Papers
Topics
Authors
Recent
Search
2000 character limit reached

Quantum Haar Random Oracle Model

Updated 14 July 2026
  • Quantum Haar Random Oracle Model is an idealized framework providing coherent oracle access to Haar-distributed quantum states and unitaries.
  • It underpins cryptographic constructions such as quantum money, succinct commitments, and quantum Merkle trees through rigorous simulation methods.
  • The model leverages advanced techniques like lazy sampling, compressed oracles, and Clebsch–Gordan transforms to ensure adaptive security against quantum adversaries.

Searching arXiv for papers on the Quantum Haar Random Oracle Model and related constructions. arxiv_search(query="Quantum Haar Random Oracle Model", max_results=10, sort_by="submittedDate") The Quantum Haar Random Oracle Model (QHROM) is an idealized framework in which parties receive oracle access to quantum objects sampled from Haar-invariant distributions, most commonly a Haar-random unitary together with its inverse, and in some formulations a Haar-random state or a family of independent Haar-random unitaries indexed by input length or classical labels. It serves as a quantum analogue of random-oracle and random-permutation idealizations, but with fully coherent oracle access: queries may be made in superposition, inverse access is often explicit, and security is typically formulated against adaptive, entangled, and even unbounded adversaries subject only to a query bound (Alagic et al., 2019). Subsequent work has developed exact or negligible-error stateful simulators, compressed-oracle and path-recording techniques, representation-theoretic constructions based on Clebsch–Gordan transforms, and cryptographic applications ranging from quantum money and pseudorandomness to succinct commitments and proof systems (Grinko et al., 30 Sep 2025).

1. Formal definitions and model variants

Across the literature, the term QHROM denotes a family of closely related ideal models rather than a single canonical interface. The common feature is oracle access to Haar-distributed quantum objects under coherent querying.

Variant Sampled object Oracle access
Random-state/unitary sampler A single Haar-random state ψ|\psi\rangle or unitary UU(d)U\in U(d) State interfaces or U,UU,U^\dagger (Alagic et al., 2019)
Invertible QHROM A single nn-qubit Haar-random unitary UU Forward and inverse superoperators U,UU,U^\dagger (Ananth et al., 2024)
Family-valued QHROM Independent Haar-random unitaries {U}N\{U_\ell\}_{\ell\in\mathbb N} Access to UU_\ell and UU_\ell^\dagger on \ell-qubit inputs (Ananth et al., 29 Sep 2025)
Label-indexed invertible QHRO Independent Haar-random unitaries UU(d)U\in U(d)0 Queries UU(d)U\in U(d)1 and inverse (Hhan et al., 2024)
Proof-system QHROM A single Haar-random unitary UU(d)U\in U(d)2 Prover and verifier both access UU(d)U\in U(d)3 (Chen et al., 2021)

In the formulation of efficient simulation, a trusted oracle machine samples either a pure state UU(d)U\in U(d)4 uniformly from the Haar measure on the unit sphere or a unitary UU(d)U\in U(d)5 uniformly from the Haar measure UU(d)U\in U(d)6 on the compact group UU(d)U\in U(d)7 (Alagic et al., 2019). In the unitary case, the basic ideal interfaces are UU(d)U\in U(d)8, UU(d)U\in U(d)9, and U,UU,U^\dagger0 (Alagic et al., 2019).

A distinct but compatible formalization fixes a security parameter U,UU,U^\dagger1 and gives every party oracle access to a family

U,UU,U^\dagger2

with oracle queries permitted in superposition on an U,UU,U^\dagger3-qubit register (Ananth et al., 29 Sep 2025). This formulation is tailored to cryptographic indistinguishability definitions.

In interactive-proof applications, QHROM is built directly into completeness and soundness conditions. An interactive protocol U,UU,U^\dagger4 is said to be a proof system in QHROM if both prover and verifier receive input U,UU,U^\dagger5 and oracle access to

U,UU,U^\dagger6

with soundness quantified against any unbounded prover making at most U,UU,U^\dagger7 total queries to U,UU,U^\dagger8 and U,UU,U^\dagger9 (Chen et al., 2021).

A related state-only idealization replaces Haar-random unitaries by an oracle that, on input nn0, supplies a fresh nn1-qubit Haar-random state nn2, equivalently an isometry nn3 (Chen et al., 2024). This is not the unitary QHROM itself, but it belongs to the same family of Haar-oracle models and is used to study separations among quantum pseudorandom notions.

2. Oracle interfaces and operational semantics

The operational content of QHROM depends on the sampled object. For Haar-random states, the ideal sampler nn4 exposes four interfaces: nn5, which returns a classical description nn6 of nn7; nn8, which outputs an nn9-qubit register in state UU0; UU1, which measures UU2; and UU3, which applies the controlled reflection

UU4

These interfaces make the state oracle more structured than a simple source of copies, because they allow coherent verification and reflection relative to the same hidden Haar state (Alagic et al., 2019).

For Haar-random unitaries, the minimal interface is forward and inverse access. The terminology “forward access” refers to oracle application of UU5, while “inverse access” refers to UU6 (Alagic et al., 2019). In proof systems and commitment schemes this inverse interface is operationally essential: the verifier uses UU7 to reverse portions of the prover’s encoding and check consistency of hidden internal registers (Chen et al., 2021).

A more refined oracle taxonomy arises in exact simulation of Haar moments. For UU8-query interaction, one can define four query types: forward, conjugate, transpose, and inverse. A recent representation-theoretic construction produces all four as exact oracles by arranging Clebsch–Gordan and dual-Clebsch–Gordan blocks in different four-gate patterns. In this formulation, forward queries implement UU9, conjugate queries simulate U,UU,U^\dagger0, transpose queries effect U,UU,U^\dagger1, and inverse queries implement U,UU,U^\dagger2 (Grinko et al., 30 Sep 2025).

This four-interface perspective clarifies that the QHROM is not merely an abstract “black box for a random unitary.” It is a model of consistent coherent access to multiple algebraically related actions of the same Haar-random object. A plausible implication is that security notions stated only for forward access may miss structure that becomes relevant when U,UU,U^\dagger3, U,UU,U^\dagger4, or U,UU,U^\dagger5 are also queryable.

3. Stateful simulation, lazy sampling, and compressed-oracle methods

A central problem in QHROM is efficient simulation of ideal Haar objects against adversaries with black-box access. The first major simulation results establish stateful simulators that remain information-theoretically indistinguishable from the ideal Haar oracle even to unbounded adversaries (Alagic et al., 2019).

For Haar-random states, the simulator maintains entanglement in the symmetric subspace. After U,UU,U^\dagger6 samples, the adversary’s reduced state is

U,UU,U^\dagger7

To simulate a new U,UU,U^\dagger8 call, the simulator applies an efficiently implementable symmetrization isometry U,UU,U^\dagger9 that extends a maximally entangled state on {U}N\{U_\ell\}_{\ell\in\mathbb N}0 to one on {U}N\{U_\ell\}_{\ell\in\mathbb N}1. The same mechanism supports {U}N\{U_\ell\}_{\ell\in\mathbb N}2 and {U}N\{U_\ell\}_{\ell\in\mathbb N}3 by inverting the last symmetrization step, performing a simple measurement or phase, and reapplying the isometry (Alagic et al., 2019).

For Haar-random unitaries, the simulator uses exact unitary {U}N\{U_\ell\}_{\ell\in\mathbb N}4-designs {U}N\{U_\ell\}_{\ell\in\mathbb N}5 and a stateful interpolation between {U}N\{U_\ell\}_{\ell\in\mathbb N}6 and {U}N\{U_\ell\}_{\ell\in\mathbb N}7. If an adversary makes at most {U}N\{U_\ell\}_{\ell\in\mathbb N}8 parallel forward or inverse queries, one can sample a uniform superposition over {U}N\{U_\ell\}_{\ell\in\mathbb N}9 in a private register and apply controlled-UU_\ell0 or controlled-UU_\ell1. Adaptive extension to the UU_\ell2-st query relies on a partial isometry UU_\ell3 guaranteed by uniqueness of Stinespring dilation. The resulting unitary simulator is exact and uses total private space UU_\ell4 qubits (Alagic et al., 2019).

These results establish a basic methodological point: a stateless UU_\ell5-design is insufficient for arbitrary adaptive interaction. A single fixed UU_\ell6-design only answers up to UU_\ell7 queries, whereas a stateful simulator stores enough information to preserve consistency indefinitely (Alagic et al., 2019).

Later work introduced the path-recording formalism as a compressed-oracle technique specialized to Haar unitary access. For an injective relation UU_\ell8, the path-recording isometry UU_\ell9 acts by

UU_\ell^\dagger0

Its right-invariance theorem states that for any UU_\ell^\dagger1-query adversary,

UU_\ell^\dagger2

providing an explicit approximation guarantee between Haar access and a path-recording oracle (Ananth et al., 2024). This formalism underlies later pseudorandomness proofs and can be viewed as a quantum analogue of compressed or lazy sampling for random functions.

4. Representation-theoretic formulation and Clebsch–Gordan simulation

A representation-theoretic formulation generalizes Haar-oracle simulation from UU_\ell^\dagger3 to arbitrary compact groups. Let UU_\ell^\dagger4 be a compact group and UU_\ell^\dagger5 a unitary representation on a UU_\ell^\dagger6-dimensional Hilbert space UU_\ell^\dagger7. The UU_\ell^\dagger8-fold tensor power admits the Schur–Weyl (Peter–Weyl) decomposition

UU_\ell^\dagger9

Here \ell0 is the finite set of irreducible representation labels appearing in \ell1, \ell2 is the carrier space of irrep \ell3, and \ell4 is the multiplicity space (Grinko et al., 30 Sep 2025).

By Schur’s lemma, the commutant of \ell5 is spanned by matrix units

\ell6

where \ell7 range over an orthonormal basis \ell8 of \ell9. The multiplicity basis may be labeled by Gelfand–Tsetlin or branching patterns

UU(d)U\in U(d)00

which encode the path of irreducible components encountered when adjoining one copy of UU(d)U\in U(d)01 at a time (Grinko et al., 30 Sep 2025).

The oracle construction introduces an auxiliary memory that purifies the Haar randomness. The memory starts in the trivial irrep state UU(d)U\in U(d)02, and each query extends a superposition over irrep labels and multiplicity patterns by interleaving a Clebsch–Gordan transform and a dual-Clebsch–Gordan transform. A single compressed Clebsch–Gordan step uses preprocessing UU(d)U\in U(d)03, a compressed unitary UU(d)U\in U(d)04 of gate-depth UU(d)U\in U(d)05 and ancilla UU(d)U\in U(d)06, and an uncomputation stage (Grinko et al., 30 Sep 2025).

For the UU(d)U\in U(d)07-th forward query, the oracle is

UU(d)U\in U(d)08

If the query arrives in state UU(d)U\in U(d)09, then

UU(d)U\in U(d)10

Tracing out memory yields

UU(d)U\in U(d)11

so UU(d)U\in U(d)12 successive queries reproduce the exact Haar integral (Grinko et al., 30 Sep 2025).

The same architecture produces conjugate, transpose, and inverse oracles by permuting the positions of Clebsch–Gordan and dual-Clebsch–Gordan blocks. Inverse access is realized by exchanging dual blocks so that

UU(d)U\in U(d)13

For the unitary group, the resulting simulator is efficient in both space and time: total gate complexity and depth

UU(d)U\in U(d)14

ancilla usage

UU(d)U\in U(d)15

and worst-case diamond-norm error at most UU(d)U\in U(d)16, with the mathematical construction itself exact and error arising only from UU(d)U\in U(d)17-approximate compilation of the Clebsch–Gordan unitaries (Grinko et al., 30 Sep 2025).

This construction is presented as a representation-theoretic generalization of Zhandry’s compressed function-oracle technique. Relative to earlier unitary-oracle simulators, it is fully constructive, supports arbitrary precision UU(d)U\in U(d)18, and unifies forward, conjugate, transpose, and inverse queries in a single framework (Grinko et al., 30 Sep 2025).

5. Cryptographic applications and proof-system uses

QHROM has been used as an idealized foundation for several quantum cryptographic constructions. One early application is information-theoretic quantum money. By replacing the ideal Haar-state oracle with the polynomial-time simulator for Haar-random states, minting becomes a call to UU(d)U\in U(d)19 and verification becomes a call to UU(d)U\in U(d)20. Because the simulator is negligibly close to the ideal oracle even for unbounded adversaries, the resulting Haar-money scheme is described as perfectly information-theoretically unforgeable and untraceable (Alagic et al., 2019).

A different application is the quantum Merkle tree. In that construction, prover and verifier share access to a Haar-random unitary UU(d)U\in U(d)21 on UU(d)U\in U(d)22 qubits and its inverse. To commit to an UU(d)U\in U(d)23-qubit state UU(d)U\in U(d)24, the prover organizes UU(d)U\in U(d)25 with UU(d)U\in U(d)26, allocates registers at the nodes of a perfect binary tree, stores the UU(d)U\in U(d)27-qubit blocks of UU(d)U\in U(d)28 at the leaves, and for each internal node applies UU(d)U\in U(d)29 to the triple consisting of the two children and the parent initialized to UU(d)U\in U(d)30. The prover sends only the root register to the verifier. To decommit to a leaf set UU(d)U\in U(d)31, the prover reveals the corresponding light cone, and the verifier reapplies UU(d)U\in U(d)32 in reverse order while checking that each recovered parent register is UU(d)U\in U(d)33. The communication to open UU(d)U\in U(d)34 leaves is UU(d)U\in U(d)35 many UU(d)U\in U(d)36-qubit registers, hence UU(d)U\in U(d)37 when UU(d)U\in U(d)38 (Chen et al., 2021).

The security claim for the quantum Merkle tree is query-bounded soundness: an unbounded cheating prover making at most UU(d)U\in U(d)39 oracle queries should not significantly exceed the target soundness, and the paper conjectures a bound of the form

UU(d)U\in U(d)40

over the Haar choice of UU(d)U\in U(d)41 (Chen et al., 2021). This suggests that the commitment’s binding property is intended to derive from the unpredictability of the unqueried action of a Haar-random unitary.

Haar-oracle models also support constructions of quantum pseudorandom objects weaker than full pseudorandom unitaries. In the invertible label-indexed QHRO model, an Even–Mansour–style function-like state generator is defined by

UU(d)U\in U(d)42

For any unbounded adversary making up to UU(d)U\in U(d)43 classical adaptive queries to the construction and up to UU(d)U\in U(d)44 adaptive quantum queries to UU(d)U\in U(d)45 and UU(d)U\in U(d)46, the distinguishing advantage between the real and ideal experiments is bounded by

UU(d)U\in U(d)47

yielding the first unconditional adaptive-secure PRFSG in that model (Hhan et al., 2024).

State-only Haar-oracle models have also been used to separate quantum pseudorandomness notions. Relative to an oracle that outputs a single Haar-random state, there exists a statistical single-copy pseudorandom state construction, and in a stronger isometry-oracle setting there is a separation showing that 1PRS can exist while PRS do not (Chen et al., 2024). This indicates that access to Haar-random quantum objects can support nontrivial cryptographic primitives even when stronger notions remain impossible.

6. Pseudorandom unitaries, limitations, and open directions

A major development in QHROM is the construction of pseudorandom unitaries directly from a shared Haar oracle. In the inverseless Haar Random Oracle Model, unbounded-query secure PRUs exist with two calls to the Haar oracle, via

UU(d)U\in U(d)48

The same work proves that any one-call construction of the form UU(d)U\in U(d)49 is insecure for unbounded-query security: it can be broken by UU(d)U\in U(d)50 non-adaptive queries. It also gives a bounded-query one-call PRU,

UU(d)U\in U(d)51

secure for UU(d)U\in U(d)52 queries, together with one-call multi-copy PRSG and PRFS constructions (Ananth et al., 2024).

In the full QHROM with inverse access, strong PRUs have now been constructed. Fixing target length UU(d)U\in U(d)53, the key space is UU(d)U\in U(d)54, with UU(d)U\in U(d)55, and

UU(d)U\in U(d)56

on the UU(d)U\in U(d)57-qubit register. The corresponding security theorem states that this family is a strong PRU in QHROM: for every QPT adversary making polynomially many forward and inverse oracle calls, the distinguishing advantage between the real experiment and one using two independent Haar-random unitaries is negligible (Ananth et al., 29 Sep 2025).

The proof strategy combines hybrid arguments with path-recording isometries. One step replaces Haar-random unitaries with Ma–Huang path-recording isometries UU(d)U\in U(d)58, incurring global trace-distance error UU(d)U\in U(d)59; later steps compare UU(d)U\in U(d)60 with simplified operators UU(d)U\in U(d)61, with operator-norm deviation UU(d)U\in U(d)62, and show that cumulative distinguishing advantage remains UU(d)U\in U(d)63 before reversing the simplifications by Haar invariance (Ananth et al., 29 Sep 2025). This places path recording at the center of modern QHROM pseudorandomness proofs.

Several limitations and open problems recur across the literature. One is the minimum number of sequential Haar calls needed for strong PRUs in QHROM; the current conjecture is that two calls are tight even with inverse access (Ananth et al., 29 Sep 2025). Another is whether comparable constructions can be instantiated in the plain model, for example from LWE or one-way functions (Ananth et al., 29 Sep 2025). On the simulation side, open questions include extending efficient Clebsch–Gordan transforms to other groups such as permutations and reducing the UU(d)U\in U(d)64-dependence in time or space toward lower bounds (Grinko et al., 30 Sep 2025). In function-like state generation, open questions include whether the same key can be reused for both masks and whether depth-1 QHRO constructions admit stronger quantum-accessible security notions (Hhan et al., 2024).

A recurrent misconception is that fixed UU(d)U\in U(d)65-designs alone realize the full QHROM. The simulation results show otherwise: a stateless UU(d)U\in U(d)66-design suffices only up to UU(d)U\in U(d)67 queries, whereas exact or negligibly accurate emulation of ongoing adaptive interaction requires stateful internal memory, whether via symmetric-subspace lazy sampling, Stinespring interpolation, path recording, or representation-theoretic compressed oracles (Alagic et al., 2019). The modern view of QHROM is therefore not just “Haar randomness as an oracle,” but a collection of techniques for maintaining coherent consistency of that randomness under extended quantum interaction.

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Quantum Haar Random Oracle Model.