CLASSICAL COMPUTER, INFORMATION PROCESSING METHOD AND INFORMATION PROCESSING PROGRAM

A self-test method for the CCZ magic state addresses the limitations of existing methods by enabling the verification of quantum adherence in a realistic scenario, ensuring the correct generation and measurement of quantum states essential for quantum computation.

DE112022001709B4Active Publication Date: 2025-05-22MITSUBISHI ELECTRIC CORP +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE112022001709
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-06-04
Filing Date
2022-05-27
Publication Date
2025-05-22
Estimated Expiration
2042-05-27

AI Technical Summary

Technical Problem

Existing self-test methods for quantum states, such as the 'bell state' self-test, require unrealistic assumptions about the inability of black box devices to exchange classical information, limiting their applicability to actual quantum systems.

Method used

The development of a self-test method that allows for the verification of quantum adherence in a Controlled Controlled-Z (CCZ) 'magic state', a representative non-stabilizer state, by using a classical computer to calculate probabilities and verify the correct generation and measurement of quantum states.

Benefits of technology

Enables self-tests on the 'magic state of CCZ', ensuring the correct generation and measurement of quantum states essential for quantum computation, thereby verifying quantum adherence in a more realistic and applicable manner.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A result confirmation unit (204) calculates a state space probability, which is a probability that a verification target device (300) has not correctly created a state space with a quantum state stored therein, a Pauli measurement probability, which is a probability that the verification target device (300) has not correctly performed a Pauli Z measurement and a Pauli X measurement, and a magic state probability, which is a probability that the verification target device (300) has not generated a magic state of CCZ.Then, the result confirmation unit (204) calculates a degree of approximation between a quantum state and the magic state of CCZ at the verification target device (300) and measurement accuracies of the Pauli-Z measurement and the Pauli-X measurement to the quantum state at the verification target device (300) using the state space probability, the Pauli measurement probability, and the magic state probability.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to techniques for verifying quantumness. BACKGROUND TO THE STATE OF THE ART

[0002] A test in which a classical computer used by a verifier exchanges only classical information with a device given as a black box whose internal operations are unknown (hereinafter referred to as a black-box device), and verifies whether the black-box device performs the "generation and measurement of quantum states" required by the verifier, is called a self-test. By performing this self-test, the classical computer used by the verifier can characterize the operation of the black-box device, which has higher computational capability than the classical computer. Self-tests enable the realization of various types of quantum information processing, such as quantum cryptography.

[0003] Non-Patent Literature 1 proposes a self-test method for "Bell states," that is, for quantum states of two quantum bits with quantum correlation. The method of Non-Patent Literature 1 can verify the generation and measurement of Bell states by exchanging only classical information between a classical computer and a black-box device. However, the method of Non-Patent Literature 1 requires an assumption that "two devices" are given as black-box devices, and the two black-box devices cannot exchange classical information during self-test execution. If this assumption is not true, self-testing for Bell states cannot be performed using the method of Non-Patent Literature 1.Since classical information can be easily exchanged by telephone or the like, the method has the disadvantage that it is not realistic to apply this assumption to actual black box devices.

[0004] To solve this problem, Non-Patent Literature 2 makes the computational assumption that a black-box device behaving quantumly is incapable of breaking a quantum-secure computer encryption, so-called lattice-based cryptography. Non-Patent Literature 2 demonstrates that such a computational assumption enables self-testing for Bell states even for "a single black-box device behaving quantumly." It is assumed that a quantum-secure computer encryption cannot be efficiently broken even by a quantum computer. Non-Patent Literature 2 therefore provides a self-testing method for Bell states on a single black-box device under a realistic assumption.

[0005] Further prior art is known from non-patent literature 3, 4 and 5. REFERENCE LISTS NON-PATENT LITERATURE Nicht-Patentliteratur 1: REICHARDT, Ben W., UNGER, Falk, VAZIRANI, Umesh. Classical command of quantum system. Nature Band 496, Seiten 456-460, (2013). Nicht-Patentliteratur 2: METGER Tony, VIDICK, Thomas. Self-testing of a single quantum device under computational assumptions. Version 2. 01-12-2020. S. 1-61. URL: https: / / arxiv.org / pdf / 2001.09161v2. - arXiv: 2001.09161v2. Nicht-Patentliteratur 3: HIRAHARA, Shuichi; GALL, François Le. Test of quantumness with small-depth quantum circuits. arXiv preprint arXiv:2105.05500v1, 12.05.2021. DOI: https: / / doi.org / 10.48550 / arXiv.2105.05500 Nicht-Patentliteratur 4: MORIMAE, Tomoyuki. Information-theoreticallysound non-interactive classical verification of quantum computing with trusted center. arXiv preprint arXiv:2003.10712, 2020. DOI: https: / / doi.org / 10.48550 / arXiv.2003.10712 Non-Patent Literature 5: MIZUTANI, Akihiro, et al. Computational self-testing for entangled magic states. arXiv preprint arXiv:2111.02700v1, November 4, 2021. DOI: https: / / doi.org / 10.48550 / arXiv.2111.02700 SUMMARY OF THE INVENTIONTECHNICAL PROBLEM

[0006] The aforementioned "Bell state" is a quantum state in a class of so-called stabilizer states, which stabilizes the Pauli-Z measurement and the Pauli-X measurement. Whether a black-box device to be verified generates a Bell state or not can be verified based on the measurement result of a stabilizer measurement formed from a Pauli-Z measurement and a Pauli-X measurement. The self-test method proposed in Non-Patent Literature 2 consists of the following two tests: (A) A test whether the verified black box device correctly performs the Pauli-Z measurement and the Pauli-X measurement; and (B) A test whether the measurement result of the stabilizer measurement of the Bell states is correct or not.

[0007] The self-test method proposed in Non-Patent Literature 2 is a test based on the properties of a stabilizer state. Accordingly, a self-test for other stabilizer states can also be performed using the method of Non-Patent Literature 2. Here, a universal set of quantum states consists of a "stabilizer state" and a "non-stabilizer state," which are two mutually exclusive groups of states. The results of Non-Patent Literature 2 have proven that self-tests for the stabilizer state are possible. However, it is unclear whether self-tests for the other state class, the non-stabilizer state, are possible within the same framework as in Non-Patent Literature 2.

[0008] A primary objective of the present disclosure is to address this challenge. More specifically, an objective of the present disclosure is to also perform a self-test for a "Magic State of CCZ (Controlled Controlled-Z)," which is a representative non-stabilizer state. The stabilizer state is a state insufficient for realizing quantum computation. In contrast, the magic state of CCZ is known to be an essential state for realizing quantum computation. Therefore, the present disclosure provides quantum verification of whether a black-box device possesses a resource state essential for realizing quantum computation. SOLUTION TO THE PROBLEM

[0009] The object is achieved according to the invention by the features of the independent claims. Advantageous further developments are possible by the measures specified in the subclaims.

[0010] A classical computer according to the present disclosure comprises: a state space probability calculation unit for calculating, using a first measurement result and a second measurement result, a state space probability, which is a probability that a quantum computer has not correctly created a state space having a first quantum state stored therein, wherein the first quantum state is a quantum state generated by the quantum computer, wherein the first measurement result is a result of the quantum computer measuring the first quantum state, and the second measurement result is a result of the quantum computer measuring a second quantum state, wherein the second quantum state is a quantum state after a change in the first quantum state caused by the measurement of the first quantum state; a Pauli measurement probability calculation unit for calculating, using a third measurement result, a fourth measurement result, and the first measurement result, a Pauli measurement probability, which is a probability that the quantum computer has incorrectly performed a Pauli Z measurement and a Pauli X measurement on a fourth quantum state, wherein the third measurement result is a result of the quantum computer measuring a third quantum state, the third quantum state being a quantum state after a change in the first quantum state caused by the measurement of the first quantum state and different from the second quantum state, and the fourth measurement result is a result of the quantum computer measuring the fourth quantum state, the fourth quantum state being a quantum state after a change in the third quantum state,caused by the measurement of the third quantum state;, a magic state probability calculation unit for calculating a magic state probability, which is a probability that the quantum computer has not generated a magic state of CCZ (Controlled Controlled-Z), using the first measurement result, the third measurement result, and the fourth measurement result; and an approximation accuracy calculation unit to calculate a degree of approximation between the fourth quantum state and the magic state of CCZ, as well as measurement accuracies of the Pauli-Z measurement and the Pauli-X measurement on the fourth quantum state using the state-space probability, the Pauli measurement probability, and the magic state probability. ADVANTAGEOUS EFFECTS OF THE INVENTION

[0011] The present disclosure also enables self-tests to be performed on the “magic state of CCZ”. BRIEF DESCRIPTION OF THE DRAWINGS Fig. 1 shows a configuration example of a quantum verification system according to Embodiment 1. Fig. 2 is a flowchart illustrating an operation example of the quantum verification system according to Embodiment 1. Fig. 3 is a flowchart illustrating the operation example of the quantum verification system according to Embodiment 1. Fig. 4 shows an example of the hardware configuration of a verification device according to Embodiment 1. DESCRIPTION OF THE EMBODIMENTS Embodiment 1.***Overview***

[0012] In the present embodiment, it is explained that a classical computer performs a self-test to verify whether a quantum computer as a black box device correctly performs “generation and measurement of a quantum state” in a magic state of CCZ, in the same framework as in Non-Patent Literature 2.

[0013] The present embodiment is achieved by generalizing “a method of verifying the generation of non-stabilizer states using the measurement results of the Pauli Z measurement and the Pauli X measurement (the results of the generalized stabilizer measurement)” described in the reference literature below.

[0014] [Reference literature] Yuki Takeuchi and Tomoyuki Morimae. Verification of Many-Qubit States. Physical Review X 8, 021060 (2018)

[0015] The verification procedure described in the reference literature assumes that only the generation of the non-stabilizer state is verifiable and that the Pauli-Z measurement and the Pauli-X measurement are performed correctly. This means that the verification procedure described in the reference literature does not verify whether the Pauli-Z measurement and the Pauli-X measurement are performed correctly, but only verifies whether the quantum states are generated correctly. A self-test requires verification of whether both the "generation of the quantum state" and the "measurement of the quantum state" were performed correctly. Accordingly, the verification procedure described in the reference literature does not achieve a self-test.

[0016] In the present embodiment, the aforementioned test (A) described in Non-Patent Literature 2 (referred to again below) about the “magic state of CCZ,” a representative non-stabilizer state, is used.

[0017] (A) A test whether the black box device to be verified correctly performs the Pauli-Z measurement and the Pauli-X measurement or not.

[0018] By performing the above-described test (A) provided in Non-Patent Literature 2 with a classical computer, the verification method described in the reference literature can be generalized to a black box device for the magic state of CCZ. Thus, the present embodiment can realize a self-test that verifies both the generation of quantum states and the measurement of quantum states in the magic state of CCZ.

[0019] In this case, the “magic state of CCZ” is a quantum state in which the “controlled phase gate (CCZ gate)” is applied to three quantum bits that are in equal superposition of “0” and “1”.

[0020] The quantum states of bits "0" and "1" are represented as "|0>" and "|1>," respectively, and a quantum state in equal superposition of "|0>" and "|1>" is represented as "|+>." In this case, the "magic state of CCZ" is a quantum state that can be represented as "|+>|+>|+>-2|1>|1>|1>."

[0021] A "Pauli-Z measurement" refers to a two-row, two-column matrix where the values ​​of the diagonal elements are "+1" and "-1" when the matrix is ​​represented by "|0>" and "|1>," and the remaining matrix elements are "0." A "Pauli-Z measurement" is a measurement that yields a measurement result of "+1" or "-1," depending on the eigenspace of this matrix into which a state is projected.

[0022] A "Pauli-X measurement" refers to a two-row, two-column matrix where two off-diagonal elements are "+1" when the matrix is ​​represented by "|0>" and "|1>," and the remaining matrix elements are "0." A "Pauli-X measurement" is a measurement that yields a measurement result of "+1" or "-1," depending on the eigenspace of this matrix into which a state is projected. *** Configuration Description ***

[0023] Fig. 1 shows a configuration example of a quantum verification system 100 according to the present embodiment.

[0024] The quantum verification system 100 comprises a verification device 200 and a verification target device 300, as shown in Fig. 1 shown.

[0025] The verification device 200 is a conventional computer that processes so-called conventional information. The verification device 200 is, for example, a PC (personal computer). An operation of the verification device 200 corresponds to an information processing method. A program for implementing the operation of the verification device 200 corresponds to an information processing program.

[0026] The verification target device 300 is a quantum computer that performs quantum computations. The verification target device 300 corresponds to a black box device.

[0027] A conventional communication channel 101 is a communication channel connecting the verification device 200 and the verification target device 300. The conventional communication channel 101 can be any communication channel that transmits digital signals, such as a telephone network and the Internet.

[0028] In the following, the configuration of the verification device 200 and the configuration of the verification target device 300 are explained sequentially.

[0029] The Fig. The verification device 200 shown in Figure 1 comprises a data generation unit 201, a key information generation unit 202, a random number generation unit 203, and a result confirmation unit 204.

[0030] Although not shown, the verification device 200 includes a verification-side information processing unit that processes conventional information to be used in the verification device 200.

[0031] The data generation unit 201 randomly selects a 3-bit character string from a set of 3-bit character strings {000, 001, 010, 100, 111}. The data generation unit 201 further transmits the 3-bit character string (θ1, θ2, θ3) selected from {000, 001, 010, 100, 111} to the key information generation unit 202.

[0032] The data generation unit 201 also generates a security parameter λ and transmits the security parameter λ to the key information generation unit 202.

[0033] Here, the 3-bit string (θ1, θ2, θ3) and the security parameter λ are also referred to as output data.

[0034] The key information generation unit 202 generates a public key (k1, k2, k3) and a trapdoor (tk1, tk2, tk3) using the output data (the 3-bit character string (θ1, θ2, θ3) and the security parameter λ) received from the data generation unit 201.

[0035] The public key (k1, k2, k3) is data used for the verification target device 300 to prove that the verification target device 300 performs the generation of the magic state of CCZ and the Pauli-Z measurement and the Pauli-X measurement on the magic state of CCZ.

[0036] The trapdoor (tk1, tk2, tk3) is data used by the verification device 200 to verify that the verification target device 300 performs the generation of the magic state of CCZ as well as the Pauli-Z measurement and the Pauli-X measurement on the magic state of CCZ.

[0037] The key information generation unit 202 calculates the public key (k1, k2, k3) and the trapdoor (tk1, tk2, tk3) according to the scheme described in Non-Patent Literature 2.

[0038] The key information generation unit 202 transmits the public key (k1, k2, k3) to the verification target device 300.

[0039] The random number generation unit 203 generates a randomly selected "0" or "1" bit. The random number generation unit 203 then transmits the generated "0" or "1" bit to the result confirmation unit 204. The result confirmation unit 204 transmits this "0" or "1" bit to the verification target device 300. This "0" or "1" bit is referred to as a probability calculation random number. The details of the probability calculation random number will be described later.

[0040] The random number generation unit 203 also generates a 3-bit random number (q1, q2, q3) and transmits the generated 3-bit random number (q1, q2, q3) to the verification target device 300 via the classical communication channel 101. The random number (q1, q2, q3) is a random number used in the measurement of a fourth quantum state, which will be discussed later. This 3-bit random number is hereinafter referred to as a measurement random number (q1, q2, q3). Details of the measurement random number (q1, q2, q3) will be discussed later.

[0041] The result confirmation unit 204 calculates a state-space probability, a Pauli measurement probability, and a magic-state probability. The details of the state-space probability, the Pauli measurement probability, and the magic-state probability will be discussed later. The result confirmation unit 204 also calculates a degree of approximation between the fourth quantum state and the magic state of CCZ, as well as the measurement accuracies of the Pauli Z measurement and the Pauli X measurement on the fourth quantum state using the state-space probability, the Pauli measurement probability, and the magic-state probability.

[0042] The result confirmation unit 204 corresponds to a state space probability calculation unit, a Pauli measure probability calculation unit, a magic state probability calculation unit, and an approximation accuracy calculation unit.

[0043] The processing performed by the result confirmation unit 204 corresponds to a state space probability calculation process, a Pauli measure probability calculation process, a magic state probability calculation process, and an approximation accuracy calculation process.

[0044] The verification target device 300 includes a quantum state generation unit 301 and a quantum state measurement unit 302. Although not shown, the verification target device 300 includes a verification target device-side information processing unit that processes data to be used in the verification target device 300.

[0045] The quantum state generation unit 301 generates quantum states.

[0046] The quantum state measuring unit 302 outputs measurement results by measuring the quantum states generated by the quantum state generating unit 301.

[0047] The verification target device 300 can be any type of computer, as long as it is a quantum computer. For example, the verification target device 300 can be a quantum computer that uses superconducting quantum bits. In this case, the quantum state generation unit 301 generates quantum states using superconducting quantum bits and microwaves. Furthermore, the quantum state measurement unit 302 measures the quantum states of the superconducting quantum bits using microwaves and obtains a measurement result in the form of an electrical signal.

[0048] Fig. 4 shows an example of a hardware configuration of the verification device 200 according to the present embodiment.

[0049] The verification device 200 comprises a processor 901, a main memory device 902, an additional memory device 903 and a communication device 904 as hardware components.

[0050] The additional storage device 903 stores programs for implementing the functions of the data generation unit 201, the key information generation unit 202, the random number generation unit 203, and the result confirmation unit 204.

[0051] These programs are loaded from the auxiliary storage device 903 into the main storage device 902. Then, the processor 901 executes the programs to perform the operations of the data generation unit 201, the key information generation unit 202, the random number generation unit 203, and the result confirmation unit 204.

[0052] Fig. 4 schematically shows a situation in which the processor 901 executes the programs for implementing the functions of the data generation unit 201, the key information generation unit 202, the random number generation unit 203 and the result confirmation unit 204.

[0053] The communication device 904 performs a classical communication with the verification target device 300 via the classical communication channel 101. ***Description of how it works***

[0054] The following explains an overview of the operation of the result confirmation unit 204 according to the present embodiment. An overview of the operation of the verification target device 300, which is necessary for describing the operation of the result confirmation unit 204, is also provided.

[0055] The verification target device 300 generates in step S403 ( Fig. 2), which will be discussed later, generates a quantum state based on the public key (k1, k2, k3) transmitted by the random number generation unit 203. The quantum state generated in step S403 is referred to as a first quantum state.

[0056] The verification target device 300 measures the first quantum state (S403). The measurement result obtained from the measurement of the first quantum state by the verification target device 300 is referred to as a first measurement result (y1, y2, y3). The verification target device 300 transmits the first measurement result (y1, y2, y3) to the verification device 200.

[0057] The steps shown below such as “S403” and “S408” correspond to the steps shown in Fig. 2 or Fig. 3 steps. Details of Fig. 2 and Fig. 3 will be discussed later.

[0058] The measurement of the first quantum state (S403) causes the quantum state to change from the first quantum state.

[0059] The quantum state after the change from the first quantum state when the value of the probability calculation random number generated by the random number generation unit 203 is “0” is called a second quantum state.

[0060] The verification target device 300 measures the second quantum state (S408). The measurement result obtained from the measurement of the second quantum state by the verification target device 300 (S408) is referred to as a second measurement result (m1, m2, m3). The verification target device 300 transmits the second measurement result (m1, m2, m3) to the verification device 200 (S409).

[0061] Meanwhile, the quantum state after the change from the first quantum state, when the value of the probability calculation random number is "1," is referred to as a third quantum state. The verification target device 300 measures the third quantum state (S412). The measurement result obtained from the measurement of the third quantum state by the verification target device 300 (S412) is referred to as a third measurement result (d1, d2, d3). The verification target device 300 transmits the third measurement result (d1, d2, d3) to the verification device 200 (S413).

[0062] Furthermore, the quantum state after the change in the third quantum state caused by the measurement of the third quantum state (S412) is referred to as a fourth quantum state. The verification target device 300 measures the fourth quantum state using the measurement random number (q1, q2, q3) generated by the random number generation unit 203 (S416). The measurement result obtained from the measurement of the fourth quantum state by the verification target device 300 (S416) is referred to as a fourth measurement result (v1, v2, v3). The verification target device 300 transmits the fourth measurement result (v1, v2, v3) to the verification device 200 (S417).

[0063] The verification target device 300 performs a quantum state generation and measurement sequence multiple times, wherein the quantum state generation and measurement sequence are formed from the generation of the first quantum state and the measurement of the first quantum state and the measurement of the second quantum state or the measurement of the third quantum state and the measurement of the fourth quantum state.

[0064] Then, each time the quantum state generation and measurement sequence is executed, the verification target device 300 transmits the first measurement result (y1, y2, y3) to the verification device 200 (S405) and the second measurement result (m1, m2, m3) to the verification device 200 (S409) or the third measurement result (d1, d2, d3) and the fourth measurement result (v1, v2, v3) to the verification device 200 (S413, S417).

[0065] As mentioned above, the result confirmation unit 204 calculates the state space probability, the Pauli measurement probability, and the magic state probability.

[0066] The result confirmation unit 204 also calculates the degree of approximation between the fourth quantum state and the magic state of CCZ, as well as the measurement accuracies of the Pauli Z measurement and the Pauli X measurement on the fourth quantum state using the state space probability, the Pauli measurement probability, and the magic state probability.

[0067] The state space probability is a probability that the verification target device 300 has not correctly created a state space in which the first quantum state is stored. The state space probability is hereinafter referred to as state space probability E1 or probability E1.

[0068] The result confirmation unit 204 calculates the state space probability E1 using the public key (k1, k2, k3) and the first measurement result (y1, y2, y3) and the second measurement result (m1, m2, m3) for each execution of the quantum state generation and measurement sequence.

[0069] The Pauli measurement probability is a probability that the verification target device 300 did not correctly perform the Pauli Z measurement and the Pauli X measurement in the fourth quantum state. The Pauli measurement probability is hereinafter referred to as Pauli measurement probability E2 or probability E2.

[0070] The result confirmation unit 204 calculates the Pauli measurement probability E2 using the public key (k1, k2, k3), the trapdoor (tk1, tk2, tk3) and the first measurement result (y1, y2, y3), the third measurement result (d1, d2, d3) and the fourth measurement result (v1, v2, v3) for each execution of the quantum state generation and measurement sequence.

[0071] The magic state probability is a probability that the verification target device 300 has not generated the magic state of CCZ. The magic state probability is hereinafter referred to as magic state probability E3 or probability E3.

[0072] The result confirmation unit 204 calculates the magic state probability E3 using the public key (k1, k2, k3), the trapdoor (tk1, tk2, tk3), and the first measurement result (y1, y2, y3), the third measurement result (d1, d2, d3), and the fourth measurement result (v1, v2, v3) for each execution of the quantum state generation and measurement sequence.

[0073] The operation of the quantum verification system 100 according to the present embodiment will now be described using a flowchart.

[0074] Fig. 2 and Fig. 3 is a flowchart illustrating a quantum verification process using the quantum verification system 100 of Fig. 1 shows.

[0075] The steps S401, S402, S406, S407 and S410 in Fig. 2 and steps S411, S414, S415 and S418 to S420 in Fig. 3 are processings performed by the verification device 200. Steps S403 to S405, S408 and S409 in Fig. 2 and steps S412, S413, S416 and S417 in Fig. 3 are processings performed by the verification target device 300.

[0076] The process consisting of steps S401 to S418 corresponds to the quantum state generation and measurement sequence. In the present embodiment, the quantum state generation and measurement sequence are repeated N times. The method for determining the value of "N" will be described later.

[0077] In step S401, the data generation unit 201 randomly selects a 3-bit character string from the group of 3-bit character strings {000, 001, 010, 100, 111}. Subsequently, the data generation unit 201 transmits the selected 3-bit character string (θ1, θ2, θ3) to the key information generation unit 202.

[0078] The data generation unit 201 also generates a security parameter λ and transmits the generated security parameter λ to the key information generation unit 202.

[0079] In step S402, the key information generation unit 202 generates a public key (k1, k2, k3) and a trapdoor (tk1, tk2, tk3) based on the output data (the 3-bit character string (θ1, θ2, θ3) and the security parameter λ) generated by the data generation unit 201. Then, the key information generation unit 202 transmits the public key (k1, k2, k3) to the verification target device 300 via the communication device 904 and the conventional communication channel 101.

[0080] Here, the trapdoor (tk1, tk2, tk3) is secret information that must be strictly protected to prevent it from leaking out of the verification device 200.

[0081] In step S403, the quantum state generation unit 301 generates a quantum state (the first quantum state) based on the public key (k1, k2, k3) transmitted from the verification device 200. Then, the quantum state measurement unit 302 performs a measurement of the generated quantum state (the first quantum state).

[0082] In step S404, the verification target device 300 stores the first measurement result (y1, y2, y3).

[0083] In step S405, the quantum state measuring unit 302 transmits the first measurement result (y1, y2, y3) to the verification device 200 via the classical communication channel 101.

[0084] In the verification device 200, the result confirmation unit 204 receives the first measurement result (y1, y2, y3) via the communication device 904. Then, the result confirmation unit 204 stores the first measurement result (y1, y2, y3) in the additional storage device 903. The additional storage device 903 stores the first measurement result (y1, y2, y3).

[0085] In step S406, the random number generation unit 203 generates a 1-bit random number (a probability calculation random number).

[0086] If the random number (the probability calculation random number) generated in step S406 is "0," steps S407 to S410 are performed. On the other hand, if the random number (the probability calculation random number) generated in step S406 is "1," steps S411 to S418 are performed. [When the random number generated in step S406 is 0]

[0087] In step S407, the random number generation unit 203 of the verification device 200 transmits the value "0" of the probability calculation random number to the verification target device 300 via the communication device 904 and the conventional communication channel 101. The random number generation unit 203 also indicates the value "0" of the probability calculation random number to the result confirmation unit 204.

[0088] In step S408, the quantum state measuring unit 302 measures the second quantum state based on the value “0” of the probability calculation random number and stores the second measurement result (m1, m2, m3).

[0089] In step S409, the quantum state measuring unit 302 transmits the second measurement result (m1, m2, m3) to the verification device 200 via the classical communication channel 101.

[0090] In step S410, the result confirmation unit 204 receives the second measurement result (m1, m2, m3) via the communication device 904. Then, the result confirmation unit 204 stores the second measurement result (m1, m2, m3) in the additional storage device 903. The additional storage device 903 stores the second measurement result (m1, m2, m3).

[0091] Further, the result confirmation unit 204 uses the public key (k1, k2, k3) generated in step S402 to determine whether the first measurement result (y1, y2, y3) transmitted from the verification target device 300 in step S405 and the second measurement result (m1, m2, m3) transmitted from the verification target device 300 in step S409 are correct or incorrect. Then, the result confirmation unit 204 stores a determination result of "correct" or "incorrect" in the auxiliary storage device 903. The auxiliary storage device 903 stores the determination result of "correct" or "incorrect." Details of how the result confirmation unit 204 makes the determination will be discussed later. [When the random number generated in step S406 is 1]

[0092] In step S411, the random number generation unit 203 of the verification device 200 transmits the value "1" of the probability calculation random number to the verification target device 300 via the communication device 904 and the conventional communication channel 101. The random number generation unit 203 also indicates the value "1" of the probability calculation random number to the result confirmation unit 204.

[0093] In step S412, the quantum state measuring unit 302 measures the third quantum state based on the value “1” of the probability calculation random number and stores the third measurement result (d1, d2, d3).

[0094] In step S413, the quantum state measuring unit 302 transmits the third measurement result (d1, d2, d3) to the verification device 200 via the classical communication channel 101.

[0095] In step S414, the result confirmation unit 204 receives the third measurement result (d1, d2, d3) via the communication device 904. Then, the result confirmation unit 204 stores the third measurement result (d1, d2, d3) in the additional storage device 903. The additional storage device 903 stores the third measurement result (d1, d2, d3).

[0096] In addition, the random number generation unit 203 generates a 3-bit measurement random number (q1, q2, q3).

[0097] In step S415, the random number generation unit 203 transmits the 3-bit measurement random number (q1, q2, q3) to the verification target device 300 via the classic communication channel 101.

[0098] The random number generation unit 203 also outputs the measurement random number (q1, q2, q3) to the result confirmation unit 204.

[0099] In step S416, the quantum state measuring unit 302 measures the fourth quantum state based on the 3-bit measurement random number (q1, q2, q3) transmitted from the verification device 200 and stores the fourth measurement result (v1, v2, v3).

[0100] In step S417, the quantum state measuring unit 302 transmits the fourth measurement result (v1, v2, v3) to the verification device 200 via the classical communication channel 101.

[0101] In step S418, the result confirmation unit 204 receives the fourth measurement result (v1, v2, v3) via the communication device 904. Then, the result confirmation unit 204 stores the fourth measurement result (v1, v2, v3) in the additional storage device 903. The additional storage device 903 stores the fourth measurement result (v1, v2, v3).

[0102] Further, the result confirmation unit 204 determines whether the first measurement result (y1, y2, y3) transmitted from the verification target device 300 in step S405, the third measurement result (d1, d2, d3) transmitted from the verification target device 300 in step S413, and the fourth measurement result (v1, v2, v3) transmitted from the verification target device 300 in step S416 are correct or incorrect, and stores a determination result of "correct" or "incorrect" in the additional storage device 903. The additional storage device 903 stores the determination result of "correct" or "incorrect".

[0103] More specifically, the result confirmation unit 204 determines whether the first measurement result (y1, y2, y3), the third measurement result (d1, d2, d3), and the fourth measurement result (v1, v2, v3) are correct or incorrect using the 3-bit character string (θ1, θ2, θ3) generated in step S401, the public key (k1, k2, k3) and the trapdoor (tk1, tk2, tk3) generated in step S402, and the measurement random number (q1, q2, q3) generated in step S414.

[0104] After the quantum state generation and measurement sequence described above have been performed N times, the result confirmation unit 204 calculates the probability E1, the probability E2, and the probability E3 in step S419 using the determination results “incorrect” obtained in step S410 and step S418.

[0105] Finally, in step S420, the result confirmation unit 204 obtains the result of the self-test based on the probability E1, probability E2, and probability E3 calculated in step S419.

[0106] Next, details of the operations of the result confirmation unit 204 in steps S410, S418, S419, and S420 will be discussed. [When the probability calculation random number specified by the random number generation unit 203 is “0”.]

[0107] That is, if a probability calculation random number of "0" is given by the random number generation unit 203 in step S407, the result confirmation unit 204 determines whether the second measurement result (m1, m2, m3) is correct or incorrect in the following process in step S410.

[0108] Note that step S410 is processing aimed at verifying whether or not the verification target device 300 has correctly created a state space with the first quantum state stored therein.

[0109] The result confirmation unit 204 determines whether the second measurement result (m1, m2, m3) is correct or incorrect by using the public key (k1, k2, k3) received from the key information generation unit 202 and the first measurement result (y1, y2, y3) and the second measurement result (m1, m2, m3) received from the verification target device 300. The result confirmation unit 204 determines whether the second measurement result (m1, m2, m3) is correct or incorrect using the method described in Non-Patent Literature 2.

[0110] If the verification target device 300 has correctly created a state space with the first quantum state stored therein, the probability that the second measurement result (m1, m2, m3) is determined to be "incorrect" is zero. However, if the verification target device 300 has not correctly created a state space in which the first quantum state is stored, the probability that the second measurement result (m1, m2, m3) is determined to be "incorrect" is greater than zero. [When the probability calculation random number specified by the random number generation unit 203 is “1”.]

[0111] If a probability calculation random number of "1" is displayed by the random number generation unit 203 in step S411, the result confirmation unit 204 determines whether the first measurement result (y1, y2, y3), the third measurement result (d1, d2, d3), and the fourth measurement result (v1, v2, v3) are correct or incorrect in step S418 in the following process.

[0112] The processing in step S418 is processing aimed at verifying whether the verification target device 300 has correctly performed the Pauli-Z measurement and the Pauli-X measurement in the fourth quantum state and whether or not it has correctly generated the magic state of CCZ.

[0113] Specifically, the result confirmation unit 204 determines the correctness or incorrectness according to the rules (a) to (e) below.

[0114] Rules (a) to (d) are rules for the result confirmation unit 204 to verify whether the verification target device 300 correctly performed the Pauli-Z measurement and the Pauli-X measurement on the fourth quantum state. Rule (e) is a rule for the result confirmation unit 204 to verify whether the verification target device 300 correctly generated the magic state of CCZ for the fourth quantum state. Rule (a): applied when (θ1, θ2, θ3) = (0, 0, 0)

[0115] The random number generation unit 203 randomly generates one of the values ​​"1, 2, 3" and transmits the generated value to the result confirmation unit 204. Assume that the value transmitted from the random number generation unit 203 to the result confirmation unit 204 is "i." Here, "i" is any one of the values ​​"1, 2, 3."

[0116] The result confirmation unit 204 obtains a public key ki corresponding to "i" from the public key (k1, k2, k3) received from the key information generation unit 202. The result confirmation unit 204 also obtains a measurement result yi corresponding to "i" from the first measurement result (y1, y2, y3) received from the verification target device 300. Then, the result confirmation unit 204 derives a bit bi from the obtained measurement result yi. Then, the result confirmation unit 204 determines whether or not (Condition 1) and (Condition 2) below hold simultaneously.

[0117] If (Condition 1) and (Condition 2) are simultaneously true, the result confirmation unit 204 stores a determination result of "incorrect" in the additional storage device 903. If even one of (Condition 1) and (Condition 2) is not true, the result confirmation unit 204 stores a determination result of "correct" in the additional storage device 903. (Condition 1) “bi differs from the measurement result vi received from the verification target device 300” (Condition 2) “qi is equal to 0”

[0118] Here, the bit bi is a check bit used to check whether the verification target device 300 has correctly created a state in the Z-basis in the i-th quantum state in the fourth quantum state and correctly performed a Pauli Z-measurement. Thus, the bit bi is referred to as an "i-th Z-basis state generation and measurement check bit." The result confirmation unit 204 calculates the "i-th Z-basis state generation and measurement check bit bi" according to the scheme described in Non-Patent Literature 2. The "i-th Z-basis state generation and measurement check bit bi" corresponds to a Z-basis check bit. The processing based on rule (a) is also referred to as a Z-basis check process.

[0119] The measurement result vi is a measurement result corresponding to the "i" of the fourth measurement result (v1, v2, v3). The bit qi is a bit corresponding to "i" of the measurement random number (q1, q2, q3). Rule (b): applied when (θ1, θ2, θ3) = (1, 0, 0)

[0120] The result confirmation unit 204 derives a bit r1 from the public key (k1, k2, k3) and the trapdoor (tk1, tk2, tk3) received from the key information generation unit 202, the first measurement result (y1, y2, y3) received from the verification target device 300, and a first measurement result d1 of the third measurement result (d1, d2, d3). Then, the result confirmation unit 204 determines whether (Condition 1) and (Condition 2) below hold simultaneously.

[0121] If (Condition 1) and (Condition 2) are simultaneously true, the result confirmation unit 204 stores a determination result of "incorrect" in the additional storage device 903. If even one of (Condition 1) and (Condition 2) is not true, the result confirmation unit 204 stores a determination result of "correct" in the additional storage device 903. (Condition 1) “r1 differs from the measurement result v1 received by the verification target device 300” (Condition 2) “q1 is equal to 1”

[0122] Here, bit r1 is a check bit used to check whether the verification target device 300 has correctly created a state in the X-basis in the first quantum state in the fourth quantum state and correctly performed a Pauli X-measurement. Thus, bit r1 is referred to as "the first X-basis state generation and measurement check bit." The result confirmation unit 204 calculates the "first X-basis state generation and measurement check bit r1" according to the scheme described in Non-Patent Literature 2. The "first X-basis state generation and measurement check bit r1" corresponds to an X-basis check bit. The processing based on rule (b) is also referred to as an X-basis check process.

[0123] The measurement result v1 is the first measurement result V1 of the fourth measurement result (v1, v2, v3). Bit q1 is the first bit q1 of the measurement random number (q1, q2, q3). Rule (c): applied when (θ1, θ2, θ3) = (0, 1, 0)

[0124] The result confirmation unit 204 derives a bit r2 from the public key (k1, k2, k3) and the trapdoor (tk1, tk2, tk3) received from the key information generation unit 202, the first measurement result (y1, y2, y3) received from the verification target device 300, and a second measurement result d2 of the third measurement result (d1, d2, d3). Then, the result confirmation unit 204 determines whether (Condition 1) and (Condition 2) below hold simultaneously.

[0125] If (Condition 1) and (Condition 2) are simultaneously true, the result confirmation unit 204 stores a determination result of "incorrect" in the additional storage device 903. If even one of (Condition 1) and (Condition 2) is not true, the result confirmation unit 204 stores a determination result of "correct" in the additional storage device 903. (Condition 1) “r2 differs from the measurement result v2 received by the verification target device 300” (Condition 2) “q2 is equal to 1”

[0126] Here, bit r2 is a check bit used to check whether the verification target device 300 has correctly created a state in the X-basis in the second quantum state in the fourth quantum state and correctly performed a Pauli X measurement. Thus, bit r2 is referred to as "the second X-basis state generation and measurement check bit." The result confirmation unit 204 calculates the "second X-basis state generation and measurement check bit r2" according to the scheme described in Non-Patent Literature 2. The "second X-basis state generation and measurement check bit r2" corresponds to an X-basis check bit. The processing based on rule (c) is also referred to as an X-basis check process.

[0127] The measurement result v2 is a second measurement result v2 of the fourth measurement result (v1, v2, v3). The bit q2 is a second bit q2 of the measurement random number q1, q2, q3. Rule (d): applied when (θ1, θ2, θ3) = (0, 0, 1)

[0128] The result confirmation unit 204 derives a bit r3 from the public key (k1, k2, k3) and the trapdoor (tk1, tk2, tk3) received from the key information generation unit 202, the first measurement result (y1, y2, y3) received from the verification target device 300, and a third measurement result d3 of the third measurement result (d1, d2, d3). Then, the result confirmation unit 204 determines whether (Condition 1) and (Condition 2) below hold simultaneously.

[0129] If (Condition 1) and (Condition 2) are simultaneously true, the result confirmation unit 204 stores a determination result of "incorrect" in the additional storage device 903. If even one of (Condition 1) and (Condition 2) is not true, the result confirmation unit 204 stores a determination result of "correct" in the additional storage device 903. (Condition 1) “r3 differs from the measurement result v3 received by the verification target device 300” (Condition 2) “q3 is equal to 1”

[0130] Here, bit r3 is a check bit used to check whether the verification target device 300 has correctly created a state in the X-basis in the third quantum state in the fourth quantum state and correctly performed a Pauli X measurement. Thus, bit r3 is referred to as "the third X-basis state generation and measurement check bit." The result confirmation unit 204 calculates the "third X-basis state generation and measurement check bit r3" according to the scheme described in Non-Patent Literature 2. The "third X-basis state generation and measurement check bit r3" corresponds to an X-basis check bit. The processing based on rule (d) is also referred to as an X-basis check process.

[0131] The measurement result v3 is a third measurement result V3 of the fourth measurement result (v1, v2, v3). Bit q3 is a third bit q3 of the measurement random number (q1, q2, q3). Rule (e): applied when (θ1, θ2, θ3) = (1, 1, 1)

[0132] The result confirmation unit 204 calculates a generalized stabilizer measurement result 1, a generalized stabilizer measurement result 2, and a generalized stabilizer measurement result 3 as described below using the fourth measurement result (v1, v2, v3) received from the verification target device 300.

[0133] The result of the generalized stabilizer measurement 1: v1+δ(v2, 1)-v3

[0134] The result of the generalized stabilizer measurement 2: v2+δ(v1, 1)-v3

[0135] The result of the generalized stabilizer measurement 3: v3+δ(v1, 1)·v2

[0136] Here, the symbol "+" represents an exclusive OR of bits. In particular, 0+0 = 0, 0+1 = 1, 1+0 = 1, and 1+1 = 0. The symbol "-" represents a product of bits. Specifically, 0-0 = 0, 0-1 = 0, 1-0 = 0, and 1-1 = 1. "δ(x, 1)" is a so-called Kronecker delta function, which outputs "1" if "x" is "1" and "0" if "x" is not "1."

[0137] In addition, the result confirmation unit 204 derives a bit u1, a bit u2, and a bit u3 from the public key (k1, k2, k3) received from the key information generation unit 202 and the first measurement result (y1, y2, y3) and the third measurement result (d1, d2, d3) received from the verification target device 300.

[0138] Here, the bit u1 is a validity check bit for checking the validity of the result of the above generalized stabilizer measurement 1. The bit u2 is a validity check bit for checking the validity of the result of the above generalized stabilizer measurement 2. The bit u3 is a validity check bit for checking the validity of the result of the above generalized stabilizer measurement 3. The result confirmation unit 204 calculates the validity check bit u1, the validity check bit u2, and the validity check bit u3 according to the scheme described in Non-Patent Literature 2.

[0139] The validity check bit u1, the validity check bit u2 and the validity check bit u3 each correspond to a generalized stabilizer measurement result check bit.

[0140] Then, the result confirmation unit 204 stores a determination result of "incorrect" in the additional storage device 903 if (Condition 1) and (Condition 2) are simultaneously satisfied in any one of (1) to (3). Otherwise, the result confirmation unit 204 stores a determination result of "correct" in the additional storage device 903. (Condition 1) "(q1, q2, q3)=(1, 0, 0)" (Condition 2) “u1 differs from the result of the generalized stabilizer measurement 1: v1+δ(v2, 1)·v3” (Condition 1) "(q1, q2, q3)=(0, 1, 0)" (Condition 2) “u2 differs from the result of the generalized stabilizer measurement 2: v2+δ(v1, 1)·v3” (Condition 1) "(q1, q2, q3)=(0, 0, 1)" (Condition 2) “u3 differs from the result of the generalized stabilizer measurement 3: v3+δ(v1, 1)·v2”

[0141] After the quantum state generation and measurement sequence is performed N times, the result confirmation unit 204 calculates the probability E1, the probability E2, and the probability E3 in step S419 using the "incorrect" determination results obtained in step S410 and step S418. The result confirmation unit 204 calculates the probability E1, the probability E2, and the probability E3 in the following process.

[0142] Probability E1: the probability that an “incorrect” determination result is obtained in step S410 Probability E2: the probability that an “incorrect” determination result is obtained in step S418 when (θ1, θ2, θ3) is different from (1, 1, 1) Probability E3: the probability that an “incorrect” determination result is obtained in step S418 when (θ1, θ2, θ3) is (1, 1, 1)

[0143] In step S420, the result confirmation unit 204 receives the result of the self-test shown below. [Result 1]

[0144] If (θ1, θ2, θ3) generated in step S401 is (1, 1, 1), the result confirmation unit 204 obtains the result that “the verification target device 300 has generated a quantum state separated from the magic state of CCZ by a distance H1(E1, E2, E3)”.

[0145] H1(E1, E2, E3) is a function defined by the above-mentioned probability E1, the probability E2 and the probability E3.

[0146] The proximity between quantum states is measured using a metric commonly known as trace distance. The distance H1(E1, E2, E3) represents the proximity between the fourth quantum state and the magic state of CCZ. The result confirmation unit 204 calculates the degree of approximation between the fourth quantum state and the magic state of CCZ by calculating the function H1(E1, E2, E3). [Result 2]

[0147] When (θ1, θ2, θ3) generated in step S401 is (1, 1, 1), the result confirmation unit 204 obtains the result that “[the probability distribution of the measurement result obtained when a quantum state generated by the verification target device 300 is measured based on the measurement random number (q1, q2, q3) generated in step S414] and [the probability distribution of the measurement result obtained when the magic state of CCZ is measured based on the measurement random number (q1, q2, q3) generated in step S414] are separated from each other by a distance H2(E1, E2, E3).”

[0148] Here H2(E1, E2, E3) is a function defined by the probability E1, the probability E2 and the above-mentioned probability E3.

[0149] The proximity between probability distributions is measured with a metric commonly known as trace distance.

[0150] In a measurement based on the measurement random number (q1, q2, q3) generated in step S414 with respect to the CCZ magic state, if the value of the bit qi (where "i" is one of the numbers "1, 2, 3") is "0", a Pauli-Z measurement is indicated, while if the value of the bit qi is "1", a Pauli-X measurement is indicated.

[0151] The result confirmation unit 204 calculates the measurement accuracies of the Pauli Z measurement and the Pauli X measurement for the fourth quantum state by calculating the function H2(E1, E2, E3). [Reasons for results 1 and 2]

[0152] If the probability E1 that an “incorrect” determination result was obtained in step S410 is zero, this means that the verification target device 300 has correctly created a state space with the first quantum state stored therein.

[0153] If the probability E2 that an "incorrect" determination result was obtained in step S418 is zero, this means that the verification target device 300 correctly performed a Pauli-Z measurement and a Paul-X measurement on the fourth quantum state.

[0154] If the probability E3 that “incorrect” was obtained in step S418 is zero, this means that the verification target device 300 has correctly generated the magic state of CCZ.

[0155] Accordingly, if each of the probability E1, the probability E2 and the probability E3 is zero, the distance H1 and the distance H2 are also zero.

[0156] If at least one of the probability E1, the probability E2, and the probability E3 is non-zero, this means that the verification target device 300 did not correctly perform a Pauli-Z measurement and / or a Pauli-X measurement on the fourth quantum state and / or that the verification target device 300 did not correctly generate the magic state of CCZ. Therefore, if the probability E1, the probability E2, and the probability E3 are larger, this means that the quantum state generated by the verification target device 300 is farther from the magic state of CCZ and / or from an ideal Pauli measurement (the accuracy of the Pauli measurement is lower).

[0157] An explicit relationship (a specific functional form) between the probability E1, the probability E2 and the probability E3 that the determination results are "incorrect" was obtained in steps S410 and S418, and the distance H1(E1, E2, E3) and the distance H2(E1, E2, E3) are determined by a calculation based on the principle of quantum mechanics. [On the value of “N”]

[0158] The value "N," or the number of repetitions of the quantum state generation and measurement sequence, is determined by the calculation accuracy T of the probability E1, probability E2, and probability E3 calculated in step S419, as well as the probability P of obtaining [Result 1] and [Result 2]. Here, the probability P is the probability that the result is correct. That is, in the case of [Result 1], the probability P is the probability that the result that "the verification target device 300 has generated a quantum state separated from the magic state of CCZ by the distance H1(E1, E2, E3)" is correct. A calculation formula (Expression 1) for the value of N using the calculation accuracy T and the probability P is shown below. However, Expression 1 shows an example of calculating the value of N; the value of N can also be determined in other ways.That is, the value of N can be determined in any way as long as it is determined from the “calculation accuracy T” and the “probability P”. N=(1 / 2T2)×ln(3 / (1−P)) In expression 1, “In” represents a natural logarithm.

[0159] The value of N in expression 1 can be derived using the probability inequality (Hoeffding inequality) known from statistical mathematics. ***Description of the effects of the embodiment***

[0160] The present embodiment enables the self-test to be performed even for the “magic state of CCZ” within the same framework as in Non-Patent Literature 2.

[0161] In the present embodiment, a classical computer can verify a black-box device whose operation is unknown. Thus, the present embodiment can verify the accuracy of generating and measuring the "magic state of CCZ," a quantum state essential for the realization of quantum computations. That is, the present embodiment enables quantum verification. ***Additional description of the hardware configuration***

[0162] Finally, the hardware configuration of the verification device 200 is additionally described.

[0163] The Fig. The processor 901 shown in Fig. 4 is an IC (integrated circuit) that performs the processing.

[0164] The processor 901 is a CPU (central processing unit), a DSP (digital signal processor), or the like.

[0165] The Fig. The main memory device 902 shown in Figure 4 is a RAM (Random Access Memory).

[0166] At the Fig. The additional storage device 903 shown in Fig. 4 is a ROM (Read Only Memory), a flash memory, an HDD (Hard Disk Drive) and the like.

[0167] The Fig. The communication device 904 shown in Fig. 4 is an electronic circuit that performs data communication processing.

[0168] The communication device 904 is, for example, a communication chip or a NIC (Network Interface Card).

[0169] Furthermore, the auxiliary storage device 903 also stores an OS (operating system).

[0170] At least a portion of the OS is executed by processor 901.

[0171] The processor 901 executes the program for implementing the functions of the data generation unit 201, the key information generation unit 202, the random number generation unit 203, and the result confirmation unit 204 while executing at least part of the OS.

[0172] By executing the OS by means of the processor 901, task management, memory management, file management, communication control and the like are performed.

[0173] At least any of information, data, signal values, and variable values ​​indicating the results of processing by the data generation unit 201, the key information generation unit 202, the random number generation unit 203, and the result confirmation unit 204 are stored in at least any one of the main storage device 902, the auxiliary storage device 903, and a register and a cache memory in the processor 901.

[0174] The programs for implementing the functions of the data generation unit 201, the key information generation unit 202, the random number generation unit 203, and the result confirmation unit 204 can be stored in a portable recording medium such as a magnetic disk, a flexible disk, an optical disk, a compact disk, a Blu-ray (registered trademark) disk, and a DVD. Then, the portable recording medium storing the programs for implementing the functions of the data generation unit 201, the key information generation unit 202, the random number generation unit 203, and the result confirmation unit 204 can be distributed.

[0175] The “units” of the data generation unit 201, the key information generation unit 202, the random number generation unit 203, and the result confirmation unit 204 can be read as “circuits” or “steps” or “operations” or “processes” or “circuit”.

[0176] Verification device 200 can be implemented by a processing circuit. The processing circuit is, for example, a logic IC (integrated circuit), a GA (gate array), an ASIC (application-specific integrated circuit), or an FPGA (field-programmable gate array).

[0177] In this case, the data generation unit 201, the key information generation unit 202, the random number generation unit 203 and the result confirmation unit 204 are implemented as parts of the processing circuit.

[0178] In this specification, a higher-level concept of processor and processing circuitry is referred to as “processing circuitry.”

[0179] That is, processors and processing circuits are each a concrete example of a “processing circuit”. LIST OF REFERENCE SYMBOLS

[0180] 100: Quantum verification system; 101: Classical communication channel; 200: Verification device; 201: Data generation unit; 202: Key information generation unit; 203: Random number generation unit; 204: Result confirmation unit; 300: Verification target device; 301: Quantum state generation unit; 302: Quantum state measurement unit

Claims

[1] Classical computer (200), including: a state space probability calculation unit (204) for calculating, using a first measurement result and a second measurement result, a state space probability, which is a probability that a quantum computer (300) has not correctly created a state space having a first quantum state stored therein, wherein the first quantum state is a quantum state generated by the quantum computer, wherein the first measurement result is a result of the quantum computer measuring the first quantum state, and the second measurement result is a result of the quantum computer measuring a second quantum state, wherein the second quantum state is a quantum state after a change in the first quantum state caused by the measurement of the first quantum state; a Pauli measurement probability calculation unit (204) for calculating, using a third measurement result, a fourth measurement result, and the first measurement result, a Pauli measurement probability, which is a probability that the quantum computer has not correctly performed a Pauli Z measurement and a Pauli X measurement on a fourth quantum state, wherein the third measurement result is a result of the quantum computer measuring a third quantum state, the third quantum state being a quantum state after a change in the first quantum state caused by the measurement of the first quantum state and different from the second quantum state, and the fourth measurement result is a result of the quantum computer measuring the fourth quantum state, the fourth quantum state being a quantum state after a change in the third quantum state,caused by the measurement of the third quantum state;, a magic state probability calculation unit (204) for calculating, using the first measurement result, the third measurement result, and the fourth measurement result, a magic state probability that the quantum computer has not generated a magic state of CCZ (Controlled Controlled-Z); and an approximation accuracy calculation unit (204) for calculating a degree of approximation between the fourth quantum state and the magic state of CCZ, as well as measurement accuracies of the Pauli-Z measurement and the Pauli-X measurement on the fourth quantum state, using the state space probability, the Pauli measurement probability, and the magic state probability. [2] A classical computer according to claim 1, further comprising: a key information generation unit (202) for generating a public key and a trapdoor from initial data, wherein the quantum computer generates the first quantum state based on the public key, the state space probability calculation unit calculates the state space probability using the first measurement result, the second measurement result and the public key, the Pauli measurement probability calculation unit calculates the Pauli measurement probability using the first measurement result, the third measurement result, the fourth measurement result, the public key and the trapdoor, and the magic state probability calculation unit calculates the magic state probability using the first measurement result, the third measurement result, the fourth measurement result, the public key, and the trapdoor. [3] A classical computer according to claim 2, wherein the Pauli measurement probability calculation unit calculates the Pauli measurement probability by performing a Z-basis check process to generate, using the first measurement result and the public key, a Z-basis check bit for checking whether or not the quantum computer has correctly created a state in Z-basis for the fourth quantum state and correctly performed the Pauli Z measurement, and to determine whether or not the Z-basis check bit agrees with the fourth measurement result, and an X-basis check process to generate, using the first measurement result, the third measurement result, the public key, and the trapdoor, an X-basis check bit for checking whether or not the quantum computer has correctly created a state in X-basis for the fourth quantum state and correctly performed the Pauli X measurement, and to determine whether or not the Z-basis check bit agrees with the fourth measurement result. [4] The classical computer according to claim 2, wherein the magic state probability calculation unit calculates the magic state probability by: calculating a generalized stabilizer measurement result using the fourth measurement result and the Kronecker delta; generating a generalized stabilizer measurement result check bit for checking the validity of the generalized stabilizer measurement result using the first measurement result, the third measurement result, the public key, and the trapdoor; and determining whether or not the generalized stabilizer measurement result agrees with the generalized stabilizer measurement result check bit. [5] Classical computer according to claim 1, further comprising: a random number generation unit (203) for generating a probability calculation random number which is a random number for determining which of a state space probability calculation, a Pauli measurement probability calculation, and a magic state probability calculation should be performed, wherein Depending on a value of the probability calculation random number, the classical computer performs one of a calculation of the state space probability by the state space probability calculation unit, a calculation of the Pauli measurement probability by the Pauli measurement probability calculation unit, and a calculation of the magic state probability by the magic state probability calculation unit. [6] Classical computer according to claim 1, wherein the quantum computer executes a quantum state generation and measurement sequence several times, wherein the quantum state generation and measurement sequence is formed from generation of the first quantum state and measurement of the first quantum state and measurement of the second quantum state or measurement of the third quantum state and measurement of the fourth quantum state, the state space probability calculation unit calculates the state space probability using the first measurement result and the second measurement result for the quantum state generation and measurement sequence, respectively, the Pauli measurement probability calculation unit calculates the Pauli measurement probability using the first measurement result, the third measurement result, and the fourth measurement result for the quantum state generation and measurement sequence, respectively, and the magic state probability calculation unit calculates the magic state probability using the first measurement result, the third measurement result, and the fourth measurement result for the quantum state generation and measurement sequence, respectively. [7] Classical computer according to claim 3, further comprising: a random number generation unit (203) for generating a measurement random number, which is a random number for use in measuring the fourth quantum state by the quantum computer, wherein the quantum computer measures the fourth quantum state using the measurement random number, and the Pauli measurement probability calculation unit in the Z-base check process, determines whether the Z-base check bit matches the fourth measurement result or not, and determines whether the measurement random number has a prescribed value or not, and in the X-base check process, determines whether the X-base check bit agrees with the fourth measurement result or not, and determines whether the measurement random number has a value other than the prescribed value or not. [8] Classical computer according to claim 4, further comprising: a random number generation unit (203) for generating a measurement random number, which is a random number for use in measuring the fourth quantum state by the quantum computer, wherein the quantum computer measures the fourth quantum state using the measurement random number, and The magic state probability calculation unit determines whether the generalized stabilizer measurement result agrees with the generalized stabilizer measurement result check bit, determines whether the measurement random number has a prescribed value, and calculates the magic state probability. [9] Information processing method, where a classical computer (200) calculates, using a first measurement result and a second measurement result, a state space probability, which is a probability that a quantum computer (300) has not correctly created a state space in which a first quantum state is stored, wherein the first quantum state is a quantum state generated by the quantum computer, wherein the first measurement result is a result of the quantum computer measuring the first quantum state, and the second measurement result is a result of the quantum computer measuring a second quantum state, wherein the second quantum state is a quantum state after a change in the first quantum state caused by the measurement of the first quantum state; the classical computer calculates a Pauli measurement probability using the third measurement result, the fourth measurement result, and the first measurement result, which is a probability that the quantum computer has incorrectly performed a Pauli Z measurement and a Pauli X measurement on a fourth quantum state, wherein the third measurement result is a result of the quantum computer measuring a third quantum state, the third quantum state being a quantum state after a change in the first quantum state caused by the measurement of the first quantum state and different from the second quantum state, and the fourth measurement result is a result of the quantum computer measuring the fourth quantum state, the fourth quantum state being a quantum state after a change in the third quantum state caused by the measurement of the third quantum state; the classical computer calculates a magic state probability using the first measurement result, the third measurement result, and the fourth measurement result, which is a probability that the quantum computer has not generated a magic state of CCZ (Controlled Controlled-Z); and the classical computer calculates a degree of approximation between the fourth quantum state and the magic state of CCZ, as well as measurement accuracies of the Pauli-Z measurement and the Pauli-X measurement on the fourth quantum state, using the state space probability, the Pauli measurement probability, and the magic state probability. [10] Information processing program that causes a classical computer (200) to execute: a state space probability calculation process for calculating, using a first measurement result and a second measurement result, a state space probability that a quantum computer (300) has incorrectly created a state space having a first quantum state stored therein, wherein the first quantum state is a quantum state generated by the quantum computer, the first measurement result being a result of the quantum computer measuring the first quantum state, and the second measurement result being a result of the quantum computer measuring a second quantum state, the second quantum state being a quantum state after a change in the first quantum state caused by the measurement of the first quantum state; a Pauli measurement probability calculation process for calculating, using a third measurement result, a fourth measurement result, and the first measurement result, a Pauli measurement probability, which is a probability that the quantum computer has incorrectly performed a Pauli Z measurement and a Pauli X measurement on a fourth quantum state, wherein the third measurement result is a result of the quantum computer measuring a third quantum state, the third quantum state being a quantum state after a change in the first quantum state caused by the measurement of the first quantum state and different from the second quantum state, and the fourth measurement result is a result of the quantum computer measuring the fourth quantum state, the fourth quantum state being a quantum state after a change in the third quantum state,caused by the measurement of the third quantum state;, a magic state probability calculation process for calculating a magic state probability, which is a probability that the quantum computer has not generated a magic state of CCZ (Controlled Controlled-Z), using the first measurement result, the third measurement result, and the fourth measurement result; and an approximation accuracy calculation process to calculate a degree of approximation between the fourth quantum state and the magic state of CCZ, as well as measurement accuracies of the Pauli-Z measurement and the Pauli-X measurement on the fourth quantum state using the state-space probability, the Pauli measurement probability, and the magic state probability.