We propose an application for near-term quantum devices: namely, generating cryptographically certified random bits, to use (for example) in proof-of-stake cryptocurrencies. Our protocol repurposes the existing "quantum supremacy" experiments, based on random circuit sampling, that Google and USTC have successfully carried out starting in 2019. We show that, whenever the outputs of these experiments pass the now-standard Linear Cross-Entropy Benchmark (LXEB), under plausible hardness assumptions they necessarily contain $\Omega(n)$ min-entropy, where $n$ is the number of qubits. To achieve a net gain in randomness, we use a small random seed to produce pseudorandom challenge circuits. In response to the challenge circuits, the quantum computer generates output strings that, after verification, can then be fed into a randomness extractor to produce certified nearly-uniform bits -- thereby "bootstrapping" from pseudorandomness to genuine randomness. We prove our protocol sound in two senses: (i) under a hardness assumption called Long List Quantum Supremacy Verification, which we justify in the random oracle model, and (ii) unconditionally in the random oracle model against an eavesdropper who could share arbitrary entanglement with the device. (Note that our protocol's output is unpredictable even to a computationally unbounded adversary who can see the random oracle.) Currently, the central drawback of our protocol is the exponential cost of verification, which in practice will limit its implementation to at most $n\sim 60$ qubits, a regime where attacks are expensive but not impossible. Modulo that drawback, our protocol appears to be the only practical application of quantum computing that both requires a QC and is physically realizable today.
翻译:我们提出了一种近期量子设备的应用:即生成经密码学认证的随机比特,用于(例如)权益证明加密货币。该协议重新利用了2019年以来谷歌和中国科学技术大学成功开展的基于随机电路采样的现有"量子霸权"实验。我们证明,当这些实验的输出通过当前标准的线性交叉熵基准(LXEB)时,在合理的硬度假设下,它们必然包含Ω(n)的最小熵,其中n为量子比特数。为实现随机性的净增益,我们使用少量随机种子生成伪随机挑战电路。量子计算机针对挑战电路生成输出字符串,经验证后输入随机提取器以产生经认证的近乎均匀比特——从而通过"自举"过程将伪随机性转化为真正的随机性。我们从两个角度证明协议的可证安全性:(i) 在随机预言机模型中论证的"长列表量子霸权验证"硬度假设下,以及(ii) 在随机预言机模型中针对可与设备共享任意纠缠的窃听者无条件成立。(注意:即使面对能查看随机预言机的计算无界敌手,我们协议的输出仍不可预测。)当前协议的核心缺陷在于验证的指数级成本,这在实际中将限制其实施至多约n~60量子比特——在该规模下攻击虽然昂贵但并非不可能。撇开此缺陷,我们的协议似乎是量子计算领域唯一既需要量子计算机又能在当下物理实现的实用型应用。