Zero Knowledge Proofs in Quantum Networks Tuhin Paul,1, ∗ Srijani Das,1, † Manasi Patra,1, ‡ and Ramij Rahaman1, §
arXiv:2609.35339v1 [quant-ph] 28 Sep 2026
1
Physics and Applied Mathematics Unit, Indian Statistical Institute, Kolkata 700108, India
Zero-knowledge proofs (ZKPs) enable the verification of a statement without revealing any information beyond its validity and constitute a fundamental primitive in cryptography and information theory. However, existing constructions rely on computational assumptions and are predominantly confined to bipartite settings, leaving their information-theoretic realization in bipartite or network scenarios largely unexplored. Here we develop a framework for zero-knowledge verification based on the indistinguishability of quantum states under operational constraints. Exploiting the fundamental limitations imposed by local operations, we show that a verifier is inherently restricted from extracting information about the underlying state while retaining the ability to verify correctness. We construct explicit protocols for multiparty quantum networks that achieve information-theoretic security, ensuring that no subset of collaborating parties can gain knowledge beyond the validity of the statement, independent of their joint computational power.
I.
INTRODUCTION
The ability to verify the validity of a statement without revealing any additional information about the underlying proof constitutes one of the most profound and counterintuitive primitives in modern cryptography and information theory. Such protocols, known as zero-knowledge proofs (ZKPs), provide a rigorous framework to achieve this task, allowing a prover to convince a verifier of the validity of a statement while ensuring that no additional information about the proof itself is disclosed. Since their introduction by Goldwasser, Micali, and Rackoff [1], ZKPs have become indispensable tools for secure authentication, privacy-preserving verification, and blockchain protocols [2–7]. Formally, a zero-knowledge proof protocol is typically formulated through an interactive exchange between two parties, a computationally unbounded prover and a polynomial-time verifier. Such protocols must satisfy three fundamental conditions: (i) completeness, which ensures that an honest prover can convince an honest verifier of a true statement with high probability; (ii) soundness, which guarantees that no dishonest prover can convince the verifier of a false statement except with negligible probability; and (iii) zero-knowledge, which requires that the verifier learns nothing beyond the validity of the statement. In the classical setting, the security of zero-knowledge protocols is inherently tied to computational assumptions. Most known constructions rely on the presumed hardness of certain mathematical problems, such as factorization [8] or discrete logarithms [9], and therefore provide only computational security. As a consequence, their security can be compromised by advances in algorithms or computational models. In particular, the
∗ [email protected] † [email protected]; srijani24˙[email protected] ‡ [email protected] § [email protected]
advent of quantum computation challenges the foundations of classical cryptographic security, as quantum algorithms [10, 11] can efficiently solve certain problems believed to be classically hard [12–15]. In 2006, Watrous [16] demonstrated that several canonical interactive proof systems, including the Goldreich-Micali-Wigderson protocols for graph isomorphism and graph 3-coloring, remain zero-knowledge against quantum verifiers. By constructing a quantum interactive proof system for a complete problem, he further established the equivalence of honest-verifier and general quantum statistical zero-knowledge, QSZKHV = QSZK. Nevertheless, these protocols lack device independence, precluding information-theoretic security against uncharacterized devices. Moreover, while zeroknowledge protocols are well understood in the bipartite regime, their extension to genuine multipartite network architectures remains largely uncharted, particularly under information-theoretic constraints. These limitations motivate the development of information-theoretically secure protocols whose security is independent of any assumptions about the verifier’s computational power, and naturally lead to the study of zero-knowledge protocols in the quantum regime. In this work, we develop a zero-knowledge framework based on the indistinguishability of quantum states [17–19], which fundamentally limits the information accessible to the verifier while retaining reliable verification of the claimed statement.We further construct explicit zeroknowledge protocols for multiparty quantum-network settings [20, 21]. Our constructions achieve informationtheoretic security, ensuring that no subset of collaborating parties can extract any knowledge beyond the validity of the proven statement, independent of their computational power. This establishes, to our knowledge, the first rigorous framework for information-theoretically secure zero-knowledge proofs in multiparty quantum scenarios, thereby substantially extending the scope of zeroknowledge cryptography into the domain of distributed quantum information processing. A fundamental question is whether the identity of a shared entangled resource can be certified without be-
2 ing revealed. We address this question by introducing zero-knowledge certification of shared entanglement, considering Bell states [22, 23] and GHZ states [24] as paradigmatic resources. We first construct a zeroknowledge protocol for Bell-state certification and identify a correlation loophole that compromises its verification. We then introduce a two-basis certification procedure that closes this loophole, but show that it remains vulnerable to higher-dimensional realizations reproducing the target correlations without implementing the intended qubit-level structure. This observation reveals that secure certification must enforce both the incompatibility of the measurement observables and the effective two-dimensionality of the underlying systems, motivating a device-independent formulation. The deviceindependent (DI) framework is central to quantumprotocol security, enabling certification of shared correlations solely from observed input-output statistics, without assumptions about the internal workings or trustworthiness of the measurement devices. We extend the construction to multipartite quantum networks, where observed nonlocal correlations enable the self-testing of the shared GHZ state and the corresponding measurement observables, yielding a device-independent zeroknowledge protocol. We establish its zero-knowledge property information-theoretically by constructing a simulator whose induced verifier view is identical or, more generally, indistinguishable from that of the real protocol, without access to the prover’s secret state. Finally, we show that these guarantees persist under noise, demonstrating the robustness of the protocols to imperfections in the shared quantum resources.
ifier, holding the other subsystem, that the prover possesses this knowledge without revealing the identity of the shared state? This question naturally leads to the problem of zero-knowledge certification of shared entanglement, wherein the prover demonstrates knowledge of the shared entangled state while keeping its identity concealed. To formalize this problem, we begin with a simple two-party task, described by the following protocol. A.
Bell-State Certification ZKP
Protocol 1. Single-Basis Bell-State Certification Protocol Setting: Let P (Prover) and V (Verifier) be two spatially separated parties who share N bipartite quantum systems arranged in an ordered sequence. Each shared pair is promised to be in one of the two Bell states. 1 ϕ− = √ (|00⟩ − |11⟩) 2 1 ψ + = √ (|01⟩ + |10⟩) 2 The prover P possesses complete knowledge of the identity of the Bell state at each position i ∈ [N ], whereas the verifier V knows only that each shared pair belongs to the set {|ϕ− ⟩ , |ψ + ⟩}. Here and throughout, we use the notation [N ] := {1, 2, . . . , N } for any natural number N . Goal: The objective of the protocol is to enable P to convince V that P knows the identity of every shared Bell state, while revealing no information about the identities themselves beyond the fact that they belong to the prescribed set. Protocol: A single round of the protocol is as follows:
II.
ENTANGLEMENT CERTIFICATION BASED ZKP
Entanglement constitutes a fundamental resource for a broad range of quantum information and quantum computation tasks. However, the mere presence of entanglement does not, by itself, guarantee the successful implementation of a given quantum protocol. Identifying and certifying the relevant structure of the shared entangled resource is equally crucial, since the operational utility of the resource depends not only on the presence of entanglement but also on the identity of the shared state. This is particularly evident in Bell tests, quantum teleportation, quantum key distribution, superdense coding, quantum random numbers generation, etc., where the performance and, in most of the cases, the security of the protocol depends critically on the specific Bell state shared by the parties. Notably, knowledge of the identity of a shared Bell state by one party is sufficient to transform it into any of the four Bell states through an appropriate local unitary operation. This observation motivates a fundamental question: Can a prover, holding one subsystem of a shared Bell pair and knowing its identity, convince a ver-
1. Challenge: The verifier V selects an index i ∈ [N ] uniformly at random and sends i to the prover P . 2. Prover’s response: Upon receiving i, the prover P measures his subsystem of the i-th Bell pair in the Pauli-Z basis, obtaining an outcome mP ∈ {+1, −1}. Hereafter, we adopt the encoding ±1 7→ {0, 1} for measurement outcomes. Using this outcome together with his knowledge of the identity of the shared Bell state, P computes ( mP , for |ϕ− ⟩ , aP = mP ⊕ 1, for |ψ + ⟩ , and sends aP to the verifier V . 3. Verification: The verifier V measures his subsystem of the same Bell pair in the Pauli-Z basis, obtaining an outcome mV ∈ {0, 1}. The verifier accepts if and only if aP = mV . ZKP Properties: We assess the protocol according to the three standard properties of a zero-knowledge proof: completeness, soundness, and zero-knowledge.
3 • Completeness: For an honest prover who possesses the correct identity of the shared Bell state, the perfect correlations of the Bell pair ensure that the prover’s response aP agrees with the verifier’s measurement outcome mV with certainty. Consequently, Pr[accept | P honest] = 1. • Soundness: Suppose that a dishonest prover does not know whether the shared state is |ϕ− ⟩ or |ψ + ⟩. From the prover’s perspective, the reduced density matrix ρP = TrV [ ϕ−
ϕ− =
I = TrV [ ψ + 2
ψ+ ]
are same and maximally mixed. Thus, without knowing the identity of the shared Bell state, the prover cannot predict the verifier’s outcome better than random guessing. The maximum success probability in a single round is therefore 1/2. For r independent repetitions, Pr(accept) ≤ 2−r . Hence, the soundness error decreases exponentially with the number of rounds. • Zero-Knowledge: The prover reveals only the predicted outcome aP and never discloses the underlying measurement outcome mP . Moreover, for both |ϕ− ⟩ and |ψ + ⟩, the verifier’s reduced state is maximally mixed, ρV = I2 , and is therefore independent of the Bell-state identity. Hence, the verifier’s local quantum state, together with the classical transcript received from the prover, carries no information about the identity of the shared Bell state beyond the prescribed prior knowledge. In particular, any strategy that enabled the verifier to distinguish |ϕ− ⟩ and |ψ + ⟩ using only local operations and the protocol transcript would violate the no-signaling principle. Thus, the protocol is zero knowledge with respect to the hidden Bellstate identity. A rigorous simulator construction establishing the indistinguishability of the real and simulated transcripts is provided in section III. Complexity: Each protocol round requires only constant-time local computation by both parties, consisting of a single projective measurement followed by constant-time classical post-processing. The classical communication cost per round is ⌈log2 N ⌉ + 1 bits, corresponding to the verifier’s challenge index i and the prover’s one-bit response. Thus, the communication complexity of a single round is O(log2 N ). Repeating the protocol for r rounds requires O(r) local measurements steps and O(r log N ) classical communication.
Loophole in the Verification: Although the protocol assumes that each shared pair is guaranteed to be in either |ϕ− ⟩ or |ψ + ⟩, the Z-basis verification test does not certify this promise. Indeed, consider the separable state ρP V =
1 (|00⟩ ⟨00| + |11⟩ ⟨11|) . 2
It exhibits the same perfect Z-basis correlations required for acceptance: whenever P obtains outcome mP , the verifier obtains the same outcome. Thus, the prover can choose aP = mP and pass the test certainty, despite possessing no information establishing the promised Bell-state structure. Hence, the verification test certifies only the observed Z-basis correlation and not the underlying state assumption, leaving a fundamental loophole in the soundness of the protocol. Closing the Correlation Loophole: For the separable state ρP V , the observed correlations are basis dependent. In particular, consider local measurements, for both P and V , in a basis other than the computational basis, |a0 ⟩ = cos θ |0⟩ + eiγ sin θ |1⟩ , |a1 ⟩ = sin θ |0⟩ − eiγ cos θ |1⟩ , In general, ρP V does not retain perfect correlations under such a basis change and is therefore distinguishable from the intended Bell-state correlations by a suitable choice of measurement setting. This observation motivates a minimal modification of the verification procedure. Rather than fixing a single measurement basis, the verifier randomly selects between two incompatible observables, e.g., Z and X. Although ρP V reproduces the required perfect Z-basis correlation through classical correlations, it cannot simultaneously reproduce the corresponding perfect correlation in the complementary X basis. Hence, testing both settings rules out the above separable-state strategy and strengthens the soundness of the protocol. More generally, a single-basis test certifies only the observed correlation, whereas complementary-basis tests constrain the underlying quantum state responsible for it. Protocol 2. Two-Basis Bell-State Certification We now modify Protocol 1 to eliminate the single-basis correlation loophole described above. Protocol setting: The parties share N bipartite systems, each promised to be in one of the two Bell states |ϕ− ⟩ or |ψ + ⟩. The prover P knows the identity of each shared state, whereas the verifier V knows only the promised ensemble. Goal. The prover convinces the verifier that he possesses the promised state information without revealing the identities of the shared Bell states. Protocol. In each round, the verifier and prover proceed as follows:
4 1. Challenge. The verifier samples i ∈ [N ] uniformly at random and independently chooses a measurement basis b ∈ Z, X uniformly at random. He sends (i, b) to P . 2. Prover’s response. The prover measures his subsystem of the i-th bipartite state in basis b, obtaining mP ∈ {0, 1}. Using his knowledge of the Bell-state identity, he computes mP for |ϕ− ⟩ and b = Z m for |ψ + ⟩ and b = X P aP = mP ⊕ 1 for |ϕ− ⟩ and b = X mP ⊕ 1 for |ψ + ⟩ and b = Z and sends aP to the verifier V . 3. Verification. The verifier measures his subsystem of the same state in the basis b, obtaining mV ∈ {0, 1}, and accepts if and only if aP = mV . ZKP Properties: For either choice b ∈ Z, X, the two possible states require opposite correlation predictions: |ϕ− ⟩ exhibits correlation in the Z basis and anticorrelation in the X basis, whereas |ψ + ⟩ exhibits the complementary pattern. Moreover, the reduced states on the prover’s subsystem are identical, ρP = I2 for both the state, so no local measurement performed by a dishonest prover, who does not know the state identity, can reveal the identity of the shared state. Consequently, in the absence of additional information, the optimal strategy is to guess the required correlation, yielding Pr(accept) ≤
1 . 2
Thus, the completeness, soundness, and zero-knowledge arguments remain unchanged from Protocol 1. Complexity: Each round involves one local projective measurement and constant-time classical postprocessing. The communication cost is ⌈log2 N ⌉ + 2 = O(log N ) bits per round, accounting for the index, basis choice, and one-bit response. Thus, over r rounds, the protocol requires O(r) local operations and O(r log N ) classical communication, with r shared Bell-state uses. This complexity is asymptotically identical to that of Protocol 1, differing only in constant communication overhead. The two-basis test also eliminates the single-basis loophole of Protocol 1. In particular, the separable state ρP V =
1 (|00⟩ ⟨00| + |11⟩ ⟨11|) 2
reproduces the perfect correlations required in the Z basis but cannot simultaneously reproduce the corresponding anticorrelations in the incompatible X basis. Hence, successful verification cannot be achieved by reproducing the statistics of a single measurement setting. The use of
complementary bases therefore rules out this separablestate strategy and closes the single-basis loophole. It is important to note that the Protocols 1 and 2 can be straightforwardly generalized to the complete Bellstate ensemble, 1 ϕ± = √ (|00⟩ ± |11⟩) , 2 1 ± ψ = √ (|01⟩ ± |10⟩) . 2 The resulting protocols retain the same essential structure and inherit analogous completeness, soundness, and zero-knowledge properties. LOCC state distinguishability & ZKP: State distinguishability and zero-knowledge proofs (ZKP) constitute fundamentally different tasks, although they may be operationally related in some cases. In state distinguishability, two parties share an unknown state drawn from a known ensemble and seek to identify it under restricted operations, such as local operations and classical communication (LOCC). By contrast, in a ZKP, the prover P seeks to convince the verifier V that P knows the identity of the shared state, without revealing any information about that identity. For example, the four Bell states{|ϕ± ⟩ , |ψ ± ⟩} cannot be perfectly distinguished by LOCC [18]. Nevertheless, when one of these states is shared between P and V , Protocol 2 enables P to demonstrate knowledge of its identity to V without revealing the identity itself. Loophole in Protocol 2: At first sight, the protocol appears loophole-free, provided that the measurement devices implement genuinely incompatible measurements and that each subsystem is guaranteed to be a qubit. However, in the absence of independent certification of these assumptions, the protocol admits a higherdimensional separable-state simulation. For example, ρP V =
1 (|Ψ1 ⟩⟨Ψ1 | + |Ψ2 ⟩⟨Ψ2 |) , 2
where P2 V1 V2 1 |Ψ1 ⟩ = |+⟩P Z |+⟩X |+⟩Z |−⟩X and P2 V1 V2 1 |Ψ2 ⟩ = |−⟩P Z |−⟩X |−⟩Z |+⟩X ,
is a classical mixture of orthogonal product states. Defining the local measurement observables for P (V ) as ZP (V ) = σzP1 (V1 ) ⊗ I P2 (V2 ) and XP (V ) = I P1 (V1 ) ⊗ σxP2 (V2 ) . one obtains ⟨ZP ZV ⟩ = 1 and ⟨XP XV ⟩ = −1, which exactly reproduce the correlations of the Bell state |ϕ− ⟩. Thus, by exploiting the indistinguishability of the measurement statistics produced by this separable, higherdimensional state from those of the target Bell state
5 |ϕ− ⟩, the prover can successfully deceive the verifier. This demonstrates that protocol security requires not only certification of the incompatibility of the measurement observables but also verification of the effective two-dimensionality of the underlying quantum systems. These considerations motivate the device-independent protocol introduced in the following section. Protocol 3. Device-independent ZKP: Bell-State Certification Protocol Setting: The prover P and verifier V share N maximally entangled two-qubit states, each of which is promised to be one of the four Bell states, {|ϕ± ⟩, |ψ ± ⟩}. The prover knows the identity of each shared state, whereas the verifier has no information about the individual state identities. Goal: The objective is for P to convince V that the selected shared state is a maximally entangled Bell state, while revealing no information about which Bell state it is. Protocol: 1. Challenge: The verifier randomly selects a subset of the shared states and communicates the corresponding choices to the prover. 2. State Transformation: For each selected state, the prover exploits his knowledge of its identity to apply the corresponding local unitary transformation I, if the state is |ψ − ⟩ , σ , if the state is |ϕ− ⟩ , X UP = + σ Y , if the state is |ϕ ⟩ , σZ , if the state is |ψ + ⟩ . Thus, irrespective of the initial Bell-state identity, the selected state is mapped to |ψ − ⟩, up to an irrelevant global phase. This transformation removes the dependence of the subsequent verification procedure on the original state identity. The prover does not reveal any information about the applied transformation UP to the verifier. 3. CHSH Test: For each selected state, the prover and verifier perform local measurements according to the settings P1 =
−Z − X √ , 2
P2 =
V1 = X,
V2 = Z
Z −X √ , 2
for P , and
for V . Both parties record their measurement settings and corresponding outcomes in each run.
4. Verification: For each run, P sends his measurement setting and outcome to V . The verifier then evaluates the CHSH correlator S = ⟨P1 V1 ⟩ + ⟨P1 V2 ⟩ + ⟨P2 V1 ⟩ − ⟨P2 V2 ⟩ from his local measurement data and the information received from P . The protocol is accepted if the observed value is consistent with the maximal quantum violation, namely, √ S ≥ 2 2 − ϵ, where ϵ > 0 is a sufficiently small tolerance accounting for finite-statistics and experimental imperfections. ZKP Properties: • Completeness: For an honest prover, who knows the identity of each selected state, the prescribed local unitary maps every selected state to |ψ − ⟩ up to an irrelevant global phase. The subsequent CHSH √ measurements therefore yield S ≃ 2 2 corresponding to the maximal quantum violation and provide a device-independent self test for |ψ − ⟩ [25]. Thus, in the ideal limit, an honest prover is accepted with unit probability, while finite-statistics and experimental imperfections result only in negligible deviations from perfect completeness. The robustness of the scheme against noise is discussed in section V. • Soundness: A prover who does not possess the promised Bell-state information is effectively described by the maximally mixed two-qubit separable state ρP V =
1 4
X β∈{ϕ± ,ψ ± }
|β⟩ ⟨β| =
IV IP 2 ⊗ 2 . 2 2
Being separable, this state cannot violate the CHSH inequality and hence satisfies S ≤ 2, the local-realistic bound [22, 23]. Consequently, a prover lacking the promised Bell-state information cannot reproduce the correlations required by the prescribed Bell test and, hence, cannot convince the verifier. We next consider a prover possessing only partial information about the shared Bell state. With probability p, the prover correctly identifies the Bell state, while with probability 1 − p,he has no information about its identity. The resulting strategy is thus a convex mixture of the informed and uninformed strategies. By convexity of the CHSH expression, the effective CHSH value satisfies Seff ≤ pSinf + (1 − p)Suninformed √ ≤ 2(1 + p( 2 − 1)),
6 where Sinf and Suninformed denote the maximal CHSH values attainable with complete and no Bell-state information, respectively. Hence, √ the deficit from the √ maximal quantum value 2 2 is √ 2 2 − Seff ≥ 2( 2 − 1)(1 − p) ≃ 0.0828(1 − p). Thus, unless p is sufficiently close to unity, the resulting CHSH violation remains appreciably below the Tsirelson bound, preventing the prover from convincing the verifier within a verification test requiring near-maximal CHSH violation. • Zero Knowledge: The prover’s state-dependent operation is local and is not revealed to the verifier. Moreover, for every Bell state, the marginal state of the verifier is, ρV = TrP (|β⟩⟨β|) =
I , 2
where, |β⟩ ∈ {|ϕ± ⟩, |ψ ± ⟩}. Since the prover’s local transformation leaves ρV invariant, the verifier’s reduced state and hence his local statistics are independent of the original Bell-state identity. The CHSH transcript therefore reveals no information about which Bell state was initially shared. Complexity: The complexity of the protocol is determined by the number of states r selected for CHSH verification and the number of measurements performed on each selected state. For each selected state, the prover performs one local unitary followed by constant-time classical post-processing. The prover communicates one measurement setting and one-bit outcome per CHSH run, resulting in O(1) classical communication per run. For r independent CHSH runs, the total local computational and measurement costs are O(r), while the prover-toverifier communication is O(r) bits. Specifying the r randomly selected states requires O(r log N ) bits. Hence, the total communication complexity is O(r log N ), while the verification complexity√is O(r). To obtain a CHSH violation satisfying S ≥ 2 2 − ϵ, the protocol requires r = O(1/ϵ2 ) samples, yielding O(1/ϵ2 ) local measurements and computational cost, O(1/ϵ2 ) prover-to-verifier communication, and O(log N/ϵ2 ) total classical communication. We now extend the entangled-state certification ZKP to a multipartite network. Specifically, a prover P1 seeks to convince n−1 verifiers, V2 , V3 , . . . , Vn of his knowledge of a randomly selected sequence of shared n-qubit GHZ 1 ⊗n ⊗n states, ϕ± |0⟩ ± |1⟩ . n = √ 2
V2 , V3 , . . . , Vn , who share N copies of an n-qubit state, with each copy promised to be one of the two GHZ states 1 ⊗n ⊗n ϕ± ± |1⟩ ). n = √ (|0⟩ 2 The prover has complete knowledge of the identity of each shared state, whereas the verifiers know only the promised ensemble. Goal: The objective is for P1 to convince the verifiers V2 , V3 , . . . , Vn that he knows the identity of each shared state, without revealing any information about it. Protocol: 1. Challenge: In each round, the verifiers randomly select Vk and r ∈ [N ], uniformly and independently. Each verifier Vj measures their subsystem of the r-th shared state in the X basis, obtaining mVj . All verifiers Vj ̸= Vk broadcast (j, mVj ), while Vk withhold his outcome mVk . 2. Prover Response: The prover measures their subsystem of the r-th shared state in the X basis, obtaining mP . Knowing the identity of the shared GHZ state and the announced outcomes aVj for j ̸= k, the prover predicts the withhold outcome of Vk as ( L mP j̸=k mVj , if the shared state is |ϕ+ n⟩, L L aVk = 1 mP j̸=k mVj , if the shared state is |ϕ− n⟩. The prover sends aVk to Vk . 3. Verification: The verifier Vk accepts the round iff mVk = aVk . The test is repeated for a sufficiently large number of rounds, with Vk selected uniformly at random in each round, ensuring that every verifier serves as the challenge verifier in a non-negligible fraction of the rounds. ZKP Properties: − • Completeness: For the states |ϕ+ n ⟩ and |ϕn ⟩, the parity of the outcomes of local X-basis measurements is, respectively, even and odd. Hence, if the prover knows the identity of the shared GHZ state and the X-basis outcomes of all verifiers Vj ̸= Vk , the outcome of the remaining verifier Vk is uniquely determined, allowing the prover to predict aVk as mVk = aVk with certainty. Thus,
Pr(accept) = 1. B.
GHZ certification ZKP
Protocol 4. ZKP: Multipartite State Certification Protocol Setting: Consider n spatially separated parties, comprising a prover P1 and n − 1 verifiers
• Soundness: If the prover lacks knowledge of the shared GHZ-state identity, the corresponding correlation pattern is inaccessible to him, and his probability of correctly predicting the outcome of Vk is
7 bounded by Pr(accept) ≤
1 . 2
Consequently, after r independent rounds, the soundness error is exponentially suppressed as Pr(accept) ≤ 2−r . • Zero-Knowledge: The reduced states of every proper subsystem S ⊊ [n] are identical for |ϕ+ n⟩ and |ϕ− n⟩ TrS ϕ+ ϕ+ = TrS ϕ− ϕ− . n n n n Consequently, even under arbitrary joint measurements on their systems, the verifiers obtain no information about the identity of the shared state, provided they have no access to the prover’s quantum system. This indistinguishability follows directly from the no-signaling principle, and hence the protocol is information-theoretically zero-knowledge. Complexity: Each round requires a single local projective measurement in the Pauli-X basis by each of the n parties, together with constant-time classical postprocessing by the prover. The classical communication per round comprises the broadcast of the selected index i ∈ [N ], requiring ⌈log2 N ⌉ bits, the (n − 2) one-bit measurement outcomes from the verifiers Vj ̸= Vk , and the prover’s one-bit prediction. Thus, the communication cost per round is O(log N + n). After r independent rounds, the protocol has computational complexity O(r), communication complexity O (r(log N + n)) , and consumes r shared GHZ states. Verification Loophole: Although the protocol assumes that each shared state is promised to be either |ϕ+ n ⟩ or |ϕ− ⟩, this promise is not certified by the verification test n itself. In particular, the separable state ρP1 V2 V3 ...Vn =
1 ⊗n ⊗n |+⟩ ⟨+| + |−⟩ ⟨−| 2
reproduces the perfect X-basis correlations required by the protocol, with all parties obtaining identical outcomes in every round. Consequently, a dishonest prover can exploit this separable state to pass the verification test without possessing the promised GHZ entanglement. This reveals a fundamental limitation of the prepare-andmeasure verification and motivates a self-testing formulation, in which the observed nonlocal correlations certify the underlying GHZ state and measurement observables, thereby establishing a device-independent protocol as described below.
Protocol 5. Device-independent ZKP: GHZ-State Certification Protocol Setting: Consider n (odd) spatially separated parties, a prover P1 and n − 1 verifiers V2 , V3 , . . . , Vn , sharing N states each of which is one of four GHZ states, 1 ⊗n ⊗n ϕ± ± |1⟩ ) n = √ (|0⟩ 2 1 ⊗(n−1) ⊗(n−1) ψn± = √ |0⟩ |1⟩ ± |1⟩ |0⟩ . 2 For each shared copy, the prover P1 holds the first qubit, while the remaining n − 1 qubits are distributed among the n − 1 verifiers. The prover knows the identity of each shared state, whereas the verifiers know only the underlying ensemble. Goal: The goal is to certify the prover’s knowledge of the state identities while revealing no information beyond the validity of the claim. Protocol: 1. Challenge: In each round, the verifiers uniformly select a state index µ ∈ [N ] and an operator index i ∈ {0, 1, . . . , n}, corresponding to Ô0 = X1 X2 · · · Xn , Ôi = X1 · · · Xi−1 Yi Yi+1 Xi+2 · · · Xn ,
∀i ∈ [n],
(1)
with n + 1 ≡ 1 (mod n). Here, Xj = σx and Yj = σy denote the local measurement observables of the j-th party. The verifiers then communicate the selected pair (µ, i) to the prover. 2. Prover Operation: Using his private knowledge of the state identity, the prover applies the corresponding local unitary I, if the state is |ϕ− n⟩, σ , if the state is |ϕ+ ⟩ , Z n UP = σX , if the state is |ψn− ⟩ , σY , if the state is |ψn+ ⟩ to his subsystem of the selected state, thereby mapiθχ ping it to |ϕ− : n ⟩ up to an irrelevant global phase e ± (UP ⊗ I ⊗n−1 ) |χ⟩ = eiθχ ϕ− ϕ± . n , |χ⟩ ∈ n , ψn The prover subsequently measures his subsystem of the selected state according to the operation label i communicated in the preceding step. 3. State certification: Following the prover’s measurement and announcement of his outcome, the verifiers perform the prescribed measurements on their respective systems and announce their outcomes. They then verify whether the resulting outcomes satisfy the eigenvalue relations − Ô0 ϕ− n = (−1) ϕn − Ôi ϕ− n = (+1) ϕn ,
∀i ∈ [n].
(2)
8 4. Verification: By Theorem 1, satisfaction of the eigenvalue relations in Eq. (2) self-tests the selected correlations to the state |ϕ− n ⟩ for odd n, thereby certifying that the prover possesses knowledge of the identity of shared ensemble. Protocol 5 can be implemented using only the two states |ϕ± n ⟩, with the corresponding completeness, soundness, and zero-knowledge analysis remaining unchanged. Conversely, Protocol 4 extends directly to the four-state ensemble employed in Protocol 5, provided that the first qubit is always held by the prover. In this case, the additional state sector can be interconverted locally by the prover through a σX bit flip on the first qubit, after which the original Protocol 4 procedure applies without modification. Since this local preprocessing is determined solely by the prover’s private state knowledge and is not revealed to the verifiers, the completeness, soundness, and zero-knowledge properties of Protocol 4 remain unchanged. ZKP Properties: • Completeness: If the prover knows the identity of every challenged state and applies the corresponding unitary I, σZ , σX , σY , each selected state is transformed into |ϕ− n ⟩. Therefore, for any challenge (µ, i) chosen by the verifiers, the eigenvalue relations (2) in Step 3. is satisfied with certainty and maximum Bell value Bn = n + 1 defined in Eq. (8) attained deterministically. Thus the protocol has perfect completeness: Pr[accept | P honest] = 1. • Soundness: To evaluate soundness, consider first a dishonest prover with no knowledge of the target state’s identity. The effective state reduces to the maximally mixed ensemble over the fourdimensional GHZ basis, ρ0 =
1X (|ϕµ ⟩⟨ϕµ | + |ψnµ ⟩⟨ψnµ |) . 4 µ∈± n n
(3)
Because Tr(ρ0 Ôi ) = 0 for all i ∈ {0, . . . , n}, any local-realistic (LR) strategy can satisfy at most n of the n + 1 eigenvalue constraints in Eq. (2). Over k independent verification rounds, the acceptance probability is bounded by k n 1 Paccept ≤ = exp −k ln 1 + , n+1 n suppressing the soundness error exponentially in k/n. When the prover possesses partial information-identifying the target state with prior probability p ∈ (0, 1) a desired local unitary transformation prepares the effective shared state − σ = p|ϕ− n ⟩⟨ϕn | + (1 − p)ρ0 ,
with ρ0 defined as in Eq. (3). In this case, the single-round acceptance probability satisfies (1) Psucc ≤ p + (1 − p)n/(n + 1) = 1 − (1 − p)/(n + 1). Consequently, across k independent rounds, the soundness error obeys 1−p . Paccept ≤ exp −k ln 1 + n+p • Zero knowledge: The prover’s correction operation UP ∈ {I, σZ , σX , σY } maps every one of the four possible states onto the same canonical state |ϕ− n ⟩ before any measurement is performed, so that the secret state identity is effectively erased from the system prior to the generation of any statistics visible to the verifiers. Since for all the parties |ϕ− n⟩ has maximally mixed marginal states, every individual measurement outcome is perfectly random. Even if the n − 1 verifiers are permitted to bring their individual qubits together and perform a joint (global) measurement, no additional information about the state identity is gained. Under such a collective measurement, the reduced state held by the verifiers is, for each of the four possible GHZ states {|ψn± ⟩ , |ϕ± n ⟩}, formally equivalent to one of the four maximally entangled twoqubit Bell states {|Φ± ⟩ , |Ψ± ⟩}, with the collective (n − 1)-qubit block playing the role of a single effective qubit. Since the four Bell states are locally indistinguishable to any party lacking access to the complementary subsystem held by the prover [18], the verifiers, even acting in concert, cannot determine which of the four states was shared. The protocol therefore remains zeroknowledge under collective verifier measurements, as no strategy, local or global, on the verifiers’ side can extract the state identity beyond the single bit certifying the validity of the prover’s claim. Moreover, because this certification relies only on the observed correlations reaching the algebraic maximum n + 1 via the self-testing/rigidity argument rather than on trusted device descriptions, the same no-extra-leakage guarantee extends even to verifiers with untrusted measurement apparatus, making the scheme device-independently zeroknowledge. Complexity. Let r denote the number of randomly sampled copies subjected to verification. In each round, the challenge (µ, i) requires ⌈log2 N ⌉ + ⌈log2 (n + 1)⌉ bits, while the prover performs one single-qubit Pauli operation and one local measurement, and each of the n − 1 verifiers performs one local X/Y measurement and announces one binary outcome. Hence, the total local measurement/unitary-operation cost is O(rn), and the classical communication complexity is O r log N + log n + n = O[r(n + log N )] bits. The verification procedure consists of checking the eigenvalue/parity relations for all r rounds. Hence the
9 overall computational complexity is O(rn). If r = O(ϵ−2 log(1/δ)) samples are required to estimate the relevant correlations to additive accuracy ϵ with failure probability at most δ, the computational complexity Ccomp and the communication complexity Ccomm becomes, 1 −2 Ccomp = O nϵ log , δ 1 −2 Ccomm = O (n + log N )ϵ log . δ For constant ϵ and δ, these reduce to O(nr) computational complexity and O[r(n + log N )] classical communication. III.
SIMULATION OF THE VERIFIER’S VIEW
The zero-knowledge property is established by showing that the verifier’s view can be simulated without access to the prover’s secret state. Specifically, we compare the superoperator describing the verifier’s view in the real protocol with a simulator superoperator constructed independently of the prover’s secret information. Equality, or more generally indistinguishability, of these superoperators ensures that the verifier gains no information about the witness beyond that implied by the validity of the statement. In what follows, we explicitly construct the simulators for the two device-independent protocols, (3) and (5). The zero-knowledge property of the remaining protocols follows directly from these constructions. We consider malicious quantum-capable verifiers whose auxiliary system is initially independent of the prover-verifier Bell state. For arbitrary quantum verifiers, we initially assume that the auxiliary quantum state is tensor-product with the prover–verifier entangled resource, corresponding to the idealized setting. In general, however, such a factorization need not hold in the presence of imperfections or coherent correlations. These coherent attacks and the corresponding robust treatment are addressed in Section V. A.
Simulator for Protocol 3
Transcript Super-operator: Let each of the shared state βsj be prepared in one of the bell states, |βsj ⟩ ∈ {|ϕ± ⟩, |ψ ± ⟩} and then the shared state be represented as, |ΦS ⟩P V =
N O
|βsj ⟩P j V j .
j=1
The identity of each of the states i.e., the string S = (s1 , . . . , sN ) is known only to the prover. In each protocol round, the verifier selects uniformly at random a subset Λ ⊆ [N ], |Λ| = k. The set of all kelement subsets is denoted by Λ̃k = {Λ ⊆ [N ] : |Λ| = k} , |Λ̃k | = N . k
For each Bell state, the prover applies a local unitary Usj such that (Usj ⊗ I) βsj = eiθsj ψ − . For a selectedNsubset Λ, defining the collective correction as, UΛ (S) = i∈Λ Usi , we have UΛ (S) ⊗ I⊗Λ |ΦS ⟩ V ! O O = eiΘS,Λ ψ− P i V i ⊗ βsj P j V j , i∈Λ
j ∈Λ /
P
where ΘS,Λ = i∈Λ θsi . Since the phase is global, it has no physical consequence. Therefore, the selected sub⊗k system is effectively |ψ − ⟩ , independent of the secret string S. Tracing out all prover systems for all the selected states as well as the unselected bell states gives us, N h i O IV j ρSV = TrP (UΛ (S) ⊗ I) |ΦS ⟩ ⟨ΦS | UΛ† (S) ⊗ I = . 2 j=1
For every selected state i ∈ Λ, the verifier chooses CHSH measurement settings xi , yi ∈ {1, 2}, independently and uniformly.The prover’s measurement settings are, Z +X P1 = − √ , 2
P2 =
Z −X √ , 2
while the verifier uses V1 = X, V2 = Z. Let ai , bi ∈ {0, 1} denote the measurement outcomes of the prover and verifier, respectively. The corresponding projectors are 1 1 Vy [I + (−1)ai Pxi ] , Πbi i = I + (−1)bi Vyi 2 2 For the selected subset Λ, define the collective projectors for the prover and verifier, respectively, as O Px O Vy MaΛ,x = Πai i , and NbΛ,y = Πbi i , Px
Πai i =
i∈Λ
i∈Λ
where x = (xi )i∈Λ and y = (yi )i∈Λ . Since the corrected ⊗k state of the selected subset is |ψn− ⟩ , the joint probability of obtaining the outcome strings a = (ai )i∈Λ and b = (bi )i∈Λ is given by h i ⊗k p(a, b | Λ, x, y, S) = Tr MaΛ,x ⊗ NbΛ,y ψ − ψ − i Y h Px Vy = Tr Πai i ⊗ Πbi i ψ − ψ − i∈Λ
= 4−k
Y 1 + (−1)ai +bi Exi yi . i∈Λ
Where for each selected pair i ∈ Λ, Exi yi ⟨Pxi ⊗ Vyi ⟩|ψ− ⟩ . Particularly for any two strings S, S ′ , p(a, b | Λ, x, y, S) = p(a, b | Λ, x, y, S ′ ).
=
(4)
10 Let V ∗ be an arbitrary quantum-capable verifier with an auxiliary register E, initially uncorrelated with the shared Bell states,i.e., ρSP V E = |ΦS ⟩ ⟨ΦS | ⊗ σE , For fixed (Λ, x, y), let WΛ,x,y denote an arbitrary CPTP map applied by V ∗ prior to receiving the prover’s response, and RΛ,x,y,a an arbitrary CPTP map applied thereafter. For fixed (Λ, x, y, a, b), let ρΛ,x,y,a,b,S be the VE corresponding normalized conditional state of the verifier’s quantum registers immediately before W. Since the conditional state and probability are independent of the secret S, and CPTP maps preserve equality, the resulting verifier state remains independent of S. h i RΛ,x,y,a ◦ WΛ,x,y ρΛ,x,y,a,b,S VE h i ′ = RΛ,x,y,a ◦ WΛ,x,y ρΛ,x,y,a,b,S . VE
∗
The simulator’s output state is ρVsim which is equal to ∗ ρVreal (S0 ) and by Eq. (6), ∗
∗
for every secret string S. Thus Protocol 3 is perfect ZK against arbitrary malicious quantum-capable verifiers with a classical communication interface. B.
Simulator for Protocol 5
Transcript Super-operator: Consider an ensemble of N shared n-qubit states, each independently chosen from the generalized GHZ set {|ψn± ⟩, |ϕ± n ⟩}the corresponding joint state shared among the prover and the verifiers is |Ψγ ⟩ =
(5)
∗
ρVsim = ρVreal (S0 ) = ρVreal (S)
N O
|γr ⟩,
|γr ⟩ ∈ |ψn± ⟩, |ϕ± n ⟩.
r=1
(6)
Upon receiving the challenge index r, the prover applies a local unitary correction Uγr conditioned on the hidden identity of the r-th system. By construction, each − selected state maps √ to the canonical GHZ target |ϕn ⟩ = ⊗n ⊗n (|0⟩ −|1⟩ )/ 2 up to an irrelevant global phase. Consequently, the verifier’s subsequent measurement statistics are strictly invariant under the initial state label. Encoding the challenge index r ∈ [N ] into a register CR , PN its coherent purification is, |chal⟩ = √1N r=1 |r⟩CR . For the generalized (n + 1)-qubit generalized GHZ operators {Ôi }ni=0 defined in Eq. (1), the measurement Pnsettings 1 state, stored in the register cI is, |set⟩ = √n+1 i=0 |i⟩cI . Conditioned on setting i, party j measures the local observable ( Yj , i ̸= 0 and j ∈ {i, i + 1}, (i) Aj = Xj , otherwise,
Simulator Super-operator: The simulator does not need to know the actual secret string S, instead it proceeds as follows:
with n + 1 ≡ 1 (mod n). The corresponding projection operator for party j yielding outcome aj ∈ {0, 1} is given (i) (i) by Πaj = 12 [I + (−1)aj Aj ]. For the r-th shared system, the corresponding measurement operator is
To obtain the classical transcript, we dephase the transcript registers T = (Λ, x, y, a, b), corresponding to measurement in their computational bases while retaining the outcomes. Crucially, the dephasing acts as DT ⊗ IV E , leaving the verifier’s quantum registers V E fully coherent. The resulting complete verifier view is therefore ∗
ρVreal (S) =
N k
1
X X 4k
p(a, b | Λ, x, y, S)
Λ∈Λ̃k a,b x,y
⊗ |Λ, x, y, a, b⟩ ⟨Λ, x, y, a, b| h i ⊗ RΛ,x,y,a ◦ WΛ,x,y ρΛ,x,y,a,b,S . VE Using Eqs. (4) and (5), we obtain ∗
∗
ρVreal (S) = ρVreal (S ′ ) for every pair of secret strings S and S ′ .
1. Choose a fixed reference string S0 = (0, . . . , 0) and prepare ρSP0V E = |βS0 ⟩⟨βS0 | ⊗ σE ,
− ⊗N
|βS0 ⟩ = |ψ ⟩
.
2. Interacting with the verifier it obtains the verifier’s challenge Λ ∈ Λ̃k , |Λ| = k, through the prescribed classical subset-selection interface. For every selected i ∈ Λ, it obtains the CHSH measurement setting pair (xi , yi ). 3. The simulator then internally executes the verifier V ∗ on this reference state. For every selected subset Λ, it performs the reference corrections and CHSH measurements and generates the corresponding prover responses.
⊗(N −r) Ma(r,i) = I ⊗(r−1) ⊗ Π(i) . aj ⊗ I j
The complete measurement outcome is denoted by a = (a1 , . . . , an ) ∈ {0, 1}n . The corresponding n-party measurement operator can be written as Ma(r,i) =
n O
Ma(r,i) . j
j=1
To define the classical transcript, let A = (A1 , . . . , An ) denote the classical outcome register. The classicalization of the challenge and outcome registers is represented by the dephasing map X DCR CI A (ρ) = |ria⟩ ⟨ria| ρ |ria⟩ ⟨ria| . r,i,a
11 The classical transcript state of the real protocol is therefore X 1 ρreal = p(a | i, r)|r i a⟩⟨r i a|. N (n + 1) r,i,a In an honest execution, each challenged state is transformed by the prover into the canonical state |ϕ− n ⟩. The conditional outcome distribution is , p(a | i, r) = p|ϕ− (a | i). In particular, the distribution is indepenn⟩ dent of both the challenged index r and the hidden state identity γr . and satisfies the GHZ parity constraints (2) i.e., ( Ln 2−(n−1) , j=1 aj = δi,0 p|ϕ− (a | i) = n⟩ 0, otherwise. for i ∈ {0, . . . , n}, where δi,0 is the Kronecker delta. If the verifier possesses an auxiliary private quantum register E, initially in state σE and independent of the shared GHZ states,then the real transcript state has the form ρreal =
N h X X 1 |r 0 a⟩⟨r 0 a| N (n + 1)2n−1 r=1 ⊕ a =1 j
+
n X
X
j
i
|r i a⟩⟨r i a| ⊗ σE .
i=1 ⊕j aj =0
Simulator Super-operator: The simulator prepares the corresponding reference state ⊗N |Ψγ 0 ⟩ = |ϕ− . n⟩
It samples the challenged index r and the measurement setting i uniformly, and coherently from the verifier. Since the reference state is already the canonical state, the simulator does not need the hidden identity of the challenged state. Interacting with the verifiers, it performs the prescribed prover-side measurement on the challenged copy and obtains the corresponding outcome. Together with the outcomes generated by the verifiers, this reproduces the ideal distribution, psim (a | r, i) = p|ϕ− (a | i) = preal (a | r, i). n⟩ Since the verifiers’ arbitrary private auxiliary register E, initially described by an arbitrary density operator σE , is independent of the hidden-state identity, the simulator initializes its auxiliary register in the same state σE . Finally, the simulator applies the same classical dephasing operation DCR CS A to the simulated transcript. The resulting simulator state is therefore, X 1 ρsim = psim (a | r, i)|r i a⟩⟨r i a| ⊗ σE , N (n + 1) r,i,a which satisfies ρreal = ρsim . Because ρsim is generated without reference to the true state identity while matching ρreal exactly, the classical transcript achieves perfect zero-knowledge.
IV.
SELF-TESTING OF GHZ CORRELATIONS
Recently, Das et al. [26] introduced a self-testing scheme for n-qubit GHZ correlations based on the Bell operator Bn = −Ô0 +
n X
Ôi
(7)
i=1
constructed from the eigenvalue relations in Eq. (2). For odd n, local-realistic (LR) constraint provides the bound |⟨Bn ⟩LR | ≤ n − 1, whereas quantum correlations allow to attain the algebraic maximum, βQ = |⟨Bn ⟩Q | = n + 1.
(8)
Moreover, saturation at βQ = ±(n+1) self-tests the GHZ states |ϕ∓ n ⟩, respectively, up to local unitaries. Here, we extend this approach to self-test not only |ϕ± n⟩ n but the complete GHZ basis |ϕn (r)± ⟩r=1 , where 1 r n−r r n−r ϕn (r)± = √ |0⟩ |1⟩ ± |1⟩ |0⟩ . 2 Our approach differs fundamentally from conventional inequality-based self-testing [26]: we require neither a Bell inequality nor a maximal-violation condition. Instead, we establish a multipartite logical no-go argument based on the set of eigenvalue relations in Eq. (2). In contrast to self-testing based on a single maximal Bellviolation constraint, our construction employs multiple simultaneous constraints to uniquely characterize the target GHZ correlations. This structure also facilitates a direct security analysis of our zero-knowledge proof (ZKP) schemes against most general coherent attacks. We state our main results about self-testing in the following two theorems. Theorem 1 (GHZ correlation self-testing). For odd n, the eigenvalue relations in Eq. (2) i.e., ⟨Ô0 ⟩ρ = −1 ⟨Ôi ⟩ρ = +1, ∀i ∈ [n]
(9)
− self-test the corresponding correlations ρ = |ϕ− n ⟩ ⟨ϕn |, √1 where |ϕ− |0⟩ n⟩ = 2
⊗n
− |1⟩
⊗n
.
Proof. The proof of the theorem follows immediately from Lemmas 1-2. Lemma 1. For odd n, the eigenvalue relations in Eq. (2) are incompatible with any local-realistic (LR) correlations and uniquely identify |ϕ− n ⟩, up to an irrelevant global phase.
12 Proof. Consider the relations in Eq. (9) collectively, with the observables defined in Eq. (1). For each site i ∈ [n], Yi occurs twice, whereas Xi occurs n − 1 times, which is even for odd n. Assigning deterministic LR values ±1 to all local observables and taking the product of all relations in Eq. (9), each assigned value on the left-hand side occurs an even number of times, yielding +1. By contrast, the product of the corresponding eigenvalues on the right-hand side is −1, leading to a contradiction. Since any probabilistic LR strategy is a convex combination of deterministic strategies, it cannot evade this contradiction. Hence, no LR correlations can satisfy all the relations in Eq. (9) simultaneously. To determine whether the relations in Eq. (9) can be satisfied by quantum correlations, and in particular by a pure n-qubit state, consider the most general n-qubit pure state, X X |ψ⟩ = αb1 ...bn |b1 . . . bn ⟩, |αb1 ...bn |2 = 1. b1 ,...,bn ∈{0,1}
X λ := P λ XP λ ,
Y λ := P λ Y P λ .
These operators fully characterize the action of the corresponding untrusted measurements within the sector Hλ . Under this decomposition, the state ρ and the observables {Ôi }ni=0 in Eq. (1) acquire the block-diagonal forms M
ρ=
pν ρν
and Ôi =
M
ν
Ôiν ,
ν
where ν = (ν1 , . . . , νn ). The corresponding block operators are Ô0ν = X ν1 · · · X νn , and, for i ∈ [n], Ôiν = X ν1 · · · X νi−1 Y νi Y νi+1 X νi+2 · · · X νn .
Using Ô0 |b1 . . . bn ⟩ = |b̄1 . . . b̄n ⟩, Ôi |b1 . . . bn ⟩ = (−1)
1⊕bi ⊕bi+1
|b̄1 . . . b̄n ⟩,
the first eigenvalue relation of Eq. (2) implies αb1 ,...,bn = −αb̄1 ,...,b̄n . Substituting this relation into the remaining eigenvalue equations yields αb1 ,...,bn = (−1)bi ⊕bi+1 αb1 ,...,bn for all i ∈ [n]. Hence, αb1 ...bn can be nonzero only when bi = bi+1 for every i, restricting ⊗n ⊗n the support of |ψ⟩ to |0⟩ and |1⟩ . Together with the first eigenvalue relation and normalization, this uniquely − − gives |ψ⟩ = e−iγ |ϕ− n ⟩ and therefore ρ = |ϕn ⟩ ⟨ϕn |.
It follows that X ⟨Ôi ⟩ρ = pν ⟨Ôiν ⟩ρν , ν
for i = 0, . . . , n, where ν = (ν1 , . . . , νn ). Because each Ôiν has eigenvalues in {±1}, the extremal conditions ⟨Ô0 ⟩ρ = −1,
⟨Ôi ⟩ρ = +1,
Lemma 2. Consider two dichotomic observables A and B acting on a Hilbert space H . Then H admits an orthogonal decomposition M H = H λ, dim(Hλ ) ≤ 2, λ∈Λ
such that each sector H λ is simultaneously invariant under A and B. Accordingly, the two observables can be expressed as M M A= Aλ , B= Bλ, λ∈Λ
For each invariant sector Hλ , let P λ denote the associated projector. The physical observables X and Y then induce the sector-restricted operators
⟨Ôiν ⟩ρν = +1,
i ∈ [n].
Lemma 1 then fixes each nonzero block to the unique − ν common eigenstate, ρν = |ϕ− n ⟩ ⟨ϕn | and hence ρ = |Ψ⟩ ⟨Ψ| ,
|Ψ⟩ =
M√
pν , ϕ− n
ν
.
ν
To extract the ideal state, let each party append an ′ ancillary qubit in |0⟩j and implement the local isometry ν
′
ν
′
Vj : |τ ⟩ j |0⟩j 7−→ |0⟩ j |τ ⟩j , The global isometry V = |Ψ⟩ ⊗ |0⟩
λ∈Λ
where Aλ := A|H λ and B λ := B|H λ denote their respective restrictions to the invariant sector H λ .
i ∈ [n],
can be attained only if every occupied block saturates the same bounds, namely ⟨Ô0ν ⟩ρν = −1,
The device-independent analysis relies on the following variant of Jordan’s lemma [27].
⟨Ôiν ⟩ρν ≡ Tr ρµ Ôiν ,
′
′⊗n
τ ∈ {0, 1}.
Nn
j=1 Vj consequently maps ′
7−→ |ξ⟩ ⊗ ϕ− , n
where |ϕ− n ⟩ is the ideal n-qubit GHZ state on the ancillary systems and |ξ⟩ contains the residual sector degrees of freedom. Thus, the target GHZ state is locally extractable, establishing the desired self-testing statement. The preceding analysis readily extends Theorem 1 to the complete set of n-qubit GHZ-basis states.
13 Theorem 2. For an odd integer n, the GreenbergerHorne-Zeilinger (GHZ)-type paradox defined by the eigenvalue relations Ô0 |ψn (Λ)± ⟩ = ±|ψn (Λ)± ⟩, ± ∓|ψn (Λ) ⟩, ± Ôi |ψn (Λ) ⟩ = ±|ψ (Λ)± ⟩, n
if {i, i + 1} ⊆ Λ or {i, i + 1} ⊆ Λ̄, otherwise,
self-tests the generalized n-qubit GHZ state 1 |ψn (Λ)± ⟩ = √ |0⟩Λ |1⟩Λ̄ ± |1⟩Λ |0⟩Λ̄ , 2 where Λ ⊆ [n] and Λ̄ = [n] \ Λ denotes its complement.
V.
ROBUSTNESS UNDER NOISE
The objective of the zero-knowledge proof (ZKP) is to enable a prover to convince the verifiers that they possess the identity of a shared quantum state without revealing the state itself. We assume that the verifiers know only the candidate ensemble and have no prior knowledge of the actual state; verification against a known state is beyond the scope of this work. The shared states are assumed to be prepared either by the prover or by an independent dealer. Soundness therefore reduces to bounding the probability that a dishonest prover, possessing incomplete or no information about the state, can falsely certify complete knowledge. The key observation is that limited knowledge of the state constrains the prover’s ability to reproduce the correlations required to win the multipartite GHZ game. Equivalently, the prover’s guessing probability for the verifiers’ joint outcomes is constrained by the observed GHZ-winning deficiency, or, equivalently, by the corresponding Bell-inequality violation. Thus, a bound on the maximal GHZ-game winning probability directly yields a bound on the verifiers’ joint-outcome guessing probability, and vice versa. We first establish the soundness bound for a single round under an i.i.d. assumption and then extend it to arbitrary coherent attacks using the entropy accumulation theorem (EAT) [28, 29]. Since the adversarial prover constitutes the primary security threat, we conservatively allow any external eavesdropper to possess arbitrary side information and to collaborate fully with the prover.
A.
GHZ paradox under noise
Any n-qubit density operator ρ (ρ ≥ 0, Tr[ρ] = 1) can be expanded in the Pauli basis as ρ=
3 X
1 Ti ...i σi ⊗ · · · ⊗ σin , 2n i ,...,i =0 1 n 1 1
n
(10)
where σ0 = I2 , {σ1 , σ2 , σ3 } ≡ {σx , σy , σz }, and the real correlation tensor elements are Ti1 ...in = Tr[ρ (σi1 ⊗ · · · ⊗ σin )], with normalization T0...0 = 1. Under a local Pauli conjugation on the first qubit, ρm = (σm ⊗ I⊗(n−1) )ρ(σm ⊗ I⊗(n−1) ) with m ∈ {1, 2, 3}, the state retains the form of Eq. (10) with transformed coefficients: Ti′1 ...in = (−1)1−δ0i1 −δmi1 +δm0 Ti1 ...in . This sign rule directly reflects the algebraic relation σm σi1 σm = (−1)1−δ0i1 −δmi1 +δm0 σi1 : components with i1 = 0 (identity) or i1 = m commute and remain invariant, while the two orthogonal non-identity Pauli components anticommute and pick up a factor of −1. After receiving the challenge index m from the verifiers, the prover applies σm before revealing any measurement outcomes. At this stage, the verifiers have no information about m. On the other hand, a prover with negligible knowledge of the identity of the shared state can satisfy the GHZ paradox with only negligible probability. We therefore restrict our analysis to the state ρ. To characterize the state ρ satisfying simultaneously the GHZ eigenvalue relations (9) within an ϵ ≥ 0-tolerance, we consider the correlation thresholds: ⟨Ô0 ⟩ρ ≤ −1 + ϵ, ⟨Ôs ⟩ρ ≥ 1 − ϵ
(∀s ∈ [n]),
(11)
which in terms of the correlation tensor elements translates to −T11...1 ≥ 1 − ϵ, T1...1221...1 ≥ 1 − ϵ, T211...12 ≥ 1 − ϵ. Defining the stabilizer generators S0 = −Ô0 and Ss = Ôs for s ∈ [n], we observe that Sj2 = I⊗n and [Sj , Sk ] = 0. The set of n independent generators {Sj }n−1 j=0 forms an Abelian stabilizer group S of order |S| = 2n , whose +1 common eigenspace is one-dimensional and uniquely specifies the pure state |ϕ− n ⟩. The corresponding rankone projector is obtained via the group average: 1 X − |ϕ− S n ⟩⟨ϕn | = n 2 S∈S n−1 X X Y 1 = n I⊗n + Sj + Sk , 2 j=0 |Λ|≥2 k∈Λ
where the third term sums all higher-order products over subsets Λ ⊆ {0, . . . , n − 1}, completing the summation over all group elements. By robust self-testing, any valid density matrix meeting the threshold conditions in Eq. (11) can be written in generic perturbed form as − ρ = (1 − η)|ϕ− n ⟩⟨ϕn | + ηρ⊥ ,
(12)
where ρ⊥ is a valid density matrix supported on the or⊥ thogonal complement supp(ρ⊥ ) ⊆ span{|Φ− n ⟩} , and the
14 noise parameter satisfies η ≤ ϵ/2. Consequently, ρ obeys the corresponding Bell inequality Tr[ρBn ] ≥ (n+1)(1−ϵ), or equivalently, −T1...1 + T221...1 + T1221...1 + T1...122 + T211...12 ≥ (n + 1)ϵ, subject to trace normalization T0...0 = 1 and global positivity ρ ≥ 0. Thus we have the following lemma. Lemma 3. If a state ρ satisfies the GHZ paradox with a noise tolerance ϵ ≥ 0 i.e., simultaneously satisfies Eq. (11), then it necessarily admits the decomposition given in Eq. (12). In particular, the isotropic Werner-like state satisfying these bounds takes the form η ⊗n − , ρW = (1 − η)|ϕ− n ⟩⟨ϕn | + n I 2 where the non-identity correlation tensor elements associated with the stabilizer group evaluate to Ti1 ...in = − (1−η) ⟨ϕ− n |σi1 . . . σin |ϕn ⟩, while all remaining coefficients vanish identically. B.
ZKP security against coherent attack
For the GHZ-paradox-based ZKP Protocol 5, the entropy accumulation theorem (EAT) [28] provides a natural framework for lifting single-round entropy bounds to sequential, multi-round executions against coherent quantum adversaries. Because the EAT itself does not prescribe the single-round entropy rate as a function of Bell violation, this relation must be certified independently via device-independent semi-definite programming (SDP) hierarchies. To establish composable zeroknowledge security against arbitrary, coherent quantum attacks, we formulate the N -round execution of Protocol 5 using the Entropy Accumulation Theorem 3. A dishonest prover may correlate all N rounds across arbitrary quantum side information E. In round i ∈ [N ], let Xi ∈ {0, . . . , n} be the verifier’s uniform GHZ challenge and Ci ∈ {0, 1} denote the binary pass/fail indicator for the parity constraints ⟨Ô0 ⟩ = −1 and ⟨Ôj ⟩ = 1 (∀j ∈ [n]). The protocol accepts provided the total acPN cepted rounds F = i=1 Ci satisfy F/N ≥ 1 − γ, bounding the observed winning frequency by qobs ≥ 1 − γ. Following the entropy accumulation framework of [28], we first define the EAT channel associated with the sequential implementation of our protocol. EAT channels: The sequential verification is modeled by completely positive trace-preserving (CPTP) maps Mi : Ri−1 → Ri Oi Si Ci , for i ∈ [N ], where Ri is the unmeasured prover state forwarded to round i + 1, Oi denotes the round-i output relevant to the verification test, Si is the corresponding quantum side-information register, and Ci is
a finite-dimensional classical register containing the outcome of the GHZ verification test. In the present protocol Ci ∈ {0, 1}, where Ci = 1 denotes acceptance and Ci = 0 denotes rejection of the GHZ constraint. For every i ∈ [N ], the maps Mi satisfy the following properties. 1. The registers Ci are classical, while Ri , Oi , and Si are quantum registers. We denote the dimension of Oi by dOi . 2. Let R′ ≃ Ri−1 be an auxiliary register isomorphic to the incoming memory. For every state τRi−1 R′ , define σRi Oi Si Ci R′ = (Mi ⊗ IR′ ) τRi−1 R′ . The register Ci is classical and its value can be obtained by a measurement on Oi Si without disturbing the corresponding post-measurement state. 3. Let E denote an arbitrary quantum environment held by the prover or adversary, including any purification of the initial shared state and any quantum side information retained throughout the protocol. For any initial joint adversary-prover state ρR0 E , the global state after N rounds, ρO1∼N S1∼N C1∼N E = TrRN [(MN ◦ · · · ◦ M1 ) ⊗ IE ] ρR0 E , where notation X1∼N denotes X1∼N = X1 , . . . , XN , satisfies the Markov chain condition O1∼(i−1) ↔ S1∼(i−1) E ↔ Si for each i ∈ [N ], equivalent to the vanishing conditional mutual information: I(O1∼(i−1) : Si | S1∼(i−1) E)ρ = 0.
(13)
The last condition is the structural requirement that permits entropy accumulation in the presence of arbitrary inter-round quantum correlations. In particular, the registers Ri may retain quantum memory between successive rounds, so that the above formulation does not impose an independent-and-identically-distributed assumption on the GHZ tests. Condition (13) holds naturally in the ZKP setting because round-by-round side information leakage Si depends only on the current query inputs and provers’ internal state, shielded from historical challenge-answer transcripts given prior side information and initial entanglement E. To quantify single-round entropic rates, let p ∈ P(C) be a distribution over the test alphabet C. We define the restricted state space n Σi (p) = σOi Si Ci Ri R′ = (Mi ⊗ IR′ ) τRi−1 R′ o τRi−1 R′ ∈ D(Ri−1 ⊗ R′ ), σCi = p , P where σCi = c∈C ⟨c|σCi |c⟩|c⟩⟨c|.
15 Definition 1. Min-tradeoff function - A continuous function fmin : P(C) → R is a min-tradeoff function for Mi if fmin (p) ≤
inf σ∈Σi (p)
H(Oi | Si R′ )σ ,
with fmin (p) = +∞ when Σi (p) = ∅, where H(A | B)σ is the conditional von Neumann entropy. In the context of the n-qubit GHZ game, the winning probability directly constrains the distance of τRi−1 R′ from ideal GHZ states via self-testing bounds. The convex function fmin (p) thereby establishes an operational lower bound on the generation rate of smooth minε entropy Hmin (O1∼N | S1∼N E) against malicious verifiers or provers, reducing the full security proof to characterizing single-round nonlocal violations. Theorem 3 (EAT for n-Qubit GHZ ZKP). Let {Mi }N i=1 be EAT channels with output dimension dim(Oi ) = dOi for each round i ∈ [N ], and let ε ∈ (0, 1) be the smoothing parameter. If fmin : P(C) → R is a convex min-tradeoff function for {Mi } satisfying fmin (freq(c1∼N )) ≥ t for all c1∼N ∈ Ω with Pr[c1∼N ]ρ|Ω > 0, then the smooth conditional min-entropy of the cumulative transcript O1∼N is lower bounded by √ ε (14) Hmin (O1∼N | S1∼N E)ρ|Ω > N t − v N , where the second-order finite-size penalty parameter v is p v = 2 (log(1 + 2dOi ) + |∇fmin |∞) 1 − 2 log(εs · pΩ ). Since, verification in Protocol 5 is governed by the eigenvalue constraints of Eq. (9) and the underlying Bell operator [Eq. (7)] is linear in the observed correlators, the proof follows directly from an extension of the entropy accumulation theorem of [28]. In the n-qubit GHZ-ZKP protocol, Eq. (14) provides the finite-round rate for extractor privacy and soundness: even if cheating provers share arbitrary entangled states across rounds, passing the GHZ nonlocal tests (pΩ ≈ 1) certifies √ that the transcript O1∼N contains at least N t − O( N ) bits of smooth min-entropy independent of the adversary’s quantum memory S1∼N E. For the zero-knowledge protocol, soundness concerns the probability that a dishonest prover is accepted without possessing the claimed GHZ-state identity. Denoting this event by Forge and the protocol acceptance event by Acc, the corresponding probability is bounded by Pr [Forge ∧ Acc] ≤ 2
ε −Hmin (O1∼N |S1∼N E)ρ|Ω
√
Extension to linear Bell operators: P This analysis n extends to the Bell operator Bn = −Ô0 + i=1 Ôi , with quantum ceiling βQ = n + 1 and local-realistic bound βLR = n − 1. We parameterize the violation by the normalized Bell score ν(β) = [β−(n−1)]/2 ∈ [0, 1]. In an N PN round sequence with observed mean βb = N −1 j=1 βj , the protocol accepts if βb ≥ β ∗ ≡ βobs − δ for confidence margin δ > 0. The single-round min-entropy against adversary E is bounded by the guessing probability: r(O | E; β) ≡ − log2 pguess (O | E; β), where pguess (O | E; β) = supρ,M {pguess (O | E) : Tr(ρB̂n ) ≥ β} is computed via the Navascués–Pironio– Acı́n (NPA) hierarchy [30]. Linearizing via an affine mintradeoff function tangent at β ∗ , f (β) = r(β ∗ )+r′ (β ∗ )(β− β ∗ ), the accumulated smooth min-entropy satisfies √ ε Hmin (O1∼N | ET1∼N )ρ|Ω ≥ N f (β ∗ ) − O( N ), yielding the guessing probability bound ∗
√
pεguess (O1∼N | ET1∼N , Ω) ≤ 2−N f (β )+O( N ) , and the asymptotic rate lim −
N →∞
1 log2 pεguess = fGHZ (βobs ) N
as δ → 0. Zero-knowledge: Statistical zero-knowledge requires an efficient simulator reproducing the verifier’s view within trace distance 1 real ρ − ρsim V 2 V
1 ≤ εZK .
(15)
dishonest ≤ ε, this Combined with soundness error Paccept guarantees composable finite-size security against coherent attacks. Eq. (15) directly underpins our primary theoretical guarantee, formalised in the following theorem.
Theorem 4 (Zero-knowledge criterion). If the GHZ Protocol 5 achieves a maximal Bell violation within tolerance εZK ≥ 0, namely ⟨B⟩ρ ≥ (1 + n) − εZK for the Bell operP ator B = −Ô0 + i∈[n] Ôi [Eq. (7)] with odd n, then the verifiers’ reduced view satisfies 1 real εZK ρ − ρsim ≤ , V 1 2 V n
.
Consequently, the probability that a dishonest prover passes the protocol while lacking the required state identity is bounded by ε(N ) ≤ 2−N t+v N .
This bound holds against arbitrary coherent attacks and therefore does not rely on an i.i.d. assumption.
real(sim)
where ρV
real(sim)
= TrP [ρP V
] with V = V2 V3 . . . Vn .
Proof. The trace distance admits the operational variational form 1 real sim sim real sim D(ρreal V , ρV ) = ∥ρV −ρV ∥1 = max Tr Π(ρV −ρV ) , 0≤Π≤I 2
16 which quantifies the optimal single-shot distinguishing probability. Let Π⋆V denote an optimal measurement operator satisfying 0 ≤ Π⋆V ≤ IV , such that ⋆ real sim D(ρreal − ρsim V , ρV ) = TrV ΠV (ρV V ) . Exploiting the duality between the partial trace and the identity channel, TrV [ΠV TrP (ρP V )] = TrP V [(IP ⊗ ΠV )ρP V ], we express this local distinguishability directly on the global space: sim ⋆ real sim D(ρreal V , ρV ) = TrP V (IP ⊗ ΠV )(ρP V , ρP V ) . Since 0 ≤ Π⋆V ≤ IV , the extended observable satisfies 0 ≤ IP ⊗ Π⋆V ≤ IP V , thus constituting a valid positive operator-valued measure (POVM) element on HP ⊗ HV . Since the global trace distance optimizes over all POVM elements on the composite Hilbert space, the restricted local strategy cannot outperform the global optimum: sim sim D ρreal = TrP V (IP ⊗ Π⋆V ) ρreal V , ρV P V − ρP V sim ≤ max TrP V ΠP V ρreal P V − ρP V 0≤ΠP V ≤IP V sim = D ρreal P V , ρP V ,
− − − and ⟨ϕ− n |ρ⊥ |ϕn ⟩ = 0, ensuring that supp(|ϕn ⟩⟨ϕn |) ⊥ − − supp(ρ⊥ ). The difference operator ∆ = |ϕn ⟩⟨ϕn | − ρ⊥ therefore decouples into mutually orthogonal subspaces. Specifically, ∆ possesses a single positive eigenvalue λ = 1 supported on span(|ϕ− n ⟩), while on the orthogonal com⊥ plement span(|ϕ− ⟩) it acts as −ρ⊥ with nonpositive n eigenvalues λk =P−ek ≤ 0, where {ek } denotes the spectrum of ρ⊥ ( k ek = 1). Summing the absolute values of thePeigenvalues directly yields the trace norm ∥∆∥1 = 1 + k ek = 2. Hence, the trace distance simplifies to
1 − |ϕ− n ⟩⟨ϕn | − ρ 1 = η. 2
(16)
Furthermore, evaluating the Bell expectation value for this state gives ⟨B⟩ρ = Tr(Bρ) ≤ (1 + n) − 2nη. Combining this upper bound with the hypothesis ⟨B⟩ρ ≥ ε (1+n)−ε, we obtain η ≤ 2n . Substituting this constraint into Eq. (16) completes the proof.
Theorem 5 (Soundness criterion). If the GHZ Protocol 5 achieves a maximal Bell violation with deficiency establishing the monotonicity of trace distance under the ε ≥ 0, namely ⟨B⟩ρ ≥ (1 + n) − ε for the Bell operaP partial trace. Applying the triangle inequality with retor B = −Ô0 + i∈[n] Ôi [Eq. (7)] with odd n, then the ⟩ and by using Lemma 4 we spect to the target state |ϕ− n soundness of the protocol in view of dishonest prover is have bounded by real sim real sim D ρV , ρV ≤ D ρP V , ρP V 2−ε dishonest real − − − − sim P ≤ ε = exp −N ln 1 + , s accept ≤ D ρP V , ϕn ϕn + D ϕn ϕn , ρP V n−1 εZK εZK εZK + = . ≤ for N consecutive rounds. 2n 2n n
Lemma 4. If a state ρ achieves maximal Bell violation with deficiency ε ≥ 0, such that ⟨B⟩ρ ≥ (1 + n) − ε for the Bell operator B defined in Eq. (7) with odd n, the trace distance to the ideal state satisfies ε 1 − ∥ϕ− . n ⟩⟨ϕn | − ρ 1 ≤ 2 2n Proof. By Lemma 3, any such state admits the decomposition − ρ = (1 − η)|ϕ− n ⟩⟨ϕn | + ηρ⊥ ,
η ≥ 0.
The trace distance gives us D ϕ− n
1 − ϕ− |ϕ− n ,ρ = n ⟩⟨ϕn | − ρ 1 2 η − |ϕ− = n ⟩⟨ϕn | − ρ⊥ 1 2 η = ∥∆∥1 (say), 2
− where ∆ = |ϕ− By definition, the orn ⟩⟨ϕn | − ρ⊥ . thogonal component satisfies ρ⊥ ≥ 0, Tr(ρ⊥ ) = 1,
Proof. Under the local-realistic (LR) constraint, the Bell expectation value is bounded by βLR ≤ n−1, which limits the single-round acceptance probability for an arbitrary (1),LR ≤ (n − 1)/(n + 1 − ε). For N dishonest prover to pacc rounds, the cumulative acceptance probability is strictly bounded by N n−1 n+1−ε 2−ε = exp −N ln 1 + . n−1 (17) Equation (17) establishes the soundness criterion of the protocol, demonstrating that the cheating probability is suppressed exponentially with the number of rounds N , with an asymptotic decay rate set by the quantumclassical margin (2 − ε)/(n − 1). dishonest Paccept ≤ εs (N, n) ≡
Completeness: For states orthogonal to the target state |ϕ− n ⟩, the GHZ paradox (9) guarantees that at least one of the n + 1 stabilizer constraints is violated, giving p(1),⊥ ≤ acc
n . n+1
17 guessing probability: √ 3p ϵ 1 + + ϵ(1 − ϵ), 2 pguess (V2 V3 | P1 ) ≤ 4 2 1 + ϵ, 2
VI.
FIG. 1: Guessing probability Pg (V2 V3 |P1 ) as a function of ϵ, where ϵ quantifies the deviation from the GHZ paradox constraints [Eq.(11)].
− For a state ρ = (1 − η)|ϕ− n ⟩⟨ϕn | + ηρ⊥ , the single-round acceptance probability for honest prover satisfies
1 − η ≤ p(honnest) (ρ) ≤ 1 − acc
η , n+1
showing that any non-target weight η > 0 induces a finite acceptance. Adversarial guessing bounds: Security against dishonest provers demands an upper bound on the adversary’s probability of correctly guessing the verifiers’ outcomes, subject to either the GHZ paradox constraints [Eq. (11)] or the corresponding Bell inequality violation. In the tripartite setting, local realism and quantum theory constrain the parameter to 1/2 ≥ ϵ ≥ 0. Formulating the NPA hierarchy [30] as a semidefinite program upper bounds the joint guessing probability for verifiers V2 and V3 (see Fig. 1). Under these constraints, the NPA hierarchy yields the analytical upper bound on the conditional
[1] S. Goldwasser, S. Micali, and C. Rackoff, The knowledge complexity of interactive proof-systems, in Proceedings of the Seventeenth Annual ACM Symposium on Theory of Computing (STOC ’85) (Association for Computing Machinery, Providence, Rhode Island, USA, 1985) pp. 291–304. [2] S. Goldwasser, S. Micali, and C. Rackoff, The knowledge complexity of interactive proof systems, SIAM Journal on Computing , 186–208 (1989). [3] X. Sun, F. R. Yu, P. Zhang, Z. Sun, W. Xie, and X. Peng, A survey on zero-knowledge proof in blockchain (2021). [4] J. Partala, T. H. Nguyen, and S. Pirttikangas, Noninteractive zero-knowledge for blockchain: A survey,
1 , 4 1 1 ≤ϵ≤ . 4 2
0≤ϵ≤
CONCLUSION
In this work, we have developed an informationtheoretically secure framework for zero-knowledge certification of shared entangled states and constructed explicit bipartite and multipartite protocols based on Bell and GHZ resources. We have shown that a naive Bellstate certification protocol admits a correlation loophole, which motivates a two-basis certification scheme and, subsequently, a device-independent formulation capable of excluding higher-dimensional realizations. Extending this approach to quantum networks, we employ recently introduced self-testing of GHZ correlations and measurement structure, thereby establishing device-independent zero-knowledge protocols. The zero-knowledge property is proven by an explicit simulation of the verifier’s view, without access to the prover’s secret information, while completeness and soundness are maintained independently of computational assumptions. We further demonstrate that these guarantees persist under noise, establishing robustness of the protocols against imperfections in the shared quantum resources. Our results connect entanglement certification, nonlocality, self-testing, and zero-knowledge verification, and provide a foundation for cryptographic primitives in distributed quantum networks.
VII.
ACKNOWLEDGMENT
R. Rahaman acknowledges support from the ANRF Advanced Research Grant (ARG), Grant No. ANRF/ARG/2025/012066/MS.
IEEE Access 8, 227945 (2020). [5] E. Ben-Sasson, A. Chiesa, C. Garman, M. Green, I. Miers, E. Tromer, and M. Virza, Zerocash: Decentralized anonymous payments from bitcoin, in 2014 IEEE Symposium on Security and Privacy (IEEE, 2014) pp. 459–474. [6] B. Bünz, J. Bootle, D. Boneh, A. Poelstra, P. Wuille, and G. Maxwell, Bulletproofs: Short proofs for confidential transactions and more, in 2018 IEEE Symposium on Security and Privacy (IEEE, 2018) pp. 315–334. [7] A. Narayanan, J. Bonneau, E. Felten, A. Miller, and S. Goldfeder, Bitcoin and Cryptocurrency Technologies: A Comprehensive Introduction (Princeton University
18 Press, Princeton, NJ, 2016). [8] R. L. Rivest, A. Shamir, and L. Adleman, A method for obtaining digital signatures and public-key cryptosystems, Commun. ACM 21, 120–126 (1978). [9] W. Diffie and M. Hellman, New directions in cryptography, IEEE Transactions on Information Theory 22, 644 (1976). [10] P. W. Shor, Polynomial-time algorithms for prime factorization and discrete logarithms on a quantum computer, SIAM Journal on Computing 26, 1484 (1997). [11] L. K. Grover, A fast quantum mechanical algorithm for database search, Proceedings of the Twenty-Eighth Annual ACM Symposium on Theory of Computing, Proceedings of the 28th Annual ACM Symposium on Theory of Computing STOC ’96, 212–219 (1996). [12] D. S. Johnson, A catalog of complexity classes, in Handbook of Theoretical Computer Science, Volume A: Algorithms and Complexity, edited by J. van Leeuwen (Elsevier, 1990) Chap. 2, pp. 67–161. [13] S. Arora and B. Barak, Computational Complexity: A Modern Approach (Cambridge University Press, Cambridge, 2009). [14] M. R. Garey and D. S. Johnson, Computers and Intractability: A Guide to the Theory of NP-Completeness (W. H. Freeman, San Francisco, 1979). [15] O. Goldreich, Computational Complexity: A Conceptual Perspective (Cambridge University Press, Cambridge, 2008). [16] J. Watrous, Zero-knowledge against quantum attacks, Proceedings of the Thirty-Eighth Annual ACM Symposium on Theory of Computing , 296–305 (2006). [17] J. Walgate, A. J. Short, L. Hardy, and V. Vedral, Local distinguishability of multipartite orthogonal quantum states, Phys. Rev. Lett. 85, 4972 (2000). [18] S. Ghosh, G. Kar, A. Roy, A. Sen(De), and U. Sen, Distinguishability of bell states, Phys. Rev. Lett. 87, 277902 (2001).
[19] J. Walgate and L. Hardy, Nonlocality, asymmetry, and distinguishing bipartite states, Phys. Rev. Lett. 89, 147901 (2002). [20] H. J. Kimble, The quantum internet, Nature 453, 1023 (2008). [21] S. Wehner, D. Elkouss, and R. Hanson, Quantum internet: A vision for the road ahead, Science 362, eaam9288 (2018). [22] J. S. Bell, On the einstein podolsky rosen paradox, Physics Physique Fizika 1, 195 (1964). [23] J. F. Clauser, M. A. Horne, A. Shimony, and R. A. Holt, Proposed experiment to test local hidden-variable theories, Phys. Rev. Lett. 23, 880 (1969). [24] D. M. Greenberger, M. A. Horne, and A. Zeilinger, Going beyond bell’s theorem, in Bell’s Theorem, Quantum Theory and Conceptions of the Universe, edited by M. Kafatos (Springer Netherlands, Dordrecht, 1989) pp. 69–72. [25] D. Mayers and A. Yao, Self testing quantum apparatus (2004), arXiv:quant-ph/0307205 [quant-ph]. [26] S. Das, M. Patra, T. Paul, A. Majumdar, and R. Rahaman, Device-independent anonymous communication in quantum networks, arXiv preprint 10.48550/arXiv.2512.21047 (2025). [27] L. Masanes, Asymptotic violation of bell inequalities and distillability, Phys. Rev. Lett. 97, 050503 (2006). [28] R. Arnon-Friedman, F. Dupuis, O. Fawzi, R. Renner, and T. Vidick, Practical device-independent quantum cryptography via entropy accumulation, Nature Communications 9, 459 (2018). [29] M. Tomamichel, R. Colbeck, and R. Renner, A fully quantum asymptotic equipartition property, IEEE Transactions on Information Theory 55, 5840 (2009), arXiv:0811.1221 [quant-ph]. [30] M. Navascués, S. Pironio, and A. Acı́n, Bounding the set of quantum correlations, Phys. Rev. Lett. 98, 010401 (2007).