Skip to main content
QUICK REVIEW

[论文解读] A quantum homomorphic encryption scheme for polynomial-sized circuits

Li Yu|arXiv (Cornell University)|Oct 2, 2018
Quantum Computing Algorithms and Architecture参考文献 40被引用 3
一句话总结

本文提出了一种基于双比特形式的量子同态加密(QHE)方案,用于多项式规模的量子电路,实现了真实产物态的完美数据隐私和良好的电路隐私。该方案引入了两种非交互式方案,其资源消耗呈线性增长;此外还提出了一种具有内嵌验证机制的交互式变体,可有效防范欺骗行为,提供渐近数据隐私,并在实际应用中实现最小信息泄露的电路隐私。

ABSTRACT

Quantum homomorphic encryption (QHE) is an encryption method that allows quantum computation to be performed on one party's private data with the program provided by another party, without revealing much information about the data nor about the program to the opposite party. It is known that information-theoretically-secure QHE for circuits of unrestricted size would require exponential resources, and efficient computationally-secure QHE schemes for polynomial-sized quantum circuits have been constructed. In this paper we first propose a QHE scheme for a type of circuits of polynomial depth, based on the rebit quantum computation formalism. The scheme keeps the restricted type of data perfectly secure. We then propose a QHE scheme for a larger class of polynomial-depth quantum circuits, which has partial data privacy. Both schemes have good circuit privacy. We also propose an interactive QHE scheme with asymptotic data privacy, however, the circuit privacy is not good, in the sense that the party who provides the data could cheat and learn about the circuit. We show that such cheating would generally affect the correctness of the evaluation or cause deviation from the protocol. Hence the cheating can be caught by the opposite party in an interactive scheme with embedded verifications. Such scheme with verification has a minor drawback in data privacy. Finally, we show some methods which achieve some nontrivial level of data privacy and circuit privacy without resorting to allowing early terminations, in both the QHE problem and in secure evaluation of classical functions. The entanglement and classical communication costs in these schemes are polynomial in the circuit size and the security parameter (if any).

研究动机与目标

  • 设计一种适用于多项式规模量子电路的QHE方案,具备强大的数据隐私和电路隐私。
  • 利用双比特形式,实现对真实产物输入态的完美数据隐私,防止信息泄露。
  • 开发一种具有内嵌验证机制的交互式QHE协议,可检测欺骗行为并维持高隐私水平。
  • 探索适用于经典线性函数评估的非交互式方案,并实现非平凡的隐私保障。
  • 研究在经典客户端参与的情况下,信息论隐私在QHE中的可行性。

提出的方法

  • 采用双比特量子计算以避免在基于测量的协议中发生数据泄露。
  • 构建了两个非交互式QHE方案:一个用于受限电路,实现完美数据隐私;另一个用于更广泛的多项式深度电路,实现部分数据隐私。
  • 提出一种交互式QHE方案(方案4),具备渐近数据隐私,但电路隐私较弱。
  • 通过在方案4中引入内嵌验证机制(方案5),使鲍勃能够在检测到爱丽丝消息无效时中止协议,从而实现对欺骗行为的检测。
  • 提出方案6和方案7,用于通过量子信息锁存和优化掩码技术评估经典线性多项式,实现在无需提前终止情况下的非平凡隐私保障。
  • 将多种方案整合用于经典函数评估,通过在末尾使用一级锁存机制,将数据泄露限制在常数数量的比特以内。

实验结果

研究问题

  • RQ1能否为多项式规模的量子电路设计一种QHE方案,使真实产物输入态实现完美数据隐私?
  • RQ2在保持数据隐私的前提下,如何优化QHE协议中的电路隐私?
  • RQ3交互式QHE方案能否在保护隐私的同时检测到数据提供方的欺骗行为?
  • RQ4在不提前终止的情况下,经典函数评估中可实现何种程度的数据和电路隐私?
  • RQ5当一方为完全经典时,能否设计出具备非平凡信息论隐私的QHE方案?

主要发现

  • 所提出的受限电路QHE方案利用双比特形式,对真实产物输入态实现了完美数据隐私。
  • 两种非交互式方案的纠缠资源和经典通信成本均与输入尺寸和电路深度的乘积呈线性关系。
  • 交互式方案4提供渐近数据隐私,但由于数据提供方可能存在欺骗行为,其电路隐私较弱。
  • 方案5通过内嵌验证机制,确保欺骗行为可被检测,并将数据泄露限制在常数数量的比特以内。
  • 方案6和方案7在经典线性多项式评估中实现了非平凡的数据和电路隐私,且无需提前终止。
  • 最终的一比特输出协议在假设电路为随机电路的前提下,确保了正确性,并将数据泄露限制在仅2比特以内。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。