Quantitative characterization of security parameters of quantum key distribution algorithm and security level grading method and device

By quantitatively characterizing the security parameters and security level classification methods of quantum key distribution algorithms, the problem of insufficient security parameters in quantum key distribution systems in practical applications is solved. This enables the classification of security levels and parameter settings for quantum key distribution systems with different application requirements, and is applicable to various quantum key distribution protocols and encoding methods.

CN116208321BActive Publication Date: 2025-12-19Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211684666.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-27
Publication Date
2025-12-19
Estimated Expiration
2042-12-27

AI Technical Summary

Technical Problem

In the existing technology, there is a lack of effective methods for quantitatively characterizing the security parameters of quantum key distribution systems and classifying their security levels according to different application requirements, resulting in insufficient security strength of quantum key distribution systems in practical applications.

Method used

This paper proposes a method and apparatus for quantitative characterizing security parameters and classifying security levels in quantum key distribution algorithms. The method quantitatively characterizes the security parameters of confidentiality amplification and low entropy by the number of guesses, measures the consistency of classical channels and keys by the authentication failure probability and the key consistency failure probability, and sets security level standards according to different application requirements.

Benefits of technology

It achieves accurate classification of security levels and quantitative characterization of parameters in quantum key distribution systems, and is applicable to various quantum key distribution protocols and encoding methods, thereby improving the security and applicability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116208321B_ABST
    Figure CN116208321B_ABST
Patent Text Reader

Abstract

The application discloses a kind of quantum key distribution algorithm security parameter quantitative characterization and security level grading method and device, can be quantitatively characterized by guessing times secret amplification security parameter and small entropy security parameter of quantum key distribution, authentication security parameter and key consistency security parameter of quantum key distribution are quantitatively characterized by failure probability, and this quantitative characterization mode establishes basis and means for quantum key distribution system security level division.The present application can be applied to single-photon encoding quantum key distribution system, entanglement state encoding quantum key distribution system and coherent state encoding quantum key distribution system and the key generated by different quantum key distribution systems, with wide application scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of quantum key distribution, in particular to a method and device for quantitatively characterizing security parameters of quantum key distribution algorithm and classifying security levels, which can be widely applied to technical specifications and detection specifications of actual quantum key distribution systems, and has practicability in industrialization and productization of quantum key distribution systems. BACKGROUND

[0002] Based on quantum mechanics principles such as quantum uncertainty and unknown quantum state non-cloning, quantum key distribution (QKD) [C.H. Bennett and G. Brassard, Proceedings of IEEE International Conference on Computers, Systems and Signal Processing, Bangalore, India. New York: IEEE, 175-179 (1984).] can negotiate information theory secure keys for two parties at a long distance, and its security does not depend on the computing or storage capacity of an eavesdropper, which is a new technical means for improving security of key protection. Main steps of quantum key distribution protocol include quantum process and classical process, wherein the quantum process is divided into quantum state generation, quantum channel transmission and quantum state measurement, and the classical process is divided into base vector comparison, error rate estimation, error correction, consistency check, privacy amplification and authentication. The quantum channel has no security assumption, but the attack behavior of an eavesdropper will introduce errors, which will be found by the two legitimate communication parties. The classical channel needs to transmit classical information such as base information, and an eavesdropper may adopt a man-in-the-middle attack. In order to resist the man-in-the-middle attack, the two receiving parties need to authenticate the classical channel in information theory security. However, the information theory security of quantum key distribution is based on the security of the algorithm used, and an insecure algorithm may directly lead to information leakage of the quantum key distribution system. The algorithms used in quantum key distribution include error rate estimation algorithm, error correction algorithm, privacy amplification algorithm, consistency check algorithm, authentication algorithm and small entropy estimation algorithm [R. Renner. International Journal of Quantum Information, (2008).], wherein the privacy amplification algorithm, the consistency check algorithm, the authentication algorithm and the small entropy estimation algorithm are directly related to the security metric of quantum key distribution. The security parameters corresponding to the privacy amplification algorithm and the small entropy estimation algorithm can be used to estimate the trace distance between the actual key and the ideal key, the security parameter corresponding to the consistency check algorithm is used to estimate the consistency of the keys generated by the two parties, and the security parameter corresponding to the authentication algorithm is used to estimate the attack ability of the man-in-the-middle in the classical channel.

[0003] The main shortcomings of the prior art are as follows: the security strength of the key generated by the actual quantum key distribution system is determined by the security parameter, however, for actual cryptographic applications, how to quantitatively characterize the security parameter required by the quantum key distribution according to different application requirements is an important problem in the actual application of the quantum key distribution system. When classifying the security levels of different quantum key distribution systems, the security parameter of the quantum key distribution system needs to be relied on, and there is currently no effective method and means for setting different security parameter ranges according to different security levels. SUMMARY

[0004] The present application is directed to the problem that when classifying the security levels of different quantum key distribution systems, the security parameter of the quantum key distribution system needs to be relied on, and there is currently no effective method and means for setting different security parameter ranges according to different security levels, and proposes a method and device for quantitatively characterizing the security parameter of a quantum key distribution algorithm and classifying the security levels, which can quantitatively characterize the privacy amplification security parameter and small entropy security parameter of the quantum key distribution by the number of guesses, and quantitatively characterize the authentication security parameter and key consistency security parameter of the quantum key distribution by the failure probability. The quantitatively characterizing method establishes a basis and means for classifying the security levels of the quantum key distribution system, and can be applied to the keys generated by different quantum key distribution systems such as single-photon encoding quantum key distribution systems, entangled state encoding quantum key distribution systems and coherent state encoding quantum key distribution systems, and has a wide range of application scenarios.

[0005] To achieve the above object, the present application adopts the following technical solutions:

[0006] The present application proposes a method for quantitatively characterizing the security parameter of a quantum key distribution algorithm and classifying the security levels, which uses the authentication failure probability ε au to measure the authentication security of the classical channel, uses the key consistency check failure probability ε con to measure the consistency of the generated key, and establishes corresponding security level standards according to different application requirements.

[0007] Given a set of security parameters (ε pa , ε min , ε au , ε con ) of the quantum key distribution system and security parameter requirements (δ pa , δ min , δ au , δ con ), the method comprises:

[0008] Step 1: Detect whether the authentication security parameter of the classical channel of the quantum key distribution system satisfies ε au < δ auIf not satisfied, the authentication security parameter does not meet the security level requirement, if satisfied, enter step 2;

[0009] Step 2: Detect whether the quantum key distribution system consistency security parameter satisfies ε con <δ con If not satisfied, the consistency security parameter does not meet the security level requirement, if satisfied, enter step 3;

[0010] Step 3: Calculate the single round attack guess number and the multi-round attack guess number through the quantum key distribution system small entropy security parameter ε min And the privacy amplification security parameter ε pa Calculate the single round attack guess number and the multi-round attack guess number, and judge whether it satisfies 2ε min +ε pa <2δ min +δ pa If not satisfied, the key security parameter does not meet the security level requirement, if satisfied, enter step 4;

[0011] Step 4: According to the small entropy security parameter ε min , the privacy amplification security parameter ε pa And the error rate, the key rate formula is calculated;

[0012] Step 5: According to the key rate formula and the random number extractor, the secret key after error correction is processed to obtain the final key.

[0013] Further, the key rate formula is:

[0014]

[0015] Where R is the key rate, dim(X) is the dimension of the quantum key distribution system, X is the key, f is the error correction efficiency, e is the error rate, The small entropy is Decided by the error rate e and the error correction efficiency f, n is the key length, H(.) is the entropy function, and E represents the eavesdropper.

[0016] Further, the method can be applied to various quantum key distribution protocols, including BB84 quantum key distribution protocol, six-state quantum key distribution protocol, continuous variable quantum key distribution protocol, measurement device independent quantum key distribution protocol and device independent quantum key distribution protocol.

[0017] Further, the method can be applied to quantum key distribution systems of various encoding modes in combination with the decoy state scheme, including polarization encoding quantum key distribution system, phase encoding quantum key distribution system and time phase encoding quantum key distribution system.

[0018] Another aspect of the present application provides a device for quantitatively characterizing security parameters of a quantum key distribution algorithm and classifying security levels, which utilizes an authentication failure probability ε au to measure the authentication security of a classical channel con to measure the consistency of generated keys, and establishes corresponding security level standards according to different application requirements

[0019] A known set of security parameters (ε pa , ε min , ε au , ε con ) of a quantum key distribution system and security parameter requirements (δ pa , δ min , δ au , δ con ) of a security level are used in the device, which comprises:

[0020] A first detection module is used to detect whether the authentication security parameters of a classical channel of a quantum key distribution system satisfy ε au < δ au If not, the authentication security parameters do not meet the security level requirements, and if yes, the second detection module is entered.

[0021] A second detection module is used to detect whether the consistency security parameters of a quantum key distribution system satisfy ε con < δ con If not, the consistency security parameters do not meet the security level requirements, and if yes, the first calculation module is entered.

[0022] A first calculation module is used to calculate the single-round attack guessing number and the multi-round attack guessing number through the small entropy security parameter ε min and the privacy amplification security parameter ε pa of a quantum key distribution system, and to determine whether 2ε min + ε pa < 2δ min + δ pa is satisfied, if not, the key security parameters do not meet the security level requirements, and if yes, the second calculation module is entered.

[0023] A second calculation module is used to calculate a key rate formula according to the small entropy security parameter ε min , the privacy amplification security parameter ε pa and the error rate.

[0024] A privacy amplification module is used to perform privacy amplification processing on the error-corrected key to obtain a final key according to the key rate formula and a random number extractor.

[0025] Further, the key rate formula is:

[0026]

[0027] wherein R is the key rate, dim(X) is the dimension of the quantum key distribution system, X is the key, f is the error correction efficiency, e is the error rate, is the small entropy, determined by the error rate e and the error correction efficiency f, n is the key length, H(.) is the entropy function, and E represents the eavesdropper.

[0028] Further, the device can be applied to various quantum key distribution protocols, including BB84 quantum key distribution protocol, six-state quantum key distribution protocol, continuous variable quantum key distribution protocol, measurement-device-independent quantum key distribution protocol and device-independent quantum key distribution protocol.

[0029] Further, the device can be applied to quantum key distribution systems of various encoding modes in combination with the decoy state scheme, including polarization encoding quantum key distribution system, phase encoding quantum key distribution system and time-phase encoding quantum key distribution system.

[0030] Compared with the prior art, the present application has the beneficial effects:

[0031] The present application can quantitatively characterize the security amplification parameter and the small entropy security parameter of quantum key distribution by the number of guesses, and quantitatively characterize the authentication security parameter and the key consistency security parameter of quantum key distribution by the failure probability. The quantitative characterization method provides a basis and means for the security level division of quantum key distribution systems, and can be applied to keys generated by different quantum key distribution systems such as single-photon encoding quantum key distribution system, entangled state encoding quantum key distribution system and coherent state encoding quantum key distribution system, and has a wide range of application scenarios.

[0032] The quantitative characterization of the security parameters of the quantum key distribution algorithm and the security level grading method and device provided by the present application are independent of specific quantum key distribution protocols and quantum key distribution systems, and therefore can be widely applied to various quantum key distribution protocols such as BB84 quantum key distribution protocol, six-state quantum key distribution protocol, continuous variable quantum key distribution protocol, measurement-device-independent quantum key distribution protocol and device-independent quantum key distribution protocol. Meanwhile, the method can be applied to quantum key distribution systems of various encoding modes in combination with the decoy state scheme, including polarization encoding quantum key distribution system, phase encoding quantum key distribution system and time-phase encoding quantum key distribution system.

[0033] The quantitative characterization of the security parameters of the quantum key distribution algorithm and the security level grading method and device provided by the present application can also be used as a basis for actual quantum key distribution system product standard specifications and security detection standard specifications. BRIEF DESCRIPTION OF DRAWINGS

[0034] Figure 1 A flow chart of a quantum key distribution protocol of an embodiment of the application;

[0035] Figure 2 A flow chart of a method for quantitatively characterizing security parameters and classifying security levels of a quantum key distribution algorithm of an embodiment of the application;

[0036] Figure 3 An example structure of a device for quantitatively characterizing security parameters and classifying security levels of a quantum key distribution algorithm of an embodiment of the application. DETAILED DESCRIPTION

[0037] The application will be further explained in conjunction with the accompanying drawings and specific embodiments:

[0038] Quantum key distribution can negotiate an information-theoretically secure key between geographically separated users. The main steps of a quantum key distribution protocol include quantum processes and classical processes. The quantum processes include quantum state generation, quantum channel transmission, and quantum state measurement. The classical processes include basis vector comparison, error rate estimation, error correction, consistency check, privacy amplification, and authentication. The specific steps of a quantum key distribution protocol are shown in FIG. 1. Figure 1

[0039] Quantum state generation: Alice prepares single-photon states as carriers of quantum bits. Alice first generates a random binary classical bit string, and randomly selects a basis from two sets of bases, and loads the randomly generated binary sequence onto the corresponding single-photon state.

[0040] Quantum channel transmission: Alice transmits the prepared single-photon state to Bob through a quantum channel. The quantum channel in an actual quantum key distribution system can be an optical fiber or free space.

[0041] Quantum state measurement: After the photon reaches Bob, Bob randomly selects a set of measurement bases from the horizontal-vertical basis or the diagonal basis to measure the received single-photon state.

[0042] Basis vector comparison: Bob publishes the measurement basis he used. If the basis used by Alice to modulate the photon state is the same as the measurement basis at Bob's end, Alice informs Bob that the basis is successful. Otherwise, both parties discard the measurement result.

[0043] ​Error rate estimation: Because the experimental instruments and the experimental environment can not meet the perfect theoretical requirements and the eavesdropper maliciously destroys the channel, the initial generated key bit string must exist a certain error. Alice and Bob randomly publish a part of the original key, when the randomly published key bits are long enough, the error rate obtained by parameter estimation is considered to be the same as the error rate of the original key bits.

[0044] Error correction: According to the error rate obtained by parameter estimation, the remaining original key bits are corrected. The error correction step can be understood as that the communication parties correct the bit errors in the channel transmission.

[0045] Consistency check: In the error correction process, the remaining key bits of Alice and Bob may not be consistent, so the consistency of the key bits of Alice and Bob is ensured by performing consistency check on the corrected bit sequence.

[0046] Privacy amplification: Although the key bits of Alice and Bob after error correction are completely the same, the channel may still introduce phase errors of quantum states, and the error correction information may also leak part of the key information, so that the eavesdropper Eve can obtain part of the information of the final key bits. In order to make the key information obtained by Eve can be exponentially small, Alice and Bob use a hash function to act on the key bits after error correction, and the key bits after action are the final secure key bits.

[0047] Authentication: The base information, error rate estimation information and error correction information transmitted in the quantum key distribution protocol need to be transmitted through a classical channel. In order to resist the man-in-the-middle attack in the classical channel, the legitimate communication parties need to perform information theory security authentication on the channel.

[0048] The application proposes that the algorithm security parameter set of quantum key distribution includes key rate security parameter ε, authentication security parameter ε au and key consistency security parameter ε con . The key rate security parameter includes privacy amplification security parameter ε pa and small entropy security parameter ε min . According to the required security parameters, the actual key rate formula can be calculated. By using the quantum residual hash lemma and the basic properties of quantum von Neumann small entropy, the relationship between the trace distance of the actual key and the ideal key and the privacy amplification security parameter and the small entropy security parameter can be estimated. The authentication security parameter and the key consistency security parameter are determined by the selection of the ε-ASU2 generic hash function family.

[0049] Table 1 shows the security parameters of the quantum key distribution algorithm.

[0050] Table 1. Security parameters of quantum key distribution algorithm

[0051] Table 1. Security parameters of quantum key distribution algorithm

[0051]

[0052] The key rate security parameter ε quantitatively estimates the trace distance between the actual key and the ideal key

[0053]

[0054] where ρ Ext(X,Y)YE is the quantum state between Alice and Eve after the secret amplification of the actual quantum key distribution system, and ρ Y describes the actual generated key. ρ U is the random number seed required for the secret amplification, and ρ n is the maximum mixed state, and ρ describes the ideal completely random key.

[0055] The SU2 hash function is used as a strong random number extractor in quantum key distribution, and the random number seed can be used to select the hash function.

[0056] Definition (SU2 hash function). Let M and T be finite sets, |M| = m, |T| = n, and a (N; m, n) hash family is a set H = {h: M→T} of N hash functions from M to T. If for any different elements m1, m2∈M and any elements t1, t2∈T (which can be equal), there are N / n2 functions such that h(m1) = t1 and h(m2) = t2.

[0057]

[0058] Then H is called an SU2 strong universal hash family.

[0059] The quantum random number extractor {0,1} n ×{0,1} d →{0,1} m is a strong random number extractor, and for the trace distance ε between the actual key and the ideal key, it satisfies the following relationship

[0060] ε = ε pa + 2ε min ,

[0061] The above formula shows that the security parameter ε of the final key is determined by the small entropy security parameter ε min and the security parameter ε pa of the secret amplification. Therefore, before the security analysis, the small entropy security parameter ε min and the secret amplification security parameter ε pa must be given.

[0062] Before secret amplification, we can assume that the quantum state of the eavesdropper is ρ XEFor the quantum states obtained in practical quantum key distribution system The small entropy form is defined as follows

[0063]

[0064] where is the set of all quantum states satisfying D(ρ XE ,ρ UE )≤ε min .

[0065] According to the quantum residual hash lemma, the secret amplified compressed key is

[0066]

[0067] When considering joint attacks, the front and back pulses can satisfy the condition of independent and identically distributed. Based on the quantum asymptotic equipartition property, the small entropy can be estimated by the following inequality

[0068]

[0069] In the security analysis of quantum key distribution, the key rate formula used for calculation is

[0070]

[0071] And is determined by the error rate e and the error correction efficiency f, so the final key rate formula is

[0072]

[0073] where dim(X) is the dimension of Alice's system, f is the error correction efficiency, n is the key length, H(.) is the entropy function, and E represents the eavesdropper Eve. In the BB84 type quantum key distribution protocol, the dimension of Alice's system is 2, so the key rate formula is revised as

[0074]

[0075] Based on the security parameters ε min and ε pa , the key rate R can be estimated.

[0076] The trace distance ε between the actual key and the ideal key is to measure the security of the key from the perspective of the legitimate communication parties. How to examine the security of the key from the perspective of the eavesdropper is an important research content in cryptography. From the perspective of the eavesdropper, the probability distribution corresponding to the key X is P X , which is assumed to be arranged as follows

[0077] p(x0x1...x n-2 x n-1 = 00...00)

[0078] ≥ p(x0x1...x n-2 x n-1 = 00...01)

[0079] ≥...

[0080] ≥ p(x0x1...x n-2 x n-1 = 11...11),

[0081] An effective attack strategy of the eavesdropper is to guess the key from high probability to low probability, so the number of guesses of the key X can be obtained as

[0082] W(X) = p(x0x1...x n-2 x n-1 = 00...00)

[0083] + 2xp(x0x1...x n-2 x n-1 = 00...01)

[0084] +...

[0085] + βxp(x0x1...x n-2 x n-1 = 11...11),

[0086] If the probability distribution corresponding to the sample set X is P X is a uniform probability distribution, i.e. then the number of guesses of the sample set X is

[0087]

[0088] It is assumed that the probability distribution of the measurement results of Alice and Eve in the quantum key distribution system is P XE , and for any measurement result, it can be obtained that

[0089]

[0090] For any measurement result e of the eavesdropper, the probability distribution P A (x|e) of Alice and the trace distance of the uniform probability distribution P U are ε e . For any measurement result e of the eavesdropper, the number of guesses of the eavesdropper satisfies

[0091]

[0092] Finally, the average number of guesses of the eavesdropper satisfies

[0093]

[0094] Obviously, if the measurement result e Δ , there may exist At this time, the eavesdropper can determine the key with certainty. However, the upper bound of the probability of this occurrence is

[0095] P E (e Δ )≤ε

[0096] For the above analysis, the present application proposes two attack strategies to measure the security of the privacy amplification parameter and the small entropy parameter.

[0097] The first attack strategy is a single round attack strategy. This strategy is to guess the key generated by each quantum key distribution according to the probability from large to small, and the number of guesses required is When the security parameter ε is small, we can get

[0098] The second attack strategy is to guess the key generated by each quantum key distribution according to the maximum possible probability, and if the guess is unsuccessful, the key of the next round of quantum key distribution is guessed. The probability of successful single guess by the eavesdropper is ε. If the eavesdropper wants to successfully guess the key with at least a probability of q, the number of guesses required is at least If the post-processing time is 1 per second, the eavesdropper needs to guess for seconds.

[0099] For the authentication security of the classical channel and the consistency confirmation of the key, the ε-ASU2 universal hash function family can be selected for security authentication and key consistency verification.

[0100] Definition (ε-ASU2 universal hash function family). Let M and T be finite sets, and |M| = m, |T| = n, an (N; m, n) hash function family is a set H = {h: M → T} of N hash functions from M to T. Let ε > 0, if H satisfies the following two conditions, H is called an ε-ASU2 universal hash function family.

[0101] (i) For any m1∈M and t1∈T, there are exactly N / n h∈H such that h(m1) = t1.

[0102]

[0103] (ii) For any two given different elements m1, m2 e M, and any two given elements t1, t2 e T (possibly equal), there are at most εN / n functions h such that h(m1) = t1, h(m2) = t2.

[0104]

[0105] Suppose H is an (N; m, n) ε-ASU2 universal hash function family, and the authentication key is randomly selected each time of authentication, then the probability of success of the attacker to forge a message and its hash value is 1 / n. After intercepting a message and its hash value, the probability of success of the forgery is not more than ε. Based on the properties of the ε-ASU2 universal hash function family, the authentication security parameter can be defined as ε au = ε.

[0106] Similarly, after the error correction step, the key needs to be confirmed for consistency, and the communication parties can also select an ε'-ASU2 universal hash function family to calculate the check value of the key after error correction. When the keys of the communication parties are inconsistent, the probability of obtaining the same check value is not more than ε, so the key consistency security parameter can be defined as ε con = ε'.

[0107] The present application proposes to use the secret amplification security parameter ε pa and the small entropy security parameter ε min to measure the number of guesses of single-round attacks and the number of guesses of multi-round attacks, and to characterize the security of the generated key according to the size of the number of guesses.

[0108] The present application proposes to use the authentication failure probability ε au to measure the authentication security of the classical channel, and to use the key consistency verification failure probability ε con to measure the consistency of the generated key.

[0109] According to the security parameters of the quantum key distribution algorithm, the present application proposes a quantitative characterization and security level grading method of the security parameters of the quantum key distribution algorithm. According to different application requirements, corresponding security level standards can be established. For example, high security level algorithm parameter range, medium security level algorithm parameter range and low security level algorithm parameter range can be established according to different security levels. A legitimate user can detect whether the security parameters of an actual quantum key distribution system meet the parameter range required by the security level according to actual application requirements. If it meets the requirements, it meets the security level requirements, otherwise it does not meet the security level requirements.

[0110] Based on the quantitative characterization and security level grading method of the quantum key distribution algorithm security parameters, the present application provides a quantum key distribution security level grading process as shown in Figure 2 .

[0111] A known set of security parameters (ε pa ,ε min ,ε au ,ε con ) and a security level requirement security parameter (δ pa ,δ min ,δ au ,δ con ) of a quantum key distribution system, and the security level classification is specifically implemented as follows:

[0112] Step 1: detecting whether the authentication security parameter of the classical channel of the quantum key distribution system satisfies ε au <δ au , if not, the authentication security parameter does not meet the security level requirement, and if yes, entering step 2;

[0113] Step 2: detecting whether the consistency security parameter of the quantum key distribution system satisfies ε con <δ con , if not, the consistency security parameter does not meet the security level requirement, and if yes, entering step 3;

[0114] Step 3: calculating the single-round attack guessing number and the multi-round attack guessing number through the small entropy security parameter ε min and the privacy amplification security parameter ε pa of the quantum key distribution system, and judging whether it satisfies 2ε min +ε pa <2δ min +δ pa , if not, the key security parameter does not meet the security level requirement, and if yes, entering step 4;

[0115] Step 4: calculating the key rate formula according to the security parameters (the small entropy security parameter ε min , the privacy amplification security parameter ε pa ) and the error rate;

[0116] Step 5: performing privacy amplification processing on the error-corrected key to obtain the final key according to the key rate formula and the random number extractor.

[0117] Further, the method can be applied to various quantum key distribution protocols, including BB84 quantum key distribution protocol, six-state quantum key distribution protocol, continuous variable quantum key distribution protocol, measurement-device-independent quantum key distribution protocol and device-independent quantum key distribution protocol.

[0118] Further, the method can be applied to quantum key distribution systems of various encoding modes in combination with the decoy state scheme, including polarization encoding quantum key distribution system, phase encoding quantum key distribution system and time-phase encoding quantum key distribution system.

[0119] On the basis of the above-mentioned embodiments, as shown in Figure 3 Another aspect of the present application proposes a device for quantitatively characterizing and classifying the security level of the security parameters of a quantum key distribution algorithm, which utilizes the authentication failure probability ε au to measure the authentication security of a classical channel, utilizes the key consistency verification failure probability ε con to measure the consistency of the generated key, and establishes corresponding security level standards according to different application requirements.

[0120] Given a set of security parameters (ε pa , ε min , ε au , ε con ) of a quantum key distribution system and security parameter requirements (δ pa , δ min , δ au , δ con ), the device comprises:

[0121] A first detection module for detecting whether the authentication security parameters of the classical channel of the quantum key distribution system satisfy ε au < δ au If not, the authentication security parameters do not meet the security level requirements, and if yes, the second detection module is entered.

[0122] A second detection module for detecting whether the consistency security parameters of the quantum key distribution system satisfy ε con < δ con If not, the consistency security parameters do not meet the security level requirements, and if yes, the first calculation module is entered.

[0123] A first calculation module for calculating the single-round attack guess number and the multi-round attack guess number through the small entropy security parameter ε min and the privacy amplification security parameter ε pa of the quantum key distribution system, and judging whether 2ε min + ε pa < 2δ min + δ pa is satisfied, if not, the key security parameters do not meet the security level requirements, and if yes, the second calculation module is entered.

[0124] A second calculation module for calculating a key rate formula according to the small entropy security parameter ε min , the privacy amplification security parameter ε pa , and the error rate.

[0125] A privacy amplification module for performing privacy amplification processing on the error-corrected key to obtain the final key according to the key rate formula and the random number extractor.

[0126] Further, the key rate formula is:

[0127]

[0128]

[0129] wherein R is the key rate, dim(X) is the dimension of the quantum key distribution system, X is the key, f is the error correction efficiency, e is the error rate, is the small entropy, determined by the error rate e and the error correction efficiency f, n is the key length, H(.) is the entropy function, and E represents the eavesdropper.

[0130] Further, the device can be applied to various quantum key distribution protocols, including BB84 quantum key distribution protocol, six-state quantum key distribution protocol, continuous variable quantum key distribution protocol, measurement-device-independent quantum key distribution protocol and device-independent quantum key distribution protocol.

[0131] Further, the device can be applied to quantum key distribution systems of various encoding modes in combination with the decoy state scheme, including polarization encoding quantum key distribution system, phase encoding quantum key distribution system and time-phase encoding quantum key distribution system.

[0132] In summary, the present application can quantitatively characterize the security amplification security parameter and small entropy security parameter of quantum key distribution by the number of guesses, and quantitatively characterize the authentication security parameter and key consistency security parameter of quantum key distribution by the failure probability. This quantitative characterization method provides a basis and means for the security level division of quantum key distribution systems, and can be applied to keys generated by different quantum key distribution systems such as single-photon encoding quantum key distribution systems, entangled state encoding quantum key distribution systems and coherent state encoding quantum key distribution systems, and has a wide range of application scenarios.

[0133] The quantitative characterization of security parameters of quantum key distribution algorithms and the security level grading method and device provided by the present application are independent of specific quantum key distribution protocols and quantum key distribution systems, and therefore can be widely applied to various quantum key distribution protocols such as BB84 quantum key distribution protocol, six-state quantum key distribution protocol, continuous variable quantum key distribution protocol, measurement-device-independent quantum key distribution protocol and device-independent quantum key distribution protocol. Meanwhile, the method can be applied to quantum key distribution systems of various encoding modes in combination with the decoy state scheme, including polarization encoding quantum key distribution system, phase encoding quantum key distribution system and time-phase encoding quantum key distribution system.

[0134] The method and device for quantitatively characterizing security parameters of a quantum key distribution algorithm and classifying security levels can also be used as a basis for actual quantum key distribution system product standard specifications and security detection standard specifications.

[0135] The above merely shows the preferred embodiments of the present application, and it should be noted that those skilled in the art can make several improvements and refinements without departing from the principles of the present application, and these improvements and refinements should also be considered within the protection scope of the present application.

Claims

1. A method for quantitatively characterizing security parameters of a quantum key distribution algorithm and classifying security levels, characterized in that, Using authentication failure probability ε au Measuring authentication security of classical channel, using key consistency check failure probability ε con Measuring the consistency of key generation, and establishing corresponding security level standards according to different application requirements; A known quantum key distribution system has a set of security parameters (ε pa ,ε min ,ε au ,ε con ) and a security level requirement security parameter (δ pa ,δ min ,δ au ,δ con ), and the method comprises: Step 1: Check whether the authentication security parameters of the quantum key distribution system classical channel satisfy ε au <δ au If not, the authentication security parameters do not meet the security level requirements, and if so, go to Step 2; Step 2: Check if the consistency security parameter of the quantum key distribution system meets ε con <δ con If not, the consistency security parameter does not meet the security level requirement, and if yes, go to Step 3. Step 3: Calculate the single-round attack guess number and the multi-round attack guess number by the small entropy security parameter ε of the quantum key distribution system min and the secret amplification security parameter ε pa Calculate the single-round attack guess number and the multi-round attack guess number, and determine whether it meets 2ε min + ε pa < 2δ min + δ pa If it does not meet, the key security parameter does not meet the security level requirement, and if it meets, go to step 4 Step 4: Calculate the secret amplification security parameter ε min , the secret amplification security parameter ε pa and the bit error rate to calculate the key rate formula; Step 5: the final key is obtained by secret amplification of the error-corrected key according to a key rate formula and a random number extractor; The key rate formula is: where R is the key rate, dim(X) is the dimension of the quantum key distribution system, X is the key, f is the error correction efficiency, e is the error rate, is small, determined by the error rate e and the error correction efficiency f, n is the key length, H(.) is the entropy function, and E represents the eavesdropper.

2. The method of claim 1, wherein the method further comprises: determining the security level of the quantum key distribution algorithm based on the security parameter. The method is applied to various quantum key distribution protocols, including BB84 quantum key distribution protocol, six-state quantum key distribution protocol, continuous variable quantum key distribution protocol, measurement-device-independent quantum key distribution protocol and device-independent quantum key distribution protocol.

3. The method of claim 1, wherein the method further comprises: determining the security level of the quantum key distribution algorithm based on the security parameter. The method is applied to various quantum key distribution systems of various encoding modes in combination with the decoy state scheme, including polarization encoding quantum key distribution system, phase encoding quantum key distribution system and time-phase encoding quantum key distribution system.

4. A device for quantitatively characterizing security parameters of a quantum key distribution algorithm and classifying security levels, characterized in that it comprises: Using authentication failure probability ε au Measuring authentication security of classical channel, using key consistency check failure probability ε con Measuring consistency of generated key, establishing corresponding security level standards according to different application requirements; A set of security parameters (ε pa ,ε min ,ε au ,ε con ) and a security level requirement security parameter (δ pa ,δ min ,δ au ,δ con ) of a known quantum key distribution system, the device comprising: The first detection module is configured to detect whether the authentication security parameter of the quantum key distribution system classical channel satisfies ε au <δ au If the authentication security parameter does not satisfy ε, the authentication security parameter does not meet the security level requirement; if the authentication security parameter satisfies ε, the second detection module is entered. The second detection module is configured to detect whether the consistency security parameter of the quantum key distribution system satisfies ε. con <δ con If the consistency security parameter does not satisfy the security level requirement, the consistency security parameter is not qualified for the security level requirement, and if the consistency security parameter satisfies the security level requirement, the first calculation module is entered. The first computation module is used to compute the low-entropy security parameter ε of the quantum key distribution system. min and security amplification parameter ε pa Calculate the number of guesses in a single round of attack and the number of guesses in multiple rounds of attack, and determine whether 2ε is satisfied. min +ε pa <2δ min +δ pa If the conditions are not met, the key security parameters do not meet the security level requirements; if they are met, the system will proceed to the second calculation module. The second calculation module is configured to calculate a key rate formula according to a small-entropy security parameter ε min , a secret amplification security parameter ε pa , and a bit error rate. The second calculation module is configured to calculate a key rate formula according to a small-entropy security parameter ε min , a secret amplification security parameter ε pa , The secret amplification module is configured to perform secret amplification on the error-corrected key according to a key rate formula and a random number extractor to obtain a final key; The key rate formula is: where R is the key rate, dim(X) is the dimension of the quantum key distribution system, X is the key, f is the error correction efficiency, e is the error rate, is small, determined by the error rate e and the error correction efficiency f, n is the key length, H(.) is the entropy function, and E represents the eavesdropper.

5. The apparatus for quantitatively characterizing security parameters of a quantum key distribution algorithm and classifying security levels according to claim 4, wherein, The device is applied to various quantum key distribution protocols, including BB84 quantum key distribution protocol, six-state quantum key distribution protocol, continuous variable quantum key distribution protocol, measurement-device-independent quantum key distribution protocol and device-independent quantum key distribution protocol.

6. The apparatus for quantitatively characterizing security parameters of a quantum key distribution algorithm and classifying security levels according to claim 4, wherein, The device is applied to various quantum key distribution systems of various encoding modes in combination with the decoy state scheme, including polarization encoding quantum key distribution system, phase encoding quantum key distribution system and time-phase encoding quantum key distribution system.

Citation Information

Patent Citations

  • Quantum key distribution, privacy amplification and data transmission methods, apparatuses, and system

    CN105553648A

  • Hybrid attack detection method for continuous variable quantum key distribution system

    CN112953973A