Search arXivSearch

arXiv subjects

Alex May

Publications and source records attributed to Alex May.

At least 19 recordsLinked to original sources

Quantum gate lower bounds for loss-tolerant position verification

Quantum position-verification is a cryptographic task wherein a verifier attempts to establish the location in space of a prover. Recent experiments have implemented a well-studied class of position-verification schemes, known as the $f$-BB84 scenario, but their security under realistic loss and imperfect state preparation remains incompletely understood. We give a new lower bound on any attack on this scheme, in particular proving nearly-linear quantum gate lower bounds on the attacker, even when allowing the attacker to declare a transmission loss of up to $50\%$, allowing for the challenges prepared by the referee to be imperfect, and allowing the quantum messages used in the protocol to be arbitrarily slow. Our results are applicable to recent and upcoming experimental implementations of $f$-BB84, and in particular establish their security under a bounded quantum gate assumption on the attacker. The key ingredient is a tight analytic tradeoff for a lossy BB84 monogamy-of-entanglement game, valid without requiring the attackers' outputs to agree, which replaces observations previously made numerically.

quant-ph

Equivalence of non-local computation tasks beyond Clifford operations

Non-local quantum computation (NLQC) studies how two collaborating players can implement channels on distributed systems using a single simultaneous round of quantum communication and shared entanglement. NLQC has applications in diverse areas, ranging from quantum position-verification to quantum gravity. Recently, it has been realized that the relationships among families of NLQC tasks are highly structured: many seemingly distinct tasks are related by reductions, wherein implementations of one task can be used to efficiently implement a second task. This is analogous to the notion of reduction in complexity theory, and reveals the relative hardness of NLQC tasks. In this work we continue the study of reductions among NLQC tasks. We focus on NLQC examples of the greatest interest in quantum position-verification; in particular examples involving large classical inputs and fixed-size quantum inputs, since these constitute the most feasible protocols for position-verification schemes. Within this setting, we find many new relationships among NLQC tasks. For instance, protocols for the simplest example of redirecting a quantum system based on a classical control imply protocols for controlled single qubit measurements in arbitrary bases, the controlled application of any Clifford unitary, and even the controlled application of any unitary of the form $U=C_1DC_0$ with $D$ an arbitrary diagonal unitary and $C_0, C_1$ Clifford circuits. This implies that many feasible position-verification schemes have the same asymptotic scaling for their entanglement cost, and hence a similar level of security. Our techniques rely on ideas from gate teleportation and measurement based quantum computation, among other areas, bringing several new strategies into NLQC which may be of independent interest.

quant-ph

New bounds on private simultaneous quantum message passing

In the private simultaneous message (PSM) setting, $k$ players obtain inputs $x_i\in\{0,1\}^n$ and then each send messages to a referee, who should learn $f(x_1,...,x_k)$ but no other information about $(x_1,...,x_k)$. The PSM setting was introduced as a minimal model for secure multiparty computation and has connections to Boolean function complexity. In the quantum setting, PSM has been related to non-local quantum computation (NLQC). The communication and correlation cost of implementing PSM remains poorly understood. Here, we give new upper and lower bounds on the (quantum) PSM model. For lower bounds, we show: 1) Ne\v{c}iporuk's measure lower bounds the entanglement required for $k$-player quantum PSM with perfect correctness. This leads to quadratic lower bounds for explicit functions. 2) The rank of the communication matrix of $f(x_1,x_2)$ lower bounds 2-player quantum PSM with perfect privacy but imperfect correctness. This implies a previously unknown lower bound on classical PSM with imperfect correctness. When allowing quantum communication and shared entanglement, these are the first lower bounds on quantum PSM that make use of the privacy condition. For upper bounds, we show: 1) Letting $s$ be the size of a quantum circuit computing $f$, $d_f$ be the circuit depth, $k$ the number of players, $n$ the number of bits received by each player, and $\epsilon$ a correctness parameter, we obtain $\mathsf{PSM}_k^*(f) \leq (kn +s) \cdot \log^{O(d_f)}(s/\epsilon)$. 2) The square of the Fourier 1 norm of $f$, $\Vert \hat{f}\Vert_1^2$, upper bounds the classical PSM complexity, $\mathsf{PSM}(f)\leq O(\Vert \hat{f} \Vert^2_1)$. In proving the first upper bound, we generalize existing $T$-depth based techniques for NLQC from $2$ to $k\geq 2$ parties, and consider cases where the Clifford layers are restricted to having small light cones.

quant-ph

Entanglement cost in non-local quantum computation

This is a book-length treatment of the subject of non-local quantum computation (NLQC). NLQC is a method for implementing quantum operations that interact two systems without directly bringing the systems together. Instead, a single round of communication and shared entanglement is used. NLQC has appeared in the context of quantum cryptography, computational complexity, communication complexity, quantum gravity, and other applications. The understanding of entanglement cost in NLQC is closely tied to questions in all of these areas. We review upper and lower bounds on entanglement cost, as well as some of the applications of NLQC and its connections to other subjects.

quant-ph

Lower bounds on non-local computation from controllable correlation

Understanding entanglement cost in non-local quantum computation (NLQC) is relevant to complexity, cryptography, gravity, and other areas. This entanglement cost is largely uncharacterized; previous lower bound techniques apply to narrowly defined cases, and proving lower bounds on most simple unitaries has remained open. Here, we give two new lower bound techniques that can be evaluated for any unitary, based on their controllable correlation and controllable entanglement. For Haar random two qubit unitaries, our techniques typically lead to non-trivial lower bounds. Further, we obtain lower bounds on most of the commonly studied two qubit quantum gates, including CNOT, DCNOT, $\sqrt{\text{SWAP}}$, and the XX interaction, none of which previously had known lower bounds. For the CNOT gate, one of our techniques gives a tight lower bound, fully resolving its entanglement cost. The resulting lower bounds have parallel repetition properties, and apply in the noisy setting.

quant-ph

Entanglement summoning from entanglement sharing

In an entanglement summoning task, a set of distributed, co-operating parties attempt to fulfill requests to prepare entanglement between distant locations. The parties share limited communication resources: timing constraints may require the entangled state be prepared before some pairs of distant parties can communicate, and a restricted set of links in a quantum network may further constrain communication. Building on earlier work, we continue the characterization of entanglement summoning. We give an if and only if condition on entanglement summoning tasks with only bidirected causal connections, and provide a set of sufficient conditions addressing the most general case containing both oriented and bidirected causal connections. Our results rely on the recent development of entanglement sharing schemes.

quant-ph

Magic and communication complexity

We establish novel connections between magic in quantum circuits and communication complexity. In particular, we show that functions computable with low magic have low communication cost. Our first result shows that the $\mathsf{D}\|$ (deterministic simultaneous message passing) cost of a Boolean function $f$ is at most the number of single-qubit magic gates in a quantum circuit computing $f$ with any quantum advice state. If we allow mid-circuit measurements and adaptive circuits, we obtain an upper bound on the two-way communication complexity of $f$ in terms of the magic + measurement cost of the circuit for $f$. As an application, we obtain magic-count lower bounds of $\Omega(n)$ for the $n$-qubit generalized Toffoli gate as well as the $n$-qubit quantum multiplexer. Our second result gives a general method to transform $\mathsf{Q}\|^*$ protocols (simultaneous quantum messages with shared entanglement) into $\mathsf{R}\|^*$ protocols (simultaneous classical messages with shared entanglement) which incurs only a polynomial blowup in the communication and entanglement complexity, provided the referee's action in the $\mathsf{Q}\|^*$ protocol is implementable in constant $T$-depth. The resulting $\mathsf{R}\|^*$ protocols satisfy strong privacy constraints and are $\mathsf{PSM}^*$ protocols (private simultaneous message passing with shared entanglement), where the referee learns almost nothing about the inputs other than the function value. As an application, we demonstrate $n$-bit partial Boolean functions whose $\mathsf{R}\|^*$ complexity is $\mathrm{polylog}(n)$ and whose $\mathsf{R}$ (interactive randomized) complexity is $n^{\Omega(1)}$, establishing the first exponential separations between $\mathsf{R}\|^*$ and $\mathsf{R}$ for Boolean functions.

quant-ph

Entanglement sharing schemes

We ask how quantum correlations can be distributed among many subsystems. To address this, we define entanglement sharing schemes (ESS) where certain pairs of subsystems allow entanglement to be recovered via local operations, while other pairs must not. ESS schemes come in two variants, one where the partner system with which entanglement should be prepared is known, and one where it is not. In the case of known partners, we fully characterize the access structures realizable for ESS when using stabilizer states, and construct efficient schemes for threshold access structures, and give a conjecture for the access structures realizable with general states. In the unknown partner case, we again give a complete characterization in the stabilizer setting, additionally give a complete characterization of the case where there are no restrictions on unauthorized pairs, and we prove a set of necessary conditions on general schemes which we conjecture are also sufficient. Finally, we give an application of the theory of entanglement sharing to resolve an open problem related to the distribution of entanglement in response to time-sensitive requests in quantum networks.

quant-ph

A complexity theory for non-local quantum computation

Non-local quantum computation (NLQC) replaces a local interaction between two systems with a single round of communication and shared entanglement. Despite many partial results, it is known that a characterization of entanglement cost in at least certain NLQC tasks would imply significant breakthroughs in complexity theory. Here, we avoid these obstructions and take an indirect approach to understanding resource requirements in NLQC, which mimics the approach used by complexity theorists: we study the relative hardness of different NLQC tasks by identifying resource efficient reductions between them. Most significantly, we prove that $f$-measure and $f$-route, the two best studied NLQC tasks, are in fact equivalent under $O(1)$ overhead reductions. This result simplifies many existing proofs in the literature and extends several new properties to $f$-measure. For instance, we obtain sub-exponential upper bounds on $f$-measure for all functions, and efficient protocols for functions in the complexity class $\mathsf{Mod}_k\mathsf{L}$. Beyond this, we study a number of other examples of NLQC tasks and their relationships.

quant-ph

Secure quantum ranging

Determining and verifying an object's position is a fundamental task with broad practical relevance. We propose a secure quantum ranging protocol that combines quantum ranging with quantum position verification (QPV). Our method achieves Heisenberg-limited precision in position estimation while simultaneously detecting potential cheaters. Two verifiers each send out a state that is entangled in frequency space within a single optical mode. An honest prover only needs to perform simple beam-splitter operations, whereas cheaters are allowed to use arbitrary linear optical operations, one ancillary mode, and perfect quantum memories-though without access to entanglement. Our approach considers a previously unstudied security aspect to quantum ranging. It also provides a framework to quantify the precision with which a prover's position can be verified in QPV, which previously has been assumed to be infinite.

quant-ph

Comparing classical and quantum conditional disclosure of secrets

The conditional disclosure of secrets (CDS) setting is among the most basic primitives studied in information-theoretic cryptography. Motivated by a connection to non-local quantum computation and position-based cryptography, CDS with quantum resources has recently been considered. Here, we study the differences between quantum and classical CDS, with the aims of clarifying the power of quantum resources in information-theoretic cryptography. We establish the following results: 1) We prove a $\Omega(\log \mathsf{R}_{0,A\rightarrow B}(f)+\log \mathsf{R}_{0,B\rightarrow A}(f))$ lower bound on quantum CDS where $\mathsf{R}_{0,A\rightarrow B}(f)$ is the classical one-way communication complexity with perfect correctness. 2) We prove a lower bound on quantum CDS in terms of two round, public coin, two-prover interactive proofs. 3) For perfectly correct CDS, we give a separation for a promise version of the not-equals function, showing a quantum upper bound of $O(\log n)$ and classical lower bound of $\Omega(n)$. 4) We give a logarithmic upper bound for quantum CDS on forrelation, while the best known classical algorithm is linear. We interpret this as preliminary evidence that classical and quantum CDS are separated even with correctness and security error allowed. We also give a separation for classical and quantum private simultaneous message passing for a partial function, improving on an earlier relational separation. Our results use novel combinations of techniques from non-local quantum computation and communication complexity.

quant-ph

Cryptographic tests of the python's lunch conjecture

In the AdS/CFT correspondence, a subregion of the CFT allows for the recovery of a corresponding subregion of the bulk known as its entanglement wedge. In some cases, an entanglement wedge contains a locally but not globally minimal surface homologous to the CFT subregion, in which case it is said to contain a python's lunch. It has been proposed that python's lunch geometries should be modelled by tensor networks that feature projective operations where the wedge narrows. This model leads to the python's lunch (PL) conjecture, which asserts that reconstructing information from past the locally minimal surface is computationally difficult. In this work, we use cryptographic tools related to a primitive known as the Conditional Disclosure of Secrets (CDS) to develop consequences of the projective tensor network model that can be checked directly in AdS/CFT. We argue from the tensor network picture that the mutual information between appropriate CFT subregions is lower bounded linearly by an area difference associated with the geometry of the lunch. Recalling that the mutual information is also computed by bulk extremal surfaces, this gives a checkable geometrical consequence of the tensor network model. We prove weakened versions of this geometrical statement in asymptotically AdS$_{2+1}$ spacetimes satisfying the null energy condition, and confirm it in some example geometries, supporting the tensor network model and by proxy the PL conjecture.

hep-th

Holographic scattering and non-minimal RT surfaces

In the AdS/CFT correspondence, the causal structure of the bulk AdS spacetime is tied to entanglement in the dual CFT. This relationship is captured by the connected wedge theorem, which states that a bulk scattering process implies the existence of $O(1/G_N)$ entanglement between associated boundary subregions. In this paper, we study the connected wedge theorem in two asymptotically AdS$_{2+1}$ spacetimes: the conical defect and BTZ black hole geometries. In these settings, we find that bulk scattering processes require not just large entanglement, but also additional restrictions related to candidate RT surfaces which are non-minimal. We argue these extra relationships imply a certain CFT entanglement structure involving internal degrees of freedom. Because bulk scattering relies on sub-AdS scale physics, this supports the idea that sub-AdS scale locality emerges from internal degrees of freedom. While the new restriction that we identify on non-minimal surfaces is stronger than the initial statement of the connected wedge theorem, we find that it is necessary but still not sufficient to imply bulk scattering in mixed states.

hep-th

Conditional disclosure of secrets with quantum resources

The conditional disclosure of secrets (CDS) primitive is among the simplest cryptographic settings in which to study the relationship between communication, randomness, and security. CDS involves two parties, Alice and Bob, who do not communicate but who wish to reveal a secret $z$ to a referee if and only if a Boolean function $f$ has $f(x,y)=1$. Alice knows $x,z$, Bob knows $y$, and the referee knows $x,y$. Recently, a quantum analogue of this primitive called CDQS was defined and related to $f$-routing, a task studied in the context of quantum position-verification. CDQS has the same inputs, outputs, and communication pattern as CDS but allows the use of shared entanglement and quantum messages. We initiate the systematic study of CDQS, with the aim of better understanding the relationship between privacy and quantum resources in the information theoretic setting. We begin by looking for quantum analogues of results already established in the classical CDS literature. Doing so we establish a number of basic properties of CDQS, including lower bounds on entanglement and communication stated in terms of measures of communication complexity. Because of the close relationship to the $f$-routing position-verification scheme, our results have relevance to the security of these schemes.

quant-ph

Rank lower bounds on non-local quantum computation

A non-local quantum computation (NLQC) replaces an interaction between two quantum systems with a single simultaneous round of communication and shared entanglement. We study two classes of NLQC, $f$-routing and $f$-BB84, which are of relevance to classical information theoretic cryptography and quantum position-verification. We give the first non-trivial lower bounds on entanglement in both settings, but are restricted to lower bounding protocols with perfect correctness. Within this setting, we give a lower bound on the Schmidt rank of any entangled state that completes these tasks for a given function $f(x,y)$ in terms of the rank of a matrix $g(x,y)$ whose entries are zero when $f(x,y)=0$, and strictly positive otherwise. This also leads to a lower bound on the Schmidt rank in terms of the non-deterministic quantum communication complexity of $f(x,y)$. Because of a relationship between $f$-routing and the conditional disclosure of secrets (CDS) primitive studied in information theoretic cryptography, we obtain a new technique for lower bounding the randomness complexity of CDS.

quant-ph

Linear gate bounds against natural functions for position-verification

A quantum position-verification scheme attempts to verify the spatial location of a prover. The prover is issued a challenge with quantum and classical inputs and must respond with appropriate timings. We consider two well-studied position-verification schemes known as $f$-routing and $f$-BB84. Both schemes require an honest prover to locally compute a classical function $f$ of inputs of length $n$, and manipulate $O(1)$ size quantum systems. We prove the number of quantum gates plus single qubit measurements needed to implement a function $f$ is lower bounded linearly by the communication complexity of $f$ in the simultaneous message passing model with shared entanglement. Taking $f(x,y)=\sum_i x_i y_i$ to be the inner product function, we obtain a $\Omega(n)$ lower bound on quantum gates plus single qubit measurements. The scheme is feasible for a prover with linear classical resources and $O(1)$ quantum resources, and secure against sub-linear quantum resources.

quant-ph

Relating non-local quantum computation to information theoretic cryptography

Non-local quantum computation (NLQC) is a cheating strategy for position-verification schemes, and has appeared in the context of the AdS/CFT correspondence. Here, we connect NLQC to the wider context of information theoretic cryptography by relating it to a number of other cryptographic primitives. We show one special case of NLQC, known as $f$-routing, is equivalent to the quantum analogue of the conditional disclosure of secrets (CDS) primitive, where by equivalent we mean that a protocol for one task gives a protocol for the other with only small overhead in resource costs. We further consider another special case of position verification, which we call coherent function evaluation (CFE), and show CFE protocols induce similarly efficient protocols for the private simultaneous message passing (PSM) scenario. By relating position-verification to these cryptographic primitives, a number of results in the cryptography literature give new implications for NLQC, and vice versa. These include the first sub-exponential upper bounds on the worst case cost of $f$-routing of $2^{O(\sqrt{n\log n})}$ entanglement, the first example of an efficient $f$-routing strategy for a problem believed to be outside $P/poly$, linear lower bounds on entanglement for CDS in the quantum setting, linear lower bounds on communication cost of CFE, and efficient protocols for CDS in the quantum setting for functions that can be computed with quantum circuits of low $T$ depth.

quant-ph

Non-local computation and the black hole interior

In a two sided black hole, systems falling in from opposite asymptotic regions can meet inside the black hole and interact. This is the case even while the two CFTs describing each asymptotic region are non-interacting. Here, we relate these behind the horizon interactions to non-local quantum computations. This gives a quantum circuit perspective on these interactions, which applies whenever the interaction occurs in the past of a certain extremal surface that sits inside the black hole and in arbitrary dimension. Whenever our perspective applies, we obtain a boundary signature for these interior collisions which is stated in terms of the mutual information. We further revisit the connection discussed earlier between bulk interactions in one sided AdS geometries and non-local computation, and recycle some of our techniques to offer a new perspective on making that connection precise.

hep-th