[Paper Review] Further Limitations on Information-Theoretically Secure Quantum Homomorphic Encryption
This paper extends limitations on information-theoretically (IT) secure quantum fully homomorphic encryption (QFHE) using Nayak’s bound, showing that any such scheme capable of evaluating a super-exponential number of n-bit Boolean functions must have communication complexity at least log|Fₙ| − o(1). The bound holds even under imperfect IT-security, demonstrating a fundamental tradeoff between functionality and efficiency in IT-secure QFHE.
In this brief note, we review and extend existing limitations on information-theoretically (IT) secure quantum fully homomorphic encryption (QFHE). The essential ingredient remains Nayak's bound, which provides a tradeoff between the number of homomorphically implementable functions of an IT-secure QHE scheme and its efficiency. Importantly, the bound is robust to imperfect IT-security guarantees. We summarize these bounds in the context of existing QHE schemes, and discuss subtleties of the imposed restrictions.
Motivation & Objective
- To extend and clarify existing limitations on information-theoretically secure quantum fully homomorphic encryption (QFHE).
- To analyze the tradeoff between the number of permissible functions and communication efficiency in IT-secure QHE schemes.
- To investigate the robustness of these bounds under imperfect IT-security guarantees.
- To explore whether leveled QFHE schemes could circumvent these limitations despite their restricted function class.
- To assess the feasibility of constructing efficient QFHE schemes with meaningful IT-security under functional or interaction constraints.
Proposed method
- Applies Nayak’s bound from quantum random access codes to derive lower bounds on communication complexity in IT-secure QHE.
- Reduces the problem of function evaluation in QHE to a quantum information retrieval task, leveraging known bounds on quantum query complexity.
- Considers both perfect and imperfect correctness, generalizing bounds to allow for small error probabilities.
- Uses a coarse counting argument to show that the number of circuits implementable in a leveled scheme grows at most exponentially with input size.
- Analyzes the implications of restricting the set of permissible functions, particularly in the context of evaluation key design and information leakage.
- Extends prior results from Yu et al. (2014) and Newman and Shi (2018) by generalizing the lower bound to depend on the size of the function class Fₙ.
Experimental results
Research questions
- RQ1Can information-theoretically secure quantum fully homomorphic encryption schemes support a super-exponential number of n-bit Boolean functions without incurring prohibitive communication costs?
- RQ2How robust are existing no-go results for IT-secure QFHE under imperfect security guarantees, such as bounded leakage or small error rates?
- RQ3Is it possible to construct a leveled QFHE scheme that maintains meaningful information-theoretic security while allowing efficient evaluation of polynomial-sized circuits?
- RQ4What role does the evaluation key play in leaking information about the plaintext, and can such leakage be harnessed to enable efficient homomorphic evaluation in IT-secure schemes?
- RQ5Can complexity-theoretic assumptions provide stronger impossibility results for single-round, offline QFHE protocols?
Key findings
- Any IT-secure QHE scheme that can evaluate a set Fₙ of n-bit Boolean functions has a communication complexity lower bounded by log|Fₙ| − o(1), even under imperfect IT-security with ε(n) = O(2^−1.01n).
- The bound remains valid when ε(n) = θ(2^−n), provided |Fₙ| grows super-exponentially, indicating that the lower bound is robust to small error in indistinguishability.
- The tradeoff between the number of permissible functions and communication cost is fundamentally constrained by quantum information-theoretic limits, as formalized by Nayak’s bound.
- Leveled QFHE schemes are not ruled out by these bounds, since the number of implementable circuits grows at most exponentially with input size, which is insufficient to trigger the super-exponential lower bound.
- The results generalize prior work by Yu et al. (2014) and Newman and Shi (2018), extending the lower bound to depend on the size of the function class rather than just the number of gates.
- Imperfect correctness or security can be accommodated via generalized versions of Nayak’s bound, preserving the core tradeoff between functionality and efficiency.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.