Signing quantum messages was proven to be impossible even under computational assumptions. We realize that this result can be circumvented if the signing procedure varies with respect to some dimension. Specifically, we provide two approaches to sign quantum messages that are the first to ensure authenticity with public verifiability: (1) We construct a notion we term time-dependent signatures assuming one-way functions. In this setting, the signature of a message depends on the time it is signed and, as a result, the verification procedure depends on the time that the signature is received. The keys are classical but the verification key needs to be continually updated. (2) We construct an information-theoretically secure signature scheme in the bounded quantum storage model where adversaries have bounded quantum memories. Our scheme can be made secure against adversaries with arbitrarily large quantum memories by increasing the size of the transmissions sufficiently, while honest users only need $O(\ell^2)$ quantum memory where $\ell$ is the size of the plaintext quantum messages. Furthermore, we apply our time-dependent signatures to perform the following tasks assuming only one-way functions: (a) Construct a quantum public key encryption scheme with authenticated quantum public keys which resist adversarial tampering. (b) Build a public-key quantum money scheme with unforgeable, unclonable, and publicly verifiable banknotes that have a limited lifespan.
翻译:即使是在计算假设下,签署量子消息已被证明是不可能的。我们意识到,如果签署过程随某个维度变化,则可以规避这一结果。具体而言,我们提供了两种签署量子消息的方法,这些方法是首批确保具有公开可验证性的真实性的方法:(1)我们构建了一个称为“时间相关签名”的概念,该概念假定存在单向函数。在此设置下,消息的签名取决于其签署的时间,因此验证过程取决于收到签名的时间。密钥是经典密钥,但验证密钥需要持续更新。(2)我们在有界量子存储模型中构建了一个信息论安全的签名方案,在该模型中,敌手拥有有界量子内存。我们的方案可以通过足够增加传输大小来抵御拥有任意大量子内存的敌手,而诚实用户仅需要$O(\ell^2)$的量子内存,其中$\ell$是明文量子消息的大小。此外,我们仅假定单向函数存在,将时间相关签名应用于以下任务:(a)构建具有防篡改认证的量子公钥加密方案;(b)构建具有不可伪造、不可克隆和公开可验证且具有有限寿命的钞票的公钥量子货币方案。