Pith. sign in

REVIEW 2 major objections 3 minor 89 references

Quantum One-Way Functions and Related Cryptographic Primitives

T0 review · 2 major / 3 minor · reviewed 2026-08-08 · deepseek-v4-flash

Pith's one-line read Quantum one-wayness is not one primitive but a spectrum of state-based constructions whose security depends on how many copies an adversary receives.

desk verdict A useful and mostly sound review that deserves refereeing; the coherent-state section has a genuine scaling typo in Eq. (15), but the intended result survives. read the letter →

arxiv 2608.05754 v1 pith:IW5IYINE submitted 2026-08-06 quant-ph cs.CRmath-phmath.MP

classification quant-phcs.CRmath-phmath.MP MSC 81P6881P4594A60 PACS 03.67.Dd03.67.-a
keywords quantumone-wayfunctionsstategeneratorspseudorandomstatesEFIpairsweakcoherentbounded-copysecuritycryptographyinformation-theoreticone-wayness
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This review tries to establish that quantum one-wayness is not a single primitive but a spectrum of state-based constructions—quantum one-way functions, one-way state generators, pseudorandom quantum states, and efficiently indistinguishable state pairs—that differ in the adversarial model, the number of accessible copies, and the physical basis of their security. It argues that information-theoretic one-wayness can hold only in bounded-copy regimes, whereas security against polynomially many copies requires computational assumptions, and it organizes the primitives into the conceptual hierarchy pseudorandom-state generator $\Rightarrow$ one-way state generator $\Rightarrow$ computational quantum one-way function. The review further argues that the path toward practical quantum cryptography should run through simple, physically realizable state families, in particular phase-encoded weak coherent states, which in the effective-qubit regime recover the logarithmic Holevo bound $\log_2(c+1)$ on accessible information. A sympathetic reader would take away that security definitions should be matched to what near-term optical hardware can actually prepare and verify.

What carries the argument

The central mechanism is the symmetric subspace of $c$ identical copies of a finite-dimensional state: for qubits it has dimension $c+1$, which yields the Holevo bound $I_{\mathrm{acc}} \le \log_2(c+1)$ and the exact-label recovery bound $\Pr[\mathrm{succ}] \le (c+1)/2^n$. The review transfers this mechanism to continuous variables by truncating each coherent state to its vacuum and single-photon sector, so that under $\sqrt{c}\,\mu \ll 1$ the state behaves as an effective qubit; the paper bounds the trace-distance error of this truncation and then uses an entropy-continuity inequality to convert that closeness into a bound on the entropy of the average state, giving the $\log_2(c+1)$ scaling.

What would settle it

Compute the exact trace distance between $c$ copies of the true coherent state and $c$ copies of its truncated effective qubit at parameters near $\sqrt{c}\,\mu \approx 1$ (for example $\mu=0.01$, $c=10^4$) and compare with the paper's estimate $\mathcal{O}(\sqrt{c}\,\mu)$. If the distance is not small in that regime, or if the entropy of the true average state exceeds $\log_2(c+1)$ by a non-negligible amount, the claim that weak coherent states recover the logarithmic Holevo bound fails.

Watch

Extended reading notes

Core claim

The central claim is that the relations among QOWFs, OWSGs, PRSGs, and EFI pairs are complementary security regimes rather than interchangeable definitions. In the bounded-copy information-theoretic model, one-wayness is enforced by physical limits: non-orthogonal states cannot be perfectly discriminated, measurement disturbs the state, and $c$ copies of a qubit state live in a symmetric subspace of dimension $c+1$, so the Holevo-accessible information is at most $\log_2(c+1)$ and exact-label recovery succeeds with probability at most $(c+1)/2^n$. Against adversaries with polynomially many copies, these limits no longer suffice—shadow tomography yields a generic attack on information-theoretic OWSG security—so OWSGs, PRSGs, and EFI pairs must rely on computational hardness, and the review states the hierarchy PRSG $\Rightarrow$ OWSG $\Rightarrow$ computational QOWF. For coherent states, the paper's own analysis claims that in the weak-photon regime $\sqrt{c}\,\mu \ll 1$ the ensemble behaves as an effective qubit ensemble, recovering the same logarithmic copy scaling and making coherent states the most experimentally accessible candidate family for quantum one-wayness.

Load-bearing premise

That the multiphoton sector of weak coherent states can be neglected when $\sqrt{c}\,\mu \ll 1$, so that the state behaves as an effective qubit and the accessible information is governed by the $\log_2(c+1)$ symmetric-subspace bound; the paper's trace-distance estimate for this approximation is the fragile step.

Editorial extensions

If this is right

  • Information-theoretically secure quantum one-way functions exist in the bounded-copy regime from quantum limits alone (conjugate coding, quantum fingerprints, single-qubit rotations), and their security degrades as the number of copies grows.
  • Against polynomially many copies, quantum one-wayness requires computational assumptions: shadow tomography provides a generic attack on information-theoretic OWSG security, and unconditionally secure OWSGs would imply a major complexity separation.
  • The conceptual hierarchy PRSG $\Rightarrow$ OWSG $\Rightarrow$ computational QOWF holds, with the converse implications generally false.
  • Weak coherent states, already used in QKD-style hardware, are the most promising near-term platform for QOWFs, provided the adversary's copy count stays in the regime $\sqrt{c}\,\mu \ll 1$.
  • Verification by fidelity threshold requires ensembles whose maximum pairwise fidelity is bounded away from 1; constructions with arbitrarily close neighboring states need protocol-level verification instead.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the paper's trace-distance scaling is corrected, the effective-qubit regime for coherent-state QOWFs may be narrower than stated, so proposed protocol parameters should be re-derived from the exact distance rather than from the approximate bound.
  • The same symmetric-subspace logic should extend to other phase-invariant continuous-variable ensembles (for instance squeezed or thermal states), suggesting a general principle: copy-limited one-wayness arises whenever the accessible states effectively live in a finite-dimensional subspace.
  • Bounded-copy security connects naturally to noisy- and bounded-storage models, where hardware constraints on stored quantum states turn the copy restriction into a physical resource.
  • The noise sensitivity of pseudorandom quantum states suggests that indistinguishability from Haar-random states is a poor target for photonic implementations; bounded-copy hiding based on simple states may be the more realistic near-term goal.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

2 major / 3 minor

Summary. This paper is a topical review of quantum one-way functions and related quantum-state primitives. It develops a common framework for classical-to-quantum QOWFs with two inversion objectives (exact-label recovery and fidelity-threshold approximate inversion) and two adversarial models (computational QPT adversaries and bounded-copy information-theoretic adversaries). It then reviews representative constructions, including conjugate coding, quantum fingerprints, single-qubit rotations, and phase-encoded coherent states, and connects them to OWSGs, EFI pairs, PRSGs, quantum t-designs, quantum money, PUFs/QPUFs, and post-quantum cryptography. The central thesis is that these primitives form a complementary spectrum whose security depends on the number of available copies and on whether the hardness is information-theoretic or computational, and that practical progress requires simple, robust, physically realizable state families with context-dependent security guarantees.

Significance. The review's contribution is synthetic and pedagogical rather than a new set of theorems. Its strengths are the explicit separation of exact-label recovery from preimage resistance, the systematic comparison of QOWFs/OWSGs/EFI/PRSGs with a summary table, the candid treatment of the gap between complexity-theoretic primitives and experimental feasibility, and the useful appendix material on symmetric subspaces and trace-distance operational interpretations. If the technical illustrations are corrected, this will be a valuable reference for physics-oriented readers. However, the main technical derivation in Section 3.2.4 contains a scaling error and an unjustified truncation step, so the review needs revision before publication.

major comments (2)
  1. [§3.2.4, Eq. (15)] The small-µ expansion in Eq. (15) is incorrect. Since |⟨ϕ_x|ψ_x⟩|² = (1+µ)e^{−µ}, the exact c-copy trace norm is 2√(1−(1+µ)^c e^{−cµ}) ≈ √(2c) µ, not √(2cµ). The same correction propagates to Eq. (16), which should read D ≲ √(c/2) µ, and to the error term D log₂ c in Eq. (18). This is not cosmetic: under the stated condition √c µ ≪ 1, the printed formula with c=100 and µ=0.01 gives D≈0.7, while the exact value is ≈0.07, so the claimed small trace-distance approximation would fail. The exact expression supports the intended effective-qubit conclusion, so I view this as a correctable error, but the formula, its validity condition, and the constants in Eq. (18) must be fixed.
  2. [§3.2.4, Eqs. (17)–(18) and footnote 7] The Audenaert–Fannes step is not justified as written. The inequality in Eq. (17) requires both states to live in the same d-dimensional Hilbert space, but the actual state ρ̄^{(c)} is supported on the infinite-dimensional symmetric subspace of (H∞)^{⊗c}, while σ̄^{(c)} is supported on the c+1-dimensional qubit symmetric subspace. Footnote 7 says the multiphoton components 'can be ignored,' but ignoring them changes the state, and the trace-distance bound of Eqs. (15)–(16) does not by itself control the entropy of the discarded component. Even after correcting the scaling in Eq. (15), Eq. (18)'s bound S(ρ̄^{(c)}) ≲ log₂(c+1) + D log₂ c + h₂(D) therefore needs an explicit projection/truncation argument, with finite-c constants stated. The block structure of the phase-averaged coherent state should make such an argument straightforward, but the manuscript should provide it rather than relying on the current footnote.
minor comments (3)
  1. [Appendix D, Eq. (30)] The displayed bound Σ_n √(P(µ,n)P(µ,n+qN)) ≤ e^{−µ}(eµ/(qN))^{qN} is too strong; the n=0 term alone is approximately e^{−µ}√(P(µ,qN)), which for µ=0.01 and N=100 exceeds the claimed right-hand side. The qualitative conclusion that the discrete phase average is close to the fully dephased state is plausible, but this inequality should be rederived or replaced by a correct tail bound.
  2. [§3.2.1] The sentence claiming that 'the optimal single-qubit measurements yield the optimal probability of recovering the entire string' appears before the commuting structure of ρ₀ and ρ₁ is explained; since the product structure alone does not rule out collective measurements, the argument would be clearer if the simultaneous diagonalizability in the Breidbart basis were invoked immediately.
  3. [§4, Eq. (24)] Equation (24) is presented as the c-copy average state for the coherent-state construction, but it is derived from the truncated effective-qubit approximation of Eq. (14), not from the exact coherent-state ensemble; an explicit reminder in the text near Eq. (24) would prevent readers from mistaking it for the exact average state.

Circularity Check

0 steps flagged · score 0.0 of 10

No circular derivation: the review's central comparisons are supported by in-line derivations and external published results; self-citations are exemplary, not load-bearing.

full rationale

I walked the paper's derivation chain. Definitions 1-2 set up an inversion game, and the one-wayness claims for Constructions 1-4 are obtained by explicit calculations (Helstrom discrimination, the symmetric-subspace dimension D_sym = c+1, Holevo and accessible-information bounds, fidelity and trace-distance estimates), not by assuming the target conclusion. In Construction 4 (Sec. 3.2.4), the effective-qubit approximation is derived rather than presupposed: Eq. (14) defines the truncated state, Eq. (15) gives the exact trace-distance expression 2 sqrt(1 - ((1+mu)e^{-mu})^c), and Eqs. (16)-(18) use it to bound S(rho_bar^(c)). The printed asymptotic approximation 'approximately sqrt(2 c mu)' in Eq. (15) is a genuine scaling typo: the small-mu expansion is sqrt(2c) mu. This is a correctness defect, not a circular step, and the exact expression supports the intended log(c+1) leading scaling. Self-citations to [38], [39], and [41] are used to point to applications (single-qubit QOWFs, quantum public-key encryption, weak-coherent-state key exchange) and are not inputs to the review's central comparisons or taxonomy. Claims about the impossibility of information-theoretic OWSGs with many copies and the PRSG => OWSG hierarchy are attributed to external works [42], [44], [65]; no fitted parameter is renamed as a prediction, and no uniqueness theorem or ansatz is imported from the author's prior work. The review is therefore self-contained against external benchmarks and contains no circular derivation chain.

Assumptions & free parameters 0 free parameters · 6 assumptions · 0 invented entities

The review introduces no new fitted parameters or invented entities. Its technical derivations rely on standard quantum information theorems (Holevo bound, no-cloning, trace-distance operational interpretation, symmetric subspace dimension) and on external hardness assumptions from the surveyed literature, such as the conjectured difficulty of graph automorphism and of approximating boson-sampling amplitudes. The original coherent-state analysis in Section 3.2.4 assumes a truncated two-level approximation in the weak-photon regime, a technical assumption stated explicitly.

assumptions (6)
  • standard math Holevo bound: at most log2(d) bits of classical information can be extracted per copy of a d-dimensional quantum state.
    Used throughout Section 3.2 to argue information-theoretic one-wayness from limited accessible information.
  • standard math No-cloning theorem and quantum measurement disturbance.
    Foundational physical principles invoked in Section 3.1 to motivate QOWF security.
  • standard math Uniform ensemble of 2^n states in a D-dimensional subspace has average exact-label recovery probability at most D/2^n.
    Used in Section 3.2.3 for the single-qubit construction; stated without proof in the paper.
  • domain assumption Graph Automorphism is not solvable in quantum polynomial time (conjecture).
    Basis for the hardness of the Kawachi et al. EFI-like pair in Section 5.
  • domain assumption Existence of post-quantum secure pseudorandom functions.
    Used in Section 6.3 as the basis for PRSG constructions, e.g., by Ji-Liu-Song and follow-ups.
  • domain assumption Average-case hardness of computing or approximating permanents underlying boson sampling.
    Security foundation for boson-sampling-based OWFs in Section 7.3.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Quantum One-Way Functions and Related Cryptographic Primitives." pith.science (2026). https://pith.science/paper/IW5IYINE

@misc{pith2026260805754,
  author       = {Pith},
  title        = {Pith review of: Quantum One-Way Functions and Related Cryptographic Primitives},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/IW5IYINE}},
  note         = {Machine review of arXiv:2608.05754}
}
read the original abstract

Quantum cryptographic primitives beyond key distribution remain a less well understood area of research. In classical cryptography, one-way functions underpin nearly all standard cryptographic protocols, motivating the search for meaningful quantum analogues and for a clear understanding of the physical and computational mechanisms that could enforce one-wayness. In this article, we review quantum one-way functions and a range of closely related quantum-state primitives, including one-way state generators, pseudorandom quantum states, and efficiently indistinguishable pairs of states. We discuss both computational and information-theoretic notions of quantum one-wayness, emphasizing the different adversarial models and security assumptions that underlie these constructions. We compare and contrast the various proposed primitives, and clarify their conceptual relationships. Particular emphasis is placed on questions of physical realizability, experimental feasibility, and robustness to noise. Finally, we outline open problems and future directions toward the development of practical quantum cryptographic primitives beyond key distribution, and the emergence of a broader quantum-cryptographic ecosystem.

Figures

Figures reproduced from arXiv: 2608.05754 by the authors.

Figure 1
Figure 1. Schematic comparison of injective and non-injective mappings in the classical and quantum settings. In the quantum case, the shaded regions represent states with finite operational overlap; distinct labels may therefore correspond to distinct, but nonorthogonal states. assumptions. Since the present review discusses constructions originating from both the cryptographic and quantum-information communities, it is usef… view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

89 extracted references · 63 canonical work pages

  1. [2]

    Scarani V, Bechmann-Pasquinucci H, Cerf N J, Duˇ sek M, L¨ utkenhaus N and Peev M 2009 Rev. Mod. Phys.81(3) 1301–1350 URL https://link.aps.org/doi/10.1103/RevModPhys.81.1301

  2. [3]

    Lo H K, Curty M and Tamaki K 2014Nature Photonics8595–604 URL https://doi.org/10.1038/nphoton.2014.149

  3. [4]

    Diamanti E, Lo H K, Qi B and Yuan Z 2016npj Quantum Information216025 URL https://doi.org/10.1038/npjqi.2016.25

  4. [5]

    Xu F, Ma X, Zhang Q, Lo H K and Pan J W 2020Rev. Mod. Phys.92(2) 025002 URL https://link.aps.org/doi/10.1103/RevModPhys.92.025002

  5. [6]

    Bozzio M, Cr´ epeau C, Wallden P and Walther P 2025Rev. Mod. Phys.97(4) 045006 URL https://link.aps.org/doi/10.1103/p84v-1xqv

  6. [7]

    Surv.57ISSN 0360-0300 URLhttps://doi.org/10.1145/3730575

    Dervisevic E, Tankovic A, Fazel E, Kompella R, Fazio P, Voznak M and Mehic M 2025ACM Comput. Surv.57ISSN 0360-0300 URLhttps://doi.org/10.1145/3730575

  7. [8]

    Nielsen M A and Chuang I L 2000Quantum Computation and Quantum Information (Cambridge, England: Cambridge University Press) ISBN 978-0-521-63503-5

  8. [9]

    Wolf R 2021Quantum Key Distribution: An Introduction with Exercises(Lecture Notes in Physicsvol 988) (Springer, Cham) ISBN 978-3-030-73990-4 URL https://doi.org/10.1007/978-3-030-73991-1

Show all 89 references
  1. [10]

    Goldreich O 2001Foundations of Cryptography, Volume 1: Basic Techniques(Cambridge University Press)

  2. [11]

    Goldreich O 2004Foundations of Cryptography, Volume 2: Basic Applications(Cambridge University Press)

  3. [12]

    Gottesman D and Chuang I 2001 Quantum digital signatures arXiv:quant-ph/0105032 (Preprintquant-ph/0105032) URLhttps://arxiv.org/abs/quant-ph/0105032

  4. [13]

    Morimae T and Yamakawa T 2024 One-wayness in quantum cryptography19th Conference on the Theory of Quantum Computation, Communication and Cryptography (TQC 2024)(Leibniz International Proceedings in Informatics (LIPIcs)vol 310) pp 4:1–4:24 arXiv:2210.03394v3

  5. [14]

    Ji Z, Liu Y K and Song F 2018 Pseudorandom quantum statesAdvances in Cryptology – CRYPTO 2018(Lecture Notes in Computer Sciencevol 10992) (Springer) pp 126–152 (Preprint1711.00385)

  6. [15]

    Kawachi T, Koyama K, Nishimura H and Yamakami T 2013Journal of Cryptology26448–479

  7. [16]

    Accessed: June 2026

    Microcrypt zoohttps://sattath.github.io/microcrypt-zoo/maintained by Or Sattath and contributors. Accessed: June 2026

  8. [17]

    H ˚ astad J, Impagliazzo R, Levin L A and Luby M 1999SIAM Journal on Computing28 1364–1396

  9. [18]

    Katz J and Lindell Y 2020Introduction to Modern Cryptography3rd ed (CRC Press)

  10. [19]

    Shor P W 1997SIAM Journal on Computing261484–1509 39 IOP PublishingJournalvv(yyyy) aaaaaa Authoret al

  11. [20]

    Goldreich O and Levin L 1989 A hard-core predicate for all one-way functionsProceedings of the 21st ACM Symposium on Theory of Computing (STOC)pp 25–32

  12. [21]

    Barnett S M 2009Quantum InformationOxford Master Series in Physics (Oxford: Oxford University Press) ISBN 9780198527633

  13. [22]

    Barnett S M and Croke S 2009Advances in Optics and Photonics1238–278

  14. [23]

    Nikolopoulos G M 2025American Journal of Physics93566–573 URL https://doi.org/10.1119/5.0268023

  15. [24]

    Holevo A S 1973Problems of Information Transmission9177–183 english translation

  16. [25]

    Wootters W K and Zurek W H 1982Nature299802–803 URL https://link.springer.com/article/10.1007/sxxxx

  17. [26]

    Buhrman H, Cleve R, Watrous J and de Wolf R 2001Physical Review Letters87167902 URL https://doi.org/10.1103/PhysRevLett.87.167902

  18. [27]

    Nikolopoulos G M and Ioannou L M 2009Physical Review A79042327

  19. [28]

    Khurana D and Tomer K 2023 Commitments from quantum one-wayness arXiv:quant-ph/2310.11526 (Preprint2310.11526)

  20. [29]

    Barenco A, Bennett C H, Cleve R, DiVincenzo D P, Margolus N, Shor P, Sleator T, Smolin J A and Weinfurter H 1995Physical Review A523457–3467

  21. [30]

    Montanaro A 2016npj Quantum Information215023

  22. [31]

    Gisin N, Ribordy G, Tittel W and Zbinden H 2002Reviews of Modern Physics74145–195 URLhttps://doi.org/10.1103/RevModPhys.74.145

  23. [32]

    Broadbent A and Schaffner C 2016Designs, Codes and Cryptography78351–382 URL https://link.springer.com/article/10.1007/s10623-015-0157-4

  24. [33]

    Bozzio M, Cr´ epeau C, Wallden P and Walther P 2024arXiv preprint arXiv:2411.08877 Submitted 13 November 2024; revised 31 August 2025 (Preprint2411.08877)

  25. [34]

    Wiesner S 1983SIGACT News1578–88

  26. [35]

    Bennett C H and Brassard G 1984 Quantum cryptography: Public key distribution and coin tossingProceedings of the IEEE International Conference on Computers, Systems and Signal Processing(Bangalore, India: IEEE) pp 175–179 the original BB84 paper

  27. [36]

    Bozzio M, Orieux A, Trigo Vidarte L, Zaquine I, Kerenidis I and Diamanti E 2018npj Quantum Information45 open Access URLhttps://doi.org/10.1038/s41534-018-0058-2

  28. [37]

    Amiri R and Andersson E 2015Entropy175635–5659 URL https://doi.org/10.3390/e17085635

  29. [38]

    Nikolopoulos G M 2008Physical Review A77032348

  30. [39]

    Seyfarth U, Nikolopoulos G M and Alber G 2012Physical Review A85022342

  31. [40]

    Audenaert K M R 2007Journal of Physics A: Mathematical and Theoretical408127–8136

  32. [41]

    Nikolopoulos G M 2025APL Quantum2016107 see also arXiv:2501.09568

  33. [42]

    Morimae T and Yamakawa T 2022 Quantum commitments and signatures without one-way functionsAdvances in Cryptology – CRYPTO 2022 – Part I(Lecture Notes in Computer Sciencevol 13507) ed Dodis Y and Shrimpton T (Heidelberg: Springer) pp 269–295

  34. [43]

    Cao S and Xue R 2022 On constructing one-way quantum state generators, and more Cryptology ePrint Archive, Paper 2022/1323 URLhttps://eprint.iacr.org/2022/1323

  35. [44]

    Cavalar B P, Goldin E, Gray M, Hall P, Liu Y and Pelecanos A 2025Quantum91679

  36. [45]

    Aaronson S 2020SIAM Journal on Computing49STOC18–368–STOC18–394 URL https://doi.org/10.1137/18M120275X 40 IOP PublishingJournalvv(yyyy) aaaaaa Authoret al

  37. [46]

    Aaronson S and Christiano P 2012 Quantum money from hidden subspacesProceedings of the 44th Annual ACM Symposium on Theory of Computing (STOC)(ACM) pp 41–60 URL https://doi.org/10.1145/2213977.2213983

  38. [47]

    Ben-David S and Sattath O 2023Quantum71120 URLhttps://arxiv.org/abs/1609.09047

  39. [48]

    Coladangelo A, Liu J, Liu Q and Zhandry M 2021 Hidden cosets and applications to unclonable cryptographyAdvances in Cryptology – CRYPTO 2021ed Malkin T and Peikert C (Cham: Springer International Publishing) pp 556–584 ISBN 978-3-030-84242-0

  40. [49]

    Zhandry M 2021Journal of Cryptology346

  41. [50]

    Zhandry M 2020 Unclonable pseudorandom functionsEUROCRYPT 2020(LNCSvol 12107) (Springer) pp 109–138

  42. [51]

    Coladangelo A, Majenz C and Zhandry M 2023 Quantum lightning and signatures from isogeniesTheory of Cryptography Conference (TCC) 2023Lecture Notes in Computer Science (Springer) URLhttps://doi.org/10.1007/978-3-031-49503-8_18

  43. [52]

    Goldreich O 1990Information Processing Letters34277–281

  44. [53]

    Brakerski Z, Canetti R and Qian L 2023 On the computational hardness needed for quantum cryptography14th Innovations in Theoretical Computer Science Conference (ITCS 2023) (Leibniz International Proceedings in Informatics (LIPIcs)vol 251) pp 24:1–24:24

  45. [54]

    Khurana D and Tomer K 2023 Commitments from quantum one-wayness Cryptology ePrint Archive, Paper 2023/1620 URLhttps://eprint.iacr.org/2023/1620

  46. [55]

    Malavolta G, Morimae T, Walter M and Yamakawa T 2024 Exponential quantum one-wayness and efi pairsSecurity and Cryptography for Networksed Galdi C and Phan D H (Cham: Springer Nature Switzerland) pp 121–138 ISBN 978-3-031-71070-4

  47. [56]

    Ambainis A and Emerson J 2007 Quantum t-designs: t-wise independence in the quantum worldProceedings of the Twenty-Second Annual IEEE Conference on Computational Complexity (CCC 2007)(IEEE Computer Society) pp 129–140

  48. [57]

    Dankert C, Cleve R, Emerson J and Livine E 2009Physical Review A80012304

  49. [58]

    Brand˜ ao F G S L, Harrow A W and Horodecki M 2016Physical Review Letters116170502 URLhttps://link.aps.org/doi/10.1103/PhysRevLett.116.170502

  50. [59]

    Cleve R, Leung D, Liu L and Wang C 2016Quantum Information & Computation16721–756

  51. [60]

    Nakata Y, Hirche C, Morgan C and Winter A 2017Journal of Mathematical Physics58 052203 URLhttps://doi.org/10.1063/1.4983266

  52. [61]

    O’Donnell R, Servedio R A and Paredes P 2023arXiv preprint(Preprint2310.13597) URL https://arxiv.org/abs/2310.13597

  53. [62]

    Brakerski Z and Shmueli O 2019 (pseudo)random quantum states with binary phaseTheory of Cryptography Conference (TCC 2019), Part I(Lecture Notes in Computer Sciencevol 11891) ed Hofheinz D and Rosen A (Heidelberg: Springer) pp 229–250 (Preprint1904.07939)

  54. [63]

    Brakerski Z and Shmueli O 2020 Scalable pseudorandom quantum statesAdvances in Cryptology – CRYPTO 2020, Part II(Lecture Notes in Computer Sciencevol 12171) ed Micciancio D and Ristenpart T (Heidelberg: Springer) pp 417–440 (Preprint2003.09447)

  55. [64]

    Bansal N, Mok W K, Bharti K, Koh D E and Haug T 2025PRX Quantum6(2) 020322 URL https://link.aps.org/doi/10.1103/PRXQuantum.6.020322

  56. [65]

    Kretschmer W 2021 Quantum pseudorandomness and classical complexity16th Conference on the Theory of Quantum Computation, Communication and Cryptography (TQC 2021)(Leibniz International Proceedings in Informatics (LIPIcs)vol 197) ed Hsieh M H (Dagstuhl, Germany: Schloss Dagstuh...

  57. [66]

    Adleman L M, DeMarrais J and Huang M D 1997SIAM Journal on Computing261524–1540 41 IOP PublishingJournalvv(yyyy) aaaaaa Authoret al

  58. [67]

    Behera A and Paul G 2018Quantum Information Processing17URL https://link.springer.com/article/10.1007/s11128-018-1965-z

  59. [68]

    Shang T, Tang Y, Chen R and Liu J 2020Quantum Engineering2e32 URL https://onlinelibrary.wiley.com/doi/abs/10.1002/que2.32

  60. [69]

    Aaronson S and Arkhipov A 2013Theory of Computing9143–252

  61. [70]

    Lund A P, Bremner M J and Ralph T C 2017npj Quantum Information315

  62. [71]

    Wang H, He Y, Li Y, Su Z E, Li B, Huang H L, Ding X, Chen M C, Chen C, Zhu J, Lu C Y and Pan J W 2020Nature Photonics14273–284

  63. [72]

    Nikolopoulos G M and Brougham T 2016Physical Review A94012315

  64. [73]

    Nikolopoulos G M 2019Quantum Information Processing18259

  65. [74]

    Wang X W, Zhou W H, Fu Y X, Gao J, Lu Y H, Chang Y J, Qiao L F, Ren R J, Jiang Z K, Jiao Z Q, Nikolopoulos G M and Jin X M 2023Phys. Rev. Lett.130(6) 060802 URL https://link.aps.org/doi/10.1103/PhysRevLett.130.060802

  66. [75]

    Nikolopoulos G M 2023Physica Scripta98014001

  67. [76]

    Pappu R, Recht B, Taylor J and Gershenfeld N 2002Science2972026–2030

  68. [77]

    McGrath T, Bagci I E, Wang Z, Roedig U and Young R J 2019Applied Physics Reviews6 011303

  69. [78]

    Gao Y, Al-Sarawi S F and Abbott D 2020Nature Electronics381–91

  70. [79]

    R¨ uhrmair U 2022Journal of Cryptographic Engineering12387–412 URL https://doi.org/10.1007/s13389-021-00283-6

  71. [80]

    Klausen M, Zhang J and Stevens M M 2025Advanced Materials372502059 URL https://advanced.onlinelibrary.wiley.com/doi/abs/10.1002/adma.202502059

  72. [81]

    Arapinis M, Delavar M, Doosti M and Kashefi E 2021Quantum5475 URL https://doi.org/10.22331/q-2021-06-15-475

  73. [82]

    Farr´ e P J, Galetsky V, Belhassen M, Pieplow G, Nilesh K, Boche H, Schr¨ oder T, N¨ otzel J and Deppe C 2025arXivabs/2508.09296URLhttps://arxiv.org/abs/2508.09296

  74. [83]

    ˇSkori´ c B 2010 Quantum readout of physical unclonable functionsProgress in Cryptology – AFRICACRYPT 2010ed Bernstein D J and Lange T (Berlin, Heidelberg: Springer Berlin Heidelberg) pp 369–386 ISBN 978-3-642-12678-9

  75. [84]

    Goorden S A, Horstmann M, Mosk A P, ˇSkori´ c B and Pinkse P W H 2014Optica1421–424 URLhttps://doi.org/10.1364/OPTICA.1.000421

  76. [85]

    Nikolopoulos G M and Diamanti E 2017Scientific Reports746047 URL https://doi.org/10.1038/srep46047

  77. [86]

    Damg ˚ ard I, Fehr S, Salvail L and Schaffner C 2005 Cryptography in the bounded-quantum-storage modelProceedings of the 46th Annual IEEE Symposium on Foundations of Computer Science (FOCS 2005)(IEEE Computer Society) pp 449–458

  78. [87]

    Wehner S, Schaffner C and Terhal B M 2008Physical Review Letters100220502

  79. [88]

    Haug T, Bharti K and Koh D E 2025Quantum91759 URL https://quantum-journal.org/papers/q-2025-06-04-1759/

  80. [89]

    Hayden P, Leung D and Winter A 2006Communications in Mathematical Physics26595–117

  81. [90]

    Mele A A 2024Quantum81340 URLhttps://doi.org/10.22331/q-2024-05-08-1340 42

Pith tools

Reviewed August 8, 2026 · model on record in the stance chip above.