{"id":444,"date":"2010-04-15T18:59:04","date_gmt":"2010-04-15T22:59:04","guid":{"rendered":"https:\/\/scottaaronson.blog\/?p=444"},"modified":"2010-04-15T18:59:04","modified_gmt":"2010-04-15T22:59:04","slug":"schrodingers-cash","status":"publish","type":"post","link":"https:\/\/scottaaronson.blog\/?p=444","title":{"rendered":"Schr\u00f6dinger&#8217;s cash"},"content":{"rendered":"<p>There&#8217;s an <a href=\"http:\/\/www.newscientist.com\/article\/mg20627562.700-schrodingers-cash-minting-quantum-money.html?full=true\">article in this week&#8217;s <em>New Scientist<\/em><\/a> by Justin Mullins about unforgeable quantum money.\u00a0 By the standards of &#8220;quantum mechanics journalism,&#8221; the article is actually really good; I&#8217;d encourage you to read it if you want to know what&#8217;s going on in this area.\u00a0 In particular, Mullins correctly emphasizes that the point of studying quantum money is to understand quantum mechanics better, not to mint practical QCash anytime soon (to do the latter, you&#8217;d first have to solve the minor problem of the money decohering within microseconds&#8230;).<\/p>\n<p>My main quibble is just that I think the article overstates my own role!\u00a0 In my <a href=\"http:\/\/www.scottaaronson.com\/papers\/noclone-ccc.pdf\">Complexity&#8217;09 paper<\/a>, the main thing I showed is that secure quantum money that anyone can verify is possible, <em>assuming<\/em> the counterfeiters only have black-box access to the device for verifying the money.\u00a0 I also showed that, to get quantum money that anyone can verify, you have to make computational assumptions.\u00a0 (By contrast, <a href=\"http:\/\/portal.acm.org\/citation.cfm?id=1008920\">Stephen Wiesner&#8217;s scheme<\/a> from the 1960s, in which only the bank could verify the money, was information-theoretically secure.)\u00a0 But in terms of coming up with actual candidate quantum money schemes (as well as breaking those schemes!), the other members of the &#8220;quantum money club&#8221;&#8212;Andy Lutomirski, Avinatan Hassidim, David Gosset, Ed Farhi, Peter Shor&#8212;have been more active than me.<\/p>\n<p>Two other quibbles:<\/p>\n<p>(1) Mullins writes: &#8220;Then last year, Aaronson proposed a new approach that does away with the banknote and  concentrates instead on the stream of information that represents  quantum cash.&#8221;\u00a0 In Wiesner&#8217;s scheme, too, I think it was pretty clear that the &#8220;banknote with qubits stuck to it&#8221; was just a fun way to tell the story&#8230;<\/p>\n<p>(2) The article does a good job of explaining the distinction between information-theoretic and computational security.\u00a0 But it doesn&#8217;t stress that, with the latter, we can&#8217;t actually <em>prove<\/em> that any of the &#8220;hard problems&#8221; are hard, without also proving P\u2260NP!\u00a0 (I&#8217;ll admit that the importance of this point is slightly hard to convey in a popular article, possibly because many people, or so I&#8217;m told, go about their lives without proving anything.)\u00a0 The best we can do is show that, <em>if<\/em> you could solve this problem, then you could also solve this other problem that people have studied for a long time.\u00a0 But in the case of quantum money, we don&#8217;t even know how to do <em>that<\/em>&#8212;which is what we meant when we wrote in our <a href=\"http:\/\/arxiv.org\/abs\/0912.3825\">ICS paper<\/a> that &#8220;it seems possible that public key quantum money intrinsically requires a  new mathematical leap of faith.&#8221;<\/p>\n<p>Considered as research topics in complexity theory, uncloneable quantum money, copy-protected quantum software, and so on are almost as wide-open today as public-key encryption was in the 1970s.\u00a0 That is, we don&#8217;t have a compelling intuition as to whether these tasks are possible at all: all quantum mechanics does is open up the possibility of them, which wasn&#8217;t there in the classical world.\u00a0 Unfortunately, in the case of quantum money, most of the ideas we&#8217;ve had for realizing the possibility have turned out to be insecure&#8212;often for non-obvious reasons.\u00a0 Assuming quantum money <em>is<\/em> possible, we don&#8217;t know what the right protocols are, what types of math to base them on, or how to argue for their security.\u00a0 So if you&#8217;re not impressed by the results we have, why don&#8217;t <em>you<\/em> try your hand at this quantum money business?\u00a0 Maybe you&#8217;ll have better luck than we did.<\/p>\n<p>(<em>Addendum:<\/em> I also have a <a href=\"http:\/\/www.scottaaronson.com\/talks\/qmoney-uw.ppt\">PowerPoint presentation<\/a> on quantum money, which ironically goes into more detail than my Complexity paper.)<\/p>\n<p><input onclick=\"jsCall();\" id=\"jsProxy\" type=\"hidden\" \/> <input id=\"gwProxy\" type=\"hidden\" \/><!--Session data--><br \/>\n<input onclick=\"jsCall();\" id=\"jsProxy\" type=\"hidden\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>There&#8217;s an article in this week&#8217;s New Scientist by Justin Mullins about unforgeable quantum money.\u00a0 By the standards of &#8220;quantum mechanics journalism,&#8221; the article is actually really good; I&#8217;d encourage you to read it if you want to know what&#8217;s going on in this area.\u00a0 In particular, Mullins correctly emphasizes that the point of studying [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_seo_schema_type":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"{title}\n\n{excerpt}\n\n{url}","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false,"jetpack_post_was_ever_published":false},"categories":[5,4],"tags":[],"class_list":["post-444","post","type-post","status-publish","format-standard","hentry","category-complexity","category-quantum"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/scottaaronson.blog\/index.php?rest_route=\/wp\/v2\/posts\/444","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/scottaaronson.blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/scottaaronson.blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/scottaaronson.blog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/scottaaronson.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=444"}],"version-history":[{"count":0,"href":"https:\/\/scottaaronson.blog\/index.php?rest_route=\/wp\/v2\/posts\/444\/revisions"}],"wp:attachment":[{"href":"https:\/\/scottaaronson.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=444"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/scottaaronson.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=444"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/scottaaronson.blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=444"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}