Improved blockchain systems and methods

A quantum analog proof-of-work consensus scheme using boson sampling addresses the challenges posed by ASICs and quantum computers, ensuring energy efficiency and resilience in blockchain networks.

JP2026517512APending Publication Date: 2026-06-01BTQ AG

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
BTQ AG
Filing Date
2024-05-27
Publication Date
2026-06-01

AI Technical Summary

Technical Problem

The scalability and security of blockchain networks are threatened by energy-intensive special-purpose processors like ASICs and the potential quadratic speedup of quantum computers in solving traditional Proof of Work (POW) consensus algorithms, which compromise the non-progressive nature of block mining.

Method used

Implementing a quantum analog proof-of-work consensus scheme using boson sampling experiments, where miners perform boson sampling to generate verification data, and a verifier analyzes this data to determine consensus, ensuring energy efficiency and resistance to quantum computers.

Benefits of technology

The proposed method maintains fair mining conditions, reduces energy consumption, and enhances blockchain resilience against quantum threats, while providing a robust consensus mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026517512000001_ABST
    Figure 2026517512000001_ABST
Patent Text Reader

Abstract

This disclosure relates to a quantum analog proof-of-work consensus method for use in a blockchain network. The method includes receiving multiple verification data obtained from multiple different miners of the blockchain network using boson sampling experiments associated with a candidate block. Each verification data may be associated with a different miner, each miner performing a boson sampling experiment using at least some information contained in the candidate block. The method may include analyzing the received multiple verification data to determine whether consensus has been achieved, and adding the candidate block to the blockchain associated with the blockchain network when consensus has been achieved.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The security of blockchain technology is, at least in part, based on the ability of participants in a peer-to-peer network to reach a consensus to validate and verify a new set of block-bundled transactions (i.e., a new block for addition to an existing blockchain) in an environment without a central verification body. A consensus algorithm is the process by which all peers in a blockchain network reach a common agreement about the current state of the distributed ledger. One of the most tested consensus algorithms that has demonstrated robustness and security is Proof of Work (POW). POW involves selecting miners to create a block based on who can solve a one-way function, which is traditionally a reverse hash problem, the fastest. The structure of the one-way function is chosen so that its parameters depend on the current block information, making pre-computation impossible, and the problem is also non-progressive, meaning the probability of successfully mining a block increases proportionally to the time or equivalent work spent solving the problem (reverse hash). [Background technology]

[0002] At least two problems exist that threaten the continued scalable use of the POW consensus algorithm. Firstly, problems such as inverse hashing used in POW consensus can be solved by special-purpose processors such as application-specific integrated circuits (ASICs), which are highly energy-intensive. A constant average block mining time must be maintained to avoid inflationary pressures on asset-based blockchains like Bitcoin with mining rewards and to maintain protocol integrity in the presence of network latency and growth. This means that as the computational speed of ASICs increases, the difficulty of the one-way function must increase, and consequently, the energy cost of mining increases. Secondly, traditionally formulated POW assumes that only classical computers are available as mining resources. Quantum computers can achieve quadratic speedups in solving unstructured problems like inverse hashing through amplitude amplification, which means that they no longer satisfy the condition of being non-progressive, as the probability of solving a problem increases non-linearly with the time spent on computation. Adversarial networks of quantum computers implementing conventional POW consensus would have fundamentally different dynamics than classical ones. Therefore, promising consensus algorithms need to mitigate risks for quantum processing. [Overview of the project] [Problems that the invention aims to solve]

[0003] The quantum analog proof-of-work consensus scheme disclosed herein provides an alternative to current consensus algorithms used in blockchain networks. Embodiments of the methods and systems disclosed herein address the threats that quantum universal computers and quantum computers pose to the security of current proof-of-work consensus algorithms and provide implementations that are more cost- and energy-efficient than existing supercomputers currently used to run consensus algorithms. [Means for solving the problem]

[0004] According to one aspect of this disclosure, a quantum analog proof-of-work consensus method for use in a blockchain network is provided. The method may include receiving a plurality of verification data obtained from a plurality of different miners of the blockchain network using boson sampling experiments associated with a candidate block. Each verification data may be associated with a different miner, each miner performing a boson sampling experiment using at least some information contained in the candidate block. The method may include analyzing the received plurality of verification data to determine whether consensus has been achieved, and adding the candidate block to the blockchain associated with the blockchain network when consensus has been achieved.

[0005] According to another aspect of this disclosure, a quantum analog proof-of-work consensus method for use in a blockchain network is provided. The method includes receiving a candidate block containing a plurality of transaction data; generating verification data by performing a boson sampling experiment using the information contained in the candidate block; and transmitting the verification data to a verification server contained within the blockchain network, wherein the verification data enables the verification server to determine whether consensus has been achieved.

[0006] According to some embodiments, information defining the initial input state of a boson sampling experiment can be obtained from a candidate block. Similarly, information defining the optical configuration of the optical network for performing the boson sampling experiment can also be obtained from a candidate block. According to some embodiments, the information contained in a candidate block can be mapped to different parameters of a boson sampling experiment. This mapping can be predefined among miners of the blockchain network. In this way, the information contained in a candidate block can be used to perform a boson sampling experiment.

[0007] At least some of the quantum analog proof-of-work consensus methods disclosed herein offer advantages over conventional consensus algorithms. The use of boson sampling experiments effectively addresses the dual challenges posed by the emerging threats of energy-intensive ASICs and quantum computers. Unlike conventional POW, which relies on computationally demanding hashes, the quantum analog approach is more energy-efficient and reduces the environmental impact and operational costs of maintaining a blockchain. In addition, at least some of the methods disclosed herein are inherently resistant to the quadratic speedup benefits of quantum computers, ensuring the integrity and security of blockchains in the post-quantum world. At least some of the consensus algorithms disclosed herein maintain the non-progressive conditions essential for fair mining, while also providing a robust mechanism for achieving consensus, thereby improving the overall scalability and resilience of the blockchain network.

[0008] Exemplary, non-limiting embodiments of this disclosure will be described with reference to the accompanying drawings. [Brief explanation of the drawing]

[0009] [Figure 1] This is a schematic diagram of a networked computer system configured to implement a blockchain including a quantum proof-of-work consensus scheme, according to embodiments disclosed herein. [Figure 2] Figure 1 is a detailed schematic diagram of a blockchain miner in a networked computer system. [Figure 3A] This flowchart illustrates a method for implementing a quantum analog proof-of-work consensus scheme according to at least some of the embodiments disclosed herein. [Figure 3B]A flowchart illustrating a method executed to analyze a plurality of received verification data according to at least some of the embodiments disclosed herein. [Figure 3C] A flowchart illustrating a method executed to authenticate a plurality of received verification data according to at least some of the embodiments disclosed herein. [Figure 3D] A flowchart illustrating a method executed to validate a plurality of authenticated verification data according to at least some of the embodiments disclosed herein. [Figure 3E] A flowchart illustrating a method executed to determine whether verification data generated by a miner satisfies threshold conditions according to at least some of the embodiments disclosed herein. [Figure 4] A table illustrating examples of a plurality of verification data according to at least some of the embodiments disclosed herein. [Figure 5] Illustrates an exemplary mode bin distribution and a true mode bin distribution implemented using the verification data illustrated in FIG. 4. [Figure 6] Illustrates an exemplary state bin distribution and a true state bin distribution implemented using the verification data of FIG. 4. [Figure 7A] An exemplary schematic diagram of the hardware implementation of the miner of FIG. 1 according to at least some of the embodiments disclosed herein. [Figure 7B] Another exemplary schematic diagram of the hardware implementation of the miner of FIG. 1 according to at least some of the embodiments disclosed herein. [Figure 7C] Yet another exemplary schematic diagram of the hardware implementation of the miner of FIG. 1 according to at least some of the embodiments disclosed herein. [Figure 8] A graph illustrating the energy performance of a quantum boson sampler, a supercomputer, and a single-core computer.

DETAILED DESCRIPTION OF THE INVENTION

[0010] The following detailed description includes references to the accompanying drawings. Wherever possible, the same reference numerals are used in the drawings and description to refer to the same or similar components and / or processes. While several exemplary embodiments are described herein, modifications, adaptations, and other implementations are possible. For example, components illustrated in the drawings may be replaced, added, or modified, and exemplary methods described herein may be modified by replacing, rearranging, deleting, or adding steps to the disclosed methods. Therefore, the following detailed description is not limited to the disclosed embodiments and examples. Instead, the appropriate scope is defined by the accompanying claims.

[0011] I. System Overview Figure 1 is a schematic diagram of a networked computer system 101 configured to implement a blockchain including a quantum proof-of-work (PoW) consensus scheme according to an embodiment of the present disclosure. For example, such a blockchain could function as a digital ledger for electronic transactions (TX), but it should be understood that any type of data can be stored on the blockchain, and references to a digital ledger for electronic transactions are for non-limiting illustrative purposes only. The type of data stored on the blockchain is not important for the purposes of this specification.

[0012] Electronic transaction data generated by different users is collected via a shared communication network 105 and stored in a transaction pool repository 103. For example, the first transaction data TX1 associated with the first user at the first user terminal 107, the second transaction data TX2 associated with the second user at the second user terminal 109, the third transaction data TX3 associated with the third user at the third user terminal 111, and the fourth transaction data TX4 associated with the fourth user at the fourth user terminal 113 are transmitted to the transaction pool 103 via the shared communication network 105. The transaction data received by the transaction pool 103 is stored for subsequent processing by at least one of several blockchain miners 115, 117, 119, and 121.

[0013] When a predetermined threshold condition is met, at least one blockchain miner 115, 117, 119, 121 stores multiple transaction data (TX1...TX4) in the transaction pool 103 for processing. For example, the predetermined threshold condition may relate to a predetermined number of electronic transactions stored in the transaction pool 103. The received transaction data is processed in bulk by at least one blockchain miner 115, 117, 119, 121. Alternatively, at least one blockchain miner 115, 117, 119, 121 retrieves multiple transaction data when the threshold condition is met. The retrieved or received transaction data is, in some cases, processed by at least one blockchain miner to generate a new candidate block 123 to be added to an existing blockchain and / or to generate a new candidate block 123 for a new blockchain. The new candidate block 123 is then distributed to multiple blockchain miners 115, 117, 119, and 121 via the communication network 105 so that a quantum consensus proof-of-work scheme can be performed by each participating miner 115, 117, 119, and 121.

[0014] As background, the process of generating blocks and adding them to the blockchain is generally called "mining." The mining process involves several different steps, including generating candidate blocks, verifying candidate blocks, and adding candidate blocks to the blockchain. The process of verifying candidate blocks may itself involve several different steps, including, for example, implementing a consensus scheme. Thus, once a candidate block 123 is generated, it may be verified by a verifier 125 to ensure that the candidate block was generated correctly before it is added to an existing blockchain or used to start a new blockchain. For example, the verification process may involve multiple blockchain miners 115, 117, 119, 121 sending verification data associated with the candidate block 123 to the verifier 125 for verification via a communication network 105. The verifier 125 analyzes the verification data received from each of the multiple blockchain miners 115, 117, 119, 121 and sends a reward to each miner whose verification data meets a threshold condition, as determined from the analysis of the relevant verification data. After verification, the candidate block is added to the blockchain.

[0015] In Figure 1, they are represented as separate entities for illustrative purposes, but any minor can also function as a verifier. Conversely, any verifier can also function as a minor.

[0016] II. Blockchain Miners Figure 2 is a detailed schematic diagram of the blockchain miners 115, 117, 119, and 121 in Figure 1. As illustrated, the blockchain miners 115, 117, 119, and 121 may include a processing unit 210 and a boson sampling unit 220. The boson sampling unit 220 may refer to any type of hardware device capable of providing samples from a boson sampling distribution. Various hardware implementations of the boson sampling unit 220 are envisioned (see, for example, Figures 7A to 7C).

[0017] As shown in Figure 2, the boson sampling unit 220 may include, but is not limited to, a single-photon source matrix 222, a linear optical network 224, and a single-photon detector matrix 226. The linear optical network 224 may relate to any type of optical system having an equal number of input and output ports, called modes (M), as well as a number of different optical paths connecting the input and output modes. Thus, the linear optical network 224 may be mathematically characterized by an M × M unitary matrix (U) that mathematically describes how the state of an input photon is transformed as it passes through the linear optical network 224. According to some embodiments, the unitary matrix U may correspond to a pseudo-Haar random matrix. The single-photon source matrix 222 may be configured to provide single photons in one or more of the input modes of the linear optical network 224, in other words, the single-photon source matrix 222 may be configured to generate input (Fock) states of the following forms:

number

number

number

[0018] As input photons pass through a linear optical network, their states are transformed. Mathematically, the input states are modified by a linear optical network 224, described by U, which performs a linear transformation of the generation (and annihilation) operators of the input modes.

[0019]

number

number

number

number

number

[0020] The single-photon detector matrix 226 can be configured to detect the presence of one or more photons in each output mode of the linear optical network 224. Thus, the output of the single-photon detector matrix 226 enables the detection of a particular output configuration S, and its output is a vector corresponding to the sample from the boson sampling distribution.

number

number

[0021] In the example illustrated in Figure 2, the number of ports M in the linear optical system 224 is equal to 4, and the input configuration includes two single photons located in two of the four input modes. As illustrated, the two single photons occupy the first two input ports (represented by shaded circles) of the linear optical network 224. The remaining two ports are in a vacuum state (represented by unshaded circles). This can be mathematically represented as |1,1,0,0>.

[0022] Figure 2 illustrates the number of ports M, which is equal to 4, and the number of input photons N, which is equal to 2. However, these quantities are not restrictive, and it should be understood that any number of ports M and a positive number of input photons N can be selected, provided that (N ≤ M). In other words, the number of ports M must be greater than or equal to the number of input photons.

[0023] Any one of the boson sampling experiment parameters, i.e., the number N of input photons, the input state of the system, the number M of output / input ports, the unitary transformation U, or a combination thereof, can be selected as a function of the information associated with and / or included in the candidate block 123 to be added to the blockchain. For example, the input state can be selected as a function of the hash value of the header of the candidate block 123. Additionally, the number N of input photons, the input state, the number M of output / input ports, and the unitary transformation U can be determined from the information associated with and / or included in the candidate block 123. According to some embodiments, a mapping rule can be predefined and shared among the miners 115, 117, 119, 121, and this mapping rule maps the information included in the candidate block 123 to any one of the above-mentioned boson sampling experiment parameters.

[0024] Alternatively, according to some embodiments, any one of the number N of input photons, the input state of the system, the number M of output / input ports, the unitary transformation U, or a combination thereof can be constant over one or more verification processes to simplify practical implementation, i.e., the same parameters can be used to verify one or more different candidate blocks 123. In such a case, the set of parameters can be communicated before the start of the verification process for the entire network.

[0025] M~N 2 In the scenario of, the probability that two or more photons reach the same output port of the linear optical system becomes statistically negligible, thus reducing the number of possible output configurations.

Number

[0026] This scenario can be referred to as the collision-free regime. In this regime,

Number

number

[0027] The processing unit 210 may include one or more types of processing devices, for example, one or more of a microprocessor, preprocessor, central processing unit (CPU), support circuitry, digital signal processor, integrated circuit, memory, or any other processing device. The processing unit 210 may be configured to communicate with the communication network 105 and one or more of the components 222, 224, and 226 of the boson sampling unit 220. The communication may include exchanging data with one of the components and / or sending one or more instructions to one or more components. For example, the processing unit 210 may instruct which port of the single-photon source matrix 222 a photon should be generated at in order to prepare the input state.

[0028] In embodiments where optical loss exists in the linear optical network 224, any blockchain miner 115, 117, 119, 121 can retrospectively select only samples where the total number of measured photons equals N, the number of input photons. Similarly, the efficiency of the single-photon detector matrix 226 may not be equal to 100%, in which case photons are present in the detector but not detected, and therefore retrospective selection may be necessary. Assuming that the loss is uniform within the linear optical network 224 and the efficiency of the single-photon detector matrix is ​​uniform, the expected distribution remains unchanged during retrospective selection. However, the sampling rate of the blockchain miners 115, 117, 119, 121 may be reduced.

[0029] III. Quantum Proof-of-Work (PoW) Consensus Scheme Figure 3A illustrates the verification process performed by the verifier 125 to verify candidate block 123 using a quantum analog proof-of-work (PoW) consensus scheme, according to several embodiments. Once candidate block 123 is transmitted to a number of initial miners 115, 117, 119, and 121 via the communication network 105, a process may be performed to verify candidate block 123 using the quantum PoW consensus scheme.

[0030] In step 302, the Validator 125 receives multiple different validation data from the Minors 115, 117, 119, and 121, each of which is obtained using a boson sampling experiment associated with the candidate block 123, and each different validation data is associated with a different Minor 115, 117, 119, and 121, each of which includes a boson sampling unit 220 configured to generate the validation data. Each Minor performs a boson sampling experiment using information associated with and / or contained within the candidate block.

[0031] According to some embodiments, the verification data relates to a bit string associated with a set of output configurations measured by the boson sampling unit 220. In some embodiments, the verification data may further include a timestamp associated with the time each output configuration is measured by the boson sampling unit 220.

[0032] In step 304, the Validator 125 analyzes the received validation data. In some embodiments, the analysis of the validation data may begin when a threshold condition is met. The threshold condition may relate to a predetermined number of received validation data. The predetermined number may depend on the candidate block 123. For example, the predetermined number of validation data may include 100, 200, 500, 1000, or any other predetermined number of validation data. The threshold condition may also refer to a predetermined elapsed period. The predetermined period may depend on the candidate block, the miner's sampling rate, i.e., the rate at which the miner can generate and measure the output configuration of the boson sampling experiment, or a statistically determined minimum number of validation data.

[0033] Based on an analysis of the received set of verification data, the Validator 125 may, in step 306, send rewards to at least some of the miners 115, 117, 119, and 121 who have joined the consensus scheme. For example, in some embodiments, as illustrated in more detail below, the analysis performed by the Validator 125 may verify which of the received set of verification data satisfy the authentication and / or validation process, and only those miners 115, 117, 119, and 121 associated with the verification data that satisfy the authentication and / or validation process receive rewards. Finally, in step 308, the Validator 125 adds candidate block 123 to the blockchain. In some embodiments, the Validator 125 may simultaneously add a record to the blockchain having candidate block 123 that proves that consensus has been reached. The record may contain different types of information. Examples of information may include one or more parameters used by each miner to conduct a boson sampling experiment (e.g., N, M, U, input state), one or more parameters used by a validator to perform an analysis of multiple validation data sets, one or more results obtained from the analysis of multiple validation data sets, or one or more additional types of data (e.g., a predetermined number of validation data received, a predetermined period).

[0034] Although verifier 125 and minors 115, 117, 119, and 121 are described as separate entities, any minor can also be a verifier. Conversely, any verifier can also be a minor.

[0035] Figure 3B illustrates the steps involved in step 304 of Figure 3A, in which the validator 125 analyzes the received validation data. The analysis may include authenticating the received validation data in step 314, then validating the received validation data in step 324, and determining in step 334 whether a threshold condition is met for each of the received validation data.

[0036] To improve security, in some embodiments, the verification data may be encrypted to prevent malicious miners from copying and recirculating genuinely generated verification data. For example, the verification data may be hashed.

[0037] In some embodiments, the hash may be calculated using a hash function on a bit string associated with the verification data. In some embodiments, all measured output configurations may be hashed along with their associated timestamps and, optionally, any further bit strings associated with the minor. It should be understood that any output configuration measured by the boson sampling unit 220 may be associated with a vector, and therefore the hash of the output configuration is associated with the hash of the associated vector.

[0038] Figure 3C illustrates further details of how multiple received verification data can be authenticated by the verifier 125 in step 314 of Figure 3B, in an embodiment in which hashes of verification data are received. In step 314a, the verifier 125 receives multiple hashed verification data. Subsequently, in step 314b, the unhashed version of the received hashed verification data is received by the verifier 123. According to some embodiments, the unhashed verification data may be received after all multiple hashed verification data have been received by the verifier 123. If hashed verification data has been generated, this data may be received in step 314b along with the unhashed verification data, at least in part depending on any other data such as timestamp data. The verifier 125 may then independently calculate the hash of all received unhashed data in step 314c. Finally, in step 314d, the verifier 125 may compare its determined hash value with the hash value received in 314a for each received verification data. Miners associated with a transmitted hash different from the hash determined by the verifier may be excluded from further participation in the verification process and consequently excluded from receiving rewards.

[0039] Figure 3D illustrates, in several embodiments, how multiple authenticated validation data can be validated by the Validator 125 in step 324 of Figure 3A. In step 324a, the Validator 125 may select a mode binning strategy. The Validator 125 may then determine the mode bin distribution for each authenticated validation data and the true mode bin distribution for the multiple authenticated validation data in step 324b. In step 324c, the Validator 125 may determine a validity coefficient for each authenticated validation data. Finally, for each authenticated validation data, the Validator 125 may validate or invalidate the associated validation data in step 324d by comparing the determined validity coefficient with a validity threshold. Miners associated with invalidated validation data are excluded from further participation in the validation process and, as a result, are excluded from receiving rewards. Further details of validating multiple authenticated validation data are described below in relation to Figure 5.

[0040] According to some embodiments, the mode bin distribution of authenticated validation data is associated with multiple output configurations of the boson sampling unit 220 of miners 115, 17, 119, and 121. In other words, it is associated with the statistical distribution of output modes measured by the miners. The true mode bin distribution is a reference distribution that can be compared to the mode bin distribution. The true mode bin distribution can be calculated based on the unitary matrix U, the input states, and the mode binning tactic employed. In other words, the true mode bin distribution can be calculated before the boson sampling experiment is performed, given that the unitary matrix, the input states, and the mode binning tactic employed are known. In contrast, the mode bin distribution is determined after the boson sampling experiment is performed, based on the observed output modes.

[0041] Figure 3E illustrates, in one embodiment, how the Validator 125 may determine in step 334 of Figure 3B whether the validation data generated by miners 115, 117, 119, and 121 meets the threshold condition. In step 334a, the Validator 125 may determine the state binning tactic for use. The Validator 125 may then determine, in step 334b, the state bin distribution for each validated validation data and the true state bin distribution for multiple validated validation data. In step 334c, the Validator 125 may determine the success coefficient for each validated validation data. Finally, in step 334d, the Validator 125 may compare the associated success coefficient for each validated validation data to the success threshold. If the success threshold is not met, the associated miner is excluded from receiving the reward. Details of how the threshold condition is determined in some embodiments are further described below in relation to Figure 6.

[0042] IV. Examples of validation data Figure 4 is a table illustrating examples of multiple validation data received from minors 115, 117, 119, and 121 having the input state exemplified in Figure 2, i.e., |1,1,0,0>. As shown here, minors 115, 117, 119, and 121 each have a measured output configuration of the boson sampling unit 220 at a given time. As illustrated, at least some of minors 115, 117, 119, and 121 measure a different number of output configurations and, therefore, transmit validation data associated with a different number of binary vectors. The statistical distribution of the received validation data and associated binary vectors can be determined. These statistics can be performed on the output ports or on the output configurations of the linear optical system 224. In addition, this distribution can be coarse-grained, requiring equal-size grouping or binning of the output statistics of the boson sampling unit 220. Coarse-grained statistics can be provided according to some given binning tactics (BT), i.e., specific methods of dividing and rearranging the output configurations into group (bin) output configurations. The example validation data is for collision-free regimes (M~N2 It is acquired via [method / platform name]. Similar to traditional blockchains (e.g., the Bitcoin blockchain), it is assumed that no single miner will dominate the network, i.e., will own more than 51% of the measured output configuration.

[0043] V. Validation of verification results Validating multiple received validation data is, as mentioned above, mode bin P (mb) This may include selecting the distribution and the true mode bin distribution. Mode binning may refer to determining coarse-grained statistics for the output modes (ports) of the linear optical system 224 according to a given mode binning strategy. Any mode binning strategy may be characterized by one or more mode binning parameters, such as the number of mode bins, the size of the mode bins (i.e., the number of output ports associated with each mode bin), or how the output ports are divided into mode bins (i.e., which output ports are associated with each bin), π (mb) It can be expressed as follows. According to some embodiments, the number and size of the mode bins are transmitted over the network 105 before the start of the verification process. The number and size of the mode bins may remain constant over one or more verification processes, i.e., identical values ​​of these parameters can be used to verify one or more candidate blocks 123. These parameters are essentially related to the number of modes M. In some cases, all mode bins are the same size, so the product of the size and the number of mode bins is equal to M.

[0044] Figure 5 illustrates an exemplary mode bin distribution and a true mode bin distribution performed using the verification data exemplified in Figure 4. An exemplary mode binning tactic 501 is exemplified in Figure 5. According to the exemplary mode binning tactic 501, the four output ports are divided into two bins, each containing two output ports (bin 1 containing ports 1 and 2 represented as {1,2}, and bin 2 containing ports 3 and 4 represented as {3,4}). The mode binning tactic 501 can be determined as a function of the verification data. For example, the mode binning tactic 501 can be selected as a function of the hash value H of the concatenated version of all authenticated verification data. Alternatively, the mode binning tactic 501 can be determined as a function of random mode binning beacons transmitted through the network 105 after the start of the verification process (when each miner sends its verification data). For example, a mapping function can be used to select the mode binning tactic 501 according to the mode binning beacon. The mode binning beacon can be constructed using a post-quantum secure verifiable random function.

[0045] Figure 5 illustrates four different mode bin distributions 515, 517, 519, and 521 corresponding to the validation data in Figure 4 received from miners 115, 117, 119, and 121. The true mode bin distribution 503

number

[0046] The validity coefficient of minor i (V i Examples of ) can take the following forms:

number

number

[0047] If candidate block 123 is successfully verified, according to some embodiments, the number of mode bins is d, and the mode binning tactic is π. (mb) The β and true mode bin distribution may be included in the record added to the blockchain along with candidate block 123. Miners 115, 117, 119, and 121 do not know the selected mode binning tactic 501 in advance, therefore M! / (M / d)! d Possible mode binning tactics exist even after one or more parameters of a boson sampling experiment have been specified, and the true mode binning distribution

number

[0048] VI. Determining the Threshold Condition Determining the threshold conditions for multiple validated verification data is possible for state bin P. (sb) This may include selecting the distribution and the true state bin distribution. State binning may refer to determining coarse-grained statistics for the output configurations (S) of the linear optical network 224 according to the selected state binning tactic. Any state binning tactic may be characterized by one or more state binning parameters, such as the number of state bins, the size of the state bins (i.e., the number of output configurations associated with each state bin), or how the output configurations are divided into state bins (i.e., which output configurations are associated with each state bin), π (sb) It can be expressed as follows. According to some embodiments and as described above, the number and size of state bins can be transmitted through network 105 before the start of the verification process. The number and size of state bins can be constant over one or more verification processes, i.e., identical values ​​of these parameters can be used to verify one or more candidate blocks 123. These parameters are essentially related to the number of modes M and the number of input photons N. In some cases, since all state bins are the same size, the product of the size and the number of state bins is equal to M! / N!(MN)! (in a collision-free regime).

[0049] Figure 6 illustrates an exemplary state bin distribution and a true state bin distribution performed using the validation data from Figure 4. For non-restrictive exemplary purposes, all miners are assumed to be validated. An exemplary state binning tactic 601 is illustrated in Figure 6. The six output configurations are divided into three bins, each containing two unique output configurations (e.g., bin 1 contains output configuration {|1,1,0,0〉,|1,0,1,0〉}, bin 2 contains output configuration {|0,1,1,0〉,|1,0,0,1〉}, and bin 3 contains output configuration {|0,1,0,1〉,|0,0,1,1〉}). State binning tactic 601 can be selected as a function of the validated validation data. For example, state binning tactic 601 is the hash value H of the concatenated version of all validated validation data. v It can be selected as a function of . Alternatively, the state binning tactic 601 can be determined as a function of random state binning beacons transmitted through network 105 after the start of the verification process (when each miner sends its verification data). For example, a mapping function can be used to select the state binning tactic 601 according to the state binning beacon. The state binning beacon can be constructed using a post-quantum secure verifiable random function.

[0050] Four different state bin distributions 615, 617, 619, and 621 are exemplified, corresponding to the validation data shown in Figure 4, which were received by miners 115, 117, 119, and 121. The true state bin distribution 603 is the expected value (E[P]) of the state bin distribution determined for all validation data. (sb) This can be calculated by calculating ]). Once the true state bin distribution is obtained, the success coefficient Su can be determined. If the success coefficient is less than the success threshold δ, the validation data satisfies the threshold condition, and the associated miner may receive a reward. If the success coefficient is greater than or equal to the success threshold δ, the validation does not satisfy the threshold condition, and the associated miner is excluded from receiving a reward.

[0051] Minor I Success Coefficient Su i Examples of this can take the following forms: Sui =|μ i -μ net | In the formula, μ i μ represents the peak state bin probability of minor i, and μ net This represents the net peak state bin probability. The net peak state bin probability is the peak probability of the true state bin distribution.

[0052] Referring to the results in Figure 6, and taking the success threshold δ = 0.1, minor A115 and minor D121 have too large a difference between their state bin distributions 615 and 621 and the true state bin distribution 603 (i.e., Su i >δ) Therefore, it will be excluded from receiving the reward. Miners B117 and C119 receive the reward. δ may be transmitted through network 105 before the start of the verification process and may remain constant across one or more verification processes, i.e., the same value for δ may be used to verify one or more candidate blocks 123.

[0053] If candidate block 123 is successfully verified, according to some embodiments, the number of state bins, state binning tactics π (sb) , success threshold δ, and net peak state bin probability μ net This could be included in the records added to the blockchain along with candidate block 123.

[0054] Unlike mode bin distributions, which can be approximated using classical (polynomial) algorithms to determine whether a miner is sincere, state bin distributions require actual samples obtained from a boson sampler to approximate peak state bin probabilities. Therefore, this additional validation layer ensures that samples come from a boson sampling distribution and provides an incentive for miners to use quantum devices to generate samples. Other incentives for using quantum devices, including the reward scheme described below, are implemented in the validation process.

[0055] VII. Boson Sampling Unit 220 Hardware Embodiment Figures 7A to 7C illustrate different exemplary hardware configurations of the boson sampling unit 220 according to different embodiments of the present disclosure. In the exemplary embodiments, the number of input / output ports (M) of the linear optical network 224 is equal to 4, and the number of input photons (N) is equal to 2. However, it should be understood that different numbers of input and output ports (M) may be used according to different embodiments, and the exemplary embodiments are provided for non-limiting exemplary purposes only.

[0056] Figure 7A is a schematic diagram of a specific boson sampling unit 720A that includes an optical system with bulk optical elements. The three main components described in relation to Figure 2 can be identified as follows: The single-photon source matrix 222 includes four single-photon sources. These single-photon sources can be implemented using various known single-photon source techniques, such as spontaneous parametric downconversion (SPDC) sources or quantum dot sources. SPDCs produce pairs of photons that are stochastically correlated. Due to the correlation, the detection of just one photon at the output of one suggests the presence of a photon at the other, enabling the stochastic and announced preparation of a single-photon state. When extended to multiple such sources, this nondeterminism suggests an exponential reduction in the rate of simultaneous state preparation from multiple sources. Multiplexing can be used to overcome this scaling problem when banks of announced SPDC sources operate in parallel and successful photon preparation events are then multiplexed to the desired boson sampling input. Quantum dot sources, on the other hand, can be configured to produce single photons on demand with high probability. In some embodiments, the input photons are synchronized. The single-photon detector matrix 226 includes four single-photon detectors. Known single-photon detector techniques, such as photon-resolved detectors or bucket detectors, may be used. In the case of a collision-free regime, bucket detectors are sufficient to determine the output configuration of the linear optical network 224. The linear optical network 224 may include bulk optical elements in free space, such as mirrors (black plates), beam splitters (light gray squares), and phase shifters (light gray plates). The gray dashed lines represent all potential optical paths of the input photons.

[0057] Figure 7B is a schematic diagram of a boson sampling unit 720B including a photonic architecture with an integrated waveguide. In this architecture, the single-photon source matrix 222 and the single-photon detector matrix 226 may be identical to those illustrated in the embodiment of Figure 7A described above. The difference between the embodiments of Figure 7A and Figure 7B lies in the use of an integrated waveguide circuit and coupler to provide the functionality of the linear optical network 224. Different potential advantages, such as stability, lower space requirements, and / or ease of manufacture, are associated with the embodiment of Figure 7B.

[0058] Figure 7C is a schematic diagram of a boson sampling unit 720C, which includes another photonic architecture configured to perform time-bin coded boson sampling. This embodiment includes a single-photon source and a single-photon detector. Instead of being spatially determined, the input / output ports of the linear optical network 224 are temporally determined. The single-photon source generates a series of pulses separated by time τ, defining a time-bin mode and input state |Ψ|. in > is included. Each time bin mode corresponds to a spatial mode in the boson sampling scheme illustrated in Figure 2. The linear optical network 224 includes one or more loops arranged in various configurations, and a bus waveguide. A stream of photons from the bus waveguide is coupled to a first loop using a switch (light gray square), which can correspond to all interference M modes, meaning its length is greater than or equal to Mτ. A second switch couples the first loop to a second loop, allowing photons from different time bins to interact. The second loop may include a phase shifter (black square). Finally, the photons are coupled again to the first loop and the bus waveguide. A single-photon detector measures the presence of photons in different time bin modes of output state.

[0059] Different hardware implementations are possible. The architecture described above is provided as a non-limiting example. The use of a hybrid coding platform that jointly uses time and polarization degrees of freedom to define modes is also envisioned. In the coming years, the performance of boson sampling experiments is expected to improve significantly. For example, the single-photon source rate, detection efficiency, and sampling rate of boson sampling experiments will increase. As a result, the generation of a given number of boson samples will be faster, affecting the block generation time. Similar to the Bitcoin blockchain, where the advent of supercomputers has drastically reduced block generation time, several levers can be implemented to adjust the latter. According to some embodiments, the block generation time can be adjusted not only by adjusting the number of input photons N, β, and γ values, but also by adjusting the mode and state bin sizes.

[0060] VIII. Reward Scheme Miners who pass all steps of the validation process (steps 314-334) may receive a reward. The amount of the reward R may depend on one or more parameters. For example, the reward may depend on the number of samples provided to the validation data, in which case a fixed reward per sample may be defined.

[0061] One of the goals of the reward system is to prevent fraudulent miners from receiving rewards. In the context of this explanation, a fraudulent miner may refer to any miner who does not use a boson sampler to generate its validation data and who has a negligible or no cost to generating the validation data. For example, a miner might submit samples from a random distribution, artificially inflate the number of committed samples, and hope to receive a large reward by chance. To solve this problem, a penalty term can be imposed on miners who do not complete all steps of the validation process. The amount of the penalty P may depend on one or more parameters. For example, the penalty may depend on the number of samples provided for the validation data, in which case a fixed penalty per sample may be defined. According to some embodiments, the penalty may be chosen as a function of the reward. For example, the value of the penalty may be chosen such that the only winning strategy for the miner is to act honestly. According to some embodiments, the values ​​of the reward R and the penalty P may be transmitted throughout the network 105 before the start of the validation process and may remain constant over one or more validation processes, i.e., the same values ​​for R and P may be used in the validation process of one or more candidate blocks 123.

[0062] Alternatively, and according to some other embodiments, miners may be required to stake some tokens to participate in the verification process (submit verification data) and have the opportunity to receive rewards. In this scenario, at the end of the verification process, successful miners reclaim their staked tokens and receive additional rewards, while unsuccessful miners lose a penalty or the lesser of their staked tokens. This mechanism differs from another common consensus mechanism known in the prior art, namely proof-of-stake, where all miners stake the same amount of tokens, and the probability of receiving a reward (mining a block) is independent of the amount staked.

[0063] A further objective of the reward system is to ensure that miners use actual quantum boson samplers rather than classical or supercomputers, since the choice between classical or supercomputers to solve the boson sampling problem is highly energy-intensive. For example, according to some embodiments, the reward value may be set so that miners are monetaryly rewarded for participating in the verification process only if the quantum boson sampler is used to provide the verification data. One way to achieve this effect is to analyze the cost of generating samples using a quantum boson sampler or supercomputer. In the context of this explanation, cost mainly refers to energy consumption, which is ultimately associated with a monetary cost. For classical computers, the best boson sampling simulator algorithm is 2 N It has a cost per sample that is proportional to N (in a collision-free regime, M=N) 2 On the other hand, for a quantum boson sampler, in the best case, the cost is proportional to N. Considering some intrinsic fixed costs that do not depend on the number of input photons (e.g., the cost of cooling the single-photon detector matrix 226), there is a wide range of values ​​for the number of input photons N, and thus the cost of using a classical boson sampling simulator is significantly higher than the cost of using a quantum boson sampler. This is illustrated in Figure 8, which shows the energy costs of a quantum boson sampler (solid curve 801), a single-core classical computer (large dashed curve 803), and a supercomputer (small dashed curve 805). Therefore, by setting the reward value higher than the cost of a quantum boson sampler but lower than the cost of a classical boson sampling simulator, the network's miners gain an incentive to use a quantum boson sampler.

[0064] IX. Gaussian Boson Sampling Single-photon (Fock state) boson sampling requires a reliable source of indistinguishable photons. This requirement represents one of the challenges in scaling up the complexity of current boson sampling experiments. An alternative to Fock state boson sampling is Gaussian boson sampling. The verification process is essentially the same as that described with respect to Figure 3A, with some differences described below. Fock state boson sampling is difficult to simulate on classical computers due to the complexity of computing the permanent, while Gaussian boson sampling is difficult to simulate due to the difficulty of computing the Haffnian (#-P complete complexity class). Instead of zero or one-photon states in the input, Gaussian boson sampling uses zero-photon or squeezed vacuum states. The required input squeezed vacuum state is prepared deterministically using a single or two-mode squeezer, thereby potentially resulting in a significant improvement in the associated sampling rate. Measurements like Fock state boson sampling are assumed to be numerical decompositions and, like Fock state boson sampling, are post-selected to result with a total number of photons equal to the average number of photons in the input. The validation step 324 of the verification process is the same except for the classical algorithm used to compute the mode bin distribution, which is also polynomial in terms of problem size, but involves computing a different function.

[0065] The above description is provided for illustrative purposes only. It is not exhaustive and does not limit this disclosure to the exact form or embodiment disclosed herein. Modifications and adaptations of this disclosure will be apparent to those skilled in the art from a review of this specification and the practice of the embodiments disclosed herein.

[0066] The features and advantages of this disclosure are evident from the detailed specification, and therefore the attached claims are intended to cover all systems and methods included in the true spirit and scope of this disclosure. As used herein, the indefinite articles "a" and "an" mean "one or more." Similarly, the use of plural terms does not necessarily indicate plural unless it is clear in the given context. Words such as "and" or "or" mean "and / or" unless specifically indicated otherwise. Furthermore, since numerous modifications and variations can easily arise from examining this disclosure, it is not desirable to limit this disclosure to the exact configurations and operations illustrated and described, and therefore all suitable modifications and equivalents included in the scope of this disclosure may be applicable.

[0067] Other embodiments will be apparent to those skilled in the art from the examination of this specification and the practice of the implementations disclosed herein. The schematic architecture and process flowcharts shown in the figures are for illustrative purposes only and are not intended to limit the invention. Furthermore, this specification and the examples are intended to be considered merely illustrative, and the true scope and spirit of the invention are set forth by the following claims. The above description is presented for illustrative purposes only. It is not exhaustive and does not limit this disclosure to the exact forms or embodiments disclosed. Modifications and adaptations of this disclosure will be apparent to those skilled in the art from the examination of this specification and the practice of the embodiments disclosed herein.

Claims

1. A quantum analog proof-of-work consensus method for use in blockchain networks, Receiving multiple verification data obtained using boson sampling experiments associated with candidate blocks from multiple different miners of the blockchain network, wherein each verification data is associated with a different miner, and each miner performs and receives the boson sampling experiment using information contained in the candidate block. The process involves analyzing the received multiple verification data to determine whether a consensus has been reached, A method comprising adding the candidate block to the blockchain associated with the blockchain network when a consensus is achieved.

2. The method according to claim 1, further comprising sending rewards to at least some of the plurality of miners of the blockchain network based on the analysis of the plurality of received verification data.

3. Analyzing the received multiple verification data to determine when a consensus has been reached is possible. Authenticating the multiple verification data received, Validating the multiple verification data that have been authenticated, The method according to claim 1 or 2, comprising determining whether the threshold conditions for the validated verification data are met.

4. Validating the multiple verification data that have been authenticated is Selecting a mode binning tactic characterized by one or more mode binning tactic parameters, For each authenticated verification data associated with each different miner, the mode bin distribution is determined based on the selected mode binning strategy. Based on the selected mode binning tactics applied to the authenticated set of validation data, the true mode bin distribution is determined. The validity coefficient is determined for each set of authenticated validation data by comparing the mode bin distribution of the authenticated set of validation data with the true bin distribution, The method according to claim 3, comprising: determining whether the determined validity coefficient satisfies a validity threshold for each authenticated verification data; and maintaining a set of authenticated verification data associated with the validity coefficient that satisfies the validity threshold.

5. The method according to claim 4, wherein determining the validity coefficient associated with the set of authenticated validation data includes determining the statistical distance of the mode bin distribution of the set of authenticated validation data to the true bin distribution of the plurality of authenticated validation data.

6. Determining whether the threshold conditions of the validated and authenticated plurality of verification data are met is: Selecting a state binning tactic characterized by one or more state binning tactic parameters, For each validated and authenticated verification data associated with each different miner, the state bin distribution is determined based on the selected state binning strategy. Determining the true state bin distribution based on the selected state binning tactics for the validated and authenticated set of validation data, The success coefficient is determined for each validated and authenticated set of validation data by comparing the state bin distribution of the validated and authenticated set of validation data with the true state bin distribution. The method according to any one of claims 3 to 5, comprising: determining whether the determined success coefficient satisfies a success threshold for each validated and authenticated verification data; and maintaining a set of validated and authenticated data associated with the success coefficient that satisfies the success threshold.

7. The method according to claim 6, wherein each miner associated with a retained set of validated and authenticated data receives a reward.

8. The method according to any one of the prior claims, wherein the candidate block is generated by a miner of the blockchain network.

9. The method according to any one of the prior claims, wherein adding the candidate block to the blockchain associated with the blockchain network when consensus is achieved includes adding a record to the blockchain confirming that consensus has been achieved.

10. A quantum analog proof-of-work consensus method for use in blockchain networks, Receiving candidate blocks containing multiple transaction data, The process involves generating validation data by conducting a boson sampling experiment using the information contained in the aforementioned candidate block, A method comprising transmitting the verification data to a verification server included in the blockchain network, wherein the verification data enables the verification server to determine whether a consensus has been achieved.

11. The method according to claim 10, further comprising receiving a reward based on an analysis of the transmitted verification data.

12. The method according to claim 10 or 11, wherein the boson sampling experiment is performed using an optical network, the verification data is generated by inputting one or more photons into the optical network and observing the output of the one or more input photons, and the boson sampling experiment is performed using information contained in the candidate block, which includes determining one or more of the input configuration of the optical network, the number of input photons, the number of modes, and a unitary transform that defines the initial configuration of the optical network, based on the information contained in the candidate block.

13. The method according to any one of the prior claims, wherein the boson sampling experiment associated with the candidate block is a Fock state boson sampling experiment or a Gaussian state boson sampling experiment.

14. A verification server comprising at least one processor configured to perform the method described in any one of claims 1 to 9.

15. A blockchain miner comprising at least one processor and one boson sampling unit configured to perform the method described in any one of claims 10 to 13.