Methods for performing authentication processes and for message exchange
By using quantum communication channels and quantum encryption protocols in a keyless system, the authentication challenge and response are encoded as qubit sequences, solving the problem of relay attacks, realizing secure detection and protection of the authentication process, and improving the security and reliability of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-02-03
- Publication Date
- 2026-04-03
AI Technical Summary
Existing keyless systems are vulnerable to relay attacks, leading to security issues in the authentication process. Furthermore, existing distance boundary protocols are ineffective in preventing relay attacks and suffer from processing delays.
The authentication challenge and response are transmitted through a quantum communication channel. By using quantum key distribution (QKD) and quantum secure direct communication (QSDC) protocols, the authentication challenge or response is encoded as a sequence of qubits, ensuring secure communication between the verification device and the response device, and detecting and preventing relay attacks.
Effectively detect and prevent relay attacks, ensure the security of the authentication process, prevent attackers from relaying authentication messages to unreachable entities, and improve the security and reliability of the system.
Smart Images

Figure CN115428394B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to a method and apparatus for performing an authentication process. This disclosure relates to a method and apparatus for transmitting and receiving messages. This disclosure also relates to a computer program and computer program product configured to, when run on a computer, execute methods for performing an authentication process and for transmitting and receiving messages. Background Technology
[0002] The authentication process is used in a variety of applications and many different industries. The authentication process typically involves a challenge sent from a first party (the verifier) to a second party (the responder). The responder generates a response based on the challenge and returns it to the verifier, who then verifies the response.
[0003] An example use case for the authentication process is in a so-called "keyless" system for cars or other vehicles. According to such a system, the car and its associated key communicate wirelessly so that when the car key is very close to the car, the car automatically unlocks after successful authentication, without the key holder pressing any buttons on the key. In an example keyless system, the car, acting as the authenticator, issues an authentication request containing a challenge. The car key, acting as the responder, calculates an authentication response based on the challenge and confidential credentials stored in the car key. The car key sends the authentication response to the car, which then unlocks the car upon successful verification. Such a keyless system can also be used to allow vehicles to enter restricted areas and for other access- or control-based use cases.
[0004] Keyless systems have proven vulnerable to so-called relay attacks, and several such attacks related to car theft and intrusion have been reported in recent years. In a relay attack, the attacker relays an authentication request from the authenticating entity (i.e., the car) to the responding entity (i.e., the car key), and then relays the subsequent authentication response from the responding entity back to the authenticating entity. The authenticating entity assumes the responding entity is very close, but in reality, due to the relaying of challenge and response messages, the responding entity may be quite far from the authenticating entity. In this way, for example, a signal can be transmitted between a car parked in a public garage and the associated key of that car held by the owner, who is far from the garage, resulting in the car unlocking even though the owner is not near the car.
[0005] Although described in the context of keyless systems for automobiles, the issue of relay attacks during the authentication process is not limited to this specific use case and hinders the development of such systems in other use cases. Furthermore, undetected message relay can also pose problems in various use cases and application scenarios, in addition to authentication process messages.
[0006] Detecting and thwarting relay attacks in keyless authentication systems depends on overcoming the inherent difficulty of measuring the proximity of communicating entities using radio waves. One potential solution is to use a distance-boundary protocol, which sets a maximum timeframe within which an authentication response must be received to be considered valid. This maximum timeframe is set based on the maximum permissible distance between communicating entities and the speed of light. While providing a means to ensure the proximity of communicating entities, distance-boundary protocols suffer from processing latency issues and therefore cannot offer a viable commercial solution to counter relay attack threats. Summary of the Invention
[0007] One object of this disclosure is to provide methods, apparatus, and computer-readable media that at least partially address one or more of the challenges described above. Another object of this disclosure is to provide methods, apparatus, and computer-readable media for collaboration to ensure that attempted relay attacks on authentication processes or message exchange processes can be detected and prevented from succeeding.
[0008] According to a first aspect of this disclosure, a method is provided for performing an authentication process between an authentication device and a response device, wherein security credentials are provided to the authentication device and the response device. The method is performed by the authentication device and includes: generating an authentication challenge and transmitting the authentication challenge to the response device. The method further includes: receiving an authentication response from the response device and verifying the authentication response. According to the method, at least one of the authentication challenge or the authentication response is encoded as a sequence of qubits and transmitted over a quantum communication channel between the authentication device and the response device.
[0009] According to another aspect of this disclosure, a method is provided for performing an authentication process between an authentication device and a response device, wherein security credentials are provided to both the authentication device and the response device. The method is performed by the response device and includes: receiving an authentication challenge from the authentication device, and generating an authentication response based on the authentication challenge. The method further includes: transmitting the authentication response to the authentication device. According to the method, at least one of the authentication challenge or the authentication response is encoded as a sequence of qubits and transmitted over a quantum communication channel between the authentication device and the response device.
[0010] According to another aspect of this disclosure, a method for transmitting a message to a second device, performed by a first device, is provided, wherein secure credentials are provided to both the first and second devices. The method includes: encoding the message into a sequence of qubits, and transmitting the encoded message to the second device over a quantum communication channel. The method further includes: receiving parameters and a first signature based on the parameters from the second device, and verifying the first signature. The method further includes: if the first signature verification is successful, generating a second signature based on the received parameters and a message symbol of the message, and sending the message symbol and the second signature to the second device.
[0011] According to another aspect of this disclosure, a method for receiving a message from a first device is provided, wherein the method is performed by a second device, and wherein security credentials are provided to both the first and second devices. The method includes: receiving an encoded message from the first device, wherein the encoded message comprises a sequence of qubits and is received on a quantum communication channel with the first device. The method further includes: estimating the message from the received qubit sequence, generating a first signature based on parameters, and sending the first signature and the parameters to the first device. The method further includes: receiving a message symbol and a second signature from the first device, the second signature being based on the parameters sent to the first device and based on the message symbol of the message. The method further includes: verifying the second signature, and if the verification of the second signature is successful, comparing the message estimated from the received qubit sequence with the received message symbol, and determining that the message has been correctly received if the error probability between the estimated message and the received message symbol is less than a threshold.
[0012] According to another aspect of this disclosure, a computer program and a computer program product are provided, which are configured to perform, when run on a computer, the methods described above for performing authentication processes and / or for transmitting and receiving messages.
[0013] According to another aspect of this disclosure, a verification device, a response device, a first device, and a second device are provided, the device including processing circuitry configured to perform methods as described above for performing an authentication process and / or for transmitting and receiving messages. Attached Figure Description
[0014] To better understand this disclosure, and to more clearly illustrate how this disclosure can be implemented, reference will now be made to the following figures by way of example, wherein:
[0015] Figure 1It is a flowchart illustrating the process steps in a method performed by a verification device for performing an authentication process between a verification device and a response device;
[0016] Figure 2 This is a flowchart illustrating the process steps in a method performed by a response device for performing an authentication process between a verification device and a response device;
[0017] Figure 3 This is a message flow diagram illustrating challenge-response based authentication, where authentication challenges are protected by relays;
[0018] Figure 4 This is a message flow diagram illustrating challenge-response based authentication, where the authentication response is protected by a relay.
[0019] Figure 5 It is a flowchart illustrating the process steps in a method for transmitting messages performed by a first device;
[0020] Figure 6 It is a flowchart illustrating the process steps in a method for receiving messages performed by a second device;
[0021] Figure 7 This is a flowchart illustrating process steps in another example of a method for transmitting messages performed by a first device;
[0022] Figure 8a and 8b A flowchart illustrating process steps in another example of a method for receiving messages performed by a second device is shown;
[0023] Figure 9 It is shown Figure 7 , 8a The message flow diagram for the implementation of the 8b method;
[0024] Figure 10a and 10b A flowchart illustrating process steps in another example of a method for transmitting messages performed by a first device is shown;
[0025] Figure 11a and 11b A flowchart illustrating process steps in another example of a method for receiving messages performed by a second device is shown;
[0026] Figure 12 It is shown Figure 10a , 10b Message flow diagrams for the implementation of methods 11a and 11b;
[0027] Figure 13This is a message flow diagram illustrating relay attack detection;
[0028] Figures 14 to 17 Examples of use cases of this disclosure are shown;
[0029] Figure 18 An example system with a heterodyne detector is shown;
[0030] Figure 19 This is a block diagram showing the functional units in the verification device;
[0031] Figure 20 This is a block diagram showing the functional units in the response device;
[0032] Figure 21 This is a block diagram showing the functional units in the first device; and
[0033] Figure 22 This is a block diagram showing the functional units in the second device. Detailed Implementation
[0034] Various aspects of this disclosure propose using quantum communication channels to transmit messages, which can be authentication challenges or authentication responses. When the sender and receiver are in close proximity, the methods according to examples of this disclosure enable the transmission of messages from the sender to the receiver such that at least one of the sender or receiver will detect any relaying of the message by an attacker. When transmitting messages from the sender to the receiver, the examples provided herein detect relay attacks by using photon-based communication instead of radio wave-based communication. An attacker attempting to relay the communication cannot measure enough information about each quantum state of the transmitted photons to correctly retransmit the message to the receiver, and is therefore forced to guess what will be detected at the receiver's location.
[0035] The examples disclosed herein can be implemented in a "keyless" system for vehicles. Both the authentication challenge (from vehicle to key) and the authentication response (from key to vehicle) can be encoded as qubits and transmitted using photon-based communication. Due to the properties of this photon-based communication, an attacker cannot relay the authentication challenge or response to an entity not near the sender of the challenge or response. The other of the authentication challenge or response can be transmitted using a non-quantum communication channel (e.g., radio-based communication).
[0036] This disclosure introduces several features of quantum cryptography, including quantum key distribution (QKD) protocols and quantum secure direct communication (QSDC) protocols. A brief discussion of these protocols is provided below to provide additional context for this disclosure.
[0037] Quantum key distribution (QKD) protocols are quantum cryptographic protocols used to establish a shared key between two parties by sending quantum states. QKD leverages specific properties of these quantum states to ensure its security. Several different methods exist for quantum key distribution using different quantum state properties. This disclosure is of particular interest to protocols that utilize the following quantum state property: measuring an unknown quantum state alters that state in some way (a consequence of quantum uncertainty). In QKD, this property is used to detect any eavesdropping on communications (which necessarily involves measurement). Discrete variable quantum key distribution (DV-QKD) protocols (often simply referred to as quantum key distribution (QKD)) use single photons as the information carrier and employ a single-photon detector at the receiver. Continuous variable quantum key distribution (CV-QKD) is a promising alternative to DV-QKD. Instead of using individual photons, CV-QKD uses several photons for each bit of information. In CV-QKD, information is encoded in the amplitude and phase of the light, and a homodyne or heterodyne detector is used at the receiver. The detector measures the quadrature of the electric fields of the light.
[0038] DV-QKD
[0039] Each single photon can be randomly encoded into one of two pairs using different polarizations, where each pair represents a polarization basis, and one pair is the conjugate of the other. States within a pair that commonly form a basis are orthogonal to each other. Examples of polarization bases are linear bases (0°, 90°) and diagonal bases (45°, 135°). An attacker cannot measure one of the states without interfering with the original states and therefore can only measure the polarization in one basis at a time. This property is used in DV-QKD, where the sender initially sends multiple photons to the receiver without revealing the randomly chosen basis used for each photon. The receiver notifies the sender on a common channel (which can be a radio-based or optical communication) that photons have been detected. Upon receiving this notification, the sender reveals the basis it used for the sent photons on the common channel. Before knowing the basis used by the sender, the receiver has already measured the state of each photon using its own (e.g., randomly chosen) basis for each photon. The receiver responds on the common channel by indicating which photon it used the correct measurement basis for. Then, the random bits of these photons are used as a shared secret between the sender and receiver.
[0040] CV-QKD
[0041] A system using CV-QKD comprises a predefined set of possible quantum states, where the states (amplitude and phase) are chosen such that their distributions overlap. The sender transmits a sequence of randomly selected states. Due to the overlapping distributions, an attacker attempting to relay or tamper with the message must guess which quantum state was transmitted for each state. Once the entire sequence has been received, the receiver discloses a random portion of its measurements to the sender over a public channel. The sender can then reveal which states were transmitted for the random portion disclosed by the receiver. Knowing the correct states, the receiver can now examine the amplitude and phase distributions of these states and calculate the variance of the distributions. If the variance is higher than expected, the receiver knows there is a problem with the transmission and must assume that the attacker tampered with the quantum states en route. Error correction is then used on the unrevealed portions of the quantum states to correct any errors in the transmission, and then privacy amplification is used to reduce the key length by the same amount as the amount leaked due to error correction. These steps are also performed over a public channel.
[0042] Quantum-Secure Direct Communication (QSDC) is a quantum cryptography protocol used to send confidential information directly through a quantum channel without the need for encryption keys or encrypted transmission. QSDC can be implemented using entangled photons. According to QSDC, the sender wants to send an M-bit message and generates a sequence of N = M + L entangled qubit pairs (e.g., entangled photon pairs), where L is an additional set of qubit pairs used for error detection. The sender randomly selects the positions of L qubit pairs from the sequence of N qubit pairs. The sender sends the first qubit of each pair to the receiver, who confirms receipt. The sender then selects a subset of the L qubit pairs (e.g., half of them) and measures their values using a randomly chosen basis (e.g., a photonic polarization basis). The sender informs the receiver of the selected qubit pair positions, and the receiver measures the selected subset of the L qubits using its randomly chosen basis. The receiver then provides the used basis and the measured values to the sender, who estimates the error rate based on the qubits measured using the same basis by both the sender and receiver. If the error rate is below a certain threshold, the sender assumes no attacker is interfering with the communication. The sender then encodes the message onto an unused second qubit and sends the second qubit of each of the N qubit pairs to the receiver. The receiver can now pair the qubits and perform a Bell measurement to extract the message. The receiver provides the measurement results for the remaining L qubit pairs for error rate estimation. If the error rate is below the certain threshold, the sender assumes no interference from an attacker. It will be understood that the attacker can never obtain the actual message (or a part of the message), but can only disrupt the communication.
[0043] Figure 1 and2 This is a flowchart illustrating process steps in methods 100 and 200 for performing an authentication process between an authentication device and a response device, wherein security credentials are provided to both the authentication device and the response device. The credentials can be suitable for enabling authenticated and integrity-protected transactions between the authentication device and the response device. The security credentials can be, for example, an asymmetric key pair or a shared symmetric key. Figure 1 Method 100 performed by the verification device is shown. Figure 2 Method 200, performed by a response device, is shown.
[0044] First refer to Figure 1 In the first step 110, the verification device generates an authentication challenge. Depending on the nature of the authentication process being performed, the authentication challenge can take any suitable form. In step 120, the verification device transmits the authentication challenge to the response device. In step 130, the verification device receives an authentication response from the response device, and in step 140, the verification device verifies the authentication response. As shown in steps 120A, 120B, 130A, and 130B, at least one of the authentication challenge or authentication response is encoded as a qubit sequence and transmitted over a quantum communication channel between the verification device and the response device, while the other of the authentication challenge or authentication response can be transmitted over a non-quantum communication channel between the verification device and the response device. These options are shown as Options A and Options B. According to Option A (steps 120A and 130A), the authentication challenge is encoded as a qubit sequence and transmitted over a quantum communication channel between the verification device and the response device, while the authentication response is transmitted over a non-quantum communication channel between the verification device and the response device. According to option B, the authentication challenge is transmitted on a non-quantum communication channel between the authentication device and the response device, while the authentication response is encoded as a sequence of qubits and transmitted on a quantum communication channel between the authentication device and the response device.
[0045] Figure 2 The corresponding method 200 executed by the responding device is shown. (Reference) Figure 2 In the first step 210, the responding device receives an authentication challenge from the verifying device. In step 220, the responding device generates an authentication response based on the authentication challenge, and in step 230, the responding device transmits the authentication response to the verifying device. As shown in steps 210A, 210B, 230A, and 230B, at least one of the authentication challenge or authentication response is encoded as a sequence of qubits and transmitted over a quantum communication channel between the verifying device and the responding device, while the other of the authentication challenge or authentication response may be transmitted over a non-quantum communication channel between the verifying device and the responding device. These options are shown as Options A and Options B, as described above.
[0046] The following is for reference. Figures 3 to 11bAdditional details are discussed on how authentication challenges and authentication responses of methods 100 and 200 can be transmitted and received according to different examples of this disclosure.
[0047] According to examples of methods 100 and 200, the sequence of qubits on which the authentication challenge or authentication response is encoded may comprise a sequence of quantum states of one or more photons. The quantum states of the one or more photons may comprise at least one of the following: photon polarization states (as used in DV-QKD), entangled states of photon pairs (as used in QSDC), or coherent states of (overlapping) light (as used in CV-QKD). Other physical implementations of qubits for encoding the authentication challenge or authentication response are also contemplated.
[0048] Methods 100 and 200 may further include: verifying, by one or both of the verification device or the response device, that at least one of the authentication challenge or authentication response, encoded as a qubit sequence and transmitted over a quantum communication channel between the verification device and the response device, has been relayed by a third party with a probability below a threshold. Different methods for implementing this verification are discussed below.
[0049] According to one use case for methods 100 and 200, at least one of the verification device or response device may be associated with a vehicle. The other of the verification device or response device may be associated with, for example, a key, an obstacle, a building, etc. The authentication process performed according to methods 100 and 200 may be used, for example, to allow at least one of the following: vehicle unlocking, vehicle control, vehicle entry into a restricted access area, etc. Examples of restricted access areas may include residential or commercial garages, residential complexes, gated communities, industrial, commercial, or government building complexes, etc.
[0050] Figure 3 and 4 These are message flow diagrams showing options A and B for methods 100 and 200, respectively.
[0051] Figure 3 This is a message flow diagram illustrating challenge-response based authentication according to examples of methods 100 and 200, where authentication challenges are relay-protected. The examples shown involve an authentication device or authenticator 104 and a response device or authenticator 103. The authentication device is equipped with an optical transmitter, while the response device is equipped with an optical receiver. In some examples, the authentication device and the response device may be associated with a vehicle and a vehicle key, or a building / obstacle and a vehicle that has managed to enter, respectively.
[0052] refer to Figure 3During the initial boot phase, both the verification device 104 and the response device 103 are provided with security credentials by the device manufacturer (steps S100 and S110). The verification device 104 then generates an authentication challenge and, using methods 100 and 200 described above, transmits an authentication request containing the authentication challenge from the verification device to the response device in a manner where relaying the authentication challenge is impossible. Details of these steps are described below and, for example, in... Figure 9 and 12 The following is shown. The responding device 103 only continues the authentication process if it successfully receives the authentication challenge in a manner that allows assumption that no authentication challenge relay has occurred. In step S401, the responding device calculates an authentication response to the challenge. The response can be, for example, a signature of the challenge, which is a signature based on a public key (if the security credential is an asymmetric key and the signature is created using a private portion of the key) or a Message Authentication Code (MAC) (if the security credential is a symmetric key). In step S500, the authentication response is returned to the authenticating party via any suitable communication channel (including, for example, radio wave-based communication, WiFi, etc.). In step S601, the authenticating device verifies the response, for example, by verifying the signature of the responding device. In step S700, the authenticating device can respond to the responding device with the authentication status (success / failure).
[0053] Figure 4 This is a message flow diagram illustrating challenge-response based authentication according to examples of methods 100 and 200, where the authentication response is relay-protected. In the example shown, the responding device is equipped with an optical transmitter, and the authenticating device is equipped with an optical receiver. This arrangement may be suitable if the authenticating device is more constrained than the responding device. In some examples, the authenticating device and the responding device may be associated with a vehicle and vehicle key, a building / obstacle and vehicle, etc., respectively.
[0054] refer to Figure 4 A similar initial boot phase is performed in steps S100 and S101, and the verification device 104 then generates an authentication challenge in step S200. Figure 4 In the example, in step S300, the authentication challenge is transmitted to the responding device via any suitable communication channel (including, for example, radio wave-based communication, WiFi, etc.). In step S400, the responding device calculates an authentication response to the challenge. The response may, for example, be a signature of the challenge. The authentication response is then transmitted from the responding device to the verifying device in a manner that makes it impossible to relay the authentication response, using methods 100 and 200 described above. Details of these steps are described below and, for example, in... Figure 9 and 12As shown in the diagram, the authentication device only continues the authentication process if it successfully receives the authentication response in a manner that allows it to assume no authentication response relay has occurred. In step S500, the authentication device verifies the response, for example, by verifying the signature of the responding device. In step S600, the authentication device can respond to the responding device with the authentication status (success / failure).
[0055] Figure 5 and 6 This is a flowchart illustrating process steps in a method for transmitting and receiving messages according to an example of this disclosure. Figure 5 and 6 The method can be used to transmit and receive messages (e.g., authentication challenge or authentication response) over a quantum communication channel in a manner that prevents message relay, as described above. Method 500 is performed by a first device (transmitting device), while method 600 is performed by a second device (receiving device). It will be understood that depending on whether the message transmitted between the devices is an authentication challenge (where the verifying device acts as the first device (transmitting device) and the responding device acts as the second device (receiving device)) or an authentication response (where the responding device acts as the first device (transmitting device) and the verifying device acts as the second device (receiving device)), the above reference... Figures 1 to 4 Either the verification device or the response device discussed can execute either method 500 or 600.
[0056] In some examples, at least one of the first or second devices may be associated with the vehicle, the message may be an authentication challenge or authentication response of the authentication process, and the authentication process may be used to allow at least one of the following: vehicle unlocking, vehicle control, and / or vehicle access to restricted areas (e.g., garages or residences, industrial, commercial, or government building complexes).
[0057] In other examples of this disclosure, the messages exchanged according to methods 500 and 600 may not be part of the authentication process, and may be any messages that an entity attempts to transmit in a manner that ensures proximity between the sender and receiver and prevents relay attacks.
[0058] First refer to Figure 5The figure illustrates the process steps in method 500, performed by a first device, for transmitting a message to a second device, wherein secure credentials are provided to both the first and second devices. In a first step 510, the first device encodes the message into a sequence of qubits, and then in step 520 transmits the encoded message to the second device over a quantum communication channel. The quantum communication channel can be, for example, free space, which is a channel suitable for transmitting a physical implementation of photon-based qubits. In step 530, the first device receives parameters and a first signature based on the parameters from the second device. In step 540, the first device verifies the first signature, for example, using a shared secure credential, and if the verification of the first signature is successful, the first device generates a second signature based on the received parameters and the message symbol. Depending on the type of secure credential, the first and second signatures can be in the form of a public-key-based signature (if the secure credential is an asymmetric key and the signature is created using a private portion of the key) or a Message Authentication Code (MAC) (if the secure credential is a symmetric key). In step 560, the first device sends the message symbol and the second signature to the second device. It will be understood that, in the specific examples of this disclosure, one or more steps of method 500 may be performed concurrently with another step, or may be performed in an order different from that described above. See below for reference. Figures 10a to 11b Let's discuss such examples in more detail.
[0059] Now for reference Figure 6 The figure illustrates a method 600 for receiving a message from a first device, wherein the method is performed by a second device, and wherein secure credentials are provided to both the first and second devices. Method 600 thus complements method 500. In a first step 610, the second device receives an encoded message from the first device, wherein the encoded message comprises a qubit sequence and is received on a quantum communication channel with the first device. In step 620, the second device estimates the message from the received qubit sequence. In step 630, the second device generates a first signature based on parameters, and in step 640, sends the first signature and parameters to the first device. In step 650, the second device receives a message symbol and a second signature from the first device, the second signature being based on the parameters sent to the first device and the message symbol. In step 660, the second device verifies the second signature, and if the verification of the second signature is successful, the second device compares the message estimated from the received qubit sequence with the received message symbol in step 670. If the error probability between the estimated message and the received message symbol is below a threshold (step 680), the second device determines that the message has been correctly received.
[0060] It will be understood that the exchange of the first and second signatures in methods 500 and 600 prevents the first device from being deceived into revealing the message symbols before the receiver has estimated the encoded message, or prevents an attacker from manipulating the message symbols to reflect the relayed encoded message. This will be referenced below. Figure 13 Let's discuss this in more detail.
[0061] Figure 7 , 8a Figures 8b and 8b are flowcharts illustrating one way in which the steps of methods 500 and 600 can be implemented and supplemented to achieve the above and additional functions. Figure 7 , 8a Methods 700 and 800 shown in 8b illustrate implementations of methods 500 and 600 using qubit implementations similar to those employed in DV-QKD or CV-QKD. Figures 10a to 11b Different implementations of methods 500 and 600 using entanglement-based protocols similar to those employed in QSDC are shown. It will be understood that in all these implementations, and compared to the protocols used for DV-QKD, CV-QVD, and QSDC, the message itself is used for error checking and for determining relay probabilities. This is possible because the method of this disclosure does not focus on the privacy of the exchanged messages, but rather on ensuring the proximity of the sender and receiver, thus detecting and preventing relay attacks. This contrasts, for example, with the QKD method, in which at least a portion of the exchanged messages forms the basis for generating a key for use by the sender and receiver, and therefore must remain private.
[0062] Figure 7 The illustration shows process steps in method 700, performed by a first device, for transmitting a message to a second device, wherein security credentials are provided to both the first and second devices. The message may be an authentication challenge, an authentication response, or any other type of message.
[0063] refer to Figure 7 In the first step 710, the first device encodes the message into a sequence of qubits. In the example shown, the qubits comprise the quantum states of one or more photons. As shown in step 710a, the quantum states of one or more photons may include at least one of non-orthogonal photonic polarization states or coherent states (which may overlap). In other examples (in... Figures 10a to 11b (As shown in the figure), the quantum state of one or more photons can include the entangled state of a photon pair.
[0064] In step 715, the first device can detect the position of the second device, and in step 720, the first device sends an encoded message to the second device over the quantum communication channel. If the first device has detected the position of the second device, then in step 720a, the first device can direct the transmission of the encoded message to the detected position of the second device. In some examples, position detection may be best suited for implementations that use photonic polarization states to encode the message. In such implementations, directing the transmission of the encoded message to the detected position of the second device may include, for example, using a laser beam with a rotating mirror, collimating the beam in the direction of the detected position.
[0065] In other examples, the first device may transmit an encoded message over an area where the second device is predicted to be present, as shown in step 720a. This action may be best suited for implementations that encode messages using coherent states of light. In such an implementation, transmitting an encoded message over an area where the second device is predicted to be present may include illuminating an area around the first device with a distribution of photons that form coherent states.
[0066] In step 730, the first device receives parameters and a first signature based on the parameters from the second device. The parameters may be, for example, a random number or pseudo-random number generated by the second device. As shown in step 730, the parameters and the first signature are received over a non-quantum communication channel. Examples of non-quantum communication channels can include any communication channel and protocol, such as radio-based (including 2G, 3G, 4G, Bluetooth, WiFi, or other proprietary protocols), Ethernet, fiber optic, wired telephone, etc.
[0067] In step 740, the first device verifies the first signature, for example, using shared security credentials. If verification of the first signature fails, the first device terminates the method. If verification of the first signature succeeds, the first device generates a second signature in step 750 based on the received parameters and the message symbol of the message. The first device then sends the message symbol and the second signature to the second device in step 760. As shown in step 760, the message symbol and the second signature are sent on a non-quantum communication channel, which can be the same non-quantum communication channel used to receive the parameters and the first signature from the second device.
[0068] As shown in 760a, the message symbol of a message includes at least one of the message value and information about how that value is encoded into qubits. The information about how the value is encoded into qubits can vary depending on the physical implementation of the qubits, but may include, for example, at least one of the following: a polarization basis used with the message value to generate a photonic polarization state, or a coherent state used to encode the message value. As described above, the polarization basis used to generate a photonic polarization state comprises a pair of states, wherein the two states within a pair are orthogonal to each other, and wherein the pair is one of two pairs of states that can be used by a second device, each pair being the conjugate of the other pair. Linear basis, diagonal basis, and circular basis are examples of state pairs forming a polarization basis.
[0069] Figure 8a and 8b A method 800 for receiving messages from a first device is shown, the method being performed by a second device, wherein security credentials are provided to both the first and second devices. Method 800 is a supplement to method 700 described above. (See reference...) Figure 8a In the first step 810, the second device receives an encoded message from the first device, wherein the encoded message includes a sequence of qubits and is received on a quantum communication channel with the first device. As shown in step 810, a qubit includes a quantum state of one or more photons, and at least one of a photonic polarization state or a coherent state (which may be overlapping) of light. In other examples (in... Figures 10a to 11b (As shown in the figure), the quantum state of one or more photons can include the entangled state of a photon pair.
[0070] In step 820, the second device estimates the message from the received qubit sequence. As shown in steps 820a and 820b, this may include at least one of the following:
[0071] a) For each received quantum state of one or more photons, select the polarization basis used for the measurement state, and use the selected basis to measure the received quantum state of one or more photons; or
[0072] b) For each received coherent state of light, measure at least one of the amplitude or phase of the light and estimate the quantum state corresponding to the measurement.
[0073] The following examples, using entanglement-based examples, illustrate other examples of estimating received messages.
[0074] In step 830, the second device generates a first signature based on parameters. These parameters can be, for example, a random or pseudo-random number generated by the second device, and the signature can be generated using the second device's security credentials. In step 840, the second device transmits the first signature and parameters to the first device over a non-quantum communication channel. (Refer to the above...) Figure 7An example of a non-quantum communication channel is discussed. In step 850, the second device receives a message symbol and a second signature from the first device, the second signature being based on the parameters sent to the first device and on the message symbol. The message symbol and signature can be received on the same non-quantum communication channel used to send the first signature and parameters.
[0075] As discussed above and shown in 850a, the message symbol of a message includes at least one of the message value and information about how that value is encoded into qubits. The information about how the value is encoded into qubits may vary depending on the physical implementation of the qubits, but may include, for example, at least one of the following: a polarization basis used with the message value to generate a photonic polarization state, or a coherent state used to encode the message value.
[0076] Now for reference Figure 8b In step 860, the second device verifies the second signature, for example, using a shared security credential. If verification of the second signature fails, the second device terminates the method without executing the remaining method steps. If verification of the second signature succeeds, the second device continues to compare the message estimated from the received qubit sequence (obtained in step 820) with the message value from the received message symbol using information received in the message symbol about how the value is encoded as qubits. For example, if the information about how the value is encoded as qubits includes a polarization basis used with the message value to generate a photon polarization state, comparing the message estimated from the received qubit sequence with the received message symbol may include comparing the estimated message with the received message value only for those message symbols for which the correct polarization basis was selected during estimation, as shown in 870a.
[0077] The second device then evaluates in step 880 whether the estimated error probability between the message and the received message symbol is higher than a threshold. If the probability is higher than the threshold, the second device determines in step 885 that potential third-party intervention has occurred during the transmission of the encoded message to the second device, and may terminate the method; if the message is part of an authentication process, the authentication process may be terminated. If the estimated error probability between the message and the received message symbol is equal to or lower than the threshold, the second device determines in step 890 that the message has been correctly received.
[0078] exist Figure 9 The message flow diagram illustrates example implementations of methods 500, 600, 700, and 800. Figure 9In the diagram, a first device is shown as sender 100, and a second device is shown as receiver 101. The sender wishes to send a message to the receiver. The sender and receiver are close enough to enable photon-based communication. Credentials are provided to both the sender and receiver for exchanging signed messages between them.
[0079] refer to Figure 9 In S200, the sender transmits the message to the receiver over a quantum channel (using a single photon with a randomly selected polarization, as in DV-QKD, or as a quantum state according to CV-QKD). After reception, the receiver estimates the value of the message. In the case of a single photon, the receiver randomly selects the polarization basis adopted by the measurement photon. In S300, the receiver generates a random number and signs the random number. In S301, the receiver transmits the random number and signature over a common channel (in... Figure 9 The random number is represented as a signature 1) and sent to the sender. This can be based on a radio channel, Wi-Fi, or other non-quantum communication channel. The sender verifies the signature on the random number to ensure that the random number was sent by the receiver. In S302, the sender sends the message symbol (in the case of using a single photon, including the message value and basis, or in the case of sending several photons per message symbol, including the quantum state) along with the signature calculated based on the received random number and message symbol (in the case of sending several photons per message symbol). Figure 9 The message symbol and signature (represented as signature 2) are sent together with the message symbol to the receiver. The message symbol and signature are transmitted over a common channel. In S400, the receiver verifies the information received in S302 by verifying the sender's signature. After successful verification, the receiver verifies that the estimated value of the message from S200 matches the value received from S302 with a sufficiently low error probability. In the case of using single photons, the receiver matches the value only for those detected photons whose randomly selected basis matches the basis used by the sender.
[0080] An attacker attempting to relay a message must estimate the message transmitted in S200. When using a single photon, the attacker randomly selects a polarization when measuring the state and then uses that polarization when relaying the message. Similarly, in a CV-QKD-based setting, due to overlapping states, the attacker must guess the quantum state and then use that state when relaying the message. As the sample size increases, correctly guessing becomes statistically unlikely, meaning that the attacker's interference becomes apparent when the receiver compares the estimated message with the received message symbol. The use of a signature ensures that the attacker cannot provide a message symbol to match the message relayed in step S200. (See below for reference.) Figure 13 The detection of relay attacks will be discussed in more detail.
[0081] Figure 10a , 10b11a and 11b are flowcharts illustrating another way in which the steps of methods 500 and 600 can be implemented and supplemented to achieve the above and additional functions. Figure 10a , 10b Methods 1000 and 1100 shown in 11a and 11b illustrate implementations of methods 500 and 600 that use entanglement-based qubit implementations similar to those employed in QSDC.
[0082] In methods 1000 and 1100 discussed below, due to the different properties of encoding as qubits, the steps of encoding and transmitting the message, as well as estimating the message, can be performed in a different order than described above. The exchange and verification of the first and second signatures still ensures that the sender is not prompted to reveal the message symbol until the receiver has received the encoded message as a qubit. However, utilizing the properties of quantum entanglement in qubit implementations provides different options for ensuring that the message is not relayed using methods 500 and 600. For example, in... Figure 10a and 10b In method 1000, the steps of encoding a message into a sequence of qubits and transmitting the encoded message to a second device over a quantum communication channel are implemented through the following steps:
[0083] a) Generate a sequence of entangled qubit pairs, where each qubit pair contains a photon.
[0084] b) Send one qubit from each pair to the second device, and retain the other qubit from each pair, and
[0085] c) Encode the message into the reserved qubits of the entangled photon pair.
[0086] After step c) has been performed, and without the sender sending the reserved qubits (the second qubit in each pair) to the receiver, the receiver can estimate the message by measuring the qubits sent to it in step b), thus utilizing the entangled state of the qubit pairs. The entangled nature of photon pairs means that encoding the message value onto one member of a pair will transform the state of the other member in that pair. Therefore, the message is transmitted via entangled pairs. Alternatively, the reserved qubits on which the message is encoded can also be sent to the receiver (on the quantum communication channel), allowing the receiver to match the entangled pairs and perform Bell measurements on the matched pairs to estimate the message. Error detection can be used to identify interference on the quantum channel used to send the qubits in step b) (before the message encoding) using additional entangled pairs. Then, using the message itself, additional error detection is performed by sending the message symbol along with the signature, allowing the receiver to verify the signature and compare the message symbol with the estimated message. See below for reference. Figure 10a , 10b11a and 11b will be used to explain the details of these steps.
[0087] Figure 10a and 10b The illustration shows process steps in method 1000, performed by a first device, for transmitting a message to a second device, wherein security credentials are provided to both the first and second devices. The message may be an authentication challenge, an authentication response, or any other type of message.
[0088] First refer to Figure 10a In the first step 1012, the first device generates a sequence of entangled qubit pairs, where each qubit in an entangled qubit pair comprises a photon. This sequence may include N pairs, where M = N + L. The M pairs may be used for message encoding, and the L pairs may be used for initial error checking. The L pairs may be located anywhere within the sequence of N pairs and are mixed with the M pairs for message encoding.
[0089] In step 1022, the first device sends one qubit from each of the N pairs to the second device over the quantum channel between the first and second devices, and retains the other qubit from each pair. In step 1030, the first device receives parameters and the following specifications from the second device over a non-quantum channel:
[0090] a) A second device is used to measure the basis of the qubits sent to the second device in the generated sequence; and
[0091] b) The value measured by the second device for the qubit being measured.
[0092] The first device also receives a first signature based on parameters and specifications. As shown in 1030a, the specifications received from the second device may also include the positions of qubits in the sequence that were sent to the second device and measured by the second device. In other examples, the specifications of the positions may be received separately in a dedicated message protected by integrity. These positions may be the positions of L qubits used for error checking.
[0093] In step 1040, the first device verifies the first signature, for example, using a shared credential. If verification fails, the first device terminates the method in step 1045. If verification succeeds, the first device continues in step 1072 to measure the reserved qubits at the aforementioned positions in the sequence, as measured by the second device, using a basis as indicated in the received specification. If the first device does not receive a specification of the positions of the qubits in the sequence sent to the second device that have been measured by the second device, the first device may first determine the positions of the qubits in the sequence sent to the second device that have been measured by the second device in step 1070. This determination may be performed based on at least one of parameters received from the second device and / or a credential shared between the first and second devices. The positions may be determined using functions known to both the first and second devices.
[0094] Now for reference Figure 10b In step 1024, the first device compares the result of the measurement in step 1072 with the measured value received in the specifications from the second device. If the error probability between the measurement result and the value received in the specifications from the second device is higher than a threshold (step 1076), the first device determines that potential intervention by a third party has occurred and can terminate the method without performing the remaining method steps.
[0095] If the error probability between the measured result and the value received in the specification from the second device is equal to or less than a threshold, the first device continues to encode the message onto the remaining reserved qubits of the entangled photon pair. The remaining reserved qubits include the reserved qubits from the M qubit pairs generated for message encoding.
[0096] In step 1024, the first device can transmit the reserved qubits to which the message is encoded over the quantum communication channel to the second device, thereby enabling the second device to perform a Bell measurement. Alternatively, the first device can omit this step, and the second device can estimate the message from the qubits sent to it in step 1022, thus relying on the properties of quantum entanglement, and use the second device to transmit the encoded message from the reserved qubits to the aforementioned qubits.
[0097] In step 1050, the first device generates a second signature based on the received parameters and the message symbol of the message. In step 1060, the first device sends the second signature and the message symbol of the message to the second device on a non-quantum channel. As shown in 1060a, the message symbol of the message includes at least one of the message value and information about how that value is encoded as qubits. If step 1024 is performed (sending the reserved qubits on the quantum channel), the first device can omit the information about how the value is encoded as qubits from the message symbol because the second device will use Bell measurements to estimate the message. If step 1024 is not performed, the first device includes information about how the value is encoded as qubits in the message symbol to assist the second device in estimating the message. The information about how the value is encoded as qubits can vary depending on the physical implementation of the qubits, but may include, for example, at least one of the following:
[0098] a) A polarization base, which is used in conjunction with a message value to generate the photonic polarization state of one of a pair of entangled photons;
[0099] b) Belki, which is used to encode message values.
[0100] Figure 11a and 11b A method 1100 for receiving a message from a first device is shown, the method being performed by a second device, wherein secure credentials are provided to both the first and second devices. Method 1100 is a supplement to method 1000 described above. As mentioned above, due to the use of different implementation qubits in method 1100, the steps of method 1100 can be performed in a slightly different order than the steps of methods 600 and 800 described above. For example, once the message has been encoded by the first device into the remaining qubits, and the remaining qubits have not been sent to the second device, the step of receiving the encoded message on the quantum channel can be divided into the step of receiving the first entangled photon in each pair of entangled photons and the step of estimating the message at the second device. In some examples, the receiving step may also include receiving the remaining qubits at the second device, provided that these qubits are sent so that the second device can perform a Bell measurement. Furthermore, the second device may perform measurements for error checking before estimating the received message. These steps are discussed in more detail below.
[0101] First refer to Figure 11aIn the first step 1112, the second device receives from the first device one qubit from each entangled qubit pair in the sequence of entangled qubit pairs generated by the first device, wherein the qubits of the entangled qubit pairs include photons. As shown in 1112, the first device reserves another qubit from each pair in the generated sequence of entangled qubit pairs so that, after one qubit from each entangled qubit pair in the sequence of entangled qubit pairs generated by the first device has been sent to the second device, the message is encoded onto the reserved qubit.
[0102] Then, in step 1192, the second device selects qubits for measurement from the qubits of the generated sequence received from the first device. The selected qubits may be qubits from L pairs of qubits used for error checking in a sequence of N qubit pairs generated by the first device. The second device may determine the position of the selected qubit based on parameters to be sent to the first device (e.g., random or pseudo-random numbers generated by the second device) and / or credentials shared between the first and second devices. The second device may use functions known to both the first and second devices to determine the position. For each selected qubit (as shown in 1194a), the second device then selects a basis for measuring the qubit in step 1194 and measures the qubit using the selected basis. The basis may be chosen randomly. In step 1130, the second device generates a first signature based on parameters (e.g., random numbers discussed above), the selected basis, and a specification of the value measured for the selected qubit in step 1194. As shown in step 1130a, the specification may also include the positions of qubits in the sequence that have been measured by the second device and sent to the second device. In other examples, the location may be sent to the first device in a dedicated message that may be protected by integrity.
[0103] In step 1140, the second device sends the specifications, parameters, and first signature to the first device over a non-quantum channel. The non-quantum channel can be a radio-based channel, WiFi, Bluetooth, etc.
[0104] As shown in 1114, in some examples, the second device can receive messages from the first device using reserved qubits encoded thereon by the first device. In other examples, the first device may omit sending the reserved qubits, and the message encoded on the reserved qubits is sent to the second device only through the entangled state of the qubit pairs generated by the first device.
[0105] Now for reference Figure 11bThe second device receives the message symbol and a second signature of the message on a non-quantum channel, the second signature being based on parameters sent to the first device and on the message symbol. The non-quantum channel can be the same channel on which the parameters, specifications, and the first signature are sent. As shown in 1150a, the message symbol of the message includes at least one of the message value and information about how that value is encoded as qubits. If step 1114 is performed (receiving the reserved qubits on the quantum channel), the information about how the value is encoded as qubits can be omitted from the message symbol, and the second device can use Bell measurements to estimate the message, as discussed below. If step 1114 is not performed, the information about how the value is encoded as qubits can be included in the message symbol to assist the second device in estimating the message, also discussed below. The information about how the value is encoded as qubits can vary depending on the physical implementation of the qubits, but can include, for example, at least one of the following:
[0106] a) A polarization base, which is used in conjunction with a message value to generate the photonic polarization state of one of a pair of entangled photons;
[0107] b) Belki, which is used to encode message values.
[0108] In step 1160, the second device verifies the second signature. If verification fails, the second device terminates the method. If verification succeeds, the second device estimates the message from the received qubit sequence in step 1122. For qubits received from the first device, this may include selecting a basis for measuring the qubits and measuring the qubits using the selected basis. Selecting a basis for measuring the qubits may include selecting a basis based on the message symbols of the message received from the first device (e.g., selecting a basis indicated in information about how message values are encoded into qubits).
[0109] In another example of receiving the reserved qubits from the first device in step 1114, estimating the message from the received qubit sequence may include: reassembling the entangled qubit pair by matching each of the received reserved qubits on which the message value is encoded with the corresponding qubit received from the first device; and performing a Bell measurement on the reassembled qubit pair, as shown in 1122a. The basis for the measurement may be included in the message symbol received from the first device.
[0110] In step 1170, the second device continues to compare the message estimated from the received qubit sequence (obtained in step 1122) using this information with the message value from the received message symbol (received in step 1150). The second device then evaluates in step 1180 whether the error probability between the estimated message and the received message symbol is higher than a threshold. If the probability is higher than the threshold, the second device determines in step 1185 that potential third-party intervention has occurred during the transmission of the encoded message to the second device, and can terminate the method, and if the message is part of an authentication process, can terminate the authentication process. If the error probability between the estimated message and the received message symbol is equal to or lower than the threshold, the second device determines in step 1190 that the message has been correctly received.
[0111] exist Figure 12 The message flow diagram illustrates example implementations of methods 500, 600, 1000, and 1100. Figure 12 In the diagram, a first device is shown as sender 100, and a second device is shown as receiver 101. The sender wishes to send a message to the receiver. The sender and receiver are close enough to enable light-based communication. Credentials are provided to both the sender and receiver for exchanging signed messages between them.
[0112] refer to Figure 12 In S200, the sender generates a sequence of N = M + L entangled photon pairs, where M is the message size and L is a set of additional photon pairs used for error detection. The positions of L photon pairs are randomly selected from the sequence of N photon pairs. The sender and receiver determine the positions of these pairs through message exchange or a shared function used to determine the positions, as discussed in more detail below. In S201, the sender sends the first photon from each pair to the receiver.
[0113] In S300, the receiver uses a randomly selected basis to measure L photon pairs. In S301, the receiver generates a random number and signs the random number along with information about the basis used and the measured value. Then, in S302, the receiver transmits the random number, the basis used, the measured value, and the signature (on a public channel) to the public channel. Figure 12 The signature is represented as 1) and sent to the sender. This can be a radio-based channel. In S303, the sender verifies the signature on the random number, the basis used, and the measured value to ensure that the information comes from the receiver. The sender then uses the basis used to measure the selected photon pair portion and estimates the error rate based on the received value. If the error rate is below a certain threshold, the sender assumes that no attacker is interfering with the communication and proceeds to the next step.
[0114] In S400, the sender encodes the message on a second photon that is not used in each pair. The sender signs the base, message symbol, and random number used to encode the message. The sender can then send the reserved photon (on which the message is encoded) to the receiver (not shown). Then in S500, the sender copies the message symbol and signature (in...) Figure 12 The signature 2) is sent to the receiver. If the reserved photons have not yet been sent, the sender also sends the basis used with the message symbol. In S501, the receiver verifies the signature to ensure that the information comes from the sender. The receiver decodes the message by measuring the first photon of each unused pair using the provided basis. In another example (not shown), the receiver reassembles the photon pairs and performs a Bell measurement to decode the message. The receiver compares the measured result with the received message value from the message symbol in S500. If the error rate is below a certain threshold, the sender assumes that no attacker is interfering with the communication and that message relay has not yet been performed.
[0115] A pseudo-random function (PRF) can be used to select the positions of L pairs out of N pairs. Such a PRF can be based on a hash function, and the seed can be chosen, for example, as a random value generated by the receiver, a fixed string (e.g., "pair selection"), and a concatenation of a shared secret between the sender and receiver. The sender and receiver can also introduce additional messages for transmitting the positions. These messages should be protected with integrity to make man-in-the-middle attacks impossible.
[0116] exist Figure 13 The text shows a diagram based on... Figure 9 The message flow is described in this example, where receiver 103 detects that a message from sender 100 has been relayed. In this example flow, one or more attackers use two devices: a first device "Attacker Device 1" 101 located near the sender and a second device "Attacker Device 2" 102 located near the receiver. (See reference...) Figure 13In S100, attacker device 1 101 detects light-based communication from the sender and guesses the base or coherent state used in order to measure the communication in S101. Attacker device 1 then relays the guessed message (including additional information) to attacker device 2 102 on a common channel (e.g., a radio channel) in S102. Attacker device 2 sends the guessed message to the receiver using light-based communication in S103. Attacker devices 1 and 2 are then configured to relay the remainder of the communication between the sender and the receiver. Because the information sent by receiver 103 in S201 is signed by the receiver, attackers (multiple) cannot deceive the sender into revealing the sent message symbol before the receiver has measured the transmitted symbol. This means that attackers (multiple) cannot delay relaying the messages in S102 and S103 to the receiver. Similarly, because the information in S203 is signed by the sender, multiple attackers cannot alter the message in S203 to match the relayed version of the message sent from S103 to the receiver. When comparing the estimated message with the message symbols received from the sender, the receiver will therefore receive an excessively high probability of error, as the attacker would have to guess the basis / coherence state in S101. The receiver can thus infer that a relay attack has occurred.
[0117] Figure 14 An example use case of this disclosure is illustrated, in which the method according to this disclosure is used to prevent relay attacks on vehicles using a keyless system. An authentication device (which may be a first device or a second device) is incorporated into vehicle 1402, and a response device (which may be a second device or a first device) is incorporated into vehicle key 1404. Each of the vehicle and the key is equipped with a radio transmitter and a receiver, and at least one of the vehicle and the key is equipped with an optical transmitter, while the other of the vehicle and the key is equipped with an optical receiver. Both the vehicle and the vehicle key are equipped with credentials, thereby enabling authenticated and integrity-protected transactions between them. Such credentials may be an asymmetric key pair or a shared symmetric key. Authentication requests or authentication responses may be sent between the vehicle and the key via optical communication of an appropriate wavelength, and the remainder of the authentication process may be performed on the radio communication link. The effect is to ensure that the vehicle is unlocked if and only if the key is within close range of the vehicle.
[0118] Figure 15 It shows the relationship with Figure 14 Similar use cases, where XR glasses 1504 replace Figure 14 The key 1404. The response device is integrated into the glasses 1504, and the authentication for unlocking the vehicle 1505 is as referenced above. Figure 14 The discussion continued as before.
[0119] Figure 16Another use case illustrating examples of this disclosure is shown, in which the method according to this disclosure is used to prevent relay attacks on vehicles entering a garage. An authentication device (which may be a first device or a second device) is incorporated into a garage door system 1602, and a response device (which may be a second device or a first device) is incorporated into a vehicle 1604. Each of the door system and the vehicle is equipped with a radio transmitter and a receiver, and at least one of the door system and the vehicle is equipped with an optical transmitter, while the other of the door system and the vehicle is equipped with an optical receiver. Both the door system and the vehicle are equipped with credentials, thereby enabling authenticated and integrity-protected transactions between them. Such credentials may be an asymmetric key pair or a shared symmetric key. Authentication requests or authentication responses may be sent between the door system and the vehicle via optical communication of an appropriate wavelength, and the remainder of the authentication process may be performed on a radio communication link. The effect is to ensure that the garage door is unlocked if and only if the vehicle is within close proximity to the garage door.
[0120] The following discussion focuses on transmitting and receiving devices that can be incorporated into or cooperate with verification and response devices.
[0121] Example transmitting devices suitable for use in conjunction with the methods discussed herein include optical transmitters with appropriate signal wavelengths and signal fields of view for the intended use case. These example transmitting devices also include receivers and transmitters, which may be based on the same technology but may also support another type of communication channel, such as RF. This other communication channel is used as a common communication channel.
[0122] In some examples, particularly those involving implementations using single-photon qubits, it may be desirable to be able to direct light toward a receiving device, and to determine the location of the receiving device using some form of location tracking technique. Techniques including Bluetooth angle of arrival, introduced in BT5.0, can be used, for example. In such examples, Bluetooth can also be used as a public communication channel. Once the location of the receiving device is determined, the light transmitter can collimate the beam in that direction to increase the probability of photons hitting the receiver. Collimation and directionality of light can be achieved in various ways, including, for example, using a laser beam with rotating mirrors.
[0123] In the continuous-variable implementation of the method disclosed herein, the single photons used in the discrete-variable implementation are changed to a photon distribution. Compared to CV-QKD, the method of this disclosure does not require maintaining the confidentiality of messages sent using light- or photon-based communication. Therefore, a larger area can be illuminated using this distribution, such as... Figure 17 As shown in the diagram above. Figure 13The discussed scenario involves an attack where, even if the attacker can receive light-based communication, once measured, this communication cannot be accurately relayed to the responding device, thus jeopardizing the authentication process and rendering the relay attack unsuccessful. This will be understood as similar to... Figure 17 The illumination system shown can be used in building entrance use cases, where a wide light signal is transmitted within a semicircle around the building door or entrance area.
[0124] Example receiving devices suitable for use with the methods according to this disclosure include optical receivers and receivers and transmitters for public communication channels. The optical receiver includes a sensor system for receiving incident photons and a system for changing polarization in front of the sensor system.
[0125] When considering the practicality of both continuous and discrete-variable implementations of the methods described herein, it becomes clear that continuous-variable implementations can achieve significantly higher bit rates than single-photon implementations. Another advantage of continuous-variable implementations is that the transmitter and receiver optics can be simpler, cheaper, and smaller compared to the corresponding single-photon components that require mechanical parts. This simplicity comes at the cost of more expensive post-processing, although this can be implemented on a standard CPU.
[0126] For applications where the light-based signal does not need to travel long distances and the signal strength at the receiver is high, such as in vehicle-to-key and garage-to-vehicle use cases, a typical filter-based receiver solution will be sufficient to filter out background interference from the message signal, although this solution will limit the range from transmitter to receiver. It will be understood that the filter mentioned here is a frequency bandpass filter (BPF) that allows a range of light wavelengths to pass through, rather than a polarization filter that allows all frequencies but aligns the polarization of the wave.
[0127] In applications with very low signal strength, continuous-variable implementations can be used with optical homodyne detectors or optical heterodyne detectors because these techniques allow for extremely narrow-band frequency detection, far superior to any available color filter. This is useful for filtering out any background light and is widely used, for example, in LIDAR systems where there is significant background light that may interfere with the signal.
[0128] Homodyne and heterodyne receivers are so-called coherent detection receivers, and they apply light to the received signal as part of the detection process to read very low signal inputs. In homodyne detection, the signal is demodulated directly in baseband. The detector requires a local oscillator whose frequency and phase are matched to the carrier signal. Information can be transmitted via amplitude, phase, or frequency modulation. In heterodyne detection systems, a local oscillator whose frequency or phase is matched to the signal is not required. Information can also be transmitted via amplitude, phase, or frequency modulation.
[0129] Figure 18An example system with a heterodyne detector is shown. Laser 1802 represents the incident light signal, for example, from a car sending an authentication request to a key over a quantum channel. Inside the key, the laser signal is received and combined with light from a local optical oscillator 1804. The combined optical detection signal passes through a bandpass filter 1806 and then proceeds in parallel through a delay 1808 and carrier recovery 1810. The signals are summed 1812 and then finally passed through a low-pass filter 1814. The signal is then transmitted to baseband.
[0130] Figures 1 to 11b The foregoing discussion illustrates different ways in which the methods disclosed herein for message exchange and authentication can be implemented. As described above, methods 100 and 200 are performed by an authentication device and a response device, respectively; methods 500, 700, and 1000 are performed by a first device (which may be either an authentication device or a response device); and methods 600, 800, and 1100 are performed by a second device (which may also be either an authentication device or a response device). This disclosure provides an authentication device, a response device, a first device, and a second device adapted to perform any or all of the steps of the methods described above.
[0131] Figure 19 This is a block diagram illustrating a verification device 1900, which can, for example, implement methods 100, 500, 600, 700, 800, 1000, and / or 1100 according to examples of this disclosure after receiving appropriate instructions from a computer program 1950. Reference Figure 19 The verification device 1900 includes processing circuitry 1910. The processing circuitry may include a processor 1902, a memory 1904, and an interface 1906. The processing circuitry 1910 is operable to perform the above-mentioned references. Figure 1 , 5 The methods discussed in 6, 7, 8a, 8b, 10a, 10b, 11a, and 11b include some or all of the steps of methods 100, 500, 600, 700, 800, 1000, and / or 1100. Specifically, refer to... Figure 1In method 100, processor 1902 can be configured to generate authentication challenges and verify subsequent authentication responses. Interface 1906 can be configured to transmit authentication challenges to a response device and receive authentication responses from the response device, wherein at least one of the authentication challenges or authentication responses is encoded as a sequence of qubits and transmitted over a quantum communication channel between the verification device and the response device. Memory 1904 may contain instructions executable by the remainder of processing circuitry 1910 to enable verification device 1900 to perform some or all of the steps of methods 100, 500, 600, 700, 800, 1000, and / or 1100, including, for example, generating authentication challenges by the processor and verifying subsequent authentication responses by the processor. The instructions may also include instructions for executing one or more telecommunications and / or data communication protocols, which may be implemented, for example, by interface 1906 when transmitting authentication challenges and receiving authentication responses. The instructions may be stored in the form of a computer program 1950.
[0132] Figure 20 This is a block diagram illustrating a response device 2000, which may, for example, implement methods 200, 500, 600, 700, 800, 1000, and / or 1100 according to examples of this disclosure upon receiving appropriate instructions from a computer program 2050. Reference Figure 20 The response device 2000 includes processing circuitry 2010. The processing circuitry may include a processor 2002, a memory 2004, and an interface 2006. The processing circuitry 2010 is operable to perform the above-mentioned references. Figure 2 , 5 The methods discussed in 6, 7, 8a, 8b, 10a, 10b, 11a, and 11b include some or all of the steps of methods 200, 500, 600, 700, 800, 1000, and / or 1100. Specifically, refer to... Figure 2 Method 200, interface 2006 can be configured to receive an authentication challenge from an authentication device and transmit an authentication response to the authentication device, wherein at least one of the authentication challenge or authentication response is encoded as a sequence of qubits and transmitted over a quantum communication channel between the authentication device and the response device. Processor 2002 can be configured to generate an authentication response based on the authentication challenge. Memory 2004 may contain instructions executable by the remainder of processing circuitry 2010 to enable response device 2000 to perform some or all of the steps of methods 200, 500, 600, 700, 800, 1000, and / or 1100, including, for example, generating an authentication response by processor 2002 based on the authentication challenge. The instructions may also include instructions for executing one or more telecommunications and / or data communication protocols, which may be implemented, for example, by interface 2006 when receiving authentication challenges and transmitting authentication responses. The instructions may be stored in the form of computer program 2050.
[0133] Figure 21 This is a block diagram illustrating a first device 2100, which can, for example, implement methods 100, 200, 500, 700, and / or 1000 according to examples of this disclosure upon receiving appropriate instructions from a computer program 2150. Reference Figure 21 The first device 2100 includes processing circuitry 2110. The processing circuitry may include a processor 2102, a memory 2104, and an interface 2106. The processing circuitry 2110 is operable to perform the above-mentioned references. Figure 1 , 2 Methods 100, 200, 500, 700, and / or 1000, discussed in 5, 7, 10a, and 10b, may include some or all of these steps. Specifically, refer to... Figure 5 In method 500, processor 2102 can be configured to encode a message into a sequence of qubits, verify a first signature, and, if the first signature verification is successful, generate a second signature based on received parameters and the message symbol of the message. Interface 2106 can be configured to transmit the encoded message to a second device over a quantum communication channel, receive parameters and a first signature based on the parameters from the second device, and, if the first signature verification by processor 2102 is successful, send the message symbol and the second signature to the second device. Memory 2104 may contain instructions executable by the remainder of processing circuitry 2110 to enable first device 2100 to perform some or all of the steps of methods 100, 200, 500, 700, and / or 1000, including, for example, encoding a message into a sequence of qubits by processor 2102, verifying the first signature, and, if the first signature verification is successful, generating a second signature based on received parameters and the message symbol of the message. The instructions may also include instructions for performing one or more telecommunications and / or data communication protocols, which may be implemented, for example, by interface 2106 when transmitting an encoded message to the second device, receiving parameters and a first signature from the second device, and sending a message symbol and a second signature to the second device. The instructions may be stored in the form of computer program 2150.
[0134] Figure 22 This is a block diagram illustrating a second device 2200, which can, for example, implement methods 100, 200, 600, 800, and / or 1100 according to examples of this disclosure upon receiving appropriate instructions from a computer program 2250. Reference Figure 22 The second device 2200 includes processing circuitry 2210. The processing circuitry may include a processor 2202, a memory 2204, and an interface 2206. The processing circuitry 2210 is operable to perform the functions described above. Figure 1 , 2The methods discussed in 6, 8a, 8b, 11a, and 11b include some or all of the steps of methods 100, 200, 600, 800, and / or 1100. Specifically, refer to... Figure 6 Method 600, interface 2206 can be configured to receive an encoded message from a first device, wherein the encoded message includes a qubit sequence and is received on a quantum communication channel with the first device; send a first signature and parameters to the first device; and receive a message symbol and a second signature from the first device, the second signature being based on the parameters sent to the first device and based on the message symbol. Processor 2202 can be configured to estimate the encoded message from the received qubit sequence, generate the first signature based on the parameters, verify the second signature received from the first device, and, if the verification of the second signature is successful, compare the message estimated from the received qubit sequence with the received message symbol. Processor 2202 can also be configured to determine that the message has been correctly received if the error probability between the estimated message and the received message symbol is below a threshold. Memory 2204 may contain instructions executable by the remainder of processing circuitry 2210 to enable second device 2200 to perform some or all of the steps of methods 100, 200, 600, 800, and / or 1100, including, for example, estimating an encoded message from a received qubit sequence by processor 2202, generating a first signature based on parameters, verifying a second signature received from the first device, and, if the second signature verification is successful, comparing the message estimated from the received qubit sequence with a received message symbol, and determining that the message has been correctly received if the error probability between the estimated message and the received message symbol is below a threshold. The instructions may also include instructions for executing one or more telecommunications and / or data communication protocols, which may be implemented, for example, by interface 2206 when receiving an encoded message from the first device (where the encoded message includes a qubit sequence and is received on a qubit communication channel with the first device), sending the first signature and parameters to the first device, and receiving the message symbol and second signature from the first device (the second signature being based on the parameters sent to the first device and based on the message symbol). Instructions can be stored in the form of a computer program 2250.
[0135] In some examples, the processors 1902, 2002, 2102, and 2202 described above may include one or more microprocessors or microcontrollers and other digital hardware (which may include digital signal processors (DSPs), application-specific digital logic, etc.). Processors 1902, 2002, 2102, and 2202 may be implemented using any type of integrated circuit (e.g., application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), etc.). Memory 1904, 2004, 2104, and 2204 may include one or more types of memory suitable for the processor, such as read-only memory (ROM), random access memory, cache memory, flash memory devices, optical storage devices, solid-state drives, hard disk drives, etc.
[0136] Another example of a verification device may include multiple functional modules that can, for example, execute examples of methods 100, 500, 600, 700, 800, 1000, and / or 1100 according to examples of this disclosure, based on computer-readable instructions received from a computer program. It will be understood that modules can be functional modules and can be implemented in any suitable combination of hardware and / or software. Modules may include one or more processors and can be integrated to any extent. Such an example verification device may include: a generation module for generating authentication challenges; a transmission module for transmitting authentication challenges to a response device; a receiving module for receiving authentication responses from the response device; and a verification module for verifying the authentication response, wherein at least one of the authentication challenges or authentication responses is encoded as a sequence of qubits and transmitted over a quantum communication channel between the verification device and the response device.
[0137] Another example of a response device may include multiple functional modules that can, for example, execute examples of methods 200, 500, 600, 700, 800, 1000, and / or 1100 according to examples of this disclosure, based on computer-readable instructions received from a computer program. It will be understood that modules can be functional modules and can be implemented in any suitable combination of hardware and / or software. Modules may include one or more processors and can be integrated to any extent. Such an example response device may include: a receiving module for receiving an authentication challenge from a verification device; a generating module for generating an authentication response based on the authentication challenge; and a transmitting module for transmitting the authentication response to the verification device, wherein at least one of the authentication challenge or the authentication response is encoded as a sequence of qubits and transmitted over a quantum communication channel between the verification device and the response device.
[0138] Another example of the first device may include multiple functional modules that can, for example, execute examples of methods 100, 200, 500, 700, and / or 1000 according to the examples of this disclosure, based on computer-readable instructions received from a computer program. It will be understood that modules can be functional modules and can be implemented in any suitable combination of hardware and / or software. Modules may include one or more processors and can be integrated to any extent. Such an example first device may include: an encoding module for encoding a message into a sequence of qubits; a transmission module for transmitting the encoded message to a second device over a quantum communication channel; a receiving module for receiving parameters and a first signature based on the parameters from the second device; a verification module for verifying the first signature; and a generation module for generating a second signature based on the received parameters and the message symbol of the message if the first signature verification is successful. The transmission module may also be used to send the message symbol and the second signature to the second device.
[0139] Another example of a second device may include multiple functional modules that can, for example, execute examples of methods 100, 200, 600, 800, and / or 1100 according to examples of this disclosure, based on computer-readable instructions received from a computer program. It will be understood that modules can be functional modules and can be implemented in any suitable combination of hardware and / or software. Modules may include one or more processors and can be integrated to any extent. Such an example second device may include: a receiving module for receiving an encoded message from a first device, wherein the encoded message comprises a sequence of qubits and is received on a quantum communication channel with the first device; and an estimation module for estimating the message from the received sequence of qubits. The example second device may also include: a generating module for generating a first signature based on parameters; and a sending module for sending the first signature and parameters to the first device. The receiving module may also be used to receive a message symbol and a second signature from the first device, the second signature being based on the parameters sent to the first device and based on the message symbol of the message. The example second device may further include: a verification module for verifying a second signature; and a comparison module for comparing the message estimated from the received qubit sequence with the received message symbol if the second signature verification is successful. The example second device may also include: a determination module for determining that the message has been correctly received if the error probability between the estimated message and the received message symbol is below a threshold.
[0140] It will be understood that the examples disclosed herein can be virtualized so that the nodes described herein can be instantiated across one or more virtual nodes in a cloud environment, and the methods and processes described herein can be run in a cloud environment.
[0141] Therefore, aspects of this disclosure provide authentication methods and methods for transmitting and receiving messages, wherein relay attacks can be detected. These methods utilize quantum communication channels to transmit messages, which can be authentication challenges or authentication responses. Quantum communication channels support photon-based communication and can, for example, include free space. The methods of this disclosure utilize at least one quantum property of light to ensure that any interference by an attacker attempting to relay a message is obvious to at least one of the sender or receiver, thereby allowing the parties to take appropriate actions, such as discarding the message, retransmitting the message, terminating the authentication process, or refusing authentication.
[0142] The methods disclosed herein can be implemented in hardware or as a software module running on one or more processors. These methods can also be executed according to the instructions of a computer program, and this disclosure also provides a computer-readable medium on which a program for performing any of the methods described herein is stored. The computer program embodying this disclosure can be stored on a computer-readable medium, or it can take the form of, for example, a signal (e.g., a downloadable data signal provided from an Internet website), or it can take any other form.
[0143] It should be noted that the above examples are illustrative and not limiting of this disclosure, and those skilled in the art will be able to devise many alternative embodiments without departing from the scope of the appended claims. The word “comprising” does not exclude the presence of elements or steps other than those listed in the claims, and “a” or “an” does not exclude a plurality, and a single processor or another unit may perform the functions of the plurality of units listed in the claims. Any reference numerals in the claims should not be construed as limiting the scope of the claims.
Claims
1. A method for performing an authentication process between a verification device and a response device, wherein, Providing security credentials to the verification device and the response device, the method being performed by the verification device, and including: Generate authentication challenge; The authentication challenge is transmitted to the response device; Receive authentication response from the response device; and Verify the authentication response; In this embodiment, at least one of the authentication challenge or the authentication response is encoded as a sequence of qubits and transmitted on a quantum communication channel between the verification device and the response device, and in this embodiment, the other of the authentication challenge or the authentication response is transmitted on a non-quantum communication channel between the verification device and the response device. The qubit sequence includes at least one of the following: a non-orthogonal photon polarization state sequence; an entangled state sequence of photon pairs; and a coherent state sequence of light.
2. The method according to claim 1, further comprising: The probability that at least one of the authentication challenge or authentication response, which is encoded as a qubit sequence and transmitted over the quantum communication channel between the authentication device and the response device, has been relayed by a third party is below a threshold.
3. The method according to claim 1 or 2, wherein, The authentication challenge is encoded as a sequence of qubits and transmitted over a quantum communication channel between the verification device and the response device; Furthermore, transmitting the authentication challenge to the response device includes: The authentication challenge is encoded as a sequence of qubits; The encoded authentication challenge is transmitted to the response device over the quantum communication channel; Receive parameters and a first signature based on the parameters from the response device; Verify the first signature; and If the first signature is successfully verified, then: Based on the received parameters and the message symbols of the authentication challenge, a second signature is generated; and The authentication challenge message symbol and the second signature are sent to the response device.
4. The method according to claim 3, wherein, Receiving parameters and a first signature based on the parameters from the response device includes receiving the parameters and the first signature on a non-quantum communication channel.
5. The method according to claim 3, wherein, Sending the authentication challenge message symbol and the second signature to the responding device includes: sending the authentication challenge message symbol and the second signature on a non-quantum communication channel.
6. The method according to claim 3, further comprising: If the verification of the first signature fails, the authentication process is terminated without executing the remaining method steps.
7. The method according to claim 3, wherein, The message symbol for the authentication challenge includes at least one of the following: The value of the authentication challenge; and Information about how this value is encoded as a qubit.
8. The method according to claim 7, wherein, The information regarding how values are encoded as qubits includes at least one of the following: Used in conjunction with authentication challenge values to generate polarization bases for photonic polarization states; Used in conjunction with the authentication challenge value to generate the polarization basis of the photon polarization state of one of a pair of entangled photons; Belki, which is used to encode the authentication challenge value; or The coherent state is used to encode the authentication challenge value.
9. The method according to claim 3, wherein, Encoding the authentication challenge as a qubit sequence includes: encoding the authentication challenge as a sequence of photonic polarization states or a sequence of coherent states of light; and wherein transmitting the encoded authentication challenge to the response device over a quantum communication channel includes: sending the qubits on which the authentication challenge is encoded to the response device.
10. The method according to claim 3, wherein, Encoding the authentication challenge as a qubit sequence includes: encoding the authentication challenge as a sequence of entangled states of photon pairs; and wherein encoding the authentication challenge as a qubit sequence and transmitting the encoded authentication challenge to the response device over a quantum communication channel includes: Generate a sequence of entangled qubit pairs, wherein the qubits of the entangled qubit pairs include photons; Send one qubit from each pair to the responding device and retain the other qubit from each pair; and The authentication challenge is encoded into the reserved qubits of the entangled photon pair.
11. The method according to claim 10, wherein, Encoding the authentication challenge into a sequence of qubits and transmitting the encoded authentication challenge to the response device over a quantum communication channel further includes: The reserved qubits encoded thereon are sent to the response device.
12. The method according to claim 10 or 11, wherein, Encoding the authentication challenge into a qubit sequence and transmitting the encoded authentication challenge to the response device over a quantum communication channel includes: Before receiving the parameters and the first signature based on the parameters from the response device, the entangled photon pair sequence is generated, and one qubit from each pair is sent to the response device; and After verifying the first signature, if the verification of the first signature is successful, the authentication challenge is encoded into the reserved qubits of the entangled photon pair.
13. The method of claim 12, further comprising receiving specifications from the response device for: The response device is used to measure the basis of the qubits sent to the response device in the generated sequence; and The value measured by the response device for the measured qubit.
14. The method of claim 13, further comprising receiving specifications from the response device for: The position of the qubit in the sequence that has been sent to the response device and measured by the response device.
15. The method according to claim 13 or 14, wherein, Receiving the specification from the response device includes: receiving the specification having the parameters and a first signature based on the parameters, wherein the first signature is also based on the specification.
16. The method of claim 14, further comprising: Using the basis indicated in the received specification and used by the response device, the reserved qubit at the position in the sequence as measured by the response device; The result of the measurement is compared with the measured value received in the specification from the response device; as well as If the error probability between the measured result and the value received in the specification from the response device is higher than a threshold, it is determined that potential third-party intervention has occurred.
17. The method of claim 16, further comprising: The position of the qubit in the sequence that has been sent to the response device and measured by the response device is determined based on at least one of the following: The parameters received from the response device; or Credentials shared between the verification device and the response device.
18. The method of claim 3, further comprising: Detect the position of the response device; Furthermore, transmitting the encoded authentication challenge to the response device over the quantum communication channel includes directing the transmission of the encoded authentication challenge to the detected location of the response device.
19. The method according to claim 3, wherein, Transmitting the encoded authentication challenge to the response device over a quantum communication channel includes transmitting the encoded authentication challenge over a region where the response device is predicted to exist.
20. The method according to claim 1 or 2, wherein, The authentication response is encoded as a sequence of qubits and transmitted over a quantum communication channel between the authentication device and the response device; And wherein receiving the authentication response from the response device includes: Receive an encoded authentication response from the response device, wherein the encoded authentication response comprises a sequence of qubits and is received on a quantum communication channel with the response device; The authentication response is estimated from the received sequence of qubits; Generate the first signature based on the parameters; Send the first signature and the parameters to the response device; The authentication response message symbol and a second signature are received from the response device, the second signature being based on the parameters sent to the response device and on the message symbol of the authentication response; Verify the second signature; and If the second signature is successfully verified, then: The authentication response estimated from the received qubit sequence is compared with the received authentication response message symbol; and If the estimated error probability between the authentication response and the received authentication response message symbol is below a threshold, then the authentication response is determined to have been correctly received.
21. The method of claim 20, further comprising: If the estimated error probability between the authentication response and the received authentication response message symbol is higher than a threshold, it is determined that potential third-party intervention has occurred during the transmission of the encoded authentication response to the verification device.
22. The method according to claim 20, wherein, Sending the first signature and the parameters to the response device includes: sending the first signature and the parameters over a non-quantum communication channel.
23. The method according to claim 20, wherein, Receiving the message symbol and the second signature of the authentication response from the response device includes receiving the message symbol and the second signature on a non-quantum communication channel.
24. The method of claim 20, further comprising: If the verification of the second signature fails, the authentication process is terminated without executing the remaining method steps.
25. The method according to claim 20, wherein, The message symbol of the authentication response includes at least one of the following: The value of the authentication response; and Information about how this value is encoded as a qubit.
26. The method of claim 20, wherein, Estimating the authentication response from the received qubit sequence includes at least one of the following: For each received quantum state of one or more photons, choose a basis for measuring the received quantum state, and use the chosen basis to measure the received quantum state of one or more photons; or For a sequence of qubits comprising a sequence of coherent states of light, for each received coherent state of light, at least one of the amplitude or phase of the light is measured, and the quantum state corresponding to the measurement is estimated.
27. The method according to claim 25, wherein, The information regarding how values are encoded as qubits includes at least one of the following: Used in conjunction with the authentication response value to generate the polarization basis of the photonic polarization state; Used in conjunction with the authentication response value to generate the polarization basis of the photonic polarization state of one of a pair of entangled photons; Belki, which is used to encode the authentication response value; or The coherent state is used to encode the authentication response value.
28. The method according to claim 25, wherein, Comparing the authentication response estimated from the received qubit sequence with the received authentication response message symbol includes: comparing the estimated authentication response with the received authentication response value using the information about how the value is encoded as qubits.
29. The method according to claim 27 or 28, wherein, The information regarding how the value is encoded as a qubit includes a polarization basis used with the authentication response value to generate a photon polarization state, and wherein comparing the authentication response estimated from the received qubit sequence with the received authentication response message symbols includes comparing the estimated authentication response with the received authentication response value only for those authentication response message symbols for which the correct polarization basis was selected during the estimation.
30. The method of claim 20, wherein, Receiving an encoded authentication response from the response device, wherein the encoded authentication response comprises a sequence of qubits and being received on a quantum communication channel with the response device comprises: receiving from the response device the qubits on which the authentication response is encoded.
31. The method according to claim 20, wherein, Receiving an encoded authentication response from the response device, wherein the encoded authentication response comprises a sequence of qubits and is received on a quantum communication channel with the response device, includes: Receive from the response device a qubit from each entangled qubit pair in a sequence of entangled qubit pairs generated by the response device, wherein the qubit of the entangled qubit pair comprises a photon; The response device retains another qubit from each entangled qubit pair in the generated sequence of entangled qubit pairs, and the authentication response is encoded by the response device onto the retained qubit.
32. The method according to claim 31, wherein, After receiving one qubit from each entangled qubit pair in the sequence of entangled qubit pairs generated by the response device, the response device encodes the authentication response onto the reserved qubit. Furthermore, estimating the authentication response from the received qubit sequence includes: For a qubit received from the response device, a basis for measuring the qubit is selected, and the selected basis is used to measure the qubit.
33. The method according to claim 32, wherein, Estimating the authentication response from the received qubit sequence includes: After receiving the message symbol and second signature of the authentication response from the response device, the authentication response is estimated from the received qubit sequence, wherein the second signature is based on the parameters sent to the response device and on the message symbol of the authentication response.
34. The method according to claim 33, wherein, For a qubit received from the response device, selecting the basis for measuring the qubit includes: selecting the basis based on the message symbol of the authentication response received from the response device.
35. The method according to claim 31, wherein, Receiving the encoded authentication response from the response device further includes the following operation, wherein the encoded authentication response comprises a sequence of qubits and is received on a quantum communication channel with the response device: The authentication response is received from the response device by the reserved qubits encoded thereon by the response device.
36. The method according to claim 35, wherein, Estimating the authentication response from the received qubit sequence includes: The entangled qubit pairs are reassembled by matching each received reserved qubit, on which the authentication response message value is encoded, with the corresponding qubit received from the response device for that reserved qubit; and Perform Bell measurements on the reassembled qubit pairs.
37. The method according to claim 31 or 32, further comprising: Select the qubits for measurement from the qubits of the generated sequence received from the response device; For each selected qubit, a basis is chosen for measuring that qubit, and the qubit is measured using the chosen basis; and Send the following specifications to the response device: The chosen basis; and The value measured for the selected qubit.
38. The method of claim 37, further comprising sending specifications of the following to the response device: The position of the qubit in the sequence that has been sent to the verification device and measured by the verification device.
39. The method according to claim 37, wherein, Sending the specification to the response device includes: sending the specification having the parameters and a first signature based on the parameters, wherein generating the first signature includes: generating the first signature based on the parameters and the specification.
40. The method of claim 37, wherein, Selecting qubits for measurement from the qubits of the generated sequence received from the response device includes: determining the position of the qubits received from the response device in the sequence based on at least one of the following: The parameters to be sent to the response device; or Credentials shared between the response device and the verification device.
41. The method according to claim 1 or 2, wherein, At least one of the verification device or the response device is associated with the vehicle.
42. The method according to claim 41, wherein, The authentication process is designed to allow at least one of the following: Vehicle unlocked; Vehicle control; The vehicle entered the restricted area.
43. A method for performing an authentication process between a verification device and a response device, wherein, Providing security credentials to the verification device and the response device, the method being executed by the response device, and including: Receive authentication challenges from the verification device; Based on the authentication challenge, an authentication response is generated; and The authentication response is transmitted to the verification device; In this embodiment, at least one of the authentication challenge or the authentication response is encoded as a sequence of qubits and transmitted on a quantum communication channel between the verification device and the response device, and in this embodiment, the other of the authentication challenge or the authentication response is transmitted on a non-quantum communication channel between the verification device and the response device. The qubit sequence includes at least one of the following: a non-orthogonal photon polarization state sequence; an entangled state sequence of photon pairs; and a coherent state sequence of light.
44. The method of claim 43, further comprising: The probability that at least one of the authentication challenge or authentication response, which is encoded as a qubit sequence and transmitted over the quantum communication channel between the authentication device and the response device, has been relayed by a third party is below a threshold.
45. The method according to any one of claims 43 to 44, wherein, The authentication response is encoded as a sequence of qubits and transmitted over a quantum communication channel between the authentication device and the response device; Furthermore, transmitting the authentication response to the verification device includes: The authentication response is encoded as a sequence of qubits; The encoded authentication response is transmitted to the verification device over a quantum communication channel; Receive parameters and a first signature based on the parameters from the verification device; Verify the first signature; and If the first signature is successfully verified, then: Based on the received parameters and the message symbols of the authentication response, a second signature is generated; and The authentication response message symbol and the second signature are sent to the verification device.
46. The method according to claim 45, wherein, Receiving parameters and a first signature based on the parameters from the verification device includes receiving the parameters and the first signature on a non-quantum communication channel.
47. The method according to claim 45, wherein, Sending the authentication response message symbol and the second signature to the verification device includes: sending the authentication response message symbol and the second signature over a non-quantum communication channel.
48. The method of claim 45, further comprising: If the verification of the first signature fails, the authentication process is terminated without executing the remaining method steps.
49. The method according to claim 45, wherein, The message symbol of the authentication response includes at least one of the following: The value of the authentication response; and Information about how this value is encoded as a qubit.
50. The method according to claim 49, wherein, The information regarding how values are encoded as qubits includes at least one of the following: Used in conjunction with the authentication response value to generate the polarization basis of the photonic polarization state; Used in conjunction with the authentication response value to generate the polarization basis of the photonic polarization state of one of a pair of entangled photons; Belki, which is used to encode the authentication response value; or The coherent state is used to encode the authentication response value.
51. The method according to claim 45, wherein, Encoding the authentication response into a qubit sequence includes: encoding the authentication response into a sequence of photonic polarization states or a sequence of coherent states of light; and wherein transmitting the encoded authentication response to the verification device over a quantum communication channel includes: sending the qubits on which the authentication response is encoded to the verification device.
52. The method according to claim 45, wherein, Encoding the authentication response into a qubit sequence includes: encoding the authentication response into a sequence of entangled states of photon pairs; and wherein encoding the authentication response into a qubit sequence and transmitting the encoded authentication response to the verification device over a quantum communication channel includes: Generate a sequence of entangled qubit pairs, wherein the qubits of the entangled qubit pairs include photons; Send one qubit from each pair to the verification device and retain the other qubit from each pair; and The authentication response is encoded into the reserved qubits of the entangled photon pair.
53. The method according to claim 52, wherein, Encoding the authentication response into a qubit sequence and transmitting the encoded authentication response to the verification device over a quantum communication channel further includes: The authentication response is encoded on the reserved qubits and sent to the authentication device.
54. The method according to claim 52 or 53, wherein, Encoding the authentication response into a qubit sequence and transmitting the encoded authentication response to the authentication device over a quantum communication channel includes: Before receiving the parameters and the first signature based on the parameters from the verification device, a sequence of entangled photon pairs is generated, and one qubit from each pair is sent to the verification device; and After verifying the first signature, if the verification of the first signature is successful, the authentication response is encoded into the reserved qubits of the entangled photon pair.
55. The method of claim 54, further comprising receiving specifications from the verification device for: The verification device is used to measure the basis of the qubits sent to the verification device in the generated sequence; and The value measured by the verification device for the qubit being measured.
56. The method of claim 55, further comprising receiving specifications from the verification device for: The position of the qubit in the sequence that has been sent to the verification device and measured by the verification device.
57. The method according to claim 55 or 56, wherein, Receiving the specification from the verification device includes: receiving the specification having the parameters and a first signature based on the parameters, wherein the first signature is also based on the specification.
58. The method of claim 56, further comprising: Using the basis indicated in the received specification and used by the verification device, the reserved qubits at the positions in the sequence as measured by the verification device are measured. The result of the measurement is compared with the measurement value received in the specification from the verification device; as well as If the error probability between the measured result and the value received in the specification from the verification device is higher than a threshold, it is determined that potential third-party intervention has occurred.
59. The method of claim 58, further comprising: The position of the qubit in the sequence that has been sent to the verification device and measured by the verification device is determined based on at least one of the following: The parameters received from the verification device; or Credentials shared between the response device and the verification device.
60. The method of claim 45, further comprising: Detect the position of the verification device; Furthermore, transmitting the encoded authentication response to the verification device over the quantum communication channel includes: directing the transmission of the encoded authentication response to the detected location of the verification device.
61. The method according to claim 45, wherein, Transmitting the encoded authentication response to the verification device via a quantum communication channel includes transmitting the encoded authentication response over a region where the verification device is predicted to exist.
62. The method according to any one of claims 43 to 44, wherein, The authentication challenge is encoded as a sequence of qubits and transmitted over a quantum communication channel between the verification device and the response device; Furthermore, receiving the authentication challenge from the verification device includes: Receive an coded authentication challenge from the verification device, wherein the coded authentication challenge includes a sequence of qubits and is received on a quantum communication channel with the verification device; Estimate the authentication challenge from the received qubit sequence; Generate the first signature based on the parameters; Send the first signature and the parameters to the verification device; The authentication challenge message symbol and a second signature are received from the authentication device, the second signature being based on the parameters sent to the authentication device and the authentication challenge message symbol. Verify the second signature; and If the second signature is successfully verified, then: The authentication challenge estimated from the received qubit sequence is compared with the received authentication challenge symbol; and If the estimated error probability between the authentication challenge and the received authentication challenge message symbol is below a threshold, then the authentication challenge is determined to have been correctly received.
63. The method of claim 62, further comprising: If the estimated error probability between the authentication challenge and the received authentication challenge message symbol is higher than a threshold, it is determined that potential third-party intervention has occurred during the transmission of the encoded authentication challenge to the responding device.
64. The method according to claim 62, wherein, Sending the first signature and the parameters to the verification device includes: sending the first signature and the parameters over a non-quantum communication channel.
65. The method according to claim 62, wherein, Receiving the message symbol and the second signature from the authentication challenge from the verification device includes receiving the message symbol and the second signature on a non-quantum communication channel.
66. The method of claim 62, further comprising: If the verification of the second signature fails, the authentication process is terminated without executing the remaining method steps.
67. The method according to claim 62, wherein, The message symbol for the authentication challenge includes at least one of the following: The value of the authentication challenge; and Information about how this value is encoded as a qubit.
68. The method according to claim 62, wherein, The authentication challenge estimated from the received qubit sequence includes at least one of the following: For each received quantum state of one or more photons, choose a basis for measuring the received quantum state, and use the chosen basis to measure the received quantum state of one or more photons; or For a sequence of qubits comprising a sequence of coherent states of light, for each received coherent state of light, at least one of the amplitude or phase of the light is measured, and the quantum state corresponding to the measurement is estimated.
69. The method according to claim 67, wherein, The information regarding how values are encoded as qubits includes at least one of the following: Used in conjunction with the authentication challenge value to generate the polarization basis of the photonic polarization state; Used in conjunction with the authentication challenge value to generate the polarization basis of the photon polarization state of one of a pair of entangled photons; Belki, which is used to encode the authentication challenge value; or The coherent state is used to encode the authentication challenge value.
70. The method of claim 67, wherein, Comparing the authentication challenge estimated from the received qubit sequence with the received authentication challenge message symbol includes: comparing the estimated authentication challenge with the received authentication challenge value using the information about how the value is encoded as qubits.
71. The method according to claim 69, wherein, The information regarding how the value is encoded as a qubit includes a polarization basis used with the authentication challenge value to generate a photon polarization state, and wherein comparing the authentication challenge estimated from the received qubit sequence with the received authentication challenge message symbols includes: comparing the estimated authentication challenge with the received authentication challenge value only for those authentication challenge message symbols for which the correct polarization basis was selected during the estimation.
72. The method according to claim 62, wherein, Receiving an encoded authentication challenge from the verification device, wherein the encoded authentication challenge comprises a sequence of qubits and being received on a quantum communication channel with the verification device comprises: receiving from the verification device the qubits on which the authentication challenge is encoded.
73. The method according to claim 62, wherein, Receiving an coded authentication challenge from the verification device, wherein the coded authentication challenge comprises a sequence of qubits and is received on a quantum communication channel with the verification device, includes: Receive one qubit from each entangled qubit pair in the sequence of entangled qubit pairs generated by the verification device, wherein the qubit of the entangled qubit pair comprises a photon; The verification device retains another qubit from each entangled qubit pair in the generated sequence of entangled qubit pairs, and the authentication challenge is encoded by the verification device into the retained qubit.
74. The method according to claim 73, wherein, After receiving one qubit from each entangled qubit pair in the sequence of entangled qubit pairs generated by the verification device, the authentication challenge is encoded by the verification device into the reserved qubit. Furthermore, estimating the authentication challenge from the received qubit sequence includes: For a qubit received from the verification device, a basis for measuring the qubit is selected, and the selected basis is used to measure the qubit.
75. The method according to claim 74, wherein, Estimating the authentication challenge from the received qubit sequence includes: After receiving the message symbol and second signature of the authentication challenge from the verification device, the authentication challenge is estimated from the received qubit sequence, wherein the second signature is based on the parameters sent to the verification device and on the message symbol of the authentication challenge.
76. The method according to claim 75, wherein, For a qubit received from the verification device, selecting the basis for measuring the qubit includes: selecting the basis based on the message symbol of the authentication challenge received from the verification device.
77. The method according to claim 73, wherein, Receiving an coded authentication challenge from the verification device, wherein the coded authentication challenge comprises a sequence of qubits and is received on a quantum communication channel with the verification device, further includes: The authentication challenge is received from the authentication device by the reserved qubits encoded thereon by the authentication device.
78. The method according to claim 77, wherein, Estimating the authentication challenge from the received qubit sequence includes: The entangled qubit pairs are reassembled by matching each received reserved qubit, on which the authentication challenge message value is encoded, with the corresponding qubit received from the verification device for that reserved qubit; and Perform Bell measurements on the reassembled qubit pairs.
79. The method according to claim 77 or 78, further comprising: Select the qubits for measurement from the qubits of the generated sequence received from the verification device; For each selected qubit, a basis is chosen for measuring that qubit, and the qubit is measured using the chosen basis; and Send the following specifications to the response device: The chosen basis; and The value measured for the selected qubit.
80. The method of claim 79, further comprising sending specifications of the following to the verification device: The position of the qubit in the sequence that has been sent to the response device and measured by the response device.
81. The method according to claim 79, wherein, Sending the specification to the verification device includes: sending the specification having the parameters and a first signature based on the parameters, wherein generating the first signature includes: generating the first signature based on the parameters and the specification.
82. The method according to claim 79, wherein, Selecting qubits for measurement from the qubits of the generated sequence received from the verification device includes: determining the position of the qubits received from the verification device in the sequence based on at least one of the following: The parameters to be sent to the verification device; or Credentials shared between the verification device and the response device.
83. The method according to any one of claims 43 to 44, wherein, At least one of the verification device or the response device is associated with the vehicle.
84. The method according to claim 83, wherein, The authentication process is designed to allow at least one of the following: Vehicle unlocked; Vehicle control; The vehicle entered the restricted area.
85. A method performed by a first device for transmitting a message to a second device, wherein, The method of providing security credentials to the first device and the second device includes: The message is encoded as a sequence of qubits; The encoded message is transmitted to the second device over the quantum communication channel; Receive parameters and a first signature based on the parameters from the second device; Verify the first signature; and If the first signature is successfully verified, then: Based on the received parameters and the message symbols of the message, a second signature is generated; and Send the message symbol and the second signature to the second device. The step of receiving parameters and a first signature based on the parameters from the second device includes receiving the parameters and the first signature on a non-quantum communication channel. The qubit sequence includes at least one of the following: a non-orthogonal photon polarization state sequence; an entangled state sequence of photon pairs; and a coherent state sequence of light.
86. The method according to claim 85, wherein, Sending the message symbol and the second signature to the second device includes: sending the message symbol and the second signature over a non-quantum communication channel.
87. The method according to claim 85 or 86, further comprising: If the verification of the first signature fails, the method is terminated without executing the remaining method steps.
88. The method according to claim 85 or 86, wherein, The message symbol of the message includes at least one of the following: The value of the message; and Information about how this value is encoded as a qubit.
89. The method according to claim 88, wherein, The information regarding how values are encoded as qubits includes at least one of the following: Used in conjunction with the message value to generate the polarization basis of the photonic polarization state; Used in conjunction with the message value to generate the polarization basis of the photonic polarization state of one of the entangled photons in a pair of entangled photons; Belki, which is used to encode the message value; or The coherent state is used to encode the message value.
90. The method according to claim 85 or 86, wherein, Encoding the message into a qubit sequence includes: encoding the message into a sequence of photonic polarization states or a sequence of coherent states of light; and wherein transmitting the encoded message to the second device over a quantum communication channel includes: sending the qubits on which the message is encoded to the second device.
91. The method according to claim 85 or 86, wherein, Encoding the message into a qubit sequence includes: encoding the message into a sequence of entangled states of photon pairs; and wherein encoding the message into a qubit sequence and transmitting the encoded message to the second device over a quantum communication channel includes: Generate a sequence of entangled qubit pairs, wherein the qubits of the entangled qubit pairs include photons; Send one qubit from each pair to the second device, and retain the other qubit from each pair; and The message is encoded into the reserved qubits of the entangled photon pair.
92. The method according to claim 91, wherein, Encoding the message into a sequence of qubits and transmitting the encoded message to the second device over a quantum communication channel further includes: The reserved qubits on which the message is encoded are sent to the second device.
93. The method according to claim 91, wherein, Encoding the message into a sequence of qubits and transmitting the encoded message to the second device over a quantum communication channel includes: Before receiving the parameters and the first signature based on the parameters from the second device, a sequence of entangled photon pairs is generated, and one qubit from each pair is sent to the second device; and After verifying the first signature, if the verification of the first signature is successful, the message is encoded into the reserved qubits of the entangled photon pair.
94. The method of claim 93, further comprising receiving specifications from the second device for: The second device is used to measure the basis of the qubits sent to the second device in the generated sequence; and The value measured by the second device for the qubit being measured.
95. The method of claim 94, further comprising receiving specifications from the second device for: The position of the qubit in the sequence that has been sent to the second device and measured by the second device.
96. The method according to claim 94 or 95, wherein, Receiving the specification from the second device includes: receiving the specification having the parameters and a first signature based on the parameters, wherein the first signature is also based on the specification.
97. The method of claim 95, further comprising: Using the base indicated in the received specification for use by the second device, the reserved qubit at the position in the sequence as measured by the second device is measured; The result of the measurement is compared with the measurement value received in the specification from the second device; as well as If the error probability between the measured result and the value received in the specification from the second device is higher than a threshold, it is determined that potential intervention by a third party has occurred.
98. The method of claim 97, further comprising: The position of the qubit in the sequence that has been sent to the second device and measured by the second device is determined based on at least one of the following: The parameters received from the second device; or Credentials shared between the first device and the second device.
99. The method according to claim 85 or 86, further comprising: Detect the position of the second device; Furthermore, transmitting the encoded message to the second device over the quantum communication channel includes directing the transmission of the encoded message to the detected location of the second device.
100. The method according to claim 85 or 86, wherein, Transmitting the encoded message to the second device over a quantum communication channel includes transmitting the encoded message over a region where the second device is predicted to exist.
101. The method according to claim 85 or 86, wherein, The message includes at least one of an authentication challenge or an authentication response, and wherein the authentication challenge or the authentication response is transmitted as part of the authentication process.
102. The method according to claim 101, further comprising: If the verification of the first signature fails, the authentication process is terminated.
103. The method according to claim 101, wherein, At least one of the first device or the second device is associated with the vehicle.
104. The method according to claim 101, wherein, The authentication process is designed to allow at least one of the following: Vehicle unlocked; Vehicle control; The vehicle entered the restricted area.
105. A method for receiving a message from a first device, wherein, The method is performed by a second device, and wherein security credentials are provided to both the first device and the second device, the method comprising: Receive an encoded message from the first device, wherein the encoded message includes a sequence of qubits and is received on a quantum communication channel with the first device; The message is estimated from the received sequence of qubits; Generate the first signature based on the parameters; Send the first signature and the parameters to the first device; The message symbol and a second signature of the message are received from the first device, the second signature being based on the parameters sent to the first device and based on the message symbol of the message; Verify the second signature; and If the second signature is successfully verified, then: The message estimated from the received qubit sequence is compared with the received message symbol; and If the estimated error probability between the estimated message and the received message symbol is below a threshold, then it is determined that the message has been correctly received. Sending the first signature and the parameters to the first device includes: sending the first signature and the parameters over a non-quantum communication channel; The qubit sequence includes at least one of the following: a non-orthogonal photon polarization state sequence; an entangled state sequence of photon pairs; and a coherent state sequence of light.
106. The method of claim 105, further comprising: If the estimated error probability between the message and the received message symbol is higher than a threshold, it is determined that potential third-party intervention has occurred during the transmission of the encoded message to the second device.
107. The method according to claim 105 or 106, wherein, Receiving the message symbol and the second signature from the first device includes receiving the message symbol and the second signature on a non-quantum communication channel.
108. The method according to claim 105 or 106, further comprising: If the verification of the second signature fails, the method is terminated without executing the remaining method steps.
109. The method according to claim 105 or 106, wherein, The message symbol of the message includes at least one of the following: The value of the message; and Information about how this value is encoded as a qubit.
110. The method according to claim 105 or 106, wherein, The message estimated from the received qubit sequence includes at least one of the following: For each received quantum state of one or more photons, choose a basis for measuring the received quantum state, and use the chosen basis to measure the received quantum state of one or more photons; or For a sequence of qubits comprising a sequence of coherent states of light, for each received coherent state of light, at least one of the amplitude or phase of the light is measured, and the quantum state corresponding to the measurement is estimated.
111. The method according to claim 109, wherein, The information regarding how values are encoded as qubits includes at least one of the following: Used in conjunction with the message value to generate the polarization basis of the photonic polarization state; Used in conjunction with the message value to generate the polarization basis of the photonic polarization state of one of the entangled photons in a pair of entangled photons; Belki, which is used to encode the message value; or The coherent state is used to encode the message value.
112. The method according to claim 111, wherein, Comparing the message estimated from the received qubit sequence with the received message symbol includes: comparing the estimated message with the received message value using the information about how the value is encoded as qubits.
113. The method according to claim 111 or 112, wherein, The information regarding how values are encoded as qubits includes a polarization basis used with the message value to generate a photon polarization state, and wherein comparing the message estimated from the received qubit sequence with the received message symbols includes comparing the estimated message with the received message value only for those message symbols for which the correct polarization basis was selected during the estimation.
114. The method according to claim 105 or 106, wherein, Receiving an encoded message from the first device, wherein the encoded message comprises a sequence of qubits and being received on a quantum communication channel with the first device comprises: receiving from the first device the qubits on which the message is encoded.
115. The method according to claim 105 or 106, wherein, Receiving an encoded message from the first device, wherein the encoded message includes a sequence of qubits and is received on a quantum communication channel with the first device, includes: Receive one qubit from each entangled qubit pair in a sequence of entangled qubit pairs generated by the first device, wherein the qubit of the entangled qubit pair comprises a photon; Wherein, the first device retains another qubit from each entangled qubit pair in the generated sequence of entangled qubit pairs, and wherein the message is encoded by the first device onto the retained qubit.
116. The method according to claim 115, wherein, After receiving from the first device one qubit of each entangled qubit pair in the sequence of entangled qubit pairs generated by the first device, the message is encoded by the first device onto the reserved qubit; and wherein estimating the message from the received qubit sequence includes: For a qubit received from the first device, a basis for measuring the qubit is selected, and the selected basis is used to measure the qubit.
117. The method according to claim 116, wherein, Estimating the message from the received qubit sequence includes: After receiving the message symbol and second signature of the message from the first device, the message is estimated from the received sequence of qubits, wherein the second signature is based on the parameters sent to the first device and the message symbol of the message.
118. The method according to claim 117, wherein, For a qubit received from the first device, selecting the basis for measuring the qubit includes: selecting the basis based on the message symbol of the message received from the first device.
119. The method according to claim 115, wherein, Receiving an encoded message from the first device, wherein the encoded message includes a sequence of qubits and is received on a quantum communication channel with the first device, further includes: The message is received from the first device, which contains reserved qubits encoded thereon by the first device.
120. The method according to claim 119, wherein, Estimating the message from the received qubit sequence includes: The entangled qubit pairs are reassembled by matching each received reserved qubit on which the message value is encoded with the corresponding qubit received from the first device. Perform Bell measurements on the reassembled qubit pairs.
121. The method according to claim 119 or 120, further comprising: Select the qubits for measurement from the qubits of the generated sequence received from the first device; For each selected qubit, a basis is chosen for measuring that qubit, and the qubit is measured using the chosen basis; and Send the specifications of the following items to the first device: The chosen basis; and The value measured for the selected qubit.
122. The method of claim 121, further comprising sending specifications of the following to the first device: The position of the qubit in the sequence that has been sent to the second device and measured by the second device.
123. The method according to claim 121, wherein, Sending the specification to the first device includes: sending the specification having the parameters and a first signature based on the parameters, wherein generating the first signature includes: generating the first signature based on the parameters and the specification.
124. The method according to claim 121, wherein, Selecting qubits for measurement from the qubits in the generated sequence received from the first device includes: determining the position of the qubits received from the first device in the sequence based on at least one of the following: The parameters to be sent to the first device; or Credentials shared between the first device and the second device.
125. The method according to claim 105 or 106, wherein, The message includes at least one of an authentication challenge or an authentication response, and wherein the authentication challenge or the authentication response is received as part of the authentication process.
126. The method of claim 125, further comprising: If the verification of the second signature fails, or if the error probability between the estimated message and the received message symbol is higher than a threshold, the authentication process is terminated.
127. The method according to claim 125, wherein, At least one of the first device or the second device is associated with the vehicle.
128. The method according to claim 125, wherein, The authentication process is designed to allow at least one of the following: Vehicle unlocked; Vehicle control; The vehicle entered the restricted area.
129. A computer program product comprising a computer-readable medium having computer-readable code stored therein, the computer-readable code being configured to, when executed by a suitable computer or processor, cause the computer or processor to perform the method according to any one of claims 1 to 128.
130. A verification device for performing an authentication process between the verification device and a response device, wherein, Security credentials are provided to the verification device and the response device, the verification device including processing circuitry configured to: Generate authentication challenge; The authentication challenge is transmitted to the response device; Receive an authentication response from the response device; as well as Verify the authentication response; In this embodiment, at least one of the authentication challenge or the authentication response is encoded as a sequence of qubits and transmitted on a quantum communication channel between the verification device and the response device, and in this embodiment, the other of the authentication challenge or the authentication response is transmitted on a non-quantum communication channel between the verification device and the response device. The qubit sequence includes at least one of the following: a non-orthogonal photon polarization state sequence; an entangled state sequence of photon pairs; and a coherent state sequence of light.
131. The verification device according to claim 130, wherein, The processing circuit is also configured to perform the method according to any one of claims 2 to 42.
132. A response device for performing an authentication process between a verification device and the response device, wherein, Security credentials are provided to the verification device and the response device, the response device including processing circuitry configured to: Receive authentication challenges from the verification device; Based on the authentication challenge, an authentication response is generated; as well as The authentication response is transmitted to the verification device; In this embodiment, at least one of the authentication challenge or the authentication response is encoded as a sequence of qubits and transmitted on a quantum communication channel between the verification device and the response device, and in this embodiment, the other of the authentication challenge or the authentication response is transmitted on a non-quantum communication channel between the verification device and the response device. The qubit sequence includes at least one of the following: a non-orthogonal photon polarization state sequence; an entangled state sequence of photon pairs; and a coherent state sequence of light.
133. The response device according to claim 132, wherein, The processing circuit is also configured to perform the method according to any one of claims 44 to 84.
134. A first device for transmitting a message to a second device, wherein, Provide security credentials to the first device and the second device, wherein the first device includes processing circuitry configured to: The message is encoded as a sequence of qubits; The encoded message is transmitted to the second device over the quantum communication channel; Receive parameters and a first signature based on the parameters from the second device; Verify the first signature; as well as If the first signature is successfully verified, then: A second signature is generated based on the received parameters and the message symbols of the message; as well as Send the message symbol and the second signature to the second device. The step of receiving parameters and a first signature based on the parameters from the second device includes receiving the parameters and the first signature on a non-quantum communication channel. The qubit sequence includes at least one of the following: a non-orthogonal photon polarization state sequence; an entangled state sequence of photon pairs; and a coherent state sequence of light.
135. The first device according to claim 134, wherein, The processing circuit is also configured to perform the method according to any one of claims 86 to 104.
136. A second device for receiving messages from a first device, wherein, Provide security credentials to the first device and the second device, the second device including processing circuitry configured to: Receive an encoded message from the first device, wherein the encoded message includes a sequence of qubits and is received on a quantum communication channel with the first device; The message is estimated from the received sequence of qubits; Generate the first signature based on the parameters; Send the first signature and the parameters to the first device; The message symbol and a second signature of the message are received from the first device, the second signature being based on the parameters sent to the first device and based on the message symbol of the message; Verify the second signature; and If the second signature is successfully verified, then: The message estimated from the received qubit sequence is compared with the received message symbol; and If the estimated error probability between the estimated message and the received message symbol is below a threshold, then it is determined that the message has been correctly received. Sending the first signature and the parameters to the first device includes: sending the first signature and the parameters over a non-quantum communication channel; The qubit sequence includes at least one of the following: a non-orthogonal photon polarization state sequence; an entangled state sequence of photon pairs; and a coherent state sequence of light.
137. The second device according to claim 136, wherein, The processing circuit is also configured to perform the method according to any one of claims 106 to 128.
Citation Information
Patent Citations
Location verification in quantum communications
US20120195597A1
Quantum position based authentication
WO2015118179A1