Computation device, computation method, and program

A quantum-classical hybrid algorithm efficiently solves LWE problems by converting them into phase estimation problems with errors, addressing the inefficiencies of existing algorithms and ensuring accurate solutions through repeated calculations.

WO2025169795A1PCT designated stage Publication Date: 2025-08-14KAWANO YASUHITO
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/002623
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-07
Filing Date
2025-01-28
Publication Date
2025-08-14

AI Technical Summary

Technical Problem

Existing algorithms for solving the Learning with Errors (LWE) problem, such as those described in Non-Patent Document 1, are not guaranteed to be polynomial-time efficient, limiting their effectiveness in solving the LWE problem even with sufficient time and memory.

Method used

A quantum-classical hybrid algorithm is proposed to efficiently solve LWE problems by converting them into a set of one-dimensional LWE-like problems, which are then transformed into phase estimation problems with errors, using quantum-classical hybrid methods to solve these problems, and finally converting the solutions back to LWE problems using classical algorithms.

Benefits of technology

The proposed method allows for the efficient solution of LWE problems, even when the initial assumptions about lattice distributions are not strictly met, by repeating calculations to eliminate errors and achieve a biased distribution towards the correct answer.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025002623_14082025_PF_FP_ABST
    Figure JP2025002623_14082025_PF_FP_ABST
Patent Text Reader

Abstract

This computation device: uses a parameter set specifying a Learning with Errors (LWE) problem; converts the LWE problem into a set of one-dimensional LWE-Like problems; converts the set of the one-dimensional LWE-Like problems into a set of error-containing phase estimation problems; solves the set of the error-containing phase estimation problems; obtains a set of solutions for the error-containing phase estimation problems; converts the set of solutions for the error-containing phase estimation problems into the solution for the LWE problem; and outputs the solution for the LWE problem.
Need to check novelty before this filing date? Find Prior Art

Description

Calculation device, calculation method, and program

[0001] The present invention relates to quantum computing technology.

[0002] The LWE (Learning with Errors) problem is a problem derived from machine learning and is also used as a candidate for next-generation quantum-safe public key cryptography. Various algorithms for solving the LWE problem have been researched. For example, Non-Patent Document 1 discloses an algorithm that reduces the LWE problem to the maximal independent set problem (MIS). This technology can be applied to solving the LWE problem by combining it with existing algorithms on quantum annealing machines that solve MIS.

[0003] Yasuhito Kawano, A reduction from an LWE problem to maximum independent set problems, Scientific Reports 13:7130 (2023) DOI 10.1038 / s41598-023-34366-7.

[0004] However, since the algorithm disclosed in Non-Patent Document 1 is not a polynomial-time reduction algorithm, it cannot be guaranteed that the algorithm disclosed in Non-Patent Document 1 can solve the LWE problem even if there is sufficient time and memory.

[0005] In view of these points, we provide a technique for efficiently solving LWE problems.

[0006] The computing device uses information for identifying an LWE problem, converts the LWE problem into a set of one-dimensional LWE-like problems, converts the set of one-dimensional LWE-like problems into a set of phase estimation problems with errors, solves the set of phase estimation problems with errors to obtain a set of solutions to the phase estimation problems with errors, converts the set of solutions to the phase estimation problems with errors into solutions to an LWE problem, and outputs the solutions to the LWE problems.

[0007] This allows us to solve the LWE problem efficiently.

[0008] FIG. 1 is a diagram illustrating a method for solving a 2-sample 1-dimensional LWE problem modulo q in this embodiment. FIG. 2 is a diagram illustrating a method for solving an m-sample n-dimensional LWE problem modulo q in this embodiment. FIG. 3 is a block diagram illustrating the overall configuration of a computing device in this embodiment. FIG. 4 is a block diagram illustrating the configuration of an LWE reduction device in this embodiment. FIG. 5 is a block diagram illustrating the configuration of a problem transformation device in this embodiment. FIG. 6 is a block diagram illustrating the configuration of a solution solving device in this embodiment. FIG. 7 is a block diagram illustrating the configuration of a solution transformation device in this embodiment. FIG. 8 is a diagram illustrating the relationship between a dual lattice, an interpolation point vector, and a subdivision point vector. FIG. 9 is a diagram illustrating a lattice formed by a dual lattice and an interpolation point vector. FIG. 10 is a diagram illustrating the relationship between a dual lattice of a lattice formed by an LWE problem, an interpolation point vector, and a label. FIG. 11 is a diagram illustrating the operation content by unitary transformation. FIG. 12A is a diagram illustrating an input quantum state. Fig. 12B is a diagram illustrating a quantum state obtained by performing a state sorting operation on an input quantum state. Fig. 12C is a diagram illustrating a quantum state obtained by performing a direct product of two 13-dimensional inverse quantum Fourier transforms on a quantum state obtained by performing a state sorting operation on an input quantum state. Fig. 13 is a diagram illustrating the relationship between observation results and labels. Fig. 14 is a diagram illustrating the relationship between the label L corresponding to the observation result z1. j FIG. 15 is a block diagram illustrating the configuration of a solution solving device according to an embodiment. FIG. 16A is a diagram illustrating a non-commutative diagram according to an embodiment. FIG. 16B is a diagram illustrating a portion of a non-commutative diagram according to an embodiment. FIG. 17 is a diagram illustrating the relationship between position and phase within a domain. FIG. 18A is a diagram illustrating a quantum state obtained by applying the direct product of two 13-dimensional inverse quantum Fourier transforms to an input quantum state. FIG. 18B is a diagram illustrating the probability distribution of the value of label L1(v'1) corresponding to observation result MO1.

[0009] An embodiment of the present invention will now be described. [Principle] First, the principle of this embodiment will be described. In this embodiment, a quantum-classical hybrid algorithm for efficiently solving LWE (Learning with Errors) problems is proposed. It is safe to assume that the quantum-classical hybrid algorithm proposed in this embodiment can efficiently solve ordinary LWE problems. In particular, under the following assumption 1, LWE problems can be efficiently solved with a high probability. Assumption 1: A hypersphere with a volume equal to the absolute value of the determinant of a lattice basis contains exactly one lattice point of the lattice. This assumption is also made in a well-known algorithm called Gaussian Heuristic, which calculates the length of a nearest neighbor vector, and is empirically considered to be approximately correct for random lattices. However, in this embodiment, this assumption 1 is not essential, and LWE problems can be efficiently solved even when assumption 1 does not strictly hold. In other words, if assumption 1 does not strictly hold, an accurate solution may not be obtained every time. However, by repeating the same calculation multiple times and selecting the most frequently occurring answer, errors can be eliminated and the correct answer can be obtained. In other words, even if Assumption 1 does not strictly hold, the LWE problem can be solved efficiently as long as the distribution of final solutions is biased toward the correct solution (for example, as long as Assumption 1 holds approximately). For example, the LWE problem can be solved efficiently if a hypersphere with the same volume as the absolute value of the determinant of the lattice basis contains almost exactly one lattice point of the lattice, regardless of the position of the hypersphere. Note that "almost one" may mean, for example, 0, 1, 2, 3, or more than 3.

[0010] <Definition of symbols> m, n, m', n': m, n, m', n' are positive integers. For example, m' satisfies m'≧m, and m'=m. For example, n'=1. α: α is a positive real number. j: j is a positive integer, and j=1,...,m'. q, q': q, q' are integers greater than 1, and satisfy 5q / 3<q'. For example, q, q' are prime numbers. Z q :Z qrepresents the quotient ring Z / qZ modulo q. Z: Z represents the set of integers. Q: Q represents the set of rational numbers. R: R represents the set of real numbers. e: e represents Napier's constant. i: i represents the imaginary unit. I m :I m represents the m × m unit matrix. |β0|: |β0| represents the absolute value of β0. ||β1||: ||β1|| represents the norm of β1. #β: #β represents the number of elements belonging to set β. det(β3): det(β3) represents the determinant of β3. β4 T :β4 T represents the transpose of β4. 〈β1,β2〉:〈β1,β2〉 represents the dot product of β1 and β2. <β1|:<β1| represents the horizontal vector β1. |β1>:|β1> represents the vertical vector β1. β1:=β2:β1:=β2 represents the definition that β1 is β2. Y [a1:a2,b1:b2] :Y [a1:a2,b1:b2] is r ows ×c olumns It represents the submatrix ranging from row a1 (including a1) to row a2 (including a2) and from column b1 (including b1) to column b2 (including b2) of matrix Y. Here, a1, a2, b1, b2, r ows , and c olumns is a positive integer, and 1≦a1<a2≦r ows , and 1≦b1<b2≦c olumns Satisfy Y [a1:a2,b1:b2] The first (or last) row (or column) in the subscript [a1:a2,b1:b2] of the [1:a2,b1:b2] Y [:a2,b1:b2] and Y [a1:a2,1:b2] Y [a1:a2,:b2] and Y [a1:rows,b1:b2] Y [a1:,b1:b2] and Y [a1:a2,b1:columns] Y [a1:a2,b1:] and Y [1:a2,1:b2] Y [:a2,:b2] and Y [a1:rows,b1:columns] Y [a1:,b1:] For example, Y [:a2,:b2] is Y [a1:a2,b1:b2] Here, the subscript "rows" means the upper left a2 × b2 matrix of "r ows" and "columns" is "c olumns " Also, Y [a1:a2,b1:b2] In the subscripts [a1:a2,b1:b2], negative values ​​mean the number of rows (or columns) from the last row (or column). [-a1:,-b1:] is Y [a1:a2,b1:b2] It means the a1×b1 matrix at the bottom right of Y [a1,b1] :Y [a1,b1] is r ows ×c olumns Represents the element in row a1, column b1 of matrix Y. Here, 1≦a1≦r ows , and 1≦b1≦c olumns γ1 mod β0:y 1 = γ1 mod β0 is expressed as γ for positive real numbers β0, γ1 and non-negative integer x1. 1 = x 1 β 0 +y 1 A positive real number y that satisfies 1 <β 0 Represents.   β1 mod β0: For real number β0 and vector β1, β1 mod β0 is the element β of vector β1. 1,1 ,...,β 1,max β for 1,1 mod β0,...,β 1,max A vector with elements mod β0 (β 1,1 mod β0,...,β 1,max mod β0), where max is a positive integer. is the element β of vector β1 1,1 ,...,β 1,max The floor function value floor(β 1,1 ),...,floor(β 1,1 ) is a vector (floor(β 1,1 ),...,floor(β 1,1 )) where the floor function value of the real number β0 represents the largest integer equal to or less than β0. represents a direct product (tensor product).

[0011] <LWE (Learning with Errors) problem> Assume that a parameter set (m, n, q, α) is given. Here, m, n, and q are called the number of samples, dimension, and modulus of the LWE problem, respectively. α is called the relative error. Let the standard deviation σ be σ = αq. N(0, σ 2 ) to Z q Let the above be a Gaussian distribution with mean 0 and standard deviation σ. Also, s∈Z q n is an n-dimensional column vector. A is an m×n matrix and a1, a2, …, a m ∈Z q n are n-dimensional row vectors. For example, a1, a2, ..., a m ∈Z q n are random row vectors. ε is a Gaussian distribution N(0,σ 2 ) is an m-dimensional column vector (error vector) with real elements that follow the Gaussian distribution N(0,σ 2 ) is a column vector chosen randomly according to t∈Z q m is an m-dimensional column vector (target vector) that satisfies the following equation (1). Here, when (A, t, q, σ) is given, equation (1) is satisfied and the elements of the error vector ε are Gaussian distributed N(0, σ 2 ) the solution s∈Z q n The problem of finding s is called the LWE problem for the parameter set (m,n,q,α). If ε is found, s is also found, so the problem of finding ε when (A,t,q,σ) is given can also be called the LWE problem for the parameter set (m,n,q,α). The difficulty of an LWE problem depends on the parameter set (m,n,q,α). If the parameter set (m,n,q,α) is the same, the difficulty of solving the LWE problem on a computer is roughly the same.

[0012] <LWE-Like Problem> In the LWE problem, all elements of the error vector ε are distributed in the same Gaussian distribution N(0,σ 2) and the elements of the target vector t and error vector ε are integer elements. A problem in which the conditions of such an LWE problem are relaxed as follows is called an LWE-like problem. ・m' number of m-dimensional error vectors ε'1, ..., ε' corresponding to m' number of LWE problems m' Each element ε' of j,μ (where j=1,...,m' and μ=1,...,m') do not follow the same standard deviation σ, but each follows the standard deviation σ' j,μ That is, the error vector ε' j Element ε' of j,μ The standard deviation σ' follows j,μ may be defined for each index j=1,...,m' and μ=1,...,m'. j and the error vector ε' j The elements of α' are allowed to be rational numbers. j,μ}j=1,...,m', μ=1,...,m'), where m', n', and q' are the number of samples, dimension, and modulus of the LWE-like problem, respectively. j,μ is the relative error. Standard deviation σ' j,μ σ' j,μ =α' j,μ Let q'. N(0,σ' j,μ 2 ) to {(t' j +z) mod q'|z∈Z} with mean 0 and standard deviation σ' j,μ Let s' be a Gaussian distribution. j ∈Z q' n' is an n'-dimensional column vector. j is an m'×n' matrix and a' j,1 ,a' j,2 ,…,a' j,m' ∈Z q' n' are n'-dimensional row vectors. For example, a' j,1 ,a' j,2 ,…,a' j,m' ∈Z q' n'are random row vectors. j ∈{(t' j +z) mod q'|z∈Z} m' is each element ε' j,μ (where j=1,...,m' and μ=1,...,m') is {(t' j +z) mod q'|z∈Z}, the Gaussian distribution N(0,σ' j,μ 2 ) is an m'-dimensional column vector (error vector) with elements according to j ∈R m' is an m'-dimensional column vector (target vector) that satisfies the following formula (2). For example, t' j is an m'-dimensional column vector t' whose elements are rational numbers and satisfy the following formula (2). j ∈Q m' is. Here, (A' j ,t' j ,q',{σ' j,μ}j=1,...,m', μ=1,...,m'), satisfy equation (2) and the error vector ε' j μ-th element ε' of j,μ is a Gaussian distribution N(0, σ' j,μ 2 ) according to ' j ∈Z q' n' The problem of finding a parameter set (m',n',q',{α' j,μ}j=1,...,m', μ=1,...,m') is called an LWE-like problem for (A' j ,t' j ,q',{σ' j,μ}j=1,...,m', μ=1,...,m') given ε' j The problem of finding a parameter set (m',n',q',{α' j,μ}j=1,...,m′,μ=1,...,m′) can be called an LWE-like problem.

[0013] <Lattice> Lattice ∧ for integer q q (X) is defined as follows: ∧ q (X):={x∈Zm |∃s"∈Z n st x≡s"X mod q} i.e., the lattice ∧ q (X) is any s"∈Z n x∈Z for which x≡s"X mod q holds m where X is a set of n m-dimensional column vectors x1,…,x n ∈Z m The set {x1,…,x n}, that is, X=[x1,…,x n ] T In other words, the lattice ∧ q (X) is the set X={x1,…,x n} vector x1,…,x n and m-dimensional vector qu1,…,qu m where u1,…,u m are m-dimensional unit vectors, where u j The j-th element of (j=1,...,m) is 1, and the other elements are 0. Lattice ∧ q The basis of (X) is X=[x1,…,x n ] T (m+n)×m matrix when It can be obtained by calculating the Hermite Normal Form (HNF) of I m is an m×m identity matrix, i.e., an (m+n)×m matrix The set of row vectors from the first row to the mth row of the Hermitian normal form of q (X)

[0014] where X=A T That is, let X be the matrix A T Then, the lattice ∧ q (A T ) becomes: ∧ q (A T ):={x∈Z m |∃s"∈Z n st x≡s"A T mod q} where (m+n) × m matrix The row vectors b1,...,b in the Hermitian normal form of m The set {b1,...,b m} is a lattice ∧ q (A T ) basis B={b1,...,b m}. Naturally, each row vector b1,...,b m The elements of are integers. For example, the lattice ∧ q (A T ) can be expressed as the following m×m matrix B: There are multiple such bases B. Using the base B, we can create a lattice ∧ q (A T ) into the lattice L(B):=∧ q (A T ) is expressed as

[0015] <Dual Lattice> Lattice ∧ q Dual lattice of (X) ∧ q ⊥ (X) is defined as follows: ∧ q ⊥ (X):={y∈Z m |<x,y> ≡0 mod q for all x∈∧ q (X)} i.e., the dual lattice ∧ q ⊥ (X) is the set of all vectors x∈∧ q About (X)<x,y> y∈Z such that ≡0 mod q m Also, the lattice ∧ q (A T ) dual lattice ∧ q ⊥ (A T ) becomes: ∧ q ⊥ (A T ):={y∈Z m |<x,y> ≡0 mod q for all x∈∧ q (A T )} where 2m×m matrix Let TM be the 2m x 2m transformation matrix used to calculate the Hermitian normal form of . [-m:,-m:] (i.e., the m×m matrix to the bottom right of the 2m×2m matrix T) Here, B - ={b - 1,…,b - m} is the dual lattice ∧ q ⊥ (A T ) base B - Naturally, each row vector b - 1,…,b - m The elements of are integers. For example, the dual lattice ∧ q ⊥ (A T ) base B - can be expressed as the following m×m matrix B. Such a basis B - There are multiple B - The superscript "-" should be written directly above the "B", but due to limitations on notation, it is written as "B - " may be written on the upper right of "B". - 1,…,b - m The superscript "-" should be written directly above the "b", but due to limitations on notation, - 1,…,b - m " is sometimes written to the upper right of "b". Base B - Using the dual lattice ∧ q ⊥ (A T ) into the dual lattice L(B - ):=∧ q ⊥ (A T ) is expressed as

[0016] Details of the above are described in the following: Reference 1: Cohen, Henri: A Course in Computational Algebraic Number Theory, Springer-Verlag, ISBN 0-387-55640-0 (1993). Reference 2: D. Micciancio and S. Goldwasser: Complexity of Lattice Problems, A Cryptographic Perspective, Kluwer Academic Publishers, ISBN: 0792376889 (2002). Reference 3: Steven D. Galbraith, Mathematics of Public Key Cryptography, Cambridge University Press, ISBN: 1107013925 (2012).

[0017] <Structure of the Method of This Embodiment> The overall method of this embodiment is shown below. Step A: Using a classical algorithm, reduce the input LWE problem to a set of phase estimation problems with errors (phase estimation with errors). Step B: Using a quantum-classical hybrid algorithm, solve all of the phase estimation problems with errors obtained in step A. Step C: Using a classical algorithm, calculate a solution to the LWE problem from the set of solutions to the phase estimation problems with errors obtained in step B.

[0018] Furthermore, Step A can be divided into two steps, Steps A1 and A2. Step A1: Reduce the input LWE problem to a set of one-dimensional LWE-like problems. Step A2: Convert the set of one-dimensional LWE-like problems obtained in Step A1 into a set of phase estimation problems with errors. The method used in Step A1 is LWE reduction. LWE reduction allows various parameters of the LWE problem to be changed. Step A1 includes a method (Step A1a) that can be applied only when the number of samples m and the dimension n of the LWE problem are m = 2 and n = 1, respectively, and a method (Step A1b) that can be applied when the number of samples m and the dimension n are arbitrary. The method in Step A1a is called the "LWE reduction in the Fibonacci setting," and the method in Step A1b is called the "LWE reduction in the extended Fibonacci setting." Step A1a (m=2 and n=1): LWE reduction in the Fibonacci setting Step A1b (any m and n): LWE reduction in the extended Fibonacci setting The LWE reduction in the Fibonacci setting is a reduction method inspired by the Fibonacci sequence. Using the LWE reduction in the Fibonacci setting, a 2-sample 1-dimensional LWE problem (m=2 and n=1) can be reduced to another 1-dimensional LWE problem with m' samples. There are no restrictions on the modulus q of LWE problems to which the LWE reduction in the Fibonacci setting can be applied, but it can only be applied to 2-sample 1-dimensional LWE problems (m=2 and n=1). This restriction on the number of samples m and the dimension n (m=2 and n=1) arises from the fact that the Fibonacci numbers form a sequence by the sum of two numbers. On the other hand, in order to remove the constraints on the number of samples m and dimension n in the LWE reduction in the Fibonacci setting, the Fibonacci n-step number, which is an extension of the Fibonacci sequence, is used to create the LWE reduction in the extended Fibonacci setting. Using the LWE reduction in the extended Fibonacci setting, an m-sample, n-dimensional LWE problem for any m and n can be reduced to another m'-sample, 1-dimensional LWE problem. The LWE reduction in the extended Fibonacci setting can be applied to LWE problems with any number of samples m and dimension n. Furthermore, there are no restrictions on the modulus q of LWE problems to which the LWE reduction in the extended Fibonacci setting can be applied.Therefore, the LWE reduction in the extended Fibonacci setting can be applied to LWE problems with any modulus q, any number of samples m, and any dimension n. However, by converting this LWE problem into an LWE problem modulo a power of 2 using the "LWE reduction in the standard setting" (see, for example, Non-Patent Document 1), and then applying the LWE reduction in the extended Fibonacci setting to the resulting LWE problem with a modulus of 2, it becomes possible to improve the efficiency of the algorithm and reduce errors.

[0019] As a result, the solution method for the LWE problem in this embodiment is as follows. <Case 1: m = 2 and n = 1 (Figure 1)> Step A1a: Using the Fibonacci setting LWE reduction, the input LWE problem (a two-sample one-dimensional LWE problem modulo q) is reduced to a set of one-dimensional LWE-like problems (two-sample one-dimensional LWE problems modulo q', i.e., m' = m = 2, n' = 1). Step A2: The set of one-dimensional LWE-like problems (two-sample one-dimensional LWE problems modulo q') obtained in Step A1a is converted into a set of phase estimation problems with errors. Step B: Using a quantum-classical hybrid algorithm, all phase estimation problems with errors obtained in Step A2 are solved. The set of solutions to the phase estimation problems with errors obtained is identical to the set of solutions to the one-dimensional LWE-like problem obtained in Step A1a. Step C: Using a classical algorithm, a solution to the LWE problem is calculated from the set of solutions to the phase estimation problems with errors obtained in Step B.

[0020] <Case 2: Arbitrary m and n (Figure 2)> Step A0: Using LWE reduction in the standard setting (see, for example, Non-Patent Document 1), convert the input LWE problem (an m-sample n-dimensional LWE problem modulo q) into an LWE problem modulo power-of-2. Note that Step A0 can be omitted. Step A1b: Using LWE reduction in the extended Fibonacci setting, reduce the input LWE problem (if Step A0 is omitted: an m-sample n-dimensional LWE problem modulo q) or the LWE problem modulo power-of-2 obtained in Step A0 (if Step A0 is executed: an m-sample n-dimensional LWE problem modulo power-of-2) to a set of 1-dimensional LWE-like problems (m-sample 1-dimensional LWE problems modulo q', i.e., m' = m, n' = 1). Step A2: Convert the set of 1D LWE-like problems (m-sample 1D LWE problems modulo q') obtained in Step A1b into a set of phase estimation problems with errors. Step B: Use a quantum-classical hybrid algorithm to solve all of the phase estimation problems with errors obtained in Step A2. The set of solutions to the phase estimation problems with errors obtained is identical to the set of solutions to the 1D LWE-like problem obtained in Step A1b. Step C: Use a classical algorithm to calculate the solution to the LWE problem from the set of solutions to the phase estimation problems with errors obtained in Step B.

[0021] <Overall Method of the Embodiment> Next, the overall method of the embodiment will be described. <Step A1> In step A1, the LWE problem described above is reduced to (A' j ,t' j ,q',{σ' j,μ}j=1,...,m,μ=1,...,m), the following equation (3) is satisfied and the error vector ε' j Element ε' of j,μ is a Gaussian distribution N(0, σ' j,μ 2 ) the solution s' j ∈Z q' n' (or, ε' j ) for the one-dimensional LWE-like problem (for the parameter set (m,n=1,q',{α' j,μ}j=1,...,m, μ=1,...,m) to generate information for reducing (transforming) the problem to a one-dimensional LWE-like problem. where t' j =[t' j,1 ,t' j,2 ,...,t' j,m ] T ∈R m For example, t' j ∈Q m' A' j =[a' j,1 ,a' j,2 ,...,a' j,m ] T and s' j ∈Z q' and ε' j =[ε' j,1 ,ε' j,2 ,...,ε' j,m ] T ∈{(t' j +z) mod q'|z∈Z} m When q' is large (for example, exponentially large), it is difficult to solve this LWE-like problem using a classical computer. Note that in step A1, it is not necessarily the case that A' j and t' j It is not necessary to calculate the vector b~ as long as information for specifying the one-dimensional LWE-like problem is generated. An example of such information is the sample point vector b~ described later. j,1 ,…,b~ j,m Here, b~ j,1 ,…,b~ j,m The superscript "~" in each of the above should be written directly above the "b", but due to limitations on notation, it is written as "b~ j,1 ,…,b~ j,m " is sometimes written to the upper right of "b". j,1 ,…,u~ j,m The same applies to other symbols such as .

[0022] <Step A2> In step A2, the set of one-dimensional LWE-like problems for j = 1,...,m in step A1 is converted into a set of phase estimation problems with errors. These phase estimation problems with errors are solved by solving the quantum state |Ψ j,t 〉 and unitary transformation (unitary operator) U j (γ) The solution s' (γ=0,1,...,q'-1) satisfies the following equation (4). j (j=1,...,m). Unlike general phase estimation problems, equation (4) is not an equality but an approximation. Here, |Ψ j,t > represents the input quantum state (quantum state) corresponding to the target vector t and j, and U j (γ) represents a unitary transformation of the phase estimation problem with errors, where γ = 0, 1,..., q'-1. The phase estimation problem with errors is solved by solving the quantum state |Ψ j,t 〉 and the unitary transformation U j (γ) (γ=0,1,...,q'-1).

[0023] We will explain equation (4) in more detail. Here, we will fix j = 1,...,m. Equation (3) for the one-dimensional LWE-like problem can be expressed as equation (5) below. Here, the sample point vector b~ j,1 ,…,b~ j,m is the lattice L(B~ j ) basis B~ j ={b~ j,1 ,...,b~ j,m} and L~ j (b~ j,1 ),...,L~ j (b~ j,m )∈Z q' is the lattice L(B~ j ) represents the label corresponding to the lattice point of the basis B~ j For example, the sample point vector b~ is expressed as an m × m matrix as follows: j,1 ,…,b~ j,m The elements of are rational numbers. L~ j (v~)∈Z q'(j'=1,...,m) is v~∈L(B~ j ) are function values. Details of these will be described later. j,1 ,…,b~ j,m is the lattice L(B~ j ) lattice points, and L~ j (b~ j,1 ),...,L~ j (b~ j,m ) is b~ j,1 ,…,b~ j,m Therefore, equation (5) is a function value of the lattice L(B~ j Any m-dimensional vector v~∈L(B~) corresponding to a lattice point of j ) can be expressed as the following equation (6). Here, the error vector ε is short, so v~∈L(B~ j ) into the lattice L(B~ j ) to vectors at or around the origin (vectors whose end points (tips) are around the origin), equation (6) can be approximated as equation (7) below. That is, the solution s' of the one-dimensional LWE-like problem j To find the set of j ) at or around the origin of the vector v~∈L(B~ j ) for j=1,...,m in Eq. (7), the solution s' j Here, for j=1,...,m, Ω j B~ j is the lattice L(B~ j ) and a grid point around the origin of the region (a set of m-dimensional vectors) Ω j ⊆Z q' m That is, choose Ω j B~ j =B R ∩L(B~ j ) is satisfied by the domain Ω j ⊆Z q' m Select Ω j B~ j ={x'B~ j ∈L(B~ j )|x'∈Ω j} and the base B~j is an m × m matrix, and B R represents the interior of a given region in m-dimensional space. If it can be approximated as in equation (7), then B R There is no limitation on the position, range, or shape of B. R is the lattice L(B~ j ) represents the interior of a given region including the origin or the area around the origin. R is the lattice L(B~ j ) may or may not include the origin. For example, B R is the volume | det(B~ j )| is the region inside the hypersphere.

[0024] Here, the set of m-dimensional vectors Ω j The uniform superposition state (quantum state) above |Ψ j,0 Define |Ψ j,0 > is expressed as the following equation (8). In addition, the superposition state |Ψ in Eq. (8) j,0 By applying a phase rotation gate (quantum rotation gate) to the quantum state |Ψ j,t > can be generated. This is called the input quantum state |Ψ j,t >Let us assume that. Equation (9) can be transformed into the following equation (10). In equation (7), v~=x'B~ j Substituting this into equation (10), we get F~ j (x"):=L~ j (x"B~ j ) is substituted, the following equation (11) is obtained. Here, the basis B~ j is an m×m matrix. In other words, the solution s' of equation (7) j The set satisfies equation (11).

[0025] The unitary transformation U for the above phase estimation problem with errors j (γ) is for any y"∈Z q' is an operator that satisfies the following equation (12) for Here, F~ j (x"):=L~ j (x"B~ j)∈Z q' is x"∈Ω j For input with label L~ j (x"B~ j ), and F~ j -1 (y") is the mapping F~ j (x"), i.e., F~ j -1 (y") is y"=L~ j (x"B~ j )∈Z q' For input x"∈Ω j It is a function that outputs #Ω j = q', then x'∈Ω j Label F~ for j (x')=L~ j (x'B~ j )∈Z q' corresponds almost one-to-one.

[0026] Next, the quantum state |Ψ expressed by equation (9) j,t > and the unitary transformation U expressed by equation (12) j (γ) As mentioned above, the quantum state |Ψ in equation (9) j,t > can be approximated as in equation (11). Furthermore, equation (11) can be transformed into the following equation (14). From equation (14), the quantum state |Ψ of equation (9) j,t >The unitary transformation U of equation (12) j (γ) The quantum state U obtained by applying j (γ) |Ψ j,t > can be approximated by the following equation (15). Here, by setting y'=y"-γ mod q' and using the relationship in equation (14), the right-hand side of equation (15) can be transformed into the following equation (16). Therefore, the quantum state to be approximated by equation (9) |Ψ j,t > and the unitary transformation U expressed by equation (12) j (γ) Therefore, the solution s' that satisfies equation (4) is j(where j=1,...,m) is the set v~=x'B~ in equation (7). j Solution s' that satisfies the given j which is a set of solutions s' for one-dimensional LWE-like problems. j That is, the set of one-dimensional LWE-like problems is the set of solutions s' for j=1,...,m that satisfy equation (4). j can be transformed into a set of error-bearing phase estimation problems.

[0027] <Step B> In Step B, the set of phase estimation problems with errors (Equation (4)) explained in Step A2 is solved to obtain s' for j=1,...,m. j First, we find the set of superposition states |Ψ in Eq. (8). j,0 >, and this superposition state |Ψ j,0 By applying a phase rotation gate to the quantum state |Ψ j,t >. Quantum state |Ψ j,t >, so s' satisfies equation (4) j As a method for identifying the phase, a "standard algorithm" for solving general phase estimation problems is known (see, for example, Reference 4). Reference 4: Nielsen and Chuang: Quantum Computation and Quantum Information, Cambridge University Press (2000). Section 5.2 "Phase Estimation"

[0028] In this embodiment, this standard algorithm is not used, and a simpler algorithm is used: j In this embodiment, first, the quantum state (input quantum state) |Ψ obtained as described above is used. j,t > State alignment operation X j and put it into quantum state X j |Ψ j,t >. State alignment operation X j That is, for any x∈Ω j X against j |x'''>=|x'''C jmod q'>. In general, X j is not necessarily a unitary transformation, but for simplicity, we use X j is defined as the following equation (17). where C j is a matrix of integer elements defined as in the following equation (18). Here, the basis B~ j , B are expressed as follows, respectively:

[0029] Next, the quantum state X obtained as described above j |Ψ j,t >Inverse quantum Fourier transform for and then put it into a quantum state. As shown in the following equation (19), this inverse quantum Fourier transform is a direct product of m q'-dimensional inverse quantum Fourier transforms.

[0030] Next, the quantum state obtained as above Observe the result z j ∈Z q' m get.

[0031] Next, the observation result z obtained as described above j Label using L j (z j B)∈Z q' Here, we obtain the label L j (v)∈Z q' is the lattice L(B):=∧ q (A T ) is the label corresponding to the grid point of the label L j (v) is the function value of v∈L(B), and is the function value of the lattice L(B~ j ) corresponding to the grid points L~ j The label L obtained in this way is the dual label of (v~). j (z j B)∈Z q' has a high probability of finding the solution s' j Therefore, the obtained label L j (z j B) Based on the solution s'j where L j (z j B) is s' j Although the probability of matching is not 1, for example, by repeating the same operation many times, multiple labels L for each j can be obtained. j (z j B), and for each j, the most frequently occurring label L j (z j B) Solve s' j Then, the solution s' is obtained with almost 1 probability. j can be obtained.

[0032] <Step C> In Step C, first, the solution s' obtained in Step B is j (j=1,...,m), Z q' The difference vector t-ε is obtained by solving the simultaneous linear equations in . The details of this process will be described later. Furthermore, using the difference vector t-ε, ​​integer q, and matrix A, a solution s∈Z that satisfies As≡t-ε mod q is obtained. q n get.

[0033] <Details of the Method of the Embodiment> Next, each step will be described in detail. <Idea of ​​Step A1 (LWE Reduction)> As mentioned above, the LWE problem is a problem in which equation (1) is satisfied and the elements of the error vector ε are distributed in a Gaussian distribution N(0, σ 2 ) is a problem of finding a solution s (or ε) that obeys the lattice ∧. q (A T ) , where the dual lattice ∧ q ⊥ (A T The quantum superposition state |Ψ0〉 corresponding to the lattice point on where: and represents a Cartesian product. [0,q) represents a half-open interval from 0 to q. That is, represents the m-dimensional half-open interval from 0 to q. The dual lattice ∧ expressed by Eq. (20) q ⊥ (A TApplying a phase rotation gate to the quantum superposition state |Ψ0〉 of the upper lattice points results in the quantum state |Ψ t 〉 represented by the following equation (21). This quantum state |Ψ t 〉 will be called the t-rotation state. Here, R c represents the region included in , and ∧ q ⊥ (A T )∩R c is assumed to be non-empty. The t-rotation state in the region R c is represented as in the following equation (22). The quantum state of equation (22) corresponds to the target vector t. Here, if t ∈ ∧ q (A T ), then |Ψ t,Rc 〉 = |Ψ 0,Rc 〉. If t is close to the lattice points of the lattice ∧ q (A T ), then |Ψ t,Rc 〉 approximates |Ψ 0,Rc [[ID=3 …]] 〉. That is, the following is satisfied. Thus, whether the target vector t is close to the lattice points of the lattice ∧ q (A T ) can be determined by whether the quantum state |Ψ t,Rc 〉 is close to the quantum state |Ψ 0,Rc 〉.

[0034] However, generally, it is difficult to find a quantum state |Ψ 0,Rc 〉 close to the quantum state |Ψ t,Rc 〉, and it is also difficult to find a target vector t close to the lattice points of the lattice ∧ q (A T ). Therefore, in order to make it easier to find such points, under the following condition 1, new points are added (interpolated) to the dual lattice ∧ q ⊥ (A T ). Condition 1: For any integer θ satisfying 0 < θ < q', and the interpolation point vectors u~ j,1 , …, u~ j,n' are selected. The interpolation point vectors u~ j,1 , …, u~j,n' The end point of the interpolation point vector u~ j,1 ,…,u~ j,n' are m-dimensional vectors, where L(B~ j ) to ∧ q ⊥ (A T )∪{u~ j,1 ,…,u~ j,n'}, the lattice L(∧ q ⊥ (A T )∪{u~ j,1 ,…,u~ j,n'}) In other words, the above-mentioned lattice L(B~ j ) is the dual lattice ∧ q ⊥ (A T ) grid points and interpolation point vector u~ j,1 ,…,u~ j,n' The dual lattice ∧ is generated based on the interpolation points of q ⊥ (A T ) grid points and interpolation point vector u~ j,1 ,…,u~ j,n' This is expressed as follows: L(B~ j ):=L(∧ q ⊥ (A T )∪{u~ j,1 ,…,u~ j,n'}) (23) Then, ∧ q ⊥ (A T )⊆L(B~ j ), so L(B~ j )∩R c Finding a point in ∧ that satisfies the given condition q ⊥ (A T )∩R c Here, the linearly independent sample point vector b~ j,1 ,…,b~ j,m' ∈L(B~ j )∩R c Select the sample point vector b~ j,1 ,…,b~ j,m'The end point of the sample point vector b~ is called the sample point. j,1 ,…,b~ j,m' are m-dimensional vectors. j,1 ,…,u~ j,n' and the sample point vector b~ j,1 ,…,b~ j,m' The elements of are not necessarily integers. That is, the interpolation point vector u~ j,1 ,…,u~ j,n' and the sample point vector b~ j,1 ,…,b~ j,m' The elements of are rational numbers. Also, the sample point vector b~ j,1 ,…,b~ j,m' Among them, m sample point vectors b~ j,1 ,…,b~ j,m B~ consisting of j ={b~ j,1 ,…,b~ j,m} is L(B~ j ) is the basis for L(B~ j ) basis B~ j For example, m × m matrix B~ j =[b~ j,1 ,…,b~ j,m ] T It can be expressed as:

[0035] c∈Z q m is the ∧ that is closest to the target vector t. q (A T ) is a column vector representing the lattice points of q (A T ) The error vector ε is ε=tc∈Z q m Therefore, t=c+ε is satisfied. Therefore, the following equation (24) holds.

[0036] b~ j,1 ,…,b~ j,m' ∈L(B~ j ), the m'-dimensional column vector of each term in equation (24) is u~ j,1 ,…,u~ j,n' ,b - j,1 ,…,b- j,m The first element of the right-hand side, 〈c, b~ j,1 〉,...,〈c,b~ j,m' 〉 is 〈c,b - j,1 〉,...,〈c,b - j,m 〉 mod q and 〈c,u~ j,1 〉,...,〈c,u~ j,n' 〉 mod q. Note that b - j,1 ,…,b - j,m ∈Z q m are m-dimensional vectors, and B - j ={b - j,1 ,…,b - j,m} is the dual lattice ∧ q ⊥ (A T ) represents a basis for the dual lattice ∧. q ⊥ (A T ) base B - j is an m×m matrix B - j =[b - j,1 ,…,b - j,m ] T It can be expressed as b - j,1 ,…,b - j,m The superscript "-" should be written directly above the "b", but due to limitations on notation, - j,1 ,…,b - j,m " is sometimes written to the upper right of "b". Similarly, the base B - j The superscript "-" should be written directly above the "B", but due to limitations on notation, it is written as "B - j " is sometimes written in the upper right corner of "B". Here, c∈∧ q (A T), so the following is satisfied. Therefore, the first element of the right-hand side of equation (24) is j,1 〉,...,〈c,b~ j,m' 〉 is 〈c,u~ j,1 〉,...,〈c,u~ j,n' 〉 mod q. Therefore, equation (24) can be expressed as an m'×n' matrix A' with integer elements. j can be expressed as the following equation (25). where: and c∈∧ q (A T ), so the following is satisfied. This means that q'〈c,u~ j,1 〉,...,q'〈c,u~ j,n' 〉 is q × integer (multiple of q). j,1 〉,...,〈c,u~ j,n' 〉 are each (q / q') × an integer. By multiplying all terms in equation (25) by (q' / q), we obtain the following equation (26). Here, all elements of the first term on the right side of equation (26) are integers. The error vector ε and the sample point vector b~ j,1 ,…,b~ j,m' Since each norm is small, the second term on the right side of equation (26) can be regarded as the error vector, and the term on the left side can be regarded as the target vector. This allows equation (26) to be regarded as equation (2) for the LWE-Like problem. This reduction method is called LWE reduction.

[0037] In this LWE reduction, there is a degree of freedom in the selection of the following parameters: Number of samples m', Dimension n', Modulus q', Interpolation point vector u~ j,1 ,…,u~ j,n' ・Sample point vector b~ j,1 ,…,b~ j,m' With these settings, we can solve the LWE problem for the parameter set (m,n,q,α) by solving the problem for another parameter set (m',n',q',{α' j}j=1,...,m') can be reduced to a set of LWE-like problems.

[0038] <Details of Step A1a (Fig. 1)> Next, we will illustrate the details of the LWE reduction (Step A1a) applicable when m = 2 and n = 1. That is, we will illustrate a method for reducing an input LWE problem (a two-sample one-dimensional LWE problem modulo q (m = 2, n = 1)) to a set of one-dimensional LWE-like problems (two-sample one-dimensional LWE problems modulo q' (m' = m = 2, n' = 1)) by LWE reduction in the Fibonacci setting.

[0039] <Fibonacci sequence> When reducing a two-sample one-dimensional LWE problem modulo q to a two-sample one-dimensional LWE problem modulo q', a vector sequence defined by the Fibonacci sequence is used. For this reason, we will first explain the basics of the Fibonacci sequence.

[0040] The Fibonacci sequence is a sequence of numbers, F0=0, F1=1, F k+1 =F k +F k-1 The sequence {F k} k=0,...,∞ Here, the 2x2 matrix Define the following:

[0041] The most famous property of the Fibonacci sequence is that when k becomes infinity, the ratio of two adjacent terms in the sequence converges to the golden number (f={(√5)+1} / 2), which satisfies the following equation (29). Furthermore, by utilizing the fact that equation (27) can be diagonalized, the general term of the Fibonacci sequence shown in equation (30) below can be obtained. This formula is called Binet's formula.

[0042] <Pisano Period> The Pisano period is a sequence of numbers modulo q {F k mod q} k=0,...,∞ The period of the sequence {F k mod q} k=0,...,∞The period of zeros that appears in the sequence is written as π~(q). For example, the Fibonacci sequence is listed from the beginning as follows: 0,1,1,2,3,5,8,13,21,34,55,89,144,233,377,610,987,1597,2584,4181,... Also, the sequence modulo 3 {F k mod 3} k=0,...,∞ If we list them from the beginning, we get the following: 0,1,1,2,0,2,2,1,0,1,1,2,0,2,2,1,0,1,1,2,0,... This sequence {F k mod 3} k=0,...,∞ Since the period of is 8, π(3) = 8. Also, this sequence {F k mod 3} k=0,...,∞ Since the period in which zeros appear is 4, π~(3)=4. π~(q) is a divisor of π(q). Note that the superscript "~" of "π~" should be written directly above the "π", but for convenience of notation, it is sometimes written diagonally above and to the right of the "π". Below are examples of the relationship between π(q) and π~(q) for q=1,...,12.

[0043] <Selection of Interpolation Point Vector and Sample Point Vector> The interpolation point vector and sample point vector are selected based on the Fibonacci sequence described above. For example, the interpolation point vector and sample point vector are selected based on the Pisano cycle described above. This will be described in detail below.

[0044] As mentioned above, Step A1a can be used when m=2 and n=1. Also, m'=m=2 and n'=1. In Step A1a, the Fibonacci sequence {F k} k=0,...,∞ element F belonging to ξυ+2 Let q' be the number of times the ξυ+2 Here, υ represents an integer equal to or greater than 0, and ξ represents a positive integer. υ and ξ may be arbitrarily determined or may be constants. For example, υ = π~(q). Note that if condition 1 is satisfied, it is not essential that υ = π~(q), but by setting υ = π~(q), the interpolation point vector u~ can be easily determined to satisfy condition 1. j,1 can be set.

[0045] Also, as mentioned above, the lattice ∧ for m=2 and n=1 q (A T ) the basis B={b1,b2} is a 3×2 matrix The set {b1, b2} is the row vectors b1 and b2 in the first and second rows of the Hermite normal form of q. For example, if q is a prime number, this Hermite normal form is expressed as the following equation (31). Here, * is a non-negative integer less than q. In this case, the row vector (1, *) in the first row of equation (31) becomes b1, and the row vector (0, q) in the second row becomes b2. For example, in this lattice ∧ q (A T ) can be expressed as the following 2x2 matrix B:

[0046] Also, the dual lattice ∧ q ⊥ (A T ) base B - Select two of the elements of the row vector in the second row that are multiples of q, and define their basis as B - 1,B - 2. Base B - 1,B - The selection of 2 is as follows:

[0047] First, a 4x2 matrix A submatrix T of the 4x4 transformation matrix T for calculating the Hermitian normal form of [-2:,-2:] (i.e., the 2x2 matrix to the bottom right of the 4x4 matrix T) is given by the following equation (32). where ω1∈Z. As mentioned before, equation (32) is the dual lattice ∧ q ⊥ (A T ) where the permutation matrix P1 is defined as in the following equation (32a). The permutation matrix P1 indicates that no permutation of elements is performed (no permutation). - Hermitian normal form HNF(B - P1) is B - and HNF(B - P1) from the right side of the permutation matrix P1 T The matrix (B- P1)P1 T Also the dual lattice ∧ q ⊥ (A T ) is also a basis for the dual lattice ∧ q ⊥ (A T ) is the basis for the following equation (33). Therefore, for an appropriate integer λ1∈Z, select η1 that can be approximated as follows: Here, f is the golden number shown in equation (29). The following equation (34) obtained for the selected η1 is used as the dual lattice ∧ q ⊥ (A T ) base B - Let's say it's 1.

[0048] Also, the permutation of the set {1,2} (permutation that swaps the elements of each column vector) is defined as permutation matrix P2. That is, permutation matrix P2 is defined as shown in the following equation (35). B - Hermitian normal form HNF(B - P2) and calculate HNF(B - From the right side of P2 T The matrix (B - P2)P2 T is expressed as the following equation (36). where ω2∈Z. Note that equation (36) is also a dual lattice ∧ q ⊥ (A T ) is also a basis for the dual lattice ∧ q ⊥ (A T ) is the basis for the following equation (37). Therefore, we select η2 that can be approximated for an appropriate integer λ2∈Z. The following equation (38) obtained for the selected η2 is converted into the dual lattice ∧ q ⊥ (A T ) base B - Let's say it's 2. jth (j=1,2) basis B - jThe vector in the k-th row (k=1,2) of b - j,κ That is, B - j ={b - j,1 ,b - j,2} and b - j,κ ∈Z 2 is.

[0049] In the following discussion, j is fixed. However, κ is not fixed. As with the Fibonacci sequence, {b - j,1 ,b - j,2} to b - j,k+1 =b - j,k +b - j,k-1 If we create a sequence of vectors that satisfy the following, it will look like this: b - j,1 , b - j,2 , b - j,1 +b - j,2 , b - j,1 +2b - j,2 ,... The sequence of this vector is expressed as follows: b - j,1 , b - j,2 , b - j,3 =b - j,1 +b - j,2 , b - j,4 =b - j,1 +2b - j,2 ,... the columns of this vector {b - j,κ} κ=1,...,∞ For this, the following equation (39) holds: Substituting k = ξυ into equation (39), we obtain the following equation (40): - j,ξυ+2 =Fξυ b - j,1 +F ξυ+1 b - j,2 (40) For example, if υ=π~(q), then F ξυ is a multiple of q, and b - j,2 Since the elements of are multiples of q (0 or q), from equation (40), b - j,ξυ+2 The elements of are also multiples of q. q ⊥ (A T ), the points where the values ​​of each coordinate are multiples of q are the dual lattice ∧ q ⊥ (A T ), so in this case the vector b - j,ξυ+2 The end point (tip) of is the dual lattice ∧ q ⊥ (A T ) lattice point. As mentioned above, it is not necessary that υ = π~(q). If υ = π~(q) is not the case, the end point is the dual lattice ∧ q ⊥ (A T ) vector b - j,ξυ+2 As shown in equation (41), the vector b - j,ξυ+2 By dividing by q', the interpolation point vector u~ that satisfies equation (22b) is obtained. j,1 In addition, the interpolation point vector u~ that satisfies equation (22b) can be obtained. j,1 Most of the interpolation point vectors u~ satisfy the above condition 1 with high probability. j,1 can be obtained. where q'=F ξυ+2 And F k+1 =F k +F k-1 Therefore, the following equation (42) is satisfied. In this case, the interpolation point vector u~ in equation (41) j,1 The interpolation points of the vector b - j,1 The end point of and vector b- j,2 At this interpolation point, the vector b - j,2 The end point of and vector b - j,1 The ratio of dividing the end point of ξυ vs. F ξυ+1 is approximately equal to the golden ratio f={(√5)+1} / 2 (equation (29)).

[0050] In addition, the subdivision point vector d~ that satisfies the following equation (43) j,1 ,…,d~ j,ξυ+1 Select . Here, the subdivision point vector d~ j,1 ,…,d~ j,ξυ+1 is b - j,1 -b - j,2 The vector d~ is the same as or opposite to the vector d~. j,1 ,…,d~ j,ξυ+1 The end points of are called subdivision points. j,τ (where τ=1,...,ξυ+1) has a length that grows exponentially with τ (approximately 1 / (1.618 τ ) at a rate of about 1 / 2.

[0051] Subdivision point vector d~ j,1 ,…,d~ j,ξυ+1 and the interpolation point vector u~ j,1 Based on and, the sample point vector b~ j,1 ,...,b~ j,m is defined. The sample point vector b~ j,1 ,...,b~ j,m is the lattice L(B~ j ):=L(∧ q ⊥ (A T )∪{u~ j,1 ,…,u~ j,n'}) (Equation (23)) j ={b~ j,1 ,...,b~ j,m}, which consists of vector b~ j,1 ,...,b~ j,m In general, m≪ξυ+1, and the subdivision point vector d~j,τ (where τ=1,...,ξυ+1) has a length that decreases exponentially with τ, so that the basis B~ j ={b~ j,1 ,...,b~ j,m}, which consists of vector b~ j,1 ,...,b~ j,m is exponentially shorter than ξυ+1. Therefore, the vector b~ j,1 ,...,b~ j,m The end points of are distributed around the origin.

[0052] Sample point vector setting example 1: In setting example 1, the subdivision point vector d~ j,1 ,…,d~ j,ξυ+1 and the interpolation point vector u~ j,1 The matrix M in the following equation (44) where du The matrix M obtained by lattice reduction of r Based on the row vector of j,1 ,...,b~ j,m is determined. For example, when m=2, the vector b~ j,1 ,b~ j,2 The lattice-reduced matrix M r Let b~ be the row vector of j,1 and b~ j,2 Let's say.

[0053] Sample point vector setting example 2: Matrix M du Without lattice reduction, the vector b~ j,1 ,...,b~ j,m In the setting example 2, the vector b~ may be set as follows: j,1 ,...,b~ j,m is defined. Matrix M du Among the row vectors of , the row vector d~ with the smallest norm j vector b~ j,1 ,b~ j,2 For example, b~ j,1 =d~ j You can also use b~ j,2 =d~ j For example, d~j =d~ j,ξυ+1 This is often the case. j,1 +Γ・d~ j The integer Γ=Γ that minimizes min Select u~ j,1 +Γ min ・d~ j vector b~ j,1 ,b~ j,2 For example, b~ j,1 =d~ j In the case of b~ j,2 =u~ j,1 +Γ min ・d~ j Then, b~ j,2 =d~ j In the case of b~ j,1 =u~ j,1 +Γ min ・d~ j Let's say.

[0054] <LWE reduction> Given sample point vector b~ j,1 ,...,b~ j,m Define an LWE-like problem for j=1,2 and μ=1,...,m. For the parameter set (m'=m=2,n'=1,q',{α' j,μ}j=1,2, μ=1,...,m) given m×1 matrix A' j , target vector t' j , standard deviation σ' j,μ is defined as follows: q'=F ξυ+2 σ' j,μ =αq'||b~ j,μ || Here, L~ j (b~ j,1 ),...,L~ j (b~ j,m )∈Z q' is the lattice L(B~ j ) represents the label corresponding to the grid point of L~ j (b~ j,1 ),...,L~ j (b~ j,m ) for any x∈Z and v~,w~∈L(B~ j), the following equations (45) and (46) are satisfied. j (xu~ j,1 )=x mod q' (45) In addition, equation (46) is L~ j (v~)=L~ j (w~), then v~-w~∈L(B - ) and v~-w~∈L(B - ) then L~ j (v~)=L~ j (w~). In other words, L~ j (v~)=L~ j (w~) and v~-w~∈L(B - ) is equivalent to the fact that, as mentioned above (Equation (23)), the subdivision point vector d~ j,1 ,…,d~ j,ξυ+1 and the interpolation point vector u~ j,1 The end points of the lattice L(B~ j ) is the grid point of the subdivision point vector d~ j,1 ,…,d~ j,ξυ+1 and the interpolation point vector u~ j,1 The label value corresponding to the end point of L~ is as follows: j (d~ j,1 )=-F1 … L~ j (d~ j,ξυ+1 )=-F ξυ+1 L~ j (u~ j,1 )=1 Furthermore, the linearity shown in the following equation (47) holds for the labels.

[0055] In this case, the solution to the LWE-like problem is as shown in the following equations (48) and (49). Here, q'〈t-ε,u~ in equation (48) j,1 〉 is a multiple of q. Because, according to the condition 1 mentioned above, q'u~ j,1 is the dual lattice ∧ q ⊥ (A T ) and t-ε is the lattice ∧ q (A T) is included in the solution s' of the LWE-like problem expressed by equation (48). j is an integer. j,μ =α||b~ j,μ Satisfies ||.

[0056] <Example of Step A1a (Fig. 1)> An example of Step A1a is shown below. Assume that the parameter set (m, n, q, α) of the input LWE problem is (m, n, q, α) = (2, 1, 5, 0.2). Here, we consider a randomly generated LWE problem where A, s, ε, and t are as follows. We will also explain an example where υ = π~(q).

[0057] <When q'=13> When υ=π~(5)=5, in step A1a, q'=F ξυ+2 =F ξπ~(5)+2 From the definition of the Fibonacci sequence, q'=F ξπ~(5)+2 =F ξπ~(5)+1 +F ξπ~(5) Furthermore, ξ can be any value as long as it is a positive integer, but here we set it to ξ = 1. Then, based on equation (27), the following equation (50) holds. Therefore, by equation (28), q'=F π~(5)+2 =F π~(5)+1 +F π~(5) =8+5=13.

[0058] Next, the base B - 1,B - First, select 2. First, as mentioned above, q (A T ) and the dual lattice ∧ q ⊥ (A T ) base B - When calculated, the following equations (51) and (52) are obtained.

[0059] Next, using the permutation matrices P1 and P2 in equations (32a) and (35), B - Hermitian normal form HNF(B - P1) and B - Hermitian normal form HNF(B -P2) is expressed by the following equations (53a) and (53b).

[0060] Therefore, HNF(B - P1) from the right side T The matrix (B - P1)P1 T and HNF(B - From the right side of P2 T The matrix (B - P2)P2 T are expressed as the following equations (53c) and (53d), respectively.

[0061] Next, we replace the elements of equation (53c) to satisfy equation (33) and obtain the basis B - 1, and then replace the elements of equation (53d) to satisfy equation (37) to obtain the basis B - 2. For example, the base B - The first and second rows of the vector b - 1,b - The elements are replaced so that the distance between the line connecting the end points of 2 and the origin satisfies the following equation (53e) to create the basis B - 1,B - Generates 2. For example, the basis B - 1,B - If you choose 2, the base B - Vector b in the first and second rows of 1 - 1,1 ,b - 1,2 The distance between the origin and the line connecting the end points of is 0.620174, and the base B - Vector b in the first and second rows of 2 - 2,1 ,b - 2,2 The distance between the line connecting the end points of the two points and the origin is 0.707107, which is close to 0.620174.

[0062] Next, the interpolation point vector u~ 1,1 ,u~ 2,1 and the sample point vector b~ 1,1,b~ 1,2 ,b~ 2,1 ,b~ 2,2 First, when q'=13, υ=π~(5)=5, and ξ=1, the interpolation point vector u~ j,1 The equation (41) expressing this is expressed as the following equation (56). Furthermore, the following equation (57) holds true from equations (28) and (50). Furthermore, from equations (54) and (55), b - 1,1 =(1,-3),b - 1,2 =(0,5),b - 2,1 =(-2,1),b - 2,2 = (5, 0). Also, q' = 13. Therefore, from equation (56), the interpolation point vector u~ j,1 are expressed as the following equations (58) and (59). That is, the interpolation point vector u~ 1,1 ,u~ 2,1 are, respectively, This is the vector in the second row divided by q'=13.

[0063] On the other hand, from equation (43), when υ = π~(5) and ξ = 1, the subdivision point vector is d~ j,1 ,…,d~ j,π~(5)+1 Since π~(5)=5, the subdivision point vector is d~ j,1 ,…,d~ j,6 Here, the row vector with the smallest norm is d~1=d~ 1,6 and d~2=d~ 2,6 is. Here, based on the above-mentioned sample point vector setting example 2, the sample point vector b 1,1 ,b~ 1,2 ,b~ 2,1 ,b~ 2,2 The setting will look like this:

[0064] Figure 8 shows the dual lattice ∧ of the above example. q ⊥ (A T ) lattice point, j=1 basis B - 1={b- 1,1 ,b - 1,2}, interpolation point vector u~ 1,1 , and the subdivision point vector d~ 1,6 9 shows the lattice L(B~ j ):=L(∧ q ⊥ (A T )∪u~ j,1 ) lattice point, and the j=1 basis B~1={b~ 1,1 ,b~ 1,2} is shown as an example.

[0065] The sample point vector b~ determined as above 1,1 ,b~ 1,2 ,b~ 2,1 ,b~ 2,2 On the other hand, when formula (2) constituting the LWE-Like problem is calculated, the following formulas (60) and (61) are obtained. Also, (σ' 1,1 , σ' 1,2 )=(1.61245, 1.61245), (σ' 2,1 , σ' 2,2 )=(1.41421, 1.84391).

[0066] <When q'=144> In the above example, ξ=1 was used, but as mentioned above, ξ can be any positive integer. If ξ=2 is used, the following equation (62) holds based on equation (27). Therefore, by equation (28), q'=F 2π~(144)+2 =F 2π~(144)+1 +F 2π~(144) =89+55=144. Note that q'=144=2 4 ×3 2 and the modulo q' is a composite number with small factors. In this way, it is easier to handle the operation when the modulo q' is a composite number with small factors. Therefore, it is desirable for the modulo q' to be a composite number.

[0067] Next, the base B - 1,B - First, we select 2. First, we use the Hermite normal form to find the lattice ∧ q (A T) and the dual lattice ∧ q ⊥ (A T ) base B - Calculating the above gives the formulas (51) and (52). Next, using the permutation matrices P1 and P2 of formulas (32a) and (35), B - Hermitian normal form HNF(B - P1) and B - Hermitian normal form HNF(B - P2) is as shown in the above equations (53a) and (53b). Therefore, HNF(B - P1) from the right side T The matrix (B - P1)P1 T and HNF(B - From the right side of P2 T The matrix (B - P2)P2 T are expressed as equations (53c) and (53d), respectively.

[0068] Next, we replace the elements of equation (53c) to satisfy equation (33) and obtain the basis B - 1, and then replace the elements of equation (53d) to satisfy equation (37) to obtain the basis B - 2. For example, the base B - The first and second rows of the vector b - 1,b - The elements are replaced so that the distance between the line connecting the end points of 2 and the origin satisfies the following equation (65) to create the basis B - 1,B - Generates 2. For example, the basis B - 1,B - If you choose 2, the base B - Vector b in the first and second rows of 1 - 1,1 ,b - 1,2 The distance between the origin and the line connecting the end points of is 0.178458, and the base B - Vector b in the first and second rows of 2 - 2,1 ,b -2,2 The distance between the line connecting the end points of the two and the origin is 0.185058, which is close to 0.186339.

[0069] Next, the interpolation point vector u~ 1,1 ,u~ 2,1 and the sample point vector b~ 1,1 ,b~ 1,2 ,b~ 2,1 ,b~ 2,2 First, when q'=144, υ=π~(5)=5, and ξ=2, the interpolation point vector u~ j,1 The equation (41) expressing this is expressed as the following equation (68). Furthermore, the following equation (69) holds true from equations (28) and (50). Furthermore, from equations (66) and (67), b - 1,1 =(1,-23),b - 1,2 =(0,5),b - 2,1 =(-22,1),b - 2,2 = (5, 0). Also, q' = 144. Therefore, from equation (68), the interpolation point vector u~ j,1 are expressed as the following equations (70) and (71). That is, the interpolation point vector u~ 1,1 ,u~ 2,1 are, respectively, This is the vector in the second row divided by q'=144.

[0070] On the other hand, from equation (43), when υ = π~(5) and ξ = 2, the subdivision point vector is d~ j,1 ,…,d~j,2π~(5)+1, and since π~(5)=5, the subdivision point vector is d~ j,1 ,…,d~ j,11 Here, the row vector with the smallest norm is d~1=d~ 1,11 and d~2=d~ 2,11 is. Here, based on the above-mentioned sample point vector setting example 2, the sample point vector b 1,1 ,b~ 1,2 ,b~2,1 ,b~ 2,2 The setting will look like this:

[0071] The sample point vector b~ determined as above 1,1 ,b~ 1,2 ,b~ 2,1 ,b~ 2,2 On the other hand, when formula (2) constituting the LWE-Like problem is calculated, the following formulas (72) and (73) are obtained. Also, (σ' 1,1 , σ' 1,2 )=(5.44059, 5.60357), (σ' 2,1 , σ' 2,2 )=(5.4037, 5.6921).

[0072] <Details of Step A1b (Figure 2)> As mentioned above, the LWE reduction in the Fibonacci setting in Step A1a can only be applied when m = 2 and n = 1. On the other hand, Step A1b illustrates the details of the LWE reduction in the extended Fibonacci setting (Step A1b), which can be applied for any m and n. That is, this illustrates a method for reducing an input LWE problem (a two-sample one-dimensional LWE problem modulo q (for any m and n)) to a set of one-dimensional LWE-like problems (m-sample one-dimensional LWE problems modulo q' (m' = m, n' = 1)) by the LWE reduction in the extended Fibonacci setting.

[0073] <Extended Fibonacci Sequence> First, we will explain the "Fibonacci n-step sequence," known as an extension of the Fibonacci sequence (extended Fibonacci sequence). The "Fibonacci n-step sequence" is a sequence in which one or more elements are 0 from the beginning, the subsequent element is 1, and the subsequent element is expressed as the sum of the n elements immediately preceding that element. However, in this embodiment, the symbol n is used to represent the dimension, and the symbol m is used to represent the number of samples. In this embodiment, the extended Fibonacci sequence is used to represent the number of samples, so to avoid confusion, the name "Fibonacci m-step sequence" is used. Here, we define the m × m matrix shown in the following equation (74).

[0074] In this case, the general term F of the Fibonacci m-step sequence k (where k=0,...,∞) is an m-dimensional vector [F k-m+2 ,...,F k ,F k+1 ] T and an m-dimensional vector [0,...,0,1] T is defined as the following equation (75). That is, the general term F of the Fibonacci m-step sequence k depends on m and k. In the following, unless there is confusion, we will consider m as fixed and define the general term of the Fibonacci m-step sequence as F k However, if you need to distinguish m, you can write the general term of the Fibonacci m-step sequence as F k (m) The modulus q in the extended Fibonacci setting is any integer greater than 1. An example of q is a power of 2, q=2 r Here, r is a positive integer. However, this does not limit the present invention. r In this case, The elements from the left end of the last row to the mrth element will be zero. For example, if m=8 and r=4, it will be as follows.

[0075] Also, the modulus q is 2 r in the case of, becomes the identity matrix. For example, if m=8, r=4, is.

[0076] In the extended Fibonacci setting, m+1 is the modulo q = 2 r It plays the role of the Pisano period in the Fibonacci setting, where the matrix The sum of the elements in the last row of G k That is, G k satisfies the following equation (76). By this definition, the sequence {G k} k=0,...,∞ We can define this sequence {G k} k=0,...,∞ is {1, m, 2m-1, 4m-3, ...}. In step A1b, the sequence {Gk} k=0,...,∞ element G belonging to ξυ Let q' be the number of G's. ξυ Here, υ represents an integer equal to or greater than 0, and ξ represents a positive integer. υ and ξ may be arbitrarily determined or may be constants. For example, υ=m+1. An example of ξ is ξ=2 r-1 However, this does not limit the present invention.

[0077] <Selection of interpolation point vector and sample point vector> The above sequence {G k} k=0,...,∞ The interpolation point vector and the sample point vector are selected based on m+1, for example. This will be described in detail below.

[0078] As mentioned above, step A1b can be used for any m and n, and m'=m and n'=1. In step A1b, the sequence {G k} k=0,...,∞ element G belonging to ξυ Let q' be the vector of the interpolation point u~. For example, υ = m+1. If condition 1 is satisfied, it is not necessary to set υ = m+1. However, by setting υ = m+1, the interpolation point vector u~ can be easily set to satisfy condition 1. j,1 can be set.

[0079] Also, as mentioned above, the (m+n) × m matrix The row vectors b1,...,b in the Hermitian normal form of m The set {b1,...,b m} is a lattice ∧ q (A T ) basis B={b1,...,b m} q=2 r In this case, all elements in the last n rows of this Hermitian normal form are zero. Here, we will express the basis B as the following matrix.

[0080] Also, as mentioned above, a 2m × m matrix The submatrix T of the 2m×2 transformation matrix T for calculating the Hermitian normal form of [-m:,-m:]But the dual lattice ∧ q ⊥ Base B of (X) - This becomes:

[0081] Dual lattice ∧ that satisfies condition 1 q ⊥ (A T ) base B - To obtain the permutation matrices P1,P2,...,P m A, B - P1,B - P2,...,B - P m The Hermitian normal form HNF(B - P1), HNF(B - P2),...,HNF(B - P m ) are selected to be the m × m matrices of the following equation (77). Here, I n represents the mn×mn identity matrix, and * m-n,n represents an mn×n matrix whose elements are non-negative integers less than q, and 0 n,m-n represents the n×mn zero matrix, and q n represents an n×n matrix whose diagonal elements are q and other elements are zero. For example, q=2 r However, this does not limit the present invention. If m is large, such permutation matrices P1, P2, ..., P m is easily found even when searching randomly. - 1=HNF(B - P1)P1 T ,B - 2=HNF(B - P2)P2 T ,...,B - m =HNF(B - P m )P m T Let us assume that B - 1,B - 2,...,B - m are the dual lattice ∧, respectively. q ⊥ (A T ) is the basis for q=2 r In this case, the base B -1,B - 2,...,B - m The elements of the last n rows of are all zero or 2. r becomes.

[0082] base B - j Let m m-dimensional row vectors that make up b - j,1 ,...,b - j,m That is, B - j is an m-dimensional vector b - j,1 ,...,b - j,m where the first m elements are b - j,1 ,...,b - j,m The sequence of vectors whose first m+ν element is the sum of the m elements immediately preceding the m+ν element is called {b - j,k} k=1,...,∞ where ν is a positive integer. Then, the following equation (78) holds. where: of Here, the interpolation point vector u~ j,1 of That is, the interpolation point vector u~ is defined as follows: j,1 Define Equation (79) can be transformed into the following equation (80). Here, the following equation (81) is satisfied. Therefore, the dual lattice ∧ q ⊥ Base B of (X) - j Interpolation point vector u~ for j,1 is the basis B - j Vector b that composes - j,1 ,...,b - j,m It exists on the m-1-dimensional hyperplane that connects the ends of

[0083] In addition, the subdivision point vector d~ that satisfies the following equation (82) j,1 ,…,d~ j,ξυ-1 For example, υ=m+1. Here, the subdivision point vector d~ j,1 ,…,d~ j,ξυ-1 is b - j,2 -b - j,1 ,...,b - j,m -b - j,1 It becomes a vector on the m-1-dimensional hyperplane created by

[0084] Subdivision point vector d~ j,1 ,…,d~ j,ξυ-1 and the interpolation point vector u~ j,1 Based on and, the sample point vector b~ j,1 ,...,b~ j,m is defined. The sample point vector b~ j,1 ,...,b~ j,m is the lattice L(B~ j ):=L(∧ q ⊥ (A T )∪{u~ j,1 ,…,u~ j,n'}) (Equation (23)) j ={b~ j,1 ,...,b~ j,m}, which consists of vector b~ j,1 ,...,b~ j,m When m≪ξυ (for example, when υ=m+1), the subdivision point vector d~ j,τ (where τ=1,...,ξυ-1) has a length that decreases exponentially with τ, so that the basis B~ j ={b~ j,1 ,...,b~ j,m}, which consists of vector b~ j,1 ,...,b~ j,m is exponentially shorter than ξυ. Therefore, the vector b~ j,1 ,...,b~ j,m The end points of are distributed around the origin.

[0085] Sample point vector setting example 3: For example, subdivision point vector d~ j,1 ,…,d~ j,ξυ-1 and the interpolation point vector u~ j,1 The matrix M in the following equation (83) where j,du The matrix M obtained by lattice reduction of j,r Based on the row vector of j,1 ,...,b~ j,m is determined. For example, the vector b~ j,1 ,...,b~ j,m The lattice-reduced matrix M j,r Let b~ be the row vector of j,1 ,...,b~ j,m Let's say.

[0086] <LWE reduction> Given sample point vector b~ j,1 ,...,b~ j,m Define an LWE-like problem for the parameter set (m'=m,n'=1,q',{α' j,μ}j=1,...,m, μ=1,...,m) j , target vector t' j , standard deviation σ' j,μ is defined as follows: j,μ =α||b~ j,μ Satisfies ||. q'=G ξυ σ' j,μ =αq'||b~ j,μ || Here, L~ j (b~ j,1 ),...,L~ j (b~ j,m )∈Z q' is the lattice L(B~ j ) represents the label corresponding to the grid point of L~ j (b~ j,1 ),...,L~ j (b~ j,m ) for any x∈Z and v~,w~∈L(B~ j) satisfies the above equations (45) and (46). j,1 ,…,d~ j,ξυ-1 and the interpolation point vector u~ j,1 The label value corresponding to the end point of L~ is as follows: j (d~ j,1 )=-G1 … L~ j (d~ j,ξυ-1 )=-G ξυ-1 L~ j (u~ j,1 )=1 Furthermore, the linearity shown in the above equation (47) holds for the labels.

[0087] In this case, the solution to the LWE-like problem is as shown in the following equations (84) and (85). Here, q〈t-ε,u~ in equation (84) j,1 〉 is a multiple of q. Because, according to the condition 1 mentioned above, q'u~ j,1 The elements of are multiples of q. Therefore, the solution s' of the LWE-like problem expressed by equation (84) j is an integer.

[0088] <Example of Step A1b (Fig. 2)> An example of Step A1b is shown below. Assume that the parameter set (m, n, q, α) of the input LWE problem is (m, n, q, α) = (4, 2, 4, 0.2). Now, consider a randomly generated LWE problem where A, s, ε, and t are as follows:

[0089] Here, we show an example where υ = m + 1 = 5. ξ can be any value as long as it is a positive integer. For example, it is preferable that ξ be a multiple of q / 2 = 2, but in this example we will set ξ = q = 4. Then, based on equation (74), the following equation (86) holds. As mentioned above, when υ=m+1, q'=G ξ(m+1) From equation (76), G for m=4 and ξ=4 ξ(m+1) Since the sum of the last line of equation (86) is 918385=5×13×71×199, we set q'=918385.

[0090] As mentioned above, the lattice ∧ q(A T ) and the dual lattice ∧ q ⊥ Base B of (X) - When calculated, the following equations (87) and (88) are obtained.

[0091] HNF(B - P1), HNF(B - P2), HNF(B - P3), HNF(B - Select permutation matrices P1, P2, P3, and P4 so that the elements of the last two rows of P1, P2, P3, and P4 are all zero or multiples of 4. For example, select permutation matrices P1, P2, P3, and P4 of the following equation (89). For the permutation matrices P1, P2, P3, and P4 in equation (89), HNF(B - P1), HNF(B - P2), HNF(B - P3), HNF(B - P4) is calculated as follows: Here, the HNF(B - P1), HNF(B - P2), HNF(B - P3), HNF(B - P4), respectively, P1 T ,P2 T ,P3 T ,P4 T The matrix applied with is as shown in the following equation (91). The elements of the last two rows of each matrix in equation (91) are all multiples of 4. - 1=HNF(B - P1)P1 T ,B - 2=HNF(B - P2)P2 T ,B - 3=HNF(B - P3)P3 T ,B - 4=HNF(B - P4)P4 T Let us assume that B - 1,B - 2,B - 3,B -4 are the dual lattices ∧ q ⊥ (A T ) is the basis of

[0092] Next, the interpolation point vector u~ j,1 (j=1,2,3,4) and sample point vector b~ j,μ (j=1,2,3,4, μ=1,...,m). First, for j=1,2,3,4, with ξ=q=4 and υ=m+1=5, When calculated, the result is the following equation (92). From equations (79) and (82), the interpolation point vector u~ j,1 (j=1,2,3,4) and subdivision point vector d~ j,1 ,…,d~j,ξ(m-1)-1 out of d~ j,17 ,d~ j,18 ,d~ j,19 These are expressed as the following equation (93). j,1 and j,1 ,…,d~j,ξ(m-1)-1 are four row vectors selected in order of smallest norm.

[0093] In this case, the vector b~ j,1 ,b~ j,2 ,b~ j,3 ,b~ j,4 is expressed as the following equation (94).

[0094] The sample point vector b~ determined as above 1,1 ,b~ 1,2 ,b~ 2,1 ,b~ 2,2 On the other hand, when calculating equation (2) that constitutes the LWE-Like problem, we get the following equations (95) to (98). Also, (σ' 1,1 , σ' 1,2 , σ' 1,3 , σ' 1,4 )=(2169.19, 6961.25, 6229.56, 212093),(σ' 2,1 , σ' 2,2 , σ'2,3 , σ' 2,4 )=(4204.07, 4978.77, 5120.35, 212103),(σ' 3,1 , σ' 3,2 , σ' 3,3 , σ' 3,4 )=(2962.14, 4908.05, 6527.02, 212102),(σ' 4,1 , σ' 4,2 , σ' 4,3 , σ' 4,4 )=(3497.63, 4362.86, 6719.15, 212112).

[0095] <Details of Step A2 (FIGS. 1 and 2)> Next, the details of the process of converting a set of one-dimensional LWE-like problems obtained by LWE reduction into a set of phase estimation problems with errors will be illustrated.

[0096] <Phase estimation problem with errors> The phase estimation problem with errors corresponding to the set of one-dimensional LWE-like problems obtained in step A1 can be solved by the unitary transformation U j (γ) (γ=0,1,...,q'-1) and quantum state |Ψ j,t 〉 is a solution s' that satisfies equation (4). j (where j=1,...,m) Solution s' of the phase estimation problem with errors j is the solution s' of the m-sample 1-dimensional LWE problem modulo q' obtained in step A1 (Fig. 1 and Fig. 2). j The general phase estimation problem is described in Reference 5. Reference 5: Nielsen and Chuang, "Quantum Computation and Quantum Information," Cambridge University Press (2000). Section 5.2 "Phase Estimation." Compared to this general phase estimation problem, the phase estimation problem with error in this form differs in the following two points. In the definition of the general phase estimation problem, the unitary transformation U j (γ)On the other hand, in the phase estimation problem with errors in this embodiment, the unitary transformation U j (γ) In the general definition of the phase estimation problem, only the approximation of equation (4) holds. j (1) Only the unitary transformation U j (γ) is U j (γ) :=(U j (1) ) γ Like, U j (1) On the other hand, in the phase estimation problem with errors in this embodiment, the unitary transformation U j (γ) Only the approximate formula (4) holds for U j (γ) (U j (1) ) γ Therefore, in this form of phase estimation problem with errors, for all γ=0,1,...,q'-1, the unitary transformation U j (γ) is given.

[0097] <Area Ω j > As mentioned above, the domain Ω j ⊆Z q' m is Ω j B~ j (Ω j B~ j The end point of the grid L(B~ j ) is a set of m-dimensional vectors (end points of m-dimensional vectors) that are the origin or lattice points around the origin of the domain Ω. j ⊆Z q' m is Ω j B~ j =B R ∩L(B~ j ) is satisfied. Ω j B~ j ={x'B~ j ∈L(B~ j )|x'∈Ω j}. Also, BR represents the interior of a given region in m-dimensional space. If it can be approximated as in equation (7), then B R There is no limitation on the position, range, or shape of B. R is the lattice L(B~ j ) represents the interior of a given region including the origin or the area around the origin. R is the lattice L(B~ j ) may or may not include the origin. For example, B R is the volume | det(B~ j )|. In this case, if Assumption 1 holds, we can prove the following Condition 2. Condition 2: For any integer γ=0,1,...,q'-1, #{x'∈Ω j |L~ j (x'B~ j )=F~ j (x')=γ}=1. Therefore, #Ω j =q', where #{x'∈Ω j |L~ j (x'B~ j )=F~ j (x')=γ} is {x'∈Ω j |F~ j (x')=γ}. That is, condition 2 is satisfied in the domain Ω j Label x' that belongs to L~ j (x'B~ j )=γ∈0,1,...,q'-1 correspond one-to-one. Note that if Assumption 1 does not hold strictly, Condition 2 does not necessarily hold strictly either. For example, depending on the value of γ, #{x'∈Ω j |L~ j (x'B~ j )=F~ j {(x')=γ} may be 1, but it may not be 1. In this case, the correct answer will not necessarily be obtained every time, but by repeating the same calculation multiple times and selecting the answer with the highest frequency, it is possible to eliminate errors and obtain the correct answer. In other words, even if condition 2 does not strictly hold, the LWE problem can be solved efficiently as long as the distribution of final solutions is biased toward the correct answer (for example, if condition 2 is approximately held).

[0098] <Input quantum state | Ψ j,t >> As mentioned above, the set of m-dimensional vectors Ω j The uniform superposition state |Ψ on j,0 Define |Ψ j,0 > is expressed as the following equation (8). The superposition state |Ψ of Eq. (8) j,0 By applying a phase rotation gate to the input quantum state |Ψ j,t > can be generated.

[0099] <Unitary transformation U j (γ) As mentioned above, the unitary transformation U j (γ) is for any y"∈Z q' is an operator that satisfies the following equation (12) for As mentioned above, F~ j (x"):=L~ j (x"B~ j )∈Z q' is x"∈Z q' m For input with label L~ j (x"B~ j ), and F~ j -1 (y") is the mapping F~ j (x"), i.e., F~ j -1 (y") is y"=L~ j (x"B~ j )∈Z q' For input x"∈Z q' m This unitary transformation U j (γ) For any γ=0,1,...,q'-1, the label y"=L~ j (x"B~ j ) is added to the square lattice Z q' m lattice point x" y" The quantum state |x"> corresponding to y"The square lattice Z is labeled with a value y"-γ mod q' that is γ smaller than y". q' m represents the operation to set the quantum state |x">y"‐γ mod q' corresponding to the lattice point x"y"‐γ mod q' of the square lattice Z q' m is Z q' It means an m-dimensional square lattice with elements

[0100] <Example of Step A2 (Figs. 1 and 2)> An example of Step A2 is shown below. Here, we show an example of the same LWE problem as the example of Step A1a. That is, the input parameter set (m, n, q, α) of the LWE problem is (m, n, q, α) = (2, 1, 5, 0.2), Also, assume that q'=13. Below, we will show an example of a phase estimation problem with an error corresponding to j=1, but a phase estimation problem with an error corresponding to j=2 can also be obtained in the same way.

[0101] First, the selection of the region Ω1 will be illustrated. As mentioned above, the region Ω1 is Ω1B~1=B R ∩L(B~1). In this example, B R The region Ω1 is selected so that it is the region inside a hypersphere (a circle in this example because m = 2) with a volume (area because m = 2 in this example) |det(B~1)|. Here, Therefore, B R If we select the region Ω1 so that the radius of Ω1B~1 is 1.26, then B R The volume (area since m=2 in this example) of is approximated to |det(B~1)|. For example, set Ω1={(1,0),(2,0),(0,1),(1,1),(2,1),(3,1),(0,2),(1,2),(2,2),(3,2),(1,3),(2,3)}. This region Ω j where x'∈Ω j Label F~1(x')=L~1(x'B~1)∈Z for 1310, in this example, #Ω1=q'-1=12, and the labels 12, 11, 5, 4, 3, 2, 10, 9, 8, 7, 1, 0, excluding 6, among the labels 0, 1, ..., 11, correspond one-to-one to the elements (1,0), (2,0), (0,1), (1,1), (2,1), (3,1), (0,2), (1,2), (2,2), (3,2), (1,3), and (2,3) of Ω1, respectively. That is, F~1(1,0)=12, F~1(2,0)=11, F~1(0,1)=5, F~1(1,1)=4, F~1(2,1)=3, F~1(3,1)=2, F~1(0,2)=10, F~1(1,2)=9, F~1(2,2)=8, F~1(3,2)=7, F~1(1,3)=1, F~1(2,3)=0. Thus, in real problems, condition 2 does not necessarily hold strictly. If condition 2 does not hold, the probability distribution of the labels will change slightly, and the correct answer may not be obtained every time. However, even in such cases, by repeating the same calculation multiple times and selecting the answer with the highest frequency, errors can be eliminated and the correct answer can be obtained.

[0102] With 8 qubits (two registers with 4 qubits each), as shown in equation (8), for x'∈Ω1={(1,0),(2,0),(0,1),(1,1),(2,1),(3,1),(0,2),(1,2),(2,2),(3,2),(1,3),(2,3)}, there is a superposition state |Ψ of |x'> 1,0 > is created as shown in the following equation (99). The superposition state |Ψ of Eq.(99) 1,0 By applying a phase rotation gate to the input quantum state |Ψ of the following equation (100a) corresponding to the target vector t, 1,t > can be generated (see equation (14)). Similarly, the superposition state |Ψ in Eq.(99) 1,0 By applying a phase rotation gate to the target vector t, the lattice point t-ε∈∧ is found. q (A T ) corresponding to the quantum state |Ψ of the following equation (100b): 1,t-ε > can be generated.

[0103] As mentioned above, the unitary transformation U1 for q'=13 and j=1 (γ) is the square lattice Z labeled y"=L~1(x"B~1) for any γ=0,1,...,12. q' m lattice point x" y" The quantum state |x"> corresponding to y" The square lattice Z is labeled with a value y"-γ mod 13 that is γ smaller than y". q' m This is the operation to make the quantum state |x">y"-γ mod 13 corresponding to the lattice point x"y"‐γ mod 13. (1) Operation by | x"> y" We illustrate the operation on the lattice L(B~1) corresponding to → |x">y"-1 mod 13, where x"∈Ω1={(1,0),(2,0),(0,1),(1,1),(2,1),(3,1),(0,2),(1,2),(2,2),(3,2),(1,3),(2,3)} and F~1(1,0)=12, F~1(2,0)=11, F~1(0,1)=5, F~1(1,1)=4, F~1(2,1)=3, F~1(3,1)=2, F~1(0,2)=10, F~1(1,2)=9, F~1(2,2)=8, F~1(3,2)=7, F~1(1,3)=1, F~1(2,3)=0. U1 (1) :|x"> y" →|x">y"‐1 mod 13 |1,0> 12 →|2,0> 11 |2,0> 11 →|0,2> 10 |0,1>5→|1,1>4 |1,1>4→|2,1>3 |2,1>3→|3,1>2 |3,1>2→|1,3>1 |0,2> 10 →|1,2>9 |1,2>9→|2,2>8 |2,2>8→|3,2>7 |3,2>7→|0,1>5 |1,3>1→|2,3>0 |2,3>0→|1,0> 12By this operation, the quantum state |x"> corresponding to each label y"∈{12, 11, 5, 4, 3, 2, 10, 9, 8, 7, 1, 0} y" is converted to the quantum state |x">y"‐1 mod 13. However, in this example, there is no quantum state |x">6 corresponding to label y"=6, so the quantum state |3,2>7 is converted to the quantum state |0,1>5. (1) and |Ψ 1,t >, the following equation (101a) holds. Also, U1 (1) and |Ψ 1,t-ε >, the following equation (101b) holds:

[0104] From equation (100b) and equation (101b), U1 (1) |Ψ 1,t-ε > and |Ψ 1,t-ε >, it can be seen that the following equation (102a) holds. From equation (102a), U1 (1) |Ψ 1,t > and|Ψ 1,t >In both cases, it can be seen that the following equation (102b) holds. For the problem considered here, the solution to equation (60) is s'1 = 9. Also, here we set j = 1, q' = 13, and γ = 1. Therefore, we can see that equation (4) holds.

[0105] Similarly, for other j and γ, the quantum state |Ψ j,t 〉 and the unitary transformation U j (γ) (γ=0,1,...,q'-1) can be defined, and the set of one-dimensional LWE-like problems can be reduced to the set of phase estimation problems with errors.

[0106] <Details of Step B (FIGS. 1 and 2)> Next, the details of the process (Step B) for solving all the phase estimation problems with errors obtained in Step A using a quantum-classical hybrid algorithm will be illustrated. As mentioned above, a "standard algorithm" is known as an algorithm for solving general phase estimation problems (see, for example, Reference 4). In this embodiment, this standard algorithm is not used, and a simpler algorithm, s', is used. j We use the following quantum algorithm to identify

[0107] <Label> The aforementioned lattice L(B):=∧ q (A T ) the label L corresponding to the grid point j (v)∈Z q' Label L j (v) is the function value of any lattice point v∈L(B) of the lattice L(B), and the lattice L(B~ j ) lattice point v~∈L(B~ j ) corresponding to the label L~ j Dual to (v~). Label L j (v) is defined as the following equation (103) for any lattice point v∈L(B). As mentioned above, u~ j,1 is the interpolation point vector. j ) at any lattice point w~∈L(B~ j ) on both sides of equation (103), j When multiplied by (w~), the following equation (104) holds. where x=L~ j If (w~), then the following equation (105) holds true from the relationship in equation (45). j (L~ j (w~)u~ j,1 )=L~ j (w~) (105) Furthermore, from equation (46), if equation (105) is satisfied, the following equation (106) holds. L~ j (w~)u~ j,1 -w~∈L(B - ) (106) where v∈L(B) and L(B -) is the dual lattice of the lattice L(B), so the following equation (107) holds: <v, L~ j (w~)u~ j,1 -w~>=0 (107) Using equation (107), equation (104) can be transformed into the following equation (108). Equation (108) is the label L in one dimension. j (v), L~ j (w~) product L j (v)・L~ j (w~) and the lattice points v∈L(B), w~∈L(B~ j ) and the inner product <v, w~>. Here, x'''∈Z q' m , y'''∈Z q' m For x'''B∈L(B), y'''B~ j ∈L(B~ j ), the following equation (109) holds from equation (108). where F j (x''):=L j (x'''B)∈Z q' and F~ j (y'''):=L~ j (y'''B~ j )∈Z q' Then, equation (109) can be transformed into the following equation (110).

[0108] <Quantum algorithm> Next, the input quantum state |Ψ j,t 〉, the solution s' of the phase estimation problem with error that satisfies equation (4) j (where j=1,...,m) First, as mentioned above, C j is defined as equation (18). Here, the matrix C j All elements of are integers, and det(C j )=q' m-1 As mentioned above, the state alignment operation X j is defined by the above equation (17). That is, the state alignment operation X jis any row vector x∈Ω j For the quantum state |x'''>, we turn it into the quantum state |x'''C j mod q'〉. That is, the input quantum state |Ψ j,t > State alignment operation X j By applying the above, the quantum state of the following equation (111) is obtained. Also, when n'=1, the solution is s' j ∈Z q' This solution s' j The quantum states of equation (11) corresponding to the possible values ​​γ=0, 1,...,q'-1 are expressed as |φ j,γ >It will look like this. where #Ω j =q', so from equations (17) and (112), for any γ∈{0,1,...,q'-1}, the quantum state |Φ j,γ 〉State alignment operation X j Quantum state X after j |Φ j,γ 〉 is expressed as the following equation (113). As described above, the direct product of m q'-dimensional inverse quantum Fourier transforms is expressed as the following equation (19). #Ω j =q', and since equations (18) and (110) are satisfied, the quantum state X j |Ψ j,γ When the direct product of m q'-dimensional inverse quantum Fourier transforms shown in equation (19) is applied to equation (114) below, the result is: Here, δ is the Kronecker delta, and if Assumption 1 holds strictly, If Assumption 1 is almost satisfied, then γ = F j When (x''') δγ, Fj(x''') is approximately 1, and γ ≠ F j When (x''') δγ, Fj(x''') becomes almost 0. Here, γ=F j If (x'') is satisfied, then for any observation x''' in equation (114), the label F j(x''') to find the value of γ (i.e., the solution s' j ) can be obtained. In addition, in the quantum state space of {|x'''>|x''''∈Ω}, the quantum state |Φ j,γ 〉(γ=0,1,...,q'-1) is an orthogonal basis. j,t 〉 is {|x'''>|x''''∈Ω j}, the quantum state |Φ j,γ 〉 (γ=0,1,...,q'-1). That is, the quantum state |Φ j,γ 〉 is the probability amplitude η j,γ Then, the input quantum state |Ψ j,t 〉 can be expressed as the following equation (115). From equations (114) and (115), the input quantum state |Ψ j,t 〉, the state alignment operation X j and the direct product of m q'-dimensional inverse quantum Fourier transforms The quantum state obtained by applying the above can be expressed as the following equation (116). The quantum state of this equation (116) When we observe, γ=F j The probability that an observation x''' that satisfies (x''') is obtained is |η j,γ | 2 Here, from equations (11) and (112), the following equation (117) is satisfied. From equation (115) and equation (117), s' j =F j (z j ) is satisfied by the observation z j Observation probability of |η j,s'j | 2 Therefore, the correct solution s' j To obtain the input quantum state |Ψ j,t 〉 to obtain the quantum state of equation (116), and observe the quantum state of equation (116) to obtain the observation result z j The process of obtaining z is repeated multiple times, and the observation result with the highest observation probability z j The label value L corresponding to j (z j B)∈Z q' Solve thej This can be done as follows.

[0109] <Execution of quantum algorithm> The solution s' is obtained by the above quantum algorithm. j The following is an example of a procedure for obtaining the quantum state. The quantum algorithm stores each quantum state in a register (quantum memory), performs quantum calculations on each quantum state stored in the register, and stores the results of the quantum calculations in the register repeatedly. This will be explained in detail below.

[0110] Input quantum state |Ψ corresponding to the one-dimensional LWE-like problem j,t > (Step B-1): Generation of the input quantum state |Ψ corresponding to the one-dimensional LWE-like problem for j=1,...,m in Step A1 j,t In this example, first, the quantum state shown in the following equation (118) is generated, and the generated quantum state is stored in a register. Under Assumption 1, the quantum state in equation (118) is labeled F~ j B with (x')=0,...,q'-1 respectively R ∩L(B~ j ) is a superposition of quantum states corresponding to the lattice points of #(B R ∩L(B~ j ))=q'.

[0111] The quantum state obtained by performing the transformation of the following equation (119) on the quantum state of equation (118) is the superposition state |Ψ of equation (8). j,0 >, and the resulting superposition state |Ψ j,0 > is stored in the register. Here, "α 1 →α 2 " is converted to α 1 α 2 The transformation in equation (119) is equivalent to the transformation in equation (120) below. where x'∈Ω j and Ω j B~ j =B R ∩L(B~ j ) and v'~=x'B~ j ∈B R ∩L(B~j Therefore, by applying the transformation of equation (119) to the quantum state of equation (118), the superposition state of equation (8) is obtained.

[0112] The superposition state |Ψ of Eq. (8) j,0 By applying a phase rotation gate to the input quantum state |Ψ j,t > can be generated.

[0113] State alignment operation X j (Step B-2): Input quantum state |Ψ of Eq. (9) j,t > State alignment operation X j and the quantum state X j |Ψ j,t > is an example of how to generate a matrix C j Inverse matrix C of j -1 can be defined as follows: C j -1 :=adj(C j ) / det(C j ) (121) where adj(C j ) is the matrix C j represents the cofactor matrix of the input quantum state |Ψ j,t >Z q' m Since the input quantum state |Ψ is expressed by the elements j,t >State alignment operation X for j is Z q' m However, as mentioned above, det(C j )=q' m-1 Therefore, Z q' m Above, the denominator of equation (121) is det(C j ) becomes 0, and the inverse matrix C j -1 does not exist. However, the inverse matrix C j -1 That is, for any y1'∈Z q' m For y1'=x1'C jmod q' and the domain Ω j If there exists x1' included in |x', it can be calculated. Therefore, as shown in the following equation (122), the quantum state |x'> is stored in the first register and the quantum state |x'C j mod q'> and store the inverse matrix C j -1 By performing quantum computation including j,t >quantum state |x'> to quantum state |x'C j mod q'> and state alignment operation X j It is possible to execute |x'>|0>→|x'>|x'C j mod q'> →|x'(+)x'C j C j -1 mod q'>|x'C j mod q'>=|0>|x'C j mod q'> (122)

[0114] Others, input quantum state |Ψ j,t > to quantum state X j |Ψ j,t There are various ways to generate a sigma. Here is an example: First, consider a set of m positive integers (k1, k2, ..., k m ), the quantum state |Ψ of the following equation (123) j,t >Define k1, k2,...,km. In addition, |Ψ j,t > The subscript "k1,k2,...,km" of k1,k2,...,km is actually "k1,k2,...,k m " (see Eq. (123)), but due to limitations on notation, it may be written as "k1, k2,..., km". Under this definition, the input quantum state |Ψ is obtained by the following two-step process (steps I and II). j,t > to quantum state X j |Ψ j,t Step I: |Ψ j,t >From|Ψ j,t>k1,k2,...,km. Step II: |Ψ j,t > Observe the upper bits of k1, k2,...,km and X j |Ψ j,t >, where Step II only succeeds probabilistically (k1, k2,..., k m (The probability of success increases when X is increased.) However, if step II fails, this can be detected. Therefore, if step II fails, step I can be executed again, and then step II can be executed. In this way, by repeating the processing of steps I and II until step II is successful, X can be reliably obtained. j |Ψ j,t > can be obtained.

[0115] Example of Step I processing: |Ψ j,t >From|Ψ j,t To generate k1, k2,...,km, we alternately copy the quantum state using the Hadamard transform (Step I-1) and correct the position of the quantum state (Step I-2). j,t >From|Ψ j,t >k1,0,...,0 and |Ψ j,t >k1,0,...,0 to |Ψ j,t >generate k1, k2,..., 0, ..., |Ψ j,t >k1,k2,...,km-1,0 to|Ψ j,t >k1, k2, ..., km are generated. The details are shown below. Step I-0: |Ψ j,t > 0,...,0 :=|Ψ j,t Step I-1: Repeat the following steps I-1-1 and I-1-2 for μ'=1, 2,..., m-1, and set |Ψ j,t >k1,...,kμ',0,...,0 to |Ψ j,t >k1,...,kμ',kμ'+1,0,...,0 are generated. Step I-1-1: The quantum state of the following equation (124) that has already been generated is set as the next operation target. Here, k <k μ'+1 |Ψ j,t>k1,...,kμ',k,0,...,0 (124) Step I-1-2: Unitary transformation U k1,...,kμ',k,0,...,0 Square root of The quantum state of equation (124) is subjected to the transformation expressed by the following equation (125). where U k1,...,kμ',k,0,...,0 defines the quantum state of equation (124) as |Ψ j,t +2 k u μ'+1 >k1,...,kμ′,k,0,...,0 (see, for example, Reference 6). μ'+1 is an m-dimensional unit vector. Reference 6: R. Beals, "Quantum computation of fourier transforms over symmetric groups," In Proceedings of the 29th annual ACM Symposium on the Theory of Computing (STOC), pages 48-53. ACM, May 1997.

[0116] Example of the process of step II: From the definition of equation (123), |Ψ j,t >k1,k2,...,km are quantum states (q'y1,...,q'y m ) is a quantum state obtained by superposing quantum states translated by Furthermore, if we look at equation (111), we find that |Ψ j,t >k1,k2,...,km is the quantum state X j |Ψ j,t 〉 to (q'y1,...,q'y m ) is almost the same as the quantum state obtained by superposing quantum states translated by |Ψ. The only difference between the two is the boundary region around them. Therefore, |Ψ j,t > k1, k2,..., km to X j |Ψ j,t To get >, |Ψ j,t>k1, k2, ..., km quantum states are generated by dividing the quantum states of each register of a group of registers (each group of registers has m registers of dimension q') that stores quantum states by q', and the registers that store the quantum states representing the quotients are observed and contracted, leaving only the m registers of dimension q' that store quantum states representing the remainder. This allows us to obtain the quantum state X j |Ψ j,t > is generated. If k1 and k2 are sufficiently large, the quantum state X in Eq. (111) j |Ψ j,t > is generated with a sufficiently large probability.

[0117] Next, the success probability of the processing in step II is expressed as |Ψ j,t >X included in k1, k2,...,km j |Ψ j,t The number of > is C j Using the constant const determined by, it can be expressed as in the following equation (126). k1,...,k m >log m + log const, then equation (126) shows that the processing in step II will succeed with a probability of 1 / e or more, where e is Napier's constant, and for any positive integer m, Note that any one of the observed quotients in step II is smaller than const / 2, or If the process of Step II fails, the correct quantum state X j |Ψ j,t If the processing of step II fails, the processing of steps I and II is repeated. The correct quantum state X j |Ψ j,t 〉 is obtained.

[0118] Step B-3: The operation of the direct product of m q'-dimensional inverse quantum Fourier transforms (QFTs) is performed on the quantum state X of equation (111) stored in m registers. j |Ψ j,t〉, the direct product of m q'-dimensional inverse quantum Fourier transforms of equation (116) is applied to the m registers. is generated.

[0119] Observation (Step B-4): Quantum state of Eq. (116) By observing, the observation result z j is obtained.

[0120] Label calculation (Step B-5): Observation result z j Using a classical computer, the observed result z j The label value L of the following equation (127) corresponding to j (z j B) and calculate the label value L j (z j B) Based on the solution s' j get. For example, the above-described steps B-1 to B-4 are repeated multiple times, and the observation result z obtained in step B-4 is j Among them, the observation result z with the highest observation probability j The label value L corresponding to j (z j B) Solve s' j Alternatively, the processes from steps B-1 to B-5 described above are repeated multiple times, and the label value L obtained in step B-5 is j (z j B) The label value L with the highest occurrence probability j (z j B) Solve s' j Let's say.

[0121] <Example of Step B (Figs. 1 and 2)> An example of Step B is shown. Here, the same example of an LWE problem as the example of Step A1a is shown. That is, the parameter set (m, n, q, α) of the input LWE problem is (m, n, q, α) = (2, 1, 5, 0.2), Also, assume that q'=13. Below, we will show an example of a phase estimation problem with an error corresponding to j=1, but a phase estimation problem with an error corresponding to j=2 can also be obtained in the same way.

[0122] Step B-1: First, the input quantum state |Ψ 1,t >. That is, using 8 qubits (2 registers with 4 qubits each), the superposition state |Ψ of equation (8) is generated. 1,0 >, this superposition state |Ψ 1,0 By applying a phase rotation gate to the input quantum state |Ψ 1,t 12A shows the input quantum state |Ψ 1,t > is shown as an example. 1,t >∈Z 13 2 and the horizontal axis of FIG. 12A is |Ψ 1,t 12A represents the first component (first-dimensional component) of |Ψ 1,t The lighter the color, the more the input quantum state |Ψ 1,t > indicates that the amplitude is large.

[0123] Step B-2: Input quantum state |Ψ of Eq. (9) j,t > State alignment operation X j and the quantum state X j |Ψ j,t In this example, the matrix C1 (equation (18)) is as follows: Therefore, the state alignment operation X1 in equation (17) becomes as follows: From this state alignment operation X1 and equation (100a), the quantum state X1|Ψ of equation (111) 1,t 〉∈Z 13 2 is expressed as the following equation (128). FIG. 12B shows the quantum state X1|Ψ 1,t The horizontal axis of FIG. 12B is X1|Ψ 1,t 〉, and the vertical axis of FIG. 12B represents X1|Ψ 1,t The lighter the color, the more the quantum state X1 |Ψ 1,t 〉 has a large amplitude.

[0124] Step B-3: The quantum state of equation (128). X1 | Ψ 1,t〉, the direct product of the 13-dimensional inverse quantum Fourier transform of equation (116) is applied. This generates the quantum state of equation (129) below. Figure 12C illustrates an example of the quantum state of equation (129). The horizontal axis of Figure 12C represents the first component of the quantum state of equation (129), and the vertical axis of Figure 12C represents the second component of the quantum state of equation (129). The lighter the color, the larger the amplitude of the quantum state of equation (129).

[0125] Step B-4: By observing the quantum state of Eq. (129), the observation result z1 = (z 1,1 ,z 1,2 )∈Z 13 2 is obtained.

[0126] Step B-5: Observation result z1 = (z 1,1 ,z 1,2 ) to calculate the label value L1(z1B) corresponding to the observation result z1. 1,1 ,z 1,2 ) and the label value L1(z1B). The horizontal axis of FIG. 13 indicates the value of the first component of z1B, and the vertical axis indicates the value of the second component of z1B. Each point represents a lattice point z1B of the lattice L(B) corresponding to the observation result z1, and the number attached to each point represents the label value L1(z1B)∈Z corresponding to each lattice point z1B. 13 For example, if the observation result is z1=(2,0), then z1B=(2,4) and L1(2,4)=9.

[0127] Step B-6: Figure 14 shows an example of the probability distribution of the value of label L1(z1B) corresponding to observation result z1. In the example of Figure 14, the probability that the value of label L1(z1B) will be 9 is 1 / 2 or more. Therefore, when the processes of steps B-1 to B-5 are repeated multiple times, the label value L1 with the highest occurrence probability is j (z j B) is 9, and we can conclude that the solution is s'1 = 9. In the example of Figure 14, the probability that the value of label L1(z1B) is 12 is also relatively high. This is because the target vector t = (1, 4) of the LWE problem handled in the example Tis close not only to the lattice point (2,4) corresponding to label L1(z1B)=9, but also to the lattice point (0,5) corresponding to label L1(z1B)=12.

[0128] <Details of Step C (Fig. 1 and Fig. 2)> Next, using a classical algorithm, the solution s' to the phase estimation problem with error obtained in Step B is j (where j=1,...,m) the set {s'1,...,s' m} to the solution s∈Z of the LWE problem q n The details of the process of calculating (step C) are illustrated below.

[0129] From the above-mentioned equation (48), the following equation (130) holds. where: is an m×m matrix with integer elements. Z q' If an inverse matrix exists for the m × m matrix U~ above, then the following equation (131) holds from equation (130). In addition, Z q' If the m × m matrix U~ does not have an inverse, then the dual lattice ∧ q ⊥ (A T )B - 1,...,B - m Select again and start the process again from step A1.

[0130] where the target vector t∈Z q m The elements of are greater than or equal to 0 and less than q. The elements of the error vector ε are Gaussian distribution N(0,σ 2 ), for example, it is greater than -q / 2 and less than q / 2. Therefore, the left side of equation (131) jth (j=1,...,m) element of (t-ε) j is -q / 2<(t-ε) j < 2q / 3. Here, Q' on the right side of equation (131) is defined as follows: Each solution s'1,...,s' of the phase estimation problem with errors obtained as above m Q corresponding to j is 0 or a small value close to 0 (Qj <2q / 3) or a large value close to q' (Q j In the former case, the only one that satisfies equation (131) for modulo q' is (t-ε) j is 0 or a small positive value close to 0 (a positive value less than 2q), and (t-ε) j =Q j Then, -q<(t-ε) j <2q. In the latter case, the only one that satisfies equation (131) for modulo q' is (t-ε) j is a negative value greater than -q, and (t-ε) j =Q j If -q, then -q<(t-ε) j <2q. That is, as shown in the following equation (132), the jth (j=1,...,m) element (t-ε) that satisfies equation (131) j can be obtained. As mentioned above, since 5q / 3 < q' is satisfied, 2q / 3 < q' - q is also satisfied. This makes it possible to find (t - ε) that satisfies equation (131).

[0131] From the above equation (1), the following equation (133) holds. Therefore, Z q If there exists an inverse element of A in , the solution s of LWE can be found based on equation (133) using (t-ε) that satisfies equation (131) obtained as above.

[0132] <Examples of Step C (FIGS. 1 and 2)> Examples of Step C are shown below. Here, examples of Step C are shown for the case where q'=13 in the example of Step A1a (FIG. 1), the case where q'=144 in the example of Step A1a (FIG. 1), and the case where q'=918385 in the example of Step A1b (FIG. 2).

[0133] <Example of Step A1a (FIG. 1) in which q'=13> In this case, equation (2) constituting the LWE-like problem becomes equations (60) and (61). Also, (σ' 1,1 , σ' 1,2)=(1.61245, 1.61245),(σ' 2,1 , σ' 2,2 )=(1.41421, 1.84391). In this case, the solutions s'1 and s'2 that satisfy equations (60) and (61) obtained by executing steps A2 and B are s'1=9 and s'2=3. In this case, ε'1 and ε'2 are respectively given by the following equation (134).

[0134] In this case, the following equation (135) holds true from equations (58), (59), and (130a). Using Hermite Normal Form, Z 13 If we calculate the inverse matrix of U~ in equation (135) in the above equation, we get the following equation (136).

[0135] Since s'1=9, s'2=3, and q'=13, the following equation (137) holds from equations (131) and (136). Therefore, the following equation (138) holds. q=5, A=[4,3] T , Substituting equation (138) into equation (133), the following equation (139) holds. Inverse of 4 on Z5 -1 Multiplying both sides of equation (139) by mod 5 gives us equation (140) below. From the first line of equation (140), we can see that the solution s of the LWE problem that satisfies equation (1) is 3.

[0136] <Example of Step A1a (FIG. 1) in which q'=144> In this case, equation (2) constituting the LWE-like problem becomes equations (72) and (73). Also, (σ' 1,1 , σ' 1,2 )=(5.44059, 5.60357), (σ' 2,1 , σ' 2,2)=(5.4037, 5.6921). In this case, the solutions s'1 and s'2 that satisfy equations (72) and (73) obtained by executing steps A2 and B are s'1=86 and s'2=26, respectively. In this case, ε'1 and ε'2 are respectively as shown in equation (141) below.

[0137] In this case, the following equation (142) holds true from equations (70), (71), and (130a). Using Hermite Normal Form, Z 13 If we calculate the inverse matrix of U~ in equation (142), we get the following equation (143).

[0138] Since s'1=86, s'2=26, and q'=144, the following equation (144) holds from equation (131) and equation (143). Therefore, the following equation (145) holds true. q=5, A=[4,3] T , Substituting equation (145) into equation (133), the following equation (146) holds. Inverse of 4 on Z5 -1 Multiplying both sides of equation (139) by mod 5 gives us equation (147) below. From the first line of equation (147), we can see that the solution s of the LWE problem that satisfies equation (1) is 3.

[0139] <Example of Step A1b (FIG. 2)> In this case, the equation (2) constituting the LWE-like problem becomes equations (95) to (98). Also, (σ' 1,1 , σ' 1,2 , σ' 1,3 , σ' 1,4 )=(2169.19, 6961.25, 6229.56, 212093),(σ' 2,1 , σ' 2,2 , σ' 2,3 , σ' 2,4)=(4204.07, 4978.77, 5120.35, 212103),(σ' 3,1 , σ' 3,2 , σ' 3,3 , σ' 3,4 )=(2962.14, 4908.05, 6527.02, 212102),(σ' 4,1 , σ' 4,2 , σ' 4,3 , σ' 4,4 )=(3497.63, 4362.86, 6719.15, 212112). In this case, the solutions s'1, s'2, s'3, s'4 that satisfy equations (95), (96), (97), and (98) obtained by executing steps A2 and B are s'1=862530, s'2=96993, s'3=470913, and s'4=55855. In this case, ε'1, ε'2, ε'3, and ε'4 are respectively as shown in equation (148) below.

[0140] In this case, the following equation (149) holds true from equations (93) and (130a). Using Hermite Normal Form, Z 918385 If we calculate the inverse matrix of U~ in equation (149) in, we get the following equation (150).

[0141] Since s'1=862530, s'2=96993, s'3=470913, s'4=55855, and q'=918385, the following equation (151) holds from equation (131) and equation (150). Therefore, the following equation (152) holds. q=4, Substituting equation (152) into equation (133), the following equation (153) holds. Here, the matrix with elements in the first and third rows of equation (153) is is the inverse matrix in Z4 In addition, the vector whose elements are the first and third lines of the right-hand side of equation (153) is Therefore, the following equation (154) holds true. In this way, the solution s of the LWE problem that satisfies equation (1) was obtained.

[0142] First Embodiment Next, a first embodiment of the present invention will be described. In the first embodiment, a computing device 1 executes the processes of steps A to C described above.

[0143] <Configuration> As illustrated in FIG. 3 , the computing device 1 of this embodiment includes an LWE reduction device 11, a problem transformation device 12, a solution-finding device 13, a solution transformation device 14, and a storage unit 15. Here, the LWE reduction device 11, the problem transformation device 12, and the solution transformation device 14 are, for example, devices obtained by loading a predetermined program into a classical computer (e.g., a von Neumann computer). Meanwhile, the solution-finding device 13 is, for example, a hybrid device that combines a device obtained by loading a predetermined program into a classical computer with a quantum computer (e.g., a gate-type quantum computer or an annealing-type quantum computer). The hybrid device may also be a device obtained by loading a predetermined program into both a classical computer and a quantum computer. Furthermore, at least one of the LWE reduction device 11, the problem transformation device 12, and the solution transformation device 14 may be a hybrid device or a quantum computer. Furthermore, the solution-finding device 13 may be a quantum computer into which a predetermined program has been loaded. Information input to the computing device 1 is stored in the storage unit 15 and is read and used as needed.

[0144] As shown in Fig. 4, the LWE reduction device 11 (computing device) of this embodiment includes a control unit 111, an interpolation point selection unit 112, and a sample point selection unit 113. The LWE reduction device 11 executes each process under the control of the control unit 111. The LWE reduction device 11 stores information obtained in each process in a memory (not shown). The information stored in this memory is read out as needed and used in each process.

[0145] As shown in Fig. 5, the problem transformation device 12 (computing device) of this embodiment has a control unit 121, a vector generation unit 122, and an input quantum state identification unit 123. The problem transformation device 12 executes each process under the control of the control unit 121. The problem transformation device 12 stores information obtained in each process in a memory (not shown). The information stored in this memory is read out as needed and used in each process.

[0146] 6 , the solution-finding device 13 (computation device) of this embodiment includes a control unit 131, an input quantum state generation unit 132, a state alignment operation unit 133, an inverse quantum Fourier transform unit 134, an observation unit 135, a label calculation unit 136, and a solution generation unit 137. The solution-finding device 13 executes each process under the control of the control unit 131. The solution-finding device 13 stores information obtained in each process in a memory (not shown). The information stored in this memory is read out as needed and used in each process.

[0147] As shown in Fig. 7, the solution conversion device 14 (calculation device) of this embodiment has a control unit 141, a difference generation unit 142, and a solution generation unit 143. The solution conversion device 14 executes each process under the control of the control unit 141. The solution conversion device 14 stores information obtained in each process in memory (not shown). The information stored in this memory is read out as needed and used in each process.

[0148] <Processing> Next, the processing of this embodiment will be described. <Preprocessing> In preprocessing, m, n, q, α, which are the parameter set for the LWE problem, and m', n', q', which are included in the parameter set for the LWE-like problem, are input to the calculation device 1 (FIG. 3) and stored in the storage unit 15 of the calculation device 1. Note that in this embodiment, an example where n' = 1 is shown, but this does not limit the present invention. Also, although not described further below, the LWE reduction device 11, problem conversion device 12, solution finding device 13, and solution conversion device 14 read at least a portion of m, n, q, α, m', n', q' from the storage unit 15 and use them in their respective processes. That is, when at least a part of m, n, q, α, m', n', q' is required for each process of the LWE reduction device 11, the problem transformation device 12, the solution finding device 13, and the solution transformation device 14, the LWE reduction device 11, the problem transformation device 12, the solution finding device 13, and the solution transformation device 14 read out the information required for each process from m, n, q, α, m', n', q' and use it for each process.

[0149] <Step A1 (FIGS. 1 and 2)> As shown in FIG. 3, a matrix A and a target vector t of an LWE problem are input to a calculation device 1, and these are then input to an LWE reduction device 11. The LWE reduction device 11 reduces an LWE problem specified by these and a parameter set (m, n, q, α) of the LWE problem to a set of one-dimensional LWE-like problems (Step A1: LWE reduction). That is, the LWE reduction device 11 uses the parameter set (m, n, q, α) of the LWE problem to be solved, the matrix A, and the target vector t, to obtain and output a set of information corresponding to m' one-dimensional LWE-like problems. In this embodiment, the set of information corresponding to the one-dimensional LWE-like problems is represented by a sample point vector b~ j,1 ,…,b~ j,m' (where j=1,...,m') is shown as an example. However, this does not limit the present invention. Details will be explained below.

[0150] As illustrated in FIG. 4, the matrix A and the target vector t are input to the interpolation point selection unit 112 of the LWE reduction device 11. For any integer θ satisfying 0 < θ < q', the interpolation point selection unit 112 selects the interpolation point vectors u~ j,1 , …, u~ j,n' that satisfy the above-described equations (22a) and (22b) and outputs them. The interpolation point vectors u~ j,1 , …, u~ j,n' are sent to the sample point selection unit 113 and the decoding device 14. In this embodiment, since n' = 1, the interpolation point selection unit 112 selects and outputs the interpolation point vector u~ j,1 , and the interpolation point vector u~ j,1 is sent to the sample point selection unit 113 and the decoding device 14.

[0151] The sample point selection unit 113 uses the interpolation point vector u~ j,1 to select and output linearly independent sample point vectors b~ j,1 , …, b~ j,m' ∈ L(B~ j ) ∩ R c . As described above, L(B~ j ) represents the lattice L(∧ q ⊥ (A T ) ∪ {u~ j,1 , …, u~ j,n'}) generated from ∧ q ⊥ (A T ) ∪ {u~ j,1 , …, u~ j,n'}. In this embodiment, since n' = 1, L(B~ j ) represents the lattice L(∧ q ⊥ (A T ) ∪ {u~ j,1}) generated from ∧ q ⊥ (A T ) ∪ {u~ j,1} (FIG. 8). The sample point vectors b~ j,1 , …, b~ j,m' (information corresponding to the one-dimensional LWE-Like problem) are sent to the problem conversion device 12.

[0152] <Step A2 (FIGS. 1 and 2)> The problem transformation device 12 receives the sample point vector b~ j,1 ,…,b~ j,m' (information corresponding to a set of one-dimensional LWE-like problems) and a target vector t are input. The problem transformation device 12 transforms the sample point vector b j,1 ,…,b~ j,m' (where j=1,...,m') is converted into a set of phase estimation problems with errors, and information corresponding to the set of phase estimation problems with errors is obtained and output. In this embodiment, the information corresponding to the set of phase estimation problems with errors is j,t , m') (where j=1,...,m') is used as an example. However, this does not limit the present invention. Details will be explained below.

[0153] As illustrated in FIG. 5, the sample point vector b j,1 ,…,b~ j,m' is input to the vector generation unit 122 and the input quantum state identification unit 123 of the problem transformation device 12. The vector generation unit 122 j B~ j =B R ∩L(B~ j ) is a set (domain) of m-dimensional vectors that satisfy j ⊆Z q' m As mentioned above, B~ j is the lattice L(B~ j ) represents the m × m matrix that represents the basis of the sample point vector b~ j,1 ,…,b~ j,m' m vectors b~ contained in j,1 ,...,b~ j,m is the base B~ j are m vectors of dimension m that make up B R represents the interior of a given region. A set of m-dimensional vectors Ω j is sent to the input quantum state identification unit 123. The target vector t is also input to the input quantum state identification unit 123. The input quantum state identification unit 123 identifies the sample point vector b j,1 ,…,b~ j,m', a target vector t and a set of m-dimensional vectors Ω j Using the input quantum state |Ψ of the above equation (9), j,t > and outputs information that identifies the input quantum state |Ψ j,t An example of information that specifies the vertical vector |Ψ j,t >. The input quantum state |Ψ j,t The information specifying the problem is sent to the solver 13 .

[0154] <Step B (FIGS. 1 and 2)> As shown in FIG. 6, the solution-finding device 13 receives the input quantum state |Ψ j,t > information that identifies the sample point vector b~ j,1 ,…,b~ j,m' , and matrix A. The solver 13 calculates the input quantum state |Ψ j,t >, and solve the set of error-containing phase estimation problems (equation (4)) corresponding to j The solution s' is obtained. j To obtain the set of j (γ) This information is not necessary.

[0155] In this embodiment, first, the input quantum state generation unit 132 of the solution-finding device 13 calculates the superposition state |Ψ of equation (8). j,0 > and generates the input quantum state |Ψ j,t >, the superposition state |Ψ j,0 By applying a phase rotation gate to the input quantum state |Ψ j,t > is generated (step B-1).

[0156] Next, the state alignment operation unit 133 adjusts the input quantum state |Ψ generated by the input quantum state generation unit 132. j,t > State alignment operation X j and put it into quantum state X j |Ψ j,t >. State alignment operation X j is a quantum operation defined by the above-mentioned equation (17). For example, the state alignment operation unit 133 calculates the sample point vector b j,1 ,…,b~ j,m'and C shown in equation (18) using matrix A. j and state alignment operation X j (Step B-2).

[0157] Next, the inverse quantum Fourier transform unit 134 converts the quantum state X j |Ψ j,t >, the inverse quantum Fourier transform of the above equation (19) and then put it into a quantum state. (Step B-3).

[0158] Next, the observation unit 135 detects the quantum state obtained as described above. Observe the result z j Observation result z j is sent to the label calculation unit 136 (step B-4).

[0159] The label calculation unit 136 calculates the observation result z j Using the aforementioned label L j (z j B) and output the label L j (z j B) is sent to the solution generating unit 137 (step B-5).

[0160] The solution generator 137 receives the label L j (z j B) is input. As mentioned above, the label L j (z j B) has a high probability of finding the solution s' j Therefore, the obtained label L j (z j B) Using the solution s' j For example, the solution generating unit 137 repeatedly executes the processes from step B-1 to step B-5 until a predetermined termination condition is met, and obtains the label L j (z j B) Based on the solution s' j For example, the solution generating unit 137 obtains and outputs the label L that appears most frequently for each j. j (z j B) Solve s' jThe termination condition may be, for example, repeating the processes from step B-1 to step B-5 a predetermined number of times, or outputting the label L with the highest frequency of appearance for each j. j (z j The difference in frequency between the solution s' and the label with the second highest frequency of occurrence may be greater than a predetermined value. j is sent to the solution conversion unit 14 (step B-6).

[0161] <Step C (FIGS. 1 and 2)> The solution conversion unit 14 converts the solution s' for each j into j , interpolation point vector u~ j,1 , and matrix A are input. The solution conversion device 14 converts the input solution s' j and the interpolation point vector u~ j,1 Calculate the solution s of the LWE problem from the set of j are input to the difference generation unit 142. The difference generation unit 142 calculates the input solutions s'1,...,s' m' m solutions s'1,...,s' out of m and the interpolation point vector u~ 1,1 ,...,u~ m,1 The difference vector t-ε of equation (131) is obtained and output. q' If the m × m matrix U~ does not have an inverse, then the dual lattice ∧ q ⊥ (A T )B - 1,...,B - m Then, the difference generating unit 142 selects again each element (t-ε) of the difference vector t-ε according to, for example, equation (132), and starts the process again from step A1. j (For example, j=1, . . . , m) can be obtained. The difference vector t−ε is sent to the solution generating unit 143.

[0162] The solution generating unit 143 uses the difference vectors t-ε, ​​q, and A to obtain and output a column vector s that satisfies As≡t-ε mod q. This column vector s is a solution to the LWE problem.

[0163] <Features of this embodiment> In this embodiment, the LWE problem is reduced to a set of one-dimensional LWE-like problems (Step A1), the resulting set of one-dimensional LWE-like problems is reduced to a set of phase estimation problems with errors (Step A2), solutions to each of the set of phase estimation problems with errors are found (Step B), and a solution to the LWE problem is calculated from the solutions to the resulting set of phase estimation problems with errors (Step C). This allows the LWE problem to be solved efficiently.

[0164] [First Modification of the First Embodiment] In the first embodiment, in step A1, the LWE reduction device 11 calculates the sample point vector b~ as information corresponding to the one-dimensional LWE-like problem. j,1 ,…,b~ j,m' However, in step A1, the LWE reduction device 11 may generate and output other information as information corresponding to the one-dimensional LWE-like problem.

[0165] For example, the LWE reduction device 11 includes a matrix generation unit 114, which generates the input sample point vector b j,1 ,…,b~ j,m' Using the matrix may be generated and output (FIG. 4).

[0166] For example, the LWE reduction device 11 has a target vector generation unit 115, and the target vector generation unit 115 generates an input sample point vector b j,1 ,…,b~ j,m' Using the target vector may be generated and output (FIG. 4).

[0167] For example, the LWE reduction device 11 includes a parameter generation unit 116, which generates an input sample point vector b j,1 ,…,b~ j,m' and α, for j=1,...,m' and μ=1,...,m', α' j,μ =α||b~ j,μ However, as mentioned above, σ' j,μ =αq'||b~ j,μ ||=q'α' j,μis satisfied.

[0168] [Modification Example 2 of the First Embodiment] In the first embodiment, in order to efficiently solve the LWE problem, in step A1, n' = 1, and the LWE reduction device 11 reduced the LWE problem to a set of one-dimensional LWE-Like problems. However, without being limited to n' = 1, the LWE reduction device 11 may reduce the LWE problem to a set of n'-dimensional LWE-Like problems. The processing of step A1 in this case is the same as the processing of step A1 in the first embodiment, except that it is not limited to n' = 1. That is, for any integer θ satisfying 0 < θ < q', the LWE reduction device 11 and satisfies the interpolation point vector u~ j,1 ,…,u~ j,n' is selected, and linearly independent sample point vectors b~ j,1 ,…,b~ j,m' ∈L(B~ j )∩R c may be selected. In this case, the LWE reduction device 11 has a matrix generation unit 114, and the matrix generation unit 114 uses the input sample point vectors b~ j,1 ,…,b~ j,m' to generate and output a matrix A' j . Also, the LWE reduction device 11 has a target vector generation unit 115, and the target vector generation unit 115 uses the input sample point vectors b~ j,1 ,…,b~ j,m' to generate and output a target vector t' j . Also, the LWE reduction device 11 has a parameter generation unit 116, and the parameter generation unit 116 uses the input sample point vectors b~ j,1 ,…,b~ j,m' and α, and for j = 1,..., m' and μ = 1,..., m', α' j,μ =α||b~ j,μ || may be calculated and output. The sample point vectors b~ j,1 ,…,b~ j,m' may be used for processing other than step A2.

[0169] [Second Embodiment] In this embodiment, an example will be described in which m = m' = 2 and n = n' = 1, and the LWE reduction in step A1 is the Fibonacci-set LWE reduction in step A1a. Hereinafter, differences from the first embodiment will be mainly described, and the same reference numerals will be used to simplify the description of matters common to the first embodiment.

[0170] 3, the computing device 2 of this embodiment includes an LWE reduction device 21, a problem transformation device 12, a solution finding device 13, a solution transformation device 14, and a storage unit 15. Here, the LWE reduction device 21 is, for example, a device obtained by loading a predetermined program into a classical computer. However, this does not limit the present invention, and the LWE reduction device 21 may be a hybrid device or a quantum computer. Information input to the computing device 2 is stored in the storage unit 15 and is read out and used as needed.

[0171] As shown in Fig. 4, the LWE reduction device 21 (computing device) of this embodiment includes a control unit 111, an interpolation point selection unit 212, and a sample point selection unit 213. The LWE reduction device 21 executes each process under the control of the control unit 111. The LWE reduction device 21 stores information obtained in each process in a memory (not shown). The information stored in this memory is read out as needed and used in each process.

[0172] <Processing> Next, the processing of this embodiment will be described. <Preprocessing> In preprocessing, m, n, q, and α, which are the parameter set for the LWE problem, and m', n', and q', which are included in the parameter set for the LWE-like problem, are input to the calculation device 2 ( FIG. 3 ) and stored in the storage unit 15 of the calculation device 2. Note that in this embodiment, an example is shown in which m = m' = 2 and n = n' = 1, but this does not limit the present invention. Also, although not described below, the LWE reduction device 21 reads at least a portion of m, n, q, α, m', n', and q' from the storage unit 15 and uses them for each process. In other words, when at least a portion of m, n, q, α, m', n', and q' is required for processing by the LWE reduction device 21, the LWE reduction device 21 reads the information necessary for each process from m, n, q, α, m', n', and q' and uses it for each process.

[0173] <Step A1a (FIG. 1)> As illustrated in FIG. 3, the matrix A and the target vector t of the LWE problem are input to the computing device 2, and these are input to the LWE reduction device 21. The LWE reduction device 21 reduces the LWE problem specified by these and the parameter set (m, n, q, α) of the LWE problem to a set of one-dimensional LWE-Like problems (Step A1a: LWE reduction). That is, the LWE reduction device 21 uses the parameter set (m, n, q, α), the matrix A, and the target vector t of the LWE problem for which a solution is sought, and obtains and outputs a set of information corresponding to m' = m = 2 one-dimensional LWE-Like problems. In this embodiment, the set of information corresponding to the one-dimensional LWE-Like problem is the sample point vectors b~ j,1 , b~ j,2 is shown as an example. However, this does not limit the present invention. Details will be described below.

[0174] As illustrated in FIG. 4, the matrix A and the target vector t are input to the interpolation point selection unit 212 of the LWE reduction device 21. The interpolation point selection unit 212 selects and outputs an interpolation point vector u~ j,1 that satisfies the above-described equations (22a) and (22b) for any integer θ satisfying 0 < θ < q'. In this embodiment, the interpolation point selection unit 212 generates and outputs the interpolation point vector u~ j,1 of the above-described equation (41) (where j = 1, 2). As described above, υ in the equation (41) is, for example, υ = π~(q), and π~(q) represents the zero period appearing in the Fibonacci sequence {F k mod q} k=0 ∞ . However, this does not limit the present invention, and υ may not be υ = π~(q) as long as υ is an integer greater than or equal to 0. The interpolation point vectors u~ j,1 (where j = 1, 2) are sent to the sample point selection unit 213 and the solution conversion device 14.

[0175] The sample point selection unit 213 uses the interpolation point vector u~ j,1 to obtain linearly independent sample point vectors b~ j,1 , b~ j,2 ∈ L(B~ j ) ∩ Rc (where j=1, 2). In this embodiment, first, the sample point selection unit 213 selects and outputs the interpolation point vector u j,1 Using this, the subdivision point vector d~ that satisfies the above-mentioned equation (43) is j,1 ,…,d~ j,ξυ+1 Next, the sample point selection unit 213 selects the subdivision point vector d j,1 ,…,d~ j,ξυ+1 and the interpolation point vector u~ j,1 Based on this, the sample point vector b~ is calculated as described above. j,1 ,…b~ j,m (For example, sample point vector setting examples 1 and 2) are obtained and output. As mentioned above, the sample point vector b~ j,1 ,…b~ j,m is the lattice L(B~ j ) basis B~ j ={b~ j,1 ,...,b~ j,m}, which is the m-dimensional vector b~ j,1 ,...,b~ j,m (In this embodiment, m=2). The sample point vector b~ j,1 ,…,b~ j,m (Information corresponding to the one-dimensional LWE-Like problem) is sent to the problem conversion device 12. The subsequent processing is the same as in the first embodiment or the modified example of the first embodiment, except that m=m′=2.

[0176] Third Embodiment In this embodiment, an example will be described in which m=m′ and n=n′=1, and the LWE reduction in step A1 is the LWE reduction in the extended Fibonacci setting in step A1b.

[0177] 3, the computing device 3 of this embodiment includes an LWE reduction device 31, a problem transformation device 12, a solution finding device 13, a solution transformation device 14, and a storage unit 15. Here, the LWE reduction device 31 is, for example, a device obtained by loading a predetermined program into a classical computer. However, this does not limit the present invention, and the LWE reduction device 31 may be a hybrid device or a quantum computer. Information input to the computing device 3 is stored in the storage unit 15 and is read out and used as needed.

[0178] As shown in Fig. 4, the LWE reduction device 31 (computing device) of this embodiment includes a control unit 111, an interpolation point selection unit 312, and a sample point selection unit 313. The LWE reduction device 31 executes each process under the control of the control unit 111. The LWE reduction device 31 stores information obtained in each process in a memory (not shown). The information stored in this memory is read out as needed and used in each process.

[0179] <Processing> Next, the processing of this embodiment will be described. <Preprocessing> In preprocessing, m, n, q, α, which are the parameter set for the LWE problem, and m', n', q', which are included in the parameter set for the LWE-like problem, are input to the calculation device 3 ( FIG. 3 ) and stored in the storage unit 15 of the calculation device 3. Note that in this embodiment, an example is shown in which m=m' and n'=1 for any positive integers m and n, but this does not limit the present invention. Also, although not described further below, the LWE reduction device 31, problem conversion device 12, solution finding device 13, and solution conversion device 14 read at least a portion of m, n, q, α, m', n', q' from the storage unit 15 and use them in their respective processes. That is, when at least a part of m, n, q, α, m', n', q' is required for each process of the LWE reduction device 31, the problem transformation device 12, the solution finding device 13, and the solution transformation device 14, the LWE reduction device 31, the problem transformation device 12, the solution finding device 13, and the solution transformation device 14 read out the information required for each process from m, n, q, α, m', n', q' and use it for each process.

[0180] <Step A1b (FIG. 2)> As illustrated in FIG. 3, the matrix A and the target vector t of the LWE problem are input to the computing device 3, and these are input to the LWE reduction device 31. The LWE reduction device 31 reduces the LWE problem specified by these and the parameter set (m, n, q, α) of the LWE problem to a set of one-dimensional LWE-Like problems (Step A1b: LWE reduction). That is, the LWE reduction device 31 uses the parameter set (m, n, q, α), the matrix A, and the target vector t of the LWE problem for which a solution is sought, and obtains and outputs a set of information corresponding to m' one-dimensional LWE-Like problems. In this embodiment, the set of information corresponding to the one-dimensional LWE-Like problems is the sample point vectors b~ j,1 , …, b~ j,m (where j = 1, ..., m). However, this does not limit the present invention. Details will be described below.

[0181] As illustrated in FIG. 4, the matrix A and the target vector t are input to the interpolation point selection unit 312 of the LWE reduction device 31. The interpolation point selection unit 312 selects and outputs an interpolation point vector u~ j,1 that satisfies the above-described equations (22a) and (22b) for any integer θ satisfying 0 < θ < q'. In this embodiment, the interpolation point selection unit 312 generates and outputs the interpolation point vector u~ j,1 (where j = 1, ..., m) of equation (79). As described above, υ in equation (79) is, for example, υ = m + 1. However, this does not limit the present invention, and υ may be any integer greater than or equal to 0 and not necessarily υ = m + 1. The interpolation point vector u~ j,1 is sent to the sample point selection unit 313 and the solution conversion device 14.

[0182] The sample point selection unit 313 uses the interpolation point vector u~ j,1 to select and output linearly independent sample point vectors b~ j,1 , b~ j,2 ∈ L(B~ j ) ∩ R c (where j = 1, ..., m). In this embodiment, first, the sample point selection unit 313 uses the interpolation point vector u~ j,1Using this, the subdivision point vector d~ that satisfies the above-mentioned equation (82) is j,1 ,…,d~ j,ξυ+1 Next, the sample point selection unit 313 selects the subdivision point vector d j,1 ,…,d~ j,ξυ+1 and the interpolation point vector u~ j,1 Based on this, the sample point vector b~ is calculated as described above. j,1 ,…b~ j,m (For example, sample point vector setting example 3) As mentioned above, the sample point vector b~ j,1 ,…b~ j,m is the lattice L(B~ j ) basis B~ j ={b~ j,1 ,...,b~ j,m}, which is the m-dimensional vector b~ j,1 ,...,b~ j,m The sample point vector b~ j,1 ,…,b~ j,m (Information corresponding to the one-dimensional LWE-Like problem) is sent to the problem conversion device 12. The subsequent processing is the same as in the first embodiment or the modified example of the first embodiment, except that m=m′=2.

[0183] [Variation 1 of the Third Embodiment] The input LWE problem (an m-sample n-dimensional LWE problem modulo q) may be converted to an LWE problem modulo a power of 2 by standard LWE reduction (see, for example, Non-Patent Document 1), and then the processing of step A1b of the third embodiment may be executed.

[0184] 3, the computing device 3 of this embodiment includes an LWE reduction device 30, an LWE reduction device 31, a problem transformation device 12, a solution finding device 13, a solution transformation device 14, and a storage unit 15. Here, the LWE reduction device 30 is, for example, a device obtained by loading a predetermined program into a classical computer. However, this does not limit the present invention, and the LWE reduction device 30 may be a hybrid device or a quantum computer.

[0185] <Pre-processing> As pre-processing, m, n, q, α, which are the parameter set of the LWE problem, and m', n', q', which are included in the parameter set of the LWE-like problem, are input to the calculation device 3 (FIG. 3) and stored in the storage unit 15 of the calculation device 3. In addition, the matrix A and the target vector t of the LWE problem are input to the calculation device 3 (FIG. 3) and stored in the storage unit 15 of the calculation device 3. The LWE reduction device 30 reads m, n, q, α, A, t from the storage unit 15, and reduces the input LWE problem by standard setting LWE reduction (see, for example, Non-Patent Document 1) modulo q=2 r The LWE problem is then converted into the following LWE problem: r (Step A0), where r is a positive integer. The other processes are the same as those in the third embodiment.

[0186] [Fourth Embodiment] In this embodiment, we will explain step A2', which is a modified example of step A2, and step B', which is a modified example of step B. That is, the difference between this embodiment and the first to third embodiments is the set of phase estimation problems with errors and the processing content for those problems.

[0187] <Step A2'> First, the processing of step A2' by a classical computer, which is necessary for the processing of this embodiment, will be described. q (A T ) sublattice basis B0,...,B ζ Here, ζ represents an integer greater than 1. For example, ζ is a sufficiently large integer greater than or equal to 1. For example, ζ is a sufficiently large integer greater than or equal to 1 and less than log2 q'. The larger ζ is, the more likely it is that the correct solution s' will be found. j On the other hand, the larger ζ is, the larger the amount of calculation becomes, so ζ may be set based on the input. In this embodiment, the basis B0,...,B ζ Each of these is expressed as an m×m matrix. Also, the basis B0,...,B ζ Each of these is B k' where k'=0,...,ζ. The basis B0 is identical to the basis B of the lattice L(B) (B0=B). Other bases B1,...,B ζThere is no limitation on how to generate the basis B0,...,B ζ are preferably different from each other. For example, the bases B0,...,B ζ is preferably an orthogonal or nearly orthogonal basis.

[0188] <base B0,...,B ζ Example of how to generate the bases B0,...,B ζ However, this is only an example and does not limit the present invention. Step A2'-1: Set kb=0 and B0=B. Step A2'-2: Set B kb row vector b kb,1 ,...,b kb,m Among these, the pair of row vectors with the smallest angle (b kb,ζ1 ,b kb,ζ2 ) where kb∈{0,...,ζ-1} and ζ1,ζ2∈{1,...,m}. That is, the following set of row vectors (b kb,ζ1 ,b kb,ζ2 ) is selected. ・B kb The row vector b in the first row of kb,ζ1 A b kb,ζ1 +b kb,ζ2 and change the second row of ζ to the row vector b kb,ζ2 A b kb,ζ1 -b kb,ζ2 In other words, the row vector b kb,ζ1 and ζ the second row vector b kb,ζ2 Then, we apply the matrix √2 times the Hadamard matrix to the matrix B kb ' is obtained. matrix B kb ' is reduced to a matrix B kb+1 Step A2'-3: If kb<ζ-1, set kb+1 as the new kb and return to step A2'-2. On the other hand, if kb=ζ-1, the process ends. This leaves the basis B0,...,B ζ By this process, the obtained basis approaches an orthogonal basis. For example, in such a basis B0,...,B ζ is a nearly orthogonal basis.

[0189] This basis B0,...,B ζ From the sequence of j,0 ,...,C j,ζ Define a column of Here, k'=0,...,ζ. Note that C defined in equation (18) j is C j,0 In general, the basis B~ j The elements of are rational numbers, but the base C j,0 ,...,C j,ζ All elements of are integers.

[0190] <Introduction of non-commutative diagram> The matrix H that satisfies equation (161) 0,1 ,H 0,2 ,...,H ζ-1,ζ Define B k" =H k"-1,k" B k"-1 (161) where k" = 1,...,ζ. That is, the matrix H k"-1,k" represents the m × m matrix that satisfies Equation (161). Furthermore, for k'1, k'2∈{0,...,ζ} and 0≦k'1<k'2≦ζ, the matrix H k'1:k'2 Define In addition, H k'1:k'2 The subscript "k'1" in the bottom right corner represents "k'1", and "k'2" represents "k'2", but due to limitations on notation, they may be written as "k'1" and "k'2", respectively. From equations (160)-(162), the following equation (163) holds. Here, m-dimensional vector h=(h1,...,h m ), we define the function of the following equation (164): m is a rational number. The function of equation (164) can also be expressed as the following equation (165). Also, define the function of the following equation (166). The function of equation (166) can also be expressed as the following equation (167). Furthermore, we define the function of the following equation (168): g(h)=(h1 mod q',...,h mmod q') (168) The function of equation (166) can also be expressed as the following equation (168a): g:(h1,...,h m )→(h1 mod q',...,h m mod q') (168a)

[0191] base C j,k' The lattice generated by L(C j,k' ) In other words, the basis C j,k' The lattice constructed by L(C j,k' ) is expressed as the lattice L(C j,k' ) is based on C j,k' By the function of equation (164), the lattice L(B~ j ) m-dimensional vector contained in B(j) h∈L(B~ j ), the m-dimensional vector of the following equation (169) C(j,k') h∈L(C j,k' ) can be defined. In particular, when k'=0, the m-dimensional vector C(j,0) h∈L(C j,0 ) can be defined as follows: Here, as shown in equation (160), the following holds:

[0192] Using the function of Eq. (166), the lattice L(C j,k" ) m-dimensional vector contained in C(j,k") h∈L(C j,k" ), the m-dimensional vector of the following equation (171) C(j,k") h∈L(C j,k" ) can be defined. where k"∈{1,...,ζ}. That is, C(j,k') h∈L(C j,k' ) and the lattice L(C j,k' ) is an m-dimensional vector C(j,k') h can be expressed by equations (169), (170), and (171). C j,k" =C j,k"-1 ・H k"-1,k" T Meet the following.

[0193] base D j,k'The lattice generated by L(D j,k' ) In other words, the basis D j,k' The lattice constructed by L(D j,k' ) is expressed as the lattice L(D j,k' ) is based on D j,k' where the lattice L(D j,k' ) is an m-dimensional vector Dg(j,k') h∈L(D j,k' ) is calculated by the function of Eq. (168) from the lattice L(C j,k' ) is an m-dimensional vector C(j,k') h:=( C(j,k') h1,..., C(j,k') h m )∈L(C j,k' ), it can be defined as the following equation (172). Dg(j,k') h:=g( C(j,k') h)=g( C(j,k') h1,..., C(j,k') h m )∈D j,k' .....(172) Furthermore, the lattice L(D j,k" ) is an m-dimensional vector D(j,k") h∈L(D j,k" ) is calculated by the function of Eq. (166) for the lattice L(D j,k"-1 ) is an m-dimensional vector D(j,k"-1) h∈L(D j,k"-1 ), it can be defined as the following equation (173). where k"∈{1,...,ζ}. That is, the lattice L(D j,k' ) is an m-dimensional vector Dg(j,k') h and D(j,k') h can be expressed by equations (172) and (173). D j,k" =D j,k"-1 ・H k"-1,k" T Meet the following.

[0194] We introduce a non-commutative diagram, as illustrated in Figure 16A. As illustrated in Figure 16A, the lattice L(B~ j ) is an m-dimensional vector B(j) h∈L(B~ j ) by applying the function expressed by equation (164), the lattice L(C j,0 ) is an m-dimensional vectorC(j,0) h∈L(C j,0 ) is obtained (Eq. (170)). For k"∈{1,...,ζ}, the lattice L(C j,k"-1 ) is an m-dimensional vector C(j,k"-1) h∈L(C j,k"-1 ) by applying the function expressed by equation (166), the lattice L(C j,k" ) is an m-dimensional vector C(j,k") h∈L(C j,k" ) is obtained (Eq. (171)). The lattice L(C j,k' ) is an m-dimensional vector C(j,k') h∈L(C j,k' ) by applying the function expressed by equation (168), the lattice L(D j,k' ) is an m-dimensional vector Dg(j,k') h∈L(D j,k' ) is obtained (Eq. (172)). Also, the lattice L(D j,k"-1 ) is an m-dimensional vector D(j,k"-1) h∈L(D j,k"-1 ) by applying the function expressed by equation (166), the lattice L(D j,k" ) is an m-dimensional vector D(j,k") h∈L(D j,k" ) is obtained (Eq. (173)).

[0195] m-dimensional vector Dg(j,k') Let the set of h be g(L(C j,k' )), the relationship in equation (174) below holds. The image of the function in equation (168) is In general, for k"=1,...,ζ, L(C j,k" )≠L(D j,k" ), but the equality holds for k'=0. That is, L(C j,0 )=L(D j,0 ) Therefore, the lattice L(D j,0 ) as a basis for C j,0 You can select C j,0 =D j,0 It may also be possible to use the following.

[0196] base E j,0 ,...,E j,ζThe columns of E are defined as follows: j,k' :=D j,k' ・H k':ζ T (When k'≠ζ) (175) E j,k' :=D j,k' (When k'=ζ) (176) where the lattice L(D j,k' ) is an m-dimensional vector D(j,k') h∈L(D j,k' ) by the function shown in Eq. (166) The m-dimensional vector obtained by applying D(j,ζ) h∈L(D j,ζ ) set In this case, the following equation (177) is established from equations (175) and (176). Therefore, the base E j,k' The lattice L(E j,k' ) is a lattice L(D j,k' ) functions In other words, the lattice L(E j,ζ ) is an m-dimensional vector that is an element of the lattice L(D j,k' ) is an m-dimensional vector D(j,k') h∈L(D j,k' ) functions Therefore, the relationship of the following equation (178) holds: L(E j,0 )⊆L(E j,1 )⊆…⊆L(E j,ζ )=L(D j,ζ ) (178) That is, the lattice L(D j,k' ) (where k'=0,...,ζ-1) The image by the lattice L(D j,ζ ) sublattice. Also, for any k', det(H k':k'+1 ) is 2 or -2, so det(E j,k' ) doubles in magnitude for every increase in k'∈{0,...,ζ}.

[0197] <Selection of Representative Using Non-Commutative Diagram> Figure 16B shows a non-commutative diagram extracted from a part of the non-commutative diagram shown in Figure 16A. As shown in Figure 16B, j ) is an m-dimensional vector B(j) Taking h as input, the above-mentioned functions are applied along the non-commutative diagram, and the result is a lattice L(D j,k' The path to obtain the m-dimensional vector, which is an element of k' and path_d k' There are two ways. k' So, m-dimensional vector B(j) By applying the function of equation (164) to h and then the function of equation (166), the lattice L(C j,k' ) is an m-dimensional vector C(j,k') h∈L(C j,k' ) is obtained, and then the function expressed by equation (168) is applied to obtain the lattice L(D j,k' ) is an m-dimensional vector Dg(j,k') h∈L(D j,k' ) is obtained. On the other hand, the path path_d k' So, m-dimensional vector B(j) By applying the function of equation (164) to h and then the function of equation (166), the lattice L(C j,k' ) is an m-dimensional vector C(j,k') h∈L(C j,k' ) is obtained, and then the function expressed by equation (168) is applied, followed by the function of equation (166) to obtain the lattice L(D j,k' ) is an m-dimensional vector D(j,k') h∈L(D j,k' ) is obtained. This diagram is non-commutative and the lattice L(B~ j ) path_u k' The lattice L(D j,k' ) and the lattice L(B~ j ) path_d k' The lattice L(D j,k' ) is different from the image to (179) is The lattice L(B~ j ) into the aforementioned Ωj L(B~ j )⊆L(B~ j ), we can show that the same relationship holds. That is, teeth, Therefore, for k'=0,...,ζ, x'∈Ω j and but, Find an m-dimensional vector x' that satisfies the condition that it is not included in and set it as x(k'). That is, the m-dimensional vector x(k') is such that x(k')∈Ω j and but, The condition that the value is not included in teeth, This condition holds true with a probability of about 1 / 2. Therefore, by randomly selecting each element of the m-dimensional vector x' from {-1, 0, 1} and repeatedly checking whether this condition is met, the above-mentioned m-dimensional vector x(k') can be set. The closer x(k') is to the origin, the better.

[0198] Such an m-dimensional vector x(0)B~ j ,...,x(ζ)B~ j For y(j,0),...,y(j,ζ), we define the lattice L(B~ j ) path_u k' The lattice L(D j,k' ) (FIG. 16B). That is, y(j,k') is defined as the following equation (180). (180) y(j,k') is an m-dimensional vector. Also, L(D j,k' )-L(D j,k'-1 ・H k'-1:k' T ) is the lattice L(D j,k' ) to the lattice L(D j,k'-1 ・H k'-1:k' T ) is excluded. Furthermore, when k' ≠ 0, ζ, applying the function of equation (166) to y(j,k') gives z(j,k') of the following equation (181a). z(j,k'):=y(j,k')・H k':ζ T∈L(E j,k' )-L(E j,k'-1 ) (181a) Let z(j,k') be L(E j,k' )-L(E j,k'-1 ) is called the representative of the vector z(j,k'). The representative z(j,k') is an m-dimensional vector. When k'=ζ, the representative z(j,k') is defined as follows: z(j,k'):=y(j,k')∈L(E j,k' )-L(E j,k'-1 ) (181b)

[0199] By using the m-dimensional vector y(j,k') defined by the representative z(j,k'), the lattice L(D j,k' ) is the sublattice L(D j,k'-1 ・H k'-1,k' T ) and the set y(j,k')+L(D j,k'-1 ・H k'-1,k' T ) can be expressed as a union with L(D j,k' )=L(D j,k'-1 ・H k'-1,k' T )∪(y(j,k')+L(D j,k'-1 ・H k'-1,k' T )) (181c) where the lattice L(D j,k'-1 ・H k'-1,k' T ) is the lattice L(C j,0 ) path_d k' is the lattice to which the image by y(j,k') belongs, and y(j,k') is the lattice L(C j,0 ) Path of elements path_u k' The representative element z(j,k') corresponding to y(j,k') is also a lattice L(C j,0 ) Path of elements path_u k' The image is based on the lattice L(E j,ζ ) is a lattice L(E j,0 ) is shifted to obtain 2 ζ It can be expressed as the union of sets. That is, the following equation (182) holds. where z(j,1)∈L(E j,1 ),...,z(j,ζ)∈L(E j,ζ ) is satisfied.

[0200] <L(D j,k' ) phase of each point> lattice L(D j,k' ) the following topology is defined for each point: 1. Representative element z(j,k")∈L(E j,k" )-L(E j,k"-1 ) (where k"=1,...,ζ) j,ζ (t,z(j,k")) is defined as the following equation (183). where Ω j ⊆Z q' m and x(k")∈Ω j Also, t∈Z q m is the target vector.

[0201] 2. Lattice L(E j,0 ) points, the phase is determined as follows. As mentioned above, C j,0 =D j,0 Therefore, the lattice L(E j,0 ) the phase at any point of the Therefore, L(B~ j ) is a topology that is naturally derived from any z(0)∈L(E j,0 ) satisfies the following equation (184) which exists uniquely for x(0)・B~ j ∈L(B~ j ) and the lattice L(E j,0 ) the phase ρ of any point j,ζ (t,z(0)) is defined as the following equation (185).

[0202] 3. For other points, the phase is determined as follows: By using the above equation (182), any L z∈L(E j,ζ ), for some δ1,...,δ ζ ∈{0,1} exists such that the following equation (186) holds. L z∈δ1z(j,1)+...+δ ζ z(j,ζ)+L(Ej,0 ) (186) such that δ1,...,δ ζ is determined, for example, as follows: Step A2'-11: Set kb=ζ. Step A2'-12: L z∈L(E j,kb )-L(E j,kb-1 ) or not. Step A2'-13: If L z∈L(E j,kb )-L(E j,kb-1 ), then δ kb :=1, L z:= L zy(j,kb)・H kb: ζ T Then proceed to step A2'-15. Step A2'-14: If L z∈L(E j,kb ), then δ kb :=0 and proceed to step A2'-15. Step A2'-15: Determine whether kb=1. If kb=1 is not true, set kb:=kb-1 and return to step A2'-12. On the other hand, if kb=1, then the obtained δ1,...,δ ζ Note that this method is just an example, and there are other methods to output δ1,...,δ ζ may be obtained.

[0203] δ1,...,δ ζ Using the above equation (182), the following equation (187) is established. By transforming equation (187), we obtain the following equation (188). From the above, using equations (183) and (185), the phase ρ j,ζ (t, L z) is defined as follows:

[0204] With the above preparation, the set Θ that satisfies the following formula (190) j,ζ Define Here, #Θ j,ζ =q' and the set Θ that can be induced from the functions of equations (164) and (166) j,ζWe can prove that the labels corresponding to the elements of have a one-to-one correspondence with the elements of {0,1,...,q'-1}. j Instead of the set Θ j,ζ Therefore, the above-mentioned assumption 1 is naturally satisfied. j,ζ Using the input quantum state |Ψ as shown in equation (191), j,t > is used to perform calculations.

[0205] <Step B'> Next, the processing of step B' by the quantum computer of this embodiment will be described. <Step B'-1> m q'-dimensional quantum registers are prepared and initialized.

[0206] <Step B'-2> In the quantum register, the quantum state |Ψ shown in the following equation (192) j,0 >to generate. For example, after creating the state of equation (193) below by Hadamard transformation, we apply the mapping |i',0,...,0>→Θ j,ζ Just execute the following. However, the quantum state |Ψ j,0 The method for generating the quantum state |Ψ is not limited to this, and other methods may be used. j,0 > may be generated.

[0207] <Step B'-3> In the quantum register, the quantum state |Ψ shown in Eq. (192) j,0 > and add an ancillary quantum bit (an auxiliary quantum bit) to generate the quantum state shown in the following equation (194). where: L z,z(0),δ1,...,δ ζ satisfies the above equation (188).

[0208] <Step B'-4> In the quantum register, a rotation gate is used to generate the quantum state shown in the following equation (195). where ρ j,ζ (t, L z) is the phase defined by equation (189).

[0209] <Step B'-5> In the quantum register, the ancillary elements are initialized (the ancillary elements are discarded) by applying the inverse operation of step B'-3 to the quantum state of equation (195). This operation results in the input quantum state |Ψ shown in the following equation (196): j,t > is obtained.

[0210] <Step B'-6> Input quantum state |Ψ of the quantum register equation (196) j,t >, the inverse quantum Fourier transform shown in equation (19) to obtain the quantum state shown in the following equation (197).

[0211] <Step B'-7> Observe the quantum state of the quantum register (197) and obtain the observation result OM j =(OM j,1 ,...,OM j,m )∈Z q' m get.

[0212] <Step B'-8> Observation results OM j Using the above, the label L shown in the following equation (198) j (z j B ζ ) (j=1,...,m) is obtained. The processing of step B'-8 may be performed using either a classical computer or a quantum computer. where z j =(OM j,1 ,...,OM j,m )∈Z q' m Also, L j (b1),...,L j (b m ) are the row vectors b1,...,b in the basis B of the lattice L(B). m For example, the label L j (b1),...,L j (b m ) is defined by equation (103). For example, the label L j (b1),...,L j (b m ) are the L in equation (103).j (v)(v=b1,...,b m )

[0213] <Step B'-9> Label L j (z j B ζ )∈Z q' Using the solution s' j Here, the label L j (z j B ζ ) has a high probability of finding the solution s' j Therefore, for example, if we repeat the above steps B'-1 to B'-8, the resulting label L j (z j B ζ ) is the most frequent solution s' of the LWE-like problem. j Output as

[0214] <Example of Step A2' and Step B'> An example of Step A2' and Step B' is shown below. Here, an example of the LWE problem is shown, which is the same as the example of Step A1a. That is, the parameter set (m, n, q, α) of the input LWE problem is (m, n, q, α) = (2, 1, 5, 0.2), Also, assume that q' = 13 and ζ = 2. Below, we will show an example of a phase estimation problem with an error corresponding to j = 1 and a procedure for solving it, but the phase estimation problem with an error corresponding to j = 2 and a procedure for solving it are similar.

[0215] First, the bases B0, B1, and B2 of the sublattice of the lattice L(B) are illustrated. The base B in equation (51) is set to the base B0. By applying the Hadamard matrix to this basis B0 and then calculating the LLL reduced matrix, the following basis B1 is obtained. Furthermore, by applying the Hadamard matrix to this basis B1 and then calculating the LLL-reduced matrix, the following basis B2 is obtained.

[0216] H 0,1 and H 1,2 becomes: That is, B1=H0,1 B0 and B2=H 1,2 Fill B1.

[0217] In this case the non-commutative diagram becomes:

[0218] Also, from the sequence of bases B0, B1, and B2, the following base C 1,0 ,C 1,1 ,C 1,2 First, using the same base B~1 as in the example of step A1a, we can define a sequence of base C 1,0 is expressed as follows: As mentioned above, D 1,0 =C 1,0 C 1,1 =C 1,0 ・H 0,1 T and C 1,2 =C 1,1 ・H 1,2 T To satisfy this, the basis C 1,1 ,C 1,2 is expressed as follows:

[0219] base C 1,1 ,C 1,2 The basis D is the image of the function of Eq. (168) 1,1 ,D 1,2 can be obtained as follows. First, Compute the Hermite normal form and select the first two rows, which gives us the following matrix: By calculating these LLL irreducible bases, we obtain the following base D 1,1 ,D 1,2 is obtained.

[0220] Next, L(E 1,1 )-L(E 1,0 ) representative z(1,1) and L(E 1,2 )-L(E 1,1 ) Select the representative element z(1,2). An example is shown below. If x(1)=(0,2), then x(1)B~1=(-2 / 13,16 / 13), and y(1,1) is as follows. Therefore, the representative z(1,1) is z(1,1):=y(1,1)・H 1:2 T =(5,1). The topology ρ of the representative z(1,1) 1,2 (t,z(1,1)) becomes as follows.

[0221] Also, if x(2) = (1,1), then x(2)B~1 = (-2 / 13,16 / 13), and y(1,2) is as follows. Therefore, the representative z(1,2) is z(1,2):=y(1,2)=(2,3). The topology ρ of the representative z(1,2) 1,2 (t,z(1,2)) is as follows.

[0222] Using these representatives z(j,1) and z(j,2), we define the lattice L(E 1,2 )=L(D 1,2 ) is the lattice L(E 1,0 ) is shifted to obtain 2 2 It can be expressed as a union of sets, i.e., the following holds: Here, the following definitions are made: The result is as follows. Here, the value at the bottom right of each element is the phase e 2πiκ' The relationship between the coordinates of each point and the phase is shown in FIG. 17. Here, the region The number of points belonging to is 13, which is exactly the same as the value of q'.

[0223] The subsequent processing is performed using a quantum computer. <Step B'-1> Prepare two 13-dimensional quantum registers and initialize them. If the quantum registers are configured with qubits, the 13th dimension is represented by four qubits, for a total of eight qubits.

[0224] <Step B'-2> Put the quantum register in a superposition state and 1,0 >to generate.

[0225] <Steps B'-3, B'-4, B'-5> Following steps B'-3, B'-4, and B'-5, the following input quantum state |Ψ is generated using a rotation gate: 1,t >to generate.

[0226] <Step B'-6> Input quantum state of the quantum register |Ψ 1,t >,|Ψ 2,t >, we perform the inverse quantum Fourier transform shown in equation (19). This results in the following quantum state in the quantum register:

[0227] <Step B'-7> Observe the quantum state of the quantum register obtained in step B'-6 and obtain the observation result OM1 = (OM 1,1 ,OM 1,2 ) is obtained. The observation result OM1 = (OM 1,1 ,OM 1,2 The horizontal axis shows the distribution of the observed OM 1,1 The vertical axis represents the distribution of the observed OM 1,2 The closer the color is to white, the higher the probability of observation.

[0228] <Step B'-8> Using the observation result OM, obtain the label L1(z1B2) as follows. Here, 11 and 12 are the labels L1(b1) and L1(b2) corresponding to the row vectors (1,2) and (0,5) of the basis B, respectively.

[0229] Figure 18B illustrates the probability distribution of the value of label L1(z1B2) corresponding to observation result OM1. In the example of Figure 18B, there is a high probability that the value of label L1(z1B2) will be 9. Therefore, if the processes of steps B'-1 to B'-8 are repeated multiple times, the label value L1(z1B2) with the highest probability of appearing will be 9, and it can be concluded that the solution is s'1 = 9.

[0230] <Configuration> Next, the configuration of the computing device 4 of this embodiment will be described. As illustrated in FIG. 3 , the computing device 4 of this embodiment includes an LWE reduction device 11, a problem transformation device 42, a solution-finding device 43, a solution transformation device 14, and a storage unit 15. Here, the problem transformation device 42 is, for example, a device obtained by loading a predetermined program into a classical computer (e.g., a von Neumann computer). On the other hand, the solution-finding device 43 is, for example, a hybrid device that combines a device obtained by loading a predetermined program into a classical computer with a quantum computer (e.g., a gate-type quantum computer or an annealing-type quantum computer). Note that the hybrid type may also be a device obtained by loading a predetermined program into both a classical computer and a quantum computer. Furthermore, the problem transformation device 42 may be a hybrid device or a quantum computer. Furthermore, the solution-finding device 43 may be a quantum computer into which a predetermined program has been loaded. Information input to the computing device 4 is stored in the storage unit 15 and is read and used as needed.

[0231] As illustrated in Fig. 5, the problem transformation device 42 (computing device) of this embodiment has a control unit 121, a vector generation unit 422, and an input quantum state identification unit 423. The problem transformation device 42 executes each process under the control of the control unit 121. The problem transformation device 42 executes each process under the control of the control unit 121. The problem transformation device 42 stores information obtained in each process in a memory (not shown). The information stored in this memory is read out as needed and used in each process.

[0232] 15 , the solution-finding device 43 (computation device) of this embodiment includes a control unit 131, an input quantum state generation unit 432, an inverse quantum Fourier transform unit 434, an observation unit 135, a label calculation unit 436, and a solution generation unit 437. The solution-finding device 43 executes each process under the control of the control unit 131. The solution-finding device 43 stores information obtained in each process in a memory (not shown). The information stored in this memory is read out as needed and used in each process.

[0233] <Processing> Next, the processing of this embodiment will be described. The processing of this embodiment differs from the processing of the first to third embodiments in that step A2 and step B are replaced with the above-mentioned step A2' and step B'. Only step A2' and step B' will be described below. Note that in this embodiment as well, the problem conversion device 42 and the solution finding device 43 read at least a portion of m, n, q, α, m', n', and q' from the storage unit 15 as necessary and use them in their respective processing.

[0234] <Step A2'> The problem transformation device 42 (FIG. 3) receives the sample point vector b~ j,1 ,…,b~ j,m' (information corresponding to the set of one-dimensional LWE-like problems), the matrix A of the LWE problem, and the target vector t are input. The sample point vector b~ j,1 ,…,b~ j,m' is output from any of the above-mentioned LWE reduction devices 11, 21, and 31. The problem transformation device 42 converts the sample point vector b j,1 ,…,b~ j,m' (where j = 1,...,m') is converted into a set of phase estimation problems with errors, and information corresponding to the set of phase estimation problems with errors is obtained and output. As mentioned above, B~ j is the lattice L(B~ j ) represents the m × m matrix that represents the basis of the sample point vector b~ j,1 ,…,b~ j,m' m vectors b~ contained in j,1 ,...,b~ j,m is the base B~ j In this embodiment, information corresponding to a set of phase estimation problems with errors is expressed as an input quantum state |Ψ j,t , m') (where j=1,...,m') is used as an example. However, this does not limit the present invention. Details will be explained below.

[0235] As illustrated in FIG. 5, the sample point vector b j,1 ,…,b~ j,mand the matrix A of the LWE problem are input to the vector generation unit 422 of the problem transformation device 42. The vector generation unit 422 uses these to generate a set of m-dimensional vectors Θ that satisfies the above-mentioned equation (190). j,ζ and output it. For example, the vector generation unit 422 first generates a basis B using a matrix A. The method of generating the basis B using the matrix A is, for example, as described in the first embodiment. This basis B is a basis B~ j The vector generation unit 422 uses the basis B to generate the sublattice bases B0,...,B of the lattice L(B). ζ and generate a matrix H that satisfies equation (161). 0,1 ,H 0,2 ,...,H ζ-1,ζ and sets the functions of equations (164), (166), and (168). Furthermore, the vector generation unit 422 uses these to generate the lattice L(B j ) and the lattice L(D j,ζ ) (Fig. 16A), and the set of m-dimensional vectors Θ that satisfies Eq. (190) j,ζ The vector generation unit 422 obtains and outputs the Ω described in the first embodiment. j B~ j =B R ∩L(B~ j ) is a set (domain) of m-dimensional vectors that satisfy j ⊆Z q' m and output it.

[0236] A set of m-dimensional vectors Ω j , a set of m-dimensional vectors Θ j,ζ and the functions of equations (164), (166), and (168) are sent to the input quantum state specifying unit 423. The input quantum state specifying unit 423 receives the sample point vector b j,1 ,…,b~ j,m and the target vector t are also input. The input quantum state specifying unit 423 uses these to determine the input quantum state |Ψ shown in the above-mentioned equation (191). j,t > and output the information that identifies it. For example, the input quantum state specifying unit 423 determines the sample point vector b j,1,…,b~ j,m , a target vector t, functions of equations (164), (166), and (168), and a set of m-dimensional vectors Ω j Using the above, we set the m-dimensional vector x(k') and define the phase ρ j,ζ (t,z(j,k")) (where k"=1,...,ζ), the phase ρ j,ζ (t,z(0)), and the phase ρ shown in equations (188) and (189). j,ζ (t, L z). Furthermore, the input quantum state specifying unit 423 obtains a set of m-dimensional vectors Θ j,ζ , target vector t, and phase ρ j,ζ (t, L z), the input quantum state |Ψ shown in Eq. (191) j,t > and output the information that specifies the input quantum state |Ψ j,t The information identifying the problem is sent to the solver 43 .

[0237] <Step B'> As shown in FIG. 15, the solver 43 receives the input quantum state |Ψ shown in equation (191). j,t The solution-finding device 43 receives information specifying the input quantum state |Ψ j,t >, and solve the set of error-containing phase estimation problems (equation (4)) corresponding to j The solution s' is obtained. j To obtain the set of j (γ) This information is not necessary.

[0238] In this embodiment, first, the input quantum state generation unit 432 of the solution-finding device 43 (FIG. 15) generates the input quantum state |Ψ shown in equation (196). j,t >to generate. For example, the input quantum state generation unit 432 prepares and initializes m q'-dimensional quantum registers (step B'-1). The input quantum state generation unit 432 generates a quantum state |Ψ shown in equation (192) in the quantum registers. j,0The input quantum state generation unit 432 generates the quantum state |Ψ shown in equation (192) in the quantum register. j,0 >, and generates the quantum state shown in equation (194) (step B'-3). The input quantum state generation unit 432 uses a rotation gate in the quantum register to generate the quantum state shown in equation (195) (step B'-4). The input quantum state generation unit 432 initializes the ancillaries by applying the inverse operation of the process in step B'-3 to the quantum state of equation (195) in the quantum register. This operation generates the input quantum state |Ψ shown in equation (196). j,t > is obtained (step B'-5).

[0239] Next, the inverse quantum Fourier transform unit 434 converts the input quantum state |Ψ of the quantum register in equation (196). j,t >, the inverse quantum Fourier transform shown in the above equation (19) and the quantum state shown in equation (197) (Step B'-6).

[0240] The observation unit 435 observes the quantum state of the quantum register in equation (197) and outputs the observation result OM j =(OM j,1 ,...,OM j,m )∈Z q' m Observation results OM j is sent to the label calculation unit 436 (step B'-7).

[0241] The label calculation unit 436 calculates the observation result OM j Using the label L shown in equation (198), j (z j B ζ )(j=1,...,m). Label L j (z j B ζ ) is sent to the solution generating unit 437 (step B'-8).

[0242] The solution generator 437 generates the label L j (z j B ζ ) to find the solution s' jAs mentioned above, the label L j (z j B ζ ) has a high probability of finding the solution s' j Therefore, the obtained label L j (z j B ζ ) to find the solution s' j For example, the solution generating unit 437 repeatedly executes the processes from step B'-1 to step B'-8 until a predetermined termination condition is met, and obtains the label L j (z j B ζ ) based on the solution s' j For example, the solution generating unit 437 obtains and outputs the label L that appears most frequently for each j. j (z j B ζ ) is solved by s' j The termination condition may be, for example, repeating the processes from step B'-1 to step B'-8 a predetermined number of times, or outputting the label L with the highest frequency of appearance for each j. j (z j B ζ The difference in frequency between the solution s' and the second most frequently occurring label may be greater than a predetermined value. j is sent to the solution transformation unit 14 (step B'-9).

[0243] The subsequent processing is as described in the first embodiment.

[0244] [Hardware Configuration] The classical computer described above is, for example, a general-purpose or dedicated computer equipped with a processor (hardware processor) such as a central processing unit (CPU) and memories such as random-access memory (RAM) and read-only memory (ROM). This computer may have one processor and memory, or may have multiple processors and memories. For example, the classical computer is a von Neumann computer. The quantum computer described above is, for example, a device having quantum bits required for quantum computation, a quantum operation unit that manipulates the quantum states of the quantum bits, and a quantum memory that stores the quantum states. For example, the quantum computer is a gate-type quantum computer or an annealing-type quantum computer.

[0245] The functions provided by the components described herein may be implemented in circuitry or processing circuitry, including quantum computers, general-purpose processors, application-specific processors, integrated circuits, ASICs (Application Specific Integrated Circuits), a Central Processing Unit (CPU), conventional circuits, and / or combinations thereof, programmed to provide the described functions. Processors include transistors and other circuits and are considered circuitry or processing circuitry. Quantum computers include qubits and other quantum circuits and are considered circuitry or processing circuitry. Examples of quantum computers include superconducting quantum computers, ion trap quantum computers, photonic quantum computers, topological qubits, neutral atom quantum computers, spin quantum computers, and quantum annealing quantum computers. Quantum computers and processors may be programmed processors that execute programs stored in memory.

[0246] In this specification, a circuitry, unit, or means is hardware that is programmed to realize or performs the described functions, which may be any hardware disclosed herein or any hardware known to be programmed to realize or perform the described functions.

[0247] If the hardware is a quantum computer or processor that is considered to be a type of circuitry, the quantum computer, circuitry, means, or unit is the combination of the hardware and / or software used to configure the hardware and / or quantum computer or processor.

[0248] [Program] The above-mentioned program may be installed on a classical computer and / or a quantum computer (hereinafter simply referred to as "computer"), or may be pre-recorded in a storage device such as a ROM or quantum memory. The program may also be recorded on a computer-readable recording medium. An example of a computer-readable recording medium is a non-transitory recording medium. Examples of such recording media include a magnetic recording device, an optical disk, a magneto-optical recording medium, a semiconductor memory, and a quantum memory.

[0249] This program may be distributed, for example, by selling, transferring, or lending a portable recording medium, such as a DVD or CD-ROM, on which the program is recorded. Furthermore, the program may be distributed by storing the program in a storage device of a server computer and transferring the program from the server computer to other computers via a network. As described above, a computer that executes such a program may first temporarily store the program recorded on a portable recording medium or transferred from the server computer in its own storage device. Then, when executing a process, the computer reads the program stored in its own storage device and executes processing in accordance with the read program. Alternatively, the program may be executed by a computer that reads the program directly from a portable recording medium and executes processing in accordance with the program. Furthermore, the computer may execute processing in accordance with the received program each time a program is transferred from the server computer to the computer. Alternatively, the server computer may not transfer the program to the computer, but may instead execute the processing function simply by issuing an execution instruction and obtaining the results, thereby executing the processing described above through a so-called ASP (Application Service Provider) service. In this embodiment, the program includes information used for processing by an electronic computer that is equivalent to a program (such as data that is not a direct instruction to a computer but has properties that dictate computer processing).

[0250] Furthermore, instead of executing a predetermined program on a computer, the functions of at least one of the devices may be realized by hardware alone, without using a program.

[0251] The present invention is not limited to the above-described embodiments. For example, the various processes described above may not only be executed in chronological order as described, but may also be executed in parallel or individually depending on the processing capabilities of the device executing the processes or as needed. Furthermore, as long as information is input to each processing unit so that the information necessary for each process can be obtained, the information input to each processing unit is not limited to that of the above-described embodiments. For example, information obtained in one processing unit may be input to another processing unit and reused, or information obtained in the past may be input and reused. Needless to say, other appropriate modifications are possible within the scope of the claims.

[0252] The industrial applicability of the present invention is exemplified below. However, these applicability is merely an example and does not limit the present invention. By using the present invention, it is possible to quickly solve the LWE problem, which can be considered a type of combinatorial optimization problem. This will have an impact on two industrial fields, for example: the field of artificial intelligence and the field of post-quantum cryptography.

[0253] For example, by applying this invention, it is possible to quickly solve subproblems of combinatorial optimization problems in the field of artificial intelligence. For example, by implementing this invention on a gate-type quantum computer and a classical computer, it becomes possible to use artificial intelligence to quickly simulate various phenomena in industry, materials, medicine, pharmaceuticals, energy, physics, chemistry, economy, real society, etc., contributing to rapid progress and development in each field.

[0254] A more specific explanation follows. The LWE problem is closely related to the shortest vector problem, which is known to be NP-hard. The shortest vector problem is known to be able to efficiently reduce other NP (nondeterministic polynomial time complexity class) problems. Since solving the reduced problem yields a solution to the original NP problem, the quantum algorithm proposed in this invention can be applied to, for example, all NP problems. NP problems include many important problems, particularly in the field of artificial intelligence, and have an extremely wide range of industrial applications. Representative application examples are listed below.

[0255] 1. Optimal Route Selection for Autonomous Driving: Optimal route selection for autonomous driving is formulated as an NP-complete problem known as the traveling salesman problem. This problem has long been studied in the field of artificial intelligence, and as the number of vertices increases, it becomes difficult to find an optimal solution using classical computers. For this reason, in recent years, there has been active research into the application of quantum computers (especially quantum annealing) to this problem. 2. Optimization of Large-Scale Integrated Circuits: Expressing the problem of optimizing large-scale integrated circuits as a logical formula results in a constraint satisfaction problem. This problem is a typical problem in artificial intelligence, and due to its high usefulness, it has a long history of research using classical algorithms. This problem is considered one of the most promising applications for quantum computers. 3. Optimization of Network Infrastructure: Optimizing increasingly large-scale and complex urban functions, such as electricity, gas, and water networks, transportation and communication networks, and oil and gas pipelines, has been difficult due to the explosive computational complexity. The application of the quantum algorithm proposed in this invention is expected to solve these problems.

[0256] For example, the problem of optimal route selection in autonomous driving can be reduced to a lattice problem by representing the combination of routes as vectors. By encoding the vector so that it approaches a lattice point within a certain distance when the length of the route is less than a certain value, solving the lattice problem will provide information about the route. For a more detailed explanation of how NP-complete problems are reduced to lattice problems, see Reference 7 below. Reference 7: Daniele Micciancio and Sha_ Goldwasser, Complexity of Lattice Problems: a cryptographic perspective, Kluwer Academic Publishers, The Kluwer International Series in Engineering and Computer Science, vol. 671 (2002). For other NP-complete problems, see the following references. Reference 8: Michael R. Garey and David S. Johnson, Computers and Intractability: A Guide to the Theory of NP-Completeness, W.H. Freeman & Co (1979). Experts conjecture that there is no efficient way to solve all NP-complete problems exactly using classical computers (the P-NP conjecture). When dealing with NP problems using classical computers for industrial applications, one is often forced to choose between using approximate calculation results at the expense of solution accuracy, or restricting to subproblems in order to obtain exact solutions. On the other hand, by using the quantum algorithm of the present invention, the accuracy of the calculation results can be significantly improved and the conditions for restricting to subproblems can be relaxed. As a result, it becomes possible to provide services that were previously unavailable.

[0257] Furthermore, in the field of post-quantum cryptography, the present invention may compromise the security of conventional lattice cryptography. While measures such as increasing the key length are necessary to compensate for this vulnerability, changing the key length may result in a deterioration in cryptographic efficiency. Using this invention to evaluate the security and cryptographic efficiency of lattice cryptography is expected to contribute to the development of cryptographic methods that solve both of these problems.

[0258] The following are examples of specific practical applications. [Structure] (1) Computing device 1-4 Input: Information for specifying the LWE problem (e.g., A, t, q, σ). Processing: Solve the LWE problem to obtain a solution to the LWE problem. Output: Information representing the solution to the LWE problem (e.g., solution s).

[0259] (2) Application Device I Input: Data containing noise (such as noise, typos, and errors) in industrial applications. Processing: Convert the problem of removing noise from the data into an LWE problem, and output the LWE problem to the computing device 1-4 (for example, send it via the Internet). Obtain information representing the solution to the LWE problem from the computing device 1-4 (for example, receive it via the Internet). Convert the information representing the solution to the LWE problem into data from which the noise has been removed. Output: Data from which the noise has been removed.

[0260] (3) Application Device II Input: Information representing a combinatorial optimization problem in an industrial application. Processing: Convert the information representing the combinatorial optimization problem into an LWE problem and output the LWE problem to the computing device 1-4 (for example, send it via the Internet). Obtain information representing a solution to the LWE problem from the computing device 1-4 (for example, receive it via the Internet). Convert the information representing the solution to the LWE problem into information representing a solution to the combinatorial optimization problem in an industrial application. Output: Information representing the solution to the combinatorial optimization problem in an industrial application.

[0261] By combining the above-mentioned computing devices 1-4 with the above-mentioned application device I or application device II, various practical applications can be constructed. Specific examples are shown below.

[0262] [Combination of computing device 1-4 and application device I] <Machine learning> Application device I: Input: Data for training a learning model while protecting privacy (e.g., distributed data in federated learning). Processing: Convert the problem of removing noise from data into an LWE problem. Send the converted LWE problem to computing device 1-4 (e.g., send via the Internet). Obtain information representing the solution to the LWE problem from computing device 1-4 (e.g., receive via the Internet). Train a privacy-protected learning model using the obtained solution. Output: Privacy-protected learning model.

[0263] <Medical field> Application device I: Input: Data for medical diagnosis (e.g., MRI images, ultrasound images, X-ray images). Processing: Convert the problem of removing noise from the data into an LWE problem. Send the converted LWE problem to computing device 1-4 (e.g., send via the Internet). Obtain information representing the solution to the LWE problem from computing device 1-4 (e.g., receive via the Internet). Convert the obtained solution into data with the noise removed. Output: Data with the noise removed.

[0264] In addition, the following may be used as input and output data for the application device I. <Natural language processing> Input: natural language data containing typos and errors. Output: natural language data with typos and errors removed. <Communications field> Input: communication signal data containing noise. Output: communication signal data with noise removed. <Manufacturing> Input: sensor data collected during the manufacturing process. Output: sensor data with noise removed. <Financial field> Input: financial time series data. Output: financial time series data with noise removed. <Automotive industry> Input: sensor data from self-driving cars. Output: sensor data with noise removed. <Environmental monitoring> Input: environmental sensor data. Output: sensor data with noise removed. <Energy field> Input: smart grid data. Output: smart grid data with noise removed. <Agriculture field> Input: sensor data obtained from agricultural sensors. Output: sensor data with noise removed. <Retail industry> Input: customer transaction data Output: customer transaction data with noise removed.

[0265] [Combination of computing device 1-4 and application device II] <Multi-objective optimization problem> Application device II: Input: Information representing a combinatorial optimization problem in an industrial application. Processing: Convert the combinatorial optimization problem into an LWE problem. Send the converted LWE problem to computing device 1-4 (e.g., send via the Internet). Obtain information representing a solution to the LWE problem from computing device 1-4 (e.g., receive via the Internet). Use the obtained solution to derive a solution to the optimization problem. Output: Information representing a solution to the combinatorial optimization problem. Examples of combinatorial optimization problems include optimal route setting for logistics, optimal route selection for autonomous driving, optimization of large-scale integrated circuits, optimization of network infrastructure, optimization of processes from raw material procurement to product delivery, optimization of production line operation schedules in manufacturing, optimization of shift allocation for personnel such as pilots and flight attendants, optimization of facility location, and optimization of asset portfolios.

[0266] 1-4: Calculation device 11-31, 30: LWE reduction device 12, 42: Problem conversion device 13, 43: Solution finding device 14: Solution conversion device

Claims

1. A computing device having: an LWE reduction unit that uses information for identifying an LWE problem to convert the LWE problem into a set of one-dimensional LWE-like problems in which the standard deviation of an error vector is determined for each element of the error vector, and obtains information for identifying the set of one-dimensional LWE-like problems; a problem conversion unit that converts the set of one-dimensional LWE-like problems into a set of phase estimation problems with errors, and obtains information for identifying the set of phase estimation problems with errors; a solution unit that solves the set of phase estimation problems with errors to obtain a set of solutions to the phase estimation problems with errors; and a solution conversion unit that converts the set of solutions to the phase estimation problems with errors into solutions to the LWE problem, and outputs the solutions to the LWE problems.

2. A computing device having an interpolation point selection unit and a sample point selection unit, where m, n, m', n', j represent positive integers, α represents a positive real number, q, q' represent integers greater than 1, and Z q represents the quotient ring Z / qZ with modulus q, Z represents the set of integers, σ = αq, and N(0, σ 2 ) represents a Gaussian distribution on Z q with mean 0 and standard deviation σ, ||β1|| represents the norm of β1, and a1, a2,..., a m ∈Z q n each represent an n-dimensional row vector, A represents an m×n matrix , ε represents an m-dimensional column vector with elements being real numbers following the Gaussian distribution N(0, σ 2 ), s ∈ Z q n represents an n-dimensional column vector, t represents an m-dimensional column vector satisfying , X represents a set {x1,..., x n ∈Z m} of n m-dimensional column vectors x1,..., x n}, <β1, β2> represents the inner product of β1 and β2, and the lattice ∧ q (X) is defined as ∧ q (X):={x ∈ Z m |∃s" ∈ Z n such that x ≡ s"X mod q}, and the dual lattice ∧ q (X) of the lattice ∧ q ⊥ (X) is ∧ q ⊥ (X):={y ∈ Z m |<x, y> ≡ 0 mod q for all x ∈ ∧ q (X)}, β4 T represents the transpose of β4, represents the direct product, R c represents the region included in, and ∧ q ⊥ (A T ) ∩ R c is not an empty set, and the interpolation point selection unit, for any integer θ satisfying 0 < θ < q', and satisfies the interpolation point vector u~ j,1 ,…,u~ j,n' Select L(B~ j ) is ∧ q ⊥ (A T )∪{u~ j,1 ,…,u~ j,n' }, the lattice L(∧ q ⊥ (A T )∪{u~ j,1 ,…,u~ j,n' }), and the sample point selection unit selects linearly independent sample point vectors b~ j,1 ,…,b~ j,m' ∈L(B~ j )∩R c Select a computing device.

3. The computing device of claim 2, wherein m=2 and n=1, m'=m=2 and n'=1, υ represents an integer greater than or equal to 0, ξ represents a positive integer, and q' is a Fibonacci sequence {F k } k=0,...,∞ element F belonging to ξυ+2 , j=1,...,m, κ=1,2, Z denotes the set of integers, and B - 1 and B - 2 is the dual lattice ∧ q ⊥ (A T ), and B - j ={b - j,1 ,b - j,2 } and b - j,κ ∈Z 2 and the interpolation point vector u~ j,1 but and the subdivision point vector d~ j,1 ,…,d~ j,ξυ+1 but and the sample point vector b~ satisfies j,1 ,…,b~ j,m' is the interpolation point vector u~ j,1 and the subdivision point vector d~ j,1 ,…,d~ j,ξυ+1 Based on the lattice L(B~ j ) basis B~ j ={b~ j,1 ,...,b~ j,m }, which is the m-dimensional vector b~ j,1 ,...,b~ j,m A computing device.

4. The computing device of claim 3, wherein π~(q) is a Fibonacci sequence {F k mod q} k=0 ∞ A computing device that represents the period of zeros that appear in , where υ = π~(q).

5. The computing device of claim 2, wherein m'=m and n'=1, j=1, . . . , m, υ represents an integer greater than or equal to 0, ξ, k represent positive integers, and an m×m matrix And the m-dimensional vector [F k-m+2 ,...,F k ,F k+1 ] T and [0,...,0,1] T Regarding B - is the dual lattice ∧ q ⊥ (A T ), and P1,P2,...,P m represents the permutation matrix, and B - P1,B - P2,...,B - P m The Hermitian normal form HNF(B - P1), HNF(B - P2),...,HNF(B - P m ) are m × m matrices and I n represents the mn×mn identity matrix, and * m-n,n represents an mn×n matrix whose elements are non-negative integers less than q, and 0 n,m-n represents the n×mn zero matrix, and q n represents an n×n matrix whose diagonal elements are q and other elements are zero, and B - 1=HNF(B - P1)P1 T ,B - 2=HNF(B - P2)P2 T ,...,B - m =HNF(B - P m )P m T represents B - j m-dimensional vector b - j,1 ,...,b - j,m where ν represents a positive integer and {b - j,k } k=1,...,∞ but the first m elements are b - j,1 ,...,b - j,m is a sequence of vectors whose first (m+ν) element is the sum of the m elements immediately preceding the (m+ν) element, teeth is the vector in the last row of the interpolation point vector u~ j,1 but and G k but is the sum of the elements in the last row of the sequence {G k } k=0,...,∞ element G belonging to ξυ and the subdivision point vector d~ j,1 ,…,d~ j,ξυ-1 but and the sample point vector b~ satisfies j,1 ,…,b~ j,m' is the interpolation point vector u~ j,1 and the subdivision point vector d~ j,1 ,…,d~ j,ξυ+1 Based on the lattice L(B j ) basis B~ j ={b~ j,1 ,...,b~ j,m }, which is the m-dimensional vector b~ j,1 ,...,b~ j,m A computing device.

6. The computing device of claim 5, wherein υ=m+1.

7. A computing device having a vector generation unit and an input quantum state identification unit, wherein m and n represent positive integers, α is a positive real number, q and q' represent integers greater than 1, j=1,...,m, e represents Napier's constant, i represents the imaginary unit, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, σ=αq, and N(0,σ 2 ) is Z q The above is a Gaussian distribution with mean 0 and standard deviation σ, and B~ j is the lattice L(B~ j ) represents the m × m matrix that represents the basis of b~ j,1 ,...,b~ j,m is the base B~ j represents the m m-dimensional vectors that make up the set β, |β0| represents the absolute value of β0, #β represents the number of elements that belong to the set β, 〈β1,β2〉 represents the inner product of β1 and β2, |β1〉 represents the column vector β1, and a1,a2,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is represents an m-dimensional column vector satisfying the above equation, and X is an m-dimensional column vector x1,…,x n ∈Z m The set {x1,…,x n }, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q}, and the lattice ∧ q Dual lattice of (X) ∧ q ⊥ (X) is ∧ q ⊥ (X):={y∈Z m |<x,y> ≡0 mod q for all x∈∧ q (X)} and β4 T represents the transposition of β4, and B R represents the interior of a given region, and Ω j ⊆Z q' m is Ω j B~ j =B R ∩L(B~ j ) and the input quantum state specifying unit specifies the input quantum state A computing device that obtains information identifying the 8. A computing device having a vector generation unit and an input quantum state identification unit, wherein m and n represent positive integers, α is a positive real number, q, q', and ζ represent integers greater than 1, j = 1,...,m, k' = 0,...,ζ, k" = 1,...,ζ, k'1,k'2 ∈ {0,...,ζ}, 0≦k'1<k'2≦ζ, e represents Napier's constant, i represents the imaginary unit, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, σ=αq, and N(0,σ 2 ) is Z q The above is a Gaussian distribution with mean 0 and standard deviation σ, and B~ j is the lattice L(B~ j ), where 〈β1,β2〉 denotes the inner product of β1 and β2, |β1〉 denotes the column vector β1, and a1,a2,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is represents an m-dimensional column vector satisfying the above equation, and X is an m-dimensional column vector x1,…,x n ∈Z m The set {x1,…,x n }, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q} and B is a lattice ∧ q (A T ), and B0,...,B ζ is the lattice ∧ q (A T ) represents an m × m matrix that represents the basis of the sublattice, where B = B0 and β4 T represents the transpose of β4, is a direct product, and H k"-1,k" is B k" =H k"-1,k" B k"-1 represents an m × m matrix that satisfies and L(C j,0 ),L(C j,1 ),...,L(C j,ζ ),L(D j,0 ),L(D j,1 ),...,L(D j,ζ ),L(E j,ζ ) is a lattice and h is an m-dimensional vector h=(h1,...,h m ) and and g(h)=(h1 mod q',...,h m mod q') is a function, B(j) h∈L(B~ j ) and and and C(j,k') h∈L(C j,k' ) and C(j,k') h:=( C(j,k') h1,..., C(j,k') h m ) and Dg(j,k') h:=g( C(j,k') h1,..., C(j,k') h m ) Dg(j,k') h∈L(D j,k' ) and and D(j,k"-1) h∈L(D j,k"-1 ) and D(j,k") h∈L(D j,k" ) and E j,k' :=D j,k' ・H k':ζ T where x(k') is an m-dimensional vector, teeth, z(j,k'):=y(j,k')・H k':ζ T and and L(E j,0 ) is E j,0 is a lattice with basis z(0)∈L(E j,0 ) and x(0)・B~ j ∈L(B~ j ) and Fulfilling and L(E j,ζ ) is E j,ζ is a lattice with a basis of L z∈L(E j,ζ ) and δ1,...,δ ζ ∈{0,1}, L z∈δ1z(j,1)+...+δ ζ z(j,ζ)+L(E j,0 ) and and the vector generation unit is A set of m-dimensional vectors Θ that satisfies j,ζ and the input quantum state specifying unit obtains the input quantum state A computing device that obtains information identifying the 9. A computing device having an input quantum state generation unit, a state alignment operation unit, an inverse quantum Fourier transform unit, an observation unit, a label calculation unit, and a solution generation unit, where m and n represent positive integers, q and q' represent integers greater than 1, j = 1,..., m, e represents the Napier number, i represents the imaginary unit, and Z q represents the quotient ring Z / qZ modulo q, Z represents the set of integers, B~ j represents an m×m matrix that is the basis of the lattice L(B~ j ), b~ j,1 ,..., b~ j,m represent m-dimensional vectors that constitute the basis B~ j , β4 T represents the transpose of β4, represents the direct product, |β0| represents the absolute value of β0, #β represents the number of elements belonging to the set β, 〈β1,β2〉 represents the inner product of β1 and β2, <β1| represents the row vector β1, |β1> represents the column vector β1, a1, a2,…, a m ∈Z q n each represent n-dimensional row vectors, A represents an m×n matrix , s∈Z q n represents an n-dimensional column vector, X represents a set {x1,…,x n ∈Z m} of n m-dimensional column vectors x1,…,x n , the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n s.t. x≡s"X mod q}, and the dual lattice ∧ q (X) of the lattice ∧ q ⊥ (X) is ∧ q ⊥ (X):={y∈Z m |<x,y>≡0 mod q for all x∈∧ q (X)}, B represents an m×m matrix that is the basis of the lattice ∧ q (A T ), the interpolation point vector u~ j,1 for any integer θ satisfying 0 < θ < q', and is a vector that satisfies B R represents the interior of a given region, and Ω j ⊆Z q' m Omega j B~ j =B R ∩L(B~ j ), and t∈Z q m represents an m-dimensional column vector, and v∈L(B):=∧ q (A T ) label L j (v) and and the input quantum state generation unit generates an input quantum state and the state alignment operation unit generates the input quantum state |Ψ j,t >State alignment operation and put it into quantum state X j |Ψ j,t >, and the inverse quantum Fourier transform unit obtains the quantum state X j |Ψ j,t >Inverse quantum Fourier transform for and then put it into a quantum state. and the observation unit obtains the quantum state Observe the result z j and the label calculation unit calculates the observation result z j Label using L j (z j B), and the solution generator obtains the label L j (z j B) Using the solution s' j A computing device that obtains 10. A computing device having an input quantum state generation unit, an inverse quantum Fourier transform unit, an observation unit, a label calculation unit, and a solution generation unit, wherein m and n represent positive integers, α is a positive real number, q, q', ζ represent integers greater than 1, j = 1,...,m, k' = 0,...,ζ, k" = 1,...,ζ, k'1,k'2 ∈ {0,...,ζ}, 0≦k'1<k'2≦ζ, e represents Napier's constant, i represents the imaginary unit, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, σ=αq, and N(0,σ 2 ) is Z q The above is a Gaussian distribution with mean 0 and standard deviation σ, and B~ j is the lattice L(B~ j ), where 〈β1,β2〉 represents the dot product of β1 and β2, 〈β1| represents the row vector β1, |β1〉 represents the column vector β1, and a1,a2,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is represents an m-dimensional column vector satisfying the above equation, and X is an m-dimensional column vector x1,…,x n ∈Z m The set {x1,…,x n }, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q} and B={b1,...,b m } is a lattice ∧ q (A T ), and b1,...,b m is a row vector in the basis B, and L j (b1),...,L j (b m ) is the lattice ∧ q (A T )=L(B) m is the label corresponding to z j =(OM j,1 ,...,OM j,m )∈Z q' m and B0,...,B ζ is the lattice ∧ q (A T ) represents an m × m matrix that represents the basis of the sublattice, where B = B0 and β4 T represents the transpose of β4, is a direct product, and H k"-1,k" is B k" =H k"-1,k" B k"-1 represents an m × m matrix that satisfies and L(C j,0 ),L(C j,1 ),...,L(C j,ζ ),L(D j,0 ),L(D j,1 ),...,L(D j,ζ ),L(E j,ζ ) is a lattice and h is an m-dimensional vector h=(h1,...,h m ) and and g(h)=(h1 mod q',...,h m mod q') is a function, B(j) h∈L(B~ j ) and and and C(j,k') h∈L(C j,k' ) and C(j,k') h:=( C(j,k') h1,..., C(j,k') h m ) and Dg(j,k') h:=g( C(j,k') h1,..., C(j,k') h m ) Dg(j,k') h∈L(D j,k' ) and and D(j,k"-1) h∈L(D j,k"-1 ) and D(j,k") h∈L(D j,k" ) and E j,k' :=D j,k' ・H k':ζ T where x(k') is an m-dimensional vector, teeth, z(j,k'):=y(j,k')・H k':ζ T and and L(E j,0 ) is E j,0 is a lattice with basis z(0)∈L(E j,0 ) and x(0)・B~ j ∈L(B~ j ) and Fulfilling and L(E j,ζ ) is E j,ζ is a lattice with a basis of L z∈L(E j,ζ ) and δ1,...,δ ζ ∈{0,1}, L z∈δ1z(j,1)+...+δ ζ z(j,ζ)+L(E j,0 ) and and and the input quantum state generation unit generates an input quantum state and the inverse quantum Fourier transform unit generates the input quantum state |Ψ j,t >Inverse quantum Fourier transform for and then put it into a quantum state. and the observation unit obtains the quantum state Observation results OM j =(OM j,1 ,...,OM j,m ), and the label calculation unit obtains the observation result OM j Label with and the solution generating unit obtains the label L j (z j B ζ ) to find the solution s' j A computing device that obtains 11. A computing device having a difference generation unit and a solution generation unit, where m and n represent positive integers, α represents a positive real number, q and q' represent integers greater than 1, j = 1,..., m, and Z q represents the quotient ring Z / qZ modulo q, β4 T represents the transpose of β4, σ = αq, and N(0, σ 2 ) represents the Gaussian distribution on Z q with mean 0 and standard deviation σ, a1, a2,…, a m ∈Z q n each represent an n-dimensional row vector, A represents an m×n matrix , ε represents an m-dimensional column vector with real elements following the Gaussian distribution N(0, σ 2 ), s ∈ Z q n represents an n-dimensional column vector, t represents an m-dimensional column vector satisfying, X represents a set of n m-dimensional column vectors x1,…, x n ∈Z m {x1,…, x n} is denoted as the lattice ∧ q (X) where ∧ q (X):={x ∈ Z m |∃s" ∈ Z n s.t. x ≡ s"X mod q}, and the dual lattice ∧ q (X) of the lattice ∧ q ⊥ (X) is ∧ q ⊥ (X):={y ∈ Z m |<x, y> ≡ 0 mod q for all x ∈ ∧ q (X)}, the interpolation point vector u~ j,1 is a vector satisfying 0 < θ < q' for any integer θ, and , and , The difference generation unit uses the solutions s'1,..., s' m to obtain the difference vector , The solution generation unit uses the difference vector t - ε, the integer q, and the matrix A to obtain the column vector s satisfying As ≡ t - ε mod q. A computing device.

12. A computing device having an interpolation point selection unit, a sample point selection unit, an input quantum state generation unit, a state alignment operation unit, an inverse quantum Fourier transform unit, an observation unit, a label calculation unit, a first solution generation unit, a difference generation unit, and a second solution generation unit, wherein m and n represent positive integers, α represents a positive real number, q and q' represent integers greater than 1, j = 1,...,m, and Z q represents the quotient ring Z / qZ modulo q, Z represents the set of integers, |β0| represents the absolute value of β0, #β represents the number of elements belonging to the set β, 〈β1,β2〉 represents the inner product of β1 and β2, 〈β1| represents the horizontal vector β1, |β1〉 represents the vertical vector β1, e represents Napier's constant, i represents the imaginary unit, σ=αq, and N(0,σ 2 ) is Z q The above represents a Gaussian distribution with mean 0 and standard deviation σ, and a1, a2, …, a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is represents an m-dimensional column vector satisfying the above equation, and X is an m-dimensional column vector x1,…,x n ∈Z m The set {x1,…,x n }, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q}, and the lattice ∧ q Dual lattice of (X) ∧ q ⊥ (X) is ∧ q ⊥ (X):={y∈Z m |<x,y> ≡0 mod q for all x∈∧ q (X)} and β4 T represents the transposition of β4, represents the direct product, and R c but represents the region contained in q ⊥ (A T )∩R c is not an empty set, and the interpolation point selection unit selects an interpolation point vector u~ that satisfies 0 < θ < q' for any integer θ that satisfies and and satisfies j,1 selects, and L(B~ j ) is ∧ q ⊥ (A T )∪u~ j,1 generates the lattice L(∧ q ⊥ (A T )∪u~ j,1 ) represents, and the sample point selection unit selects linearly independent sample point vectors b~ j,1 ,…,b~ j,m ∈L(B~ j )∩R c selects, and B - j is the dual lattice ∧ q ⊥ (A T ) represents the m×m matrix of the basis, B~ j represents the m×m matrix of the basis of the lattice L(B~ j ), B R represents the interior of a predetermined region, and Ω j ⊆Z q' m is the set of m-dimensional vectors that satisfy Ω j B~ j =B R ∩L(B~ j ), and the input quantum state generation unit generates the input quantum state , and B~ j represents the m×m matrix of the basis of the lattice L(B~ j ), B is the m×m matrix of the basis of the lattice ∧ q (A T ), and , and the state alignment operation unit performs the state alignment operation j,t on the input quantum state |Ψ to obtain the quantum state X j |Ψ j,t >, and the inverse quantum Fourier transform unit performs the inverse quantum Fourier transform on the quantum state X j |Ψ j,t >Inverse quantum Fourier transform for and then put it into a quantum state. and the observation unit obtains the quantum state Observe the result z j and the label calculation unit calculates the observation result z j Label using L j (z j B) is obtained, and b~ j,1 ,...,b~ j,m is the base B~ j Denotes m vectors of dimension m that compose B, and v∈L(B):=∧ q (A T ) label L j (v) and the first solution generating unit generates the label L j (z j B) Using the solution s' j Obtained, and the difference generator generates the solutions s'1,...,s' m Using the difference vector the second solution generating unit uses the difference vector t-ε, the integer q, and the matrix A to obtain the column vector s that satisfies As≡t-ε mod q.

13. A computing device having an interpolation point selection unit, a sample point selection unit, an input quantum state generation unit, an inverse quantum Fourier transform unit, an observation unit, a label calculation unit, a first solution generation unit, a difference generation unit, and a second solution generation unit, wherein m and n represent positive integers, α represents a positive real number, q, q', and ζ represent integers greater than 1, j = 1,...,m, k' = 0,...,ζ, k" = 1,...,ζ, k'1,k'2 ∈ {0,...,ζ}, 0≦k'1<k'2≦ζ, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, 〈β1,β2〉 denotes the dot product of β1 and β2, 〈β1| denotes the row vector β1, |β1〉 denotes the column vector β1, e denotes Napier's constant, i denotes the imaginary unit, σ=αq, and N(0,σ 2 ) is Z q The above represents a Gaussian distribution with mean 0 and standard deviation σ, and a1, a2, …, a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is represents an m-dimensional column vector satisfying the above equation, and X is an m-dimensional column vector x1,…,x n ∈Z m The set {x1,…,x n }, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q}, and the lattice ∧ q Dual lattice of (X) ∧ q ⊥ (X) is ∧ q ⊥ (X):={y∈Z m |<x,y> ≡0 mod q for all x∈∧ q (X)}, and b1,...,b m is a row vector in the basis B, and L j (b1),...,L j (b m ) is the lattice ∧ q (A T )=L(B) m is the label corresponding to z j =(OM j,1 ,...,OM j,m )∈Z q' m and B0,...,B ζ is the lattice ∧ q (A T ) represents an m × m matrix that represents the basis of the sublattice, where B = B0 and β4 T represents the transpose of β4, represents the Cartesian product, and H k"-1,k" is B k" =H k"-1,k" B k"-1 represents an m × m matrix that satisfies and L(C j,0 ),L(C j,1 ),...,L(C j,ζ ),L(D j,0 ),L(D j,1 ),...,L(D j,ζ ),L(E j,ζ ) is a lattice and h is an m-dimensional vector h=(h1,...,h m ) and and g(h)=(h1 mod q',...,h m mod q') is a function, B(j) h∈L(B~ j ) and and and C(j,k') h∈L(C j,k' ) and C(j,k') h:=( C(j,k') h1,..., C(j,k') h m ) and Dg(j,k') h:=g( C(j,k') h1,..., C(j,k') h m ) Dg(j,k') h∈L(D j,k' ) and and D(j,k"-1) h∈L(D j,k"-1 ) and D(j,k") h ∈ L(D j,k" ) and E j,k' := D j,k' ・ H k':ζ T and x(k') is an m - dimensional vector is not included in, and z(j, k') := y(j, k')・ H k':ζ T and and L(E j,0 ) is a lattice with E j,0 as the basis, z(0) ∈ L(E j,0 ) and x(0)・ B~ j ∈ L(B~ j ) and satisfies and L(E j,ζ ) is a lattice with E j,ζ as the basis L z ∈ L(E j,ζ ) and δ1,..., δ ζ ∈ {0, 1} and L z ∈ δ1z(j, 1)+...+δ ζ z(j, ζ)+L(E j,0 ) and and R c represents the region included in and ∧ q ⊥ (A T ) ∩ R c is not an empty set, and the interpolation point selection part selects an interpolation point vector u~ and that satisfies for any integer θ satisfying 0 < θ < q' j,1 and L(B~ j ) represents the lattice L(∧ q ⊥ (A T ) ∪ u~ j,1 generated from q ⊥ (A T ) ∪ u~ j,1 ) and the sample point selection part selects linearly independent sample point vectors b~ j,1 ,…, b~ j,m ∈L(B~ j )∩R c Select B - j is the dual lattice ∧ q ⊥ (A T ) represents the m × m matrix that represents the basis of B~ j is the lattice L(B~ j ), and and the input quantum state generation unit generates an input quantum state and the inverse quantum Fourier transform unit generates the input quantum state |Ψ j,t >Inverse quantum Fourier transform for and then put it into a quantum state. and the observation unit obtains the quantum state Observation results OM j =(OM j,1 ,...,OM j,m ), and the label calculation unit obtains the observation result OM j Label with and the solution generating unit obtains the label L j (z j B ζ ) to find the solution s' j A computing device that obtains 14. A calculation method comprising: an LWE reduction step in which, by an LWE reduction unit, using information for identifying an LWE problem, the LWE problem is transformed into a set of one-dimensional LWE-like problems in which the standard deviation of an error vector is determined for each element of the error vector, and information for identifying the set of one-dimensional LWE-like problems is obtained; a problem conversion step in which, by a problem conversion unit, the set of one-dimensional LWE-like problems is transformed into a set of phase estimation problems with errors, and information for identifying the set of phase estimation problems with errors is obtained; a solution step in which, by a solution conversion unit, the set of phase estimation problems with errors is solved, and a set of solutions to the phase estimation problems with errors is obtained; and a solution conversion step in which, by a solution conversion unit, the set of solutions to the phase estimation problems with errors is transformed into solutions to the LWE problem, and the solutions to the LWE problems are output.

15. A calculation method having an interpolation point selection step and a sample point selection step, where m, n, m', n', j represent positive integers, α represents a positive real number, q, q' represent integers greater than 1, and Z q represents the quotient ring Z / qZ with modulus q, Z represents the set of integers, σ = αq, and N(0, σ 2 ) represents a Gaussian distribution on Z q with mean 0 and standard deviation σ, ||β1|| represents the norm of β1, and a1, a2, …, a m ∈Z q n each represent an n-dimensional row vector, A represents an m×n matrix , ε represents an m-dimensional column vector with real elements following the Gaussian distribution N(0, σ 2 ), s ∈ Z q n represents an n-dimensional column vector, t represents an m-dimensional column vector satisfying, X represents a set {x1, …, x n ∈Z m} of n m-dimensional column vectors x1, …, x n , 〈β1, β2〉 represents the inner product of β1 and β2, and the lattice ∧ q (X) is ∧ q (X) := {x ∈ Z m | ∃s" ∈ Z n such that x ≡ s"X mod q}, and the dual lattice ∧ q (X) of the lattice ∧ q ⊥ (X) is ∧ q ⊥ (X) := {y ∈ Z m | <x, y> ≡ 0 mod q for all x ∈ ∧ q (X)}, β4 T represents the transpose of β4, represents the direct product, R c represents a region contained in, and ∧ q ⊥ (A T ) ∩ R c is not an empty set. The interpolation point selection step is such that, for any integer θ satisfying 0 < θ < q' by an interpolation point selection unit, and The interpolation point vector u~ that satisfies j,1 ,…,u~ j,n' This is the step of selecting L(B~ j ) is ∧ q ⊥ (A T )∪{u~ j,1 ,…,u~ j,n' }, the lattice L(∧ q ⊥ (A T )∪{u~ j,1 ,…,u~ j,n' }), and the sample point selection step is performed by a sample point selection unit to select linearly independent sample point vectors b~ j,1 ,…,b~ j,m' ∈L(B~ j )∩R c A calculation method is selected.

16. A calculation method having a vector generation step and an input quantum state identification step, wherein m and n represent positive integers, α is a positive real number, q and q' represent integers greater than 1, j = 1,...,m, e represents Napier's constant, i represents the imaginary unit, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, σ=αq, and N(0,σ 2 ) is Z q The above is a Gaussian distribution with mean 0 and standard deviation σ, and B~ j is the lattice L(B~ j ) represents the m × m matrix that represents the basis of b~ j,1 ,...,b~ j,m is the base B~ j represents the m m-dimensional vectors that make up the set β, |β0| represents the absolute value of β0, #β represents the number of elements that belong to the set β, 〈β1,β2〉 represents the inner product of β1 and β2, |β1〉 represents the column vector β1, and a1,a2,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is represents an m-dimensional column vector satisfying the above equation, and X is an m-dimensional column vector x1,…,x n ∈Z m The set {x1,…,x n }, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q}, and the lattice ∧ q Dual lattice of (X) ∧ q ⊥ (X) is ∧ q ⊥ (X):={y∈Z m |<x,y> ≡0 mod q for all x∈∧ q (X)} and β4 T represents the transposition of β4, and B R represents the interior of a predetermined region, and the vector generating step is performed by a vector generating unit to generate Ω j B~ j =B R ∩L(B~ j ) is an m-dimensional vector Ω j ⊆Z q' m The input quantum state specifying step is a step of obtaining an input quantum state by an input quantum state specifying unit. A calculation method in which information identifying the 17. A calculation method having a vector generation step and an input quantum state identification step, wherein m and n represent positive integers, α is a positive real number, q, q', and ζ represent integers greater than 1, j = 1,...,m, k' = 0,...,ζ, k" = 1,...,ζ, k'1,k'2 ∈ {0,...,ζ}, 0≦k'1<k'2≦ζ, e represents Napier's constant, i represents the imaginary unit, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, σ=αq, and N(0,σ 2 ) is Z q The above is a Gaussian distribution with mean 0 and standard deviation σ, and B~ j is the lattice L(B~ j ), where 〈β1,β2〉 denotes the inner product of β1 and β2, |β1〉 denotes the column vector β1, and a1,a2,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is represents an m-dimensional column vector satisfying the above equation, and X is an m-dimensional column vector x1,…,x n ∈Z m The set {x1,…,x n }, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q} and B is a lattice ∧ q (A T ), and B0,...,B ζ is the lattice ∧ q (A T ) represents an m × m matrix that represents the basis of the sublattice, where B = B0 and β4 T represents the transpose of β4, is a direct product, and H k"-1,k" is B k" =H k"-1,k" B k"-1 represents an m × m matrix that satisfies and L(C j,0 ),L(C j,1 ),...,L(C j,ζ ),L(D j,0 ),L(D j,1 ),...,L(D j,ζ ),L(E j,ζ ) is a lattice and h is an m-dimensional vector h=(h1,...,h m ) and and g(h)=(h1 mod q',...,h m mod q') is a function, B(j) h∈L(B~ j ) and and and C(j,k') h∈L(C j,k' ) and C(j,k') h:=( C(j,k') h1,..., C(j,k') h m ) and Dg(j,k') h:=g( C(j,k') h1,..., C(j,k') h m ) Dg(j,k') h∈L(D j,k' ) and and D(j,k"-1) h∈L(D j,k"-1 ) and D(j,k") h∈L(D j,k" ) and E j,k' :=D j,k' ・H k':ζ T where x(k') is an m-dimensional vector, teeth, z(j,k'):=y(j,k')・H k':ζ T and and L(E j,0 ) is E j,0 is a lattice with basis z(0)∈L(E j,0 ) and x(0)・B~ j ∈L(B~ j ) and Fulfilling and L(E j,ζ ) is E j,ζ is a lattice with a basis of L z∈L(E j,ζ ) and δ1,...,δ ζ ∈{0,1}, L z∈δ1z(j,1)+...+δ ζ z(j,ζ)+L(E j,0 ) and and the vector generating step is performed by a vector generating unit. A set of m-dimensional vectors Θ that satisfies j,ζ The input quantum state specifying step is a step of obtaining an input quantum state by an input quantum state specifying unit. A calculation method in which information identifying the 18. A computational method having an input quantum state generation step, a state alignment operation step, an inverse quantum Fourier transform step, an observation step, a label calculation step, and a solution generation step, where m, n represent positive integers, q, q' represent integers greater than 1, j = 1,..., m, e represents the Napier number, i represents the imaginary unit, and Z q represents the quotient ring Z / qZ with q as the modulus, Z represents the set of integers, B~ j represents an m×m matrix that is the basis of the lattice L(B~ j ), b~ j,1 ,..., b~ j,m represent m-dimensional vectors that form the basis B~ j , β4 T represents the transpose of β4, represents the direct product, |β0| represents the absolute value of β0, #β represents the number of elements belonging to the set β, 〈β1,β2〉 represents the inner product of β1 and β2, <β1| represents the row vector β1, |β1> represents the column vector β1, a1, a2,…, a m ∈Z q n each represent an n-dimensional row vector, A represents an m×n matrix s represents an n-dimensional column vector, s∈Z q n represents an n-dimensional column vector, X represents a set {x1,…,x n ∈Z m} of n m-dimensional column vectors x1,…,x n , the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n s.t. x≡s"X mod q}, and the dual lattice ∧ q (X) of the lattice ∧ q ⊥ (X) is ∧ q ⊥ (X):={y∈Z m |<x,y>≡0 mod q for all x∈∧ q (X)}, B represents an m×m matrix that is the basis of the lattice ∧ q (A T ), and for any integer θ satisfying 0 < θ < q', the interpolation point vector u~ j,1 ​ and represents a vector that satisfies B R represents the interior of a given region, and Ω j ⊆Z q' m Omega j B~ j =B R ∩L(B~ j ), and t∈Z q m is an m-dimensional column vector, x∈Z and v~,w~∈L(B~ j ) for L~ j (b~ j,1 ),...,L~ j (b~ j,m )∈Z q' is the lattice L(B~ j ) are the labels corresponding to the grid points of L~ j (xu~ j,1 )=x mod q' and L~ j (v~)=L~ j (w~) and v~-w~∈∧ q ⊥ (A T ) is equivalent to L~ j -1 (0),L~ j -1 (1),...,L~ j -1 (q'-1) is the label L j (b~ j,1 ),...,L~ j (b~ j,m ) among Ω j is the inverse image of the label in B, and v∈L(B):=∧ q (A T ) label L j (v) and and the input quantum state generation step is performed by an input quantum state generation unit. The state alignment operation step is a step of generating the input quantum state |Ψ by a state alignment operation unit. j,t >State alignment operation and put it into quantum state X j |Ψ j,t >, and the inverse quantum Fourier transform step is a step of obtaining the quantum state X j |Ψ j,t >Inverse quantum Fourier transform for and then put it into a quantum state. The observation step is a step of obtaining the quantum state Observe the result z j The label calculation step is a step of obtaining the observation result z j Label using L j (z j B), and the solution generating step is a step of obtaining the label L j (z j B) Using the solution s' j The calculation method is a step of obtaining 19. A computational method having an input quantum state generation step, an inverse quantum Fourier transform step, an observation step, a label calculation step, and a solution generation step, wherein m and n represent positive integers, α is a positive real number, q, q', and ζ represent integers greater than 1, j = 1,...,m, k' = 0,...,ζ, k" = 1,...,ζ, k'1,k'2 ∈ {0,...,ζ}, 0≦k'1<k'2≦ζ, e represents Napier's constant, i represents the imaginary unit, and Z q denotes the quotient ring Z / qZ modulo q, Z denotes the set of integers, σ=αq, and N(0,σ 2 ) is Z q The above is a Gaussian distribution with mean 0 and standard deviation σ, and B~ j is the lattice L(B~ j ), where 〈β1,β2〉 represents the dot product of β1 and β2, 〈β1| represents the row vector β1, |β1〉 represents the column vector β1, and a1,a2,…,a m ∈Z q n are n-dimensional row vectors, and A is an m×n matrix. where ε is the Gaussian distribution N(0, σ 2 ), and s∈Z q n represents an n-dimensional column vector, and t is represents an m-dimensional column vector satisfying the above equation, and X is an m-dimensional column vector x1,…,x n ∈Z m The set {x1,…,x n }, and the lattice ∧ q (X) is ∧ q (X):={x∈Z m |∃s"∈Z n st x≡s"X mod q} and B={b1,...,b m } is a lattice ∧ q (A T ), and b1,...,b m is a row vector in the basis B, and L j (b1),...,L j (b m ) is the lattice ∧ q (A T )=L(B) m is the label corresponding to z j =(OM j,1 ,...,OM j,m )∈Z q' m and B0,...,B ζ is the lattice ∧ q (A T ) represents an m × m matrix that represents the basis of the sublattice, where B = B0 and β4 T represents the transpose of β4, is a direct product, and H k"-1,k" is B k" =H k"-1,k" B k"-1 represents an m × m matrix that satisfies and L(C j,0 ),L(C j,1 ),...,L(C j,ζ ),L(D j,0 ),L(D j,1 ),...,L(D j,ζ ),L(E j,ζ ) is a lattice and h is an m-dimensional vector h=(h1,...,h m ) and and g(h)=(h1 mod q',...,h m mod q') is a function, B(j) h∈L(B~ j ) and and and C(j,k') h∈L(C j,k' ) and C(j,k') h:=( C(j,k') h1,..., C(j,k') h m ) and Dg(j,k') h:=g( C(j,k') h1,..., C(j,k') h m ) Dg(j,k') h∈L(D j,k' ) and and D(j,k"-1) h∈L(D j,k"-1 ) and D(j,k") h∈L(D j,k" ) and E j,k' :=D j,k' ・H k':ζ T where x(k') is an m-dimensional vector, teeth, z(j,k'):=y(j,k')・H k':ζ T and and L(E j,0 ) is E j,0 is a lattice with basis z(0)∈L(E j,0 ) and x(0)・B~ j ∈L(B~ j ) and Fulfilling and L(E j,ζ ) is E j,ζ is a lattice with a basis of L z∈L(E j,ζ ) and δ1,...,δ ζ ∈{0,1}, L z∈δ1z(j,1)+...+δ ζ z(j,ζ)+L(E j,0 ) and and and the input quantum state generation step is performed by an input quantum state generation unit. The inverse quantum Fourier transform step is a step of generating the input quantum state |Ψ by an inverse quantum Fourier transform unit. j,t >Inverse quantum Fourier transform for and then put it into a quantum state. The observation step is a step of obtaining the quantum state Observation results OM j =(OM j,1 ,...,OM j,m ), and the label calculation step is a step of obtaining the observation result OM j Label with The solution generating step is a step of obtaining the label L j (z j B ζ ) to find the solution s' j The calculation method is a step of obtaining 20. A computational method having a difference generation step and a solution generation step, where m and n represent positive integers, α represents a positive real number, q and q' represent integers greater than 1, j = 1,..., m, and Z q represents the quotient ring Z / qZ modulo q, β4 T represents the transpose of β4, σ = αq, and N(0, σ 2 ) represents a Gaussian distribution on Z q with mean 0 and standard deviation σ, a1, a2,…, a m ∈Z q n each represent an n-dimensional row vector, A represents an m×n matrix , ε represents an m-dimensional column vector with real elements following the Gaussian distribution N(0, σ 2 ), s ∈ Z q n represents an n-dimensional column vector, t represents an m-dimensional column vector satisfying , X represents a set {x1,…, x n ∈Z m} of n m-dimensional column vectors x1,…, x n , the lattice ∧ q (X) is ∧ q (X):={x ∈ Z m |∃s" ∈ Z n s.t. x ≡ s"X mod q}, and the dual lattice ∧ q (X) of the lattice ∧ q ⊥ (X) is ∧ q ⊥ (X):={y ∈ Z m |<x, y> ≡ 0 mod q for all x ∈ ∧ q (X)}, the interpolation point vectors u~ j,1 ,…, u~ j,n' for any integer θ satisfying 0 < θ < q', and are vectors satisfying , and the difference generation step is, by a difference generation unit, using the solutions s'1,..., s' m to obtain the difference vector the solution generating step is a step of obtaining, by a solution generating unit, the column vector s that satisfies As≡t-ε mod q, using the difference vector t-ε, the integer q, and the matrix A.

21. A program that causes a computer to function as the computing device of any one of claims 1, 2, 7-13.