A verifiable quantum homomorphic encryption method based on quantum obfuscation

Through a verifiable quantum homomorphic encryption method based on quantum obfuscation, the problem of verification of server computing results is solved, the user's quantum capability requirements are reduced, and non-interactive computing and result verification of general quantum circuits are realized, which improves the practicality of quantum homomorphic encryption.

CN118337379BActive Publication Date: 2025-08-12XIANGTAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410548210.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-06
Publication Date
2025-08-12
Estimated Expiration
2044-05-06

AI Technical Summary

Technical Problem

The existing quantum homomorphic encryption scheme fails to effectively verify the accuracy of the server's calculation results, and has high requirements for users' quantum capabilities and insufficient versatility.

Method used

Using a verifiable quantum homomorphic encryption method based on quantum obfuscation, by preparing quantum states and gadgets, encrypting using classic public key encryption and a Pauli key with one-digit at a time, the server performs quantum gate operations, the user decrypts and verifies the calculation results, and uses the test circuit to verify the honesty of the server.

Benefits of technology

Non-interactive T-gate problem solving and general quantum circuit computing are realized, which reduces the user's quantum capability requirements and improves the practicality of quantum homomorphic encryption and the feasibility of verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118337379B_ABST
    Figure CN118337379B_ABST
Patent Text Reader

Abstract

This invention proposes a verifiable quantum homomorphic encryption method based on quantum obfuscation. The method includes: the user first generates a public-private key pair and a computational key, prepares a quantum state, and prepares a gadget to solve a specific problem; the user encrypts the quantum state and uses a classical public key to encrypt the Pauli key and gadget required for quantum one-time pad encryption, and then prepares three obfuscation circuits; the user selects any obfuscation circuit and sends it to a server for calculation, wherein the corresponding gadget must be attached to execute a specific gate; the server performs the calculation and sends the result to the user; the user directly decrypts the calculation result of the real circuit, and after decrypting the result of the test circuit, measures it using a corresponding measurement basis, and verifies the server's honesty based on the measurement result. This invention not only achieves verifiability of calculation results through obfuscation circuits without increasing the interaction of the calculation process, but also reduces the quantum capabilities required by the user, thus having greater versatility.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a verifiable quantum homomorphic encryption method based on quantum confusion, and belongs to the field of quantum computing and quantum cryptography. Background Art

[0002] With the rapid development of quantum technology, the possibility of building a practical quantum computer is increasing. In the future, even users without sufficient quantum capabilities may need to outsource their quantum computing needs to quantum cloud servers. At the same time, to prevent privacy leaks, users may also want quantum cloud servers to be able to operate on their encrypted data. This is precisely the goal of quantum homomorphic encryption (QHE) research.

[0003] Quantum homomorphic encryption technology allows users to securely delegate quantum computing tasks to a quantum cloud server. Users send encrypted data to the server, which then performs operations on the encrypted data. Users then decrypt the data to obtain the desired result. Quantum homomorphic encryption was originally designed by Rohde et al. in 2012 based on symmetric keys (PP Rohde, JF Fitzsimons, A. Gilchrist, Quantum walks with encrypted data. Physical Review Letters, 2012, 109: 150501), which can realize quantum random walks on encrypted data. In 2013, Liang proposed a quantum fully homomorphic encryption (QFHE) scheme based on quantum one-time pad and symmetric keys (M. Liang, Symmetric quantum fully homomorphic encryption with perfect security. Quantum Information Processing, 2013, 12: 3675-3687). In 2014, he proposed a QFHE scheme that can realize quantum universal gate sets (M. Liang, Quantum fully homomorphic encryption schemebased on universal quantum circuit. Quantum Information Processing, 2013, 12: 3675-3687). Processing, 2014, 14:2749-2759), which addresses the issue of extra phases that may be introduced by homomorphic execution of T-gates, but requires an interaction between the user and the server. In 2015, Broadbent and Jeffery proposed the AUX and EPR schemes for non-interactively solving the T-gate problem (A. Broadbent, J. Stacey, Quantum homomorphic encryption for circuits of low T-gate complexity. Advances in Cryptology-CRYPTO 2015, Springer, LNCS No. 9216, pp. 609-629, 2015). However, both schemes are applicable only to quantum circuits with a constant number of T-gates and have some limitations on the number of T-gates. In 2016, Delek et al. proposed the TP scheme (Y. Dulek, C. Schaffner, F. Speelman, Quantum homomorphic encryption for polynomial-size circuits).Advances in Cryptology-CRYPTO 2016, Springer, LNCS No. 9816, pp. 3-32, 2016). This scheme designs a gadget T-Gadget based on quantum entanglement exchange and quantum transmission technology. It can solve the T-gate problem without interaction and has no limit on the number of T-gates in the quantum circuit.

[0004] However, most of the current QHE schemes do not consider verifying the results calculated by the server. In fact, malicious behavior of the server may cause errors in the calculation results. Only Alagic et al. have given a verifiable QFHE scheme based on trap codes and quantum magic states (G. Alagic, Y. Dulek, C. Schaffner, F. Speelman, Quantum fully homomorphic encryption with verification. Advances in Cryptology-ASIACRYPT 2017, Springer, LNCS No. 10624, pp. 438-467, 2017), but in this verification scheme, users need to perform complex quantum coding, and the coding of quantum states consumes more quantum resources, which has high requirements on the user's quantum ability and insufficient versatility. Therefore, if the T-gate problem can be solved non-interactively, universal computing of quantum circuits can be realized, and the correctness of the server calculation results can be verified without excessive requirements on the user, it is of great significance. Summary of the Invention

[0005] This paper proposes a verifiable quantum homomorphic encryption method based on quantum obfuscation. This method not only solves the T-gate problem non-interactively and enables universal computation using quantum circuits, but also allows users with limited quantum capabilities to effectively verify the correctness of server calculations. The core method of this invention consists of five stages: preparation, encryption, computation, decryption, and verification.

[0006] Preparation stage: The user prepares the n-bit quantum state |ψ>n and two test circuits Test for calculation in real circuits |0> and Test |+> The quantum states required in and Prepare gadgets T-Gadget and T Test -Gadget is used to solve T-gate problem and H-Gadget and H Test -Gadget is used to solve the H-gate problem. In addition, the user prepares the keys based on the classical homomorphic encryption scheme, namely the public key pk, private key sk and computation key evk; prepares the Pauli key a for quantum one-time pad i ,bi ∈{0,1} n ,i=1,2,3, which are used for encryption of three circuit input quantum states respectively.

[0007] Encryption phase: The user encrypts the initial state of each circuit with the corresponding Pauli key to obtain and The user encrypts the Pauli key a using the public key pk i and b i Get a' respectively i and b' i , where i = 1, 2, 3, and the gadget in each line is encrypted using pk.

[0008] Computation phase: If the quantum gate is from the set {X, Z, P, CNOT}, the server directly applies the quantum gate to the quantum state and sends the calculation result to the user. If the quantum gate is from the set {H, T}, the server executes the corresponding gadget in different circuits and sends the unmeasured qubits in the gadget to the user.

[0009] Decryption phase: For each gate in the set {X, Z, P, CNOT}, the user updates the key according to the homomorphic key update rule and uses the updated key to decrypt the quantum state. For the T-gate and H-gate in the real circuit, the user decrypts the unmeasured qubits in the gadget to obtain the computation result in the real circuit.

[0010] Verification phase: For two test circuits Test |0> and Test |+> By using the T-gate and H-gate in the gadget, users can decrypt the unmeasured qubits in the gadget and verify the outputs of different circuits. |0> Circuit, the user uses the computational basis to measure the quantum state, if the result is not This means that the server did not perform the operation honestly and the user rejected the calculation result. |+> Circuit, the user uses the Hadamard basis to measure the quantum state, if the result is not Likewise, the user rejects the calculation result.

[0011] The present invention realizes homomorphic operations for universal quantum circuits and can realize non-interactive verification of T-gates based on quantum confusion. Compared with previous solutions, the present invention also further reduces the user's quantum capability requirements and is more practical. In the technical route included in the present invention, the user randomly sends one of the two confused circuits or real circuits to a server that cannot distinguish between the three types of circuits. If the server performs the operation honestly, its output is the expected output, otherwise it is an erroneous result. Therefore, the user can judge whether the server performs the operation honestly by the output of the confused circuit; and in the verification technology used by the present invention, the user does not need to perform complex quantum coding to verify the calculation results. It only needs to prepare a confused circuit that requires relatively fewer quantum resources, further improving the practicality of quantum homomorphic encryption. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly describes the drawings required for use in the embodiments. The following drawings illustrate only certain embodiments of the present invention and should not be construed as limiting the scope of the present invention. Persons skilled in the art will be able to derive other relevant drawings based on these drawings without inventive effort.

[0013] Figure 1 It is a schematic diagram of the main process of the present invention.

[0014] Figure 2 Schematic diagram of interaction between two parties in an example of the present invention.

[0015] Figure 3 For transmission quantum circuits with gates.

[0016] Figure 4 This is the process of constructing T-Gadget by performing Bell measurement in the TP scheme.

[0017] Figure 5 The present invention constructs T by performing Bell measurement Test -Gadget process.

[0018] Figure 6 For constructing H-Gadget and H Test -Gadget process. DETAILED DESCRIPTION

[0019] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0020] A verifiable quantum homomorphic encryption method based on quantum confusion, Figure 1 The main flow chart of the present invention is shown. In its specific implementation, it is assumed that Alice is the user and Bob is the quantum cloud server. Figure 2 The following is a schematic diagram showing the interaction between two parties in an example of the present invention. The specific steps are as follows:

[0021] 1. Preparation

[0022] (1a) Alice prepares the quantum state |ψ> n 、 and

[0023] (1b) Alice prepares the public key pk, private key sk and computation key evk for classical homomorphic encryption;

[0024] (1c) Alice prepares the Pauli key a for quantum one-time pad i ,b i ∈{0,1} n , where i = 1, 2, 3;

[0025] (1d) Alice prepares gadgets T-Gadget and T-Gadget to solve the T-gate problem. Test -Gadget and gadgets that solve H-door problems H-Gadget and H Test -Gadget.

[0026] (1e) Specifically, the T-Gadget prepared in the real circuit is the gadget in the TP solution, and the T Test -Gadget is designed based on quantum entanglement exchange and quantum teleportation technology. Its purpose is to offset the influence of T gate so as to verify the circuit without the server knowing. Users need to design a gadget to eliminate the influence of T gate. and The execution effect of the T gate under encryption to realize two test circuits Test |0> and Test |+> Therefore, it is necessary to encrypt the quantum state and In addition The gate is transmitted to the server to ensure that the user gets the correct verification result.

[0027] about The transmission of the gate can be done by using a similar Figure 3 circuit. Figure 3 To transmit As an example, the door is used to transmit If you need to transmit other quantum gates, such as Door, just Figure 3 In the circuit The door is modified to The design of the corresponding transmission circuit can be completed by using the gate, and the circuit design of other quantum gate transmissions is similar. Figure 3 In the example, we assume that |ψ〉=cosα|0〉+sinα|1〉 is the user’s input state, and the user and the server share the Bell state. Then, the user's Bell state |β 00 >Execute Operations can get status The overall state of the system is

[0028]

[0029] in and

[0030] The user then performs Bell measurement on the quantum state in his hand and obtains the measurement results M1 and M2. The server performs Bell measurement on the state in its hand. operation, which is equivalent to performing In addition, T Test -Gadget design also requires the use of quantum entanglement exchange technology to perform Bell measurements on Bell pairs in a specific order. The specific structure is shown below.

[0031] T Test -Gadget consists of a classical part and a quantum part. Assume that the gadget requires n entangled pairs, and each qubit of the entangled pair is numbered, so a total of 2n numbers and n disjoint pairs (u1,v1),(u2,v2),...,(u n ,v n ), where u i ≠v i ∈{1,2,...,2n}. For example, when n=2, the disjoint pairs are {(1,3),(2,4)}. The classical part is determined by the private key sk and is defined as C(sk)=((u1,v1),(u2,v2),...,(u n ,v n ),q,sk), where q∈{0,1} n express The gate implements a sequential n-bit string, and the value of n depends on the security parameter κ. According to the classical part, the quantum part can be defined as where r,t∈{0,1} nis a Pauli key of length n, Q(i) is the i-th encrypted entangled state, defined as where r[i], t[i] and q[i] are the i-th bits of r, t and q respectively. Since r and t are randomly chosen, the states of these 2n qubits are This is a completely mixed state, indicating that the T Test -Quantum part G in Gadget r,t (C(sk)) can prevent the private information about sk from being leaked.

[0032] (1f) or The implementation of the H gate may cause two independent qubits to become entangled, resulting in the wrong output of the confusion circuit. |0> Circuit and Test |+> The trap bit states |0> and |+> in the circuit cannot be directly implemented by updating the key in both the real circuit and the test circuit. First, it is necessary to prepare the H-Gadget for the real calculation for the H gate. Since HPHPH = H, the operation HPHPHPH can replace the execution of a single H gate, and each P gate is equivalent to executing two T-Gadgets in the real circuit. Therefore, the H-Gadget mainly includes four H gates and six T-Gadgets. Then prepare the H-Gadget for the test circuit. Test -Gadget. For the test circuit, it is equivalent to the effect of I gate. Based on HIHIHIH=I, the test circuit for verifying the H gate is designed to have the same effect as the identity circuit. In order to maintain consistency with the actual calculation circuit, the three I gates in HIHIHIH can be replaced by six T Test -Gadget.

[0033] 2. Encryption phase

[0034] (2a) Alice uses quantum one-time pad encryption to encrypt the quantum state into

[0035] (2b) Alice encrypts the Pauli key a using the public key pk i ,b i →a' i ,b' i , i=1,2,3;

[0036] (2c) Alice encrypts the gadget in each line using the public key pk.

[0037] (2d) Specifically, the classical part C(sk) contained in the gadget in the test circuit and the key r,t used by the QOTP should be encrypted using the classical HE method as described below:

[0038]

[0039]

[0040] Here, pk' refers to the public key corresponding to the next round of execution of the test gadget. Since the gadget depends on the secret key sk, the security of the information encrypted by the public key pk corresponding to sk cannot be guaranteed. Finally, the gadget encrypted during the test circuit operation can be expressed as

[0041]

[0042] Where p(A) is the density matrix corresponding to A. If A is a random variable on the possible ground state D of a quantum system, ρ(A) = ∑ d∈d Pr[A=D]|d> <d|。

[0043] 3. Calculation phase

[0044] (3a) Bob directly executes the gates in the set {X, Z, P, CNOT};

[0045] (3b) For each gate in the set {H, T}, Bob needs to use a corresponding gadget after performing each gate operation;

[0046] (3c) Specifically, the process for the T-gate and H-gate gadgets is as follows:

[0047] In a real circuit, the server needs to input the jth bit of the quantum state of n bits Execute the T gate. Similarly, in the test circuit, the server also needs to input the jth bit of the quantum state and Execute the T gate, where the Pauli key a is encrypted for the j-th quantum state i,j ,b i,j ∈{0,1},i∈{1,2,3},j∈{0,1,2,…,n}. In a real circuit, when using T-Gadget, if a 1,j =1, the user wants the server to execute Gate. In the test circuit Test |0> and Test |+> In the example, use T Test -Gadget gadget, if a 2,j =1,a 3,j =1, the user wants the server to execute Door. Due to a i,j and sk j The information of cannot be disclosed, the private key sk jand the public key pk j The following conditions need to be satisfied, that is When the server receives an a' i,j the server cannot infer the true values of a' i,j and sk j which determine the positions where Alice applies Test gates and gates respectively in the gadgets T-Gadget and T -Gadget.

[0048] When the server uses a T-Gadget or T Test -Gadget, it should perform Bell measurements on the entangled pairs and the input quantum states in the gadget. To hide the relevant information of the gadget from the server, the measurement order is determined by the classical algorithm TP.GenMeasurement(a' i,j ) in the TP scheme. TP.GenMeasurement(a' i,j ) generates a list M which contains disjoint element pairs (h i , f i ) in {0, 1, 2,..., m} representing the qubits on which Bell measurements are performed in the gadget, where h i ≠ f i . After performing Bell measurements between the entangled pairs and the input quantum states according to the measurement order of M, the unmeasured qubits are the output qubits.

[0049] The design of the T-Gadget for the T gate adopts a similar method in the TP scheme. It is generated by the user by generating an encrypted input qubit X a Z b |ψ> and L (L ∈ Z*) Bell pairs and performing gates on the l-th (0 < l < L) qubit among them and performing Bell measurements between the quantum pairs (including the input qubit) in a specific order, where the keys a, b ∈ {0, 1} for the quantum one-time pad. Due to quantum entanglement swapping, after measuring the first qubits of two Bell states in the Bell state, the second qubits of the two Bell states will become a new entangled state. To prevent the server from knowing the specific information of the entangled pairs, different Bell measurements are performed on the entangled pairs according to the private key sk to achieve the privacy of the entangled pairs. Similarly Figure 4 in the left side, when the user and the server share 6 Bell states with serial numbers 1, 2,..., 6 respectively. The user can obtain Figure 4 the T-Gadget in the right side by performing corresponding Bell measurements on the input state with serial number 0 and these Bell states.

[0050] In Figure 4 the T-Gadget, since the user performs Bell measurements on the first qubits of different entangled pairs, the second qubits of the entangled pairs will generate multiple new entangled pairs corresponding to those in the figure. Among the newly generated entangled pairs numbered 2 and 5, due to performing Figure 4 the Bell measurement with the operation, an inverse phase gate will be attached to the entangled pair For the remaining two entangled pairs, no inverse phase gate is attached After receiving the T-Gadget sent by the user, the server can perform multiple measurements in a certain order determined by the classical algorithm TP.GenMeasurement in the TP scheme, and apply gates to the input quantum state to eliminate the possible influence that the P gate may bring during the execution of the T gate.

[0051] Similarly, for the design of T Test -Gadget, it also requires 1 encrypted input qubit X b Z b |δ> and L (L ∈ Z*) Bell pairs, where the input qubit |δ> of the Test |0> circuit is |0>, and the input qubit |δ> of the Test |+> circuit is |+>. Then, the user performs gates on the l-th (0 < l < L) qubit and performs Bell measurements between the quantum pairs (including the input qubit) in a specific order. Similarly Figure 5 on the left side, after the user performs the corresponding Bell measurements, the T Figure 5 -Gadget in the right side is generated. The server performs multiple measurements in a certain order determined by TP.GenMeasurement, and thus applies Test gates to the input quantum state to achieve the effect that the test circuit is equivalent to the identity gate when executing the T gate. Since the server side cannot distinguish between T-Gadget and T

[0052] -Gadget, the TP scheme realizes secure homomorphic computation for non-interactively executing the T gate. Test For the execution of the H gate, the server needs to execute the gadgets H-Gadget and H

[0053] corresponding to the H gate on the real circuit and the test circuit respectively. The server performs Test during the execution Figure 6When using two gadgets for the H-gate, the main process involves using an H-gate for the input quantum state, then using two T-gate gadgets, repeating this three times, and finally making an H-gate. In the real circuit, the T-gate gadget used by the server is T-Gadget; in the test circuit, the T-gate gadget used by the server is T Test -Gadget. Therefore, the H-Gadget in the real circuit realizes the effect of executing the H-gate, while the H-Gadget in the test circuit Test -Gadget implements the effect of executing I gate.

[0054] (4d) Bob sends the calculation result back to Alice.

[0055] 4. Decryption phase

[0056] (4a) Alice updates the key for each door in the set {X, Z, P, CNOT} according to the following key update rule, and then uses the updated key to decrypt the state after executing the door;

[0057] XX a Z b =X a Z b X:(a',b')=(a,b),

[0058] ZX a Z b =X a Z b Z:(a',b')=(a,b),

[0059]

[0060]

[0061]

[0062] Assume that the server has encrypted quantum state X a Z b |ψ> executes P gate to get PX a Z b |ψ>, the user updates the key to obtain the decryption key a'=a and After the user decrypts using keys a' and b', they get That is, the calculation result after executing the P gate on the quantum state |ψ> is obtained.

[0063] (4b) Alice uses the private key sk to decrypt the Pauli key after performing classical homomorphic computation on the T-gate and H-gate executed in the real circuit, and uses the decrypted Pauli key to decrypt the unmeasured qubits in the T-gate and H-gate gadgets.

[0064] 5. Verification phase

[0065] (5a) For the test circuit Test |0> and Test |+> Alice decrypts the unmeasured qubits in the T-gate and H-gate gadgets.

[0066] (5b) For the test circuit Test |0> After decrypting the quantum states, Alice uses the computational basis to measure them. If the measurement result is not Then reject the result obtained in the calculation circuit;

[0067] (5c) For the test circuit Test |+> Alice uses the Hadamard basis to measure the decrypted quantum states. If the measurement result is not Then reject the result obtained in the calculation circuit.

[0068] (5d) Specifically, for the input state in the test circuit and If the server performs malicious operations, the decrypted state will no longer be the original quantum state before encryption. and Thus, users can judge whether the server has performed the operation honestly based on the measurement results.

[0069] The above embodiments are intended only to illustrate the implementation of the present invention and are not intended to limit the scope of the present invention. Under the design principles of the present invention, modifications, transformations, and replacements that are simple and intuitive for professionals in the field and do not deviate from the technical solutions of the design principles of the present invention will still fall within the scope of protection of the present invention.

Claims

1. A verifiable quantum homomorphic encryption method based on quantum confusion, characterized in that: It includes the following five stages: Preparation stage: The user prepares the real circuit and two test circuits Test 0> and Test |+> The required quantum states, the gadgets T-Gadget and H-Gadget prepared to solve T-gate and H-gate problems in real circuits, and the gadget T prepared to solve T-gate and H-gate problems in test circuits Test -Gadget and H Test -Gadget; T-Gadget and T Test -Gadget uses quantum entanglement exchange and quantum teleportation technology to eliminate the phase gate byproducts that may be generated when executing the T gate; H-Gadget uses the operation HPHPHPH to replace the execution of a single H gate, and H Test -Gadget replaces the execution of a single I gate by designing the operation HIHIHIH; then generates a public-private key pair and a computation key based on a classical homomorphic encryption scheme, as well as a Pauli key that encrypts the input quantum state using quantum one-time pad technology; Encryption phase: The user uses quantum one-time pad technology and Pauli key to encrypt the real circuit and two test circuits Test 0> and Test |+ The quantum state in the cipher is encrypted, and the Pauli key and the classical part in the gadget are encrypted using the public key through classical homomorphic encryption, and three types of obfuscation circuits are prepared; Calculation phase: The user tests the actual circuit and two test circuits. 0> and Test +> The server can select any obfuscated circuit from the set {X, Z, P, CNOT} and send it to the server. The server cannot distinguish which obfuscated circuit it is, but needs to perform the corresponding calculation for the circuit. For gates in the set {X, Z, P, CNOT}, the corresponding gate operation is directly performed. For gates in the set {H, T}, after each gate operation, the corresponding gadget needs to be used. After the server performs the calculation, it sends the calculation result to the user. Decryption phase: For the gates in the set {X, Z, P, CNOT}, the user updates the key according to the homomorphic key update rule and uses the updated key to decrypt the quantum state. For the T-gate and H-gate executed in the real circuit, the private key is used to decrypt the Pauli key after performing the classical homomorphic computation. The decrypted Pauli key is then used to decrypt the unmeasured qubits in the T-gate and H-gate gadgets to obtain the computational results of the real circuit. Verification phase: for test circuit Test 0> and Test |+> The T-gate and H-gate executed in the test, the user decrypts the unmeasured qubits in the T-gate and H-gate gadgets; 0> Circuit, the user uses the computational basis to measure the quantum state, if the result is not Then reject its calculation result; for Test |+> Circuit, the user uses the Hadamard basis to measure the quantum state, if the result is not The user also rejects the calculation result; if the server is dishonest, the state after the user's decryption will not be the expected result, which can be detected.

2. The verifiable quantum homomorphic encryption method based on quantum confusion according to claim 1 is characterized in that: During the preparation phase: The user prepares an n-bit quantum state |ψ> for computation on a real circuit n And two test circuits Test 0> and Test |+> The quantum states required in and Prepare gadgets T-Gadget and T Test -Gadget is used to solve T-gate problem and H-Gadget and H Test -Gadget is used to solve the H-gate problem; in addition, the user prepares the keys based on the classical homomorphic encryption scheme, namely the public key pk, the private key sk and the computation key evk; prepares the Pauli key a for quantum one-time pad i ,b i ∈{0,1} n ,i=1,2,3, respectively used for encryption of three circuit input quantum states; The T-Gadget prepared in the real circuit is the gadget in the TP solution, which tests the T Test -Gadget is designed based on quantum entanglement exchange and quantum teleportation technology. Its purpose is to offset the influence of T gate so as to verify the circuit without the server knowing. Users need to design a gadget to eliminate the influence of T gate. and The execution effect of the T gate under encryption to realize two test circuits Test |0> and Test |+> The same output of ; therefore, it is necessary to encrypt the quantum state and In addition The door is transmitted to the server to ensure that the user gets the correct verification result; or The implementation of the H gate may cause two independent qubits to become entangled, resulting in the wrong output of the confusion circuit; the H gate may change the Test |0> Circuit and Test |+> The trap bit states |0> and |+> in the circuit cannot be directly implemented by updating the key in both the real circuit and the test circuit. First, it is necessary to prepare the real calculation H-Gadget for the H gate. Since HPHPHPH=H, the operation HPHPHPH can replace the execution of a single H gate, and each P gate is equivalent to executing two T-Gadgets in the real circuit. Therefore, the H-Gadget mainly includes four H gates and six T-Gadgets. Then, prepare the H-Gadget of the test circuit for the H gate. Test -Gadget; For the test circuit, it is equivalent to the effect of I gate; Based on HIHIHIH=I, the test circuit for verifying the H gate is designed to have the same effect as the identity circuit; In order to maintain consistency with the actual calculation circuit, the three I gates in HIHIHIH can be replaced by six T Test -Gadget.

3. The verifiable quantum homomorphic encryption method based on quantum confusion according to claim 2 is characterized in that: During the encryption phase: The user encrypts the initial state of each circuit with the corresponding Pauli key to obtain and The user encrypts the Pauli key a using the public key pk i and b i Get a' respectively i and b' i , where i = 1, 2, 3, and the gadget in each circuit is encrypted using pk; Specifically, the classical part C(sk) contained in the gadget in the test circuit and the key r,t used by the QOTP should be encrypted using the classical HE method as described below: Here, pk' refers to the public key corresponding to the next round of execution of the test gadget. Since the gadget depends on the secret key sk, the security of the information encrypted by the public key pk corresponding to sk cannot be guaranteed. Finally, the gadget encrypted during the test circuit operation can be expressed as Where ρ(A) is the density matrix corresponding to A; if A is a random variable on the possible ground state D of a quantum system, ρ(A) = ∑ d∈D Pr[A=D]|d> <d|。 4. The method for verifiable quantum homomorphic encryption based on quantum confusion according to claim 3, characterized in that: During the calculation phase: If the quantum gate is a gate in the set {X, Z, P, CNOT}, the server directly applies the quantum gate to the quantum state and sends the calculation result to the user. If the quantum gate is a gate in the set {H, T}, the server executes the corresponding gadget in different circuits and sends the unmeasured qubits in the gadget to the user. Specifically, the process for the T-Gate and H-Gate gadgets is as follows: In a real circuit, the server needs to input the jth bit of the quantum state of n bits Execute the T gate; similarly, in the test circuit, the server also needs to input the jth bit of the quantum state and Execute the T gate, where the Pauli key a is encrypted for the j-th quantum state i,j ,b i,j ∈{0,1},i∈{1,2,3},j∈{0,1,2,…,n}; In a real circuit, when using T-Gadget, if a 1,j =1, the user wants the server to execute Gate; in test circuit Test 0> and Test +> In the example, use T Test -Gadget gadget, if a 2,j =1,a 3,j =1, the user wants the server to execute door; due to a i,j and sk j The information of cannot be disclosed, the private key sk j and public key pk j The following conditions must be met, namely When the server receives a' i,j When the server cannot infer a' i,j and sk j The real value of these values determines the user's Test -Apply separately in Gadget Door and Door location; When the server uses a T-Gadget or T Test -Gadget, Bell measurement should be performed on the entangled pair in the gadget and the input quantum state; in order to hide the relevant information of the gadget from the server, the measurement order is determined by the classic algorithm TP.GenMeasurement(a'i,j) in the TP scheme; TP.GenMeasurement(a' i,j ) generates a list M containing disjoint pairs of elements in {0,1,2,...,m} (h i ,f i ) represents the qubit in the gadget that performs Bell measurement, where h i ≠f i After Bell measurements are performed between the entangled pair and the input quantum state according to the measurement order of M, the unmeasured qubit is the output qubit; For the execution of H-gate, the server needs to execute the gadgets H-Gadget and H-Gadget corresponding to the H-gate on the real circuit and the test circuit respectively. Test -Gadget; When the server executes the two gadgets for the H-gate, the main process includes using an H-gate for the input quantum state, then using two T-gate gadgets, repeating this three times, and finally doing an H-gate; in the real circuit, the T-gate gadget used by the server is T-Gadget; in the test circuit, the T-gate gadget used by the server is T Test -Gadget; Therefore, the H-Gadget in the real circuit realizes the effect of executing the H-gate, while the H-Gadget in the test circuit Test -Gadget implements the effect of executing I gate.

5. The method for verifiable quantum homomorphic encryption based on quantum confusion according to claim 4, characterized in that: During the decryption phase: For gates in the set {X, Z, P, CNOT}, users update the key according to the homomorphic key update rule and use the updated key to decrypt the quantum state; for T-gates and H-gates in the real circuit, users decrypt the unmeasured qubits in the gadget and obtain the calculation results in the real circuit; For the gates in the set {X, Z, P, CNOT}, the user updates the key according to the following key update rules, and then uses the updated key to decrypt the state after executing the gate; XX a Z b =X a Z b X:(a',b')=(a,b), ZX a Z b =X a Z b Z:(a',b')=(a,b), Assume that the server has encrypted quantum state X a Z b |ψ> executes P gate to get PX a Z b |ψ>, the user updates the key to obtain the decryption key a'=a and After the user decrypts using keys a' and b', they get That is, we get the calculation result after executing the P gate on the quantum state |ψ>; For the T-gate and H-gate executed in the real circuit, the user uses the private key sk to decrypt the Pauli key after performing classical homomorphic computation, and uses the decrypted Pauli key to decrypt the unmeasured qubits in the T-gate and H-gate gadgets.

6. The method for verifiable quantum homomorphic encryption based on quantum confusion according to claim 5, characterized in that: During the verification phase: For two test circuits Test |0> and Test |+> The T-gate and H-gate in the test qubits are used by the user to decrypt the unmeasured qubits in the gadget and verify the outputs of different circuits; |0> Circuit, the user uses the computational basis to measure the quantum state, if the result is not This means that the server did not perform the operation honestly and the user rejected the calculation result. |+> Circuit, the user uses the Hadamard basis to measure the quantum state, if the result is not Likewise, the user rejects the calculation result; Specifically, for the input state in the test circuit and If the server performs malicious operations, the decrypted state will no longer be the original quantum state before encryption. and Thus, users can judge whether the server has performed the operation honestly based on the measurement results.

Citation Information

Patent Citations

  • Quantum security multi-party computing method based on quantum homomorphic encryption

    CN113660085A

  • Cross quantum homomorphic encryption method based on quantum network coding

    CN116318619A