Skip to main content
QUICK REVIEW

[Paper Review] Classically Verifiable (Dual-Mode) NIZK for QMA with Preprocessing.

Tomoyuki Morimae, Takashi Yamakawa|arXiv (Cornell University)|Feb 18, 2021
Cryptography and Data Security39 references4 citations
TL;DR

This paper presents the first classically verifiable non-interactive zero-knowledge proofs (CV-NIZK) for QMA with a dual-mode property, achieving information-theoretic soundness in one mode and information-theoretic zero-knowledge in another. It constructs three schemes in preprocessing models: one information-theoretically sound and zero-knowledge CV-NIP/NIZK in the secret parameter model, and a computational CV-NIZK under the quantum hardness of Learning with Errors, resolving an open problem from Coladangelo et al. (CRYPTO '20).

ABSTRACT

We propose three constructions of classically verifiable non-interactive proofs (CV-NIP) and non-interactive zero-knowledge proofs and arguments (CV-NIZK) for QMA in various preprocessing models. - We construct an information theoretically sound CV-NIP for QMA in the secret parameter model where a trusted party generates a quantum proving key and classical verification key and gives them to the corresponding parties while keeping it secret from the other party. Alternatively, we can think of the protocol as one in a model where the verifier sends an instance-independent quantum message to the prover as preprocessing. - We construct a CV-NIZK for QMA in the secret parameter model. It is information theoretically sound and zero-knowledge. - Assuming the quantum hardness of the leaning with errors problem, we construct a CV-NIZK for QMA in a model where a trusted party generates a CRS and the verifier sends an instance-independent quantum message to the prover as preprocessing. This model is the same as one considered in the recent work by Coladangelo, Vidick, and Zhang (CRYPTO '20). Our construction has the so-called dual-mode property, which means that there are two computationally indistinguishable modes of generating CRS, and we have information theoretical soundness in one mode and information theoretical zero-knowledge property in the other. This answers an open problem left by Coladangelo et al, which is to achieve either of soundness or zero-knowledge information theoretically. To the best of our knowledge, ours is the first dual-mode NIZK for QMA in any kind of model.

Motivation & Objective

  • To construct classically verifiable non-interactive proofs (CV-NIP) and NIZKs for QMA in preprocessing models.
  • To resolve an open problem posed by Coladangelo, Vidick, and Zhang (CRYPTO '20) by achieving either information-theoretic soundness or zero-knowledge in a dual-mode NIZK system.
  • To provide a construction of CV-NIZK for QMA in a model with a trusted party generating a common reference string (CRS), where the verifier sends an instance-independent quantum message as preprocessing.
  • To achieve both information-theoretic soundness and information-theoretic zero-knowledge in two distinct, computationally indistinguishable modes of CRS generation.
  • To ensure the scheme remains secure under the quantum hardness of the Learning with Errors problem while maintaining classical verification.

Proposed method

  • Design a CV-NIP for QMA in the secret parameter model, where a trusted party generates a quantum proving key and classical verification key, and keeps the proving key secret.
  • Construct a CV-NIZK for QMA in the same secret parameter model, achieving both information-theoretic soundness and information-theoretic zero-knowledge.
  • Introduce a dual-mode construction where two modes of CRS generation are computationally indistinguishable: one offering information-theoretic soundness, the other information-theoretic zero-knowledge.
  • Leverage the quantum hardness of the Learning with Errors (LWE) problem to ensure computational security in the CRS-based model.
  • Utilize a preprocessing model where the verifier sends an instance-independent quantum message to the prover, enabling efficient verification in the final protocol.
  • Ensure classical verification by allowing the verifier to check the proof using only classical computation, even though the proof itself may involve quantum states.

Experimental results

Research questions

  • RQ1Can a classically verifiable NIZK for QMA be constructed with information-theoretic soundness and zero-knowledge in a dual-mode setting?
  • RQ2Is it possible to achieve information-theoretic soundness in one mode and information-theoretic zero-knowledge in another, with computationally indistinguishable CRS generation?
  • RQ3Can a CV-NIZK for QMA be constructed in a preprocessing model where the verifier sends a quantum message independent of the instance?
  • RQ4How can the quantum hardness of Learning with Errors be leveraged to construct a secure, classically verifiable NIZK for QMA in a CRS model?
  • RQ5Does the proposed construction resolve the open problem of achieving either information-theoretic soundness or zero-knowledge in a dual-mode NIZK system for QMA?

Key findings

  • The paper constructs the first information-theoretically sound and zero-knowledge CV-NIZK for QMA in the secret parameter model.
  • It presents a dual-mode CV-NIZK for QMA where one mode ensures information-theoretic soundness and the other ensures information-theoretic zero-knowledge, with the two modes computationally indistinguishable.
  • The construction achieves classical verification of quantum proofs in a preprocessing model where the verifier sends an instance-independent quantum message to the prover.
  • Under the quantum hardness of the Learning with Errors problem, the paper provides a CV-NIZK for QMA in a CRS model with preprocessing, matching the model of Coladangelo et al. (CRYPTO '20).
  • The work resolves an open problem left by Coladangelo, Vidick, and Zhang by achieving information-theoretic soundness or zero-knowledge in a dual-mode NIZK system for QMA.
  • To the best of our knowledge, this is the first dual-mode NIZK for QMA in any model, marking a significant advancement in quantum interactive proof systems with classical verification.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.