Quantum computing device, quantum computing system, quantum computing method, and program

Quantum secret computation using cubic double-even CSS codes addresses the issue of large quantum bit requirements in conventional methods by enabling transversal T gates without magic state verification, improving security and reducing quantum bit count.

JP7775999B2Active Publication Date: 2025-11-26NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024522791
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-05-25
Publication Date
2025-11-26
Estimated Expiration
2042-05-25

AI Technical Summary

Technical Problem

Conventional quantum secure computing technologies using self-dual CSS quantum error-correcting codes require verification of the magic quantum state, necessitating a large number of quantum bits that participants need to hold, compromising security.

Method used

Implementing quantum secret computation based on cubic double-even CSS quantum error-correcting codes, which allows for transversal T gates without the need for magic quantum state verification, reducing the number of quantum bits required to n + 3n from n 2 + 4n.

Benefits of technology

Reduces the number of quantum bits each participant needs to hold during quantum computation, enhancing security by eliminating the need for magic quantum state verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007775999000001
    Figure 0007775999000001
  • Figure 0007775999000002
    Figure 0007775999000002
  • Figure 0007775999000003
    Figure 0007775999000003
Patent Text Reader

Abstract

This quantum computing device in a quantum computing system where a plurality of quantum computing devices connected to a network perform quantum secret calculations in cooperation with one another comprises: a sharing unit that applies double encoding to an input quantum state with a triply-even CSS quantum error correction code, and shares the encoded information obtained through encoding with other quantum computing devices; a verification unit that verifies whether the encoded information is correctly encoded; a computation unit that applies a quantum circuit to the encoded information; and a reconstruction unit that acquires an output quantum state that is the result of applying the quantum circuit to the input quantum state.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to quantum secure computing technology. [Background technology]

[0002] Quantum secure computing is a technology that performs quantum computation while keeping the quantum state encrypted. A conventional technology related to quantum secure computing is disclosed in Non-Patent Document 1.

[0003] In the conventional technology disclosed in Non-Patent Document 1, a self-dual Chalderbank-Shor-Steane (CSS) quantum error correcting code is used to encode a quantum state in quantum secure computation. [Prior art documents] [Non-patent literature]

[0004] [Non-Patent Document 1] V. Lipinska, J. Ribeiro and S. Wehner, "Secure multiparty quantum computation with few qubits", Phys. Rev. A 102, 022405 (2020). Summary of the Invention [Problem to be solved by the invention]

[0005] However, when performing quantum secret computation using self-dual CSS quantum error-correcting codes, as in conventional technology, verification of the magic quantum state is required, which poses the problem of a large number of quantum bits that each participant in the quantum secret computation needs to hold during the quantum computation.

[0006] The present invention has been made in consideration of the above points, and aims to provide a technology for reducing the number of quantum bits that each participant in quantum secret computation needs to hold during quantum computation compared to conventional technology. [Means for solving the problem]

[0007] According to the disclosed technology, there is provided a quantum computing device in a quantum computing system in which a plurality of quantum computing devices connected to a network jointly perform quantum secret computation, the quantum computing device comprising: a sharing unit that double-encodes the input quantum state using a cubic double-even CSS quantum error-correcting code and shares the encoded information obtained by the encoding with other quantum computing devices; a verification unit that verifies whether the encoded information is correctly encoded; a calculation unit that operates a quantum circuit on the encoded information; From the coded information after the calculation unit operates the quantum circuit on the coded information, a reconstruction unit that acquires an output quantum state that is a result of operating the quantum circuit on the input quantum state; A quantum computing device is provided, comprising: [Effects of the Invention]

[0008] According to the disclosed technology, it is possible to reduce the number of quantum bits that each participant in quantum secret computation needs to hold during quantum computation compared to conventional techniques. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 1 is a diagram illustrating an example of the configuration of a quantum computing system. [Figure 2] FIG. 1 is a diagram illustrating an example of the configuration of a quantum computing device. [Figure 3] FIG. 2 illustrates an example of the hardware configuration of a computer. [Figure 4] FIG. 1 is a diagram illustrating an example of a functional configuration of a quantum computing device. [Figure 5] FIG. 1 is a schematic diagram illustrating quantum computing. [Figure 6] A schematic diagram of quantum circuit V is shown. [Figure 7] 1 is a flowchart showing a processing procedure of quantum computation. DETAILED DESCRIPTION OF THE INVENTION

[0010] Hereinafter, an embodiment of the present invention (the present embodiment) will be described with reference to the drawings. The embodiment described below is merely an example, and the embodiment to which the present invention is applied is not limited to the following embodiment.

[0011] In the following description, references are indicated by numbers such as [1], and the names of the references corresponding to the numbers are listed at the end of the specification.

[0012] As mentioned above, in the conventional technology, when performing quantum secret computation using self-dual CSS quantum error-correcting codes, verification of the magic quantum state is required, which poses a problem that each participant in the quantum secret computation needs to hold a large number of quantum bits during the quantum computation. Furthermore, in the conventional technology, verification of the magic quantum state involves a quantum operation that compromises the security of the quantum secret computation.

[0013] The technology according to the embodiments described below makes it possible to avoid verification of the magic quantum state and to reduce the number of quantum bits that each participant in a quantum secret computation needs to hold during the quantum computation compared to conventional techniques.

[0014] (Outline of the embodiment) First, an overview of the technology according to this embodiment will be described. This technology relates to quantum secure computation.

[0015] The existing quantum secret computation disclosed in Non-Patent Document 1 is based on the self-dual Chalderbank-Shor-Steane (CSS) quantum error correcting code. Since the T gate is non-traversal for the self-dual CSS quantum error correcting code, the T gate needs to be implemented using the gate teleportation method. However, when the T gate is implemented using the gate teleportation method, verification of the magic quantum state becomes necessary.

[0016] Therefore, in this embodiment, we propose quantum secret computation based on cubic double-even CSS quantum error correcting codes. Since the T gate is transversal for cubic double-even CSS quantum error correcting codes, verification of the magic quantum state is not necessary. However, since the H gate is non-transversal for cubic double-even CSS quantum error correcting codes, the H gate must be implemented using the teleportation method. In other words, as a result of replacing the self-dual CSS quantum error correcting code with the cubic double-even CSS quantum error correcting code, verification of the magic quantum state is avoided, and the number of quantum bits (qubits) required by each participant in quantum secret computation during quantum computation is n, where n is the number of participants. 2 +4n to n 2 Reduced to +3n.

[0017] (System configuration example) An example of the configuration of a quantum computing system according to this embodiment is shown in Fig. 1. As shown in Fig. 1, this system has a configuration in which a plurality of quantum computing devices 100 (n devices in the example of Fig. 1) are connected to a network 200. Note that n is an integer equal to or greater than 1.

[0018] A plurality of quantum computing devices 100 cooperate (jointly) to perform quantum secure computation. The network 200 is, for example, a network described below. That is, the network 200 includes a classical authenticated broadcast channel

[10] that can be realized by classical secure computation, and a shared randomness source

[11] . Each quantum computing device 100 can use the broadcast channel and the randomness source.

[0019] The network 200 also comprises a private authenticated classical channel

[12] and a quantum channel

[13] . Multiple quantum computing devices 100 are connected via the classical channel and the quantum channel.

[0020] FIG. 2 shows an example of the configuration of the quantum computing device 100 from a hardware perspective. As shown in FIG. 2, the quantum computer 100 includes a control device 400 and a quantum processor 300. The control device 400 performs quantum computation by transmitting a control signal to the quantum processor 300 and obtaining a computation result (measurement result) from the quantum processor 300. The control device 400 can be realized using a classical computer. Note that a classical computer may also be simply called a "computer."

[0021] The quantum processor 300 includes a plurality of quantum bits that constitute a quantum two-level system. There are no particular limitations on the physical system that can be used to realize the quantum bits, and any physical system can be used. For example, a superconducting circuit, an ion trap, a photon, a quantum dot, or the like can be used as the physical system. Note that the quantum processor 300 of a given quantum computing device 100 may be shared with another quantum computing device 100.

[0022] The control device 400 can be realized by, for example, causing a computer to execute a program. This computer may be a physical computer or a virtual machine on the cloud.

[0023] That is, the control device 400 can be realized by using hardware resources such as a CPU and memory built into a computer to execute a program corresponding to the processing performed by the control device 400. The program can be recorded on a computer-readable recording medium (such as a portable memory) and can be saved or distributed. The program can also be provided via a network such as the Internet or email.

[0024] Fig. 3 is a diagram showing an example of the hardware configuration of the computer. The computer in Fig. 3 includes a drive device 1000, an auxiliary storage device 1002, a memory device 1003, a CPU 1004, an interface device 1005, a display device 1006, an input device 1007, an output device 1008, and the like, all of which are interconnected by a bus BS.

[0025] A program for realizing processing on the computer is provided by a recording medium 1001 such as a CD-ROM or a memory card. When the recording medium 1001 storing the program is set in the drive device 1000, the program is installed from the recording medium 1001 to the auxiliary storage device 1002 via the drive device 1000. However, the program does not necessarily have to be installed from the recording medium 1001, but may be downloaded from another computer via a network. The auxiliary storage device 1002 stores the installed program as well as necessary files, data, etc.

[0026] The memory device 1003 reads and stores the program from the auxiliary storage device 1002 when instructed to start the program. The CPU 1004 realizes functions related to the quantum computing device 100 in accordance with the program stored in the memory device 1003. The interface device 1005 is used as an interface for sending and receiving signals to and from a network or a quantum processor, etc. The display device 1006 displays a GUI (Graphical User Interface) or the like according to a program. The input device 1007 is composed of a keyboard, mouse, buttons, a touch panel, etc., and is used to input various operation instructions. The output device 1008 outputs the calculation results.

[0027] Fig. 4 shows an example of the functional configuration of the quantum computing device 100. As shown in Fig. 4, the quantum computing device 100 has a sharing unit 110, a verifying unit 120, a calculating unit 130, and a reconstructing unit 140. The processing operations of these functional units will be described later. Each functional unit is realized by the control processing of the quantum bits by the control device 400 described above. In other words, each functional unit of the quantum computing device 100 is realized by hardware consisting of a computer and quantum bits, and a program (software).

[0028] 1 is regarded as one "quantum computing device 100," the configuration shown in FIG. 4 can also be regarded as the functional configuration of the "quantum computing device 100."

[0029] In the following, various elemental technologies for realizing the quantum computing device 100 will be described, followed by a description of the operation of the quantum computing device 100.

[0030] In the following description, the "quantum computing device 100" may be referred to as a "participant." Note that "participant" is a term often used in multi-party secure computing.

[0031] (About quantum secret computing) Quantum secret computation is a technique for performing quantum computation while encrypting the quantum state, and was first introduced in reference [1]. Quantum secret computation is performed among n participants. First, each participant i has a quantum state ρ i Input the quantum state ρ i "Inputting" means, for example, inputting a quantum state ρ i This is equivalent to preparing quantum bits.

[0032] Next, n participants jointly perform quantum computation according to an arbitrary quantum circuit U (called a protocol). Finally, each participant i outputs a quantum state ω i get.

[0033] Figure 5 is a schematic diagram showing the quantum computation described above. As shown in Figure 5, each participant i has a quantum state ρ i is input to the quantum circuit U, and the quantum state ω i The output is obtained. Quantum secret computation must satisfy the following conditions for correctness, soundness, and privacy, provided that the number of participants who do not follow the protocol is t or less out of n.

[0034] Correctness: If n participants follow the protocol, then a quantum circuit U is realized.

[0035] Soundness: Up to t participants who do not follow the protocol have no way of influencing the outcome of a quantum secret computation beyond choosing their own quantum input states.

[0036] Privacy: Up to t participants who do not follow the protocol cannot obtain any information about the quantum state entered by participants who follow the protocol.

[0037] The quantum secret computation in this embodiment is based on quantum secret sharing with secret verification proposed in Reference [2]. In this method, before starting quantum secret computation, each participant i inputs a quantum state ρ i is doubly encoded with a specific quantum error-correcting code and distributed among n participants to produce a global logical quantum state = In this specification, for convenience of description, the first character of a letter is written at the top left of the letter. For example, = P" is intended to put a double dash "=" on top of P. Logical quantum state = With respect to P, the double line "=" indicates that the original quantum state P entered by the n participants is doubly encoded.

[0038] As a result of the above process, each participant has a global logical quantum state = Holds a portion of P (called a share). Logical quantum state = Both P and the share are examples of coded information. Next, the n participants jointly decode the quantum state ρ i is correctly encoded. Then, we convert each quantum gate in the quantum circuit U into a global logical quantum state = To operate on P, each participant performs quantum operations on their own shares, communicating both classically and quantumly. Finally, each participant i collects the shares corresponding to its output from the n participants, and creates a quantum state ω i is decrypted in two steps.

[0039] To realize universal quantum computation, a set of universal quantum gates is required, and each quantum gate in the set is preferably transversal to a specific quantum error-correcting code agreed upon by n participants.

[0040] In other words, in quantum secret computation, the result of applying a local quantum operation Q to the share held by each participant is a global logical quantum state = Logical quantum operations on P = It is desirable to realize Q. However, there is no quantum error-correcting code that realizes all quantum gates in the set of universal quantum gates [3].

[0041] Therefore, non-traversal quantum gates, which are essential for realizing general-purpose quantum computation, must be implemented using auxiliary quantum states, traversal quantum gates, quantum observation and classical communication, and quantum error correction according to classical observations (i.e., gate teleportation) [4].

[0042] The quantum secure computation proposed in [5] is based on self-dual CSS quantum error correcting codes [6, 7]. In fact, the Clifford gate group (H gate, P gate, CNOT gate) and the T gate can be selected as a set of general quantum gates for self-dual CSS quantum error correcting codes [8]. The Clifford gate group is traversal for self-dual CSS quantum error correcting codes, but the T gate is not. Therefore, the quantum secure computation proposed in [5] requires a gate teleportation scheme to implement the non-traversal T gate. However, the gate teleportation scheme to implement the T gate requires verification of whether the auxiliary quantum state is a magic quantum state. Verification of this magic quantum state involves a quantum operation that renders the quantum secure computation insecure.

[0043] Therefore, in this embodiment, we propose quantum secret computation based on cubic double-even CSS quantum error correcting codes [9]. Although the same set of general-purpose quantum gates can be selected for self-dual CSS quantum error correcting codes and cubic double-even CSS quantum error correcting codes, the quantum gates that can be implemented transversally are different. If we select the Clifford gate group and the T gate as the set of general-purpose quantum gates, the P gate, CNOT gate, and T gate are transversal for cubic double-even CSS quantum error correcting codes, but the H gate is not transversal [9]. In the quantum secret computation according to this embodiment, the non-transversal H gate is implemented using the gate teleportation method [9].

[0044] In this case, the gate teleportation scheme implementing the H gate does not require verification of whether the auxiliary quantum state is a magic quantum state, because the required auxiliary quantum state can be verified using quantum secret sharing with secret verification as described in reference [5]. Therefore, in the quantum secret computation in this embodiment, the number of qubits required by each participant during quantum computation is set to n 2 +4n[5] to n 2 It can be reduced to +3n.

[0045] It should be noted that quantum gates that are not transversal for cubic double-even CSS quantum error correcting codes are not limited to H gates.

[0046] (Definition) Here, definitions of main terms used in this embodiment will be explained.

[0047] Adversary: ​​The adversary is assumed to be non-adaptive (he chooses which participants to take over before the quantum secret computation begins and does not change his decision during the quantum secret computation) and proactive (he can perform any quantum manipulation on the shares he holds). However, we assume that the number of participants the adversary can take over is at most t.

[0048] Network: n participants have access to a classical authenticated broadcast channel

[10] and a shared source of randomness

[11] , which can be realized using classical secret computation. They are also connected by private authenticated classical channels

[12] and quantum channels

[13] .

[0049] General CSS quantum error correcting code: The quantum secure computation in this embodiment is based on the cubic double-even CSS quantum error correcting code [9], which belongs to the general CSS quantum error correcting code [6, 7].

[0050] Therefore, we first explain the properties of general CSS quantum error-correcting codes. When a classical binary linear code encodes k bits into n bits, and the minimum distance is d, this is expressed as [n, k, d]. A general CSS quantum error-correcting code is defined using two classical binary linear codes V and W that satisfy the following conditions:

[0051] ·V is [n,k V ,d V ], and (d V An integer t less than or equal to -1 / 2 V It is possible to correct up to classical errors.

[0052] ·W is [n,k W ,d W ], and (d W An integer t less than or equal to -1 / 2 W It is possible to correct up to classical errors.

[0053] Classical binary linear code V ⊥ and W is V ⊥ ⊆W. However, V ⊥ denotes the dual classical binary linear code of a classical binary linear code V. Furthermore, V ⊥ is [n,k V⊥ ,d V⊥ ], and k V⊥ =nk V The subscript "V⊥" means "V⊥ " is the intention.

[0054] These two classical binary linear codes V and W form a general CSS quantum error-correcting code, denoted by [[n,k,d]], where k=k V +k W -n is satisfied. A general CSS quantum error correcting code is t V bit flips (X errors), and t W It is possible to correct up to phase flips (Z errors). In other words, the minimum distance of a general CSS quantum error correcting code is d ≥ min(d V ,d W ) and can correct t general quantum errors, an integer less than or equal to (d-1) / 2.

[0055] It is important to note that a general CSS quantum error-correcting code can be expressed as a set V∩FW (F stands for Fourier transform) using two classical binary linear codes V and W. That is, a general CSS quantum error-correcting code is a set of n-qubit quantum states such that when observed in the Z basis, a codeword of the classical binary linear code V is obtained, and when observed in the X basis, which is the Fourier transform of the Z basis, a codeword of the classical binary linear code W is obtained

[14] .

[0056] The CNOT gate is transversal for general CSS quantum error correcting codes, but the P gate, H gate, and T gate are not necessarily transversal. Also, for general CSS quantum error correcting codes, logical quantum observation can be realized through quantum observation of a one-qubit quantum state and classical communication.

[0057] Finally, as a feature of general CSS quantum error-correcting codes, when the generator S of the stabilizer is expressed using a tensor product, only the X operator and the I operator (S X ) and Z and I operators only (S Z As a result, a general CSS quantum error-correcting code can independently correct bit flips (X errors) and phase flips (Z errors).

[0058] Cubic double-even CSS quantum error-correcting code: The weight |S| of a stabilizer generator S is defined as the number of terms in the stabilizer generator S expressed using a tensor product that are different from the I operator. A CSS quantum error-correcting code is X Weight of |S X When | is a multiple of 2, that is, |S X When |=0(mod2), it is called an even CSS quantum error-correcting code. Similarly, the generator S of all stabilizers X Weight of |S X When | is a multiple of 4, that is, |S X When |=0(mod4), the general CSS quantum error correcting code is called a quadratic double-even CSS quantum error correcting code. For a quadratic double-even CSS quantum error correcting code, P= 2 The √Z gate becomes transversal.

[0059] Finally, the generator S of all stabilizers X Weight of |S X When | is a multiple of 8, that is, |S X When |=0(mod8), the CSS quantum error correcting code is called a cubic double-even CSS quantum error correcting code

[15] . For a cubic double-even CSS quantum error correcting code, T= 4 The √Z gate becomes transversal.

[16] Examples of cubic double-even CSS quantum error correcting codes include the quantum error correcting code represented by [[15,1,3]][9] and the quantum error correcting code represented by [[49,1,5]]

[17] .

[0060] (Quantum secret sharing with secret verification) The quantum secret computation in this embodiment uses quantum secret sharing with secret verification proposed in reference [2].

[0061] Quantum secret sharing with secret verification proposed in reference [2] is used in this embodiment for the following purposes.

[0062] Share: The 1-qubit quantum state ρ input by each participant i in the quantum secret computation i is doubly encoded using a specific cubic double-even CSS quantum error-correcting code and distributed among n participants, resulting in a global logical quantum state = The purpose of creating P.

[0063] Verification: n participants jointly verify the 1-qubit quantum state ρ input by each participant i. i The purpose is to verify whether the is correctly encoded.

[0064] Reconstruction: Each participant i collects the shares corresponding to its output from n participants and constructs the output quantum state ω i The purpose is to decrypt in two steps.

[0065] Quantum secret sharing with secret verification has the following properties:

[0066] Property: Quantum secret sharing with secret verification in reference [2] is applicable to general CSS quantum error correcting codes. If the minimum distance of a general CSS quantum error correcting code is d, quantum secret sharing with secret verification is information-theoretically secure against an attacker who takes over t participants with a number of participants less than or equal to (d-1) / 2. Quantum secret sharing with secret verification is 2 -Ω(r) (where r is a security parameter) probability of failure. The number of quantum qubits required by each participant is 3n, and the number of quantum qubits to be transmitted is O(n 2 r 2 )

[0067] Note that quantum secret sharing with secret verification is performed for the one-qubit quantum state ρ i is |0> i ya|+> i It can be used to verify whether a

[0068] Explain the input and output in quantum secret sharing with secret verification.

[0069] Input: Quantum secret sharing with secret verification requires the following inputs:

[0070] · One-qubit quantum state ρ input by participant i i (or one-qubit quantum state |0> i ya|+> i ).

[0071] Agreement on certain general CSS quantum error-correcting codes.

[0072] Output: Quantum secret sharing with secret verification produces the following output:

[0073] The following verified logical quantum state distributed among n participants (however, the verification method varies depending on the input of participant i):

[0074] - The input of participant i is the one-qubit quantum state ρ i In the case of = P i (where the subscript i denotes the logical quantum state created from participant i's input).

[0075] - The input of participant i is the 1-qubit quantum state |0> i If , the auxiliary logical quantum state | = 0> i .

[0076] -Participant i's input is a 1-qubit quantum state |+> i If , the auxiliary logical quantum state | = +> i .

[0077] A shared set B records the t participants who will perform quantum computations that do not follow the protocol.

[0078] (Quantum secret sharing protocol with secret verification) Next, a quantum secret sharing protocol involving secret verification will be described. The quantum secret sharing protocol has a sharing phase, a verification phase, and a reconstruction phase. The sharing unit 110 shown in FIG. 4 executes the sharing phase, the verification unit 120 executes the verification phase, and the reconstruction unit 140 executes the reconstruction phase. Each unit executes processing in collaboration with other quantum computing devices 100.

[0079] Each stage will be explained below as 1. Sharing stage, 2. Verification stage, and 3. Reconstruction stage.

[0080] <1. Sharing stage> The one-qubit quantum state ρ input by participant i i (or one-qubit quantum state |0> i ya|+> i ) is distributed among n participants in the following ways (a) and (b). As a result, the logical quantum state = P i (or auxiliary logical quantum states | = 0> i or | = +> i ) is created. That is, at the end of the sharing phase, each participant holds a share consisting of n 1-qubit quantum states shared by n participants, including themselves.

[0081] (a) Participant i has a one-qubit quantum state ρ i is encoded into a logical n-qubit quantum state using a cubic double-even CSS quantum error-correcting code, and one qubit is kept by the participant, while n-1 qubits are shared with the other n-1 participants (this is called the first stage of encoding).

[0082] (b) Each participant encodes the 1-qubit quantum state they hold into a logical n-qubit quantum state using a cubic double-even CSS quantum error-correcting code, keeps one qubit for themselves, and shares n-1 qubits with the other n-1 participants (this is called the second encoding stage).

[0083] <2. Verification stage> The n participants jointly calculate the 1-qubit quantum state ρ i (or one-qubit quantum state |0> i ya|+> i ) is correctly encoded. The verification step is based on the quantum error correction method [2,18,1] described in

[19] . Specifically, the verification is performed as follows:

[0084] The input of participant i is the one-qubit quantum state ρ i If so, then n participants will have auxiliary logical quantum states | = 0> i or | = +> i , a logical quantum state = P i In the same way as creating a logical quantum state, = P i The quantum error is propagated to an auxiliary logical quantum state, and a logical quantum observation is performed on the auxiliary logical quantum state.

[0085] · The input of participant i is the 1-qubit quantum state |0> i In the case of , n participants have auxiliary logical quantum states | = 0> i The logical quantum state we want to verify | = 0> i The logical quantum state we want to prepare and verify in the same way as we create | = 0> i The quantum error is propagated to an auxiliary logical quantum state. Then, n participants jointly perform quantum observations of the auxiliary logical quantum state in Z basis, and through two-step decoding, the classical observations are converted into the logical quantum state | = 0> i Check whether it was applicable.

[0086] ·Participant i's input is a 1-qubit quantum state |+> i In the case of , n participants have auxiliary logical quantum states | = +> i The auxiliary logical quantum state we want to verify is | = +>i The logical quantum state we want to prepare and verify in the same way as we create | = +> i The quantum error is propagated to the auxiliary logical quantum state. Then, n participants jointly perform logical quantum observation of the auxiliary logical quantum state in the X basis, which is the Fourier transform of the Z basis, and through two-step decoding, the classical observation result is converted into the logical quantum state | = +> i Check whether it was applicable.

[0087] Regardless of the input of participant i, the shared set B is updated, which records the t participants who will perform quantum computations that do not follow the protocol in the above process. If |B| ≦ t is satisfied at the end of the verification phase (i.e., the number of quantum errors in the first stage of encoding is at most t), participant i has passed the verification phase and the protocol continues. In that case, the logical quantum state that can be decoded is = P i (or auxiliary logical quantum states | = 0> i or | = +> i ) always exists because quantum errors in the first stage of encoding and quantum errors in the second stage of encoding (we assume that there are t or fewer participants who perform quantum computations that do not follow the protocol, so there are at most t quantum errors) can be corrected using a cubic double-even CSS quantum error-correcting code. Conversely, if |B|>t is satisfied, participant i does not pass the verification stage and the protocol terminates.

[0088] <3. Reconstruction stage> Participant i performs the following quantum operation on the share corresponding to his output:

[0089] (a) Collect the shares corresponding to your output from the other n-1 participants and identify the locations of quantum errors using a cubic double-even CSS quantum error-correcting code. Specifically, identify the quantum errors introduced into your shares between the verification and reconstruction stages by t participants who may perform quantum computations that do not follow the protocol. If the number of identified quantum errors is t or less, correct the quantum errors and decrypt your shares (this corresponds to the second stage of encoding).

[0090] (b) Collect the t participants who will perform quantum computations that do not follow the protocol from participants who are not included in the recorded sharing set B, and perform erasure correction on the decoded n-2t shares using a cubic double-even CSS quantum error-correcting code to decode the shares held by the participant (corresponding to the first stage of encoding). As a result, a 1-qubit quantum state ω i is obtained as the output.

[0091] (About the gate teleportation method) Next, a gate teleportation method, which is one of the elemental technologies of quantum secret computation in this embodiment, will be described.

[0092] The gate teleportation method does not crossover for cubic double-even CSS quantum error correcting codes. = P i In fact, the gate teleportation method was first introduced in [4]. The gate teleportation method is used to operate on the logical auxiliary quantum state | = +> i It consists of the preparation of the quantum error correction code, the action of P gates and CNOT gates that are transversal to the cubic double-even CSS quantum error correcting code, logical quantum observation in the X basis obtained by Fourier transforming the Z basis, classical communication, and quantum error correction according to the classical observation results (in this case, the action of the Y gate).

[0093] The gate teleportation method has the following properties:

[0094] Using gate teleportation to convert non-traversal H-gates into logical quantum states = P i The quantum gates that make up the quantum circuit V that operates on the cubic double-even CSS quantum error-correcting codes are all transversal for the cubic double-even CSS quantum error-correcting codes. Figure 6 shows a schematic diagram of the quantum circuit V. At each participant i, the global logical quantum state = n to hold a share of P 2 In addition to the one-qubit quantum states, logical auxiliary quantum states | = +> i The number of quantum qubits required to verify is 3n.

[0095] In addition, logical quantum states = P i and logical auxiliary quantum states | = +> i Both of these have been verified using quantum secret sharing with secret verification at the input stage to the gate teleportation method.

[0096] Next, we will explain the input and output of the gate teleportation method.

[0097] Input: The gate teleportation method requires the following inputs:

[0098] · Logical quantum states verified using quantum secret sharing with secret verification = P i .

[0099] · Logical auxiliary quantum states verified using quantum secret sharing with secret verification | = +> i .

[0100] A shared set B that records the t participants who will perform quantum computations without following the protocol updated in the above process.

[0101] Output: The following outputs are obtained from the gate teleportation method.

[0102] Logical quantum state acted upon by non-traversal H gates = P i .

[0103] A shared set B that records the t participants who would perform quantum computations without following the updated protocol.

[0104] (Gate Teleportation Protocol) Next, the protocol of the gate teleportation method will be described. The protocol of the gate teleportation method has a quantum computation stage, a classical computation stage, and a quantum error correction stage. The computation unit 130 shown in FIG. 4 executes these stages in collaboration with other quantum computing devices 100. Each stage will be described below as 1. quantum computation stage, 2. classical computation stage, and 3. quantum error correction stage.

[0105] <1. Quantum Computing Stage> For each participant's share consisting of n 1-qubit quantum states shared by participant i, each of the n participants performs the following quantum operations (a) to (d). However, the logical quantum state held by each participant i at the stage of input to the gate teleportation method is = P i The set of n one-qubit quantum states that constitute the share of is called the target quantum state, and the logical auxiliary quantum state | = +> i The set of n one-qubit quantum states that make up the share of is called the control quantum state.

[0106] (a) A logical P-gate acts across both the control quantum state and the target quantum state.

[0107] (b) A logical CNOT gate acts across a control quantum state and a target quantum state.

[0108] (c) A logical P-gate acts across the target quantum state.

[0109] (d) The control quantum state is logically quantum observed in the X basis, which is the Fourier transform of the Z basis, and the classical observation results are shared among n participants using a classical authenticated broadcast channel.

[0110] <2. Classical Computation Stage> The classical observations shared among n participants constitute a codeword in the binary linear code W. Through decoding (corresponding to the second stage of encoding), the n participants jointly identify the location of a classical error. Then, using the identified classical error location, they update the shared set B, which records the t participants who will perform quantum computations that do not follow the protocol. Also, through decoding (corresponding to the first stage of encoding), the n participants jointly determine whether the classical observations result in a logical quantum state | = +> i The control quantum state is determined by checking whether the state corresponds to the condition.

[0111] <3. Quantum error correction stage> Each of the n participants performs the following quantum operation on their share, which depends on the classical observations obtained through two-stage decoding:

[0112] ·Classical observations result in logical quantum states| = +> i If this applies, nothing will happen.

[0113] ·Classical observations result in logical quantum states| = -> i If this is the case, it acts across the logical Y gate.

[0114] (Quantum secret calculation) Next, quantum secret computation executed in a system consisting of multiple quantum computing devices 100 shown in Fig. 1 will be described. In the quantum secret computation, the elemental technologies such as quantum secret sharing with secret verification and gate teleportation, which have been described above, are used. The quantum secret computation in this embodiment has the following properties.

[0115] The quantum secret computation in this embodiment can be applied to any cubic double-even CSS quantum error correcting code. When the minimum distance of a cubic double-even CSS quantum error correcting code is d, the quantum secret computation is information-theoretically secure against an attacker who takes over t participants of (d-1) / 2 or less. In addition, the quantum secret computation is -Ω(r) (where κ=n+#ancillas+#H, where #ancillas is the number of auxiliary quantum states in quantum circuit U, and #H is the number of H gates in quantum circuit U) There is a probability of failure below.

[0116] The number of quantum qubits each participant needs to hold is n 2 It is +3n and consists of the following items:

[0117] Global logical quantum state = n to hold a share of P 2 1-qubit quantum states.

[0118] 3n one-qubit quantum states for verifying the logical auxiliary quantum states that make up the quantum circuit U.

[0119] · Using gate teleportation method, we can transfer non-traversal H gates to global logical quantum states. = 3n one-qubit quantum states for acting on P.

[0120] Also, the number of quantum qubits sent by each participant is O((n+#ancillas+#H)nr 2 )

[0121] The input and output in quantum secret computation are as follows:

[0122] Input: The following inputs are required for quantum secure computation:

[0123] ·One-qubit quantum state ρ input by each participant i i .

[0124] Agreement on certain cubic double-even CSS quantum error-correcting codes.

[0125] Output: The quantum secret computation produces the following output:

[0126] In case of success, each participant i outputs a one-qubit quantum state ω i get.

[0127] In case of failure, participants following the protocol replace their shares with |0>, and the quantum secret computation is aborted after completing its execution.

[0128] Note: The result of a quantum secret computation is a global logical quantum state distributed among n participants. = Ω, then the output of participant i is = Ω i =Tr [n]\i = Ω. Also, the shared set B, which records the t participants who will perform quantum computations that do not follow the protocol, is cumulative throughout the quantum secret computation, and if |B|>t is satisfied at any stage of the quantum secret computation, the participants who perform quantum computations that follow the protocol replace their shares with |0> and abort the quantum secret computation after completing it to the end.

[0129] (Quantum Secure Computation Protocol) Next, the protocol (processing procedure) of quantum secret computation will be described. Fig. 7 shows the flow of the processing procedure. The relevant functional unit of each quantum computing device 100 among the multiple quantum computing devices 100 executes the flow shown in Fig. 7 either independently or in collaboration with the relevant functional unit of another quantum computing device 100. The elemental technologies already explained are used in the processing at each stage in the flow.

[0130] 7, the sharing unit 110 performs a sharing step in S100, and the verification unit 120 performs a verification step in S200. The calculation unit 130 performs a calculation step in S300, and the reconstruction unit 140 performs a reconstruction step in S400. The processing at each step will be described below.

[0131] <S100: Sharing Stage> For each participant, n participants execute the sharing stage of quantum secret sharing with secret verification. That is, the sharing stage is executed n times in total.

[0132] Here, by executing the sharing stage of quantum secret sharing with secret verification on the 1-qubit quantum state ρ input by participant i i a logical quantum state = P i is created.

[0133] <S200: Verification Stage> For each participant, n participants execute the verification stage of quantum secret sharing with secret verification. That is, the verification stage is executed n times in total. The specific processing procedure is as follows.

[0134] S201: n participants jointly create a shared set B that records the positions of quantum errors in the second stage of encoding of quantum secret sharing with secret verification (where the subscript i means the result of executing quantum secret sharing with secret verification on the 1-qubit quantum state ρ input by participant i). If |B i,l | > t, n participants jointly record participant l in the shared set B<​​​​​​​​​​​​​​​​​​​​​It acts on P. The specific processing procedure is as follows:

[0137] S301: The one-qubit quantum state ρ input by participant i i In the case of a P gate or a T gate acting on a one-qubit quantum state that is transversal to a cubic double-even CSS quantum error-correcting code that acts on i, each of the n participants acts on a P gate or a T gate on their own share, which consists of n one-qubit quantum states shared by participant i.

[0138] S302: The one-qubit quantum state ρ input by participant i i and the one-qubit quantum state ρ input by participant j j In the case of a CNOT gate operating on a two-qubit quantum state that is transversal for a cubic double-even CSS quantum error-correcting code operating on , each of the n participants operates the CNOT gate on their own share, which consists of 2n one-qubit quantum states shared by participants i and j.

[0139] S303: The one-qubit quantum state ρ input by participant i i In the case of an H gate that is not transversal for a cubic double-even CSS quantum error-correcting code acting on , the following operations (a), (b), and (c) are performed.

[0140] (a) Participant i is in the one-qubit quantum state |+> i Prepare a logical auxiliary quantum state | using quantum secret sharing with secret verification = +> i Create a.

[0141] (b) n participants have a logical quantum state = P i and logical auxiliary quantum states | = +> i Execute the gate teleportation method on the

[0142] When (c)|B|>t is satisfied, the n participants assume that the classical observation results obtained through decoding correspond to the logical quantum state| = +> i and do nothing to their own shares.

[0143] S304: Auxiliary quantum state |0> for implementing the quantum circuit U i or|+> i is required, select the participant i not included in the shared set B that records the t participants who will perform quantum calculations not following the protocol using the shared randomness source, and participant i prepares the one - qubit quantum state |0> i or|+> i and use quantum secret sharing with secret verification to create the logical auxiliary quantum state| = ​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​⊆B i,j Create | ~ B i,j If |≦t is satisfied, participant i corrects the identified quantum error and decodes his / her share (corresponding to the second stage of encoding). As a result, participant i has the quantum state  ̄ω i We get as output | ~ B i,j If |>t is satisfied, participant i records participant j in a shared set B that records t participants who will perform quantum computations that do not follow the protocol.

[0148] S403: Participant i collects from participant j not included in the shared set B, which records t participants who will perform quantum computations that do not follow the protocol, and performs erasure correction on the decrypted n-2t shares using a cubic double-even CSS quantum error-correcting code to decrypt the shares he holds (corresponding to the first stage of encoding). As a result, participant i obtains a 1-qubit quantum state ω i is obtained as the output.

[0149] (Effects of the embodiment) The technology of this embodiment makes it possible to avoid verification of a magic quantum state that includes quantum operations that compromise the security of quantum secret computation, and to reduce the number of quantum bits that each participant in quantum secret computation needs to hold during quantum computation compared to conventional technology.

[0150] <Additional Notes> This specification discloses at least the quantum computing device, quantum computing system, quantum computing method, and program described in the following sections. (Additional note 1) A quantum computing device in a quantum computing system in which multiple quantum computing devices connected to a network jointly perform quantum secret computation, a sharing unit that double-encodes the input quantum state using a cubic double-even CSS quantum error-correcting code and shares the encoded information obtained by the encoding with other quantum computing devices; a verification unit that verifies whether the encoded information is correctly encoded; a calculation unit that operates a quantum circuit on the encoded information; a reconstruction unit that acquires an output quantum state that is a result of operating the quantum circuit on the input quantum state; A quantum computing device comprising: (Additional note 2) The calculation unit executes a quantum gate that is not transversal to the cubic double-even CSS quantum error correcting code using a gate teleportation method in a calculation that causes the quantum circuit to operate. Item 1. The quantum computing device according to item 1. (Additional note 3) The quantum gate that is not transversal for the cubic double-even CSS quantum error correcting code is the H gate. Item 2. The quantum computing device according to claim 2. (Additional note 4) A quantum computing system comprising a plurality of quantum computing devices according to any one of claims 1 to 3. (Additional note 5) A quantum computing method executed by a quantum computing device in a quantum computing system in which a plurality of quantum computing devices connected to a network jointly perform quantum secret computation, comprising: a sharing step of doubly encoding the input quantum state using a cubic double-even CSS quantum error-correcting code and sharing the encoded information obtained by the encoding with other quantum computing devices; a verification step of verifying whether the encoded information is correctly encoded; a calculation step of performing a calculation by applying a quantum circuit to the encoded information; a reconstruction step of acquiring an output quantum state that is a result of operating the quantum circuit on the input quantum state; A quantum computing method comprising: (Additional note 6) A non-transitory storage medium storing a program for causing a computer to function as each unit in the quantum computing device according to any one of claims 1 to 3.

[0151] Although the present embodiment has been described above, the present invention is not limited to such a specific embodiment, and various modifications and changes are possible within the scope of the gist of the present invention described in the claims.

[0152] [References] [1] C. Cr´epeau, D. Gottesman, and A. Smith, "Secure multi-party quantum computation", in Proceedings of the Thirty-Fourth Annual ACM Symposium on Theory of Computing, STOC '02 (ACM, New York, NY, USA, 2002), pp. 643-652. [2] V. Lipinska, G. Murta, J. Ribeiro, and S. Wehner, "Verifiable hybrid secret sharing with few qubits", Phys. Rev. A 101, 032332 (2020). [3] B. Eastin and E. Knill, "Restrictions on Transversal Encoded Quantum Gate Sets", Phys. Rev. Lett., 102, 110502 (2009). [4] D. Gottesman and I. Chuang, "Demonstrating the viability of universal quantum computation using teleportation and single-qubit operations.", Nature, 402, pp. 390-393 (1999). [5] V. Lipinska, J. Ribeiro and S. Wehner, "Secure multiparty quantum computation with few qubits", Phys. Rev. A 102, 022405 (2020). [6] A. Steane, "Multiple-particle interference and quantum error correction", Proc. R. Soc. Lond. A. 452, pp. 2551-2577 (1996). [7] A. R. Calderbank and P. W. Shor, "Good quantum error-correcting codes exist", Phys. Rev. A 54, pp. 1098-1105 (1996). [8] G. Nebe, E. M. Rains, and N. J. A. Sloane, "The Invariants of the Clifford Groups", Designs, Codes and Cryptography, 24, pp. 99-122 (2001). [9] E. Knill, R. Laflamme and W. Zurek, "Threshold Accuracy for Quantum Computation", (1996), arXiv:quant-ph / 9610011.

[10] R. Canetti, J. Garay, G. Itkis, D. Micciancio, M. Naor and B. Pinkas, "Multicast security: a taxonomy and some efficient constructions", in IEEE INFOCOM '99. Conference on Computer Communications. Proceedings. Eighteenth Annual Joint Conference of the IEEE Computer and Communications Societies. The Future is Now (Cat. No.99CH36320), Vol. 2 (IEEE, New York, NY, USA, 1999) pp. 708-716.

[11] T. Rabin and M. Ben-Or, "Verifiable Secret Sharing and Multiparty Protocols with Honest Majority", in Proceedings of the Twenty-First Annual ACM Symposium on Theory of Computing, STOC'89 (Association for Computing Machinery, New York, NY, USA, 1989) pp. 73-85.

[12] R. Canetti, "Universally composable signature, certification, and authentication", in Proceedings. 17th IEEE Computer Security Foundations Workshop, 2004. (IEEE, Pacific Grove, CA, USA, 2004) pp. 219-233.

[13] H. Barnum, C. Crepeau, D. Gottesman, A. Smith and A. Tapp, "Authentication of quantum messages", in The 43rd Annual IEEE Symposium on Foundations of Computer Science, 2002. Proceedings. (IEEE, Vancouver, BC, Canada, 2002) pp. 449-458.

[14] M. A. Nielsen and I. L. Chuang, "Quantum Computation and Quantum Information: 10th Anniversary Edition", 10th ed. (Cambridge University Press, New York, NY, USA, 2011).

[15] K. Betsumiya and A. Munemasa, "On triply even binary codes", J. London Math. Soc. 86(1), pp. 1-16, (2012).

[16] C. Jones, P. Brooks, and J. Harrington, "Gauge color codes in two dimensions", Phys. Rev. A 93, 052332 (2016).

[17] S. Bravyi and J. Haah, "Magic-state distillation with low overhead", Phys. Rev. A 86, 052329 (2012).

[18] A. Smith, "Multi-party quantum computation", (2001), arXiv:quant-ph / 0111030.

[19] AM Steane, "Active Stabilization, Quantum Computation, and Quantum State Synthesis", Phys. Rev. Lett. 78, 2252 (1997). [Explanation of symbols]

[0153] 100 quantum computing devices 110 Total Departments 120 Certification Department 130 Computing Department 140 Reconstruction Department 200 ネットワーク 1000 ドライブdevices 1001 Recording media 1002 Supplemental Memory Device 1003 メモリ device 1004 CPU 1005 インタフェース device 1006 indicates device 1007 Force input device 1008 Output device

Claims

1. A quantum computing device in a quantum computing system in which multiple quantum computing devices connected to a network jointly perform quantum secret computation, a sharing unit that double-encodes an input quantum state using a cubic double-even CSS quantum error-correcting code and shares the encoded information obtained by the encoding with other quantum computing devices; a verification unit that verifies whether the encoded information is correctly encoded; a calculation unit that operates a quantum circuit on the encoded information; a reconstruction unit that acquires, by decoding, from the coded information obtained after the calculation unit has operated the quantum circuit on the coded information, an output quantum state that is a result of operating the quantum circuit on the input quantum state; and A quantum computing device comprising:

2. The calculation unit executes a quantum gate that is not transversal to the cubic double-even CSS quantum error correcting code using a gate teleportation method in a calculation that causes the quantum circuit to operate. The quantum computing device of claim 1 .

3. The quantum gate that is not transversal to the cubic double-even CSS quantum error correcting code is the H gate. The quantum computing device of claim 2 .

4. A quantum computing system comprising a plurality of quantum computing devices according to any one of claims 1 to 3.

5. A quantum computing method executed by a quantum computing device in a quantum computing system in which a plurality of quantum computing devices connected to a network jointly perform quantum secret computation, comprising: a sharing step of doubly encoding the input quantum state using a cubic double-even CSS quantum error-correcting code and sharing the encoded information obtained by the encoding with another quantum computing device; a verification step of verifying whether the encoded information is correctly encoded; a calculation step of performing a calculation by applying a quantum circuit to the encoded information; a reconstruction step of obtaining, by decoding, from the coded information after the quantum circuit has been applied to the coded information in the calculation step, an output quantum state that is a result of applying the quantum circuit to the input quantum state; A quantum computing method comprising:

6. A program for causing a computer to function as each unit in the quantum computing device according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Magic state distillation with low space overhead and asymptotic input count

    US20180269906A1