Verifiable quantum homomorphic encryption method suitable for specific general quantum gate set
By introducing tools such as GadgetCZ in quantum homomorphic encryption, a verifiable quantum homomorphic encryption method suitable for general quantum gate set {H,P,Toffoli} was designed, which solved the problem of lack of verifiability of existing solutions and achieved effective verification and security guarantee of server computing results.
Patent Information
- Application Number
- CN202510015652.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-06
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-06
AI Technical Summary
The existing quantum homomorphic encryption scheme lacks verifiability, and users cannot effectively verify whether the calculation results returned by the server are correct, especially when using the general quantum gate set {H,P,Toffoli}.
A verifiable quantum homomorphic encryption method suitable for the universal quantum gate set {H,P,Toffoli} is designed. By using tools such as gadgetCZ in the preparation, encryption, calculation, verification and decryption stages, users can non-interactively solve the by-product problems that the Toffoli gate may bring in homomorphic computing and verify the server's calculation results.
It realizes verifiability of server computing results, ensures that users can detect and prevent server dishonest behavior, and enhances the security and reliability of quantum homomorphic encryption.
Smart Images

Figure CN119945655A_ABST
Abstract
Description
Technical Field
[0001] The invention relates to a verifiable quantum homomorphic encryption method applicable to a universal quantum gate set {H, P, Toffoli}, and belongs to the field of quantum computing and quantum cryptography. Background Art
[0002] Quantum computing is a revolutionary computing paradigm that can surpass classical computing in some aspects. For example, Shor's algorithm can solve large integer factorization and discrete logarithm problems in polynomial time, and Grover's algorithm can achieve square root acceleration when performing unordered database searches compared to classical algorithms. Today, quantum computing has been considered for applications in many fields such as cryptography, artificial intelligence, and combinatorial optimization. Although a variety of physical systems such as superconducting qubits, trapped ions, and photons have been considered for building quantum computers, their cost is extremely high, and building large-scale quantum computers remains challenging in the foreseeable future. Therefore, customers with limited quantum capabilities are likely to perform quantum computing tasks through a cloud-based model, namely, entrusting quantum computing.
[0003] Quantum homomorphic encryption (QHE) is an important method of entrusting quantum computing, which allows quantum computing to be performed directly on ciphertext quantum states without prior decryption. The server sends the calculated quantum ciphertext state to the user, and the user obtains the calculation result by decryption. In addition, the process of quantum homomorphic encryption calculation only requires one interaction between the user and the server. In 2012, Rohde et al. proposed the first QHE scheme to realize quantum walks on encrypted data (PP Rohde, JF Fitzsimons, A. Gilchrist, Quantum walks with encrypted data. Physical Review Letters, 2012, 109: 150501). In 2013, Liang constructed a general framework of QHE and quantum fully homomorphic encryption (QFHE), and proposed four QHE schemes and one QFHE scheme based on quantum one-time pad (M. Liang, Symmetric quantum fully homomorphic encryption with perfect security. Quantum Information Processing, 2013, 12: 3675-3687). Then in 2014, Liang proposed another QFHE scheme based on universal quantum circuits (M. Liang, Quantum fully homomorphic encryption scheme based on universal quantum circuit. Quantum Information Processing, 2014, 14: 2749-2759). In 2015, Broadbent and Jeffery proposed two QHE schemes that can homomorphically implement the universal gate set {H, T, CNOT}, but both can only homomorphically calculate a constant number of non-Clifford T gates (A. Broadbent, J. Stacey, Quantum homomorphic encryption for circuits of low T-gate complexity. Advances in Cryptology-CRYPTO 2015, Springer, 2015: 609-629).In 2016, Dulek et al. designed a quantum gadget to correct the byproducts produced by the T gate in the proposed quantum QHE scheme (called the TP scheme) (Y.Dulek, C.Schaffner, F.Speelman, Quantum homomorphic encryptionfor polynomial-size circuits. Advances in Cryptology-CRYPTO 2016, Springer, 2016: 3-32). The scheme allows the client to homomorphically perform a polynomial number of T gates on the encrypted quantum state. In 2017, Alagic et al. introduced the first verifiable QFHE scheme, which is also based on the {H, T, CNOT} gate set. In this QFHE scheme, the client applies quantum error correction code technology and trapped quantum bits to detect dishonest behavior of the server during homomorphic computing (G.Alagic, Y.Dulek, C.Schaffner, F.Speelman, Quantum fully homomorphic encryption with verification.Advances in Cryptology-ASIACRYPT2017, Springer, 2017:438-467). In 2018, Mahadev et al. constructed an encrypted CNOT operation by adopting a pair of trap-gate clawless functions to homomorphically compute non-Clifford Toffoli gates, and then proposed a new QHE scheme based on another universal gate set {H, P, Toffoli} (Mahadev U. Classical homomorphic encryption for quantum circuits. SIAM Journal on Computing, 2020, 52(6): FOCS18-189-FOCS18-215). In 2024, He Renke et al. proposed a verifiable QFHE scheme based on the universal quantum gate set {H, T, CNOT} based on the garbled circuit technology (He R, Chen L, Li Q, et al. Verifiable quantum homomorphic encryption based on garbled evaluation. Quantum Science and Technology, 2024, 9(4): 045051). Compared with the scheme of Alagic et al., this scheme does not require a complex encoding process.
[0004] However, most of the above QHE schemes do not consider the verifiable property, that is, whether the user can verify the correctness of the calculation results returned by the server. In fact, the server may deviate from the calculation process and return incorrect calculation results during the entrusted calculation process. Although Alagic et al. and He Renke et al. proposed verifiable QFHE schemes based on the universal quantum gate set {H, T, CNOT} based on different quantum technologies, they are not suitable for QHE schemes with universal gate sets {H, P, Toffoli}. In fact, quantum algorithms and quantum circuits such as the Grover algorithm use the universal gate set {H, P, Toffoli} for homomorphic implementation, which consumes fewer quantum gates and quantum resources than the {H, T, CNOT} gate set. Therefore, it is of great significance to design a verifiable strategy for the QHE scheme based on {H, P, Toffoli} so that users can verify the dishonest behavior of the server. Summary of the invention
[0005] The present invention proposes a verifiable quantum homomorphic encryption method applicable to the universal quantum gate set {H, P, Toffoli}. In the proposed method, users can not only solve the byproducts of the non-CliffordToffoli gate in the homomorphic calculation process non-interactively through the designed gadget, but also verify whether the calculation results returned by the server are correct. The core method of the present invention mainly includes five stages: preparation, encryption, calculation, verification and decryption.
[0006] Preparation phase: The user generates the classical key set required for the real computing circuit and two types of test circuits, including the public key set Private key collection and calculate the key set where c p , c h and c t are the number of P gates, H gates, and Toffoli gates in the quantum circuit respectively; for P gates and H gates, the user generates c for the real computation circuit p +3c h A gadget implements the identity gate and generates c for two types of test circuits p +3c h Gadget test Eliminate P gates; for Toffoli gates, users generate 3c for each type of circuit t Gadget CZ Used to eliminate possible byproducts of the Toffoli gate; users generate the n-qubit input quantum state |ψ> of the real computing circuit and the input quantum state of two types of test circuits and The user randomly generates Pauli keys a,b,c,d,e,f∈{0,1}n and encrypts the generated Pauli keys using the public key pk0.
[0007] Encryption phase: The user encrypts the input quantum state of each type of quantum circuit with the Pauli key and obtains and The user uses the public key pk1 to encrypt the Pauli key and the classical information of the gadget generated for each type of circuit; the user sends the encrypted input quantum state, gadget and encrypted Pauli key to the server.
[0008] Calculation phase: If the quantum gate is an H gate or a P gate, the server will directly apply the corresponding quantum gate to the input quantum state of each type of quantum circuit; the server uses the gadgets and gadgets generated in the preparation phase to calculate the quantum state of each type of quantum circuit. test Implement the identity gate on the real computing circuit and two types of test circuits respectively If the quantum gate is a Toffoli gate, the server passes the Gadget CZ Eliminate the possible byproducts of Toffoli gates for each type of quantum circuit; the server updates the encrypted Pauli key for each type of quantum circuit based on the gadget; then the server sends the encrypted input quantum bits and the encrypted Pauli key to the user.
[0009] Decryption phase: The user decrypts the encrypted Pauli key returned by the server and uses the decryption result to act on the X gate and Z gate to obtain the output result |ψ>, and The user measures the output results of two types of test circuits by calculating the basis and X basis respectively and Obtain corresponding measurement results;
[0010] Verification phase: If the measurement results of the two types of test circuits are in line with expectations, the user accepts the output result |ψ> of the real computing circuit returned by the server as the final output quantum state.
[0011] The present invention is designed by a small tool Gadget CZThe problem of byproducts that may be caused by the Toffoli gate in homomorphic computing can be solved in a non-interactive way, and on this basis, a verifiable method is designed for quantum homomorphic encryption computing based on the universal gate set {H, P, Toffoli}. In the designed verifiable method, the server cannot distinguish between the real computing circuit and the two types of test circuits. The user measures the output quantum state of the test circuit returned by the server through the corresponding basis. If the measurement result meets the expectation, the user accepts the calculation result of the real computing circuit. The present invention realizes homomorphic computing of the universal gate set {H, P, Toffoli} and provides verifiable properties for the corresponding quantum homomorphic encryption method, further enhancing the practicality of quantum homomorphic encryption in future quantum networks. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. The following drawings are only some embodiments of the present invention, and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.
[0013] Figure 1 It is a schematic diagram of the main process of the present invention.
[0014] Figure 2 It is a schematic diagram of the interaction between two parties of an example of the present invention.
[0015] Figure 3 The present invention constructs a Gadget by performing Bell measurement test process.
[0016] Figure 4 This is the process of constructing a Gadget by performing Bell measurement in the present invention.
[0017] Figure 5 The present invention constructs a Gadget by performing Bell measurement CZ process. DETAILED DESCRIPTION
[0018] The technical scheme in the embodiment of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiment of the present invention. Obviously, the described embodiment is only a part of the embodiment of the present invention, not all of the embodiments. Based on the embodiment of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0019] A verifiable quantum homomorphic encryption method based on the universal quantum gate set {H,P,Toffoli}, Figure 1 The main flow chart of the present invention is shown. Figure 2 The following is a schematic diagram of the interaction between two parties in an example of the present invention. In the specific implementation, assuming that Alice is a user and Bob is a quantum cloud server, the specific steps are as follows:
[0020] 1. Preparation
[0021] (1a) Alice executes the key generation algorithm for the real computing circuit and two types of test circuits Test1 and Test2 respectively. Generate a public key set Private key collection and calculate the key set where c p , c h and c t are the numbers of P gates, H gates and Toffoli gates in the quantum circuit respectively, and κ is the security parameter.
[0022] (1b) Alice prepares quantum inputs for the real computation circuit and two types of test circuits Test1 and Test2, which are the states of n qubits |ψ〉, and
[0023] (1c) Alice randomly generates Pauli keys a,b,c,d,e,f∈{0,1} n Used to encrypt quantum inputs for each class of quantum circuits.
[0024] (1d) For P gates and H gates, Alice generates c for the real computation circuit and two types of test circuits Test1 and Test2, respectively. p +3c h Gadget and Gadget test Used to implement identity gates and eliminate P-gate errors; for Toffoli gates, Alice generates 3c for each type of circuit t Gadget CZ Eliminate CNOT and CZ gate errors that may occur during homomorphic computation of Toffoli gate.
[0025] (1e) Specifically, the gadget prepared in the test circuit test , which is used to eliminate the P gate on the input quantum bit to keep the output quantum bit in the form of and (Ignore Pauli encryption), thereby verifying Bob's dishonesty through Z-basis and X-basis measurements. test It contains a classical part and a quantum part. The quantum part contains n pairs of EPR pairs and they are connected by {(s1,t1),(s2,t2),...,(sn ,t n )} is represented. The classical part is based on the private key sk0 and can be defined as {(s1, t1), (s2, t2),..., (s n ,t n ), q, sk0)}, where q ∈ {0, 1} n represents The gate acts on the position of s i . For example, if n = 3 and q = 100, then the gate acts on s1. In addition, the value of n depends on the security parameter κ. According to the classical part of Gadget test , the quantum part can be defined as where x, z ∈ {0, 1} n . Since x and z are randomly selected by Alice, Gadget test is a completely mixed state for Bob Therefore, as long as x and z are encrypted by a secure classical homomorphic encryption method, the private key sk will not be leaked to Bob. The role of the gadget Gadget prepared in the real circuit is to implement the identity gate on the input qubits. Except for the identity gate implemented on s i , the composition of the gadget Gadget is similar to that of Gadget test . Gadget is also a completely mixed state for Bob Therefore, Bob cannot distinguish between the real computing circuit and the two types of test circuits.
[0026] The construction methods of the gadget Gadget and Gadget test are similar to those in the TP scheme. Alice and Bob pre-share 2n EPR pairs. Then Alice performs the gate on the l-th (0 < l < n) entangled particle she owns and performs the corresponding Bell measurement on the entangled particles owned by Alice, where the measurement order is determined by the private key sk0 generated by Alice. Therefore, Bob cannot know the connection method of the EPR pairs in the final gadget. Similarly Figure 3 , Alice and Bob pre-share 6 EPR pairs, numbered 1, 2,..., 6, where Alice owns the first qubits {e1,..., e6} of these EPR pairs. Alice performs the corresponding Bell measurement on these e i (1 ≤ i ≤ 6) to obtain the Figure 3 gadget Gadget in test . Because Alice performs the corresponding Bell measurement on the e i(1 ≤ i ≤ 6) A Bell measurement is performed, and the second qubit of the EPR pair will be correspondingly entangled according to entanglement swapping. For example, the second qubits of the EPR pairs numbered 2 and 5 will form a new EPR pair. In the generated Gadget test , for specific EPR pairs such as those numbered 1 and 3, etc., carry operations. This is because when generating Gadget test , Alice performs a Bell measurement with operations on the corresponding EPR pairs. Except that Alice performs an identity gate on the l-th (0 < l < n) entangled particle she owns instead of gate, the construction of Gadget is similar to Gadget test . Alice can generate the Gadget in i (1 ≤ i ≤ 6) by performing a Bell measurement. Figure 4
[0027] The purpose of Gadget CZ is to eliminate possible CZ gate errors on the input qubits. It also contains a classical part and a quantum part. The quantum part contains 2n pairs of EPR pairs, and their connection method is represented by {(s1, t1), (s2, t2),..., (s 2n , t 2n )}. The classical part is based on the private key sk0 and can be defined as {(s1, t1), (s2, t2),..., (s 2n , t 2n ), r, sk0}, where r ∈ {0, 1} 2n represents that the CZ gate acts on the position of s i . For example, assuming n = 3 and q = 110000, the CZ gate acts on s1 and s2. According to the classical part of Gadget CZ , the quantum part is defined as where x, z ∈ {0, 1} 2n . And because x and z are randomly selected by Alice, Gadget CZ is a completely mixed state for Bob The construction of Gadget CZ is different from the previous two gadgets. It targets a quantum input containing two qubits, so Alice and Bob need to pre-share 4n EPR pairs. Then Alice performs a CZ gate on the l-th (0 < l < 2n) entangled particle she owns and performs a corresponding Bell measurement on the entangled particles owned by Alice. The measurement order is still determined by the private key sk0 generated by Alice. Similarly Figure 5 In the example, Alice and Bob pre-share 12 EPR pairs, numbered 1, 2, ..., 12, where Alice owns the first qubit {e1, ..., e 12}. Alice has some i (1≤i≤12) performs CZ gate operation, and then i (1≤i≤12) Perform the corresponding Bell measurement to obtain Figure 5 Gadgets in CZ .
[0028] (1f) Since the H gate changes the input qubits in the test circuit, if it works with other gates, it is impossible to maintain the form of the qubits in the test circuit |0> and |+>. or Effect on and This will change the states of the two qubits to Then, if Bob uses the CNOT gate, the two quantum bits will be entangled and generate a state Therefore, Alice cannot verify Bob's dishonest behavior through the corresponding Z and X basis measurements. In this method, the H gate is implemented by HPHPHPH=H on the real computing circuit, while the identity gate operation on the test circuit is implemented by HIHIHIH=I.
[0029] 2. Encryption phase
[0030] (2a) Alice uses the Pauli key to encrypt the quantum input of each quantum circuit to generate X a Z b |ψ>,
[0031] (2b) Alice uses public key pk1 to encrypt the Pauli keys a,b,c,d,e,f→a',b',c',d',e',f'.
[0032] (2c) Alice uses the public key pk1 to encrypt the classical information of each gadget in the quantum circuit.
[0033] (2d) Specifically, gadgets, gadgets test The classical information contains g(sk)(f(sk)) and the key x, z∈{0,1} used by QOTP n . Gadget and Gadget test The gadgets can be represented as
[0034]
[0035] and
[0036]
[0037] Gadget CZ The classical information includes the key x used by f(sk) and QOTP, where z ∈ {0, 1} 2n . Gadget CZ can be expressed as
[0038]
[0039] where ρ(X) is the density matrix corresponding to X. If X is a random variable corresponding to the possible ground states B of a quantum system, then ρ(X) = Σ b∈B Pr[X = B]|b><b|. For example, if X = {00, 11},
[0040] 3. Computation stage
[0041] (3a) Bob uses the gadget generated in the preparation stage to perform the corresponding gate operations in the set {H, P, Toffoli} on each quantum circuit.
[0042] (3b) Specifically, the process of executing the P gate and the H gate in the real computation circuit and the identity gate in the two types of test circuits Test1 and Test2 is as follows:
[0043] Bob first needs to input X a Z b |ψ> on the real computation circuit and the two types of test circuits Test1 and Test2 and execute the P gate. In the real computation circuit, Bob uses the Gadget gadget to execute the identity gate on PX a Z b |ψ>. When using the Gadget gadget, Bob determines the measurement order of the EPR pairs and the input qubits in the Gadget according to the randomly selected by Alice. The measurement order is determined by the classical algorithm in the TP scheme where the classical algorithm will generate a measurement list M containing 2n elements, M = {(h1, l1),..., (h n , l n )|h i ∈ {s0, s1,..., s n}, l i ∈ {t1,..., t n}}, s0 represents the position of the input qubit. Use Gadget on two types of test circuits Test1 and Test2 test When the measurement list M is completed, the state of the quantum bit in each type of quantum circuit becomes X A Z B P|ψ>, Where A, B, C, D, E, and F are new Pauli keys obtained based on the gadget measurement results and the updates of a, b, c, d, e, and f.
[0044] The execution of the H gate is performed as described in the preparation stage, and for the real computing circuit, it is performed according to HPHPHPH=H, wherein the P gate execution method is performed according to the flow of the above step (3b). For the two types of test circuits Test1 and Test2, it is performed according to HIHIHIH=I.
[0045] (3c) The process of executing the Toffoli gate in the real computing circuit and the identity gate in the two types of test circuits Test1 and Test2 is as follows:
[0046] Bob first needs to compare the input X between the real computing circuit and the two types of test circuits Test1 and Test2 a Z b |ψ>, Execute the Toffoli gate. Because the Toffoli gate is a non-Clifford gate, additional CZ gates and CNOT gates will appear for each type of quantum circuit. The following is an example of three quantum bits. If the input Execute the Toffoli gate on the
[0047]
[0048] Among them a1,b1,c1,d1,e1,f1∈{0,1}. At the same time, because and Therefore, for the real calculation circuit and the two types of test circuits Test1 and Test2, the additional CZ gate and CNOT gate byproducts are corrected. Since Bob does not know the values a, c, and f that determine the byproducts, he cannot distinguish the three types of circuits. CZ When using the gadget, Bob selects a random Determine the measurement order of the EPR pairs and input qubits in the gadget. The measurement order can also be determined by the classical algorithm in the TP scheme. Determine, among which or The difference is that the input qubits here are two qubits, so the EPR pairs in the original measurement order need to be expanded to 2 EPR pairs and then measured according to the measurement list. Classical algorithm A measurement list M containing 4n elements is generated, M = {(h1,l1),...,(h 2n ,l 2n )|h i ∈{i0,i1,s1,...,s 2n},l i ∈{t1,...,t 2n}}, i0, i1 represent the positions of the two input qubits. After the measurement is completed according to the measurement list M, the state of the qubit in each type of quantum circuit becomes X A Z B P|ψ>, Where A, B, C, D, E, F are new Pauli keys obtained based on the gadget measurement results and a, b, c, d, e, f.
[0049] (3d) Bob performs the calculations required for the H gate, T gate, and Toffoli gate according to step (3b) and step (3c), and then Bob updates the encrypted Pauli key based on the classical information and measurement results of all gadgets used. Assume that the final encrypted Pauli keys are
[0050] (3e) Bob sends output qubit X a' Z b' |ψ>, and and encrypt the Pauli key to Alice.
[0051] 4. Decryption phase
[0052] (4a) Alice decrypts the encrypted Pauli key sent by Bob and obtains a', b', c', d', e', f'.
[0053] (4b) Alice outputs the result X for the real computation circuit and the test circuit a' Z b' |ψ>, and Execute decryption operation Z respectively b' X a' , Z d' X c' and Z f' X e' .
[0054] 5. Verification phase
[0055] (5a) For the output quantum state of the test circuit Test1 Alice performs Z-based measurement to obtain the corresponding measurement result. Then the result |ψ> obtained in the real calculation circuit is rejected.
[0056] (5b) For the output quantum state of the test circuit Test2 Alice performs X-based measurement to obtain the corresponding measurement result. Then reject the result |ψ> obtained in the calculation circuit.
[0057] (5c) If Bob performs a malicious operation, the decrypted state of the test circuit will no longer be and Alice can then determine whether Bob has honestly performed the corresponding operations during the homomorphic computation based on the corresponding measurement results. If all measurement results are as expected, Alice accepts the output quantum state of the real computation circuit returned by Bob as the final output result.
[0058] The above embodiments are only used to illustrate the implementation of the present invention, and are not intended to limit the scope of the present invention. Under the design concept given by the present invention, modifications, changes and replacements that are simple and intuitive for professionals in the field and do not deviate from the technical solutions under the design concept of the present invention will still fall within the protection scope of the present invention.
Claims
1. A verifiable quantum homomorphic encryption method for a universal quantum gate set {H, P, Toffoli}, characterized in that: It includes the following five stages: Preparation phase: The user generates the classical key set required for the real computing circuit and two types of test circuits, including the public key set Private key collection and calculate the key set where c p , c h and c t are the number of P gates, H gates, and Toffoli gates in the quantum circuit respectively; for P gates and H gates, the user generates c for the real computation circuit p +3c h A gadget implements the identity gate and generates c for two types of test circuits p +3c h Gadget test Eliminate P gates; for Toffoli gates, users generate 3c for each type of circuit t Gadget CZ Used to eliminate possible byproducts of the Toffoli gate; users generate the n-qubit input quantum state |ψ> of the real computing circuit and the input quantum state of two types of test circuits and The user randomly generates Pauli keys a,b,c,d,e,f∈{0,1}n; Encryption stage: The user encrypts the input quantum state of each type of quantum circuit with the Pauli key to obtain X a Z b |ψ> n , and The user uses the public key pk0 to encrypt the Pauli key and the classical information of the gadget generated for each type of circuit; the user sends the encrypted input quantum state, gadget and encrypted Pauli key to the server; Calculation phase: If the quantum gate is an H gate or a P gate, the server will directly apply the corresponding quantum gate to the input quantum state of each type of quantum circuit; the server uses the gadgets and gadgets generated in the preparation phase to calculate the quantum state of each type of quantum circuit. test Implement the identity gate on the real computing circuit and two types of test circuits respectively If the quantum gate is a Toffoli gate, the server passes the Gadget CZ Eliminate the possible byproducts of each type of quantum circuit due to the Toffoli gate; the server updates the encrypted Pauli key of each type of quantum circuit based on the gadget; then the server sends the encrypted input quantum bits and the encrypted Pauli key to the user; Decryption phase: The user decrypts the encrypted Pauli key returned by the server, and then uses the decryption result to act on the X gate and Z gate to obtain the output result |ψ>, and The user measures the output results of two types of test circuits using Z-basis and X-basis respectively and Obtain corresponding measurement results; Verification phase: If the measurement results of the two types of test circuits are both as expected, the user accepts the output result |ψ> of the real computing circuit returned by the server as the final output quantum state.
2. The verifiable quantum homomorphic encryption method for the universal quantum gate set {H, P, Toffoli} according to claim 1, characterized in that: During the preparation phase: The user generates quantum inputs |ψ> for real computational circuits and two types of test circuits. and Prepare the gadgets and gadgets required for calculation test and Gadget CZ , where Gadget is used to execute the identity gate in the real computing circuit, Gadget test Used for two types of test circuits to eliminate P gate errors and Gadgets CZ For each type of quantum circuit, eliminate possible CZ and CNOT gate byproducts after executing Toffoli; Specifically, Gadget test It contains a classical part and a quantum part; the quantum part contains n pairs of EPR pairs and they can be connected by {(s1,t1),(s2,t2),...,(s n ,t n )}; the classical part is based on the private key sk0 and can be defined as {(s1,t1),(s2,t2),...,(s n ,t n ),q,sk0)}; where q∈{0,1}n represents The gate acts on i Location; according to Gadget test The classical part of the quantum part can be defined as where x,z∈{0,1} n ; The function of the gadget is to implement the identity gate on the input qubit, except for i The above implementation is the identity gate, which is composed of the same test Similar to; Gadget CZ It also contains a classical part and a quantum part; the quantum part contains 2n pairs of EPR pairs and they can be connected by {(s1,t1),(s2,t2),...,(s 2n ,t 2n )}; the classical part is based on the private key sk0 and can be defined as {(s1,t1),(s2,t2),...,(s 2n ,t 2n ),r,sk0)}; where r∈{0,1} 2n Indicates that the CZ gate acts on s i location; In addition, the user prepares the set of classical keys required for calculation, including the set of public keys Private key collection and calculate the key set where c p , c h and c t are the number of P gates, H gates and Toffoli gates in the quantum circuit respectively; the user also prepares the Pauli keys a,b,c,d,e,f∈{0,1}n for quantum one-time pad.
3. The verifiable quantum homomorphic encryption method applicable to the universal quantum gate set {H, P, Toffoli} according to claim 1, characterized in that: During the encryption phase: The user encrypts the input quantum state of each type of quantum circuit using the Pauli keys a, b, c, d, e, and f randomly generated in the preparation phase and obtains X a Z b |ψ> n , and In addition, the user encrypts the classical information of the gadget and the Pauli keys a, b, c, d, e, f generated in the preparation phase by means of the public key pk0.
4. The verifiable quantum homomorphic encryption method applicable to the universal quantum gate set {H, P, Toffoli} according to claim 1, characterized in that: During the calculation phase: If the quantum gate executed by the server is a P gate or a Toffoli gate, the server directly acts on the corresponding gate to the input quantum bit of the three types of quantum circuits, and then the server uses the gadget prepared in the preparation stage. test and Gadget CZ Eliminate errors in each quantum circuit; specifically, Gadget is used to implement the identity gate on the real computing circuit. test For implementation on test circuits Door, Gadget CZ Used to eliminate CNOT and CZ errors on real computing circuits and test circuits; if the quantum gate executed by the server is an H gate, the H gate is implemented on the real computing circuit according to HPHPHPH=H, and the identity gate is implemented on the test circuit according to HIHIHIH=I, where the P gate and the identity gate are implemented through the corresponding gadgets Gadget and Gadget test Assisted implementation.
5. The verifiable quantum homomorphic encryption method applicable to the universal quantum gate set {H, P, Toffoli} according to claim 1, characterized in that: During the decryption phase: The user decrypts the encrypted Pauli keys a', b', c', d', e', f' sent by the server, and uses the decrypted Pauli keys to calculate the output results X of each quantum circuit returned by Bob. a′ Z b′ |ψ>, and Perform the corresponding X or Z operation and obtain the output qubit |ψ〉, 6. The verifiable quantum homomorphic encryption method applicable to the universal quantum gate set {H, P, Toffoli} according to claim 1, characterized in that: During the verification phase: The user respectively tests the output qubits of two types of test circuits Test1 and Test2 and Execute Z-basis and X-basis measurements respectively to obtain corresponding measurement results; based on the measurement results of the two types of test circuits Test1 and Test2, the user can determine whether the server has performed malicious operations during the homomorphic computing process; if all measurement results are as expected, the user accepts the output result |ψ> in the real computing circuit returned by the server as the output quantum state.
Citation Information
Patent Citations
Non-interactive quantum homomorphic encryption method based on matrix decomposition
CN116684058A
Cloud privacy data quantum homomorphic encryption method based on GHZ-like state key acquisition
CN118199930A
Verifiable quantum homomorphic encryption method based on quantum confusion
CN118337379A
Quantum computing on encrypted data
US8897449B1