Questions tagged [quantum-money]

For questions about money whose security is based on aspects of the No-Cloning Theorem.

Use for questions about money whose security is based on aspects of the No-Cloning Theorem. For example, questions regarding Wiesner's scheme from the 1970's, or more recent public-key schemes from the early 2010's, or other questions about distributed ledgers and quantum money from the late 2010's.

12 questions
22
votes
1 answer

Quantum Bitcoin Subdivision

Background Recently I was reading the article "Quantum Bitcoin: An Anonymous and Distributed Currency Secured by the No-Cloning Theorem of Quantum Mechanics" which demonstrates how a quantum bitcoin could function. The article's conclusion states…
11
votes
2 answers

Rigorous security proof for Wiesner's quantum money

In his celebrated paper "Conjugate Coding", Wiesner proposed a scheme for quantum money that is unconditionally impossible to counterfeit, assuming that the issuing bank has access to a giant table of random numbers and that banknotes can be brought…
8
votes
0 answers

Are non-secret-based quantum money mini-schemes susceptable to Jogenfors' "reuse attack?"

Aaronson and Christiano call public-key or private-key quantum mini-schemes $\mathcal M$ secret-based if a mint works by first uniformly generating a secret random classical strings $r$, and then generating a banknote $\$:=(s_r,\rho_r)$, where $s_r$…
8
votes
1 answer

Do we have to trust the bank in "Quantum Money from Hidden Subspaces?"

What level of trust in the bank is needed in "Quantum Money from Hidden Subspaces" of Aaronson and Christiano (arXiv)? The bank's mint works by first generating a uniformly random classical secret string $r$, and then generating a banknote…
Mark Spinelli
  • 15,378
  • 3
  • 26
  • 83
8
votes
1 answer

Can quantum money be reliably "burned?"

One of the novel features of Bitcoin and other cryptocurrencies is that coins can be irrefutably "burned" or destroyed, by creating a transaction to send the money to a junk burn address. Thinking similarly about quantum money - from knots, or…
7
votes
1 answer

What role do Hecke operators and ideal classes perform in “Quantum Money from Modular Forms?”

Cross-posted on MO The original ideas from the 70's/80's - that begat the [BB84] quantum key distribution - concerned quantum money that is unforgeable by virtue of the no-cloning theorem. A limitation was that the quantum money required the bank…
Mark Spinelli
  • 15,378
  • 3
  • 26
  • 83
6
votes
2 answers

Can a merchant who accepts a knot-based quantum coin mint her own knot-based coin?

Referring to Farhi, Gosset, Hassidim, Lutomirski, and Shor's "Quantum Money from Knots," a mint $\mathcal{M}$ generates a run of coins, including, say, $(s,|\$\rangle)$, using a quantum computer to mint $|\$\rangle$ while publishing the public…
Mark Spinelli
  • 15,378
  • 3
  • 26
  • 83
5
votes
2 answers

How to calculate the spectral norm of the density operator used in Molina et al. 2012 paper?

In Molina et al (2012)'s article on quantum money, the proof of security of Wiesner's quantum money scheme depends on the fact that the density operator $$Q = \frac{1}{4}\sum_{k \in \{0, 1, +, -\}}\left|kkk\right>\left
Malper
  • 153
  • 4
5
votes
2 answers

Has Blockchain made Quantum Money obsolete?

Quantum Money is an old proposal that solves the forgeability problem of traditional banknotes, by leveraging the No-Cloning Theorem. Recently, blockchains solved the Double-Spending problem allowing them to be de facto usable as money. Indeed even…
Rexcirus
  • 153
  • 5
4
votes
1 answer

Are commuting unitary operators related to commuting Hamiltonians?

TL/DR: Can unitary operators: $$U_a=e^{-it(H_{a1}+H_{a2}+\cdots)}$$ and $$U_b=e^{-it(H_{b1}+H_{b2}+\cdots)}$$ commute, even though $[H_{aj},H_{ak}]\ne 0$ and $[H_{bj},H_{bk}]\ne 0$ for all $j,k$? When stated as above I'm pretty sure the answer is…
4
votes
1 answer

Can Wiesner's quantum money be realized (with logical qubits) today?

Consider Wiesner's quantum money scheme. With today's devices and today's error correction and mitigation schemes, how long can we hold $n$ logical qubits such that they are all (logically) in a product state, with each logical qubit being drawn…
Mark Spinelli
  • 15,378
  • 3
  • 26
  • 83
1
vote
0 answers

About how many qubits and how many T gates is needed to verify Quantum Money from Knots?

Dalzell, McArdle, Berta, Bienias, Chen, Gilyén, Hann, Kastoryano, Khabiboulline, Kubica, Salton, Wang, and Brandão have posted a comprehensive assessment of state-of-the-art end-to-end resources needed for many quantum algorithms. Often Dalzell et…
Mark Spinelli
  • 15,378
  • 3
  • 26
  • 83