← Latest papers
⚛️ quantum physics

Succinct Arguments for QMA from Collapsing Hash Functions

This paper presents the first succinct arguments for QMA based solely on collapsing hash functions (a Minicrypt assumption), achieved through a novel quantum-succinct claw-state generation protocol that improves upon prior work in round complexity, simplicity, and standard model security.

Original authors: James Bartusek, Giulio Malavolta

Published 2026-09-29
📖 6 min read🧠 Deep dive

Original authors: James Bartusek, Giulio Malavolta

Original paper dedicated to the public domain under CC0 1.0 (http://creativecommons.org/publicdomain/zero/1.0/). ✨ This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

In the world of cryptography, there is a constant tension between security and efficiency. On one side, we have the need to verify that a complex calculation was performed correctly without having to redo the entire calculation ourselves. This is the realm of succinct arguments, a method that allows a verifier to check a proof using far fewer resources than the time it took to create it. For decades, this technology has been a cornerstone of digital trust, enabling everything from blockchain verification to secure cloud computing. However, a significant gap has existed between the classical world of standard computers and the emerging world of quantum computers. While we know how to create these efficient proofs for classical problems using only basic, unstructured mathematical tools, doing the same for quantum problems has seemed to require much heavier, more complex cryptographic machinery. The prevailing belief was that verifying quantum proofs would always demand the kind of advanced, public-key encryption systems that are far more computationally expensive and structurally complex than the simple tools used for classical verification.

This paper changes that landscape by demonstrating that efficient verification of quantum proofs is possible using only the simplest, most fundamental cryptographic assumptions. The researchers have constructed a protocol that allows a client to verify a quantum computation with high confidence, relying solely on the existence of "collapsing hash functions." These functions are the quantum-safe version of a basic tool used to ensure data integrity, representing the weakest possible level of cryptographic security required for this task. By proving that such a system can be built without needing the heavy machinery of public-key encryption, the authors show that the ability to verify quantum computations lives in a much simpler, more accessible tier of cryptography than previously thought. This achievement bridges a critical divide, suggesting that the tools needed to secure the quantum future are already within reach, grounded in the same basic principles that secure our current digital world.

The core of this breakthrough lies in a new method for generating a specific type of quantum correlation known as a "claw state." To understand the significance, imagine a scenario where a powerful server wants to prove it has performed a complex calculation, but a weaker client wants to check the work without doing the calculation themselves. The client needs to establish a shared, secret connection with the server that proves the server is following the rules, without revealing the secret itself. In previous attempts, creating these connections required the client to perform a massive amount of quantum work or rely on complex public-key systems. The authors realized that the client does not need to be entirely classical; they can perform a small, fixed amount of quantum operations and still achieve the goal. This insight allowed them to design a protocol where the client prepares a series of carefully prepared quantum messages in advance, before any interaction begins. The server then processes these messages to generate thousands of these secret "claw" connections, all while the client only performs a tiny amount of quantum work.

The protocol works by having the client send a superposition of many possibilities at once during each round of interaction. The server, using only classical communication and its own computing power, is able to "collapse" this superposition into a set of specific, verified quantum states. The clever part of the design is that the server can generate a vast number of these states, but it cannot figure out the specific secret labels associated with them. If the server tries to guess the labels, the protocol is designed so that the probability of guessing correctly drops dramatically. To make this security robust, the researchers run this process many times in a row, sending multiple quantum messages sequentially. They then use a technique to "glue" the results of these separate runs together, creating a single, highly secure quantum state. This amplification process ensures that even if the server has a tiny chance of deviating in one instance, the chance of deviation across all instances becomes vanishingly small, effectively making the system secure against any realistic attack.

This new method for generating quantum correlations serves as the engine for a larger system called "blind delegation." In this setup, a client can delegate a complex quantum computation to a server without the server learning anything about what the computation is or what the input data looks like. The client provides the server with the necessary quantum resources, and the server performs the calculation, returning a result that the client can verify. Because the new protocol is so efficient and requires minimal quantum resources from the client, it fits perfectly into a framework that compresses the communication between the two parties. By combining this efficient delegation method with a compiler that shrinks the amount of data exchanged, the researchers created a complete system for succinct arguments for quantum problems. The final result is a protocol where the total amount of data sent back and forth is small, and the time it takes for the client to verify the result depends only on the size of the problem statement, not on how long the calculation took to run. It is important to note, however, that this protocol requires the verifier to be quantum and to use quantum communication, which is a core limitation of the current approach.

The significance of this work extends beyond just the technical details of the protocol. It resolves a long-standing question about the fundamental requirements for quantum verification. For years, it was unclear whether verifying quantum proofs required the heavy, complex tools of public-key cryptography or if they could be built from the lighter, simpler tools used for classical verification. The authors have proven that the latter is true. They have shown that the existence of these efficient quantum verification systems is guaranteed by the same basic assumptions that underpin the security of the internet today. This places the ability to verify quantum computations in a category of cryptography known as "Minicrypt," a realm defined by simple, unstructured assumptions, rather than the more complex "Cryptomania" realm that was previously thought necessary. This finding suggests that the infrastructure for a secure quantum future may be simpler and more robust than anticipated, relying on the same foundational blocks that have protected our digital world for decades.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →