An Identity-Based Quantum Partially Blind Signature Scheme Based on Quantum Teleportation

Abstract

Traditional digital signatures are based on mathematical hard problems that are vulnerable to quantum attacks. For privacy-sensitive applications such as electronic cash and electronic voting, partially blind signatures are preferable because they protect private messages while allowing signers to verify necessary public information. This paper proposes an identity-based quantum partially blind signature scheme based on quantum teleportation. Each signing session is assigned a unique identifier. The user blinds the private binary message by applying Pauli-X operations with a one-time random string, while public information remains visible to the signer. A trusted PKG performs identity authentication, signature authorization, session-key distribution, and time-period-based key lifecycle management. Quantum tags and quantum authentication codes provide verification and arbitration evidence, while quantum teleportation is used to transmit quantum information. In case of disputes, an arbitrator can verify independently stored quantum evidence, and channel monitoring enables the detection of eavesdropping and tampering. Security analysis shows that the proposed scheme satisfies partial blindness, unforgeability, and non-repudiation, and resists malicious third-party attacks. It is suitable for privacy-preserving and restricted-authorization applications such as electronic cash and electronic voting.

Share and Cite:

Zhong, J. , Lu, R. and Li, W. (2026) An Identity-Based Quantum Partially Blind Signature Scheme Based on Quantum Teleportation. Journal of Quantum Information Science, 16, 398-424. doi: 10.4236/jqis.2026.163014.

1. Introduction

Digital signatures are a core cryptographic mechanism in modern information security systems for achieving identity authentication, data integrity, non-forgeability, and non-repudiation. Following the introduction of public-key cryptography by Diffie and Hellman in 1976, the development of digital signatures was driven by the introduction of schemes such as the RSA signature scheme, the ElGamal signature, the Schnorr signature, and short signatures based on bilinear pairs [1]-[6]. However, the security of RSA, DSA, and Schnorr-type schemes primarily relies on integer factorization or the discrete logarithm problem, and Shor’s algorithm demonstrates that large-scale quantum computers with sufficient fault tolerance can solve these problems in polynomial time [7]. Consequently, in recent years, the focus of research has shifted significantly from optimizing the efficiency of classical signatures to the design, standardization, and migration implementation of post-quantum signatures, encompassing post-quantum signature approaches such as lattice, hash, coding, and multivariate schemes [8]. The advancement of quantum computing poses a fundamental threat to cryptosystems based on traditional number-theoretic problems [7] [9]. Against this backdrop, quantum signature schemes based on the principles of quantum mechanics have emerged; their security relies on physical properties such as the quantum no-cloning theorem and quantum entanglement, rather than the computational complexity of mathematical problems [10].

Blind signatures allow signers to complete a signature without knowing the content of the original message. The concept was first proposed by Chaum in 1983; its core feature is that the signer cannot see the specific content of the message being signed, and it is widely used in scenarios such as anonymous electronic cash, privacy-preserving authentication, and electronic voting [11]. Quantum blind signatures utilize mechanisms such as non-clonability, quantum one-time pad, and quantum key distribution to achieve the security properties of the signature scheme [12]. Early research on quantum blind signatures primarily focused on entanglement resources, trusted arbitration, verification efficiency, and anonymity [13]-[15]. Subsequently, entanglement-free quantum group-blind signatures and schemes based on BB84 single-photon states were proposed to enhance the anonymity of electronic voting and reduce the difficulty of quantum state preparation [16] [17]. In recent years, research in this field has continued to focus on protocol innovation while placing greater emphasis on applications, resource overhead, and formal security: In 2022, Luo et al. applied controlled quantum teleportation to proxy blind signatures [18]. In 2024, Gupta et al. constructed an electronic cash transaction scheme based on quantum blind signatures [19]. In 2025, Wang et al. proposed a bit-by-bit quantum blind signature protocol based on single-qubit rotations, utilizing qubit rotations to perform message obfuscation and signing, thereby reducing the complexity of the signing process, minimizing reliance on large amounts of quantum resources, and lowering implementation costs [20]. In 2026, Zhang et al. analyzed quantum blind signatures in supply chain finance, revealing risks such as insider attacks and entanglement measurement attacks. They constructed a security model and formally characterized the security properties of the improved scheme through four security games [21].

Although fully blind signatures can conceal the message and its session context, they make it difficult to restrict the use of the signature, which may be exploited by malicious requesters for unauthorized purposes. Partially blind signatures enhance controllability while maintaining blindness by binding public information—such as expiration dates or business categories—to private messages. In 1996, Abe and Fujisaki proposed the concept of partial blinding, which incorporates public attributes into blind signatures [22]; in 2000, Abe and Okamoto further provided a formal definition of partial blind signatures, defined completeness, partial blindness, and unforgeability, and constructed a classically provably secure scheme [23]. In the realm of quantum partially blind signatures, Cai and Niu were among the first to propose a partially blind signature scheme based on quantum cryptography, which attempts to balance the protection of private messages with control over the use of signatures by utilizing pre-negotiated shared information [24]. After analyzing existing quantum partially blind signature schemes, Zhong et al. proposed a quantum partially blind signature scheme that does not require entangled states, with the scheme’s security guaranteed by a secure quantum key distribution protocol and quantum one-time pad [25]. In contrast to the relatively limited literature on quantum partial blind signatures, the past five years have seen more systematic, provably secure research on classical post-quantum partial blind signatures. For example, in 2024, Katsumata et al. constructed the homomorphic cryptographic blind signature and partial blind signature scheme CSI-Otter based on the CSIDH group action [26], In 2026, Kuchta et al. constructed the post-quantum blind signature scheme MEBS based on the equivalence group action of the MEDS matrix code and extended it to a partial blind signature [27].

Identity-based signatures use an identity string as public verification information, which can reduce the certificate management overhead of traditional public-key infrastructure [28]. Since Shamir proposed identity-based cryptosystems and the concept of identity signatures in 1984, this technology has been widely applied in cloud computing, the Internet of Things, and lightweight authentication systems [29]. Identity-based quantum signatures integrate identity mapping with quantum cryptography, simplifying certificate management while leveraging the properties of quantum mechanics to enhance security [30]. In 2020, Xin et al. proposed an identity-based quantum signature based on Bell states, enabling verifiers to complete verification using the signer’s identity [31]. In the same year, they further developed an identity-based public-key quantum signature scheme that does not require long-term quantum storage and exhibits high efficiency in quantum key exchange [32]. In 2023, Huang et al. improved upon related schemes by generating a private key based on the signer’s identity and combining it with the verifier’s secret parameter to generate the signature; this eliminated the need for key exchange prior to signing, thereby improving protocol execution efficiency [33]. In 2024, Prajapat et al. constructed an identity-based quantum designated-verifier signature and analyzed its feasibility through quantum simulation [34]; Liu et al. further proposed an identity-based quantum signature scheme using Bell states, which reduced the implementation complexity by employing a classical bit string key and supporting key reuse [35]. In 2025, Mohanty et al. proposed an identity-based quantum signature scheme and verified its correctness and preliminary feasibility through instance runs on the IBM Qiskit simulator and the IBM Q Lima real quantum backend [36].

Quantum teleportation utilizes pre-shared entanglement, Bell-basis joint measurements, and classical auxiliary information to reconstruct the corresponding quantum state at a remote location without directly transmitting the original particle carrying the unknown input state. Bennett et al. first proposed the quantum teleportation protocol in 1993 [37]. Zeng and Keitel proposed an early quantum arbitration signature scheme by combining GHZ states, quantum one-time pad, and a trusted arbitration mechanism [38]. Wen et al. further constructed a quantum multi-signature protocol [39]; however, subsequent analysis revealed vulnerabilities to insider attacks and external attacks, indicating that the correctness of quantum teleportation cannot substitute for a security proof of the signature [40]. In 2019, Feng et al. introduced quantum walk teleportation, enabling the generation of entangled states during the signing phase [41]. In recent years, Lu et al. proposed a verifiable arbitration quantum signature scheme based on controlled quantum teleportation, incorporating identity authentication and eavesdropping detection mechanisms [42]; Singh et al. investigated the combined application of quantum digital signatures and quantum teleportation in protecting blockchain transactions [43]; Zhao et al. proposed a continuous-variable quantum digital signature protocol based on quantum teleportation, providing a continuous-variable implementation path for teleportation-based quantum signatures [44].

Existing quantum signature schemes still face limitations in privacy-sensitive applications. Conventional schemes may expose the complete message to the signer, whereas fully blind signatures conceal even the public information required for authorization or constraint verification. In addition, identity and session binding, one-time authorization, key revocation, dispute traceability, and the separation of signing and verification capabilities remain insufficiently addressed in many existing quantum blind and partially blind signature schemes. This paper proposes an identity-based quantum partially blind signature scheme based on quantum teleportation. In this scheme, users quantize classical binary information using a one-time random string and then apply Pauli-X blinding, while the pre-shared public information remains visible to the signer. The trusted private key generation center (PKG) is responsible for participant identity authentication, session establishment, blinding key freezing, signature authorization, and session key distribution. It also implements the lifecycle management of signature keys through session IDs, validity periods, and key states. The signer encodes the participants’ identities, public information, session identifiers, and other data into quantum tags, which are incorporated into the quantum authentication payload along with the blinded message to generate direct verification evidence for a designated verifier and independent arbitration evidence for an arbitrator, respectively. This scheme employs security-verified EPR entanglement resources and quantum teleportation to transmit the quantum payload. This paper presents the specific operations and quantum state evolutions for each phase and analyzes the scheme’s security in terms of correctness, partial blindness, forgery resistance, non-repudiation, resistance to third-party attacks, and dispute arbitration.

2. Relevant Basic Knowledge

Pauli gate: I,X,Y,Z , where

I=( 1 0 0 1 ),X=( 0 1 1 0 ),Y=( 0 i i 0 ),Z=( 1 0 0 1 ).

The BB84 detection rule: The communicating parties randomly select I qubits and I qubits for measurement. Following communication, half of the measured qubits and their corresponding results are randomly disclosed. The average bit error rate e of the channel is calculated, and a threshold e th is set. If e> e th , it is determined that the channel is under an eavesdropping attack.

Quantum Teleportation (Standard): The entangled pair shared by both parties is | Φ + us , where the signer holds s and the user holds u . The user has an unknown state |φ , then, |φ q | Φ + us = 1 2 x,z{ 0,1 } | Φ x,z + qu X x Z z |φ s , where | Φ x,z + represents the Bell basis, and ( x,z ) corresponds to the measurement result on ( |φ,u ) .

Performing a Bell measurement yields a two-bit result γ{ 00,01,10,11 } , the uncorrected state at the signer’s end is | φ γ s = X x Z z |φ s .

The user sends γ to the signer, and the signer performs the corresponding Pauli operation U γ on s , causing s to collapse into |φ s : Z z X x | φ γ s = Z z X x X x Z z |φ s = e iθ |φ s .

Quantum One-Time Pad (QOTP): Suppose the message to be encrypted is a quantum state ρ M consisting of n qubits. The encryption algorithm is defined as En c a,b ( ρ M )= P a,b ρ M P a,b , where P a,b = i=1 n X i a i Z i b i , and a,b { 0,1 } n are uniformly random classical keys. Here, a i =1 applies the Pauli- X operator and b i =1 applies the Pauli- Z operator on the i -th qubit.

The decryption algorithm is De c a,b ( σ )= P a,b σ P a,b . Therefore, De c a,b ( En c a,b ( ρ M ) )= P a,b P a,b ρ M P a,b P a,b = ρ M .

Furthermore, QOTP provides perfect secrecy: 1 4 n a,b P a,b ρ M P a,b = I M 2 n , which holds for any input state ρ M .

3. Detailed Design of a Quantum Partially Blind Signature Scheme

The proposed scheme is characterized by the following features. First, the protocol adopts a partially blind message structure in which the private message is hidden from the signer while the agreed public information info remains visible and is explicitly bound to the corresponding session. Second, a globally unique session identifier sid and a one-time authorization value ω sid are introduced to bind identities, public information, temporal information, and verification labels to a unique protocol execution. Third, two independent evidence branches are generated during signing: direct-verification evidence Σ D and arbitration evidence Σ A , protected by independent session keys k D sid and k A sid , respectively. Finally, a temporal key-evolution and revocation mechanism is introduced to bind signing authority to a specific time period and support dynamic revocation.

Participants and Roles: The proposed quantum partial-blind signature scheme involves five types of participants: the PKG, User, Signer, Verifier, and Arbitrator.

PKG: The Private Key Generator (PKG) is responsible for key generation and management, EPR entangled state generation and distribution, as well as system parameter generation.

User: The user is the owner of the message to be signed and holds a conventional message awaiting signature. The identity information of the User is denoted as I D U .

Signer: The signer generates a signature for the User’s message. The identity information of the Signer is denoted as I D S , and the public information info is shared with the User.

Verifier: The verifier is the unique entity responsible for validating the signature and verifying its legitimacy and correctness.

Arbitrator: The arbitrator participates only when disputes regarding signature information occur. Under normal circumstances, the arbitration procedure is not invoked.

Session ID and Label: Each protocol execution uses a globally unique session ID ( sid { 0,1 } λ sid ), where λ sid is the length of the session ID. PKG ensures that the same sid is not reused. The complete information is: Ctx[ sid ]=( I D X ,info,n,T ) , where T represents the validity period for this authorization and verification, Ctx is a database record, and sid is the unique index for that record. I D X is the identity information of the participants.

PKG generates a one-time authorization number when approving a signature: ω sid s ( 0,1 ) λ ω . The protocol uses three short-purpose constants: AUTH, DIRECT, and ARBITRATION.

The authorization tag, direct verification tag, and arbitration tag are defined as follows:

L auth =Canon( sid, ω sid ,AUTH ), L D =Canon( sid, ω sid ,DIRECT ), L A =Canon( sid, ω sid ,ARBITRATION ). (1)

Canon denotes a normalized encoding function that is unambiguous.

The quantum authentication code is defined as Q Auth . Enc k ( ρ ) , Q Auth . Dec k ( Σ )=( f, ρ ) .

Where k denotes the one-time quantum authentication key, ρ is the quantum payload to be authenticated, and Σ is the authenticated quantum state after encoding. The variable f{ acc,rej } denotes the authentication result. When f=acc , ρ represents the recovered payload.

The security of the authentication scheme is characterized by the parameter ε auth , satisfying Pr[ f=acc ρ =ρ ] ε auth .

3.1. System Initialization Phase

(1) Parameter generation: PKG specifies the security parameters: λ=( λ sid , λ ω , S auth , ε auth , n max ) , where λ sid denotes the length of the session ID, λ ω denotes the length of the one-time authorization code, S auth denotes the size of quantum authentication redundancy or trap qubits, ε auth denotes the upper bound of the quantum authentication error acceptance probability, and n max denotes the maximum binary message length allowed by the system.

PKG selects a publicly available quantum authentication scheme: Q Auth =( Q Auth .Enc, Q Auth .Dec ) , and a normalized encoding rule: Canon( x 1 ,, x t ) .

The valid identity information of each participant is denoted as I D X , X{ U,S,V,A } .

Finally, PKG establishes a session database D sid for storing session keys.

(2) Participant identity registration: Each participant X{ U,S,V,A } submits identity verification information to the PKG. After successful verification, the PKG establishes an identity–key mapping: I D X k X , where I D X denotes the identity information of participant X , and k X denotes the corresponding one-time control key pool. The mapping information is stored securely in the PKG’s protected database.

(3) Establishing a session key based on identity:

1) Session establishment: The user, signer, and verifier submit their identities and public information to the PKG: I D U ,I D S ,I D V ,I D A ,info,n,T . The PKG verifies 1n n max , T>t , and checks whether the permissions for each identity are valid. Upon successful verification, a unique session ID is generated: sid { 0,1 } λ sid , ensuring that it does not duplicate any ID in the session database. The PKG records this information: Ctx[ sid ]=( I D U ,I D S ,I D V ,I D A ,info,n,T ) .

2) One-time control key: Based on the identities and the session, the PKG generates one-time quantum authentication keys: k PU R , k PS Req , k PS Auth , for subsequent processes.

Specifically, k PU R is used by the user to register with the PKG and freeze the blinding key; k PS Req is used by the signer to submit an authorization request to the PKG; k PS Auth is used by the PKG to send a one-time quantum authorization token to the signer.

These keys are all bound to sid , the sender’s and recipient’s identities, and the intended use, and are destroyed after this session

3) Entanglement resource initialization: Based on the security parameter λ , the PKG generates n independent sets of EPR entanglement pairs, where each pair is in a maximally entangled state: i=1 n | ϕ + U i S i = i=1 n 1 2 ( | 00+| 11 ) U i S i .

The PKG distributes the particle set S={ S 1 , S 2 ,, S n } to the signer and the particle set U={ U 1 , U 2 ,, U n } to the user, thereby establishing a shared quantum channel between them.

(4) Identity-Based Quantum Private Key Extraction: The signer sends its identity to the PKG. The temporal revocable-key model divides the system’s operational lifetime into a sequence of discrete time periods and assigns each signer mutually independent or unidirectionally evolving signing keys for different periods.

Let N denote the maximum number of signatures supported by the system. The corresponding set of time or state indices is defined as: T={ 1,2,,N } . For signer S , its identity is denoted as I D S . In the i -th time period, the signer holds a signing key s k S,i , iT , which is bound to its identity and time state. The corresponding key state is represented as: s t S,i =( I D S ,i,s k S,i ,statu s S,i ) , where statu s S,i denotes the valid state of the signer in the i -th time period. It can take the following values: statu s S,i { CREATED ,FROZEN,AUTHORIZED,SIGNED,DELIVERED, VERIFIED,DISPUTED,CLOSED, ABORTED }.

The time-period-related revocation list R L i records identities that no longer possess signing authority during the i -th time period and subsequent periods. If I D S R L i , the signer is revoked from the i -th time period, and the system no longer generates, extracts, or updates valid signing keys for this signer. For any ji , it holds that I D S R L j , which provides backward revocation and terminates the signing authority for future periods. For a non-revoked signer, the signing key is updated according to the time period: s k S,i+1 keyupd( s k S,i ,I D S ,i ) . After updating, the previous key is immediately deleted: Erase( s k S,i ) . The key update mechanism only supports forward evolution and prevents recovery of previous keys. Therefore, given the current key s k S,i , it is infeasible to derive any previous key s k S,j , j<i . During the i -th time period, the signer uses only the valid key s k S,i to generate a signature: σ i Sign( params,s k S,i ,I D S ,i,m ) . When verifying a signature, the verifier must simultaneously check the correctness of the signature, the validity of the time state, and the signer’s revocation status. The verification algorithm is denoted as: bVerify( params,I D S ,i,m, σ i ,R L i ), where b{ 0,1 } .

The verification algorithm outputs 1 if and only if all the following conditions are satisfied: I D S R L i , 1iN , and σ i is a valid signature generated by the valid key of the i -th time period. Otherwise, the verification algorithm outputs 0.

(5) Signing authorization request: The signer requests signing authorization from the PKG by sending its identity information I D S and the session identifier sid to the PKG. The PKG verifies whether the required conditions are satisfied, namely, whether the signer’s identity has been authenticated, whether the user has frozen the blinding key, and whether the current request has not expired. Once all conditions are satisfied, the PKG grants authorization and independently and randomly generates two session keys: k D sid =( e D , p D ) , k A sid =( e A , p A ) . The independence requirement is defined as follows: k A and k D are mutually independent Hilbert spaces, and ρ k A k D = ρ k A ρ k D . There exists no quantum operation that can recover k A sid from k D sid . Therefore, even if one key is compromised, the other key cannot be derived. The PKG distributes k D sid to the signer S and the verifier V , and distributes k A sid to the signer S and the arbitrator A . The PKG then generates a unique authorization serial number ω sid . The corresponding authorization content is defined as: Aut h sid =Canon( I D X ,sid,info,n, ω sid ) . Finally, the PKG updates the signer’s state as: statu s S,i =AUTHORIZED .

3.2. Blinding Phase

Assume that the message to be signed by the user is a private binary message msg={ ms g 1 ,ms g 2 ,,ms g i ,,ms g n } , ms g i { 0,1 } , with the agreed-upon public message info and the entangled-particle sequence U={ U 1 , U 2 ,, U n } , which is pre-shared through the PKG.

(1) The message is quantum-encoded and partially blinded. Specifically, only the private message msg is blinded, while the public information info remains unblinded. The user first uniformly and randomly generates a basis-selection string b=( b 1 , b 2 ,, b n ) $ { 0,1 } n , b i { 0,1 } , and an n -bit classical blinding-key string r=( r 1 , r 2 ,, r n ) $ { 0,1 } n , r i { 0,1 } . For each private message bit ms g i , the user first performs a logical blinding operation using the Pauli- X operator: X i r i | ms g i =| ms g i r i . The resulting logical bit is then encoded according to the basis-selection bit b i . Thus, the i th blinded message qubit is prepared as | ϕ i B = H i b i X i r i | ms g i = H i b i | ms g i r i , namely,

| ϕ i B ={ |0, ms g i r i =0, b i =0, |1, ms g i r i =1, b i =0, |+= 1 2 ( |0+|1 ), ms g i r i =0, b i =1, |= 1 2 ( |0|1 ), ms g i r i =1, b i =1. (2)

When b i =0 , the blinded logical bit is encoded in the computational, or Z , basis Z={ |0,|1 } ; when b i =1 , it is encoded in the Hadamard, or X , basis X={ |+,| } . Here, the symbol X i in the blinding operation denotes the Pauli- X operator, whereas X={ |+,| } denotes the Hadamard measurement basis.

Let | msg= i=1 n | ms g i , H b = i=1 n H i b i , X r = i=1 n X i r i , therefore, the complete partially blinded quantum message is

| m blind = i=1 n H i b i X i r i | ms g i = i=1 n H i b i | ms g i r i = H b X r | msg. (3)

It should be noted that, in H b X r | msg , the Pauli- X blinding operation X r acts first on the logical message bits, followed by the basis-encoding operation H b . Hence, for both b i =0 and b i =1 , the random bit r i effectively maps the logical message bit ms g i to ms g i r i .

To prevent the user from selecting a new blinding key or a new basis-selection string after obtaining the signature, the user must register the blinding information with the PKG before signing. The registration information is defined as R sid =Canon( sid,block,b,r ) . The user prepares the corresponding quantum state | R sid and encodes it as Γ R = Q Auth . Enc k PU R ( | R sid R sid | ) , which is then sent to the PKG.

Upon receiving Γ R , the PKG performs authentication decoding: ( f R , ρ R sid )= Q Auth . Dec k PU R ( Γ R ) . Only when f R =acc and the decoded registration information matches the current session does the PKG store Rec[ sid ].( b,r )=( b,r ) . From that point onward, the registered basis-selection string b and blinding-key string r are frozen and cannot be modified for the current session.

(2) Quantum Teleportation (Teleporting a Blinded State to the Signer): The user performs a joint Bell measurement on the transmitted state particle and the EPR particle. Taking a single particle as an example: let |ϕ m b i =α |0 m b i +β |1 m b i , and let the EPR state be | Φ + U i S i = 1 2 ( | 00+| 11 ) U i S i . At this point, the entire system can be described as:

| φ 0 m b i U i S i = |ϕ m b i | Φ + U i S i =( α |0 m b i +β |1 m b i ) 1 2 ( |0 U i |0 S i + |1 U i |1 S i ) = 1 2 ( α| 000+α| 011+β| 100+β| 111 ) m b i U i S i . (4)

Then, the user performs a CNOT operation and obtains | φ 1 :

| φ 1 m b i U i S i =( CNOTI ) | φ 0 m b i U i S i =( CNOTI ) 1 2 ( α| 000+α| 011+β| 100+β| 111 ) m b i U i S i = 1 2 ( α| 000+α| 011+β| 110+β| 101 ) m b i U i S i . (5)

The function of the H-Gate: H|0= 1 2 ( |0+|1 ) , H|1= 1 2 ( |0|1 ) ; User applies an H-gate to the first qubit, resulting in | φ 2 :

| φ 2 m b i U i S i =( HII ) | φ 1 m b i U i S i =( HII ) 1 2 ( α| 000+α| 011+β| 110+β| 101 ) m b i U i S i = 1 2 [ α 1 2 ( |0+|1 )( | 00+| 11 ) + β 1 2 ( |0|1 )( | 10+| 01 ) ] = 1 2 ( α| 000+α| 100+α| 011+α| 111 +β| 010β| 110+β| 001 β| 101 ) m b i U i S i . (6)

To make the measurement results easier to read, we rearrange | φ 2 to get:

| φ 2 m b i U i S i = 1 2 ( | 00 m b i U i ( α|0+β|1 ) S i + | 10 m b i U i ( α|0β|1 ) S i + | 01 m b i U i ( α|1+β|0 ) S i + | 11 m b i U i ( α|1β|0 ) S i ). (7)

Next, the user measures the two qubits in the computational basis { |0,|1 } . The four possible measurement outcomes and the corresponding recovery operations are summarized in Table 1.

Table 1. Correspondence between the user’s measurement outcomes and the signer’s quantum-state recovery operations.

Measurement outcome

Post-measurement state of S i

Recovery operation U γ

Probability

00

α|0+β|1

I

1/4

01

α|1+β|0

X

1/4

10

α|0β|1

Z

1/4

11

α|1β|0

ZX

1/4

The quantum circuit design is as shown in Figure 1:

Figure 1. Three-qubit simulation circuit for quantum teleportation.

U 3 ( θ,ϕ,λ )=[ cos θ 2 e iλ sin θ 2 e iϕ sin θ 2 e i( λ+ϕ ) cos θ 2 ] , assume that θ=π/2 , ϕ=0 , and λ=0 ; the three-Qubit measurement results are output as Figure 2:

Figure 2. Probability distribution of three-qubit measurement outcomes in the quantum teleportation circuit.

The simulator measures all three qubits and therefore reports eight three-bit outcomes, each occurring with an ideal probability of approximately 1/8. However, only the last two measured bits constitute the Bell-measurement outcome γ i =( x i , z i ) . By marginalizing over the receiver-qubit measurement result, the corresponding Bell-outcome probabilities are

P Bell ( 00 )=P( 000 )+P( 100 ), P Bell ( 01 )=P( 001 )+P( 101 ), P Bell ( 10 )=P( 010 )+P( 110 ), P Bell ( 11 )=P( 011 )+P( 111 ), (8)

which are all approximately 1/4 under ideal teleportation.

Table 2. Measurement probabilities corresponding to different Bell measurement outcomes.

Bell measurement outcome ( x,z )

Quantum state ( q 2 , q 1 , q 0 )

State probability

Measurement-outcome probability

00

| 000

0.1220703

0.2529296

| 100

0.1308593

01

| 001

0.1240234

0.2490234

| 101

0.1250000

10

| 010

0.1250000

0.2470703

| 110

0.1220703

11

| 011

0.1259765

0.2509765

| 111

0.1250000

The above results were obtained through online testing on the Origin Quantum platform, with the number of shots set to 1024. Table 2 presents the simulation results for the four possible Bell measurement outcomes. For each measurement outcome , the corresponding probability is obtained by summing the probabilities of the two associated computational-basis states. The resulting probabilities for the four outcomes are all close to the theoretical value of (1/4), indicating an approximately uniform distribution of the Bell measurement results.

The user performs a Bell-basis measurement on ( | m blind ,U ) and obtains a 2-bit classical result γ i =( x i , z i ) { 0,1 } 2 , γ i { 00,01,10,11 } , γ={ ( x 1 , z 1 ),,( x i , z i ),,( x n , z n ) } { 0,1 } 2n .

Then the user sends ( sid,γ,info ) to the signer via a classical channel; the signer can only retrieve the message info , but cannot access the original message msg or quantum state |msg to be signed.

In order to check whether the channel is secure, the user generates d decoy states randomly, selecting them from four sets of non-orthogonal states: |0 , |1 , |+= 1 2 ( |0+|1 ) , |= 1 2 ( |0|1 ) . From each group, X -basis and Z -basis states are randomly selected to prepare the quantum states. The detection bit is then sent to the signer through the quantum channel.

3.3. Signing Phase

After receiving the decoy states sent by the user, both the user and the signer randomly select the X basis or Z basis for measurement. All measurement bases and measurement outcomes are stored. Half of the measurement bases and their corresponding measurement results are randomly disclosed, and the average channel error rate e is calculated. Let e th denote the threshold. If e> e th , it is determined that an eavesdropping attack exists on the channel, and set statu s S,i =ABORTED ; otherwise, proceed with the subsequent signature operations.

Quantum collapse state: After the user performs the Bell-basis measurement, the particle S in the hands of the remote signer collapses, and its state is denoted as: | φ γ S i = U γ | m blind . If the signer performs the corresponding Pauli operation U γ on S i , where U γ = Z z i X x i , then

U γ | φ γ S i = Z z i X x i | φ γ S i = Z z i X x i X x i Z z i | m blind = e iθ | m blind . (9)

Since a global phase has no physical effect, this operation restores the blinded state: | m blind = U γ | φ γ S i .

Therefore, after receiving ( sid,γ,info ) , the signer performs the Bell correction to obtain | m blind . The signer only signs when the following conditions are met: , I D S R L i , and 1iN . The generated state signature is as follows:

σ i =En c s k S,i ( | m blind ,I D S ,i,sid ). (10)

The direct verification tag is L D =Canon( sid, ω sid ,i,DIRECT ) , the arbitration tag is L A =Canon( sid, ω sid ,i,ARBITRATION ) , and the signer prepares these as the computational basis quantum states: | L D ,| L A .

The direct verification payload is | W D = | m blind D | L D , with density operator ρ W D =| W D W D | ; and the signer computes

Σ D = Q Auth .En c k D sid ( ρ W D , σ i ). (11)

Σ D is the quantum signature evidence provided to the user and ultimately verified by the designated verifier. Execute statu s S,i =SIGNED , and share the temporal key s k S,i with the verifier after the signature is completed. This temporal key will immediately lose its signature capability after the signature is completed within the period, and can only be used for subsequent verification of the completed signature.

The arbitration payload is | W A = | m blind A | L A , and its density operator is ρ W A =| W A W A | . The signer computes Σ A = Q Auth .En c k A sid ( ρ W A , σ i ) ; Σ A must be delivered directly by the signer to the arbitrator and cannot be relayed through the user or verifier.

The signer sends Σ D U to the user, and the signer sends Σ A A to the arbitrator. The arbitrator only stores Σ A and the receipt time, without decoding it immediately.

After confirming that the arbitrator has received Σ A , PKG marks this session as signed.

Sign output: The user holds Σ D ; the arbitrator holds Σ A ; PKG stores ω sid , k D sid , k A sid , and the frozen ( b,r ) .

3.4. Verification Phase

The user sends the direct verification evidence Σ D to the designated verifier via quantum teleportation. To ensure that the verification input clearly corresponds to the message m , the user can additionally prepare a reference message state | M ref | msg and deliver it to the verifier via quantum teleportation. Since m is a classical binary string, preparing a reference state on a computational-basis state does not violate the no-cloning theorem.

The user sends an unblinding request Ope n sid =Canon( sid,OPEN ) to the PKG. After the PKG verifies the user’s identity, session status, and arbitration-evidence receipt record, it securely releases the data ( r,b, k D sid , ω sid ,Ctx[ sid ] ) to the designated verifier. At this stage, only the value of ( b,r ) frozen in the database prior to signing may be retrieved; the user cannot submit a new value ( b , r ) .

The unblinding output ( Σ D ,| M ref ,r, k D sid , ω sid ,Ctx[ sid ] ) is held by the verifier, who decodes it using a one-time direct verification key: ( f D , ρ W D , σ i )= Q Auth .De c k D sid ( Σ D ) . If f D =rej , the request is immediately rejected. If authentication succeeds, the verifier records the recovered payload as ρ W D =| m blind m blind || L D L D | , where | m blind is the recovered blinded-message register; | L D is the recovered direct-verification-tag register. σ i is the temporal signature obtained after decoding. The verifier performs decryption on σ i using the temporal key s k S,i shared with the signer:

De c s k S,i ( σ i )=De c s k S,i ( En c s k S,i ( | m blind ,I D S ,i,sid ) ) (12)

and obtains ( | m blind ,I D S , i ,si d ) . It then compares sid = ? si d ; if they are the same, verification continues; otherwise, the signature is declared invalid.

The verifier measures the tag register to obtain L D and computes L D exp =Canon( sid, ω sid ,i,DIRECT ) based on the values of sid and ω sid provided by the PKG. The verification condition is L D = L D exp . At the same time, the verifier checks the PKG’s immutable record: Ctx[ sid ]=( I D U ,I D S ,I D V ,I D A ,info,n,T ) , and confirms Ctx[ sid ].I D V =I D V , Ctx[ sid ].I D S =I D S , Ctx[ sid ].info=info , and Ctx[ sid ].T>t . This step enables the short tag to indirectly bind the complete public information through sid and ω sid .

Perform quantum unblinding: The verifier applies the inverse basis-encoding operation followed by the Pauli- X unblinding operation to the blinded-message register: | M = X r H b | m blind . Under honest conditions, | m blind = H b X r | msg . Therefore,

| M = X r H b | m blind = X r H b H b X r | msg = X r X r | msg =| msg. (13)

Then, the verifier performs the same unblinding operation on the blinded-message state | m blind recovered from the temporal protected payload: | M = X r H b | m blind . If the temporal protection is correct, then | m blind =| m blind = H b X r | msg . Hence,

| M = X r H b | m blind = X r H b H b X r | msg = X r X r | msg =| msg. (14)

The verifier can perform a quantum equality check without immediately measuring the complete message. It prepares two independent auxiliary registers, |0 C 1 n and |0 C 2 n , and executes the following sequence:

i=1 n CNOT M i C 1,i CNOT M ref,i C 1,i , i=1 n CNOT M ref,i C 2,i CNOT M i C 2,i . (15)

If | M =| M ref , then the auxiliary register C 1 retains the value |0 C 1 n . If | M ref =| M , then the auxiliary register C 2 retains the value |0 C 2 n . The auxiliary-register measurement result is defined as:

f M ={ 1, C 1 = 0 n and C 2 = 0 n , 0, otherwise. (16)

The final acceptance criterion is defined as follows: Accept[ f D =acc ][ L D = L D exp ][ f M =1 ][ Ctx[ sid ]valid ] . The verifier then declares the signature valid and sets statu s S,i =VERIFIED .

3.5. Arbitration Phase

When a user, signer, or verifier disputes the verification result, the arbitrator uses Σ A —which was submitted directly by the signer and stored during the signing phase—to render a decision.

The PKG securely releases ( r, k A sid , ω sid ,Ctx[ sid ] ) to the arbitrator. The arbitrator decodes the arbitration evidence as

( f A , ρ W A , σ i )= Q Auth .De c k A sid ( Σ A ). (17)

If f A =rej , the arbitration evidence is declared invalid. If authentication succeeds, the arbitrator recovers

ρ W A =| m blind m blind || L A L A |, (18)

where σ i is the temporal signature obtained after decoding.

The arbitrator decrypts σ i using the temporal key s k S,i shared with the signer:

De c s k S,i ( σ i )=De c s k S,i ( En c s k S,i ( | m blind ,I D S ,i,sid ) ) =( | m blind I D S , i ,si d ). (19)

The arbitrator then compares sid = ? si d . If the two session identifiers are equal, the arbitration procedure continues; otherwise, the signature is declared invalid.

Then, the arbitrator calculates the expected label L A exp =Canon( sid, ω sid ,i,ARBITRATION ) , and checks L A = L A exp , then performs unblinding: | M A = X r H b | m A , | M = X r H b | m blind . The arbitrator performs an equality check between | M A , | M , and the reference state | M dis of the disputed message. The condition for arbitration acceptance is Accept[ f A =acc ][ L A = L A exp ][ | M A =| M =| M dis ][ Ctx[ sid ]valid ] . Since Σ A is evidence sent directly by the signer to the arbitrator and protected by an independent key k A sid , neither the user nor the verifier can fabricate valid arbitration evidence by modifying or re-encoding Σ D . If the results of routine verification do not match the arbitration results, the protocol treats Σ A stored by the arbitrator as the official evidence of the dispute.

4. Security Analysis

In our security model, both the PKG and the arbitrator are assumed to be trusted and non-colluding entities; scenarios in which either the PKG or the arbitrator is fully compromised are outside the scope of this work.

4.1. Correctness Analysis

The correctness of the proposed scheme requires that, when all participants honestly follow the protocol and the quantum channels are ideal, a legitimately generated signature is accepted by the designated verifier.

The user’s original message is represented by the computational-basis state | msg . Before signing, the user randomly selects a basis-selection string b { 0,1 } n and a blinding key r { 0,1 } n , and performs the bitwise Pauli- X operation followed by the basis encoding, | m blind = H b X r | msg . During quantum teleportation, the user performs Bell-basis measurements and obtains the classical outcome γ=( ( x 1 , z 1 ),,( x n , z n ) ) .

After receiving γ , the signer applies U γ and obtains | m blind . The signer then generates the temporal signature σ i and constructs the direct-verification evidence Σ D . Under honest execution, quantum authentication decoding succeeds: ( f D , ρ W D , σ i )= Q Auth . Dec k D sid ( Σ D ) . Using the corresponding temporal key s k S,i , the verifier recovers ( | m blind ,I D S , i ,si d )=( | m blind ,I D S ,i,sid ) .

After the PKG releases the basis-selection string b and the blinding key r that were frozen before signing, the verifier performs unblinding:

| M = X r H b | m blind = X r H b H b X r | msg = X r X r | msg =| msg, (20)

and similarly, | M = X r H b | m blind =| msg .

Since the reference state satisfies | M ref =| msg , the message-consistency test yields | M =| M =| M ref . Therefore, every legitimately generated signature is accepted by the designated verifier, which establishes the correctness of the proposed scheme.

4.2. Non-Forgeability Analysis

If an attacker does not know k D sid or k A sid , the probability that an unauthorized modification to Σ D or Σ A is erroneously accepted is at most ε auth . Moreover, since the authorization tag is bound to the one-time values sid and ω sid , the attacker cannot transplant authentication evidence from another session into the current session.

If the verifier accepts a different payload m ˜ 1 msg , or a different tag L ˜ D L D , then the attacker has compromised the integrity of the quantum authentication code. Therefore,

Pr[ f D =acc( m ˜ 1 , L ˜ D )( m, L D ) ] ε auth . (21)

To forge a valid signature, an external attacker must generate direct verification evidence that can pass the verifier’s authentication procedure:

Σ D = Q Auth . Enc k D sid ( ρ W D , σ i ). (22)

Assume that the session key k D sid is a uniformly random classical key of length 2n . If the attacker has no information about this key, the probability of correctly guessing the entire key is

( 1 2 ) 2n = 1 2 2n , (23)

which decreases exponentially with n .

The temporal signature σ i is generated using the temporal signing key s k S,i :

σ i = Enc s k S,i ( | m blind ,I D S ,i,sid ). (24)

Assume that s k S,i is a uniformly random n -bit key. Without knowledge of the key, an attacker attempting to forge a temporal signature can guess each key bit correctly with probability 1/2. Consequently, the probability of correctly guessing the entire key is 1 2 n , which also decreases exponentially with n .

4.3. Non-Repudiation Analysis

(1) Non-repudiation of the signer

The signer’s non-repudiation is mainly guaranteed by the independent arbitration evidence Σ A . The evidence Σ A is generated by the signer during the signing phase and is delivered directly to the arbitrator for storage. Unlike the direct-verification evidence Σ D used for routine verification, Σ A is protected by the independent arbitration key k A sid and is not transmitted through either the user or the designated verifier. Therefore, other participants cannot replace or regenerate valid arbitration evidence.

The temporal signature contained in the arbitration evidence is record as σ i and the arbitration tag is defined as Ł A . The arbitration evidence is bound to the signer identity I D S , the session identifier sid , the time period i , the one-time authorization value ω sid , and the corresponding blinded message. Valid arbitration evidence generated in one authorized session cannot be transferred to another signer, time period, or session without causing the corresponding identity, session, or tag-consistency verification to fail.

Moreover, the blinding key r and the basis-selection string b is frozen by the PKG before the signing operation, and the corresponding session information is stored in the immutable record: Ctx[ sid ] . Therefore, after the signature has been generated, the signer cannot deny the completed signing operation by modifying the message, identity information, authorization information, or session parameters, since such a claim would be inconsistent with the arbitration evidence and the session record maintained by the PKG.

In addition, the arbitration key k A sid and the direct-verification key k D sid are independently generated, and k A sid is not disclosed to the user or the designated verifier. Therefore, neither the user nor the verifier can construct valid arbitration evidence Σ A from the direct-verification evidence Σ D . If an adversary modifies or forges Σ A without authorization and the forged evidence is nevertheless accepted, then the integrity of the underlying quantum authentication scheme has been compromised. Thus, Pr[ f A =acc( ρ ˜ W A , σ ˜ i )( ρ W A , σ i ) ] ε auth .

Therefore, under the assumptions that the PKG is trustworthy, the session record is immutable, and the arbitration key k A sid remains secret, once Σ A passes authentication and its identity, time-period, session, and message information are consistent with the system records, the signer cannot deny having completed the signature in the corresponding authorized session.

(2) Non-repudiation of the user

The user’s non-repudiation mainly ensures that the user cannot deny participation in the corresponding signing session or the blinding information submitted and frozen before signing. Before the signing operation begins, the user generates the blinding key r and the basis-selection string b , and registers R sid with the PKG. The PKG stores Rec[ sid ].( b,r )=( b,r ) only if authentication succeeds and the sid contained in the authenticated data matches the current session. Once this record has been established, the blinding key r and the basis-selection string b are frozen for the current session and cannot be replaced by different value b',r' after signing.

Since sid is a globally unique session identifier and Ctx[ sid ] records the user identity I D U together with the parameters of the corresponding session, the user identity, signing session, and frozen basis-selection string and blinding key are bound to the same session record. If the user later denies participation in the session or claims that a different basis-selection string b b or blinding key r r was used, such a claim will be inconsistent with the authenticated registration record stored by the PKG.

Furthermore, the corresponding blinded message is contained in the arbitration evidence. Under honest protocol execution, | m blind = H b X r | msg . Using the basis-selection string b and the blinding key r frozen by the PKG before signing, the original message can be recovered as X r H b | m blind =| msg . If the user attempts to replace the original blinding key with a different value r r after signing, then X r H b | m blind = X r H b H b X r | msg=| msgr r , which, in general, differs from the original message | msg . Therefore, the result cannot simultaneously satisfy the consistency requirements of the arbitration evidence and the frozen blinding information maintained by the PKG.

Moreover, if an adversary attempts to forge or modify the user’s blinding-key registration information, it must construct authenticated data without knowledge of k PU R . According to the security of the quantum authentication scheme, the probability that a forged or modified registration is nevertheless accepted satisfies Pr[ f R =acc R ˜ sid R sid ] ε auth .

Therefore, under the assumptions that the PKG is trustworthy, the session record is immutable, k PU R remains secret, and the blinding key r is correctly frozen before signing, the user cannot deny participation in the corresponding signing session or alter the signing result by replacing the blinding parameter after the signature has been generated.

4.4. Partial Blindness Analysis

Given public information info and two distinct private messages ms g 0 ms g 1 , corresponding to the quantum states | ms g 0 and | ms g 1 , the protocol satisfies partial blindness if the signer’s complete views for the two messages are indistinguishable, i.e., ρ ( ms g 0 |info ) = ρ ( ms g 1 |info ) .

User blindness and the Bell-measurement process: Let the private message quantum state be | msg= i=1 n | ms g i , ms g i { 0,1 } . Before signing, the user uniformly and randomly selects a basis-selection string b and a blinding-key string r . The user first performs the Pauli- X blinding operation on the logical message bits and then performs the basis encoding. Thus, | m blind = H b X r | msg .

For the ith message bit, | ϕ i B = H i b i X i r i | ms g i = H i b i | ms g i r i . When b i =0 , | ϕ i B =| ms g i r i , whereas when b i =1 , | ϕ i B = H i | ms g i r i . Hence, the random bit r i blinds the logical value before either encoding basis is applied.

Let U i and S i denote the user’s and signer’s entangled particles, respectively. The shared EPR state is | Φ + U i S i = 1 2 ( | 00+| 11 ) U i S i . The joint system is expressed as

|Ψ= | ϕ i B m U i | Φ + U i S i . (25)

The user performs the Bell-basis operations CNOT m U i U i and H m U i , where

CNOT|a|b=|a| ab, (26)

and

H|0= 1 2 ( |0+|1 ),H|1= 1 2 ( |0|1 ). (27)

For the ith qubit, the Bell-basis measurement produces the two-bit classical result γ i =( x i , z i ){ 00,01,10,11 } . For the complete n -qubit message, the Bell-measurement result is γ=( ( x 1 , z 1 ),,( x n , z n ) ) { 0,1 } 2n . Under ideal teleportation, the Bell-measurement outcomes are uniformly distributed and independent of the input state, and hence Pr[ γ ]= 1 4 n .

Quantum state received by the signer: According to the quantum teleportation protocol, the Bell-measurement result γ determines the Pauli correction

U γ = i=1 n Z i z i X i x i { I,X,Z,XZ } n . (28)

After receiving γ , the signer performs the corresponding correction and obtains U γ | φ γ | m blind = H b X r | msg , where denotes equality up to an irrelevant global phase.

Therefore, the blindness analysis must consider the signer’s state after the Bell-measurement result γ has been received and the corresponding correction has been completed. For any fixed basis-selection string b and Bell-measurement result γ , since the blinding-key string r is uniformly random and remains unknown to the signer, the density operator observed by the signer is

ρ( msg|b,γ )= 1 2 n r { 0,1 } n H b X r | msg msg| X r H b = H b [ 1 2 n r { 0,1 } n | msgr msgr| ] H b = H b I 2 n 2 n H b = I 2 n 2 n . (29)

For any two distinct private messages ms g 0 ms g 1 , we therefore have

ρ( ms g 0 |b,γ )= I 2 n 2 n ,ρ( ms g 1 |b,γ )= I 2 n 2 n . (30)

Consequently, ρ S ( ms g 0 |b,γ )= ρ S ( ms g 1 |b,γ ) .

The above result holds for every basis-selection string b and every Bell-measurement result γ . In particular, when b i =0 , the Pauli- X operation gives X i r i | ms g i =| ms g i r i . When b i =1 , the logical value is first blinded by X i r i and then encoded in the Hadamard basis: H i X i r i | ms g i = H i | ms g i r i . Thus, the logical message value is randomized by r i under either message-encoding basis.

Finally, the signer obtains not only the restored blinded quantum state, but also the Bell-measurement result γ and the public information info . Hence, the signer’s complete classical–quantum view can be written as

ρ( msg|b,info )= 1 4 n γ { 0,1 } 2n |γγ| I 2 n 2 n | info info|. (31)

Therefore, for any two distinct private messages ms g 0 and ms g 1 associated with the same public information info , ρ( ms g 0 |b,info )=ρ( ms g 1 |b,info ) . Hence, even after receiving the complete Bell-measurement result γ and restoring the blinded quantum state, the signer cannot distinguish the user’s private message, while the agreed public information info remains visible. Therefore, the proposed protocol satisfies partial blindness.

4.5. Resistance against Third-Party Attacks

Entangling-Probe Attack: The attacker Eve prepares a blank ancillary particle in the state |e and applies an interaction V satisfying

V|0|e=|0| e 00 +|1| e 01 ,V|1|e=|1| e 10 +|1| e 11 , (32)

where the ancillary vectors satisfy the unitarity condition V V=I. For uniformly distributed inputs in the Z basis, the induced error rate is

e Z = 1 2 ( e 01 | e 01 + e 10 | e 10 ). (33)

If the attacker introduces strictly zero errors in both the Z and X bases, then the attacker cannot obtain any information about the original bit. Zero error in the Z basis requires

V|0|e=|0| e 0 ,V|1|e=|1| e 1 . (34)

For |+= 1 2 ( |0+|1 ) , linearity gives: V|+|e= |0| e 0 +|1| e 1 2 . For

|0= 1 2 ( |++| ),|1= 1 2 ( |+| ), (35)

we obtain

V|+|e= 1 2 [ |+( | e 0 +| e 1 )+|( | e 0 | e 1 ) ]. (36)

If the interaction also introduces no error in the X basis, the coefficient of | must vanish. Hence, | e 0 =| e 1 | e . Consequently,

V|0|e=|0| e ,V|1|e=|1| e . (37)

For an arbitrary input state | ψ=α |0+β|1, it follows that

V|ψ|e=|ψ| e . (38)

Therefore, the state of the attacker’s ancillary system is independent of the input state, and Eve cannot obtain any information without introducing detectable errors.

Intercept-Measure-Resend Attack: Assume that an external attacker, Eve, intercepts particles transmitted to the user or the signer. Eve measures each intercepted particle and, according to the measurement outcome, prepares a new particle and sends it to the legitimate participant. Eve randomly selects either the Z basis or the X basis for measurement.

The channel-security test requires the insertion of decoy states. For a single decoy particle, the probability of detecting Eve is p det = 1 4 , whereas the probability that Eve escapes detection is p und = 3 4 . When d decoy particles are used, the probability that Eve is detected is

P det ( d )=1 ( 3 4 ) d . (39)

If Eve attacks each transmitted particle independently with probability η , then the probability that none of the d decoy particles reveals the attack is

P und ( d,η )= ( 1 η 4 ) d . (40)

Accordingly, the overall detection probability is

P det ( d,η )=1 ( 1 η 4 ) d . (41)

Therefore, the detection probability increases with both the attack ratio η and the number of decoy particles d .

4.6. Communication Resource Analysis

In terms of communication resource overhead, let n denote the length of the private message, and let q D and q A denote the lengths of the direct verification evidence and arbitration evidence, respectively. During one complete execution of the protocol, the blinded message US , the direct verification evidence SU and UV , the arbitration evidence SA , and the reference message UV are transmitted through quantum teleportation. Therefore, the total number of logical qubits to be teleported is Q=2n+2 q D + q A .

Since teleporting a q -qubit register requires q fresh EPR pairs and 2q authenticated classical bits for Bell-measurement correction, the total number of consumed EPR pairs is N EPR =Q , and the corresponding classical correction cost is q c tele =2( 2n+2 q D + q A ) .

Let d denote the number of decoy particles used for the quantum transmission, the total quantum and classical communication costs can be expressed as q t =3( 2n+2 q D + q A )+d+ q key , and q c =2( 2n+2 q D + q A )+L , respectively, where q key denotes the additional quantum resources required for key establishment, and L includes the session identifier, authorization information, participant identities, and other authenticated classical control data. The comparison analysis with existing schemes is illustrated in Table 3.

Table 3. Comparison of functionality and resource overhead with related schemes.

Scheme

Partial

blindness

Teleportation

Arbitration

Designated

verification

Temporal

protection

Signature

size q s

Quantum cost q t

Classical cost q c

Cai and Niu [24]

Yes

NR

No

No

No

NR

NR

NR

Zhong et al. [25]

Yes

No

No

No

No

NR

NR

NR

Xia et al. [45]

No

No

NR

No

No

n

27n

2n

Tan and Ye [46]

No

Yes

No

No

No

2n

30n

l+4n

Proposed scheme

Yes

Yes

Yes

Yes

Yes

q D + q A

3( 2n+2 q D + q A ) +d+ q key

2( 2n+2 q D + q A ) +L

Note: NR denotes that the corresponding quantity is not reported or is not directly comparable under a unified resource-counting convention.

5. Conclusions

This paper proposes an identity-based quantum partially blind signature scheme based on quantum teleportation. With the aid of a random bit string of length n , the user encodes binary information into a quantum state, blinds it according to the blinding key r , and keeps the public information info openly visible, thereby achieving the partially blind signature property.

The PKG is responsible for participant identity authentication, session establishment, blind-key freezing, signature authorization, and one-time session-key distribution, and implements key lifecycle management through a unique session identifier, validity period, and state records. Signers generate direct verification evidence for a designated verifier and independent arbitration evidence for an arbitrator, respectively; the relevant quantum information is transmitted via security-verified EPR entanglement resources and quantum teleportation.

Verifiers perform routine verification through quantum authentication decoding, tag verification, and message de-blinding; in the event of a dispute, the arbitrator renders a decision based on the quantum evidence independently preserved during the signing phase. Security analysis shows that, under conditions such as a trusted PKG and arbitrator, secure classical communication channels, an ideal random source, one-time session keys, and secure quantum authentication codes, this scheme can achieve security properties including correctness, partial blindness, forgery resistance, and non-repudiation, while also providing resistance to third-party attacks.

However, its security is based on information-theoretic security under explicit attack models and trust assumptions; at the same time, quantum labels, authentication-assisting qubits, and two-branch evidence also entail certain quantum resource and storage overheads.

Acknowledgements

We express our gratitude to all contributors who engaged in the discussion of this work. This work was supported by the Hunan Provincial Natural Science Foundation of China (GrantNos.2025JJ70445), the Joint Open Fund Project of “Hunan Provincial Science and Technology Innovation Team, Hunan Provincial Key Laboratory and Provincial Characteristic Discipline of Control Science and Engineering” (Grant NO.ZNKZN2024-4).

Author Contributions

Conceptualization, Juxiu Zhong and Rongbo Lu; methodology, Juxiu Zhong; validation, Juxiu Zhong, Rongbo Lu and Wei Li; writing-original draft preparation, Juxiu Zhong; writing-review and editing, Rongbo Lu and Wei Li. All authors have read and agreed to the published version of the manuscript.

Conflicts of Interest

The authors declare no conflicts of interest regarding the publication of this paper.

References

[1] Diffie, W. and Hellman, M.E. (1976) New Directions in Cryptography. IEEE Transactions on Information Theory, 22, 644-654.[CrossRef]
[2] Rivest, R.L., Shamir, A. and Adleman, L. (1978) A Method for Obtaining Digital Signatures and Public-Key Cryptosystems. Communications of the ACM, 21, 120-126.[CrossRef]
[3] Elgamal, T. (1985) A Public Key Cryptosystem and a Signature Scheme Based on Discrete Logarithms. IEEE Transactions on Information Theory, 31, 469-472.[CrossRef]
[4] Goldwasser, S., Micali, S. and Rivest, R.L. (1988) A Digital Signature Scheme Secure against Adaptive Chosen-Message Attacks. SIAM Journal on Computing, 17, 281-308.[CrossRef]
[5] Schnorr, C.P. (1991) Efficient Signature Generation by Smart Cards. Journal of Cryptology, 4, 161-174.[CrossRef]
[6] Boneh, D., Lynn, B. and Shacham, H. (2004) Short Signatures from the Weil Pairing. Journal of Cryptology, 17, 297-319.[CrossRef]
[7] Shor, P.W. (1997) Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer. SIAM Journal on Computing, 26, 1484-1509.[CrossRef]
[8] Thomas, M., Mathews, M.M., Panchami, V., et al. (2026) Securing the Future: A Comprehensive Review of Post-Quantum Digital Signatures. Computer Science Review, 61, Article 100935.[CrossRef]
[9] Shor, P.W. (1994) Algorithms for Quantum Computation: Discrete Logarithms and Factoring. Proceedings of the 35th Annual Symposium on Foundations of Computer Science, Santa Fe, 20-22 November 1994, 124-134.[CrossRef]
[10] Gottesman, D. and Chuang, I.L. (2001) Quantum Digital Signatures. arXiv:quant-ph/0105032.
https://arxiv.org/abs/quant-ph/0105032
[11] Chaum, D. (1983) Blind Signatures for Untraceable Payments. In: Advances in Cryptology, Springer US, 199-203.[CrossRef]
[12] Li, Q., Chan, W.H. and Long, D.Y. (2021) Quantum Blind Signature: Principles, Advances and Challenges. Physics Reports, 924, 1-47.
[13] Wen, X., Niu, X., Ji, L. and Tian, Y. (2009) A Weak Blind Signature Scheme Based on Quantum Cryptography. Optics Communications, 282, 666-669.[CrossRef]
[14] Wang, T.Y. and Wen, Q.Y. (2010) Fair Quantum Blind Signatures. Chinese Physics B, 19, Article 060307.[CrossRef]
[15] Su, Q., Huang, Z., Wen, Q.Y. and Li, W.M. (2010) Quantum Blind Signature Based on Two-State Vector Formalism. Optics Communications, 283, 4408-4410.[CrossRef]
[16] Xu, R., Huang, L., Yang, W. and He, L. (2011) Quantum Group Blind Signature Scheme without Entanglement. Optics Communications, 284, 3654-3658.[CrossRef]
[17] Chen, F.L., Wang, Z.H. and Hu, Y.M. (2019) A New Quantum Blind Signature Scheme with BB84-State. Entropy, 21, Article 336.[CrossRef] [PubMed]
[18] Luo, Q., Zhang, T., Huang, X. and Jing, N. (2022) Two Quantum Proxy Blind Signature Schemes Based on Controlled Quantum Teleportation. Entropy, 24, Article 1421.[CrossRef] [PubMed]
[19] Gupta, A., Chandra, G.V., Das, N. and Paul, G. (2024) An Efficient and Secure Quantum Blind Signature-Based Electronic Cash Transaction Scheme. IET Quantum Communication, 5, 619-631.[CrossRef]
[20] Wang, F., Yu, Y., Wei, Z., Zhao, T. and Wang, J. (2025) Quantum Blind Signature Protocol Based on Single Qubit Rotation. Optics Communications, 583, Article 131629.[CrossRef]
[21] Zhang, J.H., Wang, H., Xiao, W.E. and Huang, X. (2026) Cryptanalysis of the Quantum Blind Signature Scheme for Supply Chain Finance and Its Improvement. Advanced Quantum Technologies, 9, e00785.[CrossRef]
[22] Abe, M. and Fujisaki, E. (1996) How to Date Blind Signatures. In: Lecture Notes in Computer Science, Springer, 244-251.[CrossRef]
[23] Abe, M. and Okamoto, T. (2000) Provably Secure Partially Blind Signatures. In: Lecture Notes in Computer Science, Springer, 271-286.[CrossRef]
[24] Cai, X.Q. and Niu, H.F. (2012) Partially Blind Signatures Based on Quantum Cryptography. International Journal of Modern Physics B, 26, Article 1250163.[CrossRef]
[25] Zhong, J., Liao, B., Shi, Y. and Lu, R. (2022) A Quantum Partially Blind Signature Scheme without Entanglement. International Journal of Modern Physics B, 36, Article 2250128.[CrossRef]
[26] Katsumata, S., Lai, Y., LeGrow, J.T. and Qin, L. (2024) CSI-Otter: Isogeny-Based (Partially) Blind Signatures from the Class Group Action with a Twist. Designs, Codes and Cryptography, 92, 3587-3643.[CrossRef] [PubMed]
[27] Kuchta, V., LeGrow, J.T. and Persichetti, E. (2026) Post-Quantum (Partially) Blind Signatures from Matrix Code Equivalence. Cryptography and Communications.[CrossRef]
[28] Jia, X., He, D., Zeadally, S. and Li, L. (2017) Efficient Revocable Id-Based Signature with Cloud Revocation Server. IEEE Access, 5, 2945-2954.[CrossRef]
[29] Shamir, A. (1985) Identity-Based Cryptosystems and Signature Schemes. In: Lecture Notes in Computer Science, Springer, 47-53.[CrossRef]
[30] Chen, F.L., Liu, W.F., Chen, S.G. and Wang, Z.H. (2018) Public-Key Quantum Digital Signature Scheme with One-Time Pad Private-Key. Quantum Information Processing, 17, Article No. 10.[CrossRef]
[31] Xin, X., Wang, Z. and Yang, Q. (2020) Identity-Based Quantum Signature Based on Bell States. Optik, 200, Article 163388.[CrossRef]
[32] Xin, X., Wang, Z., Yang, Q. and Li, F. (2020) Efficient Identity-Based Public-Key Quantum Signature Scheme. International Journal of Modern Physics B, 34, Article 2050087.[CrossRef]
[33] Huang, Y., Xu, G. and Song, X. (2023) An Improved Efficient Identity-Based Quantum Signature Scheme. Quantum Information Processing, 22, Article No. 36.[CrossRef]
[34] Prajapat, S., Kumar, P., Kumar, S., Das, A.K., Shetty, S. and Hossain, M.S. (2024) Designing High-Performance Identity-Based Quantum Signature Protocol with Strong Security. IEEE Access, 12, 14647-14658.[CrossRef]
[35] Liu, B., Zhu, P. and Guo, K. (2024) A Secure and Efficient Identity-Based Quantum Signature Scheme. AIP Advances, 14, Article 065020.[CrossRef]
[36] Mohanty, T., Srivastava, V., Debnath, S.K., Roy, D., Sakurai, K. and Mukhopadhyay, S. (2025) An Experimentally Validated Feasible Quantum Protocol for Identity-Based Signature. Sādhanā, 50, 23.[CrossRef]
[37] Bennett, C.H., Brassard, G., Crépeau, C., Jozsa, R., Peres, A. and Wootters, W.K. (1993) Teleporting an Unknown Quantum State via Dual Classical and Einstein-Podolsky-Rosen Channels. Physical Review Letters, 70, 1895-1899.[CrossRef] [PubMed]
[38] Zeng, G.H. and Keitel, C.H. (2002) Arbitrated Quantum-Signature Scheme. Physical Review A, 65, Article 042312.[CrossRef]
[39] Wen, X.J., Liu, Y. and Sun, Y. (2007) Quantum Multi-Signature Protocol Based on Teleportation. Zeitschrift für Naturforschung A, 62, 147-151.[CrossRef]
[40] Zuo, H.J., Zhang, K.J. and Song, T.T. (2013) Security Analysis of Quantum Multi-Signature Protocol Based on Teleportation. Quantum Information Processing, 12, 2343-2353.[CrossRef]
[41] Feng, Y., Shi, R., Shi, J., Zhou, J. and Guo, Y. (2019) Arbitrated Quantum Signature Scheme with Quantum Walk-Based Teleportation. Quantum Information Processing, 18, Article No. 154.[CrossRef]
[42] Lu, D., Li, Z., Yu, J. and Han, Z. (2022) A Verifiable Arbitrated Quantum Signature Scheme Based on Controlled Quantum Teleportation. Entropy, 24, Article 111.[CrossRef] [PubMed]
[43] Singh, S., Rajput, N.K., Rathi, V.K., Pandey, H.M., Jaiswal, A.K. and Tiwari, P. (2023) Securing Blockchain Transactions Using Quantum Teleportation and Quantum Digital Signature. Neural Processing Letters, 55, 3827-3842.[CrossRef]
[44] Zhao, W., Wang, F.Q., Mao, Y.Y., Zhong, H., et al. (2023) Teleportation-Based Continuous-Variable Quantum Digital Signature. Results in Physics, 53, Article 107018.[CrossRef]
[45] Xia, C., Li, H. and Hu, J. (2021) A Semi-Quantum Blind Signature Protocol Based on Five-Particle GHZ State. The European Physical Journal Plus, 136, Article No. 633.[CrossRef]
[46] Tan, X. and Ye, T.Y. (2024) Semiquantum Proxy Blind Signature Based on Quantum Teleportation. Scientia Sinica Physica, Mechanica & Astronomica, 54, Article 230313.[CrossRef]

Copyright © 2026 by authors and Scientific Research Publishing Inc.

Creative Commons License

This work and the related PDF file are licensed under a Creative Commons Attribution 4.0 International License.