Researchers have developed a key-decoupled circuit-model blind quantum computation protocol that enhances privacy protection in delegated quantum computing while reducing the operational burden on the client. By independently generating encryption and decryption keys, the protocol avoids gate-by-gate propagation of decryption information and conceals the target operation within its Pauli equivalence class. A low-overhead statistical verification strategy based on randomly sampled Pauli observables is further introduced to detect deviations by the quantum server. Proof-of-principle experiments on an IBM superconducting quantum processor, together with multi-qubit numerical simulations, demonstrate the feasibility and scalability of the approach for privacy-preserving quantum cloud computing.
As quantum computing increasingly moves to cloud platforms, protecting the privacy of users’ quantum data and algorithms has become an important challenge. Researchers from Jinan University and Sun Yat-sen University have developed a key-decoupled circuit-model blind quantum computation (CMBQC) protocol that simplifies client-side operations while protecting the delegated computation.
“A major limitation of conventional circuit-model blind quantum computation is that decryption information may need to be updated gate by gate, increasing the client-side burden as the circuit becomes deeper,” explains Associate Professor Xiaoqian Zhang from Jinan University. “Our protocol independently generates the encryption and decryption keys, eliminating this gate-by-gate key propagation.”
In the proposed scheme, the client only performs a Pauli-encryption operation before sending the quantum state to the server and a Pauli-decryption operation after receiving the output. The effects of the two independent keys are directly incorporated into the blinded quantum operation executed by the server, reducing the operational burden on the client.
The team further proved that the target operation is hidden within its Pauli equivalence class, meaning that the server cannot determine which specific operation in that class corresponds to the client’s true computation.
“Protecting the quantum state alone is not enough. The target computation itself may also contain sensitive information,” says Associate Professor Bingwen Feng from Jinan University. “Our approach provides an additional layer of privacy for delegated quantum computing.”
To verify whether the server performs the computation correctly, the researchers introduced a statistical verification method based on randomly sampled Pauli observables. Multiple interaction rounds are used, with one round carrying the actual computation and the others serving as verification rounds, allowing abnormal operations to be statistically detected with low overhead.
The protocol was experimentally demonstrated on IBM’s 133-qubit Torino superconducting quantum processor. In a representative test, the researchers used 16 interaction rounds, including one target computation round and 15 verification rounds, and successfully detected sufficiently large deliberately introduced deviations.
Additional experiments on several single-qubit gates and numerical simulations for representative two- and three-qubit gates further confirmed the feasibility of extending the verification strategy to multi-qubit systems.
“This work provides a simple and verifiable route toward privacy-preserving delegated quantum computation,” adds Xiaoqian Zhang. “It may help support the development of secure quantum cloud computing and networked quantum information processing.”
This paper, “Circuit-model blind quantum computation with key decoupling” was published in Quantum Research .
Xiang T, Feng B, Zhang X. Circuit-model blind quantum computation with key decoupling. Quantum Res. 2026(1):0004, https://doi.org/10.55092/qr20260004.
Quantum Research
Experimental study
Not applicable
Circuit-model blind quantum computation with key decoupling
21-Sep-2026