Improved block chain system and method

By employing a quantum analogy proof-of-work consensus method and utilizing boson sampling experiments to generate verification data, this approach addresses the vulnerability of traditional consensus algorithms to ASICs and quantum computers, achieving low energy consumption and secure scalability for blockchain.

CN121866567APending Publication Date: 2026-04-14BTQ AG
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-05-27
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

Traditional proof-of-work consensus algorithms are vulnerable to dedicated processors and quantum computers, leading to high energy consumption and security issues, making it difficult to maintain the scalability and security of blockchains in the post-quantum era.

Method used

The quantum analogy proof-of-work consensus method is adopted, and verification data is generated through boson sampling experiments. Blockchain verification is performed using boson sampling units and processing units to ensure the robustness and energy efficiency of the consensus process.

Benefits of technology

Effectively resist the speedup advantage of quantum computers, reduce blockchain operating costs, maintain the security and scalability of the blockchain, and ensure the fairness and robustness of the consensus process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121866567A_ABST
    Figure CN121866567A_ABST
Patent Text Reader

Abstract

The invention relates to a quantum analogy workload proof consensus method for a block chain network. The method includes receiving, from a plurality of different miners of the blockchain network, a plurality of verification data obtained using a bose sampling experiment associated with a candidate block. Each verification data may be associated with a different miner, and wherein each miner performs the bose sampling experiment using at least some of the information included in the candidate block. The method may include analyzing the received plurality of verification data to determine whether a consensus has been reached; and when a consensus is reached, adding the candidate block to a block chain associated with the block chain network.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] The security of blockchain technology relies, at least in part, on the ability of participants in a peer-to-peer network to reach consensus in an environment without a centralized verification authority to validate and verify a new set of block-packed transactions (i.e., a new block to be added to the existing blockchain). A consensus algorithm is the process by which all nodes in a blockchain network reach a common agreement on the current state of the distributed ledger. One of the most thoroughly tested consensus algorithms, proven robustness and security, is Proof-of-Work (PoW). PoW involves selecting a mining rig to create blocks based on the earliest solution to a one-way function, which is traditionally a reverse hashing problem. The structure of the one-way function is chosen so that its parameters depend on the current block information, making precomputation infeasible, and the problem is also non-progressive, meaning the probability of successfully mining a block increases linearly with the time or equivalent work required to solve the problem (reverse hashing).

[0002] At least two issues threaten the continued scalability of the Proof-of-Work (PoW) consensus algorithm. First, problems used in PoW consensus, such as reverse hashing, can be solved by dedicated processors (e.g., Application-Specific Integrated Circuits (ASICs), which are extremely energy-intensive. This is necessary to maintain a constant average block mining time to avoid inflationary pressures on asset-based blockchains (such as Bitcoin with mining rewards) and to maintain the integrity of the protocol in the presence of network latency and growth. This means that as the computational speed of ASICs increases, the difficulty of one-way functions must increase, thus increasing the energy cost of mining. Second, the traditional form of PoW assumes that only classical computers are available as mining resources. Quantum computers, through amplitude amplification, can achieve quadratic speedups in solving unstructured problems such as reverse hashing, meaning they no longer satisfy the no-progression condition, as the probability of solving the problem increases non-linearly with the computational time spent. Adversarial networks of quantum computers executing traditional PoW consensus will have dynamics drastically different from their classical counterparts. Therefore, future-proof consensus algorithms must be able to mitigate the effects of quantum processing. Summary of the Invention

[0003] The quantum analogue proof-of-work consensus scheme disclosed in this paper provides an alternative to the consensus algorithms used in current blockchain networks. The embodiments of the methods and systems disclosed herein address the security threats posed by quantum general-purpose computers and quantum computers to current proof-of-work consensus algorithms, and provide a more cost-effective and energy-efficient implementation than existing supercomputers currently used to execute consensus algorithms.

[0004] According to one aspect of this disclosure, a quantum analogous proof-of-work consensus method for a blockchain network is provided. The method may include: receiving from multiple different miners of the blockchain network multiple verification data obtained using boson sampling experiments associated with candidate blocks. Each verification data may be associated with a different miner, and each miner performs the boson sampling experiment using at least some information included in the candidate block. The method may include analyzing the received multiple verification data to determine whether consensus has been reached; and when consensus is reached, adding the candidate block to the blockchain associated with the blockchain network.

[0005] According to another aspect of this disclosure, a quantum analogous proof-of-work consensus method for a blockchain network is provided. The method may include: receiving candidate blocks comprising multiple transaction data; generating verification data by performing a boson sampling experiment using information included in the candidate blocks; and sending the verification data to a verification server included in the blockchain network, the verification data enabling the verification server to determine whether consensus has been reached.

[0006] According to some embodiments, information defining the initial input state of the boson sampling experiment can be obtained from the candidate blocks. Similarly, information defining the optical configuration of the optical network used for the boson sampling experiment can also be obtained from the candidate blocks. According to some embodiments, the information included in the candidate blocks can be mapped to different parameters of the boson sampling experiment. This mapping can be predefined among the mining machines of the blockchain network. In this way, the information included in the candidate blocks can be used to perform boson sampling experiments.

[0007] At least some of the quantum analogy proof-of-work consensus methods disclosed in this paper offer advantages over traditional consensus algorithms. The use of boson sampling experiments effectively addresses the dual challenges posed by the emerging threats of energy-intensive ASICs and quantum computers. Unlike classical Proof-of-Work (PoW) which relies on computationally intensive hashing, quantum analogy methods are more energy-efficient, reducing the environmental impact and operational costs of maintaining the blockchain. Furthermore, at least some of the methods disclosed in this paper are inherently resistant to the quadratic speedup advantage of quantum computers, ensuring the integrity and security of blockchains in the post-quantum era. At least some of the consensus algorithms disclosed in this paper not only retain the no-progression condition necessary for fair mining but also provide robust mechanisms for reaching consensus, thereby enhancing the overall scalability and resilience of the blockchain network. Attached Figure Description

[0008] Exemplary, non-limiting embodiments of this disclosure will be described with reference to the accompanying drawings, in which:

[0009] Figure 1This is a schematic diagram of a networked computer system configured according to embodiments disclosed herein to implement a blockchain including a quantum proof-of-work consensus scheme;

[0010] Figure 2 yes Figure 1 A detailed schematic diagram of a blockchain mining machine in a networked computer system;

[0011] Figure 3A This is a flowchart illustrating a method for implementing a quantum analog proof-of-work consensus scheme, performed according to at least some of the embodiments disclosed herein;

[0012] Figure 3B This is a flowchart illustrating a method for analyzing multiple received verification data, performed according to at least some of the embodiments disclosed herein;

[0013] Figure 3C This is a flowchart illustrating a method for authenticating multiple received verification data, performed according to at least some of the embodiments disclosed herein;

[0014] Figure 3D This is a flowchart of a method for approving multiple certified verification data, performed according to at least some of the embodiments disclosed herein;

[0015] Figure 3E This is a flowchart of a method for determining whether verification data generated by a mining machine meets threshold conditions, performed according to at least some of the embodiments disclosed herein;

[0016] Figure 4 This is a table showing examples of multiple verification data according to at least some of the embodiments disclosed herein;

[0017] Figure 5 It shows the use of Figure 4 The exemplary mode-binned distribution and the real mode-binned distribution performed on the validation data are shown.

[0018] Figure 6 It shows the use of Figure 4 The exemplary state binning distribution and the real state binning distribution are performed on the verification data;

[0019] Figure 7A Based on at least some of the embodiments disclosed herein Figure 1 An exemplary schematic diagram of the hardware implementation of a mining machine in the image;

[0020] Figure 7B Based on at least some of the embodiments disclosed herein Figure 1 Another exemplary schematic diagram of the hardware implementation of a mining machine in the image;

[0021] Figure 7C Based on at least some of the embodiments disclosed herein Figure 1 Another exemplary schematic diagram of the hardware implementation of a mining machine in the diagram; and

[0022] Figure 8 It is a graph showing the energy performance of quantum boson samplers, supercomputers, and single-core computers. Detailed Implementation

[0023] The following detailed description includes references to the accompanying drawings. Where possible, the same reference numerals are used in the drawings and description to refer to the same or similar parts and / or processes. Although several illustrative embodiments are described herein, modifications, adaptations, and other implementations are possible. For example, parts shown in the drawings may be replaced, added, or modified, and the illustrative methods described herein may be modified by replacing, reordering, removing, or adding steps to the disclosed methods. Therefore, the following detailed description is not limited to the disclosed embodiments and examples. Rather, the appropriate scope is defined by the appended claims.

[0024] I. System Overview

[0025] Figure 1 This is a schematic diagram of a networked computer system 101 configured to implement a blockchain including a quantum proof-of-work (PoW) consensus scheme, according to embodiments of this disclosure. For example, such a blockchain can be used as a digital ledger for electronic transactions (TX), but it should be understood that any type of data can be stored on the blockchain, and references to a digital ledger for electronic transactions are for non-limiting illustrative purposes only. The type of data stored on the blockchain is not important for this purpose.

[0026] Electronic transaction data generated by different users are collected and stored in the transaction pool repository 103 via a shared communication network 105. For example, first transaction data TX1 associated with a first user at a first user terminal 107, second transaction data TX2 associated with a second user at a second user terminal 109, third transaction data TX3 associated with a third user at a third user terminal 111, and fourth transaction data TX4 associated with a fourth user at a fourth user terminal 113 are sent to the transaction pool 103 via the shared communication network 105. The transaction data received by the transaction pool 103 is stored for further processing by at least one of multiple blockchain mining machines 115, 117, 119, and 121.

[0027] Once a predetermined threshold condition is met, at least one blockchain mining machine 115, 117, 119, 121 receives multiple transaction data (TX1...TX4) stored in transaction pool 103 for processing. For example, the predetermined threshold condition may relate to a predetermined number of electronic transactions stored in transaction pool 103. The received transaction data is batch-processed by at least one blockchain mining machine 115, 117, 119, 121. Alternatively, once the threshold condition is met, at least one blockchain mining machine 115, 117, 119, 121 acquires multiple transaction data. The acquired or received transaction data (as applicable) is processed by at least one blockchain mining machine to generate a new candidate block 123 to be added to the existing blockchain, and / or to generate a new candidate block 123 for a new blockchain. The new candidate block 123 is then distributed to multiple blockchain mining machines 115, 117, 119, and 121 via communication network 105, enabling the quantum consensus proof-of-work scheme to be executed by each participating mining machine 115, 117, 119, and 121.

[0028] As background, the process of generating blocks and adding them to a blockchain is commonly referred to as "mining." The mining process includes several different steps, including generating candidate blocks, validating candidate blocks, and adding candidate blocks to the blockchain. The process of validating candidate blocks may itself include several different steps, including, for example, implementing a consensus scheme. Therefore, once candidate block 123 is generated, it is verified by validator 125 to ensure that the candidate block has been correctly generated before it is added to an existing blockchain or used to launch a new blockchain (as the case may be). For example, the verification process may include multiple blockchain miners 115, 117, 119, and 121 sending verification data associated with candidate block 123 to validator 125 via communication network 105 for verification. Validator 125 analyzes the verification data received from each of the multiple blockchain miners 115, 117, 119, and 121, and sends a reward to each miner whose verification data meets a threshold condition determined based on the analysis of the associated verification data. After verification, the candidate block is added to the blockchain.

[0029] although Figure 1 For illustrative purposes, mining machines and validators are represented as separate entities, but any mining machine can also function as a validator. Conversely, any validator can also function as a mining machine.

[0030] II. Blockchain Mining Machine

[0031] Figure 2 yes Figure 1Detailed schematic diagrams of blockchain mining machines 115, 117, 119, and 121 are shown below. As illustrated, blockchain mining machines 115, 117, 119, and 121 may include a processing unit / processor 210 and a boson sampling unit 220. The boson sampling unit 220 can refer to any hardware device capable of providing samples from a boson sampling distribution. Various hardware implementations of the boson sampling unit 220 are envisioned (see, for example, [link to relevant documentation]). Figures 7A-7C ).

[0032] like Figure 2 As shown, the boson sampling unit 220 may include, but is not limited to, a single-photon source matrix 222, a linear optical network 224, and a single-photon detector matrix 226. The linear optical network 224 can refer to any optical system having an equal number of input ports and output ports (referred to as modes (M)) and multiple different optical paths connecting the input and output modes. Therefore, the linear optical network 224 can be mathematically characterized by an M x M unitary matrix (U), which mathematically describes how the state of the input photon transitions as it passes through the linear optical network 224. According to some embodiments, the unitary matrix U may correspond to a pseudo-Haar random matrix. The single-photon source matrix 222 can be configured to provide a single photon at one or more input modes of the linear optical network 224; in other words, the single-photon source matrix 222 can be configured to generate an input (Fok) state of the following form:

[0033]

[0034] in =0 or 1 represents the number of photons in the i-th input mode, M is the number of input modes and output modes, and N is the total number of photons in the input state (N≤M). It is the generator operator for input pattern i. In other words, the input state is one of the different possible combinations (i.e., the way to distribute N photons among M input patterns).

[0035] As input photons pass through a linear optical network, their states undergo a transformation. Mathematically, the input states are modified by the linear optical network 224, described by U, which performs linear transformations on the generation (and annihilation) operators of the input modes.

[0036]

[0037] It follows the system's output state vector |Ψ out > is the superposition of all possible output configurations. Each output configuration relates to a different observable output, i.e., how N photons are distributed among M output ports after passing through a linear optical network 224.

[0038]

[0039] Where S is the output configuration. ∈[0, N] is the number of photons in the i-th output mode associated with configuration S. It is the probability amplitude associated with configuration S. In the case of lossless linear optical network 224, That is, the total number of photons N is conserved. The value is related to the sum of matrix products:

[0040]

[0041] U S It is an N x N submatrix of U, Per(U) S ) is its product summation. The probability of measuring the output configuration S is given by | | 2 Given. To maintain complexity, the unitary matrix U should avoid any structure that might facilitate the computation of the product sum. Examples of such structures include matrices with multiple repeating rows / columns or diagonal matrices (whose product sum is simply the product of all diagonal elements). Without loss of generality, computation of the product sum matrix can be a #P hard problem, and general-purpose quantum computers cannot compute the product sum matrix exactly in a more efficient way.

[0042] The single-photon detector matrix 226 can be configured to detect the presence of one or more photons at each output mode of the linear optical network 224. Therefore, the output of the single-photon detector matrix 226 can detect a specific output configuration S, and its output can take the form of a vector | This takes the form of a sample from a boson sampling distribution. Without loss of generality, the number N of different output state configurations... S as follows,

[0043]

[0044] This is super-exponential over N.

[0045] exist Figure 2 In the example shown, the linear optical system 224 has 4 ports M, and the input configuration includes two single photons in two of the four input modes. As shown, the two single photons occupy the first two input ports of the linear optical network 224 (represented by shaded circles). The two remaining ports are in a vacuum state (represented by unshaded circles). This can be mathematically represented as |1,1,0,0>.

[0046] although Figure 2This indicates that the number of ports M equals 4 and the number of input photons N equals 2. However, it should be understood that these numbers are not restrictive; any number of ports M and any positive number of input photons N can be chosen, as long as (N≤M). In other words, the number of ports M must be greater than or equal to the number of input photons.

[0047] Any of the boson sampling experiment parameters (i.e., the number of input photons N, the system's input state, the number of output / input ports M, the unitary transform U, or a combination thereof) can be selected as a function of information associated with and / or included in the candidate block 123 to be added to the blockchain. For example, the input state can be selected as a function of the hash value of the header of candidate block 123. Furthermore, the number of input photons N, the input state, the number of output / input ports M, and the unitary transform U can be determined from information associated with and / or included in candidate block 123. According to some embodiments, a mapping convention can be predetermined and shared among miners 115, 117, 119, and 121, which maps the information included in candidate block 123 to any of the aforementioned boson sampling experiment parameters.

[0048] Alternatively, according to some embodiments, any one of the following—the number of input photons N, the system's input state, the number of output / input ports M, the unitary transform U, or combinations thereof—can be constant throughout one or more verification processes to simplify practical implementation; that is, the same parameters can be used to verify one or more different candidate blocks 123. In this case, the set of parameters can be communicated throughout the network before the verification process begins.

[0049] In M~N 2 In scenarios where the probability of two or more photons arriving at the same output port of a linear optical system is statistically negligible, the number of possible output configurations is reduced to:

[0050]

[0051] This situation can be called a collision-free mechanism. Under this mechanism, =0 or 1, the output of the single-photon detector matrix 226 can be expressed as a binary vector | In the form of.

[0052] Processing unit / processor 210 may include one or more types of processing devices. For example, any one or more of a microprocessor, preprocessor, central processing unit, support circuitry, digital signal processor, integrated circuit, memory, or any other processing device. Processing unit / processor 210 may be configured to communicate with communication network 105 and components 222, 224, 226 of boson sampling unit 220. Communication may include exchanging data with any of these components and / or sending one or more instructions to one or more components. For example, processing unit / processor 210 may instruct which port of single-photon source matrix 222 to generate photons in preparation of an input state.

[0053] In embodiments where optical loss exists in the linear optical network 224, any of the blockchain miners 115, 117, 119, and 121 can retroactively select only those samples where the total number of measured photons equals the number of input photons N. Similarly, the efficiency of the single-photon detector matrix 226 may not be 100%, in which case photons may be present at the detector but not detected, thus requiring retroactive selection. Assuming the loss in the linear optical network 224 is uniform and the efficiency of the single-photon detector matrix is ​​uniform, the distribution is expected to remain unchanged during retroactive selection. However, the sampling rate of the blockchain miners 115, 117, 119, and 121 may decrease.

[0054] III. Quantum Proof-of-Work (PoW) Consensus Scheme

[0055] Figure 3A The illustration shows a verification process performed by verifier 125 according to some embodiments for verifying candidate block 123 using a quantum analogous proof-of-work (PoW) consensus scheme. Once candidate block 123 is transmitted via communication network 105 to an initial plurality of miners 115, 117, 119, 121, the process of verifying candidate block 123 using the quantum PoW consensus scheme can be executed.

[0056] In step 302, verifier 125 receives multiple different verification data from miners 115, 117, 119, and 121. Each verification data is obtained using a boson sampling experiment associated with candidate block 123, and each different verification data is associated with a different miner 115, 117, 119, or 121, which includes a boson sampling unit 220 configured to generate the verification data. Each miner performs the boson sampling experiment using information associated with and / or included in the candidate block.

[0057] According to some embodiments, the verification data is associated with a bit string of a set of output configurations measured by the boson sampling unit 220. In some embodiments, the verification data may also include a timestamp associated with the time when the boson sampling unit 220 measures each output configuration.

[0058] In step 304, verifier 125 analyzes the received verification data. In some embodiments, analysis of the verification data can begin once a threshold condition is met. The threshold condition may relate to a predetermined number of received verification data. The predetermined number may depend on candidate blocks 123. For example, the predetermined number of verification data may include 100, 200, 500, 1000, or any other predetermined number of verification data. The threshold condition may also refer to a predetermined elapsed time period. The predetermined time period may depend on candidate blocks, the sampling rate of the mining rig (i.e., the rate at which the mining rig can generate and measure the output configuration of the boson sampling experiment), or a statistically determined minimum number of verification data.

[0059] Based on the analysis of multiple received verification data, validator 125 may send rewards to at least some of the mining machines 115, 117, 119, and 121 participating in the consensus scheme in step 306. For example, in some embodiments, as will be described in more detail below, the analysis performed by validator 125 may verify which of the multiple received verification data meet the authentication and / or approval process, and only those mining machines 115, 117, 119, and 121 associated with verification data that meet the authentication and / or approval process will receive rewards. Finally, in step 308, validator 125 adds candidate block 123 to the blockchain. In some embodiments, validator 125 may simultaneously add a record to the blockchain along with candidate block 123, proving that consensus has been reached. This record may include different types of information. Examples of information may include one or more parameters (e.g., N, M, U, input state) used by each miner to perform a boson sampling experiment, one or more parameters used by the validator to perform multiple validation data analyses, one or more results obtained from the multiple validation data analyses, or one or more additional types of data (e.g., a predetermined number of received validation data, a predetermined time period).

[0060] Although validator 125 and miners 115, 117, 119, and 121 are described as separate entities, any miner can also function as a validator. Conversely, any validator can also function as a miner.

[0061] Figure 3B It shows in Figure 3AStep 304 includes the steps of verifier 125 analyzing the received multiple verification data. The analysis may include authenticating the received multiple verification data in step 314, subsequently approving the received multiple verification data in step 324, and determining in step 334 whether each of the multiple received verification data meets a threshold condition.

[0062] To enhance security, in some implementations, verification data can be encrypted to prevent fraudulent miners from copying and reclaiming genuinely generated verification data. For example, verification data can be hashed.

[0063] In some embodiments, a hash function can be used to calculate a hash value for the bit string associated with the verification data. In some embodiments, the output configuration of each measurement may be hashed together with its associated timestamp, and optionally any other bit string associated with the miner. It should be understood that any output configuration measured by the boson sampling unit 220 can be associated with a vector, and therefore the hash value of the output configuration is related to the hash value of the associated vector.

[0064] Figure 3C Based on an embodiment of receiving the hash value of the verification data, the method by which the verifier 125 receives the verification data is further illustrated. Figure 3B Step 314 verifies the details of the received multiple verification data. Verifier 125 receives multiple hashed verification data in step 314a. Subsequently, in step 314b, verifier 123 receives a non-hash version of the received hashed verification data. According to some embodiments, non-hashed verification data may be received only after all hashed verification data has been received by verifier 123. If the hashed verification data depends at least partially on any other data (such as timestamp data), that data may be received along with the non-hashed verification data from step 314b. Verifier 125 can then independently calculate the hash value of all received non-hashed data in step 314c. Finally, in step 314d, verifier 125 can compare its determined hash value for each received verification data with the hash value received in 314a. Miners associated with hash values ​​transmitted that differ from the hash value determined by the verifier may be excluded from further participation in the verification process and therefore excluded from receiving rewards.

[0065] Figure 3D According to some embodiments, it is shown how the verifier 125 can... Figure 3AStep 324 approves multiple certified verification data. Validator 125 may select a pattern binning strategy in step 324a. Subsequently, validator 125 may determine the pattern binning distribution for each certified verification data in step 324b, and determine the true pattern binning distribution for multiple certified verification data. In step 324c, validator 125 may determine a validity factor for each certified verification data. Finally, in step 324d, validator 125 may compare the determined validity factor with a validity threshold for each certified verification data to approve or invalidate the associated verification data. Miners associated with invalid verification data are excluded from further participation in the verification process and therefore excluded from receiving rewards. Further details regarding the approval of multiple certified verification data will be provided below. Figure 5 Describe it.

[0066] According to some embodiments, the pattern binning distribution of the certified verification data is associated with multiple output configurations of the boson sampling units 220 of miners 115, 117, 119, and 121. In other words, it is associated with the statistical distribution of the output patterns measured by the miners. The true pattern binning distribution is a reference distribution to which the pattern binning distribution can be compared. The true pattern binning distribution can be calculated based on the unitary matrix U, the input state, and the pattern binning strategy employed. In other words, the true pattern binning distribution can be calculated before the boson sampling experiment is performed, provided that the unitary matrix, the input state, and the adopted pattern binning strategy are known. In contrast, the pattern binning distribution is determined after the boson sampling experiment is performed, based on the observed output patterns.

[0067] Figure 3E According to one embodiment, it is shown how the verifier 125 determines whether the verification data generated by the miners 115, 117, 119, and 121 meets the requirements. Figure 3B The threshold condition at step 334. Validator 125 can determine the state binning strategy to use in step 334a. Subsequently, validator 125 can determine the state binning distribution for each approved validation data in step 334b, and determine the true state binning distribution for multiple approved validation data. In step 334c, validator 125 can determine a success factor for each approved validation data. Finally, in step 334d, validator 125 can compare the associated success factor with the success threshold for each approved validation data. When the success threshold is not met, the associated mining machine will be excluded from receiving rewards. Details of how the threshold condition is determined in some embodiments will be discussed below. Figure 6 Further description.

[0068] IV. Examples of Data Validation

[0069] Figure 4 This is a table showing examples of multiple verification data received from miners 115, 117, 119, and 121, which have... Figure 2 The input state shown is |1,1,0,0>. As shown, miners 115, 117, 119, and 121 each measured the output configuration of boson sampling unit 220 at a specific time. As shown, at least some of miners 115, 117, 119, and 121 measured different numbers of output configurations, thus sending verification data associated with different numbers of binary vectors. The statistical distribution of the binary vectors associated with the received verification data can be determined. These statistics can be performed on the output port or output configuration of linear optical system 224. Furthermore, this distribution can be coarse-grained, which requires equal-sized grouping or binning of the output statistics of boson sampling unit 220. Coarse-grained statistics can be provided according to some given binning tactic (BT) (i.e., a specific way of dividing and rearranging the output configurations into groups (bins). The verification data shown is in a collision-free mechanism (M~N). 2 This is obtained under the following conditions. As with traditional blockchains (e.g., the Bitcoin blockchain), it is assumed that no single mining rig dominates the network, i.e., has more than 51% of the measured output configuration.

[0070] V. Verification of data approval

[0071] The approval of multiple received verification data can include the selection mode binning P as described above. (mb) Mode binning distribution and actual mode binning distribution. Mode binning can refer to the determination of coarse-grained statistics on the output modes (ports) of a linear optical system 224 according to a given mode binning strategy. Any mode binning strategy can be characterized by one or more mode binning parameters, such as the number of mode bins, the size of the mode bin (i.e., the number of output ports associated with that mode bin), or how the output ports are assigned to mode bins (i.e., which output ports are associated with each bin), and can be expressed as π. (mb) According to some embodiments, the number and size of pattern boxes are transmitted throughout network 105 before the verification process begins. The number and size of pattern boxes can be constant throughout one or more verification processes; that is, identical values ​​of these parameters can be used to verify one or more candidate blocks 123. These parameters are intrinsically related to the number of patterns M. In some cases, all pattern boxes are the same size, so the product of size and the number of pattern boxes equals M.

[0072] Figure 5 It shows the use of Figure 4 The exemplary mode binning distribution and the real mode binning distribution are shown in the verification data. Figure 5An exemplary pattern binning strategy 501 is illustrated. According to the illustrated pattern binning strategy 501, four output ports are divided into two bins, each bin comprising two output ports (Binary 1 includes port 1 and port 2, denoted as {1, 2}; Binary 2 includes port 3 and port 4, denoted as {3, 4}). The pattern binning strategy 501 can be determined as a function of the verification data. For example, the pattern binning strategy 501 can be selected as a function of the hash value H of the concatenated versions of all authenticated verification data. Alternatively, the pattern binning strategy 501 can be determined as a function of random pattern binning beacons transmitted throughout the network 105 after the verification process begins (once each miner has sent its verification data). For example, the pattern binning strategy 501 can be selected using a mapping function based on the pattern binning beacons. The pattern binning beacons can be constructed using a post-quantum-safe verifiable random function.

[0073] Figure 5 Four different pattern bin distributions 515, 517, 519, and 521 are shown, corresponding to the data received from miners 115, 117, 119, and 121. Figure 4 The validation data is given. The input state, pattern binning strategy 501, and unitary matrix U are known, and the true pattern binning distribution 503 is also given. The validity factor (V) can be calculated using a classical multinomial-time algorithm. Once the bin distribution of the true pattern is obtained, a validity factor (V) can be determined for each validation data point. If the validity factor is greater than or equal to the validity threshold (β), the associated validation data is invalidated, and the associated mining rig is excluded, as previously stated. If the validity factor is less than the validity threshold (β), the validation data is approved, and the associated mining rig can continue to participate in the validation process.

[0074] The effectiveness factor (V) of mining machine i i Examples can take the following form:

[0075]

[0076] in This is the probability determined for box j and mining machine i. Using Figure 5 The numerical results are used, and β=0.13 is taken as the effectiveness factor V of mining machine D121. DThe value is 0.134. Therefore, based on this, miner D 121 will be excluded, while miners A115, B 117, and C 119 will continue to participate in the verification process. The formula above corresponding to the total variation distance between distributions is exemplary. Other statistical measures, such as Kullback-Leibler divergence, Jensen-Shannon divergence, or Hellinger distance, can be used as alternative methods for calculating the validity factor. The value of β directly affects the number of samples required to distinguish the true pattern bin distribution 503 from another distribution. Changing the value of this parameter not only adjusts the difficulty level required to solve the problem but also regulates the block production time. According to some embodiments, the value of β can be transmitted throughout network 105 before the verification process begins and remains unchanged in one or more verification processes; that is, the same β value can be used to verify one or more candidate blocks 123.

[0077] According to some embodiments, once candidate block 123 is successfully verified, the number of pattern bins d, the pattern binning strategy π, etc. (mb) The distribution of β and true mode binning can be included in the record added to the blockchain along with candidate block 123. Since miners 115, 117, 119, and 121 are unaware of the selected mode binning strategy 501 beforehand, and there exists M! / (M / d)! d Several possible mode binning strategies, even after specifying one or more parameters of the boson sampling experiment, are estimated using a classical supercomputer to estimate the true mode binning distribution. Even if a fraudulent miner generates a random sample set that produces an effective pattern bin distribution within the total variation distance β, the probability is no greater than the probability of correctly guessing the probability in each bin within the β range (except for the last bin, which is given by normalization). This increases the robustness of the consensus mechanism against fraudulent miners. If, under certain circumstances, no miner passes approval step 324, consensus cannot be reached, and candidate block 123 may be rejected.

[0078] VI. Determination of Threshold Conditions

[0079] Determining threshold conditions for multiple approved verification data may include selecting state bins p (sb) State binning distribution and true state binning distribution. State binning can refer to the determination of coarse-grained statistics on the 224 output configurations (S) of a linear optical network according to the selected state binning strategy. Any state binning strategy can be characterized by one or more state binning parameters, such as the number of state bins, the size of the state bin (i.e., the number of output configurations associated with that state bin), or how the output configurations are assigned to state bins (i.e., which output configurations are associated with each bin), and can be expressed as π. (sb)According to some embodiments, as described above, the number and size of state boxes can be transmitted throughout network 105 before the verification process begins. The number and size of state boxes can be constant throughout one or more verification processes; that is, the same values ​​of these parameters can be used to verify one or more candidate blocks 123. These parameters are intrinsically related to the number of modes M and the number of input photons N. In some cases, all state boxes are the same size, so the product of size and number of state boxes equals M! / N!(MN)! (under a collision-free mechanism).

[0080] Figure 6 It shows the use of Figure 4 The verification data demonstrates exemplary state binning distributions and real state binning distributions. For non-limiting purposes, all mining rigs are considered approved. Figure 6 An exemplary state binning strategy 601 is illustrated. Six output configurations are divided into three bins, each bin containing two unique output configurations (e.g., bin 1 contains output configurations {|1,1,0,0>, |1,0,1,0>}; bin 2 contains output configurations {|0,1,1,0>,|1,0,0,1>}; bin 3 contains output configurations {|0,1,0,1>,|0,0,1,1>}). The state binning strategy 601 can be selected as a function of the approved verification data. For example, the state binning strategy 601 can be the hash value H of the concatenated versions of all approved verification data. v Alternatively, the state binning strategy 601 can be determined as a function of random state binning beacons transmitted throughout the network 105 after the verification process has begun (once each miner has sent its verification data). For example, the state binning strategy 601 can be selected based on a mapping function using the state binning beacons. The state binning beacons can be constructed using a post-quantum-safe verifiable random function.

[0081] Four different state bin distributions 615, 617, 619, and 621 are shown, corresponding to the data received from miners 115, 117, 119, and 121. Figure 4 The validation data is shown. The true state binning distribution 603 can be calculated by calculating the expected value of the state binning distribution determined for all validation data. Once the true state binning distribution is obtained, a success factor S can be determined. u If the success factor is less than the success threshold δ, the verification data meets the threshold condition, and the associated mining machine can receive a reward. If the success factor is greater than or equal to the success threshold δ, the verification does not meet the threshold condition, and the associated mining machine is excluded from receiving a reward.

[0082] The success factor of mining machine i Su i Examples can take the following form:

[0083]

[0084] in This represents the peak state binning probability of mining machine i. This represents the net peak state binning probability. The net peak state binning probability is the peak probability of the true state binning distribution.

[0085] refer to Figure 6 As a result, and taking a success threshold δ=0.1, mining machines A115 and D121 will be excluded from receiving rewards because their state bin distributions 615 and 621 differ too much from the true state bin distribution 603 (i.e., Su i >δ). Miners B 117 and C 119 are rewarded. δ can be transmitted throughout the network 105 before the verification process begins and remains unchanged in one or more verification processes; that is, the same δ value can be used to verify one or more candidate blocks 123.

[0086] According to some embodiments, once candidate block 123 is successfully verified, the number of state boxes and the state binning strategy π are determined. (sb) Success threshold δ and net peak state binning probability It can be included in the record added to the blockchain along with candidate block 123.

[0087] Unlike pattern binning distributions, which can be approximated using classical (polynomial) algorithms to determine whether a miner is honest, state binning distributions require actual samples obtained from boson samplers to approximate the peak state binning probability. Therefore, this additional validation layer ensures that samples come from the boson sampling distribution and incentivizes the miner to generate samples using quantum devices. Other incentives for using quantum devices are also implemented during validation, including the reward scheme described below.

[0088] VII. Hardware Embodiment of Boson Sampling Unit 220

[0089] Figures 7A-7C Different exemplary hardware configurations of the boson sampling unit 220 according to different embodiments of the present disclosure are shown. In the illustrated embodiment, the number of input / output ports (M) of the linear optical network 224 is equal to 4, and the number of input photons (N) is equal to 2. However, it should be understood that different numbers of input ports and output ports (M) may be used according to different embodiments, and the illustrated embodiments are for non-limiting illustrative purposes only.

[0090] Figure 7A This is a schematic diagram of a specific boson sampling unit 720A, which includes an optical system with bulk optical elements. Figure 2The three main components described in the text can be identified as follows:

[0091] • The single-photon source matrix 222 comprises four single-photon sources. These single-photon sources can be implemented using various known single-photon source techniques, such as spontaneous parametric down-conversion (SPDC) sources or quantum dot sources. Spontaneous parametric down-conversion produces probabilistically correlated photon pairs. Due to this correlation, detecting a photon in one output implies the presence of another photon in another output, thus allowing probabilistic and declarative single-photon state preparation. When scaled to multiple such sources, this nondeterminism means that the rate of simultaneous state preparation from multiple sources decreases exponentially. This scaling problem can be overcome using multiplexing when a series of declared spontaneous parametric down-conversion sources run in parallel, and then successful photon preparation events are multiplexed to the desired boson sampling input. On the other hand, quantum dot sources can be configured to produce single photons on demand with high probability. In some embodiments, the input photons are synchronized.

[0092] • The single-photon detector matrix 226 comprises four single-photon detectors. Known single-photon detector techniques can be used, such as photon number-resolved detectors or barrel detectors. For collision-free mechanisms, barrel detectors are sufficient to determine the output configuration of the linear optical network 224.

[0093] • The linear optical network 224 may include volume optical elements in free space, such as mirrors (black plates), beam splitters (light gray squares), and phase shifters (light gray plates). The broken gray lines represent all possible optical paths of the input photons.

[0094] Figure 7B This is a schematic diagram of a boson sampling unit 720B including a photonic architecture with integrated waveguides. In this architecture, the single-photon source matrix 222 and the single-photon detector matrix 226 can be integrated with those described above. Figure 7A The same as shown in the embodiments. Figure 7A and Figure 7B The difference between the embodiments lies in the use of integrated waveguide circuitry and couplers to provide the functionality of the linear optical network 224. Different potential advantages and... Figure 7B The embodiments are associated with, for example, stability, smaller space requirements and / or ease of manufacture.

[0095] Figure 7CThis is a schematic diagram of a boson sampling unit 720C that includes an alternative photonic architecture configured to perform time-binded boson sampling. This embodiment includes a single-photon source and a single-photon detector. The input / output ports of the linear optical network 224 are not spatially determined but temporally determined. The single-photon source generates time-separated pulse trains, which define the time-binding pattern and contain the input state |Ψ. in Each time bay mode corresponds to... Figure 2 The diagram illustrates a spatial mode in a boson sampling scheme. The linear optical network 224 includes a bus waveguide and one or more loops arranged in various configurations. A photon string from the bus waveguide is coupled to a first loop using switches (light gray squares). This loop can accommodate all M modes of interference, meaning its length is greater than or equal to M. T A second switch couples the first loop to the second loop, allowing photons from different time chambers to interact. The second loop may include a phase shifter (black square). Finally, the photons are coupled back to the first loop and the bus waveguide. A single-photon detector measures the presence of photons at different time chamber modes in the output state.

[0096] Different hardware implementations are possible. The architecture described above is provided only as a non-limiting example. The use of hybrid coding platforms, jointly utilizing time and polarization degrees of freedom to define modes, is also envisioned. In the coming years, the performance of boson sampling experiments is expected to improve significantly. For example, the single-photon source rate, detection efficiency, and sampling rate of boson sampling experiments will increase. Therefore, generating a predetermined number of boson samples will become faster, which will affect block generation time. Similar to the Bitcoin blockchain, the advent of supercomputers has significantly reduced block generation time, and several adjustment mechanisms can be implemented to regulate the latter. According to some embodiments, block generation time can be adjusted by modifying the input photon number N, β, and γ values, as well as the mode and state box sizes.

[0097] VIII. Reward Scheme

[0098] Miners that pass all steps of the verification process (steps 314-334) are rewarded. The amount of the reward R may depend on one or more parameters. For example, the reward may depend on the number of samples provided in the verification data, in which case a fixed reward can be defined for each sample.

[0099] One goal of the reward system is to prevent fraudulent mining machines from receiving rewards. In the context of this description, a fraudulent mining machine can refer to any mining machine that does not use a boson sampler to generate its verification data, and the cost of generating the verification data is negligible or zero. For example, a mining machine might send samples from a random distribution, artificially inflating the number of submitted samples, hoping to accidentally receive a large reward. To address this issue, a penalty can be imposed on mining machines that fail to complete all steps of the verification process. The amount of the penalty P may depend on one or more parameters. For example, the penalty may depend on the number of samples provided in the verification data, in which case a fixed penalty per sample can be defined. According to some embodiments, the penalty can be selected as a function of the reward. For example, the value of the penalty can be chosen such that the only winning strategy for the mining machine is honest behavior. According to some embodiments, the values ​​of the reward R and the penalty P can be transmitted throughout the network 105 before the verification process begins and remain unchanged throughout one or more verification processes; that is, the same values ​​of R and P can be used to verify one or more candidate blocks 123.

[0100] Alternatively, and according to some other embodiments, mining machines may be invited to stake some tokens to participate in the verification process (sending verification data) and have the opportunity to receive a reward. In this case, at the end of the verification process, successful mining machines retrieve their staked tokens and receive an additional reward, while unsuccessful mining machines lose a penalty or the smaller of their staked tokens. It should be noted that this mechanism differs from another popular consensus mechanism known in the prior art, namely Proof-of-Stake, because here all mining machines stake the same amount of tokens, and the probability of receiving a reward (mining a block) is independent of the amount staked.

[0101] A further objective of the reward system is to ensure that mining rigs use genuine quantum boson samplers, rather than classical computers or supercomputers, to solve the boson sampling problem, as the latter is highly energy-intensive. For example, according to some embodiments, the reward value can be set such that participation in the verification process is only economically rewarding if a mining rig uses a quantum boson sampler to provide verification data. One way to achieve this is to analyze the cost of generating samples using a quantum boson sampler or a supercomputer. In the context of this description, cost primarily refers to energy consumption, ultimately related to financial costs. In the case of classical computers, the best boson sampling simulator algorithm has a cost per sample that is 2... N N is proportional (in the absence of collision mechanism and M=N) 2For quantum boson samplers, the cost is proportional to N in the best case. Considering some inherent fixed costs independent of the number of input photons (e.g., the cost of cooling a 226-photon detector matrix), there exists a wide range of values ​​for the input photon number N, making the cost of using a classical boson sampling simulator significantly higher than that of using a quantum boson sampler. This is in... Figure 8 The diagram illustrates the energy costs of a quantum boson sampler (solid curve 801), a single-core classical computer (large dashed curve 803), and a supercomputer (small dashed curve 805). Therefore, setting the reward value above the cost of the quantum boson sampler but below the cost of a classical boson sampling simulator incentivizes network miners to use the quantum boson sampler.

[0102] IX. Gaussian Boson Sampling

[0103] Single-photon (Focke state) boson sampling requires a reliable, indistinguishable photon source. This requirement represents one of the challenges in expanding the complexity of current boson sampling experiments. An alternative to Focke state boson sampling is Gaussian boson sampling. The verification process is essentially related to... Figure 3A The descriptions are similar, but with some differences, as described below. Fock state boson sampling is difficult to simulate with classical computers due to the complexity of computing the product sum, while Gaussian boson sampling is difficult to simulate due to the difficulty of computing the Hafnian (a class of #-P complete complexity). Gaussian boson sampling uses zero-photon or squeezed vacuum states at the input, instead of zero or one-photon states. The required input squeezed vacuum states can be deterministically prepared using single-mode or dual-mode compressors, resulting in a significant improvement in the associated sampling rate. As with Fock state boson sampling, the measurements are assumed to be number-resolved, and as with Fock state boson sampling, a post-selection is performed on the result that the total number of photons equals the average number of photons in the input. The approval step 324 of the verification process is the same, except that the classical algorithm used to compute the mode bin distribution is also polynomial in problem size, but involves computing a different function.

[0104] The foregoing description is presented for illustrative purposes. It is not exhaustive and does not limit this disclosure to the exact forms or embodiments disclosed. Modifications and adaptations of this disclosure will be apparent to those skilled in the art from the description and practice of the embodiments disclosed herein.

[0105] The features and advantages of this disclosure are apparent from the detailed description, and therefore, it is intended that the appended claims cover all systems and methods falling within the true spirit and scope of this disclosure. As used herein, the indefinite articles “a” and “an” mean “one or more”. Similarly, the use of plural terms does not necessarily indicate a plural number unless explicitly stated in the given context. Words such as “and” or “or” mean “and / or” unless specifically indicated. Furthermore, since many modifications and variations will readily arise from studying this disclosure, it is not intended to limit this disclosure to the exact constructions and operations shown and described; therefore, all suitable modifications and equivalents may be adopted, provided they fall within the scope of this disclosure.

[0106] Other embodiments will be apparent to those skilled in the art from the description and practice of the embodiments disclosed herein. The illustrative architectures and process flowcharts shown in the figures are intended for illustrative purposes only and are not limiting. The description and examples are also intended to be illustrative only, and the true scope and spirit of the invention are indicated by the following claims. The foregoing description is presented for illustrative purposes. It is not exhaustive and does not limit this disclosure to the exact forms or embodiments disclosed. Modifications and adaptations to this disclosure will be apparent to those skilled in the art from the description and practice of the embodiments disclosed herein.

Claims

1. A quantum analogous proof-of-work consensus method for blockchain networks, the method comprising: Multiple verification data are received from multiple different mining machines in the blockchain network using boson sampling experiments associated with candidate blocks, each verification data being associated with a different mining machine, and each mining machine performing the boson sampling experiment using information included in the candidate block; Analyze the received verification data to determine whether a consensus has been reached; as well as When a consensus is reached, the candidate block is added to the blockchain associated with the blockchain network.

2. The method according to claim 1, further comprising: Based on the analysis of the received multiple verification data, rewards are sent to at least some of the multiple mining machines in the blockchain network.

3. The method according to claim 1 or 2, wherein, Analyzing the received verification data to determine when consensus is reached includes: Authenticate the received multiple verification data; Verify the certified multiple verification data; and Determine whether the threshold conditions for the approved verification data are met.

4. The method according to claim 3, wherein, Verification of the certified verification data includes: Select a pattern binning strategy, wherein the pattern binning strategy is characterized by one or more pattern binning strategy parameters; The pattern binning distribution is determined based on the pattern binning strategy selected for each certified verification data associated with each different mining machine; The true pattern binning distribution is determined based on the pattern binning strategy selected for the certified multiple verification data. A validity factor is determined for each piece of certified validation data by comparing the pattern binning distribution of the certified validation data set with the true binning distribution; and For each certified verification data, determine whether the identified validity factor meets the validity threshold, and retain a set of certified verification data associated with the validity factors that meet the validity threshold.

5. The method according to claim 4, wherein, Determining the validity factor associated with the set of certified verification data includes: determining the statistical distance of the pattern binning distribution of the set of certified verification data relative to the true binning distribution of the plurality of certified verification data.

6. The method according to any one of claims 3 to 5, wherein, Determining whether threshold conditions are met for the approved and certified verification data includes: Select a state binning strategy, wherein the state binning strategy is characterized by one or more state binning strategy parameters; The state binning distribution is determined based on the state binning strategy selected for each approved and certified verification data associated with each different mining machine; The actual state binning distribution is determined based on the state binning strategy selected for the approved and certified multiple verification data. A success factor is determined for each approved and certified verification data set by comparing its state binning distribution with the actual state binning distribution; and For each approved and certified verification data, determine whether the identified success factor meets the success threshold, and retain a set of approved and certified data associated with the success factors that meet the success threshold.

7. The method according to claim 6, wherein, Each mining machine associated with the retained set of approved and certified data is rewarded.

8. The method according to any one of the preceding claims, wherein, The candidate blocks are generated by the mining machines of the blockchain network.

9. The method according to any one of the preceding claims, wherein, Adding the candidate block to the blockchain associated with the blockchain network when consensus is reached includes adding a record to the blockchain confirming that consensus has been reached.

10. A quantum analogous proof-of-work consensus method for blockchain networks, the method comprising: Receive candidate blocks that include multiple transaction data; Verification data is generated by performing a boson sampling experiment using the information included in the candidate blocks; as well as The verification data is sent to a verification server included in the blockchain network, and the verification data enables the verification server to determine whether a consensus has been reached.

11. The method of claim 10, further comprising: Rewards are determined based on the analysis of the sent verification data.

12. The method according to claim 10 or 11, wherein, The boson sampling experiment is performed using an optical network, and the verification data is generated by inputting one or more photons into the optical network and observing the output of the one or more input photons; and performing the boson sampling experiment using information included in the candidate block includes determining one or more of the following based on the information included in the candidate block: the input configuration of the optical network, the number of input photons, the number of modes, and the unitary transform that defines the initial configuration of the optical network.

13. The method according to any one of the preceding claims, wherein, The boson sampling experiment associated with the candidate block is either a Fock state boson sampling experiment or a Gaussian state boson sampling experiment.

14. A verification server comprising at least one processor configured to perform the method of any one of claims 1 to 9.

15. A blockchain mining machine, comprising at least one processor and a boson sampling unit, wherein the at least one processor and the boson sampling unit are configured to perform the method of any one of claims 10 to 13.