Papers
Topics
Authors
Recent
Search
2000 character limit reached

Pseudorandom Isometries (PRIs) in Quantum Cryptography

Updated 14 July 2026
  • Pseudorandom isometries (PRIs) are keyed quantum maps that extend n-qubit inputs to larger outputs while preserving inner products and mimicking Haar-random isometries.
  • PRIs occupy an intermediate role between pseudorandom unitaries (PRUs) and PRF-like state generators, underpinning advanced cryptographic applications such as encryption and commitments.
  • Their construction utilizes post-quantum techniques like keyed pseudorandom phases, permutations, and quantum singular value transformation, with explicit bounds on ancilla use and output stretch.

Searching arXiv for the cited PRI papers to ground the article in the current literature. Pseudorandom isometries (PRIs) are keyed families of efficiently implementable quantum isometries that map an input register to a larger output register while remaining computationally indistinguishable from Haar-random isometries under a specified security interface. In the recent quantum-cryptographic literature, PRIs are positioned between pseudorandom unitaries (PRUs) and pseudorandom function-like state generators (PRFSGs): PRUs imply PRIs, and PRIs imply PRFSGs, while several converse implications are ruled out in black-box, resource-bounded settings (Ananth et al., 2023, Metger et al., 2024, Gulati et al., 6 Oct 2025).

1. Formal object and parameter regimes

An nn-to-(n+m)(n+m)-qubit isometry is a linear map

V:C2nC2n+mV:\mathbb C^{2^n}\to \mathbb C^{2^{n+m}}

satisfying

VV=I2n.V^\dagger V = I_{2^n}.

Equivalently, it preserves inner products and can be realized by appending mm ancilla qubits in a fixed state and then applying an (n+m)(n+m)-qubit unitary (Ananth et al., 2023).

A common parameterization fixes a security parameter λ\lambda, sets

Hin=(C2)λ,Hout=(C2)(λ+s(λ)),\mathcal H_{\mathrm{in}}=(\mathbb C^2)^{\otimes \lambda},\qquad \mathcal H_{\mathrm{out}}=(\mathbb C^2)^{\otimes (\lambda+s(\lambda))},

and defines a PRI as a keyed family

{Vk}kKλ,Vk:HinHout,\{V_k\}_{k\in\mathcal K_\lambda},\qquad V_k:\mathcal H_{\mathrm{in}}\to\mathcal H_{\mathrm{out}},

implemented by a QPT generation algorithm GG such that on input (n+m)(n+m)0 and (n+m)(n+m)1, it outputs (n+m)(n+m)2. The function (n+m)(n+m)3 is the stretch, namely the output-dimension expansion (Gulati et al., 6 Oct 2025).

The literature also uses a sampling description of a Haar-random isometry. For (n+m)(n+m)4, a Haar-random isometry from (n+m)(n+m)5 to (n+m)(n+m)6 qubits is obtained by drawing (n+m)(n+m)7 Haar-random and defining

(n+m)(n+m)8

By Haar invariance, the choice of the fixed padding state is immaterial (Metger et al., 2024).

Resource accounting is central in the later separation results. In particular, “(n+m)(n+m)9-ancilla” means that the generator uses at most V:C2nC2n+mV:\mathbb C^{2^n}\to \mathbb C^{2^{n+m}}0 ancilla qubits to implement the V:C2nC2n+mV:\mathbb C^{2^n}\to \mathbb C^{2^{n+m}}1 isometry, and at least V:C2nC2n+mV:\mathbb C^{2^n}\to \mathbb C^{2^{n+m}}2 ancillas are information-theoretically necessary to expand the dimension by V:C2nC2n+mV:\mathbb C^{2^n}\to \mathbb C^{2^{n+m}}3 (Gulati et al., 6 Oct 2025).

2. Security notions and oracle interfaces

The earliest flexible formulation introduces V:C2nC2n+mV:\mathbb C^{2^n}\to \mathbb C^{2^{n+m}}4-secure PRIs. Here V:C2nC2n+mV:\mathbb C^{2^n}\to \mathbb C^{2^{n+m}}5 specifies admissible V:C2nC2n+mV:\mathbb C^{2^n}\to \mathbb C^{2^{n+m}}6-qubit inputs, and the same isometry is reused across all V:C2nC2n+mV:\mathbb C^{2^n}\to \mathbb C^{2^{n+m}}7 copies. A keyed family V:C2nC2n+mV:\mathbb C^{2^n}\to \mathbb C^{2^{n+m}}8 is V:C2nC2n+mV:\mathbb C^{2^n}\to \mathbb C^{2^{n+m}}9-VV=I2n.V^\dagger V = I_{2^n}.0-secure if no QPT adversary VV=I2n.V^\dagger V = I_{2^n}.1 can distinguish

VV=I2n.V^\dagger V = I_{2^n}.2

from

VV=I2n.V^\dagger V = I_{2^n}.3

where VV=I2n.V^\dagger V = I_{2^n}.4 is a Haar-random isometry from VV=I2n.V^\dagger V = I_{2^n}.5 to VV=I2n.V^\dagger V = I_{2^n}.6, for every VV=I2n.V^\dagger V = I_{2^n}.7, up to negligible advantage. The same framework also defines selective PRI, with one parallel query, and adaptive PRI, with VV=I2n.V^\dagger V = I_{2^n}.8 sequential queries (Ananth et al., 2023).

A second model studies oracle access directly. In that forward-only setting, the adversary is a QPT algorithm with black-box access to the isometry VV=I2n.V^\dagger V = I_{2^n}.9 only; the model does not provide mm0, controlled access, or inverse queries. Non-adaptive security permits one parallel batch of queries on an arbitrary joint state, whereas adaptive security allows interleaving oracle calls with arbitrary QPT computation and measurement. The distinguishing advantage is

mm1

and adaptive security requires mm2 for all QPT adversaries making up to mm3 adaptive queries (Metger et al., 2024).

A third model strengthens the interface further by giving the distinguisher oracle access to both the forward isometry and its adjoint. In the real world, mm4 interacts with mm5 for uniformly random mm6. In the random world, mm7 interacts with

mm8

where mm9 is Haar-random in (n+m)(n+m)0. The pseudorandomness condition is

(n+m)(n+m)1

Non-adaptive variants restrict the distinguisher to a single batch query (Gulati et al., 6 Oct 2025).

These definitions are not interchangeable. They differ in whether the adversary receives state outputs or oracle access, whether the same isometry is reused across copies, and whether inverse access is available. This suggests that comparisons among PRI results must track the oracle model explicitly.

3. Constructions and proof techniques

A general construction from post-quantum one-way functions appends (n+m)(n+m)2 ancilla qubits in uniform superposition, applies a keyed pseudorandom phase, and then applies a keyed pseudorandom permutation. On input (n+m)(n+m)3, the keyed PRI (n+m)(n+m)4 is

(n+m)(n+m)5

where (n+m)(n+m)6, (n+m)(n+m)7 is a quantum-secure PRF, and (n+m)(n+m)8 is a quantum-secure PRP. The security analysis proceeds through hybrids from the keyed construction to an information-theoretic construction (n+m)(n+m)9, and then through λ\lambda0-fold Haar almost-invariance, type states, and symmetric-subspace arguments. Under post-quantum one-way functions, this construction is proved secure for λ\lambda1, λ\lambda2, and λ\lambda3 (Ananth et al., 2023).

A later construction starts from the λ\lambda4 ensemble, where λ\lambda5 is the product of a random computational-basis permutation λ\lambda6, a random binary phase operator λ\lambda7, and a random Clifford λ\lambda8. That work shows that the λ\lambda9 ensemble is a diamond-error Hin=(C2)λ,Hout=(C2)(λ+s(λ)),\mathcal H_{\mathrm{in}}=(\mathbb C^2)^{\otimes \lambda},\qquad \mathcal H_{\mathrm{out}}=(\mathbb C^2)^{\otimes (\lambda+s(\lambda))},0-approximate Hin=(C2)λ,Hout=(C2)(λ+s(λ)),\mathcal H_{\mathrm{in}}=(\mathbb C^2)^{\otimes \lambda},\qquad \mathcal H_{\mathrm{out}}=(\mathbb C^2)^{\otimes (\lambda+s(\lambda))},1-design with Hin=(C2)λ,Hout=(C2)(λ+s(λ)),\mathcal H_{\mathrm{in}}=(\mathbb C^2)^{\otimes \lambda},\qquad \mathcal H_{\mathrm{out}}=(\mathbb C^2)^{\otimes (\lambda+s(\lambda))},2, gives linear-depth Hin=(C2)λ,Hout=(C2)(λ+s(λ)),\mathcal H_{\mathrm{in}}=(\mathbb C^2)^{\otimes \lambda},\qquad \mathcal H_{\mathrm{out}}=(\mathbb C^2)^{\otimes (\lambda+s(\lambda))},3-designs, and yields the first non-adaptive PRUs. For PRIs, the construction makes a small modification: Hin=(C2)λ,Hout=(C2)(λ+s(λ)),\mathcal H_{\mathrm{in}}=(\mathbb C^2)^{\otimes \lambda},\qquad \mathcal H_{\mathrm{out}}=(\mathbb C^2)^{\otimes (\lambda+s(\lambda))},4 The Clifford layer is removed, Hin=(C2)λ,Hout=(C2)(λ+s(λ)),\mathcal H_{\mathrm{in}}=(\mathbb C^2)^{\otimes \lambda},\qquad \mathcal H_{\mathrm{out}}=(\mathbb C^2)^{\otimes (\lambda+s(\lambda))},5 ancillas are appended, and the resulting family is proved adaptively secure assuming quantum-secure one-way functions (Metger et al., 2024).

The proof strategy for this adaptive PRI construction is specific to isometries. Across Hin=(C2)λ,Hout=(C2)(λ+s(λ)),\mathcal H_{\mathrm{in}}=(\mathbb C^2)^{\otimes \lambda},\qquad \mathcal H_{\mathrm{out}}=(\mathbb C^2)^{\otimes (\lambda+s(\lambda))},6 adaptive queries, the strings in the appended registers are distinct with overwhelming probability when Hin=(C2)λ,Hout=(C2)(λ+s(λ)),\mathcal H_{\mathrm{in}}=(\mathbb C^2)^{\otimes \lambda},\qquad \mathcal H_{\mathrm{out}}=(\mathbb C^2)^{\otimes (\lambda+s(\lambda))},7. The analysis then proves that Hin=(C2)λ,Hout=(C2)(λ+s(λ)),\mathcal H_{\mathrm{in}}=(\mathbb C^2)^{\otimes \lambda},\qquad \mathcal H_{\mathrm{out}}=(\mathbb C^2)^{\otimes (\lambda+s(\lambda))},8 behaves as a one-sided relative-error Hin=(C2)λ,Hout=(C2)(λ+s(λ)),\mathcal H_{\mathrm{in}}=(\mathbb C^2)^{\otimes \lambda},\qquad \mathcal H_{\mathrm{out}}=(\mathbb C^2)^{\otimes (\lambda+s(\lambda))},9-design on the distinct-string subspace {Vk}kKλ,Vk:HinHout,\{V_k\}_{k\in\mathcal K_\lambda},\qquad V_k:\mathcal H_{\mathrm{in}}\to\mathcal H_{\mathrm{out}},0,

{Vk}kKλ,Vk:HinHout,\{V_k\}_{k\in\mathcal K_\lambda},\qquad V_k:\mathcal H_{\mathrm{in}}\to\mathcal H_{\mathrm{out}},1

uses gate teleportation to express adaptive query patterns, and applies operator monotonicity to convert this multiplicative comparison into a negligible distinguishing advantage. The paper presents this as the first adaptively secure PRI construction, with only {Vk}kKλ,Vk:HinHout,\{V_k\}_{k\in\mathcal K_\lambda},\qquad V_k:\mathcal H_{\mathrm{in}}\to\mathcal H_{\mathrm{out}},2 extra output qubits (Metger et al., 2024).

4. Position between PRUs and PRFSGs

PRIs are defined as an intermediate quantum pseudorandomness primitive. Ji–Liu–Song introduced PRUs as keyed unitary families that are computationally indistinguishable from Haar-random unitaries with oracle access to {Vk}kKλ,Vk:HinHout,\{V_k\}_{k\in\mathcal K_\lambda},\qquad V_k:\mathcal H_{\mathrm{in}}\to\mathcal H_{\mathrm{out}},3 and {Vk}kKλ,Vk:HinHout,\{V_k\}_{k\in\mathcal K_\lambda},\qquad V_k:\mathcal H_{\mathrm{in}}\to\mathcal H_{\mathrm{out}},4. Ananth–Qian–Yuen defined quantumly-accessible adaptively-secure PRFSGs, where a QPT algorithm {Vk}kKλ,Vk:HinHout,\{V_k\}_{k\in\mathcal K_\lambda},\qquad V_k:\mathcal H_{\mathrm{in}}\to\mathcal H_{\mathrm{out}},5 outputs {Vk}kKλ,Vk:HinHout,\{V_k\}_{k\in\mathcal K_\lambda},\qquad V_k:\mathcal H_{\mathrm{in}}\to\mathcal H_{\mathrm{out}},6 on classical input {Vk}kKλ,Vk:HinHout,\{V_k\}_{k\in\mathcal K_\lambda},\qquad V_k:\mathcal H_{\mathrm{in}}\to\mathcal H_{\mathrm{out}},7, and these outputs are indistinguishable from {Vk}kKλ,Vk:HinHout,\{V_k\}_{k\in\mathcal K_\lambda},\qquad V_k:\mathcal H_{\mathrm{in}}\to\mathcal H_{\mathrm{out}},8-indexed independent Haar-random states against superposition and adaptive queries. PRUs imply PRIs, and PRIs imply PRFSGs, while the converse implications were open before the black-box separation results (Gulati et al., 6 Oct 2025).

The {Vk}kKλ,Vk:HinHout,\{V_k\}_{k\in\mathcal K_\lambda},\qquad V_k:\mathcal H_{\mathrm{in}}\to\mathcal H_{\mathrm{out}},9-secure framework shows that PRIs also unify several earlier notions. By specializing the admissible query class GG0, one recovers pseudorandom state generators (PRSGs), PRF-like state generators, and pseudorandom state scramblers (PSS). When GG1 and GG2 is the full set, adaptive PRI becomes pseudorandom unitaries. The same work therefore describes PRIs as a flexible framework that interpolates between pseudorandom states and pseudorandom operations, while directly enabling output-length extension (Ananth et al., 2023).

Primitive Interface in the literature Relation
PRU Keyed unitaries, typically with GG3 and GG4 access or parallel queries PRUs imply PRIs
PRI Keyed isometries with stretch GG5 or GG6 PRIs imply PRFSGs
PRFSG State-generation oracle on classical GG7, quantumly accessible and adaptive Obtained from PRIs by injecting GG8-labeled inputs

Within the broader applications context, quantum PRF analogues such as PRSGs, PRFSGs, PRIs, and PRUs underpin numerous cryptographic tasks in the “Microcrypt” landscape, including symmetric-key encryption, message authentication, commitments, MPC tasks, and quantum money. In that hierarchy, PRIs capture a middle regime: more general than state generators, but weaker than fully pseudorandom unitaries in the known black-box sense (Gulati et al., 6 Oct 2025).

5. Black-box separations and oracle lower bounds

The strongest known separation results study black-box constructions, meaning constructions that use only oracle access to the given primitive and its inverse or unitary implementation, without exploiting internal structure. In that sense, three impossibility results are proved. First, there are no black-box constructions of GG9-ancilla PRUs from PRFSGs. Second, there are no black-box constructions of (n+m)(n+m)00-ancilla PRIs with (n+m)(n+m)01 stretch from PRFSGs. Third, there are no black-box constructions of (n+m)(n+m)02-ancilla PRIs with (n+m)(n+m)03 stretch from PRIs with (n+m)(n+m)04 stretch. These statements hold even in non-adaptive settings covered by the paper’s theorems (Gulati et al., 6 Oct 2025).

The impossibility results are derived from oracle separations. One oracle is the “swap + UnitaryPSPACE” oracle (n+m)(n+m)05, where (n+m)(n+m)06 contains unitaries (n+m)(n+m)07 that swap (n+m)(n+m)08 with (n+m)(n+m)09 for Haar-random (n+m)(n+m)10, and (n+m)(n+m)11 implements a UnitaryPSPACE-complete problem. Relative to (n+m)(n+m)12 and (n+m)(n+m)13, PRFSGs exist, yet (n+m)(n+m)14-ancilla non-adaptive PRUs do not, and (n+m)(n+m)15-ancilla PRIs with (n+m)(n+m)16 stretch do not. A second oracle, the Haar-random isometry oracle (n+m)(n+m)17, emulates Haar-random isometries with large stretch (n+m)(n+m)18; relative to (n+m)(n+m)19 and their inverses, adaptive PRIs with exponential stretch exist, but non-adaptive ancilla-free PRIs with (n+m)(n+m)20 stretch do not.

A central technical contribution is the direct adversary based on quantum singular value transformation (QSVT). The paper block-encodes an averaged Choi-like state (n+m)(n+m)21, where (n+m)(n+m)22 is the average CJ state from Haar-random unitaries or isometries, (n+m)(n+m)23 is the average CJ state of the candidate construction, and (n+m)(n+m)24 is a statistically close hybrid obtained by simulating all “small support” oracle queries via efficient process tomography and ignoring “large support” swaps that are nearly identity on the maximally entangled test input. Using purification-based block-encoding and a singular-value discrimination subroutine, the adversary distinguishes whether the input lies in a low-singular-value or high-singular-value subspace. The paper proves that (n+m)(n+m)25 lies almost entirely outside the support of (n+m)(n+m)26, while (n+m)(n+m)27 lies inside it, yielding distinguishing advantage (n+m)(n+m)28.

The small-ancilla and small-stretch conditions are structurally decisive in this argument. With (n+m)(n+m)29 ancilla and (n+m)(n+m)30 stretch, the generator’s action remains localized near (n+m)(n+m)31 qubits, which permits tomography of the small swaps and makes the large swaps negligible on the maximally entangled test state. The same paper contrasts this with the large-stretch regime, which in the third separation is exponential in (n+m)(n+m)32, and shows that even access to such a large-stretch PRI does not black-box compress to (n+m)(n+m)33 stretch in the stated regime (Gulati et al., 6 Oct 2025).

6. Applications, terminology, and open problems

PRIs support a broad set of cryptographic applications. The original (n+m)(n+m)34-secure framework proves length extension theorems for quantum pseudorandomness notions, message authentication schemes for quantum states, multi-copy secure public and private encryption schemes, and succinct quantum commitments (Ananth et al., 2023). In more detail, that work gives a Sign/Verify MAC based on an invertible PRI, proves many-copies-unforgeability and (n+m)(n+m)35-unforgeability, constructs multi-copy secure public-key and private-key encryption from invertible (n+m)(n+m)36-secure PRIs, and uses PRIs in a Schur-transform-based one-time encryption construction that yields succinct quantum commitments.

The black-box separation paper places these applications in an oracle-relative context. Because PRFSGs exist relative to the separation oracle (n+m)(n+m)37 and (n+m)(n+m)38, all primitives known to be constructible from PRFSGs by black-box reductions also exist relative to these oracles, including pseudorandom state generators, secret-key encryption, unclonable MACs, commitments, various MPC primitives, private-key quantum money, OWSGs/OWpuzzs, and EFI pairs (Gulati et al., 6 Oct 2025). Accordingly, the negative results do not eliminate those downstream constructions; rather, they separate the pseudorandomness primitives themselves under explicit ancilla and stretch bounds.

The term “pseudorandom isometry” also appears in an unrelated compressed-sensing literature. There it refers not to quantum isometries but to measurement matrices satisfying the Restricted Isometry Property (RIP), with entries generated from pseudorandom sources such as the Legendre symbol or more general (n+m)(n+m)39-small-bias Bernoulli families. In that setting, the main result gives a Legendre-symbol-based (n+m)(n+m)40 matrix that satisfies (n+m)(n+m)41-RIP with high probability while using

(n+m)(n+m)42

random bits, and more generally proves that any sufficiently small-bias Bernoulli source suffices for RIP (Bandeira et al., 2014). The nomenclature is therefore overloaded across quantum cryptography and compressed sensing.

Several open questions remain explicit in the current quantum PRI literature. They include non-black-box constructions that exploit internal structure rather than oracle access alone, equivalence of PRUs, PRIs, and PRFSGs beyond black-box settings, separations in other resource regimes such as (n+m)(n+m)43 ancilla or polynomial stretch, extension of oracle models to transpose or complex-conjugate queries, adaptive security for PRUs without output extension, security under inverse and controlled-query access, and stronger invertible adaptive PRI guarantees for broader query classes (n+m)(n+m)44 (Metger et al., 2024, Gulati et al., 6 Oct 2025, Ananth et al., 2023).

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Pseudorandom Isometries (PRIs).