Serial composition of quantum coin flipping and bounds on cheat detection for bit commitment
نویسنده
چکیده
Quantum protocols for coin flipping can be composed in series in such a way that a cheating party gains no extra advantage from using entanglement between different rounds. This composition principle applies to coin-flipping protocols with cheat sensitivity as well, and is used to derive two results: There are no quantum strong coin-flipping protocols with cheat sensitivity that is linear in the bias (or bit-commitment protocols with linear cheat detection) because these can be composed to produce strong coin flipping with arbitrarily small bias. On the other hand, it appears that quadratic cheat detection cannot be composed in series to obtain even weak coin flipping with arbitrarily small bias.
منابع مشابه
Large family of quantum weak coin-flipping protocols
Each classical public-coin protocol for coin flipping is naturally associated with a quantum protocol for weak coin flipping. The quantum protocol is obtained by replacing classical randomness with quantum entanglement and by adding a cheat detection test in the last round that verifies the integrity of this entanglement. The set of such protocols defines a family which contains the protocol wi...
متن کاملQuantum coin flipping with arbitrary small bias is impossible
Lo and Chau [7] showed that ideal quantum coin flipping protocol is impossible. The proof was simply derived from the impossibility proof of quantum bit commitment [7, 8]. However, the proof still leaves the possibility of quantum coin flipping protocol with arbitrary small bias. In this paper, we show that quantum coin flipping protocol with arbitrary small bias is impossible and show the lowe...
متن کاملA Simpler Proof of the Existence of Quantum Weak Coin Flipping with Arbitrarily Small Bias
God does not play dice. He flips coins instead.” And though for some reason He has denied us quantum bit commitment. And though for some reason he has even denied us strong coin flipping. He has, in His infinite mercy, granted us quantum weak coin flipping so that we too may flip coins. Instructions for the flipping of coins are contained herein. But be warned! Only those who have mastered Kita...
متن کاملWhy quantum bit commitment and quantum coin tossing are impossible ? ∗
There had been well known claims of “provably unbreakable” quantum protocols for bit commitment and coin tossing. However, we, and independently Mayers, showed that all proposed quantum bit commitment (and coin tossing) schemes are, in principle, insecure because the sender, Alice, can always cheat successfully by using an EPR-type of attack and delaying her measurements. One might wonder if se...
متن کاملWhy quantum bit commitment and ideal
There had been well known claims of “provably unbreakable” quantum protocols for bit commitment and coin tossing. However, we, and independently Mayers, showed that all proposed quantum bit commitment (and therefore coin tossing) schemes are, in principle, insecure because the sender, Alice, can always cheat successfully by using an EPR-type of attack and delaying her measurements. One might wo...
متن کامل