Blind quantum calculation provable deletion method based on quantum input

By generating quantum bit brick states in blind quantum computing and using quantum one-time pads and Hadamard gate operations, the problem of insufficient user input privacy in existing technologies is solved, the provable deletion of quantum input is achieved, and the security of blind quantum computing is enhanced.

CN120675700APending Publication Date: 2025-09-19XIANGTAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411337972.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-25
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing blind quantum computing protocols cannot ensure the privacy of user input after the calculation is completed, especially when the key and algorithm are leaked, the server may deduce the user's output or input, and the existing provable deletion framework only applies to classical input and not quantum input.

Method used

A blind quantum computing provable deletion method based on quantum input is proposed. Through four stages of preparation, encryption, calculation, deletion and verification, the brick state of quantum bits is generated and quantum one-time pad and Hadamard gate operations are used to ensure the privacy of user input.

Benefits of technology

It ensures that the server cannot restore the quantum state input by the user after the calculation is completed, enhances the security of blind quantum computing, ensures that user data is hidden in information theory, and even resists attacks with unlimited computing power.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675700A_ABST
    Figure CN120675700A_ABST
Patent Text Reader

Abstract

The invention provides a blind quantum calculation proof deletion method based on quantum input. The method comprises the following steps: a user firstly generates a Pauli key for encrypting quantum input, a classic key for verifying a deleted certificate and quantum bits for calculation; the user encrypts quantum input by using a quantum one-time pad method, generates a quantum bit sequence according to the verification key and sends the quantum bit sequence to the server; the server generates a brick state according to the requirement of a user, then measures each non-output quantum bit in the brick state one by one, and returns a measurement result to the user; after all the quantum bits are measured, the server measures the quantum bit sequence generated by the verification key by using a Hardcard base, and the measurement result is recorded as a deletion certificate and is sent to the user; and the user judges whether the server deletes the input data by checking the accuracy of the deletion certificate. According to the method, the provable deletion operation in the blind quantum calculation taking the quantum state as the input is realized, and the safety of the blind quantum calculation is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a blind quantum computing provable deletion method based on quantum input, and belongs to the field of quantum computing and quantum cryptography. Background Art

[0002] Quantum computing technology is rapidly developing, but due to the prohibitive cost of building and maintaining quantum computers, ordinary users are likely to rely solely on cloud computing to access their computing power. However, delegating computing tasks to remote quantum cloud servers can lead to the leakage of private information. To address this issue, blind quantum computing (BQC) has been proposed.

[0003] Blind quantum computing allows users with limited quantum capabilities to delegate computational tasks to a remote quantum cloud server, while ensuring the privacy of the user's input, output, and algorithm. In 2005, Childs proposed the first BQC protocol based on a circuit model (A.M. Childs, Secure Assisted Quantum Computation, Quantum Inf Comput, vol. 5, no. 6, pp. 456-466, 2005). Subsequently, Broadbent, Fitzsimons and Kashefi proposed a universal BQC protocol based on the measurement model, namely the BFK protocol (A. Broadbent, JF Fitzsimons, and E. Kashefi, Universal blind quantum computation, in Proceeding of the 50th Annual IEEE Symposium on Foundations of Computer Science, 2009, pp. 517-526.), and physically implemented the protocol using a four-qubit cluster state (S. Barz, E. Kashefi, A. Broadbent et al., Demonstration of blind quantum computing, Science, vol. 335, no. 6066, pp. 303-308, 2012.).Since then, BQC has been widely studied in various aspects, including increasing the number of servers to support fully classical clients (T. Morimae and K. Fujii, Secure entanglement distillation for double server blind quantum computation, Phys. Rev. Lett., vol. 111, no. 2, art. no. 20502, 2013.), extending the single-client protocol to accommodate multi-client situations (E. Kashefi and A. Pappa, Multiparty delegated quantum computing, Cryptography, vol. 1, no. 2, pp. 12-32, 2017.), introducing verification methods (J. F. Fitzsimons and E. Kashefi, Unconditionally verifiable blind quantum computation, Phys. Rev. A, vol. 96, art. no. 012303, 2017.), and serving different types of clients in distributed networks (J. Quan, Q. Li, and L. Li, Verifiable blind quantum computation with identity authentication for multi-type clients, IEEE Trans.Inf.Forensics Secur, vol.19, pp.1687-1698, 2024.).

[0004] However, a potential risk of these BQC protocols is their inability to ensure privacy outside the computational process. If the user's key and algorithm are leaked after the protocol is complete, the server could potentially deduce the user's output or even input. Recently, Bartusek and Khurana developed a quantum encryption with provable deletion (QECD) framework (J. Bartusek and D. Khurana, Cryptography with certified deletion, in Advances in Cryptology-CRYPTO 2023, 2023, pp. 192-223.). This framework allows a participant who stores quantum ciphertext to present a classical certificate proving that the encrypted plaintext has been deleted, making it unrecoverable even by an attacker with unlimited computational power. The framework incorporates multiple cryptographic primitives, including a blind delegation protocol with certified deletion. This protocol, for the first time, applies QECD to delegated computation to address potential privacy leaks after computation. However, it has two limitations. First, it relies on classical homomorphic encryption and therefore only works with classical inputs, not quantum inputs. Second, the protocol requires the algorithm to be public, whereas BQC ensures the privacy of the client's algorithm, thereby improving security.

[0005] Therefore, if QECD can be applied to BQC, that is, after the BQC calculation is completed, the server can present a deletion certificate for the user input data, then the security of BQC can be further enhanced, which is also of great practical significance for protecting user privacy. Summary of the Invention

[0006] This invention proposes a blind quantum computation method for provable deletion based on quantum input. When the user's input is in a quantum state and the computation is complete, the server must present the user with a deletion certificate. Once the certificate is verified by the user, even with unlimited server computing power, the user's input cannot be recovered. The core method of this invention consists of five stages: preparation, encryption, computation, deletion, and verification.

[0007] Preparation phase: The user determines the brick state structure graph G = (V, E) corresponding to his calculation, and then prepares |V| qubits for calculation based on the number of vertices in the graph |V| = n×m where x = 1,…,n, y = 1,…,m and θ x,y ∈{0,π / 4,2π / 4,…,7π / 4}; the user inputs each qubit state |ψ i >Prepare the key a required for quantum one-time pad i ∈{0,1},ξ i ∈{0,π / 4,2π / 4,…,7π / 4}, a classic random bit ti ∈{0,1} and as the verification key vk i Classic bit string in And λ is a security parameter.

[0008] Encryption phase: For the i-th input quantum bit, the user uses a random classical bit t i Encrypted quantum one-time pad key a i ,ξ i Then, the encrypted key is used to perform a quantum one-time pad operation on the input quantum bit, and the verification key vk i Bit string and Generate the corresponding quantum bit string sequence The first part of the encrypted ciphertext can be expressed as

[0009]

[0010] Then, the user uses random classical bits t i Encrypted verification key bit string Generate the second part of the ciphertext

[0011]

[0012] Calculation phase: The user sends all encrypted ciphertexts and calculation qubits to the server, and the server then entangles these qubits through the CZ gate according to the user's instructions to generate the corresponding brick state. For each qubit in the brick state, the user calculates a measurement angle δ x,y And send it to the server, the server uses the measurement base Perform measurement operations on the corresponding quantum bits and send the measurement results s x,y The result is returned to the user, who then corrects the calculation result and calculates the next measurement angle. The above process is repeated until all qubits in the brick state are measured.

[0013] Deletion phase: The quantum bit sequence in the ciphertext for the i-th input quantum bit The server performs a measurement operation on them using the Hadamard basis, and the measurement result is a classic bit string, recorded as the deletion certificate cert i .

[0014] Verification phase: User verifies each deleted certificate cert i If each certificate passes the user's verification, it can be considered that the server has deleted all the user's input data.

[0015] Compared to previous solutions, this invention enables provable deletion operations for blind quantum computations whose input is quantum states. This ensures the security of user data because the user's algorithm is also hidden from the server. Furthermore, once the deletion certificate generated by the server is verified by the user, the user's input can be considered information-theoretically hidden. This means that even a server with infinite computing power cannot recover the user's input data, which undoubtedly further enhances the security of blind quantum computations. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly describes the drawings required for use in the embodiments. The following drawings illustrate only certain embodiments of the present invention and should not be construed as limiting the scope of the present invention. Persons skilled in the art will be able to derive other relevant drawings based on these drawings without inventive effort.

[0017] Figure 1 It is a schematic diagram of the main process of the present invention.

[0018] Figure 2 Schematic diagram of interaction between two parties in an example of the present invention.

[0019] Figure 3 Brick state used in the present invention |G n×m >.

[0020] Figure 4 The brick state generated by the server according to the user's requirements in the present invention |G n×(m+1) >. DETAILED DESCRIPTION

[0021] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0022] A blind quantum computing provable deletion method based on quantum input, Figure 1 The main flow chart of the present invention is shown. In its specific implementation, it is assumed that Alice is the user, Bob is the quantum cloud server, and the user has the status The n input qubits, and the desired calculation is Figure 2 The following is a schematic diagram showing the interaction between two parties in an example of the present invention. The specific steps are as follows:

[0023] 1. Preparation

[0024] (1a) Alice determines the brick state |G of size n × m corresponding to the computation U she wants to perform. n×m >(such as Figure 3 As shown), where n represents the number of rows and m represents the number of columns;

[0025] (1b) For each row x = 1, ..., n and each column y = 1, ..., m, Alice randomly chooses an angle θ x,y ∈{0,π / 4,2π / 4,…,7π / 4}, and generate quantum bits

[0026] (1c) For each quantum input |ψ i >(1≤i≤n), Alice randomly samples a classical bit string of length λ in And λ is a security parameter, the bit string is the classic verification key, denoted as vk i =(h i ,ω i );

[0027] (1d) For each quantum input |ψ i >(1≤i≤n), Alice randomly chooses a i ,t i ∈{0,1},ξ i ∈{0,π / 4,2π / 4,…,7π / 4},i=1,2,…,n;

[0028] 2. Encryption phase

[0029] (2a) For each quantum input |ψ i >(1≤i≤n), Alice encrypts it using the quantum one-time pad to obtain And generate the first part of the ciphertext

[0030]

[0031] in And H represents Hardmard gate;

[0032] (2b) Similarly, for each quantum input |ψ i >(1≤i≤n), Alice also needs to calculate the second part of the ciphertext

[0033]

[0034] Therefore, the i-th quantum input |ψ i The ciphertext of > is ct i =[ct (1,i) ||ct(2,i) ];

[0035] 3. Calculation phase

[0036] (3a) Alice will calculate the qubit And the ciphertext ct i Send to quantum server Bob;

[0037] (3b) After Bob receives all the qubits, he sets the qubit state to and Use CZ gate to entangle and generate Figure 4 The brick state shown |G n×(m+1) >

[0038] (3c) For column y = 0 and each row x = 1, ..., n, Alice calculates the angle and

[0039]

[0040] where r x,0 Alice randomly selects the angle δ from the set {0,1}. x,0 Send to server Bob;

[0041] (3d) For each row x = 1, ..., n and each column y = 1, ..., m, Alice calculates the angle

[0042] δ x,y =φ′ x,y +θ x,y +πr x,y ,in They belong to the quantum bit |ψ x,y >X dependency set Dependent collections with Z And r x,y Alice randomly selects the angle δ from the set {0,1}. x,y Send to server Bob;

[0043] (3e) When Bob receives a measurement angle δ x,y , he used the measurement basis Perform a measurement operation on the quantum bit at row x and column y,

[0044] And the measurement results s x,y Return to user Alice;

[0045] (3f) When user Alice receives the measurement result s x,y , she based on r x,yThe value of determines whether to flip bit s x,y Specifically, if r x,y =1, then Alice flips s x,y Otherwise, she does nothing;

[0046] (3g) Repeat steps (3c)-(3f) until all qubits are measured.

[0047] 4. Deletion phase

[0048] (4a) For 1≤i≤n, Bob has a quantum sequence Each quantum bit in the Hardmard basis is measured, and the measurement result is recorded as a classical bit string This classic bit string Considered a classic certificate i ;

[0049] (4b) Bob will send all classic certificates i (1≤i≤n) is returned to user Alice.

[0050] 5. Verification phase

[0051] (5a) For each certificate cert i (1≤i≤n), Alice uses the corresponding verification key vk i =(h i ,ω i ) to check its correctness. Specifically, Alice judges that when hour, and Are they equal? ​​If they hold for all j (1≤j≤λ), then the verification is passed.

[0052] The above embodiments are intended only to illustrate the implementation of the present invention and are not intended to limit the scope of the present invention. Under the design principles of the present invention, modifications, transformations, and replacements that are simple and intuitive for professionals in the field and do not deviate from the technical solutions of the design principles of the present invention will still fall within the scope of protection of the present invention.

Claims

1. A blind quantum computing provable deletion method based on quantum input, characterized in that: The user has status The calculation that the user needs the server to perform can be expressed as The method comprises the following five stages: Preparation phase: The user determines the brick state structure graph G = (V, E) corresponding to his calculation, and prepares |V| qubits for calculation according to the number of vertices in the graph |V| = n×m where x = 1,…,n, y = 1,…,m and θ ,x,y ∈{0,π / 4,2π / 4,…,7π / 4}; the user inputs each qubit state |ψ i >Prepare the key a required for quantum one-time pad i ∈{0,1},ξ i ∈{0,π / 4,2π / 4,…,7π / 4}, a classic random bit t i ∈{0,1} and as the verification key vk i Classic bit string in And λ is a safety parameter; Encryption phase: For the i-th input quantum bit, the user uses a random classical bit t i Encryption key used as quantum one-time pad a i ,ξ i After that, the encrypted key is used to perform a quantum one-time pad operation on the input quantum bit, and then the verification key vk i Bit string and Generate the corresponding quantum bit string sequence The first part of the encrypted ciphertext can be expressed as Then, the user uses random classical bits t i Encrypted verification key vk i The bit string in Generate the second part of the ciphertext Calculation phase: The user sends all encrypted ciphertexts and calculation qubits to the server, which then entangles these qubits through the CZ gate according to the user's instructions to generate the corresponding brick state; for each qubit in the brick state, the user calculates a measurement angle δ x,y And send it to the server, and then the server uses the measurement base Perform measurement operations on the corresponding quantum bits and send the measurement results s x,y The result is returned to the user, who then corrects the calculation result and calculates the next measurement angle. The above process is repeated until all qubits in the brick state are measured. Deletion phase: The quantum bit sequence in the ciphertext for the i-th input quantum bit The server performs a measurement operation on the Hadamard basis and then records the measurement result in the form of a classic bit string as the deletion certificate cert i ; Verification phase: User verifies each deleted certificate cert u If each certificate passes the user's verification, it can be considered that the server has deleted all the user's input data.

2. The method for provably deleting a quantum input-based blind quantum computation according to claim 1, wherein: During the preparation phase: The user determines the corresponding brick state structure graph G = (V, E) according to his algorithm U, where V represents the vertex in the graph and |V| = n × m, n represents the number of rows, and m represents the number of columns; a random quantum bit is generated for each vertex in the graph G where x = 1,…,n, y = 1,…,m and θ ,x,y ∈{0,π / 4,2π / 4,…,7π / 4}; and, for each qubit input |ψ i >, each user needs to generate a key a for quantum one-time pad i ∈{0,1},ξ i ∈{0,π / 4,2π / 4,…,7π / 4},i=1,2,…,n, a classic random bit t i ∈{0,1}, and as the verification key vk i Classic bit string in And λ is a security parameter.

3. The method for provably deleting a quantum input-based blind quantum computation according to claim 1, wherein: During the encryption phase: For each input qubit |ψ i >, the user encrypts it using the quantum one-time pad And generate the first part of the ciphertext based on the classic verification key And the second part of the ciphertext Thus, for the quantum input |ψ i >The encrypted ciphertext can be expressed as ct i =[ct (1,i) ||ct (2,i) ].

4. The method for provably deleting a quantum input-based blind quantum computation according to claim 1, wherein: During the calculation phase: The server needs to convert the quantum bit|+ θx,y >with Use CZ gate to entangle to generate brick state |G n×(m+1) > For brick state |G n×(m+1) >In the first column of qubits, the user calculates the angle according to his own algorithm U and where r 0,y Randomly select from the set {0,1}; the server uses the measurement basis {|+ δx,y >,|- δx,y >} Perform measurement operations on the corresponding quantum bits and return the measurement result s x,y , if r x,y =1, the user needs to flip s x,y The bit value of r x,y =0, the user does not need to do anything else.

5. The method for provably deleting a quantum input-based blind quantum computation according to claim 1, wherein: During the deletion phase: For each qubit input ciphertext ct i The first part The server's corresponding quantum sequence Perform Hardmard basis measurement and record the measurement result as a classical bit string This classic bit string Considered a classic certificate i .

6. The method for provably deleting a quantum input-based blind quantum computation according to claim 1, wherein: During the verification phase: For each certificate cert i (1≤i≤n), each user needs to use the corresponding verification key vk i =(h i ,ω i ) to check its correctness; Specifically, users need to judge when hour, and Are they equal? ​​If they hold for all j (1≤j≤λ), then the verification is passed.