How To Track Qubits Through Space and Time
(Or: Sailing in a Quantum Boat)

James Bartusek
Columbia

,

Zikuan Huang
Shanghai Qizhi Institute

,

Leo Orshansky
Columbia

,

Henry Yuen
Columbia


Abstract

While quantum position verification aims to certify a prover’s location using quantum information, existing security definitions only guarantee that part of the successful adversarial party is in the claimed location. This leaves open the possibility that a distributed team of adversaries can jointly simulate a prover in a way that defeats the intended meaning of “being at a location” in position-based cryptography.

We introduce stronger notions of position verification that we call quantum localization, which requires that there is a specified, unclonable state at the verified spacetime point – and that this state can be found nowhere else. We show that quantum localization leads naturally to a meaningful notion of trajectory verification, in which quantum information is verifiably tracked through space and time. We construct quantum localization and trajectory verification protocols using quantum anchor states, which generalize coset states from unclonable cryptography. The security of our schemes is proven in the classical oracle (i.e. ideal obfuscation) model, which can be heuristically instantiated in the plain model using post-quantum indistinguishability obfuscation.

We also introduce and instantiate the concept of functionality localization, which guarantees that the adversary has the ability to compute a secret function at the verified spacetime point, and this function cannot be computed anywhere else. This raises the intriguing possibility of localizing computational capabilities in space and time.

More broadly, we believe our notions of quantum localization and our feasibility results provide stronger foundations for position-based cryptography.

1 Introduction↩︎

1.0.0.1 Position verification.

Is it possible to verify a quantum state’s location in space and time? In the field of quantum cryptography, this is ostensibly the goal of quantum position verification (QPV). A QPV protocol attempts to verify the physical location of a user (called the prover) by sending them challenges (which are, in general, quantum states) and receiving responses. Intuitively, the protocol is deemed secure if a successful prover, responding within some timing constraint, must be in a purported location \(L\). As argued by [1][3], secure position verification is impossible in the classical setting because a team of spoofers (all of whom are not in location \(L\)) can copy and forward messages to each other to simulate a fictitious prover in location \(L\). On the other hand, the No-Cloning Theorem of quantum mechanics stymies such copy-and-forwarding attacks, and in fact secure QPV protocols have been established in the bounded-qubits model [4][7] and the random oracle model [8].

One particularly intriguing motivation for QPV is concept of position-based cryptography, in which a user’s credential is established by their physical location (as opposed to being established by having some secret information such as a password or private key) [2]. Position-based cryptography includes tasks such as position-based encryption (i.e., an encrypted message can only be decrypted by recipients in an authorized physical location) or position-based signatures (i.e., a message’s signature ensures that it was authorized from a specific location). Recently, QPV has been generalized to privacy-preserving proofs of location that only reveal part of a prover’s location and nothing else [9] (i.e., a user can prove to the police that they were somewhere far from the scene of a crime, without revealing any other information about their specific whereabouts).

1.0.0.2 A conceptual gap.

However, closer examination reveals a gap between the intuitive goals of QPV and the formal notion of position verification considered thus far. In prior work, security of QPV was defined as follows: a team of spoofers \(\{\mathcal{P}_1,\ldots,\mathcal{P}_k\}\) can succeed in a QPV protocol with high probability only if at least one of the spoofers \(\mathcal{P}_i\) is in the correct location \(L\). This is a rather weak guarantee, however. Imagine trying to use QPV to prove that one is not near the scene of a crime. Unfortunately, the definition only guarantees that at least one spoofer wasn’t at the crime location; it doesn’t say anything about the other spoofers! In other words, the security definition of QPV does not rule out a spoofing strategy that is distributed across space and time.

We illustrate another conceptual difficulty with the security definition of QPV. Consider a natural generalization of position verification that we call trajectory verification: here we want to verify that a prover has traveled along a trajectory \(L(\cdot)\) described as a function of time \(t\). A natural approach is to run separate QPV protocols \(\left\{\Pi_i\right\}_i\) for many spacetime points \(\left\{(L(t_i),t_i)\right\}_i\), respectively, such that these points divide the trajectory into sufficiently small segments. An immediate problem is that the existing security guarantees of \(\Pi_1,\Pi_2,\ldots\) do not distinguish between whether a single prover has traveled along the trajectory \(L(\cdot)\) or whether an entire team \(\{\mathcal{P}_1,\mathcal{P}_2,\ldots\}\) of provers participated in the protocol, where each prover \(\mathcal{P}_i\) is stationed at location \(L(t_i)\), only participating in protocol \(\Pi_i\) at time \(t_i\). To rule out the latter scenario, one needs to explain why a line of provers is fundamentally different from a single prover that is moving!

1.0.0.3 This work.

These issues call for a notion of localizing the behavior of an adversary who might be a priori distributed in space and time. The main contributions of this paper are to define several notions of “quantum localization” and establish their feasibility via constructions in the (classical) ideal obfuscation model,1 which can be heuristically instantiated using post-quantum indistinguishability obfuscation of classical circuits. We then show that these notions enable meaningful notions of trajectory verification, yielding the first feasibility result for verifying the trajectory of an entity through spacetime.

We believe that our notions of localization come closer to capturing the concept of secure position verification. They give operational meaning to tracking the physical location of quantum states and computations, and lay the proper foundation for more complicated tasks such as trajectory verification.

1.1 Entanglement Localization and Trajectory Verification↩︎

We present stronger security notions for QPV that we call quantum localization, or localization for short. Informally, these security notions will guarantee that any successful prover strategy (which may involve a team of provers \(\{\mathcal{P}_1,\ldots,\mathcal{P}_k\}\) moving around) must contain a specific object at the correct point \((L,t)\) in spacetime. By “contain,” we mean that there exists a procedure called the extractor acting only on the prover’s strategy at the point \((L,t)\) that recovers the desired object. In this paper we identify three types of objects that can be localized: entanglement, (unclonable families of) quantum states, and (copy-protectable) functionalities.

We first describe entanglement localization and then describe how to build on entanglement localization in order to achieve a meaningful notion of trajectory verification.

1.1.0.1 Entanglement Localization.

Let \(\psi\) be a bipartite entangled state on registers \(\mathbf{A}\) and \(\mathbf{B}\). Consider a QPV protocol where the verifiers generate \(\psi\), keep register \(\mathbf{A}\), and send register \(\mathbf{B}\) to the prover who is purportedly at spacetime point \((L,t)\). We say that the protocol localizes the entanglement in \(\psi\) at \((L,t)\) if for any (possibly nonlocal) prover strategy that is accepted with probability \(\eta\), there exists an extractor \(\mathcal{E}\) that acts on the quantum state at spacetime point \((L,t)\) and achieves the following. With probability \(\eta\), it outputs a register \(\mathbf{B}\) that, together with the verifier’s register \(\mathbf{A}\), is close to being in the state \(\psi\). In other words, it has recovered the entangled state \(\psi\) between register \(\mathbf{A}\) and the spacetime point \((L,t)\) with the same probability as the probability that the prover succeeds in the protocol. We formally define this in 8.

Entanglement localization captures the idea that, in order to be successful, a team of provers must ensure that the quantum entanglement in the state \(\psi\) arrives at spacetime point \((L,t)\). Suppose that \(\psi\) is a pure state that is maximally entangled across the \(V : P\) cut. By monogamy of entanglement, the verifier’s register \(\mathbf{A}\) must then be unentangled with any other location \(L' \neq L\) at time \(t\).

1.1.0.2 Trajectory Verification.

The notion of entanglement localization gives rise to a natural definition of trajectory verification. Let \(L(\cdot)\) denote a trajectory in spacetime. Intuitively, a trajectory verification protocol for \(L(\cdot)\) is secure if there exists a maximally entangled state \(\psi\) such that entanglement localization can be performed with respect to \(\psi\) at spacetime points \((L(t),t)\) for all time \(t\) along the trajectory \(L(\cdot)\). Importantly, the verifier’s part of \(\psi\) remains at the same register \(V\) throughout the protocol, while the prover’s part of \(\psi\) may travel around. This definition captures the idea of a single entity moving along the trajectory \(L(\cdot)\) by tracking the movement of the entanglement \(\psi\). If the prover is accepted by the protocol, monogamy of entanglement implies that \(\psi\) couldn’t have strayed from the trajectory \(L(\cdot)\).

We note that in order to repeatedly run an entanglement localization protocol on the same state, it must satisfy an additional completeness guarantee which we call non-destructive. That is, the prover’s state must remain intact after interacting with the verifier. Therefore, our focus in this work is on building non-destructive versions of quantum localization.

1.1.0.3 Construction.

We show how to construct secure trajectory verification in the ideal obfuscation model. In this model, the \({\sf Setup}\) samples the description of an efficient classical circuit, which all parties are given black-box access to throughout the protocol. Any protocol in this model can be heuristically instantiated in the plain model by applying a candidate post-quantum indistinguishability obfuscator to the classical circuit sampled by \({\sf Setup}\).

Trajectory verification as (informally) defined above immediately yields a protocol for entanglement localization as a special case (where the trajectory is stationary at \(L\)). For the sake of exposition we first describe (a simplified version of) the entanglement localization protocol, and then describe how to extend it to obtain trajectory verification. Moreover, we focus here on the “high success probability” regime, where we only guarantee extraction success if the prover passes the protocol with probability close to 1.

Assume that space is one-dimensional and the location to be verified is the origin \(L = 0\). Place verifiers \(\mathcal{V}_L,\mathcal{V}_R\) at locations \(-1\) and \(+1\), respectively. We assume messages travel one unit of space per unit time.

The entangled state used in our protocol is what we call a quantum anchor state. Let \(S \leq T \leq \mathbb{F}_2^{3n}\) be subspaces of dimension \(n\) and \(2n\), respectively, and let \(u, v \in \mathbb{F}_2^{3n}\) be some vectors. Let \({\sf CS}= \{x_1,x_2,\ldots\}\) denote some canonical set of \(2^n\) coset representatives of \(S\) within \(T\), indexed by \(i \in [2^n]\). We define the state \[\left|\Psi\right\rangle_{\text{\faAnchor}\text{\faShip}} = \frac{1}{\sqrt{2^n}} \sum_{i \in [2^n]} \left|i\right\rangle_{\text{\faAnchor}} \otimes \left|\psi_i\right\rangle_{\text{\faShip}}\] where for each \(i \in [2^n]\), \[\left|\psi_i\right\rangle_{\text{\faShip}} = \frac{1}{\sqrt{|S|}} \sum_{s \in S} (-1)^{\langle s, u \rangle} \left|s + x_i + v\right\rangle_{\text{\faShip}}~.\] We use the icons \(\text{\faAnchor}\) and \(\text{\faShip}\) to denote the “anchor” and “vessel” registers, respectively. The reason for this naming will become apparent shortly.

Readers familiar with unclonable cryptography may recognize \(\left|\psi_i\right\rangle\) as a coset state. That is, the state \(\left|\Psi\right\rangle\) can be seen as a uniform superposition over a set of \(2^n\) possible coset states, each defined with respect to subspace \(S\), dual shift \(u\), and primal shift \(v + x_i\) for some choice of \(x_i \in {\sf CS}\). Note further that \(\left|\Psi\right\rangle\) is maximally entangled across the \(\text{\faAnchor}: \text{\faShip}\) cut with Schmidt rank \(2^n\).

In the \({\sf Setup}\) phase of the protocol (run any time before time \(t = 0\)), the verifiers generate the quantum anchor state \(\left|\Psi\right\rangle\) corresponding to random subspaces \(S \leq T \leq \mathbb{F}_2^{3n}\) and shifts \(u,v \in \mathbb{F}_2^{3n}\). Furthermore, the verifiers prepare a classical oracle \(\mathcal{O}\) (i.e., ideal obfuscation of some classical functionality) which depends on \(S,T,u,v\) and whose behavior we describe shortly. The verifiers publish the oracle \(\mathcal{O}\), which all parties (honest or adversarial) can access as a black box. They also release the vessel register \(\text{\faShip}\) to the prover, while keeping hold of the entangled anchor register \(\text{\faAnchor}\).

In the “online” phase of the protocol (at time \(t = 0\)), the verifiers sample random strings \(a,b \in \{0,1\}^n\), the left verifier sends string \(a\), and the right verifier sends string \(b\). The honest prover with register \(\text{\faShip}\) at location \(L = 0\) gets \(a,b\) at time \(t = 1\). Then,

  1. The honest prover coherently queries the oracle \(\mathcal{O}\) on input \(\left|a \oplus b, z\right\rangle\) where \(\left|z\right\rangle\) is the state of the vessel register \(\text{\faShip}\) in the standard basis. The oracle checks whether \(z \in T + v\) (For the honest prover, this will be true.) and if so, outputs a string \(r_0 = H(0,a \oplus b)\), where \(H\) is a random oracle.2 Otherwise, the oracle outputs \(\bot\).

  2. The honest prover then queries the oracle \(\mathcal{O}\) on input \(\left|a \oplus b,w\right\rangle\) where \(\left|w\right\rangle\) is the state of the vessel register \(\text{\faShip}\) in the Hadamard basis. The oracle checks whether \(w \in S^\perp + u\) (which will be the case) and if so, outputs a string \(r_1 = H(1,a \oplus b)\). Otherwise, the oracle outputs \(\bot\).

  3. The honest prover returns \((r_0,r_1)\) back to the verifiers.

We note that after each query, the vessel register and the anchor state \(\left|\Psi\right\rangle\) have not been disturbed.

The verifiers check that the responses came back by time \(t = 2\), and that \(r_0,r_1\) are indeed equal to \(H(0,a\oplus b), H(1,a \oplus b)\).3 The idea is that the only way for the prover to have “unlocked” \(r_0,r_1\) is if it performed the honest strategy above in the correct location \(L = 0\).

As mentioned above, this is the basic idea behind a protocol that allows us to extract from any prover that passes with probability close to 1. We formalize this in 32. Then, in 9.1, we apply an appropriate notion of sequential repetition in order to establish a more general result, informally stated as follows.

Theorem 1 (Entanglement localization (informal)). Let \((L,t)\) denote the spacetime point being verified. Sequentially repeating the protocol4 above satisfies the following properties:

  • Completeness: The honest prover strategy at spacetime point \((L,t)\) is accepted by the verifiers with probability \(1\).

  • Extraction soundness: Let \(\mathcal{A}\) be any (possibly nonlocal) prover strategy that makes at most a polynomial number of queries to \(\mathcal{O}\) and is accepted with probability at least \(\eta = 1/{\sf poly}({\sf{\lambda}})\). There exists an extractor \(\mathcal{E}\) that takes as input the quantum state generated by the strategy at spacetime point \((L,t)\) and, with probability \(\eta\), outputs a vessel register \(\text{\faShip}\) such that the joint state of the anchor register \(\text{\faAnchor}\) (held by the verifiers) and vessel register \(\text{\faShip}\) has fidelity \(1-1/{\sf poly}({\sf{\lambda}})\) with the quantum anchor state \(\left|\Psi\right\rangle\).

We note that our extractor requires knowledge of \(S,T,u,v\), which it can obtain by making exponentially many queries to \({\mathcal{O}}\). Indeed, we do not require any computational (or query) bound on the extractor for the above notion to be meaningful, since monogamy-of-entanglement is an information-theoretic property. However, we do show that the extractor is efficient if given a secret “extraction key” \({\sf ek}= (S,T,u,v)\), which may be a useful feature, depending on the application.

Given our entanglement localization protocol, the extension to trajectory verification is simple. Let \(L(\cdot)\) be a physically realizable trajectory in spacetime that starts at time \(0\) and ends at \(\tau\), and the spatial points are all contained within the convex hull of the verifiers (i.e., strictly between \(L = -1\) and \(L = 1\)). Discretize time \(0 = t_1 < t_2 < \cdots < t_m = \tau\), and let \(L(t_i)\) denote the spatial location of the trajectory at time \(t_i\).

The trajectory verification protocol has the same \({\sf Setup}\) as the entanglement localization protocol. In the online phase of the protocol, the verifiers run \(m\) invocations of the entanglement localization protocol in sequence for spacetime points \((L(t_i),t_i)\), sending freshly sampled \(a_i,b_i\) each time. We can compose the entanglement localization guarantees of the QPV protocol above to obtain 37, informally stated as follows.

Theorem 2 (Trajectory verification (informal)). The trajectory verification protocol above5 satisfies the following properties:

  • Completeness: An honest prover traversing the trajectory \(L(\cdot)\) is accepted with probability \(1\).

  • Extraction soundness: Let \(\mathcal{A}\) be any (possibly nonlocal) prover strategy that makes at most a polynomial number of queries to \(\mathcal{O}\) and is accepted with probability at least \(\eta = 1/{\sf poly}({\sf{\lambda}})\). There exists an extractor \(\mathcal{E}\) that, for any \(i \in [m]\), takes as input the quantum state generated by the strategy at spacetime point \((L(t_i),t_i)\) and, with probability \(\eta\), outputs a vessel register \(\text{\faShip}\) such that the joint state of the anchor register \(\text{\faAnchor}\) (held by the verifiers) and vessel register \(\text{\faShip}\) has fidelity \(1-1/{\sf poly}({\sf{\lambda}})\) with the quantum anchor state \(\left|\Psi\right\rangle\).

At this point, we hope the “anchor” and “vessel” terminology should appear natural. The \(\text{\faAnchor}\) part of the state \(\left|\Psi\right\rangle\) is “anchored” at the verifier’s location, while the \(\text{\faShip}\) part is launched into the spacetime region under the provers’ control. The provers can a priori perform arbitrarily complex operations on the vessel, but in the end, if they are to pass the trajectory verification protocol, they must faithfully sail the quantum vessel \(\text{\faShip}\) along the trajectory \(L(\cdot)\). The fact that the entanglement persists between the anchor and the points along the trajectory captures the fact that we are tracking the same quantum information through space and time.

Figure 1: A quantum anchor. Generated by GPT.

1.2 State Localization↩︎

A curious aspect of the entanglement localization and trajectory verification protocols described above is that the verifier’s register (the quantum anchor) is never acted upon after the entangled state is prepared. In fact, the verifiers don’t even need this register to check the prover’s responses. Thus, a slightly different way to describe the generation of the anchor state is as follows.

  • Sample \(S,T,u,v\) as above, and define an isometry \(\mathsf{Enc}_{S,T,u,v}\) that maps \[\mathsf{Enc}_{S,T,u,v}: \left|i\right\rangle \to \left|\psi_i\right\rangle = \frac{1}{\sqrt{|S|}} \sum_{s \in S} (-1)^{\langle s, u \rangle} \left|s + x_i + v\right\rangle.\]

  • Prepare the maximally entangled state \[\frac{1}{\sqrt{2^n}}\sum_{i \in [2^n]}\left|i\right\rangle_\text{\faAnchor}\left|i\right\rangle_\text{\faShip}\] and apply \(\mathsf{Enc}_{S,T,u,v}\) to the \(\text{\faShip}\) register.

  • Discard \(\text{\faAnchor}\).

Imagine, then, that instead of applying \(\mathsf{Enc}_{S,T,u,v}\) to half of a maximally entangled state, the verifiers sample a pure state \(\psi_k\) from some unclonable family of states \(\{\psi_k\}_{k \in [K]}\) (say, the BB84 states) and output \(\mathsf{Enc}_{S,T,u,v}\left|\psi_k\right\rangle\). If the purification of this sampling procedure is equivalent to the maximally mixed state, then this is completely identical from both the prover’s and extractor’s perspective, since neither touches the \(\text{\faAnchor}\) register. It follows then that at each intermediate time \(t_i\), the extractor acting on spacetime point \((L(t_i),t_i)\) will output a register in a state close to \(\mathsf{Enc}_{S,T,u,v}\left|\psi_k\right\rangle\). In fact, since the extractor knows \(S,T,u,v\), it can undo the isometry to recover \(\left|\psi_k\right\rangle\) itself.

Thus, even though there is no entanglement to keep track of anymore in this scenario, there is still a meaningful sense in which we have localized a quantum state \(\psi_k\) along the trajectory: At any given time \(t_i\), the state \(\psi_k\) cannot be found at any other location in space since otherwise the adversary / extractor would have been able to clone it.

This motivates the following general definition of state localization. Let \(\mathcal{S} = \{\psi_k \}_k\) denote a family of quantum states indexed by \(k\) (for example, BB84 states or coset states). Suppose the verifiers sample \(k\), generate (and potentially encode) \(\left|\psi_k\right\rangle\), and send the resulting state to the prover. We say that a protocol localizes the state family \(\mathcal{S}\) if for any (possibly nonlocal) prover strategy that is accepted with high probability, there exists an extractor \(\mathcal{E}\) that acts on the quantum state at spacetime point \((L,t)\) and outputs \(\left|\psi_k\right\rangle\) with high fidelity. Furthermore, the state extracted from \((L,t)\) must be unique, in that, in expectation over \(\psi_k \gets \mathcal{S}\), it is impossible for any adversary to output two copies of \(\psi_k\) at any time \(t\). We present a formal definition in 10.

By applying the techniques used to prove [thm:NDEL_overall,thm:TV_overall], we prove 39, informally stated as follows.

Theorem 3 (State localization (informal)). Let \(\mathcal{S}\) be any set of \(n\)-qubit states that consist of a union of orthonormal bases. Then if \(\mathcal{S}\) is unclonable, there exists a protocol that (non-destructively) localizes \(\mathcal{S}\) in the ideal obfuscation model.

While state localization is closely related to entanglement localization, there are some meaningful differences. The extractor produces a quantum state (close to) \(\psi_k\) that is classically correlated with the verifiers’ choice of \(k\). That is, unlike in the case of entanglement localization, the verifier has an actual classical description \(k\) of the state being tracked, as opposed to some entangled register. Thus, there may exist some other side information in the protocol that also depends on \(k\), which may be a useful feature depending on the application. Furthermore, in the setting of purely classical verifiers (such as that of [10]) we cannot obtain entanglement localization, but state localization is still potentially possible (e.g., the verifiers can delegate the preparation of \(\psi_k\) to the prover).

1.2.0.1 Trajectory verification with localized states.

Similarly to how trajectory verification follows naturally from our (non-destructive) entanglement localization protocol, it is straightforward to see that one could build trajectory verification from our (non-destructive) state localization protocol as well. We do not make this explicit, and only present trajectory verification based on entanglement localization in the body.

1.3 Functionality Localization↩︎

Entanglement and state localization capture the idea that the prover must carry a specific quantum state to some spacetime point \((L,t)\). However, can we say anything about the prover’s computational capabilities at \((L,t)\)? This could be desirable in a scenario like export control of secret, proprietary programs (like a foundation language model), where a company or a government would like to guarantee that the ability to run the secret program is localized to a specific location (say within an authorized datacenter).

Let \(\mathcal{F} = \{ f_k \}_k\) denote a family of functions indexed by some key \(k\) (for example, a pseudorandom function family). Suppose that at the beginning of the protocol, the verifiers sample \(k\) privately. We say that a protocol localizes functionality \(\mathcal{F}\) if for any (possibly nonlocal) prover strategy that is accepted with high probability, there exists an extractor \(\mathcal{E}\) that acts on the quantum state at verified spacetime point \((L,t)\) and is able to compute \(f_k(x)\) for a random input \(x\). On the other hand, there must be no (efficient) adversary that can, for random inputs \(x,y\), compute \(f_k(x)\) and \(f_k(y)\) at two separate locations without communicating. In other words, the ability to compute \(f_k(x)\) has been localized to \((L,t)\), and no other location (at time \(t\)) has the ability to compute \(f_k\). This is formally defined in 13.

The notion of functionality localization is closely related to the notion of quantum copy-protection, which is the concept of encoding a function \(f\) in a quantum state \(\psi_f\) that can be used to evaluate \(f\), but cannot used to compute \(f\) in two locations that cannot communicate [11]. There are broad classes of function families that are known to be copy-protectable under various cryptographic assumptions and in various models (see e.g., [12][18]). Here, we show that any functionality \(\mathcal{F}\) that can in principle be copy-protected can also be localized. In fact, we don’t even need to know an explicit copy-protection scheme for \(\mathcal{F}\). Our construction relies on a combination of techniques described above as well as the “best-possible” copy-protection guarantees given by quantum state obfuscation [19], [20]. We defer further details to 2, and establish the following theorem, stated informally.

Theorem 4 (Functionality localization (informal)). Let \(\mathcal{F} = \{ f_k \}_k\) denote any copy-protectable functionality. Then there exists a protocol that (non-destructively) localizes the functionality \(\mathcal{F}\) in the ideal obfuscation model.

1.4 The Ideal Obfuscation Model↩︎

We now provide some more context on the ideal obfuscation model (also referred to as the classical oracle model) that we use to establish the security of our protocols. In this model, one can prepare and then “obfuscate” any polynomial-time computable classical functionality \(f\), and thereafter all entities are granted black-box (superposition) access to \(f\). That is, anyone can apply the unitary \(U_f : \left|x\right\rangle\left|z\right\rangle \to \left|x\right\rangle\left|z \oplus f(x)\right\rangle\) without learning anything else about \(f\).

The ideal obfuscation model has a long history of study in quantum cryptography. In particular, it has been used to establish the feasibility of primitives for which no prior construction existed, e.g. publicly-verifiable quantum money [21], signature tokens [22], copy-protection for unlearnable programs [12], witness encryption for QMA [23], and obfuscation for quantum circuits [20], [24][26].

While ideal obfuscation of classical circuits has long been known to be impossible to achieve for certain contrived classes of functionalities [27], the ideal obfuscation model remains a useful model in which to obtain feasibility results, for the following reasons.

  • First, any construction in the ideal obfuscation model (that does not require obfuscating the contrived functions from [27]) yields a plausibly secure construction in the plain model by using indistinguishability obfuscation (iO) to obfuscate the function \(f\). While we may not have a formal reduction to the security of iO, it is a reasonable heuristic to expect that the plain model construction is secure. This is analogous to how the community proves security in the random oracle model and then replaces the random oracle with a concrete hash function in practice, without necessarily having a formal reduction to any security property of the hash function.

  • Second, a recent work [28], building on [29], has shown that the (quantum-accessible) ideal obfuscation model can be instantiated from indistinguishability obfuscation plus the heuristic use of a hash function (as opposed to an obfuscator) modeled as a “pseudorandom oracle.” This brings the ideal obfuscation model even closer to the widely-used random oracle model in that the only cryptographic object we need to treat heuristically is a hash function, which can be instantiated with a cryptographic hash such as SHA3.

We also mention that our use of oracles is to be expected, as our protocols are strengthenings of plain position-verification, which (in the unbounded entanglement setting) is only known in the random oracle model [8]. It would be considered a major breakthrough to prove the security of any our protocols, or indeed position-verification itself, in the plain model.

Finally, we remark on a slight technical gap in the informal theorem statements above. While the ideal obfuscation model requires the circuit \(f\) to be obfuscated to be polynomial-time computable, many of our constructions are most simply described as using a random oracle (plus other manipulations) to define \(f\). Thus, in order to make \(f\) efficient, we technically have to replace the random oracle with a (post-quantum) pseudorandom function, which is known from any post-quantum one-way function [30]. Thus, all of our results additionally assume one-way functions.

1.5 Non-Localizability of \(f\)-BB84↩︎

Now that we have stronger notions of position verification and have shown how to achieve them, it is natural to wonder whether these notions can be achieved with simpler protocols. We show that the well-studied \(f\)-BB84 protocol does not satisfy entanglement localization. Let \(f(x,y)\) be a random boolean function. In this protocol, the honest prover at the proper location \(L\) receives classical challenges \(x,y\) as well as half of an EPR pair. It is supposed to compute a bit \(\theta = f(x,y)\) and measure its qubit in the standard or Hadamard basis according to \(\theta\) to obtain a bit \(b\), which it sends back in response. The verifier performs the same measurement on its half of the EPR pair and checks if it got the same outcome.

Unruh showed that if \(f\) is modeled as a random oracle, then unless the spoofers \(\{ \mathcal{P}_1,\ldots,\mathcal{P}_k\}\) make \(\exp(\Omega(n))\) queries to \(f\) (where we think of \(x,y\) as \(n\)-bit strings), then any successful spoofing strategy requires at least one of the provers \(\mathcal{P}_i\) to be in the correct location \(L\) [8]. Now, is it possible to strengthen Unruh’s result to show that the EPR entanglement can be localized to where the honest prover was supposed to be? We show that, perhaps surprisingly, this is not possible. We describe one attack here and will actually describe a slightly different one in 2.

Figure 2: Non-localizability attack on f-BB84

Consider the following \(3\) prover strategy, pictured in 2. There are provers \(\mathcal{P}_L,\mathcal{P}_M,\mathcal{P}_R\) (for “left”, “middle”, and “right”). Prover \(\mathcal{P}_M\) is in the correct location but \(\mathcal{P}_L,\mathcal{P}_R\) are on either side of \(\mathcal{P}_M\). Suppose that \(\mathcal{P}_L\) and \(\mathcal{P}_R\) share a random quantum one-time pad key \(r,s \in \{0,1\}\) in superposition. Suppose that the leftmost verifier sends half of the EPR pair; call this qubit \(Q\). It gets intercepted by \(\mathcal{P}_L\), who applies a quantum one-time pad \(X^r Z^s\) to \(Q\), and forwards it to \(\mathcal{P}_M\). The middle prover \(\mathcal{P}_M\) gets the one-time padded qubit, along with \(x,y\). It computes \(\theta = f(x,y)\), and measures the qubit in the corresponding basis to obtain a bit \(c\). The middle prover \(\mathcal{P}_M\) then sends \(\theta,c\) to both \(\mathcal{P}_L\) and \(\mathcal{P}_R\). Both \(\mathcal{P}_L\) and \(\mathcal{P}_R\) compute \(b\) as follows: if \(\theta = 0\), then \(b = c \oplus r\), and otherwise \(b = c \oplus s\). All operations are controlled by the superposition of \(r,s\). It is easy to check that this strategy satisfies the timing constraints and will be accepted with probability \(1\).

Although the middle prover is performing the correct measurement, the quantum entanglement in the EPR pair cannot be localized to the middle prover. At all times in this strategy, the marginal state of the middle prover is completely uncorrelated with \(\theta\) and the verifier’s EPR qubit. Thus there is no way for the middle prover to locally extract the other end of the EPR pair; it has been nonlocally distributed between the three provers \(\mathcal{P}_L,\mathcal{P}_M,\mathcal{P}_R\).

Thus, (entanglement) localization is a rather strong security condition that doesn’t hold for all QPV protocols studied in the literature.

1.6 Outlook and Future Directions↩︎

1.6.0.1 Position-based cryptography.

In light of our new notions of localization and trajectory verification, it will be interesting to revisit implications for position-based cryptography. As mentioned, there has been a subtle but important gap between the goals of position-based cryptography and the previous formalizations of position security. In 10.2, we illustrate this gap by presenting an “attack” on the position-based signature protocol of [3] that does not violate their security definition but intuitively should not be allowed in any reasonable real-world application of position-based authentication. We then further discuss why we believe our concepts and techniques should provide a stronger foundation for position-based cryptography. We leave further exploration of new definitions and constructions of position-based cryptography to future work.

1.6.0.2 Future work.

Our work raises several other directions for future exploration, which we list here.

  • In this work, we restrict our attention to one spatial dimension. While some subtleties typically arise when generalizing to more dimensions (see e.g. [8]), we expect that our techniques should apply in higher dimensions, and we leave a formalization of this to future work.

  • A recent work [9] has shown how to build position commitments and zero-knowledge position-verification. Can we build on their techniques to obtain trajectory commitments and zero-knowledge localization protocols?

  • [10], [31] have shown how to achieve position verification with purely classical communication. Can we obtain quantum localization and trajectory verification with only classical communication?

  • Can we further generalize the notion of quantum localization? For example, can we localize any (unclonable) QMA witness, perhaps by integrating our techniques with recent work [28], [32] that shows how to non-destructively verify QMA witnesses?

  • Our localization and trajectory verification protocols all rely on highly entangled and difficult-to-implement states. Might there exist simpler protocols that are more amenable to experimental realization in the short term? We remark that simpler localization protocols are likely easier to achieve if we drop the non-destructive requirement, but such protocols would not serve as building blocks to trajectory verification.

  • Our protocols assume noiseless transmission of quantum states, and that the prover is in exactly the right position at the right time. Can we achieve more robust versions of localization and trajectory verification, which resist environmental noise and allow the prover some leeway in their declared position / trajectory?

  • In this work, we discuss the way to achieve publicly verifiable trajectory verification and publicly verifiable localization schemes except publicly verifiable function localization (See 19 for more details). Can we construct a publicly verifiable function localization scheme?

1.6.0.3 Acknowledgments.

We thank Tal Malkin, Alex May, and Saachi Mutreja for helpful discussions. HY is supported by AFOSR award FA9550-23-1-0363, NSF awards CCF-2530159, CCF-2144219, and CCF-2329939, and by the Sloan Foundation. LO is supported by a NSF Graduate Fellowship.

2 Technical Overview↩︎

In this overview, we first introduce the main techniques used to construct trajectory verification. Along the way, we’ll see how to perform entanglement and state localization. Then, we’ll cover some additional ideas required to obtain functionality localization.

2.1 Entanglement Localization and Trajectory Verification↩︎

To develop our trajectory verification scheme, we first develop a non-destructive test of entanglement, next upgrade it to entanglement localization, and finally derive trajectory verification. A non-destructive test of entanglement distributes an entangled state between two parties, \(\mathcal{V}\) (the verifier) and \(\mathcal{P}\) (the prover), and then specifies an interactive protocol that can be repeatedly used to test whether the prover still holds the state entangled with the verifier. An entanglement localization scheme is a proof system where the prover can convince the verifier that the entanglement exists across the verifier’s state and a state within a specific defined region, such as an interval \([L-\Delta, L+\Delta]\). We first consider how to verify entanglement in a non-destructive manner.

2.1.0.1 Is verifying entanglement always destructive?

We begin with the standard approach for verifying one bit of entanglement. Suppose two parties \(\mathcal{V}\) (an honest verifier) and \(\mathcal{P}\) (a potentially adversarial prover) initially share an \({\sf EPR}\) pair. The prover \(\mathcal{P}\) may perform some operations on its subsystem, resulting in a joint state \(\rho_{\mathbf{A}\mathbf{B}}\), where \(\mathbf{A}\) is held by \(\mathcal{V}\) and \(\mathbf{B}\) is held by \(\mathcal{P}\). As discussed for example in [33], the entanglement can be tested via the following protocol:

  1. \(\mathcal{V}\) samples a random bit \(b \overset{\$}{\gets}\left\{0,1\right\}\). If \(b=0\), it measures \(\mathbf{A}\) in the standard basis; otherwise, it measures \(\mathbf{A}\) in the Hadamard basis. Let the measurement outcome be \(x\). The verifier then sends \(b\) to \(\mathcal{P}\).

  2. Upon receiving \(b\), the prover \(\mathcal{P}\) performs the corresponding measurement operation and outputs a value \(x'\).

If \(\mathcal{P}\) can perfectly predict the standard or Hadamard basis measurement outcome on \(\mathcal{V}\)’s side, i.e., \(x = x'\) with probability \(1\) over the choice of \(b\), then \(\mathcal{V}\) is convinced that its qubit was maximally entangled with \(\mathcal{P}\)’s system. However, this procedure necessarily collapses the entanglement, and at first glance this appears unavoidable.

Our main observation here is the following:

To verify entanglement, it suffices to argue the existence of a procedure that would pass the measurement test, without actually executing this procedure. In other words, there is a non-collapsing test such that, if the prover passes the non-collapsing test, it implies that the prover could be used to pass the collapsing test, which is only used in the analysis.

More concretely, we design two tests \(\Pi_{\sf ncol}\) and \(\Pi_{\sf col}\) for \(\mathcal{P}\). The test \(\Pi_{\sf ncol}\) is the non-collapsing test that we actually execute. We then argue, via an indistinguishability argument, that any prover passing \(\Pi_{\sf ncol}\) must also perform well in a corresponding collapsing test \(\Pi_{\sf col}\), which certifies the presence of entanglement.

2.1.0.2 Deploying decoy qubits.

We now present a first toy example. In addition to the original \({\sf EPR}\) pair shared between \(\mathcal{V}\) and \(\mathcal{P}\), we sample \(n\) random standard-basis qubits from \(\left\{\left|0\right\rangle,\left|1\right\rangle\right\}\) and \(n\) random Hadamard-basis qubits from \(\left\{\left|+\right\rangle,\left|-\right\rangle\right\}\). These \(2n\) qubits, together with the prover’s half of the \({\sf EPR}\) pair, are randomly shuffled into the register \(\mathbf{B}\), which now contains \(2n+1\) qubits.

To test for entanglement, instead of querying the unique (hidden) entangled qubit directly, \(\mathcal{V}\) proceeds as follows:

  1. Sample a random basis (standard or Hadamard).

  2. Send \(\mathcal{P}\) the indices of the \(n\) qubits prepared in that basis and request their measurement outcomes in the corresponding basis.

  3. Check whether the answers are correct.

From the prover’s perspective, all \(2n+1\) qubits appear as random BB84 states and are thus maximally mixed. The \(2n\) additional qubits serve as decoys that hide the location of the entangled qubit. To succeed, \(\mathcal{P}\) must effectively retain all qubits, and hence preserve the entanglement. Discarding any qubit risks failing the test, since that qubit may be queried.

To formalize this intuition, consider the single-shot setting with a prover \(\mathcal{P}\) that passes the protocol with probability 1. Let \(S\) denote the indices of the standard-basis qubits, and consider some arbitrary position \(x \in S\). We claim that \(\mathcal{P}\) would also answer correctly if, instead of querying \(S\), we queried \((S \setminus \left\{x\right\}) \cup \left\{e\right\}\), where \(e\) is the index of the entangled qubit. Here, correctness for \(e\) means consistency with the standard-basis measurement outcome on \(\mathbf{A}\). This follows because \(S\) and \((S \setminus \left\{x\right\}) \cup \left\{e\right\}\) are indistinguishable from the prover’s perspective.

This illustrates our earlier principle: the test on \(S\) is non-collapsing, while the test on \((S \setminus \left\{x\right\}) \cup \left\{e\right\}\) is collapsing, as it measures the entangled qubit.

However, this approach has a clear limitation. If the test is repeated multiple times, \(\mathcal{P}\) may learn which qubit is never queried, thereby identifying the entangled qubit. Once identified, the prover can discard it and still answer future queries correctly.

2.1.0.3 Reusable security via coset states.

To address this issue, we introduce a stronger method for hiding the decoys, based on coset states. A coset state \(\left|A_{s,s'}\right\rangle\), for a subspace \(A \leq \mathbb{F}_2^n\) of dimension \(n/2\) and \(s, s' \in \mathbb{F}_2^n\), is defined as \[\left|A_{s,s'}\right\rangle = \frac{1}{\sqrt{|A|}} \sum_{a \in A} (-1)^{\left \langle {a,s'} \right \rangle} \left|a+s\right\rangle.\] This state admits the following alternative interpretation:

  1. Prepare an \(n\)-qubit state in which the first \(n/2\) qubits are random Hadamard-basis states, and the remaining \(n/2\) qubits are random standard-basis states.

  2. Sample a random change-of-basis (invertible) matrix \(U_{\sf shift} \in \mathbb{F}_2^{n \times n}\) and apply the unitary \(\mathcal{U}_{\sf shift}\) defined as \[\mathcal{U}_{\sf shift}\left|x\right\rangle := \left|U_{\sf shift} x\right\rangle.\]

The second step plays a crucial role: without knowledge of \(U_{\sf shift}\), the subspace \(A\) and the cosets \(A+s\) and \(A^\perp + s'\) are computationally hidden. In particular, given \(\left|A_{s,s'}\right\rangle\), one cannot distinguish between:

  • Access to membership oracles \(\mathcal{O}_{A+s}\) and \(\mathcal{O}_{A^\perp+s'}\), and

  • Access to membership oracles \(\mathcal{O}_{B+s}\) and \(\mathcal{O}_{C+s'}\), where \(B\) and \(C\) are random super-subspaces of dimensions \(n - \omega(\log n)\) containing \(A\) and \(A^\perp\), respectively.

Here, \(\mathcal{O}_S\) denotes the membership oracle for a set \(S\), outputting \(\top\) on inputs in \(S\) and \(\bot\) otherwise.

Intuitively, the random change of basis hides the “positions” of the standard- and Hadamard-basis qubits, in a strictly stronger manner than the random permutation from before. We now apply this idea to also hide the positions of entangled qubits. Consider the following construction:

  1. Let \(\text{\faAnchor}\) be an \(n\)-qubit register and \(\text{\faShip}\) a \(3n\)-qubit register. Initialize the first \(n\) qubits of \(\text{\faShip}\) as random Hadamard-basis states, the next \(n\) qubits as halves of \({\sf EPR}\) pairs with \(\text{\faAnchor}\), and the final \(n\) qubits as random standard-basis states.

  2. Sample a random change-of-basis matrix \(U_{\sf shift} \in \mathbb{F}_2^{3n \times 3n}\) and apply the unitary \(\mathcal{U}_{\sf shift}\) defined as \[\mathcal{U}_{\sf shift}\left|x\right\rangle := \left|U_{\sf shift} x\right\rangle\] to the register \(\text{\faShip}\).

We refer to the resulting state as the anchor state \(\left|\Psi^{\sf sk}\right\rangle_{\text{\faAnchor}\text{\faShip}}\), where \({\sf sk}= (S,T,u,v)\).

  1. \(S\) is the subspace spanned by the first \(n\) columns of \(U_{\sf shift}\).

  2. \(T\) is the subspace spanned by the first \(2n\) columns of \(U_{\sf shift}\).

  3. \(u := U_{\sf shift}^{-t} u'\) where \(u'\) is the vector obtained by appending \(2n\) zeros to the vector of Hadamard-basis values (where \(\left|+\right\rangle\) is mapped to \(0\) and \(\left|-\right\rangle\) is mapped to \(1\)), and \(U_{\sf shift}^{-t}\) is the inverse transpose of \(U_{\sf shift}\).

  4. \(v := U_{\sf shift} v'\) where \(v'\) is the vector obtained by appending \(2n\) zeros before the vector of the standard-basis values.

We clarify some facts here. First, if we measure \(\text{\faShip}\) in the standard basis, we will get a vector in \(T + v\). If we measure \(\text{\faShip}\) in the Hadamard basis, we will get a vector in \(S^\perp + u\). Combining our previous non-destructive test with the hiding property achieved by oracles, we define the following test:

  1. In the setup phase, \(\text{\faAnchor}\) is given to \(\mathcal{A}\) and \(\text{\faShip}\) is given to \(\mathcal{B}\). Sample \(\theta \overset{\$}{\gets}\{0,1\}\) and \(s \overset{\$}{\gets}\{0,1\}^{\sf{\lambda}}\). \(\theta\) is given to \(\mathcal{B}\).

  2. If \(\theta=0\), give the oracle \(\mathcal{O}_{T+v}^{\sf ncol}\) to \(\mathcal{B}\), where the oracle is defined as follows:

    • \(\mathcal{O}_{T+v}^{\sf ncol}\): On input \(z\), check whether \(z \in T + v\). Output \(s\) if it is, and output \(\bot\) otherwise.

    If \(\theta=1\), give the oracle \(\mathcal{O}_{S^\perp+u}^{\sf ncol}\) to \(\mathcal{B}\), where the oracle is defined as follows:

    • \(\mathcal{O}_{S^\perp+u}^{\sf ncol}\): On input \(z\), check whether \(z \in S^\perp + u\). Output \(s\) if it is, and output \(\bot\) otherwise.

    \(\mathcal{B}\) is supposed to return \(s\).

An honest \(\mathcal{B}\) can simply perform the corresponding basis evaluation coherently. That is, for \(\theta=0\), it computes \(\mathcal{O}_{T+v}^{\sf ncol}\) coherently on register \(\text{\faShip}\) and outputs the measurement result. For example, 3 shows the non-collapsing test when \(U_{\sf shift}=I\) and \(\theta=0\). Only the correctness of the standard-basis qubits is tested. One may notice that this is a non-collapsing test, and the state is unchanged after the test is completed.

Figure 3: The Non-collapsing Test.

Now, using the subspace bloating lemma, we design a collapsing test that is indistinguishable from the non-collapsing test from \(\mathcal{B}\)’s perspective.

  1. In the setup phase, \(\text{\faAnchor}\) is given to \(\mathcal{A}\) and \(\text{\faShip}\) is given to \(\mathcal{B}\). Sample \(\theta \overset{\$}{\gets}\{0,1\}\) and a random oracle \(\mathcal{O}_{\sf random}\). \(\theta\) is given to \(\mathcal{B}\).

  2. If \(\theta=0\), give the oracle \(\mathcal{O}_{T+v}^{\sf col}\) to \(\mathcal{B}\), where the oracle is defined as follows:

    • \(\mathcal{O}_{T+v}^{\sf col}\): On input \(z\), check whether \(z \in T + v\). Output \(\mathcal{O}_{\sf random}({\sf Can}_S(z))\) where \({\sf Can}_S(z)\) is the canonical representation of coset \(S+z\) if it is, and output \(\bot\) otherwise.

    If \(\theta=1\), give the oracle \(\mathcal{O}_{S^\perp+u}^{\sf col}\) to \(\mathcal{B}\), where the oracle is defined as follows:

    • \(\mathcal{O}_{S^\perp+u}^{\sf col}\): On input \(z\), check whether \(z \in S^\perp + u\). Output \(\mathcal{O}_{\sf random}({\sf Can}_{T^\perp}(z))\) where \({\sf Can}_{T^\perp}(z)\) is the canonical representation of coset \(T^\perp + z\) if it is, and output \(\bot\) otherwise.
  3. If \(\theta = 0\), the verifier measures \(\text{\faAnchor}\) in the standard basis to obtain \(x\). Otherwise, if \(\theta = 1\), the verifier measures \(\text{\faAnchor}\) in the Hadamard basis to obtain \(x\).

One can think of the canonical representation of a coset as a unique identifier for the coset. Now suppose that \(\theta=0\) and the prover coherently computes \(\mathcal{O}_{T+v}^{\sf col}\) on register \(\text{\faShip}\). A measurement on the oracle output will collapse the state according to which coset of \(S\) the vector \(z\) belongs to, where \(z\) is the standard-basis value on \(\text{\faShip}\). This is equivalent to measuring all entangled qubits in the standard basis. For example, 4 shows the collapsing test when \(U_{\sf shift}=I\) and \(\theta=0\).

Figure 4: The Collapsing Test.

In the collapsing test, each potential measurement result \(x\) obtained by the verifier corresponds to a different input on which the honest prover queried \(\mathcal{O}_{\sf random}\). In the main proof, we show that any (potentially adversarial) prover that passes with probability close to \(1\) in the non-collapsing test will yield the following behavior in the collapsing test with overwhelming probability:

  • If \(\theta=0\), the only input on which \(\mathcal{O}_{\sf random}\) is accessed is \({\sf Can}_S(U_{\sf shift}(0^n \times x \times 0^n) + v)\), where \(x\) is the standard-basis measurement result obtained by the verifier.

  • If \(\theta=1\), the only input on which \(\mathcal{O}_{\sf random}\) is accessed is \({\sf Can}_{T^\perp}(U_{\sf shift}^{-t}(0^n \times x \times 0^n) + u)\), where \(x\) is the Hadamard-basis measurement result obtained by the verifier.

Hence, we can test entanglement by repeatedly asking the prover to answer non-collapsing tests. If the prover is able to answer all of them, they would also succeed in the collapsing test, and we will be convinced that the prover is holding the entanglement. Indeed, a prover that passes the collapsing test will predict the verifier’s standard / Hadamard basis measurement results, allowing the extraction of EPR pairs following the strategy of [33] .

2.1.0.4 Non-localizability of \(f\)-BB84.

We now move to the second component mentioned above: Localization of entanglement. As discussed in the introduction, the famous \(f\)-BB84 protocol does not satisfy entanglement localization. Here we give an alternative attack on this protocol that better conveys the motivation for our own construction.

Consider the following strategy involving three provers. There are provers \(\mathcal{P}_L\), \(\mathcal{P}_M\), and \(\mathcal{P}_R\) (for “left",”middle", and “right"). Prover \(\mathcal{P}_M\) is in the correct location, while \(\mathcal{P}_L\) and \(\mathcal{P}_R\) are positioned on either side of \(\mathcal{P}_M\). Upon receiving the \({\sf EPR}\) pair \(\left|\Phi\right\rangle_{\mathbf{A}\mathbf{B}}\), the prover applies the following unitary: \[\left|x\right\rangle_{\mathbf{B}} \rightarrow \frac{1}{\sqrt{2}} \sum_{b \in \left\{0,1\right\}} \left|b\right\rangle_{\mathbf{L}} \left|b\right\rangle_{\mathbf{M}_0} \left|b \oplus x\right\rangle_{\mathbf{M}_1} \left|b \oplus x\right\rangle_{\mathbf{R}}\] and sends \(\mathbf{L}\), \(\mathbf{M}= \mathbf{M}_0 \otimes \mathbf{M}_1\), and \(\mathbf{R}\) to \(\mathcal{P}_L\), \(\mathcal{P}_M\), and \(\mathcal{P}_R\), respectively. It can be seen that there is no entanglement between \(\mathbf{A}\) and \(\mathbf{M}\). To pass the challenge, the prover does the following.
If \(\theta = 0\):

  • The middle prover \(\mathcal{P}_M\) sends \(\mathbf{M}_1\) to \(\mathcal{P}_L\) and \(\mathbf{M}_0\) to \(\mathcal{P}_R\).

  • The left prover \(\mathcal{P}_L\) measures \(\mathbf{L}\) and \(\mathbf{M}_1\). If the bits are the same, it outputs \(0\); otherwise, it outputs \(1\).

  • The right prover \(\mathcal{P}_R\) measures \(\mathbf{R}\) and \(\mathbf{M}_0\). If the bits are the same, it outputs \(0\); otherwise, it outputs \(1\).

If \(\theta = 1\):

  • The middle prover \(\mathcal{P}_M\) sends \(\mathbf{M}_0\) to \(\mathcal{P}_L\) and \(\mathbf{M}_1\) to \(\mathcal{P}_R\).

  • The left prover \(\mathcal{P}_L\) outputs \(0\) if its state is \(\frac{1}{\sqrt{2}} \left|00\right\rangle_{\mathbf{L}\mathbf{M}_0} + \frac{1}{\sqrt{2}} \left|11\right\rangle_{\mathbf{L}\mathbf{M}_0}\); otherwise, it outputs \(1\).

  • The right prover \(\mathcal{P}_R\) outputs \(0\) if its state is \(\frac{1}{\sqrt{2}} \left|00\right\rangle_{\mathbf{R}\mathbf{M}_1} + \frac{1}{\sqrt{2}} \left|11\right\rangle_{\mathbf{R}\mathbf{M}_1}\); otherwise, it outputs \(1\).

Intuitively, this attack works because the left prover and the right prover “encrypt” the answer, such that the answer is stored in the interference between \(\mathbf{M}\) and \(\mathbf{L}\mathbf{R}\), while the middle prover has no clue about the answer when receiving the challenge. The middle prover does not measure anything, and the measurement is delayed until the global interference becomes local at the left and right provers.

2.1.0.5 Forcing a measurement via monogamy-of-entanglement.

To bypass this attack, the key idea is to force the prover to perform a particular “measurement” (in quotes because in reality they will be performing a non-destructive oracle query) at the position of the middle prover. More precisely, we want to ensure that the prover demonstrates its ability, in principle, to measure the state in a specific basis. We begin by replacing the random basis test on the \({\sf EPR}\) pair with a non-destructive test for entanglement:

  1. In the setup phase, \(\text{\faAnchor}\) is given to \(\mathcal{A}\) and \(\text{\faShip}\) is given to \(\mathcal{B}\). Sample \(s \overset{\$}{\gets}\{0,1\}^{\sf{\lambda}}\).

  2. The left verifier \(\mathcal{V}_L\) samples \(x_L\), and the right verifier \(\mathcal{V}_R\) samples \(x_R\). Both \(x_L\) and \(x_R\) are broadcast at the appropriate time to ensure they meet at the correct position.

  3. The middle prover computes \(\theta = f(x_L, x_R)\) and performs the following:

    • If \(\theta = 0\), it is granted access to the oracle \(\mathcal{O}_{T+v}^{\sf ncol}\) and performs the coherent standard-basis measurement described above.

    • If \(\theta = 1\), it is granted access to the oracle \(\mathcal{O}_{S^\perp + u}^{\sf ncol}\) and performs the coherent Hadamard-basis measurement described above.

    • It broadcasts the result.

  4. Both the left and right verifiers receive the result broadcast by the prover. The verifier returns \(\top\) if both messages are on time and correct (equal to \(s\)); otherwise, it returns \(\bot\).

One may ask how the prover can be given access to an oracle during the middle of the computation. It can be assumed that there is a class of oracles indexed by \(x_L, x_R\), and a particular oracle is selected for the parties once they know both \(x_L\) and \(x_R\).

Now, actually proving the extractability of this simple protocol appears challenging. Our solution is to repeat this protocol twice: one standard round followed by one Hadamard round, or vice versa. For example, let’s consider the case where the first round is a standard-basis round and the second round is a Hadamard-basis round.

  1. In the setup phase, \(\text{\faAnchor}\) is given to \(\mathcal{A}\) and \(\text{\faShip}\) is given to \(\mathcal{B}\). Sample \(s_0, s_1 \overset{\$}{\gets}\{0,1\}^{\sf{\lambda}}\).

  2. The first round has \(\theta_0 = 0\). The prover is granted access to the oracle \(\mathcal{O}_{T+v}^{\sf ncol}\) with \(s_0\) encoded as the secret and performs the coherent standard-basis measurement described above.

  3. After a brief interval, the second round arrives with \(\theta_1 = 1\). The prover is granted access to the oracle \(\mathcal{O}_{S^\perp + u}^{\sf ncol}\) with \(s_1\) encoded as the secret and performs the coherent Hadamard-basis measurement described above.

  4. Both the left and right verifiers receive the results broadcast by the prover. The verifier returns \(\top\) if all messages are on time and correct; otherwise, it returns \(\bot\).

Now, let’s examine how this two-round protocol prevents the attack described above. Suppose there are three provers \(\mathcal{P}_L, \mathcal{P}_M, \mathcal{P}_R\) that succeed at passing the protocol, but where only \(\mathcal{P}_M\) is at the correct spacetime location. Furthermore, suppose that \(\mathcal{P}_M\) fails to “measure” and determine the answer for the first challenge at the correct location and time. In this case, the strategy can be recast as a successful adversary \(\mathcal{A} = (\mathcal{A}_L, \mathcal{A}_M, \mathcal{A}_R)\) in the following monogamy-of-entanglement type game.6

  1. The challenger generates \(\left|\Psi^{{\sf sk}}\right\rangle\) and gives the register \(\text{\faShip}\) to \(\mathcal{A}_M\).

  2. \(\mathcal{A}_M\) generates a bipartite state on \(\mathbf{L}\mathbf{R}\). It sends \(\mathbf{L}\) to \(\mathcal{A}_L\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R\).

  3. The challenger samples \(s_0, s_1 \overset{\$}{\gets}\{0,1\}^{\sf{\lambda}}\). It gives \(\mathcal{O}_{T+v}^{\sf ncol}\) to \(\mathcal{A}_L\) that encodes \(s_0\) as its underlying secret, and it gives \(\mathcal{O}_{S^\perp + u}^{\sf ncol}\) to \(\mathcal{A}_R\) that encodes \(s_1\) as the underlying secret. In addition, it gives \(s_0\) to \(\mathcal{A}_R\).

  4. \(\mathcal{A}_L\) returns \(s_0'\) and \(\mathcal{A}_R\) returns \(s_1'\).

  5. The challenge is passed if \(s_0' = s_0\) and \(s_1' = s_1\).

Intuitively, the reduction works as follows: \(\mathcal{P}_M\) corresponds to \(\mathcal{A}_M\), the left prover \(\mathcal{P}_L\)’s process for solving the \(\mathcal{O}_{T+v}^{\sf ncol}\) challenge is used to construct \(\mathcal{A}_L\), and the right prover \(\mathcal{P}_R\)’s process for solving the \(\mathcal{O}_{S^\perp + u}^{\sf ncol}\) challenge is used to construct \(\mathcal{A}_R\). Due to the structure of the game, we also have to include the correct “left” answer \(s_0\) in the view of the right prover, which is a non-standard variant of monogamy-of-entanglement.

In 6, we show, via a sequence of reductions, that this game is hard for any adversary to win with probability better than \(\frac{1}{2} + {\sf negl}({\sf{\lambda}})\). Thus, we can eliminate this type of prover, meaning that any successful prover must indeed “measure” (meaning query the oracle on its state) at the correct location and time. Finally, we argue that this implies the existence of an extractor that, using quantum recording techniques [34], can obtain either the result of measuring \(\text{\faShip}\) in the standard or the Hadamard basis at the correct location and time. By the previous entanglement verification arguments, we can thus localize the entanglement to the desired spacetime location.

2.1.0.6 Trajectory verification.

As mentioned earlier, trajectory verification follows fairly naturally from our entanglement localization protocol. At a high level, the verifier first sends the vessel register \(\text{\faShip}\) to the prover, and then runs the entanglement localization protocol at a series of steps along the prover’s claimed trajectory. In slightly more detail, at each step, the verifier sends a random standard- or Hadamard- basis challenge.7 Therefore, each pair of steps gives rise to a slightly modified version of the two-round protocol described above, where the cadence is not fixed standard followed by Hadamard, but rather both are randomly chosen. We show that in this modified game, one can still extract entanglement from any successful prover at the time of the first challenge. This means that one can extract entanglement from the prover at any step on their trajectory, assuming they have a high probability of passing all challenges. This is formalized in 9.2.

2.1.0.7 Optimizations and applications.

We conclude by highlighting two additional features of our constructions. First, while the informal guarantees stated above only yield meaningful extraction when the adversary succeeds with probability \(1-o(1)\), this limitation can be overcome via sequential repetition. By executing sufficiently many copies of the localization protocol in rapid succession, we can amplify soundness so that any prover accepted with non-negligible probability must still contain the localized object at the verified spacetime point. In this way, our localization guarantees can be strengthened to hold against adversaries whose success probability is merely inverse polynomial.

Second, we discuss how to upgrade our protocols to achieve public verifiability. Intuitively, because the verification procedure is implemented using public classical oracles, one can arrange the protocol so that anyone with oracle access can verify the prover’s responses, without requiring access to any secret verification key. We defer the precise formulation and construction of publicly-verifiable localization protocols to 10.1. After that, in 10.2, we discuss broader implications for position-based cryptography and related applications.

2.2 Functionality Localization↩︎

Functionality localization can be seen as a strengthening of quantum copy-protection, which enables encoding a function \(f\) (sampled from some family \(\mathcal{F}\)) into a quantum state \(\rho_f\) such that (i) \(\rho_f\) can be used to compute \(f(x)\) for any input \(x\), and (ii) no adversary can create two disjoint registers that can simultaneously be used to compute \(f\) (over some distribution \(\mathcal{D}\) on inputs \(x\)).

That is, copy-protection establishes that certain functionalities can be rendered unclonable, meaning they cannot exist in two places at once. This then raises the possibility that functionalities can be localized! In this work, we show that any functionality \(\mathcal{F}\) that can in principle be copy-protected, can also be localized, in the classical ideal obfuscation model.8

Our construction combines “best-possible” copy-protection with the techniques introduced above. A best-possible copy-protector is a scheme that takes as input a function \(f \gets \mathcal{F}\) and outputs a state \(\rho_f\) such that, if there exists any method of copy-protecting \(f\), then \(\rho_f\) is itself a copy-protected version of \(f\). The idea of best-possible copy-protection was introduced by [19], who showed that any “quantum state obfuscator” serves as a best-possible copy protection scheme. Quantum state obfuscation was then shown to exist in the classical oracle model [20].

Let \({\sf QSO}\) be a quantum state obfuscator, let \(({\sf Auth},\mathsf{Ver})\) be a message authentication code, and consider the following (simplified) proposal for functionality localization.

  • In the setup phase, the verifiers samples a functionality \(f \gets \mathcal{F}\), an authentication key \({\sf sk}\), and a random coset state \(\left|S_{v,u}\right\rangle\). Let \(\widehat{f}_{\sf sk}\) be the functionality that, on input \(x\), outputs \(f(x)\) along with a signature \(\sigma\) on the pair \((x,f(x))\). Output \(\rho_f \gets {\sf QSO}(\widehat{f}_{\sf sk})\) and \(\left|S_{v,u}\right\rangle\).

  • In the online phase, the verifiers sample \(\theta \gets \{0,1\}, x \gets \mathcal{D}\), and a random oracle \(\mathcal{O}_{\sf random}\), and do the following.

    • If \(\theta = 0\), they send \(\theta,x\) to the prover along with an oracle \(\mathcal{O}_{{\sf sk},S,v}\) that takes as input \((z,x,y,\sigma)\) and if (i) \(z \in S+v\) and (ii) \(\mathsf{Ver}({\sf sk},(x,y),\sigma) = \top\), outputs \({\mathcal{O}}_{\sf random}(x,y)\).

    • If \(\theta = 1\), they send \(\theta,x\) to the prover along with an oracle \(\mathcal{O}_{{\sf sk},S^\perp,u}\) that takes as input \((z,x,y,\sigma)\) and if (i) \(z \in S^\perp+u\) and (ii) \(\mathsf{Ver}({\sf sk},(x,y),\sigma) = \top\), outputs \({\mathcal{O}}_{\sf random}(x,y)\).

  • The honest prover, sitting at the correct spacetime point, uses \(\rho_f\) to compute \(f(x), \sigma_{x,f(x)}\), and then queries its oracle using either \(\left|S_{u,v}\right\rangle\) in the standard or Hadamard basis to obtain the value \(\mathcal{O}_{\sf random}(x,f(x))\), which it sends back to the verifier.

We note that there are several ways in which our final protocol differs from this simplified description, and we refer the reader to 9.4 for more details.

The intuition here is that, in order to succeed in the protocol, the prover must query their oracle at the correct location on \(z,x,f(x),\sigma_{x,f(x)}\), where \(z\) is either in \(S+v\) or \(S^\perp + u\). On the other hand, due to the security of the message authentication code and the hiding of \({\sf QSO}\), they will not be able to learn a signature \(\sigma_{x,y}\) on any \(y \neq f(x)\). Hence, the oracle \(\mathcal{O}_{\sf random}\) will be queried on \((x,f(x))\) but not on \((x,y)\) for any \(y \neq f(x)\). This yields the existence of an extractor that, using quantum recording techniques, can extract the value of \(f(x)\) from any successful adversarial prover at the location to be verified. We note that we crucially rely on the techniques developed above in the context of entanglement localization in order to establish that the adversary must indeed query their oracle at the correct spacetime location. In particular, even though there is no entanglement in this setting, we can view a random coset state as a “degenerate” version of the anchor state described above with the number of EPR pairs set to 0, and our techniques carry over naturally to this setting.

3 Preliminaries↩︎

3.1 General Notation↩︎

In many contexts, objects are parameterized by a security parameter \({\sf{\lambda}}\in\mathbb{N}\), which is often omitted to reduce clutter. We write PPT and QPT to denote probabilistic polynomial-time and quantum polynomial-time, respectively. Algorithms are denoted with calligraphic letters, such as \(\mathcal{A},{\mathcal{B}},\mathcal{P},\mathcal{V}\). Quantum registers are denoted with bold letters, such as \(\mathbf{A},\mathbf{B},\mathbf{X}\). We write \({\sf negl}(\lambda)\) to denote a negligible function in \(\lambda\). For a protocol \(\sf Prot\) and two parties \(\mathcal{P}\) and \(\mathcal{V}\) (prover and verifier), we write \(Y_{\mathcal{P}},Y_{\mathcal{V}}\gets{\sf Prot}(\mathcal{P}(\mathbf{A})\rightleftharpoons \mathcal{V}(\mathbf{B}))(x)\) to denote the experiment where \(\mathcal{P}\) and \(\mathcal{V}\) interact by running \(\sf Prot\) with public input \(x\), private prover input \(\mathbf{A}\), and private verifier input \(\mathbf{B}\). Here, \(Y_{\mathcal{P}}\) is some set of prover outputs and \(Y_{\mathcal{V}}\) is some set of verifier outputs. \(Y_{\mathcal{V}}\) typically includes a bit \(b\in\{\top,\bot\}\) known as the acceptance decision, with \(\top\) meaning the verifiers accept and \(\bot\) meaning that they reject.

3.2 Modeling Computations and Interactions in Spacetime↩︎

In this section, we describe our model for how algorithms and interactive protocols take place in physical spacetime, which will be important for the interpretation of our main results. This model is somewhat new to our work, but is inspired by similar sections in [35],[8], and [9]. Note that later sections of this paper, as well as our main results, do not rely closely on the wording of this section — instead, they tend to use terminology of a broader and more standard flavor. We strongly believe that our results are general enough that there is a wide variety of acceptable modeling choices under which they can retain correctness and meaningful interpretability.

3.2.0.1 Spacetime.

All of our protocols are set in a bounded one-dimensional space9, represented as \([-1,1]\). This is the line segment between two statically placed verifiers, \(\mathcal{V}_L\) at position \(-1\) and \(\mathcal{V}_R\) at position \(1\). We model time as \(\mathbb{R}^{\geq0}\), and we assume that all parties have access to a synchronized clock that reports the current time \(t \in \mathbb{R}^{\geq0}\). Units of space and time are taken such that light travels 1 unit of space in 1 unit of time. A point in spacetime is a pair \((L,t) \in [-1,1]\times\mathbb{R}^{\geq0}\), combining a spatial point with a time.

3.2.0.2 Messages.

We always consider messages to be directional — i.e. they travel either only to the left, or only to the right — and to travel with speed exactly 1 (the speed of light). We treat this process as the movement of a physical quantum register through space at the speed of light. In general, a message is a quantum state, although we often distinguish between the classical and quantum parts of a given message (for example, a party may send a string \(x\) and a qubit \(\left|\psi\right\rangle\) in the same message).

3.2.0.3 Algorithms.

We define the following model of computation in spacetime. An algorithm consists of a finite number of movable “cells”, which are quantum registers labeled \(\mathbf{R}_1,\mathbf{R}_2,\dots,\mathbf{R}_M\). Corresponding to each cell is a predetermined, continuous trajectory through space, which we’ll label \(T_1,\dots,T_M:\mathbb{R}^{\geq0}\to[-1,1]\). \(T_i(t)\) denotes the spatial location of cell \(\mathbf{R}_i\) at time \(t\). Cells can move at any speed up to the speed of light. Inputs are given to an algorithm by setting the initial value of some cells designated as input cells. Additionally, for each message that could possibly be sent or received by the algorithm, we add a cell which travels along the same path as this message, in perpetuity or until the message goes “out of bounds”, in which case the cell lingers at \(-1\) or \(1\). Prior to the departure time of a message, its corresponding cell will simply be dormant in the message’s starting location. The reason for this addition will become clear in the next paragraph.

The computational units of an algorithm are contained at the intersection points between its cells10 — let \(X\) be the set containing all of these points. At each intersection point \((L,t)\in X\), the algorithm contains a quantum circuit \(C_{L,t}\) acting on all of the cells which intersect there. \(C_{L,t}\) can implement any unitary on these cells, and the output registers can be arbitrarily subdivided among the participating cells. The size of a circuit, denoted \(|C_{L,t}|\), refers to the number of gates used to implement it, taken from some fixed universal quantum gate set. No matter the size of a circuit, it is always assumed to be an instantaneous operation. An algorithm is said to eventually terminate if \(X\) is finite, and it is said to have terminated whenever the last intersection point is reached. At termination, some of its cells are designated as outputs, and the rest discarded. As mentioned above, all messages are also treated as cells — to send a message, the algorithm transfers some information into the cell having that message’s trajectory, which occurs at the intersection point corresponding to the message departing. To receive a message, an algorithm might place a SWAP circuit between a message cell and another ancilla cell, for example.

We sometimes specify that a family of algorithms \(\{\mathcal{A}_{\sf{\lambda}}\}_{\sf{\lambda}}\) is QPT, which is defined with respect to a security parameter, and abbreviated as “\(\mathcal{A}\) is QPT” if dependence on \({\sf{\lambda}}\) is clear from context. Let \(X_{\sf{\lambda}}\) and \(\{C_{{\sf{\lambda}}}^{L,t}\}_{(L,t)\in X_{\sf{\lambda}}}\) be the sets of intersection points and circuits, respectively, for \(\mathcal{A}_{\sf{\lambda}}\). QPT is then shorthand for the following requirement: there exists some polynomial \(p({\sf{\lambda}})\) such that for all \({\sf{\lambda}}\in\mathbb{N}\),

  1. \(\mathcal{A}_{\sf{\lambda}}\) terminates, and

  2. \(\sum_{(L,t)\in X_{\sf{\lambda}}}|C_{{\sf{\lambda}}}^{L,t}|\leq p({\sf{\lambda}})~.\)

3.2.0.4 Positional Protocols.

Our protocols take place between two kinds of parties: provers and verifiers. As stated above, the verifiers always consist of two parties \(\mathcal{V}_L\) and \(\mathcal{V}_R\), whose locations are publicly known to be \(-1\) and \(1\), respectively. Provers are, in general, allowed to have circuits anywhere in \([-1,1]\). The protocol typically includes a \({\sf Setup}\) operation, whose outputs are distributed between these parties unequally. We clarify this distinction, as well as other distinctions between provers and verifiers, below:

  • All verifiers can:

    • Take as input some secret information \(\mathsf{sp}\) from \({\sf Setup}\), in addition to the public information \({\sf{pp}}\). In our protocols, these are both classical.

    • Send classical or quantum messages to any position \((L,t)\).

    • Send classical or quantum messages to other verifiers through private, trusted channels.

  • A prover can:

    • Take as input some prover-specific information from \({\sf Setup}\). In our protocols, this will always be a quantum state \(\rho\).

    • Send classical or quantum messages to any position \((L,t)\).

    • Send classical or quantum messages between its various distributed components through private, trusted channels.

  • We assume that the prover’s trajectory is a continuous function \(L(\cdot)\) with \(L(t)\in[-1,1]\) and \(\big|\frac{L(t_1)-L(t_0)}{t_1-t_0}\big|\leq 1\) for all \(t,t_0,t_1\in\mathbb{R}^{\geq0}\). The second condition is just the speed of light constraint, as measured by the secant line of the trajectory.

The following lemma is imported from [8]. It states that no adversary can distinguish an oracle reprogramming on the position decided by the xor of random domain element sampled by \(\mathcal{V}_L,\mathcal{V}_R\) if one of the domain element hasn’t reach the adversary.

Lemma 1 ([8]). Let \(\mathcal{O}_{\sf random}\) be a random oracle with exponential domain and image size and the size is a power of \(2\). Any QPT prover cannot distinguish between the following two cases with noticeable probability:

  • \(\mathcal{V}_L\) samples a uniform random vector \(x_l\) and broadcast it at time \(t_l\). \(\mathcal{V}_R\) samples a uniform random vector \(x_r\) and broadcast it at time \(t_r\).

  • \(\mathcal{V}_L\) samples a uniform random vector \(x_l\) and broadcast it at time \(t_l\). \(\mathcal{V}_R\) samples a uniform random vector \(x_r\) and broadcast it at time \(t_r\). Then the oracle \(\mathcal{O}_{\sf random}\) is reprogrammed to a uniform random output \(y\) on input \(x_l\oplus x_r\) for all space-time coordinates \((p,t)\) within the region:

    • \(t-t_l\geq p+1\).

    • \(t-t_r\geq 1-p\).

3.3 Specifying Quantum Information in Spacetime↩︎

We introduce notation, \(\mathsf{register}[\cdot](\cdot)\), for convenience in formalizing many of our extraction-based security definitions in this paper. A definition is given below.

Definition 1. Let \({\sf Exp}_{\mathcal{P},V}\) refer to some experiment, taking place between a prover \(\mathcal{P}\) and verifier \(\mathcal{V}\), and let \(R_1,\dots,R_k\) be disjoint regions of spacetime. Then, we use the following notation, \[\mathbf{A}_1,\dots,\mathbf{A}_k\gets\mathsf{register}[R_1;\dots;R_k]({\sf Exp}_{\mathcal{P},V})~,\] to mean that for \(i\in[k]\), \(\mathbf{A}_i\) is the tensor product of the following:

  1. All of \(\mathcal{P}\)’s registers within region \(R_i\).

  2. All message registers currently inflight within region \(R_i\).

  3. The transcript of all classical messages sent by \(\mathcal{V}\) which causally precede any points in \(R_i\). In other words, any verifier messages which would be “heard” within \(R_i\).

Note that this may not correspond to a physical operation – in particular, if \(R\) contains points which are at the same spatial location at different times, these might have states which cannot physically coexist – but we still allow this to be defined for notational convenience. Also, when convenient, we will use the notation “\(S~@~t\)”, where \(S\) is a spatial region and \(t\) a time, to refer to the spacetime region \(S\times\{t\}\).

3.4 Compressed Oracle↩︎

In this subsection, we recall the technique introduced by Zhandry [34]. For more details please refer to [34]. The following part is adapted from [36]. We will show two equivalent oracle forms: the standard oracle and the compressed oracle. Note that Fourier basis is considered in other papers that use this technique but here we use Hadamard basis instead for simplicity.

We first model an oracle quantum algorithm. It consists of the following registers:

  • \(\mathbf{X}\) is the register that stores either a oracle query or an answer waiting to be written.

  • \(\mathbf{U}\) is the register that stores the oracle’s response or is used to store phase for the output process (will explain later).

  • \(\mathbf{W}\) is the register that stores as ancilla qubits in the computation.

3.4.0.1 Standard oracle.

Let \(\mathcal{O}:\mathbb{F}_2^n \rightarrow \mathbb{F}_2^m\) be a random oracle. We can view an algorithm that runs in the random oracle model with respect to \(\mathcal{O}\) as the algorithm itself concatenated with a random oracle register \(\mathbf{D}\) that is initialized to \(\sum_{\mathcal{O}}\left|\mathcal{O}\right\rangle\left\langle\mathcal{O}\right|_{\mathbf{D}}\) (ignoring the normalizing factor). The register \(\mathbf{D}\) stores the random function \(\left|\mathcal{O}\right\rangle_{\mathbf{D}} = \left|\mathcal{O}(0^n)\right\rangle \left|\mathcal{O}(0^{n-1}1)\right\rangle \cdots \left|\mathcal{O}(1^n)\right\rangle\). The oracle unitary \({\sf StO}\) can be written as follows: \[\begin{align} {\sf StO}\left|x\right\rangle_{\mathbf{X}} \left|u\right\rangle_{\mathbf{U}} \left|w\right\rangle_{\mathbf{W}} \otimes \left|\mathcal{O}\right\rangle_{\mathbf{D}} = \left|x\right\rangle_{\mathbf{X}} \left|u + \mathcal{O}(x)\right\rangle_{\mathbf{U}} \left|w\right\rangle_{\mathbf{W}} \otimes \left|\mathcal{O}\right\rangle_{\mathbf{D}}, \end{align}\] The following lemma shows that the output distribution using a standard oracle is exactly the same as using a random oracle.

Lemma 2 ([34]). Let \(\mathcal{A}\) be an (unbounded) quantum algorithm making oracle queries. The output of \(\mathcal{A}\) given a random function \(\mathcal{O}\) is exactly identical to the output of \(\mathcal{A}\) given access to a standard oracle. Therefore, a random oracle with quantum query access can be perfectly simulated as a standard oracle.

Compressed oracle.

The compressed oracle can be viewed a type of lazy sampling technique. Instead of initializing \(\mathcal{O}\) at the very beginning, the compressed oracle creates a database \(\left|D\right\rangle_{\mathbf{D}}=\left|D(0^n)\right\rangle_{\mathbf{D}_{0^n}}\left|D(0^{n-1}1)\right\rangle_{\mathbf{D}_{0^{n-1}1}}\cdots\left|D(1^n)\right\rangle_{\mathbf{D}_{1^n}}\) where \(D(x)\in\mathbb{F}_2^m\cup\left\{\bot\right\}\) and \(\left|D\right\rangle\) is initialized to \(\left|\emptyset\right\rangle_{\mathbf{D}}=\left|\bot, \bot, \cdots, \bot\right\rangle\) where \(\bot\) is a symbol that indicates the lack of information of the algorithm on certain function value. Let \(|D|\) denote the number of entries in \(D\) that are not \(\bot\). The database is initialized as an empty list \(D_0\) of length \(N\), in other words, it is initialized as the pure state \(\left|\emptyset\right\rangle := \left|\bot, \bot, \cdots, \bot\right\rangle\). Let \(|D|\) denote the number of entries in \(D\) that are not \(\bot\).

For any \(D\) and \(x\) such that \(D(x) = \bot\), we define \(D \cup (x, u)\) to be the database \(D'\), such that for every \(x' \ne x\), \(D'(x') = D(x)\) and at the input \(x\), \(D'(x) = u\).

The compressed oracle is the unitary \({\sf CStO}:= {\sf StdDecomp}\cdot {\sf CStO}' \cdot {\sf StdDecomp}\), where

  • \({\sf CStO}'\) writes \(D(x)\) to the answer register \(\mathbf{U}\) by writing \(u+ D(x)\) into it when \(D(x)\neq \bot\) as usual but does nothing when \(D(x)=\bot\). Or to say that we can define addition for \(\bot\): \(u+\bot=u\), \(\forall u\in\mathbb{F}_2^m\). Formally, \[{\sf CStO}'\left|x\right\rangle_{\mathbf{X}}\left|u\right\rangle_{\mathbf{U}}\left|w\right\rangle_{\mathbf{W}}\otimes\left|D\right\rangle_{\mathbf{D}} = \left|x\right\rangle_{\mathbf{X}}\left|u+ D(x)\right\rangle_{\mathbf{U}}\left|w\right\rangle_{\mathbf{W}}\otimes\left|D\right\rangle_{\mathbf{D}}.\]

  • When the algorithm queries, the database calls \({\sf StdDecomp}\) which unfolds the database and samples a value \(y\) for positions that the algorithm does not know what the value is. More specifically, \({\sf StdDecomp}\left|x\right\rangle_{\mathbf{X}}\left|u\right\rangle_{\mathbf{U}}\left|w\right\rangle_{\mathbf{W}}\otimes\left|D\right\rangle_{\mathbf{D}} := \left|x\right\rangle_{\mathbf{X}}\left|u\right\rangle_{\mathbf{U}}\left|w\right\rangle_{\mathbf{W}}\otimes{\sf StdDecomp}_x\left|D\right\rangle_{\mathbf{D}}\), where \({\sf StdDecomp}_x\) works on \(\mathbf{D}_x\).

    • If \(D(x) = \bot\), \({\sf StdDecomp}_x\) maps \(\left|\bot\right\rangle\) to \[\frac{1}{\sqrt{N}} \sum_{y\in\mathbb{F}_2^m} \left|y\right\rangle.\]

    • If \(D(x) \ne \bot\), \({\sf StdDecomp}_x\) works on the \(x\)-th register, and it is an identity on \[\frac{1}{\sqrt{N}} \sum_{y\in\mathbb{F}_2^m} (-1)^{\langle u,y\rangle} \left|y\right\rangle\] for all \(u \ne 0\); it maps the uniform superposition \(\frac{1}{\sqrt{N}} \sum_{y\in\mathbb{F}_2^m} \left|y\right\rangle\) to \(\left|\bot\right\rangle\).

      More formally, for a \(D'\) such that \(D'(x) = \bot\), \[\begin{align} {\sf StdDecomp}_x \frac{1}{\sqrt{N}} \sum_{y\in\mathbb{F}_2^m} (-1)^{\langle u,y\rangle} \left|D' \cup (x, y)\right\rangle_{\mathbf{D}} = \frac{1}{\sqrt{N}} \sum_{y\in\mathbb{F}_2^m} (-1)^{\langle u,y\rangle} \left|D' \cup (x, y)\right\rangle_{\mathbf{D}} \end{align}\] for any \(u\ne 0\) and, \[\begin{align} {\sf StdDecomp}_x \frac{1}{\sqrt{N}} \sum_{y\in\mathbb{F}_2^m} \left|D' \cup (x, y)\right\rangle_{\mathbf{D}} =\left|D'\right\rangle_{\mathbf{D}}. \end{align}\]

    Intuitively, it swaps a uniform superposition \(\frac{1}{\sqrt{N}} \sum_{y\in\mathbb{F}_2^m} \left|y\right\rangle\) with \(\left|\bot\right\rangle\) on \(\mathbf{D}_x\) and does nothing on other orthogonal basis. So it is a well defined unitary.

Note that the compressed oracle can be implemented in an efficient way where we don’t create \(\mathbf{D}_x\) for all \(x\) and we only store all non-\(\bot\) entries. For more details, please refer to [34]. Zhandry proves that, \({\sf StO}\) and CStO are perfectly indistinguishable to any unbounded quantum algorithm.

Lemma 3 ([34]). Let \(\mathcal{A}\) be an (unbounded) quantum algorithm making oracle queries. The output of \(\mathcal{A}\) given access to the standard oracle is exactly identical to the output of \(\mathcal{A}\) given access to a compressed oracle.

4 The Quantum Anchor State↩︎

In this section we introduce the quantum anchor state, a structured bipartite quantum state that will serve as a basic primitive throughout the paper. Intuitively, the generation process starts from several \({\sf EPR}\) pairs shared between two registers \(\text{\faAnchor}\) and \(\text{\faShip}\). Some ‘decoy’ qubits are then tensored to the \(\text{\faShip}\) register. A random unitary \(U_{\sf shift}\) is applied to \(\text{\faShip}\) to ‘scramble’ and hide the entanglement among all qubits in \(\text{\faShip}\). This ensures that once \(\text{\faShip}\) is given to another party who does not know \(U_{\sf shift}\), it cannot separate the part of \(\text{\faShip}\) that is entangled with \(\text{\faAnchor}\) from the other ‘decoy’ qubits.

If not specified, in remaining paragraphs we consider vectors and matrices with elements in \(\mathbb{F}_2\). Normally, we use \(\mathcal{O}_S^b\), where \(S\) is a set of elements (subsets, cosets, subspaces) and \(b\) is any object (such as symbols, bit strings, and field elements), to denote the oracle that outputs \(b\) on input \(x\in S\) and outputs \(\bot\) otherwise. When \(b=\top\), it is called a membership oracle and we write \(\mathcal{O}_S\) for simplicity. Also, if not specified, the domain of \(\mathcal{O}_S^b\) is the natural domain depending on \(S\). For example, when \(S\) is a subset/coset/subspace of \(\mathbb{F}_2^n\), then the domain is \(\mathbb{F}_2^n\). We abuse notations like \(\left\{0,1\right\}^n\) here so they can interact with field element such as \(x\in\mathbb{F}_2^n\). For example, we use \(0^n\times x\) to denote a vector in \(\mathbb{F}_2^{2n}\) with its first \(n\) bits all zeros and its last \(n\) bits being \(x\). Another example is that we use \(U_{\sf shift}(0^n\times S)\), where \(S\) is a subset/coset/subspace of \(\mathbb{F}_2^n\) and \(U_{\sf shift}\) is a change of basis matrix, to denote the subset/coset/subspace of \(\mathbb{F}_2^{2n}\) consisting of all vectors of the form \(U_{\sf shift}(0^n\times x)\) for \(x\in S\).

Remark 5. When we define subspaces in this paper, we use the columns of a matrix to describe the subspace so that we can define the canonical representation of the subspace and its dual. For example, let \(A\leq\mathbb{F}_2^n\) be a subspace of dimension \(m\) defined by \(m\) columns of a \(n\times n\) change of basis (invertible) matrix \(U\). Let the set of indices of these columns be \(C\). This means that \(A\) is the span of the set of \(m\) columns of \(U\) with indices in \(C\). Now we define \({\sf Can}_A(s)\) and \({\sf Can}_{A^\perp}(s')\) to be the canonical representations of the cosets \(A+s\) and \(A^\perp+s'\):

  • Let \(w\) be the vector obtained by replacing \(m\) bits of \(U^{-1}s\) with indices in \(C\) by zeros. Define \({\sf Can}_A(s):=Uw\).

  • Let \(w'\) be the vector obtained by replacing \(n-m\) bits of \(U^ts'\) with indices not in \(C\) by zeros. Define \({\sf Can}_{A^\perp}(s'):=U^{-t}w'\). Here \(U^{-t}\) is defined as \(\left(U^{t} \right)^{-1}\).

To understand what this definition means, we use the following example. Let \(A\) be a \(n/2\) dimensional subspace of \(\mathbb{F}_2^n\) spanned by the first \(n/2\) columns of \(U_A\). Let \(x=U_A\left(x_A\times 0^{n/2}+0^{n/2}\times x_{A^\perp} \right)\) be a vector in \(\mathbb{F}_2^n\) where \(x_A\) and \(x_{A^\perp}\) are vectors in \(\mathbb{F}_2^{n/2}\). Then we have that \({\sf Can}_A(x)=U_A\left(0^{n/2}\times x_{A^\perp} \right)\) and \({\sf Can}_{A^\perp}(x)=U_A\left(x_A\times 0^{n/2} \right)\). Define \({\sf CS}(A):=\left\{{\sf Can}_A(s):s\in\mathbb{F}_2^n\right\}\) and \({\sf CS}(A^\perp):=\left\{{\sf Can}_{A^\perp}(s'):s'\in\mathbb{F}_2^n\right\}\).

Definition 2 (Quantum Anchor State). Let \({\sf{\lambda}}\) be the security parameter and let \(n_e({\sf{\lambda}}), n_s({\sf{\lambda}}), n_h({\sf{\lambda}})\) be polynomials. Take a uniformly random \((n_e+n_h+n_s)\times (n_e+n_h+n_s)\) change of basis (invertible) matrix \(U_{\sf shift}\). The subspaces \(S,T\) are described by the first \(n_h\) columns and the first \(n_h+n_e\) columns of \(U_{\sf shift}\), respectively. The anchor state \(\left|\Psi_{n_e,n_h,n_s}^{\sf sk}\right\rangle_{\text{\faAnchor}\text{\faShip}}\) is a bipartite state on a \(n_e\)-qubit anchor register \(\text{\faAnchor}\) and a \((n_e+n_h+n_s)\)-qubit vessel register \(\text{\faShip}\). This state is also parameterized by a secret key \({\sf sk}\), which we specify later. The state \(\left|\Psi_{n_e,n_h,n_s}^{\sf sk}\right\rangle_{\text{\faAnchor}\text{\faShip}}\) is generated in the following way:

  1. First generate a \(2(n_e+n_h+n_s)\)-qubit \({\sf EPR}\) state between \(\mathbf{U}\otimes\text{\faAnchor}\otimes\mathbf{V}\) and \(\text{\faShip}\). In other words, after this step, the registers \(\mathbf{U}\) of size \(n_h\), \(\text{\faAnchor}\) of size \(n_e\), and \(\mathbf{V}\) of size \(n_s\) are fully entangled (in the form of \({\sf EPR}\) pairs) with the first \(n_h\) qubits of \(\text{\faShip}\), the middle \(n_e\) qubits of \(\text{\faShip}\), and the last \(n_s\) qubits of \(\text{\faShip}\), respectively.

  2. Measure \(\mathbf{U}\) in the Hadamard basis to obtain a vector \(u'\in\mathbb{F}_2^{n_h}\) (\(\left|+\right\rangle\) is mapped to \(0\) and \(\left|-\right\rangle\) is mapped to \(1\) on each coordinate). Then measure \(\mathbf{V}\) in the standard basis to obtain a vector \(v'\in\mathbb{F}_2^{n_s}\). Compute \(u=U_{\sf shift}^{-t}\left(u'\times 0^{n_e+n_s} \right)\) and \(v=U_{\sf shift}\left(0^{n_h+n_e}\times v' \right)\).

  3. Apply the following change of basis unitary \(\mathcal{U}_{\sf shift}\) on \(\text{\faShip}\): \[\mathcal{U}_{\sf shift}\left|x\right\rangle_{\text{\faShip}}\rightarrow\left|U_{\sf shift}x\right\rangle_{\text{\faShip}}.\]

This procedure is shown in 5. Define the functionality \({\sf GenAnchorState}_{n_e,n_h,n_s}(1^{\sf{\lambda}})\) as the function that samples random \(S,T\), generates \(\left|\Psi^{\sf sk}_{n_e,n_h,n_s}\right\rangle_{\text{\faAnchor}\text{\faShip}}\), and outputs \(\left({\sf sk}:=(U_{\sf shift},u,v),\left|\Psi^{\sf sk}_{n_e,n_h,n_s}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\). One can see that by storing \(U_{\sf shift}\) in \({\sf sk}\), we also store \(S,T\) in it.

The generation process creates the following state on \(\text{\faAnchor}\text{\faShip}\): \[\propto\sum_{x\in\mathbb{F}_2^{n_e}}\left|x\right\rangle_{\text{\faAnchor}}\sum_{s\in S}(-1)^{\left \langle {s,u} \right \rangle}\left|s+U_{\sf shift}\left(0^{n_h}\times x\times 0^{n_s} \right)+v\right\rangle_\text{\faShip}.\]

Remark 6. We may omit the subscript when \(n_e=n_h=n_s=n\) and \(n\) is clear from the context. For example, \(\left({\sf sk},\left|\Psi^{\sf sk}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}(1^{\sf{\lambda}})\) means \(\left({\sf sk},\left|\Psi^{\sf sk}_{n,n,n}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n,n,n}(1^{\sf{\lambda}})\) when \(n\) is clear from the context.

Definition 3 (Domain Extension and Oracle Simulation). Define \({\sf DomainExtension}_{n'_h, n'_s}\) as follows:

  1. It takes \(1^{\sf{\lambda}}\) and works as an isometry on the \(\text{\faShip}\) register of an anchor state \(\left|\Psi^{\sf sk}_{n_e,n_h,n_s}\right\rangle\).

  2. Sample a uniformly random \((n_e+n_h+n_s+n'_h+n'_s)\times (n_e+n_h+n_s+n'_h+n'_s)\) change of basis matrix \(U_{\sf shift}^*\). Define \(S^*\) to be the subspace described by the first \(n'_h\) columns of \(U_{\sf shift}^*\) and define \(T^*\) to be the subspace described by the first \(n'_h+n_h+n_e+n_s\) columns of \(U_{\sf shift}^*\).

  3. Create a \(n'_h\)-qubit register \(\mathbf{U}^*\) and a \(n'_s\)-qubit register \(\mathbf{V}^*\). Then extend \(\text{\faShip}\) by tensoring it with \(n'_h\)/\(n'_s\) qubits at the front/end that are fully entangled with \(\mathbf{U}^*\)/\(\mathbf{V}^*\) in the form of \({\sf EPR}\) pairs, respectively. The extended register is called \(\text{\faShip}^*\).

  4. Measure \(\mathbf{U}^*\) in the Hadamard basis to obtain a vector \({u'}^*\in\mathbb{F}_2^{n'_h}\) (\(\left|+\right\rangle\) is mapped to \(0\) and \(\left|-\right\rangle\) is mapped to \(1\) on each coordinate). Then measure \(\mathbf{V}^*\) in the standard basis to obtain a vector \({v'}^*\in\mathbb{F}_2^{n'_s}\). Compute \(u^*={U_{\sf shift}^*}^{-t}({u'}^*\times 0^{n_h+n_e+n_s+n'_s})\) and \(v^*=U_{\sf shift}^*(0^{n'_h+n_h+n_e+n_s}\times{v'}^*)\).

  5. Apply the following change of basis unitary \(\mathcal{U}_{\sf shift}^*\) on \(\text{\faShip}^*\): \[\mathcal{U}_{\sf shift}^*\left|x\right\rangle_{\text{\faShip}^*}\rightarrow\left|U_{\sf shift}^*x\right\rangle_{\text{\faShip}^*}.\]

  6. Let \({\sf sk}^*=(U_{\sf shift}^*,u^*,v^*)\). Return \({\sf sk}^*\) and \(\text{\faShip}^*\).

Also we define

  • \(S_{\sf ext}:=U_{\sf shift}^*\left(\left\{0,1\right\}^{n'_h}\times S\times 0^{n'_s} \right)\), described by the first \(n_h+n'_h\) columns of \(U_{\sf extshift}\). Where \(U_{\sf extshift}:=U_{\sf shift}^* \begin{pmatrix} I_{n'_h} & & \\ & U_{\sf shift} & \\ & & I_{n'_s} \end{pmatrix}\).

  • \(T_{\sf ext}:=U_{\sf shift}^*\left(\left\{0,1\right\}^{n'_h}\times T\times 0^{n'_s} \right)\), described by the first \(n'_h + n_h + n_e\) columns of \(U_{\sf extshift}\).

  • \(u_{\sf ext}:={U_{\sf shift}^*}^{-t}\left(0^{n'_h}\times u\times 0^{n'_s} \right)+u^*\).

  • \(v_{\sf ext}:=U_{\sf shift}^*\left(0^{n'_h}\times v\times 0^{n'_s} \right)+v^*\).

\({\sf GenAnchorState}\) and \({\sf DomainExtension}\) are shown in 5.

Figure 5: Compact state-generation diagram. {\sf GenAnchorState} and {\sf DomainExtension}.

Here are some useful facts that we will use later in the proof.

Fact 7. Let \(n_e,n_h,n_s\) be polynomials of \({\sf{\lambda}}\) and let \(\left({\sf sk},\left|\Psi^{\sf sk}_{n_e,n_h,n_s}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n_h,n_s}(1^{\sf{\lambda}})\). The standard-basis measurement on \(\text{\faShip}\) always outputs a vector in \(T+v\), and the Hadamard-basis measurement on \(\text{\faShip}\) always outputs a vector in \(S^\perp+u\). Furthermore, the anchor state has the following symmetric property: the following two distributions are equal for fixed \(n_e,n_h,n_s\). \[\begin{align} &\left\{S,T,u,v,\left|\Psi^{\sf sk}_{n_e,n_h,n_s}\right\rangle_{\text{\faAnchor}\text{\faShip}}\middle\vert\left({\sf sk},\left|\Psi^{\sf sk}_{n_e,n_h,n_s}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n_h,n_s}(1^{\sf{\lambda}})\right\}\\ =&\left\{T^\perp,S^\perp,v,u,H^{\otimes (n_e+n_h+n_s)}_{\text{\faShip}}\left|\Psi^{\sf sk}_{n_e,n_s,n_h}\right\rangle_{\text{\faAnchor}\text{\faShip}}\middle\vert\left({\sf sk},\left|\Psi^{\sf sk}_{n_e,n_s,n_h}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n_s,n_h}(1^{\sf{\lambda}})\right\}. \end{align}\]

Fact 8. Let \(n_e,n_h,n_s,n'_h,n'_s\) be polynomials of \({\sf{\lambda}}\). The following two distributions \[\left\{\subarray{c}U_{\sf extshift},\\S_{\sf ext},T_{\sf ext},\\u_{\sf ext},v_{\sf ext},\\\text{state on }\text{\faAnchor}\text{\faShip}^*\endsubarray \middle\vert\subarray{c}\left({\sf sk},\left|\Psi^{\sf sk}_{n_e,n_h,n_s}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n_h,n_s}(1^{\sf{\lambda}})\\ {\sf sk}^*\gets{\sf DomainExtension}_{n'_h,n'_s}(1^{\sf{\lambda}})\text{ on }\text{\faShip}\text{ to obtain }\text{\faShip}^*\endsubarray\right\}\] and \[\left\{\subarray{c}U_{\sf shift},\\S,T,\\u,v,\\\text{state on }\text{\faAnchor}\text{\faShip}\endsubarray \middle\vert\left({\sf sk},\left|\Psi^{\sf sk}_{n_e,n_h+n'_h,n_s+n'_s}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n_h+n'_h,n_s+n'_s}(1^{\sf{\lambda}})\right\}\] are equal.

Fact 9. Let \(\left({\sf sk},\left|\Psi^{{\sf sk}}_{n_e,n_h,n_s}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n_h,n_s}(1^{\sf{\lambda}})\) and let \({\sf sk}^*\) be generated by \({\sf DomainExtension}_{n'_h,n'_s}(1^{\sf{\lambda}})\) working on \(\text{\faShip}\). Any party with \({\sf sk}^*\) can do the following:

  • It can simulate oracle access to \(\mathcal{O}_{T^*+v^*}^{b}\) with \(b\): on input \(z\), check whether \({U_{\sf shift}^*}^{-1}(z-v^*)\) has its last \(n'_s\) bits equal to zero. Output \(b\) if so and output \(\bot\) otherwise.

  • It can simulate oracle access to \(\mathcal{O}_{{S^*}^\perp+u^*}^{b}\) with \(b\): on input \(z\), check whether \({U_{\sf shift}^*}^t(z-u^*)\) has its first \(n'_h\) bits equal to zero. Output \(b\) if so and output \(\bot\) otherwise.

  • It can simulate oracle access to \(\mathcal{O}_{T_{\sf ext}+v_{\sf ext}}^{b}\) given oracle access to \(\mathcal{O}_{T+v}^b\): on input \(z\), let \(z'\) be the result of discarding the first \(n'_h\) bits and the last \(n'_s\) bits of \({U_{\sf shift}^*}^{-1}(z-v^*)\). If any of the last \(n'_s\) discarded bits is non-zero, output \(\bot\); otherwise forward the output of \(\mathcal{O}_{T+v}^b(z')\).

  • It can simulate oracle access to \(\mathcal{O}_{S_{\sf ext}^\perp+u_{\sf ext}}^{b}\) given oracle access to \(\mathcal{O}_{S^\perp+u}^b\): on input \(z\), let \(z'\) be the result of discarding the first \(n'_h\) bits and the last \(n'_s\) bits \({U_{\sf shift}^*}^{t}(z-u^*)\). If any of the first \(n'_h\) discarded bits is non-zero, output \(\bot\); otherwise forward the output of \(\mathcal{O}_{S^\perp+u}^b(z')\).

5 Collapsing vs Non-collapsing Oracles↩︎

Let \(a({\sf{\lambda}})\leq b({\sf{\lambda}})< c({\sf{\lambda}})\leq d({\sf{\lambda}})\) be polynomials of \({\sf{\lambda}}\). Let \(W\leq\mathbb{F}_2^d\) be a subspace of dimension \(c\). Let \(U^{(\cdot)}\) be any efficient isometry with superposition access to a classical oracle. We introduce a subspace oracle indistinguishability lemma below. In the remaining part of this section \(S,T\) are sampled so that \(T\leq W\) is a uniform random subspace of dimension \(b\) and \(S\leq T\) be a uniform random subspace of dimension \(a\).

Lemma 4. Let \(\left\{\mathcal{O}_S\right\}_S\) be any family of oracles such that \(\mathcal{O}_S\) outputs \(\bot\) on \(z\notin S\). Let \(\left\{\mathcal{O}_{S,T}\right\}_{S,T}\) be any family of oracle such that \(\mathcal{O}_{S,T}\) outputs \(\mathcal{O}_S(z)\) on \(z\in S\) and outputs \(\bot\) on \(z\notin T\). There exists a polynomial \(q({\sf{\lambda}})\) such that the following holds. Define \(\left|\psi_S\right\rangle:=U^{\mathcal{O}_S}\left|S\right\rangle\), \(\left|\psi_T\right\rangle:=U^{\mathcal{O}_{S,T}}\left|S\right\rangle\), \(\left|\phi_S\right\rangle=\frac{1}{\sqrt{\binom{c}{b}_2\binom{b}{a}_2}}\sum_{S,T}\left|S,T\right\rangle\left|\psi_{S}\right\rangle\) and \(\left|\phi_T\right\rangle=\frac{1}{\sqrt{\binom{c}{b}_2\binom{b}{a}_2}}\sum_{S,T}\left|S,T\right\rangle\left|\psi_{T}\right\rangle\) we have \[{\mathop{\mathrm{TD}}\left(\left|\phi_S\right\rangle\left\langle\phi_S\right|, \left|\phi_T\right\rangle\left\langle\phi_T\right|\right)}\leq\frac{q}{2^{(c-b)/2}}.\]

Proof. We prove it by hybrid argument. Let the number of oracle queries of \(U^\mathcal{O}\) be \(q'({\sf{\lambda}})\). Define \(\left|\psi^i\right\rangle\) to be the state after applying \(U^\mathcal{O}\) on \(\left|S\right\rangle\), where the first \(i\) queries use oracle \(\mathcal{O}_{S}\) and other queries use oracle \(\mathcal{O}_{S,T}\). We have \(\left|\psi^0\right\rangle=\left|\psi_T\right\rangle\) and \(\left|\psi^{q'}\right\rangle=\left|\psi_S\right\rangle\). Similarly we define \(\left|\phi^i\right\rangle=\frac{1}{\sqrt{\binom{c}{b}_2\binom{b}{a}_2}}\sum_{S,T}\left|S,T\right\rangle\left|\psi^i\right\rangle\). To use hybrid argument, we need the following claim.

Claim 10. For all \(0\leq i<q'\), \[{\mathop{\mathrm{TD}}\left(\left|\phi^i\right\rangle\left\langle\phi^i\right|, \left|\phi^{i+1}\right\rangle\left\langle\phi^{i+1}\right|\right)}\leq\frac{2}{2^{(c-b)/2}}.\]

Proof. Let \(\left|\psi^{\leq i}\right\rangle\) be the state of applying \(U^{\mathcal{O}_S}\) on \(\left|S\right\rangle\) but stop before the \(i+1\)-th oracle query. Define \(\Pi_{T\setminus S}\) to be the projector onto states where the value \(z\) on the oracle query register is in \(T\) but is not in \(S\). We have \[\begin{align} &{\mathop{\mathrm{TD}}\left(\left|\phi^i\right\rangle\left\langle\phi^i\right|, \left|\phi^{i+1}\right\rangle\left\langle\phi^{i+1}\right|\right)}\\ =&\frac{1}{\binom{c}{b}_2\binom{b}{a}_2}{\mathop{\mathrm{TD}}\left(\left(\sum_{S,T}\left|S,T\right\rangle\mathcal{O}_{S,T}\left|\psi^{\leq i}\right\rangle \right)\left(\sum_{S,T}\left\langle S,T\right|\left\langle\psi^{\leq i}\right|\mathcal{O}_{S,T}^{\dagger} \right), \left(\sum_{S,T}\left|S,T\right\rangle\mathcal{O}_S\left|\psi^{\leq i}\right\rangle \right)\left(\sum_{S,T}\left\langle S,T\right|\left\langle\psi^{\leq i}\right|\mathcal{O}_S^{\dagger} \right)\right)}\\ =&\sqrt{1-\left|\mathop{\mathbb{E}}_{S,T}\left[\left\langle\psi^{\leq i}\right|\mathcal{O}_{S,T}^{\dagger}\mathcal{O}_S\left|\psi^{\leq i}\right\rangle\right]\right|^2}\\ =&\sqrt{1-\left|\mathop{\mathbb{E}}_{S,T}\left[\left\langle\psi^{\leq i}\right|\Pi_{T\setminus S}\mathcal{O}_{S,T}^{\dagger}\mathcal{O}_S\Pi_{T\setminus S}\left|\psi^{\leq i}\right\rangle+\left\langle\psi^{\leq i}\right|(I-\Pi_{T\setminus S})\mathcal{O}_{S,T}^{\dagger}\mathcal{O}_S(I-\Pi_{T\setminus S})\left|\psi^{\leq i}\right\rangle\right]\right|^2}\\ \leq&\sqrt{1-\left(\left|\mathop{\mathbb{E}}_{S,T}\left[\left\langle\psi^{\leq i}\right|(I-\Pi_{T\setminus S})\mathcal{O}_{S,T}^{\dagger}\mathcal{O}_S(I-\Pi_{T\setminus S})\left|\psi^{\leq i}\right\rangle\right]\right|-\left|\mathop{\mathbb{E}}_{S,T}\left[\left\langle\psi^{\leq i}\right|\Pi_{T\setminus S}\mathcal{O}_{S,T}^{\dagger}\mathcal{O}_S\Pi_{T\setminus S}\left|\psi^{\leq i}\right\rangle\right]\right| \right)^2}\\ \leq&\sqrt{1-\left(1-\frac{2}{2^{c-b}} \right)^2}\\ \leq&\frac{2}{2^{(c-b)/2}}. \end{align}\] Now we explain these (in)equations:

  • The equation between line 2 and line 3 is by the definition of trace distance between pure state \[{\mathop{\mathrm{TD}}\left(\left|\phi\right\rangle\left\langle\phi\right|, \left|\psi\right\rangle\left\langle\psi\right|\right)}=\sqrt{1-\left|\left\langle \phi\vert \psi\right\rangle\right|^2}.\] And also notice that all cross terms for different \(S,T\) in the inner product is zero because \(\left\langle S,T\vert S',T'\right\rangle=0\) for \((S,T)\neq (S',T')\).

  • The equation between line 3 and line 4 is because that the cross terms, for example, \[\left\langle\psi^{\leq i}\right|(I-\Pi_{T\setminus S})\mathcal{O}_{S,T}^{\dagger}\mathcal{O}_S\Pi_{T\setminus S}\left|\psi^{\leq i}\right\rangle\] is zero because \(\Pi_S\) and \(\Pi_{T\setminus S}\) maps the state to disjoint basis on the query register.

  • The inequality between line 4 and line 5 is because \(\left|a+b\right|^2\geq(\left|b\right|-\left|a\right|)^2\).

  • The inequality between line 5 and line 6 is because that \(\mathcal{O}_{S,T}\) and \(\mathcal{O}_S\) is the same oracle if the input state is in \(I-\Pi_{T\setminus S}\). We have \[\begin{align} &\left|\mathop{\mathbb{E}}_{S,T}\left[\left\langle\psi^{\leq i}\right|(I-\Pi_{T\setminus S})\mathcal{O}_{S,T}^{\dagger}\mathcal{O}_S(I-\Pi_{T\setminus S})\left|\psi^{\leq i}\right\rangle\right]\right|\\ =&\mathop{\mathbb{E}}_{S,T}\left[\left|(I-\Pi_{T\setminus S})\left|\psi^{\leq i}\right\rangle\right|^2\right]\geq 1-\frac{1}{2^{c-b}} \end{align}\] and \[\begin{align} &\left|\mathop{\mathbb{E}}_{S,T}\left[\left\langle\psi^{\leq i}\right|\Pi_{T\setminus S}\mathcal{O}_{S,T}^{\dagger}\mathcal{O}_S\Pi_{T\setminus S}\left|\psi^{\leq i}\right\rangle\right]\right|\\ \leq&\mathop{\mathbb{E}}_{S,T}\left[\left|\Pi_{T\setminus S}\left|\psi^{\leq i}\right\rangle\right|^2\right]\leq\frac{1}{2^{c-b}}. \end{align}\] The last steps of both calculation are because that \(\left|\psi^{\leq i}\right\rangle\) is independent of \(T\) thus the average weight on \(\Pi_{T\setminus S}\) is at most \(\frac{1}{2^{c-b}}\).

  • The inequality between line 6 and line 7 is because \(\sqrt{1-(1-x)^2}\leq\sqrt{2x}\).

 ◻

Setting \(q({\sf{\lambda}})=2q'({\sf{\lambda}})\), we see that the lemma follows. ◻

Let \(m({\sf{\lambda}})\) be a polynomial. Now we consider the case that \(c=d\) and let \(w\) be a uniform random vector in \(\mathbb{F}_2^c\). We further define some oracles:

  • \(\mathcal{O}_{\sf any}:\mathbb{F}_2^{c}\rightarrow\mathbb{F}_2^m\) be an oracle that is sampled from a distribution depending on \(S,T,w\) such that the every output alone is independent of \(T\) given \(S,w\). (But maybe with two outputs of inputs, one can recover \(S,T,w\))

  • \(\mathcal{O}_{T+w}^{\sf ncol}:\mathbb{F}_2^{c}\rightarrow\mathbb{F}_2^{c}\cup\left\{\bot\right\}\) on input \(z\) checks if it is in \(T+w\). It returns \(\bot\) if it is not. Otherwise, it returns \(\mathcal{O}_{\sf any}({\sf Can}_S(w))\).

  • \(\mathcal{O}_{T+w}^{\sf col}:\mathbb{F}_2^{c}\rightarrow\mathbb{F}_2^{c}\cup\left\{\bot\right\}\) on input \(z\) checks if it is in \(T+w\). It returns \(\bot\) if it is not. Otherwise, it returns \(\mathcal{O}_{\sf any}({\sf Can}_S(z))\).

Lemma 5. For any efficient isometry \[\mathcal{U}^{\mathcal{O}}:\mathcal{H}_{\mathbf{S}}\otimes\mathcal{H}_{\mathbf{W}}\rightarrow\mathcal{H}_\mathbf{Z}\] with oracle access to \(\mathcal{O}\) where \(\mathcal{O}\) is either \(\mathcal{O}_{T+w}^{\sf ncol}\) or \(\mathcal{O}_{T+w}^{\sf col}\). There exists a polynomial \(q({\sf{\lambda}})\) such that let \(\left|\psi_{T+w}^{\sf ncol}\right\rangle=\mathcal{U}^{\mathcal{O}_{T+w}^{\sf ncol}}\left|S\right\rangle_{\mathbf{S}}\left|w\right\rangle_{\mathbf{W}}\) and \(\left|\psi_{T+w}^{\sf col}\right\rangle=\mathcal{U}^{\mathcal{O}_{T+w}^{\sf col}}\left|S\right\rangle_{\mathbf{S}}\left|w\right\rangle_{\mathbf{W}}\). We have \[\mathop{\mathbb{E}}_{S,T,w,\mathcal{O}_{\sf any}}\left[{\mathop{\mathrm{TD}}\left(\left|\psi_{T+w}^{\sf ncol}\right\rangle\left\langle\psi_{T+w}^{\sf ncol}\right|, \left|\psi_{T+w}^{\sf col}\right\rangle\left\langle\psi_{T+w}^{\sf col}\right|\right)}\right]\leq\frac{q}{2^{(c-b)/2}}.\]

Proof. We prove it by hybrid argument.
Hybrid 0: This is the hybrid corresponding to \(\left|\psi_{T+w}^{\sf ncol}\right\rangle=\mathcal{U}^{\mathcal{O}_{T+w}^{\sf ncol}}\left|S\right\rangle_{\mathbf{S}}\left|w\right\rangle_{\mathbf{W}}\).
Hybrid 1: In this hybrid, the final state is \(\left|\psi_{S+w}^{\sf ncol}\right\rangle=\mathcal{U}^{\mathcal{O}_{S+w}^{\sf ncol}}\left|S\right\rangle_{\mathbf{S}}\left|w\right\rangle_{\mathbf{W}}\), where the new oracle is defined as:

  • \(\mathcal{O}_{S+w}^{\sf ncol}:\mathbb{F}_2^{c}\rightarrow\mathbb{F}_2^m\cup\left\{\bot\right\}\) on input \(z\) checks if it is in \(S+w\). It returns \(\bot\) if it is not. Otherwise, it returns \(\mathcal{O}_{\sf any}({\sf Can}_S(w))\).

Claim 11. There exists polynomial \(q_0({\sf{\lambda}})\) such that \[\mathop{\mathbb{E}}_{S,T,w,\mathcal{O}_{\sf any}}\left[{\mathop{\mathrm{TD}}\left(\left|\psi_{T+w}^{\sf ncol}\right\rangle\left\langle\psi_{T+w}^{\sf ncol}\right|, \left|\psi_{S+w}^{\sf ncol}\right\rangle\left\langle\psi_{S+w}^{\sf ncol}\right|\right)}\right]\leq\frac{q_0}{2^{(c-b)/2}}.\]

Proof. \(T\) is a uniform random subspace containing \(S\) given \(S,w\). Also the output of \(\mathcal{O}_{S+w}^{\sf ncol}\) is independent of \(T\). Thus by 4 there exists such polynomial \(q_0({\sf{\lambda}})\). The reason that we can call this lemma is because \(w\) is given at the beginning so \(\mathcal{O}_{T+w}^{\sf ncol}\) is equivalent to \(\mathcal{O}_{T}^{\sf ncol}(\cdot -w)\) and \(\mathcal{O}_{S+w}^{\sf ncol}\) is equivalent to \(\mathcal{O}_{S}^{\sf ncol}(\cdot -w)\) where for \(A=S,T\) we define

  • \(\mathcal{O}_{A}^{\sf ncol}:\mathbb{F}_2^{c}\rightarrow\mathbb{F}_2^{c}\cup\left\{\bot\right\}\) on input \(z\) checks if it is in \(A\). It returns \(\bot\) if it is not. Otherwise, it returns \(\mathcal{O}_{\sf any}({\sf Can}_S(w))\).

While \(\left\{\mathcal{O}_{S}^{\sf ncol}\right\}_S\) and \(\left\{\mathcal{O}_{T}^{\sf ncol}\right\}_T\) satisfies the requirement in 4. ◻

Hybrid 2: In this hybrid, the final state is \(\left|\psi_{S+w}^{\sf col}\right\rangle=\mathcal{U}^{\mathcal{O}_{S+w}^{\sf col}}\left|S\right\rangle_{\mathbf{S}}\left|w\right\rangle_{\mathbf{W}}\), where the new oracle is defined as:

  • \(\mathcal{O}_{S+w}^{\sf col}:\mathbb{F}_2^{c}\rightarrow\mathbb{F}_2^m\cup\left\{\bot\right\}\) on input \(z\) checks if it is in \(S+w\). It returns \(\bot\) if it is not. Otherwise, it returns \(\mathcal{O}_{\sf any}({\sf Can}_S(z))\).

Claim 12. For all \(S,T,w,\mathcal{O}_{\sf any}\), \[{\mathop{\mathrm{TD}}\left(\left|\psi_{S+w}^{\sf ncol}\right\rangle\left\langle\psi_{S+w}^{\sf ncol}\right|, \left|\psi_{S+w}^{\sf col}\right\rangle\left\langle\psi_{S+w}^{\sf col}\right|\right)}=0.\]

Proof. For any vector \(z\in S+w\), \(S+w\) and \(S+z\) are the same coset. These two hybrids are identical because \(\mathcal{O}_{\sf any}({\sf Can}_S(S+w))=\mathcal{O}_{\sf any}({\sf Can}_S(S+z))\). ◻

Hybrid 3: In this hybrid, the final state is \(\left|\psi_{T+w}^{\sf col}\right\rangle=\mathcal{U}^{\mathcal{O}_{T+w}^{\sf col}}\left|S\right\rangle_{\mathbf{S}}\left|w\right\rangle_{\mathbf{W}}\).

Claim 13. There exists polynomial \(q_1({\sf{\lambda}})\) such that \[\mathop{\mathbb{E}}_{S,T,w,\mathcal{O}_{\sf any}}\left[{\mathop{\mathrm{TD}}\left(\left|\psi_{S+w}^{\sf col}\right\rangle\left\langle\psi_{S+w}^{\sf col}\right|, \left|\psi_{T+w}^{\sf col}\right\rangle\left\langle\psi_{T+w}^{\sf col}\right|\right)}\right]\leq\frac{q_1}{2^{(c-b)/2}}.\]

Proof. \(T\) is a uniform random subspace containing \(S\) given \(S,w\). Also the output of \(\mathcal{O}_{S+w}^{\sf col}\) is independent of \(T\). Thus by 4 there exists such polynomial \(q_1({\sf{\lambda}})\). The reason is similar to the one mentioned in the proof of 11. ◻

Combine all above, let \(q=q_0+q_1\), we proved the lemma. ◻

6 Monogamy-of-Entanglement Games↩︎

The purpose of this section is to prove properties of the following game.

Definition 4 (Multi-Stage Decision/Search Monogamy-of-Entanglement Game). Let \({\sf{\lambda}}\in\mathbb{N}\) be the security parameter and let \(n({\sf{\lambda}})\geq{\sf{\lambda}}\), and \(n_e({\sf{\lambda}}),m_0({\sf{\lambda}}),m_1({\sf{\lambda}})\) be polynomials. Consider the following game between the challenger and an adversary \(\mathcal{A}=\allowdisplaybreaks(\mathcal{A}_M^0,\mathcal{A}_M^1,\mathcal{A}_M^2,\mathcal{A}_L^0,\mathcal{A}_L^1,\mathcal{A}_R^0,\mathcal{A}_R^1)\):

  1. The challenger generates \(\left({\sf sk},\left|\Psi^{{\sf sk}}_{n_e,n,n}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n,n}(1^{\sf{\lambda}})\) and gives the register \(\text{\faShip}\) to \(\mathcal{A}_M\). All parties of the adversary are given oracle access to \(\mathcal{O}_{T+v}\) and \(\mathcal{O}_{S^\perp+u}\).

  2. \(\mathcal{A}_M^0\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, \(\mathcal{A}_M^0\) generates a tripartite state on \(\mathbf{L}\mathbf{M}\mathbf{R}\). It sends \(\mathbf{L}\) to \(\mathcal{A}_L^0\), sends \(\mathbf{M}\) to \(\mathcal{A}_M^1\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R^0\).

  3. \(\mathcal{A}_M^1\) is given the access to \(\mathcal{O}_{T+v}^{b_0}\) for random \(b_0\overset{\$}{\gets}\mathbb{F}_2^{m_0}\). We can imagine implementing this oracle in a purified manner, where we create a register that is initialized to \(\left|+\right\rangle_\mathbf{B}\), the uniform superposition over all \(b_0\), and \(\mathcal{A}_M^1\) is able to perform the following operation in order to access \(\mathbf{B}\): \[\sum_{b_0\in\mathbb{F}_2^{m_0}}\left|b_0\right\rangle\left\langle b_0\right|_{\mathbf{B}}\otimes\mathcal{O}_{T+v}^{b_0}.\] \(\mathcal{A}_M^1\) with access to this oracle and \(\mathbf{M}\) generates a tripartite state on \(\mathbf{M}_L\mathbf{M}'\mathbf{M}_R\). It sends \(\mathbf{M}_L\) to \(\mathcal{A}_L^0\), sends \(\mathbf{M}'\) to \(\mathcal{A}_M^2\) and sends \(\mathbf{M}_R\) to \(\mathcal{A}_R^0\). We will name the time just after all operations of \(\mathcal{A}_M^1\) are complete and before renaming the registers and splitting them as BeforeSplit.

  4. \(\mathcal{A}_L^0\) and \(\mathcal{A}_R^0\) are given access to \(\mathcal{O}_{T+v}^{b_0}\). \(\mathcal{A}_L^0\) on \(\mathbf{L}\mathbf{M}_L\) produces answer \(b_0^l\) and a state on register \(\mathbf{L}'\) that is sent to \(\mathcal{A}_L^1\). \(\mathcal{A}_R^0\) on \(\mathbf{R}\mathbf{M}_R\) produces answer \(b_0^r\) and a state on register \(\mathbf{R}'\) that is sent to \(\mathcal{A}_R^1\).

  5. \(\mathcal{A}_M^2\) is given access to \(\mathcal{O}_{T+v}^{b_0}\) and \(\mathcal{O}_{S^\perp+u}^{b_1}\) for random \(b_1\overset{\$}{\gets}\mathbb{F}_2^{m_1}\). It generates a bipartite state on \(\mathbf{M}'_L\mathbf{M}'_R\). \(\mathbf{M}'_L\) is given to \(\mathcal{A}_L^1\) and \(\mathbf{M}'_R\) is given to \(\mathcal{A}_R^1\).

  6. \(\mathcal{A}_L^1\) and \(\mathcal{A}_R^1\) are given access to \(\mathcal{O}_{T+v}^{b_0}\) and \(\mathcal{O}_{S^\perp+u}^{b_1}\). \(\mathcal{A}_L^1\) on \(\mathbf{L}'\mathbf{M}'_L\) generates the answer \(b_1^l\). \(\mathcal{A}_R^1\) on \(\mathbf{R}'\mathbf{M}'_R\) generates the answer \(b_1^r\). The adversary wins iff \(b_0^l=b_0^r=b_0\) and \(b_1^l=b_1^r=b_1\), where \(b_0\) is obtained by measuring the \(\mathbf{B}\) register.

This game is displayed in 6. Let \({\sf MultiStageSearchMonogamy}(\mathcal{A},1^{\sf{\lambda}})\) be the random variable that takes value \(1/0/\bot\) if the adversary \(\mathcal{A}\) wins/loses/aborts in the above game, respectively. Specifically, we use \({\sf MultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})\) to denote the same random variable when \(m_0({\sf{\lambda}})=1\) (but \(m_1\) can still be arbitrary).

Figure 6: The multi-stage monogamy-of-entanglement game MultiStageSearchMonogamy/MultiStageDecisionMonogamy.

The main result of this section is 11. Intuitively, it states that any adversary passing the above game with good probability has to recover the value of \(b_0\) by querying its oracle already at the time BeforeSplit. Formally, we show that for each value of \(b_0\), the states corresponding to \(b_0\) at BeforeSplit are almost orthogonal to each other. Our proof establishing this fact will involve several reductions between various monogamy-of-entanglement games.

6.1 Asymmetric Monogamy-of-Entanglement Games↩︎

Theorem 14 ([37] Theorem 5.4). Let \(A\leq\mathbb{F}_2^{n}\) be a uniformly random subspace of dimension \(n/2\) described by the first \(n/2\) columns of a uniformly random change of basis matrix \(U\). Let \(s\) be a vector in \({\sf CS}(A)\) and \(t\) be a vector in \({\sf CS}(A^\perp)\). Define the coset state as \[\left|A_{s,t}\right\rangle=\frac{1}{\sqrt{\left|A\right|}}\sum_{a\in A}(-1)^{\left \langle {a,t} \right \rangle}\left|a+s\right\rangle,\] Consider the following coset monogamy game for adversary \(\mathcal{A}=(\mathcal{A}_M,\mathcal{A}_L,\mathcal{A}_R)\).

  1. The challenger picks a random change of basis matrix \(U\) that describes a uniformly random subspace \(A\subseteq\mathbb{F}_2^n\) of dimension \(n/2\), samples \(s\overset{\$}{\gets}{\sf CS}(A)\) and \(t\overset{\$}{\gets}{\sf CS}(A^\perp)\). The challenger sends \(\left|A_{s,t}\right\rangle_{\mathbf{M}}\) to the adversary \(\mathcal{A}_M\).

  2. \(\mathcal{A}_M\) generates a bipartite state on \(\mathbf{L}\mathbf{R}\), sends \(\mathbf{L}\) to \(\mathcal{A}_L\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R\).

  3. The challenger samples \(r_L,r_R\overset{\$}{\gets}\mathbb{F}_2^n\). \(\mathcal{A}_L\) is given \((U,r_L)\) and \(\mathcal{A}_R\) is given \((U,r_R)\). \(\mathcal{A}_L\) returns \(b^l_0\) and \(\mathcal{A}_R\) returns \(b^r_1\).

The adversary wins if and only if \(b^l_0\oplus b^r_1=\left \langle {r_L,s} \right \rangle\oplus\left \langle {r_R,t} \right \rangle\). Let \({\sf CosetMonogamy}(\mathcal{A},1^{\sf{\lambda}})\) be the random variable that takes value \(1/0/\bot\) if the adversary \(\mathcal{A}\) wins/loses/aborts in the above game, respectively. For any adversary \(\mathcal{A}\), \[{\sf{Pr}}\left[{\sf CosetMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]\leq\frac{1}{2}+{\sf negl}({\sf{\lambda}}).\]

Remark 15. The canonical representation set \({\sf CS}\) defined in [37] is a bit different from ours. In [37] they don’t have \(U_A\), instead they define \({\sf Can}_A(z)\) as the lexicographically smallest element in \(A+z\). However, it is easy to see that the proof in [37] holds even if we define the canonical representation our way.

Now we present a modified version of the above game where the prover can choose to abort before the test.

Lemma 6 (Coset Monogamy-of-Entanglement Game With Abort). Let \(A\leq\mathbb{F}_2^{n}\) be a uniformly random subspace of dimension \(n/2\) described by the first \(n/2\) columns of a uniformly random change of basis matrix \(U\). Let \(s\) be a vector in \({\sf CS}(A)\) and \(t\) be a vector in \({\sf CS}(A^\perp)\). Define the coset state as \[\left|A_{s,t}\right\rangle=\frac{1}{\sqrt{\left|A\right|}}\sum_{a\in A}(-1)^{\left \langle {a,t} \right \rangle}\left|a+s\right\rangle,\] Consider the following coset monogamy game with abort for adversary \(\mathcal{A}=(\mathcal{A}_M,\mathcal{A}_L,\mathcal{A}_R)\). Modifications are highlighted.

  1. The challenger picks a random change of basis matrix \(U\) that describes a uniformly random subspace \(A\subseteq\mathbb{F}_2^n\) of dimension \(n/2\), samples \(s\overset{\$}{\gets}{\sf CS}(A)\) and \(t\overset{\$}{\gets}{\sf CS}(A^\perp)\). The challenger sends \(\left|A_{s,t}\right\rangle_{\mathbf{M}}\) to the adversary \(\mathcal{A}_M\).

  2. \(\mathcal{A}_M\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, \(\mathcal{A}_M\) generates a bipartite state on \(\mathbf{L}\mathbf{R}\), sends \(\mathbf{L}\) to \(\mathcal{A}_L\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R\).

  3. The challenger samples \(r_L,r_R\overset{\$}{\gets}\mathbb{F}_2^n\). \(\mathcal{A}_L\) is given \((U,r_L)\) and \(\mathcal{A}_R\) is given \((U,r_R)\). \(\mathcal{A}_L\) returns \(b^l_0\) and \(\mathcal{A}_R\) returns \(b^r_1\).

The adversary wins if and only if \(b^l_0\oplus b^r_1=\left \langle {r_L,s} \right \rangle\oplus\left \langle {r_R,t} \right \rangle\). Let \({\sf CosetMonogamy}(\mathcal{A},1^{\sf{\lambda}})\) be the random variable that takes value \(1/0/\bot\) if the adversary \(\mathcal{A}\) wins/loses/aborts in the above game, respectively. For any adversary \(\mathcal{A}\) such that \[{\sf{Pr}}\left[{\sf CosetMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]\geq \frac{1}{{\sf poly}({\sf{\lambda}})},\] we have \[\frac{{\sf{Pr}}\left[{\sf CosetMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf CosetMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}\leq\frac{1}{2}+{\sf negl}({\sf{\lambda}}).\]

Proof. Suppose that there exists an adversary \(\mathcal{A}\) and an inverse polynomial polynomial \(\delta({\sf{\lambda}})\) such that \[{\sf{Pr}}\left[{\sf CosetMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]\geq\delta({\sf{\lambda}}),\] and \[\frac{{\sf{Pr}}\left[{\sf CosetMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf CosetMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}\geq\frac{1}{2}+\delta({\sf{\lambda}}).\] Then we construct an adversary \(\mathcal{B}\) that breaks 14. \(\mathcal{B}\) works as follows:

  1. \(\mathcal{B}_M\) runs \(\mathcal{A}_M\). If \(\mathcal{A}_M\) aborts then \(\mathcal{B}_M\) sends an abort symbol to \(\mathcal{B}_L\) and \(\mathcal{B}_R\). Otherwise, it forwards \(\mathbf{L}\mathbf{R}\), \(\mathcal{A}_M\)’s output to \(\mathcal{B}_L\) and \(\mathcal{B}_R\), respectively.

  2. \(\mathcal{B}_L\) outputs a random bit if an abort symbol is received. Otherwise, it runs \(\mathcal{A}_L\) and forwards the answer.

  3. \(\mathcal{B}_R\) outputs a random bit if an abort symbol is received. Otherwise, it runs \(\mathcal{A}_R\) and forwards the answer.

Condition on not aborting, the winning probability of \(\mathcal{B}\) is at least \(\frac{1}{2}+\delta({\sf{\lambda}})\). On the other hand, if \(\mathcal{A}_M\) aborts, the winning probability of \(\mathcal{B}\) is exactly \(\frac{1}{2}\) because it outputs two random bits. Thus, the overall winning probability of \(\mathcal{B}\) is \[\delta({\sf{\lambda}})\cdot\left(\frac{1}{2}+\delta({\sf{\lambda}}) \right)+\left(1-\delta({\sf{\lambda}}) \right)\cdot\frac{1}{2}=\frac{1}{2}+(\delta({\sf{\lambda}}))^2.\] By contradiction, we proved the lemma. ◻

Lemma 7. Consider the following asymmetric coset monogamy game for adversary \(\mathcal{A}=(\mathcal{A}_M,\mathcal{A}_L,\mathcal{A}_R)\).

  1. The challenger picks a random change of basis matrix \(U\) that describes a uniformly random subspace \(A\subseteq\mathbb{F}_2^n\) of dimension \(n/2\) using its first \(n/2\) columns, samples \(s\overset{\$}{\gets}{\sf CS}(A)\) and \(t\overset{\$}{\gets}{\sf CS}(A^\perp)\). The challenger sends \(\left|A_{s,t}\right\rangle_{\mathbf{M}}\) to the adversary \(\mathcal{A}_M\).

  2. \(\mathcal{A}_M\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, \(\mathcal{A}_M\) generates a bipartite state on \(\mathbf{L}\mathbf{R}\), sends \(\mathbf{L}\) to \(\mathcal{A}_L\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R\).

  3. The challenger samples \(r_L,r_R\overset{\$}{\gets}\mathbb{F}_2^n\). \(\mathcal{A}_L\) is given \((U,r_L)\) and \(\mathcal{A}_R\) is given \((\left \langle {r_L,s} \right \rangle,U,r_R)\). \(\mathcal{A}_L\) returns \(b^l_0\) and \(\mathcal{A}_R\) returns \(b^r_1\).

The adversary wins if and only if \(b^l_0=\left \langle {r_L,s} \right \rangle\) and \(b^r_1=\left \langle {r_R,t} \right \rangle\). Let \({\sf AsymmetricCosetMonogamy}(\mathcal{A},1^{\sf{\lambda}})\) be the random variable that takes value \(1/0/\bot\) if the adversary \(\mathcal{A}\) wins/loses/aborts in the above game, respectively. For any efficient adversary \(\mathcal{A}\) such that \[{\sf{Pr}}\left[{\sf AsymmetricCosetMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]\geq\frac{1}{{\sf poly}({\sf{\lambda}})},\] we have \[\frac{{\sf{Pr}}\left[{\sf AsymmetricCosetMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf AsymmetricCosetMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}\leq\frac{1}{2}+{\sf negl}({\sf{\lambda}}).\]

Proof. The difference between this lemma and 14 is that \(\mathcal{A}_R\) is given the correct answer of \(\mathcal{A}_L\). For any adversary \(\mathcal{A}\) that wins with probability at least \(\frac{1}{2}+\delta({\sf{\lambda}})\) in this game condition on not aborting and its non-aborting probability is at least \(\delta({\sf{\lambda}})\) for some inverse polynomial \(\delta({\sf{\lambda}})\), we construct adversary \(\mathcal{B}\) that violates 14. \(\mathcal{B}\) is constructed as follows:

  1. \(\mathcal{B}_M\) runs \(\mathcal{A}_M\) on \(\mathbf{M}\) to obtain \(\mathbf{L}\mathbf{R}\). It aborts if \(\mathcal{A}_M\) aborts.

  2. \(\mathcal{B}_L\) receives \((U,r_L)\) and runs \(\mathcal{A}_L\) on \(\mathbf{L}\). It outputs \(b^l_0\), the output of \(\mathcal{A}_L\).

  3. \(\mathcal{B}_R\) receives \((U,r_R)\) and samples \(b_0\overset{\$}{\gets}\mathbb{F}_2\) as a guess to the answer. It runs \(\mathcal{A}_R\) with input \((b_0,U,r_R)\) on \(\mathbf{R}\). It outputs \(b^r_1\), the output of \(\mathcal{A}_R\).

The aborting probability of \(\mathcal{B}\) is exactly the same as the aborting probability of \(\mathcal{A}\), now let us investigate the winning probability of \(\mathcal{B}\) condition on not aborting. Define \[p_{l,r}^{b}=\underset{U,s,t,r_L,r_R,b_0}{\sf{Pr}}\left[\subarray{c}\mathbb{1}[b^l_0=\left \langle {r_L,s} \right \rangle]=l\\\mathbb{1}[b^r_1=\left \langle {r_R,t} \right \rangle]=r\endsubarray\middle\vert \subarray{c}\mathbb{1}[b_0=\left \langle {r_L,s} \right \rangle]=b\\ \mathcal{A}\text{ does not abort}\endsubarray\right].\] where \(\mathbb{1}[a=b]\) is \(1\) when \(a=b\) and \(0\) otherwise. From our assumption on \(\mathcal{A}\) we have \[p_{1,1}^1=\underset{U,s,t,r_L,r_R,b_0}{\sf{Pr}}\left[\subarray{c}b^l_0=\left \langle {r_L,s} \right \rangle\\b^r_1=\left \langle {r_R,t} \right \rangle\endsubarray\middle\vert \subarray{c}b_0=\left \langle {r_L,s} \right \rangle\\ \mathcal{A}\text{ does not abort}\endsubarray\right]\geq\frac{1}{2}+\delta({\sf{\lambda}}).\] Notice that whether the event \(b_0=\left \langle {r_L,s} \right \rangle\) happens or not cannot be detected by both parties with noticeable probability. For \(\mathcal{B}_L\), it does not know whether \(b_0\) is sampled correctly., so the correctness of \(b_0\) will not affect its winning probability on outputting the correct \(b^l_0=\left \langle {r_L,s} \right \rangle\). For \(\mathcal{B}_R\), as long as \(s\neq 0\) which happens with \(1-{\sf negl}\) probability, it has information about whether \(r_L\) satisfies \(\left \langle {r_L,s} \right \rangle=b_0\). So whether \(\left \langle {r_L,s} \right \rangle=b_0\) or not will not affect the winning probability of \(\mathcal{B}_R\). Thus we have for \(l=0,1\), \[p_{l,0}^1+p_{l,1}^1=p_{l,0}^0+p_{l,1}^0.\] And we have for \(r=0,1\), \[\begin{align} \left|(p_{0,r}^1+p_{1,r}^1)-(p_{0,r}^0+p_{1,r}^0)\right|={\sf negl}({\sf{\lambda}}) \end{align}\] Thus there exists a constant \(c\) such that \[\left\lVert \begin{pmatrix} p_{0,0}^0 & p_{0,1}^0 \\ p_{1,0}^0 & p_{1,1}^0 \\ \end{pmatrix} - \begin{pmatrix} p_{0,0}^1 & p_{0,1}^1 \\ p_{1,0}^1 & p_{1,1}^1 \\ \end{pmatrix} +c \begin{pmatrix} 1 & -1 \\ -1 & 1 \\ \end{pmatrix} \right\rVert_{\infty}={\sf negl}({\sf{\lambda}}).\] From this we know that the total winning probability of \(\mathcal{B}\) is \[\begin{align} &\frac{1}{2}(p_{0,0}^0+p_{1,1}^0+p_{0,0}^1+p_{1,1}^1)-{\sf negl}({\sf{\lambda}})\\ \geq&\frac{1}{2}(-p_{0,0}^0+p_{1,1}^0+p_{0,0}^1+p_{1,1}^1)-{\sf negl}({\sf{\lambda}})\\ \geq&\frac{1}{2}(-p_{0,0}^1+p_{1,1}^1+p_{0,0}^1+p_{1,1}^1)-{\sf negl}({\sf{\lambda}})\\ \geq&p_{1,1}^1-{\sf negl}({\sf{\lambda}})\\ \geq&\frac{1}{2}+\delta({\sf{\lambda}})-{\sf negl}({\sf{\lambda}}). \end{align}\] This yields a contradiction, proving the lemma. ◻

Intuitively, \(\left|A_{s,t}\right\rangle\) and \(\left|\Psi^{\sf sk}_{0,n/2,n/2}\right\rangle\) have the same distribution. The coset state is exactly the anchor state with \(n_e=0,n_h=n_s=n/2\). We can use this theorem to prove a similar statement in our case.

Lemma 8. Let \(n({\sf{\lambda}})\geq{\sf{\lambda}},n_e({\sf{\lambda}})\) be polynomials. Define the following asymmetric anchor monogamy game AsymmetricAnchorMonogamy for adversary \(\mathcal{A}=(\mathcal{A}_M,\mathcal{A}_L,\mathcal{A}_R)\).

  1. The challenger samples \(\left({\sf sk},\left|\Psi^{{\sf sk}}_{n_e,n/2,n/2}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n/2,n/2}(1^{\sf{\lambda}})\) and sends \(\text{\faShip}\) to the adversary \(\mathcal{A}_M\).

  2. \(\mathcal{A}_M\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, \(\mathcal{A}_M\) generates a bipartite state on \(\mathbf{L}\mathbf{R}\), sends \(\mathbf{L}\) to \(\mathcal{A}_L\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R\).

  3. The challenger samples \(r_L,r_R\overset{\$}{\gets}\mathbb{F}_2^{n_e+n}\). \(\mathcal{A}_L\) is given \((U_{\sf shift},r_L)\) and \(\mathcal{A}_R\) is given \((\left \langle {r_L,v} \right \rangle,U_{\sf shift},r_R)\). \(\mathcal{A}_L\) returns \(b^l_0\) and \(\mathcal{A}_R\) returns \(b^r_1\).

The adversary wins if and only if \(b^l_0=\left \langle {r_L,v} \right \rangle\) and \(b^r_1=\left \langle {r_R,u} \right \rangle\). Let \({\sf AsymmetricAnchorMonogamy}(\mathcal{A},1^{\sf{\lambda}})\) be the random variable that takes value \(1/0/\bot\) if the adversary \(\mathcal{A}\) wins/loses/aborts in the above game, respectively. For any efficient adversary \(\mathcal{A}\) such that \[{\sf{Pr}}\left[{\sf AsymmetricAnchorMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]\geq\frac{1}{{\sf poly}({\sf{\lambda}})},\] we have \[\frac{{\sf{Pr}}\left[{\sf AsymmetricAnchorMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf AsymmetricAnchorMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}\leq\frac{1}{2}+{\sf negl}({\sf{\lambda}}).\]

Proof. The proof is similar to the domain extension technique, the only difference is that we are extending the \({\sf EPR}\) part. For any adversary \(\mathcal{A}\) that wins with probability at least \(\frac{1}{2}+\delta({\sf{\lambda}})\) in this game condition on not aborting and its non-aborting probability is at least \(\delta({\sf{\lambda}})\) for some inverse polynomial \(\delta({\sf{\lambda}})\), we construct adversary \(\mathcal{B}\) that violates 7:

  1. \(\mathcal{B}_M\) receives \(\left|A_{s,t}\right\rangle\) on \(n\)-qubit register \(\mathbf{A}\), and tensors it with a \(2n_e\)-qubit \({\sf EPR}\) state \(\left|{\sf EPR}\right\rangle_{\text{\faAnchor}\mathbf{A}'}^{\otimes n_e}\) which is fully entangled between \(n_e\)-qubit register \(\text{\faAnchor}\) and \(n_e\)-qubit register \(\mathbf{A}'\). Let \(\text{\faShip}=\mathbf{A}\otimes\mathbf{A}'\), it samples a uniform random change of basis matrix \(U_{\sf shift}\) in \(\mathbb{F}_2^{n_e+n}\) and applies \[\mathcal{U}_{\sf shift}\left|z\right\rangle_{\text{\faShip}}:=\left|U_{\sf shift}z\right\rangle_{\text{\faShip}}\] on \(\mathbf{A}\otimes\mathbf{A}'\). Finally, it runs \(\mathcal{A}_M\) on \(\text{\faShip}\) to obtain \(\mathbf{L}\mathbf{R}\). It aborts if \(\mathcal{A}_M\) aborts. It sends \(\mathbf{L},U_{\sf shift}\) to \(\mathcal{B}_L\) and sends \(\mathbf{R},U_{\sf shift}\) to \(\mathcal{B}_R\).

  2. \(\mathcal{B}_L\) receives \(\mathbf{L}\) and \((U,r_L)\). It samples \(r'_L\overset{\$}{\gets}\mathbb{F}_2^{n_e}\), computes \[U'_{\sf shift}=U_{\sf shift}\begin{pmatrix} U & \\ & I_{n_e} \\ \end{pmatrix}\begin{pmatrix} I_{n/2} & & \\ & & I_{n/2}\\ & I_{n_e}\\ \end{pmatrix}.\] It runs \(\mathcal{A}_L\) on \(\mathbf{L}\) with input \[\left(U'_{\sf shift},U_{\sf shift}^{-t}\left(r_L\times r'_L \right) \right).\] It outputs \(b^l_0\), the output of \(\mathcal{A}_L\).

  3. \(\mathcal{B}_R\) receives \(\mathbf{R}\) and \((b_0,U,r_R)\). It samples \(r'_R\overset{\$}{\gets}\mathbb{F}_2^{n_e}\), computes \(U'_{\sf shift}\) in the same way and runs \(\mathcal{A}_R\) on \(\mathbf{R}\) with input \[\left(U'_{\sf shift},U_{\sf shift}\left(r_R\times r'_R \right) \right).\] It outputs \(b^r_1\), the output of \(\mathcal{A}_R\).

First note that the distribution of the state on \(\text{\faAnchor}\text{\faShip}\) after step 1 together with \(U'_{\sf shift}\) has the same distribution as \(\left(U_{\sf shift},\left|\Psi^{{\sf sk}}_{n_e,n/2,n/2}\right\rangle \right)\) sampled by \({\sf GenAnchorState}_{n_e,n/2,n/2}(1^{\sf{\lambda}})\). Let \(v'\) be the last \(n/2\) bits of \(U^{-1}v\). If \(\mathcal{A}_L\) returns correctly, its output is \[\begin{align} &\left \langle {U_{\sf shift}^{-t}(r_L\times r'_L),U_{\sf shift}(s\times 0^{n_e})} \right \rangle\\ =&\left \langle {r_L\times r'_L,s\times 0^{n_e}} \right \rangle\\ =&\left \langle {r_L,s} \right \rangle. \end{align}\] Similarly, if \(\mathcal{A}_R\) returns correctly, its output is \[\begin{align} &\left \langle {U_{\sf shift}(r_R\times r'_R),U_{\sf shift}^{-t}(t\times 0^{n_e})} \right \rangle\\ =&\left \langle {r_R\times r'_R,t\times 0^{n_e}} \right \rangle\\ =&\left \langle {r_R,t} \right \rangle. \end{align}\] ◻

Now we switch from the Goldreich-Levin style query to the oracle style query.

Lemma 9. Let \(n({\sf{\lambda}})\geq{\sf{\lambda}}\), \(n_e({\sf{\lambda}})\), and \(m_1({\sf{\lambda}})\) be polynomials. Define the following asymmetric oracle monogamy game AsymmetricOracleMonogamy for adversary \(\mathcal{A}=(\mathcal{A}_M,\mathcal{A}_L,\mathcal{A}_R)\).

  1. The challenger generates \(\left({\sf sk},\left|\Psi^{{\sf sk}}_{n_e,3n/4,3n/4}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,3n/4,3n/4}(1^{\sf{\lambda}})\) and gives the register \(\text{\faShip}\) to \(\mathcal{A}_M\).

  2. \(\mathcal{A}_M\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, \(\mathcal{A}_M\) generates a bipartite state on \(\mathbf{L}\mathbf{R}\). It sends \(\mathbf{L}\) to \(\mathcal{A}_L\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R\).

  3. The challenger samples \(b_0\overset{\$}{\gets}\mathbb{F}_2\) and \(b_1\overset{\$}{\gets}\mathbb{F}_2^{m_1}\). It gives \(\mathcal{O}_{T+v}^{b_0}\) to \(\mathcal{A}_L\). Then it gives \(b_0\) and \(\mathcal{O}_{S^\perp+u}^{b_1}\) to \(\mathcal{A}_R\).

  4. \(\mathcal{A}_L\) returns \(b_0^l\) and \(\mathcal{A}_R\) returns \(b_1^r\).

The adversary wins if \(b_0^l=b_0\) and \(b_1^r=b_1\). Note that the oracle given to \(\mathcal{A}_L\) has one-bit output, but the oracle given to \(\mathcal{A}_R\) has \(m_1\) bits output. Let \({\sf AsymmetricOracleMonogamy}(\mathcal{A},1^{\sf{\lambda}})\) be the random variable that takes value \(1/0/\bot\) if the adversary \(\mathcal{A}\) wins/loses/aborts in the above game, respectively. For any efficient adversary \(\mathcal{A}\) such that \[{\sf{Pr}}\left[{\sf AsymmetricOracleMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]\geq\frac{1}{{\sf poly}({\sf{\lambda}})},\] we have \[\frac{{\sf{Pr}}\left[{\sf AsymmetricOracleMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf AsymmetricOracleMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}\leq\frac{1}{2}+{\sf negl}({\sf{\lambda}}).\]

Proof. For any adversary \(\mathcal{A}\) that wins with probability at least \(\frac{1}{2}+\delta({\sf{\lambda}})\) in this game condition on not aborting and its non-aborting probability is at least \(\delta({\sf{\lambda}})\) for some inverse polynomial \(\delta({\sf{\lambda}})\), we consider a series of hybrids.
Hybrid 0: This hybrid corresponds to the adversary \(\mathcal{A}\) in the \({\sf AsymmetricOracleMonogamy}\) game. The non-aborting probability for \(\mathcal{A}\) is at least \(\delta({\sf{\lambda}})\) and conditional on that, the winning probability is at least \(\frac{1}{2}+\delta({\sf{\lambda}})\).
Hybrid 1: This hybrid corresponds to the adversary \(\mathcal{A}\) in the following game:

  1. The challenger generates \(\left({\sf sk},\left|\Psi^{{\sf sk}}_{n_e,n/2,n/2}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n/2,n/2}(1^{\sf{\lambda}})\). It then runs \({\sf sk}^*\gets{\sf DomainExtension}_{n/4,n/4}(1^{\sf{\lambda}})\) on \(\text{\faShip}\) and gives the register \(\text{\faShip}^*\) to \(\mathcal{A}_M\).

  2. \(\mathcal{A}_M\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, \(\mathcal{A}_M\) generates a bipartite state on \(\mathbf{L}\mathbf{R}\). It sends \(\mathbf{L}\) to \(\mathcal{A}_L\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R\).

  3. The challenger samples \(b_0\overset{\$}{\gets}\mathbb{F}_2\) and \(b_1\overset{\$}{\gets}\mathbb{F}_2^{m_1}\). It gives \(\mathcal{O}_{T_{\sf ext}+v_{\sf ext}}^{b_0}\) to \(\mathcal{A}_L\). Then it gives \(b_0\) and \(\mathcal{O}_{S_{\sf ext}^\perp+u_{\sf ext}}^{b_1}\) to \(\mathcal{A}_R\).

  4. \(\mathcal{A}_L\) returns \(b_0^l\) and \(\mathcal{A}_R\) returns \(b_1^r\). The adversary wins if \(b_0^l=b_0\) and \(b_1^r=b_1\).

Claim 16. The non-aborting probability for \(\mathcal{A}\) in Hybrid 1 is at least \(\delta({\sf{\lambda}})\) and conditional on that, the winning probability is at least \(\frac{1}{2}+\delta({\sf{\lambda}})\).

Proof. By 8 and 9, the input distribution of \(\mathcal{A}\) doesn’t change. ◻

Hybrid 2: This hybrid corresponds to the adversary \(\mathcal{A}\) in the following game:

  1. The challenger generates \(\left({\sf sk},\left|\Psi^{{\sf sk}}_{n_e,n/2,n/2}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n/2,n/2}(1^{\sf{\lambda}})\). It then runs \({\sf sk}^*\gets{\sf DomainExtension}_{n/4,n/4}(1^{\sf{\lambda}})\) on \(\text{\faShip}\) and gives the register \(\text{\faShip}^*\) to \(\mathcal{A}_M\).

  2. \(\mathcal{A}_M\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, \(\mathcal{A}_M\) generates a bipartite state on \(\mathbf{L}\mathbf{R}\). It sends \(\mathbf{L}\) to \(\mathcal{A}_L\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R\).

  3. The challenger samples \(b_0\overset{\$}{\gets}\mathbb{F}_2\) and \(b_1\overset{\$}{\gets}\mathbb{F}_2^{m_1}\). It gives \(\mathcal{O}_{T^*+v^*}^{b_0}\) to \(\mathcal{A}_L\). Then it gives \(b_0\) and \(\mathcal{O}_{{S^*}^\perp+u^*}^{b_1}\) to \(\mathcal{A}_R\).

  4. \(\mathcal{A}_L\) returns \(b_0^l\) and \(\mathcal{A}_R\) returns \(b_1^r\). The adversary wins if \(b_0^l=b_0\) and \(b_1^r=b_1\).

Claim 17. The non-aborting probability for \(\mathcal{A}\) in Hybrid 2 is at least \(\delta({\sf{\lambda}})\) and conditional on that, the winning probability is at least \(\frac{1}{2}+\delta({\sf{\lambda}})-{\sf negl}({\sf{\lambda}})\).

Proof. \(T^*\) is a uniformly random subspace of dimension \(n_e+5n/4\) satisfying \(T_{\sf ext}\leq T^*\leq\mathbb{F}_2^{n_e+3n/2}\) and it is also independent of \(v_{\sf ext}\). \(S^*\) is a uniformly random subspace of \(S_{\sf ext}\) of dimension \(n/4\) and it is also independent of \(u_{\sf ext}\). The claim follows from 4. ◻

Hybrid 3: This hybrid corresponds to the adversary \(\mathcal{A}\) in the following game:

  1. The challenger generates \(\left({\sf sk},\left|\Psi^{{\sf sk}}_{n_e,n/2,n/2}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n/2,n/2}(1^{\sf{\lambda}})\). It then runs \({\sf sk}^*\gets{\sf DomainExtension}_{n/4,n/4}(1^{\sf{\lambda}})\) on \(\text{\faShip}\) and gives the register \(\text{\faShip}^*\) to \(\mathcal{A}_M\).

  2. \(\mathcal{A}_M\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, \(\mathcal{A}_M\) generates a bipartite state on \(\mathbf{L}\mathbf{R}\). It sends \(\mathbf{L}\) to \(\mathcal{A}_L\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R\).

  3. The challenger samples \(r_L\overset{\$}{\gets}\mathbb{F}_2^{n_e+3n/2}\) and \(b_1\overset{\$}{\gets}\mathbb{F}_2^{m_1}\). It also samples \(w_v\overset{\$}{\gets}T_{\sf ext}+v_{\sf ext}\) and gives the following oracle to \(\mathcal{A}_L\):

    • \(\mathcal{O}_{T^*+w_v}^{{\sf ncol},r_L}:\mathbb{F}_2^{n_e+3n/2}\rightarrow\mathbb{F}_2\cup\left\{\bot\right\}\) on input \(z\) checks if it is in \(T^*+w_v\). It returns \(\bot\) if it is not. Otherwise, it returns \(\left \langle {r_L,{\sf Can}_{T_{\sf ext}}(w_v)} \right \rangle\).

    Then it gives \(\left \langle {r_L,{\sf Can}_{T_{\sf ext}}(w_v)} \right \rangle\) and \(\mathcal{O}_{{S^*}^\perp+u^*}^{b_1}\) to \(\mathcal{A}_R\).

  4. \(\mathcal{A}_L\) returns \(b_0^l\) and \(\mathcal{A}_R\) returns \(b_1^r\). The adversary wins if \(b_0^l=\left \langle {r_L,{\sf Can}_{T_{\sf ext}}(w_v)} \right \rangle\) and \(b_1^r=b_1\).

Claim 18. The non-aborting probability for \(\mathcal{A}\) in Hybrid 3 is at least \(\delta({\sf{\lambda}})\) and conditional on that, the winning probability is at least \(\frac{1}{2}+\delta({\sf{\lambda}})-{\sf negl}({\sf{\lambda}})\).

Proof. In the adversary’s view, \(\left \langle {r_L,v_{\sf ext}} \right \rangle\) is a uniform random bit and is equivalent to \(b_0\). Also \(T_{\sf ext}+v_{\sf ext}\) and \(T_{\sf ext}+w_v\) are the same coset. ◻

Hybrid 4: This hybrid corresponds to the adversary \(\mathcal{A}\) in the following game:

  1. The challenger generates \(\left({\sf sk},\left|\Psi^{{\sf sk}}_{n_e,n/2,n/2}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n/2,n/2}(1^{\sf{\lambda}})\). It then runs \({\sf sk}^*\gets{\sf DomainExtension}_{n/4,n/4}(1^{\sf{\lambda}})\) on \(\text{\faShip}\) and gives the register \(\text{\faShip}^*\) to \(\mathcal{A}_M\).

  2. \(\mathcal{A}_M\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, \(\mathcal{A}_M\) generates a bipartite state on \(\mathbf{L}\mathbf{R}\). It sends \(\mathbf{L}\) to \(\mathcal{A}_L\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R\).

  3. The challenger samples \(r_L\overset{\$}{\gets}\mathbb{F}_2^{n_e+3n/2}\) and \(b_1\overset{\$}{\gets}\mathbb{F}_2^{m_1}\). It also samples \(w_v\overset{\$}{\gets}T_{\sf ext}+v_{\sf ext}\) and gives the following oracle to \(\mathcal{A}_L\):

    • \(\mathcal{O}_{T^*+w_v}^{{\sf col},r_L}\)\(:\mathbb{F}_2^{n_e+3n/2}\rightarrow\mathbb{F}_2\cup\left\{\bot\right\}\) on input \(z\) checks if it is in \(T^*+w_v\). It returns \(\bot\) if it is not. Otherwise, it returns \(\left \langle {r_L,{\sf Can}_{T_{\sf ext}}(z)} \right \rangle\).

    Then it gives \(\left \langle {r_L,v_{\sf ext}} \right \rangle\) and \(\mathcal{O}_{{S^*}^\perp+u^*}^{b_1}\) to \(\mathcal{A}_R\).

  4. \(\mathcal{A}_L\) returns \(b_0^l\) and \(\mathcal{A}_R\) returns \(b_1^r\). The adversary wins if \(b_0^l=\left \langle {r_L,v_{\sf ext}} \right \rangle\) and \(b_1^r=b_1\).

Claim 19. The non-aborting probability for \(\mathcal{A}\) in Hybrid 4 is at least \(\delta({\sf{\lambda}})\) and conditional on that, the winning probability is at least \(\frac{1}{2}+\delta({\sf{\lambda}})-{\sf negl}({\sf{\lambda}})\).

Proof. Note that \(w_v\) is a uniform random vector independent of \(T_{\sf ext}\) and \(T^*\), with \({\sf Can}_{T_{\sf ext}}(w_v)=v_{\sf ext}\). For any coset of \(T_{\sf ext}\) contained in \(T^*+v^*\), \(\left \langle {r_L,{\sf Can}_{T_{\sf ext}}(z)} \right \rangle\) alone is a bit independent of \(T^*\) given \(T_{\sf ext}\). To use 5 we only need to show that we can generate the anchor state and simulate the whole game using \(T_{\sf ext}\) and \(w_v\). To be more specific, we will rewrite Hybrid 3 and Hybrid 4 as two games with input \((T_{\sf ext},T^*,w_v)\) where one of them is the collapsing version and the other one is the non-collapsing version in order to use 5. Now we rewrite Hybrid 3 and Hybrid 4 for fixed \(T_{\sf ext}\), \(T^*\) and \(w_v\).

  1. Sample random subspaces \(S^*\leq S_{\sf ext}\leq T_{\sf ext}\) where \(S^*\) is a \(n/4\) dimensional subspace and \(S_{\sf ext}\) is a \(3n/4\) dimensional subspace. Sample a \((n_e+3n/2)\times(n_e+3n/2)\) uniform random change of basis matrix \(U_{\sf shift}\) condition on the span of its first \(n/4,3n/4,n_e+3n/4,n_e+5n/4\) columns are \(S^*,S_{\sf ext},T_{\sf ext},T^*\), respectively. Sample \(u_{\sf ext}\overset{\$}{\gets}{\sf CS}(S_{\sf ext}^\perp)\) and compute \(u^*\) accordingly.

  2. Decompose \(w_v=w_s+w_x+v_{\sf ext}\) where \(w_s\in S_{\sf ext}\) and \(w_x=U_{\sf shift}\left(0^{3n/4}\times x'\times 0^{3n/4} \right)\) for a unique \(x'\). Generate the following state: \[\begin{align} \propto&\sum_{x}\left|x\right\rangle_{\text{\faAnchor}}\sum_{s\in S_{\sf ext}}(-1)^{\left \langle {u_{\sf ext},s} \right \rangle}\left|s+U_{\sf shift}\left(0^{3n/4}\times x\times 0^{3n/4} \right)+w_v\right\rangle_{\text{\faShip}^*}\\ \propto&\sum_{x}\left|x\right\rangle_{\text{\faAnchor}}\sum_{s\in S_{\sf ext}}(-1)^{\left \langle {u_{\sf ext},s} \right \rangle}\left|(s+w_s)+U_{\sf shift}\left(0^{3n/4}\times (x+x')\times 0^{3n/4} \right)+v_{\sf ext}\right\rangle_{\text{\faShip}^*}\\ \propto&\sum_{x}(-1)^{\left \langle {u_{\sf ext},w_s} \right \rangle}\left|x-x'\right\rangle_{\text{\faAnchor}}\sum_{s\in S_{\sf ext}}(-1)^{\left \langle {u_{\sf ext},s} \right \rangle}\left|s+U_{\sf shift}\left(0^{3n/4}\times x\times 0^{3n/4} \right)+v_{\sf ext}\right\rangle_{\text{\faShip}^*}. \end{align}\] Note that the adversary \(\mathcal{A}\) can only access \(\text{\faShip}\), thus it cannot detect the phase shift \((-1)^{\left \langle {u_{\sf ext},w_s} \right \rangle}\) and the control shift \(\left|x-x'\right\rangle_{\text{\faAnchor}}\). The result of the game is the same if we give the following state that is exactly the anchor state, instead of the above state. \[\propto\sum_{x}\left|x\right\rangle_{\text{\faAnchor}}\sum_{s\in S_{\sf ext}}(-1)^{\left \langle {u_{\sf ext},s} \right \rangle}\left|s+U_{\sf shift}\left(0^{3n/4}\times x\times 0^{3n/4} \right)+v_{\sf ext}\right\rangle_{\text{\faShip}^*}.\]

  3. Run \(\mathcal{A}_M\), \(\mathcal{A}_L\), \(\mathcal{A}_R\), provide the corresponding oracles and check the outcome.

From the above description, we can use 5 to show the indistinguishability. ◻

Hybrid 5: This hybrid corresponds to the adversary \(\mathcal{A}\) in the following game:

  1. The challenger generates \(\left({\sf sk},\left|\Psi^{{\sf sk}}_{n_e,n/2,n/2}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n/2,n/2}(1^{\sf{\lambda}})\). It then runs \({\sf sk}^*\gets{\sf DomainExtension}_{n/4,n/4}(1^{\sf{\lambda}})\) on \(\text{\faShip}\) and gives the register \(\text{\faShip}^*\) to \(\mathcal{A}_M\).

  2. \(\mathcal{A}_M\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, \(\mathcal{A}_M\) generates a bipartite state on \(\mathbf{L}\mathbf{R}\). It sends \(\mathbf{L}\) to \(\mathcal{A}_L\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R\).

  3. The challenger samples \(r_L\overset{\$}{\gets}\mathbb{F}_2^{n_e+3n/2}\), \(r_R\overset{\$}{\gets}\mathbb{F}_2^{n_e+3n/2}\) and \(b'_1\overset{\$}{\gets}\mathbb{F}_2^{m_1-1}\). It gives \(\mathcal{O}_{T^*+v^*}^{{\sf col},r_L}\) to \(\mathcal{A}_L\). Then it samples \(w_u\overset{\$}{\gets}S_{\sf ext}^\perp+u_{\sf ext}\), gives \(\left \langle {r_L,v_{\sf ext}} \right \rangle\) and this oracle to \(\mathcal{A}_R\):

    • \(\mathcal{O}_{{S^*}^\perp+w_u}^{{\sf ncol},r_R,b'_1}:\mathbb{F}_2^{n_e+3n/2}\rightarrow\mathbb{F}_2\cup\left\{\bot\right\}\) on input \(z\) checks if it is in \({S^*}^\perp+w_u\). It returns \(\bot\) if it is not. Otherwise, it returns \(\left \langle {r_R,{\sf Can}_{S_{\sf ext}^\perp}(w_u)} \right \rangle\times b'_1\).
  4. \(\mathcal{A}_L\) returns \(b_0^l\) and \(\mathcal{A}_R\) returns \(b_1^r\). The adversary wins if \(b_0^l=\left \langle {r_L,v_{\sf ext}} \right \rangle\) and \(b_1^r=\left \langle {r_R,{\sf Can}_{S_{\sf ext}^\perp}(w_u)} \right \rangle\times b'_1\).

Claim 20. The non-aborting probability for \(\mathcal{A}\) in Hybrid 5 is at least \(\delta({\sf{\lambda}})\) and conditional on that, the winning probability is at least \(\frac{1}{2}+\delta({\sf{\lambda}})-{\sf negl}({\sf{\lambda}})\).

Proof. In the adversary’s view, \(\left \langle {r_R,u_{\sf ext}} \right \rangle\times b'_1\) is a uniform random string and is equivalent to \(b_1\). Also \(T^*+v^*\) and \(T^*+w_v\) are the same coset, and similarly \({S^*}^\perp+u^*\) and \({S^*}^\perp+w_u\) are the same coset.. ◻

Hybrid 6: This hybrid corresponds to the adversary \(\mathcal{A}\) in the following game:

  1. The challenger generates \(\left({\sf sk},\left|\Psi^{{\sf sk}}_{n_e,n/2,n/2}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n/2,n/2}(1^{\sf{\lambda}})\). It then runs \({\sf sk}^*\gets{\sf DomainExtension}_{n/4,n/4}(1^{\sf{\lambda}})\) on \(\text{\faShip}\) and gives the register \(\text{\faShip}^*\) to \(\mathcal{A}_M\).

  2. \(\mathcal{A}_M\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, \(\mathcal{A}_M\) generates a bipartite state on \(\mathbf{L}\mathbf{R}\). It sends \(\mathbf{L}\) to \(\mathcal{A}_L\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R\).

  3. The challenger samples \(r_L\overset{\$}{\gets}\mathbb{F}_2^{n_e+3n/2}\), \(r_R\overset{\$}{\gets}\mathbb{F}_2^{n_e+3n/2}\) and \(b'_1\overset{\$}{\gets}\mathbb{F}_2^{m_1-1}\). It gives \(\mathcal{O}_{T^*+v^*}^{{\sf col},r_L}\) to \(\mathcal{A}_L\). Then it samples \(w_u\overset{\$}{\gets}S_{\sf ext}^\perp+u_{\sf ext}\), gives \(\left \langle {r_L,v_{\sf ext}} \right \rangle\) and this oracle to \(\mathcal{A}_R\):

    • \(\mathcal{O}_{{S^*}^\perp+w_u}^{{\sf col},r_R,b'_1}\)\(:\mathbb{F}_2^{n_e+3n/2}\rightarrow\mathbb{F}_2\cup\left\{\bot\right\}\) on input \(z\) checks if it is in \({S^*}^\perp+w_u\). It returns \(\bot\) if it is not. Otherwise, it returns \(\left \langle {r_R,{\sf Can}_{S_{\sf ext}^\perp}(z)} \right \rangle\times b'_1\).
  4. \(\mathcal{A}_L\) returns \(b_0^l\) and \(\mathcal{A}_R\) returns \(b_1^r\). The adversary wins if \(b_0^l=\left \langle {r_L,v_{\sf ext}} \right \rangle\) and \(b_1^r=\left \langle {r_R,u_{\sf ext}} \right \rangle\times b'_1\).

Claim 21. The non-aborting probability for \(\mathcal{A}\) in Hybrid 6 is at least \(\delta({\sf{\lambda}})\) and conditional on that, the winning probability is at least \(\frac{1}{2}+\delta({\sf{\lambda}})-{\sf negl}({\sf{\lambda}})\).

Proof. Similar to the proof of 19 except this time in the Hadamard basis. ◻

Hybrid 7: This hybrid corresponds to the adversary \(\mathcal{A}\) in the following game:

  1. The challenger generates \(\left({\sf sk},\left|\Psi^{{\sf sk}}_{n_e,n/2,n/2}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n/2,n/2}(1^{\sf{\lambda}})\). It then runs \({\sf sk}^*\gets{\sf DomainExtension}_{n/4,n/4}(1^{\sf{\lambda}})\) on \(\text{\faShip}\) and gives the register \(\text{\faShip}^*\) to \(\mathcal{A}_M\).

  2. \(\mathcal{A}_M\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, \(\mathcal{A}_M\) generates a bipartite state on \(\mathbf{L}\mathbf{R}\). It sends \(\mathbf{L}\) to \(\mathcal{A}_L\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R\).

  3. The challenger samples \(r_L\overset{\$}{\gets}\mathbb{F}_2^{n_e+3n/2}\), \(r_R\overset{\$}{\gets}\mathbb{F}_2^{n_e+3n/2}\) and \(b'_1\overset{\$}{\gets}\mathbb{F}_2^{m_1-1}\). It gives \(\mathcal{O}_{T^*+v^*}^{{\sf col},r_L}\) to \(\mathcal{A}_L\). Then it gives \(\left \langle {r_L,v_{\sf ext}} \right \rangle\) and \(\mathcal{O}_{{S^*}^\perp+u^*}^{{\sf col},r_R,b'_1}\) to \(\mathcal{A}_R\).

  4. \(\mathcal{A}_L\) returns \(b_0^l\) and \(\mathcal{A}_R\) returns \(b_1^r\). The adversary wins if \(b_0^l=\left \langle {r_L,v_{\sf ext}} \right \rangle\) and \(b_1^r=\left \langle {r_R,u_{\sf ext}} \right \rangle\times b'_1\).

Claim 22. The non-aborting probability for \(\mathcal{A}\) in Hybrid 7 is at least \(\delta({\sf{\lambda}})\) and conditional on that, the winning probability is at least \(\frac{1}{2}+\delta({\sf{\lambda}})-{\sf negl}({\sf{\lambda}})\).

Proof. \({S^*}^\perp+u^*\) and \({S^*}^\perp+w_u\) are the same coset. ◻

Using Hybrid 7 as a tool, we construct an adversary \(\mathcal{B}\) that violates 8. \(\mathcal{B}\) simulates part of the challenger in Hybrid 7.

  1. \(\mathcal{B}_M\) receives the \(\text{\faShip}\) register. It then runs \({\sf sk}^*\gets{\sf DomainExtension}_{n/4,n/4}(1^{\sf{\lambda}})\) on \(\text{\faShip}\) and gives the register \(\text{\faShip}^*\) to \(\mathcal{A}_M\) to obtain \(\mathbf{L}\mathbf{R}\). \(\mathcal{B}_M\) aborts if \(\mathcal{A}_M\) aborts. It samples \(r_L^s\overset{\$}{\gets}\mathbb{F}_2^{n/4}\). It sends \({\sf sk}^*,\mathbf{L},r_L^s\) to \(\mathcal{B}_L\) and sends \({\sf sk}^*,\mathbf{R},r_L^s\) to \(\mathcal{B}_R\).

  2. \(\mathcal{B}_L\) receives \({\sf sk}^*,\mathbf{L},r_L^s\) from \(\mathcal{B}_M\) and \((U_{\sf shift},r_L)\) from the challenger. It samples \(r_L^h\overset{\$}{\gets}\mathbb{F}_2^{n/4}\) and computes \(r'_L={U_{\sf shift}^*}^{-t}\left(r_L^h\times r_L\times r_L^s \right)\). It runs \(\mathcal{A}_L\) on \(\mathbf{L}\) with oracle access to \(\mathcal{O}_{T^*+v^*}^{{\sf col},r'_L}\). Let the output of \(\mathcal{A}_L\) be \(b^l_0\). It outputs \(b^l_0\oplus\left \langle {{U_{\sf shift}^*}^{-t}\left(0^{n_e+5n/4}\times r_L^s \right),v^*} \right \rangle\).

  3. \(\mathcal{B}_R\) receives \({\sf sk}^*,\mathbf{R},r_L^s\) from \(\mathcal{B}_M\) and \((U_{\sf shift},r_R,b_0)\) from the challenger. It computes \(b'_0=b_0\oplus\left \langle {{U_{\sf shift}^*}^{-t}\left(0^{n_e+5n/4}\times r_L^s \right),v^*} \right \rangle\). It samples \(b'_1\overset{\$}{\gets}\mathbb{F}_2^{m_1-1}\), \(r_R^h,r_R^s\overset{\$}{\gets}\mathbb{F}_2^{n/4}\) and computes \(r'_R=U_{\sf shift}^*\left(r_R^h\times r_R\times r_R^s \right)\). It runs \(\mathcal{A}_R\) on \(\mathbf{R}\) with \(b'_0\) and oracle access to \(\mathcal{O}_{{S^*}^\perp+u^*}^{{\sf col},r'_R,b'_1}\). Let the first bit of the output of \(\mathcal{A}_R\) be \(b^r_1\). It outputs \(b^r_1\oplus\left \langle {U_{\sf shift}^*\left(r_R^h\times 0^{n_e+5n/4} \right),u^*} \right \rangle\).

Claim 23. We have \[{\sf{Pr}}\left[{\sf AsymmetricAnchorMonogamy}(\mathcal{B},1^{\sf{\lambda}})\neq\bot\right]\geq\delta({\sf{\lambda}})\] and \[\frac{{\sf{Pr}}\left[{\sf AsymmetricAnchorMonogamy}(\mathcal{B},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf AsymmetricAnchorMonogamy}(\mathcal{B},1^{\sf{\lambda}})\neq\bot\right]}\geq\frac{1}{2}+\delta({\sf{\lambda}})-{\sf negl}({\sf{\lambda}}).\]

Proof. Clearly the aborting probability of \(\mathcal{B}\) is the same as the aborting probability of \(\mathcal{A}\) in Hybrid 7. For the winning probability of \(\mathcal{B}\), first we show that if \(\mathcal{A}\) outputs correctly (as in Hybrid 7) then the output of \(\mathcal{B}\) is correct. Suppose the output of \(\mathcal{A}_L\) is correct: \(b_0^l=\left \langle {r'_L,v_{\sf ext}} \right \rangle\), then the output of \(\mathcal{B}_L\) is correct: \[\begin{align} &b_0^l\oplus\left \langle {{U_{\sf shift}^*}^{-t}\left(0^{n_e+5n/4}\times r_L^s \right),v^*} \right \rangle\\ =&\left \langle {r'_L,v_{\sf ext}} \right \rangle\oplus\left \langle {{U_{\sf shift}^*}^{-t}\left(0^{n_e+5n/4}\times r_L^s \right),v^*} \right \rangle\\ =&\left \langle {{U_{\sf shift}^*}^{-t}\left(r_L^h\times r_L\times r_L^s \right),U_{\sf shift}^*\left(0^{n/4}\times v\times 0^{n/4} \right)+v^*} \right \rangle\oplus\left \langle {{U_{\sf shift}^*}^{-t}\left(0^{n_e+5n/4}\times r_L^s \right),v^*} \right \rangle\\ =&\left \langle {{U_{\sf shift}^*}^{-t}\left(r_L^h\times r_L\times r_L^s \right),U_{\sf shift}^*\left(0^{n/4}\times v\times 0^{n/4} \right)} \right \rangle\oplus\left \langle {{U_{\sf shift}^*}^{-t}\left(r_L^h\times r_L\times 0^{n/4} \right),v^*} \right \rangle\\ =&\left \langle {r_L,v} \right \rangle\oplus\left \langle {{U_{\sf shift}^*}^{-t}\left(r_L^h\times r_L\times 0^{n/4} \right),U_{\sf shift}^*\left(0^{n_e+5n/4}\times {v'}^* \right)} \right \rangle\\ =&\left \langle {r_L,v} \right \rangle. \end{align}\] Suppose the output of \(\mathcal{A}_R\) is correct for its first bit: \(b^r_1=\left \langle {r'_R,u_{\sf ext}} \right \rangle\), then the output of \(\mathcal{B}_R\) is correct: \[\begin{align} &b^r_1\oplus\left \langle {U_{\sf shift}^*\left(r_R^h\times 0^{n_e+5n/4} \right),u^*} \right \rangle\\ =&\left \langle {r'_R,u_{\sf ext}} \right \rangle\oplus\left \langle {U_{\sf shift}^*\left(r_R^h\times 0^{n_e+5n/4} \right),u^*} \right \rangle\\ =&\left \langle {U_{\sf shift}^*\left(r_R^h\times r_R\times r_R^s \right),{U_{\sf shift}^*}^{-t}\left(0^{n/4}\times u\times 0^{n/4} \right)+u^*} \right \rangle\oplus\left \langle {U_{\sf shift}^*\left(r_R^h\times 0^{n_e+5n/4} \right),u^*} \right \rangle\\ =&\left \langle {U_{\sf shift}^*\left(r_R^h\times r_R\times r_R^s \right),{U_{\sf shift}^*}^{-t}\left(0^{n/4}\times u\times 0^{n/4} \right)} \right \rangle\oplus\left \langle {U_{\sf shift}^*\left(0^{n/4}\times r_R\times r_R^s \right),u^*} \right \rangle\\ =&\left \langle {r_R,u} \right \rangle\oplus\left \langle {U_{\sf shift}^*\left(0^{n/4}\times r_R\times r_R^s \right),{U_{\sf shift}^*}^{-t}\left({u'}^*\times 0^{n_e+5n/4} \right)} \right \rangle\\ =&\left \langle {r_R,u} \right \rangle. \end{align}\] Now we show that the input distribution of \(\mathcal{A}\) in \(\mathcal{B}\) is the same as the input distribution it receives from the challenger in Hybrid 7. By definition, \(r'_L\) and \(r'_R\) are two uniform random vectors in \(\mathbb{F}_2^{n_e+3n/2}\) and \(b'_1\) is a uniform random vector in \(\mathbb{F}_2^{m_1-1}\). And \(b'_0\), given to \(\mathcal{A}_R\), is the correct answer for \(\mathcal{A}_L\): \[\begin{align} b'_0&=b_0\oplus\left \langle {{U_{\sf shift}^*}^{-t}\left(0^{n_e+5n/4}\times r_L^s \right),v^*} \right \rangle\\ &=\left \langle {r_L,v} \right \rangle\oplus\left \langle {{U_{\sf shift}^*}^{-t}\left(0^{n_e+5n/4}\times r_L^s \right),v^*} \right \rangle\\ &=\left \langle {r'_L,v_{\sf ext}} \right \rangle. \end{align}\] The last equation comes from previous calculations on the correctness of \(\mathcal{B}_L\)’s output. ◻

 ◻

6.2 Multi-Stage Monogamy-of-Entanglement Games↩︎

Lemma 10. Take any adversary \(\mathcal{A}\) in the multi-stage monogamy-of-entanglement game described in 4 such that \[{\sf{Pr}}\left[{\sf MultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]=\varepsilon'({\sf{\lambda}})\] and \[\frac{{\sf{Pr}}\left[{\sf MultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf MultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}=1-\varepsilon({\sf{\lambda}})\] for inverse polynomials \(\varepsilon({\sf{\lambda}}),\varepsilon'({\sf{\lambda}})\). Consider the state \(\text{\faKey}\text{\faAnchor}\mathbf{L}\mathbf{M}\mathbf{R}\mathbf{B}\) at BeforeSplit conditioned on \(\mathcal{A}_M^0\) not aborting, which we can write as (we also purify \({\sf sk}\) in register \(\text{\faKey}\) here):

\[\sum_{{\sf sk}}\sum_{x}\alpha_{{\sf sk},x}\left|{\sf sk}\right\rangle_{\text{\faKey}}\left|x\right\rangle_{\text{\faAnchor}}\left(\frac{1}{\sqrt{2}}\left|\psi^{\sf sk}_{x,0}\right\rangle_{\mathbf{L}\mathbf{M}\mathbf{R}}\left|0\right\rangle_\mathbf{B}+\frac{1}{\sqrt{2}}\left|\psi^{\sf sk}_{x,1}\right\rangle_{\mathbf{L}\mathbf{M}\mathbf{R}}\left|1\right\rangle_\mathbf{B} \right).\] where the state \(\left|\psi^{\sf sk}_{x,0}\right\rangle\) and \(\left|\psi^{\sf sk}_{x,1}\right\rangle\) are normalized states. We have, \[\mathop{\mathbb{E}}_{{\sf sk},x}\left[\left|\left\langle \psi^{\sf sk}_{x,0}\vert \psi^{\sf sk}_{x,1}\right\rangle\right|^2\right]\leq4\varepsilon({\sf{\lambda}})+{\sf negl}({\sf{\lambda}})\] where the expectation is over \(x\), the standard basis value on \(\text{\faAnchor}\) and over \({\sf sk}\), generated by the process of \(\left({\sf sk},\left|\Psi^{\sf sk}_{n_e,n,n}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n,n}(1^{\sf{\lambda}})\). The expectation is weighted where the weight on \({\sf sk},x\) is \(\left|\alpha_{{\sf sk},x}\right|^2\). When we say expectation over this quantity throughout this section, we mean the above weighted definition.

Remark 24. Here we assume WLOG that \(\mathcal{A}\)’s state is always purified. The purification can be taken to live within registers \(\mathbf{L}\) or \(\mathbf{R}\), and ignored by later computations. The reason we do not allow it to go into \(\mathbf{M}\) is because we later extract from the middle prover, as will be made clear in later theorems. In later of this section, expectations are weighted in the same manner where these uneven weights are due to the fact that we are conditioning on \(\mathcal{A}_M^0\) not aborting that may depend on \({\sf sk},x\).

Proof. Consider this modified version of the multi-stage monogamy-of-entanglement game, where the challenge oracles given to \(\mathcal{A}_M^1\) and \((\mathcal{A}_L^0,\mathcal{A}_R^0)\) return independently sampled random bits (\(b_0'\) and \(b_0\), respectively).

  1. The challenger generates \(\left({\sf sk},\left|\Psi^{{\sf sk}}_{n_e,n,n}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n,n}(1^{\sf{\lambda}})\) and gives the register \(\text{\faShip}\) to \(\mathcal{A}_M\). All parties of the adversary are given oracle access to \(\mathcal{O}_{T+v}\) and \(\mathcal{O}_{S^\perp+u}\).

  2. \(\mathcal{A}_M^0\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, it generates a tripartite state on \(\mathbf{L}\mathbf{M}\mathbf{R}\). It sends \(\mathbf{L}\) to \(\mathcal{A}_L^0\), sends \(\mathbf{M}\) to \(\mathcal{A}_M^1\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R^0\).

  3. \(\mathcal{A}_M^1\) is given the access to \(\mathcal{O}_{T+v}^{b'_0}\) for random \(b'_0\overset{\$}{\gets}\mathbb{F}_2\). We can consider purified version where we create a register that stores \(b'_0\), initialized to \(\left|+\right\rangle_{\mathbf{B}'}\), a uniform superposition over all \(b'_0\). And \(\mathcal{A}_M^1\) is able to perform the following operation to access \(\mathbf{B}'\): \[\sum_{b'_0\in\mathbb{F}_2}\left|b'_0\right\rangle\left\langle b'_0\right|_{\mathbf{B}'}\otimes\mathcal{O}_{T+v}^{b'_0}.\] \(\mathcal{A}_M^1\) with access to this oracle and \(\mathbf{M}\) generates a tripartite state on \(\mathbf{M}_L\mathbf{M}'\mathbf{M}_R\). It sends \(\mathbf{M}_L\) to \(\mathcal{A}_L^0\), sends \(\mathbf{M}'\) to \(\mathcal{A}_M^2\) and sends \(\mathbf{M}_R\) to \(\mathcal{A}_R^0\).

  4. \(\mathcal{A}_L^0\) and \(\mathcal{A}_R^0\) are given the access to \(\mathcal{O}_{T+v}^{b_0}\) for fresh generated \(b_0\overset{\$}{\gets}\mathbb{F}_2\). Similarly, we do this in the purified way and introduce a \(\left|+_\mathbf{B}\right\rangle_\mathbf{B}\) as the control register. \(\mathcal{A}_L^0\) on \(\mathbf{L}\mathbf{M}_L\) produces answer \(b_0^l\) and a state on register \(\mathbf{L}'\) that is sent to \(\mathcal{A}_L^1\). \(\mathcal{A}_R^0\) on \(\mathbf{R}\mathbf{M}_R\) produces answer \(b_0^r\) and a state on register \(\mathbf{R}'\) that is sent to \(\mathcal{A}_R^1\).

  5. \(\mathcal{A}_M^2\) is given the access to \(\mathcal{O}_{S^\perp+u}^{b_1}\) for random \(b_1\overset{\$}{\gets}\mathbb{F}_2^{m_1}\). It generates a bipartite state on \(\mathbf{M}'_L\mathbf{M}'_R\). \(\mathbf{M}'_L\) is given to \(\mathcal{A}_L^1\) and \(\mathbf{M}'_R\) is given to \(\mathcal{A}_R^1\).

  6. \(\mathcal{A}_L^1\) and \(\mathcal{A}_R^1\) are given the access to \(\mathcal{O}_{T+v}^{b_0}\) and \(\mathcal{O}_{S^\perp+u}^{b_1}\). \(\mathcal{A}_L^1\) on \(\mathbf{L}'\mathbf{M}'_L\) generates the answer \(b_1^l\). \(\mathcal{A}_R^1\) on \(\mathbf{R}'\mathbf{M}'_R\) generates the answer \(b_1^r\). The adversary wins iff \(b_0^l=b_0^r=b_0\) and \(b_1^l=b_1^r=b_1\).

Let \({\sf ModifiedMultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})\) be the random variable that takes value \(1/0/\bot\) if the adversary \(\mathcal{A}\) wins/loses/aborts in the above game, respectively. This game is displayed in 7.

Figure 7: The modified multi-stage decision monogamy-of-entanglement game ModifiedMultiStageDecisionMonogamy.

Claim 25. For all \({\sf{\lambda}}\in\mathbb{N}\) and any adversary \(\mathcal{A}\), the aborting probabilities are the same in both games, \[\begin{align} &{\sf{Pr}}\left[{\sf ModifiedMultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})=\bot\right]\\ =&{\sf{Pr}}\left[{\sf MultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})=\bot\right] \end{align}\] and the winning probabilities conditioned on not aborting are related \[\begin{align} &\frac{{\sf{Pr}}\left[{\sf ModifiedMultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf ModifiedMultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}\\ \geq&\frac{{\sf{Pr}}\left[{\sf MultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf MultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}-\frac{1}{2}+\frac{1}{4}\mathop{\mathbb{E}}_{{\sf sk},x}\left[\left|\left\langle \psi^{\sf sk}_{x,0}\vert \psi^{\sf sk}_{x,1}\right\rangle\right|^2\right]. \end{align}\]

Proof. Given an adversary \(\mathcal{A}\) we are able to construct two corresponding projector \(\Pi_0^{\mathcal{A}},\Pi_1^{\mathcal{A}}\) which simulate the game from BeforeSplit and project on the adversary winning in the case that \(b_0=0\), \(b_0=1\), respectively. It is crucial to notice that this projector does not act on \(\mathbf{B}'\), meaning that \(\text{\faKey}\), \(\text{\faAnchor}\), \(\mathbf{B}'\) and \(\mathbf{B}\) all serve as control registers when calculating the the maximum distinguishing probability between ModifiedMultiStageDecisionMonogamy and MultiStageDecisionMonogamy. In the game ModifiedMultiStageDecisionMonogamy, the state at BeforeSplit is \[\begin{align} \propto\sum_{{\sf sk}}\sum_x\sum_{b',b\in\mathbb{F}_2}\alpha_{{\sf sk},x}\left|{\sf sk}\right\rangle_{\text{\faKey}}\left|x\right\rangle_{\text{\faAnchor}}\left|b'_0\right\rangle_{\mathbf{B}'}\left|b_0\right\rangle_\mathbf{B}\left|\psi^{\sf sk}_{x,b'_0}\right\rangle_{\mathbf{L}\mathbf{M}\mathbf{R}}. \end{align}\] In the game MultiStageDecisionMonogamy, the state at BeforeSplit is \[\begin{align} \propto\sum_{{\sf sk}}\sum_x\sum_{b',b\in\mathbb{F}_2}\alpha_{{\sf sk},x}\left|{\sf sk}\right\rangle_{\text{\faKey}}\left|x\right\rangle_{\text{\faAnchor}}\left|b'_0\right\rangle_{\mathbf{B}'}\left|b_0\right\rangle_\mathbf{B}\left|\psi^{\sf sk}_{x,b_0}\right\rangle_{\mathbf{L}\mathbf{M}\mathbf{R}}. \end{align}\] if we include an untouched \(\mathbf{B}'\) register. Thus the maximum distinguishing probability for any \(\Pi_0^{\mathcal{A}},\Pi_1^{\mathcal{A}}\) is \[\begin{align} &\frac{{\sf{Pr}}\left[{\sf MultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf MultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}\\ &-\frac{{\sf{Pr}}\left[{\sf ModifiedMultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf ModifiedMultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}\\ =&\frac{1}{2}\mathop{\mathbb{E}}_{{\sf sk},x}\left[{\mathop{\mathrm{TD}}\left(\left|\psi^{\sf sk}_{x,0}\right\rangle\left\langle\psi^{\sf sk}_{x,0}\right|, \left|\psi^{\sf sk}_{x,1}\right\rangle\left\langle\psi^{\sf sk}_{x,1}\right|\right)}\right]\\ =&\frac{1}{2}\mathop{\mathbb{E}}_{{\sf sk},x}\left[\sqrt{1-\left|\left\langle \psi^{\sf sk}_{x,0}\vert \psi^{\sf sk}_{x,1}\right\rangle\right|^2}\right]\\ \leq&\frac{1}{2}\mathop{\mathbb{E}}_{{\sf sk},x}\left[1-\frac{1}{2}\left|\left\langle \psi^{\sf sk}_{x,0}\vert \psi^{\sf sk}_{x,1}\right\rangle\right|^2\right]\\ =&\frac{1}{2}-\frac{1}{4}\mathop{\mathbb{E}}_{{\sf sk},x}\left[\left|\left\langle \psi^{\sf sk}_{x,0}\vert \psi^{\sf sk}_{x,1}\right\rangle\right|^2\right]. \end{align}\] ◻

Now we prove another claim showing that there is not noticeable advantage for any adversary to win ModifiedMultiStageDecisionMonogamy.

Claim 26. The winning probability of any adversary \(\mathcal{A}\) in ModifiedMultiStageDecisionMonogamy is at most \(\frac{1}{2}+{\sf negl}\). For any adversary \(\mathcal{A}\) such that \[{\sf{Pr}}\left[{\sf ModifiedMultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]\geq\frac{1}{{\sf poly}({\sf{\lambda}})},\] then we have \[\frac{{\sf{Pr}}\left[{\sf ModifiedMultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf ModifiedMultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}\leq\frac{1}{2}+{\sf negl}({\sf{\lambda}}).\]

Proof. For any adversary \(\mathcal{A}\) that does not abort with at least \(\delta({\sf{\lambda}})\) probability in the game ModifiedMultiStageDecisionMonogamy, and conditioned on that it wins with probability at least \(\frac{1}{2}+\delta({\sf{\lambda}})\) for some inverse polynomial \(\delta({\sf{\lambda}})\), we construct an adversary \(\mathcal{B}=(\mathcal{B}_M,\mathcal{B}_L,\mathcal{B}_R)\) that wins the following game with probability at least \(\frac{1}{2}+\delta({\sf{\lambda}})\) conditioned on not aborting, and the non-aborting probability is at least \(\delta({\sf{\lambda}})\).

  1. The challenger generates \(\left({\sf sk},\left|\Psi^{{\sf sk}}_{n_e,n,n}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n,n}(1^{\sf{\lambda}})\) and gives the register \(\text{\faShip}\) to \(\mathcal{B}_M\).

  2. \(\mathcal{B}_M\) is given membership oracles \(\mathcal{O}_{T+v}\) and \(\mathcal{O}_{S^\perp+u}\). \(\mathcal{B}_M\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, it generates a bipartite state on \(\mathbf{L}\mathbf{R}\). It sends \(\mathbf{L}\) to \(\mathcal{B}_L\) and sends \(\mathbf{R}\) to \(\mathcal{B}_R\).

  3. The challenger samples \(b_0\overset{\$}{\gets}\mathbb{F}_2\) and \(b_1\overset{\$}{\gets}\mathbb{F}_2^{m_1}\). It gives \(\mathcal{O}_{T+v}^{b_0}\) to \(\mathcal{B}_\mathcal{L}\). Then it gives both \(\mathcal{O}_{T+v}^{b_0}\) and \(\mathcal{O}_{S^\perp+u}^{b_1}\) to \(\mathcal{B}_R\).

  4. \(\mathcal{B}_L\) returns \(b_0^l\), \(\mathcal{B}_R\) returns \(b_1^r\). The adversary wins if \(b_0^l=b_0\) and \(b_1^r=b_1\).

\(\mathcal{B}\) is constructed as follows (shown in 8):

  1. \(\mathcal{B}_M\) receives \(\text{\faShip}\) from the challenger, it calls \(\mathcal{A}_M^0\) to obtain \(\mathbf{L}\mathbf{M}\mathbf{R}\). It aborts if \(\mathcal{A}_M^0\) aborts. It then samples \(b'_0\) by itself, simulates \(\mathcal{O}_{T+v}^{b'_0}\) on its own using \(\mathcal{O}_{T+v}\), calls \(\mathcal{A}_M^1\) to obtain \(\mathbf{M}_L\mathbf{M}'\mathbf{M}_R\). It gives \(\mathbf{L}\mathbf{M}_L\) (as the \(\mathbf{L}\) register in \({\sf AsymmetricOracleMonogamy}\)) to \(\mathcal{B}_L\) and gives \(\mathbf{M}'\mathbf{M}_R\mathbf{R}\) (as the \(\mathbf{R}\) register in \({\sf AsymmetricOracleMonogamy}\)) to \(\mathcal{B}_R\).

  2. \(\mathcal{B}_L\) with access to \(\mathcal{O}_{T+v}^{b_0}\) calls \(\mathcal{A}_L^0\). It forwards the output of \(\mathcal{A}_L^0\) as \(b_0^l\).

  3. \(\mathcal{B}_R\) calls \(\mathcal{A}_M^2\) with access to \(\mathcal{O}_{T+v}^{b_0}\) and \(\mathcal{O}_{S^\perp+u}^{b_1}\) on \(\mathbf{M}'\) to obtain \(\mathbf{M}'_L\mathbf{M}'_R\). Then it calls \(\mathcal{A}_R^0\) on \(\mathbf{R}\mathbf{M}_R\) with access to \(\mathcal{O}_{T+v}^{b_0}\) to obtain \(\mathbf{R}'\). Finally it calls \(\mathcal{A}_R^1\) on \(\mathbf{M}'_R\mathbf{R}'\) with access to \(\mathcal{O}_{T+v}^{b_0},\mathcal{O}_{S^\perp+u}^{b_1}\) and forwards the output of \(\mathcal{A}_R^1\) as \(b_1^r\).

Figure 8: The adversary \mathcal{B}=(\mathcal{B}_M,\mathcal{B}_L,\mathcal{B}_R).

The same adversary \(\mathcal{B}=(\mathcal{B}_M,\mathcal{B}_L,\mathcal{B}_R)\) also wins the following game with probability at least \(\frac{1}{2}+\delta({\sf{\lambda}})-{\sf negl}\) conditioned on not aborting, and the non-aborting probability is at least \(\delta({\sf{\lambda}})-{\sf negl}({\sf{\lambda}})\).

  1. The challenger generates \(\left({\sf sk},\left|\Psi^{{\sf sk}}_{n_e,n,n}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n,n}(1^{\sf{\lambda}})\) and gives the register \(\text{\faShip}\) to \(\mathcal{B}_M\). It samples uniformly random subspace \(T^*\) of dimension \(n_e+7n/4\) such that \(T\leq T^*\leq\mathbb{F}_2^{n_e+2n}\). It also samples uniformly random subspace \(S^*\leq S\) of dimension \(n/4\).

  2. \(\mathcal{B}_M\) is given membership oracles \(\mathcal{O}_{T^*+v}\) and \(\mathcal{O}_{{S^*}^\perp+u}\). \(\mathcal{B}_M\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, it generates a bipartite state on \(\mathbf{L}\mathbf{R}\). It sends \(\mathbf{L}\) to \(\mathcal{B}_L\) and sends \(\mathbf{R}\) to \(\mathcal{B}_R\).

  3. The challenger samples \(b_0\overset{\$}{\gets}\mathbb{F}_2\) and \(b_1\overset{\$}{\gets}\mathbb{F}_2^{m_1}\). It gives \(\mathcal{O}_{T+v}^{b_0}\) to \(\mathcal{B}_\mathcal{L}\). Then it gives both \(\mathcal{O}_{T^*+v}^{b_0}\) and \(\mathcal{O}_{S^\perp+u}^{b_1}\) to \(\mathcal{B}_R\).

  4. \(\mathcal{B}_L\) returns \(b_0^l\), \(\mathcal{B}_R\) returns \(b_1^r\). The adversary wins if \(b_0^l=b_0\) and \(b_1^r=b_1\).

This is because that we can apply hybrid argument and use 4 multiple times on \(\mathcal{O}_{T+v}\), \(\mathcal{O}_{S^\perp+u}\), and \(\mathcal{O}_{T+v}^{b_0}\) given to \(\mathcal{B}_R\). Now using \(\mathcal{B}\) we construct an adversary \(\mathcal{C}=(\mathcal{C}_M,\mathcal{C}_L,\mathcal{C}_R)\) that wins AsymmetricOracleMonogamy(defined in 9) with probability \(\frac{1}{2}+\delta({\sf{\lambda}})-{\sf negl}\) conditioned on not aborting, and the non-aborting probability is at least \(\delta({\sf{\lambda}})-{\sf negl}({\sf{\lambda}})\).

  1. \(\mathcal{C}_M\) receives \(\text{\faShip}\) and runs \({\sf sk}^*\gets{\sf DomainExtension}_{n/4,n/4}(1^{\sf{\lambda}})\) on \(\text{\faShip}\). It runs \(\mathcal{B}_M\) on \(\text{\faShip}^*\) to obtain \(\mathbf{L}\mathbf{R}\). It aborts if \(\mathcal{B}_M\) aborts. It gives \({\sf sk}^*,\mathbf{L}\) to \(\mathcal{B}_L\) and \({\sf sk}^*,\mathbf{R}\) to \(\mathcal{B}_R\). All queries to \(\mathcal{O}_{T^*+v}\) is equivalent to \(\mathcal{O}_{T^*+v^*}\) and can be simulated by \({\sf sk}^*\). So do queries to \(\mathcal{O}_{{S^*}^\perp+u}\) and other oracles below.

  2. \(\mathcal{C}_L\) runs \(\mathcal{B}_L\) on \(\mathbf{L}\) with oracle access to \(\mathcal{O}_{T_{\sf ext}+v_{\sf ext}}^{b_0}\). It outputs \(b^l_0\), the output of \(\mathcal{B}_L\).

  3. \(\mathcal{C}_R\) runs \(\mathcal{B}_R\) on \(\mathbf{R}\) with oracle access to \(\mathcal{O}_{T^*+v}^{b_0}\) (simulated by \({\sf sk}^*\) and \(b_0\) given by the challenger) and \(\mathcal{O}_{S_{\sf ext}^\perp+u_{\sf ext}}^{b_1}\). It outputs \(b^r_1\), the output of \(\mathcal{B}_R\).

By contradiction, such adversary \(\mathcal{B}\) cannot exist and hence \(\mathcal{A}\) also doesn’t exist. ◻

Finally, combining 25 and 26 we get \[\begin{align} &\mathop{\mathbb{E}}_{{\sf sk},x}\left[\left|\left\langle \psi^{\sf sk}_{x,0}\vert \psi^{\sf sk}_{x,1}\right\rangle\right|^2\right]\\ \leq&4\left(\frac{{\sf{Pr}}\left[{\sf ModifiedMultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf ModifiedMultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}+\frac{1}{2}-\frac{{\sf{Pr}}\left[{\sf MultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf MultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]} \right)\\ =&4\left(\frac{{\sf{Pr}}\left[{\sf ModifiedMultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf ModifiedMultiStageDecisionMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}+\frac{1}{2}-(1-\varepsilon({\sf{\lambda}})) \right)\\ \leq&4\left(\frac{1}{2}+{\sf negl}({\sf{\lambda}})+\frac{1}{2}-(1-\varepsilon({\sf{\lambda}})) \right)\\ \leq&4\varepsilon({\sf{\lambda}})+{\sf negl}({\sf{\lambda}}). \end{align}\] ◻

Lemma 11. Take any adversary \(\mathcal{A}\) in the multi-stage monogamy-of-entanglement game described in 4 such that \[{\sf{Pr}}\left[{\sf MultiStageSearchMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]=\varepsilon'({\sf{\lambda}})\] and \[\frac{{\sf{Pr}}\left[{\sf MultiStageSearchMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf MultiStageSearchMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}=1-\varepsilon({\sf{\lambda}})\] for inverse polynomials \(\varepsilon({\sf{\lambda}}),\varepsilon'({\sf{\lambda}})\). Consider the state \(\text{\faKey}\text{\faAnchor}\mathbf{L}\mathbf{M}\mathbf{R}\mathbf{B}\) at BeforeSplit conditioned on \(\mathcal{A}_M^0\) not aborting, which we can write as (we also purify \({\sf sk}\) in register \(\text{\faKey}\) here):

\[\left|\psi\right\rangle_{\text{\faKey}\text{\faAnchor}\mathbf{L}\mathbf{M}\mathbf{R}\mathbf{B}}=\sum_{{\sf sk}}\sum_{x}\sum_{b_0\in\mathbb{F}_2^{m_0}}\frac{\alpha_{{\sf sk},x}}{\sqrt{2^{m_0}}}\left|{\sf sk}\right\rangle_{\text{\faKey}}\left|x\right\rangle_{\text{\faAnchor}}\left|\psi^{\sf sk}_{x,0}\right\rangle_{\mathbf{L}\mathbf{M}\mathbf{R}}\left|b_0\right\rangle_\mathbf{B}.\] where \(\left|\psi^{\sf sk}_{x,b_0}\right\rangle\) for all \(b_0\) are normalized states. We have, \[\mathop{\mathrm{Tr}}\left(\left|+\right\rangle\left\langle+\right|_\mathbf{B}\cdot\left|\psi\right\rangle\left\langle\psi\right|_{\text{\faKey}\text{\faAnchor}\mathbf{L}\mathbf{M}\mathbf{R}\mathbf{B}} \right)\leq\frac{1}{2^{m_0}}+2\sqrt{2}\varepsilon^{1/2}+{\sf negl}({\sf{\lambda}})\] where \(\left|+\right\rangle_\mathbf{B}=\frac{1}{\sqrt{2^{m_0}}}\sum_{b_0\in\mathbb{F}_2^{m_0}}\left|b_0\right\rangle_\mathbf{B}\) is the uniform superposition over \(b_0\).

Proof. Define the probability that the adversary \(\mathcal{A}\) wins (both parties output the correct \(b_0\)) when \(b_0=b_0^*\) conditioned on not aborting as \(1-\varepsilon_{b_0^*}({\sf{\lambda}})\). We have, \[\varepsilon=\mathop{\mathbb{E}}_{b_0}\left[\varepsilon_{b_0}\right].\] For any different \(b'_0,b''_0\in\mathbb{F}_2^{m_0}\), we must have \[\label{eq:expected95ipd} \mathop{\mathbb{E}}_{{\sf sk},x}\left[\left|\left\langle \psi^{\sf sk}_{x,b'_0}\vert \psi^{\sf sk}_{x,b''_0}\right\rangle\right|^2\right]\leq 2\left(\varepsilon_{b'_0}({\sf{\lambda}})+\varepsilon_{b''_0}({\sf{\lambda}}) \right)+{\sf negl}({\sf{\lambda}}).\tag{1}\] To prove this we construct an adversary \(\mathcal{A}'\) in 10. \(\mathcal{A}'\) runs \(\mathcal{A}\) and reprograms all the oracle outputs: reprograms \(0\) to \(b'_0\), \(1\) to \(b''_0\), and \(\bot\) unchanged. Finally, \(\mathcal{A}'\) also reprograms the output of \(\mathcal{A}\): reprograms \(b'_0\) to \(0\) and \(b''_0\) to \(1\). For this \(\mathcal{A}'\), \[\frac{{\sf{Pr}}\left[{\sf MultiStageDecisionMonogamy}(\mathcal{A}',1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf MultiStageDecisionMonogamy}(\mathcal{A}',1^{\sf{\lambda}})\neq\bot\right]}=1-\frac{1}{2}\left(\varepsilon_{b'_0}({\sf{\lambda}})+\varepsilon_{b''_0}({\sf{\lambda}}) \right).\] By 10, the state of \(\mathcal{A}'\) at BeforeSplit satisfies \[\mathop{\mathbb{E}}_{{\sf sk},x}\left[\left|\left\langle \psi^{\sf sk}_{x,0}\vert \psi^{\sf sk}_{x,1}\right\rangle\right|^2\right]\leq 2\left(\varepsilon_{b'_0}({\sf{\lambda}})+\varepsilon_{b''_0}({\sf{\lambda}}) \right)+{\sf negl}({\sf{\lambda}}).\] Hence we proved 1 . Combine all above, we have \[\begin{align} &\mathop{\mathrm{Tr}}\left(\left|+\right\rangle\left\langle+\right|_\mathbf{B}\cdot\left|\psi\right\rangle\left\langle\psi\right|_{\text{\faKey}\text{\faAnchor}\mathbf{L}\mathbf{M}\mathbf{R}\mathbf{B}} \right)\\ \leq&\frac{1}{2^{2m_0}}\mathop{\mathbb{E}}_{{\sf sk},x}\left[\sum_{b'_0,b''_0}\left|\left\langle \psi^{\sf sk}_{x,b'_0}\vert \psi^{\sf sk}_{x,b''_0}\right\rangle\right|\right]\\ =&\frac{1}{2^{2m_0}}\mathop{\mathbb{E}}_{{\sf sk},x}\left[2^{m_0}+\sum_{b'_0\neq b''_0}\left|\left\langle \psi^{\sf sk}_{x,b'_0}\vert \psi^{\sf sk}_{x,b''_0}\right\rangle\right|\right]\\ =&\frac{1}{2^{m_0}}+\frac{1}{2^{2m}}\sum_{b'_0\neq b''_0}\mathop{\mathbb{E}}_{{\sf sk},x}\left[\left|\left\langle \psi^{\sf sk}_{x,b'_0}\vert \psi^{\sf sk}_{x,b''_0}\right\rangle\right|\right]\\ \leq&\frac{1}{2^{m_0}}+\frac{1}{2^{2m}}\sum_{b'_0\neq b''_0}\sqrt{\mathop{\mathbb{E}}_{{\sf sk},x}\left[\left|\left\langle \psi^{\sf sk}_{x,b'_0}\vert \psi^{\sf sk}_{x,b''_0}\right\rangle\right|^2\right]}\\ \leq&\frac{1}{2^{m_0}}+\frac{1}{2^{2m}}\sum_{b'_0\neq b''_0}\sqrt{2\left(\varepsilon_{b'_0}({\sf{\lambda}})+\varepsilon_{b''_0}({\sf{\lambda}}) \right)+{\sf negl}({\sf{\lambda}})}\\ \leq&\frac{1}{2^{m_0}}+\frac{1}{2^{2m}}\sum_{b'_0\neq b''_0}\left(\sqrt{2\varepsilon_{b'_0}({\sf{\lambda}})+{\sf negl}({\sf{\lambda}})}+\sqrt{2\varepsilon_{b''_0}({\sf{\lambda}})+{\sf negl}({\sf{\lambda}})} \right)\\ \leq&\frac{1}{2^{m_0}}+2\sqrt{2}\mathop{\mathbb{E}}_{b_0}\left[\sqrt{\varepsilon_{b_0}({\sf{\lambda}})+{\sf negl}({\sf{\lambda}})}\right]\\ \leq&\frac{1}{2^{m_0}}+2\sqrt{2}\sqrt{\mathop{\mathbb{E}}_{b_0}\left[\varepsilon_{b_0}({\sf{\lambda}})+{\sf negl}({\sf{\lambda}})\right]}\\ \leq&\frac{1}{2^{m_0}}+2\sqrt{2}\varepsilon^{1/2}+{\sf negl}({\sf{\lambda}}) \end{align}\] The inequality between line 4 and line 5 uses \(\boldsymbol{Var}(X)=\mathop{\mathbb{E}}\left[X^2\right]-\mathop{\mathbb{E}}\left[X\right]^2\geq 0\), as well as the inequality between line 8 and line 9. ◻

7 Entanglement Extraction↩︎

7.1 Extracting Incompatible Measurement Results via Collapsing Oracles↩︎

In later sections, we consider \(n_e(\lambda)=n(\lambda)\) if not specified.

Lemma 12. Let \(n({\sf{\lambda}})\geq{\sf{\lambda}}\) and \(m_0({\sf{\lambda}})=m_1({\sf{\lambda}})=m({\sf{\lambda}})\geq{\sf{\lambda}}\) be polynomials of \({\sf{\lambda}}\). There exists an efficient extractor \(\mathcal{E}_S\) with access to \({\sf sk}\) and the register \(\mathbf{M}\) such that the following holds. Take any adversary \(\mathcal{A}\) in the multi-stage monogamy-of-entanglement game described in 4 such that \[{\sf{Pr}}\left[{\sf MultiStageSearchMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]=\varepsilon'({\sf{\lambda}})\] and \[\frac{{\sf{Pr}}\left[{\sf MultiStageSearchMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf MultiStageSearchMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}=1-\varepsilon({\sf{\lambda}})\] for inverse polynomials \(\varepsilon({\sf{\lambda}}),\varepsilon'({\sf{\lambda}})\). Then running \(\mathcal{E}_S^{\mathcal{A}_M^1}\) on the state \(\mathbf{M}\) conditioned on \(\mathcal{A}_M^0\) not aborting gives \(x\), the standard basis measurement result on \(\text{\faAnchor}\), with probability at least \(1-2\sqrt{2}\varepsilon^{1/2}-{\sf negl}({\sf{\lambda}})\). That is, with \(\mathbf{X}\) denoting the output register of \(\mathcal{E}_S^{\mathcal{A}_M^1}\), \[\mathop{\mathbb{E}}\left[\mathsf{Tr}\left(\Pi_{\sf eq}\mathcal{E}_S^{\mathcal{A}_M^1}\rho_{\mathbf{X}\mathbf{M}}\left(\mathcal{E}_S^{\mathcal{A}_M^1} \right)^\dagger\Pi_{\sf eq} \right)\middle\vert\subarray{c}\left({\sf sk},\left|\Psi^{{\sf sk}}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}(1^{\sf{\lambda}})\\ \mathcal{A}_M^0\text{ does not abort and produces }\rho_{\mathbf{X}\mathbf{M}}\text{ on }\mathbf{X}\mathbf{M}\endsubarray\right]\geq 1-2\sqrt{2}\varepsilon^{1/2}-{\sf negl}({\sf{\lambda}})\] where \(\Pi_{\sf eq}=\sum_{x}\left|x\right\rangle_{\text{\faAnchor}}\left\langle x\right|\otimes\left|x\right\rangle_{\mathbf{X}}\left\langle x\right|\) is the projector that tests whether the output is correct. Furthermore, \(\mathcal{E}_S^{\mathcal{A}_M^1}\) only makes black-box access to \(\mathcal{A}_M^1\) and acts on \(\mathbf{M}\). When we say \(\mathcal{A}_M^1\), we refer to the process only up to BeforeSplit, excluding the renaming and splitting procedure.

Proof. In this proof we consider all notations aligned with 5 with \(a=n,b=2n\) and \(c=3n\). In the following proof, all procedures are conditioned on \(\mathcal{A}_M^0\) not aborting. Here is the construction of \(\mathcal{E}_S^{\mathcal{A}_M^1}\):

  1. Set up a random oracle \(\mathcal{O}_{\sf random}\) using a compress oracle with the database on \(\left|D\right\rangle_{\mathbf{D}}\). Run \(\mathcal{A}_M^1\) in MultiStageSearchMonogamy on \(\mathbf{M}\). Simulate \(\mathcal{O}_{S^\perp+u}\) using \({\sf sk}\). Replace \(\mathcal{O}_{T+v}^{b_0}\) with

    • \(\mathcal{O}_{T+v}^{\sf col,\mathcal{O}_{\sf random}}:\mathbb{F}_2^{3n}\rightarrow\mathbb{F}_2^{m_0}\cup\left\{\bot\right\}\) on input \(z\) checks if it is in \(T+v\). It returns \(\bot\) if it is not. Otherwise, it returns \(\mathcal{O}_{\sf random}({\sf Can}_S(z))\).

    And also simulate \(\mathcal{O}_{T+v}\) using the above oracle.

  2. Measure the database register, if there is no non-\(\bot\) entry or more than one non-\(\bot\) entry, then output \(\bot\). Otherwise, let the unique entry be \((w',y)\). Output the middle \(n\) bits of \(U_{\sf shift}^{-1}w'\).

We calculate the success probability of \(\mathcal{E}_S^{\mathcal{A}_M^1}\) using a hybrid argument. In the following hybrids, when we say compute something based on \(x\), the standard basis value on \(\text{\faAnchor}\), we mean coherently do that controlled by \(x\) on \(\text{\faAnchor}\).
Hybrid 0: This is the hybrid corresponds to running \(\mathcal{E}_S^{\mathcal{A}_M^1}\) on \(\mathbf{M}\).
Hybrid 1: This is the hybrid corresponds to running \(\mathcal{E}_{S,{\sf ncol}}^{\mathcal{A}_M^1}\) on \(\mathbf{M}\) where \(\mathcal{E}_{S,{\sf ncol}}^{\mathcal{A}_M^1}\) is controlled by \(\text{\faAnchor}\) and is constructed as follows:

  1. Set up a random oracle \(\mathcal{O}_{\sf random}\) using a compress oracle with the database on \(\left|D\right\rangle_{\mathbf{D}}\). Run \(\mathcal{A}_M^1\) in MultiStageSearchMonogamy on \(\mathbf{M}\). Simulate \(\mathcal{O}_{S^\perp+u}\) using \({\sf sk}\). Sample \(w_x\overset{\$}{\gets}U_{\sf shift}\left(\left\{0,1\right\}^n\times x\times 0^n \right)+v\) where \(x\) is the standard basis value on \(\text{\faAnchor}\). Replace \(\mathcal{O}_{T+v}^{b_0}\) with

    • \(\mathcal{O}_{T+w_x}^{\sf ncol,\mathcal{O}_{\sf random}}:\mathbb{F}_2^{3n}\rightarrow\mathbb{F}_2^{m_0}\cup\left\{\bot\right\}\) on input \(z\) checks if it is in \(T+w_x\). It returns \(\bot\) if it is not. Otherwise, it returns \(\mathcal{O}_{\sf random}\left({\sf Can}_S(w_x) \right)\).

    And also simulate \(\mathcal{O}_{T+v}\) using the above oracle.

  2. Measure the database register, if there is no non-\(\bot\) entry or more than one non-\(\bot\) entry, then output \(\bot\). Otherwise, let the unique entry be \((w',y)\). Output the middle \(n\) bits of \(U_{\sf shift}^{-1}w'\).

Claim 27. We view \(x\) on \(\text{\faAnchor}\) as a classical control string. Let \(P_{D,x}\) be the distribution of database register \(\left|D\right\rangle_{\mathbf{D}}\) in Hybrid 0 conditioned on the value on \(\text{\faAnchor}\) is \(x\). Let \(P'_{D,x}\) be the corrresponding distribution for Hybrid 1. For a uniform random \(x\), the expected statistical distance between \(P_{D,x}\) and \(P'_{D,x}\) is negligible.

Proof. First note that \(w_x\) is an independent random vector given \(S\) and \(T\) is an independent subspace containing \(S\) given \(S,w_x\). To use 5 we need to show that we can construct the correct state on \(\text{\faShip}\) conditioned on the standard basis value \(x\) on \(\text{\faAnchor}\) given \(S,w_x\) so that we describe the whole hybrid as an isometry on \(\left|S,w_x\right\rangle\) for uniform random \(x\) (if we trace out \(\text{\faAnchor}\)). Decompose \(w_x\) as \(u_x+U_{\sf shift}\left(0^n\times x\times 0^n \right)+v\). We need to construct \[\propto\sum_{x\in\mathbb{F}_2^n}\left|x\right\rangle_{\text{\faAnchor}}\sum_{s\in S}(-1)^{\left \langle {s,u} \right \rangle}\left|s+U_{\sf shift}\left(0^{n_h}\times x\times 0^{n_s} \right)+v\right\rangle_\text{\faShip}\] from \[\propto\sum_{x\in\mathbb{F}_2^n}\left|x\right\rangle_{\text{\faAnchor}}\left|S,w_x\right\rangle\] by operating on \(\text{\faShip}\). We can generate the state by first generate the state on \(\text{\faShip}\) assuming \(x=0\) on \(\text{\faAnchor}\) with a random \(u\) and with \(v=0\). \[\propto\sum_{x\in\mathbb{F}_2^n}\left|x\right\rangle_{\text{\faAnchor}}\sum_{s\in S}(-1)^{\left \langle {s,u} \right \rangle}\left|s\right\rangle.\] Then we XOR \(w_x\) on the standard basis. \[\begin{align} \propto&\sum_{x\in\mathbb{F}_2^n}\left|x\right\rangle_{\text{\faAnchor}}\sum_{s\in S}(-1)^{\left \langle {s,u} \right \rangle}\left|s+w_x\right\rangle\\ \propto&\sum_{x\in\mathbb{F}_2^n}\left|x\right\rangle_{\text{\faAnchor}}\sum_{s\in S}(-1)^{\left \langle {s,u} \right \rangle}\left|s+u_x+U_{\sf shift}\left(0^n\times x\times 0^n \right)+v\right\rangle\\ \propto&\sum_{x\in\mathbb{F}_2^n}(-1)^{\left \langle {u_x,u} \right \rangle}\left|x\right\rangle_{\text{\faAnchor}}\sum_{s'\in S}(-1)^{\left \langle {s',u} \right \rangle}\left|s'+U_{\sf shift}\left(0^n\times x\times 0^n \right)+v\right\rangle. \end{align}\] In this way we get the correct state except there is a relative phase between \(\text{\faAnchor}\) and \(\text{\faShip}\) depending on the standard basis value on \(\text{\faAnchor}\) if you consider the whole purified anchor state. But note that the standard basis value on \(\text{\faAnchor}\) only acts as a control so this relative phase doesn’t affect the output distribution of the hybrid. ◻

Hybrid 2: This is the hybrid corresponds to running \(\mathcal{A}_M^1\) on \(\mathbf{M}\) but we replace \(\mathcal{O}_{T+v}^{b_0}\) with a purified version of it:

  1. Set up a random oracle \(\mathcal{O}_{\sf random}\) using a compress oracle with the database on \(\left|D\right\rangle_{\mathbf{D}}\). Run \(\mathcal{A}_M^1\) in MultiStageSearchMonogamy on \(\mathbf{M}\). Simulate \(\mathcal{O}_{S^\perp+u}\) using \({\sf sk}\). Sample \(w_x\overset{\$}{\gets}U_{\sf shift}\left(\left\{0,1\right\}^n\times x\times 0^n \right)+v\) where \(x\) is the standard basis value on \(\text{\faAnchor}\). But rename \(\mathbf{D}_{{\sf Can}_S(w_x)}\) as \(\mathbf{B}\) that stores the purified \(b_0\). And also simulate \(\mathcal{O}_{T+v}\) with \(\mathcal{O}_{T+v}^{b_0}\).

  2. Measure the database register, if there is no non-\(\bot\) entry or more than one non-\(\bot\) entry, then output \(\bot\). Otherwise, let the unique entry be \((w',y)\). Output the middle \(n\) bits of \(U_{\sf shift}^{-1}w'\).

Claim 28. Let \(P''_{D,x}\) be the distribution of database register \(\left|D\right\rangle_{\mathbf{D}}\) in Hybrid 2 conditioned on the value on \(\text{\faAnchor}\) is \(x\). For all \(x\), \(P'_{D,x}\) and \(P''_{D,x}\) are identical.

Proof. \(\mathcal{O}_{\sf random}\left({\sf Can}_S(w_x) \right)\) is just a uniform random string identically distributed as \(b_0\). ◻

Note that the probability of outputting the correct \(x\) in Hybrid 2 at least \(1-\frac{1}{2^m}-2\sqrt{2}\varepsilon^{1/2}-{\sf negl}({\sf{\lambda}})\) because:

  • There is at most one non-bot entry in the database because the only place that can be accessed is \({\sf Can}_S(w_x)\).

  • The probability that \({\sf Can}_S(w_x)\) is also a \(\bot\)-entry is at most \(\frac{1}{2^m}+2\sqrt{2}\varepsilon^{1/2}+{\sf negl}\) by 11.

Thus by hybrid argument, the probability that in Hybrid 0 it outputs \(x\) is at least \(1-\frac{1}{2^m}-2\sqrt{2}\varepsilon^{1/2}-{\sf negl}({\sf{\lambda}})\). ◻

Now we look at a similar game DualMultiStageSearchMonogamy that reverse the order of cosets given in the challenge.

Definition 5 (Dual Multi-Stage Search Monogamy-of-Entanglement Game). Let \({\sf{\lambda}}\in\mathbb{N}\) be the security parameter. Let \(n({\sf{\lambda}})\geq{\sf{\lambda}}\) and \(n_e({\sf{\lambda}}),m_0({\sf{\lambda}}),m_1({\sf{\lambda}})\) be polynomials. Consider the following game between the challenger and an adversary \(\mathcal{A}=\allowdisplaybreaks(\mathcal{A}_M^0,\mathcal{A}_M^1,\mathcal{A}_M^2,\mathcal{A}_L^0,\mathcal{A}_L^1,\mathcal{A}_R^0,\mathcal{A}_R^1)\):

  1. The challenger generates \(\left({\sf sk},\left|\Psi^{{\sf sk}}_{n_e,n,n}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}_{n_e,n,n}(1^{\sf{\lambda}})\) and gives the register \(\text{\faShip}\) to \(\mathcal{A}_M\). All parties of the adversary are given oracle access to \(\mathcal{O}_{T+v}\) and \(\mathcal{O}_{S^\perp+u}\).

  2. \(\mathcal{A}_M^0\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, it generates a tripartite state on \(\mathbf{L}\mathbf{M}\mathbf{R}\). It sends \(\mathbf{L}\) to \(\mathcal{A}_L^0\), sends \(\mathbf{M}\) to \(\mathcal{A}_M^1\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R^0\).

  3. \(\mathcal{A}_M^1\) is given access to \(\mathcal{O}_{S^\perp+u}^{b_0}\) for random \(b_0\overset{\$}{\gets}\left\{0,1\right\}^{m_0({\sf{\lambda}})}\). \(\mathcal{A}_M^1\) with access to this oracle and \(\mathbf{M}\) generates a tripartite state on \(\mathbf{M}_L\mathbf{M}'\mathbf{M}_R\). It sends \(\mathbf{M}_L\) to \(\mathcal{A}_L^0\), sends \(\mathbf{M}'\) to \(\mathcal{A}_M^2\) and sends \(\mathbf{M}_R\) to \(\mathcal{A}_R^0\). We will name the time just after all operations of \(\mathcal{A}_M^1\) are done and before renaming the registers and splitting them as BeforeSplit.

  4. \(\mathcal{A}_L^0\) and \(\mathcal{A}_R^0\) are given access to \(\mathcal{O}_{S^\perp+u}^{b_0}\). \(\mathcal{A}_L^0\) on \(\mathbf{L}\mathbf{M}_L\) produces answer \(b_0^l\) and a state on register \(\mathbf{L}'\) that is sent to \(\mathcal{A}_L^1\). \(\mathcal{A}_R^0\) on \(\mathbf{R}\mathbf{M}_R\) produces answer \(b_0^r\) and a state on register \(\mathbf{R}'\) that is sent to \(\mathcal{A}_R^1\).

  5. \(\mathcal{A}_M^2\) is given access to \(\mathcal{O}_{S^\perp+u}^{b_0}\) and \(\mathcal{O}_{T+v}^{b_1}\) for random \(b_1\overset{\$}{\gets}\left\{0,1\right\}^{m_1({\sf{\lambda}})}\). It generates a bipartite state on \(\mathbf{M}'_L\mathbf{M}'_R\). \(\mathbf{M}'_L\) is given to \(\mathcal{A}_L^1\) and \(\mathbf{M}'_R\) is given to \(\mathcal{A}_R^1\).

  6. \(\mathcal{A}_L^1\) and \(\mathcal{A}_R^1\) are given access to \(\mathcal{O}_{S^\perp+u}^{b_0}\) and \(\mathcal{O}_{T+v}^{b_1}\). \(\mathcal{A}_L^1\) on \(\mathbf{L}'\mathbf{M}'_L\) generates the answer \(b_1^l\). \(\mathcal{A}_R^1\) on \(\mathbf{R}'\mathbf{M}'_R\) generates the answer \(b_1^r\). The adversary wins iff \(b_0^l=b_0^r=b_0\) and \(b_1^l=b_1^r=b_1\).

This game is displayed in 9. Let \({\sf DualMultiStageSearchMonogamy}(\mathcal{A},1^{\sf{\lambda}})\) be the random variable that takes value \(1/0/\bot\) if the adversary \(\mathcal{A}\) wins/loses/aborts in the above game, respectively.

Figure 9: The dual multi-stage monogamy-of-entanglement game DualMultiStageSearchMonogamy.

Corollary 1. Let \(n({\sf{\lambda}})\geq{\sf{\lambda}}\) and \(m_0({\sf{\lambda}})=m_1({\sf{\lambda}})=m({\sf{\lambda}})\geq{\sf{\lambda}}\) be polynomials of \({\sf{\lambda}}\). There exists an efficient extractor \(\mathcal{E}_H\) with access to \({\sf sk}\) and the register \(\mathbf{M}\) such that the following holds. Take any adversary \(\mathcal{A}\) in the multi-stage monogamy-of-entanglement game described in 4 such that \[{\sf{Pr}}\left[{\sf DualMultiStageSearchMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]=\varepsilon'({\sf{\lambda}})\] and \[\frac{{\sf{Pr}}\left[{\sf DualMultiStageSearchMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf DualMultiStageSearchMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}=1-\varepsilon({\sf{\lambda}})\] for inverse polynomials \(\varepsilon({\sf{\lambda}}),\varepsilon'({\sf{\lambda}})\). Then running \(\mathcal{E}_H^{\mathcal{A}_M^1}\) on the state \(\mathbf{M}\) conditioned on \(\mathcal{A}_M^0\) not aborting gives \(x\), the Hadamard basis measurement result on \(\text{\faAnchor}\), with probability at least \(1-2\sqrt{2}\varepsilon^{1/2}-{\sf negl}({\sf{\lambda}})\). That is, with \(\mathbf{X}\) denoting the output register of \(\mathcal{E}_H^{\mathcal{A}_M^1}\), \[\mathop{\mathbb{E}}\left[\mathsf{Tr}\left(\Pi_{\sf eq}\mathcal{E}_H^{\mathcal{A}_M^1}\rho_{\mathbf{X}\mathbf{M}}\left(\mathcal{E}_H^{\mathcal{A}_M^1} \right)^\dagger\Pi_{\sf eq} \right)\middle\vert\subarray{c}\left({\sf sk},\left|\Psi^{{\sf sk}}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}(1^{\sf{\lambda}})\\ \mathcal{A}_M^0\text{ does not abort and produces }\rho_{\mathbf{X}\mathbf{M}}\text{ on }\mathbf{X}\mathbf{M}\endsubarray\right]\geq 1-2\sqrt{2}\varepsilon^{1/2}-{\sf negl}({\sf{\lambda}})\] where \(\Pi_{\sf eq}=\sum_{x}\left|x\right\rangle_{\text{\faAnchor}}\left\langle x\right|\otimes\left|x\right\rangle_{\mathbf{X}}\left\langle x\right|\) is the projector that tests whether the output is correct. Furthermore, \(\mathcal{E}_H^{\mathcal{A}_M^1}\) only makes black-box access to \(\mathcal{A}_M^1\) and acts on \(\mathbf{M}\). When we say \(\mathcal{A}_M^1\), we refer to the process only up to BeforeSplit, excluding the renaming and splitting procedure.

Proof. Similar to 12. By the symmetric structure of \(\left|\Psi^{\sf sk}\right\rangle_{\text{\faAnchor}\text{\faShip}}\). ◻

7.2 Entanglement Rigidity in Multi-Stage Monogamy-of-Entanglement Games↩︎

Define the Pauli operators \[\sigma_X= \begin{pmatrix} 0 & 1 \\ 1 & 0 \\ \end{pmatrix} \quad \sigma_Y= \begin{pmatrix} 0 & -i\\ i & 0\\ \end{pmatrix} \quad \sigma_Z= \begin{pmatrix} 1 & 0 \\ 0 & -1 \\ \end{pmatrix}\]

Lemma 13 (EPR Pair Rigidity, [33], Lemma 5.4). Let \(\left|\psi\right\rangle_{\mathbf{A}\mathbf{B}}\in\left(\mathbb{C}^2 \right)^{\otimes n}_{\mathbf{A}}\otimes\mathcal{H}_{\mathbf{B}}\), where \(\mathcal{H}_{\mathbf{B}}\) is arbitrary. Suppose that for every \(a\in\left\{0,1\right\}^n\) there exist observables \(X^{\mathbf{B}}(a)\) and \(Z^{\mathbf{B}}(a)\) on \(\mathcal{H}_{\mathbf{B}}\) such that \[\forall W\in\left\{X,Z\right\},\quad \mathop{\mathbb{E}}_{a}\left[\left(\sigma_W^{\mathbf{A}}(a)-W^{\mathbf{B}}(a) \right)\left|\psi\right\rangle\right]^2\leq\varepsilon,\] for some \(0\leq\varepsilon\leq 1\) where \(\sigma_W^{\mathbf{A}}(a)=\sigma_W^{a_1}\otimes \sigma_W^{a_2}\otimes\cdots\otimes \sigma_W^{a_n}\) and the expectation is under the uniform distribution over \(a\in\left\{0,1\right\}^n\). Then there exists an isometry \[\Phi_\mathbf{B}:\mathcal{H}_{\mathbf{B}}\rightarrow\left(\left(\mathbb{C}^2 \right)^{\otimes n} \right)_{\mathbf{B}'}\otimes\mathcal{H}_{\hat{\mathbf{B}}}\] such that \[\mathsf{Tr}\left(\left\langle{\sf EPR}\right|^{\otimes n}_{\mathbf{A}\mathbf{B}'}\left((I_{\mathbf{A}}\otimes\Phi_{\mathbf{B}})\left(\left|\psi\right\rangle_{\mathbf{A}\mathbf{B}}\left\langle\psi\right| \right) \right)\left|{\sf EPR}\right\rangle^{\otimes n}_{\mathbf{A}\mathbf{B}'} \right)=1-O\left(\varepsilon^{1/2} \right).\] Moreover, the isometry \(\Phi_\mathbf{B}\) can be implemented as an \(O(n)\)-size quantum circuit acting on \(\mathcal{H}_\mathbf{B}\) as well as some ancilla qubits, and that uses controlled gates for \(X^\mathbf{B}(a)\) and \(Z^\mathbf{B}(b)\) (controlled on an ancilla register of dimension \(2^n\) that contains \(a\) or \(b\)) as black boxes. Precisely, \(\Phi^\mathbf{B}\) is defined by \[\Phi_\mathbf{B}\left|\phi\right\rangle_\mathbf{B}=\left(\frac{1}{2^n}\sum_{a,b}X^\mathbf{B}(a)Z^\mathbf{B}(b)\otimes\sigma_X(a)\sigma_Z(b)\otimes I \right)\left|\phi\right\rangle_\mathbf{B}\left|{\sf EPR}\right\rangle^{\otimes n},\] and letting \(\mathcal{H}_{\hat{\mathbf{B}}}=\mathcal{H}_\mathbf{B}\otimes\left(\mathbb{C}^2 \right)^{\otimes n}\), with register \(\mathbf{B}'\) associated with the last \(n\) copies of \(\mathbb{C}^2\).

Corollary 2 (EPR Pair Rigidity (corollary)). Let \(\left|\psi\right\rangle_{\mathbf{A}\mathbf{B}}\in\left(\mathbb{C}^2 \right)^{\otimes n}_{\mathbf{A}}\otimes\mathcal{H}_{\mathbf{B}}\), where \(\mathcal{H}_{\mathbf{B}}\) is arbitrary. Let \(\widetilde{\mathbf{B}}\) be the sub-register of \(\mathbf{B}\) containing the first \(n\) qubits and define: \[\Pi_{\sf eq}=\sum_{x\in\mathbb{F}_2^n}\left|x\right\rangle_\mathbf{A}\left\langle x\right|\otimes\left|x\right\rangle_{\widetilde{\mathbf{B}}}\left\langle x\right|\otimes I_{\widetilde{\mathbf{B}}'}.\] Suppose that there exists two isometries \(\mathcal{U}_X^\mathbf{B},\mathcal{U}_Z^\mathbf{B}:\mathcal{H}_\mathbf{B}\rightarrow\mathcal{H}_{\widetilde{\mathbf{B}}}\otimes\mathcal{H}_{\widetilde{\mathbf{B}}'}\) such that \[\left|\Pi_{\sf eq}(I_\mathbf{A}\otimes \mathcal{U}_Z^\mathbf{B})\left|\psi\right\rangle\right|^2\geq 1-\varepsilon\quad\text{ and }\quad\left|\Pi_{\sf eq}(H^{\otimes n}_\mathbf{A}\otimes \mathcal{U}_X^\mathbf{B})\left|\psi\right\rangle\right|^2\geq 1-\varepsilon.\]Then there exists an isometry \[\Phi_\mathbf{B}:\mathcal{H}_{\mathbf{B}}\rightarrow\left(\left(\mathbb{C}^2 \right)^{\otimes n} \right)_{\mathbf{B}'}\otimes\mathcal{H}_{\hat{\mathbf{B}}}\] such that \[\mathsf{Tr}\left(\left\langle{\sf EPR}\right|^{\otimes n}_{\mathbf{A}\mathbf{B}'}\left((I_{\mathbf{A}}\otimes\Phi_{\mathbf{B}})\left(\left|\psi\right\rangle_{\mathbf{A}\mathbf{B}}\left\langle\psi\right| \right) \right)\left|{\sf EPR}\right\rangle^{\otimes n}_{\mathbf{A}\mathbf{B}'} \right)=1-O\left(\varepsilon^{1/2} \right).\] Moreover, the isometry \(\Phi_\mathbf{B}\) can be implemented as an \(O(n)\)-size quantum circuit acting on \(\mathcal{H}_\mathbf{B}\) as well as some ancilla qubits, and that uses controlled gates for \(\mathcal{U}_X^\mathbf{B}\) and \(\mathcal{U}_Z^\mathbf{B}\) as black boxes.

Proof. We construct observables \(W^\mathbf{B}(a)\) in 13 using \(U_X^\mathbf{B}\) and \(U_Z^\mathbf{B}\). Let (we abuse the notation of \(\mathcal{U}^\dagger\) to mean the reverse procedure of \(\mathcal{U}\)) \[W^\mathbf{B}(a)=\left(\mathcal{U}_W^\mathbf{B} \right)^{\dagger}\left(\sigma_W^{\widetilde{\mathbf{B}}}(a)\otimes I_{\widetilde{\mathbf{B}}'} \right)\mathcal{U}_W^\mathbf{B}\quad\forall W\in\left\{X,Z\right\}.\] We have \[\begin{align} \left|\Pi_{\sf eq}(I_\mathbf{A}\otimes U_Z)\left|\psi\right\rangle\right|^2\geq 1-\varepsilon\Rightarrow& \mathop{\mathbb{E}}_{a}\left[\left(\sigma_Z^{\mathbf{A}}(a)-Z^{\mathbf{B}}(a) \right)\left|\psi\right\rangle\right]^2\leq\varepsilon\\ \left|\Pi_{\sf eq}(H_\mathbf{A}^{\otimes n}\otimes U_X)\left|\psi\right\rangle\right|^2\geq 1-\varepsilon\Rightarrow& \mathop{\mathbb{E}}_{a}\left[\left(\sigma_X^{\mathbf{A}}(a)-X^{\mathbf{B}}(a) \right)\left|\psi\right\rangle\right]^2\leq\varepsilon. \end{align}\] By 13, we obtain the result. ◻

Definition 6 (Multi-Stage Independent Monogamy-of-Entanglement Game). Let \({\sf{\lambda}}\in\mathbb{N}\) be the security parameter and let \(n({\sf{\lambda}})\), \(m({\sf{\lambda}})\) be polynomials. Consider the following game between the challenger and an adversary \(\mathcal{A}=\allowdisplaybreaks(\mathcal{A}_M^0,\mathcal{A}_M^1,\mathcal{A}_M^2,\mathcal{A}_L^0,\mathcal{A}_L^1,\mathcal{A}_R^0,\mathcal{A}_R^1)\):

  1. The challenger generates \(\left({\sf sk},\left|\Psi^{{\sf sk}}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}(1^{\sf{\lambda}})\) and gives the register \(\text{\faShip}\) to \(\mathcal{A}^0_M\). It additionally samples \(\theta_0,\theta_1\overset{\$}{\gets}\left\{0,1\right\}\) and gives \(\theta_0,\theta_1\) to \(\mathcal{A}_M^0\). All parties of the adversary are given oracle access to \(\mathcal{O}_{T+v}\) and \(\mathcal{O}_{S^\perp+u}\). Let \(C_0=T+v\) and \(C_1=S^\perp+u\).

  2. \(\mathcal{A}_M^0\) can choose to abort in this step. If it aborts, the output of the game is \(\bot\). Otherwise, it generates a tripartite state on \(\mathbf{L}\mathbf{M}\mathbf{R}\). It sends \(\mathbf{L}\) to \(\mathcal{A}_L^0\), sends \(\mathbf{M}\) to \(\mathcal{A}_M^1\) and sends \(\mathbf{R}\) to \(\mathcal{A}_R^0\).

  3. The challenger samples \(b_0\overset{\$}{\gets}\mathbb{F}_2^m\), and gives \(\mathcal{A}_M^1\) oracle access to \(\mathcal{O}_{C_{\theta_0}}^{b_0}\). Then, \(\mathcal{A}_M^1\) on \(\mathbf{M}\) generates a tripartite state on \(\mathbf{M}_L\mathbf{M}'\mathbf{M}_R\). It sends \(\mathbf{M}_L\) to \(\mathcal{A}_L^0\), sends \(\mathbf{M}'\) to \(\mathcal{A}_M^2\) and sends \(\mathbf{M}_R\) to \(\mathcal{A}_R^0\). We will name the time just after all operations of \(\mathcal{A}_M^1\) are done and before renaming the registers and splitting them as BeforeSplit.

  4. \(\mathcal{A}_L^0\) and \(\mathcal{A}_R^0\) are given access to \(\mathcal{O}_{C_{\theta_0}}^{b_0}\). \(\mathcal{A}_L^0\) on \(\mathbf{L}\mathbf{M}_L\) produces answer \(b_0^l\) and a state on register \(\mathbf{L}'\) that is sent to \(\mathcal{A}_L^1\). \(\mathcal{A}_R^0\) on \(\mathbf{R}\mathbf{M}_R\) produces answer \(b_0^r\) and a state on register \(\mathbf{R}'\) that is sent to \(\mathcal{A}_R^1\).

  5. The challenger samples \(b_1\overset{\$}{\gets}\mathbb{F}_2^m\) gives \(\mathcal{A}_M^2\) oracle access to \(\mathcal{O}_{C_{\theta_0}}^{b_0}\) and \(\mathcal{O}_{C_{\theta_1}}^{b_1}\). It generates a bipartite state on \(\mathbf{M}'_L\mathbf{M}'_R\). \(\mathbf{M}'_L\) is given to \(\mathcal{A}_L^1\) and \(\mathbf{M}'_R\) is given to \(\mathcal{A}_R^1\).

  6. \(\mathcal{A}_L^1\) and \(\mathcal{A}_R^1\) are given access to \(\mathcal{O}_{C_{\theta_0}}^{b_0}\) and \(\mathcal{O}_{C_{\theta_1}}^{b_1}\). \(\mathcal{A}_L^1\) on \(\mathbf{L}'\mathbf{M}'_L\) generates the answer \(b_1^l\). \(\mathcal{A}_R^1\) on \(\mathbf{R}'\mathbf{M}'_R\) generates the answer \(b_1^r\). The adversary wins iff \(b_0^l=b_0^r=b_0\) and \(b_1^l=b_1^r=b_1\).

Let \({\sf MultiStageIndependentMonogamy}(\mathcal{A},1^{\sf{\lambda}})\) be the random variable that takes value \(1/0/\bot\) if the adversary \(\mathcal{A}\) wins/loses/aborts in the above game, respectively.

Theorem 29. Let \(n({\sf{\lambda}})\geq{\sf{\lambda}}\) and \(m_0({\sf{\lambda}})=m_1({\sf{\lambda}})=m({\sf{\lambda}})\geq{\sf{\lambda}}\) be polynomials of \({\sf{\lambda}}\). There exists an efficient extractor \(\mathcal{E}\) with access to \({\sf sk}\) and the register \(\mathbf{M}\) such that the following holds. Take any adversary \(\mathcal{A}\) in the multi-stage monogamy-of-entanglement game described in 4 such that \[{\sf{Pr}}\left[{\sf MultiStageIndependentMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]=\varepsilon'({\sf{\lambda}})\] and \[\frac{{\sf{Pr}}\left[{\sf MultiStageIndependentMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1\right]}{{\sf{Pr}}\left[{\sf MultiStageIndependentMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot\right]}=1-\varepsilon({\sf{\lambda}})\] for inverse polynomials \(\varepsilon({\sf{\lambda}}),\varepsilon'({\sf{\lambda}})\). Then running \(\mathcal{E}^{\mathcal{A}_M^1}\) on the state \(\mathbf{M}\) conditioned on \(\mathcal{A}_M^0\) not aborting extracts a state on \(\text{\faAnchor}\mathbf{X}\) that is very close to \(n\) \({\sf EPR}\)-pairs. More specifically, with \(\mathbf{X}\) denoting the output register of \(\mathcal{E}^{\mathcal{A}_M^1}\), \[\mathop{\mathbb{E}}\left[\mathsf{Tr}\left(\left\langle{\sf EPR}\right|_{\text{\faAnchor}\mathbf{X}}^{\otimes n}\mathcal{E}^{\mathcal{A}_M^1}\rho_{\mathbf{X}\mathbf{M}}\left(\mathcal{E}^{\mathcal{A}_M^1} \right)^\dagger\left|{\sf EPR}\right\rangle_{\text{\faAnchor}\mathbf{X}}^{\otimes n} \right)\middle\vert\subarray{c}\left({\sf sk},\left|\Psi^{{\sf sk}}\right\rangle_{\text{\faAnchor}\text{\faShip}} \right)\gets{\sf GenAnchorState}(1^{\sf{\lambda}})\\ \mathcal{A}_M^0\text{ does not abort and produces }\rho_{\mathbf{X}\mathbf{M}}\text{ on }\mathbf{X}\mathbf{M}\endsubarray\right]\geq 1-O\left(\varepsilon^{1/4} \right).\] Furthermore, \(\mathcal{E}^{\mathcal{A}_M^1}\) only makes black-box access to \(\mathcal{A}_M^1\) and acts on \(\mathbf{M}\). When we say \(\mathcal{A}_M^1\), we refer to the process only up to BeforeSplit, excluding the renaming and splitting procedure.

Proof. Note that the game MultiStageIndependentMonogamy is just a MultiStageSearchMonogamy with \(\frac{1}{4}\) probability, DualMultiStageSearchMonogamy with \(\frac{1}{4}\) and something else with \(\frac{1}{2}\) probability. So such adversary \(\mathcal{A}\) must succeed in MultiStageSearchMonogamy and DualMultiStageSearchMonogamy with probability at least \(1-4\varepsilon\). We can obtain two extractors \(\mathcal{E}_S^{\mathcal{A}_M^1}\) and \(\mathcal{E}_H^{\mathcal{A}_M^1}\) that, with probability \(1-O\left(\varepsilon^{1/2} \right)-{\sf negl}({\sf{\lambda}})\), extract the standard basis measurement and the Hadamard basis measurement by 12 and 1. Then by 2, we can construct \(\mathcal{E}^{\mathcal{A}_M^1}\) from \(\mathcal{E}_S^{\mathcal{A}_M^1}\) and \(\mathcal{E}_H^{\mathcal{A}_M^1}\). ◻

8 Warmup: Localizing Entanglement in the High-Success-Probability Regime↩︎

In this section, we present a warmup to the main results of the paper — a protocol allowing us to localize EPR-pair halves to within some small region of spacetime, built and proven secure using the techniques developed in the previous sections. This is a simplified variant of the entanglement localization protocol in 9.1, with the latter being a sequentially repeated version of the former. Sequential repetition will allow us to amplify extraction fidelity, even in the low-success-probability regime.

The definition and subsequent construction in this section will have a weaker form of extraction soundness than in the main result. In 9.1, we give a stronger, more general definition accompanied by a construction which satisfies it, needing no additional assumptions.

Definition 7 (Entanglement Localization, warmup version). An entanglement localization scheme consists of the following syntax:

  • \({\sf Setup}(1^{\sf{\lambda}})\to{\sf{pp}},\mathsf{sp},\mathbf{A},\mathbf{B}\): The setup algorithm takes the security parameter \(1^{\sf{\lambda}}\) and outputs the public parameters \({\sf{pp}}\), the secret parameters \(\mathsf{sp}\), and a state on the bipartite register \(\mathbf{A}\mathbf{B}\).

  • \(\mathsf{Localize}\left(\mathcal{P}(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L,t)\rightarrow \mathbf{B}',b\): This is a positional protocol between a QPT prover holding a quantum register \(\mathbf{B}\) and a PPT11 verifier with input \(\mathsf{sp}\), further specified by public inputs \({\sf{pp}}\) and the claimed location \((L,t)\). The prover’s output is a quantum register \(\mathbf{B}'\) and the verifier’s output is an acceptance indicator \(b\in\{\top,\bot\}\).

It should satisfy the following properties — parameterized by completeness probability \(\alpha({\sf{\lambda}})\), extraction fidelity \(\beta({\sf{\lambda}},\eta)\), and localization parameter \(\Delta({\sf{\lambda}})\) — for all \({\sf{\lambda}}\in\mathbb{N}\).

  • \(\alpha\)-Completeness: For any location \(L\) and time \(t\), there is a QPT prover \(\mathcal{P}\) at position \((L,t)\) such that \[\Pr\left[b = \top : \begin{array}{r} {\sf{pp}},\mathsf{sp},\mathbf{A},\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}}) \\ \mathbf{B}',b \gets \mathsf{Localize}\left(\mathcal{P}(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L,t)\end{array}\right] \geq\alpha({\sf{\lambda}}).\]

  • \((\beta,\Delta)\)-Extraction Soundness: For any \(L,t\) and QPT prover \(\mathcal{P}^*\), let \[1-\eta({\sf{\lambda}}):=\Pr\left[b = \top : \begin{array}{r} {\sf{pp}},\mathsf{sp},\mathbf{A},\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}}) \\ \mathbf{B}',b \gets \mathsf{Localize}\left(\mathcal{P}^*(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L,t)\end{array}\right]\] be the probability that \(\mathcal{P}^*\) passes the verification. Then there exists a (potentially unbounded, see 30) local extractor \(\mathcal{E}\) that extracts \(\left|{\sf EPR}\right\rangle^{\otimes n}\) from registers near location \(L\) at time \(t\) with fidelity at least \(\beta({\sf{\lambda}},\eta)\): \[\mathop{\mathbb{E}}\left[\left\langle{\sf EPR}\right|^{\otimes n}_{\mathbf{A}\mathbf{B}^*}\rho_{\mathbf{A}\mathbf{B}^*}\left|{\sf EPR}\right\rangle^{\otimes n}_{\mathbf{A}\mathbf{B}^*}:\begin{array}{r}{\sf{pp}},\mathsf{sp},\mathbf{A},\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}})\\ \mathbf{B}^*\gets\mathsf{register}[L_\Delta~@~t]\left(\mathsf{Localize}\left(\mathcal{P}^*(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L,t) \right)\\\mathbf{B}^*\gets\mathcal{E}({\sf{pp}},\mathbf{B}^*)\end{array}\right] \geq \beta({\sf{\lambda}},\eta)~,\] where \(\rho_{\mathbf{A}\mathbf{B}^*}\) is the joint state on \(\mathbf{A}\mathbf{B}^*\) after running the extractor, and \(L_\Delta=[L-\Delta,L+\Delta]\). Here we overload the notation \(\mathbf{B}^*\), meaning that we update the register \(\mathbf{B}^*\) by applying a channel to it.

We say that the entanglement localization scheme is non-destructive if it additionally satisfies the following property.

  • \(\boldsymbol{Non-destructive}\): For any spatial location \(L\) and time \(t\), \[\mathop{\mathbb{E}}\left[{\mathop{\mathrm{TD}}\left(\rho_{\mathbf{A}\mathbf{B}}, \rho_{\mathbf{A}\mathbf{B}'}\right)}:\begin{array}{r}{\sf{pp}},\mathsf{sp},\mathbf{A},\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}})\\ \mathbf{B}',b \gets \mathsf{Localize}\left(\mathcal{P}(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L,t)\end{array}\right] \leq {\sf negl}({\sf{\lambda}})~,\] where \(\rho_{\mathbf{A}\mathbf{B}}\) is the joint state on \(\mathbf{A}\mathbf{B}\) after \({\sf Setup}\) and \(\rho_{\mathbf{A}\mathbf{B}'}\) is the joint state on \(\mathbf{A}\mathbf{B}'\) later after \(\mathsf{Localize}\).

Remark 30. Note that this definition does not require the extractor \(\mathcal{E}\) to be efficient. That is, \(\mathcal{E}\) can run for unbounded time, and, in the oracle model, can make unbounded queries to its oracle. This is still meaningful, as entanglement is an information-theoretic notion that cannot be duplicated even given unbounded time. Moreover, the extractor never runs in the real world — only in the analysis. Nevertheless, we note that our extractor is efficient if additionally given an “extraction key” \({\sf ek}\) that is sampled by \({\sf Setup}\) (but not known to the prover). In our construction, \({\sf ek}=(S,T,v,u)\). We mention this here because efficient extraction given \({\sf ek}\) may be a useful feature, depending on the application.

Construction 31 (Entanglement Localization, warmup version). Let \({\sf{\lambda}}\in\mathbb{N}\) be the security parameter and \(n({\sf{\lambda}}),m({\sf{\lambda}})\geq{\sf{\lambda}}\) be polynomials. Take some localization parameter \(\Delta({\sf{\lambda}})\). We consider the following non-destructive entanglement localization scheme:

  • \({\sf Setup}(1^{\sf{\lambda}})\):

    1. Sample a uniform random subspace \(T\leq\mathbb{F}_2^{3n}\) of dimension \(2n\) and sample a uniform random subspace \(S\leq T\) of dimension \(n\). Sample two uniform random vectors \(u\in S\) and \(v\in T^\perp\).

    2. The public oracle \(\mathcal{O}:\{0,1\}\times\mathbb{F}_2^{\sf{\lambda}}\times\mathbb{F}_2^{3n}\rightarrow\mathbb{F}_2^m\cup\left\{\bot\right\}\) is based on a random oracle \(\mathcal{O}_{\sf random}:\{0,1\}\times\mathbb{F}_2^{\sf{\lambda}}\rightarrow \mathbb{F}_2^m\) that is not publicly available. \[\mathcal{O}(\theta,x,z)=\left\{ \begin{align} &\mathcal{O}_{\sf random}(\theta,x) \quad &\text{if }\theta=0\text{ and }z\in T+v,\\ &\mathcal{O}_{\sf random}(\theta,x) \quad &\text{if }\theta=1\text{ and }z\in S^\perp+u,\\ &\bot \quad &\text{otherwise} \end{align} \right.\]

    Then it generates \(\left|\Psi^{\sf sk}\right\rangle_{\mathbf{A}\mathbf{B}}\) and outputs:

    • The public parameters \({\sf{pp}}=\mathcal{O}\).

    • The secret parameters \(\mathsf{sp}=(u,v)\). This is given to the verifiers \(\mathcal{V}_L\) and \(\mathcal{V}_R\).

    • The anchor state \(\left|\Psi^{\sf sk}\right\rangle_{\mathbf{A}\mathbf{B}}\) where \(\mathbf{A}\) corresponds to the anchor register (\(\text{\faAnchor}\)) and \(\mathbf{B}\) corresponds to the vessel register (\(\text{\faShip}\)).

  • \(\mathsf{Localize}\left(\mathcal{P}(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L,t)\): Let \(\delta=\Delta/2\).

    • For \(i=0,1\), \(\mathcal{V}_L\) samples \(\theta_i\overset{\$}{\gets}\left\{0,1\right\}\) and \(x_{L,i}\overset{\$}{\gets}\mathbb{F}_2^{\sf{\lambda}}\) and broadcasts the pair at time \(t+i\delta-(L+1)\) It expects responses \(y_{L,i}\) at time \(t+i\delta+(L+1)\) for \(i=0,1\).

    • For \(i=0,1\), \(\mathcal{V}_R\) samples \(x_{R,i}\overset{\$}{\gets}\mathbb{F}_2^{\sf{\lambda}}\) and broadcasts it at time \(t+i\delta-(1-L)\) for \(i=0,1\). It expects responses \(y_{R,i}\) at time \(t+i\delta+(1-L)\).

    • If any of these responses is missing, the verifier outputs \(\bot\). Otherwise, the verifier outputs \(\top\) if and only if for each \(i\in\{0,1\}\), one of the following holds:

      • \(\theta_i=0\) and \(y_{L,i}=y_{R,i}=\mathcal{O}(0,x_{L,i}\oplus x_{R,i},v)\).

      • \(\theta_i=1\) and \(y_{L,i}=y_{R,i}=\mathcal{O}(1,x_{L,i}\oplus x_{R,i},u)\).

    • The honest prover consists of a single party always holding the \(\mathbf{B}\) register. For each \(i\in\{0,1\}\), it does the following:

      • Receive \(x_{L,i},x_{R,i}\) at time \(t+i\delta\). If \(\theta_i=0\), it coherently evaluates \(\mathcal{O}(0,x_{L,i}\oplus x_{R,i},\cdot)\) on the \(\mathbf{B}\) register and broadcasts the result. Otherwise if \(\theta_i=1\), it first applies the hadamard transform \(H^{\otimes n}\) to the \(\mathbf{B}\) register, then coherently evaluates \(\mathcal{O}(1,x_{L,i}\oplus x_{R,i},\cdot)\) and broadcasts the result, finally transforming \(\mathbf{B}\) back to the standard basis with a second \(H^{\otimes n}\).

Theorem 32 (NDEL security, warmup version). The construction in 31 is a non-destructive entanglement localization scheme with \(1\)-Completeness and \(\left(\beta,\Delta \right)\)-Extraction Soundness, where \[\beta({\sf{\lambda}},\eta)=1-O\!\left(\eta({\sf{\lambda}})^{1/4}\right)-{\sf negl}({\sf{\lambda}}).\]

Proof. For completeness, by 7, the standard basis measurement on \(\mathbf{B}\) will always give a vector in \(T+v\) and the Hadamard basis measurement on \(\mathbf{B}\) will always give a vector in \(S^\perp+u\). Thus, the coherent query result will be \(y_i=\mathcal{O}_{\sf random}(\theta_i,x_{L,i}\oplus x_{R,i})\) with probability \(1\). From there, non-destructiveness also follows, by an application of gentle measurement.

For extraction soundness, suppose that there exists a prover \(\mathcal{P}^*\) that passes localize experiment at a point \((L,t_0)\) with probability \(1-\eta\). We will turn \(\mathcal{P}^*\) into a prover \(\mathcal{A}=(\mathcal{A}_M^0,\mathcal{A}_M^1,\mathcal{A}_L^0,\mathcal{A}_R^0,\mathcal{A}_M^2,\mathcal{A}_L^1,\mathcal{A}_R^1)\) for the MultiStageIndependentMonogamy game, by chunking the execution of \(\mathcal{P}^*\) according to its spacetime geometry. This is pictured in 10. Let \(r({\sf{\lambda}})\) be the total number of queries to all oracles that \(\mathcal{P}^*\) makes (from any location and at any time), then let \(\left\{F_k:\left\{0,1\right\}\times\mathbb{F}_2^{\sf{\lambda}}\rightarrow\mathbb{F}_2^m\right\}_{k}\) be a family of \(2r\)-wise independent hash functions. Let \(\delta:=\Delta/2\), \(t_0=t\), and \(t_1:=t+\delta\). For notational clarity, we overload \(p,t\) to refer to position and time axes, respectively. We construct each component of \(\mathcal{A}\) as follows:

  1. \(\mathcal{A}_M^0\) receives register \(\mathbf{B}:=\text{\faShip}\), bases \(\theta_0,\theta_1\), and membership oracles \(\mathcal{O}_{C_0}\) and \(\mathcal{O}_{C_1}\) (where \(C_0=T+v\) and \(C_1=S^\perp+u\), as in 6) from the challenger. It then prepares to simulate the localization experiment by sampling a hash function \(F_k\) and secret-shared challenges \(x_{L,0},x_{R,0},x_{L,1},x_{R,1}\). Define \(\mathsf{info}:=(k,\theta_0,\theta_1,x_{L,0},x_{R,0},x_{L,1},x_{R,1})\).

    \(\mathcal{A}_M^0\) then begins simulating \(\mathcal{P}^*\) on input \(\mathbf{B}\), answering all of \(\mathcal{P}^*\)’s queries to \(\mathcal{O}\) as follows: a query \((\theta,x, z)\) is answered by checking membership in the corresponding coset using \(\mathcal{O}_{C_\theta}\), and then outputting \(F_k(\theta,x)\) in place of \(\mathcal{O}_{\sf random}(\theta,x)\) if the membership check passed. Crucially, \(\mathcal{P}^*\) is only simulated over a carefully chosen region of spacetime: \(\mathcal{A}_M^0\) freezes each of the simulated prover’s computations and messages just before they would touch the spacetime line \(t-p=t_0-L\) (on the right of \(L\)) or \(t+p=t_0+L\) (on the left of \(L\)). This cutoff is illustrated by a pair of dashed lines in 10. Let \(\mathbf{L}\) be the register that stores \(\mathsf{info}\) and all simulated parties/messages with \(p\in[-1,L-\delta]\) when the simulation ends. Similarly, let \(\mathbf{R}\) be the register that stores \(\mathsf{info}\) and all simulated parties/messages with \(p\in[L+\delta,1]\) when the simulation ends. Finally, let \(\mathbf{M}\) be the register that stores \(\mathsf{info}\) and all parties/messages with \(p\in[L-\delta,L+\delta]\) when the simulation ends.

  2. \(\mathcal{A}_M^1\) receives \(\mathbf{M}\) from \(\mathcal{A}_M^0\), and oracle access to \(\mathcal{O}^{b_0}_{C_{\theta_0}}\) from the challenger. It then resumes simulation of all of \(\mathcal{P}^*\)’s (real-time) computations and messages which would take place in the spacetime triangle – colored green in 10 – described by the constraints

    • \(t-p\geq t_0-L\);

    • \(t+p\geq t_0+L\);

    • \(t<t_1\),

    and halts simulation just before exiting this region. During this phase, the simulated oracle \(\mathcal{O}\) is reprogrammed so that on a query \((\theta,x,z)\) with \((\theta,x)=(\theta_0,x_{L,0}\oplus x_{R,0})\), \(\mathcal{A}_M^1\) answers with \(\mathcal{O}_{C_{\theta_0}}^{b_0}(z)\). Other oracle outputs not mentioned here are still simulated using the membership oracles and \(F_k\). Let \(\mathbf{M}_L\) be the register that stores all parties/messages with \(p\in[L-\delta,L)\) when the simulation ends. Similarly, let \(\mathbf{M}_R\) be the register that stores all parties/messages with \(p\in(L,L+\delta]\) when the simulation ends. Finally, let \(\mathbf{M}'\) be the register that stores \(\mathsf{info}\) and all parties/messages at the spacetime point \((L,t_1)\).

  3. \(\mathcal{A}_L^0\) receives \(\mathbf{L}\) from \(\mathcal{A}_M^0\), \(\mathbf{M}_L\) from \(\mathcal{A}_M^1\), and oracle access to \(\mathcal{O}^{b_0}_{C_{\theta_0}}\) from the challenger. It then resumes simulation of all of \(\mathcal{P}^*\)’s real-time computations and messages which would take place in the spacetime trapezoid – colored red in 10 – described by the constraints

    • \(p\ge -1\);

    • \(t\ge t_1\);

    • \(t+p\ge t_0+L\);

    • \(t+p<t_1+L\),

    and halts simulation just before exiting this region. During this simulation, \(\mathcal{O}\) is reprogrammed in the same way as for \(\mathcal{A}_M^1\). If the simulated prover did not send a classical message which would be received by \(\mathcal{V}_L\) at time \(t_0+L+1\), \(\mathcal{A}_L^0\) outputs \(\bot\). Otherwise, \(\mathcal{A}_L^0\) uses \(\mathcal{P}^*\)’s response message sent to \(\mathcal{V}_L\) as its output \(b_0^L\). Let \(\mathbf{L}'\) be the register that stores \(\mathsf{info}\) and all parties/messages with \(p\in[-1,L)\) when \(\mathcal{A}_L^0\)’s simulation ends.

  4. \(\mathcal{A}_R^0\) receives \(\mathbf{R}\) from \(\mathcal{A}_M^0\), \(\mathbf{M}_R\) from \(\mathcal{A}_M^1\), and oracle access to \(\mathcal{O}^{b_0}_{C_{\theta_0}}\) from the challenger. It then resumes simulation of all of \(\mathcal{P}^*\)’s real-time computations and messages which would take place in the spacetime trapezoid – colored blue in 10 – described by the constraints

    • \(p\le 1\);

    • \(t\ge t_1\);

    • \(t-p\ge t_0-L\);

    • \(t-p<t_1-L\),

    and halts simulation just before exiting this region. During this simulation, \(\mathcal{O}\) is reprogrammed in the same way as for \(\mathcal{A}_M^1\). If the simulated prover did not send a classical message which would be received by \(\mathcal{V}_R\) at time \(t_0+1-L\), \(\mathcal{A}_R^0\) outputs \(\bot\). Otherwise, \(\mathcal{A}_R^0\) uses \(\mathcal{P}^*\)’s response message sent to \(\mathcal{V}_R\) as its output \(b_0^R\). Let \(\mathbf{R}'\) be the register that stores \(\mathsf{info}\) and all parties/messages with \(p\in(L,1]\) when \(\mathcal{A}_R^0\)’s simulation ends.

  5. \(\mathcal{A}_M^2\) receives \(\mathbf{M}'\) from \(\mathcal{A}_M^1\), and oracle access to \(\mathcal{O}^{b_0}_{C_{\theta_0}}\) and \(\mathcal{O}^{b_1}_{C_{\theta_1}}\) from the challenger. It then resumes simulation of all of \(\mathcal{P}^*\)’s real-time computations and messages which would take place exactly at the point \((L,t_1)\). On top of reprogramming the oracle \(\mathcal{O}\) in the same way as for \(\mathcal{A}_M^1\), we add an additional change: on a query \((\theta,x,z)\) with \((\theta,x)=(\theta_1,x_{L,1}\oplus x_{R,1})\), it answers with \(\mathcal{O}^{b_1}_{C_{\theta_1}}(z)\). Let \(\mathbf{M}'_L\) be the register that stores all messages sent to the left from \(L\) at time \(t_1\). Similarly, let \(\mathbf{M}'_R\) be the register that stores all messages sent to the right from \(L\) at time \(t_1\).

  6. \(\mathcal{A}_L^1\) receives \(\mathbf{L}'\) from \(\mathcal{A}_L^0\), \(\mathbf{M}'_L\) from \(\mathcal{A}_M^2\), and oracle access to \(\mathcal{O}^{b_0}_{C_{\theta_0}}\) and \(\mathcal{O}^{b_1}_{C_{\theta_1}}\) from the challenger. It then resumes simulation of all of \(\mathcal{P}^*\)’s real-time computations and messages which would take place in the spacetime line segment described by

    • \(p\in[-1,L)\);

    • \(t+p=t_1+L\),

    and halts simulation just before exiting this region. \(\mathcal{O}\) is reprogrammed in the same way as for \(\mathcal{A}_M^2\). If the simulated prover did not send a classical message which would be received by \(\mathcal{V}_L\) at time \(t_1+L+1\), \(\mathcal{A}_L^1\) outputs \(\bot\). Otherwise, \(\mathcal{A}_L^1\) uses that response message as its output \(b_1^L\).

  7. \(\mathcal{A}_R^1\) receives \(\mathbf{R}'\) from \(\mathcal{A}_R^0\), \(\mathbf{M}'_R\) from \(\mathcal{A}_M^2\), and oracle access to \(\mathcal{O}^{b_0}_{C_{\theta_0}}\) and \(\mathcal{O}^{b_1}_{C_{\theta_1}}\) from the challenger. It then resumes simulation of all of \(\mathcal{P}^*\)’s real-time computations and messages which would take place in the spacetime line segment described by

    • \(p\in(L,1]\);

    • \(t-p=t_1-L\),

    and halts simulation just before exiting this region. \(\mathcal{O}\) is reprogrammed in the same way as for \(\mathcal{A}_M^2\). If the simulated prover did not send a classical message which would be received by \(\mathcal{V}_R\) at time \(t_1+1-L\), \(\mathcal{A}_R^1\) outputs \(\bot\). Otherwise, \(\mathcal{A}_R^1\) uses that response message as its output \(b_1^R\).

Figure 10: Spacetime decomposition of the prover \mathcal{A} for our localization reduction, shown with L=0.

Claim 33. For any prover \(\mathcal{P}^*\) that passes with probability \(1-\eta\), the probability that \(\mathcal{A}\) wins 6 is at least \(1-\eta-{\sf negl}\).

Proof. By [38], the \(2r\)-wise independent hash function perfectly simulates the random oracle for \(\mathcal{P}^*\). Also we can see that \(\mathcal{A}\) perfectly simulates \(\mathcal{P}^*\), since for any event simulated in \(\mathcal{A}\), all other events that can have a causal effect on that event have already been simulated. The only difference is that the oracle \(\mathcal{O}\) is reprogrammed twice, but by 1, the resulting experiment is negligibly close to the actual \(\mathsf{Localize}\) experiment. And there, \(\mathcal{P}^*\) eventually outputs \(y_{L,0}=y_{R,0}=\mathcal{O}_{\sf random}(\theta_0,x_{L,0}\oplus x_{R,0})\) and \(y_{L,1}=y_{R,1}=\mathcal{O}_{\sf random}(\theta_1,x_{L,1}\oplus x_{R,1})\) with probability \(1-\eta\). Therefore \(\mathcal{A}\) will produce the correct outputs \(b^L_0,b^R_0,b^L_1,b^R_1\) with probability \(1-\eta-{\sf negl}({\sf{\lambda}})\). ◻

By the above claim and 29, there exists an extractor \(\mathcal{E}^{\mathcal{A}_M^1}\) acting on \(\mathbf{M}\) with access to \(\mathcal{A}_M^1\) that extracts \(n\) \({\sf EPR}\) pairs within fidelity \[1-O\left(\eta^{1/4} \right)-{\sf negl}.\] Recall that \(\mathbf{M}\) is the joint register of all parties/messages with \(p\in[L-\delta,L+\delta]\) with \(t-t_0=|p-L|\), corresponding to the two bottom boundaries of the green triangle in 10. These registers can be derived from access to all parties/messages of \(\mathcal{P}^*\) in the spacetime region \([L-2\delta,L+2\delta]\times\{t_0\}\) by forward time-evolution, as pictured in the diagram. Note that this is exactly the extraction region \(L_\Delta~@~t_0\) from the definition, since \(2\delta=\Delta\). Now, let us define our final extractor \(\mathcal{E}\) that takes as input \({\sf{pp}}=\mathcal{O}\) and \(\mathsf{register}[L_\Delta~@~t_0]\) and outputs something close to \(\left|{\sf EPR}\right\rangle^{\otimes n}\). It does the following:

  • Recover the joint register \(\mathbf{M}\) via forward-simulation.

  • Recover the extraction key \({\sf ek}=(S,T,v,u)\) from \({\sf{pp}}\) by unbounded oracle queries, as discussed in 30, and run \(\mathcal{E}^{\mathcal{A}_M^1}\) on \(({\sf ek},\mathbf{M})\).

 ◻

9 Localizing Quantum Information↩︎

In this section, we present our formal definitions and constructions of the localization primitives mentioned in the introduction: entanglement localization, trajectory verification, state localization, and functionality localization. These definitions will have a stronger extraction soundness condition than was shown in the warmup, which is much more meaningful against low-success-probability adversaries. To achieve this stronger soundness, our constructions in this section employ a sequential repetition technique — each protocol is the sequential chaining of \(O(\gamma)\)-many two-round protocols.

9.1 Entanglement Localization↩︎

Definition 8 (Entanglement Localization). An entanglement localization scheme is parameterized by the security parameter \({\sf{\lambda}}\) and a bipartite state \(\sigma\)12. It consists of the following syntax:

  • \({\sf Setup}(1^{\sf{\lambda}})\to{\sf{pp}},\mathsf{sp},\mathbf{A},\mathbf{B}\): The setup algorithm takes the security parameter \(1^{\sf{\lambda}}\) and outputs the public parameters \({\sf{pp}}\), the secret parameters \(\mathsf{sp}\), and a state on the bipartite register \(\mathbf{A}\mathbf{B}\).

  • \(\mathsf{Localize}\left(\mathcal{P}(\mathbf{B}) \rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L,t)\rightarrow \mathbf{B}',b\): This is a positional protocol between a QPT prover holding a quantum register \(\mathbf{B}\) and a PPT verifier with input \(\mathsf{sp}\), further specified by the following public inputs: public parameters \({\sf{pp}}\), spatial location \(L \in [-1,1]\), and time \(t\). The prover’s output is a quantum register \(\mathbf{B}'\) and the verifier’s output is an acceptance indicator \(b\in\{\top,\bot\}\).

It should satisfy the following properties — parameterized by completeness probability \(\alpha({\sf{\lambda}})\), extraction fidelity \(\beta({\sf{\lambda}},\eta)\), extraction probability \(\beta'({\sf{\lambda}},\eta)\), and localization parameter \(\Delta({\sf{\lambda}})\) — for all \({\sf{\lambda}}\in\mathbb{N}\).

  • \(\alpha\)-Completeness: For any location \(L\) and time \(t\), there is a QPT prover \(\mathcal{P}\) at position \((L,t)\) such that \[\Pr\left[b = \top : \begin{array}{r} {\sf{pp}},\mathsf{sp},\mathbf{A},\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}}) \\ \mathbf{B}',b \gets \mathsf{Localize}\left(\mathcal{P}(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L,t)\end{array}\right] \geq\alpha({\sf{\lambda}}).\]

  • \((\beta,\beta',\Delta)\)-Extraction Soundness: For any \(L,t\) and QPT prover \(\mathcal{P}^*\), let \[\eta({\sf{\lambda}}):=\Pr\left[b = \top : \begin{array}{r} {\sf{pp}},\mathsf{sp},\mathbf{A},\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}}) \\ \mathbf{B}',b \gets \mathsf{Localize}\left(\mathcal{P}^*(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L,t)\end{array}\right]\] be \(\mathcal{P}^*\)’s success probability. Assume \(\eta({\sf{\lambda}})\ge 1/p({\sf{\lambda}})\) for some polynomial \(p\). Then there exists a local extractor \(\mathcal{E}\) acting on registers near location \(L\) at time \(t\) such that the probability of extracting \(\sigma_{\sf{\lambda}}\) with fidelity at least \(\beta({\sf{\lambda}},\eta)\) is at least \(\beta'({\sf{\lambda}},\eta)\): \[ {\sf{Pr}}\left[ F\big(\sigma_{\sf{\lambda}},\rho_{\mathbf{A}\mathbf{B}^*}\big)\ge \beta({\sf{\lambda}},\eta)~ : \begin{array}{r} {\sf{pp}},\mathsf{sp},\mathbf{A},\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}})\\ \mathbf{B}^*\gets\mathsf{register}[L_\Delta~@~t]\left(\mathsf{Localize}\left(\mathcal{P}^*(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L,t) \right)\\\mathbf{B}^*\gets\mathcal{E}({\sf{pp}},\mathbf{B}^*) \end{array} \right] \geq \beta'({\sf{\lambda}},\eta)~,\] where \(\rho_{\mathbf{A}\mathbf{B}^*}\) is the joint state on \(\mathbf{A}\mathbf{B}^*\) after running the extractor, and \(L_\Delta=[L-\Delta,L+\Delta]\).

We say that the entanglement localization scheme is non-destructive if it additionally satisfies the following property.

  • \(\boldsymbol{Non-destructive}\): For any spatial location \(L\) and time \(t\), \[\mathop{\mathbb{E}}\left[{\mathop{\mathrm{TD}}\left(\rho_{\mathbf{A}\mathbf{B}}, \rho_{\mathbf{A}\mathbf{B}'}\right)}:\begin{array}{r}{\sf{pp}},\mathsf{sp},\mathbf{A},\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}})\\ \mathbf{B}',b \gets \mathsf{Localize}\left(\mathcal{P}(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L,t)\end{array}\right] \leq {\sf negl}({\sf{\lambda}})~,\] where \(\rho_{\mathbf{A}\mathbf{B}}\) is the joint state on \(\mathbf{A}\mathbf{B}\) after \({\sf Setup}\) and \(\rho_{\mathbf{A}\mathbf{B}'}\) is the joint state on \(\mathbf{A}\mathbf{B}'\) later after \(\mathsf{Localize}\).

Construction 34 (Entanglement Localization Scheme). Let \({\sf{\lambda}}\in\mathbb{N}\) be the security parameter and \(n({\sf{\lambda}}),m({\sf{\lambda}})\geq{\sf{\lambda}}\) be polynomials. Take a localization parameter \(\Delta({\sf{\lambda}})\leq 1\) and a repetition factor \(\gamma({\sf{\lambda}})\). We consider the following non-destructive entanglement localization scheme:

  • There are two verifiers: \(\mathcal{V}_L\) at \(-1\) and \(\mathcal{V}_R\) at \(1\).

  • \({\sf Setup}(1^{\sf{\lambda}})\): Let the public oracle \(\mathcal{O}\) be generated as in the warmup construction.

    1. Generate \(\left({\sf sk},\left|\Psi^{\sf sk}\right\rangle_{\mathbf{A}\mathbf{B}} \right)\gets{\sf GenAnchorState}(1^{\sf{\lambda}})\), and let \(S,T,u,v\) be the subspaces and shifts determined by \({\sf sk}\). The extraction key is \({\sf ek}=(S,T,v,u)\), which is not given to the prover.

    2. The public oracle \(\mathcal{O}:\{0,1\}\times\mathbb{F}_2^{\sf{\lambda}}\times\mathbb{F}_2^{3n}\rightarrow\mathbb{F}_2^m\cup\left\{\bot\right\}\) is defined with respect to a random oracle \(\mathcal{O}_{\sf random}:\{0,1\}\times\mathbb{F}_2^{\sf{\lambda}}\rightarrow \mathbb{F}_2^m\) that is not publicly available: \[\mathcal{O}(\theta,x,z)=\left\{ \begin{align} &\mathcal{O}_{\sf random}(\theta,x) \quad &\text{if }\theta=0\text{ and }z\in T+v,\\ &\mathcal{O}_{\sf random}(\theta,x) \quad &\text{if }\theta=1\text{ and }z\in S^\perp+u,\\ &\bot \quad &\text{otherwise.} \end{align} \right.\]

    Then \({\sf Setup}\) outputs:

    • The public parameter \({\sf{pp}}=\mathcal{O}\).

    • The secret parameter \(\mathsf{sp}=(u,v)\), given to the verifiers.

    • The anchor state \(\left|\Psi^{\sf sk}\right\rangle_{\mathbf{A}\mathbf{B}}\), with \(\text{\faAnchor}\) renamed \(\mathbf{A}\) and \(\text{\faShip}\) renamed \(\mathbf{B}\).

  • \(\mathsf{Localize}\left(\mathcal{P}(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L,t)\): Let \(\delta=\Delta/(\gamma+2)\) and define checkpoints \(t_i=t+i\delta\) for \(i=0,1,\ldots,\gamma\).

    • For each \(i=0,1,\ldots,\gamma\), \(\mathcal{V}_L\) and \(\mathcal{V}_R\) agree through their private authenticated channel on \(\theta_i\overset{\$}{\gets}\{0,1\}\) and additive shares \(x_{L,i},x_{R,i}\overset{\$}{\gets}\mathbb{F}_2^{\sf{\lambda}}\). \(\mathcal{V}_L\) broadcasts \((\theta_i,x_{L,i})\) at time \(t_i-(L+1)\) and expects the response \(y_{L,i}\) at time \(t_i+(L+1)\). \(\mathcal{V}_R\) broadcasts \(x_{R,i}\) at time \(t_i-(1-L)\) and expects the response \(y_{R,i}\) at time \(t_i+(1-L)\).

    • If any response is missing, the verifier outputs \(\bot\). Otherwise, it accepts if and only if for every \(i=0,1,\ldots,\gamma\), \[y_{L,i}=y_{R,i}= \begin{cases} \mathcal{O}(0,x_{L,i}\oplus x_{R,i},v) & \text{if }\theta_i=0,\\ \mathcal{O}(1,x_{L,i}\oplus x_{R,i},u) & \text{if }\theta_i=1. \end{cases}\]

    • The honest prover consists of a single party always holding the \(\mathbf{B}\) register at location \(L\). For each \(i=0,1,\ldots,\gamma\), it receives \(x_{L,i},x_{R,i}\) at time \(t_i\). If \(\theta_i=0\), it coherently evaluates \(\mathcal{O}(0,x_{L,i}\oplus x_{R,i},\cdot)\) on the \(\mathbf{B}\) register in the standard basis and broadcasts the result. If \(\theta_i=1\), it coherently evaluates \(\mathcal{O}(1,x_{L,i}\oplus x_{R,i},\cdot)\) on the \(\mathbf{B}\) register in the Hadamard basis and broadcasts the result.

Theorem 35. The construction in 34 is a non-destructive entanglement localization scheme for the state \(\sigma=\left|{\sf EPR}\right\rangle\!\left\langle{\sf EPR}\right|^{\otimes n}\) in the classical oracle model with \(1\)-Completeness and \(\left(\beta,\beta',\Delta \right)\)-Extraction Soundness, where \[\beta({\sf{\lambda}},\eta)=1-O\!\left(\left(\frac{\log(1/\eta)}{\gamma}\right)^{1/4}\right)-{\sf negl}({\sf{\lambda}}), \qquad \beta'({\sf{\lambda}},\eta)=\eta({\sf{\lambda}}).\] In particular, since we only consider adversaries for which \(1/\eta\) is at most polynomial in \({\sf{\lambda}}\), for any polynomial \(t({\sf{\lambda}})\), we can set \(\gamma=c{\sf{\lambda}}t^4\) for some constant \(c\) to achieve \[\beta({\sf{\lambda}},\eta)\geq1-1/t({\sf{\lambda}})~.\]

Proof. Completeness follows from 7: the standard-basis measurement on \(\mathbf{B}\) always gives a vector in \(T+v\), and the Hadamard-basis measurement on \(\mathbf{B}\) always gives a vector in \(S^\perp+u\). Therefore the honest coherent query in every checkpoint returns \(\mathcal{O}_{\sf random}(\theta_i,x_{L,i}\oplus x_{R,i})\), and the verifier accepts. The same fact implies non-destructiveness, since the oracle response is constant on the coset supporting the honest prover’s state in the queried basis.

We prove extraction soundness. Let \(\mathcal{P}^*\) be accepted with probability \(\eta\). Let \(q_i\) denote the probability that \(\mathcal{P}^*\) passes checkpoint \(i\), conditioned on passing checkpoints \(0,\ldots,i-1\). Since \(\prod_{i=0}^{\gamma}q_i=\eta\), there exists an adjacent pair of checkpoints \(i^\star,i^\star+1\) such that \[q_{i^\star}q_{i^\star+1}\ge \eta^{2/\gamma}.\] Write \(t_0=t+i^\star\delta\) and \(t_1=t_0+\delta\). Conditioned on passing checkpoints \(0,\ldots,i^\star-1\), the checkpoints \(i^\star\) and \(i^\star+1\) form an identical experiment to the two-round localization test from 31. We therefore apply the same spacetime chunking reduction from the proof of 32, with the two target challenges at these checkpoints. As usual, the reduction \(\mathcal{A}\) simulates the hidden random oracle \(\mathcal{O}_{\sf random}\) by a \(2r({\sf{\lambda}})\)-wise independent function \(F_k\), where \(r\) is the number of oracle queries \(\mathcal{P}^*\) makes.

Importantly, due to the repetition, the first-stage reduction component \(\mathcal{A}^0_M\) must simulate the \(\mathsf{Localize}\) experiment from the beginning of time up through checkpoint \(i^\star-1\), thus ensuring that \(\mathcal{A}^0_M\) is non-aborting iff the simulated prover \(\mathcal{P}^*\) makes it to checkpoint \(i^\star\). To do this, \(\mathcal{A}^0_M\) samples challenges \((\theta_i,x_{L,i},x_{R,i})\) on its own and simulates the verifiers’ interactions with the prover as in \(\mathsf{Localize}\). If the prover responds with \(y_{L,i},y_{R,i}\) such that \(y_{L,i}\neq y_{R,i}\) or if \(y_{L,i}\neq F_k(\theta_i,x_{L,i}\oplus x_{R,i})\), \(\mathcal{A}_M^0\) aborts. The reduction reprograms \(\mathcal{O}\) only at \((\theta_{i^\star},x_{L,i^\star}\oplus x_{R,i^\star},\cdot)\) and \((\theta_{i^\star+1},x_{L,i^\star+1}\oplus x_{R,i^\star+1},\cdot)\); by 1, this changes the experiment by only a negligible amount. Thus the resulting MultiStageIndependentMonogamy adversary does not abort with probability at least \(\eta\) and wins, conditioned on not aborting, with probability at least \(q_{i^\star}q_{i^\star+1}-{\sf negl}({\sf{\lambda}})\).

Then by 29, there exists an extractor \(\mathcal{E}^{\mathcal{A}_M^1}_{i^\star}\) acting on the middle register \(\mathbf{M}\) for checkpoints \(i^\star,i^\star+1\), which with probability \(\geq\eta\) outputs a state having the following fidelity with \(\left|{\sf EPR}\right\rangle^{\otimes n}\): \[1-O\Big((1-q_{i^\star}q_{i^\star+1})^{1/4}\Big)-{\sf negl}.\] Since \(q_{i^\star}q_{i^\star+1}\ge \eta^{2/\gamma}\), this fidelity is at least \[1-O\!\left(\left(1-\eta^{2/\gamma}\right)^{1/4}\right)-{\sf negl}({\sf{\lambda}}) = 1-O\!\left(\left(\frac{\log(1/\eta)}{\gamma}\right)^{1/4}\right)-{\sf negl}({\sf{\lambda}}),\] where the last step uses \[1-\eta^{2/\gamma} = 1-\exp\!\left(-\frac{2\log(1/\eta)}{\gamma}\right) \leq \frac{2\log(1/\eta)}{\gamma}.\] It remains to translate the middle-register extractor into the extraction statement at the original time \(t\). Let \({\sf Exp}=\mathsf{Localize}(\mathcal{P}^*(\mathbf{B})\rightleftharpoons\mathcal{V}(\mathsf{sp}))({\sf{pp}},L,t)\) be the real localization experiment. The middle register \(\mathbf{M}\) is the same one used in the warmup proof: it lies on the two lower boundaries of the green triangle in 10 for the time \(t_0\). These registers can be derived from \(\mathsf{register}[L_{2\delta}~@~t_0]({\sf Exp})\) by forward simulation. Since \(t_0-t\le \gamma\delta\), recovering this \(2\delta\) neighborhood at time \(t_0\) from time \(t\) requires the region \[\mathsf{register}[L_{(\gamma+2)\delta}~@~t]({\sf Exp})=\mathsf{register}[L_\Delta~@~t]({\sf Exp}).\] The final extractor performs this forward simulation and then runs \(\mathcal{E}^{\mathcal{A}_M^1}_{i^\star}\). ◻

9.2 Trajectory Verification↩︎

Definition 9 (Trajectory Verification). A trajectory verification scheme is parameterized by the security parameter \({\sf{\lambda}}\) and a bipartite state \(\sigma\)13. It consists of the following syntax:

  • \({\sf Setup}(1^{\sf{\lambda}})\to{\sf{pp}},\mathsf{sp},\mathbf{A},\mathbf{B}\): The setup algorithm takes the security parameter \(1^{\sf{\lambda}}\) and outputs the public parameters \({\sf{pp}}\), secret parameters \(\mathsf{sp}\), and a state on the bipartite register \(\mathbf{A}\mathbf{B}\).

  • \(\mathsf{Localize}\left(\mathcal{P}(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp})\right)({\sf{pp}},L)\rightarrow \mathbf{B}',b\): The interactive verification protocol takes place between a QPT prover holding a quantum register \(\mathbf{B}\) and a PPT verifier with input \(\mathsf{sp}\). The public inputs are \({\sf{pp}}\) and the description of a continuous trajectory \(L:[0,\tau]\to[-1,1]\). \(L(t)\) is the prover’s purported location at any time \(0\leq t\leq \tau\), where \(\tau\) is some time limit included in the description of \(L\). The prover’s output is a quantum register \(\mathbf{B}'\) and the verifier’s output is an acceptance indicator \(b\in\{\top,\bot\}\).

It should satisfy the following properties — parameterized by completeness probability \(\alpha({\sf{\lambda}})\), extraction fidelity \(\beta({\sf{\lambda}},\eta)\), extraction probability \(\beta'({\sf{\lambda}},\eta)\), and localization parameter \(\Delta({\sf{\lambda}})\) — for all \({\sf{\lambda}}\in\mathbb{N}\).

  • \(\alpha\)-Completeness: For any valid trajectory \(L\), there is a QPT prover \(\mathcal{P}\) moving along \(L\) such that \[\Pr\left[b = \top : \begin{array}{r} {\sf{pp}},\mathsf{sp},\mathbf{A},\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}}) \\ \mathbf{B}',b \gets \mathsf{Localize}\left(\mathcal{P}(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L)\end{array}\right] \geq\alpha({\sf{\lambda}}).\]

  • \((\beta,\beta',\Delta)\)-Extraction Soundness: For any trajectory \(L\) and QPT prover \(\mathcal{P}^*\), let \[\eta({\sf{\lambda}}):=\Pr\left[b = \top : \begin{array}{r} {\sf{pp}},\mathsf{sp},\mathbf{A},\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}}) \\ \mathbf{B}',b \gets \mathsf{Localize}\left(\mathcal{P}^*(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L)\end{array}\right]\] be \(\mathcal{P}^*\)’s success probability in \(\mathsf{Localize}\). Assume \(\eta({\sf{\lambda}})\ge 1/p({\sf{\lambda}})\) for some polynomial \(p\). Then for any time \(t\in[0,\tau]\), there exists a (potentially unbounded, see 30) local extractor \(\mathcal{E}\) acting on registers near the claimed trajectory at time \(t\) such that the probability of extracting \(\sigma\) with fidelity at least \(\beta({\sf{\lambda}},\eta)\) is at least \(\beta'({\sf{\lambda}},\eta)\): \[ {\sf{Pr}}\left[ F\big(\sigma,\rho_{\mathbf{A}\mathbf{B}^*}\big)\ge \beta({\sf{\lambda}},\eta) : \begin{array}{r} {\sf{pp}},\mathsf{sp},\mathbf{A},\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}})\\ \mathbf{B}^*\gets\mathsf{register}[(L(t))_\Delta~@~t]\left(\mathsf{Localize}\left(\mathcal{P}^*(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L) \right)\\ \mathbf{B}^*\gets\mathcal{E}({\sf{pp}},\mathbf{B}^*) \end{array} \right] \geq \beta'({\sf{\lambda}},\eta)~,\] where \(\rho_{\mathbf{A}\mathbf{B}^*}\) is the joint state on \(\mathbf{A}\mathbf{B}^*\) after running the extractor \(\mathcal{E}\), and \((L(t))_\Delta=[L(t)-\Delta,L(t)+\Delta]\).

Now we present a construction for trajectory verification.

Construction 36 (Trajectory Verification Scheme). Let \({\sf{\lambda}}\in\mathbb{N}\) be the security parameter and \(n({\sf{\lambda}}),m({\sf{\lambda}})\geq{\sf{\lambda}}\) be polynomials. Take some localization parameter \(\Delta({\sf{\lambda}})\leq 1\) and a repetition factor \(\gamma({\sf{\lambda}})\). We consider the following trajectory verification scheme:

  • There are two verifiers: \(\mathcal{V}_L\) at \(-1\) and \(\mathcal{V}_R\) at \(1\).

  • \({\sf Setup}(1^{\sf{\lambda}})\): Let the public oracle \(\mathcal{O}\) be generated as in the warmup construction.

    1. Generate \(\left({\sf sk},\left|\Psi^{\sf sk}\right\rangle_{\mathbf{A}\mathbf{B}} \right)\gets{\sf GenAnchorState}(1^{\sf{\lambda}})\), and let \(S,T,u,v\) be the subspaces and shifts determined by \({\sf sk}\). The extraction key is \({\sf ek}=(S,T,v,u)\), which is not given to the prover.

    2. The public oracle \(\mathcal{O}:\left\{0,1\right\}\times\mathbb{F}_2^{\sf{\lambda}}\times\mathbb{F}_2^{3n}\rightarrow\mathbb{F}_2^m\cup\left\{\bot\right\}\) is defined with respect to a random oracle \(\mathcal{O}_{\sf random}:\{0,1\}\times\mathbb{F}_2^{\sf{\lambda}}\rightarrow \mathbb{F}_2^m\) that is not publicly available. \[\mathcal{O}(\theta,x,z)=\left\{ \begin{align} &\mathcal{O}_{\sf random}(\theta,x) \quad &\text{if }\theta=0\text{ and }z\in T+v,\\ &\mathcal{O}_{\sf random}(\theta,x) \quad &\text{if }\theta=1\text{ and }z\in S^\perp+u,\\ &\bot \quad &\text{otherwise} \end{align} \right.\]

    Then \({\sf Setup}\) outputs:

    • The public parameter \({\sf{pp}}=\mathcal{O}\).

    • The secret parameter \(\mathsf{sp}=(u,v)\), given to the verifiers.

    • The anchor state \(\left|\Psi^{\sf sk}\right\rangle_{\mathbf{A}\mathbf{B}}\), with \(\text{\faAnchor}\) renamed \(\mathbf{A}\) and \(\text{\faShip}\) renamed \(\mathbf{B}\).

  • \(\mathsf{Localize}\left(\mathcal{P}(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp})\right)({\sf{pp}},L)\): Suppose the claimed trajectory is \(L(t)\) with \(t\in[0,\tau]\). Let \(\delta=\Delta/(\gamma+2)\), let \(N:=\lceil \tau/\delta\rceil+\gamma\), and define an extended trajectory14 \(\widetilde{L}(s):=L(\min\{s,\tau\})\).

    • At the start of the protocol, \(\mathcal{V}_L\) and \(\mathcal{V}_R\) agree through their private authenticated channel on \(\theta_i\overset{\$}{\gets}\left\{0,1\right\}\) and additive shares \(x_{L,i},x_{R,i}\overset{\$}{\gets}\mathbb{F}_2^{\sf{\lambda}}\) for every \(i=0,1,\cdots,N\).

    • For each \(i=0,1,\cdots,N\), \(\mathcal{V}_L\) broadcasts \((\theta_i,x_{L,i})\) at time \(i\delta-(\widetilde{L}(i\delta)+1)\) and expects the response \(y_{L,i}\) at time \(i\delta+(\widetilde{L}(i\delta)+1)\). Similarly, \(\mathcal{V}_R\) broadcasts \(x_{R,i}\) at time \(i\delta-(1-\widetilde{L}(i\delta))\) and expects the response \(y_{R,i}\) at time \(i\delta+(1-\widetilde{L}(i\delta))\).

    • If any response is missing, the verifier outputs \(\bot\). Otherwise, it accepts if and only if for every \(i=0,1,\cdots,N\), \[y_{L,i}=y_{R,i}= \begin{cases} \mathcal{O}(0,x_{L,i}\oplus x_{R,i},v) & \text{if }\theta_i=0,\\ \mathcal{O}(1,x_{L,i}\oplus x_{R,i},u) & \text{if }\theta_i=1. \end{cases}\]

    • The honest prover consists of a single party always holding the \(\mathbf{B}\) register while moving along \(L\) and then remaining at \(L(\tau)\) for the final \(\gamma\) checkpoints. For \(i=0,1,\cdots,N\), it does the following:

      • Receive \(x_{L,i},x_{R,i}\) at time \(i\delta\). If \(\theta_i=0\), it coherently evaluates \(\mathcal{O}(\theta_i,x_{L,i}\oplus x_{R,i},\cdot)\) on the \(\mathbf{B}\) register in the standard basis and sends the result to \(\mathcal{V}_L,\mathcal{V}_R\). If \(\theta_i=1\), it coherently evaluates \(\mathcal{O}(\theta_i,x_{L,i}\oplus x_{R,i},\cdot)\) on the \(\mathbf{B}\) register in the Hadamard basis and sends the result to \(\mathcal{V}_L,\mathcal{V}_R\).

Theorem 37. The construction in 36 is a trajectory verification scheme for the state \(\sigma=\left|{\sf EPR}\right\rangle\!\left\langle{\sf EPR}\right|^{\otimes n}\) in the classical oracle model with \(1\)-Completeness and \(\left(\beta,\beta',\Delta \right)\)-Extraction Soundness where \[\beta({\sf{\lambda}},\eta)=1-O\!\left(\left(\frac{\log(1/\eta)}{\gamma}\right)^{1/4}\right)-{\sf negl}({\sf{\lambda}}), \qquad \beta'({\sf{\lambda}},\eta)=\eta({\sf{\lambda}}).\] In particular, since we only consider adversaries for which \(1/\eta\) is at most polynomial in \({\sf{\lambda}}\), for any polynomial \(t({\sf{\lambda}})\), we can set \(\gamma=c{\sf{\lambda}}t^4\) for some constant \(c\) to achieve \[\beta({\sf{\lambda}},\eta)\geq1-1/t({\sf{\lambda}})~.\]

Proof. Completeness is identical to the completeness argument for 32: by 7, the honest prover’s coherent query returns \(\mathcal{O}_{\sf random}(\theta_i,x_{L,i}\oplus x_{R,i})\) in every checkpoint and the vessel state is not disturbed.

We prove extraction soundness by treating the protocol as a chained execution of the simple two-round localization scheme of 31. Take a trajectory \(L\), a QPT prover \(\mathcal{P}^*\) succeeding in \(\mathsf{Localize}\) with probability \(\eta\), and fix a time \(t\in[0,\tau]\). Let \(N\) and \(\widetilde{L}\) be as in the construction. Let \(q_i\) denote the probability that \(\mathcal{P}^*\) passes checkpoint \(i\), conditioned on passing checkpoints \(0,\ldots,i-1\), so \(\prod_{i=0}^N q_i=\eta\). Set \(k:=\lceil t/\delta\rceil\) and consider the future window of adjacent checkpoint indices \[I_t:=\{k,k+1,\ldots,k+\gamma-1\}.\] Since \(N=\lceil\tau/\delta\rceil+\gamma\), this window is contained in \(\{0,\ldots,N-1\}\), and corresponds to the checkpoint times in \([t,t+\gamma\delta]\). Since all \(q_i\leq 1\), we have \(\prod_{r=k}^{k+\gamma}q_r\geq\eta\). Therefore, there exists \(i^\star\in I_t\) such that, conditioned on passing checkpoints \(0,\ldots,i^\star-1\), the probability of passing checkpoints \(i^\star\) and \(i^\star+1\) is at least \(\eta^{2/\gamma}\).

The reduction to MultiStageIndependentMonogamy is the same reduction as in the proof of 32, with the following trajectory-specific changes. First, the two localization challenge points are now \((\widetilde{L}(i^\star\delta),i^\star\delta)\) and \((\widetilde{L}((i^\star+1)\delta),(i^\star+1)\delta)\) rather than two points on a stationary worldline. Thus the middle/left/right components are obtained by cutting the prover’s spacetime computation along the corresponding light-cone boundaries. This moving-prover setting for the spacetime decomposition is pictured in 11. Concretely, in the seven-component adversary \(\mathcal{A}\) from 32, replace \(t_0,t_1\) by \(i^\star\delta,(i^\star+1)\delta\), replace the first target location \(L\) by \(\widetilde{L}(i^\star\delta)\), and replace the second target location \(L\) by \(\widetilde{L}((i^\star+1)\delta)\) in the splitting of \(\mathbf{M}_L,\mathbf{M}_R,\mathbf{L}',\mathbf{R}'\) and the final response lines.

Figure 11: Spacetime decomposition of the reduction \mathcal{A} for trajectory verification, where the prover is moving between checkpoints. In this picture, L=0 and L'=0.16.

As usual, the reduction simulates the hidden random oracle \(\mathcal{O}_{\sf random}\) by a \(2r({\sf{\lambda}})\)-wise independent function \(F_k\), where \(r\) is the number of oracle queries \(\mathcal{P}^*\) makes. Importantly, due to the repetition, the first-stage reduction component must simulate the \(\mathsf{Localize}\) experiment from the beginning of time up through checkpoint \(i^\star-1\), thus ensuring that it is non-aborting iff the simulated prover \(\mathcal{P}^*\) makes it to checkpoint \(i^\star\). To do this, it samples challenges \((\theta_i,x_{L,i},x_{R,i})\) on its own and simulates the verifiers’ interactions with the prover as in \(\mathsf{Localize}\). If the prover responds with \(y_{L,i},y_{R,i}\) such that \(y_{L,i}\neq y_{R,i}\) or if \(y_{L,i}\neq F_k(\theta_i,x_{L,i}\oplus x_{R,i})\), the reduction aborts. The oracle \(\mathcal{O}\) is reprogrammed only at the two challenge points \((\theta_{i^\star},x_{L,i^\star}\oplus x_{R,i^\star})\) and \((\theta_{i^\star+1},x_{L,i^\star+1}\oplus x_{R,i^\star+1})\). The position-verification reprogramming lemma (1) applies exactly as in the localization proof because the two additive shares of the challenge become jointly available only at the claimed spacetime point for each checkpoint.

Hence, the constructed monogamy adversary does not abort with probability at least \(\prod_{r<i^\star}q_r\geq\eta\), and conditioned on not aborting it wins with probability at least \(\eta^{2/\gamma}-{\sf negl}({\sf{\lambda}})\). Applying the extractor from 29, exactly as in 32, there exists an extractor which with probability at least \(\eta\) outputs a state having the following fidelity with \(\left|{\sf EPR}\right\rangle^{\otimes n}\): \[1-O\!\left(\left(1-\eta^{2/\gamma}\right)^{1/4}\right)-{\sf negl}({\sf{\lambda}}) = 1-O\!\left(\left(\frac{\log(1/\eta)}{\gamma}\right)^{1/4}\right)-{\sf negl}({\sf{\lambda}}).\] It remains only to translate the checkpoint extractor into the extraction statement at the target time. The input to the monogamy extractor is the middle register on the two lower boundaries of the green triangle in 11; this register can be recovered by forward simulation from \(\mathsf{register}[\widetilde{L}(i^\star\delta)_{2\delta}~@~i^\star\delta]({\sf Exp})\), where \({\sf Exp}=\mathsf{Localize}(\mathcal{P}^*(\mathbf{B})\rightleftharpoons\mathcal{V}(\mathsf{sp}))({\sf{pp}},L)\). By construction, \(0\leq i^\star\delta-t\leq\gamma\delta\). Since the valid trajectory has speed at most one, the backwards light cone of \(\mathsf{register}[\widetilde{L}(i^\star\delta)_{2\delta}~@~i^\star\delta]\) at time \(t\) is contained in \(\mathsf{register}[L(t)_{(\gamma+2)\delta}~@~t]=\mathsf{register}[L(t)_\Delta~@~t]\). Thus the final extractor acts on \(\mathsf{register}[L(t)_\Delta~@~t]\), forward-simulates to the appropriate future checkpoint neighborhood, and then runs the monogamy extractor. This gives \((\beta,\beta',\Delta)\)-soundness with \[\beta({\sf{\lambda}},\eta)=1-O\!\left(\left(\frac{\log(1/\eta)}{\gamma}\right)^{1/4}\right)-{\sf negl}({\sf{\lambda}}), \qquad \beta'({\sf{\lambda}},\eta)=\eta({\sf{\lambda}}).\] ◻

9.3 State Localization↩︎

Note that in the entanglement localization scheme, if we ignore register \(\mathbf{A}\), then we are localizing the reduced state on register \(\mathbf{B}\). This idea extends to the concept of state localization.

Definition 10 (State Localization). A state localization scheme is parameterized by the security parameter \({\sf{\lambda}}\) and a state family \(\{\left|\psi_i\right\rangle\}_{i \in [N]}\).15 It consists of the following syntax.

  • \({\sf Setup}(1^{\sf{\lambda}}) \to {\sf{pp}},\mathsf{sp},i,\mathbf{B}\): The Setup algorithm takes the security parameter \(1^{\sf{\lambda}}\) and outputs public parameters \({\sf{pp}}\), secret parameters \(\mathsf{sp}\), an index \(i\), and a state on register \(\mathbf{B}\).

  • \(\mathsf{Localize}\left(\mathcal{P}(\mathbf{B}) \rightleftharpoons \mathcal{V}(\mathsf{sp})\right)({\sf{pp}},L,t) \to \mathbf{B}',b\): This is a positional protocol between a QPT prover holding a quantum register \(\mathbf{B}\) and a PPT verifier with input \(\mathsf{sp}\), further specified by the following public inputs: public parameters \({\sf{pp}}\), spatial location \(L \in [-1,1]\), and time \(t\). The prover’s output is \(\rho'\) and the verifier’s output is an acceptance indicator \(b\in\{\top,\bot\}\).

It should satisfy the following properties — parameterized by completeness probability \(\alpha({\sf{\lambda}})\), extraction fidelity \(\beta({\sf{\lambda}},\eta)\), extraction probability \(\beta'({\sf{\lambda}},\eta)\), uniqueness error \(\zeta({\sf{\lambda}})\), and localization parameter \(\Delta({\sf{\lambda}})\) — for all \({\sf{\lambda}}\in\mathbb{N}\).

  • \(\alpha\)-Completeness: For any location \(L\) and time \(t\), there is a QPT prover \(\mathcal{P}\) at \((L,t)\) such that \[\Pr\left[b = \top : \begin{array}{r} {\sf{pp}},\mathsf{sp},i,\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}}) \\ (\mathbf{B}',b) \gets \mathsf{Localize}\big( \mathcal{P}(\mathbf{B}) \rightleftharpoons \mathcal{V}(\mathsf{sp})\big)({\sf{pp}},L,t)\end{array}\right] \geq \alpha({\sf{\lambda}}).\]

  • \((\beta,\beta',\Delta)\)-Extraction Soundness: For any QPT prover \(\mathcal{P}^*\), spatial location \(L\), and time \(t\), let \[\eta({\sf{\lambda}}) := \Pr\left[b = \top : \begin{array}{r} {\sf{pp}},\mathsf{sp},i,\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}}) \\ (\mathbf{B}',b) \gets \mathsf{Localize}\big( \mathcal{P}^*(\mathbf{B}) \rightleftharpoons \mathcal{V}(\mathsf{sp})\big)({\sf{pp}},L,t)\end{array}\right]\] be \(\mathcal{P}^*\)’s success probability. Assume \(\eta({\sf{\lambda}})\ge 1/p({\sf{\lambda}})\) for some polynomial \(p\). Then there exists a (potentially unbounded, see 30) local extractor16 \({\mathcal{E}}\) acting on registers near location \(L\) at time \(t\) such that the probability of extracting \(\left|\psi_i\right\rangle\) with fidelity at least \(\beta({\sf{\lambda}},\eta)\) is at least \(\beta'({\sf{\lambda}},\eta)\): \[ {\sf{Pr}}\left[ \left\langle\psi_i\right|\rho_{\mathbf{B}^*}\left|\psi_i\right\rangle\ge \beta({\sf{\lambda}},\eta) : \begin{array}{r} {\sf{pp}},\mathsf{sp},i,\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}})\\ \mathbf{B}^*\gets\mathsf{register}[L_\Delta~@~t]\left(\mathsf{Localize}\left(\mathcal{P}^*(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L,t) \right)\\ \mathbf{B}^*\gets{\mathcal{E}}({\sf{pp}},\mathbf{B}^*) \end{array} \right] \geq \beta'({\sf{\lambda}},\eta)~,\] where \(\rho_{\mathbf{B}^*}\) is the state on \(\mathbf{B}^*\) after running the extractor, and \(L_\Delta := [L-\Delta({\sf{\lambda}}),L+\Delta({\sf{\lambda}})]\).

  • \(\zeta\)-Uniqueness: For any (potentially unbounded) prover \(\mathcal{P}^*\), disjoint spatial regions \(L_0,L_1\), and times \(t,t'\), and local (potentially unbounded) adversaries \(\mathcal{A},{\mathcal{B}}\) acting on \(\mathbf{A}^*,\mathbf{B}^*\), respectively,

    \[\mathop{\mathbb{E}}\left[\left\langle\psi_i\right|\left\langle\psi_i\right|\rho_{\mathbf{A}^*\mathbf{B}^*}\left|\psi_i\right\rangle\left|\psi_i\right\rangle: \begin{array}{r}{\sf{pp}},\mathsf{sp},i,\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}}) \\ \mathbf{A}^*,\mathbf{B}^* \gets \mathsf{register}[L_0~@~t',L_1~@~t']\big(\mathsf{Localize}\big( \mathcal{P}^*(\mathbf{B}) \rightleftharpoons \mathcal{V}(\mathsf{sp})\big)({\sf{pp}},L,t)\big) \\ \mathbf{A}^*\mathbf{B}^* \gets \left(\mathcal{A}\otimes{\mathcal{B}} \right)(\mathbf{A}^*\otimes\mathbf{B}^*)\end{array}\right] \leq \zeta({\sf{\lambda}})~,\] where \(\rho_{\mathbf{A}^*\mathbf{B}^*}\) is the state on \(\mathbf{A}^*\mathbf{B}^*\) after running \(\mathcal{A},{\mathcal{B}}\).

We say that the state localization scheme is non-destructive* if it additionally satisfies the following property.*

  • \(\boldsymbol{Non-destructive}\): For any spatial location \(L\) and time \(t\), \[\mathop{\mathbb{E}}\left[{\mathop{\mathrm{TD}}\left(\rho_{\mathbf{B}}, \rho_{\mathbf{B}'}\right)}:\begin{array}{r}{\sf{pp}},\mathsf{sp},i,\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}})\\ \mathbf{B}',b \gets \mathsf{Localize}\left(\mathcal{P}(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp}) \right)({\sf{pp}},L,t)\end{array}\right] \leq {\sf negl}({\sf{\lambda}})~,\] where \(\rho_{\mathbf{B}}\) is the state on \(\mathbf{B}\) after \({\sf Setup}\) and \(\rho_{\mathbf{B}'}\) is the state on \(\mathbf{B}'\) later after \(\mathsf{Localize}\).

Construction 38 (Non-Destructive State Localization Scheme). Let \({\sf{\lambda}}\in\mathbb{N}\) be the security parameter and \(n({\sf{\lambda}}),m({\sf{\lambda}})\geq{\sf{\lambda}}\) be polynomials. Take some localization parameter \(\Delta({\sf{\lambda}})\leq 1\) and a repetition factor \(\gamma({\sf{\lambda}})\). Take a state family \(\{\left|\psi_i\right\rangle\}_{i \in [N]}\). We consider the following non-destructive state localization scheme:

  • There are two verifiers: \(\mathcal{V}_L\) at \(-1\) and \(\mathcal{V}_R\) at \(1\).

  • \({\sf Setup}(1^{\sf{\lambda}})\):

    • Sample \(S,T,u,v\) with the same marginal distribution as in \({\sf GenAnchorState}(1^{\sf{\lambda}})\), and let \({\sf ek}=(S,T,v,u)\) be the extraction key, which is not given to the prover. Equivalently, sample a uniformly random invertible matrix \(U_{\sf shift} \in \mathbb{F}_2^{3n \times 3n}\), let \(S\) be the subspace spanned by the first \(n\) columns of \(U_{\sf shift}\) and \(T\) be the subspace spanned by the first \(2n\) columns of \(U_{\sf shift}\), and sample \(v \gets {\sf CS}(T)\) and \(u \gets {\sf CS}(S^\perp)\).

    • Sample \(i \gets [N]\) and define the isometry \[\mathsf{Enc}_{S,T,u,v}: \left|x\right\rangle \to \frac{1}{\sqrt{2^n}}\sum_{s \in S}(-1)^{s \cdot u}\left|s + U_{\sf shift}(0^n \times x \times 0^n) + v\right\rangle,\] and compute \[\rho = \mathsf{Enc}_{S,T,u,v}\left|\psi_i\right\rangle\!\left\langle\psi_i\right|\mathsf{Enc}_{S,T,u,v}^\dagger.\]

    • Define the oracle \(\mathcal{O}:\{0,1\}\times\mathbb{F}_2^{\sf{\lambda}}\times\mathbb{F}_2^{3n}\rightarrow \mathbb{F}_2^m\cup\left\{\bot\right\}\) based on random oracle \(\mathcal{O}_{\sf random}:\{0,1\}\times\mathbb{F}_2^{\sf{\lambda}}\rightarrow \mathbb{F}_2^m\) that is not publicly available. \[\mathcal{O}(\theta,x,z)=\left\{ \begin{align} &\mathcal{O}_{\sf random}(\theta,x) \quad &\text{if }\theta=0\text{ and }z\in T+v,\\ &\mathcal{O}_{\sf random}(\theta,x) \quad &\text{if }\theta=1\text{ and }z\in S^\perp+u,\\ &\bot \quad &\text{otherwise} \end{align} \right.\]

    • Output \({\sf{pp}}= \mathcal{O}, \mathsf{sp}= (u,v), i, \rho\).

  • \(\mathsf{Localize}\left(\mathcal{P}(\mathbf{B}) \rightleftharpoons \mathcal{V}(\mathsf{sp})\right)({\sf{pp}},L,t)\): Let \(\delta=\Delta/(\gamma+2)\) and define checkpoints \(t_i=t+i\delta\) for \(i=0,1,\ldots,\gamma\).

    • For each \(i=0,1,\ldots,\gamma\), \(\mathcal{V}_L\) and \(\mathcal{V}_R\) agree through their private authenticated channel on \(\theta_i\overset{\$}{\gets}\{0,1\}\) and additive shares \(x_{L,i},x_{R,i}\overset{\$}{\gets}\mathbb{F}_2^{\sf{\lambda}}\). \(\mathcal{V}_L\) broadcasts \((\theta_i,x_{L,i})\) at time \(t_i-(L+1)\) and expects the response \(y_{L,i}\) at time \(t_i+(L+1)\). \(\mathcal{V}_R\) broadcasts \(x_{R,i}\) at time \(t_i-(1-L)\) and expects the response \(y_{R,i}\) at time \(t_i+(1-L)\).

    • If any response is missing, the verifier outputs \(\bot\). Otherwise, it accepts if and only if for every \(i=0,1,\ldots,\gamma\), \[y_{L,i}=y_{R,i}= \begin{cases} \mathcal{O}(0,x_{L,i}\oplus x_{R,i},v) & \text{if }\theta_i=0,\\ \mathcal{O}(1,x_{L,i}\oplus x_{R,i},u) & \text{if }\theta_i=1. \end{cases}\]

    • The honest prover consists of a single party always holding the \(\mathbf{B}\) register containing the state \(\rho\) at location \(L\). For each \(i=0,1,\ldots,\gamma\), it receives \(x_{L,i},x_{R,i}\) at time \(t_i\). If \(\theta_i=0\), it coherently evaluates \(\mathcal{O}(0,x_{L,i}\oplus x_{R,i},\cdot)\) on the \(\mathbf{B}\) register in the standard basis and broadcasts the result. If \(\theta_i=1\), it coherently evaluates \(\mathcal{O}(1,x_{L,i}\oplus x_{R,i},\cdot)\) on the \(\mathbf{B}\) register in the Hadamard basis and broadcasts the result.

Theorem 39. Let \(\mathcal{S} = \{\left|\psi_i\right\rangle\}_{i \in [N]}\) be any set of \(n\)-qubit states that consist of a union of orthonormal bases. That is \(\mathcal{S} = \bigcup_j \mathcal{B}_j\), where each \(\mathcal{B}_j\) consists of \(2^n\) orthonormal states.

Then the construction in 38 is a non-destructive state localization scheme for \(\mathcal{S}\) in the classical oracle model with \(\alpha({\sf{\lambda}}) = 1\), \(\left(\beta,\beta',\Delta \right)\)-Extraction Soundness for \[\beta({\sf{\lambda}},\eta)=1-O\!\left(\left(\frac{\log(1/\eta)}{\gamma}\right)^{1/4}\right)-{\sf negl}({\sf{\lambda}}), \qquad \beta'({\sf{\lambda}},\eta)=\eta({\sf{\lambda}}),\] and uniqueness parameter \[\zeta({\sf{\lambda}}) := \sup_{\mathcal{A}}\left\{\mathop{\mathbb{E}}\left[\left\langle\psi_i\right|\left\langle\psi_i\right|\rho\left|\psi_i\right\rangle\left|\psi_i\right\rangle : \begin{array}{r} \left|\psi_i\right\rangle \gets \mathcal{S} \\ \rho \gets \mathcal{A}(\left|\psi_i\right\rangle)\end{array}\right]\right\}.\] In particular, since we only require extraction soundness against adversaries for which \(1/\eta\) is at most polynomial in \({\sf{\lambda}}\), for any polynomial \(t({\sf{\lambda}})\), we can set \(\gamma=c{\sf{\lambda}}t^4\) for some constant \(c\) to achieve \[\beta({\sf{\lambda}},\eta)\geq1-1/t({\sf{\lambda}})~.\]

Before coming to the proof, we give two examples of state families that are covered by our theorem. Note that we can write any \(\mathcal{S}\) from the above theorem statement as \[\mathcal{S} = \bigcup_{U \in \mathcal{U}}\left\{U\left|x\right\rangle\right\}_{x \in \{0,1\}^n}\] for some set of unitaries \(\mathcal{U}\).

  • BB84 states: \(\mathcal{U}\) is the set of \(n\)-qubit unitaries \(H^{\theta_1} \otimes \dots \otimes H^{\theta_n}\) for each \(\theta \in \{0,1\}^n\).

  • Coset states: \(\mathcal{U}\) is the set of unitaries that first map \(\left|x\right\rangle \to \left|Bx\right\rangle\) for some full rank \(B \in \mathbb{F}_2^{n \times n}\) and then apply \(H\) to the final \(n/2\) qubits.

Proof. \(1\)-completeness and non-destructiveness follow by observation, and \(\zeta\)-uniqueness follows directly from the definition of \(\zeta\) given in the theorem statement.

Thus, it remains to argue extraction soundness. To do so, we use exactly the same extractor \({\mathcal{E}}\) as in the proof of 35. Now, note that our extraction experiment is equivalent to the following purified version.

  • In \({\sf Setup}\), rather sampling \(i \gets [N]\) and applying \(\mathsf{Enc}_{S,T,u,v}\) to \(\left|\psi_i\right\rangle\), instead prepare \[\left|\mathsf{EPR}\right\rangle^{\otimes n} = \frac{1}{\sqrt{2^n}}\sum_{x \in \{0,1\}^n}\left|x\right\rangle_\mathbf{A}\left|x\right\rangle_\mathbf{B},\] and let \(\rho_\mathbf{B}\) be the result of applying \(\mathsf{Enc}_{S,T,u,v}\) to register \(\mathbf{B}\).

  • After \({\mathcal{E}}\) outputs \(\rho_{\mathbf{B}^*}\), sample \(U \gets \mathcal{U}\) (where \(\mathcal{U}\) is defined based on \(\mathcal{S}\) as above), apply \(U^t\) to register \(\mathbf{A}\), and then measure \(\mathbf{A}\) in the standard basis to obtain \(x\). Let \(\left|\psi_{i}\right\rangle := \left|\psi_{U,x}\right\rangle = U\left|x\right\rangle\) be the state17 that is used in the expression \(\left\langle\psi_i\right|\rho_{\mathbf{B}^*}\left|\psi_i\right\rangle\).

For any choice of \(U\), the expected success probability of extracting the state is \[\begin{align} \mathop{\mathbb{E}}_x\left[\left\langle\psi_{U,x}\right|\rho_{\mathbf{B}^*}\left|\psi_{U,x}\right\rangle\right] &= \mathop{\mathrm{Tr}}\left[\left(\sum_{x}\left|x\right\rangle\!\left\langle x\right|_\mathbf{A}\otimes \left|\psi_{U,x}\right\rangle\!\left\langle\psi_{U,x}\right|_{\mathbf{B}^*}\right)U^t_\mathbf{A}\rho_{\mathbf{A}\mathbf{B}^*}U^*_\mathbf{A}\right] \\ &= \mathop{\mathrm{Tr}}\left[\left(\sum_{x}U^*\left|x\right\rangle\!\left\langle x\right|U^t_\mathbf{A}\otimes U\left|x\right\rangle\!\left\langle x\right|U^\dagger_{\mathbf{B}^*}\right)\rho_{\mathbf{A}\mathbf{B}^*}\right] \\ &= \mathop{\mathrm{Tr}}\left[\left(\left(U^* \otimes U\right)\left(\sum_{x}\left|x\right\rangle\!\left\langle x\right| \otimes \left|x\right\rangle\!\left\langle x\right|\right)\left(U^t \otimes U^\dagger\right)\right)\rho_{\mathbf{A}\mathbf{B}^*}\right] \\ &\geq \mathop{\mathrm{Tr}}\left[\left(\left(U^* \otimes U\right)\left(\left|\mathsf{EPR}\right\rangle\!\left\langle\mathsf{EPR}\right|^{\otimes n}\right)\left(U^t \otimes U^\dagger\right)\right)\rho_{\mathbf{A}\mathbf{B}^*}\right] \\ &= \mathop{\mathrm{Tr}}\left[\left(\left|\mathsf{EPR}\right\rangle\!\left\langle\mathsf{EPR}\right|^{\otimes n}\right)\rho_{\mathbf{A}\mathbf{B}^*}\right] \\ &\geq \beta({\sf{\lambda}},\eta), \end{align}\]

where the last inequality holds with probability at least \(\beta'({\sf{\lambda}},\eta)=\eta({\sf{\lambda}})\) by 35. This gives the claimed extraction soundness parameters. ◻

Remark 40. One could strengthen the completeness definition of State Localization to demand that \(\rho = \left|\psi_i\right\rangle\!\left\langle\psi_i\right|\). That is, the prover obtains the state \(\left|\psi_i\right\rangle\) itself rather than an encoded version of it.

We can achieve this stronger completeness guarantee for the set of \(3n\)-qubit coset states with subspaces of dimension \(3n/2\). Indeed, one can sample a uniformly random \(3n\)-qubit coset state by first sampling an \(n\)-qubit coset state \(\left|\psi\right\rangle\) with subspace of dimension \(n/2\), and then outputting the \(3n\)-qubit state \(\mathsf{Enc}_{S,T,u,v}\left|\psi\right\rangle\), where \(S,T,u,v\) are sampled by the \({\sf Setup}\) algorithm given above. The resulting \(3n\)-qubit state is still unclonable even given \(S,T,u,v\), and thus uniqueness continues to hold.

9.4 Functionality Localization↩︎

We first recall the notion of quantum copy-protection from [11]. Our definition of functionality localization, stated later, will be a strengthening of copy-protection.

Definition 11 (Copy-protectable functionality). A family of functions \(\mathcal{F}= \{f\}_f\) is copy-protectable with security \(\zeta = \zeta({\sf{\lambda}})\) if there exists a distribution \({\mathcal{D}}\) on its domain and algorithms

  • \({\sf{Protect}}(1^{\sf{\lambda}},f) \to \rho_f\)

  • \({\sf Eval}(\rho_f,x) \to y\)

such that the following properties hold.

  • Correctness: For any \(f \in \mathcal{F}\) and \(x \in {\mathcal{D}}\), \[\Pr[{\sf Eval}(\rho_f,x) = f(x) : \rho_f \gets {\sf{Protect}}(1^{\sf{\lambda}},f)] = 1-{\sf negl}({\sf{\lambda}}).\]

  • Security: For any QPT tri-partite adversary \((\mathcal{A},{\mathcal{B}},{\mathcal{C}})\), \[\Pr\left[y_B = f(x_B) \wedge y_C = f(x_C) : \begin{array}{r} f \gets \mathcal{F}\\ \rho_f \gets {\sf{Protect}}(1^{\sf{\lambda}},f)\\ \rho_{B,C} \gets \mathcal{A}(\rho_f) \\ x_B,x_C \gets {\mathcal{D}}\\ y_B \gets {\mathcal{B}}(x_B,B), y_C \gets {\mathcal{C}}(x_C,C)\end{array}\right] \leq \zeta({\sf{\lambda}}).\]

We also recall quantum state obfuscation, which will be used later on for our construction of functionality localization. The following definition is adapted from [20], but for simplicity we have significantly weakened the definition to work only for classical functionalities.

Definition 12 (Quantum State Obfuscation ([19],[20])). Let \(\mathcal{F}=\{f\}_f\) be a classical function family, where for each \(f\in\mathcal{F}\) there exists a quantum program \((C_f,\left|\psi_f\right\rangle)\) such that \(C_f(x,\left|\psi\right\rangle_f)=f(x)\) deterministically. A quantum state obfuscator for \(\mathcal{F}\) is a pair of QPT algorithms \(({\sf QObf},{\sf QEval})\) with the following syntax.

  • \({\sf QObf}\left(1^{\sf{\lambda}},\left|\psi\right\rangle,C\right) \to \left|\widetilde{\psi}\right\rangle\): The obfuscator takes as input the security parameter \(1^{\sf{\lambda}}\) and a quantum program \((C,\left|\psi\right\rangle)\), and outputs an obfuscated state \(\left|\widetilde{\psi}\right\rangle\).

  • \({\sf QEval}\left(x,\left|\widetilde{\psi}\right\rangle\right) \to y\): The evaluation algorithm takes an input \(x \in \{0,1\}^{m({\sf{\lambda}})}\) and an obfuscated state \(\left|\widetilde{\psi}\right\rangle\), and outputs \(y \in \{0,1\}^{m'({\sf{\lambda}})}\).

Correctness is defined as follows for any \(f\in\mathcal{F}\). \[\forall x \in \{0,1\}^{m({\sf{\lambda}})}, \Pr\left[{\sf QEval}\left(x,\left|\widetilde{\psi}\right\rangle\right) = C_f(x,\left|\psi_f\right\rangle ): \left|\widetilde{\psi}\right\rangle \gets {\sf QObf}\left(1^{\sf{\lambda}},\left|\psi_f\right\rangle,C_f\right)\right] = 1-{\sf negl}({\sf{\lambda}}).\]

Ideal Obfuscation: For any QPT adversary \(\mathcal{A}\), there exists a QPT simulator \({\sf Sim}\) such that for any \(f\in\mathcal{F}\) and QPT distinguisher \({\mathcal{D}}\),

\[\begin{align} &\bigg|\Pr\left[1 \gets {\mathcal{D}}\left(\mathcal{A}\left({\sf QObf}\left(1^{\sf{\lambda}},\left|\psi_f\right\rangle,C_f\right)\right)\right)\right]\\ & ~~~~~ - \Pr\left[1 \gets {\mathcal{D}}\left({\sf Sim}^f\left(1^{\sf{\lambda}}\right)\right)\right]\bigg| = {\sf negl}({\sf{\lambda}}). \end{align}\]

Theorem 41 (Quantum State Ideal Obfuscation in the Oracle Model, [20]). There exists a quantum state ideal obfuscator for any classical functionality, in the classical oracle model.

Now we state the main definition of this section, and present our construction of it from quantum state obfuscation and signatures.

Definition 13 (Functionality localization). A functionality localization scheme is parameterized by a function family \(\mathcal{F}= \{f:\mathcal{X}\to\mathcal{Y}\}_f\)18, and a distribution \({\mathcal{D}}\) on its domain. It consists of the following syntax.

  • \({\sf Setup}(1^{\sf{\lambda}}) \to {\sf{pp}},\mathsf{sp},f,\mathbf{B}\): The setup algorithm takes the security parameter \(1^{\sf{\lambda}}\) and outputs public parameters \({\sf{pp}}\), secret parameters \(\mathsf{sp}\), a function \(f\in\mathcal{F}\), and a state on register \(\mathbf{B}\).

  • \(\mathsf{Localize}\big( \mathcal{P}(\mathbf{B}) \rightleftharpoons \mathcal{V}(\mathsf{sp},f)\big)({\sf{pp}},L,t) \to \mathbf{B}',b\): The Localize protocol is an interaction between a QPT prover whose input is register \(\mathbf{B}\), and a PPT verifier with inputs \(\mathsf{sp}\) and \(f\), further specified by the following public inputs: public parameters \({\sf{pp}}\), spatial location \(L \in [-1,1]\), and time \(t\). The prover’s output is \(\mathbf{B}'\) and the verifier’s output is an acceptance indicator \(b\in\{\top,\bot\}\).

It should satisfy the following properties — parameterized by completeness probability \(\alpha({\sf{\lambda}})\), extraction success \(\beta({\sf{\lambda}},\eta)\), uniqueness error \(\zeta({\sf{\lambda}})\), and localization parameter \(\Delta({\sf{\lambda}})\) — for all \({\sf{\lambda}}\in\mathbb{N}\).

  • Functionality Preservation: There exists a procedure \({\sf Eval}\) such that for any \(x\in\mathcal{X}\), \[\Pr\left[{\sf Eval}(\mathbf{B},x)=f(x) : {\sf{pp}},\mathsf{sp},f,\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}})\right]=1-{\sf negl}({\sf{\lambda}})\]

  • \(\alpha\)-Completeness: For any location \(L\) and time \(t\), there is a QPT prover \(\mathcal{P}\) at \((L,t)\) such that \[\Pr\left[b = \top : \begin{array}{r} {\sf{pp}},\mathsf{sp},f,\mathbf{B}\gets{\sf Setup}(1^{\sf{\lambda}})\\ (\mathbf{B}',b) \gets \mathsf{Localize}\big( \mathcal{P}(\mathbf{B}) \rightleftharpoons \mathcal{V}(\mathsf{sp},f)\big)({\sf{pp}},L,t) \end{array}\right] \geq \alpha({\sf{\lambda}}).\]

  • \((\beta,\Delta)\)-Extraction Soundness: For any QPT prover \(\mathcal{P}^*\), spatial location \(L\), and time \(t\), let \[\eta({\sf{\lambda}}) := \Pr\left[b = \top : \begin{array}{r} {\sf{pp}},\mathsf{sp},f,\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}}) \\ (\mathbf{B}',b) \gets \mathsf{Localize}\big( \mathcal{P}^*(\mathbf{B}) \rightleftharpoons \mathcal{V}(\mathsf{sp},f)\big)({\sf{pp}},L,t)\end{array}\right]\] be \(\mathcal{P}^*\)’s success probability. Assume \(\eta({\sf{\lambda}})\ge 1/p({\sf{\lambda}})\) for some polynomial \(p\), and let spatial region \(L_\Delta := [L-\Delta({\sf{\lambda}}),L+\Delta({\sf{\lambda}})]\). Then there exists a QPT extractor \({\mathcal{E}}\) acting on registers near location \(L\) at time \(t\) such that \[ \Pr\left[y = f(x) : \begin{array}{r} {\sf{pp}},\mathsf{sp},f,\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}}) \\ \mathbf{A}^* \gets \mathsf{register}[L_\Delta~@~t]\left(\mathsf{Localize}(\mathcal{P}^*(\mathbf{B}) \rightleftharpoons \mathcal{V}(\mathsf{sp},f)\right)({\sf{pp}},L,t)) \\ x \gets {\mathcal{D}}\\ y \gets {\mathcal{E}}({\sf{pp}},x,\mathbf{A}^*)\end{array}\right] \geq \beta({\sf{\lambda}},\eta).\]

  • \(\zeta\)-Uniqueness: For any QPT prover \(\mathcal{P}^*\), disjoint spatial regions \(L_0,L_1\), times \(t,t'\), and QPT \(\mathcal{A},{\mathcal{B}}\),

    \[\Pr\left[\begin{array}{cc} y_0 = f(x_0), \\ y_1 = f(x_1) \end{array}: \begin{array}{r}{\sf{pp}},\mathsf{sp},f,\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}}) \\ \mathbf{A}^*_0,\mathbf{A}^*_1 \gets \mathsf{register}[L_0~@~t';L_1~@~t']\big(\mathsf{Localize}\big( \mathcal{P}^*(\mathbf{B}) \rightleftharpoons \mathcal{V}(\mathsf{sp},f)\big)({\sf{pp}},L,t)\big) \\ x_0 \gets {\mathcal{D}}, x_1 \gets {\mathcal{D}}\\ y_0 \gets \mathcal{A}(x_0,\mathbf{A}^*_0), y_1 \gets {\mathcal{B}}(x_1,\mathbf{A}^*_1)\end{array}\right] \leq \zeta({\sf{\lambda}}).\]

We say that the functionality localization scheme is non-destructive if it additionally satisfies the following property.

  • \(\boldsymbol{Non-destructive}\): For any spatial location \(L\) and time \(t\), \[\mathop{\mathbb{E}}\left[\mathop{\mathrm{TD}}\left(\rho_\mathbf{B},\rho_{\mathbf{B}'}\right) : \begin{array}{r} {\sf{pp}},\mathsf{sp},f,\mathbf{B}\gets {\sf Setup}(1^{\sf{\lambda}}) \\ (\mathbf{B}',b) \gets \mathsf{Localize}\big( \mathcal{P}(\mathbf{B}) \rightleftharpoons \mathcal{V}(\mathsf{sp},f)\big)({\sf{pp}},L,t)\end{array}\right] \leq {\sf negl}({\sf{\lambda}}).\]

where \(\rho_{\mathbf{B}}\) is the state on \(\mathbf{B}\) after \({\sf Setup}\) and \(\rho_{\mathbf{B}'}\) is the state on \(\mathbf{B}'\) later after \(\mathsf{Localize}\).

Remark 42. Note that in contrast to entanglement and state localization, here we require the extractor \({\mathcal{E}}\) to be efficient (QPT). This is because the uniqueness property may only hold against computationally-bounded cloners.

Construction 43 (Non-Destructive Functionality Localization Scheme). Let \(\mathcal{F}\) be a function family. Let \(n({\sf{\lambda}}),m({\sf{\lambda}})\ge {\sf{\lambda}}\) be polynomials. Take a localization parameter \(\Delta({\sf{\lambda}})\leq 1\) and a repetition factor \(\gamma({\sf{\lambda}})\). Let \(\mathsf{QSO}\) be a quantum state obfuscator, and let \(({\sf KeyGen},\mathsf{Sign},\mathsf{Ver})\) be a MAC scheme, with message space \(\{0,1\}^*\) and signature space \(\mathcal{S}\). We define the following functionality localization scheme.

  • \({\sf Setup}(1^{\sf{\lambda}})\):

    1. Sample \(f\gets\mathcal{F}\).

    2. Sample a uniformly random subspace \(S\le \mathbb{F}_2^{n}\) of dimension \(n/2\), sample \(v\overset{\$}{\gets}{\sf CS}(S)\) and \(u\overset{\$}{\gets}{\sf CS}(S^\perp)\), and prepare the coset state \(X^v Z^u\left|S\right\rangle\).

    3. Sample \({\sf sk}\gets{\sf KeyGen}(1^{\sf{\lambda}})\).

    4. Define the signed functionality \[\widehat f_{{\sf sk}}(x):=\big(f(x),\mathsf{Sign}({\sf sk},(x,f(x)))\big),\] and obfuscate it using the ideal obfuscator: \[\rho_{\mathsf{QSO}}\gets \mathsf{QSO}.{\sf QObf}(1^{\sf{\lambda}},\widehat f_{{\sf sk}}).\]

    5. Sample a public random oracle \({\mathcal{O}}_{\sf chal}:\mathbb{F}_2^m\to\mathbb{F}_2^m\).

    6. Let \(C_0:=S+v\) and \(C_1:=S^\perp+u\). Sample a random oracle \({\mathcal{O}}_{\sf random}:\mathbb{F}_2^{m}\times\mathcal{X}_{\sf{\lambda}}\times \mathcal{Y}_{\sf{\lambda}}\times\mathbb{F}_2\to \mathbb{F}_2^{m}\) and define the public oracle \(\mathcal{O}:\mathbb{F}_2^m\times\mathcal{X}\times\mathcal{Y}\times\mathcal{S}\times\{0,1\}\times\mathbb{F}_2^n\to\mathbb{F}_2^m\cup\{\bot\}\) as follows. \[{\mathcal{O}}(h,x,y,\sigma,c,z)= \begin{cases} {\mathcal{O}}_{\sf random}(h,x,y,c) & \text{if }\mathsf{Ver}({\sf sk},(x,y),\sigma)=\top\text{ and }z\in C_c,\\ \bot & \text{otherwise} \end{cases}\] Note that \({\mathcal{O}}_{\sf random}\) is not made public.

    7. Output \[{\sf{pp}}=({\mathcal{O}},{\mathcal{O}}_{\sf chal}),\qquad \mathsf{sp}=(u,v,{\sf sk}),\qquad f,\qquad \rho=(\rho_{\mathsf{QSO}},X^vZ^u\left|S\right\rangle).\]

  • \(\mathsf{Localize}\left(\mathcal{P}(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp},f)\right)({\sf{pp}},L,t)\): Let \(\delta=\Delta/(2\gamma+2)\) and define checkpoint times \(t_{2i}=t+2i\delta\) and \(t_{2i+1}=t+(2i+1)\delta\) for \(i=0,1,\ldots,\gamma-1\).

    1. For each \(i\in\{0,\ldots,\gamma-1\}\), the verifiers sample \(x_i\gets{\mathcal{D}}\), then sample the challenges \[\hat{x}_{L,i},\hat{x}_{R,i},h_{L,2i},h_{R,2i},h_{L,2i+1},h_{R,2i+1}\gets\{0,1\}^m,\] for rounds \(2i\) and \(2i+1\). Let \(\bar{x}_i:=x_i\oplus{\mathcal{O}}_{\sf chal}(\hat{x}_{L,i}\oplus\hat{x}_{R,i})\). \(\mathcal{V}_L\) and \(\mathcal{V}_R\) send \((\bar{x}_i,\hat{x}_{L,i},h_{L,2i})\) and \((\hat{x}_{R,i},h_{R,2i})\), respectively, so that they arrive at location \(L\) at time \(t_{2i}\). They send \(h_{L,2i+1}\) and \(h_{R,2i+1}\) so that they arrive at \(L\) at time \(t_{2i+1}\).

    2. For each \(i\), upon receiving the messages for checkpoint \(2i\) at location \(L\), the honest prover constructs the real challenges \(x_i\) and \(h_{2i}\) as follows: \[\begin{align} x_i&:=\bar{x}_i\oplus{\mathcal{O}}_{\sf chal}(\hat{x}_{L,i}\oplus\hat{x}_{R,i}) \\ h_{2i}&:=h_{L,2i}\oplus h_{R,2i} \end{align}\] It then evaluates \[(y_i,\sigma_i)\gets \mathsf{QSO}.{\sf QEval}(x_i,\rho_{\mathsf{QSO}}),\] and coherently queries \({\mathcal{O}}(h_{2i},x_i,y_i,\sigma_i,0,\cdot)\) on the coset state in the standard basis, obtaining an answer \(a_{2i}\), which it immediately broadcasts.

    3. For each \(i\), upon receiving the messages for checkpoint \(2i+1\) at location \(L\), the honest prover reconstructs \(h_{2i+1}:=h_{L,2i+1}\oplus h_{R,2i+1}\) and coherently queries \({\mathcal{O}}(h_{2i+1},x_i,y_i,\sigma_i,1,\cdot)\) on the same coset state in the Hadamard basis, obtaining an answer \(a_{2i+1}\), which it immediately broadcasts.

    4. If any response is missing, the verifiers output \(\bot\). Otherwise, for each \(i\), the verifiers set \(h_{2i}:=h_{L,2i}\oplus h_{R,2i}\) and \(h_{2i+1}:=h_{L,2i+1}\oplus h_{R,2i+1}\), compute \[\sigma_{x_i}:=\mathsf{Sign}({\sf sk},(x_i,f(x_i)))\] and accept iff for every \(i\in\{0,\ldots,\gamma-1\}\), \[a_{2i}={\mathcal{O}}(h_{2i},x_i,f(x_i),\sigma_{x_i},0,v) \qquad\text{and}\qquad a_{2i+1}={\mathcal{O}}(h_{2i+1},x_i,f(x_i),\sigma_{x_i},1,u).\]

Remark 44. Note that unlike the constructions of trajectory verification, entanglement localization, and state localization, 43 does not randomize the basis of each challenge. Instead it uses a fixed ordering — standard, then Hadamard. This simplification is possible because here we are no longer relying on the EPR extraction machinery of [33], and instead all we need is to show that the prover must have queried at the designated position. This is already a property we establish for the standard-then-Hadamard monogamy game in 4, and by reducing to this game instead of MultiStageIndependentMonogamy we get a quadratically better loss in \(\beta({\sf{\lambda}},\eta)\) than for the other primitives.

Lemma 14 (Functionality Preservation). 43 satisfies Functionality Preservation.

Proof. We define \({\sf Eval}(\mathbf{B},x)\) as follows. Take the state on \(\mathbf{B}\), \(\rho_\mathbf{B}=(\rho_\mathsf{QSO},X^vZ^u\left|S\right\rangle)\), run \((y,\sigma)\gets\mathsf{QSO}.{\sf QEval}(\rho_\mathsf{QSO},x)\), and output \(y\). The property follows immediately from correctness of \(\mathsf{QSO}\). ◻

Lemma 15 (Completeness, non-destructiveness). 43 satisfies \((1-{\sf negl}({\sf{\lambda}}))\)-Completeness. Furthermore, it is non-destructive.

Proof. By correctness of \(\mathsf{QSO}\), in every checkpoint pair the honest prover obtains \((f(x_i),\sigma_{x_i})\) except with negligible probability, and the state \(\rho_{\mathsf{QSO}}\) is preserved by gentle measurement. For each \(i\), on checkpoint \(2i\), \({\mathcal{O}}(h_{2i},x_i,f(x_i),\sigma_{x_i},0,\cdot)\) is constant on the coset \(S+v\), so coherently querying it on \(X^vZ^u\left|S\right\rangle\) in the standard basis returns \({\mathcal{O}}(h_{2i},x_i,f(x_i),\sigma_{x_i},0,v)\) while leaving the coset state unchanged. Similarly, \({\mathcal{O}}(h_{2i+1},x_i,f(x_i),\sigma_{x_i},1,\cdot)\) is constant on the coset \(S^\perp+u\), so coherently querying it in the Hadamard basis returns \({\mathcal{O}}(h_{2i+1},x_i,f(x_i),\sigma_{x_i},1,u)\) while again leaving the coset state unchanged. A union bound over the polynomially many checkpoints gives acceptance probability \(1-{\sf negl}({\sf{\lambda}})\) and final prover state negligibly close to the initial state. ◻

Lemma 16 (Extraction Soundness). If \((\mathsf{Sign},\mathsf{Ver})\) is a secure MAC scheme and \(\mathsf{QSO}\) is an ideal obfuscator, then 43 satisfies \(\left(\beta,\Delta \right)\)-Extraction soundness, where \[\beta({\sf{\lambda}},\eta)=\eta({\sf{\lambda}})\left(1-O\!\left(\sqrt{\frac{\log(1/\eta)}{\gamma}}\right)-{\sf negl}({\sf{\lambda}})\right).\]

Proof. The proof proceeds in several steps, which we outline below.

9.4.0.1 Removing the Signature

To analyze the construction, we first consider modifying the public oracle to reject any queries not output by the signed functionality. Define \[\label{eq:oracle95f} {\mathcal{O}}_f(h,x,y,\sigma,c,z)= \begin{cases} {\mathcal{O}}(h,x,y,\sigma,c,z) & \text{if } y=f(x),\\ \bot & \text{otherwise.} \end{cases}\tag{2}\]

Claim 45. No QPT distinguisher has more than negligible advantage in telling apart a setup which outputs \({\mathcal{O}}\), from a setup which outputs \({\mathcal{O}}_f\).

Proof. The two worlds differ only on queries \((h,x,y,\sigma,c,z)\) such that \(\mathsf{Ver}({\sf sk},(x,y),\sigma)=\top\) and \(y\neq f(x)\). Any such query contains a valid signature on a message \((x,y)\) that is never signed by the functionality \(\widehat f_{{\sf sk}}\), since the only signatures returned by \(\widehat f_{{\sf sk}}\) are on messages of the form \((x,f(x))\). If there were a distinguisher between the two worlds, then by the security of \(\mathsf{QSO}\) we could replace the obfuscated state by black-box access to the functionality \(\widehat f_{{\sf sk}}\) without losing more than negligible advantage. A standard BBBV-type search-to-distinguishing reduction would then find, with non-negligible probability, a query on which \({\mathcal{O}}\) and \({\mathcal{O}}_f\) differ, yielding a valid forgery for the MAC scheme. ◻

We may therefore analyze the experiment with \({\mathcal{O}}_f\) in place of \({\mathcal{O}}\), losing only a negligible term.

9.4.0.2 Finding a Successful Checkpoint Pair

Write \(\delta=\Delta/(2\gamma+2)\) as in the construction. Fix \(L\), \(t\), and a QPT prover \(\mathcal{P}^*\) succeeding in \(\mathsf{Localize}\) with probability \(\eta\). Let \(q_i\) denote the probability that \(\mathcal{P}^*\) passes the \(i\)-th checkpoint pairs condition on passing all previous checkpoints. There exists \(i^\star\in\{0,\ldots,\gamma-1\}\) such that the checkpoint pair \(2i^\star,2i^\star+1\) is passed with probability \[q_{i^\star}\ge \eta^{1/\gamma}\] conditioned on passing checkpoint pairs \(0,\ldots,i^\star-1\). Let time \(t^\star=t+2i^\star\delta\) be the first challenge point of the pair, and denote the failure probability by \(\varepsilon:=1-q_{i^\star}\) for convenience.

9.4.0.3 Extracting the Functionality.

We now define the implementation extractor \({\mathcal{E}}\). In addition to a sampled input \(x\), the extractor takes as input the public setup parameters \({\sf{pp}}\), and the local register \(\mathbf{A}^*\) from which it will extract. For our construction, \({\sf ek}=\emptyset\). We will split \({\mathcal{E}}\) into two parts \(\mathcal{E}_0\) and \(\mathcal{E}_1\), which also act on different parts of the input, for convenience later on in the proof.

\(\mathcal{E}_0({\sf{pp}},\mathbf{A}^*)\): The extractor first forward-simulates \(\mathbf{A}^*=\mathsf{register}[L_\Delta~@~t]\) to obtain \(\mathsf{register}[L_{2\delta}~@~t^\star]\), which we can see is possible by checking the backwards light-cone: \(t^\star-t\le 2\gamma\delta=\Delta-2\delta\). Note that when \({\mathcal{E}}_0\) is doing this forward-simulation, it is not sampling challenges or answering oracle queries on its own. Instead, it is using all information contained in \(\mathbf{A}^*\) (including inflight verifier messages, etc) along with the code of \(\mathcal{P}^*\), and access to the oracles in \({\sf{pp}}\), to simulate the prover perfectly.

Next, in the same way, \({\mathcal{E}}_0\) simulates \(\mathcal{P}^*\) inside the spacetime region for checkpoint \(2i^\star\), essentially corresponding to the light blue-shaded region of 10). Let \(R_{\vee}\) be the vee-shaped top border of this region (bottom border of the green triangle in 10), and note that its backwards light-cone is \(L_{2\delta}\) at time \(t^\star\). The output of \({\mathcal{E}}_0\) is \[\mathbf{M}:=\mathsf{register}[R_{\vee}](\text{Forward time-evolution of \mathbf{A}^*})\]

\(\mathcal{E}_1({\sf{pp}},\mathbf{M},x)\): Continuing from \(\mathcal{E}_0\), and now having additional input \(x\), the extractor now recovers \(\mathcal{V}\)’s messages for checkpoints \(2i^\star,2i^\star+1\), \[\bar{x}_{i^\star},\hat{x}_{L,i^\star},\hat{x}_{R,i^\star},h_{L,2i^\star},h_{R,2i^\star},h_{L,2i^\star+1},h_{R,2i^\star+1}\] from the transcript contained in the forward simulation. Let \(\hat{x}_{i^\star}:=\hat{x}_{L,i^\star}\oplus\hat{x}_{R,i^\star}\), \(h_{2i^\star}:=h_{L,2i^\star}\oplus h_{R,2i^\star}\), and \(h_{2i^\star+1}:=h_{L,2i^\star+1}\oplus h_{R,2i^\star+1}\).

It then simulates \(\mathcal{P}^*\) inside the spacetime triangle \(\nabla\), corresponding to the green triangle in 10. For convenience, we use \(\mathcal{P}^*_\nabla\) to refer to the portion of \(\mathcal{P}^*\)’s circuits contained within the region \(\nabla\). During its simulation of \(\mathcal{P}^*_\nabla\), \({\mathcal{E}}\) intercepts all oracle queries and responds in the following way.

  • On query \({\mathcal{O}}_{\sf chal}(x')\):

    • If \(x'=\hat{x}_{i^\star}\), respond with \(x\oplus\bar{x}_{i^\star}\);

    • otherwise, forward to the true oracle \({\mathcal{O}}_{\sf chal}\).

  • On query \({\mathcal{O}}(h,x',y,\sigma,c,z)\):

    • If \((h,x',c)=(h_{2i^\star},x,0)\), first compute \(w={\mathcal{O}}(h_{2i^\star},x,y,\sigma,c,z)\).

      • If \(w\neq\bot\), respond with \(H(y)\), where \(H\) is a compressed oracle;

      • otherwise, respond with \(\bot\).

    • otherwise, forward to the true oracle \({\mathcal{O}}\);

At the end of the simulation, \({\mathcal{E}}\) measures the database of the compressed oracle \(H\). If there is a unique non-\(\bot\) entry \(y\), it outputs \(y\); otherwise it outputs \(\bot\).

We now analyze \({\mathcal{E}}\), which proceeds very similarly to the analysis in 32.

Claim 46. In the extraction soundness experiment, \({\mathcal{E}}\) outputs \(y=f(x)\) with probability at least \(\eta(1-2\sqrt{2\varepsilon})-{\sf negl}({\sf{\lambda}})\).

Proof. We will prove this by first constructing a reduction from the \(\mathsf{Localize}\) experiment to the \({\sf MultiStageSearchMonogamy}\) game of 4, and then showing how to view our extractor \({\mathcal{E}}\) as a component in that reduction.

The reduction will be a seven-part adversary \[\mathcal{A}= \big( \underbrace{\mathcal{A}_M^0}_{\text{stage 0}}, \underbrace{\mathcal{A}_M^1,\mathcal{A}_L^0,\mathcal{A}_R^0}_{\text{stage 1}}, \underbrace{\mathcal{A}_M^2,\mathcal{A}_L^1,\mathcal{A}_R^1}_{\text{stage 2}} \big)\] for \({\sf MultiStageSearchMonogamy}\), where \(S=T\) because the parameter \(n_e\) is set to 0. The challenger samples \((S,u,v)\) and provides the initial coset-state register \(X^v Z^u\left|S\right\rangle\) to \(\mathcal{A}_M^0\). In stage 1 it gives oracle access to \({\mathcal{O}}_{S+v}^{b_0}\) for a uniformly random hidden answer \(b_0\in\mathbb{F}_2^m\), and in stage 2 it additionally gives oracle access to \({\mathcal{O}}_{S^\perp+u}^{b_1}\) for an independent uniformly random hidden answer \(b_1\in\mathbb{F}_2^m\).

The adversary \(\mathcal{A}\) is defined just as in 32, excepting a few differences specific to the functionality localization setting which we highlight below. Let \(r({\sf{\lambda}})\) be an upper bound on the number of oracle queries made by \(\mathcal{P}^*\).

  1. Once \(\mathcal{A}_M^0\) receives the coset-state \(X^vZ^u\left|S\right\rangle\) along with membership oracles \({\mathcal{O}}_{S+v}\) and \({\mathcal{O}}_{S^\perp+u}\) from the challenger, it additionally samples the rest of \({\sf Setup}\): \[f\gets\mathcal{F},\qquad {\sf sk}\gets{\sf KeyGen}(1^{\sf{\lambda}}),\qquad \rho_{\mathsf{QSO}}\gets \mathsf{QSO}.{\sf QObf}(1^{\sf{\lambda}},\widehat f_{{\sf sk}}).\] Letting \(\mathbf{B}\) be a register with state \(\rho=(\rho_{\mathsf{QSO}},X^vZ^u\left|S\right\rangle),\) the simulated prover is initialized with input \(\mathbf{B}\). \(\mathcal{A}_M^0\) also initializes two \(2r({\sf{\lambda}})\)-wise independent functions \(F_k\) and \(G_{k'}\) (for simulating \({\mathcal{O}}_{\sf random}\) and \({\mathcal{O}}_{\sf chal}\), respectively), and samples the following challenges for each \(i\in\{0,\dots,i^\star\}\) \[x_i,\bar{x}_i,\hat{x}_{L,i},\hat{x}_{R,i},h_{L,2i},h_{R,2i},h_{L,2i+1},h_{R,2i+1}\] where \(x_i\gets{\mathcal{D}}\), and the rest are uniform subject to \(x_i=\bar{x}_i\oplus G_{k'}(\hat{x}_{L,i}\oplus \hat{x}_{R,i})\). Let \(h_{2i^\star}:=h_{L,2i^\star}\oplus h_{R,2i^\star}\) and \(h_{2i^\star+1}:=h_{L,2i^\star+1}\oplus h_{R,2i^\star+1}\). The first \(i^\star\) of these challenge tuples are used, along with the hash functions \(F_k\) and \(G_{k'}\), to simulate the prover through rounds \(0,\dots,2i^\star-1\) of the \(\mathsf{Localize}\) experiment. If the prover responds incorrectly in any of these rounds, \(\mathcal{A}_M^0\) aborts. The challenges for rounds \(2i^\star\) and \(2i^\star+1\) are placed in the \(\mathsf{info}\) register which is copied along between the reduction components. In particular, \(\mathsf{info}\) contains \(x_{i^\star}\), \(h_{2i^\star}\), \(h_{2i^\star+1}\), and \(f\). Like in 37, access to the oracle \(\mathcal{O}\) is simulated using the sampled components of \({\sf Setup}\), along with \(F_k\) for the random oracle and \({\mathcal{O}}_{S+v}\) and \({\mathcal{O}}_{S^\perp+u}\) for checking coset membership. Access to \({\mathcal{O}}_{\sf chal}\) is similarly simulated with \(G_{k'}\).

  2. For the simulation of all parts of \(\mathcal{A}\) in stages 1 and 2, we reprogram the oracle as follows: all queries of the form \((h_{2i^\star},x_{i^\star},f(x_{i^\star}),\sigma,0,z)\) are remapped to \({\mathcal{O}}_{S+v}^{b_0}(z)\). In other words, \({\mathcal{O}}_{\sf random}\) is reprogrammed at the lone point \((h_{2i^\star},x_{i^\star},f(x_{i^\star}),0)\).

  3. For the simulation of stage 2, we additionally reprogram the oracle as follows: all queries of the form \((h_{2i^\star+1},x_{i^\star},f(x_{i^\star}),\sigma,1,z)\) are remapped to \({\mathcal{O}}_{S^\perp+u}^{b_1}(z)\). In other words, \({\mathcal{O}}_{\sf random}\) is reprogrammed at the lone point \((h_{2i^\star+1},x_{i^\star},f(x_{i^\star}),1)\).

Claim 47. \[\begin{align} \Pr\left({\sf MultiStageSearchMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot \right) &\ge \eta,\text{ and }\\ \frac{\Pr\left({\sf MultiStageSearchMonogamy}(\mathcal{A},1^{\sf{\lambda}})=1 \right)}{\Pr\left({\sf MultiStageSearchMonogamy}(\mathcal{A},1^{\sf{\lambda}})\neq\bot \right)} &\ge 1-\varepsilon-{\sf negl}({\sf{\lambda}}). \end{align}\]

Proof. The component \(\mathcal{A}_M^0\) aborts exactly if the simulated prover fails one of checkpoint pairs \(0,\ldots,i^\star-1\), giving the first bound. Since the tuple \((h_{2i^\star},x_{i^\star})\) is not jointly available before spacetime point \((L,t^\star)\), and the tuple \((h_{2i^\star+1},x_{i^\star})\) is not jointly available before \((L,t^\star+\delta)\), the same oracle-reprogramming argument used in 37 (invoking 1) implies the simulation of checkpoints \(2i^\star,2i^\star+1\) is negligibly close to the real-world execution of adversary \(\mathcal{P}^*\) in the \(\mathsf{Localize}\) experiment (when the oracle is \({\mathcal{O}}_f\) instead of \({\mathcal{O}}\)), conditioned on reaching checkpoint pair \(i^\star\). Then, the second inequality follows from 45. ◻

We now introduce a sequence of hybrids, where the first corresponds to the MultiStageSearchMonogamy reduction, and the last corresponds to the extraction experiment. Throughout these hybrids, probabilities are conditioned on \(\mathcal{A}_M^0\) not aborting, corresponding to the event where the real execution of \(\mathsf{Localize}\) reaches checkpoint pair \(i^\star\).

Hybrid 1: This denotes the following experiment.

  1. Run \(\mathcal{A}^0_M\) from the reduction above, and take its middle output \(\mathbf{M}'=(\mathsf{info},\mathbf{M})\). Receive \({\mathcal{O}}_{S+v}^{b_0}\) from the \({\sf MultiStageSearchMonogamy}\) challenger. Take \(x_{i^\star},h_{2i^\star},h_{2i^\star+1},f\gets\mathsf{info}\).

  2. Simulate \(\mathcal{P}^*_{\nabla}\) (defined above, in the description of \({\mathcal{E}}\)) on input \(\mathbf{M}\). In this simulation, oracle queries to \({\mathcal{O}}\) are answered with \({\mathcal{O}}'\), which depends on \(x_{i^\star},h_{2i^\star},f\) and is described below. Here, \(H\) is a compressed oracle on \(\mathcal{Y}_{\sf{\lambda}}\to\{0,1\}^m\). \[ {\mathcal{O}}'(h,x',y,\sigma,c,z)= \begin{cases} H(f(x')) & \text{if } c=0\land x'=x_{i^\star}\land h=h_{2i^\star}\land y=f(x')\land{\mathcal{O}}(h,x',y,\sigma,c,z)\neq\bot,\\ {\mathcal{O}}(h,x',y,\sigma,c,z) & \text{otherwise.} \end{cases}\]

  3. After simulating \(\mathcal{P}^*_{\nabla}\), measure the compressed oracle database of \(H\).

  4. If there is exactly one non-\(\bot\) entry \(y\), output \(y\). Otherwise, output \(\bot\).

Claim 48. Let \(p_1\) denote the probability that the output of Hybrid 1 is exactly \(f(x_{i^\star})\). Then, \[p_1\geq1-2\sqrt{2\varepsilon}-{\sf negl}({\sf{\lambda}})\]

Proof. Consider the measurement of the \(H\) database. Clearly there can be at most one non-\(\bot\) entry, since \(H\) can only be accessed at \(f(x_{i^\star})\). Thus we must now argue that the probability that the measurement of the \(H(f(x_{i^\star}))\) database entry is \(\bot\) is at most \(2\sqrt{2\varepsilon}+{\sf negl}({\sf{\lambda}})\). We will do this as follows:

First, we notice that steps 1 and 2 of Hybrid 1 are the same experiment as running \(\mathcal{A}^0_M\) and then \(\mathcal{A}^1_M\) in the MultiStageSearchMonogamy game, except that the queries \({\mathcal{O}}(h_{2i^\star},x_{i^\star},f(x_{i^\star}),\sigma,0,z)\) which \(\mathcal{A}^1_M\) would reprogram to \({\mathcal{O}}^{b_0}_{S+v}(z)\) are now instead reprogrammed to \(H(f(x_{i^\star}))\). In other words, \({\mathcal{O}}_{\sf random}(h_{2i^\star},x_{i^\star},f(x_{i^\star}),0)\) is now reprogrammed to \(H(f(x_{i^\star}))\) instead of \(b_0\). These two experiments are identical, since \(b_0\) and \(H(f(x_{i^\star}))\) are both uniformly random. Then, by 47, if we run the MultiStageSearchMonogamy reduction but replace \(\mathcal{A}_M^0\) and \(\mathcal{A}_M^1\) with steps 1 and 2 of Hybrid 1, it would succeed conditioned on non-abort with probability \(1-\varepsilon-{\sf negl}({\sf{\lambda}})\).

Finally, let \(\mathbf{B}\) denote the \(f(x_{i^\star})^{th}\) entry in the compressed oracle database of \(H\), which will initially be in the uniform superposition over \(m\)-bit output strings. We notice that the simulated prover has the following access to \(\mathbf{B}\): \[{\mathcal{O}}(h_{2i^\star},x_{i^\star},f(x_{i^\star}),\sigma,0,\cdot)=\sum_{b_0\in\mathbb{F}_2^{m_0}}\left|b_0\right\rangle_{\mathbf{B}}\left\langle b_0\right|\otimes\mathcal{O}_{S+v}^{b_0}.\] and that there is no other dependence that the prover can have on \(\mathbf{B}\). This is the same as the interface given to the adversary in 4. Now, given the last paragraph, 11 applies: if we write the purified state of the entire Hybrid 1 experiment, after step 2, as \[\left|\psi\right\rangle_{\mathbf{A}\mathbf{B}}=\sum_{{\sf sk}}\sum_{b_0\in\mathbb{F}_2^m}\left|\psi^{{\sf sk}}_{b_0}\right\rangle_{\mathbf{A}}\left|b_0\right\rangle_{\mathbf{B}}~,\] where \({\sf sk}=(S,u,v)\), \(\mathbf{A}\) is all of \(\mathcal{P}^*\)’s registers and messages at the top edge of the region \(\nabla\), and \(\mathbf{B}\) is the purified choice of \(b_0\) from 4, then, \[\mathop{\mathrm{Tr}}\left(\left|+_\mathbf{B}\right\rangle_\mathbf{B}\left\langle+_\mathbf{B}\right|\cdot\left|\psi\right\rangle_{\mathbf{A}\mathbf{B}}\left\langle\psi\right| \right)\leq2\sqrt{2\varepsilon}+{\sf negl}({\sf{\lambda}}).\] Thus, if we measure this register in the Hadamard basis, it will be \(\bot\) with probability \(\leq2\sqrt{2\varepsilon}+{\sf negl}({\sf{\lambda}})\). This proves the claim. ◻

Hybrid 2: This denotes the following experiment:

  1. Run \(\mathcal{A}^0_M\) from the reduction above, and take its middle output \(\mathbf{M}'=(\mathsf{info},\mathbf{M})\). Receive \({\mathcal{O}}_{S+v}^{b_0}\) from the \({\sf MultiStageSearchMonogamy}\) challenger. Take \(x_{i^\star},h_{2i^\star},h_{2i^\star+1}\gets\mathsf{info}\) (discarding \(f\)).

  2. Simulate \(\mathcal{P}^*_{\nabla}\) on input \(\mathbf{M}\). In this simulation, oracle queries to \({\mathcal{O}}\) are answered with \({\mathcal{O}}''\), which depends on \(x_{i^\star},h_{2i^\star}\) and is described below. Here, \(H\) is a compressed oracle on \(\mathcal{Y}_{\sf{\lambda}}\to\{0,1\}^m\). \[{\mathcal{O}}''(h,x',y,\sigma,c,z)= \begin{cases} \textcolor{red}{H(y)} & \textcolor{red}{\text{if } c=0\land x'=x_{i^\star}\land h=h_{2i^\star}\land{\mathcal{O}}(h,x',y,\sigma,c,z)\neq\bot},\\ {\mathcal{O}}(h,x',y,\sigma,c,z) & \text{otherwise.} \end{cases}\]

  3. After simulating \(\mathcal{P}^*_{\nabla}\), measure the compressed oracle database of \(H\).

  4. If there is exactly one non-\(\bot\) entry \(y\), output \(y\). Otherwise, output \(\bot\).

Claim 49. Let \(p_2\) denote the probability that the output of Hybrid 2 is exactly \(f(x_{i^\star})\). Then, \[|p_2-p_1|\leq{\sf negl}({\sf{\lambda}}).\]

Proof. We can first swap \({\mathcal{O}}\) in Hybrid 1 for \({\mathcal{O}}_f\), which is distinguishable with only negligible probability by 45. Then, the check for \(y=f(x_{i^\star})\) becomes redundant, since it already exists in \({\mathcal{O}}_f(h,x',y,\sigma,c,z)\neq\bot\), so we can remove it from the definition of \({\mathcal{O}}'\). Then, we switch back to \({\mathcal{O}}\) by another application of 45, and we get the definition of \({\mathcal{O}}''\). Since the oracle is now independent of \(f\), we can discard \(f\) from \(\mathsf{info}\). ◻

Hybrid 3: This denotes the following experiment.

  1. Run \({\sf{pp}},\mathsf{sp},f,\rho\gets{\sf Setup}(1^{\sf{\lambda}})\).

  2. Start the procedure \(\mathsf{Localize}\left(\mathcal{P}^*(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp},f)\right)({\sf{pp}},L,t)\), but freeze all circuits and messages at time \(t\). Let \(\mathbf{A}^*:=\mathsf{register}[L_\Delta~@~t]\big(\mathsf{Localize}\left(\mathcal{P}^*(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp},f)\right)({\sf{pp}},L,t)\big)\).

  3. Use the code of \(\mathcal{P}^*\), along with the oracles \(({\mathcal{O}},{\mathcal{O}}_{\sf chal})={\sf{pp}}\), to evolve \(\mathbf{A}^*\) forward to \(\mathsf{register}[L_{2\delta}~@~t^\star]\) and then find the state on all registers and messages in the region described by the following:

    1. \(s-p=t^\star-L\);

    2. \(s+p=t^\star+L\);

    3. \(p\in[L-2\delta,L+2\delta]\),

    which we call \(R_{\vee}\). The output of this step is \[\mathbf{M}:=\mathsf{register}[R_{\vee}](\text{Forward time-evolution of \mathbf{A}^*})\]

  4. Compute \(\mathsf{info}=(x_{i^\star},h_{2i^\star},h_{2i^\star+1})\) for checkpoint pair \(i^\star\) from the transcript of verifier messages in the forward simulation.

  5. Run steps 2-4 of Hybrid 2 with inputs \((\mathsf{info},\mathbf{M})\).

    • Simulate \(\mathcal{P}^*_{\nabla}\) on input \(\mathbf{M}\). In this simulation, oracle queries to \({\mathcal{O}}\) are answered with \({\mathcal{O}}''\), which depends on \(x_{i^\star},h_{2i^\star}\) and is described in Hybrid 2.

    • After simulating \(\mathcal{P}^*_{\nabla}\), measure the compressed oracle database of \(H\).

    • If there is exactly one non-\(\bot\) entry \(y\), output \(y\). Otherwise, output \(\bot\).

Claim 50. Let \(p_3\) denote the probability that the output of Hybrid 3 is exactly \(f(x_{i^\star})\). Then, \[p_3=p_2~.\]

Proof. By examining the definition of \(\mathcal{A}_M^0\), one can see that the output \[(\mathsf{info}=(x_{i^\star},h_{2i^\star},h_{2i^\star+1}),\mathbf{M})\gets\mathcal{A}_M^0()\] is equal to the output of the simulation in steps 1-4 above. In other words, we argue that since the reduction \(\mathcal{A}\) is specified in such a way as to perfectly simulate the \(\mathsf{Localize}\) experiment, Hybrid 2 and Hybrid 3 are the same experiment up to rewriting of steps. ◻

Hybrid 4: This denotes the following experiment.

  1. Run \({\sf{pp}},\mathsf{sp},f,\mathbf{B}\gets{\sf Setup}(1^{\sf{\lambda}})\), and sample \(x\gets{\mathcal{D}}\).

  2. Start the procedure \(\mathsf{Localize}\left(\mathcal{P}^*(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp},f)\right)({\sf{pp}},L,t)\), but freeze all circuits and messages at time \(t\). Let \(\mathbf{A}^*:=\mathsf{register}[L_\Delta~@~t]\big(\mathsf{Localize}\left(\mathcal{P}^*(\mathbf{B})\rightleftharpoons \mathcal{V}(\mathsf{sp},f)\right)({\sf{pp}},L,t)\big)\).

  3. Run \(\mathbf{M}\gets\mathcal{E}_0({\sf{pp}},\mathbf{A}^*)\).

  4. Run \(y\gets\mathcal{E}_1({\sf{pp}},\mathbf{M},x)\), and output \(y\).

Claim 51. Let \(p_4\) denote the probability that the output of Hybrid 4 is exactly \(f(x)\). Then, \[|p_4-p_3|\leq{\sf negl}({\sf{\lambda}})\]

Proof. We notice that step 3 of Hybrid 3 is definitionally equivalent to \(\mathbf{M}\gets{\mathcal{E}}_0({\sf{pp}},\mathbf{A}^*)\). Also, the fresh input \(x\) in Hybrid 4 has the same distribution as \(x_{i^\star}\) in Hybrid 3. Thus, the remaining steps are exactly the same procedure as \(y\gets{\mathcal{E}}_1({\sf{pp}},\mathbf{M},x)\), except that \({\mathcal{E}}_1\) reprograms \({\mathcal{O}}_{\sf chal}\) at \(\hat{x}_{i^\star}\) so the selected checkpoint challenge is this fresh \(x\) rather than the original \(x_{i^\star}\). By 1, this reprogramming can be detected only with negligible probability. ◻

Now, all that is left to notice is that Hybrid 4 is precisely the extraction experiment for checkpoint pair \(i^\star\). Also, \(\mathcal{E}\) is efficient. Thus, as a consequence of 48 through 51, the extractor succeeds with probability \(1-2\sqrt{2\varepsilon}-{\sf negl}({\sf{\lambda}})\) conditioned on reaching checkpoint pair \(i^\star\). The overall extraction experiment succeeds with probability at least \[\eta({\sf{\lambda}})\left(1-2\sqrt{2\varepsilon}-{\sf negl}({\sf{\lambda}})\right).\] ◻

Finally, \(\varepsilon=1-q_{i^\star}\le 1-\eta^{1/\gamma}\le \log(1/\eta)/\gamma\). Since \(\gamma=\gamma\), the loss term \(2\sqrt{2\varepsilon}\) is \[O\!\left(\sqrt{\frac{\log(1/\eta)}{\gamma}}\right).\] ◻

Lemma 17 (Uniqueness). Assume that \(\mathcal{F}\) is a copy-protectable functionality with security \(\zeta=\zeta({\sf{\lambda}})\), and that \(\mathsf{QSO}\) is an ideal obfuscator. Then, 43 satisfies \(\zeta\)-Uniqueness.

Proof. As noted in [19], \(\mathsf{QSO}\) is a best-possible copy-protector. In other words, if \(\mathcal{F}\) is copy-protectable with security \(\alpha\), then \((\mathsf{QSO}.{\sf QObf},\mathsf{QSO}.{\sf QEval})\) is a copy-protection scheme with security at least \(\alpha\).

We first need to argue that \(\mathsf{QSO}(\widehat{f_{\sf sk}})\) is copy-protected. This is straightforward, since \(\widehat{f_{\sf sk}}\) can always be implemented given only black-box access to \(f\in\mathcal{F}\). Intuitively this means that \(\widehat{f_{\sf sk}}\) is no more learnable than \(\mathcal{F}\) and, more concretely, there is a simple reduction which simply invokes the functionality and computes the signature portion on top of it.

Then, assume that there is an adversary \((\mathcal{P}^*,{\mathcal{I}}_0,{\mathcal{I}}_1)\) for uniqueness against 43, which succeeds with probability greater than \(1-\alpha\). There is immediately an adversary \((\mathcal{A},{\mathcal{B}},{\mathcal{C}})\) for the copy-protection security game against \((\mathsf{QSO}.{\sf QObf},\mathsf{QSO}.{\sf QEval})\) for the signed functionality \(\widehat{f_{sk}}\): \(\mathcal{A}\) is given \(\rho_\mathbf{B}\) by the challenger, samples the rest of \({\sf Setup}\) (which is independent of \(f\)) and gives everything to \(\mathcal{P}^*\), which it simulates until time \(t\). \(\mathcal{A}\)’s two outputs are the registers in regions \(L_0\) and \(L_1\) (along with copies of the public parameters \({\sf{pp}}\)), which are then given to \({\mathcal{B}}:={\mathcal{I}}_0\) and \({\mathcal{C}}:={\mathcal{I}}_1\), respectively. Then, \((\mathcal{A},{\mathcal{B}},{\mathcal{C}})\) succeeds with the same probability as \((\mathcal{P}^*,{\mathcal{I}}_0,{\mathcal{I}}_1)\). ◻

Theorem 52. Let \(\mathcal{F}\) be a classical functionality which is copy-protectable with security \(\zeta({\sf{\lambda}})\). Then there exists a non-destructive functionality localization scheme for \(\mathcal{F}\) with \((1-{\sf negl}({\sf{\lambda}}))\)-Completeness, \(\left(\beta,\Delta \right)\)-Extraction Soundness for \[\beta({\sf{\lambda}},\eta)=\eta({\sf{\lambda}})\left(1-O\!\left(\sqrt{\frac{\log(1/\eta)}{\gamma}}\right)-{\sf negl}({\sf{\lambda}})\right)\] and \(\zeta({\sf{\lambda}})\)-Uniqueness in the classical oracle model. In particular, since we only consider adversaries for which \(1/\eta\) is at most polynomial in \({\sf{\lambda}}\), for any polynomial \(t({\sf{\lambda}})\), we can set \(\gamma=c{\sf{\lambda}}t^2\) for some constant \(c\) to achieve \[\beta({\sf{\lambda}},\eta)=\eta({\sf{\lambda}})\left(1-1/t({\sf{\lambda}})\right)~.\]

Proof. Instantiating 43 in the classical oracle model gives such a scheme as claimed, with the properties following from 15, 16, and 17, respectively. ◻

10 Discussion↩︎

10.1 Publicly-Verifiable Localization↩︎

All of our constructions in 9 utilize some secret parameters \(\mathsf{sp}\) generated by \({\sf Setup}\) and then held privately by the verifiers. The purpose of \(\mathsf{sp}\) is, generally speaking, to serve as a verification key for the protocol – i.e. the eventual accept/reject decision is a deterministic predicate of two things, 1. the (classical) protocol transcript and 2. the secret parameters \(\mathsf{sp}\). It is natural to see if these can be made public, a la publicly-verifiable digital signatures. However unfortunately, in our constructions \(\mathsf{sp}\) contains the coset descriptors \(u,v\) – meaning that a prover knowing \(\mathsf{sp}\), even if he completely discards \(\rho\), could respond to all challenges perfectly, nullifying any extraction guarantees.

An optimistic reader might hope for alternative solutions, and therefore ask:

Are there sound localization schemes in which the verifiers hold no secret information? I.e., schemes where anyone can play the role of the verifiers, and achieve an extraction guarantee?

In this section, we will argue that we can indeed achieve this for entanglement localization, state localization, and trajectory verification, by making a slight modification to our existing constructions. Firstly, we introduce the formal notion of public verifiability.

Definition 14. We say that a localization scheme (e.g. one of Definitions 8,9,10, or 13) is publicly verifiable if the \(\mathsf{Localize}\) protocol takes no private verifier input \(\mathsf{sp}\). In other words, if the interface for the \(\mathsf{Localize}\) protocol can be written as \(\mathsf{Localize}\left(\mathcal{P}(\mathbf{B}) \rightleftharpoons \mathcal{V} \right)({\sf{pp}},\dots)\rightarrow \mathbf{B}',b\).

Next, we will show an idea for how to augment our constructions of each aforementioned localization scheme, so that the verifiers can check the protocol transcript without knowledge of \(u,v\). In order to give the general idea and intuition without getting too deep into the implementation details for each specific protocol, we will keep this explanation relatively high-level.

Theorem 53 (informal). Each of 34, 38, and 36 can be made publicly verifiable19.

Proof. To do this, we will apply the same, simple technique to each construction. As an initial (flawed) attempt, consider adding a public verification oracle like the following: \[{\mathcal{O}}_{\sf ver}(\{\text{challenge}_i\}_i,\{\text{response}_i\}_i)=\begin{cases} \top&\text{if }\text{response}_i={\mathcal{O}}_{\sf random}(\text{challenge}_i)~~\forall i,\\ \bot&\text{otherwise.} \end{cases}\] This is essentially an oracle for the verifiers’ accept/reject decision: it takes as input the entire protocol transcript, and one can check that its acceptance predicate is logically equivalent to the one computed by the verifiers in each of our constructions (under the proper interpretations of “challenge” and “response”).

However, we cannot add such a public oracle – in our reduction to the monogamy game, the simulated prover might play a malicious trick on us: before sending a response, check if it’s correct. If yes, send the response, and if not, instead send garbage. By doing so, a prover has not changed its success probability whatsoever. However, the monogamy game reduction is required to answer queries to this verification oracle – without knowing what the right answers are! So a prover can succeed with very high probability in the real experiment, but might (maliciously) fail to produce correct answers in any reduction where the verification oracle cannot be faithfully simulated.

To get around this, we use the following idea: at the start of \(\mathsf{Localize}\), the verifier will generate a random “key” which somehow gates access to the public verification oracle on a certain set of inputs, and release this key at the very end of the protocol. Challenges are then generated with respect to this key, meaning that the prover is unable to use the public verification oracle on the active protocol transcript until after it has produced all of its responses, circumventing the malicious behavior described above.

One such gating mechanism can be made with a simple hashing trick. Let \(H\) be a new public random oracle, such that \(H\) and \(\mathcal{O}_{\sf ver}\) are now both generated during setup and output as part of the public parameters \({\sf{pp}}\). The verifier will generate the key and challenges jointly at the start of \(\mathsf{Localize}\) as follows: \[\text{key}\gets\left\{0,1\right\}^n~,\] \[\text{challenge}_n=H(\text{key}),~~\text{challenge}_{n-1}=H(\text{challenge}_n)=H^{(2)}(\text{key}),~~\cdots~~,\text{challenge}_1=H^{(n-1)}(\text{key})~.\] These challenges will then be directly used in place of the randomly-generated challenges from our original, privately-verifiable protocols. Additionally, we will now swap out the faulty verification oracle from above, and use the following new one which will be generated in \({\sf Setup}\) jointly with \(H\): \[{\mathcal{O}}_{\sf ver}(\text{key},\{\text{challenge}_i\}_i,\{\text{response}_i\}_i)=\begin{cases} \top&\text{if }H^{(i)}(\text{key})=\text{challenge}_i~~\forall i\\ &\land~~\text{response}_i={\mathcal{O}}_{\sf random}(\text{challenge}_i)~~\forall i,\\ \bot&\text{otherwise.} \end{cases}\] Finally, the verifier broadcasts the key in a secret-shared manner (like all of the challenges) after all prover responses have been received, thus enabling public verification of the transcript.

To argue that this transformation preserves extraction soundness, we will describe the reduction from a given round \(i\) of the publicly-verifiable protocol to the MultiStageIndependentMonogamy game — an updated version of the reduction \(\mathcal{A}\) defined in 32. The reduction will work in the same way as for the original schemes, except that it is now tasked with simulating the new oracles \(\mathcal{O}_{\sf ver}\) and \(H\), as well as generating challenges and the key in the updated way. It uses a fresh \(2q\)-wise independent hash function to simulate \(H\) in the same way as was done for \(\mathcal{O}_{\sf random}\), and generates simulated verifier challenges and key according to \(H\) just as in the modified construction. It remains to show that \(\mathcal{O}_{\sf ver}\) can be simulated. On a query \(({\sf key}',\{\text{challenge}'_i\}_i,\{\text{response}'_i\}_i)\), \(\mathcal{A}\) first checks if \({\sf challenge}'_i=(\theta_0,x_{L,0}\oplus x_{R,0})\) or \({\sf challenge}'_i=(\theta_1,x_{L,1}\oplus x_{R,1})\) for any \(i\). If yes, then it outputs \(\bot\), otherwise it checks the predicate according to its simulated \(\mathcal{O}_{\sf random}\) and \(H\) and outputs appropriately. We then use a standard one-way to hiding argument to show that this simulation is computationally indistinguishable from the real experiment, since it is clearly hard to find any value \({\sf key}'\) such that \(x_{L,0}\oplus x_{R,0}\) or \(x_{L,1}\oplus x_{R,1}\) is an iterate of \({\sf key}'\) under \(H\). Thus, the reduction still wins with only negligible loss, and extraction proceeds as usual. ◻

10.1.1 Applications to Black-Box Trajectory Verification↩︎

Aside from being an interesting and desirable property on its own, public verifiability of localization protocols has a secondary benefit: allowing trajectory verification to be constructed in a relatively black-box way from a state or entanglement localization protocol. The construction is simple: run \({\sf Setup}\) as normal, and then execute back-to-back instances of \(\mathsf{Localize}\) for each checkpoint along the trajectory. The details are somewhat tedious, so we will argue about this construction at a very high level.

For completeness to hold, we must be careful that completeness of the localization protocol still holds when the prover is moving along the trajectory rather than staying in place (a la 11), and that non-destructiveness of \(\mathsf{Localize}\) applies over a short enough timescale such that the prover’s state \(\rho\) can be plugged into the next instance right away.

As for soundness, public verifiability allows for a simple black-box reduction: given an adversary for trajectory verification, simulate rounds 1 through \(i\) via the public verification algorithm. Then, forward the real \(\mathsf{Localize}\) challenges to the adversary for the given round, which it should win with high probability.

10.2 Position-Based Cryptography↩︎

Position-based authentication (PBA) is a position-based cryptographic primitive that naturally extends plain position verification, and was initially introduced together with the original construction of QPV, in Buhrman et al. ([3]). In a PBA protocol, the honest prover decides on a message \(m\) to relay to the verifiers, and the security guarantee is twofold: 1. When the honest prover is positioned in the secure location, no coalition of malicious parties located elsewhere can successfully tamper with the authenticated message, and 2. A coalition of parties with nobody in the secure location cannot pass the authentication protocol, regardless of the message. The applications of such a scheme are quite numerous and natural, e.g. authenticating military orders from a secure command center, arguably even more so than for plain position verification. As for building PBA, [3] gave a construction based on any black-box quantum position verification scheme, and Unruh showed that their QROM \(f\)-BB84 position verification scheme could be straightforwardly extended to a PBA scheme secure against all QPT attackers in the QROM ([8]).

However, we will now point out that the security notion described above, under which all PBA schemes from prior literature are proven secure, seems unsatisfying when put under scrutiny. Points 1 and 2 above rule out attacks where nobody is in the secure location, or where the honest prover algorithm runs in the presence of malicious tampering parties, but does not rule out attacks where there might be a distributed attack involving a (potentially unwitting) party in the secure location. In particular, the distributed attack on \(f\)-BB84 described in 1.5 (and depicted in 2) is an example of such an attack on the PBA scheme of Buhrman et al., when their scheme is instantiated with the \(f\)-BB84 QPV scheme.

10.2.1 An explicit “attack” scenario↩︎

We briefly describe an adversarial strategy for the PBA construction of [3], which does not constitute an attack according to the standard security definition, but is nonetheless a concerning scenario for any real-world application of PBA. To describe this attack we’ll first give a summary of their construction.

Construction 54 ([3]). Take a QPV protocol whose routines are described as \(({\sf Chal},{\sf Resp},{\sf Ver})\): \({\sf Chal}\) generates verifier challenges, and \({\sf Resp}\) computes the prover’s response, which is finally checked by \({\sf Ver}\)(including timings). Now, suppose the prover wishes to authenticate a bit \(c\in\{0,1\}\).

  1. First, the prover computes \(m={\sf Enc}(c)\), according to some carefully chosen multi-bit encoding \({\sf Enc}\).

  2. Next, for each bit \(m_i\), the prover and verifier run the following protocol:

    • Verifiers send challenges \(c_L,c_R\gets{\sf Chal}(1^{\sf{\lambda}})\).

    • If \(m_i=1\), the prover responds to both verifiers with \(r_i\gets{\sf Resp}(c_L,c_R)\). If \(m_i=0\), however, the prover sends \(r_i=\bot\) to both verifiers with some probability \(q\), and otherwise responds honestly.

  3. The verifiers compute \(b\gets{\sf Dec}(\{i:{\sf Ver}(r_i)=\top\})\).

Intuitively, this protocol is secure in their model because if nobody is at the purported location, then indeed there is nothing a malicious prover can do to inject 1s into the encoding of the message. Injecting 0s is easier, since anyone can send \(\bot\), but the encoding prevents this from ever succeeding to tamper with the true message bit.

We now get to describing our “attack”. Imagine that there are three provers, \(P_L,P_M,P_R\), where only \(P_M\) is at the true location. They participate in the scheme of 54 where the QPV scheme is \(f\)-BB84, and have the following strategy. Say, without loss of generality, that the BB84 qubit comes from the left.

  • \(P_L\) and \(P_R\) pre-determine a message bit \(c\in\{0,1\}\). They compute the encoding \({\sf Enc}(c)\), and execute the following strategy for each index \(i\) of the encoded string:

    1. When \(P_L\) receives the qubit \(H^\theta\left|b\right\rangle\), it applies a quantum one-time pad \(X^rZ^s\), where the one-time pad key \((r,s)\) belongs to private shared randomness of \(P_L\) and \(P_R\). Importantly, \(P_M\) never sees this key. \(P_L\) forwards the scrambled qubit to \(P_M\).

    2. When \(P_M\) receives the qubit, it measures in the correct basis determined by the \(f\)-BB84 challenges. It sends the measurement outcome \(b'\) to \(P_L\) and \(P_R\).

    3. \(P_L\) and \(P_R\) receive this measurement outcome, and by this time they also have full knowledge of the \(f\)-BB84 challenges. Namely, they know which basis the middle prover measured in, and thus which correction to apply from the quantum one-time pad in order to find the intended measurement outcome \(b\).

    4. If \(m_i=1\), then \(P_L\) and \(P_R\) send the outcome \(b\) to their respective nearest provers. Otherwise, if \(m_i=0\), then with probability \(q\) they instead send \(\bot\) to each prover.

It is clear that this attack would not violate the typical security definition, since it involves active participation from a prover \(P_M\) who is in the secure location. However, there is a very concerning property of this scheme – namely, that \(P_M\) is entirely unaware of the message being authenticated. In other words, there might be a prover in the right location who was simply tricked into participating, and the authenticated message in no way originates from the secure location.

10.2.2 Towards stronger security notions↩︎

To address this attack, we give some informal directions for tackling this weakness in the security definition of PBA. We propose that the localization techniques developed in this paper, for example that of functionality localization, could be used to rule out this class of cheating strategies where the middle prover is acting blindly, without knowledge of the message.

A concrete idea is the following (informal) PBA scheme:

  • Let \(\mathcal{F}=\{f_k\}_k\) be a PRF. Take \(({\sf Setup},\mathsf{Localize},{\sf Eval})\) from the functionality localization scheme in 43 instantiated for \(\mathcal{F}\). Let \(H\) be a public random oracle.

  • The verifiers run \({\sf{pp}},\mathsf{sp},f_k,\rho\gets{\sf Setup}(1^\lambda)\), and send \({\sf{pp}},\rho\) to the prover. Next, they sample two random challenge strings \(c_L,c_R\in\{0,1\}^{\sf{\lambda}}\).

  • Two routines are executed simultaneously:

    • The prover and verifiers execute \[\mathsf{Localize}\big( P(\rho) \rightleftharpoons V(\mathsf{sp},f)\big)({\sf{pp}},L,t)\]

    • The left and right verifiers send \(c_L\) and \(c_R\), respectively, towards \((L,t)\). The prover receives these, computes \(c:=c_L\oplus c_R\) and runs \(y\gets{\sf Eval}(\rho,H(m||c))\). The prover sends \((m,y)\) to both verifiers simultaneously.

  • The verifiers accept iff \(\mathsf{Localize}\) accepted and \(y=f_k(H(m||(c_L\oplus c_R)))\).

Intuitively, the point of this construction is to authenticate the prover’s message with the copy-protected PRF, which is simultaneously being localized to a single position. If a group of provers pass this protocol with high probability, then soundness of functionality localization guarantees that we can extract the ability to sign (say, uniformly random) messages from the circuits at the secure location. Uniqueness also guarantees that this cannot be happening anywhere else at time \(t\). Thus, when the verifiers receive the signed message \(m,f_k(H(m||c))\), we know that this evaluation must have taken place locally at the secure location, which additionally tells us that the prover queried the oracle value \(H(m||c)\) at this location at time \(t\). The techniques from our localization constructions would then allow this query to be recorded and “extracted” from the prover’s circuitry at that position.

We leave further exploration of this direction to future work, e.g. formalize a stronger notion of security for position-based authentication and analyze the above construction in terms of said notion.

References↩︎

[1]
A. Kent, W. J. Munro, and T. P. Spiller, “Quantum tagging: Authenticating location via quantum information and relativistic signaling constraints,” Phys. Rev. A, vol. 84, p. 012326, 2011, doi: 10.1103/PhysRevA.84.012326.
[2]
N. Chandran, V. Goyal, R. Moriarty, and R. Ostrovsky, “Position based cryptography,” in Annual international cryptology conference, 2009, pp. 391–407.
[3]
H. Buhrman et al., “Position-based quantum cryptography: Impossibility and constructions,” SIAM J. Comput., vol. 43, no. 1, pp. 150–178, 2014, doi: 10.1137/130913687.
[4]
M. Tomamichel, S. Fehr, J. Kaniewski, and S. Wehner, “A monogamy-of-entanglement game with applications to device-independent quantum cryptography,” New Journal of Physics, vol. 15, no. 10, p. 103002, 2013, doi: 10.1088/1367-2630/15/10/103002.
[5]
A. Bluhm, M. Christandl, and F. Speelman, “Position-based cryptography: Single-qubit protocol secure against multi-qubit attacks.” 2021, [Online]. Available: https://arxiv.org/abs/2104.06301v2.
[6]
V. R. Asadi, E. Culf, and A. May, “Rank lower bounds on non-local quantum computation.” 2025, [Online]. Available: https://arxiv.org/abs/2402.18647.
[7]
V. Asadi, R. Cleve, E. Culf, and A. May, “Linear gate bounds against natural functions for position-verification,” Quantum, vol. 9, p. 1604, Jan. 2025, doi: 10.22331/q-2025-01-21-1604.
[8]
D. Unruh, “Quantum position verification in the random oracle model,” in Advances in cryptology - CRYPTO 2014 - 34th annual cryptology conference, santa barbara, CA, USA, august 17-21, 2014, proceedings, part II, 2014, vol. 8617, pp. 1–18, doi: 10.1007/978-3-662-44381-1_1.
[9]
U. Girish, G. Gluch, S. Goldwasser, T. Malkin, L. Orshansky, and H. Yuen, “Private proofs of when and where,” arXiv preprint arXiv:2601.18961, 2026.
[10]
J. Liu, Q. Liu, and L. Qian, “Beating classical impossibility of position verification,” arXiv preprint arXiv:2109.07517, 2021.
[11]
S. Aaronson, “Quantum copy-protection and quantum money,” in Proceedings of the 2009 24th annual IEEE conference on computational complexity, 2009, pp. 229–242, doi: 10.1109/CCC.2009.42.
[12]
S. Aaronson, J. Liu, Q. Liu, M. Zhandry, and R. Zhang, “New approaches for quantum copy-protection,” in Advances in cryptology – CRYPTO 2021: 41st annual international cryptology conference, CRYPTO 2021, virtual event, august 16–20, 2021, proceedings, part i, 2021, pp. 526–555, doi: 10.1007/978-3-030-84242-0_19.
[13]
A. Coladangelo, J. Liu, Q. Liu, and M. Zhandry, “Hidden cosets and applications to unclonable cryptography,” in Advances in cryptology – CRYPTO 2021: 41st annual international cryptology conference, CRYPTO 2021, virtual event, august 16–20, 2021, proceedings, part i, 2021, pp. 556–584, doi: 10.1007/978-3-030-84242-0_20.
[14]
A. Coladangelo, C. Majenz, and A. Poremba, “Quantum copy-protection of compute-and-compare programs in the quantum random oracle model,” Quantum, vol. 8, p. 1330, May 2024, doi: 10.22331/q-2024-05-02-1330.
[15]
J. Liu, Q. Liu, L. Qian, and M. Zhandry, “Collusion resistant copy-protection for watermarkable functionalities,” in Theory of cryptography: 20th international conference, TCC 2022, chicago, IL, USA, november 7–10, 2022, proceedings, part i, 2022, pp. 294–323, doi: 10.1007/978-3-031-22318-1_11.
[16]
P. Ananth and A. Behera, “A modular approach to unclonable cryptography,” in Advances in cryptology – CRYPTO 2024: 44th annual international cryptology conference, santa barbara, CA, USA, august 18–22, 2024, proceedings, part VII, 2024, pp. 3–37, doi: 10.1007/978-3-031-68394-7_1.
[17]
P. Ananth, A. Behera, Z. Huang, F. Kitagawa, and T. Yamakawa, “Copy-protection from unclonable puncturable obfuscation, revisited,” in Advances in cryptology – EUROCRYPT 2026, 2026, pp. 541–570.
[18]
A. Çakan and V. Goyal, “How to copy-protect malleable-puncturable cryptographic functionalities under arbitrary challenge distributions: A unified solution to quantum protection,” in Advances in cryptology – EUROCRYPT 2026, 2026, pp. 481–509.
[19]
A. Coladangelo and S. Gunn, “How to use quantum indistinguishability obfuscation,” in Proceedings of the 56th annual ACM symposium on theory of computing, 2024, pp. 1003–1008, doi: 10.1145/3618260.3649779.
[20]
J. Bartusek, Z. Brakerski, and V. Vaikuntanathan, “Quantum state obfuscation from classical oracles,” in Proceedings of the 56th annual ACM symposium on theory of computing, 2024, pp. 1009–1017, doi: 10.1145/3618260.3649673.
[21]
S. Aaronson and P. Christiano, “Quantum money from hidden subspaces,” in Proceedings of the forty-fourth annual ACM symposium on theory of computing, 2012, pp. 41–60, doi: 10.1145/2213977.2213983.
[22]
S. Ben-David and O. Sattath, “Quantum Tokens for Digital Signatures,” Quantum, vol. 7, p. 901, Jan. 2023, doi: 10.22331/q-2023-01-19-901.
[23]
J. Bartusek and G. Malavolta, Indistinguishability Obfuscation of Null Quantum Circuits and Applications,” in 13th innovations in theoretical computer science conference (ITCS 2022), 2022, vol. 215, pp. 15:1–15:13, doi: 10.4230/LIPIcs.ITCS.2022.15.
[24]
J. Bartusek, F. Kitagawa, R. Nishimaki, and T. Yamakawa, “Obfuscation of pseudo-deterministic quantum circuits,” in Proceedings of the 55th annual ACM symposium on theory of computing, 2023, pp. 1567–1578, doi: 10.1145/3564246.3585179.
[25]
M.-Y. M. Huang and E.-C. Tang, Obfuscation of Unitary Quantum Programs ,” in 2025 IEEE 66th annual symposium on foundations of computer science (FOCS), Dec. 2025, pp. 1665–1671, doi: 10.1109/FOCS63196.2025.00088.
[26]
M. M.-Y. Huang and E.-C. Tang, “Obfuscation of arbitrary quantum circuits.” 2026, [Online]. Available: https://arxiv.org/abs/2601.08969.
[27]
B. Barak et al., “On the (im)possibility of obfuscating programs,” J. ACM, vol. 59, no. 2, pp. 6:1–6:48, 2012.
[28]
J. Bartusek, R. Jawale, J. Raizes, and K. Tomer, “A new approach to arguments of quantum knowledge.” 2025, [Online]. Available: https://arxiv.org/abs/2510.05316.
[29]
A. Jain, H. Lin, J. Luo, and D. Wichs, “The pseudorandom oracle model and ideal obfuscation,” in Advances in cryptology – CRYPTO 2023, 2023, pp. 233–262.
[30]
M. Zhandry, “How to construct quantum random functions,” J. ACM, vol. 68, no. 5, Aug. 2021, doi: 10.1145/3450745.
[31]
F. Kaleoglu et al., “On the equivalence between classical position verification and certified randomness.” 2025, [Online]. Available: https://arxiv.org/abs/2410.03982.
[32]
Y. T. Kalai, D. Khurana, and J. Raizes, “How to classically verify a quantum cat without killing it.” 2026, [Online]. Available: https://arxiv.org/abs/2602.09282.
[33]
T. Vidick and T. Zhang, “Classical proofs of quantum knowledge.” 2021, [Online]. Available: https://arxiv.org/abs/2005.01691.
[34]
M. Zhandry, “How to record quantum queries, and applications to quantum indifferentiability,” in Annual international cryptology conference, 2019, pp. 239–268.
[35]
N. Chandran, V. Goyal, R. Moriarty, and R. Ostrovsky, “Position-based cryptography,” SIAM J. Comput., vol. 43, no. 4, pp. 1291–1341, 2014, doi: 10.1137/100805005.
[36]
Z. Hao, Z. Huang, and Q. Liu, “On the need for (quantum) memory with short outputs.” 2026, [Online]. Available: https://arxiv.org/abs/2602.23763.
[37]
F. Kitagawa and T. Yamakawa, “Foundations of single-decryptor encryption.” Cryptology ePrint Archive, Paper 2025/1219, 2025, [Online]. Available: https://eprint.iacr.org/2025/1219.
[38]
M. Zhandry, “Secure identity-based encryption in the quantum random oracle model,” in Advances in cryptology - CRYPTO 2012 - 32nd annual cryptology conference, santa barbara, CA, USA, august 19-23, 2012. proceedings, 2012, vol. 7417, pp. 758–775, doi: 10.1007/978-3-642-32009-5_44.

  1. We provide more details about this model, which is sometimes referred to as the classical oracle model, in 1.4.↩︎

  2. Technically, \(H\) will be implemented by a pseudorandom function so that the oracle \(\mathcal{O}\) is efficiently computable.↩︎

  3. One way to check this is to have the verifiers remember a secret verification key \({\sf sk}= (u,v)\) consisting of the shifts and have them query \({\mathcal{O}}(a \oplus b,v)\) and \({\mathcal{O}}(a \oplus b,u)\).↩︎

  4. For technical reasons, our actual protocol is slightly more elaborate than this, where the standard- and Hadamard-basis queries are sequentially staggered (by a tiny time difference). We elaborate more on this in 2.↩︎

  5. Again, the actual trajectory verification protocol we construct is slightly different, for technical reasons.↩︎

  6. We note that the description of this game is slightly inaccurate, and we refer the reader to 6, and in particular 9, for formal details.↩︎

  7. We note that one could alternatively specify that the verify sent strictly alternating challenges, but this requires it to keep some state in between each challenge, which may be undesirable.↩︎

  8. Technically, we say that a functionality is “copy-protectable” if there exists some distribution \(\mathcal{D}\) over inputs such that \(\mathcal{F}\) is copy-protectable with respect to independent challenges \(x_0,x_1\) sampled from \(\mathcal{D}\). See 9.4 for more details.↩︎

  9. It is natural to ask whether our protocols can be extended to work in standard three-dimensional space. We expect that, similarly to [8], there is a natural generalization to three dimensions which can be then compiled to a more abstracted causal circuit, and analyzed without dealing with three-dimensional geometry. However, we leave this generalization as an open problem.↩︎

  10. This restriction is without loss of generality. Since we assume – as is standard in QPV literature – that all computation is instantaneous, any computation which is being done locally at one cell, whether the cell is stationary or moving, can always be freely pushed forward or backward to the nearest intersection points with other cells.↩︎

  11. In general, we should allow any quantum verifier. Nevertheless, our construction achieves classical verification.↩︎

  12. In reality, we localize a family of bipartite states indexed by \({\sf{\lambda}}\), i.e. \(\Sigma=\{\sigma_{\sf{\lambda}}\}_{\sf{\lambda}}\). As is standard in these contexts, we suppress the dependence on \({\sf{\lambda}}\) for notational convenience, and simply write \(\sigma\).↩︎

  13. Technically, a sequence of states indexed by \({\sf{\lambda}}\) – see 12.↩︎

  14. To enable extraction from all points along the trajectory, we must send a round of challenges after* the prover has already reached the endpoint \((L(\tau),\tau)\). We define the extension \(\widetilde{L}\) for notational convenience when sending these post-trajectory challenges.*↩︎

  15. Technically, we have one state family per security parameter \({\sf{\lambda}}\) – see 12↩︎

  16. It is crucial that this extractor does not know \(i\).↩︎

  17. In this purified version, the family of states is indexed by \(U,x\). There is a one-to-one correspondence between \(U,x\) and, \(i\) which we used in the original definition.↩︎

  18. Technically, we have one function family per security parameter \({\sf{\lambda}}\) – see 12↩︎

  19. We leave out functionality localization from this statement, because it is unclear how public verifiability should be defined with respect to the private functionality \(f\). If \(f\) itself has a natural notion of public verification (e.g. if \(f\) is a copy-protectable signing algorithm for a public-key signature scheme), then we could potentially hope to extend the techniques in this section to allow such a functionality \(f\) to be localized in a publicly verifiable way.↩︎