This paper introduces quantum analogues of non-interactive perfect and statistical zero-knowledge proof systems. Similar to the classical cases, it is shown that sharing randomness or entanglement is necessary for non-trivial protocols of non-interactive quantum perfect and statistical zero-knowledge. It is also shown that, with sharing EPR pairs a priori, the class of languages having one-sided bounded error non-interactive quantum perfect zero-knowledge proof systems has a natural complete problem. Non-triviality of such a proof system is based on the fact proved in this paper that the Graph Non-Automorphism problem, which is not known in BQP, can be reduced to our complete problem. Our results may be the first non-trivial quantum zero-knowledge proofs secure even against dishonest quantum verifiers, since our protocols are non-interactive, and thus the zero-knowledge property does not depend on whether the verifier in the protocol is honest or not. A restricted version of our complete problem derives a natural complete problem for BQP.
In this paper we propose a definition for (honest verifier) quantum statistical zero-knowledge interactive proof systems and study the resulting complexity class, which we denote QSZK. We prove several facts regarding this class that establish close connections between classical statistical zero-knowledge and our definition for quantum statistical zero-knowledge, and give some insight regarding the effect of this zero-knowledge restriction on quantum interactive proof systems.
We present efficient zero-knowledge proof systems for quasi-safe prime products and other related languages. Quasi-safe primes are a relaxation of safe primes, a class of prime numbers useful in many cryptographic applications. Our proof systems achieve higher security and better efficiency than all previously known ones. In particular, all our proof systems are perfect or statistical zero-knowledge, meaning that even a computationally unbounded adversary cannot extract any information from the proofs. Moreover, our proof systems are extremely efficient because they do not use general reductions to NP-complete problems, can be easily parallelized preserving zero-knowledge, and are non-interactive for computationally unbounded provers. The prover can also be efficiently implemented given some trapdoor information and using very little interaction. We demonstrate the applicability of quasi-safe primes by showing how they can be effectively used in the context of RSA based undeniable signatures to enforce the use of "good" public keys, i.e., keys such that if a signer can convince a recipient of the validity of a signature, then he won't be able to subsequently deny the same signature in case of a dispute.
There had been well known claims of unconditionally secure quantum protocols for bit commitment. However, we, and independently Mayers, showed that all proposed quantum bit commitment schemes are, in principle, insecure because the sender, Alice, can almost always cheat successfully by using an Einstein-Podolsky-Rosen (EPR) type of attack and delaying her measurements. One might wonder if secure quantum bit commitment protocols exist at all. We answer this question by showing that the same type of attack by Alice will, in principle, break any bit commitment scheme. The cheating strategy generally requires a quantum computer. We emphasize the generality of this ``no-go theorem'': Unconditionally secure bit commitment schemes based on quantum mechanics---fully quantum, classical or quantum but with measurements---are all ruled out by this result. Since bit commitment is a useful primitive for building up more sophisticated protocols such as zero-knowledge proofs, our results cast very serious doubt on the security of quantum cryptography in the so-called ``post-cold-war'' applications. We also show that ideal quantum coin tossing is impossible because of the EPR attack. This no-go theorem for ideal quantum coin tossing may help to shed some lights on the possibility of non-ideal protocols.
P. What is Number Theory? 1. The Integers. Numbers and Sequences. Sums and Products. Mathematical Induction. The Fibonacci Numbers. 2. Integer Representations and Operations. Representations of Integers. Computer Operations with Integers. Complexity of Integer Operations. 3. Primes and Greatest Common Divisors. Prime Numbers. The Distribution of Primes. Greatest Common Divisors. The Euclidean Algorithm. The Fundemental Theorem of Arithmetic. Factorization Methods and Fermat Numbers. Linear Diophantine Equations. 4. Congruences. Introduction to Congruences. Linear Congrences. The Chinese Remainder Theorem. Solving Polynomial Congruences. Systems of Linear Congruences. Factoring Using the Pollard Rho Method. 5. Applications of Congruences. Divisibility Tests. The perpetual Calendar. Round Robin Tournaments. Hashing Functions. Check Digits. 6. Some Special Congruences. Wilson's Theorem and Fermat's Little Theorem. Pseudoprimes. Euler's Theorem. 7. Multiplicative Functions. The Euler Phi-Function. The Sum and Number of Divisors. Perfect Numbers and Mersenne Primes. Mobius Inversion. 8. Cryptology. Character Ciphers. Block and Stream Ciphers. Exponentiation Ciphers. Knapsack Ciphers. Cryptographic Protocols and Applications. 9. Primitive Roots. The Order of an Integer and Primitive Roots. Primitive Roots for Primes. The Existence of Primitive Roots. Index Arithmetic. Primality Tests Using Orders of Integers and Primitive Roots. Universal Exponents. 10. Applications of Primitive Roots and the Order of an Integer. Pseudorandom Numbers. The EIGamal Cryptosystem. An Application to the Splicing of Telephone Cables. 11. Quadratic Residues. Quadratic Residues and nonresidues. The Law of Quadratic Reciprocity. The Jacobi Symbol. Euler Pseudoprimes. Zero-Knowledge Proofs. 12. Decimal Fractions and Continued. Decimal Fractions. Finite Continued Fractions. Infinite Continued Fractions. Periodic Continued Fractions. Factoring Using Continued Fractions. 13. Some Nonlinear Diophantine Equations. Pythagorean Triples. Fermat's Last Theorem. Sums of Squares. Pell's Equation. 14. The Gaussian Integers. Gaussian Primes. Unique Factorization of Gaussian Integers. Gaussian Integers and Sums of Squares.