An Identity-Based Quantum Partially Blind Signature Scheme Based on Quantum Teleportation ()
1. Introduction
Digital signatures are a core cryptographic mechanism in modern information security systems for achieving identity authentication, data integrity, non-forgeability, and non-repudiation. Following the introduction of public-key cryptography by Diffie and Hellman in 1976, the development of digital signatures was driven by the introduction of schemes such as the RSA signature scheme, the ElGamal signature, the Schnorr signature, and short signatures based on bilinear pairs [1]-[6]. However, the security of RSA, DSA, and Schnorr-type schemes primarily relies on integer factorization or the discrete logarithm problem, and Shor’s algorithm demonstrates that large-scale quantum computers with sufficient fault tolerance can solve these problems in polynomial time [7]. Consequently, in recent years, the focus of research has shifted significantly from optimizing the efficiency of classical signatures to the design, standardization, and migration implementation of post-quantum signatures, encompassing post-quantum signature approaches such as lattice, hash, coding, and multivariate schemes [8]. The advancement of quantum computing poses a fundamental threat to cryptosystems based on traditional number-theoretic problems [7] [9]. Against this backdrop, quantum signature schemes based on the principles of quantum mechanics have emerged; their security relies on physical properties such as the quantum no-cloning theorem and quantum entanglement, rather than the computational complexity of mathematical problems [10].
Blind signatures allow signers to complete a signature without knowing the content of the original message. The concept was first proposed by Chaum in 1983; its core feature is that the signer cannot see the specific content of the message being signed, and it is widely used in scenarios such as anonymous electronic cash, privacy-preserving authentication, and electronic voting [11]. Quantum blind signatures utilize mechanisms such as non-clonability, quantum one-time pad, and quantum key distribution to achieve the security properties of the signature scheme [12]. Early research on quantum blind signatures primarily focused on entanglement resources, trusted arbitration, verification efficiency, and anonymity [13]-[15]. Subsequently, entanglement-free quantum group-blind signatures and schemes based on BB84 single-photon states were proposed to enhance the anonymity of electronic voting and reduce the difficulty of quantum state preparation [16] [17]. In recent years, research in this field has continued to focus on protocol innovation while placing greater emphasis on applications, resource overhead, and formal security: In 2022, Luo et al. applied controlled quantum teleportation to proxy blind signatures [18]. In 2024, Gupta et al. constructed an electronic cash transaction scheme based on quantum blind signatures [19]. In 2025, Wang et al. proposed a bit-by-bit quantum blind signature protocol based on single-qubit rotations, utilizing qubit rotations to perform message obfuscation and signing, thereby reducing the complexity of the signing process, minimizing reliance on large amounts of quantum resources, and lowering implementation costs [20]. In 2026, Zhang et al. analyzed quantum blind signatures in supply chain finance, revealing risks such as insider attacks and entanglement measurement attacks. They constructed a security model and formally characterized the security properties of the improved scheme through four security games [21].
Although fully blind signatures can conceal the message and its session context, they make it difficult to restrict the use of the signature, which may be exploited by malicious requesters for unauthorized purposes. Partially blind signatures enhance controllability while maintaining blindness by binding public information—such as expiration dates or business categories—to private messages. In 1996, Abe and Fujisaki proposed the concept of partial blinding, which incorporates public attributes into blind signatures [22]; in 2000, Abe and Okamoto further provided a formal definition of partial blind signatures, defined completeness, partial blindness, and unforgeability, and constructed a classically provably secure scheme [23]. In the realm of quantum partially blind signatures, Cai and Niu were among the first to propose a partially blind signature scheme based on quantum cryptography, which attempts to balance the protection of private messages with control over the use of signatures by utilizing pre-negotiated shared information [24]. After analyzing existing quantum partially blind signature schemes, Zhong et al. proposed a quantum partially blind signature scheme that does not require entangled states, with the scheme’s security guaranteed by a secure quantum key distribution protocol and quantum one-time pad [25]. In contrast to the relatively limited literature on quantum partial blind signatures, the past five years have seen more systematic, provably secure research on classical post-quantum partial blind signatures. For example, in 2024, Katsumata et al. constructed the homomorphic cryptographic blind signature and partial blind signature scheme CSI-Otter based on the CSIDH group action [26], In 2026, Kuchta et al. constructed the post-quantum blind signature scheme MEBS based on the equivalence group action of the MEDS matrix code and extended it to a partial blind signature [27].
Identity-based signatures use an identity string as public verification information, which can reduce the certificate management overhead of traditional public-key infrastructure [28]. Since Shamir proposed identity-based cryptosystems and the concept of identity signatures in 1984, this technology has been widely applied in cloud computing, the Internet of Things, and lightweight authentication systems [29]. Identity-based quantum signatures integrate identity mapping with quantum cryptography, simplifying certificate management while leveraging the properties of quantum mechanics to enhance security [30]. In 2020, Xin et al. proposed an identity-based quantum signature based on Bell states, enabling verifiers to complete verification using the signer’s identity [31]. In the same year, they further developed an identity-based public-key quantum signature scheme that does not require long-term quantum storage and exhibits high efficiency in quantum key exchange [32]. In 2023, Huang et al. improved upon related schemes by generating a private key based on the signer’s identity and combining it with the verifier’s secret parameter to generate the signature; this eliminated the need for key exchange prior to signing, thereby improving protocol execution efficiency [33]. In 2024, Prajapat et al. constructed an identity-based quantum designated-verifier signature and analyzed its feasibility through quantum simulation [34]; Liu et al. further proposed an identity-based quantum signature scheme using Bell states, which reduced the implementation complexity by employing a classical bit string key and supporting key reuse [35]. In 2025, Mohanty et al. proposed an identity-based quantum signature scheme and verified its correctness and preliminary feasibility through instance runs on the IBM Qiskit simulator and the IBM Q Lima real quantum backend [36].
Quantum teleportation utilizes pre-shared entanglement, Bell-basis joint measurements, and classical auxiliary information to reconstruct the corresponding quantum state at a remote location without directly transmitting the original particle carrying the unknown input state. Bennett et al. first proposed the quantum teleportation protocol in 1993 [37]. Zeng and Keitel proposed an early quantum arbitration signature scheme by combining GHZ states, quantum one-time pad, and a trusted arbitration mechanism [38]. Wen et al. further constructed a quantum multi-signature protocol [39]; however, subsequent analysis revealed vulnerabilities to insider attacks and external attacks, indicating that the correctness of quantum teleportation cannot substitute for a security proof of the signature [40]. In 2019, Feng et al. introduced quantum walk teleportation, enabling the generation of entangled states during the signing phase [41]. In recent years, Lu et al. proposed a verifiable arbitration quantum signature scheme based on controlled quantum teleportation, incorporating identity authentication and eavesdropping detection mechanisms [42]; Singh et al. investigated the combined application of quantum digital signatures and quantum teleportation in protecting blockchain transactions [43]; Zhao et al. proposed a continuous-variable quantum digital signature protocol based on quantum teleportation, providing a continuous-variable implementation path for teleportation-based quantum signatures [44].
Existing quantum signature schemes still face limitations in privacy-sensitive applications. Conventional schemes may expose the complete message to the signer, whereas fully blind signatures conceal even the public information required for authorization or constraint verification. In addition, identity and session binding, one-time authorization, key revocation, dispute traceability, and the separation of signing and verification capabilities remain insufficiently addressed in many existing quantum blind and partially blind signature schemes. This paper proposes an identity-based quantum partially blind signature scheme based on quantum teleportation. In this scheme, users quantize classical binary information using a one-time random string and then apply Pauli-X blinding, while the pre-shared public information remains visible to the signer. The trusted private key generation center (PKG) is responsible for participant identity authentication, session establishment, blinding key freezing, signature authorization, and session key distribution. It also implements the lifecycle management of signature keys through session IDs, validity periods, and key states. The signer encodes the participants’ identities, public information, session identifiers, and other data into quantum tags, which are incorporated into the quantum authentication payload along with the blinded message to generate direct verification evidence for a designated verifier and independent arbitration evidence for an arbitrator, respectively. This scheme employs security-verified EPR entanglement resources and quantum teleportation to transmit the quantum payload. This paper presents the specific operations and quantum state evolutions for each phase and analyzes the scheme’s security in terms of correctness, partial blindness, forgery resistance, non-repudiation, resistance to third-party attacks, and dispute arbitration.
2. Relevant Basic Knowledge
Pauli gate:
, where
The BB84 detection rule: The communicating parties randomly select
qubits and
qubits for measurement. Following communication, half of the measured qubits and their corresponding results are randomly disclosed. The average bit error rate
of the channel is calculated, and a threshold
is set. If
, it is determined that the channel is under an eavesdropping attack.
Quantum Teleportation (Standard): The entangled pair shared by both parties is
, where the signer holds
and the user holds
. The user has an unknown state
, then,
, where
represents the Bell basis, and
corresponds to the measurement result on
.
Performing a Bell measurement yields a two-bit result
, the uncorrected state at the signer’s end is
.
The user sends
to the signer, and the signer performs the corresponding Pauli operation
on
, causing
to collapse into
:
.
Quantum One-Time Pad (QOTP): Suppose the message to be encrypted is a quantum state
consisting of
qubits. The encryption algorithm is defined as
, where
, and
are uniformly random classical keys. Here,
applies the Pauli-
operator and
applies the Pauli-
operator on the
-th qubit.
The decryption algorithm is
. Therefore,
.
Furthermore, QOTP provides perfect secrecy:
, which holds for any input state
.
3. Detailed Design of a Quantum Partially Blind Signature Scheme
The proposed scheme is characterized by the following features. First, the protocol adopts a partially blind message structure in which the private message is hidden from the signer while the agreed public information
remains visible and is explicitly bound to the corresponding session. Second, a globally unique session identifier
and a one-time authorization value
are introduced to bind identities, public information, temporal information, and verification labels to a unique protocol execution. Third, two independent evidence branches are generated during signing: direct-verification evidence
and arbitration evidence
, protected by independent session keys
and
, respectively. Finally, a temporal key-evolution and revocation mechanism is introduced to bind signing authority to a specific time period and support dynamic revocation.
Participants and Roles: The proposed quantum partial-blind signature scheme involves five types of participants: the PKG, User, Signer, Verifier, and Arbitrator.
PKG: The Private Key Generator (PKG) is responsible for key generation and management, EPR entangled state generation and distribution, as well as system parameter generation.
User: The user is the owner of the message to be signed and holds a conventional message awaiting signature. The identity information of the User is denoted as
.
Signer: The signer generates a signature for the User’s message. The identity information of the Signer is denoted as
, and the public information
is shared with the User.
Verifier: The verifier is the unique entity responsible for validating the signature and verifying its legitimacy and correctness.
Arbitrator: The arbitrator participates only when disputes regarding signature information occur. Under normal circumstances, the arbitration procedure is not invoked.
Session ID and Label: Each protocol execution uses a globally unique session ID (
), where
is the length of the session ID. PKG ensures that the same
is not reused. The complete information is:
, where
represents the validity period for this authorization and verification,
is a database record, and
is the unique index for that record.
is the identity information of the participants.
PKG generates a one-time authorization number when approving a signature:
. The protocol uses three short-purpose constants: AUTH, DIRECT, and ARBITRATION.
The authorization tag, direct verification tag, and arbitration tag are defined as follows:
(1)
Canon denotes a normalized encoding function that is unambiguous.
The quantum authentication code is defined as
,
.
Where
denotes the one-time quantum authentication key,
is the quantum payload to be authenticated, and Σ is the authenticated quantum state after encoding. The variable
denotes the authentication result. When
,
represents the recovered payload.
The security of the authentication scheme is characterized by the parameter
, satisfying
.
3.1. System Initialization Phase
(1) Parameter generation: PKG specifies the security parameters:
, where
denotes the length of the session ID,
denotes the length of the one-time authorization code,
denotes the size of quantum authentication redundancy or trap qubits,
denotes the upper bound of the quantum authentication error acceptance probability, and
denotes the maximum binary message length allowed by the system.
PKG selects a publicly available quantum authentication scheme:
, and a normalized encoding rule:
.
The valid identity information of each participant is denoted as
,
.
Finally, PKG establishes a session database
for storing session keys.
(2) Participant identity registration: Each participant
submits identity verification information to the PKG. After successful verification, the PKG establishes an identity–key mapping:
, where
denotes the identity information of participant
, and
denotes the corresponding one-time control key pool. The mapping information is stored securely in the PKG’s protected database.
(3) Establishing a session key based on identity:
1) Session establishment: The user, signer, and verifier submit their identities and public information to the PKG:
. The PKG verifies
,
, and checks whether the permissions for each identity are valid. Upon successful verification, a unique session ID is generated:
, ensuring that it does not duplicate any ID in the session database. The PKG records this information:
.
2) One-time control key: Based on the identities and the session, the PKG generates one-time quantum authentication keys:
, for subsequent processes.
Specifically,
is used by the user to register with the PKG and freeze the blinding key;
is used by the signer to submit an authorization request to the PKG;
is used by the PKG to send a one-time quantum authorization token to the signer.
These keys are all bound to
, the sender’s and recipient’s identities, and the intended use, and are destroyed after this session
3) Entanglement resource initialization: Based on the security parameter
, the PKG generates
independent sets of EPR entanglement pairs, where each pair is in a maximally entangled state:
.
The PKG distributes the particle set
to the signer and the particle set
to the user, thereby establishing a shared quantum channel between them.
(4) Identity-Based Quantum Private Key Extraction: The signer sends its identity to the PKG. The temporal revocable-key model divides the system’s operational lifetime into a sequence of discrete time periods and assigns each signer mutually independent or unidirectionally evolving signing keys for different periods.
Let
denote the maximum number of signatures supported by the system. The corresponding set of time or state indices is defined as:
. For signer
, its identity is denoted as
. In the
-th time period, the signer holds a signing key
,
, which is bound to its identity and time state. The corresponding key state is represented as:
, where
denotes the valid state of the signer in the
-th time period. It can take the following values:
The time-period-related revocation list
records identities that no longer possess signing authority during the
-th time period and subsequent periods. If
, the signer is revoked from the
-th time period, and the system no longer generates, extracts, or updates valid signing keys for this signer. For any
, it holds that
, which provides backward revocation and terminates the signing authority for future periods. For a non-revoked signer, the signing key is updated according to the time period:
. After updating, the previous key is immediately deleted:
. The key update mechanism only supports forward evolution and prevents recovery of previous keys. Therefore, given the current key
, it is infeasible to derive any previous key
,
. During the
-th time period, the signer uses only the valid key
to generate a signature:
.
When verifying a signature, the verifier must simultaneously check the correctness of the signature, the validity of the time state, and the signer’s revocation status. The verification algorithm is denoted as:
where
.
The verification algorithm outputs 1 if and only if all the following conditions are satisfied:
,
, and
is a valid signature generated by the valid key of the
-th time period. Otherwise, the verification algorithm outputs 0.
(5) Signing authorization request: The signer requests signing authorization from the PKG by sending its identity information
and the session identifier
to the PKG. The PKG verifies whether the required conditions are satisfied, namely, whether the signer’s identity has been authenticated, whether the user has frozen the blinding key, and whether the current request has not expired. Once all conditions are satisfied, the PKG grants authorization and independently and randomly generates two session keys:
,
. The independence requirement is defined as follows:
and
are mutually independent Hilbert spaces, and
. There exists no quantum operation that can recover
from
. Therefore, even if one key is compromised, the other key cannot be derived. The PKG distributes
to the signer
and the verifier
, and distributes
to the signer
and the arbitrator
. The PKG then generates a unique authorization serial number
. The corresponding authorization content is defined as:
. Finally, the PKG updates the signer’s state as:
.
3.2. Blinding Phase
Assume that the message to be signed by the user is a private binary message
,
, with the agreed-upon public message
and the entangled-particle sequence
, which is pre-shared through the PKG.
(1) The message is quantum-encoded and partially blinded. Specifically, only the private message
is blinded, while the public information
remains unblinded. The user first uniformly and randomly generates a basis-selection string ,
, and an
-bit classical blinding-key string ,
. For each private message bit
, the user first performs a logical blinding operation using the Pauli-
operator:
. The resulting logical bit is then encoded according to the basis-selection bit
. Thus, the
th blinded message qubit is prepared as
, namely,
(2)
When
, the blinded logical bit is encoded in the computational, or
, basis
; when
, it is encoded in the Hadamard, or
, basis
. Here, the symbol
in the blinding operation denotes the Pauli-
operator, whereas
denotes the Hadamard measurement basis.
Let
,
,
, therefore, the complete partially blinded quantum message is
(3)
It should be noted that, in
, the Pauli-
blinding operation
acts first on the logical message bits, followed by the basis-encoding operation
. Hence, for both
and
, the random bit
effectively maps the logical message bit
to
.
To prevent the user from selecting a new blinding key or a new basis-selection string after obtaining the signature, the user must register the blinding information with the PKG before signing. The registration information is defined as
. The user prepares the corresponding quantum state
and encodes it as
, which is then sent to the PKG.
Upon receiving
, the PKG performs authentication decoding:
. Only when
and the decoded registration information matches the current session does the PKG store
. From that point onward, the registered basis-selection string
and blinding-key string
are frozen and cannot be modified for the current session.
(2) Quantum Teleportation (Teleporting a Blinded State to the Signer): The user performs a joint Bell measurement on the transmitted state particle and the EPR particle. Taking a single particle as an example: let
, and let the EPR state be
. At this point, the entire system can be described as:
(4)
Then, the user performs a CNOT operation and obtains
:
(5)
The function of the H-Gate:
,
; User applies an H-gate to the first qubit, resulting in
:
(6)
To make the measurement results easier to read, we rearrange
to get:
(7)
Next, the user measures the two qubits in the computational basis
. The four possible measurement outcomes and the corresponding recovery operations are summarized in Table 1.
Table 1. Correspondence between the user’s measurement outcomes and the signer’s quantum-state recovery operations.
Measurement outcome |
Post-measurement state of
|
Recovery operation
|
Probability |
00 |
|
|
1/4 |
01 |
|
|
1/4 |
10 |
|
|
1/4 |
11 |
|
|
1/4 |
The quantum circuit design is as shown in Figure 1:
Figure 1. Three-qubit simulation circuit for quantum teleportation.
, assume that
,
, and
; the three-Qubit measurement results are output as Figure 2:
Figure 2. Probability distribution of three-qubit measurement outcomes in the quantum teleportation circuit.
The simulator measures all three qubits and therefore reports eight three-bit outcomes, each occurring with an ideal probability of approximately 1/8. However, only the last two measured bits constitute the Bell-measurement outcome
. By marginalizing over the receiver-qubit measurement result, the corresponding Bell-outcome probabilities are
(8)
which are all approximately 1/4 under ideal teleportation.
Table 2. Measurement probabilities corresponding to different Bell measurement outcomes.
Bell measurement outcome
|
Quantum state
|
State probability |
Measurement-outcome probability |
00 |
|
0.1220703 |
0.2529296 |
|
|
0.1308593 |
|
01 |
|
0.1240234 |
0.2490234 |
|
|
0.1250000 |
|
10 |
|
0.1250000 |
0.2470703 |
|
|
0.1220703 |
|
11 |
|
0.1259765 |
0.2509765 |
|
|
0.1250000 |
|
The above results were obtained through online testing on the Origin Quantum platform, with the number of shots set to 1024. Table 2 presents the simulation results for the four possible Bell measurement outcomes. For each measurement outcome , the corresponding probability is obtained by summing the probabilities of the two associated computational-basis states. The resulting probabilities for the four outcomes are all close to the theoretical value of (1/4), indicating an approximately uniform distribution of the Bell measurement results.
The user performs a Bell-basis measurement on
and obtains a 2-bit classical result
,
,
.
Then the user sends
to the signer via a classical channel; the signer can only retrieve the message
, but cannot access the original message
or quantum state
to be signed.
In order to check whether the channel is secure, the user generates
decoy states randomly, selecting them from four sets of non-orthogonal states:
,
,
,
. From each group,
-basis and
-basis states are randomly selected to prepare the quantum states. The detection bit is then sent to the signer through the quantum channel.
3.3. Signing Phase
After receiving the decoy states sent by the user, both the user and the signer randomly select the
basis or
basis for measurement. All measurement bases and measurement outcomes are stored. Half of the measurement bases and their corresponding measurement results are randomly disclosed, and the average channel error rate
is calculated. Let
denote the threshold. If
, it is determined that an eavesdropping attack exists on the channel, and set
; otherwise, proceed with the subsequent signature operations.
Quantum collapse state: After the user performs the Bell-basis measurement, the particle
in the hands of the remote signer collapses, and its state is denoted as:
. If the signer performs the corresponding Pauli operation
on
, where
, then
(9)
Since a global phase has no physical effect, this operation restores the blinded state:
.
Therefore, after receiving
, the signer performs the Bell correction to obtain
. The signer only signs when the following conditions are met:
,
, and
. The generated state signature is as follows:
(10)
The direct verification tag is
, the arbitration tag is
, and the signer prepares these as the computational basis quantum states:
.
The direct verification payload is
, with density operator
; and the signer computes
(11)
is the quantum signature evidence provided to the user and ultimately verified by the designated verifier. Execute
, and share the temporal key
with the verifier after the signature is completed. This temporal key will immediately lose its signature capability after the signature is completed within the period, and can only be used for subsequent verification of the completed signature.
The arbitration payload is
, and its density operator is
. The signer computes
;
must be delivered directly by the signer to the arbitrator and cannot be relayed through the user or verifier.
The signer sends
to the user, and the signer sends
to the arbitrator. The arbitrator only stores
and the receipt time, without decoding it immediately.
After confirming that the arbitrator has received
, PKG marks this session as signed.
Sign output: The user holds
; the arbitrator holds
; PKG stores
,
,
, and the frozen
.
3.4. Verification Phase
The user sends the direct verification evidence
to the designated verifier via quantum teleportation. To ensure that the verification input clearly corresponds to the message
, the user can additionally prepare a reference message state
and deliver it to the verifier via quantum teleportation. Since
is a classical binary string, preparing a reference state on a computational-basis state does not violate the no-cloning theorem.
The user sends an unblinding request
to the PKG. After the PKG verifies the user’s identity, session status, and arbitration-evidence receipt record, it securely releases the data
to the designated verifier. At this stage, only the value of
frozen in the database prior to signing may be retrieved; the user cannot submit a new value
.
The unblinding output
is held by the verifier, who decodes it using a one-time direct verification key:
. If
, the request is immediately rejected. If authentication succeeds, the verifier records the recovered payload as
, where
is the recovered blinded-message register;
is the recovered direct-verification-tag register.
is the temporal signature obtained after decoding. The verifier performs decryption on
using the temporal key
shared with the signer:
(12)
and obtains
. It then compares ; if they are the same, verification continues; otherwise, the signature is declared invalid.
The verifier measures the tag register to obtain
and computes
based on the values of
and
provided by the PKG. The verification condition is
. At the same time, the verifier checks the PKG’s immutable record:
, and confirms
,
,
, and
. This step enables the short tag to indirectly bind the complete public information through
and
.
Perform quantum unblinding: The verifier applies the inverse basis-encoding operation followed by the Pauli-
unblinding operation to the blinded-message register:
. Under honest conditions,
. Therefore,
(13)
Then, the verifier performs the same unblinding operation on the blinded-message state
recovered from the temporal protected payload:
. If the temporal protection is correct, then
. Hence,
(14)
The verifier can perform a quantum equality check without immediately measuring the complete message. It prepares two independent auxiliary registers,
and
, and executes the following sequence:
(15)
If
, then the auxiliary register
retains the value
. If
, then the auxiliary register
retains the value
. The auxiliary-register measurement result is defined as:
(16)
The final acceptance criterion is defined as follows:
. The verifier then declares the signature valid and sets
.
3.5. Arbitration Phase
When a user, signer, or verifier disputes the verification result, the arbitrator uses
—which was submitted directly by the signer and stored during the signing phase—to render a decision.
The PKG securely releases
to the arbitrator. The arbitrator decodes the arbitration evidence as
(17)
If
, the arbitration evidence is declared invalid. If authentication succeeds, the arbitrator recovers
(18)
where
is the temporal signature obtained after decoding.
The arbitrator decrypts
using the temporal key
shared with the signer:
(19)
The arbitrator then compares . If the two session identifiers are equal, the arbitration procedure continues; otherwise, the signature is declared invalid.
Then, the arbitrator calculates the expected label
, and checks
, then performs unblinding:
,
. The arbitrator performs an equality check between
,
, and the reference state
of the disputed message. The condition for arbitration acceptance is
. Since
is evidence sent directly by the signer to the arbitrator and protected by an independent key
, neither the user nor the verifier can fabricate valid arbitration evidence by modifying or re-encoding
. If the results of routine verification do not match the arbitration results, the protocol treats
stored by the arbitrator as the official evidence of the dispute.
4. Security Analysis
In our security model, both the PKG and the arbitrator are assumed to be trusted and non-colluding entities; scenarios in which either the PKG or the arbitrator is fully compromised are outside the scope of this work.
4.1. Correctness Analysis
The correctness of the proposed scheme requires that, when all participants honestly follow the protocol and the quantum channels are ideal, a legitimately generated signature is accepted by the designated verifier.
The user’s original message is represented by the computational-basis state
. Before signing, the user randomly selects a basis-selection string
and a blinding key
, and performs the bitwise Pauli-
operation followed by the basis encoding,
. During quantum teleportation, the user performs Bell-basis measurements and obtains the classical outcome
.
After receiving
, the signer applies
and obtains
. The signer then generates the temporal signature
and constructs the direct-verification evidence
. Under honest execution, quantum authentication decoding succeeds:
. Using the corresponding temporal key
, the verifier recovers
.
After the PKG releases the basis-selection string
and the blinding key
that were frozen before signing, the verifier performs unblinding:
(20)
and similarly,
.
Since the reference state satisfies
, the message-consistency test yields
. Therefore, every legitimately generated signature is accepted by the designated verifier, which establishes the correctness of the proposed scheme.
4.2. Non-Forgeability Analysis
If an attacker does not know
or
, the probability that an unauthorized modification to
or
is erroneously accepted is at most
. Moreover, since the authorization tag is bound to the one-time values
and
, the attacker cannot transplant authentication evidence from another session into the current session.
If the verifier accepts a different payload
, or a different tag
, then the attacker has compromised the integrity of the quantum authentication code. Therefore,
(21)
To forge a valid signature, an external attacker must generate direct verification evidence that can pass the verifier’s authentication procedure:
(22)
Assume that the session key
is a uniformly random classical key of length
. If the attacker has no information about this key, the probability of correctly guessing the entire key is
(23)
which decreases exponentially with
.
The temporal signature
is generated using the temporal signing key
:
(24)
Assume that
is a uniformly random
-bit key. Without knowledge of the key, an attacker attempting to forge a temporal signature can guess each key bit correctly with probability 1/2. Consequently, the probability of correctly guessing the entire key is
, which also decreases exponentially with
.
4.3. Non-Repudiation Analysis
(1) Non-repudiation of the signer
The signer’s non-repudiation is mainly guaranteed by the independent arbitration evidence
. The evidence
is generated by the signer during the signing phase and is delivered directly to the arbitrator for storage. Unlike the direct-verification evidence
used for routine verification,
is protected by the independent arbitration key
and is not transmitted through either the user or the designated verifier. Therefore, other participants cannot replace or regenerate valid arbitration evidence.
The temporal signature contained in the arbitration evidence is record as
and the arbitration tag is defined as
. The arbitration evidence is bound to the signer identity
, the session identifier
, the time period
, the one-time authorization value
, and the corresponding blinded message. Valid arbitration evidence generated in one authorized session cannot be transferred to another signer, time period, or session without causing the corresponding identity, session, or tag-consistency verification to fail.
Moreover, the blinding key
and the basis-selection string
is frozen by the PKG before the signing operation, and the corresponding session information is stored in the immutable record:
. Therefore, after the signature has been generated, the signer cannot deny the completed signing operation by modifying the message, identity information, authorization information, or session parameters, since such a claim would be inconsistent with the arbitration evidence and the session record maintained by the PKG.
In addition, the arbitration key
and the direct-verification key
are independently generated, and
is not disclosed to the user or the designated verifier. Therefore, neither the user nor the verifier can construct valid arbitration evidence
from the direct-verification evidence
. If an adversary modifies or forges
without authorization and the forged evidence is nevertheless accepted, then the integrity of the underlying quantum authentication scheme has been compromised. Thus, .
Therefore, under the assumptions that the PKG is trustworthy, the session record is immutable, and the arbitration key
remains secret, once
passes authentication and its identity, time-period, session, and message information are consistent with the system records, the signer cannot deny having completed the signature in the corresponding authorized session.
(2) Non-repudiation of the user
The user’s non-repudiation mainly ensures that the user cannot deny participation in the corresponding signing session or the blinding information submitted and frozen before signing. Before the signing operation begins, the user generates the blinding key
and the basis-selection string
, and registers
with the PKG. The PKG stores
only if authentication succeeds and the
contained in the authenticated data matches the current session. Once this record has been established, the blinding key
and the basis-selection string
are frozen for the current session and cannot be replaced by different value
after signing.
Since
is a globally unique session identifier and
records the user identity
together with the parameters of the corresponding session, the user identity, signing session, and frozen basis-selection string and blinding key are bound to the same session record. If the user later denies participation in the session or claims that a different basis-selection string
or blinding key
was used, such a claim will be inconsistent with the authenticated registration record stored by the PKG.
Furthermore, the corresponding blinded message is contained in the arbitration evidence. Under honest protocol execution,
. Using the basis-selection string
and the blinding key
frozen by the PKG before signing, the original message can be recovered as
. If the user attempts to replace the original blinding key with a different value
after signing, then
, which, in general, differs from the original message
. Therefore, the result cannot simultaneously satisfy the consistency requirements of the arbitration evidence and the frozen blinding information maintained by the PKG.
Moreover, if an adversary attempts to forge or modify the user’s blinding-key registration information, it must construct authenticated data without knowledge of
. According to the security of the quantum authentication scheme, the probability that a forged or modified registration is nevertheless accepted satisfies .
Therefore, under the assumptions that the PKG is trustworthy, the session record is immutable,
remains secret, and the blinding key
is correctly frozen before signing, the user cannot deny participation in the corresponding signing session or alter the signing result by replacing the blinding parameter after the signature has been generated.
4.4. Partial Blindness Analysis
Given public information
and two distinct private messages
, corresponding to the quantum states
and
, the protocol satisfies partial blindness if the signer’s complete views for the two messages are indistinguishable, i.e.,
.
User blindness and the Bell-measurement process: Let the private message quantum state be
,
. Before signing, the user uniformly and randomly selects a basis-selection string
and a blinding-key string
. The user first performs the Pauli-
blinding operation on the logical message bits and then performs the basis encoding. Thus,
.
For the ith message bit,
. When
,
, whereas when
,
. Hence, the random bit
blinds the logical value before either encoding basis is applied.
Let
and
denote the user’s and signer’s entangled particles, respectively. The shared EPR state is
. The joint system is expressed as
(25)
The user performs the Bell-basis operations
and
, where
(26)
and
(27)
For the ith qubit, the Bell-basis measurement produces the two-bit classical result
. For the complete
-qubit message, the Bell-measurement result is
. Under ideal teleportation, the Bell-measurement outcomes are uniformly distributed and independent of the input state, and hence
.
Quantum state received by the signer: According to the quantum teleportation protocol, the Bell-measurement result
determines the Pauli correction
(28)
After receiving
, the signer performs the corresponding correction and obtains
, where
denotes equality up to an irrelevant global phase.
Therefore, the blindness analysis must consider the signer’s state after the Bell-measurement result
has been received and the corresponding correction has been completed. For any fixed basis-selection string
and Bell-measurement result
, since the blinding-key string
is uniformly random and remains unknown to the signer, the density operator observed by the signer is
(29)
For any two distinct private messages
, we therefore have
(30)
Consequently,
.
The above result holds for every basis-selection string
and every Bell-measurement result
. In particular, when
, the Pauli-
operation gives
. When
, the logical value is first blinded by
and then encoded in the Hadamard basis:
. Thus, the logical message value is randomized by
under either message-encoding basis.
Finally, the signer obtains not only the restored blinded quantum state, but also the Bell-measurement result
and the public information
. Hence, the signer’s complete classical–quantum view can be written as
(31)
Therefore, for any two distinct private messages
and
associated with the same public information
,
. Hence, even after receiving the complete Bell-measurement result
and restoring the blinded quantum state, the signer cannot distinguish the user’s private message, while the agreed public information
remains visible. Therefore, the proposed protocol satisfies partial blindness.
4.5. Resistance against Third-Party Attacks
Entangling-Probe Attack: The attacker Eve prepares a blank ancillary particle in the state
and applies an interaction
satisfying
(32)
where the ancillary vectors satisfy the unitarity condition
For uniformly distributed inputs in the
basis, the induced error rate is
(33)
If the attacker introduces strictly zero errors in both the
and
bases, then the attacker cannot obtain any information about the original bit. Zero error in the
basis requires
(34)
For
, linearity gives:
. For
(35)
we obtain
(36)
If the interaction also introduces no error in the
basis, the coefficient of
must vanish. Hence,
. Consequently,
(37)
For an arbitrary input state
it follows that
(38)
Therefore, the state of the attacker’s ancillary system is independent of the input state, and Eve cannot obtain any information without introducing detectable errors.
Intercept-Measure-Resend Attack: Assume that an external attacker, Eve, intercepts particles transmitted to the user or the signer. Eve measures each intercepted particle and, according to the measurement outcome, prepares a new particle and sends it to the legitimate participant. Eve randomly selects either the
basis or the
basis for measurement.
The channel-security test requires the insertion of decoy states. For a single decoy particle, the probability of detecting Eve is
, whereas the probability that Eve escapes detection is
. When
decoy particles are used, the probability that Eve is detected is
(39)
If Eve attacks each transmitted particle independently with probability
, then the probability that none of the
decoy particles reveals the attack is
(40)
Accordingly, the overall detection probability is
(41)
Therefore, the detection probability increases with both the attack ratio
and the number of decoy particles
.
4.6. Communication Resource Analysis
In terms of communication resource overhead, let
denote the length of the private message, and let
and
denote the lengths of the direct verification evidence and arbitration evidence, respectively. During one complete execution of the protocol, the blinded message
, the direct verification evidence
and
, the arbitration evidence
, and the reference message
are transmitted through quantum teleportation. Therefore, the total number of logical qubits to be teleported is
Since teleporting a
-qubit register requires
fresh EPR pairs and
authenticated classical bits for Bell-measurement correction, the total number of consumed EPR pairs is
, and the corresponding classical correction cost is
.
Let
denote the number of decoy particles used for the quantum transmission, the total quantum and classical communication costs can be expressed as
, and
, respectively, where
denotes the additional quantum resources required for key establishment, and
includes the session identifier, authorization information, participant identities, and other authenticated classical control data. The comparison analysis with existing schemes is illustrated in Table 3.
Table 3. Comparison of functionality and resource overhead with related schemes.
Scheme |
Partial blindness |
Teleportation |
Arbitration |
Designated verification |
Temporal protection |
Signature size
|
Quantum cost
|
Classical cost
|
Cai and Niu [24] |
Yes |
NR |
No |
No |
No |
NR |
NR |
NR |
Zhong et al. [25] |
Yes |
No |
No |
No |
No |
NR |
NR |
NR |
Xia et al. [45] |
No |
No |
NR |
No |
No |
|
|
|
Tan and Ye [46] |
No |
Yes |
No |
No |
No |
|
|
|
Proposed scheme |
Yes |
Yes |
Yes |
Yes |
Yes |
|
|
|
Note: NR denotes that the corresponding quantity is not reported or is not directly comparable under a unified resource-counting convention.
5. Conclusions
This paper proposes an identity-based quantum partially blind signature scheme based on quantum teleportation. With the aid of a random bit string of length
, the user encodes binary information into a quantum state, blinds it according to the blinding key
, and keeps the public information
openly visible, thereby achieving the partially blind signature property.
The PKG is responsible for participant identity authentication, session establishment, blind-key freezing, signature authorization, and one-time session-key distribution, and implements key lifecycle management through a unique session identifier, validity period, and state records. Signers generate direct verification evidence for a designated verifier and independent arbitration evidence for an arbitrator, respectively; the relevant quantum information is transmitted via security-verified EPR entanglement resources and quantum teleportation.
Verifiers perform routine verification through quantum authentication decoding, tag verification, and message de-blinding; in the event of a dispute, the arbitrator renders a decision based on the quantum evidence independently preserved during the signing phase. Security analysis shows that, under conditions such as a trusted PKG and arbitrator, secure classical communication channels, an ideal random source, one-time session keys, and secure quantum authentication codes, this scheme can achieve security properties including correctness, partial blindness, forgery resistance, and non-repudiation, while also providing resistance to third-party attacks.
However, its security is based on information-theoretic security under explicit attack models and trust assumptions; at the same time, quantum labels, authentication-assisting qubits, and two-branch evidence also entail certain quantum resource and storage overheads.
Acknowledgements
We express our gratitude to all contributors who engaged in the discussion of this work. This work was supported by the Hunan Provincial Natural Science Foundation of China (GrantNos.2025JJ70445), the Joint Open Fund Project of “Hunan Provincial Science and Technology Innovation Team, Hunan Provincial Key Laboratory and Provincial Characteristic Discipline of Control Science and Engineering” (Grant NO.ZNKZN2024-4).
Author Contributions
Conceptualization, Juxiu Zhong and Rongbo Lu; methodology, Juxiu Zhong; validation, Juxiu Zhong, Rongbo Lu and Wei Li; writing-original draft preparation, Juxiu Zhong; writing-review and editing, Rongbo Lu and Wei Li. All authors have read and agreed to the published version of the manuscript.