Pseudorandom Isometries (PRIs) in Quantum Cryptography
- Pseudorandom isometries (PRIs) are keyed quantum maps that extend n-qubit inputs to larger outputs while preserving inner products and mimicking Haar-random isometries.
- PRIs occupy an intermediate role between pseudorandom unitaries (PRUs) and PRF-like state generators, underpinning advanced cryptographic applications such as encryption and commitments.
- Their construction utilizes post-quantum techniques like keyed pseudorandom phases, permutations, and quantum singular value transformation, with explicit bounds on ancilla use and output stretch.
Searching arXiv for the cited PRI papers to ground the article in the current literature. Pseudorandom isometries (PRIs) are keyed families of efficiently implementable quantum isometries that map an input register to a larger output register while remaining computationally indistinguishable from Haar-random isometries under a specified security interface. In the recent quantum-cryptographic literature, PRIs are positioned between pseudorandom unitaries (PRUs) and pseudorandom function-like state generators (PRFSGs): PRUs imply PRIs, and PRIs imply PRFSGs, while several converse implications are ruled out in black-box, resource-bounded settings (Ananth et al., 2023, Metger et al., 2024, Gulati et al., 6 Oct 2025).
1. Formal object and parameter regimes
An -to--qubit isometry is a linear map
satisfying
Equivalently, it preserves inner products and can be realized by appending ancilla qubits in a fixed state and then applying an -qubit unitary (Ananth et al., 2023).
A common parameterization fixes a security parameter , sets
and defines a PRI as a keyed family
implemented by a QPT generation algorithm such that on input 0 and 1, it outputs 2. The function 3 is the stretch, namely the output-dimension expansion (Gulati et al., 6 Oct 2025).
The literature also uses a sampling description of a Haar-random isometry. For 4, a Haar-random isometry from 5 to 6 qubits is obtained by drawing 7 Haar-random and defining
8
By Haar invariance, the choice of the fixed padding state is immaterial (Metger et al., 2024).
Resource accounting is central in the later separation results. In particular, “9-ancilla” means that the generator uses at most 0 ancilla qubits to implement the 1 isometry, and at least 2 ancillas are information-theoretically necessary to expand the dimension by 3 (Gulati et al., 6 Oct 2025).
2. Security notions and oracle interfaces
The earliest flexible formulation introduces 4-secure PRIs. Here 5 specifies admissible 6-qubit inputs, and the same isometry is reused across all 7 copies. A keyed family 8 is 9-0-secure if no QPT adversary 1 can distinguish
2
from
3
where 4 is a Haar-random isometry from 5 to 6, for every 7, up to negligible advantage. The same framework also defines selective PRI, with one parallel query, and adaptive PRI, with 8 sequential queries (Ananth et al., 2023).
A second model studies oracle access directly. In that forward-only setting, the adversary is a QPT algorithm with black-box access to the isometry 9 only; the model does not provide 0, controlled access, or inverse queries. Non-adaptive security permits one parallel batch of queries on an arbitrary joint state, whereas adaptive security allows interleaving oracle calls with arbitrary QPT computation and measurement. The distinguishing advantage is
1
and adaptive security requires 2 for all QPT adversaries making up to 3 adaptive queries (Metger et al., 2024).
A third model strengthens the interface further by giving the distinguisher oracle access to both the forward isometry and its adjoint. In the real world, 4 interacts with 5 for uniformly random 6. In the random world, 7 interacts with
8
where 9 is Haar-random in 0. The pseudorandomness condition is
1
Non-adaptive variants restrict the distinguisher to a single batch query (Gulati et al., 6 Oct 2025).
These definitions are not interchangeable. They differ in whether the adversary receives state outputs or oracle access, whether the same isometry is reused across copies, and whether inverse access is available. This suggests that comparisons among PRI results must track the oracle model explicitly.
3. Constructions and proof techniques
A general construction from post-quantum one-way functions appends 2 ancilla qubits in uniform superposition, applies a keyed pseudorandom phase, and then applies a keyed pseudorandom permutation. On input 3, the keyed PRI 4 is
5
where 6, 7 is a quantum-secure PRF, and 8 is a quantum-secure PRP. The security analysis proceeds through hybrids from the keyed construction to an information-theoretic construction 9, and then through 0-fold Haar almost-invariance, type states, and symmetric-subspace arguments. Under post-quantum one-way functions, this construction is proved secure for 1, 2, and 3 (Ananth et al., 2023).
A later construction starts from the 4 ensemble, where 5 is the product of a random computational-basis permutation 6, a random binary phase operator 7, and a random Clifford 8. That work shows that the 9 ensemble is a diamond-error 0-approximate 1-design with 2, gives linear-depth 3-designs, and yields the first non-adaptive PRUs. For PRIs, the construction makes a small modification: 4 The Clifford layer is removed, 5 ancillas are appended, and the resulting family is proved adaptively secure assuming quantum-secure one-way functions (Metger et al., 2024).
The proof strategy for this adaptive PRI construction is specific to isometries. Across 6 adaptive queries, the strings in the appended registers are distinct with overwhelming probability when 7. The analysis then proves that 8 behaves as a one-sided relative-error 9-design on the distinct-string subspace 0,
1
uses gate teleportation to express adaptive query patterns, and applies operator monotonicity to convert this multiplicative comparison into a negligible distinguishing advantage. The paper presents this as the first adaptively secure PRI construction, with only 2 extra output qubits (Metger et al., 2024).
4. Position between PRUs and PRFSGs
PRIs are defined as an intermediate quantum pseudorandomness primitive. Ji–Liu–Song introduced PRUs as keyed unitary families that are computationally indistinguishable from Haar-random unitaries with oracle access to 3 and 4. Ananth–Qian–Yuen defined quantumly-accessible adaptively-secure PRFSGs, where a QPT algorithm 5 outputs 6 on classical input 7, and these outputs are indistinguishable from 8-indexed independent Haar-random states against superposition and adaptive queries. PRUs imply PRIs, and PRIs imply PRFSGs, while the converse implications were open before the black-box separation results (Gulati et al., 6 Oct 2025).
The 9-secure framework shows that PRIs also unify several earlier notions. By specializing the admissible query class 0, one recovers pseudorandom state generators (PRSGs), PRF-like state generators, and pseudorandom state scramblers (PSS). When 1 and 2 is the full set, adaptive PRI becomes pseudorandom unitaries. The same work therefore describes PRIs as a flexible framework that interpolates between pseudorandom states and pseudorandom operations, while directly enabling output-length extension (Ananth et al., 2023).
| Primitive | Interface in the literature | Relation |
|---|---|---|
| PRU | Keyed unitaries, typically with 3 and 4 access or parallel queries | PRUs imply PRIs |
| PRI | Keyed isometries with stretch 5 or 6 | PRIs imply PRFSGs |
| PRFSG | State-generation oracle on classical 7, quantumly accessible and adaptive | Obtained from PRIs by injecting 8-labeled inputs |
Within the broader applications context, quantum PRF analogues such as PRSGs, PRFSGs, PRIs, and PRUs underpin numerous cryptographic tasks in the “Microcrypt” landscape, including symmetric-key encryption, message authentication, commitments, MPC tasks, and quantum money. In that hierarchy, PRIs capture a middle regime: more general than state generators, but weaker than fully pseudorandom unitaries in the known black-box sense (Gulati et al., 6 Oct 2025).
5. Black-box separations and oracle lower bounds
The strongest known separation results study black-box constructions, meaning constructions that use only oracle access to the given primitive and its inverse or unitary implementation, without exploiting internal structure. In that sense, three impossibility results are proved. First, there are no black-box constructions of 9-ancilla PRUs from PRFSGs. Second, there are no black-box constructions of 00-ancilla PRIs with 01 stretch from PRFSGs. Third, there are no black-box constructions of 02-ancilla PRIs with 03 stretch from PRIs with 04 stretch. These statements hold even in non-adaptive settings covered by the paper’s theorems (Gulati et al., 6 Oct 2025).
The impossibility results are derived from oracle separations. One oracle is the “swap + UnitaryPSPACE” oracle 05, where 06 contains unitaries 07 that swap 08 with 09 for Haar-random 10, and 11 implements a UnitaryPSPACE-complete problem. Relative to 12 and 13, PRFSGs exist, yet 14-ancilla non-adaptive PRUs do not, and 15-ancilla PRIs with 16 stretch do not. A second oracle, the Haar-random isometry oracle 17, emulates Haar-random isometries with large stretch 18; relative to 19 and their inverses, adaptive PRIs with exponential stretch exist, but non-adaptive ancilla-free PRIs with 20 stretch do not.
A central technical contribution is the direct adversary based on quantum singular value transformation (QSVT). The paper block-encodes an averaged Choi-like state 21, where 22 is the average CJ state from Haar-random unitaries or isometries, 23 is the average CJ state of the candidate construction, and 24 is a statistically close hybrid obtained by simulating all “small support” oracle queries via efficient process tomography and ignoring “large support” swaps that are nearly identity on the maximally entangled test input. Using purification-based block-encoding and a singular-value discrimination subroutine, the adversary distinguishes whether the input lies in a low-singular-value or high-singular-value subspace. The paper proves that 25 lies almost entirely outside the support of 26, while 27 lies inside it, yielding distinguishing advantage 28.
The small-ancilla and small-stretch conditions are structurally decisive in this argument. With 29 ancilla and 30 stretch, the generator’s action remains localized near 31 qubits, which permits tomography of the small swaps and makes the large swaps negligible on the maximally entangled test state. The same paper contrasts this with the large-stretch regime, which in the third separation is exponential in 32, and shows that even access to such a large-stretch PRI does not black-box compress to 33 stretch in the stated regime (Gulati et al., 6 Oct 2025).
6. Applications, terminology, and open problems
PRIs support a broad set of cryptographic applications. The original 34-secure framework proves length extension theorems for quantum pseudorandomness notions, message authentication schemes for quantum states, multi-copy secure public and private encryption schemes, and succinct quantum commitments (Ananth et al., 2023). In more detail, that work gives a Sign/Verify MAC based on an invertible PRI, proves many-copies-unforgeability and 35-unforgeability, constructs multi-copy secure public-key and private-key encryption from invertible 36-secure PRIs, and uses PRIs in a Schur-transform-based one-time encryption construction that yields succinct quantum commitments.
The black-box separation paper places these applications in an oracle-relative context. Because PRFSGs exist relative to the separation oracle 37 and 38, all primitives known to be constructible from PRFSGs by black-box reductions also exist relative to these oracles, including pseudorandom state generators, secret-key encryption, unclonable MACs, commitments, various MPC primitives, private-key quantum money, OWSGs/OWpuzzs, and EFI pairs (Gulati et al., 6 Oct 2025). Accordingly, the negative results do not eliminate those downstream constructions; rather, they separate the pseudorandomness primitives themselves under explicit ancilla and stretch bounds.
The term “pseudorandom isometry” also appears in an unrelated compressed-sensing literature. There it refers not to quantum isometries but to measurement matrices satisfying the Restricted Isometry Property (RIP), with entries generated from pseudorandom sources such as the Legendre symbol or more general 39-small-bias Bernoulli families. In that setting, the main result gives a Legendre-symbol-based 40 matrix that satisfies 41-RIP with high probability while using
42
random bits, and more generally proves that any sufficiently small-bias Bernoulli source suffices for RIP (Bandeira et al., 2014). The nomenclature is therefore overloaded across quantum cryptography and compressed sensing.
Several open questions remain explicit in the current quantum PRI literature. They include non-black-box constructions that exploit internal structure rather than oracle access alone, equivalence of PRUs, PRIs, and PRFSGs beyond black-box settings, separations in other resource regimes such as 43 ancilla or polynomial stretch, extension of oracle models to transpose or complex-conjugate queries, adaptive security for PRUs without output extension, security under inverse and controlled-query access, and stronger invertible adaptive PRI guarantees for broader query classes 44 (Metger et al., 2024, Gulati et al., 6 Oct 2025, Ananth et al., 2023).