quantum computation holds much promise to break cryptosystems. In 1994, Shor published an algorithm for quantum computation of factoring [<xref ref-type="bibr" rid="scirp.119508-ref22">22</xref>], which can be used for breaking keys of conventional RSA public-key cryptosystems efficiently [<xref ref-type="bibr" rid="scirp.119508-ref22">22</xref>] [<xref ref-type="bibr" rid="scirp.119508-ref23">23</xref>] [<xref ref-type="bibr" rid="scirp.119508-ref24">24</xref>] [<xref ref-type="bibr" rid="scirp.119508-ref25">25</xref>]. In 1996, Grover published a fast quantum mechanical algorithm for database search [<xref ref-type="bibr" rid="scirp.119508-ref26">26</xref>], which can be used for efficient breaking of keys of conventional encryption systems such as Data Encryption Standard (DES) cipher [<xref ref-type="bibr" rid="scirp.119508-ref24">24</xref>] - [<xref ref-type="bibr" rid="scirp.119508-ref30">30</xref>]. The success of quantum computation forces us to ask: Are quantum key distribution protocols secure, encountering powerful quantum computation?</p><p>In this research Grover’s fast quantum mechanical algorithm for database search is applied to disprove security of the theoretical quantum key distribution protocols [<xref ref-type="bibr" rid="scirp.119508-ref26">26</xref>] [<xref ref-type="bibr" rid="scirp.119508-ref27">27</xref>]. The security of QKD protocols is defined in the theoretical framework of quantum mechanical proof established in this paper. The quantum state of the final key of the theoretical QKD protocols, which is based on the information leakages to Eve, the adversary, is established. Grover’s fast quantum mechanical algorithm for database search is applied to the quantum state of the final key to result in the Insecurity Theorem [<xref ref-type="bibr" rid="scirp.119508-ref26">26</xref>] [<xref ref-type="bibr" rid="scirp.119508-ref27">27</xref>].</p><p>From the previous proofs the theoretical QKD protocols, free of quantum computation attack, are secure, while my research concludes, from quantum mechanics, that the theoretical QKD protocols are insecure.</p><p>BB84, E91 and B92 are the theoretical and fundamental QKD protocols. Their insecurity implies that all QKD protocols developed following their model are insecure, and the strategy or direction of the quantum cryptography based on QKD should be adjusted.</p><p>Discussions are given.</p></sec><sec id="s2"><title>2. The Theoretical Framework of Quantum Mechanical Proof</title><p>The theoretical framework of quantum mechanical proof in this paper consists of the theoretical QKD protocols, Grover’s fast quantum mechanical algorithm for database search and the rules of mathematical inference in quantum mechanics.</p><p>The variables in the framework are listed as:</p><p>k<sub>i</sub>: the bit string of the i-th component of the quantum state of the final key;</p><p>p<sub>j</sub>: the bit string of the j-th component of the quantum state of the plain-text;</p><p>k<sub>s</sub>: the bit string of the key, whose value is set by Alice;</p><p>p<sub>t</sub>: the bit string of the plain-text, whose value is set by Alice;</p><p>C: the bit string of the cypher-text produced by Alice’s encryption. <sub> </sub></p></sec><sec id="s3"><title>3. The Definition of Security of QKD Protocols</title><p>A QKD (quantum key distribution) protocol is secure if and only if its final key cannot be deduced from the information leakage of the protocol.</p></sec><sec id="s4"><title>4. Insecurity Theorem of the Theoretical QKD Protocols</title><p>The theoretical QKD protocols, BB84, E91 and B92, are insecure in the theoretical framework of quantum mechanical proof in this paper.</p></sec><sec id="s5"><title>5. Proof of Insecurity Theorem of the Theoretical QKD Protocols</title><sec id="s5_1"><title>5.1. Leakage of the Key-Length of BB84</title><p>After the “public discussion” of BB84 Protocol, the “remaining shared secret bits”, announced or leaked over the public channel, are used as the final key [<xref ref-type="bibr" rid="scirp.119508-ref1">1</xref>]. Thus, Eve, the adversary, overhears the “public exchange of messages” between Alice and Bob, and counts the “remaining shared secret bits” for n, the number of the bits of the final key.</p></sec><sec id="s5_2"><title>5.2. Leakage of the Key-Length of E91</title><p>Eve, the adversary, overhears the legitimate users’ public announcements, neither disturbing the quantum channel nor violating the requirement of quantum mechanics, to know n, the number of the bits of the final key, by counting the measurements or the orientations of the analyzers within the second group, which Alice and Bob used the same orientation of their analyzers for and publicly announced or leaked [<xref ref-type="bibr" rid="scirp.119508-ref2">2</xref>].</p></sec><sec id="s5_3"><title>5.3. Leakage of the Key-Length of B92</title><p>1) Detecting the key-length of EPR and non-EPR key distribution system by Eve:</p><p>For “EPR and non-EPR key distribution” system [<xref ref-type="bibr" rid="scirp.119508-ref3">3</xref>], Eve repeats for k times to eavesdrop on Alice and Bob’s public test in Step 9 and Step 10 of the system [<xref ref-type="bibr" rid="scirp.119508-ref3">3</xref>], and detects the key-length by counting the bits of the final secret key after the k repeated tests, without disturbing the quantum channel.</p><p>2) A scheme of “interferometric quantum key distribution using two non-or-thogonal low-intensity coherent states” is proposed [<xref ref-type="bibr" rid="scirp.119508-ref3">3</xref>]. According to the scheme, “Alice would randomly send red and green flashes of &lt; 1 photon intensity, and Bob would publicly report which flashes he saw, but not their colors, which would constitute the secret key.” [<xref ref-type="bibr" rid="scirp.119508-ref3">3</xref>]</p><p>My argument is that it is unnecessary for Eve to “see” the same subset of flashes. She can seize the knowledge of the key-length by eavesdropping on Bob’s public report and counting the subset flashes seen by Bob.</p></sec><sec id="s5_4"><title>5.4. Quantum State of the Final Key</title><p>The leakage of the lengths of the final keys of BB84, E91 and B92 discussed in Sections 5.1 - 5.3 results in the establishment, in terms of quantum mechanics, of | K 〉 , superposition of N (N = 2<sup>n</sup>) states of | k i 〉 (of n bits), as the quantum state of the final key.</p><p>| K 〉 = 1 2 ( | 0 〉 + | 1 〉 ) ⊗ 1 2 ( | 0 〉 + | 1 〉 ) ⊗ ⋅ ⋅ ⋅ ⊗ 1 2 ( | 0 〉 + | 1 〉 ) = 1 2 n ( | 00 ⋅ ⋅ ⋅ 0 〉 + | 00 ⋅ ⋅ ⋅ 1 〉 + ⋅ ⋅ ⋅ + | 11 ⋅ ⋅ ⋅ 1 〉 ) = 1 N ∑ i = 0 N − 1 | k i 〉 (1)</p><p>where n is the number of the bits of the final key of any one of BB84, E91 and B92. Equation (1) and the analysis below in Section 5 are valid for any one of BB84, E91 and B92 protocols.</p></sec><sec id="s5_5"><title>5.5. OTP Encryption Algorithm</title><p>Bennett and Brassard declare that “If the transmission has not been disturbed, they agree to use these shared secret bits in the well-known way as a one-time pad to conceal the meaning of subsequent meaningful communications, or for other cryptographic applications (e.g. authentication tags) requiring shared secret random information.” [<xref ref-type="bibr" rid="scirp.119508-ref1">1</xref>]. This declaration defines and publishes the encryption algorithm of QKD protocols: one-time pad encryption algorithm (OTP) [<xref ref-type="bibr" rid="scirp.119508-ref31">31</xref>].</p></sec><sec id="s5_6"><title>5.6. Quantum State of the Plain-Text</title><p>The length (the number of the bits) of the plain-text is n, equal to the length of the key, because the encryption algorithm of QKD is OTP encryption algorithm [<xref ref-type="bibr" rid="scirp.119508-ref31">31</xref>]. Therefore, the quantum state of the plain-text is</p><p>| P 〉 = 1 2 ( | 0 〉 + | 1 〉 ) ⊗ 1 2 ( | 0 〉 + | 1 〉 ) ⊗ ⋅ ⋅ ⋅ ⊗ 1 2 ( | 0 〉 + | 1 〉 ) = 1 2 n ( | 00 ⋅ ⋅ ⋅ 0 〉 + | 00 ⋅ ⋅ ⋅ 1 〉 + ⋅ ⋅ ⋅ + | 11 ⋅ ⋅ ⋅ 1 〉 ) = 1 N ∑ j = 0 N − 1 | p j 〉 (2)</p></sec><sec id="s5_7"><title>5.7. Encryption</title><p>After the protocol is implemented, Alice encrypts her plain-text by the operation</p><p>E ( k s , p t ) = C         ( 0 ≤ s ≤ N − 1 , 0 ≤ t ≤ N − 1 ) (3)</p><p>where E is the OTP (one-time pad) encryption algorithm, k<sub>s</sub> is the bit string of | k s 〉 , the key, p<sub>t</sub> is the bit string of | p t 〉 , the plain-text, C is the cipher-text. Then she sends the cipher-text and the encryption algorithm (for Bob’s decryption) to Bob during the communication between them.</p></sec><sec id="s5_8"><title>5.8. Decryption</title><p>Bob receives the cypher-text and the encryption algorithm sent by Alice to him, and establishes his decryption equation</p><p>E ( k s , p j ) = C         ( 0 ≤ s ≤ N − 1 , 0 ≤ j ≤ N − 1 ) , (4)</p><p>where E is the OTP (one-time pad) encryption algorithm, k<sub>s</sub> is the bit string of | k s 〉 , the key, p<sub>j</sub> is the bit string of | p j 〉 , C is the cipher-text.</p><p>Bob’s decryption is to solve the decryption equation, Equation (4), to find the plain-text | p t 〉 .</p><p>It is obvious that there exists at least one solution of Equation (4) because of Alice’s encrypting (Equation (3)). It is obvious that solution of Equation (4) is required to be unique for successful communication between Alice and Bob.</p><p>Solving Equation (4) is to search | P 〉 (expressed by Equation (2)) for the | p j 〉 whose bit string, p<sub>j</sub>, satisfies Equation (4). Bob prefers using Grover’s fast quantum mechanical algorithm for database search because Grover’s quantum searching algorithm is optimal [<xref ref-type="bibr" rid="scirp.119508-ref32">32</xref>]. Bob’s decryption, which needs O ( N ) Grover’s iterations, is presented in Appendix 1 of this paper.</p></sec><sec id="s5_9"><title>5.9. Key-Equation</title><p>Eve intercepts the cipher-text and the encryption algorithm sent by Alice to Bob.</p><p>For Eve, if | k i 〉 is the key and | p j 〉 is the plain-text, they satisfy</p><p>E ( k i , p j ) = C         ( 0 ≤ i ≤ N − 1 , 0 ≤ j ≤ N − 1 ) (5)</p><p>where E is the OTP encryption algorithm, k<sub>i</sub> is the bit string of | k i 〉 , p<sub>j</sub> is the bit string of | p j 〉 , C is the cipher-text. Equation (5) is the key-equation.</p></sec><sec id="s5_10"><title>5.10. Uniqueness of Solution</title><p>It is obvious that there exists at least one couple of k<sub>i</sub> and p<sub>j</sub> that satisfies Equation (5) because of Alice’s encrypting (Equation (3)). Furthermore, multiplicity of solution of Equation (5), if any, can result in multiplicity of solution of Equation (4) because of | k s 〉 ∈ { | k i 〉 | ( 0 ≤ i ≤ N − 1 ) } . Then logically, uniqueness of solution of Equation (4) can result in uniqueness of solution of Equation (5). And so, if communication between Alice and Bob is successful, solution of the key-equation Equation (5) can be unique.</p></sec><sec id="s5_11"><title>5.11. Searching by Grover’s Fast Quantum Mechanical Algorithm</title><p>Eve searches the quantum state of the secrete key (Equation (1)) for the key by Grover’s fast quantum mechanical algorithm for database search. She succeeds as the communication between Alice and Bob is successful and solution of the key-equation is unique:</p><p>1) Defining a function f ( k i , p j ) (using the key-equation Equation (5)):</p><p>f ( k i , p j ) = { 1,           E ( k i , p j ) = C 0,             E ( k i , p j ) ≠ C (6)</p><p>2) Repeating the following operations (a) and (b) for O ( N ) times (Grover Iteration) [<xref ref-type="bibr" rid="scirp.119508-ref26">26</xref>] [<xref ref-type="bibr" rid="scirp.119508-ref27">27</xref>]:</p><p>a) Applying the oracle operation [<xref ref-type="bibr" rid="scirp.119508-ref26">26</xref>] [<xref ref-type="bibr" rid="scirp.119508-ref27">27</xref>]:</p><p>| k i 〉 → O ( − 1 ) f ( k i , p j ) | k i 〉 , (7)</p><p>where f ( k i , p j ) is the function defined by Equation (6).</p><p>b) Performing Grover operation (in terms of inversion about average operation)</p><p>D | K 〉 , (8)</p><p>where the diffusion transform D can be implemented as</p><p>D = W R W , (9)</p><p>where W is the Walsh-Hadamard Transform Matrix and R is the phase rotation matrix [<xref ref-type="bibr" rid="scirp.119508-ref26">26</xref>] [<xref ref-type="bibr" rid="scirp.119508-ref27">27</xref>].</p><p>3) Measuring the resulting state of | K 〉 results in | k s 〉 , the secrete key, with a probability of O ( 1 ) [<xref ref-type="bibr" rid="scirp.119508-ref26">26</xref>] [<xref ref-type="bibr" rid="scirp.119508-ref27">27</xref>].</p></sec><sec id="s5_12"><title>5.12. Proved Insecurity Theorem of the Theoretical QKD Protocols</title><p>From the inference of Section 5, the result of Section 5.11 and the definition of security of QKD protocols suggested in Section 3, the Insecurity Theorem of the theoretical QKD protocols suggested in Section 4 is proved.</p></sec></sec><sec id="s6"><title>6. Discussions</title><p>1) An alternative approach to establishing of the quantum state of the final key, Equation (1), and the quantum state of the plain-text, Equation (2), is open to Eve. Eve intercepts the cypher-text sent by Alice to Bob and counts its bits forn, then establishes Equation (1), wheren is the key-length, and Equation (2), where n is the number of the bits of the plain-text, because the encryption algorithm of QKD is one-time pad (OTP) encryption algorithm [<xref ref-type="bibr" rid="scirp.119508-ref1">1</xref>] [<xref ref-type="bibr" rid="scirp.119508-ref31">31</xref>] and the three bit numbers (of the key, the plain-text and the cypher-text) are identical (n). This is a shortcut approach.</p><p>2) Bob’s O ( N ) Grover’s iterations are completed within a period of time decided by him, no matter how big N ( N &lt; ∞ ) is, if and only if computing speed of quantum computation is unlimited.</p><p>Eve’s O ( N ) Grover’s iterations (of Equation (7) and Equation (8)) are completed within a period of time decided by her, no matter how big N ( N &lt; ∞ ) is, if and only if computing speed of quantum computation is unlimited.</p><p>Quantum computers perform any operations allowed by quantum mechanics. Quantum computation is, in principle, of unlimited computational power (unlimited computing speed), because no limit of computing speed is possible to be defined or proved by the fundamental principles of quantum mechanics (superposition, uncertainty and entanglement) that quantum computation is based on.</p><p>Thus, the unlimited computing speed of quantum computation guarantees that both the communication between Alice and Bob and Eve’s searching for the key are successful.</p><p>3) It is obvious that it is impossible for Alice and Bob to detect Eve’s activities because the quantum transmission between them is not disturbed by Eve’s operations of eavesdropping and quantum computation. Thus, it is impossible for Alice and Bob to protect their communications from information leakage by stopping or canceling the protocols.</p><p>4) The theoretical QKD keys are conventional ones because they are constructed by conventional bits. Therefore, the essential difficulty of the theoretical QKD protocols is that the theoretical QKD keys are basically insecure. Disproof of security of the theoretical QKD protocols is logical.</p></sec><sec id="s7"><title>7. Conclusion</title><p>This research, based on quantum mechanics and quantum computation, proves that the theoretical QKD protocols, BB84, E91 and B92, are insecure in the theoretical framework of quantum mechanical proof in this paper. This result is opposite to those of the previous proofs where BB84 and B92 QKD protocols were secure. The information leakage of the theoretical QKD protocols is unavoidable because the quantum transmission of the protocols is not disturbed by Eve’s operations. The keys of the theoretical QKD protocols are conventional ones of conventional bits and basically insecure. The Insecurity Theorem of the theoretical QKD protocols proved in this paper is a logical result. The insecurity of the theoretical and fundamental QKD protocols implies that all QKD protocols developed following their model (featured by a quantum channel, a conventional channel, a conventional key and OTP encryption) are insecure, and the strategy or direction of the quantum cryptography based on QKD should be adjusted, that will stimulate more topics to be studied in the quantum information field.</p></sec><sec id="s8"><title>Acknowledgements</title><p>I thank Jin Zhao for her suggestions for this manuscript.</p></sec><sec id="s9"><title>Conflicts of Interest</title><p>The author declares no conflicts of interest.</p></sec><sec id="s10"><title>Cite this paper</title><p>Zhao, J.Z. (2022) A Quantum Mechanical Proof of Insecurity of the Theoretical QKD Protocols. Journal of Quantum Information Science, 12, 53-63. https://doi.org/10.4236/jqis.2022.123006</p></sec><sec id="s11"><title>Appendix 1</title><p>Bob searches the quantum state of the plain-text (Equation (2)) for the plain-text by Grover’s fast quantum mechanical algorithm for database search. He succeeds as solution of the decryption equation is unique for successful communication between Alice and him:</p><p>A) Defining a function g ( k s , p j ) (using the decryption equation, Equation (4)):</p><p>g ( k s , p j ) = { 1,         E ( k s , p j ) = C 0,           E ( k s , p j ) ≠ C (10)</p><p>B) Repeating the following operations (a) and (b) for O ( N ) times (Grover Iteration) [<xref ref-type="bibr" rid="scirp.119508-ref26">26</xref>] [<xref ref-type="bibr" rid="scirp.119508-ref27">27</xref>]:</p><p>a) Applying the oracle operation [<xref ref-type="bibr" rid="scirp.119508-ref26">26</xref>] [<xref ref-type="bibr" rid="scirp.119508-ref27">27</xref>]:</p><p>| p j 〉 → O ( − 1 ) g ( k s , p j ) | p j 〉 , (11)</p><p>where g ( k s , p j ) is the function defined by Equation (10).</p><p>b) Performing Grover operation (in terms of inversion about average operation)</p><p>D | P 〉 , (12)</p><p>where the diffusion transform D can be implemented as</p><p>D = W R W , (13)</p><p>where W is the Walsh-Hadamard Transform Matrix and R is the phase rotation matrix [<xref ref-type="bibr" rid="scirp.119508-ref26">26</xref>] [<xref ref-type="bibr" rid="scirp.119508-ref27">27</xref>].</p><p>C) Measuring the resulting state of | P 〉 results in | p t 〉 , the plain-text, with a probability of O ( 1 ) [<xref ref-type="bibr" rid="scirp.119508-ref26">26</xref>] [<xref ref-type="bibr" rid="scirp.119508-ref27">27</xref>].</p></sec><sec id="s12"><title>Appendix 2: Example</title><p>Suppose the OTP encryption algorithm used by Alice is XOR [<xref ref-type="bibr" rid="scirp.119508-ref33">33</xref>], then we have the information flow in FigureA1.</p></sec></body><back><ref-list><title>References</title><ref id="scirp.119508-ref1"><label>1</label><mixed-citation publication-type="other" xlink:type="simple">Bennett, C.H. and Brassard, G. (1984) Quantum Cryptography: Public Key Distribution and Coin Tossing. Proceedings of IEEE International Conference on Computers, Systems and Signal Processing, Bangalore, 10-12 December 1984, 175-179.</mixed-citation></ref><ref id="scirp.119508-ref2"><label>2</label><mixed-citation publication-type="other" xlink:type="simple">Ekert, A.K. (1991) Quantum Cryptography Based on Bell’s Theorem. Physical Review Letters, 67, 661-663. https://doi.org/10.1103/PhysRevLett.67.661</mixed-citation></ref><ref id="scirp.119508-ref3"><label>3</label><mixed-citation publication-type="other" xlink:type="simple">Bennett, C.H. (1992) Quantum Cryptography Using Any Two Nonorthogonal States. Physical Review Letters, 68, 3121-3124.  
https://doi.org/10.1103/PhysRevLett.68.3121</mixed-citation></ref><ref id="scirp.119508-ref4"><label>4</label><mixed-citation publication-type="other" xlink:type="simple">Biham, E., Boyer, M., Boykin, P.O., Mor, T. and Roychowdhury, V. (2000) A Proof of the Security of Quantum Key Distribution. Proceedings of the Thirty-Second Annual ACM Symposium on Theory of Computing, Portland, 21-23 May 2000, 715-724. https://doi.org/10.1145/335305.335406</mixed-citation></ref><ref id="scirp.119508-ref5"><label>5</label><mixed-citation publication-type="other" xlink:type="simple">Shor, P.W. and Preskill, J. (2000) Simple Proof of Security of the BB84 Quantum Key Distribution Protocol. Physical Review Letters, 85, 441-444.  
https://doi.org/10.1103/PhysRevLett.85.441</mixed-citation></ref><ref id="scirp.119508-ref6"><label>6</label><mixed-citation publication-type="other" xlink:type="simple">Mayers, D. (2001) Unconditional Security in Quantum Cryptography. Journal of the ACM, 48, 351-406. https://doi.org/10.1145/382780.382781</mixed-citation></ref><ref id="scirp.119508-ref7"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">Mayers, D. (2002) Shor and Preskill’s and Mayers’s Security Proof for the BB84 Quantum Key Distribution Protocol. The European Physical Journal D, 18, 161-170.  
https://doi.org/10.1140/epjd/e20020020</mixed-citation></ref><ref id="scirp.119508-ref8"><label>8</label><mixed-citation publication-type="other" xlink:type="simple">Gottesman, D. and Lo, H.-K. (2003) Proof of Security of Quantum Key Distribution with Two-Way Classical Communications. IEEE Transactions on Information Theory, 49, 457-475. https://doi.org/10.1109/TIT.2002.807289</mixed-citation></ref><ref id="scirp.119508-ref9"><label>9</label><mixed-citation publication-type="other" xlink:type="simple">Lo, H.-K., Chau, H.F. and Ardehali, M. (2005) Efficient Quantum Key Distribution Scheme and a Proof of Its Unconditional Security. Journal of Cryptology, 18, 133-165.  
https://doi.org/10.1007/s00145-004-0142-y</mixed-citation></ref><ref id="scirp.119508-ref10"><label>10</label><mixed-citation publication-type="other" xlink:type="simple">Renner, R., Gisin, N. and Kraus, B. (2005) Information-Theoretic Security Proof for Quantum-Key-Distribution Protocols. Physical Review A, 72, Article ID: 12332.  
https://doi.org/10.1103/PhysRevA.72.012332</mixed-citation></ref><ref id="scirp.119508-ref11"><label>11</label><mixed-citation publication-type="other" xlink:type="simple">Boyer, M., Liss, R. and Mor, T. (2020) Composable Security against Collective Attacks of a Modified BB84 QKD Protocol with Information Only in One Basis. Theoretical Computer Science, 801, 96-109.  
https://doi.org/10.1016/j.tcs.2019.08.014</mixed-citation></ref><ref id="scirp.119508-ref12"><label>12</label><mixed-citation publication-type="other" xlink:type="simple">Su, H.-Y. (2020) Simple Analysis of Security of the BB84 Quantum Key Distribution Protocol. Quantum Information Processing, 19, 169.  
https://doi.org/10.1007/s11128-020-02663-z</mixed-citation></ref><ref id="scirp.119508-ref13"><label>13</label><mixed-citation publication-type="other" xlink:type="simple">Tsurumaru, T. (2020) Leftover Hashing From Quantum Error Correction: Unifying the Two Approaches to the Security Proof of Quantum Key Distribution. IEEE Transactions on Information Theory, 66, 3465-3484.  
https://doi.org/10.1109/TIT.2020.2969656</mixed-citation></ref><ref id="scirp.119508-ref14"><label>14</label><mixed-citation publication-type="other" xlink:type="simple">Zhang, Q. and Tang, C.-J. (2002) Simple Proof of the Unconditional Security of the Bennett 1992 Quantum Key Distribution Protocol. Physical Review A, 65, Article ID: 062301. https://doi.org/10.1103/PhysRevA.65.062301</mixed-citation></ref><ref id="scirp.119508-ref15"><label>15</label><mixed-citation publication-type="other" xlink:type="simple">Tamaki, K., Koashi, M. and Imoto, N. (2003) Unconditionally Secure Key Distribution Based on Two Nonorthogonal States. Physical Review Letters, 90, Article ID: 167904. https://doi.org/10.1103/PhysRevLett.90.167904</mixed-citation></ref><ref id="scirp.119508-ref16"><label>16</label><mixed-citation publication-type="other" xlink:type="simple">Tamaki, K. and Lütkenhaus, N. (2004) Unconditional Security of the Bennett 1992 Quantum Key Distribution Protocol over Lossy and Noisy Channel. Physical Review A, 69, Article ID: 032316. https://doi.org/10.1103/PhysRevA.69.032316</mixed-citation></ref><ref id="scirp.119508-ref17"><label>17</label><mixed-citation publication-type="other" xlink:type="simple">Tamaki, K., Lütkenhaus, N., Koashi, M. and Batuwantudawe, J. (2009) Unconditional Security of the Bennett 1992 Quantum-Key-Distribution Scheme with a Strong Reference Pulse. Physical Review A, 80, Article ID: 032302.  
https://doi.org/10.1103/PhysRevA.80.032302</mixed-citation></ref><ref id="scirp.119508-ref18"><label>18</label><mixed-citation publication-type="other" xlink:type="simple">Lucamarini, M., Giuseppe, G. and Tamaki, K. (2009) Robust Unconditionally Secure Quantum Key Distribution with Two Nonorthogonal and Uninformative States. Physical Review A, 80, Article ID: 032327.  
https://doi.org/10.1103/PhysRevA.80.032327</mixed-citation></ref><ref id="scirp.119508-ref19"><label>19</label><mixed-citation publication-type="other" xlink:type="simple">Ali, N., Radzi, N.A.N., Aljunid, S.A. and Endut, R. (2020) Security of B92 Protocol with Uninformative States in Asymptotic Limit with Composable Security. AIP Conference Proceedings, 2203, Article ID: 020049. https://doi.org/10.1063/1.5142141</mixed-citation></ref><ref id="scirp.119508-ref20"><label>20</label><mixed-citation publication-type="other" xlink:type="simple">Olszewski, S. (2020) Ehrenfest Approach to the Adiabatic Invariants and Calculation of the Intervals of Time Entering the Energy Emission Process in Simple Quantum Systems. Journal of Quantum Information Science, 10, 1-9.  
https://doi.org/10.4236/jqis.2020.101001</mixed-citation></ref><ref id="scirp.119508-ref21"><label>21</label><mixed-citation publication-type="other" xlink:type="simple">Ishikawa, S. (2020) Wittgenstein’s Picture Theory in the Quantum Mechanical Worldview. Journal of Quantum Information Science, 10, 104-125.  
https://doi.org/10.4236/jqis.2020.104007</mixed-citation></ref><ref id="scirp.119508-ref22"><label>22</label><mixed-citation publication-type="other" xlink:type="simple">Shor, P.W. (1994) Algorithms for Quantum Computation: Discrete Logarithms and Factoring. In: Proc. 35th Annual Symposium on Foundations of Computer Science, IEEE Press, Los Alamitos, 124-134. https://doi.org/10.1109/SFCS.1994.365700</mixed-citation></ref><ref id="scirp.119508-ref23"><label>23</label><mixed-citation publication-type="other" xlink:type="simple">Rivest, R.L., Shamir, A. and Adleman, L. (1978) A Method for Obtaining Digital Sig Natures and Public-Key Cryptosystems. Communications of the ACM, 21, 120-126.  
https://doi.org/10.1145/359340.359342</mixed-citation></ref><ref id="scirp.119508-ref24"><label>24</label><mixed-citation publication-type="other" xlink:type="simple">Nielsen, M.A. and Chuang, I.L. (2000) Quantum Computation and Quantum Information. Cambridge University Press, Cambridge, 11, 38-39, 232-233, 248-276.</mixed-citation></ref><ref id="scirp.119508-ref25"><label>25</label><mixed-citation publication-type="other" xlink:type="simple">Mavroeidis, V., Vishi, K., Zych, M. and J&amp;#248;sang, A. (2018) The Impact of Quantum Computing on Present Cryptography. International Journal of Advanced Computer Science and Applications, 9, 405-414. https://doi.org/10.14569/IJACSA.2018.090354</mixed-citation></ref><ref id="scirp.119508-ref26"><label>26</label><mixed-citation publication-type="other" xlink:type="simple">Grover, L.K. (1996) A Fast Quantum Mechanical Algorithm for Database Search. In: Proceedings 28th ACM Symposium on the Theory of Computation, ACM Press, New York, 212-219. https://doi.org/10.1145/237814.237866</mixed-citation></ref><ref id="scirp.119508-ref27"><label>27</label><mixed-citation publication-type="other" xlink:type="simple">Grover, L.K. (1997) Quantum Mechanics Helps in Searching for a Needle in a Haystack. Physical Review Letters, 79, 325-328.  
https://doi.org/10.1103/PhysRevLett.79.325</mixed-citation></ref><ref id="scirp.119508-ref28"><label>28</label><mixed-citation publication-type="other" xlink:type="simple">Akihiro, Y. and Hirokazu, I. (2000) Quantum Cryptanalysis of Block Ciphers. Algebraic Systems, Formal Languages and Computations. RIMS Kokyuroku, 1166, 235-243.</mixed-citation></ref><ref id="scirp.119508-ref29"><label>29</label><mixed-citation publication-type="other" xlink:type="simple">Almazrooie, M., Samsudin, A., Abdullah, R. and Mutter, K.N. (2016) Quantum Exhaustive Key Search with Simplified-DES as a Case Study. SpringerPlus, 5, Article No. 1494. https://doi.org/10.1186/s40064-016-3159-4</mixed-citation></ref><ref id="scirp.119508-ref30"><label>30</label><mixed-citation publication-type="other" xlink:type="simple">Coppersmith, D., Holloway, C., Matyas, S.M. and Zunic, N. (1997) The Data Encryption Standard. Information Security Tech. Rep. No. 2, 22-24.  
https://doi.org/10.1016/S1363-4127(97)81325-8</mixed-citation></ref><ref id="scirp.119508-ref31"><label>31</label><mixed-citation publication-type="other" xlink:type="simple">Shannon, C.E. (1949) Communication Theory of Secrecy Systems. The Bell System Technical Journal, 28, 656-715. https://doi.org/10.1002/j.1538-7305.1949.tb00928.x</mixed-citation></ref><ref id="scirp.119508-ref32"><label>32</label><mixed-citation publication-type="other" xlink:type="simple">Zalka, C. (1999) Grover’s Quantum Searching Algorithm Is Optimal. Physical Review A: Atomic, Molecular and Optical Physics, 60, 2746-2751.  
https://doi.org/10.1103/PhysRevA.60.2746</mixed-citation></ref><ref id="scirp.119508-ref33"><label>33</label><mixed-citation publication-type="other" xlink:type="simple">Patil, S. and Kumar, A. (2010) Implemented Encryption Scheme (One Time Pad) Using 9’s Complement. International Journal of Advanced Research in Computer Science, 1, 49-51.</mixed-citation></ref></ref-list></back></article>