Paper 2026/1500

How to Define Expected Quantum Polynomial-Time Zero Knowledge Simulation

Zhengnan Lai, Cornell University
Nicholas Spooner, Cornell University
Max Tromanhauser, Cornell University
Abstract

Zero knowledge is formalized via a simulator — i.e., an efficient computation which simulates the view of a (malicious) verifier. The foundational results in constant-round zero knowledge [GMW86,FS90,GK96] all use expected polynomial-time (EPT) simulators, and there is evidence that strict poly-time simulators do not exist for these protocols [BL02]. In the post-quantum setting, we must upgrade the simulator to at least quantum polynomial time (QPT) in order to properly simulate quantum verifiers. Chia et al. [CCLY22] proved a surprising negative result which precludes non-trivial ZK for constant-round protocols with both (strict) QPT and a natural notion of expected quantum polynomial-time (EQPT) black-box simulation. In light of this, Lombardi, Spooner, and Ma [LMS22] introduced a novel EQPT notion, coherent-runtime EQPT or EQPT$_c$, and showed that the [GMW86,FS90,GK96] protocols all allow for EQPT$_c$ simulation. In this work, we identify a fundamental issue with the definition of EQPT$_c$ simulation, and propose a resolution. In particular, we demonstrate that EQPT$_c$ computation is not necessarily efficient and can, in fact, decide any classical decision problem. This is possible through a freedom of choice in selecting a unitary dilation for an efficient quantum channel. We propose an revised definition which carefully restricts this choice, and prove that the definition preserves the zero knowledge of the [GMW86,FS90,GK96] protocols. Additionally, by upgrading the [GK96] framework to the fully quantum setting, we demonstrate for the first time a constant-round (malicious verifier) zero knowledge proof system for QMA (with EQPT$_c$ simulation).

Metadata
Available format(s)
PDF
Category
Foundations
Publication info
Preprint.
Keywords
zero knowledgequantum rewindingproofs of knowledge
Contact author(s)
zl345 @ cornell edu
nspooner @ cornell edu
mft55 @ cornell edu
History
2026-07-25: approved
2026-07-22: received
See all versions
Short URL
https://ia.cr/2026/1500
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1500,
      author = {Zhengnan Lai and Nicholas Spooner and Max Tromanhauser},
      title = {How to Define Expected Quantum Polynomial-Time Zero Knowledge Simulation},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1500},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1500}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.