Device-independent quantum secret sharing method based on multiphoton entanglement

By employing a device-independent quantum secret sharing method based on multiphoton entangled states, the security vulnerabilities and performance evaluation issues of existing protocols under actual experimental conditions are addressed. This method enables quantitative calculation of key leakage rate and generation rate, thereby improving security and practicality.

CN116647341BActive Publication Date: 2026-04-10NANJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NANJING UNIV OF POSTS & TELECOMM
Filing Date
2023-07-11
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Existing device-independent quantum secret sharing protocols lack performance evaluation and security guidance under actual experimental conditions, and have security vulnerabilities, making them difficult to defend against attacks from imperfect devices.

Method used

A device-independent quantum secret sharing method based on multi-photon entangled states is adopted. Three-photon Greenbergee-Horne-Zeilinger states are prepared and measured and security detected under linear optical conditions. The key leakage rate and generation rate are evaluated using Svetlichny polynomials and CHSH polynomials. The final key is formed by combining public channel error correction and private amplification.

Benefits of technology

It improves the security of quantum secret sharing schemes under practical imperfect experimental conditions, can resist all attacks against imperfect devices, provides quantitative calculations of key leakage rate and generation rate, and promotes the practical application of device-independent quantum secret sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116647341B_ABST
    Figure CN116647341B_ABST
Patent Text Reader

Abstract

The present application belongs to the technical field of quantum communication, and discloses a device-independent quantum secret sharing method based on multi-photon entanglement, which requires a key sender to prepare a large number of identical three-photon GHZ states, and to send two photons in each GHZ state to two key receivers respectively; after receiving the photons, the three parties randomly select measurement bases to measure the adversary's photons, and publish the measurement bases and part of the measurement results, so as to estimate the values of Svetlichny polynomials and CHSH polynomials; the security of the transmitted key is ensured by Svetlichny inequality violation and CHSH inequality violation. The present application can resist all attacks from imperfect device ends, reduce the requirement for the security of experimental equipment, effectively enhance the security of QSS under actual experimental conditions, and has important application in the field of future quantum secure direct communication.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of quantum communication, and particularly relates to a device-independent quantum secret sharing method based on multi-photon entanglement. BACKGROUND

[0002] Quantum communication refers to information transmission by using the basic principles of quantum mechanics; quantum communication has the function of sensing eavesdropping and has absolute security, which is the biggest advantage distinguishing it from classical communication. Quantum communication includes many research branches, such as quantum key distribution (QKD) and quantum secret sharing (QSS); QKD can distribute a series of secure keys between the sender and the receiver, while QSS involves quantum key distribution among multiple parties; quantum secret sharing (QSS) allows a key distributor to split a key into several sub-keys, and the sub-keys are distributed to multiple members by using quantum states as carriers; only all members can cooperate to read the distributed key, and the security of QSS is also based on the basic principles of quantum mechanics. Although QSS has unconditional security in theory, there are still some security loopholes in actual QSS systems due to the imperfection of devices, and there are many attack schemes for these security loopholes.

[0003] Device-independent (DI) quantum communication protocols can regard all devices as black boxes, and do not care about the specific operation process in the box, but only through the classical input and output values of the black box to violate the Bell inequality to ensure the security of communication. DI quantum communication protocols can resist all attacks on imperfect device ends, and provide the highest security guarantee for quantum communication under actual experimental conditions. In the field of QSS, in 2019, Roy and Mukhopaday proposed the first DI-QSS theoretical protocol; however, the protocol belongs to a pure theoretical protocol, and important performance parameters such as the key generation rate and information leakage rate of QSS are not obtained, and it does not have a guiding role for the experimental implementation of DI-QSS. In order to quantitatively evaluate the important performance indicators of DI-QSS and strengthen the guiding role of the actual experiment of DI-QSS, it is necessary to design a DI-QSS protocol that can be experimentally implemented under linear optical conditions and evaluate its performance. SUMMARY

[0004] To solve the above technical problems, the application provides a device-independent quantum secret sharing method based on multi-photon entangled states under linear optical conditions, which gives important performance parameters such as DI-QSS key leakage rate and key production rate, and promotes the practicality of DI-QSS.

[0005] The device-independent quantum secret sharing method based on multi-photon entangled states provided by the application comprises the following steps:

[0006] Step 1: User A prepares a large number of identical three-photon Greenbergee-Horne-Zeilinger (GHZ) states Where |H> and |V> represent horizontal polarization and vertical polarization of the photons respectively; User A groups the corresponding photons of each pair of GHZ state photons into three sequences S1, S2, S3, wherein each sequence contains one photon in a pair of GHZ states; User A retains the S1 sequence and distributes all photons of the S2 sequence and the S3 sequence to user B and user C respectively through two quantum channels in turn;

[0007] Step 2: After receiving the photons, user A, user B and user C randomly select measurement bases to measure the photons in the S1, S2, S3 sequences respectively; after the measurement of all photons is completed, user A, user B and user C publish the measurement bases of each photon in the S1, S2, S3 sequences in turn;

[0008] Step 3: User A, user B and user C run device-independent security detection, if the security detection passes, the communication continues, if the security detection fails, the communication terminates;

[0009] Step 4: When user A, user B and user C all select σ x , user C publishes the measurement results of all photons, and user A and user B randomly publish the measurement results of part of the photons for estimating the error rate e caused by the photon transmission process; for the remaining photons, user B infers the measurement results of user A by combining his own measurement results and the measurement results published by user C, thereby obtaining the original key transmitted by user A;

[0010] Step 5: Repeat steps 1 to 4 until user B obtains the required number of original keys;

[0011] Step 6: User A, user B and user C perform error correction and private amplification on the obtained original keys in the public channel to form the final secure key.

[0012] Further, in the step 2, three users randomly select measurement bases, wherein the measurement bases of user A are A1=σ x , A2=σ y , the measurement bases of user B are B1=σ x , the measurement bases of user C are C1=σ x , C2=-σ y ; σ x and σ y are Pauli matrices, and the specific form is:

[0013]

[0014] Three users' measurement results are +1 or -1 under all measurement bases; if one party loses photons, the measurement result is randomly recorded as +1 or -1; the measurement results corresponding to the measurement bases of user A, user B and user C are recorded as {a1, a2}, {b1, b2, b3} and {c1, c2} respectively.

[0015] Further, in steps 3 and 4, when user A, user B and user C all select the first measurement base, the measurement results of the three parties are used to transfer the key; in the case of other measurement base selections, user A, user B and user C all publish the measurement results, which are used to estimate the value of Svetlichny polynomial S ABC and the value of CHSH polynomial S AB of photons at user A and user B; if S ABC > 4, which is equivalent to S AB > 2, it indicates that the photon transmission process is secure, and the communication continues; if S ABC ≤ 4, which is equivalent to S AB ≤ 2, it indicates that the photon transmission process is not secure, and the communication terminates.

[0016] Further, when all photon detectors at any user do not respond, the user randomly publishes the measurement result of +1 or -1; all published measurement results are used to estimate the value of Svetlichny polynomial S ABC :

[0017] S ABC = <a1b2c2> + <a1b3c1> + <a2b2c1> - <a2b3c2> + <a2b3c1> + <a2b2c2> + <a1b3c2> - <a1b2c1>,

[0018] where <a i b j c k represents the expectation value of the measurement results when user A chooses A i , i = 1, 2 measurement bases, user B chooses B j , j = 2, 3 measurement bases, and user C chooses C k , k = 1, 2 measurement bases; actually, S ABC can be rewritten as:

[0019] S ABC = S AB c2+ S AB 'c1,

[0020] where c1and c2represent the measurement results when user C chooses C1and C2measurement bases, respectively, S AB represents the CHSH polynomial of the photons at user A and user B, and S AB ' represents the equivalent version of the CHSH polynomial of the photons at user A and user B; the specific forms of S AB and S AB ' are respectively:

[0021] S AB = <a1b2> + <a2b2> + <a1b3> - <a2b3> ,

[0022] S AB '= <a2b3> + <a2b2> + <a1b3> - <a1b2>,

[0023] <a i b j > represents the expectation value of the measurement results when user A chooses A i , i = 1, 2 measurement bases, user B chooses B j , j = 2, 3 measurement bases.

[0024] Further, in step 4, when user B chooses B1 measurement base, and user A and user C choose A1 and C1 measurement bases, the form of GHZ state is rewritten as:

[0025]

[0026] wherein,

[0027] After the measurement is completed, user C publishes its measurement result; user A and user B publish part of the measurement results for estimating the error rate, and the measurement results not published by user A and user B are used for generating the key; if the measurement results of the three users are different from the four results given in the above formula, i.e. |+++>, |+->, |-+->, and |--+>, it is defined that an error occurs;

[0028] Specifically, user B combines the measurement results of user C and itself to deduce the measurement result of user A, and thus deduces the key transmitted by user A; wherein, if the measurement result of user A is |+>, it represents that the key is 0; if the measurement result of user A is |->, it represents that the key is 1.

[0029] Further, corresponding to other selection base conditions of the three users, i.e. user B chooses B1 base, and user A and user C choose A2C1 or A2C2 or A1C2 or A2C3, the three users need to discard their own measurement results.

[0030] Further, since the measurement result of user C is all published, the eavesdropper does not need to eavesdrop the photons transmitted by user A to user C; in a noisy environment, the maximum photon number ratio I BE satisfies:

[0031]

[0032] wherein, h(x) is a binary Shannon entropy:

[0033] h(x) = -xlog2(x) - (1-x)log2(1-x).

[0034] If S AB reaches the maximum value Then the maximum number of photons that the eavesdropper can eavesdrop from the process of user A sending to user B is I BE = 0, so the eavesdropper cannot obtain any key, that is, the key leakage rate of the scheme is 0; Then I BE > 0, but the communication party can estimate the upper bound of I BE In the above two cases, the communication party considers that the key transmission process is safe; if S AB ≤ 2, the eavesdropper can obtain all the keys without being found, therefore, the communication party considers that the key transmission process is not safe in this case, and gives up the communication and rechecks the channel.

[0035] Further, the actual key generation rate R satisfies:

[0036]

[0037] In order to generate the key, it is required that R > 0.

[0038] The method provided by the application can eliminate the additional requirement for the security of the quantum secret sharing protocol experimental equipment, can resist all attacks on the imperfect experimental equipment, and can effectively improve the security of the quantum secret sharing scheme under actual imperfect experimental conditions; the scheme is based on linear optical conditions and can be realized under current experimental conditions; the important performance parameters such as the key leakage rate, the key generation rate and the error rate of the DI-QSS are quantitatively calculated, which has an important guiding role for subsequent DI-QSS experiments. BRIEF DESCRIPTION OF DRAWINGS

[0039] Figure 1 is a flowchart of a device-independent quantum secret sharing method based on a multi-photon entangled state provided by an embodiment of the application;

[0040] Figure 2 is a schematic diagram of a device-independent quantum secret sharing scheme provided by an embodiment of the application. DETAILED DESCRIPTION

[0041] In order to make the content of the application more easily understood, the application will be further described in detail below according to specific embodiments and in combination with the drawings.

[0042] As shown in Figure 1 , the application provides a device-independent quantum secret sharing method based on a multi-photon entangled state, which comprises the following steps:

[0043] Step 1: User A prepares a large number of identical three-photon Greenbergee-Horne-Zeilinger (GHZ) states Wherein |H> and |V> represent the horizontal polarization and vertical polarization of the photons respectively; User A divides each pair of GHZ state photons into three sequences S1, S2, S3, wherein each sequence contains one photon in a pair of GHZ states; User A retains the S1 sequence and distributes all photons in the S2 sequence and the S3 sequence to user B and user C through two quantum channels in turn respectively;

[0044] Step 2: After receiving the photons, user A, user B and user C randomly select measurement bases to measure the photons in the S1, S2, S3 sequences respectively; User A has two sets of measurement bases, A1 = σ x and A2 = σ y , user B has three sets of measurement bases, B1 = σ x , User C has two sets of measurement bases, C1 = σ x and C2 = -σ y ; wherein σ x and σ y are Pauli matrices, and the specific form is:

[0045]

[0046] The measurement results of the three users under all measurement bases are +1 or -1; if the photons of one party are lost, the measurement results are randomly recorded as +1 or -1; the measurement results corresponding to the measurement bases of user A, user B and user C are recorded as {a1, a2}, {b1, b2, b3} and {c1, c2} respectively; after the measurement of all photons is completed, user A, user B and user C successively publish the measurement bases of each photon in the S1, S2, S3 sequences.

[0047] Step 3: Only when user A, user B and user C all select the first measurement base (A1, B1, C1), the measurement results of the three parties are used to transmit the key; in other measurement base selection cases, user A, user B and user C all publish the measurement results, which are used to estimate the value of Svetlichny polynomial (S ABC ) and the value of CHSH polynomial (S AB ) of the photons at user A and user B;

[0048] The specific case is: when user B selects the B2 or B3 measurement base, the measurement results of the three users are published regardless of the measurement bases selected by user A and user C, which are used to estimate the value of Svetlichny polynomial (S ABC ):

[0049] S ABC = <a1b2c2> + <a1b3c1> + <a2b2c1> - <a2b3c2> + <a2b3c1>

[0050] + <a2b2c2> + <a1b3c2>< a1b2c1 where, < a i b j c k represents the expectation value of the measurement result when user A chooses A i (i = 1, 2) measurement basis, user B chooses B j (j = 2, 3) measurement basis, and user C chooses C k (k = 1, 2) measurement basis. In fact, S ABC can be rewritten as:

[0051] S ABC = S AB c2 + S AB 'c1,

[0052] where c1 and c2 represent the measurement results when user C chooses C1 and C2 measurement basis, respectively, S AB represents the CHSH polynomial of the photons at user A and user B, and S AB ' represents the equivalent version of the CHSH polynomial of the photons at user A and user B. The specific forms of S AB and S AB ' can be represented as:

[0053] S AB = <a1b2> + <a2b2> + <a1b3> - <a2b3> ,

[0054] S AB '= <a2b3> + <a2b2> + <a1b3> - <a1b2>

[0055] <a i b j > represents that when user A selects A i (i = 1, 2) measurement basis, user B selects B j (j = 2, 3) measurement basis, the expected value of the measurement result obtained is;

[0056] If S ABC > 4 (equivalent to S AB > 2), it indicates that the photon transmission process is secure, and the communication continues. If S ABC ≤ 4 (equivalent to S AB ≤ 2), it indicates that the transmission process is not secure, and the communication is terminated.

[0057] Step 4: When user A, user B, and user C all select the first measurement basis (A1, B1, C1), user C publishes all the measurement results of the photons, and user A and user B randomly publish part of the measurement results of the photons for estimating the error rate e caused by the photon transmission process; for the other remaining photons, user B combines his own measurement results with the measurement results published by user C to infer the measurement results of user A, thereby obtaining the original key transmitted by user A.

[0058] When user B selects B1 measurement basis, and user A and user C select A1 and C1 measurement basis, the form of the GHZ state can be rewritten as:

[0059]

[0060] After the measurement is completed, user C publishes his measurement results. User A and user B publish part of the measurement results for estimating the error rate (if the measurement results of the three users are different from the four results |+++>, |+->, |-+->, and |--+> given in the above formula, it is defined as an error occurs), and the measurement results not published by user A and user B are used to generate the key. Specifically, user B can combine the measurement results of user C and himself to infer the measurement results of user A, thereby inferring the key transmitted by user A. Among them, if the measurement result of user A is |+>, it represents that the key is 0, and if the measurement result of user A is |->, it represents that the key is 1.

[0061] For example, if the measurement result of user B is |+>, and the measurement result published by user C is |->, user B can infer that the measurement result of user A is |->, and thereby know that the key transmitted by user A is 1;

[0062] Corresponding to the other basis selection conditions of the three users, i.e., user B selects B1 basis, and user A and user C select A2C1, A2C2, A1C2, and A2C3, the three users need to discard their own measurement results.

[0063] Step 5: Repeat steps 1 to 4 until user B gets the number of raw keys he needs.

[0064] Step 6: User A, user B and user C correct the errors and amplify the privacy of the raw keys obtained in the public channel to form the final secure keys.

[0065] Considering the influence of channel noise on the key transfer, the existence of channel noise leads to the decrease of S ABC (S AB ) and the increase of error rate e. Since the measurement results of user C are all published, the eavesdropper does not need to intercept the photons transmitted by user A to user C; the eavesdropper only needs to intercept the photons transmitted by user A to user B. In the noisy environment, it can be estimated that the maximum photon number ratio I BE satisfies:

[0066]

[0067] where h(x) is the binary Shannon entropy:

[0068] h(x) = -x log2(x) - (1 - x) log2(1 - x).

[0069] If it is assumed that the eavesdropper intercepts the photons transmitted by user A to user B and randomly prepares a photon to send to user B. In the case where the three communication parties all select the σ x basis, the eavesdropper also selects the σ x basis to measure the intercepted photons. In combination with the measurement results published by user C, the measurement results of user A can be inferred, that is, the key transferred by A is obtained; therefore, the key leakage rate of the present method is I BE .

[0070] If S AB takes the maximum value , the maximum photon number ratio I BE that the eavesdropper can eavesdrop in the process of transmitting the photons from user A to user B is 0, so the eavesdropper cannot obtain any key, that is, the key leakage rate of the present method is 0; , I BE > 0, but the communication parties can estimate the upper bound of I BE ; in the above two cases, the communication parties consider that the key transfer process is safe; if S AB ≤ 2, the eavesdropper can obtain all the keys without being found, therefore, the communication parties consider that the key transfer process is not safe in this case, give up the communication and recheck the channel.

[0071] According to the basic principle of information theory, the key generation rate R of the method satisfies:

[0072]

[0073] The above merely describes the preferred embodiments of the present application, and is not intended to further limit the present application, and any equivalent changes made according to the content of the present application and the drawings are within the scope of the present application. < / a1b3> < / a2b2> < / a2b3> < / a2b3> < / a1b3> < / a2b2> < / a1b2> < / a2b2c2> < / a2b3c1> < / a2b3c2> < / a2b2c1> < / a1b3c1> < / a1b2c2> < / a1b3> < / a2b2> < / a2b3> < / a2b3> < / a1b3> < / a2b2> < / a1b2> < / a1b3c2> < / a2b2c2> < / a2b3c1> < / a2b3c2> < / a2b2c1> < / a1b3c1> < / a1b2c2>

Claims

1. A device-independent quantum secret sharing method based on multi-photon entanglement, characterized by, Comprising the following steps: Step 1: User A prepares a large number of identical three-photon GHZ states where and denote horizontal and vertical polarization of the photons, respectively; User A groups the corresponding photons of each pair of GHZ state photons into three sequences S1, S2, S3; User A retains the S1 sequence and distributes all the photons of the S2 sequence and the S3 sequence to User B and User C, respectively, in order through two quantum channels; Step 2: After receiving the photons, user A, user B and user C randomly select the measurement bases of the sequence of S1, S2 and S3 to measure the photons respectively; after the measurement of all the photons is completed, user A, user B and user C successively announce the measurement bases of each photon in S1, S2 and S3; Step 3: User A, user B and user C run the device-independent security detection, if the security detection passes, the communication continues, if the security detection does not pass, the communication terminates; Step 4: When user A, user B and user C all choose At the base time, user C publishes the measurement results of all photons, while user A and user B publish the measurement results of part of photons randomly for estimating the error rate e caused by the photon transmission process; for the other remaining photons, user B infers the measurement results of user A by combining his own measurement results and the measurement results published by user C, so as to obtain the original key transmitted by user A; Step 5: Steps 1 to 4 are repeated until user B obtains the required number of original keys; Step 6: User A, user B and user C perform error correction and private amplification on the obtained original keys in the public channel to form the final secure key; In step 2, three users randomly select measurement bases, wherein the measurement bases of user A are the measurement bases of user B are the measurement bases of user C are ; is a Pauli matrix, and its specific form is: , Three users measure the results of +1 or -1 under all measurement bases; if a photon is lost by one party, the measurement result is randomly recorded as +1 or -1; the measurement results corresponding to the measurement bases of user A, user B, and user C are respectively recorded as , , .

2. The multiphoton entanglement based device-independent quantum secret sharing method according to claim 1, wherein: In steps 3 and 4, when users A, B, and C all choose the first measurement basis, their measurement results are used to transmit the key; when other measurement basis choices are made, users A, B, and C all publish their measurement results to estimate the Svetlichny polynomial. The value of, and the CHSH polynomial of the photons at user A and user B. The value; if it satisfies , equivalent to This indicates that the photon transmission process is safe and communication continues. , equivalent to If this happens, it means the photon transmission process is insecure, and communication is terminated.

3. The multiphoton entanglement based device-independent quantum secret sharing method according to claim 2, wherein: When none of the photon detectors at either user respond, the user randomly announces a measurement of +1 or -1; all announced measurements are used to estimate the value of the Svetlichny polynomial ​ , where represents the expected value of the measurement result when user A chooses A i , i = 1, 2 measurement basis, user B chooses B j , j = 2, 3 measurement basis, and user C chooses C k , k = 1, 2 measurement basis. In practice, the expression of can be rewritten as: , where and represent the measurement results obtained by user C choosing C1 and C2 to measure the clock time, respectively, represent the CHSH polynomials of the photons at user A and user B, represent the equivalent versions of the CHSH polynomials of the photons at user A and user B; and are expressed as , , represents the expected value of the measurement results when user A chooses A i , i = 1,2 measurement bases, user B chooses B j , j = 2,3 measurement bases.

4. The multiphoton entanglement based device-independent quantum secret sharing method according to claim 1, wherein: In step 4, when user B chooses the measurement basis, while users A and C choose and the measurement basis, the form of the GHZ state is rewritten as: , wherein ; After the measurements are completed, user C publishes all of the measurements; users A and B publish some of the measurements, which are used to estimate the error rate The measurements that users A and B do not publish are used to generate the key; if the measurements of the three users are different from the four results given by the above equation then an error is defined to have occurred; Specifically, user B combines the measurement results of user C and itself to deduce the measurement result of user A, and thus deduces the key transmitted by user A; wherein, if the measurement result of user A is , it represents that the key is 0; if the measurement result of user A is , it represents that the key is 1.

5. The multiphoton entanglement based device-independent quantum secret sharing method according to claim 1, wherein: Corresponding to the other base selection conditions of the three users, that is, user B selects B1 base, and user A and user C select A2C1 or A2C2 or A1C2 or A2C3, then the three users need to discard their own measurement results.

6. The multiphoton entanglement based device-independent quantum secret sharing method according to claim 2, wherein: Since the measurements of user C are all published, the eavesdropper does not need to eavesdrop the photons transmitted from user A to user C; in a noisy environment, the maximum photon number ratio that the eavesdropper can eavesdrop in the process of photons transmitted from user A to user B is estimated satisfies: , wherein is the binary Shannon entropy: , If The maximum value is obtained The maximum number of photons that the eavesdropper can eavesdrop from the process sent by user A to user B So the eavesdropper cannot obtain any key, that is, the key leakage rate of the scheme is 0; But the upper bound of In the above two cases, the communication party considers that the key transmission process is safe; if The eavesdropper can obtain all the keys without being found, therefore, the communication party considers that the key transmission process is not safe in this case, gives up the communication, and rechecks the channel.​ 7. The multi-photon entanglement-based device-independent quantum secret sharing method according to claim 6, characterized in that: The actual key generation rate R satisfies: , To generate the key, the following is required .