← Latest papers
⚛️ quantum physics

How Not to Build Microcrypt

This paper introduces efficient NP-aided shadow tomography to demonstrate that many proposed constructions for quantum pseudorandomness, including those designed to avoid one-way functions, inadvertently imply the existence of one-way functions or NP-hardness, thereby establishing new no-go results for building such primitives outside the NP complexity class.

Original authors: Aditya Gulati (UCSB), Dakshita Khurana (UIUC,NTT Research), Kabir Tomer (UIUC)

Published 2026-09-25
📖 6 min read🧠 Deep dive

Original authors: Aditya Gulati (UCSB), Dakshita Khurana (UIUC,NTT Research), Kabir Tomer (UIUC)

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). ✨ This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

In the quiet, high-stakes world of quantum cryptography, scientists are trying to build locks that cannot be picked, even by a computer that uses the strange rules of quantum mechanics. For decades, the foundation of all secure communication has been the "one-way function," a mathematical lock that is easy to lock but incredibly hard to unlock without a specific key. However, a new frontier has emerged called Microcrypt, a theoretical realm where researchers hope to build secure quantum systems even if those traditional one-way locks do not exist. The goal is to find new, weaker assumptions that are still strong enough to protect secrets. To do this, they have proposed new types of digital objects, such as "pseudorandom states" and "pseudorandom unitaries," which are designed to look like random noise to anyone who does not have the secret key, but are actually generated by a specific, hidden process. The big question has been whether these new objects can truly exist without relying on the old, stronger locks, or if they secretly depend on them.

A team of researchers from the University of California, Santa Barbara, the University of Illinois, and NTT Research has now answered this question with a decisive "no" for many of the leading candidates. They have developed a new method to analyze these quantum objects and have proven that several popular designs, which were thought to be safe even without traditional one-way functions, actually fail when faced with a specific type of powerful adversary. Their work shows that if you try to build these quantum locks using certain common architectural blueprints, you inadvertently create a traditional one-way function anyway. This means that the promise of building quantum cryptography on weaker foundations is more difficult than previously hoped, and many of the current favorite designs are not the solution.

The researchers' breakthrough comes from a technique they call "shadow tomography," which is a way of taking a quantum state and creating a compact classical record of it. Imagine trying to understand the shape of a complex, invisible object by shining light on it from different angles and recording the shadows it casts. In the quantum world, this process involves measuring copies of a quantum state to gather information about its structure. The team realized that for a large class of these proposed quantum states, the information gathered from these shadows is so structured that a computer with access to a specific type of logical helper—an "NP oracle"—can use it to reverse-engineer the secret key. An NP oracle is a theoretical tool that can instantly solve certain types of complex search problems, acting like a super-intelligent assistant that can check if a solution exists without having to try every single possibility one by one.

The researchers demonstrated that for many proposed quantum states, the process of finding the secret key becomes a simple search task for this helper. They showed that if the quantum state is "computable," meaning its internal numbers can be calculated by a standard computer, then an adversary with this logical helper can efficiently figure out the key. This effectively breaks the security of the system. The team applied this method to a prominent candidate known as Hamiltonian Phase States, which had been widely believed to be a safe building block for cryptography without one-way functions. Their analysis proved that these states are not safe; if they exist, they imply the existence of a traditional one-way function. This result shatters the hope that this specific design could bypass the need for stronger assumptions.

The investigation did not stop at states. The researchers also turned their attention to "pseudorandom unitaries," which are more complex quantum operations that transform data in a way that looks random. These are considered the most powerful tools in the Microcrypt toolkit. The team identified a common architectural pattern used in many of the most promising designs for these unitaries: a structure where a simple, predictable layer is sandwiched between two layers of "Clifford" operations, which are a specific type of quantum gate. They found that this specific arrangement, known as a CMC construction, leaves a distinct fingerprint. By using a special type of measurement involving entangled pairs of particles, they could extract classical clues about the hidden permutation inside the middle layer. With the help of the logical assistant, they could then search for a key that explains all the observed clues. If the unitary was truly random, no single key would ever explain all the clues. But if it was built using this specific architecture, the correct key would always fit the clues perfectly.

This discovery means that a wide range of recent proposals for secure quantum unitaries, including those that were explicitly designed to avoid one-way functions, are actually vulnerable. The researchers showed that these designs can be distinguished from true randomness and their secret keys can be recovered. They tested their method against several well-known constructions, such as those based on "PFC" (Permutation-Function-Clifford) structures and various "LRFC" (Luby-Rackoff-Function-Clifford) designs. In every case where the middle layer was a simple permutation or phase shift, the attack succeeded. The team proved that these architectures cannot be the foundation for Microcrypt because they inevitably lead back to the existence of one-way functions, defeating the purpose of trying to build cryptography on weaker assumptions.

However, the paper does not close the door on Microcrypt entirely. The researchers carefully mapped out which designs survived their attack and which did not. They found that constructions involving multiple, overlapping layers of mixing or those that use secret, non-Clifford operations in the endpoints might still be safe. These surviving candidates are now the focus for future research. The work serves as a crucial guide, or a set of guardrails, for the field. It tells scientists what not to build, preventing them from wasting time on blueprints that are fundamentally flawed. By ruling out these common approaches, the researchers have forced the community to look for fundamentally different architectures that do not inadvertently create one-way functions.

The implications of this work are profound for the future of quantum security. It clarifies that the path to building quantum cryptography without one-way functions is narrower and more treacherous than previously thought. The researchers have provided a rigorous method to test new proposals, ensuring that future designs are not just theoretically interesting but actually secure against the most powerful known attacks. Their findings suggest that if Microcrypt is to be realized, it will require entirely new ways of thinking about quantum operations, moving away from the familiar patterns that have dominated the field so far. The work stands as a testament to the power of systematic analysis in science, where proving what does not work is just as important as discovering what does.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →