Search papers, labs, and topics across Lattice.
This paper introduces ledger authenticators and the $\LAEUF$ unforgeability experiment for reactive authorization protocols, which enhance public ledger security by integrating finalized transcripts into the authentication process. By separating authentication safety from ledger liveness, the authors address critical issues such as censorship and adversarial ordering while establishing resource boundaries for secure transactions. The findings include a joint ledger and quantum random oracle execution model that proves a specific bound for secure operations, demonstrating the framework's robustness in a multi-user environment.
Quantum state persistence across classical finalization cuts reveals new vulnerabilities in ledger authentication that could lead to forgery if not properly managed.
Public ledgers increasingly authorize state transitions using prior transactions, finalized state, timing, and ordering rather than only a public key, message, and portable signature. We introduce ledger authenticators and $\LAEUF$, an unforgeability experiment for reactive authorization protocols whose public judgment algorithm reads a finalized transcript. The model separates authentication safety from ledger liveness and captures canonical transition freshness, adaptive corruption, exposure before inclusion, censorship, and adversarial ordering. We identify two conditional resource boundaries. An authenticator satisfying our single event conditions yields a contextual one-time signature. Within our rebindable reveal class, safety requires computational post-disclosure non-admissibility. When precursor admission uses only public computation and ledger scheduling, this condition is enforced by closing the evidence eligible to use a disclosed credential. If newly constructed evidence remains admissible after disclosure, censoring the honest reveal gives a forgery. We then define a joint ledger and quantum random oracle execution model in which quantum state persists across classical finalization cuts and oracle evaluations made through the ledger are charged. For a closed finalized target set of size at most $K$, we prove the bound $3\beta_{\mathsf{cut}}^2+3c_{\mathsf{co}}KQ^2/2^\lambda+6\ell/2^\lambda$, where $\beta_{\mathsf{cut}}$ accounts for fresh openings already present at the cut. A commit, close, reveal authenticator instantiates the framework and obtains a multi-user lifetime QROM bound.