Skip to main content
QUICK REVIEW

[Paper Review] Zero-knowledge against quantum attacks

John Watrous|ArXiv.org|Nov 3, 2005
Cryptography and Data Security19 references4 citations
TL;DR

This paper establishes the first general framework for zero-knowledge interactive proof systems secure against quantum polynomial-time adversaries. It proves that classical zero-knowledge protocols and quantum statistical zero-knowledge proofs (QSZK_HV) remain zero-knowledge even when verifiers use quantum computation, under the assumption of quantum-computationally concealing commitment schemes.

ABSTRACT

This paper proves that several interactive proof systems are zero-knowledge against quantum attacks. This includes a few well-known classical zero-knowledge proof systems as well as quantum interactive proof systems for the complexity class HVQSZK, which comprises all problems having "honest verifier" quantum statistical zero-knowledge proofs. It is also proved that zero-knowledge proofs for every language in NP exist that are secure against quantum attacks, assuming the existence of quantum computationally concealing commitment schemes. Previously no non-trivial proof systems were known to be zero-knowledge against quantum attacks, except in restricted settings such as the honest-verifier and common reference string models. This paper therefore establishes for the first time that true zero-knowledge is indeed possible in the presence of quantum information and computation.

Motivation & Objective

  • To establish a formal definition and security model for zero-knowledge in the presence of quantum adversaries.
  • To demonstrate that known classical zero-knowledge protocols remain secure when verifiers are quantum computers.
  • To extend the notion of zero-knowledge to quantum interactive proof systems, particularly for the class QSZK_HV.
  • To show that NP admits quantum-secure zero-knowledge proofs assuming quantum-computationally concealing commitment schemes.
  • To resolve the long-standing open question of whether true zero-knowledge is possible in a quantum world.

Proposed method

  • Adapts classical zero-knowledge simulation techniques to the quantum setting, particularly the rewinding strategy.
  • Uses a quantum simulator that treats the verifier as a black box and employs quantum measurement and state preparation.
  • Applies a hybrid argument to bound deviations in success probability due to quantum commitments, showing they deviate from classical values by a negligible amount.
  • Demonstrates that the simulator’s output is computationally indistinguishable from a real interaction using a non-uniform quantum circuit model.
  • Analyzes the eigenvalue structure of a key operator Q to show that perturbations from ideal behavior are negligible.
  • Relies on the existence of quantum-computationally concealing commitment schemes, which follow from quantum one-way permutations.

Experimental results

Research questions

  • RQ1Can classical zero-knowledge protocols remain secure when the verifier is a quantum computer?
  • RQ2Is it possible to construct a simulator for quantum verifiers that produces indistinguishable outputs from real interactions?
  • RQ3Do quantum-computational commitments enable secure zero-knowledge proofs in the quantum setting?
  • RQ4Can the statistical zero-knowledge protocol of Goldreich, Sahai, and Vadhan be proven secure against quantum attacks?
  • RQ5What are the implications of quantum zero-knowledge for concurrent and resettable zero-knowledge protocols?

Key findings

  • The paper proves that several well-known classical zero-knowledge proof systems, including those for graph isomorphism and quadratic residuosity, remain zero-knowledge against quantum polynomial-time verifiers.
  • It establishes that quantum interactive proof systems for the class QSZK_HV are zero-knowledge under the standard quantum definitions.
  • It shows that every language in NP has a zero-knowledge interactive proof system secure against quantum attacks, assuming the existence of quantum-computationally concealing commitment schemes.
  • The success probability of the quantum simulator deviates from the ideal classical case by at most a negligible function due to the eigenvalue structure of the commitment operator.
  • The simulator’s output is computationally indistinguishable from real interactions, even with arbitrary auxiliary quantum inputs, under the same assumptions.
  • The results resolve the open question of whether true zero-knowledge is possible in a quantum world, affirming that it is.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.