A method of key transport

By combining classical and quantum channels in the key transmission method, and using quantum initial state key pairs and quantum private key pairs for encryption and decryption, the eavesdropping risk in classical channels and the forgery share problem in quantum secret sharing are solved, thus achieving unconditional security and reliable recovery of information exchange.

CN115834040BActive Publication Date: 2026-02-27SHENZHEN Y& D ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211361787.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-02
Publication Date
2026-02-27
Estimated Expiration
2042-11-02

AI Technical Summary

Technical Problem

Existing technologies in classical channels have the risk of eavesdropping and the problem of irrecoverable secrets due to dishonesty of participants, while quantum secret sharing technology has the problem of participants falsifying their shares.

Method used

The key transmission method is adopted, which combines a key store, a key distribution and management subsystem, classical channels and quantum channels. It uses quantum initial state key pairs and quantum private key pairs, and uses quantum states as information carriers. It combines session keys for encryption and decryption to carry out quantum transmission, and detects forged information by comparing hash values.

Benefits of technology

It enables the detection of external interference and forgery in quantum channels, ensuring unconditional security of information exchange, reducing the irrecoverable loss of secrets caused by forgery, and improving the security and reliability of information exchange.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure BDA0003922287340000041
    Figure BDA0003922287340000041
  • Figure FDA0005531983430000021
    Figure FDA0005531983430000021
  • Figure FDA0005531983430000022
    Figure FDA0005531983430000022
Patent Text Reader

Abstract

The present application relates to the technical field of key transmission, and relates to a key transmission method, comprising: selecting a quantum initial state key pair and a quantum private key pair in a key library, and sending the quantum initial state key pair and the quantum private key pair to all participants; and sending a quantum initial state of the quantum key pair to participant C1 after encryption to form a first quantum transmission key; participant C1 performs decryption and measurement processing on the first quantum transmission key to obtain the quantum initial state key pair, performs unitary operation and encryption to obtain a second quantum transmission key, and sends the second quantum transmission key to participant C2; all participants are traversed, participant C1 receives a final quantum transmission key, and performs decryption and measurement processing on the final quantum transmission key to obtain a quantum final state key pair and a quantum key pair; and participant C1 compares a final hash value with an initial hash value to determine whether there is participant information forgery.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of key transmission, in particular to a key transmission method. BACKGROUND

[0002] In the privacy computing, there are two technical fields of trusted execution environment and cryptography.

[0003] The secret sharing technology can restore the secret information only through the cooperation of more than a certain threshold number of participants, and cannot crack the secret through a single fragment. The principle is to split the secret into multiple fragments (Share), and each fragment is managed by different participants. Only more than a certain threshold number of participants can restore the secret information, and a single fragment cannot crack the secret. In the process of issuing information in the classical channel, the distributor transmits these shares through different channels or different other participants, which can ensure that the information security can be protected under the condition that the number of channels transmitted is below a certain number or the number of other participants is below a certain number. However, the classical channel has the risk of eavesdropping.

[0004] And the quantum technology takes quantum state as information carrier, which can not only detect the interference behavior of the outside world, but also realize the theoretical unconditional security based on the basic principles of quantum mechanics. If only quantum secret sharing technology is used, it is easy to appear that the participants in the scheme are not necessarily honest, and when a cheater provides a fake share, the recovered secret is not the original secret. SUMMARY

[0005] The present application provides a key transmission method to solve the defects and deficiencies of the prior art.

[0006] To achieve the above purpose, the technical scheme adopted by the present application is a key transmission method, which is realized by a key library, a key distribution and management subsystem, a classical channel, a quantum channel and multiple participants. The key library is provided with a transmission key, a quantum private key pair and a quantum initial state key pair. The transmission key includes a quantum key pair and a classical key pair, and a session key is provided between each two participants.

[0007] The method comprises the following steps:

[0008] S1: The key distribution and management subsystem selects a quantum initial state key pair (a0, b0) and a plurality of quantum private key pairs (α i ,γ i ) from the key library and sends them to all participants C1, C2,..., Cm. The key distribution and management subsystem selects a quantum key pair (θ1, θ2) from the key library and sets a0=θ1-γ1-γ2-...-γ m, b0= θ2- α1- α2-...-α m , the quantum key pair (θ1, θ2) is quantumized by the quantum initial state key pair (a0, b0) and the session key k shared between the key issuing and management subsystem and the participant C1 0,1 is encrypted to form the first quantum transmission key and sent to the participant C1;

[0009] S2: the participant C1 decrypts and measures the obtained first quantum transmission key to obtain (a0, b0), and then the participant C1 performs a unitary operation by the quantum private key pair (α1, γ1) obtained by the participant C1 and encrypts by the session key k shared between the participant C1 and the participant C2 1,2 to obtain the second quantum transmission key, and sends the second quantum transmission key to the participant C2;

[0010] S3: the participant C2 decrypts and measures the second quantum transmission key to obtain (a1, b1), and calculates the quantum private key pair (α1, γ1) of the participant C1, and then the participant C2 performs a unitary operation by the quantum private key pair (α2, γ2) obtained by the participant C2 and encrypts by the session key k shared between the participant C2 and the participant C3 2,3 to obtain the third quantum transmission key, and sends the third quantum transmission key to the participant C3;

[0011] S4: according to the above steps, all participants are traversed, the participant C1 receives the final quantum transmission key sent from the participant Cm, and decrypts and measures the final quantum transmission key to obtain (a m , b m ), thereby calculating the quantum key pair (θ1, θ2);

[0012] S5: the participant C1 compares the final hash value (H(a m ), H(b m )) with the initial hash value (H(θ1), H(θ2)) to determine whether there is participant forgery information, and if there is no participant forgery information, the final hash value (H(a m ), H(b m )) is sent to other participants.

[0013] Preferably, in the S5, the participant C1 calculates the value of the final hash value (H(a m ), H(b m )) and the initial hash value (H(θ1), H(θ2)), and if the final hash value (H(a m ), H(b mIf the final hash value (H(θ1), H(θ2)) is equal to the initial hash value (H(θ1), H(θ2)), then it proves that no participant forged the information, and the final hash value (H(θ1), H(θ2)) is set to... m ), H(b m If the information is not sent to other participants, it proves that a participant has forged the information.

[0014] Preferably, the key library has an orthogonal matrix G, where quantum key pairs are elements in the orthogonal matrix G, and classical key pairs are column indices in the orthogonal matrix G corresponding to the quantum key pairs.

[0015] Preferably, in step S1, the first quantum transmission key includes a quantum initial state. and the first encrypted superscript The key issuance and management subsystem performs quantum initialization processing on the quantum key pair (θ1, θ2) using the quantum initial state key pair (a0, b0) to form the quantum initial state. The superscript b0 of the quantum initial state is then passed through the session key k. 0,1 Encryption to form the first encrypted superscript The quantum initial state as well as Send to participant C1.

[0016] Preferably, in step S2, the second quantum transmission key includes a second quantum state. and the second encrypted superscript The participant C1 obtained the first encrypted superscript Decryption Then through For the quantum initial state Measurement processing is performed to obtain the measurement result a0. Participant C1 uses the quantum private key pair (α1, γ1) obtained by participant C1 to perform measurement on the initial quantum key pair a0.

[0017] Preferably, in step S3, the third quantum transmission key includes a third quantum state. and the third encrypted superscript The participant C2 added the second encrypted superscript. Decryption to obtain Then through For the second quantum state The measurement receives a1 = a0 + γ1, thereby calculating the quantum private key pair (α1, γ1) of participant C1; participant C2 performs a unitary operation on the measured second quantum state using the quantum private key pair (α2, γ2) obtained by participant C2. To obtain the third quantum state and through session key k 2,3Encrypt the superscript of the third quantum state to obtain the third encrypted superscript. The third quantum state and the third encrypted superscript Send to participant C3.

[0018] Preferably, in step S4, the final quantum transmission key includes the final quantum state and the final encrypted superscript. The process is repeated for all participants, following the steps described above, until participant C1 receives the final quantum state and the final encrypted superscript from participant Cm. The participant C1 is the final encrypted superscript Decryption pass Measurement of the final quantum state is received to obtain a m Thus, quantum state is obtained.

[0019] Preferably, the key transmission method further includes S6 for recovering the quantum key pair (θ1, θ2), S6 comprising the following steps:

[0020] S61: Participant C1 performs a unitary operation using the quantum key pair (θ1, θ2) and the quantum private key pair (α1, γ1) obtained by participant C1. To form the first recoverable quantum state And through the session key k shared by participant C1 and participant C2. 1,2 The first recovered quantum state of encryption The superscript is used to form the first encrypted recovery quantum superscript. and the first recovered quantum state and the first encrypted recovery quantum superscript Send to participant C2;

[0021] S62: Participant C2 decrypts the first encrypted recovery quantum superscript. To obtain θ2+α1, and to calculate θ2 using the quantum private key pair (α1,γ1) of participant C1, participant C2 obtains the first recovered quantum state. Execute the unit operation Then through Measurement to obtain θ1;

[0022] S63: Participant C2 calculates (H(θ1), H(θ2)) and compares (H(θ1), H(θ2)) with the final hash value (H(a)). m ), H(b m If the values ​​are the same, then the correct quantum key (θ1, θ2) is obtained.

[0023] S64: The participant C2 performs a unitary operation on the quantum key pair (θ1, θ2) obtained by the participant C2, the quantum private key pair (α1, γ1), (α2, γ2) obtained by the participant C2 to form a second recovery quantum state and through the session key k shared between the participant C2 and the participant C3 2,3 the second recovery quantum state with a superscript of the second encrypted recovery quantum state and sends the second recovery quantum state with a superscript of the second encrypted recovery quantum state to the participant C3;

[0024] S65: The participant C3 decrypts the second encrypted recovery quantum state to obtain θ2+α1+α2, and through calculation, obtains θ2, the participant C3 performs a unitary operation on the second recovery quantum state to obtain θ1; and through measurement, obtains θ1;

[0025] S66: The participant C3 calculates (H(θ1), H(θ2)), and compares whether (H(θ1), H(θ2)) is identical to the final hash value (H(a m ), H(b m )), if identical, obtains the correct quantum key (θ1, θ2);

[0026] S67: The above method traverses all participants so that all participants obtain the correct quantum key (θ1, θ2).

[0027] Preferably, the key transmission method further comprises a classical key transmission method, and the classical key transmission method comprises the following steps:

[0028] A1: The key issuing and management subsystem selects a plurality of classical key pairs (xi, yi) in the key library and sends them to all participants C1, C2,..., Cm, respectively;

[0029] A2: Each participant encrypts its own classical key pair through the corresponding session key to form an encrypted classical key pair, and sends the encrypted classical key pair to other participants;

[0030] A3: Each participant decrypts the encrypted classical key obtained by the corresponding session key to obtain the classical key pair of other participants;

[0031] A4: Each participant compares the hash value corresponding to the classical key pair of the participant with the hash value corresponding to the classical key pair of other participants, if the same, it is considered that the classical channel has no one to forge information, otherwise, it is considered that the classical channel has someone to forge information.

[0032] The present application has the following beneficial effects:

[0033] The present application provides a key transmission method, taking quantum state as information carrier, which can not only detect the interference behavior of the outside world while realizing the exchange of secret information, but also realize the theoretical unconditional security based on the basic principles of quantum mechanics. If only quantum secret sharing technology is used, it is easy to appear that the participants in the scheme are not necessarily honest, and when a cheater provides a fake share, it can lead to the recovered secret not being the original secret. Therefore, the above scheme adds quantum channel related content on the basis of the classical channel, thereby reducing the phenomenon that the secret cannot be recovered when the fake share is too high. DETAILED DESCRIPTION

[0034] The present application provides a key transmission method, taking quantum state as information carrier, which can not only detect the interference behavior of the outside world while realizing the exchange of secret information, but also realize the theoretical unconditional security based on the basic principles of quantum mechanics. If only quantum secret sharing technology is used, it is easy to appear that the participants in the scheme are not necessarily honest, and when a cheater provides a fake share, it can lead to the recovered secret not being the original secret. Therefore, the above scheme adds quantum channel related content on the basis of the classical channel, thereby reducing the phenomenon that the secret cannot be recovered when the fake share is too high.

[0035] The method comprises the following steps:

[0036] S1: The key issuing and management subsystem selects quantum initial state key pair (a0, b0) and a plurality of quantum private key pairs (α i ,γ i ) from the key library and sends them to all participants C1, C2,..., Cm; the key issuing and management subsystem selects quantum key pair (θ1, θ2) from the key library, and sets a0=θ1-γ1-γ2-...-γ m , b0=θ2-α1-α2-...-α m ; the quantum initial state key pair (a0, b0) is used to process the quantum key pair (θ1, θ2) to form a first quantum transmission key, which is encrypted by the session key k 0,1 shared by the key issuing and management subsystem and the participant C1, and then sent to the participant C1;

[0037] S2: The participant C1 decrypts and measures the obtained first quantum transmission key to obtain (a0, b0), then performs a unitary operation on the quantum private key pair (α1, γ1) obtained by the participant C1, and encrypts the result by the session key k 1,2encrypting to obtain a second quantum transmission key, and sending the second quantum transmission key to the participant C2;

[0038] S3: the participant C2 decrypts and measures the second quantum transmission key to obtain (a1, b1), and calculates the quantum private key pair (α1, γ1) of the participant C1, then the participant C2 performs a unitary operation through the quantum private key pair (α2, γ2) obtained by the participant C2, and performs a unitary operation through the session key k 2,3 encrypting to obtain a third quantum transmission key, and sending the third quantum transmission key to the participant C3;

[0039] S4: all participants are traversed according to the above steps, the participant C1 receives the final quantum transmission key sent by the participant Cm, and decrypts and measures the final quantum transmission key to obtain (a m , b m ), so as to calculate the quantum key pair (θ1, θ2);

[0040] S5: the participant C1 compares the final hash value (H(a m ), H(b m )) with the initial hash value (H(θ1), H(θ2)) to determine whether there is participant forgery information, and if there is no participant forgery information, the final hash value (H(a m ), H(b m )) is sent to other participants.

[0041] The session keys between all participants are shared by the two, are non-public, and are not the same between the session keys.

[0042] Preferably, the key library is provided with an orthogonal matrix G, the quantum key pair is an element in the orthogonal matrix G, and the classical key pair is a column mark corresponding to the quantum key pair in the orthogonal matrix G.

[0043] The key secret in the application is the specific values of the quantum private key pair and the classical private key pair.

[0044] Let F d be a finite field, and let G be a d×h matrix, whose elements are all from F d , and define any d×2 sub-matrix in G, wherein all rows are composed of ordered 2-tuples (for example, all permutation combinations of four 2-tuples (0, 0), (0, 1), (1, 0), (1, 1)), and then G is called an orthogonal array with a strength of 2. Since the key pair in the application is two elements, a strength of 2 is selected.

[0045] There is a hash function H(x) ∈ F d(x) and discloses a method for channel detection.

[0046] The quantum key pair in the key library is an element of an orthogonal array G (a d x h matrix), and is generally taken in pairs. The classical key pair is determined by two elements of a row of the orthogonal array and the column index of the orthogonal array. For example, a quantum key pair (θ1, θ2) selects θ1 in the h1th column and θ2 in the h2th column of the fth row of G, and the classical key pair is the column index (h1, h2) of θ1 and θ2.

[0047] Preferably, in the S1, the first quantum transmission key comprises a quantum initial state and a first encrypted superscript The key issuing and management subsystem performs quantum initial state processing on the quantum key pair (θ1, θ2) by using the quantum initial state key pair (a0, b0) to form the quantum initial state and encrypts the superscript b0 of the quantum initial state by using the session key k 0,1 to form the first encrypted superscript The quantum initial state and are sent to the participant C1.

[0048] Preferably, in the S2, the second quantum transmission key comprises a second quantum state and a second encrypted superscript The participant C1 decrypts the obtained first encrypted superscript to obtain and then performs measurement processing on the quantum initial state by using to obtain the measurement result a0. The participant C1 performs a unitary operation on the measured quantum initial state by using the quantum private key pair (α1, γ1) obtained by the participant C1 to obtain the third quantum state

[0049] Preferably, in the S3, the third quantum transmission key comprises a third quantum state and a third encrypted superscript The participant C2 decrypts the second encrypted superscript to obtain and then performs measurement on the second quantum state to obtain a1 = a0 + γ1, thereby calculating the quantum private key pair (α1, γ1) of the participant C1; the participant C2 performs a unitary operation on the measured second quantum state by using the quantum private key pair (α2, γ2) obtained by the participant C2 to obtain the third quantum state and encrypts the superscript of the third quantum state by using the session key k 2,3 to obtain the third encrypted superscript The third quantum state and the third encrypted superscript is sent to the participant C3.

[0050] In this way, the participant C3 decrypts the third encrypted superscript to obtain b2=b1+α2=b0+α1+α2, and then receives a2=a1+γ2=a0+γ1+γ2 by measuring the third quantum state , so as to calculate (α1+α2, γ1+γ2); the participant C3 performs a unitary operation on the measured third quantum state by using the quantum private key pair (α3, γ3) obtained by the participant C3 to obtain the fourth quantum state and encrypts the superscript of the fourth quantum state by using the session key k 3,4 to obtain the fourth encrypted superscript The fourth quantum state and the fourth encrypted superscript are sent to the participant C4.

[0051] Preferably, in the S4, the final quantum transmission key includes the final quantum state and the final encrypted superscript All participants are traversed according to the above steps until the participant C1 receives the final quantum state and the final encrypted superscript from the participant Cm. The participant C1 decrypts the final encrypted superscript to obtain The participant C1 receives by measuring the final quantum state m to obtain a , so as to obtain the quantum state

[0052] Finally, a m =a m-1 +γ m =a0+γ1+...+γ m , b m =b m-1 +α m =b0+α1+...+α m , a0=θ1-γ1-γ2-...-γ m , and b0=θ2-α1-α2-...-α m , so that the quantum key pair (θ1, θ2) can be calculated.

[0053] Preferably, in the S5, the participant C1 calculates the final hash value (H(a m ), H(b m )) and the initial hash value (H(θ1), H(θ2)), and if the final hash value (H(am ), H(b m If the final hash value (H(θ1), H(θ2)) is equal to the initial hash value (H(θ1), H(θ2)), then it proves that no participant forged the information, and the final hash value (H(θ1), H(θ2)) is set to... m ), H(b m If the information is not sent to other participants, it proves that a participant has forged the information. This allows for the detection of the entire quantum channel, preventing cheaters from entering the quantum channel.

[0054] Preferably, the key transmission method further includes S6 for recovering the quantum key pair (θ1, θ2), S6 comprising the following steps:

[0055] S61: Participant C1 performs a unitary operation using the quantum key pair (θ1, θ2) and the quantum private key pair (α1, γ1) obtained by participant C1. To form the first recoverable quantum state And through the session key k shared by participant C1 and participant C2. 1,2 The first recovered quantum state of encryption The superscript is used to form the first encrypted recovery quantum superscript. and the first recovered quantum state and the first encrypted recovery quantum superscript Send to participant C2;

[0056] S62: Participant C2 decrypts the first encrypted recovery quantum superscript. To obtain θ2+α1, and to calculate θ2 using the quantum private key pair (α1,γ1) of participant C1, participant C2 obtains the first recovered quantum state. Execute the unit operation Then through Measurement to obtain θ1;

[0057] S63: Participant C2 calculates (H(θ1), H(θ2)) and compares (H(θ1), H(θ2)) with the final hash value (H(a)). m ), H(b m If the values ​​are the same, then the correct quantum key (θ1, θ2) is obtained.

[0058] S64: Participant C2 will perform unitary operations using the quantum key pair (θ1, θ2) and the quantum private key pair (α1, γ1) and (α2, γ2) obtained by participant C2. To form the second recovery quantum state And through the session key k shared by participant C2 and participant C3. 2,3 Encrypted second recovered quantum state the second recovery quantum state and the second recovery quantum state and the second recovery quantum state to the participant C3;

[0059] S65: the participant C3 decrypts the second encrypted recovery quantum superscript to obtain θ2+α1+α2, and obtains θ2 by calculation, and the participant C3 performs a unitary operation on the second recovery quantum state to obtain θ2+α1+α2, and obtains θ2 by calculation, and the participant C3 performs a unitary operation on the second recovery quantum state and obtains θ1 by measurement;

[0060] S66: the participant C3 calculates (H(θ1), H(θ2)), and compares whether (H(θ1), H(θ2)) is identical to the final hash value (H(a m ), H(b m )), if identical, the correct quantum key (θ1, θ2) is obtained;

[0061] S67: the above method traverses all participants so that all participants obtain the correct quantum key (θ1, θ2).

[0062] Preferably, the key transmission method further comprises a classical key transmission method, and the classical key transmission method comprises the following steps:

[0063] A1: the key issuing and management subsystem selects a plurality of classical key pairs (xi, yi) in the key library and sends them to all participants C1, C2,..., Cm, respectively;

[0064] A2: each participant encrypts its own classical key pair through the corresponding session key to form an encrypted classical key pair, and sends the encrypted classical key pair to other participants;

[0065] A3: each participant decrypts the encrypted classical key pair obtained by the corresponding session key to obtain the classical key pair of other participants;

[0066] A4: each participant compares the hash value corresponding to its own classical key pair with the hash value corresponding to the classical key pair of other participants, if identical, it is considered that no one forges information on the classical channel, otherwise, it is considered that someone forges information on the classical channel.

[0067] The participant C1 encrypts the classical key pair (x1, y1) of the participant C1 through the session key k 1,2 ​encrypt the classical key pair (x1, y1) obtained by the participant C1 to form an encrypted classical key pair, and send the encrypted classical key pair to the participant C2, through the session key k shared between the participant C1 and the participant C3 1,3 encrypt the classical key pair (x1, y1) obtained by the participant C1 to form an encrypted classical key pair, and send the encrypted classical key pair to the participant C2, through the session key k shared between the participant C1 and the participant C3

[0068] Each participant decrypts the encrypted classical key pair obtained by the participant to obtain the classical key pair of other participants, and judges the authenticity of the obtained classical key through comparison between the hash values. In this way, the distribution of the classical key pair and the verification of the classical channel are completed.

[0069] The transmission of the classical key pair and the transmission of the quantum key pair are carried out simultaneously, and after all the participants obtain the classical key pair and the quantum key pair, the complete key is obtained by combining them.

[0070] All the unitary operations in the application are carried out on mutually unbiased bases, if and are two standard orthogonal bases in the space C d , if are mutually unbiased, if every pair of bases in the space set is unbiased, the set is called an unbiased basis set.

[0071] In the above description, specific details such as specific system structures, techniques, etc. are presented in order to facilitate a thorough understanding of the embodiments of the application. However, it should be clear to those skilled in the art that the application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits and methods are omitted to avoid unnecessary details that hinder the description of the application.

[0072] It should be understood that when used in the specification and the appended claims of the application, the term "comprising" indicates the presence of described features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or sets thereof.

[0073] It should also be understood that, in the description of the application and the appended claims, the term "and / or" is used to indicate one or more of the items it conjoins, including the possibility of one or more of the items being present alone. It should also be understood that, in the description of the application and the appended claims, the term "comprising" is used to indicate the presence of the item to be counted, but not to exclude the presence of one or more additional items. It should also be understood that, in the description of the application and the appended claims, the term "comprising" is used to indicate the presence of the item to be counted, but not to exclude the presence of one or more additional items.

[0074] As used in the description of the application and the appended claims, the term "if' can be interpreted as meaning "when" or "upon" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrase "if it is determined" or "if [the recited condition or event] is detected" can be interpreted as meaning "upon determining" or "in response to determining" or "upon detecting [the recited condition or event]" or "in response to detecting [the recited condition or event]", depending on the context.

[0075] In addition, in the description of the application and the appended claims, the terms "first", "second", "third", etc. are only used for differentiation in description, and cannot be understood as indicating or implying relative importance.

[0076] The above-described embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application.

Claims

1. A method of key transport, the method comprising: The method is realized by a key library, a key issuing and managing subsystem, a classical channel, a quantum channel and a plurality of participants, the key library is provided with a transmission key, a quantum private key pair and a quantum initial state key pair, the transmission key comprises a quantum key pair and a classical key pair, and a session key is provided between each two participants; The method comprises the following steps: S1: the key issuing and management subsystem selects quantum initial state key pair (a0, b0) and several quantum private key pairs (α i ,γ i ) in the key library and sends them to all participants C1, C2,..., Cm, the key issuing and management subsystem selects quantum key pair (θ1, θ2) in the key library and sets a0=θ1-γ1-γ2-...-γ m , b0=θ2-α1-α2-...-α m , processes quantum key pair (θ1, θ2) by quantum initial state key pair (a0, b0) and encrypts by session key k 0,1 common to the key issuing and management subsystem and participant C1 to form the first quantum transmission key and sends it to participant C1; S2: the participant C1 decrypts and measures the obtained first quantum transmission key to obtain (a0, b0), and then the participant C1 performs a unitary operation on (a1, g1) obtained by the participant C1 through the quantum private key of the participant C1 to generate a quantum second state key pair (a1, b1), and sends the quantum second state key pair (a1, b1) to the participant C2 through the session key k shared between the participant C1 and the participant C2 1,2 encrypting to obtain a second quantum transmission key, and sending the second quantum transmission key to the participant C2; S3: the participant C2 decrypts and measures the second quantum transmission key to obtain (a1, b1), and calculates the quantum private key pair (α1, γ1) of the participant C1, then the participant C2 performs a unitary operation through the quantum private key pair (α2, γ2) obtained by the participant C2, and performs encryption through the session key k shared between the participant C2 and the participant C3 2,3 encrypts to obtain a third quantum transmission key, and sends the third quantum transmission key to the participant C3; S4: According to the above steps, all participants are traversed, the participant C1 receives the final quantum transmission key sent from the participant Cm, and the final quantum transmission key is decrypted and measured to obtain the quantum final state key pair (a m , b m ), so as to calculate the quantum key pair (θ1, θ2); S5: the participant C1 compares the final hash value (H(a m ), H(b m )) with the initial hash value (H(θ1), H(θ2)) to determine whether the participant has falsified information, and if the participant has not falsified information, the final hash value (H(a m ), H(b m )) is sent to other participants.

2. The key transfer method according to claim 1, wherein In the S5, the participant C1 calculates the final hash value (H(a m ), H(b m )) and the initial hash value (H(θ1), H(θ2)), if the final hash value (H(a m ), H(b m )) is equal to the initial hash value (H(θ1), H(θ2)), it proves that no participant forges information, and sends the final hash value (H(a m ), H(b m )) to other participants, otherwise, it proves that there is a participant who forges information.

3. The key transfer method according to claim 2, wherein The key library is provided with an orthogonal matrix G, a quantum key pair is an element in the orthogonal matrix G, a classical key pair is a column mark in the orthogonal matrix G corresponding to the quantum key pair, and the elements in the orthogonal matrix G are all from a finite field F d .

4. The key transfer method according to claim 3, wherein In the S1, the first quantum transmission key includes a quantum initial state and a first encrypted superscript The key issuing and management subsystem performs quantum initial state processing on the quantum key pair (θ1, θ2) by a quantum initial state key pair (a0, b0) to form the quantum initial state and encrypts the superscript b0 of the quantum initial state by a session key k 0,1 to form the first encrypted superscript The quantum initial state and is sent to the participant C1.

5. The key transfer method according to claim 4, wherein In step S2, the second quantum transmission key includes a second quantum state. and the second encrypted superscript The participant C1 obtained the first encrypted superscript Decryption Then through For the quantum initial state Measurement processing is performed to obtain the measurement result a0. Participant C1 performs unitary operations on the measured quantum initial state using the quantum private key pair (α1, γ1) obtained by participant C1. To obtain the second quantum state and through session key k 1,2 Encrypt the superscript of the second quantum state to obtain the second encrypted superscript. The second quantum state and the second encrypted superscript Send to participant C2.

6. The key transfer method according to claim 5, wherein The third quantum transmission key includes a third quantum state And a third encrypted superscript The participant C2 decrypts the second encrypted superscript To obtain Again through The measurement of the second quantum state Receives a1=a0+γ1, thereby calculating the quantum private key pair (α1,γ1) of the participant C1; the participant C2 performs a unitary operation on the measured second quantum state through the quantum private key pair (α2,γ2) obtained by the participant C2 To obtain the third quantum state And encrypts the superscript of the third quantum state through the session key k 2,3 To obtain the third encrypted superscript The third quantum state And the third encrypted superscript Are sent to the participant C3.

7. The key transfer method according to claim 6, wherein The final quantum transmission key comprises a final quantum state and a final encryption superscript in S4 All participants are traversed according to the above steps until participant C1 receives the final quantum state and the final encryption superscript sent by participant Cm The participant C1 decrypts the final encryption superscript The decryption result is Through The final quantum state is measured to obtain a m Thus, the quantum state is obtained 8. The key transfer method according to claim 7, wherein S6: S6 is further included for recovering the quantum key pair (θ1, θ2), and the S6 comprises the following steps: S61: The participant C1 performs a unitary operation on the quantum key pair (θ1, θ2) and the quantum secret key pair (α1, γ1) obtained by the participant C1 to form a first recovery quantum state and through a session key k common between the participant C1 and the participant C2 1,2 the first recovery quantum state with an encrypted first recovery quantum superscript and sends the first recovery quantum state and the first encrypted recovery quantum superscript to the participant C2; S62: the participant C2 decrypts the first encrypted recovery quantum superscript to obtain θ2+α1, and θ2 is calculated by the quantum private key (α1, γ1) of the participant C1, and the participant C2 calculates the first recovery quantum state Perform a unitary operation Again through Measurement to obtain θ1; S63: The participant C2 calculates (H(θ1), H(θ2)), and compares (H(θ1), H(θ2)) with the final hash values (H(a m ), H(b m )) to see if they are the same, and if so, obtains the correct quantum key (θ1, θ2); S64: said participant C2 will perform a unitary operation on the quantum key pair (θ1, θ2), the quantum secret key pair (α1, γ1), (α2, γ2) obtained by participant C2 to form a second recovery quantum state and by a session key k common between said participant C2 and said participant C3 2,3 said second recovery quantum state encrypted with the superscript of the second encrypted recovery quantum state and send said second recovery quantum state and the second encrypted recovery quantum state to participant C3; S65: said participant C3 decrypts the second encrypted recovery quantum superscript to obtain θ2+α1+α2, and by calculation θ2, said participant C3 measures the second recovery quantum state performs a unitary operation again by measurement to obtain θ1; S66: the participant C3 calculates (H(θ1), H(θ2)), and compares whether (H(θ1), H(θ2)) is identical to the final hash value (H(a m ), H(b m )). If identical, the correct quantum key (θ1, θ2) is obtained. S67: The above method traverses all the participants so that all the participants obtain correct quantum keys (θ1, θ2).

9. The key transfer method according to claim 8, wherein The key transmission method further comprises a classical key transmission method, and the classical key transmission method comprises the following steps: A1: The key issuing and managing subsystem selects a plurality of classical key pairs (xi, yi) in the key library and sends the classical key pairs to all the participants C1, C2, …, Cm respectively; A2: Each participant encrypts the classical key pair of the participant by using the corresponding session key to form an encrypted classical key pair, and sends the encrypted classical key pair to other participants; A3: Each participant decrypts the obtained encrypted classical key by using the corresponding session key to obtain the classical key pair of other participants; A4: Each participant compares the hash value corresponding to the classical key pair of the participant with the hash value corresponding to the classical key pair of other participants, if the hash values are the same, it is considered that no one forges information in the classical channel, otherwise, it is considered that someone forges information in the classical channel.

Citation Information

Patent Citations

  • Quantum threshold secret sharing method and system based on Lagrangian unitary operator

    CN110266489A

  • Quantum threshold secret sharing method and device with two verifiable ends, and electronic equipment

    CN113556229A