More specifically, sigma-protocols, the Fiat-Shamir construction, and Fischlin's proof system are quantum insecure under assumptions that are sufficient for classical security. Additionally, we show that for similar reasons, computationally binding commitments provide almost no security guarantees in a quantum setting.
To show these results, we develop the "pick-one trick", a general technique that allows an adversary to find one value satisfying a given predicate, but not two.
Category / Keywords: foundations / Quantum cryptography, proofs of knowledge, rewinding, random oracles Original Publication (with major differences): FOCS 2014 Date: received 28 Apr 2014, last revised 19 Oct 2014 Contact author: unruh at ut ee Available format(s): PDF | BibTeX Citation Version: 20141019:134739 (All versions of this report) Short URL: ia.cr/2014/296 Discussion forum: Show discussion | Start new discussion