A quantum homomorphic encryption method based on a non-Clifford gate circuit of quantum one-time pad
By using controlled-V gates and Toffoli gates for key generation and encryption operations in quantum homomorphic encryption, combined with auxiliary qubits and evaluation keys, the homomorphic evaluation complexity of non-Clifford gates is reduced, enabling faster and more secure quantum computing services.
Patent Information
- Application Number
- CN202310678171.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-08
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2043-06-08
AI Technical Summary
In existing quantum homomorphic encryption methods based on quantum one-time pad, the homomorphic evaluation of non-Clifford gates is highly complex, which affects the computational efficiency and security of quantum circuits.
A quantum homomorphic encryption method based on non-Clifford gates is adopted, using controlled-V gates and Toffoli gates as key generation and encryption operations, combined with auxiliary qubits and part of the evaluation key. The server performs quantum gate operations and sends the results to the client for decryption.
It reduces the number of quantum gates in quantum circuits, lowers the complexity of homomorphic evaluation, and provides faster and more secure quantum computing services.
Smart Images

Figure CN116545610B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of quantum computing and quantum cryptography, and in particular to a quantum homomorphic encryption method based on quantum one-time pad non-Clifford gate circuits. Background Technology
[0002] With the rapid development of practical quantum computers, an increasing number of customers are eager to have quantum computing services provided by companies that offer quantum computing to help them complete quantum calculations. These companies' quantum computing cloud servers satisfy people's curiosity about quantum computing and their daily needs. As the demand for servers increases and awareness of personal privacy protection grows, customers hope to complete quantum calculations in a manner where "personal data is sent to the server in encrypted form for computation, and then the user decrypts the server's output to obtain the computation result." This is precisely the research goal of quantum homomorphic encryption.
[0003] In quantum homomorphic encryption based on quantum one-time pad, the client encrypts the plaintext using a combination of X and Z gates from the Pauli operator to obtain the ciphertext. The server executing the evaluation algorithm on the ciphertext can provide arbitrary quantum computing services to the client because the circuit it executes can be composed of single-qubit gates (T gates) from the Clifford set gates {H, S, controlled-X} and non-Clifford set gates. The two-qubit controlled-X gate in the Clifford set gates can be denoted as the CX gate. On one hand, when the server executes quantum gates from the Clifford set gates on the ciphertext, it does not introduce gate errors, simplifying the evaluation process. On the other hand, when the server executes T gates on the ciphertext, it may introduce an S gate error. To eliminate this gate error, the client needs to provide auxiliary qubits and a portion of the evaluation key to the server, and the server also needs to send the measured results back to the client, making the evaluation process complex. Furthermore, the quantum circuits for universal quantum computing composed of the set gates {H, S, CX, T} require the server to execute a large number of quantum gates, which also increases the complexity of the evaluation process.
[0004] The set of gates constituting universal quantum computing must contain at least one non-Clifford gate. Currently, among non-Clifford gates, the homomorphic evaluation of T-gates has been the most studied, while the homomorphic evaluation of other quantum gates has been rarely investigated. If the quantum circuits constituting universal quantum computing include T-gates, this undoubtedly affects the homomorphic evaluation complexity of some quantum circuits.
[0005] In view of this, the present invention is hereby proposed. Summary of the Invention
[0006] The purpose of this invention is to provide a quantum homomorphic encryption method based on quantum one-time pad non-Clifford gate circuits, which can reduce the number of quantum gates in quantum circuits with the same computational function, reduce the complexity of the quantum circuit in the evaluation process, and provide customers with faster secure quantum computing services.
[0007] The objective of this invention is achieved through the following technical solution:
[0008] A quantum homomorphic encryption method based on quantum one-time pad non-Clifford gate circuits includes:
[0009] Key generation section: The client randomly generates an encryption key, an initial decryption key, and an evaluation key by combining the specified non-Clifford gates; the specified non-Clifford gates include: two-qubit gate controlled-V gate and three-qubit gate Tooffoli gate;
[0010] Encryption section: The client performs an encryption operation on the corresponding plaintext quantum state according to the encryption key, and sends the resulting ciphertext quantum state, a portion of the evaluation key, and auxiliary qubits to the server;
[0011] Evaluation section: Based on the non-Clifford gate, a portion of the evaluation key, and auxiliary qubits specified by the client, the server executes the corresponding homomorphic evaluation route of the ciphertext quantum state, and sends the output of the homomorphic evaluation route and the measurement results to the client;
[0012] Decryption section: The client updates the initial decryption key based on the encryption key, evaluation key, and measurement results, and performs a decryption operation on the output results to obtain the correct quantum computing results.
[0013] As can be seen from the technical solution provided by the present invention, quantum homomorphic encryption offers secure and convenient delegated computing services to clients with limited computing power. This is because the server performing quantum computing cannot obtain the plaintext information from the client's ciphertext, and the client can quickly obtain the computation result through a simple decryption operation. The present invention constructs quantum circuits with complex computational functions using controlled-V gates (CV gates, two-qubit gates) and Tooffoli gates (three-qubit gates) in the non-Clifford set. Compared with quantum circuits with the same computational function constructed from T gates, the present invention not only reduces the number of quantum gates in the quantum circuit but also reduces the complexity of homomorphic evaluation, providing clients with faster and more secure quantum computing services. Attached Figure Description
[0014] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0015] Figure 1 A flowchart of a quantum homomorphic encryption method based on a quantum one-time pad non-Clifford gate circuit provided for an embodiment of the present invention;
[0016] Figure 2 The output results provided for the embodiments of the present invention are as follows A schematic diagram of a quantum circuit for teleportation through a gate;
[0017] Figure 3 The output result provided for the embodiments of the present invention is CX. 1,2 A schematic diagram of a quantum circuit for teleportation through a gate;
[0018] Figure 4 A schematic diagram of the homomorphic evaluation quantum circuit of a two-qubit gate (CV gate) provided for an embodiment of the present invention;
[0019] Figure 5 The present invention provides a homomorphic evaluation quantum circuit for a three-qubit gate (Toffoli gate) in an embodiment of the invention. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the protection scope of the present invention.
[0021] First, the following explanations are provided for the terms that may be used in this article:
[0022] The terms “including,” “comprising,” “containing,” “having,” or other similar semantic descriptions should be interpreted as non-exclusive inclusion. For example, “including a technical feature element (such as raw material, component, ingredient, carrier, dosage form, material, size, part, component, mechanism, device, step, process, method, reaction conditions, processing conditions, parameter, algorithm, signal, data, product or article of manufacture, etc.)” should be interpreted as including not only the expressly listed technical feature element, but also other technical feature elements that are not expressly listed and are well-known in the art.
[0023] The following provides a detailed description of a quantum homomorphic encryption method based on a quantum one-time pad non-Clifford gate circuit, as provided by this invention. Contents not described in detail in the embodiments of this invention are prior art known to those skilled in the art. Where specific conditions are not specified in the embodiments of this invention, they should be performed according to conventional conditions in the art or conditions recommended by the manufacturer.
[0024] like Figure 1 The diagram shows a flowchart of a quantum homomorphic encryption method based on a quantum one-time pad non-Clifford gate circuit, provided by an embodiment of the present invention. The method mainly includes the following steps:
[0025] Step 1, Key Generation: The client randomly generates an encryption key, an initial decryption key, and an evaluation key by combining the specified non-Clifford gate.
[0026] In this embodiment of the invention, the specified non-Clifford gates mainly include: two-qubit gates (controlled-V gates) and three-qubit gates (Toffoli gates). The two-qubit gate, controlled-V gate, is denoted as the CV gate (controlled V gate), where V = X. 1 / 2 .
[0027] In this embodiment of the invention, when the specified non-Clifford gate is a two-qubit CV gate, the client randomly generates an encryption key Key.Enc = (a,b,c,d), an initial decryption key Key.Dec = (a′,b′,c′,d′), and an evaluation key Key.Eval = {g,h,s,t,x,z}; where a,b,c,d,a′,b′,c′,d′,g,h,s,t,x,z are the components in the corresponding keys, satisfying... The initial decryption key is initialized using the encryption key, i.e., a′=a, b′=b, c′=c, d′=d.
[0028] In this embodiment of the invention, when the specified non-Clifford gate is a three-qubit Tooffoli gate, the client randomly generates an encryption key Key.Enc = (a,b,c,d,e,f), an initial decryption key Key.Dec = (a′,b′,c′,d′,e′,f′), and an evaluation key Key.Eval = {g,h,p,x,y,z}, where a,b,c,d,e,f,a′,b′,c′,d′,e′,f′,g,h,p,x,y,z are components in the corresponding key, satisfying... Similarly, the initial decryption key here is initialized using the encryption key, meaning that the length and components of the initial decryption key are the same as those of the encryption key.
[0029] Step 2, Encryption: The client performs an encryption operation on the corresponding plaintext quantum state according to the encryption key, and sends the resulting ciphertext quantum state, a part of the evaluation key, and auxiliary qubits to the server.
[0030] In this embodiment of the invention, when the specified non-Clifford gate is a two-qubit CV gate, the corresponding plaintext quantum state is a two-qubit state, denoted as |Φ> 12 The client determines the combination of X and Z gates in quantum mechanics based on the encryption key Key.Enc=(a,b,c,d), for the two qubits |Φ> 12 Encryption is performed to obtain the ciphertext quantum state. in, Let X1 denote the tensor product, and X1 denote the pair of two qubits |Φ> 12 The first qubit is subjected to an X-gate operation, and X2 represents the operation on the two qubits |Φ> 12 The second qubit undergoes an X-gate operation, Z1 denotes the operation on the two qubits |Φ> 12 Perform a Z-gate operation on the first qubit, where Z2 represents the operation on the two qubits |Φ> 12 The second qubit undergoes a Z-gate operation. The above encryption process can be represented as:
[0031] Those skilled in the art will understand that in quantum mechanics, the X gate is called the NOT gate and the Z gate is called the phase flip gate.
[0032] In this embodiment of the invention, since the component a (or b, c, d) in the encryption key takes the value of 0 or 1, when a = 0, X 0 =I, where I represents the unit gate, i.e. X1 (or X2) and X have the same meaning, both representing NOT gates. The subscripts 1 and 2 are used to distinguish whether the operation object is the first qubit or the second qubit. Similarly, the operation of Z gates also uses 1 and 2 to distinguish the operation object.
[0033] More specifically, in the embodiments of the present invention, the superscript represents the component of various keys or the XOR calculation result of the components of various keys, and its value (0 or 1) determines the specific operation content of the corresponding gate. For example, when the superscript is 0, it means to perform a unit gate operation, and when the superscript is 1, it means to perform a corresponding gate operation; the subscript value (value 1 or 2, or value 3 mentioned later) determines the quantum bit of the specific operation.
[0034] In this embodiment of the invention, when the specified non-Clifford gate is a three-qubit Tooffoli gate, the corresponding plaintext quantum state is a three-qubit state, denoted as |Δ> 123The client determines the combination of X and Z gates in quantum mechanics based on the encryption key Key.Enc=(a,b,c,d,e,f), for three qubits |Δ> 123 Encryption is performed to obtain the ciphertext quantum state. in, Let X1 represent the tensor product, and X1 represent the product of three qubits |Δ> 123 The first qubit is subjected to an X-gate operation, and X2 represents the operation on the three qubits |Δ> 123 The second qubit undergoes an X-gate operation, where X3 represents the operation on the two qubits |Δ> 123 Perform an X-gate operation on the third qubit, Z1 denotes the operation on the three qubits |Δ> 123 The first qubit is subjected to a Z-gate operation, Z2 represents the operation on the three qubits |Δ> 123 The second qubit undergoes a Z-gate operation, Z3 representing the operation on the three qubits |Δ> 123 The third qubit undergoes a Z-gate operation. The above encryption process can be represented as:
[0035] The X-gate and Z-gate operations mentioned above can be implemented using conventional techniques. For ease of understanding, the first set of X-gates and Z-gates will be used below when the non-Clifford gate is used as the three-qubit Tooffoli gate. Let's take an example. When a = 0 and b = 0, Represents a three-qubit |Δ> 123 The first qubit is subjected to I1 gate operations sequentially, where I1 is the identity matrix mentioned earlier, and the subscript 1 indicates that the operation is performed on the first qubit; when a = 0 and b = 1, Represents a three-qubit |Δ> 123 The first qubit undergoes Z1 and I1 gate operations sequentially; when a = 1 and b = 0... Represents a three-qubit |Δ> 123 The first qubit undergoes I1 and X1 gate operations sequentially; when a = 1 and b = 1... Represents a three-qubit |Δ> 123 The first qubit undergoes Z1 and X1 gate operations sequentially. Since the values of X and Z are derived from a and b, a and b are called the encryption keys. The other X and Z gate operations follow the same principle.
[0036] Step 3, Evaluation: The server executes the corresponding homomorphic evaluation route of the quantum gate on the encrypted quantum state based on the non-Clifford gate, a part of the evaluation key and auxiliary qubits specified by the client, and sends the output of the homomorphic evaluation route and the measurement results to the client.
[0037] When the server executes the non-Clifford gate on the ciphertext quantum state according to the non-Clifford gate specified by the client, some gate errors will occur because the executed quantum gate is a non-Clifford gate. At this time, the client needs to provide auxiliary qubits and a part of the evaluation key to the server to help the server eliminate these gate errors.
[0038] In this embodiment of the invention, when the specified non-Clifford gate is a two-qubit CV gate, the matrix expression of the CV gate is:
[0039]
[0040] Where i represents the unit of the imaginary part of the complex number, i.e., ii 2 =-1.
[0041] If the server directly accesses the ciphertext Execute CV 1,2 Door, then:
[0042]
[0043] in, Phase gate
[0044] In this embodiment of the invention, CV gate and CV 1,2 Both gates represent controlled-V gates, and their matrix representations are the same. The difference lies in that, when it is not explicitly stated which two qubits are being controlled-V gated, CV is generally used; when using two qubits |Φ> 12 When the first qubit is the control bit and the second qubit is the target bit, a controlled-V gate operation is performed, represented as CV. 1,2 That is, when there are two values for the subscript, the qubit corresponding to the first value is used as the control bit, and the second qubit is used as the target bit to perform the corresponding gate operation. For example, CX 1,2 Represented by two qubits |Φ> 12 The first qubit is the control bit, and the second qubit is the target bit for the CX gate operation; similarly, the superscript value of 0 or 1 determines the specific operation.
[0045] That is, CV 1,2 Gates are used in ciphertext The above will appear Door, Door and The door is wrong; among them, This means that when d = 0, for |Φ>12 Perform an I1 operation on the first qubit; when d = 1, perform an I1 operation on |Φ> 12 The first qubit performs the S1 operation. and The same principle applies. Therefore, the client will assist the qubits. And a portion of the evaluation keys g, h, z, Send to the server for CV 1,2 The homomorphic evaluation of the gate is performed by the server based on a subset of the evaluation keys g, h, z. and auxiliary qubits Performing two-qubit gate CV 1,2 The homomorphic evaluation route, when CV 1,2 After the homomorphic evaluation circuit of the gate is executed, the output result is obtained. The measurement results m and n are then sent to the client; similarly, the superscript of the CZ gate also determines the specific operation content. A superscript of 0 indicates a unit gate operation, and a superscript of 1 indicates a CZ gate operation. CZ 1,2 This indicates a CZ gate operation performed with the first auxiliary qubit (|+>1|+>2) as the control bit and the second auxiliary qubit as the target bit. The subscript values 1 or 2 of the X, Z, and S gates indicate that the operation is for a two-qubit system (|Φ>1|+>2). 12 Operate on the first or second qubit; The expression represents XOR, and |+>1 and |+>2 represent the expressions for the first and second auxiliary qubits added by the client, respectively. The measurement results m and n are two classical bit information, representing two quantum bits |Φ> 12 The result information after two qubits are measured, m,n∈{0,1}.
[0046] In this embodiment of the invention, when the non-Clifford gate is a three-qubit Tooffoli gate, the matrix expression of the Tooffoli gate is:
[0047]
[0048] If the server directly accesses the ciphertext Executing the Toffoli gate, then:
[0049]
[0050] As mentioned earlier, I is the unit gate; when performing a unit gate operation on a qubit, the state of the qubit does not change. If only the first and second qubits of a three-qubit system are subjected to a CZ operation...1,2 For ease of understanding, this invention uses I3 to indicate that no unitary operator operation was performed on the third qubit. The same applies to I1 and I2.
[0051] That is: the Tofoli gate acts on the ciphertext The above will appear Door, Door and The door is wrong; among them, This means that when f = 0, for |Δ> 123 The first and second qubits perform I1 and I2 operations respectively; when f = 1, |Δ> 123 The first qubit is the control bit, and the second qubit is the target bit, for |Δ> 123 The first and second qubits are subjected to CZ gate operations. and The same principle applies. Therefore, the client will assist the qubits. A portion of the evaluation keys x, y, and z are sent to the server for homomorphic evaluation of the Tofoli gate. The server then uses this portion of the evaluation keys x, y, and z, along with auxiliary qubits, to perform the evaluation. Execute the homomorphic evaluation circuit of the three-qubit gate to obtain the output result. The measurement results k, m, and n are then sent to the client; where CZ 1,2 This indicates a CZ gate operation performed with the first auxiliary qubit (|+>1|+>2|+>3) as the control bit and the second auxiliary qubit as the target bit. 1,3 This indicates a CZ gate operation performed with the first auxiliary qubit (|+>1|+>2|+>3) as the control bit and the third auxiliary qubit as the target bit. 2,3 This indicates that a CZ gate operation is performed with the second auxiliary qubit (|+>1|+>2|+>3) as the control bit and the third auxiliary qubit as the target bit. |+>1, |+>2, and |+>3 represent the expressions for the first, second, and third auxiliary qubits added by the client, respectively. The measurement results k, m, and n are three classical bit information, representing the three qubits |Δ> 123 The result information after the three qubits are measured, k,m,n∈{0,1}.
[0052] Step 4, Decryption: The client updates the initial decryption key based on the encryption key, evaluation key, and measurement results, and performs a decryption operation on the output results to obtain the correct quantum computing results.
[0053] In this embodiment of the invention, when the specified non-Clifford gate is a two-qubit CV gate, the client updates the initial decryption key based on the encryption key, the evaluation key, and the measurement result, as follows: Obtain the updated decryption key Key.Dec = (a′, b′, c′, d′). Use the updated decryption key to determine the new combination of the X and Z gates, and perform a decryption operation on the output to obtain the correct quantum computing result CV. 1,2 |Φ》 12 .
[0054] In this embodiment of the invention, when the specified non-Clifford gate is a three-qubit Tooffoli gate, the client updates the initial decryption key based on the encryption key, the evaluation key, and the measurement result, as follows: Obtain the updated decryption key Key.Dec=(a′,b′,c′,d′,e′,f′), use the updated decryption key to determine the new combination of X gate and Z gate, and perform the decryption operation on the output to obtain the correct quantum computing result Tofoli|Δ》 123 .
[0055] The above-described solution provided by the embodiments of the present invention achieves the following beneficial effects: quantum homomorphic encryption provides secure and convenient delegated computing services for clients with limited computing power. This is because the server performing quantum computing cannot obtain the plaintext information from the client's ciphertext, and the client can quickly obtain the computation result through a simple decryption operation. The present invention provides quantum homomorphic encryption methods based on quantum one-time pad for CV gates and Tooffoli gates (non-Clifford set gates). By constructing quantum circuits with complex computational functions using CV gates and Tooffoli gates, compared with quantum circuits with the same computational functions constructed using T gates, the present invention not only reduces the number of quantum gates in the quantum circuit but also reduces the complexity of homomorphic evaluation, enabling faster secure quantum computing services for clients.
[0056] To more clearly demonstrate the technical solution and its effects provided by this invention, two specific examples are provided below.
[0057] Example 1: A quantum homomorphic encryption method based on a quantum one-time pad two-qubit gate (CV gate), mainly including the following parts:
[0058] (1) Key Generation Section: The client randomly generates a set of keys, including the encryption key Key.Enc=(a,b,c,d), the initial decryption key Key.Dec=(a′,b′,c′,d′) and the evaluation key Key.Eval={g,h,s,t,x,z}, where
[0059] (2) Encryption: The client uses Key.Enc = (a,b,c,d) to determine the combination of the X and Z gates, and then performs encryption on the two qubits |Φ> 12 Encryption will produce the ciphertext. Send to the server.
[0060] (3) Evaluation section: When the server performs CV on the ciphertext 1,2 When entering a door, there are:
[0061]
[0062] It can be observed that CV 1,2 Homomorphic evaluation of gates will occur Door, Door and The door is wrong.
[0063] According to the identity have:
[0064]
[0065] according to Figure 2 By adding an H operator as shown, the server can introduce a V. x Operator. Then, the server presses... Figure 3 The quantum circuit shown introduces a Operator.
[0066] Where H is a quantum Hadamard gate, and It is the conjugate transpose of the phase gate and the S-gate, expressed as:
[0067] Those skilled in the art will understand that, in quantum mechanics, gate operations performed on qubits can be called unitary operators or operators. For example, performing an X-gate operation on a single qubit can be described as "performing an X-unitary operator (X operator) on a single qubit".
[0068] Therefore, in order to eliminate CV 1,2 The server responds to a gate error that occurs during homomorphic evaluation. Figure 4 The quantum circuit shown performs CV on the ciphertext. 1,2 Homomorphic evaluation of the gate, where the client will assist the qubit. And a portion of the evaluation keys g, h, z, Send it to the server. At this point, the server's output is:
[0069]
[0070] The evaluation process is secure because the server cannot obtain the encryption key Key.Enc = (a,b,c,d) and the other part of the evaluation key Key.Eval = (s,t,x) without knowing them. and The value of . Let and Then we have:
[0071]
[0072] This indicates that the auxiliary qubit This is a maximum mixed state for the server, from which it is impossible for the server to obtain information about the encryption key.
[0073] The server will then output the result |Φ′> 12 The measurement results m and n are sent to the customer.
[0074] (4) Decryption section: Based on the CV executed by the server 1,2 Gate homomorphic evaluation, the client updates the initial decryption key Key.Dec, specifically... Based on the updated decryption key Key.Dec, the client decrypts the server's output to obtain CV. 1,2 |Φ> 12 .
[0075] Example 2: A quantum homomorphic encryption method based on a one-time pad three-qubit gate (Toffoli gate) mainly includes the following parts:
[0076] (1) Key generation section: The client randomly generates an encryption key Key.Enc = (a,b,c,d,e,f), an initial decryption key Key.Dec = (a′,b′,c′,d′,e′,f′), and an evaluation key Key.Eval = {g,h,p,x,y,z}, where
[0077] (2) Encryption section: Based on Key.Enc=(a,b,c,d,e,f), the client determines the combination of X gate and Z gate for the three qubits |Δ> 123 Encryption will produce the ciphertext. Send to the server.
[0078] (3) Evaluation section: When the server executes the Tofoli gate on the ciphertext, the following occurs:
[0079]
[0080] It can be observed that the homomorphic evaluation of the Tofoli gate exhibits [a certain phenomenon]. Door, Door and Door errors. To eliminate these door errors, the server still... Figure 3 The quantum circuit shown introduces the CX operator.
[0081] Therefore, the server presses Figure 5 The quantum circuit shown performs a Toffoli gate homomorphic evaluation on the ciphertext, where the client will assist the qubits. A portion of the evaluation keys x, y, and z are sent to the server. At this point, the server's output is:
[0082]
[0083] The evaluation process is also secure because the server cannot obtain the encryption key Key.Enc = (a,b,c,d,e,f) and the other part of the evaluation key Key.Eval = (g,h,p) without knowing them. and The value of . Let and Therefore:
[0084]
[0085] This indicates that the auxiliary quantum bit U(x′,y′,z′,g,h,p)|+>1|+>2|+>3 is still a maximal mixed state for the server, and the server cannot obtain the encryption key information from it.
[0086] After this, the server will output the result |Δ′> 123 The measurement results k, m, and n are sent to the customer.
[0087] (4) Decryption part: Because the server presses... Figure 5 The quantum circuit completes the homomorphic evaluation of the Toffoli gate, so the client updates the initial decryption key Key.Dec. Based on the updated Key.Dec, the client decrypts the server's output and ultimately obtains Tofoli|Δ> 123 .
[0088] Through the above description of the embodiments, those skilled in the art can clearly understand that the above embodiments can be implemented by software, or by using software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solutions of the above embodiments can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, mobile hard drive, etc.), including several instructions to cause a computer device (such as a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0089] The above description is merely a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A quantum homomorphic encryption method based on quantum one-time pad non-Clifford gate circuits, characterized in that, include: Key generation section: The client randomly generates an encryption key, an initial decryption key, and an evaluation key by combining the specified non-Clifford gates; the specified non-Clifford gates include: two-qubit gate controlled-V gate and three-qubit gate Tooffoli gate; Encryption section: The client performs an encryption operation on the corresponding plaintext quantum state according to the encryption key, and sends the resulting ciphertext quantum state, a portion of the evaluation key, and auxiliary qubits to the server; Evaluation section: Based on the non-Clifford gate, a portion of the evaluation key, and auxiliary qubits specified by the client, the server executes the corresponding homomorphic evaluation route of the ciphertext quantum state, and sends the output of the homomorphic evaluation route and the measurement results to the client; Decryption section: The client updates the initial decryption key based on the encryption key, evaluation key, and measurement results, and performs a decryption operation on the output result to obtain the correct quantum computing result; When the specified non-Clifford gate is a two-qubit controlled-V gate, the client randomly generates an encryption key Key.Enc = (a,b,c,d), an initial decryption key Key.Dec = (a′,b′,c′,d′), and an evaluation key Key.Eval = {g,h,s,t,x,z}; where a,b,c,d,a′,b′,c′,d′,g,h,s,t,x,z are the components of the corresponding key, satisfying... The initial decryption key is initialized using the encryption key; The two-qubit gate controlled-V gate is denoted as the CV gate. The server uses a subset of the evaluation keys g, h, z. and auxiliary qubits Performing two-qubit gate CV 1,2 The homomorphic evaluation route is used to obtain the output results. and the measurement results m and n; where CV 1,2 Represented by two qubits |Φ> 12 The first qubit is used as the control bit, and the second qubit is used as the target bit to perform a CV gate operation; Indicates XOR, Represents the tensor product; the X-gate is the NOT gate, the Z-gate is the phase flip gate, and the S-gate is the phase gate; CZ 1,2 This indicates that a CZ gate operation is performed with the first auxiliary qubit (|+>1|+>2) as the control bit and the second auxiliary qubit as the target bit. The matrix form of the CZ gate is: The superscripts of X-gates, Z-gates, S-gates, and CZ-gates determine the specific operation performed by each gate. The superscript represents the component of each key or the XOR operation result of its components. A superscript of 0 indicates a unit gate operation, and a superscript of 1 indicates the corresponding gate operation. The subscript values of 1 or 2 for X-gates, Z-gates, and S-gates indicate that the operation is for a two-qubit |Φ> 12 The operation is performed on either the first or second qubit. |+>1 and |+>2 represent the expressions for the first and second auxiliary qubits added by the client, respectively. The measurement results m and n represent the two-qubit |Φ> 12 The result information after two qubits are measured.
2. The quantum homomorphic encryption method based on quantum one-time pad non-Clifford gate circuits according to claim 1, characterized in that, When the specified non-Clifford gate is a two-qubit controlled-V gate, the corresponding plaintext quantum state is a two-qubit state, denoted as |Φ> 12 The client determines the combination of X and Z gates in quantum mechanics based on the encryption key Key.Enc = (a,b,c,d) to process the two qubits |Φ> 12 Encryption is performed to obtain the ciphertext quantum state.
3. The quantum homomorphic encryption method based on quantum one-time pad non-Clifford gate circuits according to claim 1, characterized in that, The client updates the initial decryption key based on the encryption key, evaluation key, and measurement results, as follows: Obtain the updated decryption key Key.Dec = (a′, b′, c′, d′). Use the updated decryption key to determine the new combination of the X and Z gates, and perform a decryption operation on the output to obtain the correct quantum computing result CV. 1,2 |Φ> 12 .
4. A quantum homomorphic encryption method based on quantum one-time pad non-Clifford gate circuits according to claim 1, characterized in that, When the specified non-Clifford gate is a three-qubit Tooffoli gate, the client randomly generates an encryption key Key.Enc = (a,b,c,d,e,f), a decryption key Key.Dec = (a′,b′,c′,d′,e′,f′), and an evaluation key Key.Eval = {g,h,p,x,y,z}, where a,b,c,d,e,f,a′,b′,c′,d′,e′,f′,g,h,p,x,y,z are the components of the corresponding key, satisfying... The initial decryption key is initialized using the encryption key.
5. A quantum homomorphic encryption method based on quantum one-time pad non-Clifford gate circuits according to claim 4, characterized in that, When the specified non-Clifford gate is a three-qubit Tooffoli gate, the corresponding plaintext quantum state is three qubits, denoted as |Δ> 123 The client determines the combination of X and Z gates in quantum mechanics based on the encryption key Key.Enc=(a,b,c,d,e,f), for three qubits |Δ> 123 Encryption is performed to obtain the ciphertext quantum state.
6. A quantum homomorphic encryption method based on quantum one-time pad non-Clifford gate circuits according to claim 5, characterized in that, In the evaluation section, the server uses a subset of evaluation keys x, y, z, and auxiliary qubits. Execute the homomorphic evaluation circuit of the three-qubit gate to obtain the output result. and the measurement results k, m and n; where CZ 1,2 This indicates a CZ gate operation performed with the first auxiliary qubit (|+>1|+>2|+>3) as the control bit and the second auxiliary qubit as the target bit. 1,3 This indicates a CZ gate operation performed with the first auxiliary qubit (|+>1|+>2|+>3) as the control bit and the third auxiliary qubit as the target bit. 2,3 This indicates that a CZ gate operation is performed with the second auxiliary qubit (where |+>1|+>2|+>3) as the control bit and the third auxiliary qubit as the target bit. The matrix form of the CZ gate is: Indicates XOR, The X gate represents the tensor product, the Z gate is the phase-flip gate, and I is the unit gate. The superscripts of the X, Z, and CZ gates determine the specific operation of each gate. The superscript represents the components of various keys or the XOR operation result of the components of various keys. A superscript of 0 indicates the execution of the unit gate operation, and a superscript of 1 indicates the execution of the corresponding gate operation. The subscript values of 1, 2, or 3 for the X, Z, and unit gate I indicate that for a three-qubit |Δ> 123 The operation is performed on the first, second, or third qubit. |+>1, |+>2, and |+>3 represent the expressions for the first, second, and third auxiliary qubits added by the client, respectively. The measurement results k, m, and n represent the three qubits |Δ> 123 The result information after the three qubits are measured, k,m,n∈{0,1}.
7. A quantum homomorphic encryption method based on quantum one-time pad non-Clifford gate circuits according to claim 6, characterized in that, The client updates the initial decryption key based on the encryption key, evaluation key, and measurement results, as follows: Obtain the updated decryption key Key.Dec=(a′,b′,c′,d′,e′,f′), use the updated decryption key to determine the new combination of the X and Z gates, and perform the decryption operation on the output to obtain the correct quantum computing result Tofoli|Δ> 123 .