Quantum key distribution method and system
By generating quantum signals and performing quantum measurements in a data processing device, and using encryption and coordination signals to determine a shared key, the problem of key length being equal to message length is solved, achieving more efficient information transmission and enhanced security.
Patent Information
- Application Number
- CN202210100413.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-01-27
- Filing Date
- 2022-01-27
- Publication Date
- 2026-02-17
- Estimated Expiration
- 2042-01-27
AI Technical Summary
In classically correlated quantum locking, the key length is equal to the message length, resulting in low information transmission efficiency and an inability to effectively utilize the security advantages of quantum correlation.
By providing an initial key in the data processing device, a quantum signal is generated and quantum measurements are performed. A shared key is determined using encryption and coordination signals. BB84, B92, entanglement-based quantum key distribution protocols are adopted, combined with fiber optic or air transmission. The coordination signal is determined by matching or mismatching the quantum base settings and measurement results, and a shared key is generated through parity checking and error correction.
This achieves the goal of reducing key length, improving information transmission efficiency, and enhancing the security and reliability of information transmission while maintaining security.
Smart Images

Figure CN114817940B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to a method for quantum key distribution. Furthermore, a system for quantum key distribution is disclosed. Background Technology
[0002] In classically correlated quantum locking, a first data processing device (“Alice”) transmits a message 'a' of length 'm' to a second data processing device (“Bob”). Message 'a' remains secret until the first data processing device further transmits a key 'k' of length '|K|' to the second data processing device. It is important to determine how short the key 'k' can be while still securely encrypting message 'a'. If the first and second data processing devices consist only of classical resources, the length of the key 'k' must be approximately the same as the length of message 'a', i.e., m ≈ |K|. An exemplary implementation is represented by a one-time pad. In this case, security follows the principle of information causality: by transmitting 'l' bits, the correlation between the first and second data processing devices cannot increase by more than 'l' bits. However, in the case of quantum correlation, the principle of information causality can be violated, resulting in potentially smaller key lengths while still maintaining the required level of security. Conversely, by keeping the key length constant, more information can be transmitted securely. Nevertheless, it is desirable to achieve even higher levels of information transmission. Summary of the Invention
[0003] One object of this disclosure is to provide an improved technique for transmitting data via quantum key distribution.
[0004] To address this problem, a method and system for quantum key distribution are provided according to the independent claim. Further embodiments are disclosed in the dependent claims.
[0005] According to one aspect, a method for quantum key distribution is provided in a system comprising multiple data processing devices, the method comprising: providing an initial key in a first data processing device and a second data processing device; providing a quantum signal comprising multiple quantum states in the second data processing device; determining multiple quantum measurement parameters in the second data processing device; determining an original signal in the second data processing device by performing quantum measurements on the multiple quantum states using the multiple quantum measurement parameters; generating an encrypted signal in the second data processing device using the initial key that indicates at least one of the multiple quantum measurement parameters, and transmitting the encrypted signal to the first data processing device; determining a coordination signal based on the encrypted signal in at least one of the first data processing device and the second data processing device; and determining a shared key based on the coordination signal by correcting a first coordination signal in at least one of the first data processing device and the second data processing device.
[0006] According to another aspect, a system for quantum key distribution is provided, the system comprising a plurality of data processing devices and configured to perform: providing an initial key in a first data processing device and a second data processing device; providing a quantum signal comprising a plurality of quantum states in the second data processing device; determining a plurality of quantum measurement parameters in the second data processing device; determining an original signal in the second data processing device by performing quantum measurements on the plurality of quantum states using the plurality of quantum measurement parameters; generating an encrypted signal in the second data processing device using the initial key indicating at least one of the plurality of quantum measurement parameters, and transmitting the encrypted signal to the first data processing device; determining a coordination signal based on the encrypted signal in at least one of the first data processing device and the second data processing device; and determining a shared key based on the coordination signal by correcting a first coordination signal in at least one of the first data processing device and the second data processing device.
[0007] The original signal can be a second original signal. The encrypted signal can be a second encrypted signal. The coordination signal can be a second coordination signal. The multiple quantum states can be multiple second quantum states. The quantum signal can be a second quantum signal.
[0008] The method may follow at least one of the following protocols: BB84 (Bennett-Brassard 1984), B92 (Bennett 1992), entanglement-based quantum key distribution, measurement device-independent quantum key distribution, and two-field quantum key distribution. The quantum signal may be transmitted via optical fiber, or alternatively via air.
[0009] The method may further include at least one of the following: determining a plurality of quantum preparation parameters in the first data processing device; preparing a first quantum signal comprising a plurality of first quantum states using the plurality of quantum preparation parameters according to a first original signal in the first data processing device; transmitting the first quantum signal from the first data processing device to a second data processing device, thereby providing a quantum signal comprising the plurality of quantum states in the second data processing device; generating a first encrypted signal indicating at least one of the plurality of quantum preparation parameters using the initial key in the first data processing device, and transmitting the first encrypted signal to the second data processing device; determining a coordination signal in the second data processing device based on the original signal and the first encrypted signal; and determining a first coordination signal in the first data processing device based on the first original signal and the encrypted signal.
[0010] The plurality of quantum states can be obtained from the plurality of first quantum states through unitary evolution of each of the plurality of first quantum states. The transmission of encrypted signals, first encrypted signals, or any other signals encrypted using an initial key can be included within a dedicated communication channel.
[0011] Each of the plurality of quantum states and / or each of the plurality of first quantum states can be a photon quantum state. Each of the plurality of quantum states and / or each of the plurality of first quantum states can be a photon polarization state.
[0012] At least one of the plurality of quantum measurement parameters and / or at least one of the plurality of quantum preparation parameters may include a quantum basis setting. At least one of the plurality of quantum measurement parameters and / or at least one of the plurality of quantum preparation parameters may also include the type of measurement result, such as indicating an uncertain result.
[0013] Quantum basis settings can include measurements on a horizontal / vertical polarization basis or on an anti-angle / diagonal polarization basis.
[0014] Each bit of the original signal in the second data processing device may correspond to one of the plurality of quantum measurement parameters and / or one of the plurality of quantum states. The coordination signal can be determined in the second data processing device based on the original signal and the first encrypted signal by discarding a bit of the original signal if a corresponding quantum measurement parameter among the plurality of quantum measurement parameters does not match a corresponding quantum preparation parameter among the quantum preparation parameters of the first encrypted signal. Each bit of the first original signal in the first data processing device may correspond to one of the plurality of quantum preparation parameters and one of the plurality of first quantum states. The first coordination signal can be determined in the first data processing device based on the first original signal and the encrypted signal by discarding a bit of the first original signal if a corresponding quantum measurement parameter among the plurality of quantum measurement parameters from the encrypted signal does not match a corresponding quantum preparation parameter among the quantum preparation parameters.
[0015] Alternatively or additionally, the coordination signal can be determined in the second data processing device based on the original signal and the quantum preparation parameters by discarding a bit from the original signal if a corresponding quantum preparation parameter in the quantum preparation parameters includes a discard flag. The discard flag may, for example, correspond to an indication of an uncertain result. Further, the first coordination signal can be determined in the first data processing device based on the first original signal and the encrypted signal by discarding a bit from the first original signal if a corresponding quantum measurement parameter from the plurality of quantum measurement parameters of the first encrypted signal and a corresponding quantum preparation parameter from the quantum preparation parameters in the encryption include a discard flag.
[0016] The method may further include at least one of the following: generating first parity data based on the first coordination signal in the first data processing device; encrypting the first parity data into encrypted first parity data using the initial key in the first data processing device, and transmitting the encrypted first parity data to the second data processing device; generating second parity data based on the coordination signal in the second data processing device; encrypting the second parity data into encrypted second parity data using the initial key in the second data processing device, and transmitting the encrypted second parity data to the first data processing device; using the first parity data and the second parity data to determine the difference between the first coordination signal and the coordination signal in both the first and second data processing devices; determining the shared key based on the first coordination signal by correcting the first coordination signal for the difference between the first coordination signal and the coordination signal in the first data processing device, and determining the coordination signal as the shared key in the second data processing device.
[0017] The method may further include: determining the first coordination signal as a shared key in the first data processing device, and determining the shared key based on the coordination signal by correcting the coordination signal for the difference between the first coordination signal and the coordination signal in the second data processing device.
[0018] The first parity check data may include a first parity bit of a first data block of the first coordination signal, and the second parity check data may include a second parity bit of a second data block of the coordination signal. Alternatively, the first parity check data may include a first parity bit of the first coordination signal, and the second parity check data may include a second parity bit of the coordination signal.
[0019] A first checksum can be determined by multiplying one of a plurality of check matrices by a first portion of a first coordination signal. A second checksum can be determined by multiplying one of a plurality of check matrices by a second portion of a second coordination signal. Check matrix information indicating at least one of the plurality of check matrices can be determined in a first or second data processing device. Check matrix information can be transmitted without encryption. Each of the plurality of check matrices, the first checksum, and / or the second checksum can be a binary value.
[0020] Correcting the first coordination signal and / or the coordination signal may include locating the erroneous bits. The erroneous bits can be determined using an error vector. The error vector can be determined based on one of multiple parity matrices and an error checksum. The error checksum can be determined by binary addition of the first and second checksums.
[0021] Errors can also be identified using a binary search. A binary search may involve iteratively dividing the first coordination signal and the second coordination signal into a first data block and a second data block, respectively, and determining and comparing the first parity value of the first data block and the second parity value of the second data block.
[0022] The method may further include at least one of the following: generating first error information based on the first coordination signal in the first data processing device, preferably encrypting the first error information into encrypted first error information using the initial key, and further preferably transmitting the first error information or the encrypted first error information to the second data processing device; generating second error information based on the coordination signal in the second data processing device, preferably encrypting the second error information into encrypted second error information using the initial key, and further preferably transmitting the second error information or the encrypted second error information to the first data processing device; determining error estimates of the first coordination signal and the coordination signal based on the first error information and the second error information in both the first and second data processing devices; and discarding erroneous portions of the first coordination signal and the coordination signal using the first error information and the second error information.
[0023] The first error message and the second error message may each include a first parity bit of a first coordination signal or a portion thereof, and a second parity bit of a second coordination signal or a portion thereof. The first error message and the second error message may be related to the first coordination signal and the second coordination signal.
[0024] The method may further include: determining hash data in the first data processing device, and encrypting the hash data into encrypted hash data using the initial key; and transmitting the encrypted hash data to the second data processing device. The method may also include: determining hash data in the second data processing device, and encrypting the hash data into encrypted hash data using the initial key; and transmitting the encrypted hash data to the first data processing device. The method may further include: determining an amplification key based on the shared key by applying a hashing method using the hash data in both the first and second data processing devices.
[0025] Hash data can indicate the random selection of a binary Toeplitz matrix.
[0026] At least one of the first parity check data, the second parity check data, and the hash data may include related data associated with at least one of the coordination signal, the first coordination signal, the shared key, and the amplification key.
[0027] The method may further include at least one of the following: generating first uncorrelated parity data in the first data processing device that is uncorrelated with at least one of the first coordination signal, the shared key, and the amplification key, and transmitting the first uncorrelated parity data to the second data processing device; and generating second uncorrelated parity data in the second data processing device that is uncorrelated with at least one of the coordination signal, the shared key, and the amplification key, and transmitting the second uncorrelated parity data to the first data processing device.
[0028] Alternatively, the first and second unrelated parity check data can also be encrypted and then transmitted.
[0029] The irrelevant data may include data block information indicating the segmentation of the first coordination signal and the second coordination signal into the first data block and the second data block.
[0030] The method may further include: providing a second initial key in the first data processing device and the second data processing device; and authenticating the first data processing device and the second data processing device using the second initial key.
[0031] The second initial key can be different from the initial key. Alternatively, the initial key and the second initial key can be the same. For example, a transmitted classical signal can be authenticated by appending a signature generated using the second initial key to each transmitted classical signal.
[0032] The shared key and / or the amplification key may be determined only in the first data processing device and the third data processing device. The method may further include: determining a plurality of additional quantum preparation parameters in the third data processing device; preparing a third quantum signal comprising a plurality of third quantum states based on a third original signal using the plurality of additional quantum preparation parameters in the third data processing device; and transmitting the third quantum signal from the third data processing device to the second data processing device.
[0033] Each of the plurality of quantum states can be a reduced state of one of the plurality of shared entangled quantum states between the first data processing device and the second data processing device.
[0034] Each of the multiple shared entangled quantum states can include entangled photon pairs.
[0035] The initial key can be provided using the RSA (Rivest-Shamir-Adleman) method or the Diffie-Hellman method. The initial key can also be distributed in different ways, such as via a trusted messenger. The initial key can be provided (distributed) in a first data processing device and a second data processing device. Alternatively, the initial key can be provided in a third data processing device.
[0036] Other classic messages can be encrypted using a shared key or an amplified key. Encryption can be performed using a one-time pad method or a symmetric key method, preferably the Advanced Encryption Standard (AES).
[0037] The length of the shared key can be equal to the length of the first parity data and / or the length of the second parity data, particularly equal to the length of the first parity check and / or the length of the second parity check. Alternatively, the length of the amplified key can be equal to the length of the first parity data and / or the length of the second parity data, particularly equal to the length of the first parity check and / or the length of the second parity check.
[0038] At least one of the following, preferably each, may be a classical signal: a first original signal, an original signal, a first encrypted signal, an encrypted signal, a first coordination signal, a coordination signal, a shared key, and an amplification key. At least one of the following, preferably each, may be composed of binary values, particularly one binary value per bit. The initial key and / or the second initial key may be provided only in the first and second data processing devices, and optionally in a third data processing device, but not in external data processing devices.
[0039] The embodiments described above related to the method for quantum key distribution can be correspondingly provided to a system for quantum key distribution. Attached Figure Description
[0040] In the following description, embodiments are illustrated by way of example and with reference to the accompanying drawings, in which:
[0041] Figure 1 A graphical representation of the arrangement of the system and external data processing equipment for quantum key distribution is shown.
[0042] Figure 2 A graphical representation of a method for quantum key distribution is shown.
[0043] Figure 3 A diagram comparing conventional quantum key distribution with methods used for quantum key distribution is shown.
[0044] Figure 4 The diagram illustrates a graphical representation of the simulated key rate as a function of the communication channel length for both conventional quantum key distribution and the proposed method. Detailed Implementation
[0045] Figure 1 A graphical representation of the arrangement of a system for quantum key distribution and an external data processing device 12 is shown. The system includes a first data processing device 10 (“Alice”) and a second data processing device 11 (“Bob”). The first data processing device 10 includes a first memory 10a, and the second data processing device 11 includes a second memory 11a.
[0046] The first data processing device 10 and the second data processing device 11 can exchange classical and / or quantum signals, for example, via a communication channel 13. The communication channel 13 may include a quantum channel configured to transmit quantum signals. For example, the communication channel 13 may include an optical fiber. The communication channel 13 may also be free space between the first data processing device 10 and the second data processing device 11. The communication channel 13 may also include a classical channel for transmitting classical signals. The quantum channel and the classical channel may share an optical fiber. Alternatively, the quantum channel and the classical channel may be separate.
[0047] The system may include multiple additional data processing devices, particularly a third data processing device (not shown) with a third memory. The third data processing device may be connected to communication channel 13. Additionally or alternatively, the third data processing device may exchange classical and / or quantum signals with the first data processing device 10 and / or the second data processing device 11 via another communication channel.
[0048] An external data processing device 12 (“Eve”) with external memory 12a is located outside the system and represents a potential eavesdropping device that may, for example, access communication channel 13 via connection 14. The external data processing device 12 may be positioned at communication channel 13 such that at least one or both of classical and / or quantum signals transmitted via communication channel 13 are received and / or retransmitted by the external data processing device 12. The external data processing device 12 may also access other communication channels. The external data processing device 12 may also be connected to multiple other external data processing devices, each of which can access communication channel 13, and / or each of which may be positioned closer to the first data processing device 10 or the second data processing device 11.
[0049] The first memory 10a, the second memory 11a, the third memory, and the external memory 12a each include a quantum memory configured to store quantum signals and a classical memory configured to store classical signals. The quantum memory can be provided using optical delay lines, controlled reversible non-uniform broadening (CRIB), the Duan-Lukin-Cirac-Zoller (DLCZ) scheme, echo-recovery with silence (ROSE), and / or hybrid photonic echo rephasing (HYPER).
[0050] The first data processing device, the second data processing device, the third data processing device, and the external data processing device (10, 11, 12) each include means for transmitting and / or receiving quantum states.
[0051] The first classical mutual information I(X:Y) of the first classical data X (e.g., in the first memory 10a of the first data processing device 10 or in the third memory of the third data processing device) and the second classical data Y (e.g., in the second memory 11a of the second data processing device 11) is given by the following formula.
[0052] I cl (X:Y)=H(X)-H(X|Y), (1)
[0053] Here, H(X) is the Shannon entropy of the first classical data X, and H(X|Y) is the Shannon entropy of the first classical data X given the second classical data Y.
[0054] The first data processing device 10 and the second data processing device 11 together include a shared quantum state ρ AB In this case, we can define classic mutual information I. cl Generalization of (A:B).
[0055] The first quantum mutual information I(A:B) of the first data A (e.g., in the first memory 10a) and the second data B (e.g., in the second memory 11a) is:
[0056] I(A:B)=S(A)-S(A|B), (2)
[0057] Each of the first data A and the second data B can include both quantum information and classical information. The first quantum mutual information is defined by (von Neumann) entropy S instead of Shannon entropy H. In the absence of quantum correlation, the first quantum mutual information I(A:B) and the first classical mutual information IB are... cl (A:B) matches.
[0058] Accessible information I for first data A and second data B acc (A:B) is
[0059]
[0060] It quantifies the maximum amount of classical correlation between the first data A and the second data B, which can be achieved in the second data processing device 11 by executing the quantum observable M = {M b The measurements described in the} description determine that each M b It is a nonnegative Hermitian operator, and where M is... b The sum of is the identity operator: ∑ b M b =1. When applied to a state When measuring subsystem B, in the shared quantum state The probability of measurement result b occurring is The trace of a matrix is denoted as Tr. The nonnegative Hermitian operator M... b Corresponding to measurement result b. Further, the quantum state reduced to B is represented as... The partial trace of B is represented as Tr B .
[0061] Quantum detuning Defined as the difference between all correlations and classical correlations. Quantum detuning D quantizes only the quantum correlation between the first data processing device 10 and the second data processing device 11:
[0062]
[0063] Accessible Information I acc This can violate the chain rule and therefore the principle of information causality. In particular, for certain quantum states, the following equation holds:
[0064] l ace (A,K:B,K)>l ace (A,K:B)+|K|。 (5)
[0065] Among them, the first accessible information I acc (A,K∶B,K) represents the accessible information when key k with key data K has been transmitted from the first data processing device 10 to the second data processing device 11, and the second accessible information I acc (A,K∶B) represents the accessible information before the key k has been transmitted to the second data processing device 11. Here, measuring with key data K can provide more information than measuring without using key data K and only obtaining key k subsequently.
[0066] Exemplary states in which equation (5) holds Represented as
[0067]
[0068] Among them, the exemplary states |a> and |a,k>, and the unitary matrix U k The identity matrices U0 and U1|a> and |a> are mutually unbiased. Their conjugate transpose is expressed as... A quantum state indexed by A (tensor product) (On the left) In the first data processing device 10, the B quantum state (tensor product) indexed by B is used. (on the right side) in the second data processing device 11. For an exemplary state The first accessible information is I acc (A, K : B, K) = m + 1, and the second accessible information is I. acc (A, K: B) = m / 2. Therefore, m / 2 of additional information is obtained using a key k that includes only a single bit. Quantum detuning D quantizes the advantages of quantum data locking.
[0069] The objective is to restrict external data processing device 12's access to shared data between first data processing device 10 and second data processing device 11. Generally, to minimize access to shared data, the second quantum mutual information I(A:E) between second data processing device 10 and external data processing device 12 is determined and minimized.
[0070] The second quantum mutual information I(A:E) can be determined by access indicator parameters determined in the second data processing device 11. Access indicator parameters may include, for example, the quantum bit error rate.
[0071] Subsequently, error correction and privacy amplification are performed in the first data processing device 10 and the second data processing device 11 to generate a key k with the following key rate.
[0072] r key ≈I(A:B)-I(A:E). (7)
[0073] Assuming the external data processing device 12 possesses virtually unlimited resources and the ability to perform any type of measurement, including collective measurements, then the second quantum mutual information I(A:E) has a Holevo capacity C χ Boundary:
[0074]
[0075] in, It is a set of third quantum states in the external data processing device 12, each third quantum state With third probability The value χ appears and is called the Holevo value. To prove the security of the method, one can consider the set of states that can lead to the determined access indicator parameters, and thereby, the second quantum mutual information I(A:E) can be restricted.
[0076] Figure 2 A graphical representation of the method used for quantum key distribution is shown.
[0077] The method allows for a reduction in the amount of data that can be determined in the external data processing device 12. Accordingly, the second quantum mutual information I(A:E) can be reduced to below C. χ The value is the boundary. Therefore, the external data processing device 12 does not need to determine classical information about the key k or other signals associated with it. This can be achieved by encrypting the post-processing information generated during post-processing and which can be determined by the external data processing device 12. As the second quantum mutual information I(A:E) decreases, the key rate r... key Increase (see equation (7)).
[0078] In the first step 21, an initial secret key is provided in the first data processing device 10 and the second data processing device 11. This can be achieved, for example, by using a known classical key distribution protocol or a quantum key distribution protocol, or a previous key from a previous execution of the method. Further, a second initial key is provided in the first data processing device 10 and the second data processing device 11 for mutual authentication.
[0079] In the second step 22, in the first memory 10a of the first data processing device 10, by using a probability distribution The random number generator generates multiple first quantum states. The first quantum signal. Therefore, it is possible to generate a probability distribution. The intermediate classical signal is obtained and stored in the classical memory of the first memory 10a, and the first quantum signal can be generated based on the intermediate classical signal. Probability distribution It can be a uniform probability distribution. Each first quantum state It can be encoded and correspond to a number of bits, such as one bit, of the (classical) first original signal. The first quantum signal is transmitted from the first data processing device 10 to the second data processing device 11 via communication channel 13.
[0080] If multiple first quantum states can be received in external data processing device 12 (via connection 14) Furthermore, if the external data processing device 12 is capable of performing a collective (measurement) attack, it will target multiple first quantum states. Each first quantum state and auxiliary (ancilla) in Perform unitary operation (and Hilbert spaces H corresponding to subsystems A and E respectively) A and H E This generates multiple third quantum states in the external memory 12a of the external data processing device 12. (corresponding to) After being further transmitted to the second data processing device 11, multiple (second) quantum states are generated in the second memory 11a of the second data processing device 11. (corresponding to) ).
[0081] In the third step 23, multiple quantum measurement parameters are determined, for example, using a random distribution in the second data processing device 11. Further, multiple second quantum states are measured using the multiple quantum measurement parameters in the second data processing device 11. This generates the classical (second) original signal. Each bit of the second original signal corresponds to one of a plurality of quantum measurement parameters and one of a plurality of second quantum states.
[0082] In the fourth step 24, basis reconciliation is performed using the communication channel 13 in the first data processing device 10 and the second data processing device 11.
[0083] In this embodiment, a (second) coordination signal is determined in the second data processing device (11) based on the second original signal and the measurement results, in such a way that if a corresponding result in the measurement results is uncertain, then (second) bits of the second original signal are discarded. Further, a (second) encrypted signal is generated in the second data processing device (11) using an initial key, and the encrypted signal is transmitted to the first data processing device (10). The second encrypted signal indicates the measurement result corresponding to the uncertain result. The second encrypted signal is then decoded in the first data processing device (10). Then, a first coordination signal is determined in the first data processing device (10) based on the first original signal, in such a way that if a corresponding result in the measurement results corresponds to an uncertain result, then (first) bits of the first original signal are discarded.
[0084] In another embodiment, a first encrypted signal indicating at least one of a plurality of quantum preparation parameters is generated using an initial key in the first data processing device (10), and the first encrypted signal is transmitted to the second data processing device (11). Conversely, a second encrypted signal indicating at least one of a plurality of quantum measurement parameters is generated using an initial key in the second data processing device (1), and the second encrypted signal is transmitted to the first data processing device (10).
[0085] Then, in the first data processing device (10), the first coordination signal is determined based on the first original signal and the second encrypted signal in such a way that if a corresponding quantum measurement parameter among the multiple quantum measurement parameters from the second encrypted signal does not match a corresponding quantum preparation parameter among the quantum preparation parameters, then one of the first bits of the first original signal is discarded.
[0086] Furthermore, in the second data processing device (11), a second coordination signal is determined based on the second original signal and multiple quantum measurement parameters in such a way that if a corresponding quantum measurement parameter among the multiple quantum measurement parameters does not match a corresponding quantum preparation parameter among the quantum preparation parameters, then one bit of the second original signal is discarded.
[0087] This type of encryption, which utilizes an initial key, is not used in known protocols.
[0088] In step 25, error estimates for the first and second coordination signals are determined. To this end, a first error message in the first coordination signal is generated in the first data processing device (10), optionally encrypted using an initial key, and transmitted to the second data processing device (11). Conversely, a second error message in the second coordination signal is generated in the second data processing device (11), optionally encrypted using an initial key, and transmitted to the first data processing device (10). Error estimates are then determined in both the first and second data processing devices (10 and 11) based on the first and second error messages. For example, the first and second error messages may each include a first parity bit of the first coordination signal or a portion thereof, and a second parity bit of the second coordination signal or a portion thereof. In this case, the first and second error messages are encrypted before transmission. Further, the error estimate is determined by comparing the first and second parity bits. Additionally or alternatively, the error estimate may also include visibility and / or decoy state statistics.
[0089] The first error message may further include a first subset of the first digits in the first coordination signal, and the second error message may include a second subset of the second digits in the second coordination signal. In this case, it is not necessary to encrypt the first and second error messages. Subsequently, the union of the first subset of the first digits and the second subset of the second digits is discarded from the first and second coordination signals.
[0090] If the error rate exceeds a threshold, the method is terminated. Otherwise, the method continues. The error estimation also provides an estimate of the second quantum mutual information I(A:E) or an estimate of the third quantum mutual information I(B:E). Erroneous portions of the first and second coordination signals can be discarded.
[0091] In step 26, error correction is performed. For this purpose, first parity data can be generated in the first data processing device (10) based on the first coordination signal, encrypted with an initial key, and transmitted to the second data processing device (11). Alternatively or additionally, second parity data can be generated in the second data processing device (11) based on the second coordination signal, encrypted with an initial key, and transmitted to the first data processing device (10).
[0092] Subsequently, the difference between the first coordination signal and the second coordination signal can be determined in the second data processing device (11) based on the first parity check data. Alternatively, the difference can be determined in the first data processing device (10).
[0093] Therefore, the shared key between the first data processing device (10) and the second data processing device (11) can be determined according to different embodiments.
[0094] According to one embodiment, in the first data processing device (10), a shared key is determined based on the first coordination signal by correcting the difference between the first coordination signal and the second coordination signal. In the second data processing device (11), the second coordination signal is determined as the shared key. It is worth noting that the shared key only needs to be the same in the first data processing device (10) and the second data processing device (11), and the specific value of the shared key is generally randomly determined. Here, the second coordination signal is determined as the master signal, and the first coordination signal is corrected (reverse coordination).
[0095] According to another embodiment, in the second data processing device (11), a shared key is determined based on the second coordination signal by correcting the difference between the first coordination signal and the second coordination signal. In the first data processing device (10), the first coordination signal is determined as the shared key. Here, the first coordination signal is determined as the master signal, and the second coordination signal is corrected (forward coordination).
[0096] The first parity data may include the first parity bit of the first data block of the first coordination signal, and the second parity data may include the second parity bit of the second data block of the second coordination signal (CASCADE method). On the other hand, data block information indicating the division of the first and second coordination signals into data blocks can be transmitted without encrypting the data block information.
[0097] Alternatively, the first parity check data may include a first parity checksum of the first coordination signal, and the second parity check data may include a second parity checksum of the second coordination signal (linear error correction code / linear block coding method). The first and second parity checksums can be determined by multiplying one of the plurality of parity check matrices respectively by (vectorized) data blocks of the first and second coordination signals. It is noteworthy that each parity check bit constitutes a parity check bit of a single-valued bit in the corresponding row of one of the plurality of parity check matrices. On the other hand, parity check matrix information indicating at least one of the plurality of parity check matrices can be transmitted without encrypting the parity check matrix information.
[0098] The amount of information leakage can be determined based on the first parity check data and / or the second parity check data, particularly based on multiple publicly disclosed parity bits, and / or based on the length of the first checksum and / or the second checksum. For increased information leakage, the portion of key information that can be determined in the external data processing device 12 may become larger.
[0099] The objective of step 6, 26, is to prevent the leakage of classical information related to the first and second coordination signals, and thus to prevent the leakage of the shared key. Prior to step 6, 26, a third probability may have already been provided in the external memory 12a of the external data processing device. The third quantum state If the external data processing device 12 includes collective attack methods, then the third probability It does not depend on being constructed as k = k1k2...k N Any shared key number k1, k2, ..., k N Therefore, with the shared key k = k1k2...k N The corresponding combination probability of each third quantum signal Having a product form
[0100]
[0101] For such a third quantum signal (e.g., a product quantum state) and the product probability distribution Quantum channel capacities are additive, and individual measurements provide the best results:
[0102]
[0103] Here, the left side represents all observables M for N quantum states. N (N times mutual information I) NThe right side represents the individual maximization of the individual observable M1 (first mutual information I1) of a single quantum state. Therefore, prior to step 26, the information about the shared key per bit is bounded by the first mutual information I1 corresponding to the individual measurement.
[0104] At step 26, without encrypting the first and second parity data, some shared key information may be leaked to the external data processing device 12. For the CASCADE method, this leakage may be due to the first and second parity bits of the data block to be transmitted. For the linear error-correcting code method, the leakage may be due to the first and / or second parity bits to be transmitted. Importantly, each leaked parity bit halves the number of possible bit combinations (codewords) for the shared key used in the first and second data processing devices 10 and 11. For example, for a three-bit string, a parity bit value of 1 means that the probabilities of bit strings 000, 011, 101, and 110 are all zero. Therefore, only four out of eight combinations remain, and each third quantum signal... Combination probability It was changed.
[0105] Without encrypting the first and second parity check data and performing error correction, the first data processing device 10 and the external data processing device 12 ultimately operate in a classical quantum channel state during encoding. Specifically, if the C bit has been leaked, the number of possible bit combinations for the shared key increases from 2... N Reduce to 2 N-C Therefore, the requirements of the quantum channel coding theorem are satisfied for both the first data processing device 10 and the external data processing device 12, since the first data processing device 10 has provided a set of codewords, while the external data processing device 12 needs to know this set of codewords to perform the collective measurement. The maximum mutual information for each bit of the collective measurement is provided by the Holevo value (see equation (8)), which is greater than the first mutual information I1 in equation (10).
[0106] Without performing error correction on the first and second parity data, it can be assumed that the first data processing device 10 and the external data processing device 12 are executing a quantum data locking protocol, thereby providing the external data processing device 12 with C bits of classical information. Because collective measurement is possible, this reduces the uncertainty in determining the shared key in the external data processing device 12 by more than C bits.
[0107] Conversely, by using the proposed method for quantum key distribution, a quantum data locking protocol can be provided without disclosing shared key information to the external data processing device 12, as discussed above. Using this method, no probability change information (which alters the combination probability) must be disclosed. Therefore, the combination probability It must have the product form shown in equation (9). This can be achieved by encrypting all classical signals associated with the shared key. Any key information associated with the shared key will alter the probability distribution. Otherwise, the additional mutual information I(K:C) between the shared key information and the leaked information would be zero.
[0108] In step 6, 26, when using the CASCADE method for error correction, the first parity bit and the second parity bit of the data block must be encrypted with the initial key. On the other hand, the data block information indicating the first and second coordination signals to the data block can be publicly transmitted because the data block information is independent of the shared key.
[0109] When using linear error-correcting codes, the checksum must be encrypted with the initial key, but the checksum information indicating at least one of the multiple checksum matrices can be publicly transmitted. In this method, all relevant data to be transmitted between the first and second data processing devices, especially post-processing data, must be encrypted with the initial key.
[0110] In step 7.27, to minimize information leakage, privacy amplification is applied to the shared key, resulting in an amplified key that is shorter than the shared key. Depending on the privacy amplification, the amount of further eavesdropper information associated with the amplified key can be determined to be close to zero.
[0111] To this end, hash data is determined in one of the first data processing device (10) and the second data processing device (11), the hash data is encrypted, and transmitted to the other of the first data processing device (10) and the second data processing device (11). Thus, the hash data is distributed between the first data processing device (10) and the second data processing device (11). Using the hash data as instruction data, a hashing method is applied to a shared key in both the first data processing device (10) and the second data processing device (11), thereby generating an amplification key in both the first data processing device (10) and the second data processing device (11). The hash data may, for example, indicate a random selection of a binary Toeplitz matrix, which is multiplied by the shared key to form a vector.
[0112] If the (same) shared key and preferably the (same) amplified key have been distributed in the first data processing device 10 and the second data processing device 11, the other (classical) message can be encrypted with the shared key or the amplified key and then transmitted from the first data processing device 10 to the second data processing device 11 and / or from the second data processing device 11 to the first data processing device 10.
[0113] Using the proposed method, the amount of information leakage during error correction becomes zero; however, the initial key is exhausted. If a one-time pad method is used to encrypt another message, the same amount of key information required for encryption is exhausted. If, alternatively, AES is used to encrypt another message, less key information than required for encryption is exhausted. Preferably, the shared key length or amplified key length is equal to the checksum length or parity data length.
[0114] Figure 3 A graph comparing a) conventional quantum key distribution without initial key encryption with b) the proposed one-time pad method is shown. Both conventional quantum key distribution and the proposed method use a second initial key for authentication. (The graph corresponds to...) Figure 3 In an embodiment of method b), the second initial key is also used as the initial key.
[0115] In conventional quantum key distribution, the amount of initial key data 30 is increased by the amount of conventional shared key data 31, which can be used to encrypt additional data. In the proposed method, in addition to the amount of initial key data 30, the amount of related key data 32 is used to encrypt related data, such as data associated with the shared key. However, here, the amount of key data that can be used to encrypt additional data not only increases the amount of conventional shared key data 31 but also further increases the key gain 33. The key gain 33 is due to a reduction in the second quantum mutual information I(A:E), i.e., a reduction in the amount of information leaked to the external data processing device 12. When using AES or another classical cryptographic method instead of one-time pad, the amount of related key data 32 can be smaller while retaining the key gain 33.
[0116] The proposed method can help legitimate users improve key rates. Potential information leakage to eavesdroppers is significantly reduced. Hardware modifications to the first data processing device 10 and the second data processing device 11 can be kept to a minimum if necessary. The method can be considered a quantum data locking protocol that locks the association between data in the first data processing device 10 (and the second data processing device 11) and data in an external data processing device 12. Appropriate quantum measurements cannot be performed in the external data processing device without additional data such as quantum measurement parameters. Additional data includes probability distribution variation data and correlation data. Security against eavesdroppers who theoretically have access to infinite quantum resources is challenged. An eavesdropper can obtain new information at a certain moment, such as the codewords used or other information related to the shared key or amplified key, and perform appropriate measurements. Therefore, the leakage of information from an initial 1-bit key can provide the eavesdropper with more than 1 bit of information.
[0117] However, importantly, the proposed method works well for practical applications where the eavesdropper's quantum memory has a time limit. Therefore, it only requires that no information related to the shared key or amplified key is leaked during the storage time in the eavesdropper's quantum memory. If classical cryptographic methods such as AES are used for encryption with the initial key, it is assumed that classical encryption methods are sufficiently secure during storage.
[0118] The method can be used with B92 and BB84 protocols, and for protocols where the first and third data processing devices 10 and 11 transmit their respective quantum states to the second data processing device 11, such as measurement-device-independent quantum key distribution or two-field quantum key distribution. Additional protocols can also be used where the first and second data processing devices 10 and 11 are initially provided with a shared entangled state and / or where a shared CCQ state is generated between the first data processing device 10, the second data processing device 11, and a potentially eavesdropping external data processing device 12.
[0119] Class B92 Protocol
[0120] Another embodiment of the method is described below, in which the B92 class protocol is used. External data processing device 12 is configured to perform a beam splitting attack.
[0121] In the first step 21, an initial key is provided in the first data processing device 10 and the second data processing device 11. The initial key is also used for mutual authentication.
[0122] In the second step 22, a sample with an intensity of μ is prepared in the first data processing device 10. A =α 2A quantum signal consisting of two coherent states |±α> (with real value α)|±α> is transmitted to a second data processing device 11. The type of the prepared coherent state corresponds to one of the first bits of the first original signal. In particular, the j-th prepared coherent state is assigned to the j-th first bit of the first original signal. For example, the first coherent state |+α> may cause the corresponding bit of the first original signal to be equal to 0, while the second coherent state |-α> may cause the corresponding bit of the first original signal to be equal to 1. The shared quantum state is described as a classical quantum state.
[0123]
[0124] In a beam splitting attack scenario, the external data processing device 12 can simulate channel loss by transferring the coherent state |±α> portion to the external memory 12a. Channel loss is represented as intensity reduction. For the optical fiber, the attenuation coefficient is δ≈0.2dB / km, and the communication channel length is l. Therefore, the external data processing device 12 is provided with an external strength μ. E =μ A (1-10 -δl / 10 The external coherent state of ) and will have an intensity μ B =μ A 10 -δl / 10 The second coherent state |±α B The data is transmitted to the second data processing device 11. The overall shared quantum state among the first data processing device 10, the second data processing device 11, and the external data processing device 12 is given by the following equation.
[0125]
[0126] in And the external coherent state is |±α E >
[0127] In the third step 23, the second data processing device 11 uses an observable M including B92. B92 ={M0,M1,M ? The measurement parameters are used to measure the second coherent state |±α. B >, where the measurement operator
[0128]
[0129] Each corresponds to one of the measurement results. In measuring the second coherent state |±α B When >, the first measurement operator M0 (corresponding to the first measurement result) and the second measurement operator M1 (corresponding to the second measurement result) generate definite signal information, while the third measurement operator M ?(Corresponding to the third measurement result) Indeterminate signal information is generated. Then, by measuring the second coherent state |±α B The determined measurement result obtained is assigned to one of the bits of the (second) original signal. Specifically, this will be achieved in the j-th iteration by measuring the second coherent state |±α. B The j-th determined measurement result in the obtained measurement results is assigned to the j-th bit of the second original signal.
[0130] In the fourth step 24, using conventional quantum key distribution, the uncertain bits in the second original signal corresponding to the third measurement result are publicly transmitted from the second data processing device 11 (e.g., via a public channel) to the first data processing device 10. In the proposed method, the uncertain bits are encrypted into an encrypted signal using an initial key before being transmitted from the second data processing device 11 to the first data processing device 10. Further, the uncertain bits are discarded in the second original signal, thereby generating a second coordination signal. After the encrypted signal is decrypted in the first data processing unit 10, the uncertain bits are also discarded in the first original signal, thereby generating a first coordination signal.
[0131] In step 25, error estimates for the first and second coordination signals are determined. First error information, including a first subset of the first digits in the first coordination signal, and second error information, including a second subset of the second digits in the second coordination signal, are determined in the first data processing device 10 and the second data processing device 11, respectively, transmitted to each other, and compared. Subsequently, the union of the first subset of the first digits and the second subset of the second digits is discarded from the first and second coordination signals. Since the first subset of the first digits and the second subset of the second digits are unrelated to the remaining digits, they can be transmitted without encrypting them using an initial key.
[0132] Additionally or alternatively, for example, the first error message and the second error message may each include a first parity bit of the first coordination signal or a portion thereof, and a second parity bit of the second coordination signal or a portion thereof. In this case, the first error message and the second error message are associated with the first coordination signal and the second coordination signal, and are therefore encrypted before transmission.
[0133] After step 25, if the external data processing device 12 has performed a beam splitting attack, the external memory 12a may include external coherent states |±α. E >
[0134] Transmitting parity bits can be beneficial for small error rates. For example, if the observed error rate is approximately 1%, transmitting 10 bits with 10 errors provides an inaccurate error estimate. It might be more beneficial to choose, for example, 1000 data blocks of length 10 and transmit parity bits for each of these 1000 blocks. The probability of parity bit mismatch is much higher, and using Bayes' theorem can provide a better error estimate. In this case, discarding bits would be disadvantageous, but the leakage of parity bits should at least be accounted for during subsequent privacy amplification.
[0135] In step 6.26, error correction is performed on the first and second coordination signals. For example, if the first coordination signal includes the first string s... A = (01100101), and the second coordination signal includes the second string s B = (01000101), then the digit 3 is incorrect. If the error estimate has been determined, then it can be determined that there is only one incorrect digit in this case. Therefore, only one incorrect digit needs to be located.
[0136] When using the CASCADE method, the first string s A The second string s B The data is randomly divided into a first data block and a second data block. For each of the first and second data blocks, a first parity bit and a second parity bit are determined, encrypted, and transmitted between the first data processing device 10 and the second data processing device 11. Erroneous bits are located using a binary search.
[0137] First string s A It has a parity check of 0, and the second string s B It has parity check 1. The first string s A The second string s B The first halves (0110) and (0100) have parity checks of 0 and 1 respectively. Since the first halves have different parity checks, the erroneous digits are located within the first halves. Further bisecting the first halves produces the first string s. A The second string s B The first quarter (01), (01) and the last quarter (10), (00). The first string s A The second string s B The first quarter (01) and (01) match and have the same parity check. Therefore, the erroneous digit is located in the first string s. A The second string s B The last quarter (10), (00), that is, at the digit 3.
[0138] In order to locate the erroneous digits, four first parity bits and second parity bits must be transmitted between the first data processing device 10 and the second data processing device 11.
[0139] When using linear block coding methods, the binary value parity-check matrix (which can be publicly transmitted) is, for example...
[0140]
[0141] Used to calculate the first checksum Second check First checksum z A It is encrypted and transmitted from the first data processing device 10 to the second data processing device 11. Alternatively, the second checksum z B The data is encrypted and transmitted from the second data processing device 11 to the first data processing device 10. Subsequently, an error checksum is determined between the first data processing device 10 and the second data processing device 11. Then, the error vector e is determined based on the following set of error checking equations:
[0142] He = z E (15)
[0143] Since the error check sub-equations are underdetermined, the error vector e can be determined, for example, via maximum likelihood or 1-norm minimization. Here, the error vector e is determined to be (00100000). T Therefore, the incorrect digit was located.
[0144] Under positive coordination, the first string s is considered... A That's correct, and it applies to the second string s. B Correction is performed, resulting in a shared key (01100101). In the case of reverse coordination, the second string s is considered... B That is correct, and for the first string s A The correction is performed to generate a shared key (01000101).
[0145] When the first parity data and the second parity data include data related to the first coordination signal and the second coordination signal (such as the first parity bit and the second parity bit when using the CASCADE method, or the first checksum and the second checksum when using linear block coding), the first parity data and the second parity data should be encrypted, for example, using a classic encryption method (such as AES or one-time pad, depending on the security requirements).
[0146] In traditional quantum key distribution, the second quantum mutual information I(A:E) leaked to the external data processing device 12 is expressed as the external coherent state |±α in the external memory 12a. E The Holevo value is the boundary, that is,
[0147]
[0148] Wherein, the binary Shannon entropy h2(x) = -x log x - (1-x)log(1-x).
[0149] In contrast, for the proposed method, the second quantum mutual information I(A:E) is bounded by a first-order capacity C1, which corresponds to individual measurements rather than collective measurements. External coherent states {|±α} E The best distinction corresponds to the error probability. Therefore, the second quantum mutual information I(A:E) is confined as
[0150]
[0151] In step 27, the shared key is shortened to an amplified key to minimize information leakage to the external data processing device 12. For this purpose, a random binary Toeplitz matrix T, for example,
[0152]
[0153] The Toeplitz matrix T is identified and publicly shared. It can be uniquely identified by its first row and its first column. Therefore, to share the Toeplitz matrix T, transmitting only the (encrypted) hash data of the first row and first column is sufficient. The amplification key is determined by multiplying the Toeplitz matrix T by the shared key, preferably left-multiplying. The row numbers of the Toeplitz matrix T depend on the estimate of the second quantum mutual information I (A:E): the greater the estimated information leakage, the shorter the amplification key.
[0154] Encrypting relevant data can be particularly useful in situations where it has already been encrypted using a one-time pad method, but some previously secure information about the amplification key has been publicly transmitted (unencrypted). If some bits of the amplification key are leaked, the combined probability... The key is altered, enabling the external data processing device 12 to perform collective measurements. Nevertheless, leaking the 1-bit initial key can provide the eavesdropping device with more than 1 bit of information. However, when the relevant data is encrypted, collective measurements are impossible, and the amplified key can still be distributed according to the proposed method.
[0155] Using the one-time pad method requires a considerable amount of key data, which reduces key gain. Therefore, encryption methods such as AES are likely preferred. It is worth noting that the encryption method must specify that, in the external coherent state |±α... E During the storage period, the encryption cannot be cracked by external data processing device 12.
[0156] Figure 4 The diagram illustrates a graphical representation of the simulated key rate *r* as a function of the communication channel length *l* for both conventional quantum key distribution and the proposed method. The channel loss is expressed as... For optical fiber, the attenuation coefficient is δ≈0.2dB / km.
[0157] Curve 40 represents the key rate of the proposed method for the B92-class protocol, curve 41 represents the key rate of the conventional B92-lke quantum key distribution method, and curve 42 represents the key rate ratio between the proposed method and conventional quantum key distribution. Curve 42 has a key rate value close to 1.75 for a large channel length l, corresponding to a key gain exceeding 70%. For curves 40 and 41, the probability p of the determination result of the second data processing device 11 is considered. conc :
[0158]
[0159] The intensity μ at point 10 of the first data processing device A Optimization was performed for each channel length. To simplify equation (19), it was assumed that the channel error rate q was zero. However, in any real-world system, the channel error rate q is positive. Therefore, encrypting related information may help improve the key rate r.
[0160] BB84 Protocol
[0161] Another embodiment of the method is described below, in which the BB84 protocol is used. Steps 21 to 27 are performed corresponding to the B92 class protocol embodiment. The difference between steps 21 to 27 and the B92 class protocol embodiment is as follows. Unlike the B92 class protocol, the single-photon BB84 protocol does not have a simple attack type like beam splitting attacks.
[0162] In the second step 22, the first photon quantum state is...
[0163]
[0164] Data is transmitted from the first data processing device 10 to the second data processing device 11. The first photon quantum state can correspond to photons with horizontal polarization, vertical polarization, diagonal polarization, and anti-diagonal polarization, respectively. Two measurement bases, + and ×, are used: HV (horizontal / vertical) basis + and AD (anti-diagonal / diagonal) basis ×. The shared quantum state of the digits is described as the classical quantum state of the photon.
[0165]
[0166] In a collective attack scenario, an auxiliary photon quantum state is attached to each photon's classical quantum state, and a unitary operation is performed by the external data processing device 12 to entangle the resulting state. The overall shared state among the first data processing device 10, the second data processing device 11, and the external data processing device 12 is given by the following equation.
[0167]
[0168] In the third step 23, the second photon quantum state is measured using the BB84 observable M in the second data processing device 11, wherein the measurement operator is...
[0169]
[0170] Subsequently, the external photon quantum state in the external data processing device 12 is represented as follows:
[0171]
[0172] The error probability of the second data processing device is q.
[0173] In the fourth step 24, the first data processing device 10 uses an initial key to generate a first encrypted signal indicating the quantum preparation parameters (i.e., the first quantum basis setting) for preparing the first photon quantum state, and transmits the first encrypted signal to the second data processing device 11. Conversely, the second data processing device 11 uses an initial key to generate a second encrypted signal indicating the quantum measurement parameters (i.e., the second quantum basis setting) for measuring the second photon quantum state, and transmits the second encrypted signal to the first data processing device 10.
[0174] Discarding the mismatched bits of the first and second original signals (the corresponding bits in the first quantum base setting and the corresponding bits in the second quantum base setting are mismatched in the mismatched bits) to generate the first and second coordinated signals respectively.
[0175] In order to distinguish between 0 and 1 without knowing the first or second quantum basis settings, non-orthogonal external photon quantum states must be distinguished in the external data processing device 12. and This distinguishes additional external photonic quantum states compared to providing a first or second quantum base setting in the third data processing device 12. and (or and This is even more difficult. Therefore, the first or second quantum base setting and the matching bits should be dedicated.
[0176] The features disclosed in this specification, drawings and / or claims may be raw materials for implementing various embodiments, either alone or in various combinations thereof.
Claims
1. A method for quantum key distribution, the method being in a system comprising a plurality of data processing devices, the method comprising: - providing an initial key in a first data processing device (10) and a second data processing device (11); - providing, in the second data processing device (11), a quantum signal comprising a plurality of quantum states; - determining, in the second data processing device (11), a plurality of quantum measurement parameters; - determining, in the second data processing device (11), an original signal by quantum measurement of the plurality of quantum states using the plurality of quantum measurement parameters; - generating, in the second data processing device (11), an encrypted signal indicative of at least one of the plurality of quantum measurement parameters using the initial key and transmitting the encrypted signal to the first data processing device (10); - determining, in at least one of the first data processing device (10) and the second data processing device (11), a reconciliation signal from the encrypted signal and the original signal; and - determining, in at least one of the first data processing device (10) and the second data processing device (11), a shared key from the reconciliation signal by correcting the reconciliation signal.
2. The method according to claim 1, further comprising at least one of: - determining, in the first data processing device (10), a plurality of quantum preparation parameters; - in the first data processing device (10), preparing a first quantum signal comprising a plurality of first quantum states from a first raw signal using the plurality of quantum preparation parameters, wherein, - the first original signal being a classical signal generated using a random number generator; - transmitting the first quantum signal from the first data processing device (10) to the second data processing device (11), thereby providing, in the second data processing device (11), the quantum signal comprising the plurality of quantum states; - generating, in the first data processing device (10), a first encrypted signal indicative of at least one of the plurality of quantum preparation parameters using the initial key and transmitting the first encrypted signal to the second data processing device (11); - determining, in the second data processing device (11), the reconciliation signal from the original signal and the first encrypted signal; and - determining, in the first data processing device (10), a first reconciliation signal from the first original signal and the encrypted signal.
3. The method of claim 2, wherein, at least one of the plurality of quantum measurement parameters and / or at least one of the plurality of quantum preparation parameters comprises a quantum basis setting.
4. The method of claim 2 or 3, wherein, providing at least one of: - each of the digits of the original signal in the second data processing device (11) corresponds to one of the plurality of quantum measurement parameters and one of the plurality of quantum states; - determining, in the second data processing device (11), the coordinated signal from the raw signal and the first encrypted signal in such a way that one of the digits of the raw signal is discarded if a corresponding one of the quantum measurement parameters does not match a corresponding one of the quantum preparation parameters from the first encrypted signal; - each of the first digits of the first raw signal in the first data processing device (10) corresponds to one of the quantum preparation parameters and one of the first quantum states; and - determining, in the first data processing device (10), the first coordinated signal from the first raw signal and the encrypted signal in such a way that one of the first digits of the first raw signal is discarded if a corresponding one of the quantum measurement parameters from the encrypted signal does not match a corresponding one of the quantum preparation parameters.
5. The method according to claim 2 or 3, further comprising at least one of: - generating, in the first data processing device (10), first parity check data from the first coordinated signal, - encrypting, in the first data processing device (10), the first parity check data into encrypted first parity check data using the initial key and transmitting the encrypted first parity check data to the second data processing device (11); - generating, in the second data processing device (11), second parity check data from the coordinated signal, - encrypting, in the second data processing device (11), the second parity check data into encrypted second parity check data using the initial key and transmitting the encrypted second parity check data to the first data processing device (10); - using, in the first data processing device (10) and in the second data processing device (11), the first parity check data and the second parity check data to determine a difference of the first coordinated signal and the coordinated signal; and - determining, in the first data processing device (10), the shared key from the first coordinated signal by correcting the first coordinated signal for the difference of the first coordinated signal and the coordinated signal, and determining, in the second data processing device (11), the coordinated signal as the shared key.
6. The method according to claim 5, wherein: - the first parity check data comprises first parity check bits of a first data block of the first coordinated signal and the second parity check data comprises second parity check bits of a second data block of the coordinated signal; or - the first parity check data comprises a first syndrome of the first coordinated signal and the second parity check data comprises a second syndrome of the coordinated signal.
7. The method according to claim 2 or 3, further comprising at least one of: - - generating first error information in the first data processing device (10) from the first coordination signal, encrypting the first error information with the initial key into encrypted first error information, and transmitting the first error information or the encrypted first error information to the second data processing device (11); - generating second error information in the second data processing device (11) from the coordination signal, encrypting the second error information with the initial key into encrypted second error information, and transmitting the second error information or the encrypted second error information to the first data processing device (10); - determining in the first data processing device (10) and in the second data processing device (11) an error estimate of the first coordination signal and of the coordination signal from the first error information and from the second error information; and - discarding error parts of the first coordination signal and of the coordination signal using the first error information and the second error information.
8. The method according to claim 5, further comprising - determining in the first data processing device (10) and / or in the second data processing device (11) hash data and encrypting the hash data with the initial key into encrypted hash data; - transmitting the encrypted hash data to the second data processing device (11) and / or to the first data processing device (10); and - determining in the first data processing device (10) and in the second data processing device (11) an amplification key from the shared key by applying a hash method using the hash data.
9. The method of claim 8, wherein, At least one of the first parity data, the second parity data and the hash data comprises related data related to at least one of the coordination signal, the first coordination signal, the shared key and the amplification key.
10. The method according to claim 8, further comprising at least one of: - generating in the first data processing device (10) first unrelated parity data not related to at least one of the first coordination signal, the shared key and the amplification key, and transmitting the first unrelated parity data to the second data processing device (11); and - generating in the second data processing device (11) second unrelated parity data not related to at least one of the coordination signal, the shared key and the amplification key, and transmitting the second unrelated parity data to the first data processing device (10).
11. The method according to any one of claims 1 to 3, further comprising - providing a second initial key in the first data processing device (10) and in the second data processing device (11); and - authenticating the first data processing device (10) and the second data processing device (11) by the second initial key.
12. The method according to claim 11, further comprising - generating in the first data processing device (10) and in the second data processing device (11) a second error information from the second coordination signal, encrypting the second error information with the second initial key into encrypted second error information, and transmitting the second error information or the encrypted second error information to the first data processing device (10) and to the second data processing device (11).
13. The method according to claim 12, further comprising - determining in the first data processing device (10) and in the second data processing device (11) a second error estimate of the second coordination signal from the second error information.
14. The method according to claim 13, further comprising - discarding error parts of the second coordination signal using the second error information.
15. The method according to any one of claims 1 to 14, further comprising - providing a second shared key in the first data processing device (10) and in the second data processing device (11); and - determining in the first data processing device (10) and in the second data processing device (11) a second amplification key from the second shared key by applying a hash method using the hash data.
16. The method according to claim 15, further comprising - generating in the first data processing device (10) and in the second data processing device (11) a second error information from the second coordination signal, encrypting the second error information with the second initial key into encrypted second error information, and transmitting the second error information or the encrypted second error information to the first data processing device (10) and to the second data processing device (11).
17. The method according to claim 16, further comprising - determining in the first data processing device (10) and in the second data processing device (11) a second error estimate of the second coordination signal from the second error information.
18. The method according to claim 17, further comprising - discarding error parts of the second coordination signal using the second error information.
19. The method according to any one of claims 1 to 18, further comprising - providing a second shared key in the first data processing device (10) and in the second data processing device (11); and - determining in the first data processing device (10) and in the second data processing device (11) a second amplification key from the second shared key by applying a hash method using the hash data.
20. The method according to any one of claims 1 to 19, further comprising - providing a second shared key in the first data processing device (10) and in the second data processing device (11); and - determining in the first data processing device (10) and in the second data processing device (11) a second amplification key from the second shared key by applying a hash method using the hash data.
12. The method of claim 8, wherein, The shared key and / or the amplification key are determined only in the first data processing device (10) and a third data processing device, and wherein the method further comprises: - providing the initial key in the third data processing device; - determining a plurality of further quantum preparation parameters in the third data processing device; - preparing, in the third data processing device, a third quantum signal comprising a plurality of third quantum states from a third raw signal using the plurality of further quantum preparation parameters; - transmitting the third quantum signal from the third data processing device to the second data processing device (11).
13. The method of any one of claims 1-3, wherein, Each of the plurality of quantum states is a reduced state of one of a plurality of shared entangled quantum states between the first data processing device (10) and the second data processing device (11).
14. The method of any one of claims 1-3, wherein, The initial key is provided using a RSA method or a Diffie-Hellman method.
15. A system for quantum key distribution, the system comprising a plurality of data processing devices and being configured to perform: - providing an initial key in a first data processing device (10) and a second data processing device (11); - providing, in the second data processing device (11), a quantum signal comprising a plurality of quantum states; - determining a plurality of quantum measurement parameters in the second data processing device (11); - determining, in the second data processing device (11), a raw signal by quantum measurement of the plurality of quantum states using the plurality of quantum measurement parameters; - generating, in the second data processing device (11), an encrypted signal indicative of at least one of the plurality of quantum measurement parameters using the initial key and transmitting the encrypted signal to the first data processing device (10); - determining, in at least one of the first data processing device (10) and the second data processing device (11), a coordinated signal from the encrypted signal and the raw signal; and - determining, in at least one of the first data processing device (10) and the second data processing device (11), a shared key from the coordinated signal by correcting the coordinated signal.
Citation Information
Patent Citations
Device-independent quantum privacy query method based on EPR pair
CN107070651A
Continuous variable quantum key distribution data error correction method based on fountain codes
CN110233728A