English

An adaptive attack on Wiesner's quantum money

Quantum Physics 2017-02-14 v4 Cryptography and Security

Abstract

Unlike classical money, which is hard to forge for practical reasons (e.g. producing paper with a certain property), quantum money is attractive because its security might be based on the no-cloning theorem. The first quantum money scheme was introduced by Wiesner circa 1970. Although more sophisticated quantum money schemes were proposed, Wiesner's scheme remained appealing because it is both conceptually clean and relatively easy to implement. We show efficient adaptive attacks on Wiesner's quantum money scheme [Wie83] (and its variant by Bennett et al. [BBBW83]), when valid money is accepted and passed on, while invalid money is destroyed. We propose two attacks, the first is inspired by the Elitzur-Vaidman bomb testing problem [EV93, KWH+95], while the second is based on the idea of protective measurements [AAV93]. It allows us to break Wiesner's scheme with 4 possible states per qubit, and generalizations which use more than 4 states per qubit.

Keywords

Cite

@article{arxiv.1404.1507,
  title  = {An adaptive attack on Wiesner's quantum money},
  author = {Aharon Brodutch and Daniel Nagaj and Or Sattath and Dominique Unruh},
  journal= {arXiv preprint arXiv:1404.1507},
  year   = {2017}
}

Comments

a revised version with Section 4 rewritten for clarity

R2 v1 2026-06-22T03:43:50.528Z