Quantum bit escrow

Dorit Aharonov, Amnon Ta-Shma, Umesh V. Vazirani, Andrew C. Yao

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

94 Scopus citations


Unconditionally secure bit commitment and coin flipping are known to be impossible in the classical world. Bit commitment is known to be impossible also in the quantum world. We introduce a related new primitive - quantum bit escrow. In this primitive Alice commits to a bit b to Bob. The commitment is bindingin the sense that if Alice is asked to reveal the bit, Alice can not bias her commitment without having a good probability of being detected cheating. The commitment is sealing in the sense that if Bob learns information about the encoded bit, then if later on he is asked to prove he was playing honestly, he is detected cheating with a good probability. Rigorously proving the correctness of quantum cryptographic protocols has proved to be a difficult task. We develop techniques to prove quantitative statements about the binding and sealing properties of the quantum bit escrow protocol. A related primitive we construct is a quantum biased coin flipping protocol where no player can control the game, i.e., even an all-powerful cheating player must lose with some constant probability, which stands in sharp contrast to the classical world where such protocols are impossible.

Original languageAmerican English
Title of host publicationProceedings of the 32nd Annual ACM Symposium on Theory of Computing, STOC 2000
Number of pages10
StatePublished - 2000
Externally publishedYes
Event32nd Annual ACM Symposium on Theory of Computing, STOC 2000 - Portland, OR, United States
Duration: 21 May 200023 May 2000

Publication series

NameProceedings of the Annual ACM Symposium on Theory of Computing
ISSN (Print)0737-8017


Conference32nd Annual ACM Symposium on Theory of Computing, STOC 2000
Country/TerritoryUnited States
CityPortland, OR


  • quantum bit commitment
  • quantum coin tossing
  • quantum cryptography


Dive into the research topics of 'Quantum bit escrow'. Together they form a unique fingerprint.

Cite this