Publicly-verifiable quantum money has been a central and challenging goal in quantum cryptography. In this study, we propose an alternative notion called 'quantum cheques' (QCs) that is more achievable and technologically practical. A quantum cheque can be verified using a public-key but only by a single user. Specifically, the payer signs the quantum cheque for a particular recipient using their ID, and the recipient can validate it without the assistance of the bank, ensuring that the payer cannot assign the same cheque to another user with a different ID. Unlike quantum money, QCs only necessitate quantum communication when a cheque is issued by the bank, meaning all payments and deposits are entirely classical! We demonstrate how to construct QCs based on the well-studied learning-with-errors (LWE) assumption. In the process, we build two novel primitives which are of independent interest. Firstly, we construct 'signatures with publicly-verifiable deletion' under LWE. This primitive enables the signing of a message $m$ such that the recipient can produce a classical string that publicly proves the inability to reproduce a signature of $m$. We then demonstrate how this primitive can be used to construct '2-message signature tokens'. This primitive enables the production of a token that can be used to sign a single bit and then self-destructs. Finally, we show that 2-message signature tokens can be used to construct QCs.
翻译:公开可验证的量子货币一直是量子密码学领域的核心挑战性目标。在本研究中,我们提出了一种更具可行性且技术实用的替代概念——"量子支票"(QCs)。量子支票可通过公钥验证,但仅限单一用户执行。具体而言,付款方使用收款方身份标识签署特定量子支票,收款方无需银行协助即可验证支票有效性,从而确保付款方无法将同一张支票分配给其他不同身份标识的用户。与量子货币不同,量子支票仅在银行签发阶段需要量子通信,这意味着所有支付与结算流程均为经典通信!我们展示了如何基于广泛研究的学习带错误(LWE)假设构建量子支票。在此过程中,我们构建了两个具有独立创新价值的原始工具:首先,基于LWE构建了"可公开验证删除签名"原语,该原语允许签署消息$m$,使接收方能生成公开证明其无法复现$m$签名的经典字符串;进而演示如何利用该原语构建"两消息签名令牌",该令牌可用于签署单个比特后自销毁。最后,我们证明两消息签名令牌可被用于构建量子支票。