A novel arbitration quantum signature method based on Bell state

By employing a novel arbitration quantum signature method based on Bell states and utilizing Bell states and a quantum one-time encryption/decryption algorithm, the security deficiencies of existing arbitration quantum signature methods are addressed, enabling more efficient and secure quantum communication.

CN116684089BActive Publication Date: 2026-03-17ZHENGZHOU UNIVERSITY OF LIGHT INDUSTRY
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-12
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

Existing arbitration quantum signature methods are not secure enough against quantum adversary attacks and are susceptible to forgery attacks and side-channel attacks, so their security performance needs to be improved.

Method used

A novel arbitration quantum signature method based on Bell states is adopted. By encoding the output value of the message's hash function, and using Bell states, the BB84 protocol, and the quantum one-time encryption and decryption algorithm, the sender, receiver, and arbitration manager exchange and measure quantum states in a specific manner, and the arbitration manager verifies the legitimacy.

Benefits of technology

It improves the security and communication efficiency of the signature process, provides formalized security proofs, resists quantum adversary attacks, and prevents forgery attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116684089B_ABST
    Figure CN116684089B_ABST
Patent Text Reader

Abstract

The application provides a novel arbitration quantum signature method based on Bell states, which is used for improving the security performance of AQS; the steps are as follows: firstly, a specific Bell state is encoded by the hash function output value of a message; secondly, the signature sender, the signature receiver and the arbitration management party exchange the encoded Bell state sequence in a specific way; the signature sender and the signature receiver respectively encrypt the measured results of the exchanged Bell state by using different keys, and send the ciphertext to the arbitration management party; finally, the arbitration management party verifies the signature legality by searching a specific table. The application performs digital signature based on Bell quantum states, BB84 protocol and quantum one-time encryption and decryption algorithm, and has formal security proof.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum communication technology, and in particular to a novel arbitration quantum signature method based on Bell states. Background Technology

[0002] The plan to "continuously deepen the integration of informatization and industrialization" places higher demands on the security of digital information communication processes. Digital signature methods play a crucial role in maintaining the integrity and verifiability of information communication. However, traditional digital signature methods rely on mathematically difficult assumptions such as large number factorization and discrete logarithms. The rapid development of quantum technology in recent years has posed a significant challenge to classical digital signature methods based on these mathematically difficult assumptions; for example, Shor's algorithm can solve the difficult problem of large number factorization in polynomial time. Therefore, finding more secure alternatives to classical digital signature methods should be prioritized as soon as possible.

[0003] At the beginning of this century, the concept of quantum signature methods was first proposed. Compared to classical digital signature methods, their security relies on the fundamental principles of quantum mechanics, thus serving as an alternative to classical digital signature methods. With continuous research in this field, various quantum signature methods have been proposed in the following years. Among them, the arbitrated quantum signature (AQS) method, by introducing a trusted arbitrator, can efficiently resolve potential disputes in the signature process and resist attacks from quantum adversaries, making it highly valuable in practice. However, the development of AQS has also exposed a series of problems. For example, some AQS based on the commutative Pauil operator cannot resist forgery attacks by the signature recipient. Furthermore, AQS based on classical private keys is vulnerable to attacks such as side-channel attacks, energy analysis, and cool-boot attacks. Therefore, improving the security performance of AQS is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0004] To address the shortcomings of the aforementioned background technologies, this invention proposes a novel arbitration quantum signature method based on Bell states. This method encodes a specific Bell state by hashing the message's hash function output. The sender, receiver, and arbitration administrator exchange the encoded Bell state sequence in a specific manner. The sender and receiver encrypt the exchanged Bell state measurement results using different keys and send the ciphertext to the arbitration administrator. The arbitration administrator verifies the signature's validity by consulting a specific table. This invention utilizes Bell quantum states, the BB84 protocol, and a quantum one-time key encryption / decryption algorithm for digital signatures, providing formalized security proof.

[0005] The technical solution of this invention is implemented as follows:

[0006] A novel arbitration quantum signature method based on Bell states includes three stages: initialization, signature generation, and signature verification.

[0007] The initialization phase steps are as follows:

[0008] S01. The sender of the signature, the receiver of the signature, and the arbitration administrator each prepare a |Ψ| of length n. - >Bell-state sequence; denoted as |AB> n |CD> n and |EF> n ;

[0009] S02, The sender of the signature shares a 2n-length key sk with the arbitration administrator through a quantum key distribution protocol. A The signature recipient shares a 2n-length key sk with the arbitration administrator via a quantum key distribution protocol. B ;

[0010] S03. The sender of the signature calculates the hash function value of message m. Then Seq is obtained by dividing the sequence into pairs in order.

[0011] The steps in the signature generation stage are as follows:

[0012] S11, The sender signs according to the value pair of each sequence Seq |AB> n Encrypt;

[0013] S12. The signature sender, signature receiver, and arbitration manager exchange their second particles. During the particle exchange, the channel is monitored for eavesdropping. If eavesdropping is detected, the signature process is terminated. If no eavesdropping is detected, proceed to step S13.

[0014] S13, Signature sender uses Bell base measurement | AFc n The classical measurement result AF is obtained. n Using quantum one-time pad encryption to encrypt classical measurement results AF n Encrypt and send the ciphertext E skA (AF n The ciphertext is sent to the arbitration management party as a signature of message m. When sending the ciphertext, the channel is also monitored for eavesdropping. If eavesdropping is detected, the signing process is terminated. If no eavesdropping is detected, the signature verification stage begins.

[0015] The steps in the signature verification stage are as follows:

[0016] S21. Signature recipient uses Bell basis measurement | CB> n The classical measurement result CB was obtained.n Using quantum one-time pad encryption to encrypt classical measurement results CB n Encrypt and send the ciphertext E skB (CB n The encrypted message is sent to the arbitration management party. When sending the encrypted message, the channel is also monitored for eavesdropping. If eavesdropping is detected, the signing process is terminated. If no eavesdropping is detected, step S22 is executed.

[0017] S22, Arbitration administrator uses Bell-based measurement |ED> n The classical measurement result ED was obtained. n And obtain AF through quantum one-time key decryption method n and CB n The arbitration administrator uses the key sk A Seq is calculated from message m, and AF is obtained from three sets of classic measurement results. n CB n and ED n Reconstruct Seq′; the arbitration administrator compares Seq with Seq′, and if they match, then the signature E is considered to be true. skA (AF n If the signature is valid, it is considered valid; otherwise, it is considered invalid.

[0018] Preferably, in step S01, the three sets of Bell states |AB> n |CD> n and |EF> n In the middle, use |A> respectively n |C> n and |E> n This refers to the sequence of the first particle in each group of Bell states; simultaneously, |B> is used respectively. n 、|D> n and |F> n This refers to the sequence of the second particle in each group of Bell states.

[0019] Preferably, the hash function value in step S03 The hash function has a length of 2n, and the sequence Seq has a length of n. The computation requires two input parameters: a message m of arbitrary length and a key sk of length 2n. A Hash function The calculation expression is: In this context, || represents bit string concatenation.

[0020] Preferably, in step S11, the signature sender matches |AB> according to the value of sequence Seq. n The encryption method is as follows:

[0021]

[0022] Among them, Seq i This represents the i-th element of the sequence Seq; j is the imaginary unit. Represents the tensor product.

[0023] Preferably, the specific method for the signature sender, signature receiver, and arbitration administrator to exchange their second particles in step S12 is as follows: the signature sender exchanges its second particle sequence |B> n The signature is given to the recipient, who then passes on the second particle sequence |D> n The arbitration administrator handed it over to the arbitration administrator, who then passed on its second particle sequence |F> n The signature is given to the sender; after the exchange is completed, the sender, receiver, and arbitration administrator each hold a copy of the signature. n |CB> n and |ED> n Three sets of quantum sequences.

[0024] Preferably, the method for detecting eavesdropping on the channel in steps S12, S13, and S21 is as follows: When the message sender sends a quantum state message in the state {|0>, |1>}, there are decoy particles randomly distributed in {|->, |+>}; then the message sender randomly inserts the decoy particles into the quantum state message sequence and records the insertion position and state of each decoy particle; finally, the sequence after the insertion of the decoy particles is sent; when the message receiver completes the sequence reception, the message sender publishes the insertion position and state of all decoy particles, and then the message receiver measures all decoy particles using the {|->, |+>} basis; if the error rate exceeds a predetermined threshold, the message receiver can determine that eavesdropping has occurred during communication.

[0025] Preferably, the corresponding formulas for the classical measurement results described in steps S13, S21, and S22 are as follows:

[0026]

[0027]

[0028]

[0029]

[0030] Among them, Ψ - Ψ + Φ - Φ + There are four Bell states, namely:

[0031] Preferably, the quantum one-time pad encryption method described in steps S13 and S21 is as follows: The quantum one-time key decryption method described in step S22 is as follows: The expressions are as follows:

[0032]

[0033]

[0034] Where, k∈{sk A ,sk B}; x is the plaintext to be encrypted, and y is the ciphertext to be decrypted.

[0035] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0036] 1) The signature process uses Bell state and quantum one-time pad technology, making the scheme more secure overall.

[0037] 2) Compared with similar Bell state quantum signature methods, the communication process is more efficient.

[0038] 3) This invention has formalized security proof. Attached Figure Description

[0039] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0040] Figure 1 This is a schematic diagram of particle exchange provided by the present invention.

[0041] Figure 2 This is a schematic diagram illustrating the information transmission during signing, as provided by the present invention. Detailed Implementation

[0042] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0043] This invention provides a novel arbitration quantum signature method based on Bell states, comprising three stages: initialization, signature generation, and signature verification. This embodiment describes the three steps in detail using Alice (signature sender), Bob (signature receiver), and Trent (trusted third-party arbitration manager).

[0044] The initialization phase steps are as follows:

[0045] S01, Alice (signature sender), Bob (signature receiver), and Trent (arbitration administrator) each prepare a signature of length n. The state sequence; denoted as |AB> n |CD> n and |EF> n Three sets of Bell states |AB> n |CD> n and |EF> n In the middle, use |A> respectively n |C> n and |E> n This refers to the sequence of the first particle in each group of Bell states; simultaneously, |B> is used respectively. n 、|D> n and |F> n This refers to the sequence of the second particle in each group of Bell states.

[0046] S02, Alice shares a 2n-length key sk with Trent via a quantum key distribution protocol. A Bob shared a 2n-length key sk with Trent via a quantum key distribution protocol. B In this embodiment, the quantum key distribution protocol can adopt the BB84 protocol. When the length n = 8, sk A =1101010011001000, sk B =0110000010010101.

[0047] S03. Alice calculates the hash function value of message m. Then The sequence Seq is obtained by dividing the data into pairs in sequence.

[0048] The hash function value The hash function has a length of 2n, and the sequence Seq has a length of n. The computation requires two input parameters: a message m of arbitrary length and a key sk of length 2n. A When calculating this hash function, sk A The hash function is appended before and after m, and then the hash value is calculated together. Therefore, the hash function... The calculation expression is: Where || denotes bit string concatenation. When the length n = 8, Seq=(11)(11)(00)(10)(10)(00)(01)(10).

[0049] The steps in the signature generation stage are as follows:

[0050] S11, Alice follows the value pair of each sequence Seq |AB> n Encryption is performed; the encryption method is as follows:

[0051]

[0052] Where i represents the sequence index (i.e., Seq) i (representing the i-th element of sequence Seq, hereinafter the same); j is the imaginary unit. Represents the tensor product.

[0053] Example: |AB> n =|Ψ + >|Ψ + >|Ψ - >|Φ + >|Φ + >|Ψ - >|Φ - >|Φ + >

[0054] S12, Alice, Bob, and Trent exchange their second particles, incorporating a channel eavesdropping detection step during the particle exchange. If eavesdropping is detected after the particle exchange, the signing process terminates; otherwise, it continues. The channel eavesdropping detection method is as follows: When the message sender transmits a quantum state message in the {|0>, |1>} state, there are decoy particles randomly distributed in {|->, |+>}. The message sender then randomly inserts decoy particles into the quantum state message sequence and records the insertion position and state of each decoy particle. Finally, the sequence after the decoy particles are inserted is transmitted. After the message receiver completes the sequence reception, the message sender publishes the insertion positions and states of all decoy particles, and then the message receiver measures all decoy particles using the {|->, |+>} basis. If the error rate exceeds a predetermined threshold, the message receiver can determine that eavesdropping has occurred during communication.

[0055] like Figure 1 As shown, the specific method for exchanging the second particle is as follows: Alice exchanges her second particle sequence |B> n Give it to Bob, who then gives him the second particle sequence |D> nThe sequence was given to Trent, who then passed it on to his second particle, |F>. n Give it to Alice; after the exchange, Alice, Bob, and Trent each hold |AF> n |CB> n and |ED> n Three sets of quantum sequences.

[0056] S13, Alice uses Bell base measurement |AF> n The classical measurement result AF is obtained. n Using quantum one-time pad encryption to encrypt classical measurement results AF n Encrypt and send the ciphertext E skA (AF n ) is sent to Trent as a signature for message m, such as Figure 2 As shown, the steps for adding channel eavesdropping detection when sending ciphertext are illustrated.

[0057] The correspondence between classical measurement results is as follows:

[0058]

[0059]

[0060]

[0061]

[0062] Among them, Ψ - Ψ + Φ - Φ + There are four Bell states, namely:

[0063] Example: Obtain the classical measurement result AF 8 = (01)(11)(00)(10)(11)(01)(01)(11), then the ciphertext E skA (AF n =1010011000011111. After adding the eavesdropping detection step, the message transmitted on the channel is |-10+1001+100-00+1+-1++111>.

[0064] The steps in the signature verification stage are as follows:

[0065] S21, Bob uses Bell base measurement | CB> n The classical measurement result CB was obtained. n Using quantum one-time pad encryption to encrypt classical measurement results CB nEncrypt and send the ciphertext E skB (CB n Send it to Trent, such as Figure 2 As shown, the steps for adding channel eavesdropping detection when sending ciphertext are illustrated.

[0066] Example: The classical measurement result CB was obtained. 8 = (00)(11)(01)(00)(10)(10)(10)(01), then the ciphertext E skB (CB n = 0101010000111100. After adding the eavesdropping detection step, the message transmitted on the channel is |010+10-100-0+01--11100->.

[0067] The quantum one-time pad encryption method is The expression is:

[0068]

[0069] Where, k∈{sk A ,sk B}

[0070] S22, Trent receives E skA (AF n ) and E skB (CB n The process also detects eavesdropping. If eavesdropping is detected, the signing process is terminated; if no eavesdropping is detected, Trent uses Bell base measurement. n The classical measurement result ED was obtained. n Then Trent decrypted the code using the quantum one-time pad method, that is, by using sk... A and SK B Decrypting E skA (AF n ) and E skB (CB n ), to obtain AF n and CB n Finally, Trent used sk A Trent calculates Seq using m and reconstructs Seq′ from three sets of measurements. He then compares the two; if they match, he considers the signature E to be correct. skA (AF n If the signature is valid, it is considered valid; otherwise, it is considered invalid.

[0071] The quantum one-time pad decryption method is as follows: The expression is:

[0072]

[0073] Where, k∈{sk A ,sk B}; x is the plaintext to be encrypted, and y is the ciphertext to be decrypted.

[0074] First, Trent decrypted the quantum one-time pad and obtained:

[0075] AF 8 =D skA (E skA (AF 8 ))=(01)(11)(00)(10)(11)(01)(01)(11),

[0076] CB 8 =D skB (E skB (CB 8 ))=(00)(11)(01)(00)(10)(10)(10)(01),

[0077] Then, Trent converted the quantum sequence back to the following using three sets of measurements:

[0078] |AF> 8 =|Φ - >|Ψ + >|Ψ - >|Φ + >|Ψ + >|Φ - >|Φ - >|Ψ + >,

[0079] |CB> 8 =|Ψ - >|Ψ + >|Φ - >|Ψ - >|Φ + >|Φ + >|Φ + >|Φ - >

[0080] Next, Trent measurement | ED> 8 Get: |ED> 8 =|Φ + >|Ψ + >|Φ - >|Ψ - >|Ψ + >|Ψ + >|Φ - >|Ψ - >

[0081] According to the entanglement property of Bell states, when |AF>8 After being measured by the Bell basis, |B>, which was originally entangled with |A>, and |E>, which was originally entangled with |Fc, will collapse into a certain random Bell state; therefore, |BE>, as an intermediate state, contains the information of the original |AB>, see Table 2; and the intermediate state |BE> can be obtained from the measurement results |ED> of Trent and Bob. 8 and |CB> 8 As can be inferred from Table 1, the table lookup process in this implementation is as follows:

[0082] According to |CB> 8 ,|ED> 8 The intermediate state can be deduced by referring to Table 1.

[0083] |BE> 8 =|Φ + >|Ψ - >|Ψ - >|Ψ - >|Φ - >|Φ - >|Ψ - >|Φ - >

[0084] Then, based on |AF> 8 ,|BE> 8 Looking up the value in Table 2, we can obtain the estimated value of Seq, Seq′ = 1111001010000110, which is consistent with the original Seq. Therefore, the signature is considered valid.

[0085] Table 1. Correspondence between intermediate states

[0086]

[0087] Table 2. Correspondence between Seq estimates

[0088]

[0089]

[0090] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A novel Bell state based arbitration quantum signature method, characterized in that, The three stages include initialization, signature generation and signature verification; The steps of the initialization stage are as follows: S01, the signature sender, the signature receiver and the arbitration management party respectively prepare n length |Ψ - Bell state sequence; respectively recorded as |AB> n , |CD> n and |EF> n ; Specifically, the first particle sequence of each group of Bell states in |AB> n , |CD> n and |EF> n is represented by |A> n , |C> n and |E> n respectively; At the same time, the second particle sequence of each group of Bell states is represented by |B> n , |D> n and |F> n respectively; S02, the signature sender shares a 2n-length key sk with the arbitration manager through a quantum key distribution protocol A S03, the signature receiver shares a 2n-length key sk with the arbitration manager through a quantum key distribution protocol B ; S03, the signing sender calculates the hash function value of the message m Then the The sequence Seq is obtained by dividing in order two by two. The steps of the signature generation stage are as follows: S11, the signing sender encrypts each pair of sequences Seq according to the value of |AB> n performs encryption;​ S12, the signature sender, the signature receiver and the arbitration management party exchange their second particles; specifically, the signature sender gives its second particle sequence |B n to the signature receiver, the signature receiver gives its second particle sequence |D n to the arbitration management party, the arbitration management party gives its second particle sequence |F n to the signature sender; After the exchange is completed, the signature sender, the signature receiver and the arbitration manager hold |AF> n , |CB> n and |ED> n three groups of quantum sequences respectively; The channel is eavesdropped when the particles are exchanged; if eavesdropping is detected, the present signature process is terminated; if no eavesdropping occurs, step S13 is executed; S13, the signature sender measures |AF> with Bell base n , and gets the classical measurement result AF n , encrypts the classical measurement result AF n using the quantum one-time pad encryption method, and sends the ciphertext E skA (AF n ) to the arbitration management party as the signature of the message m. When sending the ciphertext, eavesdropping detection is also performed on the channel. If eavesdropping is detected on the channel, the signature process is terminated. If there is no eavesdropping, the signature verification stage is entered. The steps of the signature verification stage are as follows: S21, the signature receiver measures |CB> with Bell base n , and gets the classical measurement result CB n , encrypts the classical measurement result CB n using the quantum one-time pad encryption method, and sends the ciphertext E skB (CB n ) to the arbitration management party, and also performs eavesdropping detection on the channel when sending the ciphertext; if eavesdropping on the channel is detected, the signature process is terminated; If no eavesdropping occurs, step S22 is executed; S22, the arbitration manager measures |ED> with Bell base n , and gets the classical measurement result ED n , and gets AF n and CB n by quantum one-time pad decryption method; the arbitration manager calculates Seq with the key sk A and the message m, and at the same time restores Seq' with the three groups of classical measurement results AF n , CB n and ED n ; the arbitration manager compares Seq with Seq', if they are consistent, it is considered that the signature E skA (AF n ) is legal, otherwise it is considered that the signature is illegal.

2. The novel Bell state based arbitration quantum signature method according to claim 1, characterized in that, the hash function value in step S03 with length 2nand a sequence Seq of length n; the hash function Two input parameters are required for the calculation: a message m of arbitrary length and a key sk of length 2n A ; the hash function The calculation expression is: where || denotes concatenation of bit strings. 3.The novel Bell state-based arbitration quantum signature method according to claim 1, characterized in that, The signing sender in step S11 encrypts |AB> according to the value of the sequence Seq. n The method for performing encryption is as follows: wherein Sq i represents the i-th element of the sequence Seq; j is the imaginary unit, represents the tensor product. 4.The novel Bell state-based arbitration quantum signature method according to claim 1, characterized in that, The method for eavesdropping detection in steps S12, S13 and S21 is as follows: when the message sender sends the quantum state message in the state of {|0>, |1>}, there are decoy particles randomly distributed in the state of {|->, |+>}; then the message sender randomly inserts the decoy particles into the quantum state message sequence and records the position and state of each decoy particle; finally, the sequence with the inserted decoy particles is sent; after the message receiver completes the sequence reception, the message sender discloses the position and state of all the inserted decoy particles, and then the message receiver measures all the decoy particles in the {|->, |+>} basis; if the error rate exceeds a predetermined threshold, the message receiver can determine that eavesdropping occurs during the communication. 5.The novel Bell state-based arbitration quantum signature method according to claim 1, characterized in that, The corresponding relation formula of the classical measurement result in steps S13, S21 and S22 is respectively as follows: where Ψ - ,Ψ + ,Φ - ,Φ + are four Bell states, respectively: 6.The novel Bell state-based arbitration quantum signature method according to claim 3, characterized in that, The quantum one-time pad encryption method described in steps S13 and S21 is The quantum one-time pad decryption method described in step S22 is: The expressions are respectively: wherein k e {sk A , sk B}; x is the plaintext to be encrypted, and y is the ciphertext to be decrypted.

Citation Information

Patent Citations

  • Novel arbitration quantum signature method based on XOR encryption and GHZ state

    CN114553390A

  • Quantum signature method using arbitrator and system using same

    KR1020140060022A