Identical-Copy Secure Unclonable Primitives
- Identical-copy secure unclonable primitives are quantum constructs that prevent adversaries from generating extra usable copies from multiple identical quantum states.
- They utilize the no‐cloning theorem and advanced state synthesis techniques to underpin secure protocols such as unclonable encryption, secret sharing, and one-shot signatures.
- These primitives bridge theoretical security guarantees with practical applications in copy-protection and cryptographic systems resistant to cloning attacks.
Identical-copy secure unclonable primitives are quantum cryptographic primitives whose security is defined against adversaries that either attempt to split a single quantum object into two independently usable systems, or are given multiple identical copies of the same pure quantum state and must still be unable to create additional usable copies or duplicate the protected functionality. Recent work distinguishes this setting sharply from both ordinary single-copy security and security against independently generated copies: in the identical-copy setting the adversary receives , not merely independent samples from a distribution over states, and this difference can change feasibility, hardness, and the form of viable constructions (Ananth et al., 6 Oct 2025). The same distinction appears in the broader notion of multi-copy security, where the target is a unclonability guarantee for exact duplicates of one pure state rather than merely collusion resistance for independently generated states (Çakan et al., 14 Oct 2025).
1. Copy complexity and the meaning of identical-copy security
The modern literature treats copy complexity as a first-class security parameter. A recurring taxonomy has three levels: single-copy security, where the adversary receives one copy of a quantum state; i.i.d.-copy security, where it receives independent copies, typically drawn as ; and identical-copy security, where it receives copies of the same pure state . The last notion is strictly stronger in the sense emphasized for copy-protection: the copies are “literally identical copies of one pure state,” not merely independent draws from the same distribution (Ananth et al., 6 Oct 2025).
This distinction is not cosmetic. In unclonable cryptography, identical copies can enable consistency tests, stronger adversarial coordination, and state-learning strategies that are absent or weaker in the single-copy model. The multi-copy literature therefore separates collusion resistance, where an adversary receives independently generated states, from multi-copy security, where it receives many exact copies of one pure state. The latter is the natural unclonability game and does not automatically follow from the former (Çakan et al., 14 Oct 2025).
For copy-protection, one representative formalization requires that the protected output be a pure state , and that from identical copies 0 no QPT adversary can produce 1 accepted evaluations: 2 This formulation makes the “identical-copy” issue explicit: the adversary is not trying merely to learn information about 3, but to turn 4 exact copies of one quantum program state into 5 successful functional uses (Ananth et al., 6 Oct 2025).
An analogous distinction appears in nonlocal challenge models. Some works treat independent challenge distributions, in which two separated branches of an adversary receive unrelated challenges, while others require security under identical challenge distributions, which more directly captures the inability to turn one quantum object into two responders that both work on the same challenge. This stronger identical-challenge formulation is particularly important for single-decryptor encryption and related reductions to unclonable encryption (Ananth et al., 2023).
2. Primitive families and their formal anti-duplication games
A central example is unclonable encryption. In the quantum encryption of classical messages framework 6, the message and key are classical but the ciphertext may be quantum. The standard unclonability game gives a ciphertext to an adversary, lets it split the state between Bob and Charlie, reveals the key to both, and declares success if both output the original message. The scheme is called 7-unclonable secure if any QPT adversary succeeds with probability at most
8
where 9 is the message length (Ananth et al., 2021). A stronger notion, unclonable-indistinguishability, asks the adversary to choose 0, receive an encryption of 1 for random 2, split the ciphertext, and then have both branches guess 3; security requires
4
This stronger notion implies both standard indistinguishability and unclonability and is the one that supports reductions to copy-protection (Ananth et al., 2021).
The one-bit version of this game has become a focal point. In the uncloneable-bit setting, the pirate adversary applies a CPTP map
5
to a ciphertext 6, and Bob and Charlie, after later receiving the key 7, output bits 8. They win iff 9. Strong security is the ideal bound 0 (Botteron et al., 2024).
A second major primitive is unclonable secret sharing (USS), introduced as a quantum analogue of secret sharing for a classical secret 1. A 2-USS scheme consists of QPT algorithms for share generation
3
and reconstruction
4
Correctness requires 5 when at least 6 valid shares are available. Unclonability is formalized by an indistinguishability-based game in which corrupted shareholders split each share into two parts destined for Bob and Charlie, both non-communicating, and the scheme is secure if they cannot both guess the challenge bit with probability noticeably better than 7: 8 The intended attack is precisely “copying a share and selling it to two buyers,” except that the shares are quantum states and the no-cloning principle may block the attack (Ananth et al., 2024).
A third family is one-shot signatures (OSS) and quantum signing tokens, where the quantum secret key is itself the unclonable resource. For OSS, even when the secret key is generated by the adversary, it should still be impossible to use one quantum signing key to produce two valid signatures. The representative oracle-model theorem gives secure OSS with 9-sized quantum secret keys such that for any quantum adversary making 0 oracle queries,
1
The security notion is strong unforgeability under quantum attack: the attacker should not be able to produce even two different valid signatures for the same verification key (Shmueli et al., 6 Nov 2025).
Further variants generalize the anti-duplication pattern. Single-decryptor encryption (SDE) asks that one quantum decryption key cannot be turned into two decryptors that both work. Tokenized signatures ask that one token cannot sign both messages 2 and 3. PRF copy-protection asks that one quantum key 4 cannot be transformed into two states that both evaluate the PRF correctly on random inputs (Coladangelo et al., 2021). Across these formulations, the core game is stable: one quantum object should not yield two independently useful descendants.
3. State families, indistinguishability principles, and generic lifting frameworks
Several quantum state families recur across the area. One foundational example is the hidden coset state
5
where 6 is a linear subspace and 7. These states have two complementary descriptions: in the computational basis they are supported on 8, while under full Hadamard transform they satisfy
9
This complementarity underlies direct-product hardness and monogamy-of-entanglement statements used for tokenized signatures, unclonable decryption, and copy-protection (Coladangelo et al., 2021).
A second structural ingredient is simultaneous Haar indistinguishability (SHI). Here the question is whether non-communicating but entangled players can distinguish receiving identical Haar-random states from receiving independent Haar-random states. For dimension 0, the central theorem gives advantage at most 1 in the single-copy case, and more generally 2 when each player receives 3 copies. The distributions are
4
versus
5
This theorem directly supports plain-model unclonable encryption with quantum decryption keys and leakage-resilient secret sharing (Ananth et al., 2024).
A third theme is generic upgrading of weaker copy notions to stronger ones. One approach is a simulation theorem for “phase-randomized” pure states: if
6
then an efficient simulator can reproduce 7 from 8 i.i.d. samples of a traced-out mixed-state family with trace-distance error bounded by
9
This theorem yields a generic bridge from single-copy or i.i.d.-copy security to identical-copy security for pure-state primitives such as public-key quantum money and copy-protection (Ananth et al., 6 Oct 2025).
A related but distinct framework is the purification compiler from collusion-resistant security to multi-copy security. It applies when a generation algorithm has classically determined outputs, so that classical randomness 0 determines a pure state 1. Using PRS and PRFs, the compiler forms purified states of the form
2
The resulting theorem states that 3 independently generated states can be transformed into something computationally indistinguishable from 4, thereby converting collusion resistance into identical-copy or multi-copy security (Çakan et al., 14 Oct 2025).
At a higher level of abstraction, unclonable puncturable obfuscation (UPO) packages anti-cloning into a reusable nonlocal game. In UPO security, an adversary receives either an obfuscation of a real circuit or a punctured variant, splits into Bob and Charlie, receives challenges 5, and tries to guess which world it is in; security requires
6
This modularizes identical-challenge and correlated-challenge security and becomes a common source for constructions of copy-protection, unclonable encryption, SDE, and quantum money (Ananth et al., 2023).
4. Positive constructions across the primitive landscape
The feasibility frontier is now populated by both unconditional and assumption-based constructions. For USS, information-theoretic feasibility is known when adversarial entanglement is absent or sufficiently restricted. In the disconnected-entanglement setting, a BB84-based construction secret-shares 7 classically into bits 8 with parity 9, encodes the 0 as 1, and reveals the basis string 2 in a classical share. The security analysis proves a monogamy-style lemma for tensor strategies: for one BB84 qubit the best simultaneous cloning success is bounded by 3, and for 4 qubits the parity-recovery advantage drops to
5
The same paper also gives a QROM construction secure against adversaries with arbitrary pre-shared entanglement, provided they are bounded in the number of random-oracle queries (Ananth et al., 2024).
For unclonable encryption, several milestones form a clear progression. A plain-model construction with quantum decryption keys uses SHI to show that the “same state to both players” and “independent states to each player” cases are simultaneously indistinguishable, yielding the first indistinguishability-secure UE in the plain model under that key model (Ananth et al., 2024). A later candidate for the unconditional uncloneable bit uses anti-commuting Clifford-algebra observables and conjectures the optimal success bound
6
That bound is proved for 7, numerically confirmed up to 8, and supported by an asymptotic upper bound of 9 together with a numerical upper bound of 0 (Botteron et al., 2024). The conjectural stage was overtaken by a full unconditional existence result: the uncloneable bit exists with cloning probability
1
for a scheme based on Clifford 2-designs. This gives exponentially small error above the ideal random-guess baseline and establishes strong uncloneability without computational assumptions (Bhattacharyya et al., 9 Mar 2026).
Unclonable signing primitives have also progressed toward lower persistent quantum memory. For OSS and quantum signing tokens, the central technical object is a coset state, and the main advance is a parallel measure-and-correct signing algorithm together with stronger subspace-hiding and anti-concentration lemmas. The oracle-model result gives 2-sized quantum secret keys, while standard-model variants achieve 3, 4, or 5 depending on assumptions such as subexponentially secure iO, exponentially secure one-way functions, LWE variants, lossy functions, and perfect decomposable trapdoor 6-to-7 functions (Shmueli et al., 6 Nov 2025). Earlier hidden-coset techniques had already given tokenized signatures in the plain model from computational direct-product hardness, with the one-bit unforgeability condition that from one token no QPT adversary can output valid signatures for both messages 8 and 9 (Coladangelo et al., 2021).
For copy-protection and quantum money, identical-copy security has moved from isolated constructions to generic lifting theorems. The copy-expansion framework upgrades i.i.d.-secure copy-protection into identical-copy secure copy-protection under post-quantum secure PRFs, and similarly upgrades one-copy secure money into multi-copy secure public-key quantum money under post-quantum secure iO and injective one-way functions (Ananth et al., 6 Oct 2025). The purification compiler then yields the first multi-copy secure constructions of public-key quantum money, SDE, and search-secure UE from collusion-resistant counterparts, while also introducing quantum coins, where every honest banknote is the same pure state, and upgradable quantum coins, whose verification mode can be strengthened later by publishing additional classical information (Çakan et al., 14 Oct 2025). In parallel, UPO provides modular implication theorems showing that puncturable schemes, evasive functions with preimage-sampleability, unclonable encryption, SDE, and public-key quantum money all follow from a single anti-cloning abstraction (Ananth et al., 2023).
A further line concerns revocable primitives. Multi-copy secure revocable encryption is achieved in the random permutation model, revocable programs in a classical oracle model, and revocable point functions in the random permutation model and the QROM, all using random subset states
0
The technical core is a 1 unforgeability theorem for subset states: from 2 copies of 3 and membership-oracle access, it remains hard to produce 4 distinct elements of 5 (Ananth et al., 2024).
5. Impossibility results, cloning attacks, and the role of entanglement
The same literature also maps strict limits on identical-copy security. For USS, information-theoretic security is impossible against fully connected adversaries with unbounded entanglement and unbounded computation. The attack uses ordinary teleportation, port-based teleportation, and repeated search over possibilities to move shares together, reconstruct the secret, and propagate it back to both recipients (Ananth et al., 2024). This shows that the existence of information-theoretically secure identical-copy primitives can depend critically on the entanglement graph and on whether adversaries are query-bounded, time-bounded, or both.
Even polynomially bounded entanglement can be sufficient against restricted reconstruction circuits. If a USS reconstruction circuit is implementable using Clifford gates and only 6 many 7-gates, then adversaries with polynomial time and polynomial pre-shared entanglement can attack it by teleporting shares together and homomorphically evaluating the reconstruction on Pauli-encrypted data. Each 8-gate requires guessing a hidden phase-correction bit, yielding success probability about 9; for 00, that inverse-polynomial success probability already violates security (Ananth et al., 2024).
Unclonable encryption exhibits analogous limitations. A generalization of the Broadbent–Lord information-theoretic construction to real-orthogonal monogamy games shows that the original 01 success upper bound is not tight. A simple cloning strategy based on the optimal phase-covariant cloner succeeds with probability at least
02
where 03. For the specific conjugate-encryption scheme, an even simpler attack succeeds with probability
04
These attacks show that the strongest form of indistinguishability-secure unclonable encryption is subtle and that some early information-theoretic constructions were significantly weaker than ideal (Ananth et al., 2021).
The multi-copy setting introduces a second kind of limitation: learnability from many identical copies. States long used in unclonable cryptography—specifically BB84 states 05, subspace or coset states, and SIS-based states—become vulnerable to tomography or state-learning when sufficiently many identical copies are available. The consequence drawn for revocable cryptography is that these familiar state families cannot directly underpin multi-copy secure revocable encryption or programs (Ananth et al., 2024).
These impossibility and attack results correct a common misconception that “unclonability” is a monolithic resource. The literature instead identifies several independent axes: whether copies are identical or merely i.i.d.; whether challenge distributions are identical or independent; whether attackers share disconnected, polynomial, or unbounded entanglement; whether correctness or reconstruction circuits have low non-Clifford complexity; and whether security is information-theoretic, oracle-based, or computational. Different points in this design space admit sharply different answers.
6. Classical and physical contrasts
The phrase “unclonable primitive” also appears in the literature on physical unclonable functions (PUFs), where the governing assumptions differ markedly from the quantum cryptographic setting. Optical PUFs are intended to be practically unclonable because of random and uncontrollable manufacturing variations, but manufacturer duplication can invalidate that premise. A notable nanofabrication study produced 99 nominal duplicates, discarded 36 visually damaged ones, and analyzed the remaining 63 copies of a non-trivial optical scattering structure. These exhibited “essentially the same scattering behavior,” with residual differences “close to or below noise levels,” so that from the PUF perspective the duplicates had to be treated as equivalent (Marakis et al., 2022).
The reported metrics illustrate the operational notion of equivalence. For the most similar pair among the 63 copies, the Pearson correlation between speckle patterns reached 87%, while the histogram of pairwise correlations peaked around 77%. After Gabor transformation and binarization, the like distribution of fractional Hamming distance had mean around 0.3, the unlike distribution mean around 0.48, and the distributions intersected at about 0.4, with no overlap for the tested samples (Marakis et al., 2022). In that setting, “unclonability” fails against the manufacturer even if it remains plausible against outsiders.
This physical contrast clarifies what is distinctive about quantum identical-copy security. In the PUF setting, effective duplication may both break old security assumptions and enable new applications such as group identification, anti-counterfeiting labels, and hardware encryption/decryption devices without embedded secret keys (Marakis et al., 2022). In the quantum setting, by contrast, the most significant recent development is that the uncloneable bit is now known to exist unconditionally, with security approaching the ideal 06 baseline exponentially fast (Bhattacharyya et al., 9 Mar 2026). A plausible implication is that the quantum notion has become more sharply delimited than the classical physical one: quantum identical-copy security is now supported by explicit no-cloning games, entropic monogamy bounds, and concrete constructive separations between feasible and infeasible regimes, whereas physical “unclonability” remains tightly coupled to fabrication models and operational noise thresholds.
Taken together, these developments place identical-copy secure unclonable primitives at the intersection of copy complexity, monogamy of entanglement, and quantum state synthesis. The field now contains formal definitions for exact-copy adversaries, generic compilers from weaker to stronger copy notions, unconditional and assumption-based constructions for multiple primitive families, and a substantial body of impossibility and attack results showing where unclonability fails. The resulting picture is not that unclonability is universally available, but that it is a technically precise and increasingly well-mapped quantum cryptographic resource.