Quantum money scheme based on abelian group actions and isogenies over ordinary elliptic curves
Patent Information
- Application Number
- PCT/US2024/034269
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-06-16
- Filing Date
- 2024-06-17
- Publication Date
- 2025-10-30
AI Technical Summary
Current quantum money schemes lack secure public key constructions that allow for public verification without involving the mint in transactions, and existing proposals often rely on untested cryptographic building blocks or have been broken by attacks.
A quantum money scheme based on abelian group actions and isogenies over ordinary elliptic curves, utilizing a bank note generator module to create and verify banknotes through quantum Fourier transforms and controlled group actions, ensuring secure and un-counterfeitable currency.
The scheme provides a robust and secure method for generating and verifying quantum banknotes, leveraging the hardness of discrete logarithm problems and orbit superposition problems to prevent counterfeiting and ensure quantum lightning security.
Smart Images

Figure US2024034269_30102025_PF_FP_ABST
Abstract
Description
[0001]QUANTUM MONEY SCHEME BASED ON ABELIAN GROUP ACTIONS AND ISOGENIES OVER ORDINARY ELLIPTIC CURVES CROSS-REFERENCE TO RELATED APPLICATION This application claims the benefit of U.S. Provisional Application Ser. No. 63 / 508,865 filed June 16, 2023, the content of which is incorporated by reference herein in its entirety. FIELD OF THE INVENTION The present disclosure relates to quantum cryptography, and more particularly to a quantum money scheme based on abelian group actions and isogenies over ordinary elliptic curves. BACKGROUND OF THE INVENTION Quantum money is a system of money where banknotes are quantum states. By the no-cloning theorem, such banknotes cannot be copied, leading to un-counterfeitable currency. A critical feature of quantum money is that of public verification, allowing anyone to verify while only the mint can create new banknotes. Such public key quantum money is an important central object in the study of quantum protocols, but unfortunately convincing constructions have remained elusive. Public key quantum money. In Wiesner’s original scheme of the prior art, the mint is required to verify banknotes, meaning the mint must be involved in any transaction. The involvement of the mint also leads to potential attacks. Some partial solutions have been proposed. One possible solution, however, is known as public key quantum money. Here, anyone can verify the banknote, while only the mint can create them. Unlike Wiesner’s scheme of the prior art which is well-understood, secure public key quantum money has remained elusive. While there have been many proposals for public key quantum money, they mostly either (1) have been subsequently broken, or (2) rely on new cryptographic building blocks that have received little attention from the cryptographic community. The two exceptions are: • Other work has proved that quantum money can be built from post-quantum indis- tinguishability obfuscation (iO). While iO has received considerable attention and even has a convincing pre-quantum instaniation, the post-quantum study of iO has been much less thorough. While some post-quantum proposals have been made, their post-quantum hardness is not well-understood. • Other work constructs quantum money from isogenies over super-singular elliptic curves. However, there is a crucial missing piece to their proposal, namely generating uniform superpositions over super-singular curves, which is currently unknown how to do. This is closely related to the major open question of obliviously sampling super-singular elliptic curves. In light of the above state of affairs, the existence of public key quantum money is largely considered open. Cryptography from group actions and isogenies. Isogenies were first proposed for use in post-quantum cryptography by Couveignes and Rostovtsev and Stolbunov. Isogenies give a Diffie-Hellman-like structure, but importantly are immune to Shor’s algorithm for discrete logarithms due to a more restricted structure. This restricted structure, while helping preserve security against quantum attacks, also makes the design of cryptosystems based on them more complex. Thus, significant effort has gone into building security cryptosystems from isogenies and understanding their post-quantum security. Certain isogenies such as CSIDH can be abstracted as abelian group actions. However, many other isogenies (such as SIDH and OSIDH) cannot be abstracted as abelian group actions. Even among abelian group actions, we must distinguish between “effective group actions” (EGAs) and restricted EGAs (REGAs). The former satisfies the notion of a clean group action, whereas in the latter, the group action can only be efficiently computed for a certain small set of group elements. Unfortunately, there are currently no known EGAs from isogenies with better than quasi-polynomial security, though at concrete security levels variants of CSIDH could plausibly be an EGA. With the state-of-the-art, evaluating CSIDH as an EGA would require time1 / 3on a quantum computer, while the best quantu attack is time 2n1 / 2. By setting n = log3(λ), one gets polynomial-time evaluation and the best attack taking time λlog1 / 2(λ). In any case, the status of isogeny-based group actions is quickly evolving, and suitable EGAs may someday be found. While some non-isogeny abelian group actions have been proposed, currently all such examples have been broken. For this reason, group actions are largely considered synonymous with isogenies, though this may change if more secure group actions are found. The vast majority of the isogeny and group action literature has focused on post-quantum cryptography — classical protocols that are immune to quantum attacks. Two prior works have used isogenies / group actions to build quantum protocols. The first builds a proof of quantumness. We note that proofs of quantumness can also be achieved under several “standard” cryptographic tools, such as LWE or certain assumptions on hash functions. In contrast, no prior quantum money protocol could be based on similar standard building blocks. The second quantum protocol based on isogenies, and builds quantum money from walkable invariants, and propose an instantiation using isogenies over super-singular elliptic curves. However, such isogenies cannot be described as abelian group actions, and even more importantly their proposal is incomplete, as discussed above. Thus, there is a need for the first application of group actions or isogenies to obtain a new feasibility result from standard tools. BRIEF SUMMARY OF THE INVENTION This summary is provided to introduce a selection of concepts in a simplified form that are further described below in the detailed description. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used as an aid in determining the scope of the claimed subject matter. As disclosed herein, we construct public key quantum money from abelian group actions, which can be instantiated by isogenies over ordinary elliptic curves. Group actions, and the isogenies they abstract, are one of the leading contenders for post-quantum secure cryptosystems. The disclosed constructions could plausibly even be quantum lightning, a strengthening of quantum money with additional applications. According to an aspect of the present disclosure, a system for a quantum money scheme is provided. The system includes a bank note generator module. This module is configured to instantiate a set, a group, and a group action operation. The set is a collection of elliptic curves with a given number of points, the group is an abelian group, and the group action operation is based on isogenies. The module is further configured to initialize a first register and a second register in a joint state. The module computes the group action operation in superposition, applies a quantum Fourier transform over the group to the first register, and measures the first register to obtain a measurement outcome. The second register then collapses to a specific state. The module outputs a banknote comprising the measurement outcome as a serial number and the specific state as a money state. The banknote is stored in a quantum computer storage device. According to other aspects of the present disclosure, the system may include a verification module. This module may be configured to verify the banknote by executing one or more times instructions for choosing a random element from the group, initializing a qubit, applying a controlled group action, and projecting the qubit onto a specific state. If all of the projections are accepted, then the banknote is considered verified. In some embodiments, if the banknote is an honest banknote state, the state of the system may be represented by a specific state. According to yet another aspect of the present disclosure, the banknote generation module may be further configured to sign the serial number using a digital signature scheme upon generating a banknote. In some embodiments, the verification module may be further configured to verify the signature and to consider the banknote valid if the signature on the serial number is valid. According to another aspect of the present disclosure, the group action in the system may be derived from isogenies over ordinary elliptic curves. The Construction Abelian Group Actions. We will use additive group notation for abelian groups. An abelian group action consists of an abelian group G and a set X , such that G “acts” on X as follows through the binary relation ∗ : G×X → X with the property that g∗(h∗x) = (g+h)∗x for all g, h ∈ G, x ∈ X . We will also assume a regular group action, which means that for every x ∈ X , the map g 7→ g ∗ x is a bijection. The main group action used in cryptography are those arising from isogenies over (ordinary) elliptic curves. Here, X is the set of elliptic curves with a given number of points, and G is the class group, acting on X via isogenies. The basic hard problem on group actions is the discrete logarithm problem: given x, y ∈ X , computing g such that y = g ∗ x (which exists and is unique by regularity). In group actions based on isogenies, this corresponds to the well-known hard problem of computing isogenies between elliptic curves. Other hard problems are possible, such as analogs of computational / decisional Diffie-Hellman, and more. The QFT. The disclosed quantum money scheme will utilize the quantum Fourier transform (QFT) over general abelian groups. This is a quantum procedure that maps |g^ 7→1∑ √ χ(g, h)|h^ . |G| h∈G Here, χ is some potentially complex phase term. In the case of G being the additive group ZN, χ(g, h) is defined as ei2πgh / N, with a slightly more complicated definition for non-cyclic groups. Note that the group aoperation is +, so gh in the exponent is not the group operation, but instead multiplication in the ring ZN. The main property we need from χ (besides making the QFT unitary) is that it is bilinear, in the sense that χ(g, h1+ = · χ(g, h2). It is also = . The Quantum Money Scheme. The disclosed quantum money scheme can be composed as follows. √1∑ Gen: initialize a register in the stateg∈G|g^. Let x ∈ X be arbitrary. Then by 1 ∑ computing the group action in √|G| h∈G|g^|g ∗ x^. Next, apply the QFT over G to the first register. The result is: 1 ∑ χ(g, h)|h, g ∗ x^ =√ 1∑ |h^|Gh∗ x^ Here, |Gh∗ x^ is the g∈G∗ ∗ x^ is, up to an overall phase, independent of x. Now measure h, in which case the second register collapses to |Gh∗ x^. Output h as the serial number, and |Gh∗ x^ as the money state. To verify a banknote $, choose a random g ∈ G, and in^itialize a new qubit with (|0^ + ^^√ ^ ^|0, y^ if b = 0 / 2. Then the controlled action 7→ . If $ is the √1|0^+ χ(g, h)−1|1^ |Gh∗ x^ 2 We can then measure the |0^ + χ(g, h−1 ) |1^, which will accept with probability 1 for honest banknote states. We can repeat this process λ times. It is possible to show that if all λ trials accept, the result state is 2Θ(λ)-close to the honest banknote state. An alternate scheme. Suppose the adversary can generate a uniform superposition over X . This does not appear possible over isogenies, but may be true in certain group actions. Let us also assume that a non-negligible fraction of elements in G have order 2. In such a group action, the adversary can then construct∑x∈X|x, x^. Then we show that we can measure, say, the first register in the basis {|Gh∗ of the measurement is the value h, and the two registers each ∗ x^|G−h∗ x^. This follows because the two registers are maximally entangled. If h has order 2, then both states are copies of the valid quantum money state with serial number h. Even if h does not have order 2, the ability to construct two states with closely related serial numbers may be a concern. Such an attack does not immediately break quantum money security, since the adversary is not actually copying a given quantum money state. But it does show that the scheme would fail to achieve quantum lightning, which requires that it is hard to construct two banknotes with the same serial number, even for the mint. In light of this weakness, we design a different quantum money scheme for group actions where it is possible to construct the uniform superposition over X . Now a banknote with serial number h is actually |Gh∗ x^|G−h∗ x^. Minting uses the attack above. Quantum lightning security then follows from the assumed hardness of constructing f |Gh∗ x^|Gh∗ x^|G−h∗ x^|G−h∗ x^ for a common h. Note that the would yield ℓ states |Ghi∗ x^ for ∑ i = 1, ... , ℓ, such that the hiare random conditioned onihi= 0. In it this attack strategy only yields a single constraint on the hi. Meanwhile, to quantum lightning security of our modified scheme, one would need to generate hisatisfying three constraints. Thus, our modified scheme is plausibly secure in this scenario. Security. We here give an informal intuition for why our scheme may be secure. We focus on the isogeny setting, where it appears hard to generate the uniform superposition over X . For all isogenie-based group actions with efficiently computable actions, the group G has smooth order. Note that, unlike standard groups where a smooth order means discrete log is easy, in group actions this is not necessarily the case. However, in the quantum setting, smooth-order group actions yield the following potential attack strategy. For a subgroup H of G and an element x ∈ X , define the state 1 ∑ x^ Consider the task of computing |H∗x^, given (a description of) H and x, which we call the orbit superposition problem. If this were computationally easy, then in smooth-order group actions discrete logarithms are quantumly easy. To see this, let G0= {1} ⊆ G1⊆ · · · ⊆ Gn= G be a polynomial-length series of subgroups of G such that Gk / Gk−1is cyclic and polynomial sized. Such a series is guaranteed to exist by smoothness. Let gkbe a generator of Gk / Gk−1, and let its order be pk. Given x, y ∈ X , then y = h∗x where h can be uniquely written as j1·g1+j2·g2+· · ·+jn·gnfor some jk∈ [0, pk− 1]. We can compute the jk, and hence the discrete log h, as follows. First compute |Gn−1∗ x^ as well as |Gn−1∗ [(j · gn) ∗ y])^ for j ∈ [pn]. For exactly j = jn, |Gn−1∗ [(j · gn) ∗ y])^ = |Gn−1∗ y^, and for all other j, |Gn−1∗ [(j · gn) ∗ y]^ is orthogonal to by computing several copies of each state and swap test. Now one can run the same procedure on x and ((−jn) · gn−1) ∗ y to find jn−1. By proceeding in this way, one eventually recovers all the ji. While this might indicate a weakness in the discrete logarithm problem in smooth-order group actions, another takeaway is that the orbit superposition problem must be hard in such group actions. We can slightly generalize the above, which we call the generalized orbit superposition problem (GOSP). Here, we define as x^ The GOSP problem is to, given H, x, y, compute simultaneously |Hh∗ x^, |Hh∗ y^ for some h (which can be chosen by the adversary). The standard OSP problem is equivalent to GOSP except that it requires h = 0. It is a straightforward adaptation of the above argument that the hardness of discrete logs implies the hardness of GOSP. Verification in our scheme is statistically close to accepting exactly the honest banknote state, so we might as well treat it as such. Thus, the security of the quantum money scheme relies on the difficulty of computing two copies of |Gh∗x^ for a common h. In fact, under this assumption, the scheme obtains the stronger notion of quantum lightning. The intuition for this problem comes from the hardness of GOSP. Unfortunately, GOSP is an harder problem (and hence assuming hardness is a milder assumption): our scheme’s security is basically the special case where H = G and x = y. Therefore, we cannot directly base quantum lightning hardness on the discrete logarithm problem. But this at least shows the problems are similar, and we therefore conjecture that they have similar hardness. The foregoing general description of the illustrative embodiments and the following detailed description thereof are merely exemplary aspects of the teachings of this disclosure and are not restrictive. BRIEF DESCRIPTION OF THE DRAWINGS FIG. 1 illustrates a block diagram of a quantum money system, according to aspects of the present disclosure. This system includes a bank note generator module with registers and a bank note verification module. FIG. 2 depicts a block diagram of the quantum money system in communication with a client device via a communications network, according to aspects of the present disclosure. FIG. 3 shows a block diagram of an apparatus for global qubit placement assignment, featuring a processor connected to memory, input / output circuitry, communications circuitry, and qubit positioning circuitry, according to aspects of the present disclosure. DETAILED DESCRIPTION The following description sets forth exemplary aspects of the present disclosure. It should be recognized, however, that such description is not intended as a limitation on the scope of the present disclosure. Rather, the description also encompasses combinations and modifications to those exemplary aspects described herein. The present disclosure provides a quantum money scheme that leverages the principles of abelian group actions and isogenies over ordinary elliptic curves. This scheme is designed to create a system of money where banknotes are quantum states, offering a potential solution for creating un-counterfeitable currency. The quantum money scheme utilizes a bank note generator module and a verification module to generate and verify banknotes, respectively. The bank note generator module is configured to instantiate a set and a group, along with a group action operation. The module initializes registers, computes the group action operation in superposition, applies the quantum Fourier transform over the group to a register, and measures the register to obtain a measurement outcome. The outcome is then used to output a banknote. The verification module verifies the banknote by executing a series of instructions, including choosing a random group element, initializing a qubit, applying a controlled group action, and projecting the qubit onto a specific state. The quantum money scheme as described herein may offer a robust and secure method for creating and verifying quantum banknotes. 1 Preliminaries Here we give our notation and definitions, assuming the reader is familiar with the basics of quantum computation. 1.1 Quantum Fourier Transform over Abelian Groups Let G be an abelian group, which we will denote additively. We here define our notation for the quantum Fourier transform over G. Write G = Zn1×Zn2×Znkwhere Znjare the additive cyclic groups on njelements, and associate elements g ∈ G with tuples g = (g1, ... , gk) where g ∈ Z . The2 jnjn define χ : G → C by ∏k Observe the following: χG(g, h) = χG(h, g) χG(g1+ g2, h) = χG(g1, h)× χG(g2, h) The quantum Fourier QFTGdefined as ∑ QFTG|g^ = √ 1χ(g, h)|h^ . |G|h∈G Observe that QFTG= the standard QFT corresponds to QFTZnjand can be implemented efficiently, so can QFTG. From this point on, we will only work with a single group, so we will drop the sub-script and simply write etc. 1.2 Quantum Money and Quantum Lightning Here we define quantum money and quantum lightning. In the case of quantum money, we focus on mini-schemes, which are essentially the setting where there is only ever a single valid banknote produced by the mint. Such mini-schemes can be upgraded generically to full quantum money schemes using digital signatures. Syntax. Both quantum money mini-schemes and quantum lightning share the same syntax: • Gen(1λ) is a quantum polynomial-time (QPT) algorithm that takes as input the security parameter (written in unary) with samples a classical serial number σ and quantum banknote $. • Ver(σ, $) takes as input the serial number and a supposed banknote, and either accepts or rejects, denoted by 1 and 0 respectively. Correctness. Both quantum money mini-schemes and quantum lightning have the same correctness requirement, namely that valid banknotes produced by Gen are accepted by Ver. Concretely, there exists a negligible function negl(λ) such that Pr[Ver(σ, $) = 1 : (σ, $)← Gen(1λ)] ≥ 1− negl(λ) . Security. We now discuss the security requirements, which differ between quantum money and quantum lightning. Definition 1.1. Consider a QPT adversary A, which takes as input a serial number σ and banknote $, and outputs two potentially entangled states $1, $2, which it tries to pass off as two banknnotes. (Gen,Ver) is a secure quantum money mini-scheme if, for all such A, there exists a negligible negl(λ) such that the following holds: [ ] . Definition 1.2. Consider a QPT adversary B, which takes as input the security parameter λ, and outputs a serial number σ and two potentially entangled states $1, $2, which it tries to pass off as two banknnotes. (Gen,Ver) is a secure quantum lightning scheme if, for all such B, there exists a negligible negl(λ) such that the following holds: [ ] Pr Ver(σ, $1) = Ver(σ, $2) = 1 : (σ, $1, $2)← B(1λ) ≤ negl(λ) . Quantum lightning trivially implies quantum money: any quantum money adversary A can be converted into a quantum lightning adversary B by having B run both Gen and A. But quantum lightning is potentially stronger, as it means that even if the serial number is chosen adversarially, it remains hard to devise two valid banknotes. This in particular means there is some security against the mint, which yields a number of additional applications. Remark 1. One limitation of quantum lightning as defined above is that it cannot hold against non-uniform attackers with quantum advice, as such attackers could have σ, $1, $2hard-coded in their advice. This can be remedied by either insisting on only uniform attackers or attackers with classical advice. Alternatively, one can work in a trusted setup model, where a trusted third party generates a common reference string that is then inputted into Gen,Ver. 1.3 Group Actions An (abelian) group action consists of a family of (abelian) groups G = (Gλ)λ(written additively), a family of sets X = (Xλ)λ, and a binary operation ∗ : Gλ×Xλ→ Xλsatisfying the following properties: • Identity: If e ∈ Gλis the identity element, then e ∗ x = x for Xλ. • Compatibility: For . We will additionally require the following properties: • Efficiently computable: There is a QPT procedure Construct which, on input 1λ, outputs a description of Gλand an element xλ∈ Xλ. The operation ∗ is also computable by a QPT algorithm. • Efficiently Recognizable: There is a QPT procedure Recog which recognizes elements in Xλ. That is, for any λ and any string x (not necessarily in Xλ), Recog(1λ, x) accepts x overwhelming probability if x ∈ Xλ, and rejects with probability if x∈ / Xλ. • For every x, y ∈ Xλ, there is exactly one g ∈ Gλsuch that y = g ∗ x. Cryptographic group actions. At a minimum, a cryptographically useful group action will satisfy the following discrete log assumption: Definition 1.3. The discrete log assumption holds on (G,X ) if, for all QPT adversaries A, there exists a negligible λ such that Pr[A(g ∗ xλ) = g : g ← Gλ] ≤ negl(λ) . We will always the discrete log assumption, and this assumption provides intuition for what may and may not be hard on a group action. However, the discrete log assumption will not be sufficient for justifying the security of our construction. 2 Our Quantum Lightning Scheme Here, we give our basic quantum lightning construction, which assumes a cryptographic group action. Construction 2.1. Let Gen,Ver be the following QPT procedures: • Gen(1λ): Initialize quantum registers S (for serial number) and M (for money) to states |0^Sand |0^M, respectively. Then do the following: ∑ – Apply QFTGλto S, yielding the state√ 1|Gλ| g∈Gλ|g^S. – Apply in superposition the map |g^S|y^M7→ |g^S|y ⊕ (g ∗ xλ)^. The joint state of 1 ∑ the system S ⊗M is then√|Gλ| g∈Gλ|g^S|g ∗ xλ^M. – Apply QFTGλto S again, h)|h^S|g ∗ xλ^M– Measure S, giving the serial collapses to the knote $ = |Gλ∗ xλ^ :=√ 1∑ banh|Gλ| g∈Gλχ(g, h)|g ∗ xλ^M. Output (σ, $). • Ver(σ, $) : by applying the assumed for recognizing Xλin superposition. Then repeat the following λ times: √ – Initialize a new register H to (|0^H+ |1^H) / 2. – Choose a random group element u ∈ Gλ. – Apply to H⊗M in superposition the map ^ ^ ^ ^ ^|0^H|y^Mif b = 0 Apply|b^H|y^M7→^1 In the case that result of applying Apply is: ^^^^ √ – MeasureH in the basis Bh,u:= {(|0^H+χ(u, h)|1^H) / 2, (|0^H−χ(u, h)|1^H) / 2}, giving a bit b ∈ {0, 1}. Discard the H register. In the case that $ is the correct banknote state |Ghλ ∗ xλ^, b will be 0 with probability 1, and M will be left in the original If all the buare 0 and the support of $ is contained in Xλ, then accept. If any of the b are 1, or if the support is not contained in Xλ, reject. We see that for the correct banknote, Ver accepts with probability 1. 2.1 Accepting States of the Verifier Above we showed that honest banknote states are accepted by the verifier. We now prove that, roughly, honest banknote states are the only states accepted by the verifier, with overwhelming probability. Theorem 2.2. Let |ψ^ be a state over M. Then Pr[Ver(h, |ψ^) = 1] ≤ ∥^ψ|Ghλ ∗ xλ^∥2+ 2−λ. In other a negligible error. The remainder of this subsection is devoted to proving Theorem 2.2. Lemma 2.3. For h′̸= h, ^Gh′λ ∗ xλ|Ghλ ∗ xλ^ = 0 Proof. 0 Let |ψ^ be a a state with support on X . Since the |Gh∗xλ^ are orthogonal and the number of h equals the size of X , the |Ghλ∗xλ^ form a basis for the set of states with support on X . We can then write |ψ^ =∑h αh|Gh ∑λ ∗xλ^ whereh|αh|2= 1. Consider a single iteration of Ver on serial number H to (|0^+ |1^) / √2, applies the map Apply, and then measures H is basis Bh,uto get outcome b. post-measurement state of M conditioned on b = 0. ∑ Lemma 2.4. Conditioned on u, p := Pr[bu= 0] =14h′ ∥αh′∥2∥1 + χ(u, h− h′)∥2, and Apply (but before measurement) is: ∑ |ϕ^ = α′√1(|0^ + χ(u, h′)|1^h′h 2H H) |Gλ∗ xλ^Mh′∈GλThen p =1∑ 4h′ h− h′)∥2. Before re- ∑1+χ(u,h−h′)∗ xλ^M. We now iterate, replacing αh′with αh′ 1+χ(u,h−h′) 2 / after λ trials, conditioned on trial i using bi, we have that λ pfinal:= Pr[b1= · · · = bλ= 0] =1∑ 4λ∥αh′∥2∏ + χ(ui, h− h′)∥2h′1=1 We now average over u to get λ E[pfinal] is then the overall probability that Ver accepts |ψ^. This completes the proof of Theorem 2.2. 2.2 Computing the Serial Number Here, we show that, given a valid banknote $ = |Ghλ ∗ xλ^ with unknown serial number h, it is possible to efficiently compute h. Theorem 2.5. There exists a QPT algorithm Findh and a negligible function negl(λ) such that, on input |Ghλ ∗ xλ^, outputs h with probability at least 1− negl(λ). Proof. Recall from the description of Ver that, for a given u and given |Ghλ ∗ xλ^, we can compute the state |τu,h^|Ghλ ∗ xλ^ where |τu,h^ :=√ 12 (|0^H+ χ(u, h)|1^H). process still gives us |Ghλ ∗ many different ui. A naive solution is to compute many copies of |τu,h^ for some u ∈ Gλ, and then do state tomography to recover χ(u, h). If Gλwere cyclic, then χ(u, h) will uniquely determine h. The problem is that, since Gλis exponentially large, the distance between χ(u, h) as h varies will be exponentially small. This means doing state tomography to a sufficiently small error to recover h would require exponentially-many samples and therefore be inefficient. However, by choosing the uicarefully and being a bit more thoughtful, we can recover h in polynomial time. Our strategy will still be to compute many copies,h^ for some u and do state tomography to recover an estimate χˆ(u, h) for χ(u, h). In time poly(λ, 1 / ^, log(1 / δ)), we can guarantee that Pr h)− χ(u, h)∥ < ^] ≥ 1− δ, for any desired inverse-polynomial ^ and exponentially-small δ. The cyclic case. Suppose Gλis cyclic, and is therefore isomorphic to the additive group ZN. In this case, χ(u, h) = ei2πuh / N= ωNuh, where ωN= ei2π / N. Now when we do state tomorgraphy and recover χˆ(u, h), we learn an estimate of uh mod N . In more detail, given real number a and real number R, we let a mod R denote the unique value of a − Rk for integer k that lies in (−R / 2, R]. We can assume, by normalizing if necessary, that χˆ(u, h) = eiθfor θ ∈ (−π, π]. Then by the tomography guarantee, we have |θ − (2πuh / N) mod 2π| ≤ ^, or equivalently |Nθ / 2π − uh mod N | ≤ ^N / 2π, except with negligible probability This means we reduce the computation of h to the following classical task: we get to choose arbitrary ui∈ ZNfor i = 1, ... , n. In response, we learn uih+ eimod N , where eiis some random [−^N / 2π, ^N / 2π]. In vector notation, we can write a vector u ∈ ZnN , and receiving uh+ e mod N , where e is a vector whose components are independent random variables that are guaranteed to be in [−^N / 2π, ^N / 2π]. The goal is to compute h. This looks very similar to a 1-dimensional version of the LWE problem (or more accurately, bounded distance decoding) except that in our case we get to choose the vector u in whatever way so as to make the task easy. We can then use known techniques to find h. In particular, we can choose u = (1, 2, 4, , 8, · · · , 2n−1) where n = ⌈log2N⌉. This is known as the gadget “matrix”. In our case the matrix has width 1, whereas in general applications the matrix will have many columns. Importantly, u has an efficiently computable “trapdoor”. That is, write N =∑ni=02i×Ni, and let ^^^^^^^^^^^^^^^^^^^^^ Then A is full rank over the integers, but satisfies A · u mod N = 0n. Set ^ = π / n. Thus, given v := uh+ e mod N , we can compute A−1· (A · v mod N) = A−1· (A · e mod N) = A−1· (A · e) = e . Above, we used the fact that the entries of A ·e have absolute value at most n×^N / 2π < N / 2, meaning that reduction mod N has no effect. Once we compute e, we can then compute uh = v − e, and then h is just the first component. The general case. We cow consider the case of general groups. Let Gλ= Zn1× Zn2× · · · × Znk. Write h = (h1, · · · , hk). By choosing u = (u1, 0, · · · , 0), the task of computing h1reduces to the case where Gλ= Zn1, which can be solved via the algorithm above. Likewise, we can computeh2, · · · , hk, and hence h. 2.3 An Attack in Certain Group Actions, and an Alternative Scheme As discussed in Section ??, there may be a security vulnerability in the case where it is possible to construct∑y∈Xλ|y^. In particular, if the group also has a non-negligible fraction of elements of order 2, then Construction 2.1 fails to be quantum lightning. In more detail, we can first generat∑Xλ|y^, and then using the CNOT gate construct∑y∈Xλ|y, y^. Next, we apply the algorithm guaranteed by Theorem 2.5 to the first register, which measures the register in the basis {|Ghλ^}h. Call the outcome h. The state of the two registers then collapses to the (unnormalized) state: ( ( hh )∑hh )∑^λ Thus, after normalizing, we get |Ghλ^|G−λh^. If h = −h, then we obtain two copies of the |Ghλ^ with the same serial number. In light of this potential attack, we briefly describe an alternative scheme which leverages the attack in the construction to give banknotes that appears resilient to the attack. Construction 2.6. Let Gen′,Ver′be the following QPT procedures: en′∑ • G (1λ): Initialize quantum registers M0,M1to states√ 1|Xλ| x|x^M0and |0^M1, respectively. Then do the following: – Apply the CNOT operation to M0,M1, resulting in the state√ 1|X ||x, x^M0,M1λ. – Apply the algorithm guaranteed by Theorem 2.5 toM and h. Then the joint system of M0,M1collapses to |Ghλ^M0|G−λh^M1. – Output (σ = h, $ = |Ghλ^M0|G−λh^M1). • Ver′(σ, $). potentially entangled states $0, $1. Then run Ver(h, $0) and Ver(−h, $1), where Ver is from Construction 2.1. Ver′accepts if and only if both applications of Ver accept. Example Systems and Apparatuses of the Present Disclosure With reference to FIG. 1, the disclosed systems, methods, and computer-readable media with instructions for a quantum money system can include a bank note generator module further comprising registers, and a bank note verification module which produces verification results. To accomplish this, the parties may use any of the computer systems, including the communications networks, described herein. Continuing from the exemplary aspects of the present disclosure, FIG. 1 provides a visual representation of the quantum money system 001. This system is integral to the operation of the quantum money scheme, which is designed to leverage the principles of quantum mechanics to create a secure and un-counterfeitable form of currency. The quantum money system 001 includes two primary components: the bank note generation module 005 and the bank note verification module 020. The bank note generation module 005 is responsible for the creation of quantum banknotes. Within this module, there are registers 010 that play a central role in the generation process. These registers 010 are initialized in a specific joint state that is integral to the quantum mechanical operations that follow. The bank note generation module 005 operates by performing a series of quantum computations that involve the instantiation of a set of elliptic curves and an abelian group, along with a group action operation based on isogenies. These computations are performed in superposition, a state that is characteristic of quantum systems, allowing for the simultaneous processing of multiple potential outcomes. Once the quantum computations are complete, the bank note generation module 005 applies a quantum Fourier transform to the first register. This transform is a quantum analog of the classical Fourier transform and is used to translate the quantum information into a form that can be measured and interpreted. The application of the quantum Fourier transform is a complex process that manipulates the probabilities of the quantum states within the register. Following the quantum Fourier transform, the bank note generation module 005 measures the first register. This measurement collapses the quantum state of the register into a single outcome, which is used to determine the serial number of the quantum banknote. The second register, as a result of this measurement, collapses into a state that is associated with the serial number, forming the money state of the banknote. The final step in the banknote generation process is the outputting of the banknote, which comprises the serial number and the money state. This banknote is then stored in a quantum computer storage device, ensuring that the quantum state is preserved and that the banknote remains secure. The bank note verification module 020 is the counterpart to the bank note generation module 005 and is responsible for verifying the authenticity of the quantum banknotes. The verification process involves inputs 015 from the bank note generation module 005, which include the serial number and the money state of the banknote. The bank note verification module 020 executes a series of quantum operations to verify that the banknote is genuine. These operations include the initialization of a qubit, the application of a controlled group action, and the projection of the qubit onto a specific state. If the banknote passes all the verification steps, the verification module 020 produces a verification result 025, confirming the authenticity of the banknote. The quantum money system 001, as depicted in FIG. 1, is a sophisticated arrangement that combines the principles of quantum mechanics with advanced cryptographic techniques. The system ensures that the generation and verification of banknotes are secure processes that cannot be replicated or counterfeited. The use of quantum states as banknotes represents a novel approach to currency, with the potential to transform the financial industry and provide a new level of security in monetary transactions. In summary, FIG. 1 illustrates the components and processes involved in the quantum money system 001. The bank note generation module 005 and the bank note verification module 020 work in tandem to create and verify quantum banknotes, utilizing the properties of quantum mechanics to ensure the integrity and security of the currency. The detailed operation of these modules demonstrates the innovative application of quantum cryptography in the development of a quantum money scheme. FIG. 2 illustrates a block diagram of a system that may be specially configured within which embodiments of the present disclosure may operate. Specifically, FIG. 2 depicts an example system 100. The example system 100 includes a client device 104 and a quantum computing system 102. The client device 104 and quantum computing system 102 are communicable via a communications network 106. It should be appreciated that, in other embodiments, the system 100 includes one or more additional and / or alternative devices, which may operate independently and / or communicate with other devices of the system. In some embodiments the client device 104 embodies one or more computing devices embodied in hardware, software, firmware, and / or any combination thereof. The client device 104 may be embodied by a user device configured to provide various functionality. In this regard, the client device 104 may embody a conventional computing environment that interacts with the quantum computing system 102. Non-limiting examples of a client device 104 include a specially configured mobile device, tablet, smartphone, personal computer, laptop, enterprise terminal, and / or the like. In some embodiments, the client device 104 is configured entirely by specially configured software application(s) installed to and / or otherwise executable via the client device 104 to provide various functionality for accessing and / or otherwise controlling the quantum computing system 102 as described herein. In various embodiments, the client device 104 is a conventional and / or classical computer. In some embodiments, the client device 104 includes specially configured hardware, software, firmware, and / or a combination thereof, that enables access to and / or configuration of the quantum computing system 102. In some embodiments, the client device 104 provides access to functionality for generating and / or retrieving a quantum program for execution via a quantum computer of the quantum computing system 102. In this regard, the client device 104 may receive one or more user input(s) for constructing and / or that otherwise embody the quantum program to be executed. In this regard, a user of the client device 104 may interact with the client device 104 to construct a quantum circuit, store the quantum circuit, and submitting the quantum circuit for execution via a quantum computing system, such as the quantum computing system 102. In some embodiments, the client device 104 is embodied by a user-facing device of the quantum computing system 102, for example such that communications can occur without requiring the communications network 106. Alternatively or additionally, in some embodiments, the client device 104 enables user input and / or output for accessing the quantum computing system 102 to execute a quantum program. In some embodiments, the client device 104 communicates with one or more computing devices of the quantum computing system 102, such as a controller, that generates and / or compiles instructions for executing via a quantum computer. For example, in some embodiments, the quantum computing system 102 includes a controller that receives the quantum program from the client device 104 and compiles it to produce control system instructions embodying hardware manipulation instructions for running the quantum program on a specific quantum computer. In some embodiments, the controller is embodied by one or more computing devices external from but communicable with the quantum computing system 102. For example, the controller may be embodied by a circuit compiler embodied in a dedicated computing system embodied in hardware, software, firmware, and / or a combination thereof internal or external to the quantum computing environment 102, dedicated hardware communicable with a quantum computer of the quantum computing system 102, software executing on a computing system communicable with the quantum computer of the quantum computing system 102, and / or the like, The quantum computing system 102 may include one or more computing device(s) that enable compilation of a quantum program and / or use of a quantum computer for preforming a quantum program. In some embodiments, for example, the quantum computing system 102 includes a controller, a quantum computing environment, and various devices for physically manipulating the quantum computer. The quantum computing environment may include an ion trap architecture (e.g., linear, loop, and / or the like) for storing and manipulating qubits for gating. The controller may embody one or more computing device(s) embodied in hardware, software, firmware, and / or a combination thereof, that control the various devices that manipulate the quantum computer. Such control device(s) may include laser(s), cooling device(s), and / or the like. In some embodiments, the controller embodies a conventional computing system, for example specially configured via one or more specialized software application(s) to execute one or more process(es) that determine positions for the qubits at various time steps and / or instructions for repositioning the qubits to such position. For example, the controller may determine position assignments for each qubit at various time steps, and / or instructions embodying swap commands to cause the qubits to reach such positions at each of the appropriate time steps. In some embodiments, one or more device(s) of the quantum computing system 102 (e.g., a controller) receive data from the client device 104 that embodies the quantum program, instructions to be performed to manipulate the quantum computer, and / or the like. FIG. 3 illustrates a block diagram of an example apparatus for global qubit placement assignment that may be specially configured in accordance with at least some example embodiment of the present disclosure. In some embodiments, the controller of the quantum computing system 102 is embodied by one or more computing systems, such as the apparatus 300 as depicted and described in FIG. 3. The apparatus 300 includes processor 302, memory 304, input / output circuitry 306, communications circuitry 308, and qubit positioning circuitry 310. The apparatus 300 may be configured, using one or more of the sets of circuitry 302, 304, 306, 308, and / or 310, to execute the operations described herein. Although components are described with respect to functional limitations, it should be understood that the particular implementations necessarily include the user of particular computing hardware. It should also be understood that certain of the components described herein may include similar or common hardware. For example, two sets of circuitry may both leverage use of the same processor(s), network interface(s), storage medium(s), and / or the like, to perform their associated functions, such that duplicate hardware is not required for each set of circuitry. The user of the term “circuitry” as used herein with respect to components of the apparatuses described herein should therefore be understood to include particular hardware configured to perform the functions associated with the particular circuitry as described herein. Particularly, the term “circuitry” should be understood broadly to include hardware and, in some embodiments, software for configuring the hardware. For example, in some embodiments, “circuitry” includes processing circuitry, storage media, network interfaces, input / output devices, and / or the like. Alternatively or additionally, in some embodiments, other elements of the apparatus 300 may provide or supplement the functionality of another particular set of circuitry. For example, the processor 302 in some embodiments provides processing functionality to any of the sets of circuitry, the memory 304 provides storage functionality to any of the sets of circuitry, the communications circuitry 308 provides network interface functionality to any of the sets of circuitry, and / or the like. In some embodiments, the processor 302 (and / or co-processor or any other processing circuitry assisting or otherwise associated with the processor) may be in communication with the memory 304 via a bus for passing information among components of the apparatus 300. In some embodiments, for example, the memory 304 is non-transitory and may include, for example, one or more volatile and / or non-volatile memories. In other words, for example, the memory 304 in some embodiments includes or embodies an electronic storage device (e.g., a computer readable storage medium). In some embodiments, the memory 304 is configured to store information, data, content, applications, instructions, or the like, for enabling the apparatus 300 to carry out various functions in accordance with example embodiments of the present disclosure. The processor 302 may be embodied in a number of different ways. For example, in some example embodiments, the processor 302 includes one or more processing devices configured to perform independently. Additionally or alternatively, in some embodiments, the processor 302 includes one or more processor(s) configured in tandem via a bus to enable independent execution of instructions, pipelining, and / or multithreading. The use of the terms “processor” and “processing circuitry” may be understood to include a single core processor, a multi-core processor, multiple processors internal to the apparatus 300, and / or one or more remote or “cloud” processor(s) external to the apparatus 300. In an example embodiment, the processor 302 may be configured to execute instructions stored in the memory 304 or otherwise accessible to the processor. Alternatively or additionally, the processor 302 in some embodiments is configured to execute hard-coded functionality. As such, whether configured by hardware or software methods, or by a combination thereof, the processor 302 may represent an entity (e.g., physically embodied in circuitry) capable of performing operations according to an embodiment of the present disclosure while configured accordingly. Alternatively or additionally, as another example in some example embodiments, when the processor 302 is embodied as an executor of software instructions, the instructions may specifically configure the processor 302 to perform the algorithms embodied in the specific operations described herein when such instructions are executed. As one particular example, the processor 302 may be configured to perform various operations associated with improved traitor tracing, for example as described with respect to operation of the quantum computing system 102 and / or as described further herein. In some embodiments, the apparatus 300 includes input / output circuitry 306 that may, in turn, be in communication with processor 302 to provide output to the user and, in some embodiments, to receive an indication of a user input. The input / output circuitry 306 may comprise one or more user interface(s) and may include a display that may comprise the interface(s) rendered as a web user interface, an application user interface, a user device, a backend system, or the like. In some embodiments, the input / output circuitry 306 may also include a keyboard, a mouse, a joystick, a touch screen, touch areas, soft keys a microphone, a speaker, or other input / output mechanisms. The processor 302 and / or input / output circuitry 306 comprising the processor may be configured to control one or more functions of one or more user interface elements through computer program instructions (e.g., software and / or firmware) stored on a memory accessible to the processor (e.g., memory 304, and / or the like). In some embodiments, the input / output circuitry 306 includes or utilizes a user-facing application to provide input / output functionality to a client device and / or other display associated with a user. The communications circuitry 308 may be any means such as a device or circuitry embodied in either hardware or a combination of hardware and software that is configured to receive and / or transmit data from / to a network and / or any other device, circuitry, or module in communication with the apparatus 300. In this regard, the communications circuitry 308 may include, for example, a network interface for enabling communications with a wired or wireless communication network. For example, the communications circuitry 308 may include one or more network interface card(s), antenna(s), bus(es), switch(es), router(s), modem(s), and supporting hardware, firmware, and / or software, or any other device suitable for enabling communications via one or more communication network(s). Additionally or alternatively, the communications circuitry 308 may include circuitry for interacting with the antenna(s) and / or other hardware or software to cause transmission of signals via the antenna(s) or to handle receipt of signals received via the antenna(s). In some embodiments, the communications circuitry 308 enables transmission to and / or receipt of data from a client device in communication with the apparatus 300. It should be appreciated that, in some embodiments, qubit positioning circuitry 310 may include a separate processor, specially configured field programmable gate array (FPGA), or a specially programmed application specific integrated circuit (ASIC). Additionally or alternatively, in some embodiments, one or more of the sets of circuitries 302-310 are combinable. Alternatively or additionally, in some embodiments, one or more of the sets of circuitry perform some or all of the functionality described associated with another component. For example, in some embodiments, one or more of the sets of circuitry 302-310 are combined into a single module embodied in hardware, software, firmware, and / or a combination thereof. Similarly, in some embodiments, one or more of the sets of circuitry, for example qubit positioning circuitry 310 is combined such that the processor 302 performs one or more of the operations described above with respect to each of these modules. Quantum Money Systems In the detailed description of the present disclosure, various embodiments and aspects of a system for storing and transferring quantum money are described. The system leverages advanced quantum technologies and cryptographic principles to ensure the security and reliability of quantum currency transactions. Quantum money, as used herein, refers to a form of currency or value representation that utilizes the principles of quantum mechanics for its creation, storage, transfer, and verification. The quantum money system disclosed herein includes methods for storing quantum money using quantum memory technologies, transferring quantum money through secure communication protocols, and addressing challenges associated with these processes. Storing Quantum Money Quantum memory technologies are employed to store quantum money securely. These technologies are designed to maintain the integrity of quantum states over time, which is paramount for preserving the value and authenticity of quantum money. The following are exemplary quantum memory technologies utilized in various embodiments: Ion Traps: Ion traps confine ions using electromagnetic fields. The ions act as qubits, which are the basic units of quantum information. Ion traps are characterized by their long coherence times and high-fidelity operations, making them suitable for storing quantum states for extended periods. Superconducting Qubits: These qubits utilize superconducting circuits that operate at cryogenic temperatures. Superconducting qubits can be integrated into complex quantum circuits, providing scalability and relatively good coherence times, which are beneficial for the storage of quantum money. Topological Qubits: Topological qubits encode information in topological states of matter, offering inherent resistance to local noise and decoherence. Although topological qubits are in the experimental phase, they show promise for robust and fault-tolerant quantum storage. Quantum error correction is an integral part of maintaining the fidelity of stored quantum money. Error correction codes are implemented to protect quantum information from decoherence and operational errors. Notable error correction codes include: Surface Code: The surface code employs a 2D lattice arrangement of qubits. Logical qubits are encoded in the collective state of multiple physical qubits. The surface code is advantageous due to its high error threshold and potential for scalability. Concatenated Codes: Concatenated codes utilize a hierarchical structure of error correction, applying multiple layers to improve error rates. These codes are suitable for long-term storage of quantum money due to their ability to enhance error correction capabilities. Isolation of quantum systems is another aspect of storing quantum money. Minimizing interactions with the environment is achieved through various isolation techniques, such as: Cryogenic Environments: Superconducting qubits are stored in dilution refrigerators that maintain temperatures near absolute zero. This reduces thermal noise and decoherence, contributing to the stability of the quantum states. Vacuum Chambers: Ion traps and other qubit types are stored in ultra-high vacuum chambers to prevent interactions with air molecules and other particles, which could lead to decoherence. Transferring Quantum Money The transfer of quantum money between parties is secured through quantum communi- cation protocols. These protocols ensure that any eavesdropping attempts are detectable, thereby maintaining the confidentiality and integrity of the transaction. Exemplary protocols include: Quantum Key Distribution (QKD): QKD protocols, such as the BB84 and E91 protocols, provide secure methods for transferring quantum states. The BB84 protocol uses non- orthogonal quantum states for secure communication, while the E91 protocol relies on entangled qubits to establish a secure connection. Quantum Teleportation: Quantum teleportation enables the transfer of quantum infor- mation without the physical movement of the quantum state. This process involves shared entangled qubits between the sender and receiver, a Bell-state measurement, and classical communication to complete the transfer. Quantum Networks: The development of quantum networks is integral to the transfer of quantum money. Quantum networks connect quantum nodes, such as quantum computers and quantum memory devices, through entanglement and quantum repeaters. Quantum repeaters extend the range of quantum communication, while the concept of a quantum internet allows for the secure and efficient transfer of quantum information. In some embodiments, the invention includes systems, methods, and computer-readable media configured for a quantum money scheme, comprising: a bank note generator module, the module configured for: (a) instantiating a set X , a group G, and a group action operation ∗, wherein the set X is a set of elliptic curves with a given number of points, group G is an abelian group, and the group action ∗ is based on isogenies;1∑ (b) initializing a first register and a second register in a joint state√|G| g^|0^ ; 1 ∑ (c) computing the group action operation ∗ in superposition to compute√|G| h∈G|g^|g∗ x^ , where x ∈ X is arbitrary; (d) applying a quantum Fourier transform over G to the first register; (e) measuring the first register to obtain measurement outcome h, such that the second register collapses to |Gh∗ x^ ; (f) outputting a banknote $ comprising h as a serial number and |Gh∗ x^ as a money state; and (g) storing the banknote $ in a quantum computer storage device. In some further embodiments, the result of the quantum Fourier transform over G to the first register is executed such that the result can be represented by: 1 ∑ χ(g, h)|h, g ∗ x^ =√ 1∑ |h^|Gh∗ x^ ; and; ∑ wherein |Gh∗ x^ is the state√ 1|G| g∈Gχ(g, h)|g ∗ x^ . Some further embodiments the verification module config- ured for verifying the executing one or more times instructions for: (a) choosing a random g ∈ G; (b) initializing a qubit with (|0^+ |1^) / √2; ^ (d) projecting the qubit onto the which will accept with probability 1 for honest banknote states; and if all of the projections are accepted, then the banknote is considered verified. According to some further embodiments, if $ is the honest banknote state, then the state of the system becomes: 1 ( ) √ ∗ . According to some module, upon generating a banknote, signs the serial number using a digital signature scheme. According to some further further embodiments, the verification module, upon verifying the signature, only considers the banknote valid if the signature on the serial number is valid. In some further embodiments, the group action is derived from isogenies over ordinary elliptic curves. Although an example processing system has been described above, implementations of the subject matter and the functional operations described herein can be implemented in other types of digital electronic circuitry, or in computer software, firmware, or hardware, including the structures disclosed in this specification and their structural equivalents, or in combinations of one or more of them. Embodiments of the subject matter and the operations described herein can be im- plemented in digital electronic circuitry, or in computer software, firmware, or hardware, including the structures disclosed in this specification and their structural equivalents, or in combinations of one or more of them. Embodiments of the subject matter described herein can be implemented as one or more computer programs, i.e., one or more modules of computer program instructions, encoded on computer storage medium for execution by, or to control the operation of, information / data processing apparatus. Alternatively, or in addition, the program instructions can be encoded on an artificially-generated propagated signal, e.g., a machine-generated electrical, optical, or electromagnetic signal, which is generated to encode information / data for transmission to suitable receiver apparatus for execution by an information / data processing apparatus. A computer storage medium can be, or be included in, a computer-readable storage device, a computer-readable storage substrate, a random or serial access memory array or device, or a combination of one or more of them. Moreover, while a computer storage medium is not a propagated signal, a computer storage medium can be a source or destination of computer program instructions encoded in an artificially-generated propagated signal. The computer storage medium can also be, or be included in, one or more separate physical components or media (e.g., multiple CDs, disks, or other storage devices). The operations described herein can be implemented as operations performed by an information / data processing apparatus on information / data stored on one or more computer- readable storage devices or received from other sources. The term “data processing apparatus” encompasses all kinds of apparatus, devices, and machines for processing data, including by way of example a programmable processor, a computer, a system on a chip, or multiple ones, or combinations, of the foregoing. The apparatus can include special purpose logic circuitry, e.g., an FPGA (field programmable gate array) or an ASIC (application-specific integrated circuit). The apparatus can also include, in addition to hardware, code that creates an execution environment for the computer program in question, e.g., code that constitutes processor firmware, a protocol stack, a repository management system, an operating system, a cross-platform runtime environment, a virtual machine, or a combination of one or more of them. The apparatus and execution environment can realize various different computing model infrastructures, such as web services, distributed computing and grid computing infrastructures. A computer program (also known as a program, software, software application, script, or code) can be written in any form of programming language, including compiled or interpreted languages, declarative or procedural languages, and it can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, object, or other unit suitable for use in a computing environment. A computer program may, but need not, correspond to a file in a file system. A program can be stored in a portion of a file that holds other programs or information / data (e.g., one or more scripts stored in a markup language document), in a single file dedicated to the program in question, or in multiple coordinated files (e.g., files that store one or more modules, sub-programs, or portions of code). A computer program can be deployed to be executed on one computer or on multiple computers that are located at one site or distributed across multiple sites and interconnected by a communication network. The processes and logic flows described herein can be performed by one or more pro- grammable processors executing one or more computer programs to perform actions by operating on input information / data and generating output. Processors suitable for the execution of a computer program include, by way of example, both general and special purpose microprocessors, and any one or more processors of any kind of digital computer. Generally, a processor will receive instructions and information / data from a read-only memory or a random access memory or both. The essential elements of a computer are a processor for performing actions in accordance with instructions and one or more memory devices for storing instructions and data. Generally, a computer will also include, or be operatively coupled to receive information / data from or transfer information / data to, or both, one or more mass storage devices for storing data, e.g., magnetic, magneto-optical disks, or optical disks. However, a computer need not have such devices. Devices suitable for storing computer program instructions and information / data include all forms of non-volatile memory, media and memory devices, including by way of example semiconductor memory devices, e.g., EPROM, EEPROM, and flash memory devices; magnetic disks, e.g., internal hard disks or removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks. The processor and the memory can be supplemented by, or incorporated in, special purpose logic circuitry. To provide for interaction with a user, embodiments of the subject matter described herein can be implemented on a computer having a display device, e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor, for displaying information / data to the user and a keyboard and a pointing device, e.g., a mouse or a trackball, by which the user can provide input to the computer. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback, e.g., visual feedback, auditory feedback, or tactile feedback; and input from the user can be received in any form, including acoustic, speech, or tactile input. In addition, a computer can interact with a user by sending documents to and receiving documents from a device that is used by the user; for example, by sending web pages to a web browser on a user’s client device in response to requests received from the web browser. Embodiments of the subject matter described herein can be implemented in a computing system that includes a back-end component, e.g., as an information / data server, or that includes a middleware component, e.g., an application server, or that includes a front-end component, e.g., a client computer having a graphical user interface or a web browser through which a user can interact with an implementation of the subject matter described herein, or any combination of one or more such back-end, middleware, or front-end components. The components of the system can be interconnected by any form or medium of digital information / data communication, e.g., a communication network. Examples of communi- cation networks include a local area network (“LAN”) and a wide area network (“WAN”), an inter-network (e.g., the Internet), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks). The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. In some embodiments, a server transmits information / data (e.g., an HTML page) to a client device (e.g., for purposes of displaying information / data to and receiving user input from a user interacting with the client device). Information / data generated at the client device (e.g., a result of the user interaction) can be received from the client device at the server. While this specification contains many specific implementation details, these should not be construed as limitations on the scope of any disclosures or of what may be claimed, but rather as descriptions of features specific to particular embodiments of particular disclosures. Certain features that are described herein in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment can also be implemented in multiple embodiments separately or in any suitable subcombination. Moreover, although features may be described above as acting in certain combinations and even initially claimed as such, one or more features from a claimed combination can in some cases be excised from the combination, and the claimed combination may be directed to a subcombination or variation of a subcombination. Similarly, while operations are depicted in the drawings in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Moreover, the separation of various system components in the embodiments described above should not be understood as requiring such separation in all embodiments, and it should be understood that the described program components and systems can generally be integrated together in a single software product or packaged into multiple software products. Thus, particular embodiments of the subject matter have been described. Other embodi- ments are within the scope of the following claims. In some cases, the actions recited in the claims can be performed in a different order and still achieve desirable results. In addition, the processes depicted in the accompanying figures do not necessarily require the particular order shown, or sequential order, to achieve desirable results. In certain implementations, multitasking and parallel processing may be advantageous. Throughout this disclosure, various terms and phrases are used to describe features of the disclosed technology. It is to be understood that these terms and phrases may encompass a variety of meanings and definitions, as is common in the field of technology and patent law. The definitions of these terms may vary depending on the context in which they are used, the specific embodiment being described, or the interpretation of the technology by those skilled in the art. For instance, terms such as "computing device," "processor," "memory," and "network" may refer to a wide range of devices, components, systems, and configurations known in the art, and their specific definitions may differ based on the implementation or design of the system. Similarly, phrases like "securely storing," "computing a vector," and "generating a message" may involve various methods, techniques, and processes that achieve the same or similar outcomes but may be executed in different manners. It is also to be understood that the use of terms in the singular or plural form is not intended to limit the scope of the claims. For example, the mention of "a computing device" does not preclude the presence of multiple computing devices within a system. Likewise, references to "a network" may include various interconnected networks or a single network comprising multiple segments or layers. Furthermore, the use of the term "may" in relation to an action or feature indicates that the action or feature is possible, but not necessarily mandatory. This term is used to describe optional or alternative aspects of the disclosed technology that provide flexibility in how the technology may be implemented or utilized. The definitions provided herein are intended to serve as examples and are not exhaustive. Those skilled in the art may ascribe different meanings to these terms based on the context, the specific technology being described, or the advancements in the field. Therefore, the definitions of the terms and phrases used in this disclosure and the claims are to be interpreted broadly and in a manner consistent with the understanding of those skilled in the relevant art. The use of the word "a" or "an" when used in conjunction with the claims herein is to be interpreted as including one or more than one of the element it introduces. Similarly, the use of the term "or" is intended to be inclusive, such that the phrase "A or B" is intended to include A, B, or both A and B, unless explicitly stated otherwise. The term "comprising" is to be interpreted as inclusive or open-ended and does not exclude additional, unrecited elements or method steps. However, the term "consisting of" excludes any element, step, or ingredient not specified in the claim. The term "consisting essentially of" limits the scope of a claim to the specified materials or steps and those that do not materially affect the basic and novel characteristic(s) of the claimed disclosure. Reference throughout the specification to "one embodiment," "another embodiment," "an embodiment," and so forth, means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure, and may not necessarily be present in all embodiments. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments without limitation. The use of the terms "first," "second," and the like does not imply any order or sequence, but are used to distinguish one element from another, and the terms "top," "bottom," "front," "back," "leading," "trailing," and the like are used for descriptive purposes and are not necessarily to be construed as limiting. The terms "connected," "coupled," or any variant thereof, mean any direct or indirect connection or coupling between two or more elements, and may encompass the presence of one or more intermediate elements between the two elements that are connected or coupled to each other. As used herein, the term "messages" may refer to any form of data or information that can be processed, transmitted, or stored in a digital format. Messages may include, but are not limited to, arbitrary-length plaintext messages, pre-hashed messages, concatenated messages, binary data, network protocol messages, database records, and time-stamped messages. Messages may be composed of characters, symbols, or binary data and may represent various forms of content such as text, numbers, multimedia, executable code, or any other data that can be digitally encoded. Messages may be used as input for cryptographic functions, such as keyed hash functions, where they are transformed into a fixed-size hash value influenced by a secret cryptographic key. The term "messages" encompasses a wide range of data types and structures, from simple text strings to complex structured data, and may include metadata, headers, footers, or other information that facilitates the processing, transmission, or interpretation of the content. Messages may be generated by users, systems, or processes and may be intended for various purposes, including communication, authentication, verification, logging, or any other function that involves the use of digital data. The description of the embodiments of the present disclosure is intended to be illustrative, and not to limit the scope of the claims. Many alternatives, modifications, and variations will be apparent to those skilled in the art. A number of implementations have been described. Nevertheless, it will be understood that various modifications may be made without departing from the spirit and scope of the disclosure. Accordingly, other implementations are within the scope of the following claims. A number of implementations have been described. Nevertheless, it will be understood that various modifications may be made without departing from the spirit and scope of the disclosure. Accordingly, other implementations are within the scope of the following claims.
Claims
CLAIMS 1. A system for a quantum money scheme, the system comprising: a bank note generator module, the module configured for: (a) instantiating a set X , a group G, and a group action operation ∗, wherein the set X is a set of elliptic curves with a given number of points, group G is an abelian group, and the group action ∗ is based on isogenies; 1 ∑ (b) initializing a first register and a second register in a joint state√g∈G|g^|0^ ;(c) computing the group action operation ∗ in superposition toh∈G|g^|g∗ x^ , where x ∈ X is arbitrary; (d) applying a quantum Fourier transform over G to the first register; (e) measuring the first register to obtain measurement outcome h, such that the second register collapses to |Gh∗ x^ ; (f) outputting a banknote $ comprising h as a serial number and |Gh∗ x^ as a money state; and (g) storing the banknote $ in a quantum computer storage device.
2. The system of claim 1, wherein the result of the quantum Fourier transform over G to the first register is executed such that the result can be represented by: 1 ∑ ∑ χ(g, h)|h, g ∗ x^ =√ 1|h^|Gh∗ x^ ; |G| g,h∈G |G| h and;h 1∑ wherein |G ∗ x^ is the state ^ .
3. The system of claim 1, further comprising a verification module, the verification module configured for verifying the banknote $ by: executing one or more times instructions for: (a) choosing a random g ∈ G; (b) initializing a qubit with (|0^+ |1^) / √2;^^ ^ ^(d) projecting the qubit onto the state |0^ + χ(g, h)−1|1^, which will accept with probability 1 for honest banknote states; and if all of the projections are accepted, then the banknote is considered verified.
4. The system of claim 3, wherein if $ is the honest banknote state, then the state of the system becomes: ( ) √1|0^+ χ(g, h)−1|1^ |Gh∗ x^ .
25. The system of claim 1, wherein the banknote generation module, upon generating a banknote, signs the serial number using a digital signature scheme.
6. The system of claim 5, wherein the verification module, upon verifying the signature, only considers the banknote valid if the signature on the serial number is valid.
7. The system of claim 1, wherein the group action is derived from isogenies over ordinary elliptic curves.
8. A quantum money scheme method, the method comprising: executing at a bank note generator module, instructions configured for: (a) instantiating a set X , a group G, and a group action operation ∗, wherein the set X is a set of elliptic curves with a given number of points, group G is an abelian group, and the group action ∗ is based on isogenies; ∑ (b) initializing a first register and a second register in a joint state√ 1|G| g∈G|g^|0^ ; (c) computing the group action operation ∗ in superposition toh∈G|g^|g∗ x^ , where x ∈ X is arbitrary; (d) applying a quantum Fourier transform over G to the first register; (e) measuring the first register to obtain measurement outcome h, such that the second register collapses to |Gh∗ x^ ; (f) outputting a banknote $ comprising h as a serial number and |Gh∗ x^ as a money state; and (g) storing the banknote $ in a quantum computer storage device.
9. The method of claim 8, wherein the result of the quantum Fourier transform over G to the first register is executed such that the result can be represented by: 1 ∑ χ(g, h)|h, g ∗ x^ =√ 1∑ |h^|Gh∗ x^ ; |G| g,h∈G |G| h.
10. The method of claim 8, further comprising executing at a verification module instructions configured for verifying the banknote $ by: executing one or more times instructions for: (a) choosing a random g ∈ G; (b) initializing a qubit with (|0^+ |1^) / √2;^^ ^ ^ ^(d) projecting the qubit onto the state |0^ + χ(g, h)−1|1^, which will accept with probability 1 for honest banknoteif all of the projections are accepted, then the banknote is considered verified.
11. The method of claim 10, wherein if $ is the honest banknote state, then the state of the system becomes: √1( ) |0^+ χ(g, h)−1|1^ |Gh∗ x^ .
212. The method of claim 8, further comprising, at the banknote generation module, executing instructions for, upon generating a banknote, signing the serial number using a digital signature scheme.
13. The method of claim 12, further comprising, at the verification module, executing instructions for verifying the signature, and only considering the banknote valid if the signature on the serial number is valid.
14. The method of claim 8, wherein the group action is derived from isogenies over ordinary elliptic curves.
15. A non-transitory computer-readable medium storing instructions that, when executed by a quantum computing system, cause the system to perform operations for a quantum money scheme, the operations comprising: (a) instantiating a set X , a group G, and a group action operation ∗, wherein the set X is a set of elliptic curves with a given number of points, group G is an abelian group, and the group action ∗ is based on isogenies; 1 ∑ (b) initializing a first register and a second register in a joint state√|G| g∈G|g^|0^ ; (c) computing the group action operation ∗ in superposition to|g^|g∗ x^ , where x ∈ X is arbitrary;(d) applying a quantum Fourier transform over G to the first register; (e) measuring the first register to obtain measurement outcome h, such that the second register collapses to |Gh∗ x^ ; (f) outputting a banknote $ comprising h as a serial number and |Gh∗ x^ as a money state; and (g) storing the banknote $ in a quantum computer storage device.
16. The computer-readable medium of claim 15, wherein the quantum Fourier transform applied to the first register results in a state represented by: ;wherein ∗ is the stateg∈Gχ(g, h) ∗ .
17. The computer-readable medium of claim 15, further storing instructions for verifying the banknote $, the verification comprising: executing one or more times instructions for: (a) choosing a random g ∈ G; (b) initializing a qubit with (|0^+ |1^) / √2; ^^ ^ ^ ^|0, y^ if b = 0 (c) applying a controlled group action |b, y^ , wherein b repre-1 sents contents of the qbit and y represents contents of the money state; (d) projecting the qubit onto the state |0^ + χ(g, h)−1|1^, which will accept with probability 1 for honest banknote states; and if all of the projections are accepted, then the banknote is considered verified.
18. The computer-readable medium of claim 17, wherein if $ is an honest banknote state, the state of the system is represented by: 1 ( ) √ |0^+ χ(g, h)−1|1^ |Gh∗ x^ .
219. The computer-readable medium of claim 15, further storing instructions for the banknote generation module to sign the serial number using a digital signature scheme upon generating a banknote.
20. The computer-readable medium of claim 19, further storing instructions for the verification module to verify the signature and to consider the banknote valid if the signature on the serial number is valid.
21. The computer-readable medium of claim 15, wherein the group action is derived from isogenies over ordinary elliptic curves.