A fully homomorphic encryption system hides data from unauthorized parties,
while still allowing them to perform computations on the encrypted data. Aside
from the straightforward benefit of allowing users to delegate computations to
a more powerful server without revealing their inputs, a fully homomorphic
cryptosystem can be used as a building block in the construction of a number of
cryptographic functionalities. Designing such a scheme remained an open problem
until 2009, decades after the idea was first conceived, and the past few years
have seen the generalization of this functionality to the world of quantum
machines. Quantum schemes prior to the one implemented here were able to
replicate some features in particular use-cases often associated with
homomorphic encryption but lacked other crucial properties, for example,
relying on continual interaction to perform a computation or leaking
information about the encrypted data. We present the first experimental
realisation of a quantum fully homomorphic encryption scheme. We further
present a toy two-party secure computation task enabled by our scheme. Finally,
as part of our implementation, we also demonstrate a post-selective two-qubit
linear optical controlled-phase gate with a much higher post-selection success
probability (1/2) when compared to alternate implementations, e.g. with
post-selective controlled-Z or controlled-X gates (1/9).Comment: 11 pages, 16 figures, 2 table