Wiesner's Quantum Money Scheme

Mar
03
2026

Quantum money was first proposed by Stephen Wiesner in the early 1970s and eventually published in 1983 [3]. It is widely regarded as the first cryptographic application of genuinely quantum mechanical principles, predating even quantum key distribution. The core insight was remarkably simple yet revolutionary: quantum states cannot, in general, be cloned.

Unlike classical information, which can be copied arbitrarily many times without disturbance, unknown quantum states are protected by the no-cloning theorem. Wiesner realized that this physical limitation could serve as a cryptographic resource. In particular, it suggested the possibility of constructing banknotes whose unforgeability would not rely on computational hardness assumptions, but instead on the fundamental laws of quantum mechanics.

Wiesner's proposal is based on a simple but powerful idea: encode information in randomly chosen conjugate bases, so that any attempt to measure without knowing the basis inevitably introduces detectable disturbance. 

Fix a security parameter $n$. Each banknote consists of a classical serial number $\$$ together with an $n$-qubit quantum state $|\psi_\$\rangle$. To mint a banknote, the bank generates a unique serial number and samples two uniformly random strings
\[
x \in \{0,1\}^n, \qquad \theta \in \{0,1\}^n.
\]
For each position $i = 1, \dots, n$, it prepares the single-qubit state
\[
|x_i\rangle_{\theta_i} = H^{\theta_i} |x_i\rangle.
\]

In other words:

  • If $\theta_i = 0$, the qubit is prepared in the computational basis,  i.e., $|0\rangle$ or $|1\rangle$.
  • If $\theta_i = 1$, the qubit is prepared in the Hadamard basis, i.e., $|+\rangle$ or $|-\rangle$
     

The full banknote state is therefore:

\[
|\psi_\$\rangle = \bigotimes_{i=1}^{n} |x_i\rangle_{\theta_i}.
\]

The bank stores the classical description $(x,\theta)$ in a secure database associated with the serial number $\$$. This information is never revealed to the holder of the banknote. Figure 1 illustrates the overall structure of the scheme.

Figure 1. Schematic representation of Wiesner's quantum banknote generation and verification process.

 

Verification proceeds by retrieving $(x,\theta)$ from the database and measuring each qubit in the corresponding basis $\theta_i$. The bank accepts the banknote if and only if all measurement outcomes match the string $x$. Since the measurements are performed in the correct bases, an honest banknote is accepted with probability $1$ (ignoring physical noise).

The security intuition relies on the fact that the computational basis $\{|0\rangle,|1\rangle\}$ and the Hadamard basis $\{|+\rangle,|-\rangle\}$ are mutually unbiased. Measuring a qubit prepared in one basis using the other produces a uniformly random outcome and irreversibly disturbs the state. A counterfeiter who does not know $\theta$ must therefore guess measurement bases. For each qubit, choosing the wrong basis, which occurs with probability $1/2$, destroys the encoded bit with probability $1/2$. These errors accumulate across qubits, making successful forgery exponentially unlikely in $n$.

At first sight, Wiesner’s scheme appears to achieve something extraordinary: a form of money whose non-forgeability follows directly from the structure of quantum mechanics. However, this intuitive argument must be formalized carefully, and as we shall see, its practical limitations are more subtle than they initially appear.

Since Wiesner's original proposal, quantum money has developed into a significant research direction within quantum cryptography and quantum complexity theory. Early formalizations of security appeared in the work of Aaronson [1], who framed the problem using game-based definitions and explored the possibility of public-key quantum money. Subsequent research has investigated constructions based on topology [2], group actions, and more recently quantum lightning schemes [4], which attempt to achieve stronger notions such as collision resistance for quantum states.

Despite this progress, the field remains far from practical implementation. No fully satisfactory public-key quantum money scheme is currently known under standard cryptographic assumptions.

References

[1] Scott Aaronson. "Quantum Copy-Protection and Quantum Money". Proceedings of the 24th Annual IEEE Conference on Computational Complexity (CCC), 2009.

[2] Edward Farhi et al. "Quantum Money from Knots". Proceedings of the 3rd Innovations in Theoretical Computer Science Conference (ITCS), 2012.

[3] Stephen Wiesner. "Conjugate Coding". SIGACT News 15(1), 1983.

[4] Mark Zhandry. "Quantum Lightning Never Strikes the Same State Twice". EUROCRYPT 2019.

Do you have any questions?

Add new comment

Restricted HTML