Semi-quantum Tokenized Signatures
Omri Shmueli
Abstract
Quantum tokenized signature schemes (Ben-David and Sattath, QCrypt 2017) allow a sender to generate and distribute quantum unclonable states which grant their holder a one-time permission to sign in the name of the sender. Such schemes are a strengthening of public-key quantum money schemes, as they imply public-key quantum money where some channels of communication in the system can be made classical.
An even stronger primitive is semi-quantum tokenized signatures, where the sender is classical and can delegate the generation of the token to a (possibly malicious) quantum receiver. Semi-quantum tokenized signature schemes imply a powerful version of public-key quantum money satisfying two key features:
-The bank is classical and the scheme can execute on a completely classical communication network. In addition, the bank is stateless and after the creation of a banknote, does not hold any information nor trapdoors except the balance of accounts in the system. Such quantum money scheme solves the main open problem presented by Radian and Sattath (AFT 2019). -Furthermore, the classical-communication transactions between users in the system are direct and do not need to go through the bank. This enables the transactions to be both classical and private. While fully-quantum tokenized signatures (where the sender is quantum and generates the token by itself) are known based on quantum-secure indistinguishability obfuscation and injective one-way functions, the semiquantum version is not known under any computational assumption. In this work we construct a semi-quantum tokenized signature scheme based on quantum-secure indistinguishability obfuscation and the subexponential hardness of the Learning with Errors problem. In the process, we show new properties of quantum coset states and a new hardness result on indistinguishability obfuscation of classical subspace membership circuits.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- Software with Certified DeletionJames Bartusek, Vipul Goyal, Dakshita Khurana, Giulio Malavolta et al.EUROCRYPT 2024 · 13 citations
- On One-Shot Signatures, Quantum vs. Classical Binding, and Obfuscating PermutationsOmri Shmueli, Mark ZhandryCRYPTO 2025 · 6 citations
- Quantum One-Time Protection of Any Randomized AlgorithmSam Gunn, Ramis MovassaghCRYPTO 2025 · 2 citations
- Public-Key Quantum Fire and Key-Fire From Classical OraclesAlper Çakan, Vipul Goyal, Omri ShmueliCRYPTO 2026
Builds on2
Related papers
- One-shot signatures and applications to hybrid quantum/classical authenticationRyan Amos, Marios Georgiou, Aggelos Kiayias, Mark ZhandrySTOC 2020 · 6 citations
- Uncloneable Cryptography in Linear Quantum MemoryAndrew Huang, Omri Shmueli, Vinod Vaikuntanathan, Mark ZhandryCRYPTO 2026 · 2 citations
- Another Round of Breaking and Making Quantum Money: - How to Not Build It from Lattices, and MoreJiahui Liu, Hart Montgomery, Mark ZhandryEUROCRYPT 2023 · 21 citations
- On the Cryptographic Futility of Non-collapsing MeasurementsAlper Çakan, Dakshita Khurana, Tomoyuki Morimae, Yuki Shirakawa et al.EUROCRYPT 2026 · 1 citation
- A Modular Approach to Unclonable CryptographyPrabhanjan Ananth, Amit BeheraCRYPTO 2024 · 6 citations
