English

Quantum Bit String Commitment

Quantum Physics 2009-11-07 v4 Cryptography and Security

Abstract

A bit string commitment protocol securely commits NN classical bits in such a way that the recipient can extract only M<NM<N bits of information about the string. Classical reasoning might suggest that bit string commitment implies bit commitment and hence, given the Mayers-Lo-Chau theorem, that non-relativistic quantum bit string commitment is impossible. Not so: there exist non-relativistic quantum bit string commitment protocols, with security parameters ϵ\epsilon and MM, that allow AA to commit N=N(M,ϵ)N = N(M, \epsilon) bits to BB so that AA's probability of successfully cheating when revealing any bit and BB's probability of extracting more than N=NMN'=N-M bits of information about the NN bit string before revelation are both less than ϵ\epsilon. With a slightly weakened but still restrictive definition of security against AA, NN can be taken to be O(exp(CN))O(\exp (C N')) for a positive constant CC. I briefly discuss possible applications.

Keywords

Cite

@article{arxiv.quant-ph/0111099,
  title  = {Quantum Bit String Commitment},
  author = {Adrian Kent},
  journal= {arXiv preprint arXiv:quant-ph/0111099},
  year   = {2009}
}

Comments

Published version. (Refs updated.)