Can you sign a quantum state?

Gorjan Alagic1,2, Tommaso Gagliardoni3, and Christian Majenz4

1QuICS, University of Maryland, College Park, MD, USA
2National Institute of Standards and Technology, Gaithersburg, MD, USA
3Kudelski Security, Zurich, Switzerland
4Centrum Wiskunde & Informatica and QuSoft, Amsterdam, Netherlands

Cryptography with quantum states exhibits a number of surprising and counterintuitive features. In a 2002 work, Barnum et al. argue that these features imply that digital signatures for quantum states are impossible (Barnum et al., FOCS 2002). In this work, we ask: can all forms of signing quantum data, even in a possibly weak sense, be completely ruled out? We give two results which shed significant light on this basic question.
First, we prove an impossibility result for digital signatures for quantum data, which extends the result of Barnum et al. Specifically, we show that no nontrivial combination of correctness and security requirements can be fulfilled, beyond what is achievable simply by measuring the quantum message and then signing the outcome. In other words, $\textit{only classical signature schemes exist}$.
We then show a positive result: a quantum state can be signed with the same security guarantees as classically, provided that it is also encrypted with the public key of the intended recipient. Following classical nomenclature, we call this notion $\textit{quantum signcryption}$. Classically, signcryption is only interesting if it provides superior performance to encypt-then-sign. Quantumly, it is far more interesting: it is the only signing method available. We develop "as-strong-as-classical" security definitions for quantum signcryption and give secure constructions based on post-quantum public-key primitives. Along the way, we show that a natural hybrid method of combining classical and quantum schemes can be used to "upgrade" a secure classical scheme to the fully-quantum setting, in a wide range of cryptographic settings including signcryption, authenticated encryption, and CCA security.

► BibTeX data

► References

Cited by

[1] Prabhanjan Ananth, Aditya Gulati, Fatih Kaleoglu, and Yao-Ting Lin, Lecture Notes in Computer Science 14654, 226 (2024) ISBN:978-3-031-58736-8.

[2] Fuyuki Kitagawa, Tomoyuki Morimae, Ryo Nishimaki, and Takashi Yamakawa, Lecture Notes in Computer Science 14926, 93 (2024) ISBN:978-3-031-68393-0.

[3] Yi-Kai Liu and Dustin Moody, "Post-quantum cryptography and the quantum future of cybersecurity", Physical Review Applied 21 4, 040501 (2024).

[4] Davide Li Calsi, Paul Kohl, JinHyeock Choi, and Janis Nötzel, "The impact of message losses and retransmissions on quantum cryptographic protocols", Computer Networks 253, 110735 (2024).

[5] Giulio Malavolta and Michael Walter, Lecture Notes in Computer Science 14926, 126 (2024) ISBN:978-3-031-68393-0.

[6] Gorjan Alagic, Christian Majenz, Alexander Russell, and Fang Song, "Quantum-secure message authentication via blind-unforgeability", arXiv:1803.03761, (2018).

[7] Siyu Xiong, Bangying Tang, Hui Han, Jinquan Huang, Mingqiang Bai, Fangzhao Li, Wanrong Yu Zhiwen Mo, and Bo Liu, "Efficient Arbitrated Quantum Digital Signature with Multi-Receiver Verification", arXiv:2406.07824, (2024).

[8] Jiahui Liu, Qipeng Liu, and Luowen Qian, "Beating Classical Impossibility of Position Verification", arXiv:2109.07517, (2021).

[9] Christian Majenz, Christian Schaffner, and Jeroen van Wier, "Non-malleability for quantum public-key encryption", arXiv:1905.05490, (2019).

