A method for enhancing security strength of quantum key distribution

By employing a security enhancement function to perform operations on the key during the post-processing of the quantum key distribution system, the problem of insufficient key security in practical applications is solved, and the key security strength is improved. This method is applicable to various QKD systems and deployed networks.

CN116170134BActive Publication Date: 2026-04-21Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Chinese People's Liberation Army Cyberspace Force Information Engineering University
Filing Date
2022-12-21
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

In practical applications, existing quantum key distribution systems suffer from differences in generated keys compared to the ideal key distribution due to hardware and environmental variations, which affects security. Furthermore, users find it difficult to adjust security parameters to meet different needs.

Method used

By employing custom security enhancement functions to operate on the generated key during the post-processing of the quantum key distribution system, the security of the key is enhanced. This includes methods such as XOR operations to generate a new key Z, thereby improving the security strength.

Benefits of technology

Without changing existing hardware and algorithms, this system significantly improves the security strength of keys, is suitable for QKD systems with various encoding schemes, and can be directly applied to deployed QKD networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116170134B_ABST
    Figure CN116170134B_ABST
Patent Text Reader

Abstract

The application provides a quantum key distribution security strength enhancement method. The method comprises the following steps: step 1: when the security parameter epsilon of the generated original key X is greater than the security parameter required by the actual application, a new key Y is generated; step 2: a self-defined security enhancement function is used, the key X and the key Y are input as independent variables into the security enhancement function for operation, and the operation result is used as the final key Z. When the security parameter of the generated original key is greater than the security parameter required by the actual application, the security strength is enhanced by using M independent original keys, and the specific operation comprises: the M independent original keys are input as independent variables into the security enhancement function for operation, and the operation result is used as the final key Z.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum key distribution technology, and in particular to a method for enhancing the security strength of quantum key distribution. Background Technology

[0002] The key is the core of a cryptographic system's security. Information-theoretically secure keys combined with one-time pad cryptography can form information-theoretically secure confidential communication. Therefore, ensuring key security is a crucial issue in the field of information security. Quantum Key Distribution (QKD) is a novel technology for improving key security. Its security mechanism is based on the quantum uncertainty principle and the no-cloning principle. No attacker can obtain the key generated by legitimate parties by eavesdropping, a conclusion that has been rigorously proven in theory. The QKD protocol was proposed by Brassard and Bennett in 1984. It can establish information-theoretically secure keys for long-distance communication between parties. The security of QKD is guaranteed by the fundamental principles of quantum mechanics; even if a third-party eavesdropper possesses infinite computing and storage capabilities, they cannot obtain the key information. The main steps of the QKD protocol include quantum and classical processes. The quantum processes are quantum state preparation, transmission, and measurement, while the classical processes are basis setting, error correction, and secure amplification.

[0003] However, the unconditional security of QKD relies on the assumption that all components are ideal. In reality, the light source, modulator, and detector in a QKD system deviate from this ideal, creating various channels for information leakage and impacting the system's security. Therefore, the actually generated keys differ from the ideal key with a uniform probability distribution. From an eavesdropper's perspective, the ideal key distribution follows a uniform probability distribution, meaning the key is completely random for the eavesdropper. However, the keys generated by a real-world QKD system often differ from the ideal key. This difference leads to a non-uniform probability distribution, giving eavesdroppers a higher probability of guessing certain keys. By measuring the statistical distance between the actual key and the ideal key, the security strength of the keys generated by a real-world QKD system can be effectively assessed.

[0004] In practice, the security strength of keys generated by a QKD system is determined by security parameters. However, for real-world cryptographic applications, the given security strength of a QKD system's keys is often insufficient. Therefore, meeting the key security requirements of different strengths is a crucial issue for the practical application of QKD systems. Furthermore, users of QKD systems may be unfamiliar with them, necessitating the modification of QKD system security parameter settings by qualified technical personnel. Summary of the Invention

[0005] To address the issue that traditional methods require specialized technicians to modify the security parameters of the QKD system to meet the security strength requirements of the keys, this invention provides a method for enhancing the security strength of quantum key distribution. This method can enhance the security of the keys generated by the QKD system by adding key post-processing without modifying the existing hardware and algorithm parameters of the QKD system.

[0006] This invention provides a method for enhancing the security strength of quantum key distribution, comprising:

[0007] Step 1: When the security parameter ε of the generated original key X is greater than the security parameter required by the actual application. When that happens, a new key Y is generated;

[0008] Step 2: Define a custom security enhancement function, input the keys X and Y as independent variables into the security enhancement function for calculation, and use the calculation result as the final key Z.

[0009] Furthermore, it also includes:

[0010] When the security parameters of the generated raw key are greater than the security parameters required by the actual application. In this case, the security strength is enhanced by using M independent original keys, specifically by inputting the M independent original keys as independent variables into the security enhancement function for calculation, and using the calculation result as the final key Z.

[0011] Furthermore, the security enhancement function employs an XOR operation.

[0012] Furthermore, the original key X, the new key Y, and M independent original keys are generated using either classical key generation or quantum key generation.

[0013] The beneficial effects of this invention are:

[0014] This invention only requires modification to the post-processing of QKD, without changing the hardware devices and software algorithms of existing QKD systems. Therefore, it can be widely applied to QKD systems with various coding schemes such as polarization QKD system, phase QKD system, and time-phase QKD system, and can be directly applied to existing QKD networks. Attached Figure Description

[0015] Figure 1 For existing quantum key distribution protocol procedures;

[0016] Figure 2 A schematic diagram illustrating a method for enhancing the security strength of quantum key distribution according to an embodiment of the present invention;

[0017] Figure 3The present invention provides a quantum key distribution protocol flow based on enhanced security obtained by applying the quantum key distribution security strength enhancement method to the QKD protocol. Detailed Implementation

[0018] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of the embodiments of this invention will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0019] Before introducing the technical solution of this invention, a brief overview of the traditional QKD protocol process is provided. QKD allows information-theoretically secure keys to be negotiated between users in different locations, such as... Figure 1 As shown, the traditional QKD protocol process includes a quantum stage and a classical stage. The quantum stage includes the preparation, transmission and measurement of quantum states, while the classical stage includes basis pairing, parameter estimation, error correction and security amplification.

[0020] Quantum state preparation: The sender, Alice, prepares a single-photon state as the carrier of the qubit. Alice first generates a set of random binary classical bit strings, then randomly selects one basis from two sets of basis, and loads the randomly generated binary sequence onto the corresponding single-photon state.

[0021] Quantum state transmission: The sender, Alice, transmits the prepared single-photon state to the receiver, Bob, via a quantum channel. In a practical QKD system, the quantum channel can be either an optical fiber or free space.

[0022] Measurement of quantum states: After the photon arrives at Bob's end, Bob randomly selects a pair of received single-photon states from either the horizontal vertical basis or the diagonal basis for measurement.

[0023] Basis matching: Bob announces the measurement basis he used. If the basis used by Alice when modulating the photon state is the same as the measurement basis at Bob's end, Alice notifies Bob that basis matching was successful. Otherwise, both parties discard the measurement results.

[0024] Parameter estimation: Due to the fact that experimental instruments and environments can never meet the theoretical requirements perfectly, and due to malicious sabotage by eavesdroppers in the channel, the initially generated key bit string will inevitably contain a certain number of errors. Alice and Bob randomly publish a portion of the original key. When the randomly published key bits are long enough, the bit error rate obtained by parameter estimation is considered to be the same as the bit error rate of the original key bits.

[0025] Error correction: Based on the bit error rate obtained from parameter estimation, the remaining original key bits are corrected. The error correction step can be understood as the two communicating parties correcting bit errors in the channel transmission so that Alice and Bob's remaining key bits are exactly the same.

[0026] Secrecy Amplification: Although Alice and Bob's corrected key bits are identical, the channel may still introduce phase errors in the quantum state. Simultaneously, the error correction information may leak some key information, allowing Eve, the eavesdropper, to obtain partial information about the final key bits. To ensure that the key information obtained by Eve is exponentially small, Alice and Bob use a hash function to process the corrected key bits; the processed key bits are the final secure key bits.

[0027] The bit sequence obtained after compression using the security amplification function is the key obtained by a real QKD system. Ideally, legitimate communicating parties hope to obtain an ideal key, which is a completely random bit sequence for an eavesdropper. However, due to system errors and the presence of eavesdroppers, the key obtained by a real QKD system is often non-ideal, meaning an eavesdropper can obtain a certain amount of information. If the trace distance between the actual key and the ideal key is ε, it is called an ε-secure key, and ε is also the security parameter of the key.

[0028]

[0029] Where P X It is the key obtained from the actual QKD system, while P U It is the ideal key, therefore It is a uniform probability distribution, N=2 n Where n is the key space size and n is the key length. The above formula defines the security parameter ε of a practical QKD system. This security parameter ε can further estimate the guessing ability of an eavesdropper, as explained below:

[0030] For a known sample set X, its corresponding probability distribution is P. X Assume their probability distributions are arranged as follows:

[0031] p(x0x1…x n-2 x n-1 =00…00)

[0032] ≥p(x0x1…x n-2 x n-1 =00…01)

[0033] ≥…

[0034] ≥p(x0x1…x n-2 x n-1 =11…11),

[0035] Then the number of guesses for the sample set X is defined as:

[0036] W(X) = p(x0x1…x) n-2 x n-1 =00…00)

[0037] +2×p(x0x1…x n-2 x n-1 =00…01)

[0038] +…

[0039] +N×p(x0x1…x n-2 x n-1 =11…11),

[0040] If the probability distribution corresponding to the sample set X is P X It is a uniform probability distribution, that is Then the number of guesses for the sample set X is

[0041]

[0042] For a sample set X, its corresponding probability distribution is P. X If P X With uniform probability distribution P U If the trace distance is ε, then the estimated number of guesses for the sample set X is ε.

[0043]

[0044] Therefore, given ε, the eavesdropper's ability to guess the key can be accurately estimated.

[0045] In a practical QKD system, the security parameter ε for generating keys is determined by the low-entropy security parameter ε. min and the security parameter ε of confidentiality amplification pa The decision was made jointly, among which

[0046] ε=ε pa +2ε min ,

[0047] Therefore, the low-entropy security parameter ε must be determined before security analysis. min and security amplification parameter ε pa Once the security parameter ε and the bit error rate of the protocol are determined, the confidentiality amplification and compression parameters can be obtained.

[0048] Due to safety parameter ε min and ε paOnce the key is generated in the QKD system, it is fixed. Therefore, the security strength ε of the key obtained after QKD key security amplification is determined. How to further enhance the security strength of the key under the condition of known QKD key security strength ε is very important for the practical application of QKD system.

[0049] Example 1

[0050] This invention provides a method for enhancing the security strength of quantum key distribution. This embodiment uses two independent keys as an example and includes the following steps:

[0051] S101: When the original key X is generated (let's assume X = x0x1…x), n-2 x n-1 The safety parameter ε is greater than the safety parameter required for actual application. When that happens, a new key Y is generated (let's assume Y = y0y1…y). n-2 y n-1 The security parameter of key Y is denoted as δ;

[0052] Specifically, the original key X and the new key Y are generated using either classical key generation or quantum key generation.

[0053] S102: Define a custom security enhancement function f, input the keys X and Y as independent variables into the security enhancement function f for operation, and use the operation result as the final key Z.

[0054] For example, if the security enhancement function f uses an XOR operation, then the key Z = z0z1…z n-2 z n-1 ;in Furthermore, the security parameter of key Z is 2εδ. The specific explanation is as follows:

[0055] (1) Taking a key length of 2 as an example, let's assume the probability distribution of key X is as follows:

[0056]

[0057] The security strength of key X is:

[0058]

[0059] Let's assume the probability distribution of key Y is as follows:

[0060]

[0061] The security strength of key Y is:

[0062]

[0063] After post-processing using the security enhancement function f, the probability distribution of the new key Z is as follows:

[0064]

[0065]

[0066]

[0067]

[0068] The security strength of key Z is

[0069]

[0070] (2) Taking the key length n as an example, let's assume the probability distribution of the key X is as follows:

[0071]

[0072] The security strength of key X is:

[0073]

[0074] Let's assume the probability distribution of Y is as follows:

[0075]

[0076] The security strength of key Y is:

[0077]

[0078] The probability distribution of the new key Z obtained after post-processing using the security enhancement function f is as follows:

[0079]

[0080] The security strength of key Z is

[0081]

[0082] When N=2, D(P) Z ,P U )=2εδ,when N>2

[0083] Example 2

[0084] In practical applications, multiple initial key blocks can be selected for processing according to the security strength requirements of different applications. Based on the above embodiment 1, this embodiment presents another method for enhancing the security strength of quantum key distribution in the scenario where there are M independent original keys, specifically including:

[0085] When the security parameters of the generated raw key are greater than the security parameters required by the actual application. In this case, the generated M independent original keys are used (let's assume X0, X1, ..., X...). M-1 To enhance security, specific measures include: Figure 2 As shown, M independent original keys are input as independent variables into the security enhancement function for operation, and the operation result is used as the final key Z.

[0086] Specifically, the M independent original keys are generated using either classical key generation or quantum key generation.

[0087] For example, taking the XOR operation in the security enhancement function as an example, X0, X1, ..., X M-1 The M keys are XORed bit by bit to obtain a new key Z, and the security parameter of key Z is 2. M-1 ε0ε1…ε M-1 Where ε0, ε1, ..., ε M-1 The security parameters are for the M original keys.

[0088]

[0089] This post-processing method effectively enhances the security strength of QKD keys. If a key has a security strength of 0, then the post-processed key X will also have a security strength of 0. This is true if all security parameters satisfy ε0, ε1, ..., ε M-1 If ≤τ, then the full strength of key Z is 2. M-1 τ M .

[0090] It is understandable that when the enhancement method of the present invention is applied to the traditional QKD protocol, such as Figure 3 As shown, in the security-enhanced QKD protocol, the user compares the security parameter ε of the key generated by QKD with the security strength δ required by the application. If If the security parameters of the QKD-generated key meet the security strength required by the application, then the QKD key can be used as the final key. If If the security parameters of the QKD-generated key do not meet the security strength required by the application, the QKD key cannot be directly used as the final key. Based on the QKD key security enhancement scheme proposed in this invention, the key generated by the QKD system can be further processed to obtain a new key security parameter ε′, making... The corresponding enhanced bit sequence can be used as the final key, and the security strength of the key is greatly improved.

[0091] It should be noted that this invention is not limited to keys generated by QKD, but can also be applied to any key generation method that measures security strength based on trace distance. Furthermore, this invention is not limited to performing a bit-by-bit XOR operation on the generated key; it also includes other transformations on the generated key (e.g., compressing different keys using a hash function). In other words, the security enhancement function can be customized according to the needs of the scenario.

[0092] Keys generated based on QKD can be used in various scenarios. On one hand, keys generated by different QKD systems—for example, those using different techniques for discrete and continuous variables—have varying security strengths. Therefore, the initial key block can be composed of keys generated by different QKD techniques, effectively improving the security of keys from different QKD systems. On the other hand, the security strength of a key generated by a single QKD system may not meet the requirements of practical cryptographic applications. Therefore, this method can be used to combine QKD keys obtained through different post-processing steps to improve the security of the final key.

[0093] Since this invention only requires modification to the post-processing of QKD without changing the hardware devices and software algorithms of the existing QKD system, it can be widely applied to QKD systems with various coding schemes such as polarization QKD system, phase QKD system and time phase QKD system, and can be directly applied to the actual QKD networks that have been deployed.

[0094] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for enhancing the security strength of quantum key distribution, characterized in that, Without modifying the existing hardware and algorithm parameters of the QKD system, the security of the generated keys is enhanced by adding key post-processing, including: Step 1: When the security parameter ε of the original key X generated by the QKD system is greater than the security parameter φ required by the actual application, a new key Y is generated using quantum key generation; the original key refers to the compressed sequence generated by the QKD system after security amplification. Step 2: Define a custom security enhancement function. Input the original key X and the new key Y as independent variables into the security enhancement function for operation, and use the operation result as the final key Z of the QKD system. The security enhancement function uses XOR operation or hash function.

2. The method for enhancing the security strength of quantum key distribution according to claim 1, characterized in that, Also includes: The QKD system generates M independent original keys and obtains the security parameters of M independent original keys; When the security parameter of the original key generated by the QKD system is greater than the security parameter φ required for practical applications, M independent original keys are used to enhance the security strength. Specifically, this involves inputting the M independent original keys generated using quantum key generation as independent variables into the security enhancement function for computation, and using the computation result as the final key. .

Citation Information

Patent Citations

  • A method for enhancing data secrecy and a quantum key distribution terminal

    CN109274484A