A loss-tolerant reference-frame-independent quantum digital signature method
Through the loss-tolerant reference frame-independent quantum digital signature method, the problem of state preparation error in the quantum digital signature protocol is solved, and more efficient key generation and signature performance is achieved, reducing the difficulty and cost of experiments.
Patent Information
- Application Number
- CN202211254229.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-13
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-10-13
AI Technical Summary
In actual applications, the existing quantum digital signature protocol has state preparation error problems, which affects the key generation and signature performance, and is difficult to experiment.
The quantum digital signature method is adopted that is independent of the loss tolerance reference frame, and the Z, X, and Y bases are randomly selected for projection measurement, and the loss tolerance method is used to process the preparation error to reduce security vulnerabilities and experimental difficulty.
It reduces the impact of state preparation error on key generation, reduces unnecessary communication costs and technical difficulty, improves signature rate and system performance, and performs superiorly especially in the presence of state preparation errors.
Smart Images

Figure CN115643024B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of quantum digital signatures in quantum communication, and specifically relates to a loss-tolerant reference-frame-independent quantum digital signature method. Background Art
[0002] Digital signatures play an important role in modern cryptographic communication. One of the purposes is to replace traditional manual signatures and seals in a network environment. As one of the means to ensure network information security, the digital signature mechanism can solve problems such as forgery, repudiation, impersonation, and tampering. However, with the improvement of software and hardware and the rapid development of quantum computers, the security of classical digital signatures is threatened. Therefore, people have proposed quantum digital signatures (QDS) to cope with new threats. The security of quantum digital signatures is guaranteed by the laws of quantum mechanics and theoretically has unconditional security. The first quantum protocol was proposed by D. Gottesman and I. Chuang. In this protocol, long-term quantum storage, non-destructive state comparison technology, and a quantum channel without eavesdropping are required. From an experimental technology perspective, these requirements are difficult to achieve. After this protocol, many quantum digital signature protocols have been proposed and implemented experimentally. Among them, the quantum digital signature protocol proposed by R. Amiri et al. that does not require a secure quantum channel allows a third-party eavesdropping on the quantum channel. In this protocol, the sender and the receiver prepare keys during the KGP process. Currently, quantum digital signature protocols are relatively mature, but in practical applications, there may still be problems with state preparation errors, that is, errors are generated by the modulator during the preparation of the light source. This error will affect the generation of keys and the performance of digital signatures. Summary of the Invention
[0003] The purpose of the present invention is to propose a loss-tolerant reference-frame-independent quantum digital signature method for the deficiencies of the above-mentioned existing technologies and apply it to a quantum digital signature system. In the key generation stage, a loss-tolerant reference-frame-independent method is adopted, which does not require calibration of the reference frames of both communication parties, only requires the preparation of four states, and allows state preparation errors. This not only reduces the security vulnerabilities of quantum digital signatures but also lowers the experimental difficulty.
[0004] The technical solution adopted by the present invention to solve the technical problem is to use a loss-tolerant reference-frame-independent quantum digital signature method. During the quantum key distribution process, the two communication parties are the sender and the receiver respectively. The sender and the receiver randomly select projection measurements from the Z basis, X basis, and Y basis and announce the measurement results. Assume that the total number of pulses sent by the sender is N, and the gain obtained according to the reference-frame-independent protocol and the bit error rate The number of pulses and the number of bit errors in different bases can be obtained. Then, through the loss tolerance method, the vacuum state and single-photon response counts in different bases can be obtained, and the single-photon bit error rate in different bases can be calculated.
[0005] This method includes a sending stage and a message stage. Among them, Alice is the sender, and Bob and Charlie are the receivers.
[0006] In the key distribution stage, Alice and Bob, Alice and Charlie generate bit strings according to the key generation protocol. Among them, Alice sends quantum states to Bob and Charlie respectively, and Bob (Charlie) performs projective measurements on the quantum states.
[0007] In the message stage, the sender Alice sends the message to be signed and the signature to Bob and Charlie. Bob and Charlie match the signature with their own keys and judge whether to receive the signature and the message according to whether the corresponding threshold conditions are met.
[0008] A loss-tolerant reference-frame-independent quantum digital signature method is applied to a quantum digital signature system. The quantum digital signature system includes legitimate parties Alice, Bob, and Charlie. In the quantum key distribution process, the two communicating parties are the sender and the receiver respectively. Alice is the sender, and Bob and Charlie are the receivers respectively;
[0009] The method includes a key distribution stage and a message stage, specifically:
[0010] Step 1, in the key distribution stage, Alice sends N pulses, and Bob and Charlie are the receivers. The specific steps are as follows:
[0011] Step 1.1, in the key generation stage, according to the loss-tolerant reference-frame-independent key generation protocol, define
[0012] The sender Alice randomly selects Z A , X A , Y A to prepare four quantum states and send the states. After the receiver Bob receives the states sent by Alice, he randomly selects Z B , X B , Y B to measure the received states, or after the receiver Charlie receives the states sent by Alice, he randomly selects Z C , X C , Y C to measure the received states. Taking time-phase-encoded RFI-QKD as an example, assuming that there are no defects in state preparation on the Z basis, the state corresponding to the short arm is |0Z >, the state corresponding to the long arm is |1 Z >. However, due to the state preparation errors caused by the actual optical attenuator or intensity modulator, Alice actually prepares |0 Z > and |1 Z > with probabilities of and In the X basis and Y basis, the asymmetric splitting ratios of the beam splitters are also defects that lead to imperfect state preparation, generally denoted as δ3 and δ4. In addition, the phase modulator may also cause some phase errors θ1 and θ2. According to the above description, and due to the presence of the deflection angle β, the four states sent by Alice to Bob and Charlie can be expressed as:
[0013]
[0014]
[0015]
[0016]
[0017] Among them, δ1, δ2, δ3, and δ4 respectively correspond to the errors in actually preparing |φ 0Z >, |φ 1Z >, |φ 0x >, |φ 0Y >; θ1 and θ2 are the phase errors caused by the phase modulator; β is the deflection angle.
[0018] In the Z basis, X basis, and Y basis, each basis has two states. One is the positive state, represented by Z 0 , X 0 , Y 0 ; the other is the negative state, represented by Z 1 , X 1 , Y 1 >.
[0019] Step 1.2, in the virtual protocol, Alice randomly prepares four quantum states respectively The density matrices corresponding to these four states That is where s ∈ {0, 1} and ω ∈ {X, Y, Z}.
[0020]
[0021] Here is The vector coefficients projected onto the Bloch sphere, where I is the identity matrix, and are the Pauli matrices.
[0022] Alice prepares a quantum state
[0023]
[0024] and measures the virtual system A using the Z basis, then sends the virtual system A to Charlie e , and then sends the virtual system B to Bob o b.
[0025] A e represents Alice's extended system, represents the purified state of. Emitting and emitting can also be equivalently represented as the same process.
[0026] Therefore, in this virtual protocol, Alice also needs to prepare two other states as well as
[0027] After the receiver Bob receives the state sent by Alice, he randomly selects Z B , X B or Y B basis to measure the received state. After the receiver Charlie receives the state sent by Alice, he randomly selects Z C , X C , Y C to measure the received state.
[0028] Step 1.3, Alice and Bob or Charlie randomly select a part of the bits k from the original number of pulses N for estimating the error rate during channel transmission. If the error rate is greater than a certain value, the protocol is terminated. Define the remaining n bits after Bob selects a part of the bits between Alice and Bob as
[0029] the remaining n bits after Alice selects a part of the bits as Define the remaining n bits after Alice selects a part of the bits between Alice and Charlie as the remaining n bits after Charlie selects a part of the bits as Bob divides his remaining n bits of the key into two equal-length parts, denoted as and and and sends Send it to Charlie through a secure classical channel; similarly, Charlie divides his remaining n-bit key into two equal parts, denoted as and and send to Bob through a secure classical channel. After the exchange, the symmetric key held by Bob is The symmetric key held by Charlie is
[0030] Step 2, in the message phase, Alice sends the message and signature (m, Sig m ) to the recipient Bob. Sig m represents the signature of the message m, where Bob compares the signature with the symmetric key held by himself at the corresponding positions and records the number of mismatches; if the number of mismatches in both parts is less than s a (n / 2), then Bob receives this signed message and sends the signed message (m, Sig m ) to Charlie, otherwise rejects the signed message and terminates the signature. Charlie compares the signature with the symmetric key held by himself at the corresponding positions and records the number of mismatches; if the number of mismatches in both parts is less than s v (n / 2), then Charlie receives this signed message, otherwise rejects the signed message and terminates the signature.
[0031] Furthermore, the joint probability when Alice or Bob measures the received state in the α basis or ω basis and obtains the binary bit s or j is
[0032]
[0033] where α, ω ∈ {X, Y, Z}, s, j ∈ {0, 1};
[0034] P jω,vir is the probability that Alice sends the virtual system A or B, k is the probability that the recipient chooses to measure in the ω basis, q sα|t represents the transmission rate of σ t , and σ t is related to the channel parameters.
[0035] Furthermore, the probability P jX,vir that Alice sends the virtual system A or B is expressed as
[0036] P jX,vi r = |<jX |Ψ Z > AB | 2
[0037] Among them, So we get
[0038]
[0039] and
[0040]
[0041]
[0042] Here is the joint probability that Alice randomly selects one quantum state from four quantum states to send and Bob measures it in the X basis.
[0043] And the matrix A satisfies
[0044]
[0045] Furthermore, define the virtual phase error rate e αω as the result after measurement :
[0046]
[0047] where αω ∈ {XX, XY, YX, YY}, is the joint probability that Alice or Bob obtains the binary bit s or j when measuring in the α basis or ω basis, s, j ∈ {0, 1}.
[0048] Furthermore, according to the decoy state method, the gain Q μ,sω,jα , Q v,sω,jα
[0049]
[0050]
[0051] Here μ and v represent the intensities of the signal state and the decoy state respectively, and Q μ,sω,jα and Q v,sω,jα can be directly obtained in the experiment, then we can obtain the lower bound of the single photon counting rate
[0052]
[0053] Here Y0 represents the counting rate at 0 photons, Then we can obtain the single - photon counting rate in the Z - basis and the single - photon bit error rate e ZZ .
[0054]
[0055]
[0056]
[0057] Furthermore, the security level ε of the protocol is:
[0058] ε = max{P(robust), P(forge), P(repudiation)}.
[0059] Where P(robust) is the robustness probability; P(forge) represents the forgery probability, that is, the probability that a forged Alice's signature is received by both Bob and Charlie; P(repudiation) represents the repudiation probability, that is, the probability that Alice's signature is received by Bob but rejected by Charlie.
[0060] Furthermore, in the presence of an eavesdropper Eve, the minimum entropy in the KGP process is:
[0061]
[0062] Where is the binary Shannon function, satisfying H(x)= - x log2(x)-(1 - x)log2(1 - x), ε is the failure probability for parameter estimation, Z represents the Z - basis, E represents the eavesdropper Eve, represents the lower bound of the single - photon response count in the Z - basis, I E represents the amount of information stolen by Eve:
[0063]
[0064] C E =(1 - 2e XX ) 2 +(1 - 2e XY ) 2 +(1 - 2e YX ) 2 +(1 - 2e YY ) 2 ,
[0065]
[0066]
[0067] Among them and are intermediate parameters, and C E is the information statistic obtained by the eavesdropper; H is the binary Shannon entropy function, satisfying H(x) = -x log2(x) - (1 - x)log2(1 - x)
[0068] Furthermore, in the presence of the eavesdropper Eve, the minimum bit error rate p caused by Eve's information stealing e satisfies:
[0069] The beneficial effects of the present invention are as follows: Compared with general quantum number signature schemes, in the key generation stage of the present invention, a loss-tolerant reference-frame-independent quantum key distribution method is adopted, which reduces the impact of state preparation errors on key preparation, reduces unnecessary communication cost losses, and reduces the technical difficulty. The simulation results prove that the loss-tolerant reference-frame-independent quantum digital signature can cope with the situation of state preparation errors, thereby obtaining quite good performance, which clearly proves the possibility of the loss-tolerant reference-frame-independent protocol being practical in quantum digital signatures. In the case of a deviation in the reference frame, the method of the present invention can still play a good role in loss tolerance. BRIEF DESCRIPTION OF THE DRAWINGS
[0070] Figure 1 is the principle flow chart of the loss-tolerant reference-frame-independent quantum digital signature of the method of the present invention.
[0071] Figure 2 is the comparison chart of the signature rates of two quantum digital signature schemes.
[0072] Figure 3 is the simulation chart of the reference-frame-independent signature rates without using the loss-tolerant method and the reference-frame-independent signature rates using the loss-tolerant method under different state preparation errors when β = 0.
[0073] Figure 4 When it is, the simulation chart of the reference-frame-independent signature rates without using the loss-tolerant method and the reference-frame-independent signature rates using the loss-tolerant method under different state preparation errors. DETAILED DESCRIPTION OF THE INVENTION
[0074] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings.
[0075] A loss-tolerant reference-frame-independent quantum digital signature method described in the present invention specifically includes a key distribution stage and a message stage.
[0076] In the key generation stage, using the gain and the quantum bit error rate The number of pulses and the number of bit errors in the corresponding basis can be calculated.
[0077] When the sending basis is the Z basis and the measurement basis is also the Z basis, the number of pulses is:
[0078]
[0079] Where P u ,P v ,P w are optimization parameters, representing the probability that the sender Alice selects the Z basis, the probability that the receiver Bob (Chatlie) selects the Z basis, the probability of selecting the signal state, the probability of selecting the decoy state, and the probability of selecting the vacuum state. Among them, P w = 1 - P u - P v . respectively represent the gains of the signal state, decoy state, and vacuum state in the corresponding Z basis, represents the total number of pulses in the corresponding Z basis, while represents the number of pulses in the signal state, decoy state, and vacuum state in the corresponding Z basis. Similarly, the number of pulses in the X A X B(C) ,X A Y B(C) ,Y A X B(C) ,Y A Y B(C) can also be obtained.
[0080] Correspondingly, when the sending basis is the Z basis and the measurement basis is also the Z basis, the number of bit errors is:
[0081]
[0082] Where P u ,P v ,P w are optimization parameters, representing the probability that the sender Alice selects the Z basis, the probability that the receiver Bob (Charlie) selects the Z basis, the probability of selecting the signal state, the probability of selecting the decoy state, and the probability of selecting the vacuum state. Among them, P w = 1 - P u - P v . respectively represent the gains of the signal state, decoy state, and vacuum state in the corresponding Z basis, respectively represent the qubit bit error rates of the signal state, decoy state, and vacuum state in the corresponding Z basis. represents the total number of bit errors in the corresponding Z basis, respectively represent the number of bit errors in the signal state, decoy state, and vacuum state in the Z basis. Similarly, the XA X B(C) ,X A Y B(C) ,Y A X B(C) ,Y A Y B(C) The number of error codes under
[0083] Using Hoeffding's inequality, the upper and lower bounds of the number of pulses and error codes corresponding to the basis can be obtained. For Z A Z B basis
[0084]
[0085] where k ∈ (u, v, w), ∈ PE is the security parameter of the system.
[0086] After that, the vacuum state count and single photon state count corresponding to the basis can be calculated. For Z A Z B basis, the vacuum state count is:
[0087]
[0088] The single photon state count is:
[0089]
[0090] where k = {u, v, w}, τ n represents the probability of preparing an n-photon state; similarly, the vacuum state count and single photon state count under X A X B(C) ,X A Y B(C) ,Y A X B(C) ,Y A Y B(C) can be calculated.
[0091] Define I E as the amount of information obtained by the eavesdropper through eavesdropping:
[0092]
[0093] C E =(1 - 2e XX ) 2 +(1 - 2e XY ) 2 +(1 - 2e YX ) 2 +(1 - 2e YY ) 2 , (7)
[0094]
[0095]
[0096] where and are intermediate parameters, C E is the information statistic obtained by the eavesdropper; R is the binary Shannon entropy function, satisfying H(x) = -x log2(x) - (1 - x)log2(1 - x), e ZZ , e XX , e XY , e YX , e YY is the single - photon bit - error rate.
[0097] For a loss - tolerant reference - frame - independent quantum digital signature, in the presence of an eavesdropper Eve, the minimum entropy in the KGP process and it is possible to determine the minimum rate P of introducing errors in the KGP process in the presence of an eavesdropper Eve e value:
[0098]
[0099] where n is the length to be signed.
[0100] In the sending stage, Alice sends the message and the signature (m, Sig m ) to the receivers Bob and Charlie, Sig m represents the signature of the message m, where Bob compares the sent by Alice with his own at the corresponding positions respectively and records the number of mismatches; if the number of mismatches in both parts is less than s a (n / 2), then Bob receives this signed message and sends the signed message (m, Sig m ) received from Alice to Charlie, otherwise rejects the signed message and terminates the signature. Charlie compares the received with his own at the corresponding positions respectively and records the number of mismatches; if the number of mismatches in both parts is less than s v (n / 2), then Bob receives this signed message, otherwise rejects the signed message and terminates the signature. s a , s v are set security thresholds, which are related to the maximum bit - error rate in the worst - case scenario (deflection angle is 45°) It is related to the minimum bit error rate \(p_e\) introduced by the eavesdropper. where is the upper bound of the bit error rate estimated by the Serfling inequality (\(n\) is the length to be signed, and \(k\) is the number of bits used to estimate the bit error rate during channel transmission):
[0101]
[0102]
[0103]
[0104] For the security analysis of a loss-tolerant reference-frame-independent quantum digital signature, the proposed scheme of the present invention comprehensively considers the robustness probability, forgery probability, and repudiation probability. The robustness probability is a measure of the failure probability of the protocol when the system operates normally, and it satisfies:
[0105] \(P(robust)\leq 2\epsilon\) pE , (14)
[0106] where \(\epsilon\) PE is the failure probability of estimating the error rate between Alice - Bob and Alice - Charlie using the Serfling inequality. The repudiation probability is a measure of the probability that Alice's signature is accepted by Bob but rejected by Charlie, and it satisfies:
[0107]
[0108] The forgery probability is a measure of the probability that a forged signature of Alice can be accepted by both Bob and Charlie, and it satisfies:
[0109] \(P(forge)\leq a+\epsilon\) F + 8\(\epsilon\) PE , (16)
[0110] where \(a\) is a preset constant probability, and \(\epsilon\) F is a parameter related to the probability that Bob discovers that the error rate is less than \(s\) v .
[0111]
[0112] In summary, the security of the protocol needs to satisfy:
[0113] \(\epsilon\geq P(robust)=P(repudiation)=P(forge)\), (18)
[0114] To make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the following further elaborates on the present invention in detail in combination with specific simulation results and with reference to the accompanying drawings.
[0115] The system parameters used in the simulation of the present invention's solution are shown in Table 1: α is the loss coefficient of the quantum channel; P dc is the dark count rate; η d is the detection efficiency of the detector; ∈ PE is the failure probability of the bit error rate estimation. In addition, under a given security level, the signature rate is optimized with all parameters, and the optimized parameters include the intensities of the signal state and the decoy state {u, v}, the probabilities of selecting the signal state and the decoy state {P u , P v}, the probability that Alice selects the Z basis the probability that Bob (Charlie) selects the Z basis
[0116] Figure 1 Fig. shows the principle flow chart of the present solution. The principle of the present solution is to apply loss-tolerant reference-frame-independent key distribution to quantum digital signatures.
[0117] Figure 2 The signature rates of the reference-frame-independent quantum digital signature and the BB84 quantum digital signature scheme are compared at different transmission distances, and the signature rates at different reference-frame deflection angles are also compared. Here, we consider the cases of no deflection angle (β = 0) and the worst deflection angle which have the greatest impact on the system performance. The dark black dotted line and the light black dotted line in the figure represent the signature rate images of the reference-frame-independent quantum digital signature and the BB84 quantum digital signature when the reference-frame deflection angle β = 0, respectively. The dark black solid line and the light black solid line in the figure represent the signature rate images of the reference-frame-independent quantum digital signature and the BB84 quantum digital signature when the reference-frame deflection angle respectively. According to Figure 2 it can be concluded that at the same deflection angle, compared with the BB84 quantum digital signature scheme, the signature rate and the secure transmission distance of the reference-frame-independent quantum digital signature scheme have better performance. And even in the worst-case deflection angle the signature rate of the reference-frame-independent quantum digital signature scheme still has good performance, and it is less affected by the deflection angle than the BB84 quantum digital signature scheme.
[0118] Figure 3(a) and (b) in it show the difference in the signature rates of the reference-frame-independent quantum digital signature protocol without using the loss tolerance method and with using the loss tolerance when the same reference deflection angle β = 0, but different state preparation errors (δ = 0, 0.2, 0.3). In the two figures, the solid line, the dotted line, and the dashed line represent the signature rate curves when the state preparation errors are δ = 0, 0.2, and 0.3 respectively. When the state preparation error is 0, the signature rates of the two schemes are basically the same. However, as the state preparation error increases, the signature rate of the protocol without using the loss tolerance scheme drops faster, while the signature rate of this protocol drops more slowly. For example, the gap between the signature rates at δ = 0 and δ = 0.2 is not large. For further research, we simulated the signature rate images of the two methods at the deflection angle and the result is as shown in Figure 4 .
[0119] Figure 4 (a) and (b) in it show the difference in the signature rates of the reference-frame-independent quantum digital signature protocol without using the loss tolerance method and with using the loss tolerance when the same reference deflection angle but different state preparation errors (δ = 0, 0.2, 0.3). After comparison, when the state preparation error is 0, the signature rates of the two schemes are basically the same. However, as the state preparation error increases, the signature rate of the protocol without using the loss tolerance scheme drops faster, while the signature rate of this protocol drops more slowly. This conclusion is the same as that after comparison with Figure 3 . The above results show that this protocol has a relatively good immunity to the state preparation error.
[0120] Table 1
[0121] α <![CDATA[P dc > <![CDATA[η d > <![CDATA[∈ PE > 0.2 dB / km <![CDATA[3.0×10 -6 > 14.5% <![CDATA[10 -5 >
[0122] The above is only the preferred embodiment of the present invention, and the protection scope of the present invention is not limited to the above embodiment. Any equivalent modification or change made by those of ordinary skill in the art according to the content disclosed by the present invention shall be included in the protection scope recorded in the claims.
Claims
1. A loss-tolerant reference-frame-independent quantum digital signature method, characterized in that Including the following steps: Step 1, in the key distribution phase, according to the loss-tolerant reference-frame-independent key generation protocol, the sender Alice randomly selects Z A , Y A , Y A to prepare four quantum states and send them to Bob and Charlie; The four quantum states are: Among them, δ1, δ2, δ3, and δ4 respectively correspond to the errors of the actually prepared |φ 0Z >, |φ 1Z >, |φ 0X >, |φ 0Y >; θ1 and θ2 are the phase errors caused by the phase modulator; β is the deflection angle; Step 2, in the virtual protocol, Alice prepares and sends the quantum state After the receiver Bob receives the quantum state sent by Alice, randomly select Z B , X B or Y B basis to measure the received state. After the receiver Charlie receives the quantum state sent by Alice, randomly select Z C , X C , Y C to measure the received state.
2. The loss-tolerant reference-frame-independent quantum digital signature method according to claim 1, wherein In step 2, the joint probability when Alice or Bob measures the received state in the α basis or ω basis and obtains the binary bit s or j is where α, ω ∈ {X, Y, Z}, s, j ∈ {0, 1}; P jω,vir is the probability that Alice sends virtual system A or B, k is the probability that the receiver chooses to measure in the ω basis, q sα|t represents the transmission rate of σ t and σ t is the channel parameter.
3. The method for loss-tolerant reference-frame-independent quantum digital signature according to claim 2, wherein In step 2, the virtual phase bit error rate e αω is for measurement of the result after where αω ∈ {XX, XY, YX, YY}, is the joint probability when Alice or Bob measures in the α basis or ω basis and obtains the binary bits s or j, s, j ∈ {0, 1}.
4. The loss-tolerant reference-frame independent quantum digital signature method according to claim 1, wherein The minimum entropy in the KGP process in the presence of an eavesdropper Eve is as follows: where is the binary Shannon function, satisfying H(x) = -x log2(x) - (1 - x) log2(1 - x), ε is the failure probability for parameter estimation, Z represents the Z basis, E represents the eavesdropper Eve, represents the lower bound of the single - photon response count of the Z basis, I E represents the amount of information stolen by Eve: C E = (1 - 2e XX ) 2 + (1 - 2e XY ) 2 + (1 - 2e YX ) 2 + (1 - 2e YY ) 2 , wherein and are intermediate parameters, C E is the information statistic obtained by the eavesdropper; H is the binary Shannon entropy function, satisfying H(x) = -x log2(x) - (1 - x) log2(1 - x).
5. The loss-tolerant reference-frame independent quantum digital signature method according to claim 4, wherein In the presence of an eavesdropper Eve, the minimum bit error rate p caused by Eve's information theft e Satisfies:
Citation Information
Patent Citations
Quantum digital signature method based on double-field protocol
CN111541544A
Quantum digital signature and quantum digital signcryption method
CN113779645A