Cryptographic aspects of quantum reading

Besides achieving secure communication between two spatially-separated parties, another important issue in modern cryptography is related to secure communication in time, i.e., the possibility to confidentially store information on a memory for later retrieval. Here we explore this possibility in the setting of quantum reading, which exploits quantum entanglement to efficiently read data from a memory whereas classical strategies (e.g., based on coherent states or their mixtures) cannot retrieve any information. From this point of view, the technique of quantum reading can provide a new form of technological security for data storage.


Introduction
Quantum cryptography [1,2] aims to realize a completely unbreakable scheme for the distribution of a secret key between two remote parties, usually called Alice and Bob. Indeed quantum key distribution (QKD) relies its security on one of the the most fundamental physical laws, the uncertainty principle, which is actively exploited for detecting and overcoming the presence of a malicious eavesdropper, usually called Eve. In this scenario, an important role is also played by quantum entanglement [3], which can be exploited to make QKD protocols device-independent, i.e., more robust to practical flaws (e.g., in the detectors) which may potentially be exploited by Eve. Very recently, quantum discord [4] (see Ref. [5] for its computation with Gaussian states) has also been identified as a useful resource for device-dependent QKD with trusted noise [6], e.g., in scenarios such as measurement-device independent QKD [7][8][9][10].
In this preliminary study, we investigate a different but still important problem: The confidential storage of information on a physical device, such as an optical memory. It has been recently proven that quantum entanglement can provide an advantage in the readout of classical data from optical memories, especially in the low-energy regime, i.e., when a few photons are irradiated over the memory cells. This approach is known as quantum reading [11] (see also follow-up papers [12][13][14][15][16][17][18][19][20][21][22][23]), a notable application of quantum channel discrimination to a practical task as the memory readout. From this point of view, another well-known protocol is quantum illumination, which aims at improving target detection [25][26][27][28][29][30][31], and has been recently extended to its most natural domain, the microwaves [32].
Here we show how the performance advantage given by quantum reading can be exploited to completely hide classical information in optical memories. The strategy is to design a photo-degradable optical memory whose cells have very close reflectivities (each reflectivity encoding a bit-value). Because of the photodegrable effects, each cell can only be read with a limited number of photons. In these low-energy conditions, we find that only well-tailored quantum sources (in particular, entangled) are able to discriminate two very close reflectivities and, therefore, retrieve the information stored in the cell. Specifically, we derive a simple analytical formula which relates the reflectivities of the memory cell with the mean number of photons to be employed by the quantum source.
This approach would provide a layer of technological security to the stored data, in the sense that only an advanced laboratory equipped with quantum-correlated sources would be able to read the information, whereas any other standard optical reader based on classical states, such as coherent states or even thermal states, can only extract a negligible number of bits.
The paper is organized as follows. In Sec. 2, we briefly review the basic setup of quantum reading and we discuss the performances achievable by quantum entanglement and classical (coherent) states. Then, in Sec. 3 we show how to design memories which are not accessible to classical methods. Finally, Sec. 4 is for conclusions.

Basic setup for quantum reading
For our purpose we consider the simplest version of quantum reading, considering only ideal optical memories, i.e., with high reflectivities, and neglecting decoherence effects (see Ref. [11] for more advanced models). Each memory cell is assumed to be in one of two hypotheses: Non-unit reflectivity r 0 := r < 1 (encoding bit-value 0) or unit reflectivity r 1 = 1 (encoding bit-value 1). Mathematically, this is equivalent to distinguish between a lossy channel E r whose loss parameter is the reflectivity r < 1 and an identity channel I.
In symmetric quantum hypothesis testing, these two hypotheses have the same cost, so that we aim to optimize the mean error probability. In other words, we need to minimizep := p(1|0)p 0 + p(0|1)p 1 , where p 0 and p 1 are the a priori probabilities of the two hypotheses, while p(1|0) is the probability of a false positive and p(0|1) is the probability of a false negative. For simplicity, we consider here equiprobable hypotheses, i.e., p 0 = p 1 = 1/2, which means that a bit of information is stored per cell. The amount of information which is retrieved in the readout process is therefore given by is the binary formula of the Shannon entropy [33].

Classical Benchmark
To distinguish between the two hypotheses Alice exploits an input source of light (a transmitter) and an output detection scheme (a receiver). In the classical reading setup, the transmitter consists of a single bosonic mode, the signal (S), which is prepared in a coherent state |α sent to the memory cell. At the output, the receiver is typically a photodetector counting the number of photons reflected, followed by a digital processing based on a classical hypothesis test. The performance of this receiver can be bounded by considering an optimal quantum measurement, constructed from the Helstrom matrix ρ 0 − ρ 1 of the two possible output states ρ 0 = | √ rα √ rα| and ρ 1 = |α α|. The minimum error probability is given by the Helstrom bound [34] which is here very simple to compute since the two states are pure. In fact, for two arbitrary pure states |ϕ 0 and |ϕ 1 , the Helstrom bounds readsp where the trace distance [3] D is determined by the fidelity In our specific case, we have [2] F wheren = |α| 2 is the mean number of photons of the input coherent state. As a result, we achieve the following Helstrom bound for the coherent state transmitter which is therefore able to read an average of I class read = I read (p class ) bits per cell.

Quantum Transmitter
In the quantum reading setup, we consider a transmitter composed of two entangled modes, that we call signal (S) and reference (R). This is taken to be an Einstein-Podolsky-Rosen (EPR) state, also known as a two-mode squeezed vacuum state [2]. An EPR state is a zero-mean pure Gaussian state |µ SR with covariance matrix (CM) where µ ≥ 1 quantifies both the mean number of thermal photons in each mode, given byn = (µ−1)/2, and the amount of entanglement between the signal and reference modes [2]. The signal mode, withn mean photons, is sent to read the memory cell and its reflection S is combined with the reference mode in an optimal quantum measurement. Given the state ρ SR = |µ SR µ| of the input modes S and R, we get two possible states for the output modes S and R at the receiver. One is just the input EPR state, while the other state σ 0 is a mixed Gaussian state with CM The minimum mean error probability is given by the Helstrom boundp quantum = [1 − D(σ 0 , σ 1 )]/2, where D(σ 0 , σ 1 ) is the trace distance between σ 0 and σ 1 . The Helstrom bound is difficult to compute when one or both the output states are mixed. For this reason, we resort to an upper-bound, known as quantum Chernoff bound (QCB) [35][36][37]. This can be written as where C s := Tr(σ s 0 σ 1−s 1 ) is the s-overlap between the two states. In the specific case where one of the output states is pure σ 1 = |ϕ ϕ|, we may write C = F , using the quantum fidelity F = ϕ| σ 0 |ϕ . For zero-mean Gaussian states, this fidelity can easily be computed in terms of their CMs [38,39]. In fact, we have As a result, the mean error probability associated with this quantum transmitter is upperbounded by the QCB as followsp Thus, the EPR transmitter is able to read at least I quant read = I read (p QCB quantum ) bits per cell.

Data secured by quantum reading
We can compare the readout performances of the two transmitters by considering the information gain ∆ := I quant read − I class read . Its positivity means that quantum reading outperforms the classical readout strategy. In particular, for ∆ 1 bit per cell we have that the EPR transmitter reads all data, while the classical transmitter is not able to retrieve any information. Here we aim to exploit this feature to make the data storage secure in absence of entanglement (and, more generally, quantum resources). As we can see from Fig. 1, the value of the gain ∆ is close to the maximum value of 1 bit per cell when the memory cell is characterized by very high reflectivities, i.e., r 1. In particular, the good region where ∆ > 0.95 is particularly evident at low photon numbers, while it tends to shrink towards r = 1 for increasing energy.
We now discuss how we can exploit this advantage of quantum reading for designing a secure classical memory. Let us expand the information quantities I class read and I quant read at the leading order in (1 − r) 0. We find As we can see, at high reflectivities, there is a different behaviour of these quantities in the mean number of photonsn. In particular, we may write We can see that only quantum reading enables to retrieve non-zero information from the memory (combining this performance with suitable error correcting codes would enable us to achieve a complete readout of the memory). In the following Fig. 2, we show the behaviour of the two information quantities I class read and I quant read in terms of the mean photon numbern and assuming the condition of Eq. (15). We can see that, at any fixed energyn irradiated over the memory cell, there is a memory with reflectivity r satisfying Eq. (15) which is readable by using a quantum transmitter with signal energyn but unreadable by a classical transmitter with the same irradiated energyn. More precisely, any classical transmitter with energy up ton is inefficient. In fact, let us fix some valuen max and consider a memory with 1 − r =n −1 max , then the performance of all classical transmitters with signal energyn ≤n max is shown in Fig. 3. We see that the optimal classical transmitter is that with the maximal energyn max as clearly expected from the monotonic expression in Eq. (5).
Thus, if we construct a theoretical memory which can be irradiated with at mostn max photons per cell (otherwise data is lost, e.g., due to photodegrable effects) and having reflectivity r satisfying Eq. (15), then this will be unreadable by any classical transmitter based on coherent states while its data can be retrieved by a quantum transmitter with signal energy n max .   Figure 3. We plot the information quantity I class read in log-scale forn ≤n max . We consider the readout of a memory with 1 − r =n −1 max . Here we consider the numerical valuen max = 1000 but the behaviour is generic.
Note that in general, we can design a memory with reflectivity r such that for some constant c. For largen, we have I class read → 0, while I quant read tends to a constant ≤ 1 which depends on c. For instance, we have I quant read → 0.895 for c = 0.1, and I quant read → 0.997 for c = 0.01. In the following Fig. 4, we show the behaviour of the two information quantities I class read and I quant read assuming the condition of Eq. (17) with c = 0.1. We see how the memories remains unreadable by classical means while the peformance of quantum reading approaches 1 bit per cell.

Conclusion
In this preliminary study on the cryptographic aspects of quantum reading, we have shown how it is possible to construct classical memories which cannot be read by classical means, namely coherent states (and mixtures of coherent states, by invoking the same convexity arguments of Ref. [26]) but still they can be read using quantum entanglement. In particular, we have considered an EPR state and we have connected the mean number of photons to be employed by this quantum source with the reflectivies to be used in the memory cells, see Eq. (15) and also its generalization in Eq. (17). Note that other non-classical states may also provide non-trivial advantages with respect to coherent states and their mixtures. In general, the security provided by the scheme relies on the technological difference between two types of labs, one limited to classical sources and the other able to access quantum features, such as entanglement or squeezing.
It is interesting to discuss the connections between our scheme of data-hiding by quantum reading and the traditional technique of quantum data hiding [40,41]. The latter is about to store classical information into entangled states, so that it can only be retrieved by joint measurements. It is clearly an application of quantum state discrimination. By contrast, data-hiding by quantum reading is related to the problem of quantum channel discrimination. Classical data is stored in a channel (not a state) and quantum entanglement is used as an input resource to be processed by the channel. This is a crucial difference, also for practical purposes, since data stored in a classical memory does not decohere (like the entangled states typically prepared in quantum data hiding), and quantum entanglement is used a resource on demand, which is needed only for the readout of the information (not for the storage process).
Note that our study can be extended in several ways. We have only considered ideal memories where the cells are addressed individually and have very high reflectivities (in particular, we have assumed unit reflectivity for one of the two bit values stored in the cell). There is no inclusion of additional noise sources in the model, e.g., coming from stray photons scattered during the readout process, neither analysis of diffraction or other optical effects. Finally, we have also assumed that high values of entanglement can be generated. While this is possible theoretically, it is very hard to achieve experimentally. This would not be a problem if we were able to construct memories which are extremely photo-sensitive, so that that the maximum values of tolerable energies are of the order ofn max 10 photons per cell.