Skip to main content
QUICK REVIEW

[Paper Review] A quantum homomorphic encryption scheme for polynomial-sized circuits

Li Yu|arXiv (Cornell University)|Oct 2, 2018
Quantum Computing Algorithms and Architecture40 references3 citations
TL;DR

This paper proposes a quantum homomorphic encryption (QHE) scheme for polynomial-sized quantum circuits using rebit formalism, achieving perfect data privacy for real product states and good circuit privacy. It introduces two non-interactive schemes with linear resource scaling and an interactive variant with embedded verifications that ensure security against cheating, offering asymptotic data privacy and practical circuit privacy with minimal information leakage.

ABSTRACT

Quantum homomorphic encryption (QHE) is an encryption method that allows quantum computation to be performed on one party's private data with the program provided by another party, without revealing much information about the data nor about the program to the opposite party. It is known that information-theoretically-secure QHE for circuits of unrestricted size would require exponential resources, and efficient computationally-secure QHE schemes for polynomial-sized quantum circuits have been constructed. In this paper we first propose a QHE scheme for a type of circuits of polynomial depth, based on the rebit quantum computation formalism. The scheme keeps the restricted type of data perfectly secure. We then propose a QHE scheme for a larger class of polynomial-depth quantum circuits, which has partial data privacy. Both schemes have good circuit privacy. We also propose an interactive QHE scheme with asymptotic data privacy, however, the circuit privacy is not good, in the sense that the party who provides the data could cheat and learn about the circuit. We show that such cheating would generally affect the correctness of the evaluation or cause deviation from the protocol. Hence the cheating can be caught by the opposite party in an interactive scheme with embedded verifications. Such scheme with verification has a minor drawback in data privacy. Finally, we show some methods which achieve some nontrivial level of data privacy and circuit privacy without resorting to allowing early terminations, in both the QHE problem and in secure evaluation of classical functions. The entanglement and classical communication costs in these schemes are polynomial in the circuit size and the security parameter (if any).

Motivation & Objective

  • To design a QHE scheme for polynomial-sized quantum circuits with strong data and circuit privacy.
  • To achieve perfect data privacy for real product input states using rebit formalism to prevent information leakage.
  • To develop an interactive QHE protocol with embedded verifications that detect cheating and maintain high privacy.
  • To explore non-interactive schemes for classical linear function evaluation with nontrivial privacy guarantees.
  • To investigate the feasibility of information-theoretic privacy in QHE with classical clients.

Proposed method

  • Uses rebit quantum computation to avoid data leakage during measurement-based protocols.
  • Constructs two non-interactive QHE schemes: one for restricted circuits with perfect data privacy, another for broader polynomial-depth circuits with partial data privacy.
  • Introduces an interactive QHE scheme (Scheme 4) with asymptotic data privacy but weaker circuit privacy.
  • Enhances Scheme 4 with embedded verifications (Scheme 5), allowing Bob to abort if Alice’s messages fail validation, thus detecting cheating.
  • Proposes Scheme 6 and Scheme 7 for evaluating classical linear polynomials using quantum information locking and optimized masking, achieving nontrivial privacy without early termination.
  • Combines schemes for classical function evaluation, using one-level locking at the end to limit data leakage to a constant number of bits.

Experimental results

Research questions

  • RQ1Can a QHE scheme be constructed for polynomial-sized quantum circuits with perfect data privacy for real product states?
  • RQ2How can circuit privacy be optimized while maintaining data privacy in QHE protocols?
  • RQ3Can interactive QHE schemes detect cheating by the data provider while preserving privacy?
  • RQ4What level of data and circuit privacy can be achieved in classical function evaluation without early termination?
  • RQ5Is it possible to design a QHE scheme with nontrivial information-theoretic privacy when one party is fully classical?

Key findings

  • The proposed QHE scheme for restricted circuits achieves perfect data privacy for real product input states using rebit formalism.
  • Both non-interactive schemes scale entanglement and classical communication costs linearly with the product of input size and circuit depth.
  • The interactive Scheme 4 provides asymptotic data privacy, though circuit privacy is weak due to potential cheating by the data provider.
  • Scheme 5, with embedded verifications, ensures that cheating is detectable and limits data leakage to a constant number of bits.
  • Schemes 6 and 7 for classical linear polynomial evaluation achieve nontrivial data and circuit privacy without requiring early termination.
  • The final protocol for one-bit output ensures correctness and limits data leakage to just 2 bits, under the assumption of random circuits.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.