Reuse & Permissions

It is not necessary to obtain permission to reuse this article or its components as it is available under the terms of the Creative Commons Attribution 4.0 International license. This license permits unrestricted use, distribution, and reproduction in any medium, provided attribution to the author(s) and the published article's title, journal citation, and DOI are maintained. Please note that some figures may have been included with permission from other third parties. It is your responsibility to obtain the proper permission from the rights holder directly for these figures.

Export citation

Export citation

Choose format for download:

Download Citation
  • Letter
  • Open Access

Impossibility of quantum private queries

Esther Hänggi*

Severin Winkler*

  • *These authors contributed equally to this work.

Phys. Rev. Research 8, L022036 – Published 28 May, 2026

DOI: https://doi.org/10.1103/2pd6-j1xf

Abstract

Symmetric private information retrieval is a cryptographic task allowing a user to query a database and obtain exactly one entry without revealing to the owner of the database which element was accessed. The task is a variant of general two-party protocols called one-sided secure function evaluation and is closely related to oblivious transfer. Under the name quantum private queries, quantum protocols have been proposed to solve this problem in a cheat-sensitive way: In such protocols, it is not impossible for dishonest participants to cheat, but they risk detection [Giovannetti et al., Phys. Rev. Lett. 100, 230502 (2008)]. We give an explicit attack against any cheat-sensitive symmetric private information retrieval protocol, showing that any protocol that is secure for the user cannot have nontrivial security guarantees for the owner of the database: The user is even able to retrieve the complete database.

View figure in article

Physics Subject Headings (PhySH)

Article Text

Supplemental Material

References (57)

  1. C. H. Bennett and G. Brassard, Quantum cryptography: Public key distribution and coin tossing, in Proceedings of IEEE International Conference on Computers, Systems, and Signal Processing, Bangalore, 1984 (IEEE, New York, 1984), p. 175.
  2. A. K. Ekert, Quantum cryptography based on Bell's theorem, Phys. Rev. Lett. 67, 661 (1991).
  3. A. Stefanov, N. Gisin, O. Guinnard, L. Guinnard, and H. Zbinden, Optical quantum random number generator, J. Mod. Opt. 47, 595 (2000).
  4. T. Jennewein, U. Achleitner, G. Weihs, H. Weinfurter, and A. Zeilinger, A fast and compact quantum random number generator, Rev. Sci. Instrum. 71, 1675 (2000).
  5. S. Wiesner, Conjugate coding, SIGACT News 15, 78 (1983).
  6. G. Brassard and C. Crépeau, Quantum bit commitment and coin tossing protocols, in CRYPTO’90 (Springer Berlin Heidelberg, Berlin, Heidelberg, 1991), pp. 49–61.
  7. C. H. Bennett, G. Brassard, C. Crépeau, and H. Skubiszewska, Practical quantum oblivious transfer, in CRYPTO’91 (Springer Berlin Heidelberg, Berlin, Heidelberg, 1992), pp. 351–366.
  8. G. Brassard, C. Crepeau, R. Jozsa, and D. Langlois, A quantum bit commitment scheme provably unbreakable by both parties, in FOCS’93 (IEEE Computer Society, NW Washington, DC, 1993), pp. 362–371.
  9. M. Ardehali, A quantum bit commitment protocol based on EPR states, arXiv:quant-ph/9505019.
  10. B. Chor, O. Goldreich, E. Kushilevitz, and M. Sudan, Private information retrieval, in FOCS’95 (IEEE Computer Society, NW Washington, DC, 1995), pp. 41–50.
  11. D. Mayers, Unconditionally secure quantum bit commitment is impossible, Phys. Rev. Lett. 78, 3414 (1997).
  12. H. K. Lo and H. F. Chau, Is quantum bit commitment really possible? Phys. Rev. Lett. 78, 3410 (1997).
  13. H. K. Lo, Insecurity of quantum secure computations, Phys. Rev. A 56, 1154 (1997).
  14. A. Kitaev, Quantum coin-flipping (unpublished).
  15. A. Ambainis, A new protocol and lower bounds for quantum coin flipping, in STOC’01 (Association for Computing Machinery, New York, 2001), pp. 134–142.
  16. H. Buhrman, M. Christandl, and C. Schaffner, Complete insecurity of quantum protocols for classical two-party computation, Phys. Rev. Lett. 109, 160501 (2012).
  17. R. Colbeck, The impossibility of secure two-party classical computation, Phys. Rev. A 76, 062308 (2007).
  18. R. W. Spekkens and T. Rudolph, Degrees of concealment and bindingness in quantum bit commitment protocols, Phys. Rev. A 65, 012310 (2001).
  19. A. Chailloux and I. Kerenidis, Optimal quantum strong coin flipping, in FOCS’09 (IEEE Computer Society, USA, 2009), pp. 527–533.
  20. A. Chailloux, G. Gutoski, and J. Sikora, Optimal bounds for semi-honest quantum oblivious transfer, Chicago J. Theor. Comput. Sci. 2016 (2016).
  21. D. Aharonov, A. Ta-Shma, U. V. Vazirani, and A. C. Yao, Quantum bit escrow, in STOC’00 (Association for Computing Machinery, New York, 2000), pp. 705–714.
  22. C. Mochon, Quantum weak coin-flipping with bias of 0.192, in FOCS’04 (IEEE Computer Society, USA, 2004), pp. 2–11.
  23. M. Franklin and M. Yung, Communication complexity of secure computation (extended abstract), in STOC’92 (Association for Computing Machinery, New York, 1992), pp. 699–710.
  24. Y. Aumann and Y. Lindell, Security against covert adversaries: Efficient protocols for realistic adversaries, J. Cryptol. 23, 281 (2010).
  25. R. W. Spekkens and T. Rudolph, A quantum protocol for cheat-sensitive weak coin flipping, Phys. Rev. Lett. 89, 227901 (2002).
  26. S. Neves, V. Yacoub, U. Chabaud, M. Bozzio, I. Kerenidis, and E. Diamanti, Experimental cheat-sensitive quantum weak coin flipping, Nat. Commun. 14, 1855 (2023).
  27. L. Hardy and A. Kent, Cheat sensitive quantum bit commitment, Phys. Rev. Lett. 92, 157901 (2004).
  28. H. Buhrman, M. Christandl, P. Hayden, H.-K. Lo, and S. Wehner, Possibility, impossibility, and cheat sensitivity of quantum-bit string commitment, Phys. Rev. A 78, 022316 (2008).
  29. V. Giovannetti, S. Lloyd, and L. Maccone, Quantum private queries, Phys. Rev. Lett. 100, 230502 (2008).
  30. V. Giovannetti, S. Lloyd, and L. Maccone, Quantum private queries: Security analysis, IEEE Trans. Inf. Theory 56, 3465 (2010).
  31. F. De Martini, V. Giovannetti, S. Lloyd, L. Maccone, E. Nagali, L. Sansoni, and F. Sciarrino, Experimental quantum private queries with linear optics, Phys. Rev. A 80, 010302 (2009).
  32. M. Jakobi, C. Simon, N. Gisin, J.-D. Bancal, C. Branciard, N. Walenta, and H. Zbinden, Practical private database queries based on a quantum-key-distribution protocol, Phys. Rev. A 83, 022301 (2011).
  33. L. Olejnik, Secure quantum private information retrieval using phase-encoded queries, Phys. Rev. A 84, 022313 (2011).
  34. P. Chan, I. Lucio-Martinez, X. Mo, C. Simon, and W. Tittel, Performing private database queries in a real-world environment using a quantum protocol, Sci. Rep. 4, 5233 (2014).
  35. S. Winkler and J. Wullschleger, On the efficiency of classical and quantum oblivious transfer reductions, in CRYPTO’10 (Springer-Verlag, Berlin, Heidelberg, 2010), pp. 707–723.
  36. L. Salvail, C. Schaffner, and M. Sotáková, On the power of two-party quantum cryptography, in ASIACRYPT’09 (Springer-Verlag, Berlin, Heidelberg, 2009), pp. 70–87.
  37. J. Bartusek, A. Coladangelo, D. Khurana, and F. Ma, One-way functions imply secure computation in a quantum world, in CRYPTO’21 (Springer-Verlag, Berlin, Heidelberg, 2021), pp. 467–496.
  38. Note that the database for the protocol [29] uses an additional dummy entry at index 0. Thus, here the n actual database entries are x1,...,xn.
  39. This is an attack type often used in quantum two-party protocols and corresponds to the player keeping the purification of the state.
  40. C. Helstrom, Quantum Detection and Estimation Theory (Academic Press, New York, 1976).
  41. See Supplemental Material at http://link.aps.org/supplemental/10.1103/2pd6-j1xf for technical details, which includes Refs.  [54, 55, 56, 57].
  42. S. Fehr and C. Schaffner, Composing quantum protocols in a classical environment, in TCC ’09 (2009), pp. 350–367.
  43. E. Hänggi and S. Winkler, Lower bounds for quantum secure function evaluation reductions, arXiv:2405.12121.
  44. A stronger correctness condition would require that both players always accept the protocol if it is honestly executed. Since this stronger requirement satisfies our correctness condition, our impossibility result also holds in this case, for any 0≤δ≤1.
  45. In this trivial protocol, Alice sends all n database entries xi to Bob, who retrieves the database entry of his choice and always accepts. Alice rejects the protocol with probability ɛ independently of everything else. This protocol is correct and obviously secure for Bob. Since no strategy of Bob is accepted with probability at least 1−δ>1−ɛ, Definition t2 becomes trivial for 0≤δ<ɛ.
  46. B. Chor, E. Kushilevitz, O. Goldreich, and M. Sudan, Private information retrieval, J. ACM 45, 965 (1998).
  47. A. Nayak, Optimal Lower Bounds for Quantum Automata and Random Access Codes (1999), p. 369.
  48. F. Le Gall, Quantum private information retrieval with sublinear communication complexity, Theory Comput. 8, 369 (2012).
  49. Ä. Baumeler and A. Broadbent, Quantum private information retrieval has linear communication complexity, J. Cryptol. 28, 161 (2015).
  50. S. Onofri and V. Giovannetti, Probabilistic versions of quantum private queries, arXiv:2401.05754.
  51. A. Winter, Coding theorem and strong converse for quantum channels, IEEE Trans. Inf. Theory 45, 2481 (1999).
  52. M. M. Wilde, Quantum Information Theory (Cambridge University Press, Cambridge, England, 2013).
  53. A. Uhlmann, The transition probability in the state space of *-algebra, Rep. Math. Phys. 9, 273 (1976).
  54. M. A. Nielsen and I. L. Chuang, Quantum Computation and Quantum Information (Cambridge University Press, Cambridge, England, 2000).
  55. W. F. Stinespring, Positive functions on C*-algebras, Proc. Amer. Math. Soc. 6, 211 (1955).
  56. R. Renner, Security of quantum key distribution, Ph.D. thesis, ETH Zurich, Switzerland, 2005.
  57. S. Winkler, M. Tomamichel, S. Hengl, and R. Renner, Impossibility of growing quantum bit commitments, Phys. Rev. Lett. 107, 090502 (2011).

Outline

Information

Sign In to Your Journals Account

Filter

Filter

Article Lookup

Enter a citation