Encrypted Cloning in Quantum Information
- Encrypted cloning is a quantum-information method that creates many maximally mixed clones, each useless until decrypted using a specialized single-use key.
- It leverages aspects of the no-cloning theorem and secret-sharing access structures to allow only one chosen clone to recover the original quantum state, ensuring controlled redundancy.
- Protocols extend from qubits to qudits, integrating practical circuit designs, security bounds, and experimental validations to demonstrate both recoverability and inherent leakage constraints.
Encrypted cloning denotes a family of quantum-information constructions in which quantum mechanics is used to control not merely secrecy, but the multiplicity of usable recoveries. In one prominent sense, an unknown quantum state is transformed into many encrypted “clones,” each individually useless and typically maximally mixed, while a separate single-use key system allows one chosen clone to be decrypted perfectly at a later time (Yamaguchi et al., 6 Jan 2025). In a second, closely related sense, the term appears in the literature on uncloneable encryption, where the objective is the converse: to prevent a single quantum ciphertext from being split into two systems that both enable successful decryption once the key is revealed (Botteron et al., 2024). Taken together, these lines of work define a technical landscape in which no-cloning, monogamy of entanglement, secret-sharing access structures, and quantum cryptographic security notions are all central (Bhattacharyya et al., 9 Mar 2026).
1. Conceptual scope and relation to the no-cloning theorem
The standard no-cloning theorem forbids a universal operation that maps an arbitrary unknown state to . Encrypted cloning does not implement such a map. In the Yamaguchi–Kempf construction, the output systems that are informally called “clones” are not independently accessible copies of ; rather, each signal system is a potential recovery location whose reduced state is useless without a correlated quantum key, and decryption consumes that key so that only one plaintext copy can be obtained (Yamaguchi et al., 6 Jan 2025).
A structural reformulation casts quantum encrypted cloning as an access-structure property. An unknown input state is encoded by an isometry
and there exists a non-qualified subsystem together with several non-qualified subsystems such that each union is qualified, while all qualified sets used for “cloning” intersect on the same key subsystem . In this reading, what is cloned is not the state itself but a set of alternative redemption opportunities, all of which share a common intersection and therefore never violate no-cloning (Gianini et al., 4 Jun 2026).
The uncloneable-encryption literature studies the dual problem for classical messages encoded into quantum ciphertexts. A quantum encryption of classical messages is given by $(\Gen,\Enc,\Dec)$, with 0, 1, and 2. The no-cloning game asks whether a pirate can apply a CPTP map 3 to a single ciphertext, distribute two systems to Bob and Charlie, and later—after both receive the same classical key—enable them both to output the correct message. Security is expressed by bounding
4
where 5 is the trivial random-guessing baseline for a bit (Botteron et al., 2024).
2. Canonical encrypted cloning of unknown qubits
The canonical qubit protocol starts from an unknown input qubit 6 in state 7 and 8 Bell pairs 9, each prepared as
0
The signal qubits 1 are intended to become encrypted clones, while the noise qubits 2 form the decryption key (Yamaguchi et al., 6 Jan 2025).
Encryption is performed by the unitary
3
which acts on 4 and leaves the 5 untouched. After encoding, each individual signal qubit is maximally mixed, and the channel from 6 to a single 7 has quantum capacity
8
whereas the channel from 9 to 0 has
1
This precisely formalizes that no single clone carries usable quantum information, while one chosen clone together with the full key does (Yamaguchi et al., 6 Jan 2025).
To decrypt from 2, the protocol uses
3
where 4. The resulting transformation recovers 5 exactly on 6, while the rest of the system becomes independent of 7. The key is therefore single-use in the operational sense that, after one decryption, the remaining systems no longer contain the original quantum information (Yamaguchi et al., 6 Jan 2025).
This protocol yields arbitrarily many encrypted qubit clones in principle. It also admits a gate-level decomposition: encoding uses 8 two-qubit gates and 9 single-qubit gates, decryption uses at most 0 two-qubit gates, and the full encode–decode pipeline uses at most 1 two-qubit gates (Yamaguchi et al., 6 Jan 2025).
3. Qudit generalizations, AME structure, and secret-sharing interpretations
The qubit construction was generalized to arbitrary finite dimension 2. One approach introduces generalized Pauli operators 3, collective operators
4
and replaces the qubit exponential construction with a CAZAC-based unitary
5
where 6 is chosen from a Zadoff–Chu sequence. The resulting encrypted state has the property that each single share 7 is maximally mixed, 8, while a decryption unitary acting on one chosen share and all key qudits recovers 9 exactly. The circuit analysis gives 0 and 1 for encryption, while decryption has
2
so the decryption overhead is 3 (Ceară, 6 Apr 2026).
A complementary generalization uses Weyl–Heisenberg displacement operators
4
and defines
5
with a matching decryption unitary built from generalized Bell projectors and transposed Weyl operators. This formulation proves that, for 6 and a uniform input state, the encrypted five-party state is 7, and that a partially encrypted Bell-pair construction yields an 8 state equivalent to a pure-state 9 threshold QSS scheme. The paper consequently formalizes QSS as the natural framework within which encrypted cloning can be contextualised (Lim et al., 26 May 2026).
The access-structure viewpoint was then abstracted further. A QSS scheme supports a quantum encrypted-cloning structure whenever its family of qualified sets contains a non-qualified common intersection 0 and qualified supersets 1 whose non-common parts 2 are themselves non-qualified. Perfect QSS yields perfectly hidden clones, whereas ramp QSS yields intermediate, partially informative non-redeeming subsystems. This generalizes encrypted cloning from a specific Pauli-based protocol to an access-structure primitive encompassing threshold-like, ramp, hierarchical, and compartmented architectures (Gianini et al., 4 Jun 2026).
4. Confidentiality, informative subsets, and leakage
Encrypted cloning was introduced to make redundancy compatible with no-cloning, not to guarantee perfect confidentiality for every unauthorized subsystem. For the qubit protocol, each individual signal qubit is maximally mixed, but a complete classification of storage-register subsets shows that unauthorized subsets can nevertheless leak structured information (Gianini et al., 11 Apr 2026).
For the qubit scheme, any subset 3 that misses a complete pair 4 is completely non-informative. The only nontrivial unauthorized case is an aligned subset of size 5,
6
containing exactly one qubit from each pair. Its reduced state is
7
Hence leakage is parity-dependent and restricted to the 8-component of the input Bloch vector. This establishes that the protocol has a structural confidentiality limitation: some unauthorized subsets are completely non-informative, while others are partially informative but still non-authorized (Gianini et al., 11 Apr 2026).
The qudit case exhibits an arithmetic generalization of the qubit parity rule. For the aligned subset
9
with 0, the reduced state is completely uninformative if and only if
1
If the gcd is larger than 2, then nontrivial solutions of a system of congruences survive in the reduced state, and the subset retains residual dependence on 3 through specific generalized Pauli operators 4. The qubit result is recovered as the special case 5, where the condition reduces to the previously derived parity classification (Bai et al., 12 May 2026).
A recurring conclusion of this line of work is therefore that encrypted cloning and perfect secrecy are distinct objectives. In these protocols, encryption is introduced to enable cloning-compatible redundancy, and confidentiality properties have to be analyzed explicitly rather than inferred from the existence of a single-use key (Gianini et al., 11 Apr 2026).
5. Uncloneable encryption: preventing encrypted cloning of classical messages
The phrase also refers to a cryptographic task in which encrypted cloning is to be ruled out. Broadbent–Lord introduced unclonable encryption, and subsequent work revisited its relationship to semantic security, generalized the underlying monogamy-game viewpoint, and exhibited concrete lower-bound attacks on BB84-type one-time schemes. In particular, qubit-wise generalized conjugate encryptions admit a 6 cloning attack, and Broadbent–Lord’s original conjugate encryption admits a 7 attack, showing that the previously known 8 upper bound was not tight (Ananth et al., 2021).
A 2024 candidate for unconditional uncloneable encryption constructs an uncloneable bit from pairwise anti-commuting Hermitian unitaries 9 arising from a Clifford-algebra representation. The ciphertexts are
0
and decryption measures in the eigenbasis of 1. The conjectured optimal no-cloning success probability is
2
with the bound proved for 3, matched numerically up to 4 via the NPA hierarchy, an asymptotic level-1 upper bound of 5, and a numerical level-2 upper bound of 6 at 7 (Botteron et al., 2024).
That conjectural picture was superseded by a 2026 unconditional existence result. The scheme 8 uses an 9-qubit Clifford unitary 2-design, encrypting a bit as $(\Gen,\Enc,\Dec)$0 where $(\Gen,\Enc,\Dec)$1 fixes the first qubit and maximally mixes the remaining $(\Gen,\Enc,\Dec)$2. The cloning value satisfies
$(\Gen,\Enc,\Dec)$3
so two non-communicating adversaries given the same key after splitting the ciphertext cannot beat random guessing by more than an exponentially small term. The proof combines a decoupling step, the operational interpretation of conditional min-entropy, an exponential de Finetti theorem, an AEP argument, and strong subadditivity in the form
$(\Gen,\Enc,\Dec)$4
which enforces monogamy of entanglement in the security game (Bhattacharyya et al., 9 Mar 2026).
Once an information-theoretic uncloneable bit is available, later work shows that many-time secure uncloneable encryption for arbitrary-length messages can be bootstrapped in “microcrypt.” If many-time secure symmetric key encryption exists, then many-time secure $(\Gen,\Enc,\Dec)$5 uncloneable encryption for arbitrary-length messages exists; if pseudorandom unitaries exist, then many-time secure $(\Gen,\Enc,\Dec)$6 uncloneable encryption with identical copy security exists. This places uncloneable encryption within a broader program of deriving quantum unclonable primitives from minimal reusable assumptions (Bartusek et al., 26 May 2026).
6. Experimental status, resource profile, and broader technical uses
Encrypted cloning is no longer purely formal. A 2026 experiment on IBM Heron-R2 superconducting processors implemented the Yamaguchi–Kempf protocol on up to 154 qubits and reported that encrypted cloning is stable under hardware noise, even when used as a module, namely in parallel, series or interleaved, while preserving pre-existing entanglement. The work explicitly interprets this as showing that quantum information can be spread at will, in theory and in practice, without dilution or degradation, if encrypted or obscured, with the actual constraint being that the decryption mechanism must be single-use (Yamaguchi et al., 11 Feb 2026).
The resource profile remains architecture-dependent. For qubits, the canonical protocol scales linearly in the number of encrypted clones at the level of two-qubit gates, and the qudit generalization preserves $(\Gen,\Enc,\Dec)$7 for encryption while moving the main complexity burden into a decryption stage that scales as $(\Gen,\Enc,\Dec)$8. This makes encrypted cloning conceptually simple but shifts practical difficulty toward decryption, generalized Bell-basis control, and multi-qudit conditional operations (Yamaguchi et al., 6 Jan 2025, Ceară, 6 Apr 2026).
The term should also be distinguished from other technical uses of “cloning.” In SGX systems, cloning attacks or forking attacks refer to the ability to run multiple enclaves with the same identity on the same platform, thereby creating several concurrent encrypted state histories despite sealing and, in some cases, monotonic counters; the paper’s survey finds roughly 20% of 72 analyzed SGX-based proposals insecure against such attacks (Wilde et al., 14 Jan 2026). In deep learning, “cloning” denotes black-box reconstruction of a surrogate model from input–output access, and one line of work studies how to poison outputs imperceptibly so as to prevent such cloning of weights (Kenway, 2018). These are conceptually separate from the quantum-information primitive, but they underscore a common theme: encryption or confidentiality alone does not settle the question of whether functional capability can be duplicated.