QCCC Bit Commitments
- QCCC bit commitments are schemes that use local quantum computations with classical commit and open phases to enforce security via correctness, hiding, and binding conditions.
- They leverage various security frameworks—from relativistic no-signalling to computational hardness assumptions—to overcome the impossibility of perfectly secure non-relativistic protocols.
- Experimental implementations, including BB84-based and optical communication methods, have demonstrated practical low cheating probabilities under stringent security parameters.
QCCC bit commitments are bit-commitment schemes in which the parties may perform local quantum computation while the interaction itself is carried by classical communication. In the recent formalizations, a QCCC commitment has a commit phase and an open phase over classical channels only; at the end of commit, the committer may retain a private quantum state while the receiver holds a classical transcript, and security is usually expressed through correctness, hiding, and a sum-binding condition such as (Goldin et al., 2024, Ananth et al., 29 Sep 2025). The subject sits at the intersection of several strands of quantum cryptography: general impossibility and lower-bound results for non-relativistic quantum bit commitment, relativistic protocols that restore unconditional security by exploiting Minkowski causality, and computational or oracle-based constructions that realize commitments under specifically quantum assumptions (Chailloux et al., 2011, Kent, 2011, Khurana et al., 2023).
1. Definition and security notions
In the QCCC formalism used in recent work, a commitment scheme is given by QPT algorithms for the committer and receiver that exchange only classical messages in both the commit and open phases. During the protocol, the committer may keep a private quantum state and the receiver may keep local quantum side information, but the transcript itself is classical (Goldin et al., 2024). Security is usually divided into three parts: correctness, hiding, and binding. The hiding requirement states that the receiver cannot distinguish a commitment to $0$ from a commitment to $1$ except with negligible advantage; the binding requirement states that no efficient cheating committer can later open the same commitment successfully to both values except with negligible excess over unity, typically written as (Goldin et al., 2024, Ananth et al., 29 Sep 2025).
The same structure appears in more general quantum bit-commitment definitions. In the standard information-theoretic formulation, honest commitment to bit produces a joint state , with Bob’s reduced state . Bob’s cheating power is lower-bounded by Helstrom distinguishability, while Alice’s equivocation power is expressed through the probabilities of unveiling both bits after commit (Chailloux et al., 2011). In perfectly hiding protocols, Bob’s reduced state after commit is independent of ; in the separable-operations model, this is written as (Chaoui et al., 13 Jan 2025).
A recurrent technical distinction is between unconditional, statistical, computational, and model-restricted security. Unconditional security is obtained in relativistic protocols whose security relies on no-signalling, no-cloning, or monogamy of entanglement (Kent, 2011, Adlam et al., 2015). Computational security appears in constructions based on one-way state generators, hidden-permutation state distinction, or oracle assumptions (Khurana et al., 2023, Yamakami, 2013, Goldin et al., 2024). Restricted-adversary models include limitations to separable operations, polynomial-size cheating circuits, or technological constraints such as the absence of practical long-term quantum memory (Chaoui et al., 13 Jan 2025, Sheikholeslam et al., 2011, Danan et al., 2012).
2. Impossibility results and lower-bound landscape
A central fact in the field is that perfectly secure bit commitment is impossible through asynchronous exchange of classical and quantum information. This impossibility is stated explicitly in several later works and underlies the modern search for supplementary assumptions, whether relativistic, computational, or physical (Lunghi et al., 2014, Lunghi et al., 2013). Non-relativistic quantum protocols are also constrained quantitatively: the optimal cheating probability of any information-theoretic quantum bit-commitment protocol is at least approximately $0.739$, and there exists a protocol with cheating probability arbitrarily close to $0$0 by combining bit commitment with weak coin flipping (Chailloux et al., 2011). The same work shows that any classical bit-commitment protocol with access to perfect weak or strong coin flipping still has cheating probability at least $0$1 (Chailloux et al., 2011).
This lower-bound perspective is important for QCCC because it explains why the classical-channel restriction does not by itself create secure commitments. Additional structure is needed. One route is relativistic space-time separation; another is computational one-wayness; a third is an explicit restriction on the adversary’s quantum operations (Kent, 2011, Khurana et al., 2023, Chaoui et al., 13 Jan 2025).
Recent work also identifies specific assumptions that do not suffice in a black-box way. In particular, pseudorandom unitaries do not yield QCCC bit commitments via any fully black-box construction with only forward oracle access. The impossibility theorem rules out such reductions even with arbitrary polynomially many rounds of classical interaction, and the underlying distinguishing-advantage bound is of order $0$2 (Ananth et al., 29 Sep 2025). Conversely, oracle results show that QCCC commitments can exist in relativized worlds that collapse other complexity classes: there is a quantum oracle relative to which $0$3 but QCCC commitments exist, and QCCC commitments imply one-way puzzles in that framework (Goldin et al., 2024). The same paper states that one-way puzzles cannot exist if $0$4, and uses this to position QCCC commitments inside the class it calls “CountCrypt” (Goldin et al., 2024).
3. Relativistic and no-summoning foundations
The main unconditional-security route for bit commitment comes from combining quantum information with special relativity. In Kent’s flying-qudit protocol, Bob chooses an unknown pure qudit state $0$5 and hands it to Alice at a point $0$6. To commit to bit $0$7, Alice sends the qudit at light speed along one of two opposite light-like rays $0$8 or $0$9, and to unveil she returns it at a point $1$0. Bob verifies using the projector $1$1 (Kent, 2011). The hiding property is exact because Bob receives no $1$2-dependent information before unveiling, while binding follows from the no-cloning theorem and no-superluminal signalling. The cheating bound is $1$3, which tends to $1$4 as $1$5 (Kent, 2011).
A second major relativistic construction is the BB84 measurement-outcome protocol. Bob sends $1$6 random BB84 states to Alice at a commitment point $1$7. To commit to $1$8, Alice measures all qubits in the computational basis; to commit to $1$9, she measures in the Hadamard basis. She then sends the encrypted outcome string at light speed to two space-like separated unveiling points 0 and 1, and Bob accepts only if the two unveiled records agree and are consistent with the states he prepared (Kent, 2011). The protocol is perfectly hiding, and its binding analysis reduces cheating to simultaneous inference of incompatible BB84 outcomes. Using the optimal single-qubit Breidbart strategy, the overall cheating probability is bounded by
2
so the protocol is unconditionally binding with exponentially decaying 3 (Kent, 2011).
The same geometric intuition was later recast in the language of summoning. In this viewpoint, a cheating strategy would require Alice to guarantee return of an unknown quantum state at more than one space-like separated site, which is ruled out by no-summoning. The fidelity-based form of the argument yields the same approximate-cloning bound 4 for unveiling probabilities, and the paper argues that protocols of this type can be proven secure against some classes of post-quantum but non-signalling adversaries (Kent, 2018).
Relativistic protocols also admit entanglement-based deterministic variants. In deterministic relativistic quantum bit commitment, Alice prepares 5 Bell singlets, gives one labelled half-set to Bob at the commitment point, and later supplies the matching remote halves at the unveiling point corresponding to the committed bit. Verification consists of Bell-basis measurements projecting onto 6, and the binding analysis uses monogamy of entanglement together with causality. For the ideal ETBC scheme, the operator bound 7 yields
8
while Bob’s reduced state is independent of the committed bit (Adlam et al., 2015).
4. Practical and experimental realizations
The relativistic program led rapidly to field implementations. “Experimental unconditionally secure bit commitment” implemented the BB84 outcome-transmission protocol with two quantum key distribution systems, 1 GHz free-space optical links, and unveiling agents separated by more than 9 km (Liu et al., 2013). Bob used four laser diodes at 0 nm with mean photon number 1 and repetition rate 2 MHz; Alice’s setup used a rotatable HWP, PBS, and two silicon SPDs with 3 quantum efficiency and dark count about 4 cps (Liu et al., 2013). For the experimental thresholds 5, 6, and 7, the paper computed 8 and therefore total security parameter 9 per run (Liu et al., 2013).
A second field demonstration modified the earlier quantum-communication-plus-relativity protocol so that the quantum exchange could occur before the actual commitment. In that protocol, Bob measures Alice’s BB84 pulses in a random basis in advance, reports the detected subset to his remote agents, and only at commit time sends the one-bit mask 0 to encode the true commitment 1 (Lunghi et al., 2013). The commitment duration is
2
so for the Geneva–Singapore separation 3 km the experiment achieved 4 ms (Lunghi et al., 2013). With 5, 6 pulses per block, observed 7, QBER 8, and about 9 detections, the finite-size analysis gave 0 (Lunghi et al., 2013).
Relativistic commitments based only on classical communication were developed in parallel. The one-round sBGKW protocol is secure against quantum adversaries for a duration bounded by the light-travel time 1, while the multi-round finite-field protocol extends the commitment time arbitrarily and is proven secure against classical attacks (Lunghi et al., 2014). The paper gives a concrete antipodal-Earth example with 2 rounds, 3, total duration about 4 ms, and multi-round binding parameter 5 (Lunghi et al., 2014).
This line culminated in a 24-hour implementation using timed high-speed optical communication and fast data processing only, with all agents located within the city of Geneva (Verbanis et al., 2016). For 6 km, 7, and roughly 8 rounds, the experiment exchanged about 9 GB of data at an average rate of 0 MB/s (Verbanis et al., 2016). The theoretical cheating bound is
1
and the paper argues that the same protocol family could be extended to one year by increasing separation and relaxing response times (Verbanis et al., 2016).
| Protocol family | Main operational feature | Reported figure |
|---|---|---|
| BB84 outcome transmission (Liu et al., 2013) | Quantum measurements at commit, encrypted records sent to two remote agents | 2 per run |
| Quantum communication + relativity (Lunghi et al., 2013) | Quantum phase decoupled from commit time | 3 ms, 4 |
| Multi-round classical relativistic (Lunghi et al., 2014) | Finite-field sustain rounds | up to 5 ms, 6 |
| 24-hour relativistic commitment (Verbanis et al., 2016) | Timed high-speed optical communication only | 7 h demonstration |
5. Computational and oracle-based QCCC constructions
A distinct research direction studies QCCC commitments under computational assumptions. A non-interactive example is Yamakami’s scheme exploiting the computational hardness of quantum state distinction (Yamakami, 2013). Alice commits by sending a reduced state 8 derived from hidden-permutation states 9, and later reveals 0 so that Bob can run the state-partitioning test. The scheme is computationally concealing and statistically binding under the assumption that no polynomial-time quantum algorithm distinguishes the ensembles 1 and 2 with non-negligible advantage; this assumption is stated to be guaranteed, for example, by computational hardness of the graph automorphism problem on a quantum computer (Yamakami, 2013).
More recent work identifies a broader constructive pathway from quantum one-wayness. “Commitments from Quantum One-Wayness” proves that pure-state one-way state generators imply one-way puzzles, and that one-way puzzles imply quantum bit commitments (Khurana et al., 2023). The construction passes through shadow tomography, weak pseudoentropy generators, pseudoentropy generators, and imbalanced EFI, and the final protocol is explicitly QCCC in the sense that “only classical messages” are exchanged while any quantum work remains local (Khurana et al., 2023). The resulting commitment is computationally hiding and computationally binding under the assumption of a pure-state one-way state generator with linear copy security (Khurana et al., 2023).
Oracle constructions sharpen the complexity-theoretic picture. In “CountCrypt,” the QCCC commitment protocol is defined by a classical commit message and a two-message classical opening phase, while the parties obtain quantum states only from internal oracle calls to 3 and 4 (Goldin et al., 2024). The protocol is statistically hiding because the commit transcript is a uniformly random suffix 5 independent of the committed bit, and computationally binding because opening both values would require effectively holding two orthogonal Haar-random states that the oracle never provides simultaneously (Goldin et al., 2024). The paper states that, with probability 6 over the choice of 7, the protocol is statistically hiding and computationally binding as a QCCC bit-commitment scheme (Goldin et al., 2024).
Composable extensions also exist. “A Private Quantum Bit String Commitment” gives an entanglement-based protocol using an EPR-pair source and two random oracles 8 and 9, with composability proven in the random oracle model (Gama et al., 2020). Alice measures her halves of $0.739$0 EPR pairs in randomly chosen $0.739$1 or $0.739$2 bases, forms $0.739$3 and $0.739$4, and Bob reconstructs the committed string after Alice reveals $0.739$5 (Gama et al., 2020). The paper defines $0.739$6-concealing, $0.739$7-binding, and $0.739$8-privacy, requires an authenticated classical channel for privacy, and remarks that a single-bit QCCC commitment is obtained as a special case (Gama et al., 2020).
6. Restricted-adversary models, practical assumptions, and disputed regimes
Some protocols recover security by limiting the adversary’s admissible quantum operations. “Secure quantum bit commitment from separable operations” proves that in any perfectly hiding bit-commitment protocol, an honestly committing Alice restricted to separable operations will be detected with high probability if she later attempts to alter her commitment (Chaoui et al., 13 Jan 2025). In the AME$0.739$9 example, Bob’s reduced state is exactly maximally mixed for both bits, and the binding proof shows
$0$00
With the optimal choice of Schmidt weights this becomes $0$01, so the protocol is $0$02-honest-binding and Alice is caught with probability at least $0$03 (Chaoui et al., 13 Jan 2025). This model is not unconditional against arbitrary quantum adversaries, but it isolates a precise operational restriction.
Other proposals rely on bounded cheating resources rather than separability. In the single-qubit-unitary protocol of Sheikholeslam and Gulliver, Bob sends $0$04 and $0$05, Alice applies her secret $0$06 to the state indexed by the committed bit, and Bob later inverts using $0$07 (Sheikholeslam et al., 2011). The protocol is perfectly concealing in the noiseless ideal and is argued to be computationally binding against polynomial-size entanglement attacks because a cheating unitary would have to act coherently over an exponentially large space indexed by $0$08; the paper states $0$09 and overall cheating probability at most $0$10 under parallel repetition (Sheikholeslam et al., 2011).
A more explicitly technological approach is the practical protocol based on limitations on nondemolition measurements and long-term quantum memory (Danan et al., 2012). Bob sends BB84 polarization states at secret random times, Alice immediately announces the detection times, and later reveals the basis and outcomes. The concealing property is perfect in the ideal model, while binding relies on the claim that Alice cannot both identify photon arrival times nondestructively and preserve the polarization qubit until the opening phase. If she attempts basis-independent cheating with the Breidbart basis, the per-photon error is
$0$11
so Bob can set $0$12 to detect cheating with overwhelming probability (Danan et al., 2012).
Counterfactual schemes provide yet another physical variant. In the counterfactual protocol built from an N09-style comparison primitive, the relevant parameters for $0$13 are
$0$14
and the paper states that choosing, for example, $0$15 and $0$16 makes both the binding and concealing errors $0$17 (Song et al., 2018). The same paper argues that the standard Mayers–Lo–Chau attack is not implementable with current technology because it would require keeping a macroscopic optical switch in coherent superposition of timings (Song et al., 2018). This does not contradict the general no-go theorems; rather, it places the security claim in a technologically bounded regime.
Taken together, these results show that “QCCC bit commitments” name not a single security theorem but a family of constructions separated by their auxiliary assumptions. Unconditional security is obtained in relativistic models using no-signalling, no-cloning, no-summoning, or monogamy of entanglement (Kent, 2011, Adlam et al., 2015). Computational QCCC commitments arise from one-way state generators, one-way puzzles, random oracles, or oracle worlds such as CountCrypt (Khurana et al., 2023, Gama et al., 2020, Goldin et al., 2024). Restricted-operation and technological models sit between these extremes, often clarifying which physical or algorithmic resource is doing the cryptographic work (Chaoui et al., 13 Jan 2025, Danan et al., 2012).