Why quantum bit commitment and ideal quantum coin tossing are impossible
Hoi-Kwong Lo, H. F. Chau
Abstract
There had been well known claims of ``provably unbreakable'' quantum protocols for bit commitment and coin tossing. However, we, and independently Mayers, showed that all proposed quantum bit commitment (and therefore coin tossing) schemes are, in principle, insecure because the sender, Alice, can always cheat successfully by using an EPR-type of attack and delaying her measurements. One might wonder if secure quantum bit commitment and coin tossing protocols exist at all. Here we prove that an EPR-type of attack by Alice will, in principle, break any realistic quantum bit commitment and ideal coin tossing scheme. Therefore, provided that Alice has a quantum computer and is capable of storing quantum signals for an arbitrary length of time, all those schemes are insecure. Since bit commitment and coin tossing are useful primitives for building up more sophisticated protocols such as zero-knowledge proofs, our results cast very serious doubt on the security of quantum cryptography in the so-called ``post-cold-war'' applications.
Create a lesson
Related papers
Spectral Fingerprints of Gauge Theories on a Quantum Computer
Graham Van Goffrier, Debasish Banerjee, Bipasha Chakraborty et al.
Dynamics of local quantum information in random unitary circuits
Ratul Thakur, Sthitadhi Roy
Factorized Boolean representations for efficient quantum synthesis
Mehul Shah, Robert Fiszer, Marek Perkowski
Detuning- and Stark-robust Rydberg gates
Elie Bataille, Gyohei Nomura, Manuel Endres
Krylov Break Times from an Inhomogeneous Lieb--Robinson Light Cone
Shunji Matsuura, Yoji Kawamura, Joseph Salfi et al.
Stochastic transport of a Goldstone mode in a self-organized atomic crystal
Zhanhai Yu, Di Xiang, Xiaotian Zhang et al.