Quantum bit escrow

Uncondit ionally secure bit commi tmen t and coin flipping are known to be impossible in the classical world. Bit commitment is known to be impossible also in the quan tum world. We introduce a related new primitive quantum bit escrow. In this primitive Alice commits to a bit b to Bob. The commi tment is bindingin the sense tha t if Alice is asked to reveal the bit, Alice can not bias her commi tmen t wi thout having a good probability of being detected cheating. The commitment is sealing in the sense tha t if Bob learns information about the encoded bit, then if later on he is asked to prove he was playing honestly, he is detected cheating with a good probability. Rigorously proving the correctness of quan tum cryptographic protocols has proved to be a difficult task. We develop techniques to prove quant i ta t ive s ta tements about the binding and sealing propert ies of the quan tum bit escrow protocol. A related primitive we construct is a quan tum biased coin flipping protocol where no player can control the game, i.e., even an all-powerful cheating player must lose with some constant probability, which stands in sharp contrast to the classical world where such protocols are impossible.