Quantum information has the property that measurement is an inherently destructive process. This feature is most apparent in the principle of complementarity, which states that mutually incompatible observables cannot be measured at the same time. Recent work by Broadbent and Islam (TCC 2020) builds on this aspect of quantum mechanics to realize a cryptographic notion called certified deletion. While this remarkable notion enables a classical verifier to be convinced that a (private-key) quantum ciphertext has been deleted by an untrusted party, it offers no additional layer of functionality. In this work, we augment the proof-of-deletion paradigm with fully homomorphic encryption (FHE). We construct the first fully homomorphic encryption scheme with certified deletion -- an interactive protocol which enables an untrusted quantum server to compute on encrypted data and, if requested, to simultaneously prove data deletion to a client. Our scheme has the desirable property that verification of a deletion certificate is public; meaning anyone can verify that deletion has taken place. Our main technical ingredient is an interactive protocol by which a quantum prover can convince a classical verifier that a sample from the Learning with Errors (LWE) distribution in the form of a quantum state was deleted. As an application of our protocol, we construct a Dual-Regev public-key encryption scheme with certified deletion, which we then extend towards a (leveled) FHE scheme of the same type. We introduce the notion of Gaussian-collapsing hash functions -- a special case of collapsing hash functions defined by Unruh (Eurocrypt 2016) -- and we prove the security of our schemes under the assumption that the Ajtai hash function satisfies a certain strong Gaussian-collapsing property in the presence of leakage.
翻译:量子信息具有测量本质上具有破坏性的属性。 这个特征在互补原则中最为明显, 它指出, 无法同时测量相互不兼容的可观察到性。 广域与伊斯兰教( TCC 2020) 最近的工作建立在量子机械学的这一方面上, 实现一个加密概念, 称为认证删除。 虽然这个显著的概念使古典校验官能够相信一个( 私钥) 量子密码器被一个不信任的一方删除, 它没有提供额外的功能层。 在这项工作中, 我们用完全同质层加密( FHE) 来强化排量校验范范范式。 我们用认证的删除了第一个完全同质加密( TCC 2020), 一个互动协议使一个不受信任的量子服务器能够对加密数据进行编译, 如果被请求, 可以同时向客户证明数据删除。 我们的计划具有理想的属性, 也就是任何人可以核实删除了。 我们的主要技术成分是一个互动协议, 通过这个协议, 量校准可以说服一个典型的校正校准者, 学习的样本与错误( LWE) 假设的自动分配。 我们的“ ” ” 向一个标准”, 我们的“ 我们的“ 的“ 向” 向” 的“ 的“ 向” 向” 的“ 的” 的” 的“ 向” 向” 的“ 的” 的“ 向” 的“ 的” 向”, 我们的“ 的“ 向” 的“ 向” 向” 向” 向” 的“ 的“ 的” 向” 向” 的“ 的” 向” 向” 向” 的“ 的“ 的“ 的“ 的“ 的” 的“ 的” 的“ 的“ ” 的“ 的” 的“ 的” 的” 的” 的” 向” 向” 向” 向” 的“ 的“ 的“ 的“ 的“ 的” 的”, 我们的” 的” 的” 的“ 的“, 我们的“ ” ” ”,, 我们的” 的“ 的“