We explore a very simple distribution of unitaries: random (binary) phase -- Hadamard -- random (binary) phase -- random computational-basis permutation. We show that this distribution is statistically indistinguishable from random Haar unitaries for any polynomial set of orthogonal input states (in any basis) with polynomial multiplicity. This shows that even though real-valued unitaries cannot be completely pseudorandom (Haug, Bharti, Koh, arXiv:2306.11677), we can still obtain some pseudorandom properties without giving up on the simplicity of a real-valued unitary. Our analysis shows that an even simpler construction: applying a random (binary) phase followed by a random computational-basis permutation, would suffice, assuming that the input is orthogonal and \emph{flat} (that is, has high min-entropy when measured in the computational basis). Using quantum-secure one-way functions (which imply quantum-secure pseudorandom functions and permutations), we obtain an efficient cryptographic instantiation of the above.
翻译:我们研究了一种非常简单的酉变换分布:随机(二进制)相位-哈达玛变换-随机(二进制)相位-随机计算基置换。我们证明,对于任何具有多项式重数的正交输入状态(在任何基下)的多项式集合,该分布在统计上与随机Haar酉变换不可区分。这表明尽管实值酉变换无法完全实现伪随机性(Haug, Bharti, Koh, arXiv:2306.11677),我们仍能在不放弃实值酉变换简洁性的前提下获得某些伪随机性质。我们的分析表明,一个更简单的构造:对输入施加随机(二进制)相位后接随机计算基置换即可满足要求,前提是输入是正交且"平坦"的(即在计算基下测量时具有高最小熵)。利用量子安全单向函数(这意味着量子安全伪随机函数和置换),我们实现了上述构造的高效密码学实例化。