Skip to main content
QUICK REVIEW

[論文レビュー] A quantum homomorphic encryption scheme for polynomial-sized circuits

Li Yu|arXiv (Cornell University)|Oct 2, 2018
Quantum Computing Algorithms and Architecture参考文献 40被引用数 3
ひとこと要約

本稿では、再ビット形式を用いて多項式サイズの量子回路のための量子ホモomorphic暗号(QHE)方式を提案し、実プロダクト状態に対して完全なデータプライバシーと良好な回路プライバシーを達成する。線形リソーススケーリングを実現する2つの非インタラクティブ方式と、不正行為の検出を保証する埋め込み検証を備えたインタラクティブバージョンを導入し、漸近的なデータプライバシーと最小限の情報漏洩れを伴う実用的な回路プライバシーを提供する。

ABSTRACT

Quantum homomorphic encryption (QHE) is an encryption method that allows quantum computation to be performed on one party's private data with the program provided by another party, without revealing much information about the data nor about the program to the opposite party. It is known that information-theoretically-secure QHE for circuits of unrestricted size would require exponential resources, and efficient computationally-secure QHE schemes for polynomial-sized quantum circuits have been constructed. In this paper we first propose a QHE scheme for a type of circuits of polynomial depth, based on the rebit quantum computation formalism. The scheme keeps the restricted type of data perfectly secure. We then propose a QHE scheme for a larger class of polynomial-depth quantum circuits, which has partial data privacy. Both schemes have good circuit privacy. We also propose an interactive QHE scheme with asymptotic data privacy, however, the circuit privacy is not good, in the sense that the party who provides the data could cheat and learn about the circuit. We show that such cheating would generally affect the correctness of the evaluation or cause deviation from the protocol. Hence the cheating can be caught by the opposite party in an interactive scheme with embedded verifications. Such scheme with verification has a minor drawback in data privacy. Finally, we show some methods which achieve some nontrivial level of data privacy and circuit privacy without resorting to allowing early terminations, in both the QHE problem and in secure evaluation of classical functions. The entanglement and classical communication costs in these schemes are polynomial in the circuit size and the security parameter (if any).

研究の動機と目的

  • 多項式サイズの量子回路のための強力なデータプライバシーと回路プライバシーを備えたQHE方式の設計。
  • 再ビット形式を用いて実プロダクト入力状態に対して完全なデータプライバシーを達成し、情報漏洩れを防止する。
  • 不正行為の検出が可能で、高いプライバシーを維持するインタラクティブQHEプロトコルの開発。
  • 非自明なプライバシーガラントを備えた非インタラクティブ方式による古典的線形関数評価の探求。
  • 古典的クライアントを含むQHEにおいて、情報理論的プライバシーが実現可能かどうかの調査。

提案手法

  • 測定ベースプロトコル中のデータ漏洩れを回避するため、再ビット量子計算を用いる。
  • 2つの非インタラクティブQHE方式を構築:1つは完全なデータプライバシーを達成する制限付き回路向け、もう1つはより広範な多項式的深さの回路向けで部分的なデータプライバシーを提供。
  • 漸近的なデータプライバシーを提供するが、回路プライバシーは弱いインタラクティブQHE方式(スキーム4)を導入。
  • スキーム4に埋め込み検証を追加(スキーム5)し、アリスのメッセージが検証に合格しない場合にボブが中止できるようにし、不正行為の検出を可能にする。
  • 量子情報ロックと最適化されたマスキングを用いた古典的線形多項式評価のためのスキーム6およびスキーム7を提案。早期終了を必要とせず、非自明なプライバシーを達成。
  • 1段階のロックを最終段階に適用して古典関数評価のための方式を統合し、データ漏洩れを定数ビットに制限。

実験結果

リサーチクエスチョン

  • RQ1多項式サイズの量子回路のためのQHE方式を、実プロダクト状態に対して完全なデータプライバシーを達成できるように構築可能か?
  • RQ2QHEプロトコルにおいてデータプライバシーを維持しつつ、回路プライバシーを最適化する方法は何か?
  • RQ3インタラクティブQHE方式は、データ提供者の不正行為を検出可能でありつつ、プライバシーを維持できるか?
  • RQ4早期終了を必要としない状況で、古典的関数評価におけるデータおよび回路プライバシーの水準はどの程度達成可能か?
  • RQ51人の参加者が完全に古典的である場合、非自明な情報理論的プライバシーを備えたQHE方式を設計可能か?

主な発見

  • 制限付き回路向けに提案されたQHE方式は、再ビット形式を用いて実プロダクト入力状態に対して完全なデータプライバシーを達成する。
  • 2つの非インタラクティブ方式とも、入力サイズと回路深さの積に比例してエンタングルメントおよび古典的通信コストが線形にスケーリングされる。
  • インタラクティブスキーム4は漸近的なデータプライバシーを提供するが、データ提供者の不正行為の可能性があるため回路プライバシーは弱い。
  • 埋め込み検証を備えたスキーム5は、不正行為が検出可能であり、データ漏洩れを定数ビットに制限する。
  • 古典的線形多項式評価のためのスキーム6およびスキーム7は、早期終了を必要とせず、非自明なデータプライバシーと回路プライバシーを達成する。
  • 1ビット出力の最終プロトコルは正しさを保証し、ランダム回路を仮定するとデータ漏洩れをわずか2ビットに制限する。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。