Computing device, calculating method and program
A quantum-classical hybrid algorithm efficiently solves the LWE problem by converting it into one-dimensional LWE-like problems and phase estimation problems with errors, addressing the inefficiency of existing algorithms and ensuring accurate solutions.
Patent Information
- Application Number
- JP2025012242
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-07
- Filing Date
- 2025-01-28
- Publication Date
- 2025-08-20
AI Technical Summary
Existing algorithms for solving the Learning with Errors (LWE) problem are not polynomial-time reduction algorithms, making it uncertain if they can solve the problem even with sufficient time and memory.
A quantum-classical hybrid algorithm is used to convert the LWE problem into a set of one-dimensional LWE-like problems, which are then converted into phase estimation problems with errors, solved using a quantum-classical hybrid algorithm, and finally converted back into solutions for the LWE problem.
This approach allows for efficient solving of the LWE problem, even when the initial assumption about lattice point distribution is not strictly accurate, by eliminating errors through repeated calculations and selecting the most frequent answer.
Smart Images

Figure 2025121868000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to quantum computing technology. [Background technology]
[0002] The LWE (Learning with Errors) problem is a problem derived from machine learning, and is also used as a candidate for next-generation quantum-safe public key cryptography. Various algorithms for solving the LWE problem have been researched. For example, Non-Patent Document 1 discloses an algorithm that reduces the LWE problem to the maximal independent set problem (MIS). This technology can be applied to solving the LWE problem by combining it with an existing algorithm on a quantum annealing machine that solves the MIS. [Prior art documents] [Non-patent literature]
[0003] [Non-Patent Document 1] Yasuhito Kawano, A reduction from an LWE problem to maximum independent set problems, Scientific Reports 13:7130 (2023) DOI 10.1038 / s41598-023-34366-7. Summary of the Invention [Problem to be solved by the invention]
[0004] However, since the algorithm disclosed in Non-Patent Document 1 is not a polynomial-time reduction algorithm, it cannot be guaranteed that the algorithm disclosed in Non-Patent Document 1 can solve the LWE problem even if there is sufficient time and memory.
[0005] In view of these points, we provide a technique for efficiently solving LWE problems. [Means for solving the problem]
[0006] The computing device uses information for identifying an LWE problem, converts the LWE problem into a set of one-dimensional LWE-like problems, converts the set of one-dimensional LWE-like problems into a set of phase estimation problems with errors, solves the set of phase estimation problems with errors to obtain a set of solutions to the phase estimation problems with errors, converts the set of solutions to the phase estimation problems with errors into solutions to an LWE problem, and outputs the solutions to the LWE problems. [Effects of the Invention]
[0007] This allows us to solve the LWE problem efficiently. [Brief explanation of the drawings]
[0008] [Figure 1] FIG. 1 is a diagram for explaining a method for solving a two-sample one-dimensional LWE problem modulo q in this embodiment. [Figure 2] FIG. 2 is a diagram for explaining a method for solving an m-sample n-dimensional LWE problem modulo q in this embodiment. [Figure 3] FIG. 3 is a block diagram illustrating the overall configuration of the computing device according to the embodiment. [Figure 4] FIG. 4 is a block diagram illustrating the configuration of the LWE returning device according to the embodiment. [Figure 5] FIG. 5 is a block diagram illustrating the configuration of the problem conversion device according to the embodiment. [Figure 6] FIG. 6 is a block diagram illustrating the configuration of the solution finding device of the embodiment. [Figure 7] FIG. 7 is a block diagram illustrating the configuration of a solution conversion device according to an embodiment. [Figure 8] FIG. 8 is a diagram illustrating the relationship between the dual grid, the interpolation point vectors, and the subdivision point vectors. [Figure 9] FIG. 9 is a diagram illustrating a lattice formed by a dual lattice and interpolation point vectors. [Figure 10]FIG. 10 is a diagram illustrating the relationship between the dual lattice of the lattice on which the LWE problem is constructed, the lattice formed by the interpolation point vectors, and the labels. [Figure 11] FIG. 11 is a diagram illustrating the operation content by unitary transformation. [Figure 12] Fig. 12A is a diagram illustrating an input quantum state, Fig. 12B is a diagram illustrating a quantum state obtained by performing a state alignment operation on the input quantum state, and Fig. 12C is a diagram illustrating a quantum state obtained by applying a direct product of two 13-dimensional inverse quantum Fourier transforms to the quantum state obtained by performing a state alignment operation on the input quantum state. [Figure 13] FIG. 13 is a diagram illustrating the relationship between the observation results and the labels. [Figure 14] FIG. 14 is a diagram illustrating the probability distribution of the value of the label Lj(z1B) corresponding to the observation result z1. [Figure 15] FIG. 15 is a block diagram illustrating the configuration of the solution finding device of the embodiment. [Figure 16] 16A and 16B are diagrams illustrating a non-commutative diagram of an embodiment, and a portion of the non-commutative diagram of an embodiment, respectively. [Figure 17] FIG. 17 is a diagram illustrating the relationship between the position in the region and the phase. [Figure 18] Fig. 18A is a diagram illustrating a quantum state obtained by applying the direct product of two 13-dimensional inverse quantum Fourier transforms to an input quantum state. Fig. 18B is a diagram illustrating a probability distribution of the value of label L1(v'1) corresponding to observation result MO1. DETAILED DESCRIPTION OF THE INVENTION
[0009] Hereinafter, an embodiment of the present invention will be described. [principle] First, the principle of this embodiment will be explained. In this embodiment, a quantum-classical hybrid algorithm for efficiently solving the Learning with Errors (LWE) problem is proposed. Using the quantum-classical hybrid algorithm proposed in this embodiment, it can be considered that the normal LWE problem can be efficiently solved. In particular, under the following Assumption 1, the LWE problem can be efficiently solved with a high probability. Assumption 1: A hypersphere having the same volume as the absolute value of the determinant of the basis of a lattice contains only one lattice point of that lattice. This assumption is also assumed in a well-known algorithm for calculating the length of the closest vector called the Gaussian Heuristic, and is considered to be empirically almost correct for random lattices. However, in this embodiment, this Assumption 1 is not essential, and even if Assumption 1 does not strictly hold, the LWE problem can be efficiently solved. That is, when Assumption 1 does not strictly hold, every time, an exact solution is not necessarily obtained, but by repeating the same calculation multiple times and selecting the answer with the highest frequency, errors can be eliminated and the correct answer can be obtained. In other words, even when Assumption 1 does not strictly hold, if the distribution of the final solution is biased towards the correct answer (for example, if Assumption 1 almost holds), the LWE problem can be efficiently solved. For example, if a hypersphere having the same volume as the absolute value of the determinant of the basis of a lattice contains almost only one lattice point of that lattice regardless of the position of the hypersphere, the LWE problem can be efficiently solved. Note that "almost one" may be, for example, 0, 1, 2, 3, or 4 or more.
[0010] <Definition of symbols> m, n, m', n': m, n, m', n' are positive integers. For example, m' satisfies m'≥m, and m' = m. For example, n' = 1. α: α is a positive real number. j: j is a positive integer, and j = 1,..., m'. q, q': q, q' are integers greater than 1 and satisfy 5q / 3 < q'. For example, q, q' are prime numbers. Z q :Z q denotes the quotient ring Z / qZ modulo q. Z:Z represents the set of integers. Q: Q represents the set of rational numbers. R: R represents the set of real numbers. e:e represents Napier's constant. i:i represents the imaginary unit. I m :I m represents an m×m identity matrix. |β0|: |β0| represents the absolute value of β0. ||β1||:||β1|| represents the norm of β1. #β: #β represents the number of elements belonging to set β. det(β3): det(β3) represents the determinant of β3. β4 T :β4 T represents the transposition of β4. 〈β1,β2〉:〈β1,β2〉 represents the dot product of β1 and β2. <β1|:<β1| represents the horizontal vector β1. |β1>:|β1> represents the vertical vector β1. β1:=β2:β1:=β2 means that β1 is defined as β2. Y [a1:a2,b1:b2] :Y [a1:a2,b1:b2] is r ows ×c olumns It represents the submatrix ranging from row a1 (including a1) to row a2 (including a2) and from column b1 (including b1) to column b2 (including b2) of matrix Y. Here, a1, a2, b1, b2, r ows , and c olumns is a positive integer, 1≦a1 <a2≦r ows , and 1≦b1 <b2≦c olumns Satisfy Y [a1:a2,b1:b2] The first (or last) row (or column) in the subscript [a1:a2,b1:b2] of the [1:a2,b1:b2] Y [:a2,b1:b2] and Y [a1:a2,1:b2] Y [a1:a2,:b2] and Y [a1:rows,b1:b2] Y [a1:,b1:b2]and Y [a1:a2,b1:columns] Y [a1:a2,b1:] and Y [1:a2,1:b2] Y [:a2,:b2] and Y [a1:rows,b1:columns] Y [a1:,b1:] For example, Y [:a2,:b2] is Y [a1:a2,b1:b2] Here, the subscript "rows" means the upper left a2 × b2 matrix of "r ows " and "columns" is "c olumns " Also, Y [a1:a2,b1:b2] In the subscripts [a1:a2,b1:b2], negative values mean the number of rows (or columns) from the last row (or column). [-a1:,-b1:] is Y [a1:a2,b1:b2] This means the a1×b1 matrix at the bottom right of Y [a1,b1] :Y [a1,b1] is r ows ×c olumns Represents the element in row a1, column b1 of matrix Y. Here, 1≦a1≦r ows , and 1≦b1≦c olumns Meet the following. γ1mod β0:y1=γ1mod β0 represents a positive real number y1<β0 that satisfies γ1=x1β0+y1, where β0, γ1 are positive real numbers and x1 is a non-negative integer. β1mod β0: For real number β0 and vector β1, β1mod β0 is the element β of vector β1. 1,1 ,...,β 1,max β for 1,1 mod β0,...,β 1,max A vector with elements mod β0 (β 1,1 mod β0,...,β 1,max mod β0), where max is a positive integer.
number
Number
[0011] <LWE (Learning with Errors) Problem> Assume that a parameter set (m, n, q, α) is given. Here, m, n, and q are the number of samples, dimension, and modulus of the LWE problem, respectively. α is called the relative error. Let the standard deviation σ be σ = αq. Let N(0, σ 2 ) be a Gaussian distribution on Z q with mean 0 and standard deviation σ. Also, let s ∈ Z q n be an n-dimensional column vector. A is an m × n matrix
Number
Number
[0012] <LWE-Like Problem> In the LWE problem, all elements of the error vector ε follow the same Gaussian distribution N(0, σ 2 ). Also, the elements of the target vector t and the error vector ε are integer elements. The problem obtained by relaxing the conditions of such an LWE problem as follows is called an LWE-like problem. · For m' LWE problems, the m' m-dimensional error vectors ε'1,…,ε' m' each element ε' j,μ (where j = 1,..., m' and μ = 1,..., m') do not follow the same standard deviation σ, but may follow standard deviations σ' j,μ respectively. That is, the standard deviation σ' j that the element ε' j,μ of the error vector ε' j,μ follows may be determined for each index j = 1,..., m' and μ = 1,..., m'. · Rational numbers are allowed as elements of the target vector t' j and the error vector ε' j . That is, assume that the parameter set (m', n', q', {α' j,μ} j=1,...,m',μ=1,...,m' ) is given. Here, m', n' and q' are the number of samples, dimension, and modulus of the LWE-like problem respectively. α' j,μ is the relative error. Let the standard deviation σ' j,μ be σ' j,μ = α' j,μ q'. Let N(0, σ' j,μ 2 ) be {(t'j +z) mod q'|z∈Z} with mean 0 and standard deviation σ' j,μ Let s' be a Gaussian distribution. j ∈Z q' n' is an n'-dimensional column vector. j is an m'×n' matrix
number
number
[0013] <grid> For integer q, the lattice ∧ q (X) is defined as follows: ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q} That is, the lattice ∧ q (X) is any s"∈Z n x∈Z for which x≡s"X mod q holds m where X is a set of n m-dimensional column vectors x1,…,x n ∈Z m The set {x1,…,x n}, that is, X=[x1,…,x n ] T In other words, the lattice ∧ q (X) is the set X={x1,…,x n} vector x1,…,x n and m-dimensional vector qu1,…,qu m where u1,…,u m are m-dimensional unit vectors, where u j The jth element of (j=1,...,m) is 1, and the other elements are 0. q The basis of (X) is X=[x1,…,x n ]T (m+n)×m matrix when
number
number
[0014] where X=A T That is, let X be the matrix A T Then, the lattice ∧ q (A T ) becomes as follows: ∧ q (A T ):={x∈Z m |∃s"∈Z n st x≡s"A T mod q} where, (m+n) × m matrix
number
number
[0015] <Dual Lattice> Lattice ∧ q Dual lattice of (X) ∧ q ⊥ (X) is defined as follows: ∧ q ⊥ (X):={y∈Z m |<x,y> ≡0 mod q for all x∈∧ q (X)} That is, the dual lattice ∧ q ⊥ (X) is the set of all vectors x∈∧ q About (X)<x,y> y∈Z such that ≡0 mod q m Also, the lattice ∧ q (A T ) dual lattice ∧ q ⊥ (A T ) becomes: ∧ q ⊥ (A T ):={y∈Z m |<x,y> ≡0 mod q for all x∈∧ q (A T )} Here, a 2m×m matrix
number
number
number
[0016] The above details are described below. Reference 1: Cohen, Henri: A Course in Computational Algebraic Number Theory, Springer-Verlag, ISBN 0-387-55640-0 (1993). Reference 2: D. Micciancio and S. Goldwasser: Complexity of Lattice Problems, A Cryptographic Perspective, Kluwer Academic Publishers, ISBN: 0792376889 (2002). Reference 3: Steven D. Galbraith, Mathematics of Public Key Cryptography, Cambridge University Press, ISBN: 1107013925 (2012).
[0017] <Structure of the method of this embodiment> The overall method of this embodiment will be described below. Step A: Using a classical algorithm, reduce the input LWE problem to a set of phase estimation problems with errors. Step B: Using a quantum-classical hybrid algorithm, solve all the error-bearing phase estimation problems obtained in Step A. Step C: Using a classical algorithm, calculate the solution to the LWE problem from the set of solutions to the phase estimation problem with errors obtained in Step B.
[0018] Furthermore, step A can be divided into the following two steps, steps A1 and A2. Step A1: Reduce the input LWE problem to a set of one-dimensional LWE-like problems. Step A2: The set of one-dimensional LWE-like problems obtained in step A1 is converted into a set of phase estimation problems with errors. The method used in step A1 is LWE reduction. LWE reduction allows for various parameters of the LWE problem to be varied. Step A1 includes a method (step A1a) that can be applied only when the number of samples m and the dimension n of the LWE problem are m=2 and n=1, respectively, and a method (step A1b) that can be applied when the number of samples m and the dimension n are arbitrary. The method in step A1a is called "LWE reduction in the Fibonacci setting," and the method in step A1b is called "LWE reduction in the extended Fibonacci setting." Step A1a (m=2 and n=1): LWE reduction in the Fibonacci setting Step A1b (for any m and n): LWE reduction for the extended Fibonacci setting The LWE reduction in the Fibonacci setting is a reduction method inspired by the Fibonacci sequence. Using the LWE reduction in the Fibonacci setting, a 2-sample 1-dimensional LWE problem (m=2 and n=1) can be reduced to another 1-dimensional LWE problem with m' samples. There are no restrictions on the modulus q of LWE problems to which the LWE reduction in the Fibonacci setting can be applied, but it can only be applied to 2-sample 1-dimensional LWE problems (m=2 and n=1). This restriction on the number of samples m and the dimension n (m=2 and n=1) arises from the fact that the Fibonacci sequence is formed by the sum of two numbers. On the other hand, in order to remove the constraints on the number of samples m and dimension n in the LWE reduction in the Fibonacci setting, the Fibonacci n-step number, an extension of the Fibonacci sequence, is used to create the LWE reduction in the extended Fibonacci setting. Using the LWE reduction in the extended Fibonacci setting, an m-sample, n-dimensional LWE problem for any m and n can be reduced to another m'-sample, 1-dimensional LWE problem. The LWE reduction in the extended Fibonacci setting can be applied to LWE problems with any number of samples m and dimension n. Furthermore, there are no restrictions on the modulus q of LWE problems to which the LWE reduction in the extended Fibonacci setting can be applied. Therefore, the LWE reduction in the extended Fibonacci setting can be applied to LWE problems with any modulus q, any number of samples m, and any dimension n. However, by using the "LWE reduction in the standard setting" (see, for example, Non-Patent Document 1), this LWE problem can be transformed into an LWE problem modulo a power of 2, and then applying the LWE reduction in the extended Fibonacci setting to the resulting LWE problem modulo a power of 2, making it possible to make the algorithm more efficient and reduce errors.
[0019] As a result, the solution to the LWE problem in this embodiment is as follows: <case 1:m="2かつn=1(図1)"> Step A1a: By reducing the input LWE problem (a 2-sample 1-dimensional LWE problem modulo q) to the Fibonacci setting of LWE, it is reduced to a set of 1-dimensional LWE-Like problems (2-sample 1-dimensional LWE problems modulo q', that is, m' = m = 2, n' = 1). Step A2: Convert the set of 1-dimensional LWE-Like problems (2-sample 1-dimensional LWE problems modulo q') obtained in Step A1a into a set of phase estimation problems with error. Step B: Use a quantum-classical hybrid algorithm to solve all the phase estimation problems with error obtained in Step A2. The set of solutions of the obtained phase estimation problems with error coincides with the set of solutions of the 1-dimensional LWE-Like problems obtained in Step A1a. Step C: Use a classical algorithm to calculate the solution of the LWE problem from the set of solutions of the phase estimation problems with error obtained in Step B.
[0020] <Case 2: Arbitrary m and n (Figure 2)> Step A0: By reducing the input LWE problem (an m-sample n-dimensional LWE problem modulo q) to the standard setting of LWE (see, for example, Non-Patent Document 1, etc.), it is converted into an LWE problem modulo a power of 2. However, Step A0 is optional. Step A1b: By reducing the input LWE problem (when Step A0 is omitted: an m-sample n-dimensional LWE problem modulo q) or the LWE problem modulo a power of 2 obtained in Step A0 (when Step A0 is executed: an m-sample n-dimensional LWE problem modulo a power of 2) to the extended Fibonacci setting of LWE, it is reduced to a set of 1-dimensional LWE-Like problems (m-sample 1-dimensional LWE problems modulo q', that is, m' = m, n' = 1). Step A2: Convert the set of 1-dimensional LWE-Like problems (m-sample 1-dimensional LWE problems modulo q') obtained in Step A1b into a set of phase estimation problems with error. Step B: Using the quantum-classical hybrid algorithm, solve all the phase estimation problems with errors obtained in step A2. The set of solutions to the phase estimation problems with errors obtained is identical to the set of solutions to the one-dimensional LWE-like problem obtained in step A1b. Step C: Using a classical algorithm, calculate the solution to the LWE problem from the set of solutions to the phase estimation problem with errors obtained in Step B.
[0021] <Overall Method of the Embodiment> Next, the overall method of the embodiment will be described. <Step A1> In step A1, the LWE problem described above is reduced to (A' j ,t' j ,q',{σ' j,μ } j=1,...,m,μ=1,...,m ) is given, the following equation (3) is satisfied, and the error vector ε' j Element ε' of j,μ is a Gaussian distribution N(0, σ' j,μ 2 ) the solution s' j ∈Z q' n' (or, ε' j ) for a one-dimensional LWE-like problem (parameter set (m, n=1, q', {α' j,μ } j=1,...,m,μ=1,...,m ) to generate information to reduce (transform) it to a 1-dimensional LWE-like problem for
number
[0022] <Step A2> In step A2, the set of one-dimensional LWE-like problems for j = 1,...,m in step A1 is transformed into a set of phase estimation problems with errors. These phase estimation problems with errors are solved by solving the quantum state |Ψ j,t 〉 and unitary transformation (unitary operator) U j (γ) The solution s' where (γ=0,1,...,q'-1) satisfies the following equation (4) j (j=1,...,m). Unlike general phase estimation problems, equation (4) is not an equality but an approximation.
number
[0023] We will explain equation (4) in more detail. Here, we will fix j = 1,...,m. Equation (3) for the one-dimensional LWE-like problem can be expressed as equation (5) below.
number
number
number
number
[0024] Here, the set of m-dimensional vectors Ω j The uniform superposition state (quantum state) |Ψ j,0 Define |Ψ j,0 > is expressed as the following equation (8).
number
number
number
number
[0025] The unitary transformation U for the above mentioned phase estimation problem with errors j (γ) is for any y"∈Z q' is an operator that satisfies the following equation (12) for
number
[0026] Next, the quantum state |Ψ expressed by equation (9) j,t > and the unitary transformation U expressed by equation (12) j (γ) As mentioned above, the quantum state |Ψ in Eq. (9) j,t > can be approximated as in equation (11).
number
number
number
number
[0027] <Step B> In step B, the set of phase estimation problems with errors (equation (4)) explained in step A2 is solved to obtain s' for j=1,...,m. j First, we find the set of superposition states |Ψ in Eq. (8). j,0 > and generate this superposition state |Ψ j,0 By applying a phase rotation gate to the quantum state |Ψ j,t > to generate the quantum state |Ψ j,t > to satisfy equation (4) j As a method for identifying the phase, a "standard algorithm" for solving a general phase estimation problem is known (see, for example, Reference 4). Reference 4: Nielsen and Chuang: Quantum Computation and Quantum Information, Cambridge University Press (2000). Section 5.2 "Phase Estimation"
[0028] In this embodiment, this standard algorithm is not used, and a simpler algorithm is used: j In this embodiment, first, the quantum state (input quantum state) |Ψ obtained as described above is used. j,t > for state alignment operation X j and quantum state X j |Ψ j,t > to obtain the state alignment operation X j That is, for any x∈Ω j X against j |x'''>=|x'''C j mod q'>. In general, X j is not necessarily a unitary transformation, but for simplicity, we use X j is defined as the following equation (17).
number
number
number
[0029] Next, the quantum state X obtained as above j |Ψ j,t > the inverse quantum Fourier transform
number
number
number
[0030] Next, the quantum state obtained as above
number
[0031] Next, the observation result z obtained as described above j Label using L j (z j B)∈Z q' Here, we obtain the label L j (v)∈Z q' is the lattice L(B):=∧ q (A T ) is the label corresponding to the grid point of the label L j (v) is the function value of v∈L(B), and is the function value of the lattice L(B~ j ) corresponding to the grid points L~ j The label L obtained in this way is the dual label of (v~). j (z j B)∈Z q' has a high probability of finding the solution s' j Therefore, the obtained label L j (z j B) Based on the solution s' j where L j (z j B) is s' j Although the probability of matching is not 1, for example, by repeating the same operation many times, multiple labels L for each j can be obtained. j (z j B), and for each j, the most frequently occurring label L j (z j B) Solve s' j Then, the solution s' is obtained with almost 1 probability. j can be obtained.
[0032] <Step C> In step C, first, the solution s' obtained in step B is j (j=1,...,m), Z q' The difference vector t-ε is obtained by solving the simultaneous linear equations in . The details of this process will be described later. Furthermore, using the difference vector t-ε, integer q, and matrix A, a solution s∈Z that satisfies As≡t-ε mod q is obtained. q n get.
[0033] <Details of the method of the embodiment> Next, each step will be described in detail. <Idea for Step A1 (LWE reduction)> As mentioned above, the LWE problem is a problem where equation (1) is satisfied and the elements of the error vector ε are Gaussian distributed N(0, σ 2 ) is the problem of finding a solution s (or ε) that obeys the lattice ∧. q (A T ) , where the dual lattice ∧ q ⊥ (A T The quantum superposition state |Ψ0〉 corresponding to the lattice point on
number
number
number
number
number
number
number
number
[0034] However, generally, it is difficult to find a quantum state |Ψ 0,Rc 〉 close to the quantum state |Ψ t,Rc 〉, and it is also difficult to find a target vector t close to the lattice points of the lattice ∧ q (A T ). Therefore, in order to make it easier to find such points, under the following condition 1, new points (interpolation points) are added to the dual lattice ∧ q ⊥ (A T ). Condition 1: For any integer θ satisfying 0 < θ < q',
Number
Number
[0035] c∈Z q m is the ∧ that is closest to the target vector t. q (A T ) is a column vector representing the lattice points of q (A T ) The error vector ε is ε=tc∈Z q m Therefore, t=c+ε is satisfied. Therefore, the following equation (24) holds.
number
[0036] b~ j,1 ,…,b~ j,m' ∈L(B~ j ), the m'-dimensional column vector of each term in equation (24) is u~ j,1 ,…,u~ j,n' ,b - j,1 ,…,b - j,m The first element of the right-hand side, 〈c, b~ j,1 〉,...,〈c,b~ j,m' 〉 is 〈c,b - j,1 〉,...,〈c,b - j,m 〉 mod q and 〈c,u~ j,1 〉,...,〈c,u~ j,n' 〉 mod q. Note that b - j,1 ,…,b - j,m ∈Z q m are m-dimensional vectors, and B - j ={b - j,1 ,…,b - j,m } is the dual lattice ∧ q ⊥ (A T ) represents a basis for the dual lattice ∧. q ⊥ (A T ) base B - j is an m × m matrix B - j =[b - j,1 ,…,b - j,m ] T It can be expressed as b - j,1 ,…,b - j,m The superscript "-" should be written directly above the "b", but due to limitations on notation, - j,1 ,…,b - j,m " is sometimes written to the upper right of "b". Similarly, the base B - j The superscript "-" should be written directly above the "B", but due to limitations on notation, it is written as "B - j " is sometimes written in the upper right corner of "B". Here, c∈∧ q (A T ), the following is satisfied:
number
number
number
number
number
[0037] In this LWE reduction, there is some freedom in the choice of the following parameters: Number of samples m' ·Dimension n' ·Law q' Interpolation point vector u~ j,1 ,…,u~ j,n' ·Sample point vector b~ j,1 ,…,b~ j,m' With these settings, we can solve the LWE problem for the parameter set (m,n,q,α) by solving the problem for another parameter set (m',n',q',{α' j } j=1,...,m' ) can be reduced to a set of LWE-like problems.
[0038] <Details of Step A1a (Figure 1)> Next, we will illustrate the details of the LWE reduction (Step A1a) applicable when m = 2 and n = 1. That is, we will illustrate a method for reducing an input LWE problem (a two-sample one-dimensional LWE problem modulo q (m = 2, n = 1)) to a set of one-dimensional LWE-like problems (two-sample one-dimensional LWE problems modulo q' (m' = m = 2, n' = 1)) by the LWE reduction in the Fibonacci setting.
[0039] <Fibonacci sequence> To reduce a two-sample one-dimensional LWE problem modulo q to a two-sample one-dimensional LWE problem modulo q', a vector sequence defined by the Fibonacci sequence is used. Therefore, we first explain the basics of the Fibonacci sequence.
[0040] The Fibonacci sequence is a sequence of numbers, F0=0, F1=1, F k+1 =F k +F k-1 The sequence {F k } k=0,...,∞ Here, the 2x2 matrix
number
number
[0041] The most famous property of the Fibonacci sequence is that when k becomes infinity, the ratio of two adjacent terms in the sequence converges to the golden number (f={(√5)+1} / 2), which satisfies the following equation (29).
number
number
[0042] <Pisano Period> The Pisano cycle is a sequence of numbers modulo q {F k mod q} k=0,...,∞ The period of the sequence {F k mod q} k=0,...,∞ The period of zeros that appears in the following is written as π~(q). For example, if we list the Fibonacci sequence from the beginning, it looks like this: 0,1,1,2,3,5,8,13,21,34,55,89,144,233,377,610,987,1597,2584,4181,... Also, the modulo 3 sequence {F k mod 3} k=0,...,∞ If we list them from the beginning, they look like this: 0,1,1,2,0,2,2,1,0,1,1,2,0,2,2,1,0,1,1,2,0,... This sequence {F k mod 3} k=0,...,∞ Since the period of is 8, π(3) = 8. Also, this sequence {F k mod 3} k=0,...,∞ Since the period in which zeros appear is 4, π~(3)=4. π~(q) is a divisor of π(q). Note that the superscript "~" in "π~" should be written directly above "π", but for convenience of notation, it is sometimes written diagonally above and to the right of "π". Below are examples of the relationship between π(q) and π~(q) for q=1,...,12. [Table 1]
[0043] <Selection of interpolation point vector and sample point vector> The interpolation point vectors and the sample point vectors are selected based on the Fibonacci sequence described above. For example, the interpolation point vectors and the sample point vectors are selected based on the Pisano cycle described above. This will be explained in detail below.
[0044] As mentioned above, Step A1a can be used when m=2 and n=1. Also, m'=m=2 and n'=1. In Step A1a, the Fibonacci sequence {F k } k=0,...,∞ element F belonging to ξυ+2 Let q' be the number of times that the ξυ+2 Here, υ represents an integer equal to or greater than 0, and ξ represents a positive integer. υ and ξ may be arbitrarily determined or may be constants. For example, υ = π~(q). Note that if condition 1 is satisfied, it is not essential that υ = π~(q), but by setting υ = π~(q), the interpolation point vector u~ that easily satisfies condition 1 can be obtained. j,1 can be set.
[0045] Also, as mentioned above, the lattice ∧ for m=2 and n=1 q (A T ) the basis B={b1,b2} is a 3×2 matrix
number
number
number
[0046] Also, the dual lattice ∧ q ⊥ (A T ) base B - Select two of the elements of the row vector in the second row that are multiples of q, and define their basis as B - 1,B - 2. Base B - 1,B - The selection of 2 is as follows:
[0047] First, a 4x2 matrix
number
number
number
number
number
[0048] Also, the permutation of the set {1,2} (permutation that swaps the elements of each column vector) is defined as permutation matrix P2. That is, permutation matrix P2 is defined as shown in the following equation (35).
number
number
number
number
[0049] In the following discussion, j is fixed. However, κ is not fixed. As with the Fibonacci sequence, {b - j,1 ,b - j,2 } to b - j,k+1 =b - j,k +b - j,k-1 If we create a sequence of vectors that satisfy b - j,1 , b - j,2 , b - j,1 +b - j,2 , b - j,1 +2b - j,2 ,... The sequence of this vector is expressed as follows: b - j,1 , b - j,2 , b - j,3 =b - j,1 +b - j,2 , b - j,4 =b - j,1 +2b - j,2 ,... The columns of this vector {b - j,κ } κ=1,...,∞ For this, the following equation (39) holds:
number
number
number
[0050] In addition, the subdivision point vector d~ that satisfies the following equation (43) j,1 ,…,d~ j,ξυ+1 Select .
number
[0051] Subdivision point vector d~ j,1 ,…,d~ j,ξυ+1 and the interpolation point vector u~ j,1 Based on and, the sample point vector b~ j,1 ,...,b~ j,m is defined. The sample point vector b~ j,1 ,...,b~ j,m is the lattice L(B~ j ):=L(∧ q ⊥ (A T )∪{u~ j,1 ,…,u~ j,n' }) (Equation (23)) basis B~ j ={b~ j,1 ,...,b~ j,m }, which consists of vector b~ j,1 ,...,b~ j,m In general, m≪ξυ+1, and the subdivision point vector d~ j,τ (where τ=1,...,ξυ+1) has a length that decreases exponentially with τ, so that the basis B~ j ={b~ j,1 ,...,b~ j,m }, which consists of vector b~ j,1 ,...,b~ j,m is exponentially shorter than ξυ+1. Therefore, the vector b~ j,1 ,...,b~ j,m The end points of are distributed around the origin.
[0052] Sample point vector setting example 1: In setting example 1, the subdivision point vector d~ j,1 ,…,d~ j,ξυ+1 and the interpolation point vector u~ j,1 The matrix M in the following equation (44) where du The matrix M obtained by lattice reduction of r Based on the row vector of j,1 ,...,b~ j,m is determined.
number
[0053] Sample point vector setting example 2: matrix M du Without lattice reduction, the vector b~ j,1 ,...,b~ j,m In the setting example 2, the vector b~ may be set as follows: j,1 ,...,b~ j,m is determined. ·Matrix M du Among the row vectors of , the row vector d~ with the smallest norm j vector b~ j,1 ,b~ j,2 For example, b~ j,1 =d~ j You can also use b~ j,2 =d~ j For example, d~ j =d~ j,ξυ+1 This often happens. ·u~ j,1 +Γ·d~ j The integer Γ=Γ that minimizes min Select u~ j,1 +Γ min d~ j vector b~ j,1 ,b~ j,2 For example, b~ j,1 =d~ j In the case of b~ j,2 =u~ j,1 +Γ min d~ j Then, b~ j,2 =d~ j In the case of b~ j,1 =u~ j,1 +Γ min ·d~ j Let it be so.
[0054] <Reduction to LWE> For the determined sample point vectors b~ j,1 ,...,b~ j,m , define an LWE-Like problem. For the parameter sets (m' = m = 2, n' = 1, q', {α' j,μ} j=1,2,μ=1,...,m ) given for j = 1, 2 and μ = 1,..., m, define the m×1 matrix A' j , the target vector t' j , and the standard deviation σ' j,μ as follows.
Number
Number
Number
number
[0055] In this case, the solution to the LWE-like problem is as shown in the following equations (48) and (49).
number
number
[0056] <Example of Step A1a (Figure 1)> An example of Step A1a is shown. Assume that the parameter set \((m, n, q, \alpha)\) of the input LWE problem is \((m, n, q, \alpha)=(2, 1, 5, 0.2)\). Here, assume a randomly generated LWE problem where \(A, s, \varepsilon, t\) are as follows. Also, here an example where \(\upsilon=\pi(5)\) will be explained.
Number
[0057] <When \(q' = 13\)> When \(\upsilon=\pi(5)=5\), in Step A1a, \(q' = F ξυ+2 =F ξπ~(5)+2 According to the definition of the Fibonacci sequence, \(q' = F ξπ~(5)+2 =F ξπ~(5)+1 +F ξπ~(5) is. Also, \(\xi\) can be any positive integer value, but here \(\xi = 1\) is set. Then, based on equation (27), the following equation (50) holds.
Number
[0058] Next, select bases \(B - _1, B - _2. First, as described above, the base \(B\) of the lattice \(\wedge q (A T ) and the base \(B q ⊥ (A T ) of the dual lattice \(\wedge - When calculated, the following equations (51) and (52) are obtained.
number
[0059] Next, using the permutation matrices P1 and P2 in equations (32a) and (35), B - Hermitian normal form HNF(B - P1) and B - Hermitian normal form HNF(B - P2) is expressed by the following equations (53a) and (53b).
number
[0060] Therefore, HNF(B - From the right side of P1 T The matrix (B - P1)P1 T and HNF(B - From the right side of P2 T The matrix (B - P2)P2 T are expressed as the following equations (53c) and (53d), respectively.
number
[0061] Next, we replace the elements of equation (53c) to satisfy equation (33) and obtain the basis B - 1, and then replace the elements of equation (53d) to satisfy equation (37) to obtain the basis B - 2. For example, the base B - The first and second rows of the vector b - 1,b - The elements are replaced so that the distance between the line connecting the end points of 2 and the origin satisfies the following equation (53e) to create the basis B - 1,B - Generates 2.
number
number
[0062] Next, the interpolation point vector u~ 1,1 ,u~ 2,1 and the sample point vector b~ 1,1 ,b~ 1,2 ,b~ 2,1 ,b~ 2,2 First, when q'=13, υ=π~(5)=5, and ξ=1, the interpolation point vector u~ j,1 The equation (41) expressing this is expressed as the following equation (56).
number
number
number
number
number
[0063] On the other hand, from equation (43), when υ = π~(5) and ξ = 1, the subdivision point vector is d~ j,1 ,…,d~ j,π~(5)+1 Since π~(5)=5, the subdivision point vector is d~ j,1 ,…,d~ j,6 Here, the row vector with the smallest norm is d~1=d~ 1,6 and d~2=d~ 2,6 is.
number
number
[0064] Figure 8 shows the dual lattice ∧ of the above example. q ⊥ (A T ) lattice point, j=1 basis B - 1={b - 1,1 ,b - 1,2 }, interpolation point vector u~ 1,1 , and the subdivision point vector d~ 1,6 is illustrated. Also, in FIG. 9, the lattice L(B~ j ):=L(∧ q ⊥ (A T )∪u~ j,1 ) lattice points, and the basis B~1={b~ 1,1 ,b~ 1,2} for j = 1 are illustrated.
[0065] For the sample point vectors b~ 1,1 ,b~ 1,2 ,b~ 2,1 ,b~ 2,2 determined as above, calculating the formula (2) that constitutes the LWE-Like problem results in the following formulas (60) and (61).
Number
Number
[0066] <When q' = 144> In the above example, ξ = 1 was used, but as described above, ξ can be any positive integer. If ξ = 2, the following formula (62) holds based on formula (27).
Number
[0067] Next, the basis B - 1,B - First, we select 2. First, we use the Hermite normal form to find the lattice ∧ q (A T ) and the dual lattice ∧ q ⊥ (A T ) base B - Calculating the above gives the formulas (51) and (52). Next, using the permutation matrices P1 and P2 of formulas (32a) and (35), B - Hermitian normal form HNF(B - P1) and B - Hermitian normal form HNF(B - P2) is as shown in the above equations (53a) and (53b). Therefore, HNF(B - From the right side of P1 T The matrix (B - P1)P1 T and HNF(B - From the right side of P2 T The matrix (B - P2)P2 T are expressed as equations (53c) and (53d), respectively.
[0068] Next, we replace the elements of equation (53c) to satisfy equation (33) and obtain the basis B - 1, and then replace the elements of equation (53d) to satisfy equation (37) to obtain the basis B - 2. For example, the base B - The first and second rows of the vector b - 1,b - The elements are replaced so that the distance between the line connecting the end points of 2 and the origin satisfies the following equation (65) to create the basis B - 1,B - Generates 2.
number
number
[0069] Next, the interpolation point vector u~ 1,1 ,u~ 2,1 and the sample point vector b~ 1,1 ,b~ 1,2 ,b~ 2,1 ,b~ 2,2 First, when q'=144, υ=π~(5)=5, and ξ=2, the interpolation point vector u~ j,1 The equation (41) expressing this is expressed as the following equation (68).
number
number
number
number
number
[0070] On the other hand, from equation (43), when υ = π~(5) and ξ = 2, the subdivision point vector is d~ j,1 ,…,d~ j,2π~(5)+1 Since π~(5)=5, the subdivision point vector is d~ j,1 ,…,d~ j,11 Here, the row vector with the smallest norm is d~1=d~ 1,11 and d~2=d~ 2,11 is.
number
number
[0071] The sample point vector b~ determined as above 1,1 ,b~ 1,2 ,b~ 2,1 ,b~ 2,2 On the other hand, when formula (2) constituting the LWE-Like problem is calculated, the following formulas (72) and (73) are obtained.
number
number
[0072] <Details of Step A1b (Figure 2)> As mentioned above, the LWE reduction in the Fibonacci setting in step A1a is applicable only when m = 2 and n = 1. On the other hand, step A1b illustrates the details of the LWE reduction in the extended Fibonacci setting (step A1b), which is applicable for any m and n. That is, we illustrate a method for reducing an input LWE problem (a two-sample one-dimensional LWE problem modulo q (for any m and n)) to a set of one-dimensional LWE-like problems (m-sample one-dimensional LWE problems modulo q' (m' = m, n' = 1)) by the LWE reduction in the extended Fibonacci setting.
[0073] <Extended Fibonacci Sequence> First, we will explain the "Fibonacci n-step sequence," also known as an extension of the Fibonacci sequence (extended Fibonacci sequence). The "Fibonacci n-step sequence" is a sequence in which one or more elements are 0 from the beginning, the subsequent element is 1, and the subsequent element is expressed as the sum of the n elements immediately preceding that element. However, in this embodiment, the symbol n is used to represent the dimension, and the symbol m is used to represent the number of samples. In this embodiment, the extended Fibonacci sequence is used to represent the number of samples, so to avoid confusion, the name "Fibonacci m-step sequence" is used. Here, we define the m × m matrix shown in the following equation (74).
number
[0074] In this case, the general term F of the Fibonacci m-step sequence k (where k=0,...,∞) is the m-dimensional vector [F k-m+2 ,...,F k ,F k+1 ] T and an m-dimensional vector [0,...,0,1] T is defined as the following equation (75).
number
number
number
[0075] Also, the modulus q is 2 r in the case of,
number
number
[0076] In the extended Fibonacci setting, m+1 is the modulo q = 2 r It plays the role of the Pisano period in the Fibonacci setting, where the matrix
number
number
[0077] <Selection of interpolation point vector and sample point vector> The above sequence {G k } k=0,...,∞ The interpolation point vector and the sample point vector are selected based on m+1, for example. This will be described in detail below.
[0078] As mentioned above, step A1b can be used for any m and n, and m'=m and n'=1. In step A1b, the sequence {G k } k=0,...,∞ element G belonging to ξυ Let q' be the vector of the interpolation point u~. For example, υ = m+1. If condition 1 is satisfied, it is not necessary to set υ = m+1. However, by setting υ = m+1, the interpolation point vector u~ can be easily set to satisfy condition 1. j,1 can be set.
[0079] Also, as mentioned above, the (m+n) × m matrix
number
number
[0080] Also, as mentioned above, a 2m × m matrix
number
[0081] Dual lattice ∧ that satisfies condition 1 q ⊥ (A T ) base B - To obtain the permutation matrices P1,P2,...,P m A, B - P1,B - P2,...,B - P m The Hermitian normal form HNF(B - P1), HNF(B - P2),...,HNF(B - P m ) are selected to be the m × m matrices of the following equation (77).
number
[0082] base B - j Let m m-dimensional row vectors that make up b - j,1 ,...,b - j,m That is, B - j is an m-dimensional vector b - j,1 ,...,b - j,m where the first m elements are b - j,1 ,...,b - j,m The sequence of vectors whose first m+ν element is the sum of the m elements immediately preceding the m+ν element is called {b - j,k } k=1,...,∞ where ν is a positive integer. Then, the following equation (78) holds.
number
number
number
number
number
number
number
[0083] In addition, the subdivision point vector d~ that satisfies the following equation (82) j,1 ,…,d~ j,ξυ-1 For example, υ=m+1.
number
[0084] Subdivision point vector d~ j,1 ,…,d~ j,ξυ-1 and the interpolation point vector u~ j,1 Based on and, the sample point vector b~ j,1 ,...,b~ j,m is defined. The sample point vector b~ j,1 ,...,b~ j,m is the lattice L(B~ j ):=L(∧ q ⊥ (A T )∪{u~ j,1 ,…,u~ j,n' }) (Equation (23)) basis B~ j ={b~ j,1 ,...,b~ j,m }, which consists of vector b~ j,1 ,...,b~ j,m When m ≪ ξυ (for example, when υ = m + 1), the subdivision point vector d~ j,τ (where τ=1,...,ξυ-1) has a length that decreases exponentially with τ, so that the basis B~ j ={b~ j,1 ,...,b~ j,m }, which consists of vector b~ j,1 ,...,b~ j,m is exponentially shorter than ξυ. Therefore, the vector b~ j,1 ,...,b~ j,m The end points of are distributed around the origin.
[0085] Sample point vector setting example 3: For example, the subdivision point vector d~ j,1 ,…,d~ j,ξυ-1 and the interpolation point vector u~ j,1 The matrix M of the following equation (83) with the row vectors of j,du The matrix M obtained by lattice reduction j,r Based on the row vectors of, the vector b~ j,1 ,...,b~ j,m is defined.
Number
[0086] <LWE Reduction> For the defined sample point vectors b~ j,1 ,...,b~ j,m define the LWE-Like problem. When the parameter set (m' = m, n' = 1, q', {α' j,μ} j=1,...,m,μ=1,...,m ) is given for j = 1,..., m and μ = 1,..., m, the m×1 matrix A' j , the target vector t' j , and the standard deviation σ' j,μ are defined as follows. Note that α' j,μ = α||b~ j,μ || is satisfied.
Number
Number
[0087] In this case, the solution to the LWE-like problem is as shown in the following equations (84) and (85).
number
number
[0088] <Example of Step A1b (Fig. 2)> Here is an example of step A1b.,Suppose the parameter set (m,n,q,α) of the input LWE problem is (m,n,q,α)=(4,2,4,0.2).,Now, suppose we have a randomly generated LWE problem,where,A,s,∈,t,is as follows:
number
[0089] Here, we show an example where υ = m + 1 = 5. ξ can be any value as long as it is a positive integer. For example, it is preferable that ξ be a multiple of q / 2 = 2, but in this example we will set ξ = q = 4. Then, based on equation (74), the following equation (86) holds.
number
[0090] As mentioned above, the lattice ∧ q (A T ) and the dual lattice ∧ q ⊥ Base B of (X) - When calculated, the following equations (87) and (88) are obtained.
number
[0091] HNF(B - P1), HNF(B - P2), HNF(B - P3), HNF(B - Select permutation matrices P1, P2, P3, and P4 so that the elements of the last two rows of P1, P2, P3, and P4 are all zero or multiples of 4. For example, select permutation matrices P1, P2, P3, and P4 of the following equation (89).
number
number
number
[0092] Next, the interpolation point vector u~ j,1 (j=1,2,3,4) and sample point vector b~ j,μ (j=1,2,3,4, μ=1,...,m). First, for j=1,2,3,4, with ξ=q=4 and υ=m+1=5,
number
number
number
[0093] In this case, the vector b~ j,1 ,b~ j,2 ,b~ j,3 ,b~ j,4 is expressed as the following equation (94).
number
[0094] The sample point vector b~ determined as above 1,1 ,b~ 1,2 ,b~ 2,1 ,b~ 2,2 On the other hand, when calculating equation (2) that constitutes the LWE-Like problem, we get the following equations (95) to (98).
number
number
number
number
[0095] <Details of Step A2 (Figures 1 and 2)> Next, we will show the details of the process of converting a set of one-dimensional LWE-like problems obtained by LWE reduction into a set of phase estimation problems with errors.
[0096] <Phase estimation problem with errors> The phase estimation problem with errors corresponding to the set of one-dimensional LWE-like problems obtained in step A1 can be solved by the unitary transformation U j (γ) (γ=0,1,...,q'-1) and the quantum state |Ψ j,t 〉 is a solution s' that satisfies equation (4). j (where j=1,...,m)
number
[0097] <areaΩ j > As mentioned above, the domain Ω j ⊆Z q' m is Ω j B~ j (Ω j B~ j The end point of the grid L(B~ j ) is a set of m-dimensional vectors (end points of m-dimensional vectors) that are the origin or lattice points around the origin of the domain Ω. j ⊆Z q' m is Ω j B~ j =B R ∩L(B~ j ) is satisfied. Ω j B~ j ={x'B~ j ∈L(B~ j )|x'∈Ω j }. Also, B R represents the interior of a given region in m-dimensional space. If it can be approximated as in equation (7), then B R There is no limitation on the position, range, or shape of B. R is the lattice L(B~ j ) represents the interior of a given region including the origin or the area around the origin. R is the lattice L(B~ j ) may or may not include the origin. For example, B R is the volume |det(B~ j )| is the area inside the hypersphere. In this case, if assumption 1 holds, the following condition 2 can be shown. Condition 2: For any integer γ=0,1,...,q'-1, #{x'∈Ω j |L~ j (x'B~ j )=F~ j (x')=γ}=1. Therefore, #Ω j =q' holds. where #{x'∈Ω j |L~ j (x'B~ j )=F~ j (x')=γ} is {x'∈Ω j |F~ j (x')=γ}. That is, condition 2 is satisfied in the domain Ω j Label x' that belongs to L~ j (x'B~ j )=γ∈0,1,...,q'-1 correspond one-to-one. Note that if assumption 1 is not strictly true, condition 2 may not be strictly true either. For example, depending on the value of γ, #{x'∈Ω j |L~ j (x'B~ j )=F~ j {(x')=γ} may be 1, or it may not be 1. In this case, the correct answer may not be obtained every time, but by repeating the same calculation multiple times and selecting the answer with the highest frequency, it is possible to eliminate errors and obtain the correct answer. In other words, even if condition 2 does not strictly hold, the LWE problem can be solved efficiently as long as the distribution of final solutions is biased toward the correct answer (for example, if condition 2 is approximately held).
[0098] <input quantum state|Ψ j,t >> As mentioned above, the set of m-dimensional vectors Ω j The uniform superposition state |Ψ on j,0 Define |Ψ j,0 > is expressed as the following equation (8).
number
number
[0099] <Unitary transformation U j (γ) > As mentioned above, the unitary transformation U j (γ) is for any y"∈Z q' is an operator that satisfies the following equation (12) for
number
[0100] <Example of Step A2 (FIGS. 1 and 2)> An example of step A2 is shown. Here, we show an example of the same LWE problem as the example of step A1a. That is, the parameter set (m, n, q, α) of the input LWE problem is (m, n, q, α) = (2, 1, 5, 0.2),
number
[0101] First, the selection of the region Ω1 will be illustrated. As mentioned above, the region Ω1 is Ω1B~1=B R ∩L(B~1). In this example, B R The region Ω1 is selected so that it is the region inside a hypersphere (a circle in this example because m = 2) with a volume (area because m = 2 in this example) |det(B~1)|. Here,
number
[0102] For 8 qubits (2 registers with 4 qubits each), as shown in equation (8), for x'∈Ω1={(1,0),(2,0),(0,1),(1,1),(2,1),(3,1),(0,2),(1,2),(2,2),(3,2),(1,3),(2,3)}, the superposition state |Ψ of |x'> 1,0 > is created as shown in equation (99) below.
number
number
number
[0103] As mentioned above, the unitary transformation U1 for q'=13 and j=1 (γ) is the square lattice Z labeled y"=L~1(x"B~1) for any γ=0,1,...,12. q' m lattice point x" y" The quantum state |x> y" The square lattice Z is labeled with a value y"-γ mod 13 that is γ smaller than y". q' m lattice point x" y"‐γ mod 13 The quantum state |x> y"-γ mod 13 In Figure 11 and below, we consider the unitary transformation U1 (1) Operation by |x"> y" →|x"> y"‐1 mod 13 We illustrate the operation on the lattice L(B~1) corresponding to where x"∈Ω1={(1,0),(2,0),(0,1),(1,1),(2,1),(3,1),(0,2),(1,2),(2,2),(3,2),(1,3),(2,3)} and F~1(1,0)=12, F~1(2,0)=11, F~1(0,1)=5, F~1(1,1)=4, F~1(2,1)=3, F~1(3,1)=2, F~1(0,2)=10, F~1(1,2)=9, F~1(2,2)=8, F~1(3,2)=7, F~1(1,3)=1, F~1(2,3)=0. U1 (1) :|x"> y" →|x"> y"‐1 mod 13 |1,0> 12 →|2,0> 11 |2,0> 11 →|0,2> 10 |0,1>5→|1,1>4 |1,1>4→|2,1>3 |2,1>3→|3,1>2 |3,1>2→|1,3>1 |0,2> 10 →|1,2>9 |1,2>9→|2,2>8 |2,2>8→|3,2>7 |3,2>7→|0,1>5 |1,3>1→|2,3>0 |2,3>0→|1,0> 12 By this operation, the quantum state |x"> corresponding to each label y"∈{12, 11, 5, 4, 3, 2, 10, 9, 8, 7, 1, 0} y" is in quantum state |x"> y"‐1 mod 13 However, in this example, there is no quantum state |x>6 corresponding to label y"=6, so the quantum state |3,2>7 is converted to the quantum state |0,1>5. (1) and |Ψ 1,t >, the following equation (101a) holds:
number
number
[0104] From equation (100b) and equation (101b), U1 (1) |Ψ 1,t-ε > and |Ψ 1,t-ε >, it can be seen that the following equation (102a) holds.
number
number
[0105] Similarly, for other j and γ, the quantum state |Ψ j,t 〉 and the unitary transformation U j (γ) (γ=0,1,...,q'-1) can be defined, and the set of one-dimensional LWE-like problems can be reduced to the set of phase estimation problems with errors.
[0106] <Details of Step B (Figures 1 and 2)> Next, the details of the process (Step B) for solving all the phase estimation problems with errors obtained in Step A using a quantum-classical hybrid algorithm will be illustrated. As mentioned above, a "standard algorithm" is known as an algorithm for solving general phase estimation problems (see, for example, Reference 4). In this embodiment, this standard algorithm is not used, and a simpler algorithm, s', is used. j We use the following quantum algorithm to identify
[0107] <label> The aforementioned lattice L(B):=∧ q (A T ) corresponding to the grid points L j (v)∈Z q' Label L j (v) is the function value of any lattice point v∈L(B) of the lattice L(B), and the lattice L(B~ j ) lattice point v~∈L(B~ j ) corresponding to the label L~ j Dual to (v~). Label L j (v) is defined as the following equation (103) for any lattice point v∈L(B).
number
number
number
number
number
[0108] <Quantum Algorithm> Next, the input quantum state |Ψ j,t 〉, the solution s' of the phase estimation problem with error that satisfies equation (4) j (where j=1,...,m) is calculated. First, as mentioned above, C j is defined as equation (18).
number
number
number
number
number
number
number
number
number
number
number
number
number
[0109] <Execution of quantum algorithms> The solution s' is obtained by the above quantum algorithm. j The following is an example of the procedure for obtaining the quantum state. The quantum algorithm stores each quantum state in a register (quantum memory), performs quantum calculations on each quantum state stored in the register, and stores the results of the quantum calculations in the register repeatedly. The details of this process are explained below.
[0110] Input quantum state |Ψ corresponding to the one-dimensional LWE-like problem j,t > Generation (Step B-1): The input quantum state |Ψ corresponding to the one-dimensional LWE-like problem for j=1,...,m in step A1 j,t In this example, first, the quantum state shown in the following equation (118) is generated, and the generated quantum state is stored in a register.
number
[0111] The quantum state obtained by performing the transformation of the following equation (119) on the quantum state of equation (118) is the superposition state |Ψ of equation (8). j,0 >, and the resulting superposition state |Ψ j,0 > is stored in the register.
number
number
number
[0112] The superposition state |Ψ in Eq. (8) j,0 By applying a phase rotation gate to the input quantum state |Ψ j,t > can be generated.
number
[0113] State alignment operation X j (Step B-2): The input quantum state |Ψ in Eq. (9) j,t > for state alignment operation X j and the quantum state X j |Ψ j,t Here is an example of how to generate matrix C j Inverse matrix C of j -1 can be defined as the following equation (121). C j -1 :=adj(C j ) / det(C j ) (121) where adj(C j ) is the matrix C j represents the cofactor matrix of the input quantum state |Ψ j,t >Z q' m Since the input quantum state |Ψ j,t >State alignment operation X for j is Z q' m However, as mentioned above, det(C j )=q' m-1 Therefore, Z q' m Above, the denominator of equation (121) is det(C j ) becomes 0, and the inverse matrix C j -1 does not exist. However, the inverse matrix C j -1 That is, for any y1'∈Z q' m For y1'=x1'C j mod q' and the domain Ω j If there exists x1' included in |x', it can be calculated. Therefore, as shown in the following equation (122), the quantum state |x'> is stored in the first register and the quantum state |x'C j mod q'> and store the inverse matrix C j -1 By performing quantum computation including j,t >to convert the quantum state |x'> into the quantum state |x'C j mod q'> and state alignment operation X j It is possible to execute the following. |x'>|0>→|x'>|x'C j mod q'> →|x'(+)x'C j C j -1 mod q'>|x'C j mod q'>=|0>|x'C j mod q'> (122)
[0114] Others, input quantum state |Ψ j,t > to quantum state X j |Ψ j,t There are various ways to generate the above. Here is an example: First, a set of m positive integers (k1, k2,..., k m ), the quantum state |Ψ of the following equation (123) j,t > k1,k2,...,km Define
number
[0115] Example of Step I processing: |Ψ j,t >From|Ψ j,t > k1,k2,...,km To generate |Ψ, we alternately copy the quantum state using the Hadamard transformation (Step I-1) and correct the position of the quantum state (Step I-2). j,t >From|Ψ j,t > k1,0,...,0 Generate |Ψ j,t > k1,0,...,0 From |Ψ j,t > k1,k2,...,0 Generate,···,|Ψ j,t > k1,k2,...,km-1,0 From |Ψ j,t > k1,k2,...,km The following is an example of the details. Step I-0: |Ψ j,t > 0,...,0 :=|Ψ j,t >Set it as follows. Step I-1: Repeat steps I-1-1 and I-1-2 below for μ'=1, 2,..., m-1, and |Ψ j,t > k1,...,kμ',0,...,0 From |Ψ j,t > k1,...,kμ',kμ'+1,0,...,0 Generate. Step I-1-1: The quantum state of the following equation (124) that has already been generated is set as the next operation target. Here, k <k μ'+1 is. |Ψ j,t > k1,...,kμ',k,0,...,0 (124) Step I-1-2: Unitary transformation U k1,...,kμ',k,0,...,0 Square root of
number
number
[0116] Example of Step II processing: From the definition of equation (123), |Ψ j,t > k1,k2,...,km is the quantum state
number
number
number
[0117] Next, the success probability of the processing in step II is shown. |Ψ j,t > k1,k2,...,km X included in j |Ψ j,t > The number of C j Using the constant const determined by, it can be expressed as in the following equation (126).
number
number
number
[0118] Action of the Cartesian product of m q'-dimensional inverse quantum Fourier transforms (Step B-3): The quantum state X of equation (111) stored in m registers j |Ψ j,t 〉, the direct product of m q'-dimensional inverse quantum Fourier transforms of equation (116) is applied to the m registers.
number
[0119] Observation (Step B-4): The quantum state of Eq.(116)
number
[0120] Label Calculation (Step B-5): Observation result z j Using a classical computer, the observed result z j The label value L of the following equation (127) corresponding to j (z j B) and calculate the label value L j (z j B) Based on the solution s' j get.
number
[0121] <Example of Step B (Figs. 1 and 2)> Here is an example of Step B. Here, we show the same example of an LWE problem as in Step A1a. That is, the input parameter set (m, n, q, α) of the LWE problem is (m, n, q, α) = (2, 1, 5, 0.2),
number
[0122] Step B-1: First, the input quantum state |Ψ 1,t > is generated by using 8 qubits (2 registers with 4 qubits each) to generate the superposition state |Ψ 1,0 >, this superposition state |Ψ 1,0 By applying a phase rotation gate to the input quantum state |Ψ 1,t Figure 12A shows the input quantum state |Ψ 1,t > is an example. |Ψ 1,t >∈Z 13 2 and the horizontal axis of FIG. 12A is |Ψ 1,t 12A represents the first component (first-dimensional component) of |Ψ 1,t The lighter the color, the greater the quantum state |Ψ 1,t > indicates that the amplitude is large.
[0123] Step B-2: The input quantum state |Ψ in Eq. (9) j,t > for state alignment operation X j and the quantum state X j |Ψ j,t In this example, the matrix C1 (equation (18)) is as follows:
number
number
number
[0124] Step B-3: The quantum state of equation (128). X1|Ψ 1,t 〉, the direct product of the 13-dimensional inverse quantum Fourier transform of equation (116) is applied. This generates the quantum state of equation (129) below.
number
[0125] Step B-4: By observing the quantum state of equation (129), the observation result z1 = (z 1,1 ,z 1,2 )∈Z 13 2 is obtained.
[0126] Step B-5: Observation result z1=(z 1,1 ,z 1,2 ) to calculate the label value L1(z1B) corresponding to the observation result z1. 1,1 ,z 1,2 ) and the label value L1(z1B). The horizontal axis of FIG. 13 indicates the value of the first component of z1B, and the vertical axis indicates the value of the second component of z1B. Each point represents a lattice point z1B of the lattice L(B) corresponding to the observation result z1. The number attached to each point indicates the label value L1(z1B)∈Z corresponding to each lattice point z1B. 13 For example, if the observation result is z1=(2,0), then z1B=(2,4) and L1(2,4)=9.
[0127] Step B-6: FIG. 14 illustrates the probability distribution of the value of label L1(z1B) corresponding to observation result z1. In the example of FIG. 14, the probability that the value of label L1(z1B) will be 9 is 1 / 2 or more. Therefore, when the processes of steps B-1 to B-5 are repeated multiple times, the label value L1 with the highest occurrence probability is j (z j B) is 9, and we can conclude that the solution is s'1 = 9. In the example of Figure 14, the probability that the value of label L1(z1B) is 12 is also relatively high. This is because the target vector t = (1, 4) of the LWE problem handled in the example T is close not only to the lattice point (2,4) corresponding to label L1(z1B)=9, but also to the lattice point (0,5) corresponding to label L1(z1B)=12.
[0128] <Details of Step C (Figures 1 and 2)> Next, we use the classical algorithm to find the solution s' of the phase estimation problem with errors obtained in step B. j (where j=1,...,m) is the set {s'1,...,s' m } to the solution s∈Z of the LWE problem q n The details of the process (step C) for calculating the following will be illustrated.
[0129] From the above-mentioned equation (48), the following equation (130) holds.
number
number
number
[0130] where the target vector t∈Z q m The elements of are non - negative and less than q. Also, the elements of the error vector ε follow a Gaussian distribution N(0, σ 2 ), for example, greater than -q / 2 and less than q / 2. Therefore, the left - hand side of equation (131)
Number
Number
Number
[0131] From the above equation (1), the following equation (133) holds.
number
[0132] <Example of Step C (Figs. 1 and 2)> Examples of Step C are shown below. Examples of Step C are shown for the case where q'=13 in the example of Step A1a (FIG. 1), the case where q'=144 in the example of Step A1a (FIG. 1), and the case where q'=918385 in the example of Step A1b (FIG. 2).
[0133] <Example of Step A1a (FIG. 1) in which q'=13> In this case, equation (2) constituting the LWE-Like problem becomes equations (60) and (61).
number
number
number
[0134] In this case, the following equation (135) holds true from equations (58), (59), and (130a).
number
number
[0135] Since s'1=9, s'2=3, and q'=13, the following equation (137) holds from equations (131) and (136).
number
number
number
number
[0136] <Example of Step A1a (FIG. 1) in which q'=144> In this case, equation (2) constituting the LWE-like problem becomes equations (72) and (73).
number
number
number
[0137] In this case, the following equation (142) holds true from equations (70), (71), and (130a).
number
number
[0138] Since s'1=86, s'2=26, and q'=144, the following equation (144) holds from equation (131) and equation (143).
number
number
number
number
[0139] <Example of Step A1b (FIG. 2)> In this case, equation (2) constituting the LWE-Like problem becomes equations (95) to (98).
number
number
number
number
number
[0140] In this case, the following equation (149) holds true from equations (93) and (130a).
number
number
[0141] Since s'1=862530, s'2=96993, s'3=470913, s'4=55855, and q'=918385, the following equation (151) holds from equation (131) and equation (150).
number
number
number
number
number
number
number
number
[0142] [First embodiment] Next, a first embodiment of the present invention will be described. In the first embodiment, a computing device 1 executes the processes of steps A to C described above.
[0143] <Configuration> As illustrated in FIG. 3 , the computing device 1 of this embodiment includes an LWE reduction device 11, a problem transformation device 12, a solution-finding device 13, a solution transformation device 14, and a storage unit 15. Here, the LWE reduction device 11, the problem transformation device 12, and the solution transformation device 14 are, for example, devices obtained by loading a predetermined program into a classical computer (e.g., a von Neumann computer). Meanwhile, the solution-finding device 13 is, for example, a hybrid device that combines a device obtained by loading a predetermined program into a classical computer with a quantum computer (e.g., a gate-type quantum computer or an annealing-type quantum computer). The hybrid device may be a device obtained by loading a predetermined program into both a classical computer and a quantum computer. Furthermore, at least one of the LWE reduction device 11, the problem transformation device 12, and the solution transformation device 14 may be a hybrid device or a quantum computer. Furthermore, the solution-finding device 13 may be a quantum computer into which a predetermined program has been loaded. Information input to the computing device 1 is stored in the storage unit 15 and is read and used as needed.
[0144] As shown in Fig. 4, the LWE reduction device 11 (computing device) of this embodiment includes a control unit 111, an interpolation point selection unit 112, and a sample point selection unit 113. The LWE reduction device 11 executes each process under the control of the control unit 111. The LWE reduction device 11 stores information obtained in each process in a memory (not shown). The information stored in this memory is read out as needed and used in each process.
[0145] As illustrated in Fig. 5, problem transformation device 12 (computation device) of this embodiment has control unit 121, vector generation unit 122, and input quantum state identification unit 123. Problem transformation device 12 executes each process under the control of control unit 121. Problem transformation device 12 stores information obtained in each process in memory (not shown). The information stored in this memory is read out as needed and used in each process.
[0146] As illustrated in Fig. 6, the solution-finding device 13 (computation device) of this embodiment has a control unit 131, an input quantum state generation unit 132, a state alignment operation unit 133, an inverse quantum Fourier transform unit 134, an observation unit 135, a label calculation unit 136, and a solution generation unit 137. The solution-finding device 13 executes each process under the control of the control unit 131. The solution-finding device 13 stores information obtained in each process in a memory (not shown). The information stored in this memory is read out as needed and used in each process.
[0147] As shown in Fig. 7, the solution conversion device 14 (calculation device) of this embodiment has a control unit 141, a difference generation unit 142, and a solution generation unit 143. The solution conversion device 14 executes each process under the control of the control unit 141. The solution conversion device 14 stores information obtained in each process in memory (not shown). The information stored in this memory is read out as needed and used in each process.
[0148] <Processing> Next, the processing of this embodiment will be described. <Pre-processing> As a pre-processing step, the parameter set for the LWE problem, m, n, q, α, and the parameter set for the LWE-like problem, m', n', q', included in the parameter set for the LWE-like problem, are input to the calculation device 1 (FIG. 3) and stored in the storage unit 15 of the calculation device 1. Note that in this embodiment, an example where n' = 1 is shown, but this does not limit the present invention. Also, although not explained further below, the LWE reduction device 11, problem conversion device 12, solution finding device 13, and solution conversion device 14 read at least a portion of m, n, q, α, m', n', q' from the storage unit 15 and use them in their respective processes. That is, when at least a part of m, n, q, α, m', n', q' is required for each process of the LWE reduction device 11, the problem transformation device 12, the solution finding device 13, and the solution transformation device 14, the LWE reduction device 11, the problem transformation device 12, the solution finding device 13, and the solution transformation device 14 read out the information required for each process from m, n, q, α, m', n', q' and use it for each process.
[0149] <Step A1 (Figures 1 and 2)> As illustrated in FIG. 3, the matrix A and the target vector t of the LWE problem are input to the computing device 1, and these are input to the LWE reduction device 11. The LWE reduction device 11 reduces the LWE problem specified by these and the parameter set (m, n, q, α) of the LWE problem to a set of one-dimensional LWE-Like problems (step A1: LWE reduction). That is, the LWE reduction device 11 uses the parameter set (m, n, q, α), the matrix A, and the target vector t of the LWE problem for which a solution is sought, and obtains and outputs a set of information corresponding to m' one-dimensional LWE-Like problems. In this embodiment, the set of information corresponding to the one-dimensional LWE-Like problems is the sample point vectors b~ j,1 , …, b~ j,m' (where j = 1, ..., m') is shown as an example. However, this does not limit the present invention. Details will be described below.
[0150] As illustrated in FIG. 4, the matrix A and the target vector t are input to the interpolation point selection unit 112 of the LWE reduction device 11. The interpolation point selection unit 112 selects and outputs interpolation point vectors u~ j,1 , …, u~ j,n' that satisfy the above-described equations (22a) and (22b) for any integer θ satisfying 0 < θ < q'. The interpolation point vectors u~ j,1 , …, u~ j,n' are sent to the sample point selection unit 113 and the solution conversion device 14. In this embodiment, since n' = 1, the interpolation point selection unit 112 selects and outputs the interpolation point vector u~ j,1 , and the interpolation point vector u~ j,1 is sent to the sample point selection unit 113 and the solution conversion device 14.
[0151] The sample point selection unit 113 uses the interpolation point vector u~ j,1 to select and output linearly independent sample point vectors b~ j,1 , …, b~ j,m' ∈ L(B~ j ) ∩ R c . As described above, L(B~ j ) is ∧ q ⊥ (A T ) ∪ {u~ j,1 ,…,u~ j,n' }, the lattice L(∧ q ⊥ (A T )∪{u~ j,1 ,…,u~ j,n' In this embodiment, n'=1, so L(B~ j ) is ∧ q ⊥ (A T )∪{u~ j,1 }, the lattice L(∧ q ⊥ (A T )∪{u~ j,1 }) (Figure 8). The sample point vector b~ j,1 ,…,b~ j,m' (Information corresponding to the one-dimensional LWE-like problem) is sent to the problem conversion device 12.
[0152] <Step A2 (Figures 1 and 2)> The problem transformation device 12 receives the sample point vector b~ j,1 ,…,b~ j,m' (information corresponding to a set of one-dimensional LWE-like problems) and a target vector t are input. The problem conversion device 12 converts the sample point vector b~ j,1 ,…,b~ j,m' (where j=1,...,m') is converted into a set of phase estimation problems with errors, and information corresponding to the set of phase estimation problems with errors is obtained and output. In this embodiment, the information corresponding to the set of phase estimation problems with errors is calculated based on the input quantum state |Ψ j,t An example is shown in which the information is used to specify j=1,...,m' (where j=1,...,m'). However, this does not limit the present invention. Details will be explained below.
[0153] As illustrated in Figure 5, the sample point vector b~ j,1 ,…,b~ j,m' is input to the vector generation unit 122 and the input quantum state identification unit 123 of the problem transformation device 12. The vector generation unit 122 j B~ j =B R ∩L(B~ j ) is a set (domain) of m-dimensional vectors Ω j ⊆Z q' m As mentioned above, B~ j is the lattice L(B~ j ) represents the m × m matrix that represents the basis of the sample point vector b~ j,1 ,…,b~ j,m' m vectors b~ contained in j,1 ,...,b~ j,m is the base B~ j are m vectors of dimension m that make up B R represents the interior of a given region. A set of m-dimensional vectors Ω j is sent to the input quantum state identification unit 123. The target vector t is also input to the input quantum state identification unit 123. The input quantum state identification unit 123 identifies the sample point vector b~ j,1 ,…,b~ j,m' , a target vector t and a set of m-dimensional vectors Ω j Using the input quantum state |Ψ of the above equation (9), j,t The quantum state |Ψ is generated and output. j,t An example of information that identifies > is the vertical vector |Ψ j,t > is the sequence representing the input quantum state |Ψ j,t The information specifying the problem is sent to the solution solving unit 13.
[0154] <Step B (Figures 1 and 2)> As shown in FIG. 6, the solver 13 receives an input quantum state |Ψ j,t > information that identifies the sample point vector b~ j,1 ,…,b~ j,m' , and matrix A are input. The solver 13 calculates the input quantum state |Ψ j,t >, and solve the set of error-containing phase estimation problems (equation (4)) corresponding to j The solution s' is obtained. j To obtain the set of j (γ) This information is not necessary.
[0155] In this embodiment, first, the input quantum state generation unit 132 of the solution-finding device 13 calculates the superposition state |Ψ of equation (8). j,0 > and generates the input quantum state |Ψ j,t Based on the information that identifies the superposition state |Ψ j,0 By applying a phase rotation gate to the input quantum state |Ψ j,t > (Step B-1).
[0156] Next, the state alignment operation unit 133 adjusts the input quantum state |Ψ generated by the input quantum state generation unit 132. j,t > for state alignment operation X j and quantum state X j |Ψ j,t >. State alignment operation X j is a quantum operation defined by the above-mentioned equation (17). For example, the state alignment operation unit 133 calculates the sample point vector b~ j,1 ,…,b~ j,m' and C shown in equation (18) using matrix A. j Identify and perform the state alignment operation X j (Step B-2).
[0157] Next, the inverse quantum Fourier transform unit 134 converts the quantum state X j |Ψ j,t >, the inverse quantum Fourier transform of the above equation (19)
number
number
[0158] Next, the observation unit 135 detects the quantum state obtained as described above.
number
[0159] The label calculation unit 136 calculates the observation result z j Using the aforementioned label L j (z j B) and output the label L j (z j B) is sent to the solution generating unit 137 (step B-5).
[0160] The solution generator 137 receives the label L j (z j B) is input. As mentioned above, the label L j (z j B) has a high probability of finding the solution s' j Therefore, the obtained label L j (z j B) Using the solution s' j For example, the solution generating unit 137 repeatedly executes the processes from step B-1 to step B-5 until a predetermined termination condition is met, and obtains the label L j (z j B) Based on the solution s' j For example, the solution generating unit 137 obtains and outputs the label L that appears most frequently for each j. j (z j B) Solve s' j The termination condition may be, for example, repeating the processes from step B-1 to step B-5 a predetermined number of times, or outputting the label L with the highest frequency of appearance for each j. j (z j The difference in frequency between the solution s' and the label with the second highest frequency of occurrence may be greater than a predetermined value. j is sent to the solution transformation unit 14 (step B-6).
[0161] <Step C (Figures 1 and 2)> The solution converter 14 stores the solution s' for each j. j , interpolation point vector u~ j,1 , and matrix A are input. The solution conversion device 14 converts the input solution s' j and the interpolation point vector u~ j,1 Calculate the solution s of the LWE problem from the set of j are input to the difference generation unit 142. The difference generation unit 142 calculates the input solutions s'1,...,s' m' m solutions s'1,...,s' out of m and the interpolation point vector u~ 1,1 ,...,u~ m,1 The difference vector t-ε of equation (131) is obtained and output. q' If the m × m matrix U~ does not have an inverse, then the dual lattice ∧ q ⊥ (A T )B - 1,...,B - m Then, the difference generating unit 142 selects again the elements (t-ε) of the difference vector t-ε according to the equation (132), for example. j (For example, j=1, . . . , m) can be obtained. The difference vector t−ε is sent to the solution generating unit 143.
[0162] The solution generating unit 143 uses the difference vectors t-ε, q, and A to obtain and output a column vector s that satisfies As≡t-ε mod q. This column vector s is a solution to the LWE problem.
[0163] <Features of this form> In this embodiment, the LWE problem is reduced to a set of one-dimensional LWE-like problems (Step A1), the resulting set of one-dimensional LWE-like problems is reduced to a set of phase estimation problems with errors (Step A2), solutions to each of the set of phase estimation problems with errors are found (Step B), and a solution to the LWE problem is calculated from the solutions to the resulting set of phase estimation problems with errors (Step C). This allows the LWE problem to be solved efficiently.
[0164] [Modification 1 of the First Embodiment] In the first embodiment, in step A1, the LWE reduction device 11 calculates the sample point vector b~ as information corresponding to the one-dimensional LWE-like problem. j,1 ,…,b~ j,m' However, in step A1, the LWE reduction device 11 may generate and output other information as information corresponding to the one-dimensional LWE-like problem.
[0165] For example, the LWE reduction device 11 includes a matrix generation unit 114, which generates the input sample point vector b~ j,1 ,…,b~ j,m' Using the matrix
number
[0166] For example, the LWE reduction device 11 has a target vector generation unit 115, and the target vector generation unit 115 generates an input sample point vector b~ j,1 ,…,b~ j,m' Using the target vector
number
[0167] For example, the LWE reduction device 11 includes a parameter generation unit 116, which generates a sample point vector b~ j,1 ,…,b~ j,m' and α, for j=1,...,m' and μ=1,...,m', α' j,μ =α||b~ j,μ However, as mentioned above, σ' j,μ =αq'||b~ j,μ ||=q'α' j,μ Meet the following.
[0168] [Modification 2 of the First Embodiment] In the first embodiment, in order to efficiently solve the LWE problem, in step A1, n' = 1, and the LWE reduction device 11 reduces the LWE problem to a set of one-dimensional LWE-Like problems. However, it is not limited to n' = 1, and the LWE reduction device 11 may reduce the LWE problem to a set of n'-dimensional LWE-Like problems. The processing of step A1 in this case is the same as the processing of step A1 in the first embodiment, except that it is not limited to n' = 1. That is, for any integer θ satisfying 0 < θ < q', the LWE reduction device 11
Number
Number
[0169] [Second embodiment] In this embodiment, an example will be described in which m=m'=2 and n=n'=1, and the LWE reduction in step A1 is the Fibonacci-set LWE reduction in step A1a. Hereinafter, differences from the first embodiment will be mainly described, and the same reference numerals will be used to simplify the description of matters common to the first embodiment.
[0170] <Configuration> As shown in Fig. 3, the computing device 2 of this embodiment includes an LWE reduction device 21, a problem transformation device 12, a solution finding device 13, a solution transformation device 14, and a storage unit 15. Here, the LWE reduction device 21 is, for example, a device obtained by loading a predetermined program into a classical computer. However, this does not limit the present invention, and the LWE reduction device 21 may be a hybrid device or a quantum computer. Information input to the computing device 2 is stored in the storage unit 15 and is read out and used as needed.
[0171] As shown in Fig. 4, the LWE reduction device 21 (computing device) of this embodiment includes a control unit 111, an interpolation point selection unit 212, and a sample point selection unit 213. The LWE reduction device 21 executes each process under the control of the control unit 111. The LWE reduction device 21 stores information obtained in each process in a memory (not shown). The information stored in this memory is read out as needed and used in each process.
[0172] <Processing> Next, the processing of this embodiment will be described. <Pre-processing> As a preprocessing, the parameters m, n, q, α of the LWE problem and m', n', q' included in the parameter set of the LWE-like problem are input to the computing device 2 (Fig. 3) and stored in the storage unit 15 of the computing device 2. In this embodiment, an example where m = m' = 2 and n = n' = 1 is shown, but this does not limit the present invention. Also, although the subsequent description is omitted, the LWE reduction device 21 reads at least a part of m, n, q, α, m', n', q' from the storage unit 15 and uses them for respective processes. That is, when at least a part of m, n, q, α, m', n', q' is required for the process of the LWE reduction device 21, the LWE reduction device 21 reads the information necessary for each process from m, n, q, α, m', n', q' and uses it for respective processes.
[0173] <Step A1a (Fig. 1)> As illustrated in Fig. 3, the matrix A and the target vector t of the LWE problem are input to the computing device 2, and these are input to the LWE reduction device 21. The LWE reduction device 21 reduces the LWE problem specified by these and the parameter set (m, n, q, α) of the LWE problem to a set of one-dimensional LWE-Like problems (Step A1a: LWE reduction). That is, the LWE reduction device 21 uses the parameter set (m, n, q, α), the matrix A, and the target vector t of the LWE problem for which a solution is sought, and obtains and outputs a set of information corresponding to m' = m = 2 one-dimensional LWE-Like problems. In this embodiment, the set of information corresponding to the one-dimensional LWE-Like problem is the sample point vectors b~ j,1 , b~ j,2 is shown as an example. However, this does not limit the present invention. Details will be described below.
[0174] As illustrated in Fig. 4, the matrix A and the target vector t are input to the interpolation point selection unit 212 of the LWE reduction device 21. The interpolation point selection unit 212 selects and outputs an interpolation point vector u~ j,1 that satisfies the above-described equations (22a) and (22b) for any integer θ satisfying 0 < θ < q'. In this embodiment, the interpolation point selection unit 212 uses the interpolation point vector u~ j,1 (where j=1, 2) is generated and output. As mentioned above, υ in equation (41) is, for example, υ=π~(q), and π~(q) is the Fibonacci sequence {F k mod q} k=0 ∞ However, this does not limit the present invention, and as long as υ is an integer equal to or greater than 0, it does not have to be υ=π~(q). j,1 (where j=1, 2) is sent to the sample point selection unit 213 and the solution transformation unit 14.
[0175] The sample point selection unit 213 selects the interpolation point vector u~ j,1 Using the linearly independent sample point vector b~ j,1 ,b~ j,2 ∈L(B~ j )∩R c (where j=1, 2). In this embodiment, first, the sample point selection unit 213 selects and outputs the interpolation point vector u~ j,1 Using this, the subdivision point vector d~ that satisfies the above-mentioned equation (43) is j,1 ,…,d~ j,ξυ+1 Next, the sample point selection unit 213 selects the subdivision point vector d~ j,1 ,…,d~ j,ξυ+1 and the interpolation point vector u~ j,1 Based on this, the sample point vector b~ is calculated as described above. j,1 ,…b~ j,m (For example, sample point vector setting examples 1 and 2) As mentioned above, the sample point vector b~ j,1 ,…b~ j,m is the lattice L(B~ j ) basis B~ j ={b~ j,1 ,...,b~ j,m }, which is an m-dimensional vector b~ j,1 ,...,b~ j,m (In this embodiment, m=2). The sample point vector b j,1 ,…,b~ j,m (Information corresponding to the one-dimensional LWE-Like problem) is sent to the problem conversion device 12. The subsequent processing is the same as in the first embodiment or the modified example of the first embodiment, except that m=m′=2.
[0176] [Third embodiment] In this embodiment, an example will be described in which m=m' and n=n'=1, and the LWE reduction in step A1 is the LWE reduction in the extended Fibonacci setting in step A1b.
[0177] <Configuration> As illustrated in Fig. 3, the computing device 3 of this embodiment includes an LWE reduction device 31, a problem transformation device 12, a solution finding device 13, a solution transformation device 14, and a storage unit 15. Here, the LWE reduction device 31 is, for example, a device obtained by loading a predetermined program into a classical computer. However, this does not limit the present invention, and the LWE reduction device 31 may be a hybrid device or a quantum computer. Information input to the computing device 3 is stored in the storage unit 15 and is read out and used as needed.
[0178] As shown in Fig. 4, the LWE reduction device 31 (computing device) of this embodiment includes a control unit 111, an interpolation point selection unit 312, and a sample point selection unit 313. The LWE reduction device 31 executes each process under the control of the control unit 111. The LWE reduction device 31 stores information obtained in each process in a memory (not shown). The information stored in this memory is read out as needed and used in each process.
[0179] <Processing> Next, the processing of this embodiment will be described. <Pre-processing> As a pre-processing step, the parameter set for the LWE problem, m, n, q, α, and the parameter set for the LWE-like problem, m', n', q', are input to the calculation device 3 (FIG. 3) and stored in the storage unit 15 of the calculation device 3. Note that in this embodiment, an example is shown in which m=m' and n'=1 for any positive integers m and n, but this does not limit the present invention. Also, although not described further below, the LWE reduction device 31, problem conversion device 12, solution finding device 13, and solution conversion device 14 read at least a portion of m, n, q, α, m', n', q' from the storage unit 15 and use them in their respective processes. That is, when at least a part of m, n, q, α, m', n', q' is required for each process of the LWE reduction device 31, the problem conversion device 12, the solution finding device 13, and the solution conversion device 14, the LWE reduction device 31, the problem conversion device 12, the solution finding device 13, and the solution conversion device 14 read out the information required for each process from m, n, q, α, m', n', q' and use it for each process.
[0180] <Step A1b (Figure 2)> As illustrated in FIG. 3, a matrix A and a target vector t of an LWE problem are input to a calculation device 3, and these are then input to an LWE reduction device 31. The LWE reduction device 31 reduces the LWE problem, specified by these and a parameter set (m, n, q, α) of the LWE problem, to a set of one-dimensional LWE-like problems (step A1b: LWE reduction). That is, the LWE reduction device 31 uses the parameter set (m, n, q, α) of the LWE problem to be solved, the matrix A, and the target vector t, to obtain and output a set of information corresponding to m' one-dimensional LWE-like problems. In this embodiment, the set of information corresponding to the one-dimensional LWE-like problems is obtained by using the sample point vectors b~ j,1 ,…,b~ j,m (where j=1,...,m) is an example, but this does not limit the present invention. Details are explained below.
[0181] As illustrated in FIG. 4, the matrix A and the target vector t are input to the interpolation point selection unit 312 of the LWE reduction device 31. For any integer θ satisfying 0 < θ < q', the interpolation point selection unit 312 selects and outputs an interpolation point vector u~ that satisfies the above-described equations (22a) and (22b). j,1 In this embodiment, the interpolation point selection unit 312 generates and outputs the interpolation point vector u~ of equation (79) (where j = 1,..., m). As described above, υ in equation (79) is, for example, υ = m + 1. However, this does not limit the present invention, and υ may be an integer greater than or equal to 0 and not necessarily υ = m + 1. The interpolation point vector u~ is sent to the sample point selection unit 313 and the deconversion device 14. j,1 (Here, j = 1,..., m). j,1
[0182] The sample point selection unit 313 uses the interpolation point vector u~ to select and output linearly independent sample point vectors b~, b~ ∈ L(B~) ∩ R j,1 (where j = 1,..., m). In this embodiment, first, the sample point selection unit 313 uses the interpolation point vector u~ to select subdivision point vectors d~,..., d~ that satisfy the above-described equation (82). Next, the sample point selection unit 313 obtains and outputs the sample point vectors b~,..., b~ based on the subdivision point vectors d~,..., d~ and the interpolation point vector u~ (for example, setting example 3 of the sample point vector). As described above, the sample point vectors b~,..., b~ are m-dimensional vectors b~,..., b~ that constitute the basis B~ = {b~,..., b~} of the lattice L(B~). The sample point vectors b~,..., b~ j,1 ,b~ j,2 ∈L(B~ j )∩R c j,1 j,1 ,…,d~ j,ξυ+1 j,1 ,…,d~ j,ξυ+1 j,1 j,1 ,…b~ j,m j,1 ,…b~ j,m j )の基底B~ j ={b~ j,1 ,...,b~ j,m}を構成するm次元のベクトルb~ j,1 ,...,b~ j,m j,1 ,…,b~ j,m (Information corresponding to the one-dimensional LWE-Like problem) is sent to the problem conversion device 12. The subsequent processing is the same as in the first embodiment or the modified example of the first embodiment, except that m=m′=2.
[0183] [Modification 1 of the third embodiment] The processing of step A1b in the third embodiment may be performed after converting the input LWE problem (an m-sample n-dimensional LWE problem modulo q) into an LWE problem modulo a power of 2 by standard LWE reduction (see, for example, Non-Patent Document 1).
[0184] 3, the computing device 3 of this embodiment includes an LWE reduction device 30, an LWE reduction device 31, a problem transformation device 12, a solution finding device 13, a solution transformation device 14, and a storage unit 15. Here, the LWE reduction device 30 is, for example, a device obtained by loading a predetermined program into a classical computer. However, this does not limit the present invention, and the LWE reduction device 30 may be a hybrid device or a quantum computer.
[0185] <Pre-processing> As a pre-processing step, m, n, q, α, which are the parameter set of the LWE problem, and m', n', q', which are included in the parameter set of the LWE-like problem, are input to the calculation device 3 (FIG. 3) and stored in the storage unit 15 of the calculation device 3. In addition, the matrix A and the target vector t of the LWE problem are input to the calculation device 3 (FIG. 3) and stored in the storage unit 15 of the calculation device 3. The LWE reduction device 30 reads m, n, q, α, A, t from the storage unit 15, and reduces the input LWE problem by standard setting LWE reduction (see, for example, Non-Patent Document 1) modulo q=2 r The LWE problem is then converted into the following LWE problem, and the q stored in the storage unit 15 is converted into a power of 2, q=2 r (Step A0), where r is a positive integer. The other processes are the same as those in the third embodiment.
[0186] [Fourth embodiment] In this embodiment, we will explain step A2', which is a modified example of step A2, and step B', which is a modified example of step B. That is, the difference between this embodiment and the first to third embodiments is the set of phase estimation problems with errors and the processing content for those problems.
[0187] <Step A2'> First, the processing of step A2' by a classical computer, which is necessary for the processing of this embodiment, will be described. First, the lattice L(B)=∧ q (A T ) sublattice basis B0,...,B ζ Here, ζ represents an integer greater than 1. For example, ζ is a sufficiently large integer greater than or equal to 1. For example, ζ is a sufficiently large integer greater than or equal to 1 and less than log2q'. The larger ζ is, the more likely it is that the correct solution s' j On the other hand, the larger ζ is, the larger the amount of calculation becomes, so ζ may be set based on the input. In this embodiment, the basis B0,...,B ζ Each of these is expressed as an m×m matrix. Also, the basis B0,...,B ζ Each of these is B k' where k'=0,...,ζ. The basis B0 is identical to the basis B of the lattice L(B) (B0=B). Other bases B1,...,B ζ There is no limitation on how to generate the basis B0,...,B ζ are preferably different from each other. For example, the bases B0,...,B ζ is preferably an orthogonal or nearly orthogonal basis.
[0188] <base B0,...,B ζ Example of how to generate base B0,...,B ζ However, this is merely an example and does not limit the present invention. Step A2'-1: Set kb=0 and set B0=B. Step A2'-2:B kb row vector b kb,1 ,...,b kb,m Among these, the pair of row vectors with the smallest angle (b kb,ζ1 ,b kb,ζ2 ) where kb∈{0,...,ζ-1} and ζ1,ζ2∈{1,...,m}. That is, the following set of row vectors (b kb,ζ1 ,b kb,ζ2 ) is selected.
number
number
[0189] This basis B0,...,B ζ From the sequence of j,0 ,...,C j,ζ Define a column of
number
[0190] <Introduction of Non-Commutative Diagram> The matrix H that satisfies equation (161) 0,1 , H 0,2 ,..., H ζ-1,ζ is defined. B k" = H k"-1,k" B k"-1 (161) Here, k" = 1,..., ζ. That is, the matrix H k"-1,k" represents an m×m matrix that satisfies equation (161). Furthermore, for k'1, k'2 ∈ {0,..., ζ} and 0 ≤ k'1 < k'2 ≤ ζ, the matrix H k'1:k'2 is defined as in equation (162).
Number
Number
Number
Number
number
number
[0191] base C j,k' The lattice generated by L(C j,k' ) In other words, the basis C j,k' The lattice constructed by L(C j,k' ) is expressed as the lattice L(C j,k' ) is based on C j,k' By the function of equation (164), the lattice L(B~ j ) m-dimensional vector contained in B(j) h∈L(B~ j ), the m-dimensional vector of the following equation (169) C(j,k') h∈L(C j,k' ) can be defined.
number
number
number
[0192] Using the function of Eq. (166), the lattice L(C j,k" ) m-dimensional vector contained in C(j,k") h∈L(C j,k" ), the m-dimensional vector of the following equation (171) C(j,k") h∈L(C j,k" ) can be defined.
number
[0193] base D j,k' The lattice generated by L(D j,k' ) In other words, the basis D j,k' The lattice constructed by L(D j,k' ) is expressed as the lattice L(D j,k' ) is based on D j,k' where the lattice L(D j,k' ) is an m-dimensional vector Dg(j,k') h∈L(D j,k' ) is calculated by the function of Eq. (168) from the lattice L(C j,k' ) is an m-dimensional vector C(j,k') h:=( C(j,k') h1,..., C(j,k') h m )∈L(C j,k' ), it can be defined as the following equation (172). Dg(j,k') h:=g( C(j,k') h)=g( C(j,k') h1,..., C(j,k') h m )∈D j,k' .....(172) Furthermore, the lattice L(D j,k" ) is an m-dimensional vector D(j,k") h∈L(D j,k" ) is calculated by the function of Eq. (166) for the lattice L(D j,k"-1 ) is an m-dimensional vector D(j,k"-1) h∈L(D j,k"-1 ), it can be defined as the following equation (173).
number
[0194] We introduce a non-commutative diagram, as illustrated in Figure 16A. As illustrated in Figure 16A, the lattice L(B~ j ) is an m-dimensional vector B(j) h∈L(B~ j ) by applying the function expressed by equation (164), the lattice L(C j,0 ) is an m-dimensional vector C(j,0) h∈L(C j,0 ) is obtained (Eq. (170)). For k"∈{1,...,ζ}, the lattice L(C j,k"-1 ) is an m-dimensional vector C(j,k"-1) h∈L(C j,k"-1 ) by applying the function expressed by equation (166), the lattice L(C j,k" ) is an m-dimensional vector C(j,k") h∈L(C j,k" ) is obtained (Eq. (171)). The lattice L(C j,k' ) is an m-dimensional vector C(j,k') h∈L(C j,k' ) by applying the function expressed by equation (168), the lattice L(D j,k' ) is an m-dimensional vector Dg(j,k') h∈L(D j,k' ) is obtained (Eq. (172)). Also, the lattice L(D j,k"-1 ) is an m-dimensional vector D(j,k"-1) h∈L(D j,k"-1 ) by applying the function expressed by equation (166), the lattice L(D j,k" ) is an m-dimensional vector D(j,k") h∈L(D j,k" ) is obtained (Equation (173)).
[0195] m-dimensional vector Dg(j,k') Let the set of h be g(L(C j,k' )), the relationship in equation (174) below holds.
number
number
[0196] base E j,0 ,...,E j,ζ The columns of are defined as follows: (175) and (176). E j,k' :=D j,k' H k':ζ T (When k'≠ζ) (175) E j,k' :=D j,k' (When k'=ζ) (176) Here, the lattice L(D j,k' ) is an m-dimensional vector D(j,k') h∈L(D j,k' ) by the function shown in Eq. (166)
number
number
number
number
number
number
[0197] <Representative selection using non-commutative diagrams> FIG. 16B is a non-commutative diagram that is a part of the non-commutative diagram shown in FIG. 16A. As shown in FIG. 16B, the lattice L(B~ j ) is an m-dimensional vector B(j) Taking h as input, the above-mentioned functions are applied along the non-commutative diagram, and the result is a lattice L(D j,k' The path to obtain the m-dimensional vector, which is an element of k' and path_d k' There are two ways. k' So, m-dimensional vector B(j) By applying the function of equation (164) to h and then the function of equation (166), the lattice L(C j,k' ) is an m-dimensional vector C(j,k') h∈L(C j,k' ) is obtained, and then the function expressed by equation (168) is applied to obtain the lattice L(D j,k' ) is an m-dimensional vector Dg(j,k') h∈L(D j,k' ) is obtained. On the other hand, the path path_d k' So, m-dimensional vector B(j) By applying the function of equation (164) to h and then the function of equation (166), the lattice L(C j,k' ) is an m-dimensional vector C(j,k') h∈L(C j,k' ) is obtained, and then the function expressed by equation (168) is applied, followed by the function of equation (166) to obtain the lattice L(D j,k' ) is an m-dimensional vector D(j,k') h∈L(D j,k' ) is obtained. This diagram is non-commutative and the lattice L(B~ j ) path_u k' The lattice L(D j,k' ) and the lattice L(B~ j ) path_d k' The lattice L(D j,k' ) is different from the image to
number
number
number
number
number
number
number
number
number
number
[0198] Such an m-dimensional vector x(0)B~ j ,...,x(ζ)B~ j For y(j,0),...,y(j,ζ), we define the lattice L(B~ j ) path_u k' The lattice L(D j,k' ) (Fig. 16B). That is, y(j,k') is defined as the following equation (180).
number
[0199] By using the m-dimensional vector y(j,k') defined by the representative z(j,k'), the lattice L(D j,k' ) is the sublattice L(D j,k'-1 H k'-1,k' T ) and the set y(j,k')+L(D j,k'-1 H k'-1,k' T ) can be expressed as a union with . That is, the following equation (181c) holds. L(D j,k' )=L(D j,k'-1 H k'-1,k' T )∪(y(j,k')+L(D j,k'-1 H k'-1,k' T )) (181c) Here, the lattice L(D j,k'-1 H k'-1,k' T ) is the lattice L(C j,0 ) path_d k' is the lattice to which the image by y(j,k') belongs, and y(j,k') is the lattice L(C j,0 ) Path of elements path_u k' The representative element z(j,k') corresponding to y(j,k') is also a lattice L(C j,0 ) Path of elements path_u k' The image is based on the lattice L(E j,ζ ) is a lattice L(E j,0 ) is shifted to obtain 2 ζ It can be expressed as the union of sets. That is, the following equation (182) holds.
number
[0200] <L(D j,k' ) Phase of each point> Lattice L(D j,k' ) the following phases are defined for each point. 1. Representative element z(j,k")∈L(E j,k" )-L(E j,k"-1 ) (where k"=1,...,ζ) j,ζ (t,z(j,k")) is defined as the following equation (183).
number
[0201] 2. Lattice L(E j,0 ) the phase is determined as follows: As mentioned above, C j,0 =D j,0 Therefore, the lattice L(E j,0 ) the phase at any point of the
number
number
number
[0202] 3. For other points, the phase is determined as follows: According to the above equation (182), any L z∈L(E j,ζ ), for some δ1,...,δ ζ ∈{0,1} exists such that the following equation (186) holds. L z∈δ1z(j,1)+...+δ ζ z(j,ζ)+L(E j,0 ) (186) Such δ1,...,δ ζ is determined, for example, as follows: Step A2'-11: Set kb=ζ. Step A2'-12: L z∈L(E j,kb )-L(E j,kb-1 ) and determine whether it is. Step A2'-13: If L z∈L(E j,kb )-L(E j,kb-1 ), then δ kb :=1, L z:= L zy(j,kb)·H kb: ζ T Then proceed to step A2'-15. Step A2'-14: If L z∈L(E j,kb ), then δ kb :=0 and proceed to step A2'-15. Step A2'-15: Determine whether kb=1. If kb=1, set kb=kb-1 and return to step A2'-12. On the other hand, if kb=1, use the obtained δ1,...,δ ζ Output. Note that this method is just an example, and there are other methods for δ1,...,δ ζ may be obtained.
[0203] δ1,...,δ ζ Using the above equation (182), the following equation (187) is established.
number
number
number
[0204] With the above preparation, the set Θ that satisfies the following formula (190) j,ζ Define
number
number
[0205] <Step B'> Next, the processing of step B' by the quantum computer of this embodiment will be described. <Step B'-1> Prepare and initialize m q'-dimensional quantum registers.
[0206] <Step B'-2> In the quantum register, the quantum state |Ψ shown in the following equation (192) j,0 > to generate.
number
number
[0207] <Step B'-3> In the quantum register, the quantum state |Ψ shown in equation (192) j,0 > and add an ancillary quantum bit to generate the quantum state shown in equation (194) below.
number
[0208] <Step B'-4> In the quantum register, a rotation gate is used to generate the quantum state shown in the following equation (195).
number
[0209] <Step B'-5> In the quantum register, the ancillary elements are initialized (the ancillary elements are discarded) by applying the reverse operation of step B'-3 to the quantum state of equation (195). This operation results in the input quantum state |Ψ shown in the following equation (196): j,t > is obtained.
number
[0210] <Step B'-6> The input quantum state |Ψ of the quantum register equation (196) j,t >, the inverse quantum Fourier transform shown in equation (19)
number
number
[0211] <Step B'-7> Observe the quantum state of the quantum register (197) and obtain the observation result OM j =(OM j,1 ,...,OM j,m )∈Z q' m get.
[0212] <Step B'-8> Observation results OM j Using the above, the label L shown in the following equation (198) j (z j B ζ ) (j=1,...,m) is obtained. The processing of step B'-8 may be performed using either a classical computer or a quantum computer.
number
[0213] <Step B'-9> Label L j (z j B ζ )∈Z q' Using the solution s' j Here, the label L j (z j B ζ ) has a high probability of finding the solution s' j Therefore, for example, if we repeat the above steps B'-1 to B'-8, the resulting label L j (z j B ζ ) is the most frequent solution s' of the LWE-like problem. j Output as
[0214] <Example of Step A2' and Step B'> Here, we present an example of Step A2' and Step B'. Here, we present an example of the same LWE problem as the example of Step A1a. That is, the input parameter set (m, n, q, α) of the LWE problem is (m, n, q, α) = (2, 1, 5, 0.2),
number
[0215] First, the bases B0, B1, and B2 of the sublattice of the lattice L(B) are illustrated. The base B in equation (51) is set to the base B0.
number
number
number
[0216] H 0,1 and H 1,2 becomes:
number
[0217] In this case the non-commutative diagram becomes:
number
[0218] Also, from the sequence of bases B0, B1, and B2, the following base C 1,0 ,C 1,1 ,C 1,2 First, using the same base B~1 as in the example of step A1a, we can define a sequence of base C 1,0 is expressed as follows:
number
number
number
[0219] base C 1,1 ,C 1,2 The basis D is the image of the function of Eq. (168) 1,1 ,D 1,2 can be obtained as follows. First,
number
number
number
[0220] Next, L(E 1,1 )-L(E 1,0 ) representative z(1,1) and L(E 1,2 )-L(E 1,1 ) select the representative z(1,2). Here is an example: If x(1)=(0,2), then x(1)B~1=(-2 / 13,16 / 13), and y(1,1) is as follows.
number
number
[0221] Also, if x(2) = (1,1), then x(2)B~1 = (-2 / 13,16 / 13), and y(1,2) is as follows.
number
number
[0222] Using these representatives z(j,1) and z(j,2), we define the lattice L(E 1,2 )=L(D 1,2 ) is the lattice L(E 1,0 ) is shifted to obtain 2 2 It can be expressed as a union of sets, i.e., the following holds:
number
number
number
number
[0223] Subsequent processing is carried out using a quantum computer. <Step B'-1> Two 13-dimensional quantum registers are prepared and initialized. When the quantum registers are configured with qubits, the 13th dimension is represented by four qubits, for a total of eight qubits.
[0224] <Step B'-2> Let the quantum register be in a superposition state, and 1,0 > to generate.
number
[0225] <Steps B'-3, B'-4, B'-5> Following steps B'-3, B'-4, and B'-5, the following input quantum state |Ψ is obtained using a rotation gate: 1,t > to generate.
number
[0226] <Step B'-6> The input quantum state of the quantum register |Ψ 1,t >,|Ψ 2,t >, we perform the inverse quantum Fourier transform shown in equation (19). This results in the following quantum state in the quantum register:
number
[0227] <Step B'-7> The quantum state of the quantum register obtained in step B'-6 is observed and the observation result OM1 = (OM 1,1 ,OM 1,2 ) is obtained. The observation result OM1 = (OM 1,1 ,OM 1,2 The horizontal axis shows the distribution of the observed OM 1,1 The vertical axis represents the distribution of the observed OM 1,2 The closer the color is to white, the higher the probability of observation.
[0228] <Step B'-8> Using the observation result OM, we obtain the label L1(z1B2) as follows:
number
[0229] Figure 18B illustrates the probability distribution of the value of label L1(z1B2) corresponding to observation result OM1. In the example of Figure 18B, there is a high probability that the value of label L1(z1B2) will be 9. Therefore, if the processes of steps B'-1 to B'-8 are repeated multiple times, the label value L1(z1B2) with the highest probability of occurrence will be 9, and it can be concluded that the solution is s'1=9.
[0230] <Configuration> Next, the configuration of the computing device 4 of this embodiment will be described. As illustrated in FIG. 3, the computing device 4 of this embodiment includes an LWE reduction device 11, a problem transformation device 42, a solution-finding device 43, a solution transformation device 14, and a storage unit 15. Here, the problem transformation device 42 is, for example, a device obtained by loading a predetermined program into a classical computer (e.g., a von Neumann computer). On the other hand, the solution-finding device 43 is, for example, a hybrid device that combines a device obtained by loading a predetermined program into a classical computer with a quantum computer (e.g., a gate-type quantum computer or an annealing-type quantum computer). Note that the hybrid type may also be a device obtained by loading a predetermined program into a classical computer and a quantum computer. Furthermore, the problem transformation device 42 may be a hybrid device or a quantum computer. Furthermore, the solution-finding device 43 may be a quantum computer into which a predetermined program has been loaded. Information input to the computing device 4 is stored in the storage unit 15 and is read out and used as needed.
[0231] As illustrated in Fig. 5, problem transformation device 42 (computation device) of this embodiment has control unit 121, vector generation unit 422, and input quantum state identification unit 423. Problem transformation device 42 executes each process under the control of control unit 121. Problem transformation device 42 executes each process under the control of control unit 121. Problem transformation device 42 stores information obtained in each process in memory (not shown). The information stored in this memory is read out as needed and used in each process.
[0232] 15, the solution-finding device 43 (computation device) of this embodiment has a control unit 131, an input quantum state generation unit 432, an inverse quantum Fourier transform unit 434, an observation unit 135, a label calculation unit 436, and a solution generation unit 437. The solution-finding device 43 executes each process under the control of the control unit 131. The solution-finding device 43 stores information obtained in each process in a memory (not shown). The information stored in this memory is read out as needed and used in each process.
[0233] <Processing> Next, the processing of this embodiment will be explained. The processing of this embodiment differs from the processing of the first to third embodiments in that step A2 and step B are replaced with the above-mentioned step A2' and step B'. Only step A2' and step B' will be explained below. Note that in this embodiment as well, the problem conversion device 42 and the solution finding device 43 read at least a portion of m, n, q, α, m', n', and q' from the storage unit 15 as necessary, and use them in their respective processing.
[0234] <Step A2'> The problem transformation device 42 (FIG. 3) includes a sample point vector b~ j,1 ,…,b~ j,m' (information corresponding to a set of one-dimensional LWE-like problems), the matrix A of the LWE problem, and the target vector t are input. The sample point vector b~ j,1 ,…,b~ j,m' is output from any of the above-mentioned LWE reduction devices 11, 21, and 31. The problem transformation device 42 converts the sample point vector b~ j,1 ,…,b~ j,m' (where j = 1,...,m') is converted into a set of phase estimation problems with errors, and information corresponding to the set of phase estimation problems with errors is obtained and output. As mentioned above, B~ j is the lattice L(B~ j ) represents the m × m matrix that represents the basis of the sample point vector b~ j,1 ,…,b~ j,m' m vectors b~ contained in j,1 ,...,b~ j,m is the base B~ j In this embodiment, the information corresponding to the set of phase estimation problems with errors is expressed as the input quantum state |Ψ j,t An example is shown in which the information is used to specify j=1,...,m' (where j=1,...,m'). However, this does not limit the present invention. Details will be explained below.
[0235] As illustrated in Figure 5, the sample point vector b~ j,1 ,…,b~ j,m and the matrix A of the LWE problem are input to the vector generation unit 422 of the problem transformation device 42. The vector generation unit 422 uses these to generate a set of m-dimensional vectors Θ that satisfies the above-mentioned equation (190). j,ζ and output it.
number
[0236] A set of m-dimensional vectors Ω j , a set of m-dimensional vectors Θ j,ζ and the functions of equations (164), (166), and (168) are sent to the input quantum state specifying unit 423. The input quantum state specifying unit 423 receives the sample point vector b~ j,1 ,…,b~ j,m and the target vector t are also input. Using these, the input quantum state specifying unit 423 determines the input quantum state |Ψ j,t > Obtain and output information that identifies the
number
[0237] <Step B'> As shown in FIG. 15, the solver 43 receives the input quantum state |Ψ shown in equation (191). j,t The solution-finding device 43 receives information specifying the input quantum state |Ψ j,t >, and solve the set of error-containing phase estimation problems (equation (4)) corresponding to j The solution s' is obtained. j To obtain the set of j (γ) This information is not necessary.
[0238] In this embodiment, first, the input quantum state generation unit 432 of the solution-finding device 43 (FIG. 15) generates the input quantum state |Ψ shown in equation (196). j,t > to generate.
number
[0239] Next, the inverse quantum Fourier transform unit 434 calculates the input quantum state |Ψ of the quantum register equation (196). j,t >, the inverse quantum Fourier transform shown in the above equation (19)
number
number
[0240] The observation unit 435 observes the quantum state of the quantum register in equation (197) and outputs the observation result OM j =(OM j,1 ,...,OM j,m )∈Z q' m Observation results OM j is sent to the label calculation unit 436 (step B'-7).
[0241] The label calculation unit 436 calculates the observation result OM j Using the label L shown in equation (198), j (z j B ζ )(j=1,...,m).
number
[0242] The solution generator 437 generates the label L j (z j B ζ ) to find the solution s' j As mentioned above, the label L j (z j B ζ ) has a high probability of finding the solution s' j Therefore, the obtained label L j (z j B ζ ) to find the solution s' j For example, the solution generating unit 437 repeatedly executes the processes from step B'-1 to step B'-8 until a predetermined termination condition is met, and obtains the label L j (z j B ζ ) based on the solution s' j For example, the solution generating unit 437 obtains and outputs the label L that appears most frequently for each j. j (z j B ζ ) is solved by s' j The termination condition may be, for example, repeating the processes from step B'-1 to step B'-8 a predetermined number of times, or outputting the label L with the highest frequency of appearance for each j. j (z j B ζ The difference in frequency between the solution s' and the second most frequently occurring label may be greater than a predetermined value. j is sent to the solution transformation unit 14 (step B'-9).
[0243] The subsequent processing is as explained in the first embodiment.
[0244] [Hardware configuration] The classical computer mentioned above is, for example, a general-purpose or dedicated computer equipped with a processor (hardware processor) such as a central processing unit (CPU) and memories such as random-access memory (RAM) and read-only memory (ROM). This computer may have one processor and memory, or multiple processors and memories. For example, the classical computer is a von Neumann computer. The quantum computer mentioned above is, for example, a device equipped with qubits required for quantum computation, a quantum operation unit that manipulates the quantum states of the qubits, and a quantum memory that stores the quantum states. For example, the quantum computer is a gate-type quantum computer or an annealing-type quantum computer.
[0245] The functions provided by the components described herein may be implemented in circuitry or processing circuitry, including quantum computers, general-purpose processors, application-specific processors, integrated circuits, ASICs (Application Specific Integrated Circuits), a Central Processing Unit (CPU), conventional circuits, and / or combinations thereof, programmed to provide the described functions. Processors include transistors and other circuits and are considered circuitry or processing circuitry. Quantum computers include qubits and other quantum circuits and are considered circuitry or processing circuitry. Examples of quantum computers include superconducting quantum computers, ion trap quantum computers, photonic quantum computers, topological qubits, neutral atom quantum computers, spin quantum computers, and quantum annealing quantum computers. Quantum computers and processors may be programmed processors that execute programs stored in memory.
[0246] In this specification, a circuitry, unit, or means is hardware that is programmed to realize or performs the described functions, which may be any hardware disclosed herein or any hardware known to be programmed to realize or perform the described functions.
[0247] If the hardware is a quantum computer or processor that is considered to be a type of circuitry, the quantum computer, circuitry, means, or unit is the combination of the hardware and / or software used to configure the hardware and / or quantum computer or processor.
[0248] [program] The above-mentioned program may be installed in a classical computer and / or a quantum computer (hereinafter simply referred to as a "computer"), or may be recorded in advance in a storage device such as a ROM or quantum memory. The program may also be recorded on a computer-readable recording medium. An example of a computer-readable recording medium is a non-transitory recording medium. Examples of such recording media include a magnetic recording device, an optical disk, a magneto-optical recording medium, a semiconductor memory, and a quantum memory.
[0249] This program may be distributed, for example, by selling, transferring, or lending a portable recording medium, such as a DVD or CD-ROM, on which the program is recorded. Furthermore, the program may be distributed by storing the program in a storage device of a server computer and transferring the program from the server computer to other computers via a network. As described above, a computer that executes such a program may, for example, first temporarily store the program recorded on a portable recording medium or transferred from the server computer in its own storage device. Then, when executing a process, the computer reads the program stored in its own storage device and executes processing in accordance with the read program. Alternatively, the program may be executed by a computer that reads the program directly from a portable recording medium and executes processing in accordance with the program. Furthermore, the computer may execute processing in accordance with the received program each time a program is transferred from the server computer to the computer. Alternatively, the server computer may not transfer the program to the computer, but may instead execute the processing function simply by issuing an execution instruction and obtaining the results, thereby executing the processing described above through a so-called ASP (Application Service Provider) type service. In this embodiment, the program includes information used for processing by an electronic computer that is equivalent to a program (such as data that is not a direct instruction to a computer but has properties that dictate computer processing).
[0250] Furthermore, instead of executing a predetermined program on a computer, the functions of at least one of the devices may be realized by hardware alone, without using a program.
[0251] The present invention is not limited to the above-described embodiments. For example, the various processes described above may not only be executed in chronological order as described, but may also be executed in parallel or individually depending on the processing capabilities of the device executing the processes or as needed. Furthermore, as long as information is input to each processing unit so that the information necessary for each process can be obtained, the information input to each processing unit is not limited to that of the above-described embodiments. For example, information obtained in one processing unit may be input to another processing unit and reused, or information obtained in the past may be input and reused. Needless to say, other appropriate modifications are possible within the scope of the claims. [Industrial Applicability]
[0252] The industrial applicability of the present invention is exemplified below. However, these applicability is merely an example and does not limit the present invention. By using the present invention, it is possible to quickly solve the LWE problem, which can be considered a type of combinatorial optimization problem. This will have an impact on two industrial fields, for example: the field of artificial intelligence and the field of post-quantum cryptography.
[0253] For example, by applying this invention, it is possible to quickly solve subproblems of combinatorial optimization problems in the field of artificial intelligence. For example, by implementing this invention on a gate-type quantum computer and a classical computer, it will become possible to use artificial intelligence to quickly simulate various phenomena in industry, materials, medicine, pharmaceuticals, energy, physics, chemistry, economy, real society, etc., contributing to rapid progress and development in each field.
[0254] A more specific explanation follows. The LWE problem is closely related to the shortest vector problem, which is known to be NP-hard. The shortest vector problem is known to be able to efficiently reduce other NP (nondeterministic polynomial time complexity class) problems. Since solving the reduced problem yields a solution to the original NP problem, the quantum algorithm proposed in this invention can be applied to, for example, all NP problems. NP problems include many important problems, particularly in the field of artificial intelligence, and have an extremely wide range of industrial applications. Representative application examples are listed below.
[0255] 1. Optimal route selection for autonomous driving: Optimal route selection for autonomous driving vehicles is formulated as an NP-complete problem called the traveling salesman problem. This problem has long been studied in the field of artificial intelligence, and as the number of vertices increases, it becomes difficult to find an optimal solution using classical computers. For this reason, in recent years, there has been active research into the application of quantum computers (especially quantum annealing) to this problem. 2. Large-scale integrated circuit optimization: When the problem of optimizing large-scale integrated circuits is expressed as a logical formula, it becomes a constraint satisfaction problem. This problem is a typical problem in artificial intelligence, and because of its usefulness, it has a long history of research using classical algorithms. This problem is considered to be one of the most promising applications for quantum computers. 3. Network infrastructure optimization: Optimizing large-scale and complex urban functions such as electricity, gas, and water networks, transportation and communication networks, and oil and gas pipelines has been difficult due to the explosion of computational complexity. The application of the quantum algorithm proposed in this invention is expected to provide a solution to these problems.
[0256] For example, the problem of optimal route selection in autonomous driving can be reduced to a lattice problem by representing the combination of routes as vectors. When the length of the route is below a certain level, the vector is encoded so that it approaches the lattice point within a certain distance, and by solving the lattice problem, information about the route can be obtained. For a more detailed explanation of how to reduce an NP-complete problem to a lattice problem, see Reference 7 below. Reference 7: Daniele Micciancio and Sha Goldwasser, Complexity of Lattice Problems: a cryptographic perspective, Kluwer Academic Publishers, The Kluwer International Series in Engineering and Computer Science, vol. 671 (2002). For other NP-complete problems, see the following references: Reference 8: Michael R. Garey and David S. Johnson, Computers and Intractability: A Guide to the Theory of NP-Completeness, WH Freeman & Co (1979). Experts predict that there is no efficient way to solve all NP problems exactly using classical computers (the P-NP conjecture). When dealing with NP problems using classical computers for industrial applications, one is often forced to choose between using approximate calculation results at the expense of solution accuracy, or restricting to subproblems in order to obtain exact solutions. On the other hand, by using the quantum algorithm of the present invention, the accuracy of calculation results can be significantly improved and the conditions for restricting to subproblems can be relaxed. As a result, it becomes possible to provide services that were previously unavailable.
[0257] Furthermore, in the field of post-quantum cryptography, the present invention may compromise the security of conventional lattice cryptography. While measures such as increasing the key length are necessary to compensate for this vulnerability, changing the key length may result in a deterioration in cryptographic efficiency. Using this invention to evaluate the security and cryptographic efficiency of lattice cryptography is expected to contribute to the development of cryptographic methods that solve both of these problems.
[0258] The following are some concrete practical applications: [structure] (1) Computing device 1-4 Input: Information to specify the LWE problem (e.g., A, t, q, σ). · Processing: Solve the LWE problem to get the solution of the LWE problem. · Output: Information representing the solution to the LWE problem (e.g., solution s).
[0259] (2) Application Device I Input: Noisy data (noise, typos, errors, etc.) in industrial applications. Processing: Convert the problem of removing noise from the data into an LWE problem, and output the LWE problem to the computing device 1-4 (e.g., send it via the Internet). Obtain information representing the solution to the LWE problem from the computing device 1-4 (e.g., receive it via the Internet). Convert the information representing the solution to the LWE problem into data with the noise removed. · Output: Noise-removed data.
[0260] (3) Application Device II Input: Information representing a combinatorial optimization problem in an industrial application. Processing: Converting information representing the combinatorial optimization problem into an LWE problem, and outputting the LWE problem to the computing device 1-4 (e.g., sending it via the Internet). Obtaining information representing a solution to the LWE problem from the computing device 1-4 (e.g., receiving it via the Internet). Converting the information representing the solution to the LWE problem into information representing a solution to a combinatorial optimization problem in an industrial application. · Output: Information representing the solution of a combinatorial optimization problem in industrial applications.
[0261] By combining the above-mentioned computing devices 1-4 with the above-mentioned application device I or application device II, various practical applications can be constructed. Specific examples are shown below.
[0262] [Combination of Calculation Device 1-4 and Application Device I] <Machine Learning> Application Device I: Input: Data for training a learning model in a privacy-preserving manner (e.g., distributed data in federated learning). Processing: Convert the problem of removing noise from data into an LWE problem. Send the converted LWE problem to computing devices 1-4 (e.g., send via the internet). Receive information representing a solution to the LWE problem from computing devices 1-4 (e.g., receive via the internet). Use the obtained solution to train a privacy-preserving learning model. Output: A privacy-preserving trained model.
[0263] <Medical field> Application Device I: Input: Data for medical diagnosis (e.g. MRI images, ultrasound images, x-ray images). Processing: Convert the problem of removing noise from data into an LWE problem. Send the converted LWE problem to computing device 1-4 (e.g., send via the Internet). Receive information representing the solution to the LWE problem from computing device 1-4 (e.g., receive via the Internet). Convert the obtained solution into noise-removed data. Output: Denoised data.
[0264] In addition, the following may be used as input and output data of the application device I. <Natural Language Processing> Input: Natural language data containing typos and errors. Output: Natural language data with typos and errors removed. <Communications field> Input: Noisy communication signal data. Output: Noise-removed communication signal data. <Manufacturing industry> Input: Sensor data collected during the manufacturing process. Output: Denoised sensor data. <Financial sector> Input: Financial time series data. Output: Denoised financial time series data. <Automotive industry> Input: Self-driving car sensor data. Output: Denoised sensor data. <Environmental monitoring> Input: Environmental sensor data. Output: Denoised sensor data. <Energy field> Input: Smart grid data. Output: Denoised smart grid data. <Agriculture> Input: Sensor data obtained from agricultural sensors. Output: Denoised sensor data. <Retail> Input: Customer transaction data Output: Denoised customer transaction data.
[0265] [Combination of Calculation Device 1-4 and Application Device II] <Multi-objective optimization problem> Application Device II: Input: Information representing a combinatorial optimization problem in an industrial application. Processing: Convert the combinatorial optimization problem into an LWE problem. Send the converted LWE problem to computing device 1-4 (e.g., send via the Internet). Receive information representing the solution to the LWE problem from computing device 1-4 (e.g., receive via the Internet). Use the obtained solution to derive a solution to the optimization problem. Output: Information representing the solution to the combinatorial optimization problem. Examples of combinatorial optimization problems include optimal route setting for logistics, optimal route selection for autonomous driving vehicles, optimization of large-scale integrated circuits, optimization of network infrastructure, optimization of processes from raw material procurement to product delivery, optimization of production line operation schedules in the manufacturing industry, optimization of shift allocation for personnel such as pilots and flight attendants, optimization of facility location, and optimization of asset portfolios. [Explanation of symbols]
[0266] 1~4: Computing device 11~31,30: LWE return device 12,42: Problem transformation device 13,43: Solving device 14: Solution conversion device< / case>
Claims
1. Using information for identifying the LWE problem, converting the LWE problem into a set of one-dimensional LWE-Like problems where the standard deviation followed by the error vector is determined for each element of the error vector, and obtaining information for identifying the set of the one-dimensional LWE-Like problems, an LWE reduction unit; Converting the set of the one-dimensional LWE-Like problems into a set of phase estimation problems with error, and obtaining information for identifying the set of the phase estimation problems with error, a problem conversion unit; Solving the set of the phase estimation problems with error to obtain a set of solutions of the phase estimation problems with error, a solution finding unit; Converting the set of solutions of the phase estimation problems with error into the solution of the LWE problem, and outputting the solution of the LWE problem, a solution conversion unit; A computing device having the above components.
2. A computing device having an interpolation point selection unit and a sample point selection unit, m, n, m', n', j are positive integers, α is a positive real number, q, q' are integers greater than 1, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, σ=αq, and N(0,σ 2 ) is Z q The above represents a Gaussian distribution with mean 0 and standard deviation σ, and ||β 1 || is β 1 represents the norm of a 1 ,a 2 ,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. [Number 327] where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is [Number 328] represents an m-dimensional column vector satisfying the above, and X is an m-dimensional column vector x 1 ,…,x n ∈Z m Set {x 1 ,…,x n } and 〈β 1 ,β 2 〉 is β 1 and β 2 represents the inner product of the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q}, and the lattice ∧ q Dual lattice of (X) ∧ q ⊥ (X) is ∧ q ⊥ (X):={y∈Z m |<x,y> ≡0 mod q for all x∈∧ q (X)}, and β 4 T is β 4 represents the transpose of [Number 329] represents the direct product, and R c but [Number 330] represents the region contained in q ⊥ (A T )∩R c is not an empty set, For any integer θ satisfying 0 < θ < q', the interpolation point selection unit [Number 331] and [Number 332] The interpolation point vector u~ that satisfies j,1 ,…,u~ j,n' Select L(B~ j ) is ∧ q ⊥ (A T )∪{u~ j,1 ,…,u~ j,n' }, the lattice L(∧ q ⊥ (A T )∪{u~ j,1 ,…,u~ j,n' }), The sample point selection unit selects linearly independent sample point vectors b j,1 ,…,b~ j,m' ∈L(B~ j )∩R c Select a computing device.
3. The computing device according to Claim 2, m=2 and n=1, m'=m=2 and n'=1, υ represents an integer greater than or equal to 0, ξ represents a positive integer, and q' is a Fibonacci sequence {F k } k=0,...,∞ element F belonging to ξυ+2 , j=1,...,m, κ=1,2, Z denotes the set of integers, and B - 1 and B - 2 is the dual lattice ∧ q ⊥ (A T ), and B - j ={b - j,1 ,b - j,2 } and b - j,κ ∈Z 2 and the interpolation point vector u~ j,1 but [Number 333] where Subdivision point vector d~ j,1 ,…,d~ j,ξυ+1 but [Number 334] satisfies The sample point vector b~ j,1 ,…,b~ j,m' is the interpolation point vector u~ j,1 and the subdivision point vector d~ j,1 ,…,d~ j,ξυ+1 Based on the lattice L(B~ j ) basis B~ j ={b~ j,1 ,...,b~ j,m }, which is the m-dimensional vector b~ j,1 ,...,b~ j,m A computing device.
4. The computing device according to Claim 3, π~(q) is the Fibonacci sequence {F k mod q} k=0 ∞ A computing device that represents the period of zeros that appear in , where υ = π~(q).
5. The computing device according to Claim 2, where m' = m and n' = 1, j = 1,.., m, υ represents an integer of 0 or more, ξ and k represent positive integers, and the m × m matrix [Number 335] And the m-dimensional vector [F k-m+2 ,...,F k ,F k+1 ] T and [0,...,0,1] T Regarding [Number 336] satisfies B - is the dual lattice ∧ q ⊥ (A T ), and P 1 ,P 2 ,...,P m represents the permutation matrix, and B - P 1 ,B - P 2 ,...,B - P m The Hermitian normal form HNF(B - P 1 ),HNF(B - P 2 ),...,HNF(B - P m ) are m × m matrices [Number 337] and I n represents the mn×mn identity matrix, and * m-n,n represents an mn×n matrix whose elements are non-negative integers less than q, and 0 n,m-n represents the n×mn zero matrix, and q n represents an n×n matrix whose diagonal elements are q and other elements are zero, and B - 1 =HNF(B - P 1 )P 1 T ,B - 2 =HNF(B - P 2 )P 2 T ,...,B - m =HNF(B - P m )P m T represents B - j m-dimensional vector b - j,1 ,...,b - j,m where ν represents a positive integer and {b - j,k } k=1,...,∞ but the first m elements are b - j,1 ,...,b - j,m is a sequence of vectors whose first (m+ν) element is the sum of the m elements immediately preceding the (m+ν) element, [Number 338] is [Number 339] is the vector in the last row of the interpolation point vector u~ j,1 but [Number 340] and G k but [Number 341] is the sum of the elements in the last row of the sequence {G k } k=0,...,∞ element G belonging to ξυ and Subdivision point vector d~ j,1 ,…,d~ j,ξυ-1 but [Number 342] satisfies The sample point vector b~ j,1 ,…,b~ j,m' is the interpolation point vector u~ j,1 and the subdivision point vector d~ j,1 ,…,d~ j,ξυ+1 Based on the lattice L(B j ) basis B~ j ={b~ j,1 ,...,b~ j,m }, which is the m-dimensional vector b~ j,1 ,...,b~ j,m A computing device.
6. The computing device according to Claim 5, where υ = m + 1.
7. A computing device having a vector generation unit and an input quantum state identification unit, m and n are positive integers, α is a positive real number, q and q' are integers greater than 1, j = 1,...,m, e is Napier's constant, i is the imaginary unit, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, σ=αq, and N(0,σ 2 ) is Z q The above is a Gaussian distribution with mean 0 and standard deviation σ, and B~ j is the lattice L(B~ j ) represents the m × m matrix that represents the basis of b~ j,1 ,...,b~ j,m is the base B~ j represents the m m-dimensional vectors that make up |β 0 | is β 0 represents the absolute value of , #β represents the number of elements belonging to set β, and 〈β 1 ,β 2 〉 is β 1 and β 2 represents the dot product of |β 1 > is the vertical vector β 1 represents a 1 ,a 2 ,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. [Number 343] where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is [Number 344] represents an m-dimensional column vector satisfying the above, and X is an m-dimensional column vector x 1 ,…,x n ∈Z m Set {x 1 ,…,x n }, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q}, and the lattice ∧ q Dual lattice of (X) ∧ q ⊥ (X) is ∧ q ⊥ (X):={y∈Z m |<x,y> ≡0 mod q for all x∈∧ q (X)}, and β 4 T is β 4 represents the transpose of B R represents the interior of a given region, Ω j ⊆Z q' m is Ω j B~ j =B R ∩L(B~ j ) represents the set of m-dimensional vectors that satisfy The input quantum state identification unit obtains information for identifying the input quantum state [Number 345] .
8. A computing device having a vector generation unit and an input quantum state identification unit, Let m and n be positive integers, α be a positive real number, q, q', and ζ be integers greater than 1, j = 1,...,m, k' = 0,...,ζ, k" = 1,...,ζ, and k' 1 ,k' 2 ∈{0,...,ζ} and 0≦k' 1 <k' 2 ≦ζ, where e is Napier's constant, i is the imaginary unit, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, σ=αq, and N(0,σ 2 ) is Z q The above is a Gaussian distribution with mean 0 and standard deviation σ, and B~ j is the lattice L(B~ j ), and 〈β 1 ,β 2 〉 is β 1 and β 2 represents the dot product of |β 1 > is the vertical vector β 1 represents a 1 ,a 2 ,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. [Number 346] where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is [Number 347] represents an m-dimensional column vector satisfying the above, and X is an m-dimensional column vector x 1 ,…,x n ∈Z m Set {x 1 ,…,x n }, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q} and B is a lattice ∧ q (A T ) is an m × m matrix that represents the basis of B 0 ,...,B ζ is the lattice ∧ q (A T ), where B = B 0 and β 4 T is β 4 represents the transpose of [Number 348] is a direct product, [Number 349] and H k"-1,k" is B k" =H k"-1,k" B k"-1 represents an m × m matrix that satisfies [Number 350] where L(C j,0 ),L(C j,1 ),...,L(C j,ζ ),L(D j,0 ),L(D j,1 ),...,L(D j,ζ ),L(E j,ζ ) is a lattice, h is an m-dimensional vector h=(h 1 ,...,h m ) and [Number 351] [Number 352] and g(h)=(h 1 mod q',...,h m mod q') is a function, B(j) h∈L(B~ j ) and [Number 353] where [Number 354] where C(j,k') h∈L(C j,k' ) and C(j,k') h:=( C(j,k') h 1 ,..., C(j,k') h m ) and Dg(j,k') h:=g( C(j,k') h 1 ,..., C(j,k') h m ) Dg(j,k') h∈L(D j,k' ) and [Number 355] and D(j,k"-1) h∈L(D j,k"-1 ) and D(j,k") h∈L(D j,k" ) and E j,k' :=D j,k' ・H k':ζ T and x(k') is an m-dimensional vector, [Number 356] is [Number 357] not included in z(j,k'):=y(j,k')・H k':ζ T and [Number 358] and L(E j,0 ) is E j,0 is a lattice with basis z(0)∈L(E j,0 ) and x(0)・B~ j ∈L(B~ j ) and [Number 359] satisfies [Number 360] and L(E j,ζ ) is E j,ζ is a lattice with a basis of L z∈L(E j,ζ ) and δ 1 ,...,δ ζ ∈{0,1}, L z∈δ 1 z(j,1)+...+δ ζ z(j,ζ)+L(E j,0 ) and [Number 361] where The vector generation unit [Number 362] A set of m-dimensional vectors Θ that satisfies j,ζ Obtained, The input quantum state identification unit obtains information for identifying the input quantum state [Number 363] .
9. A computing device having an input quantum state generation unit, a state alignment operation unit, an inverse quantum Fourier transform unit, an observation unit, a label calculation unit, and a solution generation unit, m and n are positive integers, q and q' are integers greater than 1, j=1,...,m, e is Napier's constant, i is the imaginary unit, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, and B~ j is the lattice L(B~ j ) represents the m × m matrix that represents the basis of b~ j,1 ,...,b~ j,m is the base B~ j represents the m-dimensional vector that composes β 4 T is β 4 represents the transpose of [Number 364] represents the direct product, and |β 0 | is β 0 represents the absolute value of , #β represents the number of elements belonging to set β, and 〈β 1 ,β 2 〉 is β 1 and β 2 represents the dot product of 1 | is the horizontal vector β 1 represents |β 1 > is the vertical vector β 1 represents a 1 ,a 2 ,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. [Number 365] represents, where \(s\in\mathbb{Z}\) q n represents an \(n -\)dimensional column vector, and \(X\) is a set of \(n\) \(m -\)dimensional column vectors \(x\) 1 ,…, \(x\) n \(\in\mathbb{Z}\) m The set \(\{x\) 1 ,…, \(x\) n \}\) is denoted as the lattice \(\Lambda\) q (X)\) is \(\Lambda\) q (X):=\(\{x\in\mathbb{Z}\) m |\(\exists s''\in\mathbb{Z}\) n such that \(x\equiv s''X\bmod q\}\), and the dual lattice \(\Lambda\) q (X)\) of the lattice \(\Lambda\) q ⊥ (X)\) is \(\Lambda\) q ⊥ (X):=\(\{y\in\mathbb{Z}\) m |\(\langle x,y\rangle\equiv0\bmod q\) for all \(x\in\Lambda\) q (X)\}\), and \(B\) represents an \(m\times m\) matrix that is a basis of the lattice \(\Lambda\) q (A T )\), and for any integer \(\theta\) satisfying \(0 <\theta<q'\), the interpolation point vector \(\tilde{u}\) j,1 [Number 366] and [Number 367] is a vector that satisfies B R represents the interior of a given region, and Ω j ⊆Z q' m Omega j B~ j =B R ∩L(B~ j ), and t∈Z q m represents an m-dimensional column vector, and v∈L(B):=∧ q (A T ) label L j (v) [Number 368] where [Number 369] where The input quantum state generation unit generates the input quantum state [Number 370] , The state alignment operation unit is configured to j,t > State alignment operation [Number 371] and put it into quantum state X j |Ψ j,t > The inverse quantum Fourier transform unit converts the quantum state X j |Ψ j,t >Inverse quantum Fourier transform for [Number 372] performs [Number 373] to obtain the quantum state , [Number 374] Observe the result z j Obtained, The label calculation unit calculates the observation result z j Label using L j (z j B) is obtained, The solution generating unit determines the label L j (z j B) Using the solution s' j A computing device that obtains The observation unit observes the quantum state
10. Let m and n be positive integers, α be a positive real number, q, q', and ζ be integers greater than 1, j = 1,...,m, k' = 0,...,ζ, k" = 1,...,ζ, and k' 1 ,k' 2 ∈{0,...,ζ} and 0≦k' 1 <k' 2 ≦ζ, where e is Napier's constant, i is the imaginary unit, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, σ=αq, and N(0,σ 2 ) is Z q The above is a Gaussian distribution with mean 0 and standard deviation σ, and B~ j is the lattice L(B~ j ), and 〈β 1 ,β 2 〉 is β 1 and β 2 represents the dot product of 1 | is the horizontal vector β 1 represents |β 1 > is the vertical vector β 1 represents a 1 ,a 2 ,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. [Number 375] where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is [Number 376] represents an m-dimensional column vector satisfying the above, and X is an m-dimensional column vector x 1 ,…,x n ∈Z m Set {x 1 ,…,x n }, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q} and B={b 1 ,...,b m } is a lattice ∧ q (A T ) is an m × m matrix that represents the basis of 1 ,...,b m is a row vector in the basis B, and L j (b 1 ),...,L j (b m ) is the lattice ∧ q (A T )=L(B) 1 ,...,b m is the label corresponding to z j =(OM j,1 ,...,OM j,m )∈Z q' m and B 0 ,...,B ζ is the lattice ∧ q (A T ), where B = B 0 and β 4 T is β 4 represents the transpose of [Number 377] A computing device having an input quantum state generation unit, an inverse quantum Fourier transform unit, an observation unit, a label calculation unit, and a solution generation unit, [Number 378] and H k"-1,k" is B k" =H k"-1,k" B k"-1 represents an m × m matrix that satisfies [Number 379] is a direct product, L(C j,0 ),L(C j,1 ),...,L(C j,ζ ),L(D j,0 ),L(D j,1 ),...,L(D j,ζ ),L(E j,ζ ) is a lattice, h is an m-dimensional vector h=(h 1 ,...,h m ) and [Number 380] [Number 381] and g(h)=(h 1 mod q',...,h m mod q') is a function, B(j) h∈L(B~ j ) and [Number 382] where [Number 383] where C(j,k') h∈L(C j,k' ) and C(j,k') h:=( C(j,k') h 1 ,..., C(j,k') h m ) and Dg(j,k') h:=g( C(j,k') h 1 ,..., C(j,k') h m ) Dg(j,k') h∈L(D j,k' ) and [Number 384] and D(j,k"-1) h∈L(D j,k"-1 ) and D(j,k") h∈L(D j,k" ) and E j,k' :=D j,k' ・H k':ζ T and where [Number 385] x(k') is an m-dimensional vector, [Number 386] is z(j,k'):=y(j,k')・H k':ζ T and [Number 387] and L(E j,0 ) is E j,0 is a lattice with basis z(0)∈L(E j,0 ) and x(0)・B~ j ∈L(B~ j ) and [Number 388] not included in [Number 389] and L(E j,ζ ) is E j,ζ is a lattice with a basis of L z∈L(E j,ζ ) and δ 1 ,...,δ ζ ∈{0,1}, L z∈δ 1 z(j,1)+...+δ ζ z(j,ζ)+L(E j,0 ) and [Number 390] satisfies [Number 391] where where The input quantum state generation unit generates an input quantum state [Number 392] and The inverse quantum Fourier transform unit converts the input quantum state |Ψ j,t >Inverse quantum Fourier transform for [Number 393] performs operations to [Number 394] obtain a quantum state The observation unit obtains the quantum state [Number 395] Observation results OM j =(OM j,1 ,...,OM j,m ) and The label calculation unit calculates the observation result OM j Label with [Number 396] **Claim 11** The solution generating unit determines the label L j (z j B ζ ) to find the solution s' j A computing device that obtains A computing device having a difference generation unit and a solution generation unit, and m, n are positive integers, α is a positive real number, q, q' are integers greater than 1, j = 1,...,m, and Z q represents the quotient ring Z / qZ modulo q, and β 4 T is β 4 represents the transpose of N(0,σ 2 ) is Z q represents a Gaussian distribution with mean 0 and standard deviation σ, and a 1 ,a 2 ,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. [Number 397] where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is [Number 398] represents an \(m\)-dimensional column vector that satisfies, and \(X\) is a set of \(n\) \(m\)-dimensional column vectors \(x 1 ,…,x n ∈Z m denoted as the set \(\{x 1 ,…,x n \}\), and the lattice \(\Lambda q (X)\) is defined as \(\Lambda q (X):=\{x\in\mathbb{Z} m |\exists s\in\mathbb{Z} n \text{ s.t.}x\equiv sX\bmod q\}\), and the dual lattice \(\Lambda q ^*(X)\) of the lattice \(\Lambda q ⊥ (X)\) is \(\Lambda q ⊥ ^*(X):=\{y\in\mathbb{Z} m |\langle x,y\rangle\equiv0\bmod q\text{ for all}x\in\Lambda q (X)\}\), and for any integer \(\theta\) such that \(0 < \theta<q'\), the interpolation point vector \(\tilde{u} j,1 [Number 399] is a vector that satisfies [Number 400] and [Number 401] obtains The difference generation unit generates the solution s' 1 ,...,s' m Using the difference vector [Number 402] The solution generation unit uses the difference vector t - ε, the integer q, and the matrix A to obtain the column vector s that satisfies As ≡ t - ε mod q. A computing device **Claim 12** A computing device having an interpolation point selection unit, a sample point selection unit, an input quantum state generation unit, a state alignment operation unit, an inverse quantum Fourier transform unit, an observation unit, a label calculation unit, a first solution generation unit, a difference generation unit, and a second solution generation unit, For any integer θ that satisfies 0 < θ < q', the interpolation point selection unit m, n are positive integers, α is a positive real number, q, q' are integers greater than 1, j = 1,...,m, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, and |β 0 | is β 0 represents the absolute value of , #β represents the number of elements belonging to set β, and 〈β 1 ,β 2 〉 is β 1 and β 2 represents the dot product of 1 | is the horizontal vector β 1 represents |β 1 > is the vertical vector β 1 where e represents Napier's constant, i represents the imaginary unit, σ = αq, and N(0, σ 2 ) is Z q represents a Gaussian distribution with mean 0 and standard deviation σ, and a 1 ,a 2 ,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. [Number 403] where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is [Number 404] represents an m-dimensional column vector satisfying the above, and X is an m-dimensional column vector x 1 ,…,x n ∈Z m Set {x 1 ,…,x n }, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q}, and the lattice ∧ q Dual lattice of (X) ∧ q ⊥ (X) is ∧ q ⊥ (X):={y∈Z m |<x,y> ≡0 mod q for all x∈∧ q (X)}, and β 4 T is β 4 represents the transpose of [Number 405] represents the direct product, and R c but [Number 406] represents the region contained in q ⊥ (A T )∩R c is not an empty set, and [Number 407] The input quantum state generation unit generates an input quantum state [Number 408] The interpolation point vector u~ that satisfies j,1 Select L(B~ j ) is ∧ q ⊥ (A T )∪u~ j,1 The lattice L(∧ q ⊥ (A T )∪u~ j,1 ) and The sample point selection unit selects linearly independent sample point vectors b j,1 ,…,b~ j,m ∈L(B~ j )∩R c Select B - j is the dual lattice ∧ q ⊥ (A T ) represents the m × m matrix that represents the basis of B~ j is the lattice L(B~ j ) is an m × m matrix that represents the basis of B R represents the interior of a given region, Ω j ⊆Z q' m Omega j B~ j =B R ∩L(B~ j ) is a set of m-dimensional vectors that satisfy and [Number 409] and B~ j is the lattice L(B~ j ), and B is the lattice ∧ q (A T ), and [Number 410] performs operations to The state alignment operation unit is configured to j,t > State alignment operation [Number 411] and put it into quantum state X j |Ψ j,t > The inverse quantum Fourier transform unit converts the quantum state X j |Ψ j,t >Inverse quantum Fourier transform for [Number 412] obtain a quantum state [Number 413] The observation unit is the quantum state and [Number 414] Observe the result z j Obtained, The label calculation unit calculates the observation result z j Label using L j (z j B) is obtained, b~ j,1 ,...,b~ j,m is the base B~ j Denotes m vectors of dimension m that compose B, and v∈L(B):=∧ q (A T ) label L j (v) [Number 415] and The first solution generating unit determines the label L j (z j B) Using the solution s' j Obtained, [Number 416] obtains The difference generation unit generates the solution s' 1 ,...,s' m Using the difference vector [Number 417] The second solution generation unit uses the difference vector t - ε, the integer q, and the matrix A to obtain the column vector s that satisfies As ≡ t - ε mod q. A computing device **Claim 13** A computing device having an interpolation point selection unit, a sample point selection unit, an input quantum state generation unit, an inverse quantum Fourier transform unit, an observation unit, a label calculation unit, a first solution generation unit, a difference generation unit, and a second solution generation unit, represents a direct product, Let m and n be positive integers, α be a positive real number, q, q', ζ be integers greater than 1, j = 1,...,m, k' = 0,...,ζ, k" = 1,...,ζ, and k' 1 ,k' 2 ∈{0,...,ζ} and 0≦k' 1 <k' 2 ≦ζ and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, and 〈β 1 ,β 2 〉 is β 1 and β 2 represents the dot product of 1 | is the horizontal vector β 1 represents |β 1 > is the vertical vector β 1 where e represents Napier's constant, i represents the imaginary unit, σ = αq, and N(0, σ 2 ) is Z q represents a Gaussian distribution with mean 0 and standard deviation σ, and a 1 ,a 2 ,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. [Number 418] where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is [Number 419] represents an m-dimensional column vector satisfying the above, and X is an m-dimensional column vector x 1 ,…,x n ∈Z m Set {x 1 ,…,x n }, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q}, and the lattice ∧ q Dual lattice of (X) ∧ q ⊥ (X) is ∧ q ⊥ (X):={y∈Z m |<x,y> ≡0 mod q for all x∈∧ q (X)}, and b 1 ,...,b m is a row vector in the basis B, and L j (b 1 ),...,L j (b m ) is the lattice ∧ q (A T )=L(B) 1 ,...,b m is the label corresponding to z j =(OM j,1 ,...,OM j,m )∈Z q' m and B 0 ,...,B ζ is the lattice ∧ q (A T ), where B = B 0 and β 4 T is β 4 represents the transpose of [Number 420] and [Number 421] and H k"-1,k" is B k" =H k"-1,k" B k"-1 represents an m × m matrix that satisfies [Number 422] and L(C j,0 ),L(C j,1 ),...,L(C j,ζ ),L(D j,0 ),L(D j,1 ),...,L(D j,ζ ),L(E j,ζ ) is a lattice, h is an m-dimensional vector h=(h 1 ,...,h m ) and [Number 423] [Number 424] and g(h)=(h 1 mod q',...,h m mod q') is a function, B(j) h∈L(B~ j ) and [Number 425] and [Number 426] x(k') is an m-dimensional vector, C(j,k') h∈L(C j,k' ) and C(j,k') h:=( C(j,k') h 1 ,..., C(j,k') h m ) and Dg(j,k') h:=g( C(j,k') h 1 ,..., C(j,k') h m ) Dg(j,k') h∈L(D j,k' ) and [Number 427] and D(j,k"-1) h∈L(D j,k"-1 ) and D(j,k") h∈L(D j,k" ) and E j,k' :=D j,k' ・H k':ζ T and is [Number 428] not included in [Number 429] satisfies z(j,k'):=y(j,k')・H k':ζ T and [Number 430] and L(E j,0 ) is E j,0 is a lattice with basis z(0)∈L(E j,0 ) and x(0)・B~ j ∈L(B~ j ) and [Number 431] and [Number 432] and L(E j,ζ ) is E j,ζ is a lattice with a basis of L z∈L(E j,ζ ) and δ 1 ,...,δ ζ ∈{0,1}, L z∈δ 1 z(j,1)+...+δ ζ z(j,ζ)+L(E j,0 ) and [Number 433] For any integer θ that satisfies 0 < θ < q', the interpolation point selection unit R c but [Number 434] represents the region contained in q ⊥ (A T )∩R c is not an empty set, and [Number 435] and [Number 436] The interpolation point vector u~ that satisfies j,1 Select L(B~ j ) is ∧ q ⊥ (A T )∪u~ j,1 The lattice L(∧ q ⊥ (A T )∪u~ j,1 ) and The sample point selection unit selects linearly independent sample point vectors b j,1 ,…,b~ j,m ∈L(B~ j )∩R c Select B - j is the dual lattice ∧ q ⊥ (A T ) represents the m × m matrix that represents the basis of B~ j is the lattice L(B~ j ), and [Number 437] The input quantum state generation unit generates an input quantum state and [Number 438] performs operations to The inverse quantum Fourier transform unit converts the input quantum state |Ψ j,t >Inverse quantum Fourier transform for [Number 439] obtain a quantum state [Number 440] The observation unit obtains the quantum state **Claim 14** [Number 441] Observation results OM j =(OM j,1 ,...,OM j,m ) and The label calculation unit calculates the observation result OM j Label with [Number 442] An LWE reduction step in which an LWE reduction unit uses information for specifying an LWE problem to convert the LWE problem into a set of one-dimensional LWE-Like problems in which the standard deviation followed by the error vector is determined for each element of the error vector, and obtains information for specifying the set of one-dimensional LWE-Like problems; The solution generating unit determines the label L j (z j B ζ ) to find the solution s' j A computing device that obtains A problem conversion step in which a problem conversion unit converts the set of one-dimensional LWE-Like problems into a set of phase estimation problems with error, and obtains information for specifying the set of phase estimation problems with error; A solution finding step in which a solution finding unit solves the set of phase estimation problems with error to obtain a set of solutions to the phase estimation problems with error; A solution conversion step of converting, by a solution conversion unit, a set of solutions of the phase estimation problem with error into solutions of the LWE problem and outputting the solutions of the LWE problem; A calculation method having the above. **Claim 15** A calculation method having an interpolation point selection step and a sample point selection step, m, n, m', n', j are positive integers, α is a positive real number, q, q' are integers greater than 1, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, σ=αq, and N(0,σ 2 ) is Z q The above represents a Gaussian distribution with mean 0 and standard deviation σ, and ||β 1 || is β 1 represents the norm of a 1 ,a 2 ,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. [Number 443] where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is [Number 444] represents an m-dimensional column vector satisfying the above, and X is an m-dimensional column vector x 1 ,…,x n ∈Z m Set {x 1 ,…,x n } and 〈β 1 ,β 2 〉 is β 1 and β 2 represents the inner product of the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q}, and the lattice ∧ q Dual lattice of (X) ∧ q ⊥ (X) is ∧ q ⊥ (X):={y∈Z m |<x,y> ≡0 mod q for all x∈∧ q (X)}, and β 4 T is β 4 represents the transpose of [Number 445] represents the direct product, and R c but [Number 446] represents the region contained in q ⊥ (A T )∩R c is not an empty set, wherein the interpolation point selection step is, for any integer θ satisfying 0 < θ < q', by an interpolation point selection unit, [Number 447] and [Number 448] The interpolation point vector u~ that satisfies j,1 ,…,u~ j,n' selecting L(B~ j ) is ∧ q ⊥ (A T )∪{u~ j,1 ,…,u~ j,n' }, the lattice L(∧ q ⊥ (A T )∪{u~ j,1 ,…,u~ j,n' }), The sample point selection step is performed by a sample point selection unit to select linearly independent sample point vectors b~ j,1 ,…,b~ j,m' ∈L(B~ j )∩R c a step of selecting A calculation method. **Claim 16** A calculation method having a vector generation step and an input quantum state specification step, m and n are positive integers, α is a positive real number, q and q' are integers greater than 1, j = 1,...,m, e is Napier's constant, i is the imaginary unit, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, σ=αq, and N(0,σ 2 ) is Z q The above is a Gaussian distribution with mean 0 and standard deviation σ, and B~ j is the lattice L(B~ j ) represents the m × m matrix that represents the basis of b~ j,1 ,...,b~ j,m is the base B~ j represents the m m-dimensional vectors that make up |β 0 | is β 0 represents the absolute value of , #β represents the number of elements belonging to set β, and 〈β 1 ,β 2 〉 is β 1 and β 2 represents the dot product of |β 1 > is the vertical vector β 1 represents a 1 ,a 2 ,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. [Number 449] where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is [Number 450] represents an m-dimensional column vector satisfying the above, and X is an m-dimensional column vector x 1 ,…,x n ∈Z m Set {x 1 ,…,x n }, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q}, and the lattice ∧ q Dual lattice of (X) ∧ q ⊥ (X) is ∧ q ⊥ (X):={y∈Z m |<x,y> ≡0 mod q for all x∈∧ q (X)}, and β 4 T is β 4 represents the transpose of B R represents the interior of a given region, The vector generating step is performed by a vector generating unit. j B~ j =B R ∩L(B~ j ) is an m-dimensional vector Ω j ⊆Z q' m This is the step of obtaining wherein the input quantum state specification step is a step of obtaining, by an input quantum state specification unit, information for specifying an input quantum state [Number 451] A calculation method. **Claim 17** A calculation method having a vector generation step and an input quantum state specification step, Let m and n be positive integers, α be a positive real number, q, q', and ζ be integers greater than 1, j = 1,...,m, k' = 0,...,ζ, k" = 1,...,ζ, and k' 1 ,k' 2 ∈{0,...,ζ} and 0≦k' 1 <k' 2 ≦ζ, where e is Napier's constant, i is the imaginary unit, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, σ=αq, and N(0,σ 2 ) is Z q The above is a Gaussian distribution with mean 0 and standard deviation σ, and B~ j is the lattice L(B~ j ), and 〈β 1 ,β 2 〉 is β 1 and β 2 represents the dot product of |β 1 > is the vertical vector β 1 represents a 1 ,a 2 ,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. [Number 452] where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is [Number 453] represents an m-dimensional column vector satisfying the above, and X is an m-dimensional column vector x 1 ,…,x n ∈Z m Set {x 1 ,…,x n }, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q} and B is a lattice ∧ q (A T ) is an m × m matrix that represents the basis of B 0 ,...,B ζ is the lattice ∧ q (A T ), where B = B 0 and β 4 T is β 4 represents the transpose of [Number 454] which is a direct product, [Number 455] and H k"-1,k" is B k" =H k"-1,k" B k"-1 represents an m × m matrix that satisfies [Number 456] and L(C j,0 ),L(C j,1 ),...,L(C j,ζ ),L(D j,0 ),L(D j,1 ),...,L(D j,ζ ),L(E j,ζ ) is a lattice, h is an m-dimensional vector h=(h 1 ,...,h m ) and [Number 457] [Number 458] and g(h)=(h 1 mod q',...,h m mod q') is a function, B(j) h∈L(B~ j ) and [Number 459] and [Number 460] and C(j,k') h∈L(C j,k' ) and C(j,k') h:=( C(j,k') h 1 ,..., C(j,k') h m ) and Dg(j,k') h:=g( C(j,k') h 1 ,..., C(j,k') h m ) Dg(j,k') h∈L(D j,k' ) and [Number 461] and D(j,k"-1) h∈L(D j,k"-1 ) and D(j,k") h∈L(D j,k" ) and E j,k' :=D j,k' ・H k':ζ T and x(k') is an m-dimensional vector, [Number 462] which is [Number 463] not included in z(j,k'):=y(j,k')・H k':ζ T and [Number 464] and L(E j,0 ) is E j,0 is a lattice with basis z(0)∈L(E j,0 ) and x(0)・B~ j ∈L(B~ j ) and [Number 465] and satisfies [Number 466] and L(E j,ζ ) is E j,ζ is a lattice with a basis of L z∈L(E j,ζ ) and δ 1 ,...,δ ζ ∈{0,1}, L z∈δ 1 z(j,1)+...+δ ζ z(j,ζ)+L(E j,0 ) and [Number 467] and wherein the vector generation step is by a vector generation unit, [Number 468] A set of m-dimensional vectors Θ that satisfies j,ζ This is the step of obtaining and the input quantum state specification step is a step of obtaining, by an input quantum state specification unit, information for specifying an input quantum state [Number 469] A calculation method. **Claim 18** A calculation method having an input quantum state generation step, a state alignment operation step, an inverse quantum Fourier transform step, an observation step, a label calculation step, and a solution generation step, m and n are positive integers, q and q' are integers greater than 1, j=1,...,m, e is Napier's constant, i is the imaginary unit, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, and B~ j is the lattice L(B~ j ) represents the m × m matrix that represents the basis of b~ j,1 ,...,b~ j,m is the base B~ j represents the m-dimensional vector that composes β 4 T is β 4 represents the transpose of [Number 470] represents the direct product, and |β 0 | is β 0 represents the absolute value of , #β represents the number of elements belonging to set β, and 〈β 1 ,β 2 〉 is β 1 and β 2 represents the dot product of 1 | is the horizontal vector β 1 represents |β 1 > is the vertical vector β 1 represents a 1 ,a 2 ,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. [Number 471] represents, where \(s\in\mathbb{Z}\) q n represents an \(n\)-dimensional column vector, and \(X\) is a set of \(n\) \(m\)-dimensional column vectors \(x\) 1 ,…, \(x\) n \(\in\mathbb{Z}\) m The set \(\{x\) 1 ,…, \(x\) n \} is denoted as the lattice \(\Lambda\) q (X)\) is \(\Lambda\) q (X):=\(\{x\in\mathbb{Z}\) m |\(\exists s''\in\mathbb{Z}\) n such that \(x\equiv s''X\bmod q\}\), and the dual lattice \(\Lambda\) q (X)\) of the lattice \(\Lambda\) q ⊥ (X)\) is \(\Lambda\) q ⊥ (X):=\(\{y\in\mathbb{Z}\) m |\(\langle x,y\rangle\equiv0\bmod q\) for all \(x\in\Lambda\) q (X)\}\), and \(B\) represents an \(m\times m\) matrix that is the basis of the lattice \(\Lambda\) q (A T )\), and for any integer \(\theta\) satisfying \(0\lt\theta\lt q'\), the interpolation point vector \(\tilde{u}\) j,1 [Number 472] and [Number 473] represents a vector that satisfies B R represents the interior of a given region, and Ω j ⊆Z q' m Omega j B~ j =B R ∩L(B~ j ), and t∈Z q m is an m-dimensional column vector, x∈Z and v~,w~∈L(B~ j ) for L~ j (b~ j,1 ),...,L~ j (b~ j,m )∈Z q' is the lattice L(B~ j ) are the labels corresponding to the grid points of L~ j (xu~ j,1 )=x mod q' and L~ j (v~)=L~ j (w~) and v~-w~∈∧ q ⊥ (A T ) is equivalent to L~ j -1 (0),L~ j -1 (1),...,L~ j -1 (q'-1) is the label L j (b~ j,1 ),...,L~ j (b~ j,m ) among Ω j is the inverse image of the label in B, and v∈L(B):=∧ q (A T ) label L j (v) [Number 474] and [Number 475] and wherein the input quantum state generation step is a step of generating, by an input quantum state generation unit, an input quantum state [Number 476] A step of generating The state alignment operation step is performed by a state alignment operation unit to align the input quantum state |Ψ j,t >State alignment operation [Number 477] and put it into quantum state X j |Ψ j,t >, The inverse quantum Fourier transform step is performed by an inverse quantum Fourier transform unit to convert the quantum state X j |Ψ j,t >Inverse quantum Fourier transform for [Number 478] performing [Number 479] to obtain a quantum state wherein the observation step is, by an observation unit, for the quantum state [Number 480] Observe the result z j This is the step of obtaining The label calculation step is performed by a label calculation unit to calculate the observation result z j Label using L j (z j B) is the step to obtain The solution generating step is performed by a solution generating unit to generate the label L j (z j B) Using the solution s' j The calculation method is a step of obtaining **Claim 19** A calculation method having an input quantum state generation step, an inverse quantum Fourier transform step, an observation step, a label calculation step, and a solution generation step, Let m and n be positive integers, α be a positive real number, q, q', and ζ be integers greater than 1, j = 1,...,m, k' = 0,...,ζ, k" = 1,...,ζ, and k' 1 ,k' 2 ∈{0,...,ζ} and 0≦k' 1 <k' 2 ≦ζ, where e is Napier's constant, i is the imaginary unit, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, σ=αq, and N(0,σ 2 ) is Z q The above is a Gaussian distribution with mean 0 and standard deviation σ, and B~ j is the lattice L(B~ j ), and 〈β 1 ,β 2 〉 is β 1 and β 2 represents the dot product of 1 | is the horizontal vector β 1 represents |β 1 > is the vertical vector β 1 represents a 1 ,a 2 ,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. [Number 481] where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is [Number 482] represents an m-dimensional column vector satisfying the above, and X is an m-dimensional column vector x 1 ,…,x n ∈Z m Set {x 1 ,…,x n }, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q} and B={b 1 ,...,b m } is a lattice ∧ q (A T ) is an m × m matrix that represents the basis of 1 ,...,b m is a row vector in the basis B, and L j (b 1 ),...,L j (b m ) is the lattice ∧ q (A T )=L(B) 1 ,...,b m is the label corresponding to z j =(OM j,1 ,...,OM j,m )∈Z q' m and B 0 ,...,B ζ is the lattice ∧ q (A T ), where B = B 0 and β 4 T is β 4 represents the transpose of [Number 483] which is a direct product, [Number 484] and H k"-1,k" is B k" =H k"-1,k" B k"-1 represents an m × m matrix that satisfies [Number 485] and L(C j,0 ),L(C j,1 ),...,L(C j,ζ ),L(D j,0 ),L(D j,1 ),...,L(D j,ζ ),L(E j,ζ ) is a lattice, h is an m-dimensional vector h=(h 1 ,...,h m ) and [Number 486] [Number 487] and g(h)=(h 1 mod q',...,h m mod q') is a function, B(j) h∈L(B~ j ) and [Number 488] and [Number 489] and C(j,k') h∈L(C j,k' ) and C(j,k') h:=( C(j,k') h 1 ,..., C(j,k') h m ) and Dg(j,k') h:=g( C(j,k') h 1 ,..., C(j,k') h m ) Dg(j,k') h∈L(D j,k' ) and [Number 490] and D(j,k"-1) h∈L(D j,k"-1 ) and D(j,k") h∈L(D j,k" ) and E j,k' :=D j,k' ・H k':ζ T and x(k') is an m-dimensional vector, [Number 491] which is [Number 492] not included in z(j,k'):=y(j,k')・H k':ζ T and [Number 493] and L(E j,0 ) is E j,0 is a lattice with basis z(0)∈L(E j,0 ) and x(0)・B~ j ∈L(B~ j ) and [Number 494] and satisfies [Number 495] and L(E j,ζ ) is E j,ζ is a lattice with a basis of L z∈L(E j,ζ ) and δ 1 ,...,δ ζ ∈{0,1}, L z∈δ 1 z(j,1)+...+δ ζ z(j,ζ)+L(E j,0 ) and [Number 496] and [Number 497] and wherein the input quantum state generation step is a step of generating, by an input quantum state generation unit, an input quantum state [Number 498] A step of generating The inverse quantum Fourier transform step is performed by an inverse quantum Fourier transform unit to convert the input quantum state |Ψ j,t >Inverse quantum Fourier transform for [Number 499] performing [Number 500] to obtain a quantum state wherein the observation step is, by an observation unit, for the quantum state [Number 501] Observation results OM j =(OM j,1 ,...,OM j,m ) and The label calculation step is performed by a label calculation unit to calculate the observation result OM j Label with [Number 502] A step of obtaining The solution generating step is performed by a solution generating unit to generate the label L j (z j B ζ ) to find the solution s' j The calculation method is a step of obtaining **Claim 20** A calculation method having a difference generation step and a solution generation step, m, n are positive integers, α is a positive real number, q, q' are integers greater than 1, j = 1,...,m, and Z q represents the quotient ring Z / qZ modulo q, and β 4 T is β 4 represents the transpose of N(0,σ 2 ) is Z q represents a Gaussian distribution with mean 0 and standard deviation σ, and a 1 ,a 2 ,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. [Number 503] where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is [Number 504] represents an m - dimensional column vector that satisfies, and X is a set of n m - dimensional column vectors x 1 ,…,x n ∈Z m denoted as the set {x 1 ,…,x n}, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n such that x≡s"X mod q}, and the dual lattice ∧ q (X) of the lattice ∧ q ⊥ (X) is ∧ q ⊥ (X):={y∈Z m |<x,y>≡0 mod q for all x∈∧ q (X)}, and for the interpolation point vectors u~ j,1 ,…,u~ j,n' for any integer θ satisfying 0 < θ < q', [Number 505] and [Number 506] is a vector satisfying [Number 507] and The difference generating step generates a solution s' by a difference generating unit. 1 ,...,s' m Using the difference vector [Number 508] A step of obtaining the solution generating step is a step of obtaining, by a solution generating unit, the column vector s that satisfies As≡t-ε mod q, using the difference vector t-ε, the integer q, and the matrix A.
21. A program that causes a computer to function as the computing device of any one of claims 1, 2, and 7-13.