When elementary quantum systems, such as polarized photons, are used to transmit digital information, the uncertainty principle gives rise to novel cryptographic phenomena unachievable with traditional transmission media, e.g. a communications channel on which it is impossible in principle to eavesdrop without a high probability of being detected. With such a channel, a one-time pad can safely be reused many times as long as no eavesdrop is detected, and, planning ahead, part of the capacity of these uncompromised transmissions can be used to send fresh random bits with which to replace the one-time pad when an eavesdrop finally is detected. Unlike other schemes for stretching a one-time pad, this scheme does not depend on complexitytheoretic assumptions such as the difficulty of factoring. Note written on 29 June 2014: This paper was written in November 1982 and originally submitted to the Fifteenth Annual ACM Symposium on Theory of Computing, but it was rejected. Shortly thereafter, two of the authors (Charles H. Bennett and Gilles Brassard) discovered what became known as BB84, which seemed like such a better idea that they gave up on resubmitting this earlier work. On the occasion of the 30th anniversary of the BB84 paper, Natural Computing has invited us to get this paper finally published. This freshly typeset version is scrupulously faithful to the original 1982 submission, except for the correction of about one dozen typographical mistakes and a few footnotes written in retrospect by the authors. ∗ 2014 update on email: chdbennett@gmail.com. † 2014 update on email: brassard@iro.umontreal.ca; update on affiliation: also Senior Fellow of ETH-ITS and of CIFAR.
In their article, ‘That is not dead which can eternal lie: the aestivation hypothesis for resolving Fermi’s paradox’, Sandberg et al. try to explain the Fermi paradox (we see no aliens) by claiming that Landauer’s principle implies that a civilization can in principle perform far more ( $${\sim } 10^{30}$$ times more) irreversible logical operations (e.g., error-correcting bit erasures) if it conserves its resources until the distant future when the cosmic background temperature is very low. So perhaps aliens are out there, but quietly waiting. Sandberg et al. implicitly assume, however, that computer-generated entropy can only be disposed of by transferring it to the cosmological background. In fact, while this assumption may apply in the distant future, our universe today contains vast reservoirs and other physical systems in non-maximal entropy states, and computer-generated entropy can be transferred to them at the adiabatic conversion rate of one bit of negentropy to erase one bit of error. This can be done at any time, and is not improved by waiting for a low cosmic background temperature. Thus aliens need not wait to be active. As Sandberg et al. do not provide a concrete model of the effect they assert, we construct one and show where their informal argument goes wrong.
Disclaimer/Complaints regulations If you believe that digital publication of certain material infringes any of your rights or (privacy) interests, please let the Library know, stating your reasons. In case of a legitimate complaint, the Library will make the material inaccessible and/or remove it from the website. Please Ask the Library: http://uba.uva.nl/en/contact, or a letter to: Library of the University of Amsterdam, Secretariat, Singel 425, 1012 WP Amsterdam, The Netherlands. You will be contacted as soon as possible.
References: 1. Charles H. Bennett, Gilles Brassard, Claude Crépeau, Richard Jozsa, Asher Peres, and William K. Wootters. Teleporting an unknown quantum state via dual classical and Einstein-Podolsky-Rosen channels. Phys. Rev. Lett. 70, 1895 (1993). 2. D. Bouwmeester, J. Pan, K. Mattle, M. Eibl, H. Weinfurter and A. Zeilinger. Experimental quantum teleportation. Phil. Trans. R. Soc. Lond. A 356, 1733-1737 (1998). 3. Charles H. Bennett. Quantum Information and Computation. Physics Today 48, 24-30 (October 1995). 4. Mark Beck, Quantum Mechanics, Theory and Experiments, Oxford University Press (2012). 5. EPR Paradox Timeline
Dual to the usual noisy channel coding problem, where a noisy (classical or quantum) channel is used to simulate a noiseless one, reverse Shannon theorems concern the use of noiseless channels to simulate noisy ones, and more generally the use of one noisy channel to simulate another. For channels of nonzero capacity, this simulation is always possible, but for it to be efficient, auxiliary resources of the proper kind and amount are generally required. In the classical case, shared randomness between sender and receiver is a sufficient auxiliary resource, regardless of the nature of the source, but in the quantum case, the requisite auxiliary resources for efficient simulation depend on both the channel being simulated, and the source from which the channel inputs are coming. For tensor power sources (the quantum generalization of classical memoryless sources), entanglement in the form of standard ebits (maximally entangled pairs of qubits) is sufficient, but for general sources, which may be arbitrarily correlated or entangled across channel inputs, additional resources, such as entanglement-embezzling states or backward communication, are generally needed. Combining existing and new results, we establish the amounts of communication and auxiliary resources needed in both the classical and quantum cases, the tradeoffs among them, and the loss of simulation efficiency when auxiliary resources are absent or insufficient. In particular, we find a new single-letter expression for the excess forward communication cost of coherent feedback simulations of quantum channels (i.e., simulations in which the sender retains what would escape into the environment in an ordinary simulation), on nontensor-power sources in the presence of unlimited ebits but no other auxiliary resource. Our results on tensor power sources establish a strong converse to the entanglement-assisted capacity theorem.
When elementary quantum systems, such as polarized photons, are used to transmit digital information, the uncertainty principle gives rise to novel cryptographic phenomena unachievable with traditional transmission media, e.g. a communications channel on which it is impossible in principle to eavesdrop without a high probability of disturbing the transmission in such a way as to be detected. Such a quantum channel can be used in conjunction with ordinary insecure classical channels to distribute random key information between two users with the assurance that it remains unknown to anyone else, even when the users share no secret information initially. We also present a protocol for coin-tossing by exchange of quantum messages, which is secure against traditional kinds of cheating, even by an opponent with unlimited computing power, but ironically can be subverted by use of a still subtler quantum phenomenon, the Einstein-Podolsky-Rosen paradox.
When elementary quantum systems, such as polarized photons, are used to transmit digital information, the uncertainty principle gives rise to novel cryptographic phenomena unachievable with traditional transmission media, e.g. a communications channel on which it is impossible in principle to eavesdrop without a high probability of being detected. With such a channel, a one-time pad can safely be reused many times as long as no eavesdrop is detected, and, planning ahead, part of the capacity of these uncompromised transmissions can be used to send fresh random bits with which to replace the one-time pad when an eavesdrop finally is detected. Unlike other schemes for stretching a one-time pad, this scheme does not depend on complexity-theoretic assumptions such as the difficulty of factoring.
We point out that arguments for the security of Kish's noise-based cryptographic protocol have relied on an unphysical no-wave limit, which if taken seriously would prevent any correlation from developing between the users. We introduce a noiseless version of the protocol, also having illusory security in the no-wave limit, to show that noise and thermodynamics play no essential role. Then we prove generally that classical electromagnetic protocols cannot establish a secret key between two parties separated by a spacetime region perfectly monitored by an eavesdropper. We note that the original protocol of Kish is vulnerable to passive time-correlation attacks even in the quasi-static limit. Finally we show that protocols of this type can be secure in practice against an eavesdropper with noisy monitoring equipment. In this case the security is a straightforward consequence of Maurer and Wolf's discovery that key can be distilled by public discussion from correlated random variables in a wide range of situations where the eavesdropper's noise is at least partly independent from the users' noise.
A lot of research has been done on multipartite correlations, but the problem of satisfactorily defining genuine multipartite correlations-those not trivially reducible to lower partite correlations-remains unsolved. In this paper we propose three reasonable postulates which each measure or indicator of genuine multipartite correlations (or genuine multipartite entanglement) should satisfy. We also introduce the concept of degree of correlations, which gives partial characterization of multipartite correlations. Then, we show that covariance does not satisfy two postulates and hence it cannot be used as an indicator of genuine multipartite correlations. Finally, we propose a candidate for a measure of genuine multipartite correlations based on the work that can be drawn from a local heat bath by means of a multipartite state.
Dual to the usual noisy channel coding problem, where a noisy (classical or quantum) channel is used to simulate a noiseless one, reverse Shannon theorems concern the use of noiseless channels to simulate noisy ones, and more generally the use of one noisy channel to simulate another. For channels of nonzero capacity, this simulation is always possible, but for it to be efficient, auxiliary resources of the proper kind and amount are generally required. In the classical case, shared randomness between sender and receiver is a sufficient auxiliary resource, regardless of the nature of the source, but in the quantum case the requisite auxiliary resources for efficient simulation depend on both the channel being simulated, and the source from which the channel inputs are coming. For tensor power sources (the quantum generalization of classical IID sources), entanglement in the form of standard ebits (maximally entangled pairs of qubits) is sufficient, but for general sources, which may be arbitrarily correlated or entangled across channel inputs, additional resources, such as entanglement-embezzling states or backward communication, are generally needed. Combining existing and new results, we establish the amounts of communication and auxiliary resources needed in both the classical and quantum cases, the tradeoffs among them, and the loss of simulation efficiency when auxiliary resources are absent or insufficient. In particular we find a new single-letter expression for the excess forward communication cost of coherent feedback simulations of quantum channels (i.e. simulations in which the sender retains what would escape into the environment in an ordinary simulation), on non-tensor-power sources in the presence of unlimited ebits but no other auxiliary resource. Our results on tensor power sources establish a strong converse to the entanglement-assisted capacity theorem.
We study the power of closed timelike curves (CTCs) and other nonlinear extensions of quantum mechanics for distinguishing nonorthogonal states and speeding up hard computations. If a CTC-assisted computer is presented with a labeled mixture of states to be distinguished--the most natural formulation--we show that the CTC is of no use. The apparent contradiction with recent claims that CTC-assisted computers can perfectly distinguish nonorthogonal states is resolved by noting that CTC-assisted evolution is nonlinear, so the output of such a computer on a mixture of inputs is not a convex combination of its output on the mixture's pure components. Similarly, it is not clear that CTC assistance or nonlinear evolution help solve hard problems if computation is defined as we recommend, as correctly evaluating a function on a labeled mixture of orthogonal inputs.
This article reports an open discussion that took place during the Keenan Symposium "Meeting the Entropy Challenge" (held in Cambridge, Massachusetts, on October 4, 2007) following the short presentations - each reported as a separate article in the present volume - by Adrian Bejan, Bjarne Andresen, Miguel Rubi, Signe Kjelstrup, David Jou, Miroslav Grmela, Lyndsay Gordon, and Eric Schneider.All panelists and the audience were asked to address the following questionsIs the second law relevant when we trap single ions, prepare, manipulate and measure single photons, excite single atoms, induce spin echoes, measure quantum entanglement? Is it possible or impossible to build Maxwell demons that beat the second law by exploiting fluctuations?Is the maximum entropy generation principle capable of unifying nonequilibrium molecular dynamics, chemical kinetics, nonlocal and nonequilibrium rheology, biological systems, natural structures, and cosmological evolution?Research in quantum computation and quantum information has raised many fundamental questions about the foundations of quantum theory. Are any of these questions related to the second law?
The first essay discusses, in nontechnical terms, the paradox implicit in defining a random integer as one without remarkable properties, and the resolution of that paradox at the cost of making randomness a property which most integers have but can’t be proved to have. The second essay briefly reviews the search for randomness in the digit sequences of natural irrational numbers like π and artificial ones like Champernowne’s C = 0.12345678910111213 . . ., and discusses at length Chaitin’s definable-but-uncomputable number Ω, whose digit sequence is so random that no betting strategy could succeed against it. Other, Cabalistic properties of Ω are pointed out for the first time.
The thermodynamics of computation is well understood for computing engines (rdquoBrownian computersrdquo) that are ideal in the sense that they can make forward and backward steps along the intended computation path, but not transitions to unrelated states. The thermodynamics of error-prone computations and error-correcting mechanisms is less well understood. We explore the speed-error-dissipation tradeoff for a family of hypothetical coupled chemical reaction schemes loosely patterned on RNA and DNA polymerases, which suffer errors at some intrinsic hardware rate and, in the case of DNA polymerases, use proofreading - cyclic dissipative reaction path - to correct most of the errors initially introduced. Even simple non-proofreading systems exhibit nontrivial features, for example a regime where the copying process is pulled slowly forward, against a backward external driving force, by the entropy of incorporated errors.
In this talk, I discuss the mystery of the second law and its relation to quantum information. There are many explanations of the second law, mostly satisfactory and not mutually exclusive. Here, I advocate quantum mechanics and quantum information as something that, through entanglement, helps resolve the paradox or the puzzle of the origin of the second law. I will discuss the interpretation called quantum Darwinism and how it helps explain why our world seems so classical, and what it has to say about the permanence or transience of information. And I will discuss a simple model illustrating why systems away from thermal equilibrium tend to be more complicated.