Another Round of Breaking and Making Quantum Money: How to Not Build It from Lattices, and More

by   Hart Montgomery, et al.

Public verification of quantum money has been one of the central objects in quantum cryptography ever since Wiesner's pioneering idea of using quantum mechanics to construct banknotes against counterfeiting. So far, we do not know any publicly-verifiable quantum money scheme that is provably secure from standard assumptions. In this work, we provide both negative and positive results for publicly verifiable quantum money. **In the first part, we give a general theorem, showing that a certain natural class of quantum money schemes from lattices cannot be secure. We use this theorem to break the recent quantum money scheme of Khesin, Lu, and Shor. **In the second part, we propose a framework for building quantum money and quantum lightning we call invariant money which abstracts some of the ideas of quantum money from knots by Farhi et al.(ITCS'12). In addition to formalizing this framework, we provide concrete hard computational problems loosely inspired by classical knowledge-of-exponent assumptions, whose hardness would imply the security of quantum lightning, a strengthening of quantum money where not even the bank can duplicate banknotes. **We discuss potential instantiations of our framework, including an oracle construction using cryptographic group actions and instantiations from rerandomizable functional encryption, isogenies over elliptic curves, and knots.


page 1

page 2

page 3

page 4


Quantum Money from Abelian Group Actions

We give a candidate construction of public key quantum money, and even a...

Franchised Quantum Money

The construction of public key quantum money based on standard cryptogra...

From the Hardness of Detecting Superpositions to Cryptography: Quantum Public Key Encryption and Commitments

Recently, Aaronson et al. (arXiv:2009.07450) showed that detecting inter...

Quantum Lightning Never Strikes the Same State Twice

Public key quantum money can be seen as a version of the quantum no-clon...

Publicly verifiable quantum money from random lattices

Publicly verifiable quantum money is a protocol for the preparation of q...

Can you sign a quantum state?

Cryptography with quantum states exhibits a number of surprising and cou...

Indistinguishability Obfuscation of Null Quantum Circuits and Applications

We study the notion of indistinguishability obfuscation for null quantum...

Please sign up or login with your details

Forgot password? Click here to reset