Blind quantum calculation method and device
Through the preparation of encrypted hypergraphs and the detection of stabilizers between the quantum server and the client, the problems of quantum computing security and client capability requirements are solved, the blindness and correctness verification of quantum computing are achieved, security is guaranteed and computing time is reduced.
Patent Information
- Application Number
- CN202410298446.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-15
- Publication Date
- 2025-09-16
AI Technical Summary
In existing technologies, the security of quantum computing on the client side is difficult to guarantee, and the client side needs to have quantum computing capabilities, which makes it difficult to popularize quantum computing on a large scale.
By preparing an encrypted hypergraph state based on a trapdoor injective function between the quantum server and the client, the client randomly selects an encrypted hypergraph state and verifies it, and the quantum server performs detection based on stabilizers to achieve blindness and correctness verification of quantum computing.
Without requiring the client to have quantum computing capabilities, the blindness and correctness verification of quantum computing are achieved, the security between the client and the server is guaranteed, and the calculation time is reduced.
Smart Images

Figure CN120654843A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Internet data analysis, and in particular to a blind quantum computing method and device. Background Art
[0002] Quantum computing is an emerging computing method. Due to the inherent physical properties of quantum physics, quantum computing can demonstrate superior performance compared to classical computing in terms of storage capacity and computational efficiency. However, the current model of performing quantum computing on quantum clients requires the client to have certain quantum computing capabilities, which is difficult to implement, making it difficult to achieve large-scale popularization in a short period of time.
[0003] Currently, one way for classical clients that does not require quantum computing capabilities is to interact with quantum servers and complete quantum computing through the quantum servers. However, this method cannot protect the client's quantum data security. Summary of the Invention
[0004] The purpose of the present invention is to solve the above-mentioned problems existing in the prior art and provide a blind quantum method and device.
[0005] The blind quantum protection method provided by the present invention is achieved through the following technical solutions: a quantum server and a client prepare multiple encrypted hypergraph states based on a trapdoor injective function; the client randomly selects at least one encrypted hypergraph state to be verified from the multiple encrypted hypergraph states; the quantum server detects the at least one encrypted hypergraph state based on a stabilizer to obtain a detection result, and the stabilizer is determined by the client according to the encrypted hypergraph state to be verified; when the detection result meets a preset condition, it is verified that the decrypted data of the multiple encrypted hypergraph states by the client is correct; or when the detection result does not meet the preset condition, it is verified that the decrypted data of the multiple encrypted hypergraph states by the client is incorrect; when it is verified that the decrypted data of the multiple encrypted hypergraph states by the client is correct, the quantum server performs quantum computing through the encrypted hypergraph state.
[0006] Furthermore, the quantum server and the client prepare multiple encrypted hypergraph states based on the trapgate injective function, including: the quantum server generates n initial state quantum bits; the client generates n groups of trapgate injective functions, and encodes and maps the trapgate injective functions to the multiple initial state quantum bits to obtain multiple coded state quantum bits; the client randomly selects the images of the n groups of trapgate injective functions, and calculates a key, which is stored locally on the client; the server collapses and entangles the multiple coded state quantum bits based on the images of the n groups of trapgate injective functions sent by the client to obtain the multiple encrypted hypergraph states.
[0007] Furthermore, the n sets of trapdoor injective functions generated by the client are f k,0 , f k,1 (1≤k≤n); the client randomly selects the n groups of images of the trapdoor injective function and calculates the key, including: the client randomly selects the n groups of images y1, y2, ..., y n , where y k Corresponding trapdoor injective function f k,0 , f k,1 The image of any one of them; and each y is calculated based on the n sets of trapdoor injective functions k The corresponding preimage x k And the trapdoor function subscript b k ∈{0, 1}, the trapdoor function subscript b k is the key.
[0008] Furthermore, the n initial state quantum bits are The n coded state quantum bits are The server performs collapse processing and entanglement processing on the plurality of coded state quantum bits based on the images of the n groups of trapdoor single-shot functions sent by the client to obtain the plurality of encrypted hypergraph states, including: the server performs collapse processing and entanglement processing on the plurality of coded state quantum bits based on the images of the n groups of trapdoor single-shot functions sent by the client n , for the plurality of coded state quantum bits Perform collapse processing: the last register is based on y k Perform measurement and collapse the coded state quantum bit to |b k >|x k >, discard the original image x k The register where the state of the reserved |b k > Perform Hadamard gate calculation to obtain collapsed state quantum bits The server performs entanglement processing: Based on CZ e The gate performs hypergraph entanglement calculation to obtain the multiple encrypted hypergraphs Enc(|H>).
[0009] Furthermore, the quantum server detects the at least one encrypted hypergraph state based on the stabilizer to obtain a detection result, including: the stabilizer is where X i =(|+><+|-|-><-|) i , g i is the stabilizer corresponding to the i-th bit of the at least one encrypted hypergraph state; based on The Pauli test is performed on the encrypted hypergraph state to obtain the stabilizer gi The test results are The result of the Pauli X measurement on the i-th bit of the encrypted hypergraph is x i The value is 0 or 1, and the result of the Pauli Z measurement of the jth bit of the encrypted hypergraph state is z j The value is 0 or 1; when the stable subg i The test results When the decrypted data of the multiple encrypted hypergraphs are verified to be correct, when the stable sub-g i The test results If it is not established, verify that the decrypted data of the multiple encrypted hypergraphs are wrong; wherein, the b i Key b k The method comprises the following steps: when verifying that the decrypted data of the plurality of encrypted hypergraphs by the client are correct, the quantum server performs quantum computing on the correct plurality of encrypted hypergraphs, and sends the ciphertext computing result to the client; the client performs quantum computing on the plurality of encrypted hypergraphs based on the key b k Decrypt and obtain the plaintext calculation result.
[0010] The blind quantum protection device provided by the present invention is implemented by the following technical solutions: a preparation module, used for preparing multiple encrypted hypergraph states between a quantum server and a client based on a trapdoor injective function; a selection module, used for the client to randomly select at least one encrypted hypergraph state to be verified from the multiple encrypted hypergraph states; a detection module, used for the quantum server to detect the at least one encrypted hypergraph state based on a stabilizer to obtain a detection result, wherein the stabilizer is determined by the client based on the encrypted hypergraph state to be verified; a verification module, used for verifying that decrypted data of the multiple encrypted hypergraph states by the client is correct when the detection result meets a preset condition; or verifying that the decrypted data of the multiple encrypted hypergraph states by the client is incorrect when the detection result does not meet the preset condition; and a calculation module, used for, when the decrypted data of the multiple encrypted hypergraph states by the client is verified to be correct, the quantum server performs quantum calculations using the encrypted hypergraph state.
[0011] Furthermore, the preparation module includes: a generation submodule, which is used by the quantum server to generate n initial state quantum bits; a mapping submodule, which is used by the client to generate n groups of trapgate injective functions, and encode and map the trapgate injective functions to the multiple initial state quantum bits to obtain multiple coded state quantum bits; a selection submodule, which is used by the client to randomly select the images of the n groups of trapgate injective functions and calculate the key, and the key is stored locally on the client; a processing submodule, which is used by the server to collapse and entangle the multiple coded state quantum bits based on the images of the n groups of trapgate injective functions sent by the client to obtain the multiple encrypted hypergraph states.
[0012] Furthermore, the n sets of trapdoor injective functions generated by the client are f k,0 , f k,1 (1≤k≤n); the selection submodule is also used for the client to randomly select the n groups of trapdoor injective functions images y1, y2, ..., y n , where y k Corresponding trapdoor injective function f k,0 , f k,1 The image of any one of them; and each y is calculated based on the n sets of trapdoor injective functions k The corresponding preimage x k And the trapdoor function subscript b k ∈{0, 1}, the trapdoor function subscript b k is the key.
[0013] Furthermore, the n initial state quantum bits generated by the generation submodule are The n coded state quantum bits obtained by encoding and mapping the mapping submodule are: The processing submodule includes: a collapse processing submodule and an entanglement processing submodule: the collapse processing submodule is used for the server to process the images y1, y2, ..., y of the n groups of trapdoor injective functions sent by the client. n , for the plurality of coded state quantum bits Perform collapse processing: the last register is based on y k Perform measurement and collapse the coded state quantum bit to |b k >|x k >, discard the original image x k The register where the state of the reserved |b k > Perform Hadamard gate calculation to obtain collapsed state quantum bits The entanglement processing submodule is used for the server to perform entanglement processing: Based on CZ eThe gate performs hypergraph entanglement calculation to obtain the multiple encrypted hypergraphs Enc(|H>).
[0014] Furthermore, the stabilizer is where X i =(|+><+|-|-><-|) i , g i is the stabilizer corresponding to the i-th bit of the at least one encrypted hypergraph; the detection module is further configured to: The Pauli test is performed on the encrypted hypergraph state to obtain the stabilizer g i The test results are The result of the Pauli X measurement on the i-th bit of the encrypted hypergraph is x i The value is 0 or 1, and the result of the Pauli Z measurement of the jth bit of the encrypted hypergraph state is z j The value is 0 or 1; the verification module is also used to stabilize the sub-g i The test results When the decrypted data of the multiple encrypted hypergraphs are verified to be correct, when the stable sub-g i The test results If it is not established, verify that the decrypted data of the multiple encrypted hypergraphs are wrong; wherein, the b i Key b k The computing module is further configured to, when verifying that the decrypted data of the plurality of encrypted hypergraphs by the client is correct, execute quantum computing on the correct plurality of encrypted hypergraphs and send the ciphertext computing result to the client; the client executes quantum computing on the correct plurality of encrypted hypergraphs based on the key b k Decrypt and obtain the plaintext calculation result.
[0015] Compared with the prior art, the present invention has the following beneficial effects:
[0016] 1. The security of the interaction between the client and the server is guaranteed by preparing an encrypted hypergraph through a trapdoor injective function between the client and the server.
[0017] 2. By generating a trapdoor injective function by the client and storing the key corresponding to the trapdoor injective function locally on the client, it is possible to control the quantum server to encrypt the calculation hypergraph based on post-quantum security technology, thereby achieving the blindness of quantum computing.
[0018] 3. The client remotely operates the server to detect the encrypted hypergraph state based on the stabilizer, thereby realizing the classical verification of quantum computing.
[0019] 4. Without requiring the client to have quantum computing capabilities, it can simultaneously achieve the blindness and verification of quantum computing, and can simultaneously meet the blindness protection of quantum computing and the classical verification of the correctness of quantum computing.
[0020] 5. It can achieve high parallelism in calculations. Compared with the existing method of performing quantum computing through the client, the present invention can achieve the complexity of linear calculations through parallel computing, greatly reducing the required computing time. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 Schematic diagram of the blind quantum computing method in this embodiment;
[0022] Figure 2 is another flow chart of the blind quantum computing method in this specific embodiment;
[0023] Figure 3 Schematic diagram of the structure of the blind quantum computing device in this specific embodiment;
[0024] Figure 4 is a schematic structural diagram of the preparation module in this specific embodiment;
[0025] Figure 5 It is a structural diagram of the processing submodule in this specific implementation. DETAILED DESCRIPTION
[0026] The present invention is further described in detail below with reference to the accompanying drawings:
[0027] refer to Figure 1 As shown, the blind quantum computing method in this specific embodiment includes:
[0028] 101. Based on the trapdoor injective function, multiple encrypted hypergraphs are prepared between the quantum server and the client.
[0029] 102. The client randomly selects at least one encrypted hypergraph state to be verified from multiple encrypted hypergraph states.
[0030] 103. The quantum server detects at least one encrypted hypergraph state based on the stabilizer and obtains the detection result.
[0031] The stable sub-node is determined by the client according to the encrypted hypergraph state to be verified.
[0032] 104. When the detection result meets the preset condition, verify that the decrypted data of the multiple encrypted hypergraphs by the client is correct; or when the detection result does not meet the preset condition, verify that the decrypted data of the multiple encrypted hypergraphs by the client is incorrect.
[0033] 105. When it is verified that the decrypted data of the plurality of encrypted hypergraphs by the client is correct, the quantum server performs quantum computing using the encrypted hypergraph.
[0034] Through the embodiments of the present invention, it is possible to use a semi-trusted (honest but curious) quantum server to complete a classically verifiable blind quantum computing task. For the semi-trusted quantum server scenario, the embodiments of the present invention propose a classically verifiable blind quantum computing scheme based on an encrypted hypergraph state based on a single quantum server-single classical client model, which achieves the compatibility of classical blindness protection and classical verification of computational correctness. In the embodiments of the present invention, based on the idea of quantum one-time pad, the classical client controls the quantum server's encrypted computing resource state (i.e., encrypted hypergraph state) with the help of post-quantum security technology to protect the blindness of quantum computing; at the same time, under the post-quantum security assumption, the classical client remotely controls the quantum server to perform stable sub-detection, thereby verifying the correctness of the computation.
[0035] refer to Figure 2 As shown, another blind quantum computing method in this specific embodiment includes:
[0036] 201. The quantum server generates n initial state quantum bits.
[0037] In the embodiment of the present invention, hypergraph is an abstract concept in mathematics. A hypergraph H = (V, E) consists of a set of vertices and hyperedge sets Composition, |V| = n is the number of vertices of the hypergraph, hyperedges Each hypergraph state |H> can correspond to a hypergraph structure H = (V, E). An n-qubit hypergraph state |H> can be expressed as: in represents the control Z gate acting on the quantum bit corresponding to the hyperedge e. In particular, when When CZ e =-1.
[0038] 202. The client generates n sets of trapdoor injective functions, and maps the trapdoor injective function encodings to a plurality of initial state quantum bits to obtain a plurality of encoded state quantum bits.
[0039] For the embodiment of the present invention, the trapdoor injective function is a concept derived from the trapdoor clawless function. (where b∈{0,1}) satisfies: f k,0 With f k,1 are all injective functions, and for every x 0,y , there exists a unique x 1,y Satisfy f k,0 (x0, y) = f k,1 (x 1,y)=y; At the same time, for a known y, it is difficult for an attacker (even if he has the ability of quantum computing) to simultaneously find the corresponding original image (x 0,y , x 1,y ); but if you have a "trapdoor" t k , the attacker can quickly restore (x 0,y , x 1,y The basic properties of trapdoor-clawless functions can be summarized as: unidirectionality (the inversion can only be obtained if the trapdoor is known) and range overlap.
[0040] In the embodiment of the present invention, the trapdoor injective function still satisfies the unidirectionality compared to the trapdoor clawless function, but does not satisfy the range overlap; in contrast, the trapdoor injective function satisfies the range disjointness. (where b∈{0,1}) satisfies: g k,0 With g k,1 are all injective functions with disjoint ranges; at the same time, for a known y, it is difficult for an attacker (even with quantum computing capabilities) to find the corresponding g k,0 (x0) = y or g k,1 (x1) = y; but if the attacker has a "trapdoor", he can quickly restore the original image x0 or x1.
[0041] 203. The client randomly selects n groups of images of the trapdoor injective function and calculates the key, which is stored locally on the client.
[0042] Among them, the n sets of trapdoor injective functions generated by the client can be expressed as f k,0 , f k,1 (1≤k≤n).
[0043] In the embodiment of the present invention, step 203 may specifically be: the client randomly selects n groups of trapdoor injective function images y1, y2, ..., y n , where y k Corresponding trapdoor injective function f k,0 , f k,1 The image of any one of them; and based on n sets of trapdoor injective functions, each y is calculated k The corresponding preimage x k And the trapdoor function subscript b k ∈{0, 1}, the trapdoor function subscript b k is the key.
[0044] In the embodiment of the present invention, the Pauli Z encryption of the hypergraph is mainly realized by randomly selecting whether to use the Pauli Z transformation for each qubit of the hypergraph. Then the hypergraph state after Pauli Z encryption can be expressed as: Where b is a random string of 0s and 1s of length n, indicating the random choice of using or not using the Pauli Z transform on n qubits.
[0045] In the embodiment of the present invention, the Pauli Z encryption can achieve complete obfuscation of the hypergraph |H>, that is, satisfying the following equation: That is, for computing participants who do not know the encryption key (i.e., a random string of 0s and 1s b), the encrypted hypergraph state is equivalent to a completely mixed state, which does not expose any information about the hypergraph state other than the number of qubits.
[0046] 204. Based on the images of the n groups of trapdoor injective functions sent by the client, the server performs collapse and entanglement processing on multiple coded state quantum bits to obtain multiple encrypted hypergraph states.
[0047] Among them, n initial state quantum bits can be expressed as n coded-state quantum bits can be expressed as
[0048] Specifically, step 203 may include the following two steps: (1) the server generates images y1, y2, ..., y based on the n groups of trapdoor injective functions sent by the client. n , for multiple coded state quantum bits Perform collapse processing: the last register is based on y k Perform measurement and collapse the coded state quantum bit to |b k >|x k >, discard the original image x k The register where the state of the reserved |b k > Perform Hadamard gate calculation to obtain collapsed state quantum bits (2) The server performs entanglement processing: Based on CZ e The gate performs hypergraph entanglement calculation to obtain multiple encrypted hypergraphs Enc(|H>).
[0049] 205. The client randomly selects at least one encrypted hypergraph state to be verified from the multiple encrypted hypergraph states.
[0050] 206. The quantum server detects at least one encrypted hypergraph state based on a stabilizer to obtain a detection result. The stabilizer is determined by the client based on the encrypted hypergraph state to be verified.
[0051] 207. The client decrypts the multiple encrypted hypergraphs to obtain decrypted data.
[0052] 208. When the detection result meets the preset condition, verify that the decrypted data of the multiple encrypted hypergraphs by the client is correct; or when the detection result does not meet the preset condition, verify that the decrypted data of the multiple encrypted hypergraphs by the client is incorrect.
[0053] The above stabilizer can be expressed as where X i =(|+><+|-|-><-|) i , g i is the stabilizer corresponding to the i-th bit of at least one encrypted hypergraph state.
[0054] In the embodiment of the present invention, for a certain n-qubit hypergraph state ρ, a stabilizer is performed. The detection can be achieved by the Pauli X and Z measurements of a single bit: the result of the X measurement on the i-th bit is (x i It may be 0 or 1), and the result of Z measurement on the jth bit is (Z j It may be 0 or 1). Then, the stabilizer g i The test results can be expressed as in when When it is established, the hypergraph state ρ passes through the stabilizer g i For hypergraphs encrypted with Pauli Z, the stable sub-detection needs to be adjusted accordingly. The following commutative properties exist between operators X, Z, and CZ: i Z i =-Z i X i 、X i Z j =Z j X i (i≠j), Z i CZ e =CZ e Z i Therefore, for the hypergraph state after Pauli Z encryption, its stabilizer before encryption satisfies:
[0055] Among them, b i represents the i-th bit of a random string of 0s and 1s. Therefore, the random key b∈{0,1} is used to n Perform Pauli Z encryption on n-qubit hypergraph Enc(ρ), and stabilize g i The detection can be achieved by single-bit Pauli X and Z measurements: the result of X measurement on the i-th bit is (x i It may be 0 or 1), and the result of Z measurement on the jth bit is (z j It may be 0 or 1). Then, the stabilizer g i The test results can be expressed as in when When it is established, the encrypted hypergraph state Enc(ρ) is stabilized by g i Detection.
[0056] Specifically, step 208 may include: based on Perform Pauli test on the encrypted hypergraph state and obtain the stabilizer g i The test results are The result of the Pauli X measurement on the i-th bit of the encrypted hypergraph is x i The value is 0 or 1. The result of the Pauli Z measurement on the jth bit of the encrypted hypergraph is z j The value is 0 or 1. When the stable subg i The test results When it is established, the decrypted data of multiple encrypted hypergraphs are verified to be correct; when the stable sub-g i The test results If it is not true, the decrypted data of multiple encrypted hypergraphs is verified to be wrong; i Key b k The i-th bit of .
[0057] 209. When it is verified that the decrypted data of the plurality of encrypted hypergraphs by the client are correct, the quantum server performs quantum computation on the correct plurality of encrypted hypergraphs and sends the ciphertext computation result to the client; the client performs quantum computation based on the key b. k Decrypt and obtain the plaintext calculation result.
[0058] In an embodiment of the present invention, a quantum one-time pad method is specifically adopted, that is, random Pauli X and Pauli Z operators are used to encrypt the quantum state, and the key is stored locally on the client, so that the input and output of the quantum calculation are secret from the quantum server; and based on the universal blind quantum computing (UBQC) model in the "prepare-send" mode: the client encodes the input of the calculation into a quantum state and sends it to the server, and then commands the server to perform quantum operations through classical communication, adding random parameters during encoding and commanding to protect the blindness of the calculation process, and after obtaining the calculation result, error correction is completed locally to restore the correct result; at the same time, based on the measurement-based quantum computing (MBQC) model in the "receive-measure" mode: the quantum server generates a universal resource state, the local client receives the resource state and completes the calculation through local measurement, and the locality of the operation is used to achieve blindness protection of quantum computing.
[0059] In an embodiment of the present invention, it is specifically implemented in a single classical client-single quantum server model. This model is based on some post-quantum security assumptions. Post-quantum cryptography technology can be used to construct an interactive proof architecture between the classical client and the quantum server, thereby achieving correct verification of quantum computing.
[0060] For the embodiment of the present invention, the interaction protocol between the client and the quantum server satisfies the following three properties: completeness, reliability, blindness, and security.
[0061] (1) Completeness of the protocol: When the server prepares the correct hypergraph and performs measurements correctly according to the client's instructions, the final calculation result must be correct.
[0062] (2) Reliability of the protocol: Considering an ideal environment (i.e., without noise interference), if we believe that the final calculation result is correct, we can use mathematical tools such as Serfling's Bound to prove that: if N total =2nN test as well as Then the target resource state ρ used for calculation tgt At least The probability of satisfying: in, Indicates rounding up, c is a constant, n≥4, is the correct encrypted hypergraph state.
[0063] The completeness and reliability of the above protocol jointly satisfy the correctness of the protocol.
[0064] (3) Blindness of the protocol: In the above protocol, we encrypt the initial computational resource state (i.e., the hypergraph state), and then the server completes the computation. Therefore, the computation process and the length of the input and output are known to the server, but the content of the input and output is kept confidential. Therefore, the protocol is able to protect the blindness of the input and output content of the computation.
[0065] (4) Security of the protocol: The protocol is secure for semi-trusted servers (i.e., honest but curious): Under the semi-trusted assumption, the server will perform operations according to the protocol requirements, which can protect the correctness and integrity of the calculation results. At the same time, due to the blindness of the protocol, the server cannot know the specific content of the calculation results (only the length of the result), which can protect the confidentiality of the calculation results. However, the protocol is insecure for completely malicious servers: Malicious servers can distinguish between the verification process and the calculation process, and can perform malicious actions during the calculation process without being detected, thereby deceiving the client into accepting an incorrect calculation result.
[0066] Through the embodiments of the present invention, it is possible to use a semi-trusted (honest but curious) quantum server to complete a classically verifiable blind quantum computing task. For the semi-trusted quantum server scenario, the embodiments of the present invention propose a classically verifiable blind quantum computing scheme based on an encrypted hypergraph state based on a single quantum server-single classical client model, which achieves the compatibility of classical blindness protection and classical verification of computational correctness. In the embodiments of the present invention, based on the idea of quantum one-time pad, the classical client controls the quantum server's encrypted computing resource state (i.e., encrypted hypergraph state) with the help of post-quantum security technology to protect the blindness of quantum computing; at the same time, under the post-quantum security assumption, the classical client remotely controls the quantum server to perform stable sub-detection, thereby verifying the correctness of the computation.
[0067] refer to Figure 3 As shown, the blind quantum computing device of this specific embodiment includes:
[0068] The preparation module 31 is used to prepare multiple encrypted hypergraphs between the quantum server and the client based on the trapdoor injective function.
[0069] The selection module 32 is configured to cause the client to randomly select at least one encrypted hypergraph state to be verified from the multiple encrypted hypergraph states.
[0070] The detection module 33 is configured to detect the at least one encrypted hypergraph state based on a stabilizer by the quantum server to obtain a detection result, wherein the stabilizer is determined by the client according to the encrypted hypergraph state to be verified.
[0071] The verification module 34 is used to verify that the decrypted data of the multiple encrypted hypergraphs by the client is correct when the detection result meets the preset conditions; or to verify that the decrypted data of the multiple encrypted hypergraphs by the client is incorrect when the detection result does not meet the preset conditions.
[0072] The computing module 35 is configured to, when verifying that the decrypted data of the plurality of encrypted hypergraphs by the client is correct, enable the quantum server to perform quantum computing using the encrypted hypergraph.
[0073] refer to Figure 4 As shown, further, the preparation module 31 includes:
[0074] The generation submodule 311 is used for the quantum server to generate n initial state quantum bits.
[0075] The mapping submodule 312 is configured to generate n sets of trapdoor injective functions by the client, and encode and map the trapdoor injective functions to the multiple initial-state quantum bits to obtain multiple encoded-state quantum bits.
[0076] The selection submodule 313 is used for the client to randomly select the n groups of images of the trapdoor injective function and calculate a key, and the key is stored locally on the client.
[0077] The processing submodule 314 is configured to cause the server to perform collapse and entanglement processing on the plurality of coded-state quantum bits based on the images of the n groups of trapdoor injective functions sent by the client, so as to obtain the plurality of encrypted hypergraph states.
[0078] The n sets of trapdoor injective functions generated by the client are f k,0 , f k,1 (1≤k≤n).
[0079] The selection submodule 313 is also used for the client to randomly select the n groups of trapdoor injective functions, i.e., images y1, y2, ..., y n , where y k Corresponding trapdoor injective function f k,0 , f k,1 The image of any one of them; and each y is calculated based on the n sets of trapdoor injective functions k The corresponding preimage x k And the trapdoor function subscript b k ∈{0, 1}, the trapdoor function subscript b k is the key.
[0080] The n initial state quantum bits generated by the generation submodule are
[0081] The n coded state quantum bits obtained by encoding and mapping the mapping submodule are:
[0082] refer to Figure 5 As shown, further, the processing submodule 314 includes: a collapse processing submodule 3141 and an entanglement processing submodule 3142:
[0083] The collapse processing submodule 3141 is used for the server to process the n sets of trapdoor injective functions based on their images y1, y2, ..., y n , for the plurality of coded state quantum bits Perform collapse processing: the last register is based on y k Perform measurement and collapse the coded state quantum bit to |b k >|x k >, discard the original image x k The register where the state of the reserved |b k > Perform Hadamard gate calculation to obtain collapsed state quantum bits
[0084] The entanglement processing submodule 3142 is used for the server to perform entanglement processing: Based on CZ e The gate performs hypergraph entanglement calculation to obtain the multiple encrypted hypergraphs Enc(|H>).
[0085] The stabilizer is where X i =(|+><+|-|-><-|) i , g i is the stabilizer corresponding to the i-th bit of the at least one encrypted hypergraph state.
[0086] The detection module 33 is also used based on The Pauli test is performed on the encrypted hypergraph state to obtain the stabilizer g i The test results are The result of the Pauli X measurement on the i-th bit of the encrypted hypergraph is x i The value is 0 or 1, and the result of the Pauli Z measurement of the jth bit of the encrypted hypergraph state is z j The value is 0 or 1.
[0087] The verification module 34 is also used to stabilize the g i The test results When the decrypted data of the multiple encrypted hypergraphs are verified to be correct, when the stable sub-g i The test results If it is not established, verify that the decrypted data of the multiple encrypted hypergraphs are wrong; wherein, the b i Key b k The i-th bit of .
[0088] The computing module 35 is further configured to, when verifying that the decrypted data of the plurality of encrypted hypergraphs by the client are correct, execute quantum computing on the correct plurality of encrypted hypergraphs and send the ciphertext computing result to the client; the client executes quantum computing on the correct plurality of encrypted hypergraphs based on the key b k Decrypt and obtain the plaintext calculation result.
[0089] The blind quantum computing device provided by this embodiment can implement the method implementation provided above. For specific functional implementation, please refer to the description in the method embodiment, which will not be repeated here.
[0090] The above technical solution is only one embodiment of the present invention. For those skilled in the art, it is easy to make various types of improvements or modifications based on the principles disclosed in the present invention, and it is not limited to the technical solution described in the above specific embodiments of the present invention. Therefore, the above description is only preferred and does not have a restrictive meaning.
Claims
1. A blind quantum computing method, characterized in that: include: The quantum server and client prepare multiple encrypted hypergraphs based on the trapdoor injective function; The client randomly selects at least one encrypted hypergraph state to be verified from the multiple encrypted hypergraph states; The quantum server detects the at least one encrypted hypergraph state based on a stabilizer to obtain a detection result, wherein the stabilizer is determined by the client according to the encrypted hypergraph state to be verified; When the detection result satisfies a preset condition, verifying that the decrypted data of the plurality of encrypted hypergraphs by the client are correct; or, when the detection result does not satisfy a preset condition, verifying that the decrypted data of the plurality of encrypted hypergraphs by the client is erroneous; When it is verified that the decrypted data of the plurality of encrypted hypergraphs by the client is correct, the quantum server performs quantum computing using the encrypted hypergraph.
2. The blind quantum computing method according to claim 1, characterized in that The quantum server and the client prepare multiple encrypted hypergraphs based on the trapdoor injective function, including: The quantum server generates n initial state quantum bits; The client generates n groups of trapdoor injective functions, and encodes and maps the trapdoor injective functions to the multiple initial state quantum bits to obtain multiple encoded state quantum bits; The client randomly selects the n groups of images of the trapdoor injective function and calculates a key, and the key is stored locally on the client; The server performs collapse processing and entanglement processing on the multiple coded state quantum bits based on the images of the n groups of trapdoor injective functions sent by the client to obtain the multiple encrypted hypergraph states.
3. The blind quantum computing method according to claim 2, characterized in that The n sets of trapdoor injective functions generated by the client are f k,0 , f k,1 (1≤k≤n); The client randomly selects the n groups of images of the trapdoor injective function and calculates the key, including: The client randomly selects the n groups of trapdoor injective functions images y1, y2, ..., y n , where y k Corresponding trapdoor injective function f k,0 , f k,1 The image of any one of them; and each y is calculated based on the n sets of trapdoor injective functions k The corresponding preimage x k And the trapdoor function subscript b k ∈{0, 1}, the trapdoor function subscript b k is the key.
4. The blind quantum computing method according to claim 3, characterized in that The n initial state quantum bits are The n coded state quantum bits are The server performs collapse processing and entanglement processing on the plurality of coded state quantum bits based on the images of the n groups of trapdoor injective functions sent by the client to obtain the plurality of encrypted hypergraph states, including: The server generates images y1, y2, ..., y1 of the n groups of trapdoor injective functions sent by the client. n , for the plurality of coded state quantum bits Perform collapse processing: the last register is based on y k Perform measurement and collapse the coded state quantum bit to |b k >|x k >, discard the original image x k The register where the state of the reserved |b k > Perform Hadamard gate calculation to obtain collapsed state quantum bits The server performs entanglement processing: The hypergraph entanglement calculation is performed based on the CZe gate to obtain the multiple encrypted hypergraphs Enc(|H>).
5. The blind quantum computing method according to claim 4, characterized in that The quantum server detects the at least one encrypted hypergraph state based on the stabilizer to obtain a detection result, including: The stabilizer is where X i =(|+><+|-|-)<-|) i , g i is the stabilizer corresponding to the i-th bit of the at least one encrypted hypergraph state; based on The Pauli test is performed on the encrypted hypergraph state to obtain the stabilizer g i The test results are The result of the Pauli X measurement on the i-th bit of the encrypted hypergraph is x i The value is 0 or 1, and the result of the Pauli Z measurement of the jth bit of the encrypted hypergraph state is Z j The value is 0 or 1; When the stabilizer g i The test results When the decrypted data of the multiple encrypted hypergraphs are verified to be correct, when the stable sub-g i The test results If it is not established, verify that the decrypted data of the multiple encrypted hypergraphs are wrong; wherein, the b i Key b k The i-th bit of When the decrypted data of the plurality of encrypted hypergraphs by the client is verified to be correct, the quantum server performs quantum computing using the encrypted hypergraph, including: When it is verified that the decrypted data of the plurality of encrypted hypergraphs by the client are correct, the quantum server performs quantum computation on the correct plurality of encrypted hypergraphs and sends the ciphertext computation result to the client; The client is based on the key b k Decrypt and obtain the plaintext calculation result.
6. A blind quantum computing device, characterized in that: include: Preparation module, used to prepare multiple encrypted hypergraphs between quantum server and client based on trapdoor injective function; A selection module, configured for the client to randomly select at least one encrypted hypergraph state to be verified from the multiple encrypted hypergraph states; a detection module, configured for the quantum server to detect the at least one encrypted hypergraph state based on a stabilizer to obtain a detection result, wherein the stabilizer is determined by the client according to the encrypted hypergraph state to be verified; a verification module, configured to verify that the decrypted data of the plurality of encrypted hypergraphs by the client are correct when the detection result satisfies a preset condition; or, when the detection result does not satisfy a preset condition, verifying that the decrypted data of the plurality of encrypted hypergraphs by the client is erroneous; The computing module is configured to, when verifying that the decrypted data of the plurality of encrypted hypergraphs by the client is correct, enable the quantum server to perform quantum computing using the encrypted hypergraph.
7. The blind quantum computing device according to claim 6, characterized in that The preparation module includes: A generation submodule, configured for the quantum server to generate n initial state quantum bits; A mapping submodule, configured for the client to generate n groups of trapdoor injective functions, and to encode and map the trapdoor injective functions to the multiple initial-state qubits to obtain multiple coded-state qubits; A selection submodule, configured for the client to randomly select the n groups of images of the trapdoor injective function and calculate a key, wherein the key is stored locally on the client; A processing submodule is used for the server to perform collapse processing and entanglement processing on the multiple coded state quantum bits based on the images of the n groups of trapdoor injective functions sent by the client to obtain the multiple encrypted hypergraph states.
8. The blind quantum computing device according to claim 7, characterized in that The n sets of trapdoor injective functions generated by the client are f k,0 , f k,1 (1≤k≤n); The selection submodule is also used for the client to randomly select the n groups of trapdoor injective functions, i.e., images y1, y2, ..., y n , where y k Corresponding trapdoor injective function f k,0 , f k,1 The image of any one of them; and each y is calculated based on the n sets of trapdoor injective functions k The corresponding preimage x k And the trapdoor function subscript b k ∈{0, 1}, the trapdoor function subscript b k is the key.
9. The blind quantum computing device according to claim 8, characterized in that The n initial state quantum bits generated by the generation submodule are The n coded state quantum bits obtained by encoding and mapping the mapping submodule are: The processing submodule includes: a collapse processing submodule and an entanglement processing submodule: The collapse processing submodule is used for the server to process the images y1, y2, ..., y of the n groups of trapdoor injective functions sent by the client. n , for the plurality of coded state quantum bits Perform collapse processing: measure the last register based on yk and collapse the coded state quantum bit to |b k >|x k >, discard the original image x k The register where the state of the reserved |b k > Perform Hadamard gate calculation to obtain collapsed state quantum bits The entanglement processing submodule is used for the server to perform entanglement processing: Based on CZ e The gate performs hypergraph entanglement calculation to obtain the multiple encrypted hypergraphs Enc(|H>).
10. The blind quantum computing device according to claim 9, characterized in that The stabilizer is where X i =(|+><+|-|-><-|) i , g i is the stabilizer corresponding to the i-th bit of the at least one encrypted hypergraph state; The detection module is also used based on The Pauli test is performed on the encrypted hypergraph state to obtain the stabilizer g i The test results are The result of the Pauli X measurement on the i-th bit of the encrypted hypergraph is x i The value is 0 or 1, and the result of the Pauli Z measurement of the jth bit of the encrypted hypergraph state is z j The value is 0 or 1; The verification module is also used as a stabilizer g i The test results When the decrypted data of the multiple encrypted hypergraphs are verified to be correct, when the stable sub-g i The test results If it is not established, verify that the decrypted data of the multiple encrypted hypergraphs are wrong; wherein, the b i Key b k The i-th bit of The computing module is further configured to, when verifying that the decrypted data of the plurality of encrypted hypergraphs by the client is correct, execute quantum computing on the correct plurality of encrypted hypergraphs by the quantum server and send the ciphertext computing result to the client; the client executes quantum computing on the correct plurality of encrypted hypergraphs based on the key b k Decrypt and obtain the plaintext calculation result.