[Paper Review] Zero-knowledge against quantum attacks
This paper establishes the first general framework for zero-knowledge interactive proof systems secure against quantum polynomial-time adversaries. It proves that classical zero-knowledge protocols and quantum statistical zero-knowledge proofs (QSZK_HV) remain zero-knowledge even when verifiers use quantum computation, under the assumption of quantum-computationally concealing commitment schemes.
This paper proves that several interactive proof systems are zero-knowledge against quantum attacks. This includes a few well-known classical zero-knowledge proof systems as well as quantum interactive proof systems for the complexity class HVQSZK, which comprises all problems having "honest verifier" quantum statistical zero-knowledge proofs. It is also proved that zero-knowledge proofs for every language in NP exist that are secure against quantum attacks, assuming the existence of quantum computationally concealing commitment schemes. Previously no non-trivial proof systems were known to be zero-knowledge against quantum attacks, except in restricted settings such as the honest-verifier and common reference string models. This paper therefore establishes for the first time that true zero-knowledge is indeed possible in the presence of quantum information and computation.
Motivation & Objective
- To establish a formal definition and security model for zero-knowledge in the presence of quantum adversaries.
- To demonstrate that known classical zero-knowledge protocols remain secure when verifiers are quantum computers.
- To extend the notion of zero-knowledge to quantum interactive proof systems, particularly for the class QSZK_HV.
- To show that NP admits quantum-secure zero-knowledge proofs assuming quantum-computationally concealing commitment schemes.
- To resolve the long-standing open question of whether true zero-knowledge is possible in a quantum world.
Proposed method
- Adapts classical zero-knowledge simulation techniques to the quantum setting, particularly the rewinding strategy.
- Uses a quantum simulator that treats the verifier as a black box and employs quantum measurement and state preparation.
- Applies a hybrid argument to bound deviations in success probability due to quantum commitments, showing they deviate from classical values by a negligible amount.
- Demonstrates that the simulator’s output is computationally indistinguishable from a real interaction using a non-uniform quantum circuit model.
- Analyzes the eigenvalue structure of a key operator Q to show that perturbations from ideal behavior are negligible.
- Relies on the existence of quantum-computationally concealing commitment schemes, which follow from quantum one-way permutations.
Experimental results
Research questions
- RQ1Can classical zero-knowledge protocols remain secure when the verifier is a quantum computer?
- RQ2Is it possible to construct a simulator for quantum verifiers that produces indistinguishable outputs from real interactions?
- RQ3Do quantum-computational commitments enable secure zero-knowledge proofs in the quantum setting?
- RQ4Can the statistical zero-knowledge protocol of Goldreich, Sahai, and Vadhan be proven secure against quantum attacks?
- RQ5What are the implications of quantum zero-knowledge for concurrent and resettable zero-knowledge protocols?
Key findings
- The paper proves that several well-known classical zero-knowledge proof systems, including those for graph isomorphism and quadratic residuosity, remain zero-knowledge against quantum polynomial-time verifiers.
- It establishes that quantum interactive proof systems for the class QSZK_HV are zero-knowledge under the standard quantum definitions.
- It shows that every language in NP has a zero-knowledge interactive proof system secure against quantum attacks, assuming the existence of quantum-computationally concealing commitment schemes.
- The success probability of the quantum simulator deviates from the ideal classical case by at most a negligible function due to the eigenvalue structure of the commitment operator.
- The simulator’s output is computationally indistinguishable from real interactions, even with arbitrary auxiliary quantum inputs, under the same assumptions.
- The results resolve the open question of whether true zero-knowledge is possible in a quantum world, affirming that it is.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.