[Paper Review] Quantum Attacks on Classical Proof Systems - The Hardness of Quantum Rewinding
This paper demonstrates that classically secure proof systems—such as sigma-protocols, Fiat-Shamir constructions, and Fischlin's scheme—are quantum-insecure under standard classical assumptions, using an oracle separation to show that quantum adversaries can break them despite classical security. The core technique, the 'pick-one trick,' enables an adversary to find one valid witness or response without being able to find two, exploiting the no-cloning theorem to undermine quantum rewinding.
Quantum zero-knowledge proofs and quantum proofs of knowledge are inherently difficult to analyze because their security analysis uses rewinding. Certain cases of quantum rewinding are handled by the results by Watrous (SIAM J Comput, 2009) and Unruh (Eurocrypt 2012), yet in general the problem remains elusive. We show that this is not only due to a lack of proof techniques: relative to an oracle, we show that classically secure proofs and proofs of knowledge are insecure in the quantum setting. More specifically, sigma-protocols, the Fiat-Shamir construction, and Fischlin's proof system are quantum insecure under assumptions that are sufficient for classical security. Additionally, we show that for similar reasons, computationally binding commitments provide almost no security guarantees in a quantum setting. To show these results, we develop the "pick-one trick", a general technique that allows an adversary to find one value satisfying a given predicate, but not two.
Motivation & Objective
- To investigate whether classically secure proof systems remain secure in the quantum setting.
- To determine if the insecurity stems from limitations in proof techniques or from inherent flaws in the protocols.
- To develop a general quantum attack technique that bypasses quantum rewinding and no-cloning constraints.
- To demonstrate that even computationally binding commitments and standard zero-knowledge proof systems fail under quantum attacks.
- To establish an oracle separation showing that quantum adversaries can break classical proof systems where classical techniques fail.
Proposed method
- Introduces the 'pick-one trick'—a quantum attack strategy that allows an adversary to find one valid response to a predicate but not two, exploiting quantum state interference.
- Uses an oracle model to construct a relativized world where classical security assumptions hold but quantum attacks succeed.
- Applies representation theory of symmetric groups to analyze the behavior of quantum algorithms in the attack framework.
- Constructs adversaries that break sigma-protocols, Fiat-Shamir, and Fischlin’s scheme by manipulating commitment and response phases without cloning quantum states.
- Leverages the fact that quantum rewinding fails due to the no-cloning theorem, and shows that existing quantum rewinding techniques (e.g., Watrous, Unruh) are insufficient for general proof-of-knowledge systems.
- Demonstrates that even with perfect or negligible soundness, quantum adversaries can forge valid proofs by exploiting the structure of quantum measurement and state collapse.
Experimental results
Research questions
- RQ1Can classically secure proof systems, such as sigma-protocols, remain secure against quantum adversaries?
- RQ2Is the failure of quantum rewinding a limitation of proof techniques or an inherent flaw in the protocols?
- RQ3Can quantum adversaries break the Fiat-Shamir transformation and Fischlin’s proof system under classical assumptions?
- RQ4To what extent do computationally binding commitments remain secure in the quantum random oracle model?
- RQ5Does the no-cloning theorem fundamentally undermine the security of quantum-rewinding-based proofs of knowledge?
Key findings
- Sigma-protocols that are classically secure are quantum-insecure, even under classical assumptions of special soundness and computational soundness.
- The Fiat-Shamir transformation is insecure in the quantum random oracle model, despite classical security under standard assumptions.
- Fischlin’s proof system, which is classically secure, is broken by a quantum adversary using the pick-one trick, even when the underlying protocol is classically sound.
- Computationally binding commitments provide almost no security in the quantum setting, as quantum adversaries can find multiple valid openings.
- The pick-one trick enables an adversary to find one valid witness or response but not two, exploiting quantum interference to bypass standard rewinding security.
- An oracle separation is constructed to show that quantum attacks can break classically secure proof systems, proving that the insecurity is not merely due to proof technique limitations.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.