---
title: QCCC Bit Commitments
url: https://www.emergentmind.com/topics/qccc-bit-commitments
type: topic
---

# QCCC Bit Commitments

QCCC bit commitments are bit-commitment schemes in which the parties may perform local quantum computation while the interaction itself is carried by classical communication. In the recent formalizations, a QCCC commitment has a commit phase and an open phase over classical channels only; at the end of commit, the committer may retain a private quantum state while the receiver holds a classical transcript, and security is usually expressed through correctness, hiding, and a sum-binding condition such as $p_0+p_1\le 1+\varepsilon$ [2410.14792, 2509.24484]. The subject sits at the intersection of several strands of quantum cryptography: general impossibility and lower-bound results for non-relativistic quantum bit commitment, relativistic protocols that restore unconditional security by exploiting Minkowski causality, and computational or oracle-based constructions that realize commitments under specifically quantum assumptions [1102.1678, 1101.4620, 2310.11526].

## 1. Definition and security notions

In the QCCC formalism used in recent work, a commitment scheme is given by QPT algorithms for the committer and receiver that exchange only classical messages in both the commit and open phases. During the protocol, the committer may keep a private quantum state and the receiver may keep local quantum side information, but the transcript itself is classical [2410.14792]. Security is usually divided into three parts: correctness, hiding, and binding. The hiding requirement states that the receiver cannot distinguish a commitment to $0$ from a commitment to $1$ except with negligible advantage; the binding requirement states that no efficient cheating committer can later open the same commitment successfully to both values except with negligible excess over unity, typically written as $p_0+p_1\le 1+\mathrm{negl}(n)$ [2410.14792, 2509.24484].

The same structure appears in more general quantum bit-commitment definitions. In the standard information-theoretic formulation, honest commitment to bit $b$ produces a joint state $|\psi_b\rangle\in\mathcal H_A\otimes\mathcal H_B$, with Bob’s reduced state $\sigma_b=\mathrm{Tr}_A|\psi_b\rangle\langle\psi_b|$. Bob’s cheating power is lower-bounded by Helstrom distinguishability, while Alice’s equivocation power is expressed through the probabilities of unveiling both bits after commit [1102.1678]. In perfectly hiding protocols, Bob’s reduced state after commit is independent of $b$; in the separable-operations model, this is written as $\mathrm{Tr}_A[\rho_{AB}^0]=\mathrm{Tr}_A[\rho_{AB}^1]$ [2501.07351].

A recurrent technical distinction is between unconditional, statistical, computational, and model-restricted security. Unconditional security is obtained in relativistic protocols whose security relies on no-signalling, no-cloning, or monogamy of entanglement [1101.4620, 1504.00943]. Computational security appears in constructions based on one-way state generators, hidden-permutation state distinction, or oracle assumptions [2310.11526, 1309.0436, 2410.14792]. Restricted-adversary models include limitations to separable operations, polynomial-size cheating circuits, or technological constraints such as the absence of practical long-term quantum memory [2501.07351, 1111.6311, 1202.3331].

## 2. Impossibility results and lower-bound landscape

A central fact in the field is that perfectly secure bit commitment is impossible through asynchronous exchange of classical and quantum information. This impossibility is stated explicitly in several later works and underlies the modern search for supplementary assumptions, whether relativistic, computational, or physical [1411.4917, 1306.4801]. Non-relativistic quantum protocols are also constrained quantitatively: the optimal cheating probability of any information-theoretic quantum bit-commitment protocol is at least approximately $0.739$, and there exists a protocol with cheating probability arbitrarily close to $0.739+O(\varepsilon)$ by combining bit commitment with weak coin flipping [1102.1678]. The same work shows that any classical bit-commitment protocol with access to perfect weak or strong coin flipping still has cheating probability at least $3/4$ [1102.1678].

This lower-bound perspective is important for QCCC because it explains why the classical-channel restriction does not by itself create secure commitments. Additional structure is needed. One route is relativistic space-time separation; another is computational one-wayness; a third is an explicit restriction on the adversary’s quantum operations [1101.4620, 2310.11526, 2501.07351].

Recent work also identifies specific assumptions that do **not** suffice in a black-box way. In particular, pseudorandom unitaries do not yield QCCC bit commitments via any fully black-box construction with only forward oracle access. The impossibility theorem rules out such reductions even with arbitrary polynomially many rounds of classical interaction, and the underlying distinguishing-advantage bound is of order $O(q(\kappa)^2/2^n)$ [2509.24484]. Conversely, oracle results show that QCCC commitments can exist in relativized worlds that collapse other complexity classes: there is a quantum oracle relative to which $BQP=QCMA$ but QCCC commitments exist, and QCCC commitments imply one-way puzzles in that framework [2410.14792]. The same paper states that one-way puzzles cannot exist if $BQP=PP$, and uses this to position QCCC commitments inside the class it calls “CountCrypt” [2410.14792].

## 3. Relativistic and no-summoning foundations

The main unconditional-security route for bit commitment comes from combining quantum information with special relativity. In Kent’s flying-qudit protocol, Bob chooses an unknown pure qudit state $|\psi\rangle\in\mathcal H\cong\mathbb C^d$ and hands it to Alice at a point $P$. To commit to bit $i\in\{0,1\}$, Alice sends the qudit at light speed along one of two opposite light-like rays $L_0$ or $L_1$, and to unveil she returns it at a point $Q_i\in L_i$. Bob verifies using the projector $P_\psi=|\psi\rangle\langle\psi|$ [1101.4620]. The hiding property is exact because Bob receives no $i$-dependent information before unveiling, while binding follows from the no-cloning theorem and no-superluminal signalling. The cheating bound is $p_0+p_1\le 1+\frac{2}{d+1}$, which tends to $1$ as $d\to\infty$ [1101.4620].

A second major relativistic construction is the BB84 measurement-outcome protocol. Bob sends $N$ random BB84 states to Alice at a commitment point $P$. To commit to $b=0$, Alice measures all qubits in the computational basis; to commit to $b=1$, she measures in the Hadamard basis. She then sends the encrypted outcome string at light speed to two space-like separated unveiling points $Q_0$ and $Q_1$, and Bob accepts only if the two unveiled records agree and are consistent with the states he prepared [1108.2879]. The protocol is perfectly hiding, and its binding analysis reduces cheating to simultaneous inference of incompatible BB84 outcomes. Using the optimal single-qubit Breidbart strategy, the overall cheating probability is bounded by
$$
P_{\rm cheat}\le \left(\tfrac12+\tfrac{1}{2\sqrt2}\right)^N,
$$
so the protocol is unconditionally binding with exponentially decaying $\varepsilon(N)$ [1108.2879].

The same geometric intuition was later recast in the language of summoning. In this viewpoint, a cheating strategy would require Alice to guarantee return of an unknown quantum state at more than one space-like separated site, which is ruled out by no-summoning. The fidelity-based form of the argument yields the same approximate-cloning bound $F_0+F_1\le 1+\frac{2}{d+1}$ for unveiling probabilities, and the paper argues that protocols of this type can be proven secure against some classes of post-quantum but non-signalling adversaries [1804.05246].

Relativistic protocols also admit entanglement-based deterministic variants. In deterministic relativistic quantum bit commitment, Alice prepares $2N$ Bell singlets, gives one labelled half-set to Bob at the commitment point, and later supplies the matching remote halves at the unveiling point corresponding to the committed bit. Verification consists of Bell-basis measurements projecting onto $|\Psi^-\rangle$, and the binding analysis uses monogamy of entanglement together with causality. For the ideal ETBC scheme, the operator bound $\|P_0P_1\|=2^{-N}$ yields
$$
p_0+p_1\le 1+2^{-N+1}+2^{-2N},
$$
while Bob’s reduced state is independent of the committed bit [1504.00943].

## 4. Practical and experimental realizations

The relativistic program led rapidly to field implementations. “Experimental unconditionally secure bit commitment” implemented the BB84 outcome-transmission protocol with two quantum key distribution systems, 1 GHz free-space optical links, and unveiling agents separated by more than $20$ km [1306.4413]. Bob used four laser diodes at $850$ nm with mean photon number $\mu=0.183\pm10\%$ and repetition rate $50$ MHz; Alice’s setup used a rotatable HWP, PBS, and two silicon SPDs with $50\%$ quantum efficiency and dark count about $100$ cps [1306.4413]. For the experimental thresholds $N_{\rm tol}=107$, $E_{\rm tol}=1.5\%$, and $\varepsilon_{\rm rect}=\varepsilon_{\rm diag}=2.1\times10^{-3}$, the paper computed $\varepsilon_b\le 5.68\times10^{-2}$ and therefore total security parameter $\varepsilon\le 5.68\times10^{-2}$ per run [1306.4413].

A second field demonstration modified the earlier quantum-communication-plus-relativity protocol so that the quantum exchange could occur before the actual commitment. In that protocol, Bob measures Alice’s BB84 pulses in a random basis in advance, reports the detected subset to his remote agents, and only at commit time sends the one-bit mask $b'=b\oplus a$ to encode the true commitment $a$ [1306.4801]. The commitment duration is
$$
T=\frac{d}{2c},
$$
so for the Geneva–Singapore separation $d=9\,354$ km the experiment achieved $T\approx 15.6$ ms [1306.4801]. With $\mu=(5.0\pm0.5)\times10^{-2}$, $N=2.2\times10^6$ pulses per block, observed $p_{\rm det}\approx0.32\%$, QBER $\approx3.4\%$, and about $n\approx7000$ detections, the finite-size analysis gave $\varepsilon\le 5.5\times10^{-8}$ [1306.4801].

Relativistic commitments based only on classical communication were developed in parallel. The one-round sBGKW protocol is secure against quantum adversaries for a duration bounded by the light-travel time $d/c$, while the multi-round finite-field protocol extends the commitment time arbitrarily and is proven secure against classical attacks [1411.4917]. The paper gives a concrete antipodal-Earth example with $m+1=6$ rounds, $n=512$, total duration about $212$ ms, and multi-round binding parameter $c_5\approx2.3\times10^{-10}$ [1411.4917].

This line culminated in a 24-hour implementation using timed high-speed optical communication and fast data processing only, with all agents located within the city of Geneva [1605.07442]. For $L=7.0$ km, $n=128$, and roughly $5\times10^9$ rounds, the experiment exchanged about $162$ GB of data at an average rate of $0.5$ MB/s [1605.07442]. The theoretical cheating bound is
$$
\epsilon\le m\,2^{(-n+3)/2},
$$
and the paper argues that the same protocol family could be extended to one year by increasing separation and relaxing response times [1605.07442].

| Protocol family | Main operational feature | Reported figure |
|---|---|---|
| BB84 outcome transmission [1306.4413] | Quantum measurements at commit, encrypted records sent to two remote agents | $\varepsilon\le 5.68\times10^{-2}$ per run |
| Quantum communication + relativity [1306.4801] | Quantum phase decoupled from commit time | $T\approx 15.6$ ms, $\varepsilon\le 5.5\times10^{-8}$ |
| Multi-round classical relativistic [1411.4917] | Finite-field sustain rounds | up to $212$ ms, $c_5\approx 2.3\times10^{-10}$ |
| 24-hour relativistic commitment [1605.07442] | Timed high-speed optical communication only | $24$ h demonstration |

## 5. Computational and oracle-based QCCC constructions

A distinct research direction studies QCCC commitments under computational assumptions. A non-interactive example is Yamakami’s scheme exploiting the computational hardness of quantum state distinction [1309.0436]. Alice commits by sending a reduced state $\rho_a(n)$ derived from hidden-permutation states $\rho_{T,s}$, and later reveals $(a,T)$ so that Bob can run the state-partitioning test. The scheme is computationally concealing and statistically binding under the assumption that no polynomial-time quantum algorithm distinguishes the ensembles $\{\rho_0(n)\}$ and $\{\rho_1(n)\}$ with non-negligible advantage; this assumption is stated to be guaranteed, for example, by computational hardness of the graph automorphism problem on a quantum computer [1309.0436].

More recent work identifies a broader constructive pathway from quantum one-wayness. “Commitments from Quantum One-Wayness” proves that pure-state one-way state generators imply one-way puzzles, and that one-way puzzles imply quantum bit commitments [2310.11526]. The construction passes through shadow tomography, weak pseudoentropy generators, pseudoentropy generators, and imbalanced EFI, and the final protocol is explicitly QCCC in the sense that “only classical messages” are exchanged while any quantum work remains local [2310.11526]. The resulting commitment is computationally hiding and computationally binding under the assumption of a pure-state one-way state generator with linear copy security [2310.11526].

Oracle constructions sharpen the complexity-theoretic picture. In “CountCrypt,” the QCCC commitment protocol is defined by a classical commit message and a two-message classical opening phase, while the parties obtain quantum states only from internal oracle calls to $\mathsf{SG}$ and $\mathsf{Mix}$ [2410.14792]. The protocol is statistically hiding because the commit transcript is a uniformly random suffix $x_{>1}$ independent of the committed bit, and computationally binding because opening both values would require effectively holding two orthogonal Haar-random states that the oracle never provides simultaneously [2410.14792]. The paper states that, with probability $1$ over the choice of $(\mathsf{SG},\mathsf{Mix},\mathsf{PSPACE})$, the protocol is statistically hiding and computationally binding as a QCCC bit-commitment scheme [2410.14792].

Composable extensions also exist. “A Private Quantum Bit String Commitment” gives an entanglement-based protocol using an EPR-pair source and two random oracles $H_1$ and $H_2$, with composability proven in the random oracle model [2001.11911]. Alice measures her halves of $n$ EPR pairs in randomly chosen $Z$ or $X$ bases, forms $c_1=m\oplus H_1(b\|O)$ and $c_2=H_2(b)$, and Bob reconstructs the committed string after Alice reveals $b$ [2001.11911]. The paper defines $\varepsilon$-concealing, $\varepsilon$-binding, and $\varepsilon$-privacy, requires an authenticated classical channel for privacy, and remarks that a single-bit QCCC commitment is obtained as a special case [2001.11911].

## 6. Restricted-adversary models, practical assumptions, and disputed regimes

Some protocols recover security by limiting the adversary’s admissible quantum operations. “Secure quantum bit commitment from separable operations” proves that in any perfectly hiding bit-commitment protocol, an honestly committing Alice restricted to separable operations will be detected with high probability if she later attempts to alter her commitment [2501.07351]. In the AME$(3,d)$ example, Bob’s reduced state is exactly maximally mixed for both bits, and the binding proof shows
$$
p_s(0)\le \lambda_{\max}^2N_2,\qquad p_s(1)\le \frac{1}{N_2}.
$$
With the optimal choice of Schmidt weights this becomes $p_{\rm switch}=1/d$, so the protocol is $1/d$-honest-binding and Alice is caught with probability at least $1-1/d$ [2501.07351]. This model is not unconditional against arbitrary quantum adversaries, but it isolates a precise operational restriction.

Other proposals rely on bounded cheating resources rather than separability. In the single-qubit-unitary protocol of Sheikholeslam and Gulliver, Bob sends $U_B|\phi_0\rangle$ and $U_B|\phi_1\rangle$, Alice applies her secret $U_A$ to the state indexed by the committed bit, and Bob later inverts using $U_B^\dagger U_A^\dagger$ [1111.6311]. The protocol is perfectly concealing in the noiseless ideal and is argued to be computationally binding against polynomial-size entanglement attacks because a cheating unitary would have to act coherently over an exponentially large space indexed by $|\mathcal S_A|\cdot|\mathcal S_B|$; the paper states $\varepsilon(n)\approx 1/|\mathcal S_B|=2^{-n}$ and overall cheating probability at most $m\,2^{-n}$ under parallel repetition [1111.6311].

A more explicitly technological approach is the practical protocol based on limitations on nondemolition measurements and long-term quantum memory [1202.3331]. Bob sends BB84 polarization states at secret random times, Alice immediately announces the detection times, and later reveals the basis and outcomes. The concealing property is perfect in the ideal model, while binding relies on the claim that Alice cannot both identify photon arrival times nondestructively and preserve the polarization qubit until the opening phase. If she attempts basis-independent cheating with the Breidbart basis, the per-photon error is
$$
e_{\rm BB84\to Breidbart}=\sin^2\!\frac{\pi}{8}\approx 15\%,
$$
so Bob can set $Q_{\max}<15\%$ to detect cheating with overwhelming probability [1202.3331].

Counterfactual schemes provide yet another physical variant. In the counterfactual protocol built from an N09-style comparison primitive, the relevant parameters for $r=t=\frac12$ are
$$
p=\tfrac38,\qquad q=\tfrac14,\qquad p'=\tfrac78,\qquad p_{\rm alter}=\tfrac56,
$$
and the paper states that choosing, for example, $m=70$ and $n=130$ makes both the binding and concealing errors $\lesssim10^{-6}$ [1807.01602]. The same paper argues that the standard Mayers–Lo–Chau attack is not implementable with current technology because it would require keeping a macroscopic optical switch in coherent superposition of timings [1807.01602]. This does not contradict the general no-go theorems; rather, it places the security claim in a technologically bounded regime.

Taken together, these results show that “QCCC bit commitments” name not a single security theorem but a family of constructions separated by their auxiliary assumptions. Unconditional security is obtained in relativistic models using no-signalling, no-cloning, no-summoning, or monogamy of entanglement [1101.4620, 1504.00943]. Computational QCCC commitments arise from one-way state generators, one-way puzzles, random oracles, or oracle worlds such as CountCrypt [2310.11526, 2001.11911, 2410.14792]. Restricted-operation and technological models sit between these extremes, often clarifying which physical or algorithmic resource is doing the cryptographic work [2501.07351, 1202.3331].

Source: https://www.emergentmind.com/topics/qccc-bit-commitments