Method of creating encrypted clones of a qudit with quantum processor

The method of creating encrypted clones using a quantum processor addresses the no-cloning theorem by entangling clones with noise qubits, enabling secure, deterministic recovery of quantum states while respecting the theorem's constraints.

WO2026087623A1PCT designated stage Publication Date: 2026-04-30KEMPF ACHIM +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
KEMPF ACHIM
Filing Date
2025-10-22
Publication Date
2026-04-30

AI Technical Summary

Technical Problem

The no-cloning theorem prohibits the creation of identical, independent copies of an arbitrary quantum state, posing challenges for quantum data duplication and redundancy, and existing cloning methods suffer from limitations such as imperfect fidelity, probabilistic success, or state-specific applicability, making them unsuitable for secure data storage and fault-tolerant computation.

Method used

A method for creating encrypted clones of a quantum state using a quantum processor, where each clone is entangled with noise qubits that hold the encryption key, allowing deterministic decryption of one clone while maintaining compliance with the no-cloning theorem.

Benefits of technology

This approach enables the creation of multiple perfect copies of arbitrary quantum states, ensuring data integrity and security by encrypting each clone, with decryption consuming the key, thus adhering to the no-cloning theorem and preventing unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025080545_30042026_PF_FP_ABST
    Figure EP2025080545_30042026_PF_FP_ABST
Patent Text Reader

Abstract

The method can include preparing a quantum state ρ A in a system qubit A; preparing n pairs of ancillary qubits {Si,Ni}, each pair of ancillary qubits including a signal qubit Si, and a noise qubit Ni, wherein the signal qubit Si and noise qubit Ni of each pair of ancillary qubits is prepared in a maximally entangled (Bell) state |Φ〉 SiNi ; and applying an encoding operation (I) to the system qubit A and the signal qubits {Si}, including entangling the system qubit A with the signal qubits, turning the signal qubits {Si} into noisy copies of the quantum state ρ A .
Need to check novelty before this filing date? Find Prior Art

Description

METHOD OF CREATING ENCRYPTED CLONES OF A QUDIT WITH QUANTUM PROCESSOR TECHNICAL FIELD

[0001] This application generally relates to the field of quantum computing, and more specifically to methods and systems for handling quantum information.BACKGROUND

[0002] The field of quantum information processing is governed by principles that are fundamentally different from those of classical information. Perhaps the most foundational and consequential of these is the no-cloning theorem, first formalized by Wootters, Zurek, and Dieks in 1982. The theorem states that it is impossible to create an identical, independent copy of an arbitrary, unknown quantum state. This prohibition is not a limitation of current technology but a direct consequence of the mathematical structure of quantum mechanics, specifically the principle of unitary evolution. Physical processes in quantum mechanics, in the absence of measurement, are described by a unitary operator, U. A hypothetical universal cloning machine would have to perform a transformation that takes an arbitrary unknown state \ fj)Aon a system A and a blank initial state |0)Bon a system B, and outputs two identical copies of the original state:The impossibility of such a universal unitary operator U can be demonstrated by considering its action on two distinct, non-orthogonal quantum states, \ (J) and \<p). Unitarity requires that the inner product between states is preserved by the transformation. Therefore, the inner product of the initial states must equal the inner product of the final states:

[0003] This equation, (i | ) = 〈ψ|φ〉2only holds if the inner product | (i |<p) I is equal to 0 or 1. This implies that the statesand \<p) must be either orthogonal or identical. Consequently, no single unitary process can successfully clone two arbitrary, non-orthogonal states, proving that a universal quantum cloning machine with perfect fidelity is physically impossible. This theorem has profound implications. It prevents the use of classical error correction techniques that rely on creating backup copies, necessitating the development of sophisticated quantumerror correction codes. It also forms the bedrock of security for quantum key distribution (QKD), as an eavesdropper cannot intercept and perfectly copy a quantum key without disturbing the original state in a detectable way. The no-cloning theorem, therefore, presents a fundamental barrier to any task that requires data duplication or redundancy, a common requirement in classical data storage and transmission.

[0004] Accordingly, there remained room in quantum computing for processes which allow to alleviate the impacts of the no-cloning theorem, namely in applications which could benefit from quantum data duplication or redundancy.SUMMARY

[0005] Different approaches can aim to alleviate the effect of the no-cloning theorem in quantum computing.

[0006] In a first example approach, approximate cloning can be performed. Approximate cloning abandons the goal of perfect fidelity to achieve a deterministic outcome. A system for performing approximate cloning can be designed to produce “good” copies of an arbitrary unknown state, where "good" may involve maximizing the fidelity between the input state pAand the output copies. For the canonical case of creating two copies from a single input qubit (a 1 2 cloner), the optimal fidelity of each copy with the original state is limited to 5 / 6, or approximately 83.3%. This fidelity limit is not a technological constraint but a fundamental one. The process necessarily introduces noise and results in an irretrievable loss of information. While this approach may be useful for tasks like quantum state estimation or for certain attacks on cryptographic protocols, the inherent imperfection of the copies makes it fundamentally unsuitable for applications like secure data storage or fault-tolerant computation, where perfect fidelity is paramount. Accordingly, methods based on approximate cloning may suffer from accumulating errors with each cloning generation, leading to a degradation of the quantum information.

[0007] In a second example approach, probabilistic cloning can be performed. Probabilistic cloning can, in principle, produce clones with high fidelity for a specific set of states. However, they do so at the cost of determinism. The cloning process succeeds only with a certain probability, which is less than 1 for non-orthogonal input states. A drawback of this approachis the outcome upon failure. A failure event may result in the complete destruction or irreversible alteration of the original quantum state. The maximum success probability is fundamentally limited and depends on the set of states being cloned.

[0008] Accordingly, probabilistic cloning may be ill adapted for applications involving valuable data. For example, in a data backup scenario, a failure of the cloning process would result in the loss of the very data one intended to protect.

[0009] In a third example approach, state-dependent cloning can be performed. Such a process may achieve higher fidelities than universal cloners but do so by sacrificing universality. Such processes can be specifically designed to operate on a restricted, predefined subset of quantum states. For instance, a phase-covariant cloner can optimally copy states that lie on the equator of the Bloch sphere but performs sub-optimally for other states. Other schemes are designed for specific sets of linearly independent states.

[0010] The requirement of a priori knowledge about the state to be cloned can limits the applicability of state-dependent cloning processes and render them ill adapted to general-purpose quantum information processing, where the state to be manipulated or stored is an unknown result of a previous computation.

[0011] It will be understood that each one of the three above-identified approaches may suffer from some limitations, making them maladapted to some applications.

[0012] In some embodiments, it was found that a fourth approach, encrypted cloning, could offer advantages, or an alternative, to one or more of the three approaches presented above. Such an approach can allow the creation of multiple, individually decryptable, perfect copies of arbitrary states, controlled by a master key. The decryption of any one of the copies renders the key unable to decrypt the remaining copies.

[0013] Indeed, it was found that while the no-cloning theorem forbids the creation of multiple independent and separable perfect copies. It does not prohibit the creation of a larger, entangled quantum system from which a single perfect copy can later be extracted.

[0014] In some embodiments, it was found possible to perform a process which creates a set of entangled and encrypted copies that, as a whole, respect the no-cloning theorem while individually providing resources for deterministic data recovery.

[0015] Quantum operations harnessed to human use, such as processes of creating encrypted clones, are performed with systems referred to as quantum computers, or quantum processors. The quantum computer can control the interaction between quantum states. While a classical computer holds classical information in binary “bits”, a quantum computer holds quantum information in qudits. Similarly to how bits can be embodied in many different ways with the goal of encoding the information in the form of binary 0’s and 1’s, the qudits can be embodied in many different ways with the goal of encoding the quantum information in the form of a superposition of states in a quantum system. The qudits may be two-level quantum systems, in which the quantum information can be encoded as a superposition of states |0) and |1>, in which case they may alternately be referred to as qubits. Alternately, the qudits may have more than two levels, such as d levels, in which case they can hold the quantum information as a superposition of states |0>, |1),... |d - 1). The latter set of orthonormal basis states is called the computational basis and can be chosen arbitrarily for each qudit. The expression “register” can be used in the context of a quantum computer to refer to a set of one or more qudits dedicated (temporarily - such as in the context of a specific quantum operation - or more permanently) to a given purpose in the context of performing quantum operations.

[0016] Indeed, encrypted clones of a qubit, A, can be produced through a unitary transformation, and that each of the encrypted clones can then be decrypted through a unitary transformation. The decryption of an encrypted clone consumes the decryption key, i.e., only one decryption is possible, in agreement with the no-cloning theorem. The number of gate operations needed for the encryption and decryption may scale linearly with the number of clones.

[0017] Such a process can begin with the preparation of n pairs of maximally entangled qubits, (SbNt), i =where we will refer to the St andas signal qubits and noise qubits respectively. The method of encrypted cloning then has A interact with all signal qubits Sbi = through a unitary operator U^c, that acts nontrivially only on qubit A and the signalqubits. Through this encoding operation, complete information about qubit A gets imprinted into each of the signal qubits St. At the same time, each of these imprints is encrypted due to the quantum noise in the Stfrom their initial maximal entanglement with the Nt. In this specification, the signal qubits Stcan be referred to alternatively as encrypted clones, or as noisy copies, of the original state of A.

[0018] The noise qubitsi = 1... n do not take part in the process of encrypted cloning, i.e., U^cacts as the identity on the Hilbert space of the N(. Therefore, theacquire neither classical nor quantum information about A. Instead, the role of the noise qubits is to keep a record of the quantum noise in the signal qubits so that, together, the set of all noise qubits N, i = 1... n forms the encryption key. By using and thereby consuming this key, any one and only one of the encrypted clones SLcan then be decrypted to reproduce the original state of qubit A. The decryption or ‘denoising’ of an encrypted clone Skis accomplished by a unitary, ^t acts nontrivially only on Skand the noise qubits Ni, i = 1... n, and it reproduces the original state of qubit A in qubit Sk.

[0019] In accordance with one aspect, there is provided a method for creating noisy copies of a quantum state pA, the method comprising: preparing the quantum state pAin a system qubit A; preparing n pairs of ancillary qubits {Si V, each pair of ancillary qubits including a signal qubit St, and a noise qubit N wherein the signal qubit Stand noise qubit / V, of each pair of ancillary qubits is prepared in a maximally entangled state | >Si7Vi Jar|d applying an encoding operation to the system qubit A and the signal qubits {S;}, including entangling the system qubit A with the signal qubits, turning the signal qubits {S into noisy copies of the quantum state pA.

[0020] In accordance with one aspect, there is provided a method for recovering a quantum state pA, the method comprising preparing a noisy copy of the quantum state pAin a signal qubit S;, preparing noise qubits { / V }, oneof the noise qubits { / V } being in a maximally entangled state |<>>s.w.with the signal qubit SL, and applying a decoding operationto the signal qubit 5^ and all noise qubits {^}, including recovering the quantum state pA.

[0021] In accordance with one aspect, there is provided a method for recovering a quantum state pA, the method comprising preparing a post-encoding state pAin a system qubit, preparing noise qubits {Nc}, applying a decoding operation U^c, where n is even, to the quantum state pAand all noise qubits {^}, including recovering the quantum state pA.

[0022] In accordance with one aspect, there is provided a method for recovering a quantum state pA, the method comprising preparing a post-encoding state pAin a system qubit, preparing system qubits {£}, applying a decoding operation U^?cto the system qubit and all system qubits { }, including recovering the quantum state pA, the decoding operation corresponding to an inverse of an encoding operation having transformed the quantum state pAinto the post-encoding state pA.

[0023] In accordance with one aspect, there is provided a method for recovering a quantum state pA, the method comprising preparing a pair of qubits (Sk, Nk) forming part of n pairs of ancillary qubits {Si Nt} being in a maximally entangle state \<p)SiNt > and, for each of the other n pairs of ancillary qubits {Si Ni} where i #= k, at least one of the signal qubit SLand the noise qubit Ni of the corresponding pair St Nt, and applying a decoding operation U^cto the pair (Sk, Nk) amongst the n pairs of ancillary qubits {Si V and, for each of the n pairs of ancillarynumbers satisfying |a = 1 and for any / for which i #= k. wherein when ucacts on the noise qubit Nj, then= a^Nl)T, where? denotes a transpose operation in a computational basis, and wherein whenacts on the signal Si, then / ?,. < =.

[0024] In accordance with another aspect, there is provided a quantum computer for creating n encrypted clones of a quantum state pA, the quantum computer comprising a system qudit, n ancillary qudit pairs, and a controller, the controller having a processor and a non-transitory memory, the non-transitory memory having instructions stored thereon, the instructions, when executed upon by the processor, causing the quantum computer to: prepare the quantumstate pAin the system qudit; prepare Bell states in the n ancillary qudit pairs with each of the n ancillary qubit pairs indexed i e {1,and including a signal qudit SLand a noise qudit Ni, the signal qudit SLand the noise qudit Ntof each one of the n ancillary qudit pairs being in one of the Bell states; and apply an encrypted cloning operator U. between the n signal qudits {Sj} and the system qudit while maintaining the noise qudits { / VJ isolated, thereby encoding information from quantum state ρAinto the n signal qudits {Si}.

[0025] In accordance with another aspect, there is provided a method of creating n encrypted clones of an initial qubit with a quantum computer the method comprising: preparing a quantum state pAin a system qubit of the quantum computer; preparing Bell states in n ancillary qubit pairs of a quantum computer with each of the n ancillary qubit pairs indexed i e {1,..., n} and including a signal qubit Stand a noise qubit Nt, the signal qubit Stand the noise qubit Ntof each ancillary qubit pair sharing a same quantum fluctuation; and applying an encrypted cloning operator U^. between the n signal qubits {S and the system qubit while maintaining the noise qubits { / VJ electromagnetically isolated, thereby encoding information from quantum state pAinto the n signal qubits {SJ, the noise qubits { / VJ holding a record of the quantum fluctuations in the n signal qubits {SJ.

[0026] Many further features and combinations thereof concerning the present improvements will appear to those skilled in the art following a reading of the instant disclosure.DESCRIPTION OF THE FIGURES

[0027] In the figures,

[0028] Fig. 1 is a schematic view of an example quantum computer;

[0029] Fig. 2 is a diagram of a quantum circuit;

[0030] Fig. 3 is a diagram of a quantum circuit;

[0031] Figs. 4A to 4C are diagrams of quantum circuits;

[0032] Fig. 5 is a schematic view of another example of a quantum computer; and

[0033] Fig. 6 is a schematic view of an example of a classical computer;DETAILED DESCRIPTION

[0034] Fig. 1 presents a highly simplistic example of a quantum computer (which may alternately be referred to as a quantum processor) operating on the basis of circuit-based quantum computations. The quantum computer shown in Fig. 1 has a quantum system which includes a plurality of quantum subsystems. In the context of quantum computing, the quantum subsystems are used to host logical states, in which case they can be referred to as qudits, and the quantum system can be referred to as a quantum processor 40. Quantum computers can have many quantum subsystems, such as 10’s of qudits, 100’s of qudits, or more. The nature of the qudits, how logical states are prepared and hosted in the qubits, and how operations (quantum interactions) are performed between the qudits, depend on the choice of architecture.

[0035] Indeed, quantum systems are subject to quantum interactions between different particles / fields. Quantum interactions typically involve the evolution of one or more quantum states over time. Quantum computers seek to control such quantum interactions in a manner to produce benefits for human use. Examples of particles which can exhibit quantum behavior at the subatomic level, and which can be harnessed for the purpose of quantum computing, include electrons and photons, but other approaches exist such as phonon-based approaches or cold atom / ion-based approaches. Various architectures exist for use as quantum computers and which are operable to control the evolution of quantum states, and the choice of a given architecture depends on the type of particles which are selected to exhibit quantum behavior in a given embodiment. Some architectures are more efficient for addressing certain types of problems. Quantum mechanics allows the quantum subsystems to be in a coherent superposition of more than one state simultaneously, a property which is fundamental to quantum computing.

[0036] The quantum computer can control the interaction between quantum states. While a classical computer holds classical information in binary “bits”, a quantum computer holds quantum information in qudits. Similarly to how bits can be embodied in many different ways with the goal of encoding the information in the form of binary 0’s and 1’s, the qudits can beembodied in many different ways with the goal of encoding the quantum information in the form of a superposition of states in a quantum system. The qudits may be two-level quantum systems, in which the quantum information can be encoded as a superposition of states |0) and |1>, in which case they may alternately be referred to as qubits. Alternately, the qudits may have more than two levels, such as d levels, in which case they can hold the quantum information as a superposition of states |0>, |1),... |d - 1). The latter set of orthonormal basis states is called the computational basis and can be chosen arbitrarily for each qudit. The expression “register” can be used in the context of a quantum computer to refer to a set of one or more qudits dedicated (temporarily - such as in the context of a specific quantum operation - or more permanently) to a given purpose in the context of performing quantum operations.

[0037] In many applications where qudits are based on bosonic encoding, for example, the logical states may be driven in some form of resonator using some form of driving hardware. The driving hardware is controlled by a component which will be referred to herein as a controller 42 for simplicity, and which may include a classical computer (i.e., a computer which uses binary bits rather than qubits to encode information). In many embodiments, the qudits are refrigerated to cryogenic temperatures and thermally insulated from the external environment. In an adiabatic quantum computing architecture, the quantum subsystems can be directly operably interconnected to one another. In circuit-based quantum computing, the quantum subsystems are typically interconnected to one another via couplers which are used to selectively control the interactions between the quantum subsystems. The couplers can also be quantum subsystems operable to host states via which the logical states of the two or more connecting quantum subsystems are to interact and are also driven by driving hardware which can be controlled by the same controller 42 for convenience. Readout ports can be provided via which the state of the qubits can be read, an operation which can be said to involve “measuring.”

[0038] Readout ports are used, for instance, when the results of quantum computations are intended to be read shortly after having been completed. Readout ports are optional and may be omitted namely in situations where the results of the controlled quantum interaction(s) are not intended to be read shortly after having been completed. This can the case, namely, when the quantum interactions are intended to perform encrypted cloning operations, since in manyapplications of encrypted cloning operations, the resulting encrypted clones are not intended to be read shortly after having been created.

[0039] The controller 42 can be expected to include a memory which can include computer-readable instructions executable to perform functions driving the operation of the controller 42 and devices it controls, and data. The functions can include a “driving program,” for instance, which, in the case of circuit-based quantum computing, can include a sequence of gates, typically referred to as a quantum circuit, stored as data in the memory. When the states of the qubits are read, the measured values can be stored in the form of data, for instance.

[0040] Performing a quantum computation can involve a quantum interaction, such as entanglement, between the physical states (which encode information) of the different quantum subsystems. However, for a quantum computation to occur, one may further actively initialize (prepare) the physical states of the quantum subsystems prior to the quantum interaction. Moreover, in many embodiments, the physical states resulting from the quantum interaction are actively measured (readout). Moreover, when performing a quantum computation in a circuit-based model, one may additionally actively control the interaction via a coupler which is changed from a configuration where it impedes interaction to a configuration where it favors interaction, and then back.

[0041] Henceforth, performing a given quantum computation can involve the steps of initializing (preparing), interacting, and measuring. “Interacting” can involve applying one or more gates, operators, or encoding, and can be performed in accordance with a quantum circuit, typically referred to as a “circuit” for short. Accordingly, any of the steps of preparing, initializing, interacting, and measuring may have corresponding hardware elements and an active control process associated therewith.

[0042] Any active control step may require associated elements of hardware. Moreover, in practical implementations, it is impossible to manually control the hardware associated with the active control steps in a context of the amount of time available to perform any one of these steps. Accordingly, automated control can be used to implement the active control steps. The automated control processes can take the form of associated functions defined by corresponding software modules. Accordingly, several elements of hardware, such aspreparing hardware, initializing hardware, coupler control hardware, and measuring hardware may involve automated, active control in the context of performing a single quantum computation. The control functions for such hardware elements may be performed via corresponding software modules which can be in the form of computer-readable instructions driving the operation of the controller.

[0043] The components of the quantum processor, such as the quantum subsystems and some or all of the control hardware, may be refrigerated to cryogenic temperatures and insulated from the environment and can therefore be said to be inside a refrigerator (e.g., cryogenic refrigerator), which can be a dilution refrigerator for instance. Components of the classical computer such as its processor and its non-transitory memory can be located outside the refrigerator. Electrical connections can therefore extend across an enclosure of the refrigerator, between the ambient temperature environment and the cryogenic environment. The combination of the classical computer, of the quantum processor, of the electrical connections, and of the refrigerator can be referred to collectively as a “quantum computer.”

[0044] While a simplistic scenario having a minimum of 2 quantum subsystems is schematized in solid lines in Fig. 1, in practice, it can be preferred to embody quantum computers with a significantly greater number of quantum subsystems, used as qubits, which can significantly affect the complexity of the overall system, both from the hardware and from the control process points of view.

[0045] It will also be noted thatqudits, including qubits, can be implemented either as physical qudits or logical qudits. Physical qubits typically correspond to a scenario where individual subsystems of hardware / individual physical states encode quantum information, which, in many cases, is subject to error. Logical qudits typically correspond to a scenario where multiple, e.g., redundant, elements of hardware encode the quantum information in an error-corrected way. In this specification, the expression qudit encompasses either physical qudit or logical qudit unless otherwise specified.

[0046] Returning to embodiments of methods of creating encrypted clones of a qubit, or qudit, it was found that one way to compose with the absolute prohibition of the no-cloning theorem is to perform the cloning concurrently with encryption. Accordingly, a method can create anumber n of "encrypted clones" of an arbitrary unknown quantum state (which will be referred to below as state pA). The number n can be an integer greater than or equal to two. In accordance with some embodiments, each encrypted clone, when examined individually, is in a maximally mixed state, revealing no information about the original state. However, any single one of the n encrypted clones can be deterministically decrypted to yield the original state by a quantum operation that consumes a quantum key.

[0047] The process of creating n encrypted clones can be performed with a quantum computer having a system qubit A which can be prepared in quantum state (superposition) pAto be cloned in an encrypted manner. The quantum computer can further have n ancillary qubit pairs. Each one of the n ancillary qubit pairs, indexed by i e {l,...,n], includes a “signal qubit" (S and a “noise qubit" (Nj) prepared in a Bell state | )s w. and therefore sharing the same quantum fluctuations. The system qubit and the ancillary qubits can be embodied as qudits.

[0048] Indeed, each pair (SbNi) can be prepared (initialized) in a Bell state (e.g., maximally entangled state), for example:

[0049] There are many Bell states, which are related to one another by a basis choice on a qubit system. The signal qubit and the noise qubit of each pair have the same quantum fluctuations (noise). In other words, they would both look like complete noise when looked at individually, but they share the same quantum fluctuations / noise. This initial entanglement between the signal qubit and the noise qubit of each pair is the source of the noise that will be used to encrypt the information from the system qubit.

[0050] The signal qubits {S are then brought to interact with the system qubit, (e.g., via a coupler) while the noise qubits {^} are kept separate in the sense that they are prevented from inadvertently interacting with the system qubit A, with the signal qubits {S, or with any other particles or fields which could disturb the quantum states of the noise qubits {^} during the encoding process and until the eventual decoding process has been completed. Theinteraction can correspond to the application of an encrypted cloning operator U^., and can be alternately referred to as an encoding operation. There are various ways in which the encrypted cloning operatorcan be embodied, some examples of which will be provided below. Subsequently to the application of the encrypted cloning operatoreach signal qubit SLis an encrypted clone, which can alternately be referred to as a noisy copy, of the quantum state pA. Subsequently to the application of the encrypted cloning operatorthe collective state of the noise qubits, { / V, can hold a record of the quantum fluctuations in the corresponding signal qubits (or noisy copies), and can be stored as a quantum decryption key.

[0051] Accordingly, there can be more than one encrypted clone SLfor each initial quantum state pA. Various use cases of the encrypted clones are possible; some examples being detailed below for illustrative purposes. Depending on the use case, the encrypted clones may be retained (stored) in the quantum computer or transmitted to one or more other quantum computer for storage (e.g., different ones of the encrypted clones can be sent to different quantum computers such as quantum “clouds”). The decryption key, which can be here in the form of the collective state of the noise qubits { / VJ, can be stored in the quantum computer, or transmitted to another quantum computer for storage, for instance. The process can be repeated in series, and / or in parallel, for a plurality of initial quantum states pA,pA'i,pA»..., producing a plurality of sets of encrypted clones {S, {S ’, {S ”... and decryption keys { / V, { / V ’, { / V£} ”... corresponding to respective ones the different initial quantum states PA’PA''’PA"---- lnsome embodiments, it can be preferred to store such associated decryption keys { / V, {Ni} ’, {Ni} ”... together, and to store individual encrypted clones St, S-, S”... corresponding to respective ones of the different initial quantum states pA>pA'’>pA" -with one another (e.g. store decryption keys { / V, {Nt}’, {Ni}”... in a first set of quantum registers, or first quantum computer, first encrypted clones Si,... in a second set of quantum registers, or second quantum computer, second encrypted clones S2, S2', S2in a third set of quantum registers, or third quantum computer, and so forth.

[0052] In many embodiments, the identity operator and the Pauli operators for the j’th signal and noise qubits can be represented byrespectively, in their { 10), |1)} basis. An owner of quantum data, say Alice, possesses a qubit A and aims to createn encrypted clones of the state of qubit A. To this end, Alice lets her qubit A interact with the n signal qubits {S;}”=1. More specifically, the information from the original qubit A is imprinted onto the set of all n signal qubits {S via an encrypted cloning operator U^c- The encrypted cloning operator U^ccanact jointly on the Hilbert space of qubit A and all n signal qubits {<!■

[0053] Indeed, the encoding operation U^ccan be defined by:where the sigma’s with superscripts A and St refer to the Pauli matrices acting on qubit A or signal qubit SLrespectively, in arbitrarily chosen computational bases, and where the coefficients atlare any choice of complex numbers such that all |a = 1 and U^. is unitary, i.e., any choice of numbers obeying,(a) if n is odd, Re(aoa^ + in+1Re a2a3) = 0, Re(a0a2) + in+1Re(a3a ) = 0, Re(aoa3~) + in+Re(a a2) = 0,(b) and if n is even, Re(aoa ~) — in+2Im a2a3) = 0, Re(a0a2) — in+2Im(a3a ') =

[0054] On the other hand, the decoding operation U^ccan be defined by:where |<> are four Bell states, atlare complex coefficients used to specify the encoding operation above, and T denotes a transpose operation in a computational basis.

[0055] In some embodiments, the encrypted cloning operatorcan take the form:

[0056] whereand a3are the Pauli- X and Pauli- operators, respectively, and the superscripts denote the qubit on which they act. Of course, axes X and Z may be chosen here arbitrarily and other forms of U^CIincluding namely rotations of the form of eq. 2, are possible. This encrypted cloning operator U^cin Equation (2) corresponds to the case where a0= 1,ai =a3 = i, anda2 = ~in+1- This encrypted cloning operator U^. entangles qubit A with the signal qubits {S=1. After this operation, the state of each individual signal qubit S^, when traced over all other systems, can be a maximally mixed state, ps. = meaning it containszero information about the initial state of A. The post-encoding state of qubit A is also maximally mixed.

[0057] The unitary U^cacts as the identity operator on the noise qubits’ tensor factor of the Hilbert space. Therefore, when U^. is compiled into a succession of native gates of a quantum processor, no gates act on the noise qubits, i.e., the noise qubits are noninteracting ancillas that may as well be kept physically apart (electromagnetically insulated) during the encrypted cloning operation. Hence, the noise qubits carry neither classical nor quantum information about Alice’s qubit.

[0058] The encryption operation (and decryption operation, as will be presented in greater detail below) can be described by unitary evolutions that involve multiple qubits. There can be a technical challenge in directly implementing such a many-qubit interaction. An example way of implementing such many-qubit interactions involves first decomposing the operations into two qubit gates. In this example, the number of two-qubit gates needed to create n encrypted clones, and to subsequently decrypt one of them, increases linearly with n.

[0059] In some embodiments, there can be a factorjnthe encryption operation. In the computational basis, this operation changes the phase by e-itor eifdepending on the parity of the number of qubits involved. Therefore, it can be realized by thequantum circuit presented in Fig. 2, where a standard notation is used for rotation Ri(0) =

[0060] Since another part of the encryption operation,, is related tovja|oca|unjtary operations, it can be implemented by the quantum circuit presented in Fig. 3, where H denotes the Hadamard gate.

[0061] The encryption operation in examples above corresponds to t = ~. Therefore, the 4encryption operation with 4n two-qubit gates and 2n + 4 single-qubit unitary operations.

[0062] After the process of encrypted cloning, Bob (which can be Alice or another entity) may want, at some point, to recover the initial state of qubit A from a subset of the signal qubits and noise qubits. Correspondingly, we consider this quantum channel from Alice to Bob:

[0063] Here, we defined <ps. N.=\<p){<p\s N. Also, we lets denote the qubit(s) that Bob chooses to use to try to reproduce the original state pAof qubit A. We let B denote the complementary system toB. For example, if B = Sltthen BNn. If Bob uses any one signal qubit, St, and all noise qubits, Nlt..., Nn, then Bob can retrieve Alice’s qubit perfectly, in the sense that the channel from Alice to Bob is of full quantum capacity CQ'.

[0064] The capacity can drop to zero if Bob omits even only one noise qubit.

[0065] Eq. (4) can be demonstrated by explicitly constructing a decrypting operation. To this end, we show that Alice’s initial state pAis fully recovered from S1N1N2••• Nnby the decrypting operationdefined for n > 1 by

[0066] Here, T denotes the transpose operation with respect tothe computational basis {| 0>, 11>}, and the coefficients are defined by a0= 1, a = a3= i and a2= — in+1.

[0067] In this example embodiment, the unitary decoding operator, uc, embodied in accordance with eq. 5, is applied to the joint system of Skand {^}. In this expression, the {| are the four orthogonal Bell states, T denotes the transpose operation in the computational basis, and the atlare specific complex coefficients given by a0= 1, a = a3= i, and a2= -in+1. This unitary operation effectively uses the information stored in the noise qubits to cancel the encryption noise in the signal qubit Sk, perfectly restoring the original state of A onto the qubit Sk. The application of this operation consumes the key in the sense that the final state of the noise qubits is no longer correlated with the remaining signal qubits in the required way to permit another decryption, thus ensuring compliance with the no-cloning theorem.

[0068] First, it is straightforward to check that U^cis unitary by using the fact that forms an orthonormal basis of a two-qubit system and |a2= 1. Therefore,is a quantum channel. Second, from Eq. (2),‘^>S1N1N2---Nn^> S1°7'Gl^S1N1N2- Nn(I;;l>1)=I 'X ' 151(9)holds for any initial pure state \ (J)Aof Alice’s qubit. Therefore, Alice’s initial state can be retrieved perfectly from S1N1N2••• Nn. As one can also decrypt the same information from SiN1N2- "Nn due to the symmetry under exchanging the roles of S1N1and S^i in the decoding operation, Eq. (4) is demonstrated for any i. Therefore, Bob can recover the original state of qubit A using one arbitrary signal qubit and all noise qubits. One signal qubit alone may not be sufficient to recover the original state of A since otherwise it could also be recovered from the remaining signal qubits due to symmetry, thereby violating the no-cloning theorem. Indeed,(no“ cloning) (10)since JVA^Sis anti-degradable due to the permutation symmetry among signal qubits, and the quantum capacity vanishes for any anti-degradable channel.

[0069] A decomposition of the decryption operation in Eq. (5) into two-qubit gates can include first decomposing decryption operation as:is a two-qubit unitary operation relating the computational basis and the Bell basis:with a binary representation. =and

[0070] Sincecan be implemented by controlled-controlled unitary operation, the quantum circuits presented at Fig. 4A, 4B and 4C can be used. Each controlled-controlled unitary operation can be implemented by five two-qubit gates. Therefore, the decryption operation can be implemented with 15n + 7 two-qubit gates. In summary, in some embodiments, the whole protocol can be implemented with at most 21n + 11 two-qubit gates in total.

[0071] Accordingly, each signal qubit can be made to contain an encrypted but perfect clone of Alice’s original qubit, A. Each clone can be perfectly encrypted in the sense that it is noisy to the extent that each individually is in a maximally mixed state. Yet, each encrypted clone can also have a perfect copy of the original state of A in the sense that the original state of A can be perfectly recovered from the encrypted clone by decrypting (which can alternately be referred to here as ‘denoising’ or ‘decoding’) using only the noise qubits which never interacted with A and therefore contain no classical or quantum information about A.

[0072] Consistence with the no-cloning theorem demands that, after decrypting one signal qubit, it is impossible to reuse the noise qubits to decrypt another signal qubit. Indeed, after decoding, as Eq. (8) shows, the state of the (n - 1) unused signal qubits and n noise qubits is independent of Alice’s information. Of course, it would not violate no-cloning if, after denoising one signal qubit, Bob runs the unitary decoding operation Eq. (5) in reverse and then chooses to denoise another signal qubit.

[0073] The pair of encoding and decoding unitary operations, as in Eqs. (2) and (5), can be replaced by rotated versions. For example, can be replaced ®while in the encoding operation in Eq. (2), the coefficients in Eq. (7) changeinto a0= 1, a = a2= i and a3= -(-i)n+1. Then, Alice’s quantum information can be retrieved using the decoding operation (5) with these coefficients.

[0074] More generally, the encoding and decoding unitaries of Eqs. (2) and (5) can be replaced by any unitary that acts the same way on the initial states and on the encoded states respectively.

[0075] The choice of encoding and decoding unitaries can be important in practical applications, where the encoding and decoding unitaries need to be decomposed, i.e., compiled into the universal native one- and two-qubit gates of a given quantum processor. The number of two-qubit gates that is required to implement the copying and retrieval operations may scale well, namely by growing only linearly with n.

[0076] Indeed, in accordance with some embodiments, an optional feature can provide a method for data recovery in the catastrophic event that the quantum key is lost. This "keyless" recovery is enabled by the invertible nature of the encoding operation.

[0077] In accordance with such embodiments, rather than discarding the post-encoding system qubit A, which will be in a state which we will refer to as pAafter the encoding operation, the system qubit A in state pA' can be stored securely, for example, in a trusted cloud location, such as along with one of the signal qubits. If the owner loses the key (the set of noise qubits { / Vi}), recovery is still possible. The owner retrieves the post-encoding qubit A and all n signal qubits {S. By applying the inverse of the encoding operation, iff, to this collection of n + 1 qubits, the original state of A is recovered. This feature provides a failsafe for data owners, adding value and applicability to some use cases.

[0078] Indeed, in a case where Alice, the owner of the quantum data, is also the owner of the quantum clouds, or is trusting the quantum cloud provider(s), the owner can enable an additional security feature that allows her to recover the original quantum state A even in thecase of a loss of all noise qubits. To enable this security feature, the owner sends not only the n copies to quantum clouds but also sends the post-encoding qubit (which is at his stage in a quantum state pAwhich is maximally mixed) to a quantum cloud. Now even if Alice were to lose all of her noise qubits, she could still recover the original quantum state A, namely by running the encoding unitary in reverse on the collection of all signal qubits and the quantum state pA'.

[0079] In addition, if Alice maintains access to all n noise qubits but loses all signal qubits Sitshe can recover the original qubit A by using the quantum state pA', at least if n is even.

[0080] Indeed, from Eq. (7), the state of the total system after encoding can also be written as

[0081] Since, for even n,whereis a unitary operator acting on qubits AN ■■■Nn, implying that we can decrypt the original state state pAfrom state pA' with the key N ••• Nnby performing UAN N

[0082] In effect, at least if n is even, the post-encoding quantum state of the system qubit A, pA', can serve as an encrypted clone as well.

[0083] Moreover, a method for data recovery can be provided when the quantum key is incomplete but not entirely lost. This protocol can enhance the system’s robustness against partial key corruption or loss, a realistic scenario in many applications.

[0084] The method addresses the situation where one or more noise qubits, say Nj, are lost or have decohered. The owner can still recover the original state by retrieving the corresponding signal qubit, S,-, from its storage location. A modified decoding operation is then constructed by substituting the retrieved signal qubits, for the missing noise qubit Nj in the standard decoding operator. For example, the term a^Nj)Tin the decoding operator is replaced with a]. Applying this modified decoding operation to another signal qubit (e.g., Sk) and the remaining set of qubits (the incomplete key plus the substitute signal qubit S,) still allows for the perfect recovery of the original state.

[0085] For instance, in a scenario where the owner of the quantum data, Alice, loses access to some of the n noise qubits but retains access to at least one noise qubit. In this case, the owner can still recover the original state of A from any subsystem composed of one pair of signal and noise qubits plus at least one half of each of the remaining (n - 1) pairs of signal and noise qubits. For example, the original state of A can be recovered using S S2and N1N3N4••• Nnby replacing

[0086] While, therefore, the loss of some noise or signal qubits can be compensated, the loss of even just one pair of signal and noise qubits makes it impossible to retrieve qubit A, and the channel capacity drops to zero. This is because the reduced state of (n - 1) pairs of signal and noise qubits is givena^erthe encoding, independently of \ )A, as seen in Eq. (7).

[0087] In some embodiments, reusability of the quantum key and its associated resources can be harnessed. This contrasts with classical one-time pad cryptography, where key reuse is catastrophic for security.

[0088] Indeed, in some embodiments, multiple, sequential cycles of secure quantum information processing can be performed. After a first cycle of encoding an initial quantum state pAand subsequently decoding one of the encrypted clones, the decoding operation can deterministically restore the initial resource state of the n maximally entangled signal and noise qubit pairs. The method can then involve utilizing this same, now-restored, set of entangled qubit pairs to perform a second, subsequent cycle of encoding and decoding of a second, different quantum state. This process can be repeated. This feature can allow migrating from scenarios of a static storage solutions into scenarios of dynamic cryptographic resources, a reusable “quantum multi-time pad," which can affect efficiency and resource cost of secure quantum communication and computation.

[0089] For applications requiring a very large number of encrypted clones, the complexity of the decoding step — which may involve operating on all n noise qubits simultaneously — can become a practical bottleneck. A process which can be referred to herein as "iterated cloning" may address this scalability challenge.

[0090] Indeed, there is also the possibility to create a large number of encrypted clones of A by repeatedly creating, say, two additional clones of A, by using the n = 2 encrypted cloning method. In this case, while the last created pair of encrypted clones requires all noise qubits for decryption, the first pair of encrypted clones requires only the first two noise qubits for decryption.

[0091] Alternatively, a favorable scaling of the number of noise qubits required for decryption can be obtained, for example, by creating 3 encrypted clones (counting also A as an encrypted clone) using the n = 2 method, then creating 3 encrypted clones of each of these encrypted clones and so on, say k times. This yields 3kencrypted clones along with 2(1 + 3 -1 - 1- 3k-1) = 3k- 1 noise qubits. This means that to create m + 1: = 3kencrypted clones, m noise qubits required, as in the original method for n = m (counting also A as an encrypted clone). However, when using this iterated encrypted cloning method, each of the 3kencrypted clone requires for its decryption merely 2k specific noise qubits.

[0092] The method can include a hierarchical approach. First, a small number of encrypted clones (e.g., m = 3) of the original state A are created. Then, for each of these first-generationclones, m second-generation clones are created using a fresh set of resource qubits. This process can be repeated k times. The result can be an exponential increase in the total number of final clones, which scales as mk. However, the number of key qubits required to decrypt any single final clone grows only linearly with the number of iterations, k. For example, decrypting a third-generation clone may then require only the key qubits from the first, second, and third cloning stages relevant to its specific creation path, rather than the total number of key qubits created in the entire process. This method provides an exponential reduction in the decryption complexity for a given clone, which can affect practical scalability.

[0093] The encrypted cloning method can encrypt and decrypt without measurements, unitarily, in such a way that, after decryption, the n maximally entangled pairs are restored and are, therefore, available again for encryption.

[0094] Various applications may exist.

[0095] In some embodiments, a process of creating encrypted clones can be used to provide secure and redundant storage of quantum information. In such embodiments, there can be a need for a quantum data storage solution that is simultaneously off-site, redundant, and encrypted with an owner-held key. An owner of sensitive quantum data can use the method to create n encrypted clones, distribute these clones to n different physical locations (e.g., multiple quantum cloud servers, or different storage units within a single quantum computer), while retaining the compact quantum key on-site. This can provide robust protection against both local disasters (key is safe) and failures at the storage provider (data is redundant). The perfect encryption can allow that the cloud provider, or any adversary gaining access to the stored clones, cannot extract information about the data.

[0096] Indeed, the owner of quantum data may need, for security reasons, that these data are stored (a) off-site, (b) redundantly in multiple quantum clouds to protect, e.g., from hardware failures, and (c) encrypted, with the key kept by the owner on-site.

[0097] A method of creating encrypted clones can be used for this purpose. To this end, the owner of a qubit, A, creates n encrypted clones and distributes them to n quantum clouds for storage. The owner can then discard the original qubit A. The owner retains the n noise qubits,which together serve as the key. Condition a) is fulfilled because on-site are only the noise qubits and they do not carry information about qubit A. Condition b) is fulfilled since the owner can decrypt (i.e., denoise) any one of the redundantly stored encrypted clones to recover qubit A, by using the noise qubits. Condition c) is fulfilled since each of the encrypted clones that are hosted off-site in one of the quantum clouds is maximally mixed and independent of the initial state of A.

[0098] The inherent redundancy of a method of creating encrypted clones can make it well-suited for communication over lossy channels. In applications like quantum radar or free-space quantum communication, photons carrying quantum information may be lost due to absorption or scattering. By encoding the information into n photons, each an encrypted clone, a message can be successfully transmitted as long as at least one of the n photons reaches the receiver. The receiver, who possesses the corresponding key (composed of n idler photons retained at the source), can then perfectly recover the information from the single surviving photon. This provides a powerful mechanism for increasing the success rate and effective range of quantum communication protocols.

[0099] Indeed, an encrypted cloning approach can also be explored for quantum sensing. Useful for sensing could also be the fact that, for large n, the ability to recover original state A can be extremely sensitive to any interactions that a to-be-probed system may have with the n noise qubits.

[0100] Vice versa, in encrypted cloning we have enhanced robustness in the transmission of the signal qubits, in the sense that if n signal qubits are sent, it suffices that even just one arrives to achieve full recovery. For example, a quantum radar type setup can be embodied in which n noise qubits in photons are kept as idlers while n signal photons are emitted, of which only one signal photon needs to be received.

[0101] The ability to create multiple encrypted clones can enable novel paradigms in secure quantum computing. A client can use the method to create n encrypted clones of their input state pAand send them to a quantum cloud provider. The client can then instruct the provider to perform the same quantum computation on each of the clones in parallel. This can be in the form of blind quantum computation, as the provider operates on encrypted states andlearns nothing about the input, the computation, or the output. Upon receiving the n encrypted results, the client can use their key to decrypt any one of them to obtain the final answer. The redundancy may be used by the client to partially decrypt multiple results to check for computational errors or faults on the provider’s quantum computer. This application provides a path toward verifiable, secure, and parallelized delegated quantum computation

[0102] A method of creating encrypted clones can be used in a quantum error-correcting code that which can be powerful against errors in the form of the complete loss of a qubit, known as an erasure error. Therefore, a method of creating encrypted clones can be used for fault-tolerant quantum memories in physical architectures where qubit loss is a significant error mechanism (e.g., certain photonic or neutral-atom architectures), providing uses in fault-tolerant quantum computing.

[0103] A method of creating n encrypted clones can be adapted to create novel methods for quantum state tomography (the complete characterization of an unknown state) or state verification. For example, n encrypted clones of an unknown state can be created. A subset of these clones, say n - 1 of them, could then be subjected to various destructive measurements (e.g., measurements in the X, Y, and Z bases) to gather statistical information about the state. A final, unmeasured clone may then perfectly be recovered by the owner using the key. This can allow for a hybrid approach where one obtains both classical statistics from the majority of the copies and a single perfect quantum version of the state. This could enable verification protocols where one checks the classical measurement outcomes against the properties of the final recovered quantum state, providing a tool for quantum characterization and verification.

[0104] The sensitivity of a method of decoding an encrypted clone to the state of the key qubits can be repurposed from a potential liability into a powerful feature for sensing. For example, in a distributed quantum sensing system a central station and n remote sensor nodes can be implemented. The central station can prepare n entangled signal-noise pairs. The central station can retain the n noise qubits (the key) and send the n signal qubits to the remote nodes. At each node, a signal qubit interacts with the local environment (e.g., a magnetic field, gravitational gradient, or temperature). The signal qubits are then returned to the central station. The owner then performs the encoding operation on a known probe qubit A and thereturned signal qubits, creating a set of encrypted clones. Finally, the owner can attempt to decrypt one of the clones using the pristine key qubits. The fidelity of the recovered state can be sensitive to the integrated effect of the environmental interactions across all sensor nodes. By analyzing the degradation of the fidelity, one can obtain a highly precise measurement of the distributed physical quantity. Such example implementations can help create a new class of sensitive, networked quantum sensors.

[0105] This is reminiscent of how unitarity also forces quantum linear amplifiers to introduce quantum noise. It can be interesting, therefore, to explore whether an encrypted cloning type approach can be used to develop new quantum amplifier architectures in which the necessary quantum noise is introduced through maximally entangled pairs - in such a way that halves of these pairs may later serve to at least partially denoise a quantum amplified signal. Similarly, also the no-programming theorem arises from unitarity and an encrypted cloning approach may, therefore, provide a new perspective.

[0106] In one example, quantum summoning is an adversarial game played in spacetime. At an event X, Player 1 gives Player 2 a qubit A. Then, at some event from a pre-agreed upon set of events in the causal future of X, Player 1 asks Player 2 to produce qubit A. Player 2 is able to win this challenge if all events Ytare timelike to another, because then Player 2 can transport or teleport qubit A from one Ytto the next until it is summoned by Player 1. The no quantum summoning theorem states that Player 2 cannot possess an always-winning strategy if some of the Ytare spacelike to another, as this would contradict no-cloning.

[0107] While encrypted cloning is clearly consistent with the no quantum summoning theorem, the application of encrypted cloning to quantum encrypted multi-cloud storage also shows that a variant of quantum summoning is possible also for spacelike separated Y^. Player 2 deposits encrypted clones at each of the Yt. Then, Player 1 can summon qubit A at anyof her choosing - even if some or all of the Ytare spacelike separated from another - provided that Player 1 brings the decryption key, i.e., the noise qubits. Recall that the noise qubits do not carry any classical or quantum information about A.

[0108] The encrypted cloning operation can be consistent not only with the no-cloning theorem, but also with quantum secret sharing. To see this, we need to consider what inquantum secret sharing is called the access structure, namely the list of so-called authorized or unauthorized sets of parties (subsystems) from which a secret qubit can or cannot be recovered respectively. In encrypted cloning, any subsystem containing one pair of signal and noise qubits and one half of each of the remaining (n - 1) pairs is authorized, while any subsystem of (n - 1) pairs or n noise qubits is unauthorized. The two necessary and sufficient conditions required for quantum secret sharing, namely (a) that the complement of any authorized set is unauthorized and (b) monotonicity, i.e., that any superset of an authorized set is authorized, are readily verified.

[0109] Since any quantum secret sharing scheme can correct erasure errors on the complementary system to an authorized set, encrypted cloning can, therefore, also be embodied as an error-correcting code. For example, after encrypted cloning, the original state of qubit A can be retrieved even if (n - 1) signal qubits are lost.

[0110] In embodiments where system qubit A is initially maximally entangled with an ancilla qubit A. After the encrypted cloning, A is, therefore, simultaneously maximally entangled with each set of qubits from which the original state of A can be recovered.

[0111] This fact does not violate entanglement monogamy since the monogamy argument only applies to disjoint sets of subsystems while in encrypted cloning every set of qubits from which the original state of A can be reconstructed overlaps with any other such set.

[0112] Similar to encrypted cloning, which assumes that initially we have a number of maximally entangled pairs of signal and noise qubits, in the case of black holes, the degrees of freedom of the black hole and the degrees of freedom of the Hawking radiation that it has emitted by the Page time can be assumed to be maximally entangled. Then, similar to the imprinting of a qubit A into the signal qubits in encrypted cloning, when sending a qubit A into a black hole, it may become imprinted into the degrees of freedom in the black hole through fast scrambling. In encrypted cloning, A can be recovered from even just a single one of the encrypted clones SL. Similarly in spirit, in the Hayden-Preskill model, as soon as some more of the degrees of freedom (perhaps analogous to the imprinted signal qubits) evaporate from the black hole, qubit A can be recovered with the help of all of the prior degrees of freedom of the Hawking radiation (analogous to the noise qubits).

[0113] Encrypted cloning can be generalized from qubits to qudits. Additional work may explore the corresponding scaling of the minimal resources needed.

[0114] Encrypted cloning need not be associated with cryptography and adversarial setups at all.

[0115] More generally, in some embodiments, encrypted cloning can be seen as a method to evade a constraint imposed by unitarity, namely no-cloning. To this end, encrypted cloning enlarges the system (leaving the original system an open system) to introduce quantum noise through maximum entanglement with ancillas, in such a way that later denoising is possible.

[0116] Moreover, encrypted cloning could provide a form of redundancy, fault tolerance, scalability or parallelism, such as perhaps quantum homomorphic parallel computation, wherever direct duplication is forbidden by the no-cloning theorem.

[0117] The methods presented above can be applied on a wide variety of quantum computers. For instance, Fig. 5 illustrates a simplified system-level block diagram of another example of a quantum computer 100 which can be used to implement the processes described above. In this example, the quantum computer 100 is based on a photonic architecture and uses principles of measurement-based quantum computing (MBQC) and offers a contrast to the example quantum computer 40 presented in Fig. 1, and which used principles of gate-based quantum computing. The components of the quantum computer 100, described in more detail below, can be configured to one or more of: create, generate, shape, measure, decode, and error-correct a selected entangled cluster state that serves as a resource for measurementbased fault-tolerant quantum computation. For example, the quantum computer 100 may be a measurement-based quantum computer in the Raussendorf-Harrington-Goyal (RHG) model using continuous-variable (CV) qubits. Although an example is described below in the context of a measurement-based quantum computing model based on a photonic platform, it is understood that embodiments of the methods described herein are also applicable to other quantum platforms, including superconducting qubits, trapped ion qubits, and any other quantum platforms, and may be of use in circuit-based quantum computing models and even potentially in adiabatic quantum computing models.

[0118] Returning to the example presented in Fig. 5, in some embodiments, the quantum computer 100 includes a source module 102, a stitcher 104, and a quantum processing unit (QPU) 106. Each of the source module 102, the stitcher 104, and the QPU 106 represents logical functionality that can be implemented exclusively via hardware, exclusively via software, or via a combination of hardware and software. The functional delineation between the separate elements within the quantum computer 100 may only be a conceptual representation of the overall operation of the quantum computer 100.

[0119] The source module 102 is configured to generate a plurality of input quantum states. In the case of photonic quantum platforms, the source module 102 may include a plurality of Gaussian Boson Sampling (GBS) sources each configured to generate a continuous-variable (CV) state of light, such as Gottesman-Kitaev-Preskill (GKP) state. Data is mapped onto the generated CV states.

[0120] In some embodiments, the source module 102 may include a local pulse train generator. The local pulse train generator is configured to generate a train of local optical pulses that are also referred to as a local oscillator (LO) signal that is operably coupled to elements of quantum computer 100, such as QPU 106, and particularly to the optical detectors (e.g., homodyne detectors) used for projective measurements and for measurement-based quantum computation.

[0121] A steady supply of CV states that include both encoded bosonic qubits and squeezed vacuum states may be generated by the source module 102 and sent to the stitcher 104 via a network of optical connections. In some embodiments, the source module 102, the stitcher 104, and the QPU 106 are implemented on photonic integrated circuits (PICs), and the optical network may be implemented using optical fibers compatible with existing optical technologies, which may have a lower level of propagation loss compared to on-chip waveguides. In some embodiments, the source module 102 generates the desired CV states by performing Pauli measurements on intermediary CV states within the source module 102. In the case of photonic quantum computing architectures, the Pauli measurements may be performed by way of homodyne detection.

[0122] The states generated by the source module 102 are provided to the stitcher 104, which is configured to stitch the input states into a lattice structure in accordance with a specific encoding scheme. In some embodiments, the stitcher 104 can interfere these states, such as through a network of static 50:50 beamsplitters with phase delays or reconfigurable beamsplitters into what is referred to as a higher dimensional multimode entangled state, referred to hereinbelow as a cluster state for short, before sending / routing the multimode entangled state to the QPU 106 to be processed. As used herein, “stitching” refers to the creation / imposition of entanglement between the different modes at different lattice sites. In some embodiments, during operation of the quantum computer 100, non-deterministically generated encoded qubits and non-Gaussian states of light can be stitched into a random but known subset of the sites (by virtue of them being generated at a random subset of locations, and not being generated at other locations), while the remaining sites are populated with deterministically generated Gaussian states, such as squeezed vacuum states for example. An indication of whether or not a location is within the subset of the sites is provided.

[0123] Measurements can be performed on the higher dimensional multimode entangled state by a measurement module 108 of the QPU 106 to provide electric field quadrature information (e.g., the position or amplitude quadrature referred to herein as the “q quadrature” and the momentum or phase quadrature referred to herein as the “p quadrature”). The measurements are performed by one or more optical detectors of the measurement module 108. In some embodiments, the optical detectors are homodyne detectors which can be used to perform measurements on each macronode of the multimode state to reduce each macronode into a single node with multiple edges. The measurement outcomes can be used by the quantum computing system to perform error correction and can also be utilized by the system to perform measurement-based quantum computation (MBQC). The optical detectors, (e.g., homodyne detectors) may be configured to perform quadrature measurements by interfering the optical modes of an input entangled resource state and the train of local optical pulses on a beamsplitter and detecting the optical power difference of the two beam splitter outputs as an indication of the modal property(ies) of the quantum state of the given optical pulse. The measurement outcomes collected on the multimode entangled states (i.e., at the physical hardware layer) can be processed together to implement one or more aspects of an error correction code. The measurement results can be processed by the QPU 106, whichmay be configured to take, as inputs, the measurement outcomes that have been realized to perform the logical operations.

[0124] The control of the at least one of and typically each one of the source module 102, stitcher 104, and quantum processing unit 106 cannot be performed manually and is performed via hardware and software elements which will be referred to herein as a controller. The controller can be a classical computer, i.e., a computer based on bits rather than qubits for computation, including at least one processor wherein control instructions are stored in computer-readable memory and are accessible to the at least one processor. The control instructions can include a plurality of functions, such as a source module control function, a stitcher module control function, and a quantum processing unit control function, each of which can include a plurality of sub-processes. The control instructions typically include a definition of logical states which are mapped to the specific hardware elements of the given embodiment.

[0125] The process can be applied by other types of quantum computers as well, such as adiabatic quantum computers for instance. In this specification, the expression quantum computer is not to be construed as being limited to a specific type of quantum computer unless explicitly specified.

[0126] It will be understood that the expression “classical computer” as used herein, is not to be interpreted in a limiting manner. It is rather used in a broad sense to generally refer to the combination of some form of one or more processing units and some form of memory system accessible by the processing unit(s). The memory system can be of the non-transitory type. The use of the expression “computer” in its singular form as used herein includes within its scope the combination of two or more computers working collaboratively to perform a given function. Moreover, the expression “computer” as used herein includes within its scope the use of partial capabilities of a given processing unit. Example computers include supercomputers, desktops, laptops, smartphones, smart watches, less elaborated controller devices, etc.

[0127] An example classical computer 400 is presented in Fig. 6. In this example, the computer 400 includes a processing unit 412 and a memory system 414 storing instructions 416.

[0128] A processing unit 412 can be embodied in the form of a general-purpose microprocessor or microcontroller, a digital signal processing (DSP) processor, an integrated circuit, a field programmable gate array (FPGA), a reconfigurable processor, or a programmable readonly memory (PROM), to name a few examples.

[0129] The memory system 414 can include a suitable combination of any suitable type of computer-readable memory located either internally or externally, and accessible by the processor in a wired or wireless manner, either directly or over a network such as the Internet. A computer-readable memory can be embodied in the form of random-access memory (RAM), read-only memory (ROM), compact disc read-only memory (CDROM), electro-optical memory, magneto-optical memory, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or ferroelectric RAM (FRAM), to name a few examples.

[0130] A computer 400 can have one or more input / output (I / O) interfaces to allow communication with a human user and / or with another computer via an associated input, output, or input / output device such as a keyboard, a mouse, a touchscreen, an antenna, a port, etc. Each I / O interface can enable the computer to communicate and / or exchange data with other components, to access and connect to network resources, to serve applications, and / or to perform other computing applications by connecting to a network (or multiple networks) capable of carrying data including the Internet, Ethernet, plain old telephone service (POTS) line, public switch telephone network (PSTN), integrated services digital network (ISDN), digital subscriber line (DSL), coaxial cable, fiber optics, satellite, mobile, wireless (e.g., Wi-Fi, Bluetooth, WiMAX), SS7 signaling network, fixed line, local area network, or wide area network, to name a few examples.

[0131] It will be understood that a computer can perform functions or processes via hardware or a combination of both hardware and software. For example, hardware can include logic gates included as part of a silicon chip of a processor. Software (e.g., an application orprocess) can be in the form of data such as computer-readable instructions stored in a non-transitory computer-readable memory accessible by one or more processing units. With respect to a computer or a processing unit, the expression “configured to” relates to the presence of hardware or a combination of hardware and software which is operable to perform the associated functions. Different elements of a computer, such as processor and / or memory, can be local, in part remote, or in whole remote and / or distributed and / or virtual.

[0132] The methods and systems performed by the classical computer in the context of the present disclosure may be implemented in a high-level procedural or object-oriented programming or scripting language, or a combination thereof, to communicate with or assist in the operation of a computer system, for example the controller. Alternatively, the methods and systems described herein may be implemented in assembly or machine language. The language may be a compiled or interpreted language. Program code for implementing the methods and systems described herein may be stored on a storage media or a device, for example a ROM, a magnetic disk, an optical disc, a flash drive, or any other suitable storage media or device. The program code may be readable by a general or special-purpose programmable computer for configuring and operating the computer when the storage media or device is read by the computer to perform the procedures described herein. Embodiments of the methods and systems described herein may also be considered to be implemented by way of a non-transitory computer-readable storage medium having a computer program stored thereon. The computer program may comprise computer-readable instructions which cause a computer, or more specifically the processing unit of the computing device, to operate in a specific and predefined manner to perform the functions described herein.

[0133] Computer-executable instructions may be in many forms, including program modules, executed by one or more computers or other devices. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform particular tasks or implement particular abstract data types. Typically, the functionality of the program modules may be combined or distributed as desired in various embodiments. The technical solution of embodiments may be in the form of a software product. The software product may be stored in a non-volatile or non-transitory storage medium, which can be a compact disk read-only memory (CDROM), a USB flash disk, or a removable hard disk. The software product includesa number of instructions that enable a computer device (personal computer, server, or network device) to execute the methods provided by the embodiments.

[0134] The embodiments described herein are implemented by physical computer hardware. The embodiments described herein provide useful physical machines and particularly configured computer hardware arrangements. The embodiments described herein are directed to electronic and optical machines and methods implemented by electronic and optical machines adapted for processing and transforming electromagnetic signals which represent various types of information. The embodiments described herein pervasively and integrally relate to machines, and their uses; and the embodiments described herein have no meaning or practical applicability outside their use with computer hardware, machines, and various hardware components. Substituting the physical hardware particularly configured to implement various acts for non-physical hardware, using mental steps for example, may substantially affect the way the embodiments work. Such computer hardware limitations are clearly essential elements of the embodiments described herein, and they cannot be omitted or substituted for mental means without having a material effect on the operation and structure of the embodiments described herein. The computer hardware is essential to implement the various embodiments described herein and is not merely used to perform steps expeditiously and in an efficient manner.

[0135] As can be understood, the examples described above and illustrated are intended to be exemplary only. For instance, the processes described above can be applied to physical qubits or logical qubits. Moreover, operations on qudits can be conducted by dissociation into operations on qubits, where r is the smallest integer for which d ≤ 2rand where the encrypted cloning and the decryption operation on the qudits is performed by the encrypted cloning and decryption operation applied simultaneously to r qubits. The scope is indicated by the appended claims.

Claims

WHAT IS CLAIMED IS:

1. A method for creating noisy copies of a quantum state pA, the method comprising: preparing the quantum state pAin a system qubit A;preparing n pairs of ancillary qubits {Si,Ni}, each pair of ancillary qubits including a signal qubit Si, and a noise qubit Niwherein the signal qubit Siand noise qubit Niof each pair of ancillary qubits is prepared in a |φ⟩SN, andapplying an encoding operationto the system qubit A and the signal qubits {Si}, including entangling the system qubit A with the signal qubits, turning the signal qubits {Si} into noisy copies of the quantum state pA.

2. The method of claim 1, wherein U(n)enc= ... where σ(A)μand σ(S_i)μare Pauli matrices acting on system qubit A and signal qubit Sirespectively, in arbitrarily chosen computational bases, and where atlare complex numbers satisfying |αμ| = 1 and U(n)encis unitary.

3. The method claim 1 or 2 wherein the applying the encoding operation is performed using sequences of one-qubit and multi-qubit gates.

4. The method of any one of claims 1 to 3 whereinand o-3are Pauli-X and Pauli-Z operators in computational bases.

5. The method of any one of claims 1 to 3, further comprising applying a decoding operation U(n)decto one of the noisy copies and all noise qubits {Ni}, including recovering the quantum state ρA. / " (N,)T |, 6. The method of claim 5, wherein U(n)dec= Σ3μ=0αμ(|φμ⟩⟨φμ|S_k N_k) ⊗ (⊗nj=1, j≠kσμ(N_j)T), where |φμ⟩ are four Bell states, αμare complex numbers satisfying |αμ| = 1 and T denotes a transpose operation in a computational basis.

7. The method of claim 5 wherein U(n)enc= e-iπ / 4 σ⊗(⊗ σ)· e-iπ / 4 σ⊗(⊗ σ)v=i3and3are Pauli-X and Pauli-Z operators in computational bases, andcomputational basis.

8. The method any one of claims 5 to 7 wherein the decoding operation is implemented using sequences of one-qubit and multi-qubit gates.

9. The method of any one of claims 1 to 4, wherein, subsequently to said applying the encoding operation U(n)enc, the system qubit A is in quantum state ρA', and where n is even, further comprising applying a decoding operation U(n)decto the quantum state ρA' and all noise qubits {Ni}, including recovering the quantum state ρA.

10. The method of any one of claims 1 to 4, wherein, subsequently to said applying the encoding operation U(n)enc, the system qubit A is in quantum state ρA', further comprising applying a decoding operation corresponding to an inverse of the encoding operation to the quantum state pA' and all the noisy copies, including recovering the quantum state ρA.

11. The method of any one of claims 1 to 4, further comprising applying a decoding operation U(n)dectoa pair (Sk, Nk) amongst the n pairs of ancillary qubits {Si,Ni} and,for each of the n pairs of ancillary qubits where i ≠ k, to one of the signal qubit Siand the noise qubit Ni,wherein U(n)dec= Σ3μ=0αμ(|φμ⟩⟨φμ|S_k N_k) ⊗ (⊗ni=1, i≠kRμ,i), where |φμ⟩ are four Bell states, αμare complex numbers satisfying |αμ| = 1 and for any i for which i ≠ kwhen U(n)decacts on the noise qubit Ni, then Rμ,i= σμ(N_i)T, where T denotes a transpose operation in a computational basis, andwhen U(n)decacts on the signal Si, then Rμ,i= σμ(S_i).

12. The method of any one of claims 1 to 11, used for securely storing quantum data offsite with redundancy and encryption, further comprising, subsequently to said applying the encoding operation, discarding the system qubit A, retaining the noise qubits {Ni} on-site as an encryption key, and sending the noisy copies {Si} to n off-site cloud storage locations.

13. The method of any one of claims 1 to 11, further comprising distributing the noisy copies across one or more on-site or off-site storage locations.

14. The method of claim 13 further comprising storing the noise qubits at a secure location, separate from the one or more on-site or off-site storage locations.

15. The method of any one of claims 1 to 11 further comprising transmitting the system qubit and the noisy copies to off-site cloud storage.

16. The method of claim 15, further comprisingrecovering the noisy copies and the system qubit from the off-site cloud storage; andrecovering quantum state pAby operating a reverse of the encoding operation on the noisy copies and the system qubit.

17. The method of any one of claims 1 to 11, further comprising: distributing the signal qubits {Si} and the noise qubits {Ni} and the system qubit among multiple parties according to a predefined access structure, and allowing the quantum state pAto be recovered only when a specific combination of the multiple parties collaborates to utilize the qubits in accordance with the predefined access structure.

18. The method of any one of claims 1 to 11 used for robust transmission of quantum information through a lossy channel, wherein the plurality of noisy copies are transmitted through the channel.

19. The method of any one of claims 1 to 11, wherein the noisy copies are encoded into photons and transmitted towards a target while the noise qubits are retained as idler qubits.

20. The method of any one of claims 1 to 11 used for performing parallel blind quantum computation, wherein an identical or different quantum computation is applied to each of the plurality of noisy copies.

21. The method of any one of claims 1 to 11 used for quantum information escrow or conditional transfer, including distributing noisy copies to one or more recipients, and providing a quantum decryption key to a chosen recipient only upon satisfaction of a predefined condition.

22. The method of any one of claims 1 to 11 used for mitigation of qubit loss, including recovering the original quantum state pA.

23. The method of any one of claims 1 to 11 used for quantum sensing, further comprising:exposing a subset of the noise qubits, the noisy copies and the system qubit A, to an environment or to a system under test;attempting to recover the original quantum state pAfrom the subset by using a corresponding decoding operation;determining information about the environment or system under test based on a degree of success or failure of recovering the original quantum state, wherein interactions with the subset of qubits affect the ability to recover the original quantum state.

24. The method of one of claims 1 to 23, further comprising iterating, wherein at least one of the noisy copies generated in a first iteration is used as an input qubit in a subsequent iteration, thereby generating a hierarchical set of noisy copies with anexponential reduction in the number of qubits required for decryption of any single noisy copy.

25. A quantum computer for creating n encrypted clones of a quantum state pA, the quantum computer comprising a system qudit, n ancillary qudit pairs, and a controller, the controller having a processor and a non-transitory memory, the non-transitory memory having instructions stored thereon, the instructions, when executed upon by the processor, causing the quantum computer to:prepare the quantum state pAin the system qudit;prepare Bell states in the n ancillary qudit pairs with each of the n ancillary qubit pairs indexed i ∈ {1,...,n} and including a signal qudit SLand a noise qudit Nt, the signal qudit SLand the noise qudit Ntof each one of the n ancillary qudit pairs being in one of the Bell states; andapply an encrypted cloning operator U(n)encbetween the n signal qudits {Si} and the system qudit while maintaining the noise qudits {Ni} isolated, thereby encoding information from quantum state ρAinto the n signal qudits {Si}.