Unconditionally Secure Commitments with Quantum Auxiliary Inputs
Tomoyuki Morimae, Barak Nehoran, Takashi Yamakawa
Abstract
We show the following unconditional results on quantum commitments in two related yet different models:
-
We revisit the notion of quantum auxiliary-input commitments introduced by Chailloux, Kerenidis, and Rosgen (Comput. Complex. 2016) where both the committer and receiver take the same quantum state, which is determined by the security parameter, as quantum auxiliary inputs. We show that computationally-hiding and statistically-binding quantum auxiliary-input commitments exist unconditionally, i.e., without relying on any unproven assumption, while Chailloux et al. assumed a complexity-theoretic assumption, QIP ⊆ QMA. On the other hand, we observe that achieving both statistical hiding and statistical binding at the same time is impossible even in the quantum auxiliary-input setting. To the best of our knowledge, this is the first example of unconditionally proving computational security of any form of (classical or quantum) commitments for which statistical security is impossible. As intermediate steps toward our construction, we introduce and unconditionally construct post-quantum sparse pseudorandom distributions and quantum auxiliaryinput EFI pairs which may be of independent interest.
-
We introduce a new model which we call the common reference quantum state (CRQS) model where both the committer and receiver take the same quantum state that is randomly sampled by an efficient setup algorithm. We unconditionally prove that there exist statistically hiding and statistically binding commitments in the CRQS model, circumventing the impossibility in the plain model.
We also discuss their applications to zero-knowledge proofs, oblivious transfers, and multi-party computations.
As an application of our quantum auxiliary-input commitments, we plug them into Blum's Hamiltonicity protocol [Blu87] to obtain the following theorem.
Theorem 1.3. There exist zero-knowledge proofs for NP in the quantum auxiliary-input setting with nonuniform simulation (with quantum advice) and soundness error 1/2.
We can also use our quantum auxiliary-input commitments to instantiate the 3-coloring protocol of [GMR89] and the quantum Σ-protocol for QMA of [BG22]. On the other hand, unfortunately, we do not know how to instantiate the construction of OTs of [BCKM21] using our quantum auxiliary-input commitments. This is due to the fact that there may not be an efficient way to generate the quantum auxiliaryinput, which prevents us from applying Watrous' rewinding lemma [Wat09] that is used in the security proof in [BCKM21].
Commitments in the CRQS model. Our result on quantum auxiliary-input commitments is theoretically interesting. However, the fact that there is no efficient way to generate the quantum auxiliary input makes it unlikely to have uses in real-world applications. We therefore consider an alternative model that involves only efficiently generatable states. Specifically, we introduce a new notion that we call the common reference quantum state (CRQS) model, where an efficient setup algorithm randomly samples a classical key k and then distributes many copies of a (pure) quantum state |ψ k associated with the key k. It is a natural quantum analog of the common reference string model in classical cryptography.
At first glance, the CRQS model may look similar to the quantum auxiliary-input setting since in both settings, the committer and receiver receive some quantum state as a resource for executing the protocol. However, the crucial differences are that:
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 02c7532d-13da-42d8-bdb6-4a4e8a4cf461Cited by top-tier papers4
- The Power of a Single Haar Random State: Constructing and Separating Quantum PseudorandomnessBoyang Chen, Andrea Coladangelo, Or SattathEUROCRYPT 2025 · 6 citations
- Oracle Separation Between Quantum Commitments and Quantum One-WaynessJohn Bostanci, Boyang Chen, Barak NehoranEUROCRYPT 2025 · 3 citations
- Pseudorandom Unitaries in the Haar Random Oracle ModelPrabhanjan Ananth, John Bostanci, Aditya Gulati, Yao-Ting LinCRYPTO 2025 · 2 citations
- Founding Quantum Cryptography on Quantum Advantage, or, Towards Cryptography from #P HardnessDakshita Khurana, Kabir TomerSTOC 2025 · 2 citations
Builds on13
- Cryptography from Pseudorandom Quantum StatesPrabhanjan Ananth, Luowen Qian, Henry YuenCRYPTO 2022 · 78 citations
- Quantum Commitments and Signatures Without One-Way FunctionsTomoyuki Morimae, Takashi YamakawaCRYPTO 2022 · 74 citations
- One-Way Functions Imply Secure Computation in a Quantum WorldJames Bartusek, Andrea Coladangelo, Dakshita Khurana, Fermi MaCRYPTO 2021 · 57 citations
- Oblivious Transfer Is in MiniQCryptAlex B. Grilo, Huijia Lin, Fang Song, Vinod VaikuntanathanEUROCRYPT 2021 · 56 citations
- Secure Multi-party Quantum Computation with a Dishonest MajorityYfke Dulek, Alex B. Grilo, Stacey Jeffery, Christian Majenz et al.EUROCRYPT 2020 · 41 citations
Related papers
- Unconditionally Secure Quantum Commitments with PreprocessingLuowen QianCRYPTO 2024 · 9 citations
- Commitments to Quantum StatesSam Gunn, Nathan Ju, Fermi Ma, Mark ZhandrySTOC 2023 · 16 citations
- Non-malleable Commitments Against Quantum AttacksNir Bitansky, Huijia Lin, Omri ShmueliEUROCRYPT 2022 · 6 citations
- Black-Box Separations for Non-interactive Classical Commitments in a Quantum WorldKai-Min Chung, Yao-Ting Lin, Mohammad MahmoodyEUROCRYPT 2023 · 7 citations
- Certified Everlasting Zero-Knowledge Proof for QMATaiga Hiroka, Tomoyuki Morimae, Ryo Nishimaki, Takashi YamakawaCRYPTO 2022 · 16 citations
