# Quantum Coin

(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

This example protocol is a private-key protocol which implements Quantum Money, a unique object generated by a Trusted Third Party (TTP). It is then circulated among untrusted clients (Transferability). Each client should be able to prove the authenticity of his owned quantum money to a verifier. On the other hand, an adversary must fail in counterfeiting the quantum money with overwhelmingly high probability (Unforgeability).

Tags: Multi Party Protocols, Quantum Enhanced Classical Functionality, Specific Task, Prepare (bank) and Measure (client)

## Outline

In this scheme, a Trusted Third Party (TTP) and a coin holder run the following procedure for generating and verifying a quantum coin:

• Quantum coin Generation - The TTP chooses k random 4-bit strings, keeps them in secret and produce k quantum states. A newly issued quantum coin consists of a piece of paper glued to k quantum registers that hold k quantum states. The piece of paper contains a unique identification tag and k initially unmarked positions, where the i-th position has to be marked in k-bit classical register P when the corresponding quantum state is used in the verification protocol.
• Quantum coin Verification - To verify a quantum coin through classical communication with the TTP, its holder sends the identification number of the quantum coin to the TTP. Then, the TTP and the coin holder exchange some classical information for choosing some quantum registers. The coin holder measures the chosen registers and sends their corresponding classical information to the TTP. The TTP verifies the authenticity of the coin by the secret information he possesses.

## Notations

• ${\displaystyle HMP_{4}}$-states: ${\displaystyle |\alpha (x)\rangle ={\dfrac {1}{2}}\sum _{1\leq i\leq 4}(-1)^{x_{i}}|i\rangle }$, ${\displaystyle x\in \{0,1\}^{4}}$
• for ${\displaystyle m,a,b\in \{0,1\}}$, ${\displaystyle (x,m,a,b)\in HMP_{4}}$ if ${\displaystyle b={\begin{cases}x_{1}\oplus x_{2+m}&{\text{if }}a=0\\x_{3-m}\oplus x_{4}&{\text{if }}a=1\end{cases}}}$
• ${\displaystyle HMP_{4}}$-queries: An ${\displaystyle HMP_{4}}$-query is an element ${\displaystyle m\in \{0,1\}}$. A valid answer to the query w.r.t. ${\displaystyle x\in \{0,1\}^{4}}$ is a pair ${\displaystyle (a,b)\in \{0,1\}\times \{0,1\}}$, such that ${\displaystyle (x,m,a,b)\in HMP_{4}}$. An ${\displaystyle HMP_{4}}$ -state can be used to answer an ${\displaystyle HMP_{4}}$ -query with certainty: If ${\displaystyle m=0}$, let
 ${\displaystyle v_{1}{\overset {def}{=}}{\dfrac {|1\rangle +|2\rangle }{\sqrt {2}}}}$            ${\displaystyle v_{2}{\overset {def}{=}}{\dfrac {|1\rangle -|2\rangle }{\sqrt {2}}}}$            ${\displaystyle v_{3}{\overset {def}{=}}{\dfrac {|3\rangle +|4\rangle }{\sqrt {2}}}}$            ${\displaystyle v_{4}{\overset {def}{=}}{\dfrac {|3\rangle -|4\rangle }{\sqrt {2}}}}$


otherwise (m = 1), let

 ${\displaystyle v_{1}{\overset {def}{=}}{\dfrac {|1\rangle +|3\rangle }{\sqrt {2}}}}$            ${\displaystyle v_{2}{\overset {def}{=}}{\dfrac {|1\rangle -|3\rangle }{\sqrt {2}}}}$            ${\displaystyle v_{3}{\overset {def}{=}}{\dfrac {|2\rangle +|4\rangle }{\sqrt {2}}}}$            ${\displaystyle v_{4}{\overset {def}{=}}{\dfrac {|2\rangle -|4\rangle }{\sqrt {2}}}}$


Measure ${\displaystyle |\alpha (x_{i})\rangle }$ in the basis ${\displaystyle {v_{1},v_{2},v_{3},v_{4}}}$, and let ${\displaystyle (a,b)}$ be ${\displaystyle (0,0)}$ if the outcome is ${\displaystyle v_{1}}$; ${\displaystyle (0,1)}$ in the case of ${\displaystyle v_{2}}$; ${\displaystyle (1,0)}$ in the case of ${\displaystyle v_{3}}$; ${\displaystyle (1,1)}$ in the case of ${\displaystyle v_{4}}$. Then ${\displaystyle (x,m,a,b)\in HMP_{4}}$ always.

## Properties

• General Features:
• No need to quantum communication for quantum coin verification.
• The classical communication channel used for verification can be unencrypted.
• The database of the bank is static, and therefore many de-centralized “verification branches” can exist that do not have to communicate with one another.
• The number of verifications that a quantum coin can go through is limited.
• Security Claims:
• The coins are exponentially hard to counterfeit.
• Secure against an adversary who uses adaptive “attempted verifications” in order to collect information about a coin.

## Protocol Description

Stage 1: Quantum coin generation
Input: A secret record consists of ${\displaystyle k}$ entries ${\displaystyle x_{1},...,x_{k}}$,${\displaystyle x_{i}\in \{0,1\}^{4}}$
Output: A “fresh” quantum coin
The Trusted Third Party (TTP) chooses ${\displaystyle x_{1},...,x_{k}\in \{{0,1}\}^{4}}$ at random, keeps them in secret and produces quantum states ${\displaystyle |\alpha (x_{1})\rangle ,...,|\alpha (x_{k})\rangle }$. A “fresh” quantum coin corresponding to this record consists of:

• ${\displaystyle k}$ quantum registers consisting of 2 qubits each, where the ${\displaystyle i}$-th register contains ${\displaystyle |\alpha (x_{i})\rangle }$;
• a ${\displaystyle k}$-bit classical register ${\displaystyle P}$, that is initially set to ${\displaystyle 0^{k}}$;
• a unique identification number.

Stage 2: Quantum coin verification
Input: the identification number of the quantum coin
Output: Accept or Reject

This stage is run as follows:

• The holder sends the identification number of the quantum coin to the TTP.
• The TTP chooses uniformly at random a set ${\displaystyle L_{bn}\subset [k]}$ of size ${\displaystyle t}$, and sends it to the coin holder.
• The holder consults with ${\displaystyle P}$ and chooses uniformly at random a set ${\displaystyle L_{hl}\subset L_{bn}}$ consisting of ${\displaystyle 2t/3}$ yet unmarked positions. He sends ${\displaystyle L_{hl}}$ to the bank and marks in ${\displaystyle P}$ all the elements of ${\displaystyle L_{hl}}$ as used.
• The TTP chooses at random ${\displaystyle 2t/3}$ values ${\displaystyle m_{i}\in \{{0,1}\}}$, one for each ${\displaystyle i\in L_{hl}}$ , and sends them to the coin holder.
• The holder measures the quantum registers corresponding to the elements of ${\displaystyle L_{hl}}$ in order to produce ${\displaystyle 2t/3}$ pairs ${\displaystyle (a_{i},b_{i})}$ (refer to ${\displaystyle HMP_{4}}$-queries in Notations), such that ${\displaystyle (x_{i},m_{i},a_{i},b_{i})\in HMP_{4}}$ for all ${\displaystyle i\in L_{hl}}$. He sends the list of ${\displaystyle (a_{i},b_{i})}$s to the TTP.
• The TTP checks whether ${\displaystyle (x_{i},m_{i},a_{i},b_{i})\in HMP_{4}}$ for all ${\displaystyle i\in L_{hl}}$, in which case it confirms validity of the quantum coin. Otherwise, the coin is declared to be a counterfeit.

## Further Information

Gavinsky, Dmitry. "Quantum money with classical verification." 2012 IEEE 27th Conference on Computational Complexity. IEEE, 2012, Available at: http://users.math.cas.cz/~gavinsky/papers/QuMoClaV.pdf

*contributed by Mashid Delavar