Tightness of the mixed time–space term for one-way states

Determine whether the mixed term \(\sqrt{ST}/N\) in the timespace security bound for recovering the key from a random binary phase state is tight, and establish whether barriers analogous to those in the classical preprocessing setting obstruct identifying the correct dependence.

Background

The paper proves that a quantum adversary with SS qubits of advice and TT random-oracle queries recovers the key of a random binary phase state with probability at most O((T2+1+S(T+1))/N)O((T^2+1+\sqrt{S(T+1)})/N) in the regime K=NK=N. The term involving S(T+1)\sqrt{S(T+1)} captures the interaction between preprocessing space and online queries, while the T2T^2 term corresponds to the online-query contribution. The authors note that the bound is tight when either the advice is absent or the adversary makes no online queries, but the tightness of the mixed term remains unresolved. They also connect this issue to classical timespace tradeoffs, where sharpening analogous bounds would have implications for circuit lower bounds.

References

Whether the mixed term $\frac{\sqrt{ST}}{N}$ is tight remains an open problem; in particular, it would be interesting to understand whether there are barriers (like in the classical setting ) to identifying this term.

— Time-space lower bounds for breaking quantum cryptography  (2610.02101 - Dong et al., 1 Oct 2026) in Section 1, subsection “Our Results,” paragraph beginning “For our first result”