Skip to main content

WAI Extension: Quantum-Operations Attestation (wai.quantum.calibration · wai.quantum.job)

Mirrored from the canonical text at commit 117bad22 ().

Status: Draft. Engine: wai-rs/src/quantum_ops.rs (feature quantum_ops). The verify-half of WAI (wai.asset.provenance’s lineage, specialized) applied to the quantum processing industry.

0. What this extension adds

A calibration run or a QPU job leaves a dataset (commonly HDF5), a state snapshot and a log. This extension adds a receipt over each operation with two properties:

  1. cryptographic signature + portability — a record a third party verifies from the bytes alone;
  2. measured joules — the energy of the operation, carried with its acquisition class, on hardware whose dilution refrigerator and control racks draw kilowatts.

Related reproducibility work exists (version capture of the software that ran, QBOM bills of materials, hash-chained audit traces such as QCIVET’s); the receipt here is signed, content-addressed and joule-metered. It is not a control system and runs no hardware: the calibration/job is performed by the sink’s control stack, exactly as WAI dispatches a decode to a sink’s codec. WAI owns the receipt.

1. Two receipts, cross-linked

wai.quantum.calibration — CalibrationReceipt

A signed record of one bring-up / tune-up run:

merkle_root covers [config_hash] ++ evidence leaves; one Ed25519 signature covers the whole payload.

wai.quantum.job — JobReceipt

A signed record of one dispatched circuit:

2. The grant — gate ⊗ meter ⊗ receipt in one object

GrantRef = capability ⊗ joule-ceiling (⊗ optional funds-ceiling, JCP §4.8 dual ceiling). The full grant lives in the JCP layer; the receipt binds its content hash plus the ceilings it enforces.

The enforcement is the sharp part: the joule ceiling is checked inside verify(). A receipt whose measured joules_micro exceeds its grant ceiling is not valid — an operation that blew its energy grant cannot produce a passing receipt. This is the whole portfolio thesis (gate, meter, receipt) collapsed into a single verifiable object. honors_budget() exposes the check on its own; a grant with joule_ceiling_micro = u64::MAX opts out (still signs everything else).

3. Conformance

4. What this is NOT

5. Integration (where it attaches)

The natural attach point is the control-system → cloud boundary: the moment a calibration node or a job completes, the control system already holds everything a receipt needs (config, evidence datasets, result, timing, backend identity), and the power rails are already instrumented — so adding a signature + a joule figure is incremental. Open-source insertion points:

  1. Quantify (quantify-core) — one HDF5-write point covers every node.
  2. A lab-OS task-management and database layer, as a control plane; in production chip testing a signed pass/fail is the record a test produces.
  3. QUAlibrate/QUAM — the per-node boundary, and its existing record of package versions, map onto a signed, metered receipt.
  4. Qubex/qube-calib — a CalibrationNote artifact per node.

6. The metric

This extension carries joules per verified calibration and joules per QPU job as signed, portable, content-addressed, grant-bounded records.