Succinct blind Quantum computation using a random oracle
Jiayu Zhang
Abstract
In the universal blind quantum computation problem, a client wants to make use of a single quantum server to evaluate C |0 where C is an arbitrary quantum circuit while keeping C secret. The client's goal is to use as few resources as possible. This problem, with a representative protocol by Broadbent, Fitzsimons and Kashefi(Broadbent et al., 2009), has become fundamental to the study of quantum cryptography, not only because of its own importance, but also because it provides a testbed for new techniques that can be later applied to related problems (for example, quantum computation verification). Known protocols on this problem are mainly either information-theoretically (IT) secure or based on trapdoor assumptions (public key encryptions).
In this paper we study how the availability of symmetric-key primitives, modeled by a random oracle, changes the complexity of universal blind quantum computation. We give a new universal blind quantum computation protocol. Similar to previous works on IT-secure protocols (for example, BFK (Broadbent et al., 2009)), our protocol can be divided into two phases. In the first phase the client prepares some quantum gadgets with relatively simple quantum gates and sends them to the server, and in the second phase the client is entirely classical -it does not even need quantum storage. Crucially, the protocol's first phase is succinct, that is, its complexity is independent of the circuit size. Given the security parameter κ, its complexity is only a fixed polynomial of κ, and can be used to evaluate any circuit (or several circuits) of size up to a subexponential of κ. In contrast, known schemes either require the client to perform quantum computations that scale with the size of the circuit (Broadbent et al., 2009), or require trapdoor assumptions (Mahadev, 2018a).
How to understand this statement Let's explain the statement above.
- The conclusion is (almost) the same as Lemma 7.2.1, and the extra "2 -2η " term is small enough to be ignored if you are trying to get an intuitive understanding.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e6e5ed0f-097e-4c3b-a4d5-b98c1b745686Cited by top-tier papers3
- Public Key Encryption with Secure Key LeasingShweta Agrawal, Fuyuki Kitagawa, Ryo Nishimaki, Shota Yamada et al.EUROCRYPT 2023 · 22 citations
- On the Impossibility of Key Agreements from Quantum Random OraclesPer Austrin, Hao Chung, Kai-Min Chung, Shiuan Fu et al.CRYPTO 2022 · 20 citations
- Quantum garbled circuitsZvika Brakerski, Henry YuenSTOC 2022 · 10 citations
Related papers
- Classical Verification of Quantum Computations in Linear TimeJiayu ZhangFOCS 2022 · 9 citations
- Constant-Round Blind Classical Verification of Quantum SamplingKai-Min Chung, Yi Lee, Han-Hsuan Lin, Xiaodi WuEUROCRYPT 2022 · 7 citations
- Breaking the Barrier on Garbled Circuit Size in the Random Oracle ModelJunru Li, Yifan SongCRYPTO 2026
- Lower Bounds for Garbled Circuits from Shannon-Type Information InequalitiesJake Januzelli, Mike Rosulek, Lawrence RoyCRYPTO 2025 · 3 citations
- Round Efficient Secure Multiparty Quantum Computation with Identifiable AbortBar Alon, Hao Chung, Kai-Min Chung, Mi-Ying Huang et al.CRYPTO 2021 · 16 citations
