An authenticated quantum key distribution protocol based on Bell states
By introducing Bell state-based authentication mechanism and position mapping function in the quantum key distribution protocol, the problem of the lack of identity authentication and noise resistance of existing protocols is solved, and secure key distribution and identity authentication in undesirable environments are realized.
Patent Information
- Application Number
- CN202111413795.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-25
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2041-11-25
AI Technical Summary
The lack of identity authentication and inability to resist environmental noise in existing quantum key distribution protocols leads to insecure key distribution in the environment of imperfect channels and measurement equipment.
The authentication quantum key distribution protocol based on Bell state (BBS-AQKD) is adopted to ensure the security of the identity of both parties of the communication through one distribution and two rounds of authentication, and a position mapping function is introduced into the protocol to achieve fast identity verification, error estimation and error correction.
This protocol can realize identity authentication, key distribution and error correction in an environment with noisy, unsafe channels and imperfect measurement equipment, improve communication security and key negotiation efficiency, and can resist man-in-the-middle attacks and measurement attacks.
Smart Images

Figure CN116170132B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network security, and specifically relates to a Bell-state-based authenticated quantum key distribution protocol for protecting network communication security. Background Art
[0002] Nowadays, information security has become one of the most concerned issues. Many information security incidents in recent years have prompted people to study more advanced information encryption technology. As the core of information security, cryptography plays a vital role. In 1917, Mauborgne and Vernam proposed a one-time pad encryption scheme. Then in 1949, information scientist Shannon proved the unconditional security of this encryption scheme in "Mathematical Principles of Communication". The so-called one-time pad includes two key points: first, the length of the key used by the two communicating parties must be consistent with the length of the encrypted information; second, the key used in each communication is only used to encrypt this conversation, that is, any key can only be used once. With the help of one-time pad technology, the currently commonly used encryption systems can be divided into symmetric encryption and asymmetric encryption. Symmetric encryption refers to the use of the same key by both communicating parties for encryption and decryption operations; and asymmetric encryption is also called public-private key encryption, where the public key and private key are different. Usually, the public key is used to encrypt information and the private key is used to decrypt information. Under the requirements of communication security, no matter which encryption system is used, the most important link is the generation and transmission of the key. The Diffie-Hellman protocol is often used in symmetric encryption algorithms to implement symmetric key negotiation, while asymmetric encryption algorithms such as RSA use the mathematical problem of large prime number decomposition to ensure the security of the public-private key system. However, with the emergence of quantum computing, traditional encryption algorithms have begun to show inherent drawbacks. In 1994, Shor proposed a quantum algorithm for large number decomposition, which made all asymmetric algorithms based on mathematical problems such as discrete logarithms and large prime number decomposition invalid, seriously threatening the security of network communications. With the continuous advancement of theoretical research and hardware technology, the security of conventional encryption methods will be greatly reduced within the visible time range. There is an urgent need for an encryption method that can resist quantum computing attacks. Quantum key distribution technology perfectly solves this problem.
[0003] Quantum key distribution refers to the use of the physical properties of quantum mechanics to distribute symmetric keys between communicating parties. The security of quantum keys is based on the two most basic principles of quantum mechanics: the Heisenberg uncertainty principle and the quantum no-cloning theorem. The former ensures that attackers cannot determine the key by measuring the quantum state, and the latter ensures that attackers cannot obtain the key by cloning the quantum state. In 1984, scientists Bennett and Brassard proposed the world's first quantum key distribution protocol, the BB84 protocol, using the polarization state of single photons. The protocol uses the four polarization states of photons under two basis vectors for encoding. The sender and the receiver agree on the encoding corresponding to each polarization state of photons through a public channel in advance, and then coordinate with the receiver by sending a series of photons in different polarization states to jointly agree on a set of quantum keys. After the first quantum key distribution protocol was proposed, quantum secure communication based on quantum keys has developed rapidly. As the name suggests, quantum secure communication refers to the use of quantum technology combined with relevant knowledge of cryptography to ensure the security and integrity of communication. With the characteristics of high flexibility and strong feasibility of quantum key distribution technology, quantum secure communication technology has been verified on a large scale in theory and practical applications. In summary, designing a secure key agreement protocol and applying it to real environments is of great significance in future unconditionally secure communication networks. Summary of the invention
[0004] The purpose of the present invention is to address the problems of existing representative QKD protocols, such as lack of identity authentication and inability to resist environmental noise. The present invention proposes a Bell-state-based authentication quantum key distribution protocol, the BBS-AQKD (Based on Bell State with Authentication Quantum Key Distribution) protocol. This protocol, with the help of the characteristics of quantum entanglement, ensures the security of the identities of both parties in communication through one-time distribution and two-round authentication, and has functions such as fast identity verification, error estimation, and error correction, solving the problems existing in existing representative protocols. The technical solution adopted by the present invention includes the following steps:
[0005] Step 1: Alice first generates a random sequence S of length L. A =s1s2...s L , and according to S A The Bell state is prepared based on the results of
[0006] Step 2: Alice extracts a particle from each Bell state, combines them in order to form a sequence P1 of length L, saves it in her own quantum pool, and sends another particle sequence P2 of length L, which is also combined in order, to Bob in turn;
[0007] Step 3: After Bob receives the particle sequence sent by Alice, both parties use the shared long-term key K l The value of selects the measurement basis;
[0008] Step 4: Alice and Bob, the two communicating parties, agree on the binary sequence represented by the quantum state according to the rules, and then convert the quantum states they measure into the corresponding binary sequence K A and K B , Alice takes out the odd bits of the inferred binary sequence to form a new sequence. Similarly, Bob also takes out the odd bits of his own binary sequence to form a new sequence. The new sequences of both parties are recorded as K Aodd and K Bodd , the same even-numbered bits also form the sequence K Aeven and K Beven ;
[0009] Step 5: Bob randomly selects a hash function h B Send it to Alice, Alice uses h B and two random numbers r generated by the quantum random number generator A1 and r A2 , perform a series of calculations, and obtain the results Messag A and P A Send to Bob;
[0010] Step 6: When Bob receives the authentication information, he uses h B , K l Messag sent by Alice A Perform a series of calculations to verify Alice’s identity and record the number of bit errors || R B ||;
[0011] Step 7: While Bob is authenticating Alice, Alice is also authenticating Bob. First, Alice randomly selects a hash function h A Send it to Bob, Bob uses h A and two random numbers r generated by the quantum random number generator B1 and r B2 . Perform a series of calculations and send the results to Messag B and P B Send to Alice;
[0012] Step 8: After Alice receives the authentication information, she uses h A , K l Perform a series of calculations with MessagB sent by Bob to verify Bob's identity and record the number of bit errors || RA ||;
[0013] Step 9. Alice and Bob publish their calculated ||R A || and ||RB||, and calculate the bit error rate and when or When any one of them exceeds the set threshold, the key distribution is terminated;
[0014] Step 10: When the bit error rates of both parties are within the set threshold, the identity authentication of both parties is considered successful. In general, some post-processing operations are required for the remaining keys. Similarly, if the estimated channel bit error rate is higher than the threshold set by the BBS-AQKD protocol, it is considered that there is an eavesdropper in the negotiation process and the negotiation is terminated.
[0015] Step 11: Perform error correction and confidentiality amplification techniques on the remaining key K raw Further processing is performed to obtain the final security key K final .
[0016] Positive effects of the present invention
[0017] (1) The dual-bit representation method proposed in the present invention can ensure that when both parties are legitimate users, the odd bits of the binary sequences of both parties are completely consistent, and such consistency is independent of the transmission channel and the measurement equipment.
[0018] (2) The two-stage authentication scheme proposed in the present invention has two advantages. One is that it can significantly improve the efficiency of identity authentication between the sender and the receiver. The second advantage is that it increases the key formation rate of the communicating parties.
[0019] (3) The quantum key distribution protocol proposed in this invention can realize multiple functions such as identity authentication, key distribution and error correction in an environment with noisy, insecure channels and imperfect measurement equipment. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 It is a basic flow chart of the example method of the present invention. DETAILED DESCRIPTION
[0021] Modern communications pay more and more attention to the confidentiality of communication data while ensuring high-speed and efficient data transmission. Building a quantum transmission network and realizing unconditional quantum key distribution will be the focus of future research to ensure communication security. With the continuous development of quantum technology, it has become possible to use quantum devices to build quantum networks and realize quantum encrypted online communications, remote video conferencing and other applications. The generation and distribution of quantum keys are attracting the attention of more and more scholars.
[0022] However, there are still many problems in the existing research on QKD protocols. For example, most of the widely used QKD protocols do not solve the problem of identity authentication, so most QKD protocols are subject to man-in-the-middle attacks. The eavesdropper Eve can pretend to be a legitimate user, establish a quantum communication channel with Alice and Bob respectively, and use the conventional QKD protocol to complete the key distribution, so that all information of both parties can be stolen without being noticed in the subsequent communication process. In addition, there are various real noises and measurement errors in the actual application environment. These factors will affect the accuracy of the key. Existing research often does not take the imperfect operating environment into consideration.
[0023] In view of the various problems existing in the above existing research, the present invention proposes a Bell-state-based authenticated quantum key distribution protocol, the BBS-AQKD protocol, for short-distance point-to-point key distribution. The protocol utilizes the characteristics of the entangled state and introduces a special position mapping function to achieve functions such as fast identity verification, secondary identity authentication, error estimation and correction, and key distribution during key negotiation. It can run simply and efficiently in an undesirable real environment, and verifies the security of shared keys and identity authentication through theoretical analysis, and can resist third-party man-in-the-middle attacks and measurement attacks.
[0024] The present invention provides a Bell-state-based authenticated quantum key distribution protocol, and the specific process is as follows:
[0025] Step 1: Alice first generates a random sequence S of length L. A =s1s2...s L , and according to S A The Bell state is prepared based on the results of
[0026] Step 2: Alice extracts a particle from each Bell state, combines them in order to form a sequence P1 of length L, saves it in her own quantum pool, and sends another particle sequence P2 of length L, which is also combined in order, to Bob in turn;
[0027] Step 3: After Bob receives the particle sequence sent by Alice, both parties use the shared long-term key K l The value of selects the measurement basis;
[0028] Step 4: Alice and Bob, the two communicating parties, agree on the binary sequence represented by the quantum state according to the rules, and then convert the quantum states they measure into the corresponding binary sequence K A and K B, Alice takes out the odd bits of the inferred binary sequence to form a new sequence. Similarly, Bob also takes out the odd bits of his own binary sequence to form a new sequence. The new sequences of both parties are recorded as K Aodd and K Bodd , the same even-numbered bits also form the sequence K Aeven and K Beven ;
[0029] Step 5: Bob randomly selects a hash function h B Send it to Alice, Alice uses h B and two random numbers r generated by the quantum random number generator A1 and r A2 , perform a series of calculations, and obtain the results Messag A and P A Send to Bob;
[0030] Step 6: When Bob receives the authentication information, he uses h B , K l Messag sent by Alice A Perform a series of calculations to verify Alice’s identity and record the number of bit errors || R B ||;
[0031] Step 7: While Bob is authenticating Alice, Alice is also authenticating Bob. First, Alice randomly selects a hash function h A Send it to Bob, Bob uses h A and two random numbers r generated by the quantum random number generator B1 and r B2 . Perform a series of calculations and send the results to Messag B and P B Send to Alice;
[0032] Step 8: After Alice receives the authentication information, she uses h A , K l Perform a series of calculations with MessagB sent by Bob to verify Bob's identity and record the number of bit errors || R A ||;
[0033] Step 9. Alice and Bob publish their calculated ||R A || and ||R B ||, and calculate the bit error rate and when or When any one of them exceeds the set threshold, the key distribution is terminated;
[0034] Step 10: When the bit error rates of both parties are within the set threshold, the identity authentication of both parties is considered successful. In general, some post-processing operations are required for the remaining keys. Similarly, if the estimated channel bit error rate is higher than the threshold set by the BBS-AQKD protocol, it is considered that there is an eavesdropper in the negotiation process and the negotiation is terminated.
[0035] Step 11: Perform error correction and confidentiality amplification techniques on the remaining key K raw Further processing is performed to obtain the final security key K final .
Claims
1. A Bell-state-based authenticated quantum key distribution protocol, characterized in that: The protocol includes the following steps: Step 1: Alice first generates a random sequence S of length L. A =s1s2…s L , and according to S A The Bell state is prepared based on the results of Step 2: Alice extracts a particle from each Bell state, combines them in order to form a sequence P1 of length L, saves it in her own quantum pool, and sends another particle sequence P2 of length L, which is also combined in order, to Bob in turn; Step 3: After Bob receives the particle sequence sent by Alice, both parties use the shared long-term key K l The value of selects the measurement basis; Step 4: Alice and Bob, the two communicating parties, agree on the binary sequence represented by the quantum state according to the rules, and then convert the quantum states they measure into the corresponding binary sequence K A and K B Alice takes out the odd bits of the inferred binary sequence to form a new sequence. Similarly, Bob also takes out the odd bits of his own binary sequence to form a new sequence. The new sequences of both parties are recorded as K Aodd and K Bodd , the same even number of bits also form the sequence K Aeven and K Beven ; Step 5: Bob randomly selects a hash function h B Send it to Alice, Alice uses h B and two random numbers r generated by the quantum random number generator A1 and r A2 , perform a series of calculations, and obtain the results Messag A and P A Send to Bob; Step 6: After Bob receives the authentication information, he uses h B , K l Messag sent by Alice A Perform a series of calculations to verify Alice’s identity and record the number of bit errors || R B ||; Step 7: While Bob is authenticating Alice, Alice is also authenticating Bob. First, Alice randomly selects a hash function h A Send it to Bob, Bob uses h A and two random numbers r generated by the quantum random number generator B1 and r B2 , perform a series of calculations, and obtain the results Messag B and P B Send to Alice; Step 8: After Alice receives the authentication information, she uses h A , K l Messag sent by Bob B Perform a series of calculations to verify Bob's identity and record the number of bit errors || R A ||; Step 9. Alice and Bob publish their calculated ||R A || and ||R B ||, and calculate the bit error rate and when or When any one of them exceeds the set threshold, the key distribution is terminated; Step 10: When the bit error rates of both parties are within the set threshold, the identity authentication of both parties is considered successful. Generally, some post-processing operations are required for the remaining keys. Similarly, if the estimated channel bit error rate is higher than the threshold set by the BBS-AQKD protocol, it is considered that there is an eavesdropper in the negotiation process and the negotiation is terminated. Step 11: Perform error correction and confidentiality amplification techniques to the remaining key K raw Further processing is performed to obtain the final security key K final .
2. The Bell-state-based authenticated quantum key distribution protocol according to claim 1, characterized in that: The Bell state preparation rule described in step 1 is as follows 3. The Bell-state-based authenticated quantum key distribution protocol according to claim 1, characterized in that: Step 3 requires selecting the measurement basis according to the following rules:
4. The Bell-state-based authenticated quantum key distribution protocol according to claim 1, characterized in that: Step 4 requires double bit conversion according to the following rules; And according to the characteristics of quantum entanglement, Alice can judge the quantum state received by Bob through her own quantum state and the situation of sending Bell state, as shown in the following formula Alice infers the quantum state received by Bob:
5. The Bell-state-based authenticated quantum key distribution protocol according to claim 1, characterized in that: Step 5 Alice uses h B and two random numbers r generated by the quantum random number generator A1 and r A2 , perform the following calculations; Messag A It is a password used to quickly authenticate Alice’s identity. T is the length of the password. Messag A It consists of six parts: Auth A2 , r A1 , r A2 , T A1 , T A2 and T A3 , where the first part is Auth A2 It is used to authenticate Alice for the first time. The following five parts ensure the secondary authentication of Alice's identity. A3 , Alice can make a Aeven To P A The only mapping operation f A , where f A The specific meaning is that when (Auth A3 ) i = 0, Alice looks for the k0th "0" in K Aeven The position where it appears in and record its position as (P A ) i ,k0 is Auth A3 The cumulative number of "0"s when the i-th position is reached. Otherwise, Alice looks for the k1-th "1" and records it. k1 is the Auth A3 The cumulative number of "1"s at the i-th position, and so on, after finding T positions, Alice will A and Messag A Sent to Bob as authentication information.
6. The Bell-state-based authenticated quantum key distribution protocol according to claim 5, characterized in that: Step 6 Bob uses h B , K l Messag sent by Alice A Perform the following calculations; Get Auth B3 After that, Bob performs function mapping P′ B , where Bob's operation f′ B This means that when (Auth′ B3 ) i = 0, Bob looks for the k0th "0" in K Beven The position where it appears in the B ) i Otherwise, Bob records the position where the k1th "1" appears. Similarly, Bob uses Auth′ B3 Get T position information P′ B First, Bob uses the above formula to calculate Auth′ B2 With Auth A2 For comparison, if Bob finds Auth′ B2 and Auth A2 If there is a discrepancy between one of them, Alice’s identity can be directly deemed as illegal and the negotiation can be abandoned; After the first round of identity authentication is passed, a second round of identity authentication is required. Bob uses the P transmitted by Alice to A , and the P′ calculated by oneself B Do the following: a) P A and P′ B Align by bit; b) From P′ B Starting from the first position, find the first A Non-corresponding position i; c) If Then Replace with 0, and all the position information of 0 after position i is moved to the position information of the previous 0. All 1 position information is moved to the next 1 position information; similarly, if Then Replace with 1, At the same time, all the 1 position information after position i moves to the previous 1 position information, and all the 0 position information moves to the next 0 position information; d) Find the next non-corresponding position and repeat c) until P A and P′ B Completely correspond, and record the number of non-correspondences as ||R B ||.
7. The Bell-state-based authenticated quantum key distribution protocol according to claim 6, characterized in that: Steps 7 and 8 indicate that while Bob is authenticating Alice, Alice is also authenticating Bob, and Alice and Bob use the same authentication method as steps 5 and 6.
8. The Bell-state-based authenticated quantum key distribution protocol according to claim 3, characterized in that: Step 9 The bit error rate is calculated as follows
Citation Information
Patent Citations
The quantum secret information direct communication method with mutual authentication
AU2020100261A4
Authenticable multi-user quantum key distribution method based on single particles
CN110266493A