Data synchronization method, key generation method and device in key generation in qkd device
By replacing inconsistent sifted key and final key data with equal amounts of random numbers in the QKD device and adding a marker before the final key data output, the problem of attackers tampering with data synchronization is solved, ensuring the stability of the quantum key generation process and the normal operation of the key management system.
Patent Information
- Application Number
- CN202111002393.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-08-30
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2041-08-30
AI Technical Summary
In existing quantum key distribution (QKD) devices, attackers can tamper with the data synchronization process, causing the sifted key and final key data to become out of sync, resulting in error correction failure and chaos in the key management system.
Within the QKD device, based on hash value comparison, inconsistent Found key and Final key data are replaced with an equal amount of random numbers, and a mark is added before the Final key data is output to prevent data from being misled as inconsistent, thus ensuring the stability of the data synchronization and error correction process.
It effectively prevents attackers from misleading data synchronization, ensures data consistency within QKD devices, avoids chaos in the key management system, and improves the robustness of the system and the stability of data processing.
Smart Images

Figure CN115733604B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication and information security technology, and in particular to a method for data synchronization during the key generation process within a QKD device. Background Technology
[0002] Quantum key distribution (QKD) technology enables two communicating parties to generate and share a random, secure key for encrypting and decrypting information by transmitting quantum state optical pulse signals. The BB84 protocol based on decoy states is the most mature and widely used quantum key distribution protocol to date, and its operation process is as follows: Figure 1 As shown, from Figure 1 As can be seen from this, the key generation process includes:
[0003] Alice and Bob establish a classical network connection via a classical channel. Alice then prepares quantum photons according to the BB84 protocol and transmits them to Bob via the quantum channel. Bob then detects the quantum photons. Next, Alice and Bob perform basis vector comparison according to the BB84 protocol, extracting the sifted key with consistent basis vectors. Then, an error correction algorithm is used to correct the sifted key with some errors at both ends and negotiate to reach a consensus. At this point, both ends obtain the corrected key. Then, both ends enhance the confidentiality of the corrected key to eliminate information leakage introduced in the previous steps. Both ends obtain the final key, which is finally output to the key management system for use by the final key user.
[0004] During the generation of these process data, the QKD devices at both ends need to use a classical data channel to match and synchronize the sifted key and final key process data, so that the quantum key data generated by both ends are consistent after error correction and security enhancement.
[0005] Patent application CN 106161012 A discloses a post-processing system and method for quantum key distribution based on polar code error correction, aiming to reduce the computational delay introduced by the post-processing from the sieved key to the final key, thereby improving the generation rate of quantum secure keys. Patent application CN 109274480 A discloses a data authentication method and quantum key distribution system based on the HMAC-SM3 algorithm. The hash value obtained using the HMAC-SM3 algorithm has higher security and is not easily cracked during transmission, improving the accuracy of data integrity authentication. Patent application CN109274484 A discloses a method for enhancing the confidentiality of data and a quantum key distribution terminal, applicable to quantum key distribution (QKD) terminals for enhancing the confidentiality of corrected key data, improving the security of the enhanced data.
[0006] The patent applications mentioned above concern the rate and security of quantum key distribution, not data synchronization. The following describes existing sifted key synchronization procedures and existing final key synchronization procedures.
[0007] 1) Existing Sifted key synchronization process
[0008] Existing technical solutions do not authenticate the sifted key data itself. Instead, they authenticate the data integrity of the network interaction data during the basis vector comparison process that generates the sifted key. If the data integrity authentication passes, it is assumed that the basis vector comparison process has not been tampered with, the sifted key data is saved, and the sifted key data blocks at both ends are considered synchronized. The detailed process is shown in Table 1 below. Figure 2 .
[0009] Table 1. Explanation of basis vector alignment interaction data.
[0010]
[0011] Figure 2 The dashed box in the middle is a simplified diagram of data integrity authentication. Based on this process, the hash values obtained at both ends are compared to determine whether the sifted key should be saved. Afterwards, the synchronized sifted key data from both ends enters the error correction module, generating consistent corrected key data from both ends.
[0012] Note that the above hash value comparison generally employs data integrity protection. Private authentication keys are added to both ends during the hash value calculation and comparison result exchange process, preventing attackers from tampering with the comparison result undetected. However, if an attacker were to tamper with the final comparison result sent by Bob to Alice, changing it from "inconsistent comparison between the two ends" to "consistent comparison between the two ends," that is, modify the comparison result message frame from Bob to Alice (…), the attacker would be unable to detect the tampering. Figure 2 If the last step (arrow in the middle) damages its data integrity, Alice will consider the comparison result unreliable and discard the Sifted key.
[0013] The above sifted key data synchronization scheme has a problem: if an attacker tampers with the final comparison result Bob sends to Alice, changing it from "matching at both ends" to "mismatching at both ends," or modifies the comparison result message frame from Bob to Alice (…), then… Figure 2 If the final step (arrow in the image) compromises data integrity, Alice will consider the sifted key inconsistent (or the comparison result unreliable) and discard it, while Bob will retain his own sifted key, causing the sifted key data at both ends to be out of sync. Furthermore, since QKD generates keys from random light emission and detection, the size of the sifted key data blocks generated each time is inconsistent, leading to a complete misalignment of the sifted key data at both ends in subsequent data processing. This makes it very difficult to resynchronize them in subsequent data processing, and the QKD device will be unable to generate symmetric quantum keys.
[0014] 2) Existing Final key synchronization process
[0015] Regarding the final key data, after the confidentiality enhancement process, Alice and Bob will calculate the hash value of their own final key data and compare them interactively. If the hash values match, the final key data is retained; otherwise, it is discarded. The flowchart is as follows: Figure 3 As shown:
[0016] This scheme suffers from the same problem as Sifted key data synchronization: if an attacker tampers with the final step of Bob's comparison result sent to Alice, changing it from "matching at both ends" to "mismatching at both ends," or modifies the comparison result message frame from Bob to Alice (…), the problem persists. Figure 3If the final step (arrow in the middle) compromises data integrity, Alice will consider the Final key inconsistent (or the comparison result unreliable) and discard it, while Bob will retain his Final key and output it normally to the next-level management device receiving the QKD output key, resulting in a desynchronization of the Final key data between the two ends. Since the Final key is the last step before the QKD device outputs the key, this desynchronization will affect the management device receiving the QKD output key, potentially causing chaos in the key management system.
[0017] The existing sifted key and final key data synchronization schemes have a problem: attackers can tamper with the comparison results sent by Bob to Alice in the last step of the synchronization process, changing it from "matching at both ends" to "not matching at both ends", or modify the comparison result message frame to destroy its data integrity. In this case, Alice will discard its own data, while Bob will retain its own data, resulting in data desynchronization between the two ends.
[0018] Asynchronous sifted key data will cause complete misalignment of intermediate key data within the QKD device. Subsequent error correction modules will be unable to correct the misaligned sifted key data at both ends, resulting in no corrected key data being generated and preventing the QKD device from generating quantum keys. Furthermore, misalignment of the final key data at both ends will affect the management device receiving the QKD output key, potentially causing chaos in the key management system. Summary of the Invention
[0019] The technical problem to be solved by this invention is how to avoid the inability to generate quantum keys or the chaos in the key management system due to inconsistent data synchronization.
[0020] The present invention solves the above-mentioned technical problems through the following technical means: a sifted key synchronization method in the key generation process of a QKD device, wherein the sifted key synchronization occurs during the quantum key distribution process, when the Alice-end QKD device generates a sifted key with a certain error ratio during the basis vector comparison stage with the Bob-end QKD device;
[0021] When the basis vectors of Alice's QKD device match those of Bob's QKD device, the sifted key data from both ends is retained; if the matching does not match, the sifted key data is replaced with an equal amount of random numbers.
[0022] This invention addresses the Sifted key data generated by the basis vector comparison process at both ends of the QKD device. When determining the usability of Sifted key data based on the data integrity authentication result (Hash comparison process) of the basis vector comparison network interaction data, Sifted key data with inconsistent Hash comparisons is not directly discarded. Instead, it is replaced with an equal amount of local random numbers and output to the subsequent error correction process. This prevents attackers from launching misleading attacks on the Sifted key data synchronization process, preventing the data that should be synchronized at both ends from being misled into being inconsistent, thereby causing data to be erroneously discarded at one end and resulting in data desynchronization between the two ends.
[0023] As an optimized technical solution, the random number is provided by a local noise source.
[0024] As an optimized technical solution, the basis vector alignment process is as follows:
[0025] Step S21: Bob sends the original probe basis information B1 to Alice.
[0026] Step S22: Alice performs basis vector comparison to obtain basis vector comparison result A1, generates Siftedkey to be synchronized, and sends basis vector comparison result A1 to Bob. At the same time, Alice calculates the detection rate information A2 based on the original detection basis vector information B1 sent by Bob and sends the detection rate information A2 to Bob.
[0027] Step S23: Bob receives the basis comparison result A1 sent by Alice, performs basis comparison, evaluates the error rate of the signal state and the decoy state based on the basis comparison result A1, obtains the error rate information B2 of the signal state and the decoy state, Bob receives the detection rate information A2 sent by Alice and saves it, and Bob generates the Sifted key to be synchronized.
[0028] Step S24: Bob sends error rate information B2 of the signal state and decoy state to Alice.
[0029] Step S25: Alice receives and saves the error rate information B2 of the signal state and the decoy state;
[0030] Step S26: Alice calculates the hash value of (A1+A2+B1+B2) to obtain the first hash value, and sends the first hash value to Bob.
[0031] Step S27: Bob calculates the hash value of (A1+A2+B1+B2) to obtain the second hash value, and compares it with the first hash value to generate the first comparison result. The first comparison result is either "matching" or "matching inconsistent", and the first comparison result is sent to Alice.
[0032] Step S28: Alice receives the second comparison result;
[0033] Step S29: If the first comparison result is "matching", Bob's end retains the Sifted key; if the first comparison result is "mismatching", Bob's end replaces the Sifted key with an equal amount of random numbers. If the second comparison result is "matching", Alice's end retains the Sifted key; if the second comparison result is "mismatching", Alice's end replaces the Sifted key with an equal amount of random numbers.
[0034] The present invention also provides a quantum key generation method employing the sifted key synchronization method in the key generation process of the QKD device described in any of the above schemes, comprising the following steps:
[0035] Step S1: Alice and Bob establish a classical network connection through a classical channel. Alice prepares quantum photons according to the BB84 protocol and transmits the prepared quantum photons to Bob through the quantum channel. Bob then detects the quantum photons.
[0036] Step S2: Alice and Bob complete the basis alignment process according to the BB84 protocol and extract the sifted key with consistent basis vectors.
[0037] Step S3: Use an error correction algorithm to correct the errors in the sifted key at both ends and negotiate to reach a consensus. At this point, both ends obtain the corrected key. In this step, if the basis vector comparison in step S2 results in an "inconsistent comparison", the replacement random number will be different from the real sifted key obtained by the consistent comparison. The sifted key data blocks at both ends will fail to correct the error in this error correction step and will be discarded.
[0038] Step S4: Both ends enhance the security of the Corrected key, and both ends obtain the Final key, which is then output to the key management system for use by the final key user.
[0039] The present invention also provides a quantum key generation device employing the sifted key synchronization method in the QKD device key generation process described in any of the above schemes, comprising the following modules:
[0040] A detection module is prepared to perform the following steps: Alice and Bob establish a classical network connection through a classical channel. Alice prepares quantum photons according to the BB84 protocol and transmits the prepared quantum photons to Bob through a quantum channel. Bob then completes the detection of the quantum photons.
[0041] The basis vector alignment module is used to perform the following steps: Alice and Bob complete the basis vector alignment process according to the BB84 protocol and extract the sifted key with consistent basis vectors;
[0042] The error correction module is used to perform the following steps: use an error correction algorithm to correct the sifted key with certain errors at both ends and negotiate to reach a consensus. At this time, both ends obtain the corrected key. In this step, if the basis vector comparison results in "inconsistent comparison", the replacement random number is different from the real sifted key obtained by the consistent comparison. The sifted key data blocks at both ends will fail to correct the error in this error correction step and be discarded.
[0043] The security enhancement module performs the following steps: both ends enhance the security of the corrected key, both ends obtain the final key, and finally output it to the key management system for use by the final key user.
[0044] The present invention also provides a final key synchronization method for the key generation process within a QKD device. This final key synchronization process occurs during the quantum key distribution process, when the Alice-side QKD device and the Bob-side QKD device are generating the final key.
[0045] When Alice's QKD device compares the hash value of the final key with that of Bob's QKD device, if the comparison matches, the final key data of each device is output normally; if the comparison does not match, the final key data of this device is marked and then output.
[0046] As an optimized technical solution, the marker is a "discrepancy" marker.
[0047] As an optimized technical solution, the synchronization process before Final key output is as follows:
[0048] Alice calculates the hash value of the final key, obtains the third hash value, and sends it to Bob.
[0049] Bob calculates the hash value of the final key, obtains the fourth hash value, compares it with the third hash value and the fourth hash value, generates the third comparison result, and sends the third comparison result to Alice.
[0050] Alice receives the fourth comparison result. Due to the possibility of an attack, the fourth comparison result is either "matched" or "inconsistent". The fourth comparison result may be different from the third comparison result.
[0051] If the third alignment result is "matching", Bob's end will output the final key normally. If the third alignment result is "mismatching", Bob's end will mark the final key and output it. If the fourth alignment result is "matching", Alice's end will output the final key normally. If the fourth alignment result is "mismatching", Alice's end will mark the final key and output it.
[0052] The present invention also provides a quantum key generation method employing the final key synchronization method of the key generation process within a QKD device as described in any of the above schemes, comprising the following steps:
[0053] Step S1: Alice and Bob establish a classical network connection through a classical channel. Alice prepares quantum photons according to the BB84 protocol and transmits the prepared quantum photons to Bob through the quantum channel. Bob then detects the quantum photons.
[0054] Step S2: Alice and Bob complete the basis alignment process according to the BB84 protocol and extract the sifted key with consistent basis vectors.
[0055] Step S3: Use an error correction algorithm to correct the errors in the False keys at both ends and negotiate to reach a consensus. At this point, both ends obtain the Corrected key.
[0056] Step S4: Both ends enhance the security of the Corrected key, and both ends obtain the Final key, which is then output to the key management system for use by the final key user.
[0057] The present invention also provides a quantum key generation device employing the final key synchronization method for the key generation process within a QKD device as described in any of the above schemes, comprising the following modules:
[0058] A detection module is prepared to perform the following steps: Alice and Bob establish a classical network connection through a classical channel. Alice prepares quantum photons according to the BB84 protocol and transmits the prepared quantum photons to Bob through a quantum channel. Bob then completes the detection of the quantum photons.
[0059] The basis vector alignment module is used to perform the following steps: Alice and Bob complete the basis vector alignment process according to the BB84 protocol and extract the sifted key with consistent basis vectors;
[0060] The error correction module performs the following steps: using an error correction algorithm to correct the sifted key with certain errors at both ends and negotiating to reach a consensus. At this point, both ends obtain the corrected key.
[0061] The security enhancement module performs the following steps: both ends enhance the security of the corrected key, both ends obtain the final key, and finally output it to the key management system for use by the final key user.
[0062] This invention addresses the security enhancement of Final key data between two QKD devices. When determining the usability of Final key data based on the Hash comparison process, Final key data with inconsistent Hash comparisons is not directly discarded. Instead, an "inconsistent" flag is added and output to the management device that subsequently receives the QKD output key. This prevents attackers from launching misleading attacks during the Final key data synchronization process, preventing data that should be synchronized at both ends from being mistakenly considered inconsistent, thus avoiding the problem of data being erroneously discarded at one end and causing data asynchrony between the two ends, and avoiding chaos in the key management system.
[0063] The present invention also provides a method for generating quantum keys within a QKD device, comprising the following steps:
[0064] Step S1: Alice and Bob establish a classical network connection through a classical channel. Alice prepares quantum photons according to the BB84 protocol and transmits the prepared quantum photons to Bob through the quantum channel. Bob then detects the quantum photons.
[0065] Step S2: Alice and Bob complete the basis vector alignment process according to the BB84 protocol, and extract the sifted key with consistent basis vectors. The basis vector alignment process is as follows:
[0066] Step S21: Bob sends the original probe basis information B1 to Alice.
[0067] Step S22: Alice performs basis vector comparison to obtain basis vector comparison result A1, generates Siftedkey to be synchronized, and sends basis vector comparison result A1 to Bob. At the same time, Alice calculates the detection rate information A2 based on the original detection basis vector information B1 sent by Bob and sends the detection rate information A2 to Bob.
[0068] Step S23: Bob receives the basis comparison result A1 sent by Alice, performs basis comparison, evaluates the error rate of the signal state and the decoy state based on the basis comparison result A1, obtains the error rate information B2 of the signal state and the decoy state, Bob receives the detection rate information A2 sent by Alice and saves it, and Bob generates the Sifted key to be synchronized.
[0069] Step S24: Bob sends error rate information B2 of the signal state and decoy state to Alice.
[0070] Step S25: Alice receives and saves the error rate information B2 of the signal state and the decoy state;
[0071] Step S26: Alice calculates the hash value of (A1+A2+B1+B2) to obtain the first hash value, and sends the first hash value to Bob.
[0072] Step S27: Bob calculates the hash value of (A1+A2+B1+B2) to obtain the second hash value, and compares it with the first hash value to generate the first comparison result. The first comparison result is either "matching" or "matching inconsistent", and the first comparison result is sent to Alice.
[0073] Step S28: Alice receives the second comparison result;
[0074] Step S29: If the first comparison result is "matching", Bob's end retains the Sifted key; if the first comparison result is "mismatching", Bob's end replaces the Sifted key with an equal amount of random numbers. If the second comparison result is "matching", Alice's end retains the Sifted key; if the second comparison result is "mismatching", Alice's end replaces the Sifted key with an equal amount of random numbers.
[0075] Step S3: Use an error correction algorithm to correct the errors in the sifted key at both ends and negotiate to reach a consensus. At this time, both ends obtain the corrected key. In this step, if the basis vector comparison in step S29 results in an "inconsistent comparison", the replacement random number is different from the real sifted key obtained by the consistent comparison. The sifted key data blocks at both ends will fail to correct the error in this error correction step and will be discarded.
[0076] Step S4: Both ends enhance the security of the Corrected key, and both ends obtain the Final key. Finally, the Final key is output to the key management system for use by the final key user. The synchronization process before the Final key is output is as follows:
[0077] Alice calculates the hash value of the final key, obtains the third hash value, and sends it to Bob.
[0078] Bob calculates the hash value of the final key, obtains the fourth hash value, compares it with the third hash value and the fourth hash value, generates the third comparison result, and sends the third comparison result to Alice.
[0079] Alice receives the fourth comparison result. Due to the possibility of an attack, the fourth comparison result is either "matched" or "inconsistent". The fourth comparison result may be different from the third comparison result.
[0080] If the third alignment result is "matching", Bob's end will output the final key normally. If the third alignment result is "mismatching", Bob's end will mark the final key and output it. If the fourth alignment result is "matching", Alice's end will output the final key normally. If the fourth alignment result is "mismatching", Alice's end will mark the final key and output it.
[0081] The present invention also provides a quantum key generation device within a QKD device, comprising the following modules:
[0082] A detection module is prepared to perform the following steps: Alice and Bob establish a classical network connection through a classical channel. Alice prepares quantum photons according to the BB84 protocol and transmits the prepared quantum photons to Bob through a quantum channel. Bob then completes the detection of the quantum photons.
[0083] The basis vector alignment module performs the following steps: Alice and Bob complete the basis vector alignment process according to the BB84 protocol, and extract the sifted key with consistent basis vectors. The basis vector alignment process is as follows:
[0084] Step S21: Bob sends the original probe basis information B1 to Alice.
[0085] Step S22: Alice performs basis vector comparison to obtain basis vector comparison result A1, generates Siftedkey to be synchronized, and sends basis vector comparison result A1 to Bob. At the same time, Alice calculates the detection rate information A2 based on the original detection basis vector information B1 sent by Bob and sends the detection rate information A2 to Bob.
[0086] Step S23: Bob receives the basis comparison result A1 sent by Alice, performs basis comparison, evaluates the error rate of the signal state and the decoy state based on the basis comparison result A1, obtains the error rate information B2 of the signal state and the decoy state, Bob receives the detection rate information A2 sent by Alice and saves it, and Bob generates the Sifted key to be synchronized.
[0087] Step S24: Bob sends error rate information B2 of the signal state and decoy state to Alice.
[0088] Step S25: Alice receives and saves the error rate information B2 of the signal state and the decoy state;
[0089] Step S26: Alice calculates the hash value of (A1+A2+B1+B2) to obtain the first hash value, and sends the first hash value to Bob.
[0090] Step S27: Bob calculates the hash value of (A1+A2+B1+B2) to obtain the second hash value, and compares it with the first hash value to generate the first comparison result. The first comparison result is either "matching" or "matching inconsistent", and the first comparison result is sent to Alice.
[0091] Step S28: Alice receives the second comparison result;
[0092] Step S29: If the first comparison result is "matching", Bob's end retains the Sifted key; if the first comparison result is "mismatching", Bob's end replaces the Sifted key with an equal amount of random numbers. If the second comparison result is "matching", Alice's end retains the Sifted key; if the second comparison result is "mismatching", Alice's end replaces the Sifted key with an equal amount of random numbers.
[0093] The error correction module is used to perform the following steps: using an error correction algorithm to correct the sifted key with certain errors at both ends and negotiate to reach a consensus. At this time, both ends obtain the corrected key. In this step, if the basis vector comparison in step S29 results in an "inconsistent comparison", the replacement random number is different from the real sifted key obtained by the consistent comparison. The sifted key data blocks at both ends will fail to correct the error in this error correction step and be discarded.
[0094] The security enhancement module performs the following steps: both ends enhance the security of the Corrected key, both ends obtain the Final key, and finally output it to the key management system for use by the final key user. The synchronization process before the Final key is output is as follows:
[0095] Alice calculates the hash value of the final key, obtains the third hash value, and sends it to Bob.
[0096] Bob calculates the hash value of the final key, obtains the fourth hash value, compares it with the third hash value and the fourth hash value, generates the third comparison result, and sends the third comparison result to Alice.
[0097] Alice receives the fourth comparison result. Due to the possibility of an attack, the fourth comparison result is either "matched" or "inconsistent". The fourth comparison result may be different from the third comparison result.
[0098] If the third alignment result is "matching", Bob's end will output the final key normally. If the third alignment result is "mismatching", Bob's end will mark the final key and output it. If the fourth alignment result is "matching", Alice's end will output the final key normally. If the fourth alignment result is "mismatching", Alice's end will mark the final key and output it.
[0099] In summary, the advantages of this invention are:
[0100] 1. This application can prevent attackers from launching misleading attacks on the synchronization process of Sifted key and Final key data, preventing the data that should be synchronized at both ends from being misled into being inconsistent, thereby causing data to be erroneously discarded at one end and causing the data at both ends to be out of sync, thus avoiding chaos in the key management system.
[0101] 2. By adopting this improved solution, the data processing of QKD devices can be made more robust. If an occasional error occurs in the synchronization process of Sifted key and Final key data caused by non-attacks within the QKD device, the QKD device still has the ability to automatically correct it, ensuring that the internal data flow of QKD is restored normally and QKD services do not need to be interrupted and restarted.
[0102] 3. This technical solution is not limited to any particular platform and can be applied to ARM, CPU, or other computing chips, making it widely applicable. Attached Figure Description
[0103] Figure 1 This is a flowchart of the existing deceptive BB84 protocol operation;
[0104] Figure 2 It is the existing BB84 protocol runtime basis vector comparison data interaction and Sifted key synchronization graph;
[0105] Figure 3 This is a diagram showing the synchronization of Final key data after enhanced security during runtime of the existing BB84 protocol.
[0106] Figure 4 This is the basis vector alignment data interaction and Sifted key synchronization diagram of the improved part of Embodiment 1 of the present invention;
[0107] Figure 5 This is a diagram of the BB84 protocol runtime basis vector comparison data interaction and Sifted key synchronization in Embodiment 1 of the present invention.
[0108] Figure 6 This is a diagram showing the final key data synchronization after enhanced security during BB84 protocol runtime, according to Embodiment 2 of the present invention. Detailed Implementation
[0109] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0110] This invention designs a new synchronization mechanism, the core of which is to no longer discard Sectedkey and Final key data with inconsistent hash values. Through different processing mechanisms, it ensures that the intermediate key data in the QKD device is not misaligned, and provides a marker during the Final key data output stage to inform the management device receiving the QKD output key which key data has problems, thereby reducing the impact on the key management system.
[0111] Example 1
[0112] This embodiment discloses an improved sifted key synchronization process, which occurs during the quantum key distribution process, when the Alice-end QKD device generates a sieved key with a certain error ratio during the basis vector comparison stage with the Bob-end QKD device.
[0113] like Figure 4 As shown, the improved synchronization mechanism is as follows: when the basis vectors of Alice's QKD device and Bob's QKD device are consistent, the Sifted key data of both ends is retained; when the comparison is inconsistent, the Sifted key data is replaced with an equal amount of random numbers. The random numbers are provided by a local noise source, so it can be guaranteed that if both ends replace the Sifted key data with an equal amount of random numbers at the same time, the data after replacement at both ends will be different.
[0114] By adopting this improved synchronization measure, if an attacker were to launch another attack, they could tamper with the comparison result Bob sends to Alice in the final step of the synchronization process. For example, changing the result from "matching at both ends" to "mismatching at both ends," Alice's end will no longer discard its own Sifted key data block. Instead, it will replace it with an equal amount of random numbers to prevent Alice from discarding its own data due to mismatch, while Bob's end retains its own data due to a match, causing data desynchronization between the two ends. Similarly, if the comparison result changes from "mismatching at both ends" to "matching at both ends" due to an attack, the handling method is similar. Bob's end will no longer discard its own Sifted key data block, but will replace it with an equal amount of random numbers to prevent Bob from discarding its own data due to mismatch, while Alice's end retains its own data due to a match, causing data desynchronization between the two ends.
[0115] Since the difference between the random number and the actual sifted key obtained by comparison is around 50%, which exceeds the error correction capability of the error correction algorithm in the error correction stage (generally, the error correction capability of the error correction algorithm in QKD does not exceed 11%), the sifted key data blocks at both ends will be discarded if the error correction fails in the subsequent error correction steps of the quantum key distribution process, so as not to cause the subsequent sifted key data to be completely misaligned.
[0116] This embodiment also discloses a complete key generation method using the above-described Sifted key synchronization process, the process of which is as follows:
[0117] Step S1: Alice and Bob establish a classical network connection through a classical channel. Alice prepares quantum photons according to the BB84 protocol and transmits the prepared quantum photons to Bob through the quantum channel. Bob then detects the quantum photons.
[0118] Step S2: Alice and Bob complete the basis vector comparison process according to the BB84 protocol, and extract the sifted key with consistent basis vectors, such as... Figure 5 As shown, the specific basis vector alignment process is as follows:
[0119] Step S21: Bob sends the original probe basis information B1 to Alice.
[0120] Step S22: Alice performs basis vector comparison to obtain basis vector comparison result A1, generates Siftedkey to be synchronized, and sends basis vector comparison result A1 to Bob. At the same time, Alice calculates the detection rate information A2 based on the original detection basis vector information B1 sent by Bob and sends the detection rate information A2 to Bob.
[0121] Step S23: Bob receives the basis comparison result A1 sent by Alice, performs basis comparison, evaluates the error rate of the signal state and the decoy state based on the basis comparison result A1, obtains the error rate information B2 of the signal state and the decoy state, Bob receives the detection rate information A2 sent by Alice and saves it, and Bob generates the Sifted key to be synchronized.
[0122] Step S24: Bob sends error rate information B2 of the signal state and decoy state to Alice.
[0123] Step S25: Alice receives and saves the error rate information B2 of the signal state and the decoy state;
[0124] Step S26: Alice calculates the hash value of (A1+A2+B1+B2) to obtain the first hash value, and sends the first hash value to Bob.
[0125] Step S27: Bob calculates the hash value of (A1+A2+B1+B2) to obtain the second hash value, and compares it with the first hash value to generate the first comparison result. The first comparison result is either "matching" or "matching inconsistent", and the first comparison result is sent to Alice.
[0126] Step S28: Alice receives the second comparison result. Due to the possibility of attack, the second comparison result is either "matching" or "matching". The second comparison result may be different from the first comparison result.
[0127] Step S29: If the first comparison result is "matching", Bob's end retains the Sifted key; if the first comparison result is "mismatching", Bob's end replaces the Sifted key with an equal amount of random numbers. If the second comparison result is "matching", Alice's end retains the Sifted key; if the second comparison result is "mismatching", Alice's end replaces the Sifted key with an equal amount of random numbers.
[0128] Step S3: Use an error correction algorithm to correct the erroneous sifted key at both ends and negotiate to reach a consensus. At this point, both ends obtain the corrected key. In this step, if a "comparison discrepancy" occurs in step S29, the difference between the replaced random number and the real sifted key obtained from the comparison will be around 50%, which exceeds the error correction capability of the error correction algorithm. Therefore, the sifted key data blocks at both ends will fail to correct the error in this error correction step and be discarded, so as not to cause the subsequent sifted key data to be completely misaligned.
[0129] Step S4: Both ends enhance the confidentiality of the Corrected key to eliminate information leakage introduced in the previous steps. Both ends obtain the final key and finally output it to the key management system for use by the final key user.
[0130] This embodiment also discloses a quantum key generation device employing the sifted key synchronization method in the key generation process of the QKD device described above, comprising the following modules:
[0131] A detection module is prepared to perform the following steps: Alice and Bob establish a classical network connection through a classical channel. Alice prepares quantum photons according to the BB84 protocol and transmits the prepared quantum photons to Bob through a quantum channel. Bob then completes the detection of the quantum photons.
[0132] The basis vector alignment module is used to perform the following steps: Alice and Bob complete the basis vector alignment process according to the BB84 protocol and extract the sifted key with consistent basis vectors;
[0133] The error correction module is used to perform the following steps: use an error correction algorithm to correct the sifted key with certain errors at both ends and negotiate to reach a consensus. At this time, both ends obtain the corrected key. In this step, if the basis vector comparison results in "inconsistent comparison", the replacement random number is different from the real sifted key obtained by the consistent comparison. The sifted key data blocks at both ends will fail to correct the error in this error correction step and be discarded.
[0134] The security enhancement module performs the following steps: both ends enhance the security of the corrected key, both ends obtain the final key, and finally output it to the key management system for use by the final key user.
[0135] Example 2
[0136] This embodiment discloses an improved Final key synchronization process that occurs during quantum key distribution when the Alice-side QKD device and the Bob-side QKD device generate the final key.
[0137] like Figure 6 As shown, the improved synchronization mechanism is as follows: When Alice's QKD device compares the hash value of the final key with that of Bob's QKD device, if the comparison matches, the final key data of each device is output normally; if the comparison does not match, the final key data of this device is marked as "inconsistent" and then output.
[0138] By employing this improved synchronization measure, if an attacker were to launch another attack, they could tamper with the comparison result Bob sends to Alice in the final step of the synchronization process. For example, changing the result from "matching at both ends" to "matching at both ends is inconsistent," Alice would no longer discard its own Final key data block but instead output Final key data marked "inconsistent." Alternatively, if the attacker were to launch another attack, they could tamper with the comparison result Bob sends to Alice in the final step of the synchronization process, changing it from "matching at both ends is inconsistent" to "matching at both ends," Bob would no longer discard its own Final key data block but instead output Final key data marked "inconsistent." In this way, the management devices receiving the QKD output keys at both ends will at least synchronously receive the same amount of Final key data, instead of one end having data while the other end lacks synchronized data, thus reducing potential chaos in the key management system.
[0139] This embodiment also discloses a complete key generation method using the above-described Final key synchronization process, the process of which is as follows:
[0140] Step S1: Alice and Bob establish a classical network connection through a classical channel. Alice prepares quantum photons according to the BB84 protocol and transmits the prepared quantum photons to Bob through the quantum channel. Bob then detects the quantum photons.
[0141] In step S2, Alice and Bob complete the basis comparison process according to the BB84 protocol and extract the sifted key with consistent basis vectors.
[0142] Step S3: Use an error correction algorithm to correct the False key with certain errors at both ends and negotiate to reach a consensus. At this point, both ends obtain the corrected key.
[0143] Step S4: Both ends enhance the confidentiality of the Corrected key to eliminate information leakage introduced in previous steps. Both ends obtain the final key, which is then output to the key management system for use by the final key user. The synchronization process before the final key is output in this step is as follows:
[0144] Alice calculates the hash value of the final key, obtains the third hash value, and sends it to Bob.
[0145] Bob calculates the hash value of the final key, obtains the fourth hash value, compares it with the third hash value and the fourth hash value, generates the third comparison result, and sends the third comparison result to Alice.
[0146] Alice receives the fourth comparison result. Due to the possibility of an attack, the fourth comparison result is either "matched" or "inconsistent". The fourth comparison result may be different from the third comparison result.
[0147] If the third alignment result is "matching", Bob's end will output the final key normally. If the third alignment result is "mismatching", Bob's end will mark the final key and output it. If the fourth alignment result is "matching", Alice's end will output the final key normally. If the fourth alignment result is "mismatching", Alice's end will mark the final key and output it.
[0148] The above marker can be an "inconsistent" marker.
[0149] This embodiment also discloses a quantum key generation device employing the aforementioned final key synchronization method for the key generation process within a QKD device, comprising the following modules:
[0150] A detection module is prepared to perform the following steps: Alice and Bob establish a classical network connection through a classical channel. Alice prepares quantum photons according to the BB84 protocol and transmits the prepared quantum photons to Bob through a quantum channel. Bob then completes the detection of the quantum photons.
[0151] The basis vector alignment module is used to perform the following steps: Alice and Bob complete the basis vector alignment process according to the BB84 protocol and extract the sifted key with consistent basis vectors;
[0152] The error correction module performs the following steps: using an error correction algorithm to correct the sifted key with certain errors at both ends and negotiating to reach a consensus. At this point, both ends obtain the corrected key.
[0153] The security enhancement module performs the following steps: both ends enhance the security of the corrected key, both ends obtain the final key, and finally output it to the key management system for use by the final key user.
[0154] Example 3
[0155] This embodiment discloses a quantum key generation method within a QKD device, comprising the following steps:
[0156] Step S1: Alice and Bob establish a classical network connection through a classical channel. Alice prepares quantum photons according to the BB84 protocol and transmits the prepared quantum photons to Bob through the quantum channel. Bob then detects the quantum photons.
[0157] Step S2: Alice and Bob complete the basis vector alignment process according to the BB84 protocol, and extract the sifted key with consistent basis vectors. The basis vector alignment process is as follows:
[0158] Step S21: Bob sends the original probe basis information B1 to Alice.
[0159] Step S22: Alice performs basis vector comparison to obtain basis vector comparison result A1, generates Siftedkey to be synchronized, and sends basis vector comparison result A1 to Bob. At the same time, Alice calculates the detection rate information A2 based on the original detection basis vector information B1 sent by Bob and sends the detection rate information A2 to Bob.
[0160] Step S23: Bob receives the basis comparison result A1 sent by Alice, performs basis comparison, evaluates the error rate of the signal state and the decoy state based on the basis comparison result A1, obtains the error rate information B2 of the signal state and the decoy state, Bob receives the detection rate information A2 sent by Alice and saves it, and Bob generates the Sifted key to be synchronized.
[0161] Step S24: Bob sends error rate information B2 of the signal state and decoy state to Alice.
[0162] Step S25: Alice receives and saves the error rate information B2 of the signal state and the decoy state;
[0163] Step S26: Alice calculates the hash value of (A1+A2+B1+B2) to obtain the first hash value, and sends the first hash value to Bob.
[0164] Step S27: Bob calculates the hash value of (A1+A2+B1+B2) to obtain the second hash value, and compares it with the first hash value to generate the first comparison result. The first comparison result is either "matching" or "matching inconsistent", and the first comparison result is sent to Alice.
[0165] Step S28: Alice receives the second comparison result;
[0166] Step S29: If the first comparison result is "matching", Bob's end retains the Sifted key; if the first comparison result is "mismatching", Bob's end replaces the Sifted key with an equal amount of random numbers. If the second comparison result is "matching", Alice's end retains the Sifted key; if the second comparison result is "mismatching", Alice's end replaces the Sifted key with an equal amount of random numbers.
[0167] Step S3: Use an error correction algorithm to correct the errors in the sifted key at both ends and negotiate to reach a consensus. At this time, both ends obtain the corrected key. In this step, if the basis vector comparison in step S29 results in an "inconsistent comparison", the replacement random number is different from the real sifted key obtained by the consistent comparison. The sifted key data blocks at both ends will fail to correct the error in this error correction step and will be discarded.
[0168] Step S4: Both ends enhance the security of the Corrected key, and both ends obtain the Final key. Finally, the Final key is output to the key management system for use by the final key user. The synchronization process before the Final key is output is as follows:
[0169] Alice calculates the hash value of the final key, obtains the third hash value, and sends it to Bob.
[0170] Bob calculates the hash value of the final key, obtains the fourth hash value, compares it with the third hash value and the fourth hash value, generates the third comparison result, and sends the third comparison result to Alice.
[0171] Alice receives the fourth comparison result. Due to the possibility of an attack, the fourth comparison result is either "matched" or "inconsistent". The fourth comparison result may be different from the third comparison result.
[0172] If the third alignment result is "matching", Bob's end will output the final key normally. If the third alignment result is "mismatching", Bob's end will mark the final key and output it. If the fourth alignment result is "matching", Alice's end will output the final key normally. If the fourth alignment result is "mismatching", Alice's end will mark the final key and output it.
[0173] This embodiment also provides a quantum key generation device, including the following modules:
[0174] A detection module is prepared to perform the following steps: Alice and Bob establish a classical network connection through a classical channel. Alice prepares quantum photons according to the BB84 protocol and transmits the prepared quantum photons to Bob through a quantum channel. Bob then completes the detection of the quantum photons.
[0175] The basis vector alignment module performs the following steps: Alice and Bob complete the basis vector alignment process according to the BB84 protocol, and extract the sifted key with consistent basis vectors. The basis vector alignment process is as follows:
[0176] Step S21: Bob sends the original probe basis information B1 to Alice.
[0177] Step S22: Alice performs basis vector comparison to obtain basis vector comparison result A1, generates Siftedkey to be synchronized, and sends basis vector comparison result A1 to Bob. At the same time, Alice calculates the detection rate information A2 based on the original detection basis vector information B1 sent by Bob and sends the detection rate information A2 to Bob.
[0178] Step S23: Bob receives the basis comparison result A1 sent by Alice, performs basis comparison, evaluates the error rate of the signal state and the decoy state based on the basis comparison result A1, obtains the error rate information B2 of the signal state and the decoy state, Bob receives the detection rate information A2 sent by Alice and saves it, and Bob generates the Sifted key to be synchronized.
[0179] Step S24: Bob sends error rate information B2 of the signal state and decoy state to Alice.
[0180] Step S25: Alice receives and saves the error rate information B2 of the signal state and the decoy state;
[0181] Step S26: Alice calculates the hash value of (A1+A2+B1+B2) to obtain the first hash value, and sends the first hash value to Bob.
[0182] Step S27: Bob calculates the hash value of (A1+A2+B1+B2) to obtain the second hash value, and compares it with the first hash value to generate the first comparison result. The first comparison result is either "matching" or "matching inconsistent", and the first comparison result is sent to Alice.
[0183] Step S28: Alice receives the second comparison result;
[0184] Step S29: If the first comparison result is "matching", Bob's end retains the Sifted key; if the first comparison result is "mismatching", Bob's end replaces the Sifted key with an equal amount of random numbers. If the second comparison result is "matching", Alice's end retains the Sifted key; if the second comparison result is "mismatching", Alice's end replaces the Sifted key with an equal amount of random numbers.
[0185] The error correction module is used to perform the following steps: using an error correction algorithm to correct the sifted key with certain errors at both ends and negotiate to reach a consensus. At this time, both ends obtain the corrected key. In this step, if the basis vector comparison in step S29 results in an "inconsistent comparison", the replacement random number is different from the real sifted key obtained by the consistent comparison. The sifted key data blocks at both ends will fail to correct the error in this error correction step and be discarded.
[0186] The security enhancement module performs the following steps: both ends enhance the security of the Corrected key, both ends obtain the Final key, and finally output it to the key management system for use by the final key user. The synchronization process before the Final key is output is as follows:
[0187] Alice calculates the hash value of the final key, obtains the third hash value, and sends it to Bob.
[0188] Bob calculates the hash value of the final key, obtains the fourth hash value, compares it with the third hash value and the fourth hash value, generates the third comparison result, and sends the third comparison result to Alice.
[0189] Alice receives the fourth comparison result. Due to the possibility of an attack, the fourth comparison result is either "matched" or "inconsistent". The fourth comparison result may be different from the third comparison result.
[0190] If the third alignment result is "matching", Bob's end will output the final key normally. If the third alignment result is "mismatching", Bob's end will mark the final key and output it. If the fourth alignment result is "matching", Alice's end will output the final key normally. If the fourth alignment result is "mismatching", Alice's end will mark the final key and output it.
[0191] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A sifted key synchronization method for the key generation process within a QKD device, characterized in that: The sifted key synchronization occurs during the quantum key distribution process, when the Alice-side QKD device generates the sifted key with a certain error ratio during the basis vector comparison stage with the Bob-side QKD device. When the hash values of all network interaction data during the basis vector comparison process between Alice's QKD device and Bob's QKD device match, the sifted key data at both ends is retained; when the comparison does not match, the sifted key data at the corresponding end is replaced with an equal amount of random numbers. The network interaction data includes the original probe basis information sent by the first QKD device to the second QKD device, the basis comparison result obtained by the second QKD device through basis comparison, the error rate information of the signal state and decoy state evaluated by the first QKD device based on the basis comparison result, and the detection rate information statistically obtained by the second QKD device based on the original probe basis information.
2. The sifted key synchronization method for the key generation process within a QKD device as described in claim 1, characterized in that: The random numbers are provided by a local noise source.
3. The sifted key synchronization method for the key generation process within a QKD device as described in claim 1, characterized in that: The basis vector alignment process is as follows: Step S21: Bob sends the original probe basis information B1 to Alice. Step S22: Alice performs basis vector comparison to obtain basis vector comparison result A1, generates a Sifted key to be synchronized, and sends the basis vector comparison result A1 to Bob. At the same time, Alice calculates the detection rate information A2 based on the original detection basis vector information B1 sent by Bob and sends the detection rate information A2 to Bob. Step S23: Bob receives the basis comparison result A1 sent by Alice, performs basis comparison, evaluates the error rate of the signal state and the decoy state based on the basis comparison result A1, obtains the error rate information B2 of the signal state and the decoy state, Bob receives the detection rate information A2 sent by Alice and saves it, and Bob generates the Sifted key to be synchronized. Step S24: Bob sends error rate information B2 of the signal state and decoy state to Alice. Step S25: Alice receives and saves the error rate information B2 of the signal state and the decoy state; Step S26: Alice calculates the hash value of (A1+A2+B1+B2) to obtain the first hash value, and sends the first hash value to Bob. Step S27: Bob calculates the hash value of (A1+A2+B1+B2) to obtain the second hash value, and compares it with the first hash value to generate the first comparison result. The first comparison result is either "matching" or "matching inconsistent", and the first comparison result is sent to Alice. Step S28: Alice receives the second comparison result; Step S29: If the first comparison result is "matching", Bob's end retains the Sifted key; if the first comparison result is "mismatching", Bob's end replaces the Sifted key with an equal amount of random numbers. If the second comparison result is "matching", Alice's end retains the Sifted key; if the second comparison result is "mismatching", Alice's end replaces the Sifted key with an equal amount of random numbers.
4. A quantum key generation method employing the sifted key synchronization method in the key generation process within a QKD device as described in any one of claims 1 to 3, characterized in that: Includes the following steps: Step S1: Alice and Bob establish a classical network connection through a classical channel. Alice prepares quantum photons according to the BB84 protocol and transmits the prepared quantum photons to Bob through the quantum channel. Bob then detects the quantum photons. Step S2: Alice and Bob complete the basis vector alignment process according to the BB84 protocol and extract the Siftedkey with consistent basis vectors. Step S3: Use an error correction algorithm to correct the sifted key with certain errors at both ends and negotiate to reach a consensus. At this time, both ends obtain the corrected key. In this step, if the basis vector comparison in step S2 results in an "inconsistent comparison", the replacement random number is different from the real sifted key obtained by the consistent comparison. The sifted key data blocks at both ends will fail to correct errors in the error correction step and be discarded. Step S4: Both ends enhance the security of the Corrected key, and both ends obtain the Final key, which is then output to the key management system for use by the final key user.
5. A quantum key generation device employing the sifted key synchronization method in the key generation process within a QKD device according to any one of claims 1 to 3, characterized in that: Includes the following modules: A detection module is prepared to perform the following steps: Alice and Bob establish a classical network connection through a classical channel. Alice prepares quantum photons according to the BB84 protocol and transmits the prepared quantum photons to Bob through a quantum channel. Bob then completes the detection of the quantum photons. The basis vector alignment module is used to perform the following steps: Alice and Bob complete the basis vector alignment process according to the BB84 protocol and extract the sifted key with consistent basis vectors; The error correction module is used to perform the following steps: use an error correction algorithm to correct the sifted key with certain errors at both ends and negotiate to reach a consensus. At this time, both ends obtain the corrected key. In this step, if the basis vector comparison results in "inconsistent comparison", the replacement random number is different from the real sifted key obtained by the consistent comparison. The sifted key data blocks at both ends will fail to correct errors in the error correction step and be discarded. The security enhancement module performs the following steps: both ends enhance the security of the corrected key, both ends obtain the final key, and finally output it to the key management system for use by the final key user.
6. A method for generating quantum keys within a QKD device, characterized in that: Includes the following steps: Step S1: Alice and Bob establish a classical network connection through a classical channel. Alice prepares quantum photons according to the BB84 protocol and transmits the prepared quantum photons to Bob through the quantum channel. Bob then detects the quantum photons. Step S2: Alice and Bob complete the basis vector alignment process according to the BB84 protocol and extract the Siftedkey with consistent basis vectors. The basis vector alignment process is as follows: Step S21: Bob sends the original probe basis information B1 to Alice. Step S22: Alice performs basis vector comparison to obtain basis vector comparison result A1, generates a Sifted key to be synchronized, and sends the basis vector comparison result A1 to Bob. At the same time, Alice calculates the detection rate information A2 based on the original detection basis vector information B1 sent by Bob and sends the detection rate information A2 to Bob. Step S23: Bob receives the basis comparison result A1 sent by Alice, performs basis comparison, evaluates the error rate of the signal state and the decoy state based on the basis comparison result A1, obtains the error rate information B2 of the signal state and the decoy state, Bob receives the detection rate information A2 sent by Alice and saves it, and Bob generates the Sifted key to be synchronized. Step S24: Bob sends error rate information B2 of the signal state and decoy state to Alice. Step S25: Alice receives and saves the error rate information B2 of the signal state and the decoy state; Step S26: Alice calculates the hash value of (A1+A2+B1+B2) to obtain the first hash value, and sends the first hash value to Bob. Step S27: Bob calculates the hash value of (A1+A2+B1+B2) to obtain the second hash value, and compares it with the first hash value to generate the first comparison result. The first comparison result is either "matching" or "matching inconsistent", and the first comparison result is sent to Alice. Step S28: Alice receives the second comparison result; Step S29: If the first comparison result is "matching", Bob's end retains the Sifted key; if the first comparison result is "mismatching", Bob's end replaces the Sifted key with an equal amount of random numbers. If the second comparison result is "matching", Alice's end retains the Sifted key; if the second comparison result is "mismatching", Alice's end replaces the Sifted key with an equal amount of random numbers. Step S3: Use an error correction algorithm to correct the errors in the sifted key at both ends and negotiate to reach a consensus. At this time, both ends obtain the corrected key. In this step, if the basis vector comparison in step S29 results in an "inconsistent comparison", the replacement random number is different from the real sifted key obtained by the consistent comparison. The sifted key data blocks at both ends will fail to correct errors in the error correction step and be discarded. Step S4: Both ends enhance the security of the Corrected key, and both ends obtain the Final key. Finally, the Final key is output to the key management system for use by the final key user. The synchronization process before the Final key is output is as follows: Alice calculates the hash value of the final key, obtains the third hash value, and sends it to Bob. Bob calculates the hash value of the final key, obtains the fourth hash value, compares it with the third hash value and the fourth hash value, generates the third comparison result, and sends the third comparison result to Alice. Alice receives the fourth comparison result, which is either "matched" or "inconsistent". If the third comparison result is "matching", Bob's end will output the final key normally. If the third comparison result is "mismatching", Bob's end will mark the final key and output it. If the fourth comparison result is "matching", Alice will output the final key normally. If the fourth comparison result is "mismatching", Alice will mark the final key and output it.
7. A quantum key generation device within a QKD device, characterized in that: Includes the following modules: A detection module is prepared to perform the following steps: Alice and Bob establish a classical network connection through a classical channel. Alice prepares quantum photons according to the BB84 protocol and transmits the prepared quantum photons to Bob through a quantum channel. Bob then completes the detection of the quantum photons. The basis vector alignment module performs the following steps: Alice and Bob complete the basis vector alignment process according to the BB84 protocol, and extract the sifted key with consistent basis vectors. The basis vector alignment process is as follows: Step S21: Bob sends the original probe basis information B1 to Alice. Step S22: Alice performs basis vector comparison to obtain basis vector comparison result A1, generates a Sifted key to be synchronized, and sends the basis vector comparison result A1 to Bob. At the same time, Alice calculates the detection rate information A2 based on the original detection basis vector information B1 sent by Bob and sends the detection rate information A2 to Bob. Step S23: Bob receives the basis comparison result A1 sent by Alice, performs basis comparison, evaluates the error rate of the signal state and the decoy state based on the basis comparison result A1, obtains the error rate information B2 of the signal state and the decoy state, Bob receives the detection rate information A2 sent by Alice and saves it, and Bob generates the Sifted key to be synchronized. Step S24: Bob sends error rate information B2 of the signal state and decoy state to Alice. Step S25: Alice receives and saves the error rate information B2 of the signal state and the decoy state; Step S26: Alice calculates the hash value of (A1+A2+B1+B2) to obtain the first hash value, and sends the first hash value to Bob. Step S27: Bob calculates the hash value of (A1+A2+B1+B2) to obtain the second hash value, and compares it with the first hash value to generate the first comparison result. The first comparison result is either "matching" or "matching inconsistent", and the first comparison result is sent to Alice. Step S28: Alice receives the second comparison result; Step S29: If the first comparison result is "matching", Bob's end retains the Sifted key; if the first comparison result is "mismatching", Bob's end replaces the Sifted key with an equal amount of random numbers. If the second comparison result is "matching", Alice's end retains the Sifted key; if the second comparison result is "mismatching", Alice's end replaces the Sifted key with an equal amount of random numbers. The error correction module is used to perform the following steps: using an error correction algorithm to correct the sifted key with certain errors at both ends and negotiate to reach a consensus. At this time, both ends obtain the corrected key. In this step, if the basis vector comparison in step S29 results in an "inconsistent comparison", the replacement random number is different from the real sifted key obtained by the consistent comparison. The sifted key data blocks at both ends will fail to correct the error in the error correction step and be discarded. The security enhancement module performs the following steps: both ends enhance the security of the Corrected key, both ends obtain the Final key, and finally output it to the key management system for use by the final key user. The synchronization process before the Final key is output is as follows: Alice calculates the hash value of the final key, obtains the third hash value, and sends it to Bob. Bob calculates the hash value of the final key, obtains the fourth hash value, compares it with the third hash value and the fourth hash value, generates the third comparison result, and sends the third comparison result to Alice. Alice receives the fourth comparison result, which is either "matched" or "inconsistent". If the third comparison result is "matching", Bob's end will output the final key normally. If the third comparison result is "mismatching", Bob's end will mark the final key and output it. If the fourth comparison result is "matching", Alice will output the final key normally. If the fourth comparison result is "mismatching", Alice will mark the final key and output it.
Citation Information
Patent Citations
Quantum key distribution after-treatment system and method based on polar code correction
CN106161012A
Data authentication method based on HMAC-SM3 algorithm and quantum key distribution system
CN109274480A
A method for enhancing data secrecy and a quantum key distribution terminal
CN109274484A
A key error correction method and a quantum key distribution system
CN109936445A