Papers for

quantum cryptography engineers

Papers whose findings have a practical use for this group, as judged from the abstract. Open a paper to read what it means in practice.

Quantum proof systems with fewer messages achieve perfect correctness

Achieving perfect completeness for one- and two-message quantum proof systems

Abstract: While quantum interactive proof systems using at least three messages can achieve perfect completeness, as shown by Kitaev and Watrous (STOC 2000), whether perfect completeness is achievable for one- and two-message quantum proof systems has remained open. For the one-message case, whether $\sf QMA$ can achieve perfect completeness was posed as an open problem in Watrous (FOCS 2000) and Aharonov and Naveh (2002); for the two-message case, the corresponding problems were (implicitly) posed in Jain, Upadhyay, and Watrous~(FOCS 2009) and Kobayashi, Le Gall, and Nishimura (SICOMP, 2019). In this work, we establish that ${\sf QIP}(2)$, ${\rm qq}\text{-}{\sf QAM}$, $\sf QAM$, and $\sf QMA$ can achieve perfect completeness. Here ${\rm qq}\text{-}{\sf QAM}$ denotes the class of promise problems admitting two-message quantum-public-coin quantum interactive proof systems in which the verifier's only message consists of half-EPR pairs. Our main technical contributions are the follows: 1. For $\sf QMA$ (and directly for $\sf QAM$), an exactly constructible block-encoded matrix whose kernel certifies yes instances, constructed from the acceptance operator induced by the verification circuit. 2. For ${\sf QIP}(2)$ (and implicitly ${\rm qq}\text{-}{\sf QAM}$), a new turn-halving transformation that preserves completeness and ensures that the resulting proof system retains at least two messages, provided that the terminal state before the final measurement is efficiently preparable.

Mon 14 SeptComputational Complexity
The gist
Quantum proof systems help verify complex problems by exchanging messages between a prover and a verifier. Until now, it was unknown if systems with only one or two messages could always be perfectly certain when accepting correct answers. The authors show that these simpler systems can indeed achieve perfect correctness, meaning they never wrongly reject true cases. They use new mathematical constructions and transformations to prove this for several classes of quantum proof systems.
Open 2609.15926v1

Quantum pseudorandom states differ fundamentally from pseudorandom unitaries

Derivatives of Quantum Randomness: Separating Pseudorandom Unitaries from Pseudorandom (Function-like) States

Abstract: Quantum computation gives rise to new pseudorandom primitives for states and unitaries, including pseudorandom state generators (PRSGs), pseudorandom function-like state generators (PRFSGs), and pseudorandom unitaries (PRUs). In this paper, we show a full unitary oracle separation between PRFSGs and PRUs. The separation holds between the strongest state notion and the weakest unitary notion: even adaptively secure, quantum-accessible PRFSGs do not imply non-adaptively secure, forward-only PRUs, even when their implementations are allowed to be non-unitary and use an arbitrary number of ancillary qubits. This reveals a fundamental distinction between pseudorandomness for quantum states and for quantum unitaries. Our main technical idea is to view a candidate PRU construction with access to state generation oracles as a map from the underlying oracle states to implemented unitaries, and to study the derivatives of this map. These derivatives are inherently low rank, and we exploit this low-rank structure to distinguish the resulting unitaries from truly random ones. We believe this differential perspective may be useful for studying other structural questions about quantum states and unitaries.

Sun 13 SeptCryptography and Security
The gist
Quantum computers can create special random-like objects called pseudorandom states and pseudorandom unitaries, which are important for cryptography and computing. This paper finds that the strongest forms of pseudorandomness for quantum states do not automatically give you the simplest forms of pseudorandomness for quantum unitaries, even if you have a lot of extra resources. The authors use a new idea of studying changes (derivatives) in how these quantum operations work to prove this difference. This shows a basic separation between two kinds of quantum pseudorandomness that was not clear before.
Open 2609.14626v1