<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">32320</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2023.032320</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Quantum Oblivious Transfer with Reusable Bell State</article-title>
<alt-title alt-title-type="left-running-head">Quantum Oblivious Transfer with Reusable Bell State</alt-title>
<alt-title alt-title-type="right-running-head">Quantum Oblivious Transfer with Reusable Bell State</alt-title>
</title-group>
<contrib-group content-type="authors">
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Kuo</surname><given-names>Shu-Yu</given-names>
</name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Tseng</surname><given-names>Kuo-Chun</given-names>
</name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Chou</surname><given-names>Yao-Hsin</given-names>
</name><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<contrib id="author-4" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Tseng</surname><given-names>Fan-Hsun</given-names>
</name><xref ref-type="aff" rid="aff-4">4</xref><email>tsengfh@gs.ncku.edu.tw</email></contrib>
<aff id="aff-1"><label>1</label><institution>Department of Computer Science and Engineering, National Chung Hsing University</institution>, <addr-line>Taichung, 40227</addr-line>, <country>Taiwan</country></aff>
<aff id="aff-2"><label>2</label><institution>Department of Physics, National Taiwan University</institution>, <addr-line>Taipei, 106216</addr-line>, <country>Taiwan</country></aff>
<aff id="aff-3"><label>3</label><institution>Department of Computer Science and Information Engineering, National Chi Nan University</institution>, <addr-line>Puli, 54561</addr-line>, <country>Taiwan</country></aff>
<aff id="aff-4"><label>4</label><institution>Department of Computer Science and Information Engineering, National Cheng Kung University</institution>, <addr-line>Tainan, 701401</addr-line>, <country>Taiwan</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Fan-Hsun Tseng. Email: <email>tsengfh@gs.ncku.edu.tw</email></corresp>
</author-notes>
<pub-date pub-type="epub" date-type="pub" iso-8601-date="2022-08-16"><day>16</day>
<month>08</month>
<year>2022</year></pub-date>
<volume>74</volume>
<issue>1</issue>
<fpage>915</fpage>
<lpage>932</lpage>
<history>
<date date-type="received">
<day>13</day>
<month>5</month>
<year>2022</year>
</date>
<date date-type="accepted">
<day>24</day>
<month>6</month>
<year>2022</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2023 Kuo et al.</copyright-statement>
<copyright-year>2023</copyright-year>
<copyright-holder>Kuo et al.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_32320.pdf"></self-uri>
<abstract>
<p>In cryptography, oblivious transfer (OT) is an important multi-party cryptographic primitive and protocol, that is suitable for many upper-layer applications, such as secure computation, remote coin-flipping, electrical contract signing and exchanging secrets simultaneously. However, some no-go theorems have been established, indicating that one-out-of-two quantum oblivious transfer (QOT) protocols with unconditional security are impossible. Fortunately, some one-out-of-two QOT protocols using the concept of Cr&#x00E9;peau&#x2019;s reduction have been demonstrated not to conform to Lo&#x2019;s no-go theorem, but these protocols require more quantum resources to generate classical keys using all-or-nothing QOT to construct one-out-of-two QOT. This paper proposes a novel and efficient one-out-of-two QOT which uses quantum resources directly instead of wasting unnecessary resources to generate classical keys. The proposed protocol is not covered by Lo&#x2019;s no-go theorem, and it is able to check the sender&#x2019;s loyalty and avoid the attack from the receiver. Moreover, the entangled state of the proposed protocol is reusable, so it can provide more services for the participants when necessary. Compared with other QOT protocols, the proposed protocol is more secure, efficient, and flexible, which not only can prevent external and internal attacks, but also reduce the required resources and resource distribution time.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Quantum cryptography; information security</kwd>
<kwd>quantum oblivious transfer</kwd>
<kwd>bell State</kwd>
</kwd-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>The concept of oblivious transfer (OT) in classical cryptography was first introduced by Rabin [<xref ref-type="bibr" rid="ref-1">1</xref>] in 1981. In the oblivious transfer protocol, a sender, Alice, wants to transfer a secret message <inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mi>m</mml:mi><mml:mo>&#x2208;</mml:mo></mml:math></inline-formula> {0,1} to a receiver, Bob. However, Bob only has a 50% probability of learning the message <inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:mi>m</mml:mi></mml:math></inline-formula>. That is, Bob could either learn the message <inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:mi>m</mml:mi></mml:math></inline-formula> with 100% reliability, or have zero knowledge of <inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:mi>m</mml:mi></mml:math></inline-formula>. In addition, at the end of the OT protocol, Alice remains oblivious as to whether Bob learned the message <inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:mi>m</mml:mi></mml:math></inline-formula>. This used to be called the all-or-nothing oblivious transfer protocol. Subsequently, the idea of one-out-of-two oblivious transfer was presented by Even&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-2">2</xref>] in 1985. In one-out-of-two oblivious transfer, sender Alice wants to transfer one of two secret messages, <inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, to receiver Bob, and Bob can choose which message he wishes to learn, but has no idea what the other message is. Analogously, Alice knows nothing about which message Bob learns when the protocol is over. In 1987, Cr&#x00E9;peau [<xref ref-type="bibr" rid="ref-3">3</xref>] presented a reduction method to build a one-out-of-two OT using a <inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:mi>p</mml:mi></mml:math></inline-formula>-all-or-nothing OT, in which Bob can learn the secret message <inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:mi>m</mml:mi></mml:math></inline-formula> with <inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:mi>p</mml:mi></mml:math></inline-formula> probability, and this reduction method is hereinafter referred to as Cr&#x00E9;peau&#x2019;s reduction. In the reduction method, Bob can learn the secret bit with <inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:mi>p</mml:mi></mml:math></inline-formula> probability in each round of the all-or-nothing OT. After repeated rounds, he divides the result into two key sets, including the conclusive set <inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, which is the secret bit that he learns with certainty, while he learns nothing about the secret bit for the other inconclusive set <inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>. According to Bob&#x0027;s choice <inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:mi>j</mml:mi></mml:math></inline-formula>, Bob asks that Alice encrypt her message, <inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, using <inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mover><mml:mi>J</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover></mml:mrow></mml:msub></mml:math></inline-formula>, respectively. Then, Bob ultimately can learn the message <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. Using the above reduction, Cr&#x00E9;peau proved that these two types of OT are equivalent in classical cryptography, so secure all-or-nothing OT can lead to secure one-out-of-two OT. Subsequently, ever more research into extending OT application has been undertaken, and hotly discussed [<xref ref-type="bibr" rid="ref-4">4</xref>], as with secure computation, bit commitment, remote coin-flipping, electrical contract signing, exchanging secrets simultaneously, and so on.</p>
<p>The classical OT protocols are based on complex mathematical problems, such as the discrete logarithm problem [<xref ref-type="bibr" rid="ref-4">4</xref>]. However, if powerful quantum computers become available in the near future, these protocols in classical cryptography will no longer be secure. Certain complex mathematical problems can be solved extremely quickly using quantum algorithms, such as Shor&#x2019;s algorithm [<xref ref-type="bibr" rid="ref-5">5</xref>] or Grover&#x2019;s search algorithm [<xref ref-type="bibr" rid="ref-6">6</xref>]. Therefore, as greater advances are being made toward developing quantum computing, quantum cryptography research aimed at achieving better security has begun to receive increasing attention. The security of quantum cryptography is based on physical principles rather than mathematical complexity, so it is easy to design cryptographic protocols with unconditional security, which is impossible in classical cryptography. For example, the well-known quantum key distribution (QKD) proposed by Charles Bennett and Gilles Brassard in 1984 (BB84 protocol) [<xref ref-type="bibr" rid="ref-7">7</xref>], is proven to be unconditionally secure [<xref ref-type="bibr" rid="ref-8">8</xref>,<xref ref-type="bibr" rid="ref-9">9</xref>].</p>
<p>Quantum oblivious transfer (QOT) has also been extensively discussed. The first all-or-nothing QOT was proposed by Cr&#x00E9;peau&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-10">10</xref>] in 1988, and Bennett&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-11">11</xref>] proposed the first one-out-of-two QOT protected by quantum error correction codes (QECC) in 1991. In 1994, Cr&#x00E9;peau presented a one-out-of-two QOT [<xref ref-type="bibr" rid="ref-12">12</xref>] based on the quantum bit commitment (QBC), but its security can only work on the assumption that Bob cannot delay the quantum measurement if the protocol lacks an auxiliary of QBC. In 1995 Yao [<xref ref-type="bibr" rid="ref-13">13</xref>] further proved that the protocol [<xref ref-type="bibr" rid="ref-12">12</xref>] is secure against coherent measurement if QBC is secure. However, in 1997, the Mayers-Lo-Chau (MLC) no-go theorem [<xref ref-type="bibr" rid="ref-14">14</xref>,<xref ref-type="bibr" rid="ref-15">15</xref>] declared that an unconditionally secure QBC does not exist, so it is impossible for any QOT protocols based on the QBC to be unconditionally secure. Following this, Lo&#x2019;s no-go theorem [<xref ref-type="bibr" rid="ref-16">16</xref>] further discussed the insecurity of quantum secure computations, and posited that all one-sided two-party computations (which allow only one of the two parties to learn the result) are necessarily insecure, so an ideal one-out-of-two quantum oblivious transfer is also impossible. In addition, because of the connection between all-or-nothing OT and one-out-of-two OT, which has been proven to be equivalent in classical cryptography [<xref ref-type="bibr" rid="ref-3">3</xref>], these no-go theorems have caused difficulty in the development of both all-or-nothing and one-out-of-two QOTs.</p>
<p>In 2002, Shimizu&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-17">17</xref>] proposed a communication scheme that is analogous to a one-out-of-two QOT with a 50% probability of completing the communication, meaning that Bob will not learn the message unambiguously to evade Lo&#x2019;s theorem [<xref ref-type="bibr" rid="ref-16">16</xref>]. They [<xref ref-type="bibr" rid="ref-18">18</xref>] later improved the security of their protocol against entangled pair attacks. In 2005, Wolf&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-19">19</xref>] showed a simple reduction between OT and PR-boxes, which is a non-locality machine described by Popescu&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-20">20</xref>]. In 2006, He&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-21">21</xref>] proposed an all-or-nothing QOT using four entangled states, and proved that the protocol does not belong to the QOT protocol defined by Lo&#x2019;s no-go theorem. They found that the one-out-of-two QOT using Cr&#x00E9;peau&#x2019;s reduction [<xref ref-type="bibr" rid="ref-3">3</xref>] is not a rigorous one-out-of-two QOT black box function as specified in Lo&#x2019;s theorem, because the inputs of Alice and Bob are dependent on each other. Therefore, they suggested that the equivalence between the two types of OT required a reexamination at the quantum level. He&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-22">22</xref>] proved that the two types of OT are nonequivalent at the quantum level later. Because Bob inputs his choice before Alice inputs her message and Alice&#x2019;s input will vary depending on Bob&#x2019;s choice, the one-out-of-two QOT using Cr&#x00E9;peau&#x2019;s reduction does not satisfy the definition of ideal one-sided two-party computations in Lo&#x2019;s no-go theorem. The inputs of Alice and Bob are dependent on each other, so the black box function differs from the function defined in Lo&#x2019;s theorem [<xref ref-type="bibr" rid="ref-16">16</xref>]. Subsequently, Yang&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-23">23</xref>] developed a one-out-of-two QOT using tripartite entangled states combined with the concept of Cr&#x00E9;peau&#x2019;s reduction [<xref ref-type="bibr" rid="ref-3">3</xref>] and considered that the one-out-of-two QOT using Cr&#x00E9;peau&#x2019;s reduction is not covered by the cheating strategy of Lo&#x2019;s no-go theorem.</p>
<p>Once the nonequivalence of the two types of QOT was proven, more researchers discussed the issue of QOT using different methods and reduction schemes. The literature can be classified and described systematically as follows.
<list list-type="alpha-lower">
<list-item>
<p>PR non-locality box: After Wolf&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-19">19</xref>] showed the reduction between OT and PR-boxes, Buhrman&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-24">24</xref>] presented a QBC protocol based on PR-boxes extended Wolf&#x2019;s reduction method, and used a previous idea to further construct a one-out-of-two QOT. In 2011, Chou&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-25">25</xref>] simulated a non-local PR box using ten-qubit entanglement, and used it to build a one-out-of-two QOT. To date, there has been little discussion on the relationship between the no-go theorems and the QOT protocols based on PR non-locality box, so its validity is open to question.</p></list-item>
<list-item>
<p>QBC-based QOT: When some unconditionally secure QBC can be obtained under relativistic or experimental constraints, it is a good idea to try to build QOT upon relativistic QBC. However, there are still some doubts about this method, and the most prominent question is &#x201C;Can relativistic bit commitment lead to secure quantum oblivious transfer?&#x201D; [<xref ref-type="bibr" rid="ref-26">26</xref>].</p></list-item>
<list-item>
<p>Bit-string QOT: Apart from relativistic QBC, another concept of bit-string from QBC is also applied to QOT, called bit-string QOT. Souto&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-27">27</xref>], in 2015, proposed bit-string QOT inspired by Kent&#x2019;s bit-string commitment [<xref ref-type="bibr" rid="ref-28">28</xref>]. However, He [<xref ref-type="bibr" rid="ref-29">29</xref>] pointed out that Souto&#x2019;s all-or-nothing QOT protocol is not secure. A dishonest Alice can always mislead Bob into learning nothing and ensure that Bob cannot detect, because Bob checks Alice&#x2019;s loyalty only when he learns the message correctly. This vulnerability will become a serious problem when Souto&#x2019;s all-or-nothing QOT [<xref ref-type="bibr" rid="ref-27">27</xref>] is used as a building block for more complicated protocols, such as one-out-of-two QOT using Cr&#x00E9;peau&#x2019;s reduction [<xref ref-type="bibr" rid="ref-3">3</xref>]. Souto&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-30">30</xref>] responded that He&#x2019;s attack is not within the scope of the all-or-nothing OT protocol proposed by Rabin [<xref ref-type="bibr" rid="ref-1">1</xref>], and Souto thinks that a successful cheating strategy, which is one in which only one security criterion is violated, while the others are satisfied. Even so, to achieve the abovementioned security requirement, Souto constructed a semi-honest one-out-of-two QOT against malicious Alice relying on the use of their protocol and a secure bit commitment protocol. Recently, Plesch&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-31">31</xref>] agreed with He&#x2019;s viewpoint [<xref ref-type="bibr" rid="ref-29">29</xref>] that all-or-nothing QOTs with security flaws cannot be used to construct a secure one-out-of-two QOT, and introduced an improved version of the reduction protocol to remedy the weaknesses of the original protocol. This means that using Cr&#x00E9;peau&#x2019;s reduction to build a secure one-out-of-two QOT necessarily requires a perfect all-or-nothing QOT.</p></list-item>
<list-item>
<p>Cr&#x00E9;peau&#x2019;s reduction: After He&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-22">22</xref>] proved that the one-out-of-two QOT using Cr&#x00E9;peau&#x2019;s reduction [<xref ref-type="bibr" rid="ref-3">3</xref>], where the effect of Alice&#x2019;s input will be affected by Bob&#x2019;s input, is not covered by Lo&#x2019;s theorem [<xref ref-type="bibr" rid="ref-16">16</xref>], someone-out-of-two QOT protocols [<xref ref-type="bibr" rid="ref-32">32</xref>&#x2013;<xref ref-type="bibr" rid="ref-35">35</xref>] using Cr&#x00E9;peau&#x2019;s reduction were developed, and one proposed in 2017 is a flexible one-out-of-n QOT using any two non-orthogonal states. Yang&#x00A0;et&#x00A0;al.&#x00A0;[<xref ref-type="bibr" rid="ref-34">34</xref>] explained that their QOT protocol is not perfect concealing, which is the essential assumption in Lo&#x2019;s theorem. Perfect concealing means that Alice has no information about Bob&#x2019;s input, and the density matrix of Alice&#x2019;s subsystem is independent of Bob&#x2019;s measurement, so Bob can always implement an attack to read Alice&#x2019;s message determinately. This type of QOT protocol is not covered by Lo&#x2019;s theorem according to He&#x2019;s proof [<xref ref-type="bibr" rid="ref-22">22</xref>]; however, they need to spend additional quantum resources to generate classical keys by all-or-nothing OT, then use the classical keys to achieve the goal of one-out-of-two QOT. The proposed protocol is similar to this type, but it uses the quantum resource on one-out-of-two QOT directly.</p></list-item>
<list-item>
<p>Others: In addition, some QOT protocols have been proposed from different viewpoints, such as practical QOT [<xref ref-type="bibr" rid="ref-36">36</xref>], which is based on technological limitations, the weak form of QOT [<xref ref-type="bibr" rid="ref-37">37</xref>,<xref ref-type="bibr" rid="ref-38">38</xref>], which weakens the security of the definition of OT, and probability-typed QOT [<xref ref-type="bibr" rid="ref-39">39</xref>] whose communication success has some probability, etc. In 2019, He used his proof [<xref ref-type="bibr" rid="ref-22">22</xref>] to propose a practical all-or-nothing QOT protocol [<xref ref-type="bibr" rid="ref-40">40</xref>] with a single photon, which helps researchers think another way to secure computation. Some researchers [<xref ref-type="bibr" rid="ref-41">41</xref>] only showed that their QOT is not built by a bit commitment protocol and is not covered by the MLC no-go theorem [<xref ref-type="bibr" rid="ref-14">14</xref>,<xref ref-type="bibr" rid="ref-15">15</xref>], but they did not mention Lo&#x2019;s no-go theorem [<xref ref-type="bibr" rid="ref-16">16</xref>].</p></list-item>
</list></p>
<p>In order to address this complicated and challenging issue, in this paper we propose an innovative one-out-of-two QOT. Our novel ideas and main contributions are as follows.
<list list-type="alpha-lower">
<list-item>
<p>First, we discuss previous QOT protocols in detail and provide a novel idea to build a one-out-of-two QOT using Cr&#x00E9;peau&#x2019;s reduction [<xref ref-type="bibr" rid="ref-3">3</xref>], which has been proven to not rigorously satisfy the requirement of Lo&#x2019;s no-go theorem [<xref ref-type="bibr" rid="ref-16">16</xref>] in He&#x2019;s proof [<xref ref-type="bibr" rid="ref-22">22</xref>]. This means that the proposed protocol is not covered by the no-go theorem.</p></list-item>
<list-item>
<p>Second, previous one-out-of-two QOT protocols [<xref ref-type="bibr" rid="ref-32">32</xref>&#x2013;<xref ref-type="bibr" rid="ref-35">35</xref>] using Cr&#x00E9;peau&#x2019;s reduction are built upon all-or-nothing QOT, so they need to use more resources to generate classical keys for inputting Bob&#x2019;s choice. The proposed protocol improves previous limits and uses the choice of different basis to replace the way Bob chooses. Therefore, our protocol can directly establish a one-out-of-two QOT, not through an all-or-nothing QOT, which means the proposed protocol can be more efficient.</p></list-item>
<list-item>
<p>Third, the proposed protocol has the strong ability to check the sender&#x2019;s loyalty and avoid an attack from the receiver. It means that our one-out-of-two QOT protocol can prevent multiple external and internal attacks to provide significant security.</p></list-item>
<list-item>
<p>Moreover, the starting resource distribution is the sharing of a Bell state by Alice and Bob, and the Bell state is reusable because the entanglement property of the Bell state will not be destroyed at the end of this protocol. In this way, it can save more quantum resources. These reused entangled states can provide Alice and Bob to apply other entanglement services, such as teleportation [<xref ref-type="bibr" rid="ref-42">42</xref>], dense coding [<xref ref-type="bibr" rid="ref-43">43</xref>], quantum repeaters [<xref ref-type="bibr" rid="ref-44">44</xref>], quantum key distribution [<xref ref-type="bibr" rid="ref-45">45</xref>], quantum asymmetric key [<xref ref-type="bibr" rid="ref-46">46</xref>], quantum secure direct communication [<xref ref-type="bibr" rid="ref-47">47</xref>], and so on.</p></list-item>
</list></p>
</sec>
<sec id="s2">
<label>2</label>
<title>Preliminaries</title>
<p>In quantum computing, the qubit is the basic information unit. The qubits <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mn>1</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mn>0</mml:mn></mml:mtd></mml:mtr></mml:mtable><mml:mo>]</mml:mo></mml:mrow></mml:math></inline-formula> and <inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mn>0</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mn>1</mml:mn></mml:mtd></mml:mtr></mml:mtable><mml:mo>]</mml:mo></mml:mrow></mml:math></inline-formula> are a pair of basis vectors of a 2D plane in <italic>z-basis</italic>, and the other common base is <italic>x-basis</italic> {<inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:mrow><mml:mo>|</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>}, where <inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:mrow><mml:mo>|</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac></mml:mstyle><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>and <inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:mrow><mml:mo>|</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac></mml:mstyle><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. The following is an explanation of the properties of quantum mechanics, such as superposition, entanglement, quantum gates and measurement.</p>
<sec id="s2_1">
<label>2.1</label>
<title>Superposition</title>
<p>The qubit differs from the classical bit, which can only have one of two states (either 0 or 1). The qubit can be represented as multiple states at the same time. That is, when the qubit |&#x03C8;&#x3009;<inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:mo>=</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B1;</mml:mi></mml:mrow><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B2;</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> is measured in <italic>z-basis</italic>, there is <inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>&#x03B1;</mml:mi><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula> probability that the measurement result equals <inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, and <inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>&#x03B2;</mml:mi><mml:msup><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula> probability that the measurement result equals <inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>. For example, there is a <inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:mn>50</mml:mn><mml:mrow><mml:mtext>%&#xA0;</mml:mtext></mml:mrow></mml:math></inline-formula>probability that the measurement result in the <italic>z-basis</italic> of the qubit <inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:mrow><mml:mo>|</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac></mml:mstyle><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is either |0&#x3009; or |1&#x3009;.</p>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>Entanglement</title>
<p>Another powerful property in quantum mechanics is entanglement, which occurs between two or more qubits. The common and simplest example of entanglement is called a Bell state, in which two qubits are entangled with each other; the Bell states consist of four specific entangled two-qubit states, as shown in <xref ref-type="disp-formula" rid="eqn-1">Eq. (1)</xref>.</p>
<p><disp-formula id="ueqn-1"><mml:math id="mml-ueqn-1" display="block"><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>00</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>11</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-2"><mml:math id="mml-ueqn-2" display="block"><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>00</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>11</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-3"><mml:math id="mml-ueqn-3" display="block"><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>&#x03C8;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>01</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>10</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>&#x03C8;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>01</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>10</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p>An entangled state made up of more than two qubits is called a Greenberger&#x2013;Horne&#x2013;Zeilinger (GHZ) state. The proposed protocol mainly uses the two following states, <inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>G</mml:mi><mml:mi>H</mml:mi><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>G</mml:mi><mml:mi>H</mml:mi><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> shown in <xref ref-type="disp-formula" rid="eqn-2">Eqs. (2)</xref> and <xref ref-type="disp-formula" rid="eqn-3">(3)</xref>.</p>
<p><disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>G</mml:mi><mml:mi>H</mml:mi><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>111</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>G</mml:mi><mml:mi>H</mml:mi><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>011</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>101</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>110</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
</sec>
<sec id="s2_3">
<label>2.3</label>
<title>Quantum Gate</title>
<p>A quantum gate is an operation in quantum computing. There are five common basic operations, including <inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:mi>I</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mtable columnalign="center center" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mn>1</mml:mn></mml:mtd><mml:mtd><mml:mn>0</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mn>0</mml:mn></mml:mtd><mml:mtd><mml:mn>1</mml:mn></mml:mtd></mml:mtr></mml:mtable><mml:mo>]</mml:mo></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:mi>Z</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mtable columnalign="center center" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mn>1</mml:mn></mml:mtd><mml:mtd><mml:mn>0</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mn>0</mml:mn></mml:mtd><mml:mtd><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mtd></mml:mtr></mml:mtable><mml:mo>]</mml:mo></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:mi>Y</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mtable columnalign="center center" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mn>0</mml:mn></mml:mtd><mml:mtd><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mn>1</mml:mn></mml:mtd><mml:mtd><mml:mn>0</mml:mn></mml:mtd></mml:mtr></mml:mtable><mml:mo>]</mml:mo></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-37"><mml:math id="mml-ieqn-37"><mml:mi>X</mml:mi><mml:mo>=</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mtable columnalign="center center" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mn>0</mml:mn></mml:mtd><mml:mtd><mml:mn>1</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mn>1</mml:mn></mml:mtd><mml:mtd><mml:mn>0</mml:mn></mml:mtd></mml:mtr></mml:mtable><mml:mo>]</mml:mo></mml:mrow></mml:math></inline-formula> and <inline-formula id="ieqn-38"><mml:math id="mml-ieqn-38"><mml:mi>H</mml:mi><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac></mml:mstyle><mml:mrow><mml:mo>[</mml:mo><mml:mtable columnalign="center center" rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mn>1</mml:mn></mml:mtd><mml:mtd><mml:mn>1</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mn>1</mml:mn></mml:mtd><mml:mtd><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mtd></mml:mtr></mml:mtable><mml:mo>]</mml:mo></mml:mrow></mml:math></inline-formula>. The operations can be performed on one qubit to change the state of that qubit, as shown in <xref ref-type="table" rid="table-1">Tab. 1</xref>.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Examples of five common quantum gates</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Initial State</th>
<th><inline-formula id="ieqn-39"><mml:math id="mml-ieqn-39"><mml:mi>I</mml:mi></mml:math></inline-formula></th>
<th><italic>X</italic></th>
<th><italic>Y</italic></th>
<th><italic>Z</italic></th>
<th><italic>H</italic></th>
</tr>
</thead>
<tbody>
<tr>
<td><inline-formula id="ieqn-40"><mml:math id="mml-ieqn-40"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-41"><mml:math id="mml-ieqn-41"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-42"><mml:math id="mml-ieqn-42"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-43"><mml:math id="mml-ieqn-43"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-44"><mml:math id="mml-ieqn-44"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-45"><mml:math id="mml-ieqn-45"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-46"><mml:math id="mml-ieqn-46"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-47"><mml:math id="mml-ieqn-47"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-48"><mml:math id="mml-ieqn-48"><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-49"><mml:math id="mml-ieqn-49"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-50"><mml:math id="mml-ieqn-50"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-51"><mml:math id="mml-ieqn-51"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-52"><mml:math id="mml-ieqn-52"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-53"><mml:math id="mml-ieqn-53"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-54"><mml:math id="mml-ieqn-54"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-55"><mml:math id="mml-ieqn-55"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-56"><mml:math id="mml-ieqn-56"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-57"><mml:math id="mml-ieqn-57"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-58"><mml:math id="mml-ieqn-58"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-59"><mml:math id="mml-ieqn-59"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-60"><mml:math id="mml-ieqn-60"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-61"><mml:math id="mml-ieqn-61"><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-62"><mml:math id="mml-ieqn-62"><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-63"><mml:math id="mml-ieqn-63"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s2_4">
<label>2.4</label>
<title>Controlled-not Gate (CNot)</title>
<p>In addition to the above five basic operations, the proposed protocol also uses the controlled-not gate. The controlled-not gate acts on two or more qubits, and consists of control bits and a target bit. Controlled-not gates most commonly operate in <italic>z-basis</italic> (<inline-formula id="ieqn-64"><mml:math id="mml-ieqn-64"><mml:mi>Z</mml:mi><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>) as follows: if the control bit <italic>a</italic> is <inline-formula id="ieqn-65"><mml:math id="mml-ieqn-65"><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, the target bit <italic>b</italic> maintains its state; if the control bit <italic>a</italic> is <inline-formula id="ieqn-66"><mml:math id="mml-ieqn-66"><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, the target bit <italic>b</italic> reverses its state. For example, if the control bit <italic>a</italic> is <inline-formula id="ieqn-67"><mml:math id="mml-ieqn-67"><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, the state of target bit <italic>b</italic> will become <inline-formula id="ieqn-68"><mml:math id="mml-ieqn-68"><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula> from <inline-formula id="ieqn-69"><mml:math id="mml-ieqn-69"><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, or become <inline-formula id="ieqn-70"><mml:math id="mml-ieqn-70"><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula> from <inline-formula id="ieqn-71"><mml:math id="mml-ieqn-71"><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, as shown in <xref ref-type="disp-formula" rid="eqn-4">Eq. (4)</xref>. Similarly, a controlled-not gate operating in <italic>x-basis</italic> (<inline-formula id="ieqn-72"><mml:math id="mml-ieqn-72"><mml:mi>X</mml:mi><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>) can change the target bit <italic>b</italic> from <inline-formula id="ieqn-73"><mml:math id="mml-ieqn-73"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> to <inline-formula id="ieqn-74"><mml:math id="mml-ieqn-74"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> or change it from <inline-formula id="ieqn-75"><mml:math id="mml-ieqn-75"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> to <inline-formula id="ieqn-76"><mml:math id="mml-ieqn-76"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula> if the control bit <italic>a</italic> is <inline-formula id="ieqn-77"><mml:math id="mml-ieqn-77"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo></mml:math></inline-formula>, as shown in <xref ref-type="disp-formula" rid="eqn-5">Eq. (5)</xref>. A controlled-not gate can easily create and release the entanglement property, as shown in <xref ref-type="disp-formula" rid="eqn-4">Eqs. (4)</xref> and <xref ref-type="disp-formula" rid="eqn-5">(5)</xref>. If controlled-not gate is performed two times continuously, the result would equal to do nothing as <inline-formula id="ieqn-78"><mml:math id="mml-ieqn-78"><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mo>&#x22C5;</mml:mo><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mo>=</mml:mo><mml:mi>I</mml:mi></mml:math></inline-formula>. This is because the controlled-not gate is a unitary operator <inline-formula id="ieqn-79"><mml:math id="mml-ieqn-79"><mml:mi>U</mml:mi><mml:msup><mml:mi>U</mml:mi><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:mi>I</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-80"><mml:math id="mml-ieqn-80"><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mo>=</mml:mo><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:msup><mml:mi>t</mml:mi><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup></mml:math></inline-formula>.</p>
<p><disp-formula id="ueqn-7"><mml:math id="mml-ueqn-7" display="block"><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>00</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>10</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="eqn-4"><label>(4)</label><mml:math id="mml-eqn-4" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>00</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>11</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-9"><mml:math id="mml-ueqn-9" display="block"><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="eqn-5"><label>(5)</label><mml:math id="mml-eqn-5" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
</sec>
<sec id="s2_5">
<label>2.5</label>
<title>Bell Measurement and GHZ Measurement</title>
<p>There are four Bell states: <inline-formula id="ieqn-81"><mml:math id="mml-ieqn-81"><mml:mrow><mml:mo>|</mml:mo><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-82"><mml:math id="mml-ieqn-82"><mml:mrow><mml:mo>|</mml:mo><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-83"><mml:math id="mml-ieqn-83"><mml:mrow><mml:mo>|</mml:mo><mml:msup><mml:mi>&#x03C8;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, and <inline-formula id="ieqn-84"><mml:math id="mml-ieqn-84"><mml:mrow><mml:mo>|</mml:mo><mml:mi mathvariant="normal">&#x03A8;</mml:mi><mml:msup><mml:mi>&#x03C8;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, and Bell measurement is used to distinguish these Bell states. Bell measurement consists of two quantum gates, including a controlled-not (<inline-formula id="ieqn-85"><mml:math id="mml-ieqn-85"><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow></mml:math></inline-formula>) gate in <italic>z-basis</italic> and a Hadamard (<italic>H</italic>) gate. In <italic>z-basis</italic>, the Bell measurement results of <inline-formula id="ieqn-86"><mml:math id="mml-ieqn-86"><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-87"><mml:math id="mml-ieqn-87"><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-88"><mml:math id="mml-ieqn-88"><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>&#x03C8;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-89"><mml:math id="mml-ieqn-89"><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>&#x03C8;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> are &#x201C;00&#x201D;, &#x201C;01&#x201D;, &#x201C;10&#x201D; and &#x201C;11&#x201D;, respectively. For example, Bell measurement is performed on the Bell state <inline-formula id="ieqn-90"><mml:math id="mml-ieqn-90"><mml:msub><mml:mrow><mml:mo>|</mml:mo><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>00</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>11</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. First, the <inline-formula id="ieqn-91"><mml:math id="mml-ieqn-91"><mml:mi>Z</mml:mi><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> gate is performed, where qubit <inline-formula id="ieqn-92"><mml:math id="mml-ieqn-92"><mml:mi>a</mml:mi></mml:math></inline-formula> is the control bit and qubit <inline-formula id="ieqn-93"><mml:math id="mml-ieqn-93"><mml:mi>b</mml:mi></mml:math></inline-formula> is the target bit. Then, the <inline-formula id="ieqn-94"><mml:math id="mml-ieqn-94"><mml:msub><mml:mi>H</mml:mi><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> gate is performed on qubit <inline-formula id="ieqn-95"><mml:math id="mml-ieqn-95"><mml:mi>a</mml:mi></mml:math></inline-formula>, and the measurement result is &#x201C;00&#x201D;, as shown in <xref ref-type="disp-formula" rid="eqn-6">Eq. (6)</xref>.</p>
<p><disp-formula id="eqn-6"><label>(6)</label><mml:math id="mml-eqn-6" display="block"><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>00</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>11</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>00</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>10</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub></mml:mover><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>00</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p>The GHZ measurement serves to distinguish the GHZ states, and the gates performing on <inline-formula id="ieqn-96"><mml:math id="mml-ieqn-96"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>G</mml:mi><mml:mi>H</mml:mi><mml:mi>Z</mml:mi><mml:msub><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mo>&#x2026;</mml:mo><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> are <inline-formula id="ieqn-97"><mml:math id="mml-ieqn-97"><mml:mi>Z</mml:mi><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-98"><mml:math id="mml-ieqn-98"><mml:mi>Z</mml:mi><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, &#x2026;, <inline-formula id="ieqn-99"><mml:math id="mml-ieqn-99"><mml:mi>Z</mml:mi><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>n</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-100"><mml:math id="mml-ieqn-100"><mml:msub><mml:mrow><mml:mtext>H</mml:mtext></mml:mrow><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. For example, the GHZ measurement result of <inline-formula id="ieqn-101"><mml:math id="mml-ieqn-101"><mml:msub><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mtext>GHZ</mml:mtext></mml:mrow><mml:mrow><mml:mi>Z</mml:mi></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is &#x201C;000&#x201D; in <italic>z-basis</italic>, as shown in <xref ref-type="disp-formula" rid="eqn-7">Eq. (7)</xref>.</p>
<p><disp-formula id="ueqn-12"><mml:math id="mml-ueqn-12" display="block"><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>G</mml:mi><mml:mi>H</mml:mi><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>111</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>101</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="eqn-7"><label>(7)</label><mml:math id="mml-eqn-7" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>100</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub></mml:mover><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>Basic Idea</title>
<p>This section briefly introduces the basic idea of the proposed one-out-of-two QOT protocol. That is, this section will only discuss the easiest case in which both <inline-formula id="ieqn-102"><mml:math id="mml-ieqn-102"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-103"><mml:math id="mml-ieqn-103"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> are only one bit messages; both Alice and Bob are honest, and their channel is free of external eavesdroppers. The qubit in a different state is immune to different quantum operations, as shown in <xref ref-type="table" rid="table-1">Tab. 1</xref>. For example, in <italic>z-basis</italic>, operations <italic>X</italic> and <inline-formula id="ieqn-104"><mml:math id="mml-ieqn-104"><mml:mi>Y</mml:mi></mml:math></inline-formula> can change the qubit <inline-formula id="ieqn-105"><mml:math id="mml-ieqn-105"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula> to <inline-formula id="ieqn-106"><mml:math id="mml-ieqn-106"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, but operations <italic>I</italic> and <italic>Z</italic> cannot, that is, the qubit with <italic>z-basis</italic> is immune to operations <italic>I</italic> and <italic>Z</italic>. On the other hand, the qubit with <italic>x-basis</italic> is immune to operations <italic>I</italic> and <italic>X</italic>. The proposed protocol utilizes the property of immunity to achieve the goal of one-out-of-two OT. The basic idea of the proposed one-out-of-two QOT protocol is described below:
<list list-type="roman-lower">
<list-item><label>Step B1.</label><p>Alice shares a Bell state <inline-formula id="ieqn-107"><mml:math id="mml-ieqn-107"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup></mml:mrow><mml:msub><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> with Bob. The qubit in Alice&#x2019;s hand is <inline-formula id="ieqn-108"><mml:math id="mml-ieqn-108"><mml:mi>a</mml:mi></mml:math></inline-formula>, and the other qubit in Bob&#x2019;s hand is <inline-formula id="ieqn-109"><mml:math id="mml-ieqn-109"><mml:mi>b</mml:mi></mml:math></inline-formula>, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>&#x2460;.</p></list-item>
<list-item><label>Step B2.</label><p>Bob makes a choice <inline-formula id="ieqn-110"><mml:math id="mml-ieqn-110"><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> as to which message <inline-formula id="ieqn-111"><mml:math id="mml-ieqn-111"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> he wants to receive from Alice, and then prepares a single qubit <inline-formula id="ieqn-112"><mml:math id="mml-ieqn-112"><mml:mi>c</mml:mi></mml:math></inline-formula> according to <inline-formula id="ieqn-113"><mml:math id="mml-ieqn-113"><mml:mi>j</mml:mi></mml:math></inline-formula>, and performs the <inline-formula id="ieqn-114"><mml:math id="mml-ieqn-114"><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> operation, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1a</xref> &#x2461;. When <inline-formula id="ieqn-115"><mml:math id="mml-ieqn-115"><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>, Bob prepares the qubit <inline-formula id="ieqn-116"><mml:math id="mml-ieqn-116"><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula> with the <italic>z-basis</italic>, and performs the <inline-formula id="ieqn-117"><mml:math id="mml-ieqn-117"><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> operation, as shown in <xref ref-type="disp-formula" rid="eqn-8">Eq. (8)</xref>, where Bob wants to learn <inline-formula id="ieqn-118"><mml:math id="mml-ieqn-118"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>. On the other hand, when <inline-formula id="ieqn-119"><mml:math id="mml-ieqn-119"><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, Bob prepares the qubit <inline-formula id="ieqn-120"><mml:math id="mml-ieqn-120"><mml:mrow><mml:mo>|</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula> with the <italic>x-basis</italic>, and performs the <inline-formula id="ieqn-121"><mml:math id="mml-ieqn-121"><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> operation, as shown in <xref ref-type="disp-formula" rid="eqn-9">Eq. (9)</xref>. Then, Bob sends qubit <inline-formula id="ieqn-122"><mml:math id="mml-ieqn-122"><mml:mi mathvariant="bold-italic">b</mml:mi></mml:math></inline-formula> to Alice, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1a</xref> &#x2462;.</p></list-item>
<list-item><label>Step B3.</label><p>Once Alice receives qubit <inline-formula id="ieqn-123"><mml:math id="mml-ieqn-123"><mml:mi>b</mml:mi></mml:math></inline-formula> from Bob, and performs one of the <italic>I</italic>, <italic>Z</italic>, <italic>X</italic> or <italic>Y</italic> operations on qubit <inline-formula id="ieqn-124"><mml:math id="mml-ieqn-124"><mml:mi>a</mml:mi></mml:math></inline-formula> or qubit <inline-formula id="ieqn-125"><mml:math id="mml-ieqn-125"><mml:mi>b</mml:mi></mml:math></inline-formula> randomly, according to her messages <inline-formula id="ieqn-126"><mml:math id="mml-ieqn-126"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-127"><mml:math id="mml-ieqn-127"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1b</xref> &#x2463;. The <italic>I</italic>, <italic>Z</italic>, <italic>X</italic> and <italic>Y</italic> operations indicate that Alice&#x2019;s messages <inline-formula id="ieqn-128"><mml:math id="mml-ieqn-128"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-129"><mml:math id="mml-ieqn-129"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, are &#x201C;00&#x201D;, &#x201C;01&#x201D;, &#x201C;10&#x201D; and &#x201C;11&#x201D;, respectively. Alice then sends the qubit performed operation to Bob, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1b</xref> &#x2464;. For example, it is present that Alice&#x2019;s messages, <inline-formula id="ieqn-130"><mml:math id="mml-ieqn-130"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula> and <inline-formula id="ieqn-131"><mml:math id="mml-ieqn-131"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, when she performs the <italic>Z</italic> operation on qubit <italic>b</italic>, as shown in <xref ref-type="disp-formula" rid="eqn-8">Eq. (8)</xref>.</p></list-item>
<list-item><label>Step B4.</label><p>On receiving qubit <inline-formula id="ieqn-132"><mml:math id="mml-ieqn-132"><mml:mi>a</mml:mi></mml:math></inline-formula> or <inline-formula id="ieqn-133"><mml:math id="mml-ieqn-133"><mml:mi>b</mml:mi></mml:math></inline-formula> from Alice, Bob performs the controlled-not <inline-formula id="ieqn-134"><mml:math id="mml-ieqn-134"><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> or <inline-formula id="ieqn-135"><mml:math id="mml-ieqn-135"><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> operation, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1c</xref> &#x2465;. (<inline-formula id="ieqn-136"><mml:math id="mml-ieqn-136"><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> &#x003D; <inline-formula id="ieqn-137"><mml:math id="mml-ieqn-137"><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> when <inline-formula id="ieqn-138"><mml:math id="mml-ieqn-138"><mml:mi>j</mml:mi><mml:mo>=</mml:mo></mml:math></inline-formula> 0, and <inline-formula id="ieqn-139"><mml:math id="mml-ieqn-139"><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mrow><mml:mi>a</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>&#x003D;<inline-formula id="ieqn-140"><mml:math id="mml-ieqn-140"><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> when <inline-formula id="ieqn-141"><mml:math id="mml-ieqn-141"><mml:mi>j</mml:mi><mml:mo>=</mml:mo></mml:math></inline-formula> 1; the same rule applies to <inline-formula id="ieqn-142"><mml:math id="mml-ieqn-142"><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>.) The controlled-not gate can bring the influence of Alice&#x2019;s operation into qubit <inline-formula id="ieqn-143"><mml:math id="mml-ieqn-143"><mml:mi>c</mml:mi></mml:math></inline-formula> and release the entangled relationship between qubit <inline-formula id="ieqn-144"><mml:math id="mml-ieqn-144"><mml:mi>c</mml:mi></mml:math></inline-formula> and the Bell state consisting of qubits <inline-formula id="ieqn-145"><mml:math id="mml-ieqn-145"><mml:mi>a</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-146"><mml:math id="mml-ieqn-146"><mml:mi>b</mml:mi></mml:math></inline-formula>. In <xref ref-type="disp-formula" rid="eqn-8">Eq. (8)</xref>, <inline-formula id="ieqn-147"><mml:math id="mml-ieqn-147"><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>, Bob performs <inline-formula id="ieqn-148"><mml:math id="mml-ieqn-148"><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, and the influence of Alice&#x2019;s operation affects the qubit <inline-formula id="ieqn-149"><mml:math id="mml-ieqn-149"><mml:mi>c</mml:mi></mml:math></inline-formula>, but the entanglement property of the Bell state is not destroyed.</p></list-item>
<list-item><label>Step B5.</label><p>Bob measures qubit <inline-formula id="ieqn-150"><mml:math id="mml-ieqn-150"><mml:mi>c</mml:mi></mml:math></inline-formula> with the <italic>z-basis</italic> {<inline-formula id="ieqn-151"><mml:math id="mml-ieqn-151"><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>} when <inline-formula id="ieqn-152"><mml:math id="mml-ieqn-152"><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>, or with the <italic>x-basis</italic> {<inline-formula id="ieqn-153"><mml:math id="mml-ieqn-153"><mml:mrow><mml:mo>|</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>} when <inline-formula id="ieqn-154"><mml:math id="mml-ieqn-154"><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1d</xref> &#x2466;. Bob can obtain message <inline-formula id="ieqn-155"><mml:math id="mml-ieqn-155"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, which he chose in <italic>Step B2</italic>, if the measurement result is <inline-formula id="ieqn-156"><mml:math id="mml-ieqn-156"><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula> or <inline-formula id="ieqn-157"><mml:math id="mml-ieqn-157"><mml:mrow><mml:mo>|</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, message <inline-formula id="ieqn-158"><mml:math id="mml-ieqn-158"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>; if the measurement result is <inline-formula id="ieqn-159"><mml:math id="mml-ieqn-159"><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula> or <inline-formula id="ieqn-160"><mml:math id="mml-ieqn-160"><mml:mrow><mml:mo>|</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, message <inline-formula id="ieqn-161"><mml:math id="mml-ieqn-161"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>. In <xref ref-type="disp-formula" rid="eqn-8">Eq. (8)</xref>, <inline-formula id="ieqn-162"><mml:math id="mml-ieqn-162"><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo></mml:math></inline-formula> after Bob measures the qubit <inline-formula id="ieqn-163"><mml:math id="mml-ieqn-163"><mml:mi>c</mml:mi></mml:math></inline-formula> with <italic>z-basis</italic>, and obtains the measurement result <inline-formula id="ieqn-164"><mml:math id="mml-ieqn-164"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>. He learns <inline-formula id="ieqn-165"><mml:math id="mml-ieqn-165"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>0.</mml:mn></mml:math></inline-formula></p></list-item>
<list-item><label>Step B6. (Reusable)</label><p>Through the above steps, the communication for one-out-of-two QOT between Alice and Bob is complete. It is worth noting that the controlled-not gate is used to transfer the influence of Alice&#x2019;s operation into qubit <inline-formula id="ieqn-166"><mml:math id="mml-ieqn-166"><mml:mi>c</mml:mi></mml:math></inline-formula>; it does not destroy the entanglement property of the Bell state. Therefore, the Bell state can be reused after adjustment. If Alice and Bob want to start the next communication, Alice simply needs to perform the same operation as in <italic>Step B3</italic> to adjust the Bell state to return to <inline-formula id="ieqn-167"><mml:math id="mml-ieqn-167"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup></mml:mrow><mml:msub><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>.</mml:mo></mml:math></inline-formula></p></list-item></list></p>
<p>For clarity, another example is given to show the process of the proposed protocol. In <xref ref-type="disp-formula" rid="eqn-9">Eq. (9)</xref>, Alice&#x2019;s message, <inline-formula id="ieqn-168"><mml:math id="mml-ieqn-168"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-169"><mml:math id="mml-ieqn-169"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, is still &#x201C;01&#x201D;, but Bob wants to learn the message <inline-formula id="ieqn-170"><mml:math id="mml-ieqn-170"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>.</p>
<p><disp-formula id="ueqn-14"><mml:math id="mml-ueqn-14" display="block"><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>00</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>11</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>110</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-15"><mml:math id="mml-ueqn-15" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>111</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>111</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="eqn-8"><label>(8)</label><mml:math id="mml-eqn-8" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>110</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>00</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>11</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-17"><mml:math id="mml-ueqn-17" display="block"><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-18"><mml:math id="mml-ueqn-18" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="eqn-9"><label>(9)</label><mml:math id="mml-eqn-9" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>The steps of the basic idea. (a) Step B1 and Step B2, (b) Step B3, (c) Step B4, (d) Step B5</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_32320-fig-1.png"/>
</fig>
</sec>
<sec id="s4">
<label>4</label>
<title>Relationship with the No-go Theorems</title>
<p>It is important at this point to discuss the relationship between this protocol and the no-go theorems, including the MLC no-go theorem [<xref ref-type="bibr" rid="ref-8">8</xref>,<xref ref-type="bibr" rid="ref-9">9</xref>] and Lo&#x2019;s no-go theorem [<xref ref-type="bibr" rid="ref-10">10</xref>]. In the MLC no-go theorem, it is considered that all QOT protocols based on QBC are not secure because an unconditionally secure QBC is not possible. However, the proposed protocol is not based on QBC, so this section focuses on Lo&#x2019;s no-go theorem. It then uses the viewpoint in He&#x2019;s proof about Cr&#x00E9;peau&#x2019;s reduction to show that the proposed protocol can avoid the strategy in Lo&#x2019;s no-go theorem.</p>
<p>Lo&#x2019;s no-go theorem proves that any protocol is insecure if it satisfies the definition of the ideal one-side two-party secure computation, which is described in Definition A. In a secure computation, suppose Alice has a private (i.e., secret) input <inline-formula id="ieqn-171"><mml:math id="mml-ieqn-171"><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>n</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, Bob has a private input <inline-formula id="ieqn-172"><mml:math id="mml-ieqn-172"><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>m</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, and Alice helps Bob compute a prescribed function <inline-formula id="ieqn-173"><mml:math id="mml-ieqn-173"><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:mi>r</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>. According to Lo&#x2019;s cheating strategy, Bob can change the value of <inline-formula id="ieqn-174"><mml:math id="mml-ieqn-174"><mml:mi>j</mml:mi></mml:math></inline-formula> from <inline-formula id="ieqn-175"><mml:math id="mml-ieqn-175"><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> to <inline-formula id="ieqn-176"><mml:math id="mml-ieqn-176"><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> by applying a unitary transformation to his own quantum machine; he can then learn <inline-formula id="ieqn-177"><mml:math id="mml-ieqn-177"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-178"><mml:math id="mml-ieqn-178"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>.</p>
<p>However, He&#x2019;s proof [<xref ref-type="bibr" rid="ref-6">6</xref>] showed that Lo&#x2019;s no-go theorem only considered a situation of rigorous one-out-of-two OT, whose definition is described in Definition B. According to He&#x2019;s proof, in the one-out-of-two QOT using Cr&#x00E9;peau&#x2019;s reduction [<xref ref-type="bibr" rid="ref-3">3</xref>] described in Definition C, Alice&#x2019;s input <inline-formula id="ieqn-179"><mml:math id="mml-ieqn-179"><mml:mi>i</mml:mi></mml:math></inline-formula> will vary according to Bob&#x2019;s input <inline-formula id="ieqn-180"><mml:math id="mml-ieqn-180"><mml:mi>j</mml:mi></mml:math></inline-formula>, and its value is not determined until Bob&#x2019;s input has been completed. Therefore, the one-out-of-two OT using Cr&#x00E9;peau&#x2019;s reduction does not satisfy the rigorous one-out-of-two OT because the function should be <inline-formula id="ieqn-181"><mml:math id="mml-ieqn-181"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>, not <inline-formula id="ieqn-182"><mml:math id="mml-ieqn-182"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>. As a result, after Bob inputs <inline-formula id="ieqn-183"><mml:math id="mml-ieqn-183"><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula> and learns the message <inline-formula id="ieqn-184"><mml:math id="mml-ieqn-184"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, Bob cannot learn the other message by changing the value from <inline-formula id="ieqn-185"><mml:math id="mml-ieqn-185"><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> to <inline-formula id="ieqn-186"><mml:math id="mml-ieqn-186"><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> because the value <inline-formula id="ieqn-187"><mml:math id="mml-ieqn-187"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> is meaningless. If Bob wants to learn the other message <inline-formula id="ieqn-188"><mml:math id="mml-ieqn-188"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>, he must change the value of <inline-formula id="ieqn-189"><mml:math id="mml-ieqn-189"><mml:mi>i</mml:mi></mml:math></inline-formula> from <inline-formula id="ieqn-190"><mml:math id="mml-ieqn-190"><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> to <inline-formula id="ieqn-191"><mml:math id="mml-ieqn-191"><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>. However, this is impossible without Alice&#x2019;s help, so Bob&#x2019;s strategy will not succeed alone. Consequently, the one-out-of-two QOT using Cr&#x00E9;peau&#x2019;s reduction is not covered by Lo&#x2019;s cheating strategy.</p>
<p><bold>Definition A: ideal one-side two-party secure computation</bold></p>
<p><bold>(1)</bold> Bob learns <inline-formula id="ieqn-192"><mml:math id="mml-ieqn-192"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> unambiguously.</p>
<p><bold>(2)</bold> Alice learns nothing about <inline-formula id="ieqn-193"><mml:math id="mml-ieqn-193"><mml:mi>j</mml:mi></mml:math></inline-formula> or <inline-formula id="ieqn-194"><mml:math id="mml-ieqn-194"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>.</mml:mo></mml:math></inline-formula></p>
<p><bold>(3)</bold> Bob learns nothing about <inline-formula id="ieqn-195"><mml:math id="mml-ieqn-195"><mml:mi>i</mml:mi></mml:math></inline-formula> more than it logically follows from the values of <inline-formula id="ieqn-196"><mml:math id="mml-ieqn-196"><mml:mi>j</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-197"><mml:math id="mml-ieqn-197"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>.</p>
<p><bold>Definition B: rigorous one-out-of-two OT</bold></p>
<p><bold>(1)</bold> Alice inputs <inline-formula id="ieqn-198"><mml:math id="mml-ieqn-198"><mml:mi>i</mml:mi></mml:math></inline-formula>, which is a pair of messages <inline-formula id="ieqn-199"><mml:math id="mml-ieqn-199"><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>.</p>
<p><bold>(2)</bold> Bob inputs <inline-formula id="ieqn-200"><mml:math id="mml-ieqn-200"><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula> or <inline-formula id="ieqn-201"><mml:math id="mml-ieqn-201"><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>.</p>
<p><bold>(3)</bold> At the end of the protocol, Bob learns about the message <inline-formula id="ieqn-202"><mml:math id="mml-ieqn-202"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>, but not the other message <inline-formula id="ieqn-203"><mml:math id="mml-ieqn-203"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mover><mml:mi>J</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover></mml:mrow></mml:msub></mml:math></inline-formula>, i.e., the protocol is an ideal one-side two-party secure computation <inline-formula id="ieqn-204"><mml:math id="mml-ieqn-204"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-205"><mml:math id="mml-ieqn-205"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>.</p>
<p><bold>(4)</bold> Alice does not know which <inline-formula id="ieqn-206"><mml:math id="mml-ieqn-206"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> Bob learned.</p>
<p><bold>Definition C: One-out-of-two OT using Cr&#x00E9;peau&#x2019;s reduction</bold></p>
<p><bold>(1)</bold> Bob inputs <inline-formula id="ieqn-207"><mml:math id="mml-ieqn-207"><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula> or <inline-formula id="ieqn-208"><mml:math id="mml-ieqn-208"><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>.</p>
<p><bold>(2)</bold> Alice inputs <inline-formula id="ieqn-209"><mml:math id="mml-ieqn-209"><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, where Alice&#x2019;s input <inline-formula id="ieqn-210"><mml:math id="mml-ieqn-210"><mml:mi>i</mml:mi></mml:math></inline-formula> will vary according to Bob&#x2019;s input <inline-formula id="ieqn-211"><mml:math id="mml-ieqn-211"><mml:mi>j</mml:mi></mml:math></inline-formula>.</p>
<p><bold>(3)</bold> At the end of the protocol, Bob learns about the message <inline-formula id="ieqn-212"><mml:math id="mml-ieqn-212"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> but not the other message <inline-formula id="ieqn-213"><mml:math id="mml-ieqn-213"><mml:msub><mml:mrow><mml:mtext>m</mml:mtext></mml:mrow><mml:mrow><mml:mover><mml:mi>J</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mover><mml:mi>J</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mover><mml:mi>J</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>.</p>
<p><bold>(4)</bold> Alice does not know which <inline-formula id="ieqn-214"><mml:math id="mml-ieqn-214"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> Bob learned.</p>
<p>The proposed protocol is similar to Cr&#x00E9;peau&#x2019;s reduction; the function is also <inline-formula id="ieqn-215"><mml:math id="mml-ieqn-215"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>, but not <inline-formula id="ieqn-216"><mml:math id="mml-ieqn-216"><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Bob must input the value of <inline-formula id="ieqn-217"><mml:math id="mml-ieqn-217"><mml:mi>j</mml:mi></mml:math></inline-formula> before Alice inputs her messages, and the effect of Alice&#x0027;s input will be affected by <inline-formula id="ieqn-218"><mml:math id="mml-ieqn-218"><mml:mi>j</mml:mi></mml:math></inline-formula>. As the situation where Alice&#x0027;s messages <inline-formula id="ieqn-219"><mml:math id="mml-ieqn-219"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-220"><mml:math id="mml-ieqn-220"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, are &#x201C;01&#x201D; in <xref ref-type="disp-formula" rid="eqn-8">Eq. (8)</xref> and <xref ref-type="disp-formula" rid="eqn-9">Eq. (9)</xref>, the entangled state is <inline-formula id="ieqn-221"><mml:math id="mml-ieqn-221"><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac></mml:mstyle><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>111</mml:mn><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> when Bob inputs <inline-formula id="ieqn-222"><mml:math id="mml-ieqn-222"><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>; conversely, the entangled state is <inline-formula id="ieqn-223"><mml:math id="mml-ieqn-223"><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac></mml:mstyle><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mo>+</mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> when Bob inputs <inline-formula id="ieqn-224"><mml:math id="mml-ieqn-224"><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>.</p>
<p>According to Lo&#x2019;s theorem, Alice&#x2019;s input and Bob&#x2019;s input are independent in rigorous one-out-of-two OT, <inline-formula id="ieqn-225"><mml:math id="mml-ieqn-225"><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> so the result will be the same, whoever inputs first, Alice or Bob. After learning <inline-formula id="ieqn-226"><mml:math id="mml-ieqn-226"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula>, Bob can always find the inverse operation <inline-formula id="ieqn-227"><mml:math id="mml-ieqn-227"><mml:msubsup><mml:mi>U</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup></mml:math></inline-formula>to clear <inline-formula id="ieqn-228"><mml:math id="mml-ieqn-228"><mml:mi>j</mml:mi></mml:math></inline-formula> by himself, and then perform <inline-formula id="ieqn-229"><mml:math id="mml-ieqn-229"><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mover><mml:mi>J</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover></mml:mrow></mml:msub></mml:math></inline-formula> to learn the other message <inline-formula id="ieqn-230"><mml:math id="mml-ieqn-230"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mover><mml:mi>J</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mover><mml:mi>J</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-231"><mml:math id="mml-ieqn-231"><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mover><mml:mi>J</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>U</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mover><mml:mi>J</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. However, He&#x2019;s proof showed that Lo&#x2019;s theorem does not cover the one-out-of-two OT using Cr&#x00E9;peau&#x2019;s reduction, in which Alice&#x2019;s input <inline-formula id="ieqn-232"><mml:math id="mml-ieqn-232"><mml:mi>i</mml:mi></mml:math></inline-formula> will vary according to Bob&#x2019;s input <inline-formula id="ieqn-233"><mml:math id="mml-ieqn-233"><mml:mi>j</mml:mi></mml:math></inline-formula>. That is Alice&#x2019;s input and Bob&#x2019;s input are dependent, <inline-formula id="ieqn-234"><mml:math id="mml-ieqn-234"><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2260;</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, and if Bob uses Lo&#x2019;s strategy, he will learn a meaningless value <inline-formula id="ieqn-235"><mml:math id="mml-ieqn-235"><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mi>i</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>j</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mover><mml:mi>J</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> because <inline-formula id="ieqn-236"><mml:math id="mml-ieqn-236"><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mover><mml:mi>J</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msubsup><mml:mi>U</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2260;</mml:mo><mml:mrow><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mover><mml:mi>J</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover></mml:mrow></mml:msub></mml:math></inline-formula>. In the proposed protocol, <inline-formula id="ieqn-237"><mml:math id="mml-ieqn-237"><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2260;</mml:mo><mml:mrow><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mover><mml:mi>J</mml:mi><mml:mo accent="false">&#x00AF;</mml:mo></mml:mover></mml:mrow></mml:msub></mml:math></inline-formula> when Alice performs the <italic>Z</italic>, <italic>X</italic> or <italic>Y</italic> operation. For example, Bob inputs his choice before Alice inputs her message, and Bob can learn <inline-formula id="ieqn-238"><mml:math id="mml-ieqn-238"><mml:mo>,</mml:mo><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow></mml:mrow></mml:msub></mml:math></inline-formula> correctly, as shown in <xref ref-type="disp-formula" rid="eqn-9">Eq. (9)</xref>. In contrast, if Alice inputs her message before Bob makes his choice, Bob will learn nothing about the message, as shown in <xref ref-type="disp-formula" rid="eqn-10">Eq. (10)</xref>. (Because the controlled-not gate is performed twice continuously, the result will equal doing nothing as <italic>CNot</italic><inline-formula id="ieqn-239"><mml:math id="mml-ieqn-239"><mml:mo>&#x22C5;</mml:mo></mml:math></inline-formula><italic>CNot</italic> <inline-formula id="ieqn-240"><mml:math id="mml-ieqn-240"><mml:mo>=</mml:mo></mml:math></inline-formula><italic>I</italic>, so it cannot bring the influence from Alice&#x2019;s operation into qubit <italic>c</italic>, Bob cannot learn any information.) Therefore, the proposed protocol, like the one-out-of-two OT using Cr&#x00E9;peau&#x2019;s reduction in He&#x2019;s proof, is secure against Lo&#x2019;s cheating strategy. The proposed protocol utilizes the quantum property to implement the result using Cr&#x00E9;peau&#x2019;s reduction, which means it is simpler and more efficient.</p>
<p><disp-formula id="ueqn-20"><mml:math id="mml-ueqn-20" display="block"><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-21"><mml:math id="mml-ueqn-21" display="block"><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-22"><mml:math id="mml-ueqn-22" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="eqn-10"><label>(10)</label><mml:math id="mml-eqn-10" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
</sec>
<sec id="s5">
<label>5</label>
<title>The Proposed Protocol</title>
<p>The starting point of the protocol is the sharing of a Bell state <inline-formula id="ieqn-241"><mml:math id="mml-ieqn-241"><mml:mrow><mml:mo>|</mml:mo><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula> by Alice and Bob, as with many of the existing protocols, such as: the protocols in quantum teleportation, quantum dense coding, quantum repeater, quantum key distribution, quantum asymmetric key and quantum secure direct communication. This kind of start is flexible, and not limited to only one service between Alice and Bob. Furthermore, the entanglement property of the Bell state will not be destroyed at the end of this QOT protocol, so it can be reused. Moreover, secure one-out-of-two QOT must guarantee that Bob can only learn one of Alice&#x2019;s messages, and ensure that Alice cannot learn Bob&#x2019;s choice and choose which message Bob learns. In the proposed protocol, Bob can check Alice&#x2019;s loyalty to avoid attacking, and Bob only can learn one of Alice&#x2019;s messages certainly.</p>
<p>This section discusses the details of the one-out-of-two QOT protocol, which is based on the basic idea described in the previous section, and includes channel checking, in which we use the decoy qubits [<xref ref-type="bibr" rid="ref-48">48</xref>] to find the external eavesdroppers. Alice transfers one of two <inline-formula id="ieqn-242"><mml:math id="mml-ieqn-242"><mml:mi>k</mml:mi></mml:math></inline-formula>-bit messages, <inline-formula id="ieqn-243"><mml:math id="mml-ieqn-243"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msubsup><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> and <inline-formula id="ieqn-244"><mml:math id="mml-ieqn-244"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msubsup><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msubsup><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, to Bob. The detailed steps are as follows:</p>
<p><list list-type="roman-lower">
<list-item><label>Step P1.</label><p>Alice shares <inline-formula id="ieqn-245"><mml:math id="mml-ieqn-245"><mml:mi>k</mml:mi></mml:math></inline-formula> Bell states <inline-formula id="ieqn-246"><mml:math id="mml-ieqn-246"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup></mml:mrow><mml:msub><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> with Bob, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1a</xref> &#x2460;. We call the qubit sequence in Alice&#x2019;s hand <inline-formula id="ieqn-247"><mml:math id="mml-ieqn-247"><mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mrow><mml:mtext>a</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>a</mml:mtext></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>a</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>k</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, and the other qubit sequence in Bob&#x2019;s hand <inline-formula id="ieqn-248"><mml:math id="mml-ieqn-248"><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>.</p></list-item>
<list-item><label>Step P2.</label><p>For each <inline-formula id="ieqn-249"><mml:math id="mml-ieqn-249"><mml:mi>i</mml:mi></mml:math></inline-formula> bit, Bob makes a choice <inline-formula id="ieqn-250"><mml:math id="mml-ieqn-250"><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2208;</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula> to learn <inline-formula id="ieqn-251"><mml:math id="mml-ieqn-251"><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> from Alice; the set of <inline-formula id="ieqn-252"><mml:math id="mml-ieqn-252"><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is <inline-formula id="ieqn-253"><mml:math id="mml-ieqn-253"><mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>k</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>,. According to <inline-formula id="ieqn-254"><mml:math id="mml-ieqn-254"><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, Bob additionally prepares a single qubit sequence, <inline-formula id="ieqn-255"><mml:math id="mml-ieqn-255"><mml:mrow><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:msub><mml:mrow><mml:mtext>c</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mrow><mml:mtext>c</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mtext>k</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>,., and performs <inline-formula id="ieqn-256"><mml:math id="mml-ieqn-256"><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> operation, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1a</xref> &#x2461;. That is, Bob prepares the single qubit <inline-formula id="ieqn-257"><mml:math id="mml-ieqn-257"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> in state <inline-formula id="ieqn-258"><mml:math id="mml-ieqn-258"><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula> with <italic>z-basis</italic>, and performs <inline-formula id="ieqn-259"><mml:math id="mml-ieqn-259"><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> operation when <inline-formula id="ieqn-260"><mml:math id="mml-ieqn-260"><mml:msub><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>, as in the situation in <xref ref-type="disp-formula" rid="eqn-8">Eq. (8)</xref>. On the other hand, when <inline-formula id="ieqn-261"><mml:math id="mml-ieqn-261"><mml:msub><mml:mrow><mml:mtext>j</mml:mtext></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, Bob prepares the single qubit <inline-formula id="ieqn-262"><mml:math id="mml-ieqn-262"><mml:msub><mml:mrow><mml:mtext>c</mml:mtext></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> in state <inline-formula id="ieqn-263"><mml:math id="mml-ieqn-263"><mml:mrow><mml:mo>|</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula> with <italic>x-basis</italic>, and performs <inline-formula id="ieqn-264"><mml:math id="mml-ieqn-264"><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> operation, as in the situation in <xref ref-type="disp-formula" rid="eqn-9">Eq. (9)</xref>.</p></list-item>
<list-item><label>Step P3.</label><p>After this, Bob randomly inserts <inline-formula id="ieqn-265"><mml:math id="mml-ieqn-265"><mml:mi>n</mml:mi></mml:math></inline-formula> single qubits as decoy qubits in state <inline-formula id="ieqn-266"><mml:math id="mml-ieqn-266"><mml:mrow><mml:mo>{</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>}</mml:mo></mml:mrow></mml:math></inline-formula> into <inline-formula id="ieqn-267"><mml:math id="mml-ieqn-267"><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> for channel checking, and then sends <inline-formula id="ieqn-268"><mml:math id="mml-ieqn-268"><mml:msubsup><mml:mi>S</mml:mi><mml:mrow><mml:mi>b</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> consisting of <inline-formula id="ieqn-269"><mml:math id="mml-ieqn-269"><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and decoy qubits to Alice, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1a</xref> &#x2462;.</p></list-item>
<list-item><label>Step P4.</label><p>Once Alice has received <inline-formula id="ieqn-270"><mml:math id="mml-ieqn-270"><mml:msubsup><mml:mi>S</mml:mi><mml:mrow><mml:mi>b</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>, Alice and Bob use the decoy qubits to check the security of their communication channel. The detection process and detection rate of channel checking are described in the &#x201C;External Attack&#x201D; section. If they find that there is an outside eavesdropper present, they abort this communication and restart. Otherwise, they continue to the next step.</p></list-item>
<list-item><label>Step P5.</label><p>Alice performs one of the <italic>I</italic>, <italic>Z</italic>, <italic>X</italic> or <italic>Y</italic> operations on qubit <inline-formula id="ieqn-271"><mml:math id="mml-ieqn-271"><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> or <inline-formula id="ieqn-272"><mml:math id="mml-ieqn-272"><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> randomly, according to the <inline-formula id="ieqn-273"><mml:math id="mml-ieqn-273"><mml:mi>i</mml:mi></mml:math></inline-formula>-th bit in both of her messages, <inline-formula id="ieqn-274"><mml:math id="mml-ieqn-274"><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> and <inline-formula id="ieqn-275"><mml:math id="mml-ieqn-275"><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula>, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1b</xref> &#x2463;. The <italic>I</italic>, <italic>Z</italic>, <italic>X</italic> and <italic>Y</italic> operations indicate that <inline-formula id="ieqn-276"><mml:math id="mml-ieqn-276"><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> and <inline-formula id="ieqn-277"><mml:math id="mml-ieqn-277"><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> are &#x201C;00&#x201D;, &#x201C;01&#x201D;, &#x201C;10&#x201D; and &#x201C;11&#x201D;, respectively. For example, if Alice performs the <italic>X</italic> operation on <inline-formula id="ieqn-278"><mml:math id="mml-ieqn-278"><mml:msub><mml:mi>a</mml:mi><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, then <inline-formula id="ieqn-279"><mml:math id="mml-ieqn-279"><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msubsup></mml:math></inline-formula> is &#x201C;1&#x201D; and <inline-formula id="ieqn-280"><mml:math id="mml-ieqn-280"><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mn>3</mml:mn></mml:mrow></mml:msubsup></mml:math></inline-formula> is &#x201C;0&#x201D;, and if she performs the <italic>Z</italic> operation on <inline-formula id="ieqn-281"><mml:math id="mml-ieqn-281"><mml:msub><mml:mi>b</mml:mi><mml:mrow><mml:mn>5</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, then <inline-formula id="ieqn-282"><mml:math id="mml-ieqn-282"><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow><mml:mrow><mml:mn>5</mml:mn></mml:mrow></mml:msubsup></mml:math></inline-formula> is &#x201C;0&#x201D; and <inline-formula id="ieqn-283"><mml:math id="mml-ieqn-283"><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mn>5</mml:mn></mml:mrow></mml:msubsup></mml:math></inline-formula> is &#x201C;1&#x201D;. The qubits on which Alice performs operations compose a new set <inline-formula id="ieqn-284"><mml:math id="mml-ieqn-284"><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>.</p></list-item>
<list-item><label>Step P6.</label><p>As in <italic>Step P3</italic>, Alice randomly inserts <inline-formula id="ieqn-285"><mml:math id="mml-ieqn-285"><mml:mi>n</mml:mi></mml:math></inline-formula> single qubits as decoy qubits in state <inline-formula id="ieqn-286"><mml:math id="mml-ieqn-286"><mml:mrow><mml:mo>{</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>}</mml:mo></mml:mrow></mml:math></inline-formula> into <inline-formula id="ieqn-287"><mml:math id="mml-ieqn-287"><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> for channel checking, and then sends <inline-formula id="ieqn-288"><mml:math id="mml-ieqn-288"><mml:msubsup><mml:mi>S</mml:mi><mml:mrow><mml:mi>d</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> consisting of <inline-formula id="ieqn-289"><mml:math id="mml-ieqn-289"><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and decoy qubits to Bob, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1b</xref> &#x2464;.</p></list-item>
<list-item><label>Step P7.</label><p>As in <italic>Step P4</italic>, Alice and Bob check the security of the channel and remove the decoy qubits from <inline-formula id="ieqn-290"><mml:math id="mml-ieqn-290"><mml:msubsup><mml:mi>S</mml:mi><mml:mrow><mml:mi>d</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> to revert <inline-formula id="ieqn-291"><mml:math id="mml-ieqn-291"><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. If they detect someone eavesdropping between them, they will stop this communication, if not, they will continue.</p></list-item>
<list-item><label>Step P8.</label><p>As in <italic>Step P2</italic>, Bob performs the controlled-not operation <inline-formula id="ieqn-292"><mml:math id="mml-ieqn-292"><mml:mi>C</mml:mi><mml:mi>N</mml:mi><mml:mi>o</mml:mi><mml:msub><mml:mi>t</mml:mi><mml:mrow><mml:mi>d</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> according to <inline-formula id="ieqn-293"><mml:math id="mml-ieqn-293"><mml:msub><mml:mi>S</mml:mi><mml:mrow><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1c</xref> &#x2465;. If <inline-formula id="ieqn-294"><mml:math id="mml-ieqn-294"><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>, Bob performs the <inline-formula id="ieqn-295"><mml:math id="mml-ieqn-295"><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> operation, as in the situation in <xref ref-type="disp-formula" rid="eqn-8">Eq. (8)</xref>; otherwise, Bob performs the <inline-formula id="ieqn-296"><mml:math id="mml-ieqn-296"><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> operation if <inline-formula id="ieqn-297"><mml:math id="mml-ieqn-297"><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, as in the situation in <xref ref-type="disp-formula" rid="eqn-9">Eq. (9)</xref>.</p></list-item>
<list-item><label>Step P9.</label><p>Bob measures qubit <inline-formula id="ieqn-298"><mml:math id="mml-ieqn-298"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> with <italic>z-basis</italic> <inline-formula id="ieqn-299"><mml:math id="mml-ieqn-299"><mml:mrow><mml:mo>{</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>}</mml:mo></mml:mrow></mml:math></inline-formula> when <inline-formula id="ieqn-300"><mml:math id="mml-ieqn-300"><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>, as in the situation in <xref ref-type="disp-formula" rid="eqn-8">Eq. (8)</xref>, or with <italic>x-basis</italic> <inline-formula id="ieqn-301"><mml:math id="mml-ieqn-301"><mml:mrow><mml:mo>{</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>}</mml:mo></mml:mrow></mml:math></inline-formula> when <inline-formula id="ieqn-302"><mml:math id="mml-ieqn-302"><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, as in the situation in <xref ref-type="disp-formula" rid="eqn-9">Eq. (9)</xref>, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1d</xref> &#x2466;. If the measurement result of <inline-formula id="ieqn-303"><mml:math id="mml-ieqn-303"><mml:msub><mml:mi>c</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is <inline-formula id="ieqn-304"><mml:math id="mml-ieqn-304"><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula> or <inline-formula id="ieqn-305"><mml:math id="mml-ieqn-305"><mml:mrow><mml:mo>|</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, then the message <inline-formula id="ieqn-306"><mml:math id="mml-ieqn-306"><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> is &#x201C;0&#x201D;; if the measurement result is <inline-formula id="ieqn-307"><mml:math id="mml-ieqn-307"><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula> or <inline-formula id="ieqn-308"><mml:math id="mml-ieqn-308"><mml:mrow><mml:mo>|</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, then <inline-formula id="ieqn-309"><mml:math id="mml-ieqn-309"><mml:msubsup><mml:mi>m</mml:mi><mml:mrow><mml:msub><mml:mi>j</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msubsup></mml:math></inline-formula> is &#x201C;1&#x201D;.</p></list-item>
<list-item><label>Step P10.</label><p>Bob now utilizes some Bell states to check whether or not Alice is honest by internal attack detection, which is explained in detail in Section 6. If Bob finds that Alice is dishonest, Bob will stop the upper-layer application after this.</p></list-item></list></p>
</sec>
<sec id="s6">
<label>6</label>
<title>Security Analysis</title>
<p>In this section, the security of the proposed protocol is discussed, including both external and internal attack detection. External attack detection guards against an outside eavesdropper (Eve) stealing Alice&#x2019;s message information, while internal attack detection guards against either dishonest Alice or dishonest Bob.</p>
<sec id="s6_1">
<label>6.1</label>
<title>External Attack</title>
<p>Alice and Bob must ensure that the communication channel between them is secure, otherwise, Eve can eavesdrop on their messages illicitly without being spotted. In the proposed protocol, several single qubits are used as decoy qubits [<xref ref-type="bibr" rid="ref-48">48</xref>], and inserted into the transmitted sequence for channel checking, as in <italic>Step P3</italic> and <italic>Step P6</italic> of this protocol. The sender prepares the decoy qubits in state <inline-formula id="ieqn-310"><mml:math id="mml-ieqn-310"><mml:mrow><mml:mo>{</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>}</mml:mo></mml:mrow></mml:math></inline-formula> randomly. If both the sender and the receiver measure the qubit with the same basis, they must obtain the same measurement results. That is, if their measurement results with the same basis differ, then an eavesdropper is present. Two common external attack strategies are discussed below, including the intercept-and-resend attack and the entangling attack.</p>
<p><bold>Intercept-and-resend attack:</bold> When the sender sends the qubit sequence to the receiver, Eve intercepts all qubits to measure them in order to learn the messages during the transmission, and then resends the qubits to the receiver. In the proposed protocol, the sender will insert the decoy qubits into the qubit sequence with random states and positions. To steal the message, Eve intercepts the qubits and measures them. However, Eve may change the state of decoy qubits by measuring with wrong basis because she is unaware of the basis on which each decoy qubit is prepared. Eve will be detected with a 25% probability for each decoy qubit. With <inline-formula id="ieqn-311"><mml:math id="mml-ieqn-311"><mml:mi>n</mml:mi></mml:math></inline-formula> decoy qubits, this guarantees the probability of detecting Eve by <inline-formula id="ieqn-312"><mml:math id="mml-ieqn-312"><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mn>3</mml:mn><mml:mn>4</mml:mn></mml:mfrac></mml:mstyle><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>n</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula>.</p>
<p><bold>Entangling attack:</bold> After intercepting the qubit sequence during the transmission, Eve prepares an ancillary qubit <inline-formula id="ieqn-313"><mml:math id="mml-ieqn-313"><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mtext>E</mml:mtext></mml:mrow><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></inline-formula> and performs a unitary operation <inline-formula id="ieqn-314"><mml:math id="mml-ieqn-314"><mml:mi>U</mml:mi></mml:math></inline-formula> on the intercepted qubit to entangle with qubit <inline-formula id="ieqn-315"><mml:math id="mml-ieqn-315"><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mtext>E</mml:mtext></mml:mrow><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>. If the decoy qubit in state <inline-formula id="ieqn-316"><mml:math id="mml-ieqn-316"><mml:mrow><mml:mo>{</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>}</mml:mo></mml:mrow></mml:math></inline-formula> is entangled with the qubit <inline-formula id="ieqn-317"><mml:math id="mml-ieqn-317"><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mtext>E</mml:mtext></mml:mrow><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, the unitary operation <inline-formula id="ieqn-318"><mml:math id="mml-ieqn-318"><mml:mi>U</mml:mi></mml:math></inline-formula> is defined in <xref ref-type="disp-formula" rid="eqn-11">Eq. (11)</xref>.</p>
<p><disp-formula id="ueqn-24"><mml:math id="mml-ueqn-24" display="block"><mml:mi>U</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>E</mml:mi><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mi>a</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>00</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>b</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>01</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-25"><mml:math id="mml-ueqn-25" display="block"><mml:mi>U</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>E</mml:mi><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mi>c</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>10</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>d</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>11</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-26"><mml:math id="mml-ueqn-26" display="block"><mml:mi>U</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>E</mml:mi><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:mrow><mml:mo>(</mml:mo><mml:mi>U</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>E</mml:mi><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>U</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>E</mml:mi><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-27"><mml:math id="mml-ueqn-27" display="block"><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>a</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>00</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>b</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>01</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>c</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>10</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>d</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>11</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mi>a</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>00</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>b</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>01</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>c</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>10</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>d</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>11</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-28"><mml:math id="mml-ueqn-28" display="block"><mml:mi>U</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>E</mml:mi><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:mrow><mml:mo>(</mml:mo><mml:mi>U</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>E</mml:mi><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>U</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mi>E</mml:mi><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p><disp-formula id="eqn-11"><label>(11)</label><mml:math id="mml-eqn-11" display="block"><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>a</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>00</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>b</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>01</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>c</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>10</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>d</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>11</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>a</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>00</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>b</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>01</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>c</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>10</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>d</mml:mi><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:msub><mml:mi>e</mml:mi><mml:mrow><mml:mn>11</mml:mn></mml:mrow></mml:msub><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula></p>
</sec>
<sec id="s6_2">
<label>6.2</label>
<title>Internal Attack</title>
<p>An unconditionally secure one-out-of-two QOT must guarantee that Bob can only learn one of Alice&#x2019;s messages, and ensure that Alice cannot learn Bob&#x2019;s choice and choose which message Bob learns. Thus, internal attacks can be divided into two parts, the first part is from the sender, Alice, while the second part is from the receiver, Bob.</p>
<p><bold>Alice&#x2019;s attack:</bold> In the proposed QOT protocol, if dishonest Alice wants to learn Bob&#x2019;s choice by an illicit method, she must determine whether the entangled state is <inline-formula id="ieqn-319"><mml:math id="mml-ieqn-319"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>GHZ</mml:mtext></mml:mrow><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:msub><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> or <inline-formula id="ieqn-320"><mml:math id="mml-ieqn-320"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>GHZ</mml:mtext></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:msub><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> after Bob inputs his choice and sends qubit <inline-formula id="ieqn-321"><mml:math id="mml-ieqn-321"><mml:mi>b</mml:mi></mml:math></inline-formula> to her.</p>
<p>The first way of doing this might be GHZ measurement, but this is impossible because Alice does not have the whole entangled state. The second way could be through single qubit measurement. For example, Alice gets the result &#x201C;01&#x201D; after measuring qubit <inline-formula id="ieqn-322"><mml:math id="mml-ieqn-322"><mml:mi>a</mml:mi></mml:math></inline-formula> and qubit <inline-formula id="ieqn-323"><mml:math id="mml-ieqn-323"><mml:mi>b</mml:mi></mml:math></inline-formula> with <italic>z-basis</italic>. In this way, Alice can be sure that the entangled state is <inline-formula id="ieqn-324"><mml:math id="mml-ieqn-324"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>GHZ</mml:mtext></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:msub><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, which indicates that Bob wants message <inline-formula id="ieqn-325"><mml:math id="mml-ieqn-325"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>. However, this attack will be detected by Bob in the final step. The key point is that Alice&#x2019;s attack destroys the entangled state, and Bob can check whether the entangled state is complete.</p>
<p>Once Bob has learned the message in <italic>Step P9</italic>, the entanglement property of the Bell state consisting of qubits <inline-formula id="ieqn-326"><mml:math id="mml-ieqn-326"><mml:mi>a</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-327"><mml:math id="mml-ieqn-327"><mml:mi>b</mml:mi></mml:math></inline-formula> is not destroyed if Alice is honest, and the Bell state will become <inline-formula id="ieqn-328"><mml:math id="mml-ieqn-328"><mml:msub><mml:mrow><mml:mo>|</mml:mo><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-329"><mml:math id="mml-ieqn-329"><mml:msub><mml:mrow><mml:mo>|</mml:mo><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-330"><mml:math id="mml-ieqn-330"><mml:msub><mml:mrow><mml:mo>|</mml:mo><mml:msup><mml:mi>&#x03C8;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-331"><mml:math id="mml-ieqn-331"><mml:msub><mml:mrow><mml:mo>|</mml:mo><mml:msup><mml:mi>&#x03C8;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> according to Alice&#x2019;s operation, <italic>I</italic>, <italic>Z</italic>, <italic>X</italic>, or <italic>Y</italic>. Without knowing Alice&#x2019;s operation, Bob can use this phenomenon to detect whether Alice is honest or not. For example, if Alice&#x2019;s message is &#x201C;01&#x201D;, the Bell state will become <inline-formula id="ieqn-332"><mml:math id="mml-ieqn-332"><mml:msub><mml:mrow><mml:mo>|</mml:mo><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, which Alice knows but Bob does not. Then Bob performs one of the operations, <italic>I</italic>, <italic>Z</italic>, <italic>X</italic>, or <italic>Y</italic>, on the qubit in his hands, sends it to Alice and asks Alice which operation he has performed. If Alice is honest, she can perform a Bell measurement to identify Bob&#x2019;s operation by the Bell measurement result and the Bell state <inline-formula id="ieqn-333"><mml:math id="mml-ieqn-333"><mml:msub><mml:mrow><mml:mo>|</mml:mo><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>.</p>
<p><bold>Bob&#x2019;s attack:</bold> If dishonest Bob wants to learn both of Alice&#x2019;s messages, <inline-formula id="ieqn-334"><mml:math id="mml-ieqn-334"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-335"><mml:math id="mml-ieqn-335"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, Bob does not prepare one single qubit because it only has two states: 0 or 1, to identify one message. In order to recognize the situation of the two messages: &#x201C;00&#x201D;, &#x201C;01&#x201D;, &#x201C;10&#x201D; and &#x201C;11&#x201D;, Bob prepares different states instead of one single qubit in <italic>Step P2</italic>. Two kinds of Bob&#x2019;s attacks are discussed below.</p>
<p>Attack 1, Bob will prepare a Bell state instead of a single qubit, and use Bell measurement to identify which operation (<italic>I</italic>, <italic>Z</italic>, <italic>X</italic>, or <italic>Y</italic>) Alice performs. For example, Alice shares <inline-formula id="ieqn-336"><mml:math id="mml-ieqn-336"><mml:msub><mml:mrow><mml:mo>|</mml:mo><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> with Bob. Bob wants to learn both of Alice&#x2019;s messages, <inline-formula id="ieqn-337"><mml:math id="mml-ieqn-337"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-338"><mml:math id="mml-ieqn-338"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, so he does not prepare a single qubit but a Bell state <inline-formula id="ieqn-339"><mml:math id="mml-ieqn-339"><mml:msub><mml:mrow><mml:mo>|</mml:mo><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:msup><mml:mi>b</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:msub></mml:math></inline-formula> instead, and sends qubit <inline-formula id="ieqn-340"><mml:math id="mml-ieqn-340"><mml:mi>b</mml:mi><mml:mrow><mml:mtext>&#x2032;</mml:mtext></mml:mrow></mml:math></inline-formula> to Alice, as shown in <xref ref-type="fig" rid="fig-2">Fig. 2a</xref>. After channel checking, Alice performs one of four operations on the qubit <inline-formula id="ieqn-341"><mml:math id="mml-ieqn-341"><mml:mi>a</mml:mi></mml:math></inline-formula> or qubit <inline-formula id="ieqn-342"><mml:math id="mml-ieqn-342"><mml:mi>b</mml:mi></mml:math></inline-formula> randomly in <italic>Step P5</italic>, as shown in <xref ref-type="fig" rid="fig-2">Fig. 2b</xref>. If Alice performs the operation on the qubit <inline-formula id="ieqn-343"><mml:math id="mml-ieqn-343"><mml:mi>a</mml:mi></mml:math></inline-formula> and sends it to Bob, then Bob can perform the Bell measurement on qubit <inline-formula id="ieqn-344"><mml:math id="mml-ieqn-344"><mml:mi>a</mml:mi></mml:math></inline-formula> and qubit <inline-formula id="ieqn-345"><mml:math id="mml-ieqn-345"><mml:mi>b</mml:mi></mml:math></inline-formula> to identify Alice&#x2019;s operation, as shown in <xref ref-type="fig" rid="fig-2">Fig. 2c</xref>, and if Alice performs the operation on qubit <inline-formula id="ieqn-346"><mml:math id="mml-ieqn-346"><mml:mi>b</mml:mi><mml:mrow><mml:mtext>&#x2032;</mml:mtext></mml:mrow></mml:math></inline-formula> and sends it to Bob, then Bob can perform the Bell measurement on qubits <inline-formula id="ieqn-347"><mml:math id="mml-ieqn-347"><mml:mi>b</mml:mi><mml:mrow><mml:mtext>&#x2032;</mml:mtext></mml:mrow></mml:math></inline-formula> and <inline-formula id="ieqn-348"><mml:math id="mml-ieqn-348"><mml:mi>c</mml:mi></mml:math></inline-formula> to identify Alice&#x2019;s operation, as shown in <xref ref-type="fig" rid="fig-2">Fig. 2d</xref>.</p>
<p>However, this strategy still cannot successfully learn both of Alice&#x2019;s messages because Alice performs the operation on qubit <inline-formula id="ieqn-349"><mml:math id="mml-ieqn-349"><mml:mi>a</mml:mi></mml:math></inline-formula> or qubit <inline-formula id="ieqn-350"><mml:math id="mml-ieqn-350"><mml:msup><mml:mi>b</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x2032;</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula> randomly. Bob does not know which qubit Alice selected to perform the operation, so Bob cannot perform the Bell measurement on the correct Bell state to identify Alice&#x2019;s operation.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Steps of Bob&#x2019;s attack 1: (a) Step 1, (b) Step 2, (c) Step 3, and (d) Step 4</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_32320-fig-2.png"/>
</fig>
<p>Attack 2, Bob prepares two single qubits, <inline-formula id="ieqn-351"><mml:math id="mml-ieqn-351"><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula> and <inline-formula id="ieqn-352"><mml:math id="mml-ieqn-352"><mml:mrow><mml:mo>|</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, and performs two types of <italic>CNot</italic> operations: <italic>ZCNot</italic> and <italic>XCNot</italic>, to learn both of Alice&#x2019;s messages: <inline-formula id="ieqn-353"><mml:math id="mml-ieqn-353"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-354"><mml:math id="mml-ieqn-354"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>. For example, Alice shares <inline-formula id="ieqn-355"><mml:math id="mml-ieqn-355"><mml:msub><mml:mrow><mml:mo>|</mml:mo><mml:msup><mml:mi>&#x03D5;</mml:mi><mml:mrow><mml:mo>+</mml:mo></mml:mrow></mml:msup><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> with Bob in the beginning. Then Bob prepares the single qubit <inline-formula id="ieqn-356"><mml:math id="mml-ieqn-356"><mml:mrow><mml:mtext>c</mml:mtext></mml:mrow></mml:math></inline-formula> in state <inline-formula id="ieqn-357"><mml:math id="mml-ieqn-357"><mml:msub><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and performs <inline-formula id="ieqn-358"><mml:math id="mml-ieqn-358"><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. After that, Bob prepares another single qubit <inline-formula id="ieqn-359"><mml:math id="mml-ieqn-359"><mml:mi>d</mml:mi><mml:msub><mml:mrow><mml:mo>|</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, performs <inline-formula id="ieqn-360"><mml:math id="mml-ieqn-360"><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and sends the qubit <inline-formula id="ieqn-361"><mml:math id="mml-ieqn-361"><mml:mi>b</mml:mi></mml:math></inline-formula> to Alice, as shown in <xref ref-type="fig" rid="fig-3">Fig. 3a</xref>.</p>
<p>Alice performs one of four operations: <italic>I</italic>, <italic>Z</italic>, <italic>X</italic>, and <italic>Y</italic>, on qubits <inline-formula id="ieqn-362"><mml:math id="mml-ieqn-362"><mml:mi>a</mml:mi></mml:math></inline-formula> or <inline-formula id="ieqn-363"><mml:math id="mml-ieqn-363"><mml:mi>b</mml:mi></mml:math></inline-formula> randomly after channel checking, as shown in <xref ref-type="fig" rid="fig-3">Fig. 3b</xref>. There are two situations. The first is that Alice performs <italic>Z</italic> operation on qubit <inline-formula id="ieqn-364"><mml:math id="mml-ieqn-364"><mml:mi>b</mml:mi></mml:math></inline-formula> and sends it to Bob, which is shown in <xref ref-type="disp-formula" rid="eqn-12">Eq. (12)</xref>. Bob then performs <inline-formula id="ieqn-365"><mml:math id="mml-ieqn-365"><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-366"><mml:math id="mml-ieqn-366"><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> in an orderly manner, as shown in <xref ref-type="fig" rid="fig-3">Figs. 3c</xref> and <xref ref-type="fig" rid="fig-3">3d</xref>, and measures qubit <inline-formula id="ieqn-367"><mml:math id="mml-ieqn-367"><mml:mi>d</mml:mi></mml:math></inline-formula> with <italic>x-basis</italic> and qubit <inline-formula id="ieqn-368"><mml:math id="mml-ieqn-368"><mml:mi>c</mml:mi></mml:math></inline-formula> with <italic>z-basis</italic>, as shown in <xref ref-type="fig" rid="fig-3">Fig. 3e</xref> The measurement result of qubit <inline-formula id="ieqn-369"><mml:math id="mml-ieqn-369"><mml:mi>c</mml:mi></mml:math></inline-formula> is <inline-formula id="ieqn-370"><mml:math id="mml-ieqn-370"><mml:mrow><mml:mo>|</mml:mo><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, which indicates that <inline-formula id="ieqn-371"><mml:math id="mml-ieqn-371"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> is &#x201C;0&#x201D;, and qubit <inline-formula id="ieqn-372"><mml:math id="mml-ieqn-372"><mml:mi>d</mml:mi></mml:math></inline-formula> is <inline-formula id="ieqn-373"><mml:math id="mml-ieqn-373"><mml:mrow><mml:mo>|</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow></mml:math></inline-formula>, which means that <inline-formula id="ieqn-374"><mml:math id="mml-ieqn-374"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> is &#x201C;1&#x201D;.</p>
<p>The other situation, shown in <xref ref-type="disp-formula" rid="eqn-13">Eq. (13)</xref>, is where Alice performs <italic>Z</italic> operation on qubit <inline-formula id="ieqn-375"><mml:math id="mml-ieqn-375"><mml:mi>a</mml:mi></mml:math></inline-formula> and sends it to Bob. However, after Bob performs <inline-formula id="ieqn-376"><mml:math id="mml-ieqn-376"><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> and <inline-formula id="ieqn-377"><mml:math id="mml-ieqn-377"><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> in an orderly manner, he will get random measurement results in this situation by measuring qubit <inline-formula id="ieqn-378"><mml:math id="mml-ieqn-378"><mml:mi>d</mml:mi></mml:math></inline-formula> with <italic>x-basis</italic> and qubit <inline-formula id="ieqn-379"><mml:math id="mml-ieqn-379"><mml:mi>c</mml:mi></mml:math></inline-formula> with <italic>z-basis</italic>. It would seem that Bob can perform the Bell measurement on qubits <inline-formula id="ieqn-380"><mml:math id="mml-ieqn-380"><mml:mi>c</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-381"><mml:math id="mml-ieqn-381"><mml:mi>d</mml:mi></mml:math></inline-formula> to identify Alice&#x2019;s operation, as shown in <xref ref-type="fig" rid="fig-3">Fig. 3f</xref>. Even so, Bob still cannot learn both of Alice&#x2019;s message for the same reasons as in attack 1, Alice performs an operation on qubits <inline-formula id="ieqn-382"><mml:math id="mml-ieqn-382"><mml:mi>a</mml:mi></mml:math></inline-formula> or <inline-formula id="ieqn-383"><mml:math id="mml-ieqn-383"><mml:mi>b</mml:mi></mml:math></inline-formula> randomly. Because Bob cannot be sure which qubit Alice selected, Bob may learn the wrong message by using the wrong measurement method.</p>
<p><disp-formula id="ueqn-30"><mml:math id="mml-ueqn-30" display="block"><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>00</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>11</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>110</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-31"><mml:math id="mml-ueqn-31" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>111</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-32"><mml:math id="mml-ueqn-32" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-33"><mml:math id="mml-ueqn-33" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>b</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-34"><mml:math id="mml-ueqn-34" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>111</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="eqn-12"><label>(12)</label><mml:math id="mml-eqn-12" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>110</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>00</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>11</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-36"><mml:math id="mml-ueqn-36" display="block"><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>00</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>11</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>110</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-37"><mml:math id="mml-ueqn-37" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>111</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:msub><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mrow><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-38"><mml:math id="mml-ueqn-38" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>b</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-39"><mml:math id="mml-ueqn-39" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mi>Z</mml:mi><mml:mrow><mml:mi>a</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-40"><mml:math id="mml-ueqn-40" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">X</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2213;</mml:mo><mml:mo>&#x00B1;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo>&#x2213;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x00B1;</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mo>&#x00B1;</mml:mo><mml:mo>&#x00B1;</mml:mo><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="ueqn-41"><mml:math id="mml-ueqn-41" display="block"><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0011</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1101</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1110</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p><disp-formula id="eqn-13"><label>(13)</label><mml:math id="mml-eqn-13" display="block"><mml:mover><mml:mo stretchy="false">&#x2192;</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="italic">Z</mml:mi><mml:mi mathvariant="italic">C</mml:mi><mml:mi mathvariant="italic">N</mml:mi><mml:mi mathvariant="italic">o</mml:mi><mml:mi mathvariant="italic">t</mml:mi></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:mover><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0000</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>0011</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1111</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>1100</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>00</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>11</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2297;</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt></mml:mfrac><mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>00</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mn>11</mml:mn><mml:mo>&#x27E9;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mi>c</mml:mi><mml:mi>d</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p>In the above, two different kinds of Bob&#x0027;s attacks were discussed, and it was found that Bob&#x2019;s attack needs to change the state; i.e., the state will be others but not <inline-formula id="ieqn-384"><mml:math id="mml-ieqn-384"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>GHZ</mml:mtext></mml:mrow><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:msub><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> or <inline-formula id="ieqn-385"><mml:math id="mml-ieqn-385"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>GHZ</mml:mtext></mml:mrow><mml:mrow><mml:mi>x</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:msub><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>. If Alice wants to check whether Bob is honest, she can measure the qubits <inline-formula id="ieqn-386"><mml:math id="mml-ieqn-386"><mml:mi>a</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-387"><mml:math id="mml-ieqn-387"><mml:mi>b</mml:mi></mml:math></inline-formula> in her hand and then ask Bob announce his choice to compare with the measurement result. For example, Alice will know that Bob is cheating if her measurement result is &#x201C;01&#x201D; but Bob announces that his choice is <inline-formula id="ieqn-388"><mml:math id="mml-ieqn-388"><mml:msub><mml:mi>m</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, which indicates that the state should be <inline-formula id="ieqn-389"><mml:math id="mml-ieqn-389"><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow><mml:mrow><mml:msub><mml:mrow><mml:mtext>GHZ</mml:mtext></mml:mrow><mml:mrow><mml:mi>z</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:msub><mml:mo fence="false" stretchy="false">&#x27E9;</mml:mo><mml:mrow><mml:mi>a</mml:mi><mml:mi>b</mml:mi><mml:mi>c</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Bob&#x2019;s attack 2. (a) Step 1, (b) Step 2, (c) Step 3, (d) Step 4, (e) Step 5-1, (f) Step 5-2</title>
</caption>
<graphic mimetype="image" mime-subtype="png" xlink:href="CMC_32320-fig-3.png"/>
</fig>
</sec>
</sec>
<sec id="s7">
<label>7</label>
<title>Discussion and Conclusion</title>
<p>This study proposes a novel and efficient protocol for one-out-of-two QOT despite the difficulties presented by no-go theorems. The proposed protocol has three main contributions. First, the relationship between the no-go theorems and our protocol was described herein, and it was shown that the proposed protocol is not based on the QBC and thus does not conform to the MLC no-go theorem. The proposed protocol is similar to Cr&#x00E9;peau&#x2019;s reduction; it does not satisfy the definition of rigorous one-out-of-two QOT according He&#x2019;s proof, so it is not covered by Lo&#x2019;s no-go theorem. Second, compared with other QOTs, the proposed protocol uses quantum resources directly, instead of wasting the resources on generating classical keys. Third, the proposed protocol can check the sender&#x2019;s loyalty and avoid attack from the receiver, so it does satisfy the two security requirements of OT. Furthermore, the entanglement property of the Bell state is reusable once communication via the protocol is complete. In summary, the proposed protocol is the first attempt to directly build a one-out-of-two QOT not covered by the no-go theorem, preventing external and internal attacks, and the quantum sources can be reused, which means that this protocol is more secure, efficient, and flexible. This paper provides a path for the future design of secure and efficient QOT.</p>
</sec>
</body>
<back>
<fn-group>
<fn fn-type="other"><p><bold>Funding Statement:</bold> This work was supported in part by the Ministry of Science and Technology (MOST) in Taiwan under Grants MOST108-2638-E-002-002-MY2, MOST109-2222-E-005-002-MY3, MOST110-2627-M-002-002, MOST110-2221-E-260-014, MOST110-2222-E-006-011, MOST111-2218-E-005-007-MBK, and MOST111-2119-M-033-001, and was also supported in part by Higher Education Sprout Project, Ministry of Education to the Headquarters of University Advancement at National Cheng Kung University.</p>
</fn>
<fn fn-type="conflict"><p><bold>Conflicts of Interest:</bold> The authors declare that they have no conflicts of interest to report regarding the present study.</p>
</fn>
</fn-group>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>M. O.</given-names> <surname>Rabin</surname></string-name></person-group>, &#x201C;<article-title>How to exchange secrets by oblivious transfer</article-title>,&#x201D; in <conf-name>Technical Report TR-81</conf-name>, <publisher-name>Aiken Computation Laboratory, Harvard University</publisher-name>, <year>1981</year>. </mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Even</surname></string-name>, <string-name><given-names>O.</given-names> <surname>Goldreich</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Lempel</surname></string-name></person-group>, &#x201C;<article-title>A randomized protocol for signing contracts</article-title>,&#x201D; <source>Communications of the ACM</source>, vol. <volume>28</volume>, no. <issue>6</issue>, pp. <fpage>637</fpage>&#x2013;<lpage>647</lpage>, <year>1985</year>.</mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Cr&#x00E9;peau</surname></string-name></person-group>, &#x201C;<chapter-title>Equivalence between two flavours of oblivious transfers</chapter-title>,&#x201D; in <source>Proc</source>. <publisher-name>Springer CRYPTO,</publisher-name> <publisher-loc>Santa Barbara, CA, USA</publisher-loc>, pp. <fpage>350</fpage>&#x2013;<lpage>354</lpage>, <year>1987</year>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>V. K.</given-names> <surname>Yadav</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Andola</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Verma</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Venkatesan</surname></string-name></person-group>, &#x201C;<chapter-title>A survey of oblivious transfer protocol</chapter-title>,&#x201D; <source>ACM Computing Surveys (CSUR)</source>, <publisher-name>Just Accepted</publisher-name>, <year>2021</year>. <uri>https://doi.org/10.1145/3503045</uri>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>P. W.</given-names> <surname>Shor</surname></string-name></person-group>, &#x201C;<article-title>Algorithm for quantum computation: Discrete logarithms and factoring</article-title>,&#x201D; in <conf-name>Proc. IEEE FOCS</conf-name>, <publisher-loc>Santa Fe, NM, USA</publisher-loc>, pp. <fpage>124</fpage>&#x2013;<lpage>134</lpage>, <year>1994</year>. </mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>L. K.</given-names> <surname>Grover</surname></string-name></person-group>, &#x201C;<article-title>A fast quantum mechanical algorithm for database search</article-title>,&#x201D; in <conf-name>Proc. ACM STOC</conf-name>, <publisher-loc>New York, NY, USA</publisher-loc>, pp. <fpage>212</fpage>&#x2013;<lpage>219</lpage>, <year>1996</year>. </mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>C. H.</given-names> <surname>Bennett</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Brassard</surname></string-name></person-group>, &#x201C;<article-title>Quantum cryptography: Public key distribution and coin tossing</article-title>,&#x201D; in <conf-name>Proc. IEEE CSSP</conf-name>, <publisher-loc>Bangalore, India</publisher-loc>, pp. <fpage>175</fpage>&#x2013;<lpage>179</lpage>, <year>1984</year>. </mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H. K.</given-names> <surname>Lo</surname></string-name> and <string-name><given-names>H. F.</given-names> <surname>Chau</surname></string-name></person-group>, &#x201C;<article-title>Unconditional security of quantum key distribution over arbitrarily long distances</article-title>,&#x201D; <source>Science</source>, vol. <volume>283</volume>, no. <issue>5410</issue>, pp. <fpage>2050</fpage>&#x2013;<lpage>2056</lpage>, <year>1999</year>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>P. W.</given-names> <surname>Shor</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Preskill</surname></string-name></person-group>, &#x201C;<article-title>Simple proof of security of the BB84 quantum key distribution protocol</article-title>,&#x201D; <source>Physical Review Letters</source>, vol. <volume>85</volume>, no. <issue>2</issue>, pp. <fpage>441</fpage>&#x2013;<lpage>444</lpage>, <year>2000</year>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Cr&#x00E9;peau</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Kilian</surname></string-name></person-group>, &#x201C;<article-title>Achieving oblivious transfer using weakened security assumptions</article-title>,&#x201D; in <conf-name>Proc. IEEE FOCS</conf-name>, <publisher-loc>White Plains, NY, USA</publisher-loc>, pp. <fpage>42</fpage>&#x2013;<lpage>52</lpage>, <year>1988</year>. </mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>C. H.</given-names> <surname>Bennett</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Brassard</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Cr&#x00E9;peau</surname></string-name> and <string-name><given-names>M. H.</given-names> <surname>Skubiszewska</surname></string-name></person-group>, &#x201C;<chapter-title>Practical quantum oblivious transfer</chapter-title>,&#x201D; in <source>Proc</source>. <publisher-name>Springer EUROCRYPT</publisher-name>, <publisher-loc>Brighton, UK</publisher-loc>, pp. <fpage>351</fpage>&#x2013;<lpage>366</lpage>, <year>1991</year>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Cr&#x00E9;peau</surname></string-name></person-group>, &#x201C;<article-title>Quantum oblivious transfer</article-title>,&#x201D; <source>Journal of Modern Optics</source>, vol. <volume>41</volume>, no. <issue>12</issue>, pp. <fpage>2445</fpage>&#x2013;<lpage>2454</lpage>, <year>1994</year>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A. C. C.</given-names> <surname>Yao</surname></string-name></person-group>, &#x201C;<article-title>Security of quantum protocols against coherent measurements</article-title>,&#x201D; in <conf-name>Proc. ACM STOC</conf-name>, Las Vegas, Nevada, USA, pp. <fpage>67</fpage>&#x2013;<lpage>75</lpage>, <year>1995</year>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D.</given-names> <surname>Mayers</surname></string-name></person-group>, &#x201C;<article-title>Unconditionally secure quantum bit commitment is impossible</article-title>,&#x201D; <source>Physical Review Letters</source>, vol. <volume>78</volume>, no. <issue>17</issue>, pp. <fpage>3414</fpage>&#x2013;<lpage>3417</lpage>, <year>1997</year>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H. K.</given-names> <surname>Lo</surname></string-name> and <string-name><given-names>H. F.</given-names> <surname>Chau</surname></string-name></person-group>, &#x201C;<article-title>Is quantum bit commitment really possible?</article-title>,&#x201D; <source>Physical Review Letters</source>, vol. <volume>78</volume>, no. <issue>17</issue>, pp. <fpage>3410</fpage>&#x2013;<lpage>3413</lpage>, <year>1997</year>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H. K.</given-names> <surname>Lo</surname></string-name></person-group>, &#x201C;<article-title>Insecurity of quantum secure computations</article-title>,&#x201D; <source>Physical Review A</source>, vol. <volume>56</volume>, no. <issue>2</issue>, pp. <fpage>1154</fpage>&#x2013;<lpage>1162</lpage>, <year>1997</year>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Shimizu</surname></string-name> and <string-name><given-names>N.</given-names> <surname>Imoto</surname></string-name></person-group>, &#x201C;<article-title>Communication channels analogous to one out of two oblivious transfers based on quantum uncertainty</article-title>,&#x201D; <source>Physical Review A</source>, vol. <volume>66</volume>, no. <issue>5</issue>, pp. <fpage>052316</fpage>, <year>2002</year>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Shimizu</surname></string-name> and <string-name><given-names>N.</given-names> <surname>Imoto</surname></string-name></person-group>, &#x201C;<article-title>Communication channels analogous to one out of two oblivious transfers based on quantum uncertainty. II. closing EPR-type loopholes</article-title>,&#x201D; <source>Physical Review A</source>, vol. <volume>67</volume>, no. <issue>3</issue>, pp. <fpage>034301</fpage>, <year>2003</year>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Wolf</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Wullschleger</surname></string-name></person-group>, &#x201C;<article-title>Oblivious transfer and quantum non-locality</article-title>,&#x201D; in <conf-name>Proc. IEEE ISIT</conf-name>, <publisher-loc>Adelaide, SA, Australia</publisher-loc>, pp. <fpage>1745</fpage>&#x2013;<lpage>1748</lpage>, <year>2005</year>. </mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="book"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Popescu</surname></string-name> and <string-name><given-names>D.</given-names> <surname>Rohrlich</surname></string-name></person-group>, &#x201C;<chapter-title>Causality and nonlocality as axioms for quantum mechanics</chapter-title>,&#x201D; in <source>Proc</source>. <publisher-loc>Dordrecht, ZH, Holland</publisher-loc>: <publisher-name>Springer CLMP</publisher-name>, pp. <fpage>383</fpage>&#x2013;<lpage>389</lpage>, <year>1998</year>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G. P.</given-names> <surname>He</surname></string-name> and <string-name><given-names>Z.</given-names> <surname>Wang</surname></string-name></person-group>, &#x201C;<article-title>Oblivious transfer using quantum entanglement</article-title>,&#x201D; <source>Physical Review A</source>, vol. <volume>73</volume>, no. <issue>1</issue>, pp. <fpage>012331</fpage>, <year>2006</year>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G. P.</given-names> <surname>He</surname></string-name> and <string-name><given-names>Z.</given-names> <surname>Wang</surname></string-name></person-group>, &#x201C;<article-title>Nonequivalence of two flavors of oblivious transfer at the quantum level</article-title>,&#x201D; <source>Physical Review A</source>, vol. <volume>73</volume>, no. <issue>4</issue>, pp. <fpage>044304</fpage>, <year>2006</year>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Huang</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Yao</surname></string-name> and <string-name><given-names>Z.</given-names> <surname>Chen</surname></string-name></person-group>, &#x201C;<article-title>Quantum oblivious transfer using tripartite entangled states</article-title>,&#x201D; in <conf-name>Proc. IEEE FGCN</conf-name>, <publisher-loc>Jeju-Island, Korea</publisher-loc>, pp. <fpage>464</fpage>&#x2013;<lpage>468</lpage>, <year>2007</year>. </mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Buhrman</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Christandl</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Unger</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Wehner</surname></string-name> and <string-name><given-names>A.</given-names> <surname>Winter</surname></string-name></person-group>, &#x201C;<article-title>Implications of superstrong non-locality for cryptography</article-title>,&#x201D; <source>Proceedings of the Royal Society A: Mathematical, Physical and Engineering Sciences</source>, vol. <volume>462</volume>, no. <issue>2071</issue>, pp. <fpage>1919</fpage>&#x2013;<lpage>1932</lpage>, <year>2006</year>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y. H.</given-names> <surname>Chou</surname></string-name>, <string-name><given-names>C. Y.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>H. C.</given-names> <surname>Chao</surname></string-name>, <string-name><given-names>J. H.</given-names> <surname>Park</surname></string-name> and <string-name><given-names>R. K.</given-names> <surname>Fan</surname></string-name></person-group>, &#x201C;<article-title>Quantum entanglement and non-locality based secure computation for future communication</article-title>,&#x201D; <source>IET Information Security</source>, vol. <volume>5</volume>, no. <issue>1</issue>, pp. <fpage>69</fpage>&#x2013;<lpage>79</lpage>, <year>2011</year>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G. P.</given-names> <surname>He</surname></string-name></person-group>, &#x201C;<article-title>Can relativistic bit commitment lead to secure quantum oblivious transfer?</article-title>,&#x201D; <source>The European Physical Journal D</source>, vol. <volume>69</volume>, no. <issue>4</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>8</lpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Souto</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Mateus</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Ad&#x00E3;o</surname></string-name> and <string-name><given-names>N.</given-names> <surname>Paunkovi&#x0107;</surname></string-name></person-group>, &#x201C;<article-title>Bit-string oblivious transfer based on quantum state computational distinguishability</article-title>,&#x201D; <source>Physical Review A</source>, vol. <volume>91</volume>, no. <issue>4</issue>, pp. <fpage>042306</fpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Kent</surname></string-name></person-group>, &#x201C;<article-title>Quantum bit string commitment</article-title>,&#x201D; <source>Physical Review Letters</source>, vol. <volume>90</volume>, no. <issue>23</issue>, pp. <fpage>237901</fpage>, <year>2003</year>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G. P.</given-names> <surname>He</surname></string-name></person-group>, &#x201C;<article-title>Comment on &#x201C;Bit-string oblivious transfer based on quantum state computational distinguishability</article-title>,&#x201D; <source>Physical Review A</source>, vol. <volume>92</volume>, no. <issue>4</issue>, pp. <fpage>046301</fpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Souto</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Mateus</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Adao</surname></string-name> and <string-name><given-names>N.</given-names> <surname>Paunkovi&#x0107;</surname></string-name></person-group>, &#x201C;<article-title>Reply to &#x201C;comment on &#x2018;Bit-string oblivious transfer based on quantum state computational distinguishability&#x2019;</article-title>,&#x201D; <source>Physical Review A</source>, vol. <volume>92</volume>, no. <issue>4</issue>, pp. <fpage>046302</fpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Plesch</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Paw&#x0142;owski</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Pivoluska</surname></string-name></person-group>, &#x201C;<article-title>1-out-of-2 oblivious transfer using a flawed bit-string quantum protocol</article-title>,&#x201D; <source>Physical Review A</source>, vol. <volume>95</volume>, no. <issue>4</issue>, pp. <fpage>042324</fpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y. G.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Xu</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Tian</surname></string-name> and <string-name><given-names>H.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Quantum oblivious transfer with an untrusted third party</article-title>,&#x201D; <source>Optik-International Journal for Light and Electron Optics</source>, vol. <volume>125</volume>, no. <issue>18</issue>, pp. <fpage>5409</fpage>&#x2013;<lpage>5413</lpage>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y. G.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>S. J.</given-names> <surname>Sun</surname></string-name> and <string-name><given-names>Y.</given-names> <surname>Wang</surname></string-name></person-group>, &#x201C;<article-title>Quantum oblivious transfer based on a quantum symmetrically private information retrieval protocol</article-title>,&#x201D; <source>International Journal of Theoretical Physics</source>, vol. <volume>54</volume>, no. <issue>3</issue>, pp. <fpage>910</fpage>&#x2013;<lpage>916</lpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y. G.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Lei</surname></string-name>, <string-name><given-names>W. M.</given-names> <surname>Shi</surname></string-name> and <string-name><given-names>Y. H.</given-names> <surname>Zhou</surname></string-name></person-group>, &#x201C;<article-title>Quantum oblivious transfer with relaxed constraints on the receiver</article-title>,&#x201D; <source>Quantum Information Processing</source>, vol. <volume>14</volume>, no. <issue>8</issue>, pp. <fpage>3031</fpage>&#x2013;<lpage>3040</lpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y. G.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>W. F.</given-names> <surname>Cao</surname></string-name>, <string-name><given-names>X. B.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>Y. H.</given-names> <surname>Zhou</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Flexible quantum oblivious transfer</article-title>,&#x201D; <source>International Journal of Theoretical Physics</source>, vol. <volume>56</volume>, no. <issue>4</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>12</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y. B.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>Q. Y.</given-names> <surname>Wen</surname></string-name>, <string-name><given-names>S. J.</given-names> <surname>Qin</surname></string-name>, <string-name><given-names>F. Z.</given-names> <surname>Guo</surname></string-name> and <string-name><given-names>Y.</given-names> <surname>Sun</surname></string-name></person-group>, &#x201C;<article-title>Practical quantum all-or-nothing oblivious transfer protocol</article-title>,&#x201D; <source>Quantum Information Processing</source>, vol. <volume>13</volume>, no. <issue>1</issue>, pp. <fpage>131</fpage>&#x2013;<lpage>139</lpage>, <year>2014</year>.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Chailloux</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Gutoski</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Sikora</surname></string-name></person-group>, &#x201C;<article-title>Optimal bounds for semi-honest quantum oblivious transfer</article-title>,&#x201D; <source>arXiv preprint arXiv:1310.3262,</source> <year>2013</year>. [Online]. Available: <uri>https://arxiv.org/abs/1310.3262</uri>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G. P.</given-names> <surname>He</surname></string-name></person-group>, &#x201C;<article-title>Secure quantum weak oblivious transfer against individual measurements</article-title>,&#x201D; <source>Quantum Information Processing</source>, vol. <volume>14</volume>, no. <issue>6</issue>, pp. <fpage>2153</fpage>&#x2013;<lpage>2170</lpage>, <year>2015</year>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Gisin</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Popescu</surname></string-name>, <string-name><given-names>V.</given-names> <surname>Scarani</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Wolf</surname></string-name> and <string-name><given-names>J.</given-names> <surname>Wullschleger</surname></string-name></person-group>, &#x201C;<article-title>Oblivious transfer and quantum channels as communication resources</article-title>,&#x201D; <source>Natural Computing</source>, vol. <volume>12</volume>, no. <issue>1</issue>, pp. <fpage>13</fpage>&#x2013;<lpage>17</lpage>, <year>2013</year>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>G. P.</given-names> <surname>He</surname></string-name></person-group>, &#x201C;<article-title>Practical quantum oblivious transfer with a single photon</article-title>,&#x201D; <source>Laser Physics</source>, vol. <volume>29</volume>, no. <issue>3</issue>, pp. <fpage>035201</fpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M. L.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Shi</surname></string-name>, <string-name><given-names>Y. H.</given-names> <surname>Liu</surname></string-name> and <string-name><given-names>Q. J.</given-names> <surname>Zheng</surname></string-name></person-group>, &#x201C;<article-title>A novel application of probabilistic teleportation: p-Rabin quantum oblivious transfer of a qubit</article-title>,&#x201D; <source>International Journal of Theoretical Physics</source>, vol. <volume>58</volume>, no. <issue>10</issue>, pp. <fpage>3333</fpage>&#x2013;<lpage>3341</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-42"><label>[42]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C. H.</given-names> <surname>Bennett</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Brassard</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Cr&#x00E9;peau</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Jozsa</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Peres</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Teleporting an unknown quantum state via dual classical and Einstein-Podolsky-Rosen channels</article-title>,&#x201D; <source>Physical Review Letters</source>, vol. <volume>70</volume>, no. <issue>13</issue>, pp. <fpage>1895</fpage>&#x2013;<lpage>1899</lpage>, <year>1993</year>.</mixed-citation></ref>
<ref id="ref-43"><label>[43]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C. H.</given-names> <surname>Bennett</surname></string-name> and <string-name><given-names>S. J.</given-names> <surname>Wiesner</surname></string-name></person-group>, &#x201C;<article-title>Communication via one-and two-particle operators on Einstein-Podolsky-Rosen states</article-title>,&#x201D; <source>Physical Review Letters</source>, vol. <volume>69</volume>, no. <issue>20</issue>, pp. <fpage>2881</fpage>&#x2013;<lpage>2884</lpage>, <year>1992</year>.</mixed-citation></ref>
<ref id="ref-44"><label>[44]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>H. J.</given-names> <surname>Briegel</surname></string-name>, <string-name><given-names>W.</given-names> <surname>D&#x00FC;r</surname></string-name>, <string-name><given-names>J. I.</given-names> <surname>Cirac</surname></string-name> and <string-name><given-names>P.</given-names> <surname>Zoller</surname></string-name></person-group>, &#x201C;<article-title>Quantum repeaters: The role of imperfect local operations in quantum communication</article-title>,&#x201D; <source>Physical Review Letters</source>, vol. <volume>81</volume>, no. <issue>26</issue>, pp. <fpage>5932</fpage>&#x2013;<lpage>5935</lpage>, <year>1998</year>.</mixed-citation></ref>
<ref id="ref-45"><label>[45]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y. S.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>C. F.</given-names> <surname>Li</surname></string-name> and <string-name><given-names>G. C.</given-names> <surname>Guo</surname></string-name></person-group>, &#x201C;<article-title>Quantum key distribution via quantum encryption</article-title>,&#x201D; <source>Physical Review A</source>, vol. <volume>64</volume>, no. <issue>2</issue>, pp. <fpage>024302</fpage>, <year>2001</year>.</mixed-citation></ref>
<ref id="ref-46"><label>[46]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>F.</given-names> <surname>Gao</surname></string-name>, <string-name><given-names>Q.</given-names> <surname>Wen</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Qin</surname></string-name> and <string-name><given-names>F.</given-names> <surname>Zhu</surname></string-name></person-group>, &#x201C;<article-title>Quantum asymmetric cryptography with symmetric keys</article-title>,&#x201D; <source>Science in China Series G: Physics Mechanics and Astronomy</source>, vol. <volume>52</volume>, no. <issue>12</issue>, pp. <fpage>1925</fpage>&#x2013;<lpage>1931</lpage>, <year>2009</year>.</mixed-citation></ref>
<ref id="ref-47"><label>[47]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Bostr&#x00F6;m</surname></string-name> and <string-name><given-names>T.</given-names> <surname>Felbinger</surname></string-name></person-group>, &#x201C;<article-title>Deterministic secure direct communication using entanglement</article-title>,&#x201D; <source>Physical Review Letters</source>, vol. <volume>89</volume>, no. <issue>18</issue>, pp. <fpage>187902</fpage>, <year>2002</year>.</mixed-citation></ref>
<ref id="ref-48"><label>[48]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W. Y.</given-names> <surname>Hwang</surname></string-name></person-group>, &#x201C;<article-title>Quantum key distribution with high loss: Toward global secure communication</article-title>,&#x201D; <source>Physical Review Letters</source>, vol. <volume>91</volume>, no. <issue>5</issue>, pp. <fpage>057901</fpage>, <year>2003</year>.</mixed-citation></ref>
</ref-list>
</back>
</article>
