Papers
Topics
Authors
Recent
Search
2000 character limit reached

Pseudorandom Function-like State Generators (PRFSGs)

Updated 14 July 2026
  • PRFSGs are keyed quantum state generators that, for each classical input, output quantum states nearly indistinguishable from independently sampled Haar-random states.
  • They support a range of security models—from selective to adaptive, classically and quantumly accessible—highlighting their cryptographic robustness.
  • Constructed using pseudorandom states, post-quantum one-way functions, and Haar random oracles, PRFSGs underpin encryption, authentication, and commitment protocols.

Pseudorandom function-like state generators (PRFSGs), also called pseudorandom function-like states (PRFS) generators, are keyed quantum state generators that take a classical input xx and output a quantum state G(k,x)G(k,x) such that the resulting state family is computationally indistinguishable from a family of independently sampled Haar-random states. They are the quantum analogue of pseudorandom functions, but with state-valued outputs rather than bitstrings. The literature studies several security variants—selective, adaptive, classically accessible, and quantumly accessible—and places PRFSGs at a central point in the landscape of quantum pseudorandomness, where they connect pseudorandom quantum states, pseudorandom unitaries, quantum pseudorandom generators, and several cryptographic applications including encryption, commitments, and message authentication (Ananth et al., 2023).

1. Definition and basic formalism

The foundational formulation treats a PRFSG as a QPT algorithm with a classical secret key and a classical point input, producing an n(λ)n(\lambda)-qubit quantum state. In the selectively secure form, for all polynomials q()q(\cdot) and t()t(\cdot), any non-uniform QPT distinguisher AA, and any family of pairwise distinct inputs

(x1,,xq(λ)){0,1}m(λ),(x_1,\dots,x_{q(\lambda)}) \in \{0,1\}^{m(\lambda)},

there exists a negligible function ν()\nu(\cdot) such that

Prk{0,1}λ[A(x1,,xq,G(k,x1)t,,G(k,xq)t)=1]Prψ1,,ψqHn[A(x1,,xq,ψ1t,,ψqt)=1]ν(λ).\Bigg\lvert \Pr_{k\leftarrow \{0,1\}^{\lambda}} \Big[ A\big(x_1,\dots,x_q,\,G(k,x_1)^{\otimes t},\dots,G(k,x_q)^{\otimes t}\big)=1 \Big] - \Pr_{\ket{\psi_1},\dots,\ket{\psi_q}\leftarrow H_n} \Big[ A\big(x_1,\dots,x_q,\,\ket{\psi_1}^{\otimes t},\dots,\ket{\psi_q}^{\otimes t}\big)=1 \Big] \Bigg\rvert \le \nu(\lambda).

Here the reference distribution is qq independent Haar-random G(k,x)G(k,x)0-qubit states, and the distinguisher receives G(k,x)G(k,x)1 copies of each queried output. The notion is selective because the queried points must be fixed and pairwise distinct in advance (Ananth et al., 2023).

This formalization generalizes pseudorandom state generators (PRSGs) by adding an input label. A PRS generator can be viewed as the special case with no input, while a PRFSG is “function-like” in the same way that a classical pseudorandom function generalizes a pseudorandom generator. The original PRFS formulation also emphasized that outputs may be pure states, or in some constructions only satisfy recognizable abort, where the output has the form

G(k,x)G(k,x)2

with G(k,x)G(k,x)3 a known abort state (Ananth et al., 2021).

A useful structural property proved for PRFS generators is that outputs indexed by different labels are nearly orthogonal on average, while outputs on the same label are nearly pure on average. Concretely, for G(k,x)G(k,x)4,

G(k,x)G(k,x)5

and

G(k,x)G(k,x)6

which is obtained using a SWAP-test argument against the Haar ideal (Ananth et al., 2021).

2. Security variants and query models

The literature distinguishes several PRFSG security notions that differ mainly in how the adversary accesses the input interface.

Variant Query model Characteristic feature
Selective security Classical inputs fixed in advance Distinct queried points chosen before the experiment
APRFS / classically-accessible adaptive security Adaptive classical queries Input register is measured in the computational basis
Quantumly-accessible adaptive security Coherent superposition queries Oracle must support coherent query access

The selectively secure notion was the starting point, and the literature explicitly notes that it follows the standard selective-security style used to avoid impossible adaptive self-query attacks against state-valued outputs (Ananth et al., 2023). In this model, repeated querying of the same classical point can be used to obtain multiple copies.

Adaptive classically-accessible notions were later formalized under the name APRFS. In this setting, the adversary may choose each query based on the prior transcript, but the query register is measured in the computational basis, so superposition access is disallowed. The ideal oracle returns an independently sampled Haar-random state for each fresh classical input, consistent across repeated queries to the same input (Ananth et al., 2024).

The strongest standard version is the quantumly-accessible adaptively-secure PRFSG, in which the generator must support coherent query access of the form

G(k,x)G(k,x)7

Its security experiment compares oracle access to G(k,x)G(k,x)8 against an ideal oracle that, for each G(k,x)G(k,x)9, samples an independent Haar-random state n(λ)n(\lambda)0, while allowing the adversary to query quantumly and adaptively (Gulati et al., 6 Oct 2025).

This taxonomy is operationally significant. A recurring misconception is to treat classically-accessible adaptive security as nearly equivalent to quantum-accessible security. The literature does not support that identification: some constructions are secure against any polynomial number of classical queries yet admit explicit quantum-accessible attacks (Hhan et al., 2024).

3. Constructions and existence results

The earliest construction route derived PRFSGs from pseudorandom states. If n(λ)n(\lambda)1 and n(λ)n(\lambda)2, then a n(λ)n(\lambda)3-qubit PRS generator yields a n(λ)n(\lambda)4-PRFS generator with recognizable abort. The construction writes a PRS state as

n(λ)n(\lambda)5

and then repeatedly measures the first n(λ)n(\lambda)6 qubits until the desired prefix n(λ)n(\lambda)7 appears, outputting the residual n(λ)n(\lambda)8-qubit state (Ananth et al., 2021).

A second route uses post-quantum one-way functions. Adaptive classically-accessible PRFSGs can be obtained by composing a post-quantum PRF n(λ)n(\lambda)9 with a PRS generator q()q(\cdot)0, setting q()q(\cdot)1 and outputting q()q(\cdot)2. Stronger quantumly-accessible adaptive variants were then shown feasible from post-quantum one-way functions as well, including constructions based on binary-phase PRS and, separately, constructions from pseudorandom unitaries (Ananth et al., 2022).

Idealized Haar-oracle models provide particularly simple constructions. In the inverseless quantum Haar random oracle model q()q(\cdot)3, the one-query generator

q()q(\cdot)4

is proved to be an APRFS generator when q()q(\cdot)5. The construction uses a single Haar-oracle call, and the analysis relies on the path-recording formalism and a prefix collision-free path-recording oracle tailored to function-like state generation (Ananth et al., 2024).

In the invertible QHRO model, where all parties access a common Haar-random unitary q()q(\cdot)6 and its inverse, an Even–Mansour-style wrapper gives a classically-accessible adaptively secure PRFSG: q()q(\cdot)7 If an adversary makes q()q(\cdot)8 classical PRFSG queries and q()q(\cdot)9 quantum queries to t()t(\cdot)0 and/or t()t(\cdot)1, the distinguishing advantage is bounded by

t()t(\cdot)2

where t()t(\cdot)3. Since t()t(\cdot)4 is exponential in t()t(\cdot)5, this is negligible for polynomially bounded t()t(\cdot)6 and t()t(\cdot)7 (Hhan et al., 2024).

A more recent line studies scalability. An isometric procedure based on recursive Beta-distributed amplitude splitting and random phase injection yields scalable PRS, and from this the first construction of scalable and quantum-accessible adaptive PRFS from quantum-secure one-way functions. The construction is explicitly isometric and introduces no entanglement or correlations with the environment, which is the property used to extend scalable PRS to adaptive PRFS (Batra et al., 30 Jul 2025).

4. Relation to PRFs, PRSGs, PRUs, PRIs, QPRFs, and UPSGs

PRFSGs are explicitly positioned as the quantum analogue of pseudorandom functions: a classical PRF outputs bits or strings, while a PRFSG outputs quantum states indexed by a classical input. They also generalize PRSGs, since fixing an input recovers a single state family. In this sense, PRSGs are the “single-state” special case of PRFSGs (Ananth et al., 2021).

At the level of stronger quantum pseudorandom primitives, the established implication chain is

t()t(\cdot)8

A pseudorandom unitary yields a pseudorandom isometry by applying it to t()t(\cdot)9, and a pseudorandom isometry yields a PRFSG by applying the isometry to basis states or embedding the input coherently. The converse implications remain unknown in general, and later black-box impossibility results show that the reverse implications fail in important regimes (Gulati et al., 6 Oct 2025).

The relation to classical-output pseudorandomness is more indirect. One major theorem shows that logarithmic-output PRFSGs imply selectively secure QPRFs. Assuming selectively secure AA0-PRFS for some constant AA1 and AA2, there exists a selectively secure QPRF

AA3

with pseudodeterminism AA4 and output length AA5. The construction applies the PRFSG on several independent keys, runs a pseudodeterministic extractor on polynomially many copies of each output state, and XORs the resulting bitstrings (Ananth et al., 2023).

The literature also compares PRFSGs with unpredictable state generators (UPSGs). PRFSs imply UPSGs, but the converse is explicitly open. The known applications of PRFSs considered in that work—IND-CPA-secure secret-key encryption, MACs with unclonable tags, private-key quantum money, OWSGs, and EFIs—are all shown achievable from UPSGs as well. This suggests that, for many applications, unpredictability may suffice even where full pseudorandomness is unavailable (Morimae et al., 2024).

A plausible implication is that PRFSGs occupy an intermediate position: stronger than bare PRSGs because of their function-like indexing, but weaker than transformation-level notions such as PRUs and PRIs, whose outputs must preserve unitary or isometric structure on arbitrary quantum inputs.

5. Cryptographic applications

The original motivation for PRFSGs was cryptographic. From PRFS generators, one obtains statistically binding and computationally hiding commitments and pseudo one-time encryption schemes; the commitment construction further implies maliciously secure multiparty computation protocols in the dishonest majority setting. The same framework also yields CPA-secure symmetric-key quantum encryption and reusable MACs, using a tester that checks consistency of a candidate state with AA6 (Ananth et al., 2021).

Logarithmic-output PRFSGs support a different type of “dequantized” application through QPRFs. The resulting QPRFs yield non-adaptive CPA-secure private-key encryption with classical ciphertexts, via

AA7

Correctness is proved by majority vote and pseudodeterminism, while security follows by a hybrid argument that replaces QPRF outputs by independent random strings. This establishes the chain

AA8

and shows that state-valued pseudorandomness can support classical-communication cryptography (Ananth et al., 2023).

Adaptive PRFSGs in idealized Haar-unitary models inherit the standard application suite associated with PRFSGs. The invertible-QHRO construction is presented as implying IND-CPA secret-key encryption and EUF-CMA message authentication codes, and via known reductions also private-key quantum money, commitments, multi-party computation, bounded-poly-time secure signatures, and one-way state-like primitives (Hhan et al., 2024).

The literature on logarithmic-output PRFS also shows that commitment and encryption schemes with classical communication can be obtained using verifiable tomography. In that setting, the low output dimension is essential because tomography remains polynomial-time only when the state dimension is polynomially bounded in the security parameter (Ananth et al., 2022).

6. Separations, limits, and open directions

A central theme in the modern theory of PRFSGs is that quantum pseudorandom notions do not appear to collapse to a single primitive in the way classical PRGs and PRFs do. The sharpest formal evidence comes from black-box separations. There are no black-box constructions of non-adaptive AA9-ancilla PRUs from PRFSGs, and no black-box constructions of (x1,,xq(λ)){0,1}m(λ),(x_1,\dots,x_{q(\lambda)}) \in \{0,1\}^{m(\lambda)},0-ancilla PRIs with (x1,,xq(λ)){0,1}m(λ),(x_1,\dots,x_{q(\lambda)}) \in \{0,1\}^{m(\lambda)},1 stretch from PRFSGs. The corresponding oracle separation produces a world in which quantumly-accessible adaptively-secure PRFSGs exist relative to (x1,,xq(λ)){0,1}m(λ),(x_1,\dots,x_{q(\lambda)}) \in \{0,1\}^{m(\lambda)},2 and (x1,,xq(λ)){0,1}m(λ),(x_1,\dots,x_{q(\lambda)}) \in \{0,1\}^{m(\lambda)},3, but non-adaptive (x1,,xq(λ)){0,1}m(λ),(x_1,\dots,x_{q(\lambda)}) \in \{0,1\}^{m(\lambda)},4-ancilla PRUs do not (Gulati et al., 6 Oct 2025).

The proof technology behind these separations is itself notable. The adversary uses process tomography, a UnitaryPSPACE-complete oracle, and especially quantum singular value transformation via singular value discrimination to implement a projector that distinguishes the PRU candidate from Haar randomness. This establishes that the gap between PRFSGs and stronger unitary or isometric notions is not merely definitional but survives black-box compilation attempts (Gulati et al., 6 Oct 2025).

A different oracle-based line gives further evidence that PRFSGs need not yield PRUs. One paper constructs a unitary oracle relative to which adaptively-secure quantum-accessible PRFSGs exist, but non-adaptively secure PRUs without ancilla do not. Under an isoperimetric inequality-style conjecture, the same work argues that short-output PRFSGs do not straightforwardly yield QPRGs with negligible correctness error, and that some natural attempts to extend short PRFSG output lengths toward longer PRSGs are impossible (Bouaziz--Ermann et al., 6 Oct 2025).

Negative results also arise inside positive constructions. The (x1,,xq(λ)){0,1}m(λ),(x_1,\dots,x_{q(\lambda)}) \in \{0,1\}^{m(\lambda)},5 construction in the invertible QHRO model is not quantum-accessible secure: it is not a PRU and not a quantum-accessible non-adaptive PRFSG. The attack uses a variant of Simon’s algorithm for quantum states, exploiting the hidden-shift structure induced by (x1,,xq(λ)){0,1}m(λ),(x_1,\dots,x_{q(\lambda)}) \in \{0,1\}^{m(\lambda)},6 to recover secret masks (Hhan et al., 2024).

On the existence side, the literature remains conditional in the standard model. One work explicitly treats PRFSGs as assumptions and derives QPRFs and classical-ciphertext encryption from them, rather than proving unconditional existence. Open questions highlighted in that context include whether the inverse-polynomial pseudodeterminism error in QPRF-style constructions can be reduced to negligible, whether QPRF- or QPRG-like objects can be fully dequantized or related more sharply to classical PRFs and PRGs, and whether logarithmic-output quantum-state primitives are closer to classical cryptography or inherently quantum cryptography (Ananth et al., 2023).

Taken together, these results support a stable picture. PRFSGs are robust enough to instantiate substantial cryptographic functionality, yet current evidence indicates that they are not interchangeable with PRUs, PRIs, classical PRFs, or PRGs. This suggests a genuinely stratified landscape of quantum pseudorandomness rather than a single equivalence class of pseudorandom primitives.

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Pseudorandom Function-like State Generators (PRFSGs).