# Information-Theoretically Secure Data Origin Authentication with Quantum and Classical Resources

^{1}

^{2}

^{3}

^{*}

## Abstract

**:**

## 1. Introduction

## 2. Unconditionally Secure Classical MACs

**Definition**

**1.**

**Theorem**

**1.**

## 3. Theoretical Framework for Unconditionally Secure Prepare-and-Measure QMACs

**Definition**

**2.**

**Impersonation attack**—Eve wants to impersonate Alice without knowing the actual secret key k, and without having access to any valid message-tag pair. To this end, she chooses a pair $(m,|{\Psi}_{{\tau}^{\prime}}\rangle )$ with ${\tau}^{\prime}=f({k}^{\prime},m)$, and sends it to Bob, hoping that Bob will accept it as a valid message originated from Alice.

**Definition**

**3.**

**Substitution attack**—Eve does not know the secret key k of Alice and Bob, but she has access to a single valid message-tag pair $(m,|{\Psi}_{\tau}\rangle )$. Her task is to produce another message ${m}^{\prime}\ne m$, such that the pair $({m}^{\prime},|{\Psi}_{\tilde{\tau}}\rangle )$ with $\tilde{\tau}=f(k,{m}^{\prime})$ will be accepted by Bob as a valid message originated from Alice.

## 4. Results

**Theorem**

**2.**

**Proof.**

#### 4.1. A QMAC with Quantum Key

#### 4.2. Decision Making Based on a Symmetry Test

## 5. Summary

## Author Contributions

## Funding

## Conflicts of Interest

## Abbreviations

MAC | Message authentication code |

QMAC | Quantum message authentication code |

## Appendix A

