REVIEW 2 major objections 5 minor 1 cited by
Quantum pseudoresources imply cryptography
T0 review · 2 major / 5 minor · reviewed 2026-08-16 · deepseek-v4-flash
Pith's one-line read Quantum pseudoresources—state families that hide a resource gap from efficient observers—are enough to build commitments, oblivious transfer, and secure multiparty computation.
desk verdict Clean reduction from an all-keys pseudoresource gap to commitments via a new EPFI primitive, but the claimed coverage of known pseudoentanglement definitions is not substantiated. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is the relative entropy of resource, $R_{\mathrm{rel}}(\rho) = \min_{\sigma \in F} D(\rho\|\sigma)$, measuring the state's distance from the free states of a resource theory. The argument is carried by a continuity bound for this quantity: when two states are $\epsilon$-close in trace distance, their resource values differ by at most $\epsilon \kappa + (1+\epsilon) h(\epsilon/(1+\epsilon))$, where $\kappa$ is the maximum variation of $R_{\mathrm{rel}}$ over the state space and $h$ is the binary entropy. Arranging the resource gap $\eta \geq 2 + 1/\mathrm{poly}(n)$ with $\kappa = \mathrm{polylog}(d)$ forces every cross-pair of pseudoresource states to be $\Omega(1/\mathrm{poly}(n))$ far in trace distance. The EPFI-to-commitment step is carried by amplification of many copies plus the purification-fidelity relation: pairwise trace-distance farness becomes a vanishing fidelity gap, giving honest statistical binding, while computational indistinguishability directly gives hiding.
What would settle it
Take any candidate $\eta$-gap pseudoresource satisfying the hypotheses of the main theorem and compute $\min_{k,k'} \Delta(\psi_k, \phi_{k'})$ for the constructed EPFI pair. The theorem predicts this minimum is $\Omega(1/\mathrm{poly}(n))$; a single key pair with negligible trace distance, or a computationally indistinguishable family with only average-case resource gap containing an exceptional pair with near-equal resource, would falsify the conclusion.
Extended reading notes
Core claim
On its own terms, the central claim is that pseudoresources are cryptographically sufficient: for $\eta \geq 2 + 1/\mathrm{poly}(n)$, an $\eta$-gapped pseudoresource (with the total variation $\kappa$ of the relative entropy of resource at most polylogarithmic in the dimension) yields EPFI pairs, and EPFI pairs yield canonical quantum commitments, hence oblivious transfer, secure multiparty computation, and related primitives. For pure-state pseudoentanglement measured by entanglement entropy, the threshold is $\eta \geq 1/(2e) + 1/\mathrm{poly}(n)$, via reduced density matrices and an entropy-continuity inequality; for mixed states measured by regularized relative entropy of entanglement, it is $\eta \geq 2 + 1/\mathrm{poly}(n)$, via the corresponding continuity bound. The same machinery yields a new proposed functionality, computationally locked entanglement, in which high entanglement is hidden from keyless observers but distillable with the key.
Load-bearing premise
All constructions assume the resource gap holds for every pair of keys—a worst-case gap—and that the resource measure's total variation $\kappa$ is polylogarithmic in dimension; if either fails, the pairwise trace-distance farness that binding requires is not guaranteed.
Editorial extensions
If this is right
- Any resource theory whose free states are convex, closed, and contain a full-rank state inherits the result: an $\eta$-gapped pseudoresource with $\eta \geq 2 + 1/\mathrm{poly}(n)$ and $\kappa = \mathrm{polylog}(d)$ yields EPFI pairs and therefore quantum commitments.
- All known pure-state pseudoentanglement constructions with an entanglement-entropy gap of at least $1/(2e) + 1/\mathrm{poly}(n)$ become usable for cryptography, because their reduced density matrices form EPFI pairs.
- Mixed-state pseudoentanglement defined through the regularized relative entropy of entanglement, with gap at least $2 + 1/\mathrm{poly}(n)$, yields EPFI pairs even when the gap is invisible to the computational entanglement measures of earlier definitions.
- From EPFI pairs, the paper obtains statistically binding and computationally hiding canonical quantum commitments; by standard reductions these give oblivious transfer, secure multiparty computation, and further quantum cryptographic protocols.
- Computationally locked entanglement, if it can be instantiated, supplies a key-controlled entanglement functionality suitable for authenticated teleportation and certified routing in quantum networks, usable polynomially many times.
Reading between the lines
- Not shown in the paper, but a natural next test: can the worst-case per-key gap be relaxed to an average-case gap? The proofs quantify over all key pairs, so a positive result would substantially widen the class of pseudoresources that yield cryptography.
- The paper leaves the threshold $\eta \geq 2 + 1/\mathrm{poly}(n)$ tied to the continuity inequality used; a tighter inequality would lower the gap and improve the commitment parameters. That quantitative relationship is an inference from the proof structure, not an additional theorem in the paper.
- If the reverse direction holds—EPFI pairs or commitments themselves yield some pseudoresource—then pseudoresources would sit exactly at the minimal-assumption level of quantum cryptography; the paper proves only the forward direction.
- Computationally locked entanglement relaxes the requirement that both families be efficiently generated, so it may be constructible from weaker assumptions than full pseudoentanglement; whether it is would clarify which resource-gap notions are essential.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper introduces EPFI pairs, a family-indexed generalization of EFI pairs in which every element of one family is statistically far from every element of the other, while the two families are computationally indistinguishable. It proves (Theorem 3.3) that EPFI pairs imply statistically binding, computationally hiding canonical quantum commitments, thereby inheriting known consequences such as oblivious transfer and multiparty computation. The main technical claim (Theorem 4.3) is that any 'η-gap pseudoresource'—two efficiently generated, computationally indistinguishable families of states with a large gap in relative entropy of resource—yields EPFI pairs, provided the resource gap is at least 2+1/poly(n) and the maximum resource variation κ is polylog(d). The paper then specializes to entanglement, giving results for pure-state pseudoentanglement (Theorem 5.2) and mixed-state pseudoentanglement (Corollary 5.5), and proposes a new functionality called computationally locked entanglement. The paper claims that every known pure-state pseudoentanglement construction satisfies the required gap.
Significance. If the results hold as stated, the paper would establish a general bridge from quantum resource theories (entanglement, magic, coherence) to quantum cryptography, complementing known minimal-assumption results for EFI pairs. The EPFI-to-commitment reduction is a clean and useful generalization of the EFI construction, and the paper is careful to spell out the commitment scheme and its security proof. The asymptotic-continuity-based approach to turning resource gaps into trace-distance gaps is elegant. However, the current formulation relies on a worst-case (all-pairs) gap condition that is not obviously satisfied by existing pseudoentanglement constructions, and the proof of the central pseudoresource theorem contains an incorrect inversion of Winter's inequality. These issues currently limit the scope of the claimed implication.
major comments (2)
- [Section 4.2, Theorem 4.3] The proof step 'it follows from Equation (3) that, for every k,k′∈{0,1}^κ, Δ(ψ_k,φ_k′) ≥ |R_rel(ψ_k)-R_rel(φ_k′)| - 2/κ' is not a consequence of Lemma 2.16. The lemma gives, for any ρ,σ with Δ(ρ,σ) ≤ ε, the upper bound |R_rel(ρ)-R_rel(σ)| ≤ εκ + (1+ε)h(ε/(1+ε)). Inverting this requires choosing ε such that εκ + (1+ε)h(ε/(1+ε)) < η, and the resulting lower bound on Δ does not take the stated form. As written, the right-hand side can exceed 1 (e.g., for η=2 and κ=10 it is 1.8), so the inequality cannot hold for a trace distance. This invalidates the proof of the central theorem; the authors must provide a correct inversion and verify that the conditions η ≥ 2+1/poly(n) and κ = polylog(d) indeed imply Δ ≥ Ω(1/poly).
- [Section 5.1, Definition 5.1 and Theorem 5.2] The 'for all k,k′' entanglement gap in Definition 5.1 is a worst-case condition that standard pseudoentanglement constructions do not satisfy. In the ABF+23-style construction, the high-entanglement ensemble is a distribution over (near-)Haar-random states, whose entanglement is at least n/2 - O(1) only with probability 1 - negl; the key set may include exceptional states with low entanglement. Since the EPFI farness condition (Definition 3.2) and the commitment binding condition (Eq. (5)) are also quantified over all keys, the theorem does not apply to these average-case constructions. The paper's assertion in Section 5.1 that 'every known construction of pseudoentanglement from pure state ensembles ... exhibits an entanglement entropy gap of at least 1/2e + 1/poly(n)' is therefore unsubstantiated unless the authors provide an argument that restricts the key space to good keys (or otherwise converts the high-probability gap into an all-pairs gap) while preserving computational indistinguishability. The same concern applies to the mixed-state pseudoentanglement definitions in Definitions 5.4 and Corollary 5.5.
minor comments (5)
- [Introduction, Informal Definition 1 vs Definition 4.2] The informal description says the resource gap holds for 'states sampled from each family', but Definition 4.2 requires the gap for all key pairs; this discrepancy should be resolved because it affects the scope of the results.
- [Section 2.3, Definitions 2.9 and 2.10] In Definition 2.9, the condition '∀k∈N+' should be '∀λ∈N+'; the same typo appears in Definition 2.10.
- [Section 5.1, proof of Theorem 5.2] The constant 'c' in the Fannes bound is actually c(Δ); please write it as c(Δ) and use the bound c(Δ) ≤ 1/(2e) explicitly to derive the stated lower bound.
- [Section 5.3, Lemma 5.7] The statement 'ˆE^ε_D < ˆE^ε_C' should be '≤', and the proof would benefit from a more explicit description of how the distillation algorithm yields a distinguisher between the two families.
- [Throughout] There are several typographical errors, e.g., 'statistical biding' in Section 2.6, 'ω(log(n)))' in Section 5.1, and 'ca be extended' in Section 3; a careful proofreading would improve readability.
Circularity Check
No circularity: the pseudoresource-to-EPFI-to-commitment reductions are genuine derivations from stated premises; the only caveat is an all-pairs worst-case gap assumption, which is a correctness concern, not circularity.
full rationale
The derivation chain is: (i) define eta-gap pseudoresource (Definition 4.2) with an all-pairs relative-entropy-of-resource gap plus computational indistinguishability; (ii) prove Theorem 4.3 by applying Winter's continuity inequality (Lemma 2.16, Eq. 3) to lower-bound pairwise trace distance by (|R_rel gap| - 2)/kappa; (iii) feed this into Definition 3.2 of EPFI; (iv) prove Theorem 3.3 that EPFI yields canonical quantum commitments, with honest binding from pairwise trace distance plus Uhlmann/Holevo-Helstrom and hiding from computational indistinguishability; and (v) obtain oblivious transfer and MPC by citing published reductions [GLSV21, BCKM21]. Each step is a derivation from stated premises rather than a renamed input. The EPFI definition is admittedly close to the commitment property, but the paper derives pairwise statistical farness from the resource gap via an external inequality instead of assuming it, and binding/hiding are separate consequences of the EPFI properties. The only author-overlap citation is GLSV21, a CRYPTO-published result used downstream for oblivious transfer from commitments; it is not the source of the pseudoresource-to-EPFI implication and has independent support. The paper also flags its own definitional choices, e.g., Remark 5.3 and the discussion in Section 5.2. The main legitimate concern raised by the skeptical reading is that Definitions 4.2, 5.1, and 5.4 require the resource gap to hold for every key pair, while some known pseudoentanglement constructions only give the entanglement gap with overwhelming probability over a sampler; Section 5.1's assertion that every known pure-state construction satisfies the required gap is not proved in detail. This is an assumption-matching and correctness question, not circularity, because the theorem is still a genuine implication from its all-pairs hypothesis.
Assumptions & free parameters
assumptions (6)
- domain assumption The set of free states F(H) is convex, closed, and bounded, and contains a full-rank state.
- standard math Winter's Fannes-type inequality and the Fannes inequality hold for the measures used here (Lemmas 2.15, 2.16, 2.17).
- standard math EFI pairs are equivalent to canonical quantum commitments, and commitments imply oblivious transfer and multiparty computation.
- domain assumption The pseudoresource families satisfy a worst-case resource gap for every pair of keys.
- standard math The extremality chain E_D^inf <= E_R^inf <= E_C^inf holds, together with the computational measure bounds Ehat_D^inf <= E_D^inf and E_C^inf <= Ehat_C^inf.
- domain assumption If a state family has computational distillable entanglement above c, it can be distinguished from a family with computational entanglement cost at most c.
Cite this review
Pith. "Pith review of Quantum pseudoresources imply cryptography." pith.science (2026). https://pith.science/paper/2FYWIDFZ
@misc{pith2026250415025,
author = {Pith},
title = {Pith review of: Quantum pseudoresources imply cryptography},
year = {2026},
howpublished = {\url{https://pith.science/paper/2FYWIDFZ}},
note = {Machine review of arXiv:2504.15025}
}
read the original abstract
While one-way functions (OWFs) serve as the minimal assumption for computational cryptography in the classical setting, in quantum cryptography, we have even weaker cryptographic assumptions such as pseudo-random states, and EFI pairs, among others. Moreover, the minimal assumption for computational quantum cryptography remains an open question. Recently, it has been shown that pseudoentanglement is necessary for the existence of quantum cryptography (Goul\~ao and Elkouss 2024), but no cryptographic construction has been built from it. In this work, we study the cryptographic usefulness of quantum pseudoresources -- a pair of families of quantum states that exhibit a gap in their resource content yet remain computationally indistinguishable. We show that quantum pseudoresources imply a variant of EFI pairs, which we call EPFI pairs, and that these are equivalent to quantum commitments and thus EFI pairs. Our results suggest that, just as randomness is fundamental to classical cryptography, quantum resources may play a similarly crucial role in the quantum setting. Finally, we focus on the specific case of entanglement, analyzing different definitions of pseudoentanglement and their implications for constructing EPFI pairs. Moreover, we propose a new cryptographic functionality that is intrinsically dependent on entanglement as a resource.
Figures
Forward citations
Cited by 1 Pith paper
-
Quantifying mixed-state entanglement via partial transpose and realignment moments
The p4-negativity, a fourth-moment quantity measurable with four copies of a state, lower-bounds the partial-transpose negativity and suffices to determine the Haar-random-state entanglement phase diagram.
Reference graph
Works this paper leans on
-
[1]
Quantum pseudoentanglement, 2023
Scott Aaronson, Adam Bouland, Bill Fefferman, Soumik Ghosh, Umesh Vazirani, Chenyi Zhang, and Zixin Zhou. Quantum pseudoentanglement, 2023
work page 2023
-
[2]
Interactive proofs for quantum computations, 2008
Dorit Aharonov, Michael Ben-Or, and Elad Eban. Interactive proofs for quantum computations, 2008
work page 2008
-
[3]
Computational entanglement theory, 2023
Rotem Arnon-Friedman , Zvika Brakerski, and Thomas Vidick. Computational entanglement theory, 2023
work page 2023
-
[4]
Cryptography from pseudorandom quantum states, 2021
Prabhanjan Ananth, Luowen Qian, and Henry Yuen. Cryptography from pseudorandom quantum states, 2021
work page 2021
-
[5]
Bennett, Gilles Brassard, Claude Cr\'epeau, Richard Jozsa, Asher Peres, and William K
Charles H. Bennett, Gilles Brassard, Claude Cr\'epeau, Richard Jozsa, Asher Peres, and William K. Wootters. Teleporting an unknown quantum state via dual classical and einstein-podolsky-rosen channels. Phys. Rev. Lett. , 70:1895--1899, Mar 1993
work page 1993
-
[6]
One-way functions imply secure computation in a quantum world
James Bartusek, Andrea Coladangelo, Dakshita Khurana, and Fermi Ma. One-way functions imply secure computation in a quantum world. In Advances in Cryptology--CRYPTO 2021: 41st Annual International Cryptology Conference, CRYPTO 2021, Virtual Event, August 16--20, 2021, Proceedings, Part I 41 , pages 467--496. Springer, 2021
work page 2021
-
[7]
Baumgratz, M
T. Baumgratz, M. Cramer, and M. B. Plenio. Quantifying coherence. Phys. Rev. Lett. , 113:140401, Sep 2014
2014
-
[8]
On the computational hardness needed for quantum cryptography
Zvika Brakerski, Ran Canetti, and Luowen Qian. On the computational hardness needed for quantum cryptography. In Yael Tauman Kalai, editor, 14th Innovations in Theoretical Computer Science Conference (ITCS 2023) , volume 251 of Leibniz International Proceedings in Informatics (LIPIcs) , pages 24:1--24:21, Dagstuhl, Germany, 2023. Schloss Dagstuhl--Leibniz...
work page 2023
Show all 37 references
-
[9]
Briegel, W
H.-J. Briegel, W. D\"ur, J. I. Cirac, and P. Zoller. Quantum repeaters: The role of imperfect local operations in quantum communication. Phys. Rev. Lett. , 81:5932--5935, Dec 1998
1998
-
[10]
Pseudorandom density matrices, 2024
Nikhil Bansal, Wai-Keong Mok, Kishor Bharti, Dax Enshan Koh, and Tobias Haug. Pseudorandom density matrices, 2024
2024
-
[11]
Fernando G. S. L. Brandão and Martin B. Plenio. A reversible theory of entanglement and its relation to the second law. Communications in Mathematical Physics , 295(3):829–851, February 2010
2010
-
[12]
Optimal routing for quantum networks
Marcello Caleffi. Optimal routing for quantum networks. IEEE Access , 5:22299--22312, 2017
2017
-
[13]
Quantum resource theories
Eric Chitambar and Gilad Gour. Quantum resource theories. Reviews of Modern Physics , 91(2), April 2019
2019
-
[14]
The structure of bipartite quantum states - insights from group theory and cryptography, 2006
Matthias Christandl. The structure of bipartite quantum states - insights from group theory and cryptography, 2006
2006
-
[15]
Donald and Michal Horodecki
Matthew J. Donald and Michal Horodecki. Continuity of relative entropy of entanglement, 1999
1999
-
[16]
Donald, Michał Horodecki, and Oliver Rudolph
Matthew J. Donald, Michał Horodecki, and Oliver Rudolph. The uniqueness theorem for entanglement measures. Journal of Mathematical Physics , 43(9):4252–4272, September 2002
2002
-
[17]
DiVincenzo, D.W
D.P. DiVincenzo, D.W. Leung, and B.M. Terhal. Quantum data hiding. IEEE Transactions on Information Theory , 48(3):580–598, March 2002
2002
-
[18]
A continuity property of the entropy density for spin lattice systems
Mark Fannes. A continuity property of the entropy density for spin lattice systems. Communications in Mathematical Physics , 31:291--294, 1973
1973
-
[19]
Pseudo-entanglement is necessary for efi pairs, 2024
Manuel Goulão and David Elkouss. Pseudo-entanglement is necessary for efi pairs, 2024
2024
-
[20]
Yelin, and Yihui Quek
Andi Gu, Lorenzo Leone, Soumik Ghosh, Jens Eisert, Susanne F. Yelin, and Yihui Quek. Pseudomagic quantum states. Physical Review Letters , 132(21), May 2024
2024
-
[21]
Oblivious transfer is in miniqcrypt
Alex B Grilo, Huijia Lin, Fang Song, and Vinod Vaikuntanathan. Oblivious transfer is in miniqcrypt. In Annual International Conference on the Theory and Applications of Cryptographic Techniques , pages 531--561. Springer, 2021
2021
-
[22]
Andi Gu, Salvatore F. E. Oliviero, and Lorenzo Leone. Magic-induced computational separation in entanglement theory, 2024
2024
-
[23]
Pseudorandom unitaries are neither real nor sparse nor noise-robust, 2024
Tobias Haug, Kishor Bharti, and Dax Enshan Koh. Pseudorandom unitaries are neither real nor sparse nor noise-robust, 2024
2024
-
[24]
Application of a resource theory for magic states to fault-tolerant quantum computing
Mark Howard and Earl Campbell. Application of a resource theory for magic states to fault-tolerant quantum computing. Phys. Rev. Lett. , 118:090501, Mar 2017
2017
-
[25]
Helstrom
Carl W. Helstrom. Quantum detection and estimation theory. Journal of Statistical Physics , 1:231--252, 1969
1969
-
[26]
Quantum entanglement
Ryszard Horodecki, Paweł Horodecki, Michał Horodecki, and Karol Horodecki. Quantum entanglement. Reviews of Modern Physics , 81(2):865–942, June 2009
2009
-
[27]
Statistical decision theory for quantum systems
A.S Holevo. Statistical decision theory for quantum systems. Journal of Multivariate Analysis , 3(4):337--394, 1973
1973
-
[28]
Quantum pseudorandomness and classical complexity
William Kretschmer. Quantum pseudorandomness and classical complexity. Schloss Dagstuhl – Leibniz-Zentrum für Informatik, 2021
2021
-
[29]
Entanglement theory with limited computational resources, 2025
Lorenzo Leone, Jacopo Rizzo, Jens Eisert, and Sofiene Jerbi. Entanglement theory with limited computational resources, 2025
2025
-
[30]
Quantum Commitments and Signatures Without One-Way Functions , page 269–295
Tomoyuki Morimae and Takashi Yamakawa. Quantum Commitments and Signatures Without One-Way Functions , page 269–295. Springer Nature Switzerland, 2022
2022
-
[31]
Plenio and S
Martin B. Plenio and S. Virmani. An introduction to entanglement measures, 2006
2006
-
[32]
Alexander Streltsov, Gerardo Adesso, and Martin B. Plenio. Colloquium: Quantum coherence as a resource. Rev. Mod. Phys. , 89:041003, Oct 2017
2017
-
[33]
transition probability
A. Uhlmann. The “transition probability” in the state space of a -algebra. Reports on Mathematical Physics , 9(2):273--279, 1976
1976
-
[34]
Collapse-binding quantum commitments without random oracles
Dominique Unruh. Collapse-binding quantum commitments without random oracles. Cryptology ePrint Archive, Paper 2016/508, 2016
2016
-
[35]
The resource theory of stabilizer quantum computation
Victor Veitch, S A Hamed Mousavian, Daniel Gottesman, and Joseph Emerson. The resource theory of stabilizer quantum computation. New Journal of Physics , 16(1):013009, January 2014
2014
-
[36]
Tight uniform continuity bounds for quantum entropies: Conditional entropy, relative entropy distance and energy constraints
Andreas Winter. Tight uniform continuity bounds for quantum entropies: Conditional entropy, relative entropy distance and energy constraints. Communications in Mathematical Physics , 347(1):291–313, March 2016
2016
-
[37]
General properties of quantum bit commitments (extended abstract)
Jun Yan. General properties of quantum bit commitments (extended abstract). In Shweta Agrawal and Dongdai Lin, editors, Advances in Cryptology -- ASIACRYPT 2022 , pages 628--657, Cham, 2022. Springer Nature Switzerland
2022
Reviewed August 16, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.