![Page 1: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/1.jpg)
The Cryptographic Hardness of Decoding Hawking Radiation
Scott Aaronson (MIT)
![Page 2: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/2.jpg)
Black Holes and Computational Complexity??
YES!Amazing connection made last year by Harlow & Hayden
But first, let’s review 40 years of black hole history
SZK
QSZK
BPPBQP
AMQAM
![Page 3: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/3.jpg)
Bekenstein, Hawking 1970s: Black holes have entropy and temperature! They emit radiation
The Information Loss Problem: Calculations suggest that Hawking radiation is thermal—uncorrelated with whatever fell in. So, is infalling information lost forever? Would violate the unitarity / reversibility of QM
OK then, assume the information somehow gets out!
The Xeroxing Problem: How could the same qubit | fall inexorably toward the singularity, and emerge in Hawking radiation? Would violate the No-Cloning Theorem
Black Hole Complementarity (Susskind, ‘t Hooft): An external observer can describe everything unitarily without including the interior at all! Interior should be seen as “just a scrambled re-encoding” of the exterior degrees of freedom
![Page 4: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/4.jpg)
Violates monogamy of entanglement! The same qubit can’t be maximally entangled with 2 things
The Firewall Paradox (AMPS 2012)
B = Interior of “Old”
Black Hole
R = Faraway Hawking Radiation
H = Just-Emitted Hawking Radiation
Near-maximal entanglement
Also near-maximal entanglement
![Page 5: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/5.jpg)
Harlow-Hayden 2013 (arXiv:1301.4504): Striking argument that Alice’s first task, decoding the entanglement between R and H, would require exponential timeComplexity theory to the rescue of quantum field theory??Two obvious questions:
(1) Who cares if this is true?
(2) Is it true? Does the decoding task require exponential time?
![Page 6: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/6.jpg)
Caveats of Complexity Arguments1. Asymptotic
E.g., 88 chess takes O(1) time! Only for nn chess can we give evidence of hardness. But for black holes, n1070…
2. (Usually) ConjecturalRight now, we can’t even prove P≠NP! To get where we want, we almost always need to make assumptions. Question is, which assumptions?
3. Worst-CaseWe can argue that a natural formalization of Alice’s decoding task is “generically” hard. We can’t rule out that a future quantum gravity theory would make her task easy, for deep reasons not captured by our formalization.
![Page 7: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/7.jpg)
Quantum Circuits
![Page 8: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/8.jpg)
Given a description of a quantum circuit C, such that
Promised that, by acting only on R (the “Hawking radiation part”), it’s possible to distill an EPR pair
between R and H
Problem: Distill such an EPR pair, by applying a unitary transformation UR to the qubits in R
The HH Decoding Problem
21100
BHR
nC 0
![Page 9: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/9.jpg)
Problem: That would require waiting until the black hole was fully evaporated ( no more firewall problem)
When the BH is “merely” >50% evaporated, we know from Page’s argument that “generically,” there will exist a UR that distills an EPR pair between R and B
But interestingly, Page’s argument doesn’t suggest any efficient procedure to find UR or apply it!
Isn’t the Decoding Task Trivial?Just invert C!
![Page 10: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/10.jpg)
Set Equality: Given two efficiently-computable injective functions f,g:{0,1}n{0,1}p(n). Promised that Range(f) and Range(g) are either equal or disjoint. Decide which.
In the “black-box” setting, this problem requires at least ~2n/3 steps, even with a QC (A. 2002 Zhandry 2013). For explicit f,g, we can’t prove unconditional hardness, but solving it would give Graph Isomorphism, SZK…
Theorem (Harlow-Hayden): Suppose there’s a polynomial-time quantum algorithm for HH decoding. Then there’s also a polynomial-time quantum algorithm for Set Equality (and indeed, QSZK=BQP)
The HH Hardness Result
![Page 11: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/11.jpg)
Intuition: If Range(f) and Range(g) are disjoint, then the B register decoheres all entanglement between R and H, leaving only classical correlation
If, on the other hand, Range(f)=Range(g), then there’s some permutation of the |x,1R states that puts the last qubit of R into an EPR pair with H
Thus, if we had a reliable way to distill EPR pairs whenever possible, then we could also decide Set Equality
The HH Construction
nx
BHRBHRnRHBxgxxfx
1,01
11,00,2
1
(easy to prepare in poly(n) time given f,g)
![Page 12: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/12.jpg)
My Alternative Hardness Result
Theorem (A. 2013): Suppose there’s a poly-time quantum algorithm for the HH decoding problem. Then there’s also a poly-time quantum algorithm to invert any injective OWF
One-Way Function (OWF): A collection of functions f:{0,1}n{0,1}p(n) (one for each n) such that:1.f(x) is computable in poly(n) time2.For all polynomial-time adversaries A,
nxfxfAf
nx poly1Pr
1,0
“Standard workhorses” of modern cryptography. Widely believed that there exist OWFs secure even against QCs
![Page 13: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/13.jpg)
nxBHRHR
nnp
nRHBxxfx
1,01
11,00,02
1
Suppose applying UR to R decodes an EPR pair between R and H. Then for some states {|x}x, we must have
11,,00,0 xRxnnp
R xfUxU
x
xnnp
xfW
xV
,0
So from UR, we can get unitaries V,W such that
nnpxxfWV 01
My Construction
(again, easy to prepare in poly(n) time given f)
![Page 14: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/14.jpg)
Generalization to Arbitrary OWFsKnown Classical Fact: Given any OWF f, it’s possible to produce another OWF g that, with probability at least ~1/n, is injective on at least a ~1/n fraction of its range
cn
xBHRHR
nnp
n n
xxgx
1,01
11,00,02
1
Now H is many qubits, not just oneBut a more complicated argument shows that, if we can distill even 1 EPR pair between R and H, we must be able to invert g, and hence f
![Page 15: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/15.jpg)
Comparison of ArgumentsAdvantages of my argument:Existence of OWFs is a “safer” assumption than hardness of finding collisionsWorks even against “nonuniform” algorithms (which spend exponential preparation time before the black hole is formed)
Advantage of HH argument:Works even if Alice gets access to H as well as R
![Page 16: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/16.jpg)
Concluding RemarksThere’s good evidence that decoding Hawking radiation requires an exponentially-long quantum computationAdmittedly, “real” black holes won’t produce states that look anything like
But intuitively, greater genericity seems like it should only make Alice’s decoding task harder! Would be great to formalize this (connections to quantum money?)
Would also be great if computational considerations could give any clues about the black hole interior…
nxBHRHR
nnp
nRHBxxfx
1,01
11,00,02
1
![Page 17: The Cryptographic Hardness of Decoding Hawking Radiation](https://reader036.vdocument.in/reader036/viewer/2022062502/568156de550346895dc48435/html5/thumbnails/17.jpg)
A Curious Open ProblemWe’ve seen what computational powers are necessary for Alice to solve the HH decoding problem (inverting one-way functions, solving Set Equality)What computational powers would suffice to let her solve it in quantum polynomial time?(Not obvious how to do it even if given, say, an oracle for the halting problem…)