Cryptographic schemes for hybrid classical-quantum computer systems
Patent Information
- Authority / Receiving Office
- AU · AU
- Patent Type
- Applications
- Current Assignee / Owner
- RIGETTI AUSTRALIA PTY LTD
- Filing Date
- 2025-01-22
- Publication Date
- 2026-08-06
AI Technical Summary
Existing cryptographic schemes lack robust security and resistance to known-plaintext attacks, especially in hybrid classical-quantum computing environments, where quantum computing resources are not fully utilized for secure communication.
A cryptographic scheme utilizing quantum computing resources, specifically quantum logic circuits with parametric quantum gates, is employed to generate a shared secret for symmetric encryption, ensuring secure communication by encrypting and decrypting messages using a quantum logic circuit as a symmetric key, resistant to known-plaintext attacks and noise, and enabling error mitigation techniques.
Provides enhanced security and resistance to known-plaintext attacks with potentially shorter keys, allowing secure communication between trusted parties over public channels, leveraging quantum computing resources for improved encryption and decryption processes.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Attorney Docket No.: RIGET-127WO1 Cryptographic Schemes for Hybrid Classical-Quantum Computer Systems CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application claims priority to U.S. Provisional Patent Application No. 63 / 623,454, filed January 22, 2024, entitled “Quantum Cryptographic Systems.” The above- referenced priority document is incorporated herein by reference. TECHNICAL FIELD
[0002] The following description relates generally to cryptographic schemes for hybrid classical-quantum computer systems. BACKGROUND
[0003] Quantum computers can perform computational tasks by storing and processing information within quantum states of quantum systems. For example, qubits (i.e., quantum bits) can be stored in, and represented by, an effective two-level sub-manifold of a quantum coherent physical system. A variety of physical systems have been proposed for quantum computing applications. Examples include superconducting circuits, trapped ions, spin systems, and others. BRIEF DESCRIPTION OF THE DRAWINGS
[0004] FIG.1 is a block diagram of an example computing environment.
[0005] FIGS.2A-2C are flow charts showing aspects of an example cryptographic process.
[0006] FIG.3 is a block diagram showing aspects of an example quantum logic circuit.
[0007] FIGS.4A-4C are block diagrams showing aspects of example quantum logic circuits.
[0008] FIG.5 is a table showing an example mapping scheme.Attorney Docket No.: RIGET-127WO1
[0009] FIG.6 is a schematic diagram showing aspects of an example quantum processor unit graph used in a quantum simulator for performing the example process shown in FIGS. 2A-2C.
[0010] FIG.7 is a schematic diagram showing aspects of an example quantum logic circuit to be applied on the quantum processor unit graph in FIG.6.
[0011] FIG.8 is a schematic diagram showing aspects of a quantum processor unit graph of a quantum processor unit for performing the example process shown in FIGS.2A- 2C.
[0012] FIG.9A is a plot showing the critical threshold value ^∗as a function of numbers of quantum logic circuit runs.
[0013] FIG.9B is a plot showing the share of ineligible pairs of Pauli operators as a function of the number of quantum logic circuit runs, corresponding to the experiments in FIG.9A.
[0014] FIG.10A includes plots showing a cumulative distribution function for expectation values of second-order Pauli operators across 5,000 randomly generated configurations during 100,000 quantum logic circuit runs on a noise-free quantum simulator.
[0015] FIG.10B is a histogram of the noise component in the estimation of second-order Pauli expectation values.
[0016] FIG.11 includes a plot showing the threshold value ^ (6 standard deviations) and a plot showing the share of ineligible pairs of Pauli operators as functions of the number of quantum logic circuit runs.
[0017] FIGS.12A-12B includes plots showing the corresponding Cumulative Distribution Function (CDF) for second-order Pauli expectation magnitudes of the absolute values of second-order Pauli expectation values obtained by operation of a 5-qubit superconducting quantum processor unit across 5,040 randomly generated configurations; and by operation of a quantum simulator performed on a classical processor unit across 5,000 randomly generated configurations.Attorney Docket No.: RIGET-127WO1
[0018] FIG.12C includes a plot showing the CDF for the magnitude of all second-order Pauli expectation values, of only the positive second-order Pauli expectation values, and of only the negative second-order Pauli expectation values, obtained by operation of a 5-qubit superconducting quantum processor unit across 5,040 randomly generated configurations and 100,000 quantum logic circuit runs.
[0019] FIG.13 includes a table showing aspects of an example encoding scheme for encoding the gate type in a quantum logic circuit.
[0020] FIG.14 is a table showing the number of bits needed to specify the quantum logic circuit, the maximum and expected numbers of bits that can be encoded using a quantum logic circuit and second-order Pauli operators for various values of ^. DETAILED DESCRIPTION
[0021] In a general aspect, a cryptographic scheme utilizes quantum computing resources. In some implementations, the cryptographic scheme can be executed in a computing environment that includes one or more quantum processing units deployed in a hybrid classical-quantum computer system. In some cases, the cryptographic scheme is a symmetric encryption protocol that can be used to securely send confidential messages over a public communication channel. As an example, a message sender can use the cryptographic scheme to generate an encrypted message, which can be sent to a message recipient over a public communication channel, and the message recipient can use the cryptographic scheme to decrypt the message. An adversary who accesses the encrypted message on the public communication channel cannot decrypt the message without access to a shared secret that is known to the message sender and the message recipient.
[0022] In a symmetric encryption protocol, a shared secret (e.g., a symmetric key) is used to encrypt and decrypt the message, which means that the shared secret can only be shared with trusted parties. In some contexts, a physically secure channel using a public- key cryptosystem can be established to ensure that none of the potentially many key copies is ever exposed. The shared secret may be established between trusted parties in another manner in some cases. Symmetric encryption schemes allow communication between trusted parties to be almost perfectly secure as long as the key remains unknown to theAttorney Docket No.: RIGET-127WO1 potential adversary. In one or more of the examples described below, the symmetric key used in a symmetric encryption / decryption process includes a quantum logic circuit and other information. In some instances, the encrypted version of the message can be generated based on execution of the quantum logic circuit; and can be sent to the recipient. The recipient, after receiving the encrypted version of the message from the sender, can generate an unencrypted version of the message based on executions of the quantum logic circuit.
[0023] In some aspects of what is described here, a hybrid cryptographic system, that includes a quantum computing system and a classical computing system, is configured to obtain a secret key that can be used for symmetric encryption / decryption. In some instances, a quantum computing system includes one or more quantum processing units each of which includes several qubit devices. In certain instances, a quantum computing system may include a quantum simulator. In some examples, the quantum computing system can be configured to encrypt a message by executing the quantum logic circuit. In some implementations, a quantum logic circuit functions as the symmetric key / shared secret, and the quantum logic circuit includes quantum logic gates applied to quantum registers (e.g., qubits). In some instances, to specify the quantum logic circuit with a width of ^ qubits as part of the secret key, the maximum number of bits needed in the secret key is defined as ^^ / ^while the maximum number of bits in the message that the quantum logic circuit can encode is defined as ^^.
[0024] In some instances, a quantum logic circuit may be a parametric quantum logic circuit which includes one or more parametric quantum logic gates (e.g., randomized rotation angles or other random parameters). The quantum logic gates may include single- qubit quantum logic gates, such as, for example, single qubit rotations. In some examples, the quantum logic gates include two-qubit quantum logic gates (e.g., Controlled-phase gates, Controlled-NOT gates, CZ gates or iSWAP gates); suitable native gates may be selected in some cases. In some instances, a parametric quantum logic circuit can be used to augment the amount of securely shared information by introducing a symmetric key dependence on one or more parameters of the parametric quantum logic gates.Attorney Docket No.: RIGET-127WO1
[0025] In some implementations, the systems and techniques described here can provide technical advantages and improvements. The systems and techniques presented here may provide improved security (e.g., “perfect” security or security that cannot be compromised by known technologies) and resistance to known-plaintext attacks using a potentially shorter key than the length of the message. In some cases, the systems and techniques presented here can be effectively used as subroutines to perform bulk plain text encoding. In some cases, the systems and techniques presented here can be used to encrypt any type of data, and thus, can be used for various communication scenarios. In some cases, the systems and techniques presented here can utilize measurements of expectation values of Pauli observables, which can allow the use of error mitigation techniques and enable noise resistance. In some cases, a combination of these and potentially other advantages and improvements may be obtained.
[0026] FIG.1 is a block diagram of an example computing environment 100, according to an example embodiment. The example computing environment 100 shown in FIG.1 includes a computing system 101 and user devices 110A, 110B, 110C. A computing environment may include additional or different features, and the components of a computing environment may operate as described with respect to FIG.1 or in another manner.
[0027] The example computing system 101 includes classical and quantum computing resources and exposes their functionality to the user devices 110A, 110B, 110C (referred to collectively as “user devices 110”). The computing system 101 shown in FIG.1 includes one or more servers 108, quantum computing systems 103A, 103B, a local network 109, and other resources 107. The computing system 101 may also include one or more user devices (e.g., the user device 110A) as well as other features and components. A computing system may include additional or different features, and the components of a computing system may operate as described with respect to FIG.1 or in another manner.
[0028] The example computing system 101 can provide services to the user devices 110, for example, as a cloud-based or remote-accessed computer system, as a distributed computing resource, as a supercomputer or another type of high-performance computing resource, or in another manner. The computing system 101 or the user devices 110 mayAttorney Docket No.: RIGET-127WO1 also have access to one or more other quantum computing systems (e.g., quantum computing resources that are accessible through the wide area network 115, the local network 109, or otherwise).
[0029] The user devices 110 shown in FIG.1 may include one or more classical processors, memory, user interfaces, communication interfaces, and other components. For instance, the user devices 110 may be implemented as laptop computers, desktop computers, smartphones, tablets, or other types of computer devices. In the example shown in FIG.1, to access computing resources of the computing system 101, the user devices 110 send information (e.g., programs, instructions, commands, requests, input data, etc.) to the servers 108; and in response, the user devices 110 receive information (e.g., application data, output data, prompts, alerts, notifications, results, etc.) from the servers 108. The user devices 110 may access services of the computing system 101 in another manner, and the computing system 101 may expose computing resources in another manner.
[0030] In the example shown in FIG.1, the local user device 110A operates in a local environment with the servers 108 and other elements of the computing system 101. For instance, the user device 110A may be co-located with (e.g., located within 0.5 to 1 km of) the servers 108 and possibly other elements of the computing system 101. As shown in FIG. 1, the user device 110A communicates with the servers 108 through a local data connection.
[0031] The local data connection in FIG.1 is provided by the local network 109. For example, some or all of the servers 108, the user device 110A, the quantum computing systems 103A, 103B, and the other resources 107 may communicate with each other through the local network 109. In some implementations, the local network 109 operates as a communication channel that provides one or more low-latency communication pathways from the server 108 to the quantum computing systems 103A, 103B (or to one or more of the elements of the quantum computing systems 103A, 103B). The local network 109 can be implemented, for instance, as a wired or wireless Local Area Network, an Ethernet connection, or another type of wired or wireless connection. The local network 109 may include one or more wired or wireless routers, wireless access points (WAPs),Attorney Docket No.: RIGET-127WO1 wireless mesh nodes, switches, high-speed cables, or a combination of these and other types of local network hardware elements. In some cases, the local network 109 includes a software-defined network that provides communication among virtual resources, for example, among an array of virtual machines operating on the server 108 and possibly elsewhere.
[0032] In the example shown in FIG.1, the remote user devices 110B, 110C operate remotely from the servers 108 and other elements of the computing system 101. For instance, the user devices 110B, 110C may be located at a remote distance (e.g., more than 1 km, 10 km, 100 km, 1,000 km, 10,000 km, or farther) from the servers 108 and possibly other elements of the computing system 101. As shown in FIG.1, each of the user devices 110B, 110C communicates with the servers 108 through a remote data connection.
[0033] The remote data connection in FIG.1 is provided by a wide area network 115, which may include, for example, the Internet or another type of wide area communication network. In some cases, remote user devices use another type of remote data connection (e.g., satellite-based connections, a cellular network, a virtual private network, etc.) to access the servers 108. The wide area network 115 may include one or more internet servers, firewalls, service hubs, base stations, or a combination of these and other types of remote networking elements. Generally, the computing environment 100 can be accessible to any number of remote user devices.
[0034] The example servers 108 shown in FIG.1 can manage interaction with the user devices 110 and utilization of the quantum and classical computing resources in the computing system 101. For example, based on information from the user devices 110, the servers 108 may delegate computational tasks to the quantum computing systems 103A, 103B and the other resources 107; the servers 108 can then send information to the user devices 110 based on output data from the computational tasks performed by the quantum computing systems 103A, 103B, and the other resources 107.
[0035] As shown in FIG.1, the servers 108 are classical computing resources that include classical processors 111 and memory 112. The servers 108 may also include one or more communication interfaces that allow the servers to communicate via the localAttorney Docket No.: RIGET-127WO1 network 109, the wide area network 115, and possibly other channels. In some implementations, the servers 108 may include a host server, an application server, a virtual server, or a combination of these and other types of servers. The servers 108 may include additional or different features and may operate as described with respect to FIG.1 or in another manner.
[0036] The classical processors 111 can include various kinds of apparatus, devices, and machines for processing data, including, by way of example, a microprocessor, a central processing unit (CPU), a graphics processing unit (GPU), an FPGA (field programmable gate array), an ASIC (application specific integrated circuit), or combinations of these. The memory 112 can include, for example, a random-access memory (RAM), a storage device (e.g., a writable read-only memory (ROM) or others), a hard disk, or another type of storage medium. The memory 112 can include various forms of volatile or non-volatile memory, media, and memory devices, etc.
[0037] Each of the example quantum computing systems 103A, 103B operates as a quantum computing resource in the computing system 101. The other resources 107 may include additional quantum computing resources (e.g., quantum computing systems, quantum simulators, or both) as well as classical (non-quantum) computing resources such as, for example, digital microprocessors, specialized co-processor units (e.g., graphics processing units (GPUs), cryptographic co-processors, etc.), special purpose logic circuitry (e.g., field programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), etc.), systems-on-chips (SoCs), etc., or combinations of these and other types of computing modules.
[0038] In some implementations, the servers 108 generate programs, identify appropriate computing resources (e.g., a QPU or QVM) in the computing system 101 to execute the programs, and send the programs to the identified resources for execution. For example, the servers 108 may send programs to the quantum computing system 103A, the quantum computing system 103B, or any of the other resources 107. The programs may include classical programs, quantum programs, hybrid classical / quantum programs, and may include any type of function, code, data, instruction set, etc.Attorney Docket No.: RIGET-127WO1
[0039] In some instances, programs can be formatted as source code that can be rendered in human-readable form (e.g., as text) and can be compiled, for example, by a compiler running on the servers 108, on the quantum computing systems 103, or elsewhere. In some instances, programs can be formatted as compiled code, such as, for example, binary code (e.g., machine-level instructions) that can be executed directly by a computing resource. Each program may include instructions corresponding to computational tasks that, when performed by an appropriate computing resource, generate output data based on input data. For example, a program can include instructions formatted for a quantum computer system, a simulator, a digital microprocessor, co- processor or other classical data processing apparatus, or another type of computing resource.
[0040] In some cases, a program may be expressed in a hardware-independent format. For example, quantum machine instructions may be provided in a quantum instruction language such as Quil, described in the publication “A Practical Quantum Instruction Set Architecture,” arXiv:1608.03355v2, dated Feb.17, 2017, or another quantum instruction language. For instance, the quantum machine instructions may be written in a format that can be executed by a broad range of quantum processing units or simulators. In some cases, a program may be expressed in high-level terms of quantum logic gates or quantum algorithms, in lower-level terms of fundamental qubit rotations and controlled rotations, or in another form. In some cases, a program may be expressed in terms of control signals (e.g., pulse sequences, delays, etc.) and parameters for the control signals (e.g., frequencies, phases, durations, channels, etc.). In some cases, a program may be expressed in another form or format. In some cases, a program may utilize Quil-T, described in the publication “Gain deeper control of Rigetti quantum processing units with Quil-T,” available at https: / / medium.com / rigetti / gain-deeper-control-of-rigetti-quantum-processors-with- quil-t-ea8945061e5b dated Dec.10, 2020, which is hereby incorporated by reference in the present disclosure.
[0041] In some implementations, the servers 108 include one or more compilers that convert programs between formats. For example, the servers 108 may include a compiler that converts hardware-independent instructions to binary programs for execution by theAttorney Docket No.: RIGET-127WO1 quantum computing systems 103A, 103B. In some cases, a compiler can compile a program to a format that targets a specific quantum resource in the computer system 101. For example, a compiler may generate a different binary program (e.g., from the same source code) depending on whether the program is to be executed by the quantum computing system 103A or the quantum computing system 103B.
[0042] In some cases, a compiler generates a partial binary program that can be updated, for example, based on specific parameters. For instance, if a quantum program is to be executed iteratively on a quantum computing system with varying parameters on each iteration, the compiler may generate the binary program in a format that can be updated with specific parameter values at runtime (e.g., based on feedback from a prior iteration, or otherwise); the parametric update can be performed without further compilation. In some cases, a compiler generates a full binary program that does not need to be updated or otherwise modified for execution.
[0043] In some implementations, the servers 108 generate a schedule for executing programs, allocate computing resources in the computing system 101 according to the schedule, and delegate the programs to the allocated computing resources. The servers 108 can receive, from each computing resource, output data from the execution of each program. Based on the output data, the servers 108 may generate additional programs that are then added to the schedule, output data that is provided back to a user device 110, or perform another type of action.
[0044] In some implementations, all or part of the computing system 101 operates as a hybrid computing environment. For example, quantum programs can be formatted as hybrid classical / quantum programs that include instructions for execution by one or more quantum computing resources (e.g., the quantum-based algorithms) and instructions for execution by one or more classical resources. The servers 108 can allocate quantum and classical computing resources in the hybrid computing environment, and delegate programs to the allocated computing resources for execution. The quantum computing resources in the hybrid environment may include, for example, one or more quantum processing units (QPUs), one or more quantum virtual machines (QVMs), one or more quantum simulators, or possibly other types of quantum resources. The classicalAttorney Docket No.: RIGET-127WO1 computing resources in the hybrid environment may include, for example, one or more digital microprocessors, one or more specialized co-processor units (e.g., graphics processing units (GPUs), cryptographic co-processors, etc.), special purpose logic circuitry (e.g., field programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), etc.), systems-on-chips (SoCs), or other types of computing modules.
[0045] In some cases, the servers 108 can select the type of computing resource (e.g., quantum or classical) to execute an individual program, or part of a program, in the computing system 101. For example, the servers 108 may select a particular quantum processing unit (QPU) or other computing resource based on availability of the resource, speed of the resource, information or state capacity of the resource, a performance metric (e.g., process fidelity) of the resource, or based on a combination of these and other factors. In some cases, the servers 108 can perform load balancing, resource testing and calibration, and other types of operations to improve or optimize computing performance.
[0046] Each of the example quantum computing systems 103A, 103B shown in FIG.1 can perform quantum computational tasks by executing quantum machine instructions (e.g., a binary program compiled for the quantum computing system). In some implementations, a quantum computing system can perform quantum computation by storing and manipulating information within quantum states of a composite quantum system. For example, qubits (i.e., quantum bits) can be stored in, and represented by, an effective two-level sub-manifold of a quantum coherent physical system. In some instances, quantum logic can be executed in a manner that allows large-scale entanglement within the quantum system. Control signals can manipulate the quantum states of individual qubits and the joint states of multiple qubits. In some instances, information can be read out from the composite quantum system by measuring the quantum states of the qubits. In some implementations, the quantum states of the qubits are read out by measuring the transmitted or reflected signal from auxiliary quantum devices that are coupled to individual qubits.
[0047] In some implementations, a quantum computing system can operate using gate- based models for quantum computing. For example, the qubits can be initialized in an initial state, and a quantum logic circuit comprised of a series of quantum logic gates can beAttorney Docket No.: RIGET-127WO1 applied to transform the qubits and extract measurements representing the output of the quantum computation. Individual qubits may be controlled by single-qubit quantum logic gates, and pairs of qubits may be controlled by two-qubit quantum logic gates (e.g., entangling gates that are capable of generating entanglement between the pair of qubits). In some implementations, a quantum computing system can operate using adiabatic or annealing models for quantum computing. For instance, the qubits can be initialized in an initial state, and the controlling Hamiltonian can be transformed adiabatically by adjusting control parameters to another state that can be measured to obtain an output of the quantum computation.
[0048] In some models, fault-tolerance can be achieved by applying a set of high-fidelity control and measurement operations to the qubits. For example, quantum error correcting codes can be deployed to achieve fault-tolerant quantum computation. Other computational regimes may be used; for example, quantum computing systems may operate in non-fault-tolerant regimes. In some implementations, a quantum computing system is constructed and operated according to a scalable quantum computing architecture. For example, in some cases, the architecture can be scaled to a large number of qubits to achieve large-scale general purpose coherent quantum computing. Other architectures may be used; for example, quantum computing systems may operate in small- scale or non-scalable architectures.
[0049] The example quantum computing system 103A shown in FIG.1 includes a quantum processing unit 102A and a control system 105A, which controls the operation of the quantum processing unit 102A. Similarly, the example quantum computing system 103B includes a quantum processing unit 102B and a control system 105B, which controls the operation of a quantum processing unit 102B. A quantum computing system may include additional or different features, and the components of a quantum computing system may operate as described with respect to FIG.1 or in another manner.
[0050] In some instances, all or part of the quantum processing unit 102A functions as a quantum processing unit, a quantum memory, or another type of subsystem. In some examples, the quantum processing unit 102A includes a superconducting quantum circuit system. The superconducting quantum circuit may include data qubit devices, stabilizerAttorney Docket No.: RIGET-127WO1 qubit devices, coupler devices, readout devices, and possibly other devices that are used to store and process quantum information. In some cases, multiple data qubit devices are operatively coupled to a single stabilizer check qubit device through respective coupler devices. In some implementations, the quantum processing unit 102A is implemented utilizing aspects designed or generated from the components and processes shown in FIGS. 2-4, or in another manner. In certain examples, the qubit devices and the coupler devices are implemented as superconducting quantum circuit devices that include Josephson junctions, for example, in Superconducting QUantum Interference Device (SQUID) loops or other arrangements, and are controlled by radio-frequency signals, microwave signals, and bias signals delivered to the quantum processing unit 102A.
[0051] In some instances, the quantum processing modules can include a superconducting quantum circuit that includes one or more quantum circuit devices. For instance, a superconducting quantum circuit may include qubit devices, readout resonator devices, Josephson junctions, or other quantum circuit devices. In some implementations, quantum circuit devices in a quantum processing unit can be collectively operated to define a single logical qubit. A logical qubit includes a quantum register, for instance multiple physical qubits or qudits, and associated circuitry, that supports physical operations which can be used to detect or correct errors associated with logical states in a quantum algorithm. Physical operations supported by the quantum register associated with a logical qubit may include single-qubit or multi-qubit quantum logic gates and readout mechanisms. Error detection or correction mechanisms associated with a logical qubit may be based on quantum error correction schemes such as the surface code, color code, Bacon- Shor codes, low-density parity check codes (LDPC), some combination of these, or others.
[0052] The quantum processing unit 102A may include, or may be deployed within, a controlled environment. The controlled environment can be provided, for example, by shielding equipment, cryogenic equipment, and other types of environmental control systems. In some examples, the components in the quantum processing unit 102A operate in a cryogenic temperature regime and are subject to very low electromagnetic and thermal noise. For example, magnetic shielding can be used to shield the system components from stray magnetic fields, optical shielding can be used to shield the systemAttorney Docket No.: RIGET-127WO1 components from optical noise, thermal shielding and cryogenic equipment can be used to maintain the system components at controlled temperature, etc.
[0053] In some implementations, the example quantum processing unit 102A can process quantum information by applying control signals to the qubits in the quantum processing unit 102A. The control signals can be configured to encode information in the qubits, to process the information by performing quantum logic gates or other types of operations, or to extract information from the qubits. In some examples, the operations can be expressed as single-qubit quantum logic gates, two-qubit quantum logic gates, or other types of quantum logic gates that operate on one or more qubits. A quantum logic circuit, which includes a sequence of quantum logic operations, can be applied to the qubits to perform a quantum algorithm. The quantum algorithm may correspond to a computational task, a hardware test, a quantum error correction procedure, a quantum state distillation procedure, or a combination of these and other types of operations.
[0054] The example control system 105A includes controllers 106A and signal hardware 104A. Similarly, control system 105B includes controllers 106B and signal hardware 104B. All or part of the control systems 105A, 105B can operate in a room- temperature environment or another type of environment, which may be located near the respective quantum processing units 102A, 102B. In some cases, the control systems 105A, 105B include classical computers, signaling equipment (microwave, radio, optical, bias, etc.), electronic systems, vacuum control systems, refrigerant control systems, or other types of control systems that support operation of the quantum processing units 102A, 102B.
[0055] The control systems 105A, 105B may be implemented as distinct systems that operate independent of each other. In some cases, the control systems 105A, 105B may include one or more shared elements; for example, the control systems 105A, 105B may operate as a single control system that operates both quantum processing units 102A, 102B. Moreover, a single quantum computing system may include multiple quantum processing units, which may operate in the same controlled (e.g., cryogenic) environment or in separate environments.Attorney Docket No.: RIGET-127WO1
[0056] The example signal hardware 104A includes components that communicate with the quantum processing unit 102A. The signal hardware 104A may include, for example, waveform generators, amplifiers, digitizers, high-frequency sources, DC sources, AC sources, etc. The signal hardware may include additional or different features and components. In the example shown, components of the signal hardware 104A are adapted to interact with the quantum processing unit 102A. For example, the signal hardware 104A can be configured to operate in a particular frequency range, configured to generate and process signals in a particular format, or the hardware may be adapted in another manner.
[0057] In some instances, one or more components of the signal hardware 104A generate control signals, for example, based on control information from the controllers 106A. The control signals can be delivered to the quantum processing unit 102A during operation of the quantum computing system 103A. For instance, the signal hardware 104A may generate signals to implement quantum logic operations, readout operations, or other types of operations. As an example, the signal hardware 104A may include arbitrary waveform generators (AWGs) that generate electromagnetic waveforms (e.g., microwave or radiofrequency) or laser systems that generate optical waveforms. The waveforms or other types of signals generated by the signal hardware 104A can be delivered to devices in the quantum processing unit 102A to operate qubit devices, readout devices, bias devices, coupler devices, or other types of components in the quantum processing unit 102A.
[0058] In some instances, the signal hardware 104A receives and processes signals from the quantum processing unit 102A. The received signals can be generated by the execution of a quantum program on the quantum computing system 103A. For instance, the signal hardware 104A may receive signals from the devices in the quantum processing unit 102A in response to readout or other operations performed by the quantum processing unit 102A. Signals received from the quantum processing unit 102A can be mixed, digitized, filtered, or otherwise processed by the signal hardware 104A to extract information, and the information extracted can be provided to the controllers 106A or handled in another manner. In some examples, the signal hardware 104A may include a digitizer that digitizes electromagnetic waveforms (e.g., microwave or radiofrequency) or optical signals, and a digitized waveform can be delivered to the controllers 106A or toAttorney Docket No.: RIGET-127WO1 other signal hardware components. In some instances, the controllers 106A process the information from the signal hardware 104A and provide feedback to the signal hardware 104A; based on the feedback, the signal hardware 104A can in turn generate new control signals that are delivered to the quantum processing unit 102A.
[0059] In some implementations, the signal hardware 104A includes signal delivery hardware that interfaces with the quantum processing unit 102A. For example, the signal hardware 104A may include filters, attenuators, directional couplers, multiplexers, diplexers, bias components, signal channels, isolators, amplifiers, power dividers, and other types of components. In some instances, the signal delivery hardware performs preprocessing, signal conditioning, or other operations to the control signals to be delivered to the quantum processing unit 102A. In some instances, signal delivery hardware performs preprocessing, signal conditioning, or other operations on readout signals received from the quantum processing unit 102A.
[0060] The example controllers 106A communicate with the signal hardware 104A to control the operation of the quantum computing system 103A. The controllers 106A may include classical computing hardware that directly interfaces with components of the signal hardware 104A. The example controllers 106A may include classical processors, memory, clocks, digital circuitry, analog circuitry, and other types of systems or subsystems. The classical processors may include one or more single- or multi-core microprocessors, digital electronic controllers, special purpose logic circuitry, e.g., an FPGA (field programmable gate array) or an ASIC (application specific integrated circuit), or other types of data processing apparatus. The memory may include any type of volatile or non-volatile memory or another type of computer storage medium. The controllers 106A may also include one or more communication interfaces that allow the controllers 106A to communicate via the local network 109 and possibly other channels. The controllers 106A may include additional or different features and components.
[0061] In some implementations, the controllers 106A include memory or other components that store quantum state information, for example, based on qubit readout operations performed by the quantum computing system 103A. For instance, the states of one or more qubits in the quantum processing unit 102A can be measured by qubit readoutAttorney Docket No.: RIGET-127WO1 operations, and the measured state information can be stored in a cache or other type of memory system in one or more of the controllers 106A. In some cases, the measured state information is subsequently used in the execution of a quantum program, a quantum error correction procedure, a quantum processing unit (QPU) calibration or testing procedure, or another type of quantum process.
[0062] In some implementations, the controllers 106A include memory or other components that store a quantum program containing quantum machine instructions for execution by the quantum computing system 103A. In some instances, the controllers 106A can interpret the quantum machine instructions and perform hardware-specific control operations according to the quantum machine instructions. For example, the controllers 106A may cause the signal hardware 104A to generate control signals that are delivered to the quantum processing unit 102A to execute the quantum machine instructions.
[0063] In some instances, the controllers 106A extract qubit state information from qubit readout signals, for example, to identify the quantum states of qubits in the quantum processing unit 102A or for other purposes. For example, the controllers may receive the qubit readout signals (e.g., in the form of analog waveforms) from the signal hardware 104A, digitize the qubit readout signals, and extract qubit state information from the digitized signals. In some cases, the controllers 106A compute measurement statistics based on qubit state information from multiple shots of a quantum program. For example, each shot may produce a bitstring representing qubit state measurements for a single execution of the quantum program, and a collection of bitstrings from multiple shots may be analyzed to compute quantum state probabilities.
[0064] In some implementations, the controllers 106A include one or more clocks that control the timing of operations. For example, operations performed by the controllers 106A may be scheduled for execution over a series of clock cycles, and clock signals from one or more clocks can be used to control the relative timing of each operation or groups of operations. In some implementations, the controllers 106A may include classical computer resources that perform some or all of the operations of the servers 108 described above. For example, the controllers 106A may operate a compiler to generate binary programs (e.g., full or partial binary programs) from source code; the controllers 106A may includeAttorney Docket No.: RIGET-127WO1 an optimizer that performs classical computational tasks of a hybrid classical / quantum program; the controllers 106A may update binary programs (e.g., at runtime) to include new parameters based on an output of the optimizer, etc.
[0065] The other quantum computing system 103B and its components (e.g., the quantum processing unit 102B, the signal hardware 104B, and controllers 106B) can be implemented as described above with respect to the quantum computing system 103A; in some cases, the quantum computing system 103B and its components may be implemented or may operate in another manner.
[0066] In some implementations, the quantum computing systems 103A, 103B are disparate systems that provide distinct modalities of quantum computation. For example, the computer system 101 may include both an adiabatic quantum computing system and a gate-based quantum computer system. As another example, the computer system 101 may include a superconducting circuit-based quantum computing system and an ion trap-based quantum computer system. In such cases, the computer system 101 may utilize each quantum computing system according to the type of quantum programs that is being executed, according to availability or capacity, or based on other considerations.
[0067] In some instances, one or more components of the computing system 101 shown in FIG.1 are configured to perform the operations of the example processes shown in FIGS. 2A-2C, or another process. For example, a classical computing system (e.g., the classical processors 111 in the servers 108) can be configured to generate a random string of Pauli operators; determine a quantum logic circuit shown in FIG.4A; determine a modified quantum logic circuit shown in FIG.4B based on a random string of Pauli operators; request the quantum computing systems 103A, 103B to executing the modified quantum logic circuit on qubits; and perform measurement on each of the qubits according to the generated random string of Pauli operators to determine expectation values. In some instances, the components of the computing system 101 may be configured to perform other operations. In some implementations, the computing system 101 may be implemented as a quantum cryptographic system; and may be configured to iteratively: execute quantum cryptographic encryption and decryption algorithms to encrypt or decrypt a message. For example, the quantum cryptographic encryption and decryptionAttorney Docket No.: RIGET-127WO1 algorithms shown in FIGS.2A-2C may be performed in the computing system 101 in FIG.1 or in another type of hybrid computing system.
[0068] FIGS.2A-2C are flow charts showing aspects of an example encryption and decryption process 200. The example encryption and decryption process 200 is a symmetric encryption and decryption scheme that can be executed by one or more hybrid computer systems (e.g., the computer system 101 shown in FIG.1) which includes one or more quantum computing resources (e.g., the quantum processing units or the quantum simulators) and one or more classical computing resources. The example process 200 is based on execution of a quantum logic circuit on multiple qubits and measurements of quantum states. In the example process 200, the same key shared with trusted parties is used to encrypt and decrypt the message. The example process 200 can be configured to make the communication between trusted parties almost perfectly secure (e.g., as secure as a one-time pad system) as long as the key remains unknown to the potential adversary. The example process 200 uses a quantum logic circuit that is executable on a quantum processor unit or a quantum simulator. The example process 200 can be used to generate output based symmetric encryption of data and improve performance and security of encryption algorithms. In some instances, the example process 200 can be embedded into classical pipelines. The example process 200 may include additional or different operations, including operations to fabricate additional or different components, and the operations may be performed in the order shown or in another order. In some cases, operations in the example process 200 can be combined, iterated, or otherwise repeated or performed in another manner.
[0069] The example process 200 shown in FIGS.2A-2C is performed by two entities: a message sender (“Alice”) and a message recipient (“Bob”). In the example shown, an entity represented by Alice or Bob may correspond to a computing device, a computer system, an IP address or other network address, or another type of computer-readable identifier or instance of a computer resource. Accordingly, the computations and other operations of each entity may be performed by one or more processors or other elements of a computer system or computing environment. Similarly, information sent to or received by an entityAttorney Docket No.: RIGET-127WO1 may be sent to or received by an element (e.g., one or more processors, memories, or interfaces) of the respective computer system or computing environment.
[0070] At 202, a quantum logic circuit and a mapping scheme are obtained by Alice. In the example shown in FIG.2A, the quantum logic circuit and mapping scheme correspond to a shared secret that is used in the example encryption and decryption process 200. The shared secret may include additional or different information in some cases. In some implementations, Alice generates the shared secret, for example, on the same computer system that performs Alice’s other operations in the encryption and decryption process 200. In some implementations, Bob generates the shared secret, for example, on the same computer system that performs Bob’s other operations in the encryption and decryption process 200. In some implementations, the shared secret is generated by a trusted third party and then shared with Alice and Bob. For example, the shared secret may be confidentially shared with Alice and Bob over a private communication channel, using a public key infrastructure (PKI), or in another manner.
[0071] In some instances, a quantum logic circuit and a mapping scheme are randomly generated. In some instances, the quantum logic circuit includes multiple quantum logic gates applied on ^ quantum registers (e.g., qubits defined by qubit devices). The quantum logic circuit includes multiple layers (^) of quantum logic gates. In some instances, the number of layers M can be determined by the number of quantum registers where thequantum logic circuit is applied, e.g., ^ = ^^^(2√^). In some examples, a quantum logicgate may be a single-qubit quantum logic gate, a two-qubit quantum logic gate, or another multi-qubit quantum logic gate. In some instances, a single-qubit quantum logic gate may be a rotation gate with a random rotation around the ^, ^ or ^ axis; and a two-qubit quantum logic gate may be any suitable native quantum logic gate (e.g., CZ or iSWAP). In some instances, a quantum logic circuit may be implemented as the example quantum logic circuit 300 shown in FIG.3 or in another manner.
[0072] FIG.3 is a block diagram showing aspects of an example quantum logic circuit 300. The quantum logic circuit 300 is a parametric quantum logic circuit that includes a sequence of quantum logic gates. The sequence includes one or more parametric quantum logic gates. A parametric quantum logic gate is controlled by an adjustable parameter (e.g.,Attorney Docket No.: RIGET-127WO1^^, … , ^^). As shown in FIG. 3, the example quantum logic circuit 300 includes single-qubitquantum logic gates, two-qubit quantum logic gates, and other multi-qubit quantum logic gates. The sequence of quantum logic gates in the example quantum logic circuit 300 may be grouped into multiple (^) layers 302-1, 302-2, …, 302-(^-1), and 302-^. Quantum logic gates in the same layer may be performed during the same time period. As shown in FIG.3, the first layer 302-1 of quantum logic gates are performed during the first time period ^^; the second layer 302-2 of quantum logic gates are performed during the second time period ^^; the (^-1)-th layer 302-(^-1) of quantum logic gates are performed during the (^-1)-th time period ^^^^; and the ^-th layer 302-^ of quantum logic gates are performed during the ^-th time period ^^.
[0073] In some instances, a quantum logic gate includes a unitary linear operator that transforms the quantum state (represented by a complex unit vector in a high-dimensional Hilbert space), thus implementing the computational protocol. In some instances, a multi- qubit quantum logic gates can be used to create entanglement among multiple qubits. The final quantum state, |^^〉 is obtained after the execution of the quantum logic circuit to the initial quantum state, |^^〉:^^ = ^^(^^) … ^^(^^)^^(^^)^^. (1)
[0074] In some instances,the ^-th layer of quantum logic gates can produce a classical bitstring, which is a sample from one of the probability distributions encoded in the final quantum state. The computational basis is the ^-basis (unless explicitly specified otherwise) and the measurement of the qubit state in the ^-basis gives us either “0” (corresponding to the +1 eigenvalue of the Pauli # operator) or “1” (corresponding to the −1 eigenvalue of the Pauli # operator). The outcome is probabilistic, but running the same quantum logic circuit multiple times allows us to calculate the expectation value of Pauli # on the corresponding qubit. Changing the ^-basis to the ^-basis or the ^-basis allows us to calculate the expectation values of, respectively, Pauli % and Pauli & operators.
[0075] To measure these expectation values, “change of basis” gates are added to the quantum circuit before measurement. For example, to remain in the ^-basis, add nothing toAttorney Docket No.: RIGET-127WO1 the qubit or a change of basis gate may be an identity gate '. To transform the ^-basis into the ^-basis, a change of basis gate may be an ( gate. To transform the ^-basis into the ^- basis, change of basis gates may be ()*gates with the )*gate being applied first.
[0076] The gates used to change the basis (the “change of basis” gates) are as follows: '= +1 0 1 1(2) 01- , ( = + 11 −1-, )* = +1 00 −^-.
[0077] In somearound the ^, ^ and ^ axis by angle ^ can be defined as: écos 7^ ^28 −^sin 728ù
[0078] The CZ and iSWAPé1 0 0 01 0 0ù
[0079] In somelogic circuit with one or more parametric quantum logic gates. In some instances, security can be dramatically improved by using a parametric quantum logic circuit. In certain examples, the parametric quantum logic gates in a parametric quantum logic circuit may beAttorney Docket No.: RIGET-127WO1 in the same layer or layers. In some instances, the parametric quantum logic gates may be at different positions (e.g., in different layers) of the quantum logic circuit. For example, a parametric quantum logic circuit may include a layer of single-qubit quantum logic gates. In some implementations, the parameters (e.g., rotation angles) of the parametric single-qubit quantum logic gates have the form IJ^, where IJ ∈ [−1,1], ^ = 1, … , ^. In someinstances, the coefficient IJcan be randomly generated; and ^ has the same value for all the single-qubit quantum logic gates in the first layer. In some instances, the quantum logic circuit with the first layer of parametric single-qubit quantum logic gates may be implemented as the example quantum logic circuit 440 shown in FIG.4C.
[0080] In some instances, making one or more layers of a quantum logic circuit adjustable turns the generated quantum logic circuit into a de facto family of quantum logic circuits, where the configuration of adjustable parameters plays the role of a “seed” that can be set according to some rules. For example, it can be derived from the time stamp of some process as explained below. In some instances, the parametric quantum logic circuit can improve the amount of data (e.g., the number of bits) that can be encoded before the same pairs of Pauli operators are reused. In some instances, the values of the parameters of the parameters of the parametric quantum logic gates in the parametric quantum logic circuit can be regularly reset (e.g., change seed values). In this case, the same pairs of Pauli operators may have different expectation values for different seeds. This should prevent any meaningful attempt at analysis of large amounts of intercepted encrypted text as long as the seed is changed before the Pauli pairs are repeated. The systems and techniques presented here allow the reuse of the same quantum logic circuit multiple times since every configuration of adjustable parameters can lead to the corresponding unique quantum state in which Pauli operators are measured.
[0081] In some implementations, a mapping scheme is configured and generated to provide a one-to-one mapping between any desired plain text symbol and a 2^-digit bitstring with exactly ^ “0”s and exactly ^ “1”s. In some instances, a mapping scheme may be randomly generated by the operation of the classical computing system of the hybrid computer system. In some implementations, the number of “0”s and “1”s in each randomly generated bitstring is the same to prevent any possible attempt at frequency analysis. AnAttorney Docket No.: RIGET-127WO1 example mapping scheme may be implemented as the mapping scheme 500 shown in FIG. 5 or in another manner.
[0082] For example, Alice and Bob, two trusted parties, would like to communicate securely via unsecure channels. They meet at Alice’s office, which is a secure place, where Alice generates a quantum logic circuit (e.g., the example quantum logic circuit 400 shown in FIG.4A) in the form of Python code on her laptop. As shown in FIG.4A, the randomly generated quantum logic circuit 400 is applied on 5 quantum registers (N=5) and 6 layers of single-qubit and two-qubit quantum logic gates. The single-qubit quantum logic gates are random rotations around the ^ and ^ axes; and the two-qubit quantum logic gates are CZ (controlled #) gates that create entanglement between two qubits wherein the two- qubit quantum logic gate is applied. In some implementations, the quantum logic circuit is completely hardware agnostic. Execution of this quantum logic circuit can transform the initial quantum state 0⊗Ointo a unique entangled quantum state ^ that can only be fully described by specifying 2Oprobability amplitudes, where ^ is the number of qubits. In some instances, the random mapping of the plain text symbols to the bitstrings of fixed length can be generated by Alice simultaneously with the generation of the quantum logic circuit. An example random mapping that illustrates this principle is shown in FIG.5, in which each plain text symbol is represented by a 12-bit bitstring with six “0”s and six “1”s.
[0083] At 204, the quantum logic circuit and mapping scheme are shared with Bob. As shown in FIG.2A, the quantum logic circuit and the mapping scheme are transferred from Alice to Bob in a secured manner, e.g., over a private communication channel, using a public key infrastructure (PKI), or in another secured manner. In some instances, the quantum logic circuit and the mapping scheme may be shared between Alice and Bob in another manner. For example, if the shared secret is generated by a trusted third party, it may be shared with Alice and Bob confidentially over a private communication channel, using a public key infrastructure (PKI), or otherwise. Accordingly, Bob may obtain the quantum logic circuit and the mapping scheme directly from the third party, and Alice would not need to send them to Bob in such cases. Alternatively, in some cases, Bob may generate the quantum logic circuit and the mapping scheme, and Bob shares them with Alice in a secureAttorney Docket No.: RIGET-127WO1 manner. In the example shown, the quantum logic circuit is part of a symmetric key that can be used by the trusted parties to encrypt and decrypt data specified in binary format.
[0084] In some instances, the amount of information needed to fully specify a quantum logic circuit (e.g., the number of bits needed to describe a quantum logic circuit) can be significantly smaller than the amount of information that can be securely encoded using the quantum logic circuit. In some implementations, a quantum logic circuit applied on ^ qubits with ^ layers of quantum logic gates can be fully specified by providing adescription for each of the ^ × ^ circuit nodes. In some instances, a circuit node in aquantum logic circuit corresponds to a quantum logic gate applied on a respective qubit. For example, when a single-qubit quantum logic gate is applied on a single qubit, a circuit node can be used to represent the single-qubit quantum logic gate. When a two-qubit quantum logic gate is applied to two qubits, two circuit nodes can be used, e.g., one for each qubit, to represent the two-qubit quantum logic gate. In some instances, for a given circuit node, information of gate type, e.g., a single-qubit quantum logic gate including an identity gate ' or a two-qubit quantum logic gate, can be specified using 3-bit scheme or another type of scheme. FIG.13 includes a table 1300 showing aspects of an example encoding scheme for encoding the gate type in a quantum logic circuit.
[0085] In some instances, parameters of parametric single qubit gates in the quantum logic circuit can be specified using an encoding mechanism. For example, the rotation angles of parametric single-qubit quantum gates, which is a continuous variable on theinterval [−Q, Q], can be specified using a standard 32-bit precision binary encoding oranother type of encoding. In some instances, a quantum logic circuit with ^ qubits and ^layers of quantum logic gates can be encoded as a bitstring of length (R + S) × ^ × ^, withR-bit encoding of the gate type and S-bit encoding of the gate parameter (rotation angles).Equivalently, a random bitstring of length (R + S) × ^ × ^ can be translated into thecorresponding quantum logic circuit.
[0086] In some instances, a two-qubit quantum logic gate may not be symmetrical with respect to the two qubits where the two-qubit quantum logic gate is applied. To discriminate between the two qubits, one may be called the target and the other may be called the control. In certain examples, the roles of the control and target qubits are definedAttorney Docket No.: RIGET-127WO1 by their specific function the operation of the two-qubit quantum logic gate. For example, a control qubit may determine whether or not an operation will be performed on the target qubit; and a target qubit is the qubit upon which the operation is performed conditioned on the state of the control qubit. In some instances, for two-qubit quantum logic gates, whether the given circuit node is a target or a control can be specified using a single-bit binary indicator or another type of indicator. In some instances, the locations of the circuit nodes of a corresponding two-qubit quantum logic gate in the same layer can be specified to fully define the two-qubit quantum logic gate. For example, the qubit index which is aninteger number between 0 and ^ − 1 can be used. In this case, a total number of bits torepresent this number in a binary format is ^^^(log^(^)) + 1. (5)
[0087] For example, a 10-bit bitstring can be used when ^ = 1,000 and a 17-bitbitstring can be used when ^ = 100,000. In some instances, a total number of^ × ^ × (3 + 32) bits can be used to fully specify a quantum logic circuit with 32-bitprecision for all rotation angles.
[0088] In some implementations, there are 3Wpossible configurations of the measurement bases, which is indicative of the amount of information a quantum logic circuit can be used to encode. When expectation values of second-order Paulis, HJXYis used, with H= Z%, &, #[,X = Z%, &, #[,Z [(6) ^= 1, … , ^ − 1 ,\ = Z^ + 1, … , ^[.
[0089] The total number of possible combinations of second-order Pauli operators can be expressed as: ^(^ − 1)× 9. (7)2
[0090] In some instances, not all possible combinations of second-order Pauli operators can be used due to measurement noise. For a reasonably large number of quantum logicAttorney Docket No.: RIGET-127WO1 circuit runs, about 80% or another value of the total number of second-order Pauli operators can be used.
[0091] FIG.14 is a table 1400 showing the number of bits needed to specify the quantum logic circuit, the maximum and expected numbers of bits that can be encoded using a quantum logic circuit and second-order Pauli operators for various values of ^.Assuming ^ = 80% and the quantum processor unit in a quantum computing system or thequantum processor unit graph in a quantum simulator has a square grid connectivity, the number of layers of quantum logic gates in the quantum logic circuit, ^= ^^^a√^ × 2b (8)can be used to ensure that the most distant qubits can be connected. The maximum number of bits needed to specify the quantum logic circuit grows with ^ as ^^ / ^, while the maximum number of bits that can be encoded by the quantum logic circuit grows as ^^.
[0092] In some instances, additional information is used to further specify the mapping scheme. As shown in the table 500 of FIG.5, the example mapping scheme contains27 × 3 = 81 characters. Assuming a predetermined ordering, it uses a total number of81 × 12 = 972 bits to specify the mapping scheme, which can be added to the total numberof bits needed to specify the quantum logic circuit when a symmetric key is shared from Alice to Bob.
[0093] In some instances, one of the Quantum Key Distribution (QKD) protocols, e.g., the Bennett-Brassard (BB84) protocol can be used to securely communicate the encrypted message between Alice and Bob. A QKD protocol is a secure communication method that enables two parties to produce a shared random secret key known only to them, which then can be used in later processes (e.g., operations 206, 210) to encrypt and decrypt messages.
[0094] At 206, a message to be communicated from Alice to Bob is encrypted. In the example shown in FIGS.2A-2C, Alice generates the encrypted version of the message based on execution of the quantum logic circuit on a quantum computing system. One or more of the operations and sub-operations shown in FIG.2B may be used to generate the encrypted version of the message. In some cases, another process may be used to generate theAttorney Docket No.: RIGET-127WO1 encrypted version of the message based on execution of the quantum logic circuit on a quantum computing system.
[0095] In the example shown in FIG.2B, at 212, the message is converted to a bitstring using the mapping scheme (e.g., using the mapping scheme 500 shown in FIG.5, or another type of mapping scheme may be used). At 214, a random vector of Pauli operators is generated. The random vector of Pauli operators is configured to specify measurement bases (e.g., a list of measurement bases) on respective qubits. In some implementations, the length of the vector of Pauli operators is equal to the width of the quantum logic circuit, with one-to-one mapping between the elements of the vector of Pauli operators and thequantum registers. For example, a vector of Pauli operators [#^, &^, %^, … , &W] represents ameasurement applied on a first qubit in the Z-basis, a measurement applied on a second qubit in the Y-basis, a measurement applied on a third qubit in the X-basis, …, and a measurement applied on a ^-th qubit in the Y-basis.
[0096] At 216, a time stamp of when the random vector of Pauli operators is generated is obtained. In some implementations, the time stamp value can be used to determine parameters of one or more layers of parametric quantum logic gates in the quantum logic circuit. For example, a time stamp value can be used to determine the parameter values of the first layer of single-qubit rotation gates in the quantum logic circuit. In some instances, the time stamp is an integer number. In some instances, the time stamp has a format of YYMMDDhhmmss. In some instances, the time stamp may be configured using another format. In some instances, the time stamp is used to determine the value of ^ in the rotation angles of the first layer of single-qubit quantum logic gates. For example, the time stamp modulo 2Q (double precision) is the value of parameter ^ in the first layer of the generated quantum logic circuit.
[0097] At 218, the generated quantum logic circuit is modified according to the random vector of Pauli operators. In some implementations, the quantum logic circuit is modified by adding “change of basis” gates to each quantum register to the generated quantum logic circuit. In some implementations, gates to the respective quantum registers are determined in accordance with the vector of Pauli operators corresponding to the respective quantum registers. In some implementations, no gate needs to be added to quantum registers withAttorney Docket No.: RIGET-127WO1 Pauli # (^-basis); a Hadamard gate ( can be added to a quantum register with Pauli % (e.g., transformation from the ^-basis to the ^-basis); ()*to quantum registers with Pauli & (e.g., transformation from the ^-basis to the ^-basis). In some implementations, Pauli %, & and # gates can be expressed as: %= +0 1 0 −^ 1 0 (9)1 0- , & = +^ 0 - , # = +0 −1-.
[0098] At 220, thequantum states are measured. In some instances, the modified quantum logic circuit can be executed d times and the measurement results (e.g., multiple measurement bitstrings) canbe stored in a d × ^ array. In some examples, the measurement results are converted tomultiple eigenvalue vectors (e.g., eigenvalues of corresponding Pauli operators) based on the measured quantum states of corresponding qubits. For example, in response to a quantum state in measurement bitstring is measured as “0”, the eigenvalue of the corresponding Pauli operator is +1; and in response to a quantum state is measured as “1”,the eigenvalue of the corresponding Pauli operator is −1. In this case, the d × ^ arrayincludes multiple eigenvalue vectors, each of which includes eigenvalues of either +1 or −1. The number of rows is equal to the number of executions of the modified quantum logic circuit; and the number of columns is equal to the number of qubits where the modified quantum logic circuit is applied.
[0099] At 222, a subset of pairs of Pauli operators are determined by computing expectation values of the pairs of Pauli operators. In some implementations, pairs of quantum registers ^ and \ (without replacement) are determined. The expectation value of Pauli operators HJHYis calculated as the dot product of columns ^ and \, normalised by the number of rows. In response to the expectation value of Pauli operators HJHYof a pair of quantum registers ^ and \ is greater than a first threshold value e.g., ^, this pair of quantum registers ^ and \ can be used to encode “1”; and in response to the expectation value of Pauli operators HJHYof a pair of quantum registers ^ and \ is less than a second threshold value e.g., −^, this pair of quantum registers ^ and \ can be used to encode “0”. In some instances, the first and second threshold values are the algorithm’s parameters and can be pre-determined. In some instances, the first threshold value is greater than ef, e.g., ^ ≥ ef,Attorney Docket No.: RIGET-127WO1 where f is the estimated average standard deviation of expectation values; and the value of e can be selected from some general considerations.
[0100] At 224, K-bits of the bitstring are encoded using the subset of pairs of Paulioperators. In some instances, h < ^(^ − 1) / 2. In some instances, the expectation value ofPauli operators (without replacement) of a random pair of quantum registers can be calculated and compared to the first and second threshold values to determine whether the pair can be used to encode a bit in the bitstring. For example, in response to a first bit in the bitstring has a value of “1”, a pair of quantum registers with an expectation value of Paulioperators greater than the first threshold value (HJHY > ^) can be randomly selected forencoding the first bit in the bitstring; in response to a second bit in the bitstring has a value of “0”, a pair of quantum registers with an expectation value of Pauli operators less than thesecond threshold value (HJHY < −^) can be randomly selected for encoding the second bit inthe bitstring. If the expectation value of Pauli operators of a pair of quantum registers (^, \)greater than the second threshold value and less than the first threshold value (e.g., −^ ≤HJHY ≤ ^), the pair can be discarded or put on hold (for the next suitable bit in the bitstring).
[0101] In some instances, sub-operations 214, 216, 218, 220, 222, 224 can be repeated for the next h bits in the bitstring. For example, a new random vector of Pauli operators is generated; its associated time stamp can be obtained as an integer number in the format YYMMDDhhmmss; the quantum logic circuit can be modified based on the new random vector of Pauli operators; the modified quantum logic circuit can be executed multiple times; a new subset of pairs of Pauli operators are determined by computing expectation values of pairs of Pauli operators; and the second h bits are encoded using the new subset of pairs of Pauli operators. The sub-operations 214, 216, 218, 220, 222, 224 may be further repeated multiple times until the bitstring is completely encoded. For example, when the length of the bitstring is l, m vectors of Pauli operators, m time stamps, and m cycles of d-times of quantum logic circuit runs: (m − 1)h < l ≤ mh, can be used.
[0102] At 226, an array of pairs of qubit indices associated with the determined pairs of Pauli operators through the D-cycles of iterations of sub-operations 214, 216, 218, 220, 222, and 224.Attorney Docket No.: RIGET-127WO1
[0103] Referring back to the example described above, Alice may decide to send Bob an encrypted message including a letter “K” in binary format, e.g., a corresponding bitstring of the letter K may be [1001011] according to the mapping scheme 500 shown in FIG.5.
[0104] Alice starts with generating a random string of Pauli operators %, & and # having the same length as the width of the quantum logic circuit (^=5). For example, the random vector of Pauli operators may be expressed as [%, #, &, &, %], (10)where X is a Pauli X gate, Y is a Pauli Y gate, and Z is a Pauli Z gate, which are expressed in equation (9).
[0105] The randomly generated vector of Pauli operators can be configured to determine the bases in which respective qubits are measured. In this example, the first and fifth qubits are measured in the ^-basis; the second qubit is measured in the ^-basis; and the third and fourth qubits are measured in the ^-basis. The objective is to calculate the expectation values of Pauli operators on various quantum registers. The expectation valuesof a tensor product of two Pauli operators Hn and Ho on quantum registers p and q, Hn ⊗ Hoincludes %^ ⊗ #^, %^ ⊗ &^, %^ ⊗ &r, %^ ⊗ %s, #^ ⊗ &^,(11)#^ ⊗ &r, #^ ⊗ %s, &^ ⊗ &r, &^ ⊗ %s, &r ⊗ %s.
[0106] To measure these expectation values, Alice has to add “change of basis” gates (e.g., the quantum logic gates 424 to the example quantum logic circuit 400 to obtain a modified quantum logic circuit 420 and perform the measurement 426 (as shown in FIG. 4B). Specifically, nothing (or identity gate ') is added to the second quantum register 412-2 before the measurement as the computational basis is the ^-basis. ( gates are added to the first and fifth quantum registers 412-1, 412-5 before the measurement to transform the ^- basis into the ^-basis. ()*gates are added to the third and fourth quantum registers 412-3, 412-4 before the measurement to transform the ^-basis into the ^-basis (the )*gate should be applied first).Attorney Docket No.: RIGET-127WO1
[0107] Next, Alice executes the modified quantum logic circuit 100,000 times (e.g., 100,000 quantum logic circuit runs and d=100,000) and saves the measurement results ina 100,000 × 5 array. If “0” is measured, the eigenvalue of the corresponding Pauli operatoris +1. If “1” is measured, the eigenvalue of the corresponding Pauli operator is −1. Therefore, the array entries are either +1 or −1. The number of rows is equal to the number of the quantum logic circuit runs and the number of columns is equal to the number of quantum registers.
[0108] Then, Alice computes the expectation values for the pairs of Pauli operators(tensor products of two Pauli operators). The expectation value Hn ⊗ Ho ≡ HnHo is the dotproduct of columns p and q, normalised by the number of rows. Alice may get %^#^ = −0.76160%^&^ = 0.22724%^&r = −0.005740.13070#^&^ = 0.81316(12) #^&r = 0.02814#^%s = −0.09922&^&r = −0.01034&^%s = 0.12158&r%s = 0.00368.
[0109] If the expectation value HnHois larger than a chosen threshold value ^, the pair HnHocan be used to encode “1”. If expectation value HnHois smaller than −^, the pair HnHocan be used to encode “0”. The value of ^ depends on the circuit configuration and thenumber of runs. Alice sets it at ^ = 0.01. Therefore, Alice can use the following pairs ofPauli operators for encrypting her message: (13) %^#^ ⇒ 01Attorney Docket No.: RIGET-127WO1 #^&r ⇒ 100&^%s ⇒ 1&r%s ⇒ − (y^zy{^R^^|^}Rq~y^Rqq^^^^ℎ^^^ℎy[−^, ^]^^^y^}Rq)
[0110] In some implementations, two additional important elements of the security protocol provide additional protection. In particular, no Pauli pairs are repeated in each cycle; and only some of the possible Pauli pairs are used in each cycle. In some implementations, expectation values of second-order Pauli operators can be used to provide additional degrees of security. The proposed symmetric encryption algorithm relies on the fact that the knowledge of which Pauli operators have been measured reveals nothing about their expectation values unless the quantum state in which they have been measured is also known.
[0111] At 208, the encrypted message is communicated from Alice to Bob. The encrypted message may be sent from Alice to Bob over an unsecured (e.g., public) communication channel. For instance, the encrypted message may be shared with Bob over the Internet or via email, text message, etc.
[0112] In some instances, the encrypted message includes a first array. The first array may include an array of Pauli operators arranged in m rows and ^ columns. Each p-th rowis the vector of Pauli operators used to encrypt [(p − 1)h + 1, ph] section of the bitstring.The encrypted message may also include a second array that includes a vector of time stamps of m entries. Each entry in the vector of time stamps corresponds to a row of Pauli operators in the first array. The encrypted message may also include a third array that includes an array of pairs of qubit indices. The third array includes m rows and h columns.Each p-th row is the vector of quantum register index pairs used to encrypt [(p − 1)h +1, ph] section of the bitstring. In some instances, the arrays in the encrypted message maybe communicated from Alice to Bob separately. For example, the first and second arrays in the encrypted message can be communicated form Alice to Bob through a first unsecured communication channel (e.g., through a first email); and the third array in the encrypted message can be communicated from Alice to Bob through a second unsecuredAttorney Docket No.: RIGET-127WO1 communication channel (e.g., through a second separate email). In some instances, the arrays in the encrypted message may be communicated between Alice and Bob in another manner. Referring to the example above, Alice sends Bob a text message that reads: XZYYX. Then Alice sends Bob an email that reads: (1,3) (1,2) (2,5) (1,5) (3,4) (2,3) (2,4).
[0113] In some implementations, two unsecure channels (e.g., text and email) can be used to transmit the encrypted message during operation 208. Even if both channels are compromised it is impossible to decipher the encrypted message without knowledge of the quantum logic circuit that creates the quantum state in which the Pauli operators are measured. In other words, the quantum logic circuit plays the role of a symmetric key used to encrypt and decrypt messages between two trusted parties.
[0114] At 210, the encrypted message is decrypted. In the example shown in FIGS.2A- 2C, Bob generates the decrypted version of the message based on execution of the quantum logic circuit on a quantum computing system. One or more of the operations and sub- operations shown in FIG.2C may be used to generate the decrypted version of the message. In some cases, another process may be used to generate the decrypted version of the message based on execution of the quantum logic circuit on a quantum computing system.
[0115] As shown in FIG.2C, at 232, the values of the parameters of the single-qubit quantum logic gates in the first layer of the quantum logic circuit are determined. In some instances, elements of the second array in the encrypted message can be used to determine values of respective parameters of respective parametric quantum logic gates in the received quantum logic circuit. For example, when the first layer of the received quantum logic circuit includes parametric single-qubit rotation gates, each entry of the second array (e.g., the vector of time stamps) in the encrypted message received from Alice modulo 2Q can be used as a respective value to be assigned to the parameter ^ of a respective single- qubit rotation gate in the first layer of the received quantum logic circuit.
[0116] At 234, the received quantum logic circuit is modified. For example, the corresponding basis transformation gates are added to at the end of the quantum logic circuit, by Bob, prior to measurement operations based on the first row from the first array (e.g., the array of Pauli operators) in the encrypted message received from Alice.Attorney Docket No.: RIGET-127WO1
[0117] At 236, the modified quantum logic circuit is executed d times and themeasurement results (+1, −1) are stored in a first d × ^ array. After modifying thereceived quantum logic circuit with the basis transformation gates, the modified quantum logic circuit is executed, by Bob, 100,000 times (d=100,000) and quantum states aremeasured. The measurement results can be saved in the first d × ^ array.
[0118] At 238, the expectation values of Pauli operators of pairs of quantum registers inthe first d × ^ array are calculated based on the entries in the first row of the third array.For example, dot products of Pauli operators in columns ^ and \ of the first d × ^ array arecalculated based on corresponding entries in the first row of the third array (e.g., the array of pairs of qubit indices). For example, in response to the value of the dot product of Paulioperators in columns ^ and \ of the first d × ^ array is positive, the corresponding entry inthe third array is decrypted as “1”; and in response to the value of the dot product of Paulioperators in columns ^ and \ of the first d × ^ array is negative, the corresponding entry inthe third array is decrypted as “0”. After decrypting the entries in the first row of the third array, a first set of h bits are decrypted by Bob.
[0119] In some instances, the sub-operations 232, 234, 236 and 238 may be repeated. For example, the parameter values of the parametric single-qubit rotation gates are determined based on the second column of the second array; the second row of the first array is used to modify the measurement bases of the quantum logic circuit; the modified quantum logic circuit is executed d times and measurement results are stored in a secondd × ^ array; the expectation values of Pauli operators of pairs of quantum registers in thesecond d × ^ array are calculated based on the entries in the second row of the third array;and a second set of h bits are decrypted. The sub-operations 232, 234, 236 and 238 are further repeated until all the m sets of h bits in the third array are decrypted and thus the entire bitstring is obtained.
[0120] At 242, the decrypted bitstring is translated into plain texts using the mapping scheme.
[0121] Referring to the example above, after Bob receives the text message, Bob can determine the parameter values of the parametric single-qubit rotation gates in the firstAttorney Docket No.: RIGET-127WO1 layer of the received quantum logic circuit. As shown in the example quantum logic circuit 420 in FIG.4C, the single-qubit quantum logic gates in the first layer are parametric, e.g., rotation gates around the ^, ^ and ^ axes by angle IJ^, where ^ indicates the quantumregister number. Coefficients IJ ∈ [−1,1] are fixed. Parameter ^ may be a function of thetime stamp associated with the generation of the random vector of Pauli operators. For example, the time stamp may be expressed in the format: YYMMDDhhmmss. For example, 13:03:46 on 27 November 2023 would be represented by the following integer number: 231127130346. Then the value of parameter ^ is set equal to YYMMDDhhmmss modulo2Q. In our example it would be ^ = 1.32392129. The value of ^ is unique for each timestamp. At the same time the knowledge of ^ will be of no use unless the whole quantum logic circuit is known. It means that the time stamp can also be shared between the trusted parties using the unsecure channel – the same channel that is used for communicating the vector of Pauli operators.
[0122] Bob can then change the measurement bases on quantum registers 1, 3, 4 and 5 (add ( to the first and fifth quantum registers and add ()*to the third and fourth quantum registers). In some instances, the modified quantum logic circuit may be implemented as the example quantum logic circuit 420 shown in FIG.4B.
[0123] Bob knows what expectation values he needs to calculate and in what order. Bob runs the quantum logic circuit (the same as Alice’s) d times and obtains respective expectation values. The expectation values obtained by Bob may be different from the expectation values obtained by Alice which is caused by the finite number of quantum logic circuit runs, hardware noise or other effects. For example, the expectation values obtained by Bob are %^&^ = 0.22762 ⇒ 1%^#^ = −0.76166 ⇒ 0#^%s = −0.09430 ⇒ 0%^%s = 0.12724 ⇒ 1(14) &^&r = −0.00986 ⇒ 0#^&^ = 0.81240 ⇒ 1#^&r = 0.03230 ⇒ 1Attorney Docket No.: RIGET-127WO1
[0124] The pairs of indices are decrypted into a bitstring of [1001011] by Bob, and Bob can learn that Alice would like to get in touch with him.
[0125] In some instances, assuming ^ = 2,500, ^ = 100, d = 500,000, h = 1,000,000,^ = 0.01, e = 6, ^ = 6, the example process 200 shown in FIGS, 2A-2C may allowencryption of 26 full pages of dense normal text per single vector of Pauli operators (40 lines × 80 symbols per line × 12 bits per symbol). The 6-sigma threshold is equivalent to 1 typo per about 26,000 pages of dense normal text.
[0126] In some instances, the example process 200 may be a multiple key encryption protocol. For example, the quantum logic circuit may be split into two or more sections, e.g., a first section includes a first ^^layers of quantum logic gates and a second sectionincludes a second ^^ layers oflogic gates (^^ + ^^ = ^). The first section of thequantum logic circuit with the first ^^layers can be communicated from Alice to Bob; and the second section of the quantumcircuit with the second ^^layers can be communicated from Alice to Charlie. In this case, decryption can be performed if both Bob and Charlie combine their sections into a single quantum logic circuit.
[0127] In some implementations, the proposed symmetric encryption algorithm relies on the fact that the knowledge of which Pauli operators have been measured on the quantum computer reveals nothing about their expectation values unless the quantum state in which they have been measured is also known. The techniques and systems presented here are compatible with different types of quantum computing hardware (e.g., quantum computing hardware agnostic). In other words, the methods presented here can be coded to run on any type of hardware (e.g. superconducting, trapped ion, diamond vacancy, photonic, etc.)
[0128] In some instances, approximate state or quantum shadow techniques can be used to speed up and / or improve the quality of results obtained from the execution of the quantum logic circuit on the hybrid computing system In some instances, other techniques can be used to improve the quality of the results obtained from the execution of the quantum logic circuit on the hybrid computing system, for example, randomized readout techniques, twirling techniques, or other techniques.Attorney Docket No.: RIGET-127WO1
[0129] The example process 200 can be used to encrypt and decrypt a meaningful amount of plain text. A sample message taken from the short story by Edgar Allan Poe, The Gold-Bug, is used. For example, a sample message includes “A good glass in the bishop’s hostel in the devil’s seat. Forty-one degrees and thirteen minutes northeast and by north. Main branch seventh limb east side. Shoot from the left eye of the death’s-head. A bee line from the tree through the shot fifty feet out.”
[0130] In some implementations, encryption and decryption of this message using the example process 200 shown in FIGS.2A-2C can be performed by operation of a quantum simulator, a quantum processor unit (e.g., superconducting quantum processor unit or another type of quantum processor unit), or a combination of both. The message includes 258 characters (counting spaces) and can be translated a bitstring, e.g., a 3,096-bit bitstring using the mapping scheme 500 shown in FIG.5.
[0131] FIG.6 is a schematic diagram showing aspects of an example quantum processor unit graph 600 used in a quantum simulator for performing the example process 200 shown in FIGS.2A-2C. The example quantum processor unit graph 600 includes twenty qubit devices 602 configured in a square-grid lattice. Each qubit device 602 is connected to neighboring qubit devices through respective physical connections 604 (e.g., capacitively coupler devices, tunable coupler devices, etc.). In some instances, a two-qubit quantum logic gate can be applied directly to two qubit devices 602 that are physically connected by a physical connection 604.
[0132] FIG.7 is a schematic diagram showing aspects of an example quantum logic circuit 700 to be applied on the quantum processor unit graph 600 in FIG.6. The quantum logic circuit 700 includes multiple layers 702, 704 of quantum logic gates. In particular, the quantum logic circuit 700 includes three layers (e.g., 702-1, 702-2, 702-3) of parametric single-qubit quantum logic gates with adjustable parameters ( / 0, / >) and three layers (e.g., 704-1, 704-2, 704-3) of non-parametric two-qubit quantum logic gates (iSWAP gates). The quantum logic circuit 700 includes 100 configurable parameters for 100 parametric single- qubit quantum logic gates. The parameter (e.g., the rotation angle ^YJ ) of a single-qubit quantum logic gate in the example quantum logic circuit 700 is defined on the intervalAttorney Docket No.: RIGET-127WO1[−Q / 2, Q / 2], thus attempting to provide sufficiently uniform coverage of the qubit states onthe Bloch sphere. The two-qubit quantum logic gates are applied between qubits defined by qubit devices that have direct physical connections.
[0133] In some instances, a single cycle (single set of basis gates) of executions ofquantum logic circuit 700 can produce at most (20 ⋅ 19) / 2 = 190 unique pairs of Paulioperators. In some instances, not all pairs of Pauli operators may be eligible for encoding purposes due to the finite number of executions of the quantum logic circuit (e.g., quantum logic circuit runs) in a single cycle (e.g., the expectation values are between the two threshold values). Therefore, multiple cycles of executions of the quantum logic circuit 700 are needed to encode 3,096 bits.
[0134] As shown in FIG.7, with 10,000 quantum circuit runs in each cycle, the threshold value ^ can be set to 0.05 in order to ensure the 6 standard deviations confidence level. This can be a demanding requirement that may push the number of cycles up significantly unless the number of quantum logic circuit runs is increased to reduce the threshold value.
[0135] In some instances, the threshold value of ^ can be decreased without increasing the number of quantum logic circuit runs and without sacrificing the accuracy using an error detection and error correction technique suggested by the very nature of the proposed encryption protocol. For example, the encryption protocol may represent every plain text character as a bitstring with equal numbers of “0”s and “1”s. For example, six “0”s and six “1”s according to the mapping scheme 500 shown in FIG.5. If the decrypted bitstring has unequal number of “0”s and “1”s, the bitstring has been encrypted / decrypted incorrectly. As long as the error rate remains low, it is highly unlikely that two errors (two bit-flips) occur for the same bitstring and, therefore, all occurred errors can be detected. In some instances, an error correction technique can be applied. For example, if the decrypted bitstring has seven “0”s and five “1”s, each “0” can be flipped into “1” one by one and the obtained seven new bitstrings with equal number of “0”s and “1”s can be tested as to whether they encode a plain text character. In some instances, other error detection and correction techniques can be used.Attorney Docket No.: RIGET-127WO1
[0136] An error-free encryption and decryption can be achieved when the threshold value ^ is set to 0.035. When the threshold value is below 0.035, incorrect encryption and decryption can be observed. For example, a decrypted message may read: “A good glass in the bishop’s hostel in the devil’s seat. Forty-one degrees and thirteen minutes northeast and by north. Main branch sev$nth limb east side. Shoot from the left eye of the death’s- head. A bee line from the tree through the $hot fifty feet out.” In this example decrypted message, the symbol $ indicates detected incorrectly encrypted / decrypted character. In some instances, an application of an error correction mechanism can be used to restore the decrypted message to its original form: “A good glass in the bishop’s hostel in the devil’s seat. Forty-one degrees and thirteen minutes northeast and by north. Main branch seventh limb east side. Shoot from the left eye of the death’s-head. A bee line from the tree through the shot fifty feet out.”
[0137] In particular, the first incorrect bitstring has been error-corrected to the bitstring representing character “e” and the second incorrect bitstring has been error- corrected to the bitstring representing character “s”. In some cases, an error correction technique can suggest several valid substitutions. To ensure uniqueness, the mapping scheme between plain text characters and the corresponding bitstrings should beorganized in such a way that the Hamming distance between any two bitstrings is > 2. Thismay require longer bitstrings (e.g., 14-bit long or above) but would significantly increase the number of eligible pairs of Pauli operators – often by a substantial multiple for relatively small number of quantum logic circuit runs.
[0138] When the threshold value ^ is less than 0.03, more than one error per bitstring can be observed at 10,000 quantum logic circuit runs. In this case, it can be difficult to correct the errors using an error correction technique. In some instances, the number of quantum logic circuit runs can be increased to work with such threshold value.
[0139] In some instances, the quantum simulator is operated on a classical hardware. Increasing the number of qubits in a quantum processor unit graph from 20 to 30 can slightly more than double the number of eligible pairs of Pauli operators per cycle but can increase the number of probability amplitudes of the quantum state (and, therefore, theAttorney Docket No.: RIGET-127WO1 memory requirements) by three orders of magnitude. In some instances, the number of qubits can be further increased.
[0140] FIG.8 is a schematic diagram showing aspects of a quantum processor unit graph 800 of a quantum processor unit for performing the example process shown in FIGS. 2A-2C. The quantum logic circuit represented by the quantum processor unit graph 800 includes 84 qubit devices 802 configured in a square-grid lattice. Each qubit device 802 is connected to neighboring qubit devices through respective physical connections 804 (e.g., capacitively coupler devices, tunable coupler devices, etc.). In some instances, a two-qubit quantum logic gate can be applied directly to two qubit devices 802 that are physically connected by a physical connection 804. A quantum logic circuit that can be applied on the quantum processor unit represented by the quantum processor unit graph 800 may include multiple layers of quantum logic gates similar to the one shown in FIG.7 with a total number of configurable parameters of 420.
[0141] In some implementations, the critical threshold value for a given number of quantum logic circuit runs can be determined. For example, for any threshold value greater than the critical threshold value, more than one error per bitstring may not be observed in the decrypted message. In some instances, one or more bit-flip errors in any given bitstring can be detected and corrected using the error correction mechanism described above. In some instances, increasing number of bit-flip errors per bitstring may become difficult to detect and correct causing the encryption / decryption process to break down completely.
[0142] FIG.9A is a plot 900 showing the critical threshold value ^∗as a function of numbers of quantum logic circuit runs. Three separate experiments 902, 904, 906 are performed for each number of quantum logic circuit runs. Thirteen threshold values ^∗can be obtained from each experiment (one for each cycle) plotted at each of the number of quantum logic circuit runs. The lines 912, 914, 916 corresponding to the three experiments are a visual aid connecting the average of the thirteen critical threshold values from each experiment for each of the four numbers of quantum logic circuit runs (e.g., 100,000, 200,000, 300,000, and 400,000). FIG.9B is a plot 920 showing the share of ineligible pairs of Pauli operators as a function of the number of quantum logic circuit runs, corresponding to the experiments in FIG.9A. In some instances, noise of the quantum computing systemAttorney Docket No.: RIGET-127WO1 may contribute significantly to the attenuation of the magnitude of the expectation values and, therefore, to the percentage of ineligible pairs of Pauli operators.
[0143] In some instances, to reduce the impact of calibration drift with time on the quantum computing system, an additional error mitigation technique can be used. Each expectation value can be calculated four times, each using 100,000 quantum logic circuit runs. Averaging one, two, three or four of these values generated estimates of the expectations using 100K, 200K, 300K and 400K shots respectively. The standard deviations can be calculated. In some instances, expectation values with large standard deviations (e.g., greater than a predetermined threshold value) can be discarded as these had a higher likelihood of being inaccurate, potentially changing sign and thereby leading to errors. In some instances, this error mitigation technique may be applied when encrypting data bits. However, it may not be used to exclude expectation values when decrypting as the decryption algorithm uses the expectations specified by the encryption process (e.g., the example process 208 shown in FIG.2B), for example, via the array that includes pairs of qubit indices. The decryption algorithm (e.g., the example process 210 shown in FIG.2C) can use the standard deviation information in situations where an error occurs and results in more than one potential decoded character. In some instances, a character resulting from flipping the bit which has the largest standard deviation may be the error that occurred.
[0144] In some instances, sampling without replacement may be used. As long as there are at least 12 unique pairs of quantum registers then these could be used to encode a character (needing 12 bits) and accurately decode it even in the presence of a single expectation value error.
[0145] Note that since the expectation values of Pauli operators on separate qubits commute, for unique Pauli operators Hnand Hoon qubits p and q, the second-order Paulioperator Hn ⊗ Ho is equal to Ho ⊗ Hn. Therefore, the pair (p, q) where p < q can be definedto represent the expectation value ^ of Hn ⊗ Ho = Ho ⊗ Hn and the pair (q, p) where p < qcan be defined to represent the negated expectation value −^. This means that each expectation value measured can be used to represent either a "0" or a "1". This removes any issues related to unequal numbers of positive and negative Pauli expectations.Attorney Docket No.: RIGET-127WO1
[0146] FIG.10A includes plots 1000, 1010 showing a cumulative distribution functionfor expectation values of second-order Pauli operators ^(%) = H^|SRS^q^^^(|HnHo| ≤ %)across 5,000 randomly generated configurations during 100,000 quantum logic circuit runson a noise-free quantum simulator. The 6-sigma threshold is ^ = 0.0058. The quantumcircuit structure used to build the CDF corresponds to the one given by FIG.4B with random rotation angles and random choices of measurement bases. In total, 5,000 random configurations (rotation angles and Pauli pairs) are used to build the CDF. Each expectation value was calculated with 1,000,000 quantum logic circuit runs, that is bitstring samples. The unique configurations were created by five different allocations of ( and ()*gates in the final layer of the quantum circuit and 100 randomly generated configurations of rotation angles for each allocation of ( and ()*gates. Considering that the 5-qubit quantum circuit can support the calculation of expectation values for 10 unique Pauli pairs,the total number of calculated second-order Pauli expectation values is 5 × 10 × 100 =5,000.
[0147] The standard deviations of expectation values for 50 random Pauli pairs and circuit configurations can be also calculated. The average standard deviation has been estimated to be 0.00096 for 1,000,000 quantum logic circuit runs. Applying the 6-sigma rule (standard confidence bands widely used in experimental disciplines to claim a scientific discovery) an estimate for the value of ^: 0.0058 can be obtained.
[0148] As shown in the plot 1010 of FIG.10A, 12.1% of second-order Pauli expectationvalues can be found in the interval [−0.0058, 0.0058]. This is the proportion of Pauli pairsthat can be discarded: if the expectation value of a second-order Pauli operator is close to zero, its sign may change and may become uncertain. The threshold value ^ is configured to provide conservative confidence bands.
[0149] In some instances, a safety margin can be added to account for the “model risk”and set the critical threshold value ^ = 0.01. In this case, the proportion of Pauli pairs thatmay be discarded as ineligible for encoding increases to 16.5% or, roughly, one in six.
[0150] FIG.10B is a histogram 1020 of the noise component in the estimation of second-order Pauli expectation values. Vertical dashed red lines indicate 1 standardAttorney Docket No.: RIGET-127WO1 deviation bands. The histogram 1020 shows the distribution of ^ as a function of the deviation from the sample mean. The distribution is bell-shaped without heavy tails. The vertical dashed lines 1022 indicate a one-standard deviation band that contain approximately 2 / 3 of the dataset population. This suggests that the application of the 6- sigma rule is a reasonable and workable approach.
[0151] In some instances, the 6-sigma rule is used if the noise in the estimation of second-order Pauli expectation values is normally distributed, e.g., there are no heavy tails. Let % be the true expectation value of a Pauli pair and % be the estimate of the expectation value of the same Pauli pair obtained with d quantum logic circuit runs. Then the noise, ^, can be quantified as the deviation from the true value: ^= % − %. (15)
[0152] If the calculation of % is repeated many times, the sample mean %^can be used as an approximation of the true expectation value %: ^= % − %^. (16)
[0153] Measurement noise depends on the number of quantum logic circuit runs performed on the quantum computing system and this noise can be measured and quantified. To obtain good results, noise due to gate errors should be less than the measurement noise.
[0154] In some instances, a large number of quantum logic circuit runs (e.g., 1,000,000 quantum logic circuit runs) can be used, for example, when a large dataset is to be encrypted / decrypted. In certain examples, other numbers of quantum logic circuit runs can be used, e.g., a smaller number of quantum logic circuit runs can be used to increase the speed which may result in a smaller number of eligible Pauli pairs, for example, due to an increase in the noise, when a small dataset is to be encrypted / decrypted.
[0155] FIG.11 includes a plot 1100 showing the threshold value ^ (6 standard deviations) and a plot 1110 showing the share of ineligible pairs of Pauli operators as functions of the number of quantum logic circuit runs. A short message can be encrypted in milliseconds at the price of throwing out 2 / 3 of possible Pauli pairs, which should not be aAttorney Docket No.: RIGET-127WO1 problem for a short message and sufficiently wide quantum logic circuit applied on a sufficient number of qubits.
[0156] For example, a superconducting quantum processor unit with 5 qubits is used to execute the quantum logic circuit 420 shown in FIG.4B. By changing the allocation of ( and ()*gates in the final layer, the measurement bases and calculated expectation values forall possible second-order Paulis can be changed. With ^ = 5 the number of all possiblePauli pairs is 9 × ^(^ − 1) / 2 = 90. The number of possible random configurations ofrotation angles is set at 56. This can result in 90 × 56 = 5,040 expectation values ofsecond-order Paulis, all calculated with 100,000 quantum logic circuit runs.
[0157] FIGS.12A-12B includes plots showing the corresponding Cumulative Distribution Function (CDF) for second-order Pauli expectation magnitudes of the absolute values of second-order Pauli expectation values obtained by operation of a 5-qubit superconducting quantum processor unit (plots 1200, 1210) across 5,040 randomly generated configurations; and by operation of a quantum simulator performed on a classical processor unit (plots 1220, 1230) across 5,000 randomly generated configurations. The vertical dashed lines 1212, 1232 in the plots 1210, 1230 cross the %axis at % = ^, where ^ is 6 standard deviations of the second-order Pauli expectation valuesfrom the corresponding mean values. The 6-sigma threshold value ^ in the situation wherethe superconducting quantum processor unit is used is 0.057, e.g., ^ = 0.057. The 6-sigmathreshold value ^ in the situation when the quantum simulator is used is 0.018, e.g., ^ =0.018. The horizontal dashed lines 1214, 1234 in the plots 1210, 1230 indicate the probability that the second-order Pauli expectation value would be smaller than ^, and thus, it cannot be used for encoding purposes. As shown in FIGS.12A-12B, when 100,000 quantum logic circuit runs are performed, the share of ineligible pairs of Pauli operators is about 57% in the situation when the superconducting quantum processor unit is used (the plot 1210) and about 20% for the noise-free quantum simulator.
[0158] In some instances, the quantities of positive and negative second-order Pauli expectation values are balanced. For example, in the situation when the superconducting quantum processor unit is used, the share of positive expectation values is 49.7% and the share of negative expectation values is 50.3%; and the share of positive expectation valuesAttorney Docket No.: RIGET-127WO1 greater than the 6-sigma threshold value ^ is 21.6% and the share of negative expectation values less than −^ is 21.9%.
[0159] FIG.12C includes a plot 1240 showing the CDF for the magnitude of all second- order Pauli expectation values (curve 1242), of only the positive second-order Pauli expectation values (curve 1244), and of only the negative second-order Pauli expectation values (curve 1246), obtained by operation of a 5-qubit superconducting quantum processor unit across 5,040 randomly generated configurations and 100,000 quantum logic circuit runs. As shown in FIG.12C, the three curves 1242, 1244, 1246 overlap with one another.
[0160] In some instances, the same quantum logic circuit can be used to encrypt more bits using the expectation values of higher-order Pauli operators (third-order or above), e.g., HJHYHn, HJHYHnHo, …. In some instances, the expectation values of higher-order Pauli operators may be smaller in magnitude and the measurement noise can be larger. In some examples, a small fraction of the higher-order Pauli expectation values can be used for encryption if the number of quantum logic circuit runs is kept within a reasonable limit.
[0161] Some of the subject matter and operations described in this specification can be implemented in digital electronic circuitry, or in computer software, firmware, or hardware, including the structures disclosed in this specification and their structural equivalents, or in combinations of one or more of them. Some of the subject matter described in this specification can be implemented as one or more computer programs, i.e., one or more modules of computer program instructions, encoded on a computer storage medium for execution by, or to control the operation of, data-processing apparatus. A computer storage medium can be, or can be included in, a computer-readable storage device, a computer-readable storage substrate, a random or serial access memory array or device, or a combination of one or more of them. Moreover, while a computer storage medium is not a propagated signal, a computer storage medium can be a source or destination of computer program instructions encoded in an artificially generated propagated signal. The computer storage medium can also be, or be included in, one or more separate physical components or media.Attorney Docket No.: RIGET-127WO1
[0162] Some of the operations described in this specification can be implemented as operations performed by a data processing apparatus on data stored on one or more computer-readable storage devices or received from other sources.
[0163] In a general aspect, hybrid classical-quantum cryptographic systems are presented.
[0164] In a first example, an encryption method includes obtaining a message to send to a recipient; obtaining a shared secret that includes a quantum logic circuit and is known by the recipient; generating an encrypted version of the message based on the quantum logic circuit; and sending the encrypted version of the message to the recipient.
[0165] Implementations of the first example may include one or more of the following features. Generating the encrypted version of the message includes generating a random list of measurement bases; generating a modified quantum logic circuit based on the random list of measurement bases; obtaining a plurality of measurement bitstrings based on a quantum computing resource executing multiple iterations of the modified quantum logic circuit; converting the plurality of measurement bitstrings to a plurality of eigenvalue vectors; identifying a plurality of operators based on the random list of measurement bases; calculating expectation values for each of the plurality of operators based on the plurality of eigenvalue vectors; generating a list of operators selected from the plurality of operators. The list of operators represents a mapping between a subset of the expectation values and the message; and the encrypted version of the message includes the random list of measurement bases and the list of operators.
[0166] Implementations of the first example may include one or more of the following features. The method further includes generating a time stamp associated with the random list of measurement bases. The modified quantum logic circuit is generated based on the random list of measurement bases and the time stamp; and the encrypted version of the message includes the time stamp. The random list of measurement bases includes a measurement basis for each qubit in the quantum logic circuit. The random list of measurement bases includes a random list of Pauli operators, the random list of Pauli operators includes a Pauli operator for each respective qubit in the quantum logic circuit,Attorney Docket No.: RIGET-127WO1 and each operator in the list of operators includes a pair of Pauli operators from the random list of Pauli operators. The message includes a binary message, and the method includes generating the binary message based on a plaintext massage according to a mapping scheme that is known by the recipient.
[0167] In a second example, a decryption method includes receiving an encrypted version of a message from a sender; obtaining a shared secret that is known by the sender, the shared secret including a quantum logic circuit; and generating an unencrypted version of the message based on the quantum logic circuit.
[0168] Implementations of the second example may include one or more of the following features. The encrypted version of the message includes a random list of measurement bases and a list of operators, and generating the unencrypted version of the message includes generating a modified quantum logic circuit based on the random list of measurement bases; obtaining a plurality of measurement bitstrings based on a quantum computing resource executing multiple iterations of the modified quantum logic circuit; converting the plurality of measurement bitstrings to a plurality of eigenvalue vectors; and calculating expectation values for the list of operators based on the plurality of eigenvalue vectors.
[0169] In a third example, a hybrid computer system configured to perform an encryption process, includes a quantum computing system; and a classical computing system configured to obtain a message to send to a recipient; obtain a shared secret that is known by the recipient, the shared secret including a quantum logic circuit; generate an encrypted version of the message based on an execution of the quantum logic circuit on the quantum computing system; and send the encrypted version of the message to the recipient.
[0170] Implementations of the third example may include one or more of the following features. Generating the encrypted version of the message includes generating a random list of measurement bases; generating a modified quantum logic circuit based on the random list of measurement bases; obtaining a plurality of measurement bitstrings based on the quantum computing system executing multiple iterations of the modified quantumAttorney Docket No.: RIGET-127WO1 logic circuit; converting the plurality of measurement bitstrings to a plurality of eigenvalue vectors; identifying a plurality of operators based on the random list of measurement bases; calculating expectation values for each of the plurality of operators based on the plurality of eigenvalue vectors; and generating a list of pairs of qubit indices associated with a subset of operators selected from the plurality of operators. The subset of operators represents a mapping between a subset of the expectation values and the message. The encrypted version of the message includes the random list of measurement bases and the list of pairs of qubit indices.
[0171] Implementations of the third example may include one or more of the following features. Generating the encrypted version of the message includes generating a time stamp associated with the random list of measurement bases. The modified quantum logic circuit is generated based on the random list of measurement bases and the time stamp, and the encrypted version of the message includes the time stamp. The random list of measurement bases includes a measurement basis for each qubit in the quantum logic circuit. The random list of measurement bases corresponds to a random list of Pauli operators. The random list of Pauli operators includes a Pauli operator for each respective qubit in the quantum logic circuit, and each operator in the subset of operators includes a pair of Pauli operators from the random list of Pauli operators.
[0172] Implementations of the third example may include one or more of the following features. The message includes a binary message, and the classical computing system is configured to generate the binary message based on a plaintext massage according to a mapping scheme. The classical computer system is configured to generate the mapping scheme; and send the mapping scheme to the recipient. The classical computing system is configured to, after obtaining the shared secret, encode the quantum logic circuit using a predetermined encoding scheme.
[0173] In a fourth example, a hybrid computer system configured to perform an decryption process include a quantum computing system; and a classical computing system configured to receive an encrypted version of a message from a sender; obtain a shared secret that is known by the sender, the shared secret including a quantum logic circuit;Attorney Docket No.: RIGET-127WO1 generate an unencrypted version of the message based an execution of the quantum logic circuit on the quantum computing system.
[0174] Implementations of the fourth example may include one or more of the following features. The encrypted version of the message includes a random list of measurement bases and a list of qubit pairs, and generating the unencrypted version of the message includes generating a modified quantum logic circuit based on the random list of measurement bases; obtaining a plurality of measurement bitstrings based on the quantum computing system executing multiple iterations of the modified quantum logic circuit; converting the plurality of measurement bitstrings to a plurality of eigenvalue vectors; and calculating expectation values based on the plurality of eigenvalue vectors and the list of qubit pairs.
[0175] Implementations of the fourth example may include one or more of the following features. The encrypted version of the message includes a time stamp associated with the random list of measurement bases, and the classical computing system is configured to generate the modified quantum logic circuit based on the time stamp. The random list of measurement bases includes a measurement basis for each qubit in the quantum logic circuit. The random list of measurement bases corresponds to a random list of Pauli operators, the random list of Pauli operators includes a Pauli operator for each respective qubit in the quantum logic circuit, and each of the expectation values corresponds to a pair of Pauli operators from the random list of Pauli operators.
[0176] Implementations of the fourth example may include one or more of the following features. The unencrypted version of the message includes a binary message, and the classical computing system is configured to convert the binary message to a plaintext massage according to a mapping scheme. The classical computer system is configured to receive the mapping scheme from the sender. The classical computing system is configured to, after obtaining the shared secret, decode the quantum logic circuit using a predetermined decoding scheme.
[0177] While this specification contains many details, these should not be understood as limitations on the scope of what may be claimed, but rather as descriptions of featuresAttorney Docket No.: RIGET-127WO1 specific to particular examples. Certain features that are described in this specification or shown in the drawings in the context of separate implementations can also be combined. Conversely, various features that are described or shown in the context of a single implementation can also be implemented in multiple implementations separately or in any suitable sub-combination.
[0178] Similarly, while operations are depicted in the drawings in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Moreover, the separation of various system components in the implementations described above should not be understood as requiring such separation in all implementations, and it should be understood that the described program components and systems can generally be integrated together in a single product or packaged into multiple products.
[0179] A number of embodiments have been described. Nevertheless, it will be understood that various modifications can be made. Accordingly, other embodiments are within the scope of the following claims.
Claims
Attorney Docket No.: RIGET-127WO1 CLAIMS What is claimed is:
1. A hybrid computer system configured to perform an encryption process, the system comprising: a quantum computing system; and a classical computing system configured to: obtain a message to send to a recipient; obtain a shared secret that is known by the recipient, the shared secret comprising a quantum logic circuit; generate an encrypted version of the message based on an execution of the quantum logic circuit on the quantum computing system; and send the encrypted version of the message to the recipient.
2. The hybrid computer system of claim 1, wherein generating the encrypted version of the message comprises: generating a random list of measurement bases; generating a modified quantum logic circuit based on the random list of measurement bases; obtaining a plurality of measurement bitstrings based on the quantum computing system executing multiple iterations of the modified quantum logic circuit; converting the plurality of measurement bitstrings to a plurality of eigenvalue vectors; identifying a plurality of operators based on the random list of measurement bases; calculating expectation values for each of the plurality of operators based on the plurality of eigenvalue vectors; and generating a list of pairs of qubit indices associated with a subset of operators selected from the plurality of operators, wherein the subset of operators represents a mapping between a subset of the expectation values and the message, wherein the encrypted version of the message comprises the random list of measurement bases and the list of pairs of qubit indices.Attorney Docket No.: RIGET-127WO1 3. The hybrid computer system of claim 2, comprising generating a time stamp associated with the random list of measurement bases, wherein the modified quantum logic circuit is generated based on the random list of measurement bases and the time stamp, and the encrypted version of the message comprises the time stamp.
4. The hybrid computer system of claim 2, wherein the random list of measurement bases comprises a measurement basis for each qubit in the quantum logic circuit.
5. The hybrid computer system of claim 4, wherein the random list of measurement bases corresponds to a random list of Pauli operators, the random list of Pauli operators comprises a Pauli operator for each respective qubit in the quantum logic circuit, and each operator in the subset of operators comprises a pair of Pauli operators from the random list of Pauli operators.
6. The hybrid computer system of claim 1, wherein the message comprises a binary message, and the classical computing system is configured to: generate the binary message based on a plaintext massage according to a mapping scheme.
7. The hybrid computer system of claim 6, wherein the classical computer system is configured to: generate the mapping scheme; and send the mapping scheme to the recipient.
8. The hybrid computer system of any one of claims 1 through 7, wherein the classical computing system is configured to: after obtaining the shared secret, encode the quantum logic circuit using a predetermined encoding scheme.
9. A hybrid computer system configured to perform an decryption process, the system comprising: a quantum computing system; and a classical computing system configured to: receive an encrypted version of a message from a sender; obtain a shared secret that is known by the sender, the shared secretAttorney Docket No.: RIGET-127WO1 comprising a quantum logic circuit; generate an unencrypted version of the message based an execution of the quantum logic circuit on the quantum computing system.
10. The hybrid computer system of claim 9, wherein the encrypted version of the message comprises a random list of measurement bases and a list of qubit pairs, and generating the unencrypted version of the message comprises: generating a modified quantum logic circuit based on the random list of measurement bases; obtaining a plurality of measurement bitstrings based on the quantum computing system executing multiple iterations of the modified quantum logic circuit; converting the plurality of measurement bitstrings to a plurality of eigenvalue vectors; and calculating expectation values based on the plurality of eigenvalue vectors and the list of qubit pairs.
11. The hybrid computer system of claim 10, wherein the encrypted version of the message comprises a time stamp associated with the random list of measurement bases, and the classical computing system is configured to generate the modified quantum logic circuit based on the time stamp.
12. The hybrid computer system of claim 10, wherein the random list of measurement bases comprises a measurement basis for each qubit in the quantum logic circuit.
13. The hybrid computer system of claim 12, wherein the random list of measurement bases corresponds to a random list of Pauli operators, the random list of Pauli operators comprises a Pauli operator for each respective qubit in the quantum logic circuit, and each of the expectation values corresponds to a pair of Pauli operators from the random list of Pauli operators.
14. The hybrid computer system of claim 9, wherein the unencrypted version of the message comprises a binary message, and the classical computing system is configured to: convert the binary message to a plaintext massage according to a mapping scheme.Attorney Docket No.: RIGET-127WO1 15. The hybrid computer system of claim 14, wherein the classical computer system is configured to: receive the mapping scheme from the sender.
16. The hybrid computer system of any one of claims 9 through 15, wherein the classical computing system is configured to: after obtaining the shared secret, decode the quantum logic circuit using a predetermined decoding scheme.