---
title: Quantum Haar Random Oracle Model
url: https://www.emergentmind.com/topics/quantum-haar-random-oracle-model
type: topic
---

# Quantum Haar Random Oracle Model

Searching arXiv for recent papers on the Quantum Haar Random Oracle Model and related constructions.
arxiv_search(query="Quantum Haar Random Oracle Model", max_results=10, sort_by="submittedDate")
The Quantum Haar Random Oracle Model (QHROM) is an idealized framework in which parties receive oracle access to quantum objects sampled from Haar-invariant distributions, most commonly a Haar-random unitary together with its inverse, and in some formulations a Haar-random state or a family of independent Haar-random unitaries indexed by input length or classical labels. It serves as a quantum analogue of random-oracle and random-permutation idealizations, but with fully coherent oracle access: queries may be made in superposition, inverse access is often explicit, and security is typically formulated against adaptive, entangled, and even unbounded adversaries subject only to a query bound [1910.05729]. Subsequent work has developed exact or negligible-error stateful simulators, compressed-oracle and path-recording techniques, representation-theoretic constructions based on Clebsch–Gordan transforms, and cryptographic applications ranging from quantum money and pseudorandomness to succinct commitments and proof systems [2509.26623].

## 1. Formal definitions and model variants

Across the literature, the term QHROM denotes a family of closely related ideal models rather than a single canonical interface. The common feature is oracle access to Haar-distributed quantum objects under coherent querying.

| Variant | Sampled object | Oracle access |
|---|---|---|
| Random-state/unitary sampler | A single Haar-random state \(|\psi\rangle\) or unitary \(U\in U(d)\) | State interfaces or \(U,U^\dagger\) [1910.05729] |
| Invertible QHROM | A single \(n\)-qubit Haar-random unitary \(U\) | Forward and inverse superoperators \(U,U^\dagger\) [2410.19320] |
| Family-valued QHROM | Independent Haar-random unitaries \(\{U_\ell\}_{\ell\in\mathbb N}\) | Access to \(U_\ell\) and \(U_\ell^\dagger\) on \(\ell\)-qubit inputs [2509.24432] |
| Label-indexed invertible QHRO | Independent Haar-random unitaries \(\{U_x\}_x\) | Queries \(|x\rangle|\psi\rangle\mapsto |x\rangle U_x|\psi\rangle\) and inverse [2411.03201] |
| Proof-system QHROM | A single Haar-random unitary \(G\in U(2^\lambda)\) | Prover and verifier both access \(G,G^\dagger\) [2112.14317] |

In the formulation of efficient simulation, a trusted oracle machine samples either a pure state \(|\psi\rangle\in\mathbb C^d\) uniformly from the Haar measure on the unit sphere or a unitary \(U\in U(d)\) uniformly from the Haar measure \(d\mu_{\mathrm{Haar}}(U)\) on the compact group \(U(d)\) [1910.05729]. In the unitary case, the basic ideal interfaces are \(\mathcal O^u.\mathrm{Gen}()\), \(\mathcal O^u.\mathrm{Forward}(\rho)\to U\rho U^\dagger\), and \(\mathcal O^u.\mathrm{Inverse}(\rho)\to U^\dagger \rho U\) [1910.05729].

A distinct but compatible formalization fixes a security parameter \(n\) and gives every party oracle access to a family
\[
\{U_\ell:\ell\in\mathbb N\}
\quad\text{and}\quad
\{U_\ell^\dagger:\ell\in\mathbb N\},
\qquad
U_\ell \overset{\sf Haar}{\longleftarrow} U(2^\ell),
\]
with oracle queries permitted in superposition on an \(\ell\)-qubit register [2509.24432]. This formulation is tailored to cryptographic indistinguishability definitions.

In interactive-proof applications, QHROM is built directly into completeness and soundness conditions. An interactive protocol \(\Pi\) is said to be a proof system in QHROM if both prover and verifier receive input \(x\in\{0,1\}^n\) and oracle access to
\[
G \stackrel{\$}{\leftarrow} \mathrm{Haar}\bigl(U(2^\lambda)\bigr)
\quad\text{and}\quad
G^\dagger,
\]
with soundness quantified against any unbounded prover making at most \(t\) total queries to \(G\) and \(G^\dagger\) [2112.14317].

A related state-only idealization replaces Haar-random unitaries by an oracle that, on input \(1^m\), supplies a fresh \(m\)-qubit Haar-random state \(\ket{\psi_m}\), equivalently an isometry \(V_m:\ket{0}\mapsto\ket{\psi_m}\) [2404.03295]. This is not the unitary QHROM itself, but it belongs to the same family of Haar-oracle models and is used to study separations among quantum pseudorandom notions.

## 2. Oracle interfaces and operational semantics

The operational content of QHROM depends on the sampled object. For Haar-random states, the ideal sampler \(\mathcal O^s\) exposes four interfaces: \(\mathcal O^s.\mathrm{Gen}()\), which returns a classical description \(\tilde\psi\) of \(|\psi\rangle\); \(\mathcal O^s.\mathrm{Sample}()\), which outputs an \(n\)-qubit register in state \(|\psi\rangle\); \(\mathcal O^s.\mathrm{Verify}()\), which measures \(\{\Pi_\psi=|\psi\rangle\langle\psi|,\mathbb 1-|\psi\rangle\langle\psi|\}\); and \(\mathcal O^s.\mathrm{Reflect}(C\otimes \rho)\), which applies the controlled reflection
\[
R_\psi := |0\rangle\langle 0|_C\otimes\mathbb 1 + |1\rangle\langle 1|_C\otimes(\mathbb 1-2|\psi\rangle\langle\psi|).
\]
These interfaces make the state oracle more structured than a simple source of copies, because they allow coherent verification and reflection relative to the same hidden Haar state [1910.05729].

For Haar-random unitaries, the minimal interface is forward and inverse access. The terminology “forward access” refers to oracle application of \(U\), while “inverse access” refers to \(U^\dagger\) [1910.05729]. In proof systems and commitment schemes this inverse interface is operationally essential: the verifier uses \(G^\dagger\) to reverse portions of the prover’s encoding and check consistency of hidden internal registers [2112.14317].

A more refined oracle taxonomy arises in exact simulation of Haar moments. For \(t\)-query interaction, one can define four query types: forward, conjugate, transpose, and inverse. A recent representation-theoretic construction produces all four as exact oracles by arranging Clebsch–Gordan and dual-Clebsch–Gordan blocks in different four-gate patterns. In this formulation, forward queries implement \(U\), conjugate queries simulate \(U^*\), transpose queries effect \(U^T\), and inverse queries implement \(U^{-1}\) [2509.26623].

This four-interface perspective clarifies that the QHROM is not merely an abstract “black box for a random unitary.” It is a model of consistent coherent access to multiple algebraically related actions of the same Haar-random object. A plausible implication is that security notions stated only for forward access may miss structure that becomes relevant when \(U^\dagger\), \(U^T\), or \(U^*\) are also queryable.

## 3. Stateful simulation, lazy sampling, and compressed-oracle methods

A central problem in QHROM is efficient simulation of ideal Haar objects against adversaries with black-box access. The first major simulation results establish stateful simulators that remain information-theoretically indistinguishable from the ideal Haar oracle even to unbounded adversaries [1910.05729].

For Haar-random states, the simulator maintains entanglement in the symmetric subspace. After \(t\) samples, the adversary’s reduced state is
\[
\tau_t=\mathbb E_{\psi\sim \mathrm{Haar}}\bigl[|\psi\rangle\langle\psi|^{\otimes t}\bigr]
=\Pi^{\mathrm{Sym}}_{n,t}/\dim \mathrm{Sym}_{n,t}.
\]
To simulate a new \(\mathrm{Sample}()\) call, the simulator applies an efficiently implementable symmetrization isometry \(V^{t\to t+1}\) that extends a maximally entangled state on \(\mathrm{Sym}^t(\mathbb C^{2^n})\) to one on \(\mathrm{Sym}^{t+1}(\mathbb C^{2^n})\). The same mechanism supports \(\mathrm{Verify}\) and \(\mathrm{Reflect}\) by inverting the last symmetrization step, performing a simple measurement or phase, and reapplying the isometry [1910.05729].

For Haar-random unitaries, the simulator uses exact unitary \(t\)-designs \(D_t\) and a stateful interpolation between \(D_t\) and \(D_{t+1}\). If an adversary makes at most \(t\) parallel forward or inverse queries, one can sample a uniform superposition over \(D_t\) in a private register and apply controlled-\(U_{t,i}\) or controlled-\(U_{t,i}^\dagger\). Adaptive extension to the \((t+1)\)-st query relies on a partial isometry \(W^{(t,\ell)}:B_t\to B_{t+1}\) guaranteed by uniqueness of Stinespring dilation. The resulting unitary simulator is exact and uses total private space \(\log |I_t|=O(t\cdot 2n)\) qubits [1910.05729].

These results establish a basic methodological point: a stateless \(t\)-design is insufficient for arbitrary adaptive interaction. A single fixed \(t\)-design only answers up to \(t\) queries, whereas a stateful simulator stores enough information to preserve consistency indefinitely [1910.05729].

Later work introduced the path-recording formalism as a compressed-oracle technique specialized to Haar unitary access. For an injective relation \(R\subset [N]\times [N]\), the path-recording isometry \(\mathrm{PR}\) acts by
\[
\mathrm{PR}:|x\rangle_A|R\rangle_E
\mapsto (N-|R|)^{-1/2}\sum_{y\notin \mathrm{Im}(R)} |y\rangle_A |R\cup\{(x,y)\}\rangle_E.
\]
Its right-invariance theorem states that for any \(t\)-query adversary,
\[
\mathrm{TD}(\rho_{\mathrm{Haar}},\rho_{\mathrm{PR}})
\le \frac{2t(t-1)}{N+1},
\]
providing an explicit approximation guarantee between Haar access and a path-recording oracle [2410.19320]. This formalism underlies later pseudorandomness proofs and can be viewed as a quantum analogue of compressed or lazy sampling for random functions.

## 4. Representation-theoretic formulation and Clebsch–Gordan simulation

A representation-theoretic formulation generalizes Haar-oracle simulation from \(U(d)\) to arbitrary compact groups. Let \(G\) be a compact group and \(R:G\to \mathrm{End}(V)\) a unitary representation on a \(d\)-dimensional Hilbert space \(V\). The \(t\)-fold tensor power admits the Schur–Weyl (Peter–Weyl) decomposition
\[
V^{\otimes t}\cong \bigoplus_{\lambda\in \hat G^{(t)}} V_\lambda\otimes M_\lambda,
\qquad
R(g)^{\otimes t}\cong \bigoplus_{\lambda\in \hat G^{(t)}} [R_\lambda(g)\otimes I_{M_\lambda}]
\quad \forall g\in G.
\]
Here \(\hat G^{(t)}\) is the finite set of irreducible representation labels appearing in \(V^{\otimes t}\), \(V_\lambda\) is the carrier space of irrep \(R_\lambda\), and \(M_\lambda\) is the multiplicity space [2509.26623].

By Schur’s lemma, the commutant of \(R^{\otimes t}\) is spanned by matrix units
\[
E^\lambda_{T,S}=I_{V_\lambda}\otimes |T\rangle\langle S|_{M_\lambda},
\]
where \(T,S\) range over an orthonormal basis \(B(\lambda)\) of \(M_\lambda\). The multiplicity basis may be labeled by Gelfand–Tsetlin or branching patterns
\[
T=(T_0,t_1,T_1,\ldots,t_t,T_t),
\]
which encode the path of irreducible components encountered when adjoining one copy of \(R\) at a time [2509.26623].

The oracle construction introduces an auxiliary memory that purifies the Haar randomness. The memory starts in the trivial irrep state \(|\emptyset\rangle_{\mathrm{mem}}\), and each query extends a superposition over irrep labels and multiplicity patterns by interleaving a Clebsch–Gordan transform and a dual-Clebsch–Gordan transform. A single compressed Clebsch–Gordan step uses preprocessing \(P_k\), a compressed unitary \(\widetilde{\mathrm{CG}}_k\) of gate-depth \(\widetilde O(k^4)\) and ancilla \(\widetilde O(k^2)\), and an uncomputation stage [2509.26623].

For the \(k\)-th forward query, the oracle is
\[
fO_k=(I_{\mathrm{input}}\otimes \mathrm{CG}_k)\cdot
(\mathrm{SWAP}_{\mathrm{input},\mathrm{multiplicity}})\cdot
(I_{\mathrm{input}}\otimes d\mathrm{CG}_k).
\]
If the query arrives in state \(|i,j\rangle_{\mathrm{in}}\), then
\[
|\emptyset\rangle_{\mathrm{mem}}|i,j\rangle_{\mathrm{in}}
\mapsto
\sum_{\lambda,T,S}\frac{1}{\sqrt{d_\lambda}}|\lambda,T\rangle_{\mathrm{mem}}
\,(E^\lambda_{T,S}\otimes I)\,|i,j\rangle_{\mathrm{in}}
\otimes |\lambda,S\rangle_{\mathrm{mem}}.
\]
Tracing out memory yields
\[
\int dU\, U^{\otimes t}\otimes U^{\dagger\otimes t}
=
\sum_{\lambda,T,S}\frac{1}{d_\lambda}E^\lambda_{T,S}\otimes E^\lambda_{T,S}^\dagger,
\]
so \(t\) successive queries reproduce the exact Haar integral [2509.26623].

The same architecture produces conjugate, transpose, and inverse oracles by permuting the positions of Clebsch–Gordan and dual-Clebsch–Gordan blocks. Inverse access is realized by exchanging dual blocks so that
\[
iO: |w\rangle_{\mathrm{mem}}|\psi\rangle_{\mathrm{in}}
\mapsto
|w\rangle_{\mathrm{mem}}(U_w^{-1}|\psi\rangle_{\mathrm{in}}).
\]
For the unitary group, the resulting simulator is efficient in both space and time: total gate complexity and depth
\[
\widetilde O\!\bigl(t^5\,\mathrm{poly}(\log d,\log 1/\epsilon)\bigr),
\]
ancilla usage
\[
\widetilde O\!\bigl(t^2\,\mathrm{poly}(\log d,\log 1/\epsilon)\bigr),
\]
and worst-case diamond-norm error at most \(t\epsilon\), with the mathematical construction itself exact and error arising only from \(\epsilon\)-approximate compilation of the Clebsch–Gordan unitaries [2509.26623].

This construction is presented as a representation-theoretic generalization of Zhandry’s compressed function-oracle technique. Relative to earlier unitary-oracle simulators, it is fully constructive, supports arbitrary precision \(\epsilon\), and unifies forward, conjugate, transpose, and inverse queries in a single framework [2509.26623].

## 5. Cryptographic applications and proof-system uses

QHROM has been used as an idealized foundation for several quantum cryptographic constructions. One early application is information-theoretic quantum money. By replacing the ideal Haar-state oracle with the polynomial-time simulator for Haar-random states, minting becomes a call to \(\mathrm{Sample}()\) and verification becomes a call to \(\mathrm{Verify}()\). Because the simulator is negligibly close to the ideal oracle even for unbounded adversaries, the resulting Haar-money scheme is described as perfectly information-theoretically unforgeable and untraceable [1910.05729].

A different application is the quantum Merkle tree. In that construction, prover and verifier share access to a Haar-random unitary \(G\) on \(\lambda\) qubits and its inverse. To commit to an \(N\)-qubit state \(\sigma\), the prover organizes \(N=b\cdot \ell\) with \(\ell=2^d\), allocates registers at the nodes of a perfect binary tree, stores the \(b\)-qubit blocks of \(\sigma\) at the leaves, and for each internal node applies \(G\) to the triple consisting of the two children and the parent initialized to \(|0^b\rangle\). The prover sends only the root register to the verifier. To decommit to a leaf set \(S\), the prover reveals the corresponding light cone, and the verifier reapplies \(G^\dagger\) in reverse order while checking that each recovered parent register is \(|0^b\rangle\). The communication to open \(k\) leaves is \(O(k\log \ell)\) many \(b\)-qubit registers, hence \(O(\lambda\log N)\) when \(b=\lambda/3\) [2112.14317].

The security claim for the quantum Merkle tree is query-bounded soundness: an unbounded cheating prover making at most \(t\) oracle queries should not significantly exceed the target soundness, and the paper conjectures a bound of the form
\[
s(n,t,\lambda)=s_{\mathrm{target}}+\mathrm{poly}(t)\,2^{-\Omega(\lambda)}
\]
over the Haar choice of \(G\) [2112.14317]. This suggests that the commitment’s binding property is intended to derive from the unpredictability of the unqueried action of a Haar-random unitary.

Haar-oracle models also support constructions of quantum pseudorandom objects weaker than full pseudorandom unitaries. In the invertible label-indexed QHRO model, an Even–Mansour–style function-like state generator is defined by
\[
|\phi_k(x)\rangle = X_{k_1} U_x X_{k_0}|x\rangle_A.
\]
For any unbounded adversary making up to \(p\) classical adaptive queries to the construction and up to \(q\) adaptive quantum queries to \(U_x\) and \(U_x^{-1}\), the distinguishing advantage between the real and ideal experiments is bounded by
\[
\frac{p^3+p^2 q^2}{2^n}=\mathrm{negl}(n),
\]
yielding the first unconditional adaptive-secure PRFSG in that model [2411.03201].

State-only Haar-oracle models have also been used to separate quantum pseudorandomness notions. Relative to an oracle that outputs a single Haar-random state, there exists a statistical single-copy pseudorandom state construction, and in a stronger isometry-oracle setting there is a separation showing that 1PRS can exist while PRS do not [2404.03295]. This indicates that access to Haar-random quantum objects can support nontrivial cryptographic primitives even when stronger notions remain impossible.

## 6. Pseudorandom unitaries, limitations, and open directions

A major development in QHROM is the construction of pseudorandom unitaries directly from a shared Haar oracle. In the inverseless Haar Random Oracle Model, unbounded-query secure PRUs exist with two calls to the Haar oracle, via
\[
G_k^U = U\cdot (X^k\otimes I)\cdot U.
\]
The same work proves that any one-call construction of the form \(G_k^U=B\cdot U\cdot A\) is insecure for unbounded-query security: it can be broken by \(\Omega(\lambda/\log\lambda)\) non-adaptive queries. It also gives a bounded-query one-call PRU,
\[
G_k^U=(Z^k\otimes I)\cdot U,
\]
secure for \(\ell=O(\lambda/\log^{1+\epsilon}\lambda)\) queries, together with one-call multi-copy PRSG and PRFS constructions [2410.19320].

In the full QHROM with inverse access, strong PRUs have now been constructed. Fixing target length \(n\), the key space is \(\mathcal K=\{0,1\}^{3n}\), with \(k=k_1\Vert k_2\Vert k_3\), and
\[
G_k^U = X^{k_3}\,U\,X^{k_2}\,U\,X^{k_1}
\]
on the \(n\)-qubit register. The corresponding security theorem states that this family is a strong PRU in QHROM: for every QPT adversary making polynomially many forward and inverse oracle calls, the distinguishing advantage between the real experiment and one using two independent Haar-random unitaries is negligible [2509.24432].

The proof strategy combines hybrid arguments with path-recording isometries. One step replaces Haar-random unitaries with Ma–Huang path-recording isometries \(V_i\), incurring global trace-distance error \(O(q^2/2^{n/8})\); later steps compare \(V_i\) with simplified operators \(F_i\), with operator-norm deviation \(O(q/\sqrt{2^n})\), and show that cumulative distinguishing advantage remains \(O(q^2/\sqrt{2^n})\) before reversing the simplifications by Haar invariance [2509.24432]. This places path recording at the center of modern QHROM pseudorandomness proofs.

Several limitations and open problems recur across the literature. One is the minimum number of sequential Haar calls needed for strong PRUs in QHROM; the current conjecture is that two calls are tight even with inverse access [2509.24432]. Another is whether comparable constructions can be instantiated in the plain model, for example from LWE or one-way functions [2509.24432]. On the simulation side, open questions include extending efficient Clebsch–Gordan transforms to other groups such as permutations and reducing the \(t\)-dependence in time or space toward lower bounds [2509.26623]. In function-like state generation, open questions include whether the same key can be reused for both masks and whether depth-1 QHRO constructions admit stronger quantum-accessible security notions [2411.03201].

A recurrent misconception is that fixed \(t\)-designs alone realize the full QHROM. The simulation results show otherwise: a stateless \(t\)-design suffices only up to \(t\) queries, whereas exact or negligibly accurate emulation of ongoing adaptive interaction requires stateful internal memory, whether via symmetric-subspace lazy sampling, Stinespring interpolation, path recording, or representation-theoretic compressed oracles [1910.05729]. The modern view of QHROM is therefore not just “Haar randomness as an oracle,” but a collection of techniques for maintaining coherent consistency of that randomness under extended quantum interaction.

Source: https://www.emergentmind.com/topics/quantum-haar-random-oracle-model