A multi-level secure information integrity authentication method based on active quantum walks

The construction of the keyed quantum hash function is solved through the active quantum walk method, which solves the flexibility and computing efficiency problems of the existing quantum hash function, realizes multi-level security information integrity authentication, and improves the security and flexibility of the hash function.

CN116707764BActive Publication Date: 2025-09-05BEIHANG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310675679.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-08
Publication Date
2025-09-05
Estimated Expiration
2043-06-08

AI Technical Summary

Technical Problem

The existing quantum hash functions based on controllable alternating quantum roaming lack flexibility, making it difficult to generate hash values ​​of any length, and are inefficient in computing on classical computers, which cannot meet the needs of different security levels.

Method used

The active quantum roaming method is adopted to control the activity parameters, ring size and initial quantum states by parameterizing the control of activity parameters, ring size and initial quantum states, and to construct a keyed quantum hash function to realize multi-level security information integrity authentication.

Benefits of technology

Generating hash values ​​that meet different security levels improves the flexibility and collision resistance of hash functions, and can be calculated on classic computers with polynomial time complexity to achieve multi-level security information integrity authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116707764B_ABST
    Figure CN116707764B_ABST
Patent Text Reader

Abstract

The present invention discloses a multi-level security information integrity authentication method based on active quantum walks, comprising the following steps: step 1: initialization of a keyed quantum hash function; step 2: execution of a controlled alternating active quantum walk method; and step 3: use POVM to measure and obtain the terminal quantum state |Ψ>. final Corresponding to the probability distribution P of each vertex on the ring; Step 4: Execute the post-processing method, process the probability of each vertex on the ring by interception and modulo operation, and connect to obtain the final hash value h. The present invention introduces the activity coefficient as a new parameter to participate in the construction of the keyed quantum hash function, and constructs a multi-level security information integrity authentication method based on active quantum walks. In terms of security, starting from the periodicity of quantum walks, the conditions for constructing a theoretically collision-resistant keyed quantum hash function are given; in terms of practicality, the flexibility and scalability of the keyed quantum hash function are improved, providing a practical solution for the practical application of the keyed quantum hash function.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention specifically relates to a multi-level security information integrity authentication method based on active quantum walks, and belongs to the technical field of network security. Background Art

[0002] Cryptographic hash functions (hash functions) are one of the most important primitives in modern cryptography, used to ensure data integrity during transmission. Furthermore, they are considered a key component of nearly all encryption schemes and many security applications. Classically, hash functions can map messages of arbitrary length to fixed-size outputs, exhibiting excellent initial value sensitivity, resistance to preimage attacks, resistance to secondary preimage attacks, and collision resistance. A message authentication code (MAC) is a keyed hash function that not only verifies data integrity but also authenticates and identifies the source of the data. A MAC accepts two inputs: a message and a key, and returns a hash value as output. MACs require that, without knowing the key, it is difficult to find two different messages with the same output. MACs can be constructed based on hash functions or block ciphers. Since hash-based MACs are much faster than those based on block ciphers, they are now commonly constructed based on hash functions, such as MACs.

[0003] Generally speaking, there are two types of classical hash functions. One is collision-resistant hash functions with provably secure specifications, and the other is specialized hash functions based on iteratively constructed compression functions. In recent years, significant progress has been made in cryptanalytic attacks targeting the internal compression functions and iterative structures of specialized hash functions. Furthermore, with the development of quantum computing technology and methods, some hash functions based on mathematically difficult problems are facing severe challenges.

[0004] Quantum computing is a type of computing that exploits quantum mechanical phenomena such as superposition, interference, and entanglement. Because the superposition of quantum states allows for highly parallel computation, quantum computers can solve complex problems that are intractable on conventional computers. Using quantum computing methods to design quantum hash functions is a novel approach.

[0005] Research on quantum hash functions can be divided into two categories: classical input-classical output quantum hash functions based on quantum computing methods, and classical input-quantum output quantum hash functions based on quantum one-way functions. Existing quantum hash function models are generally based on quantum one-way functions or quantum computing methods. The characteristics of these methods and the main problems they face are as follows:

[0006] (1) Quantum hash function with classical input and quantum output

[0007] Quantum one-way functions can be used to map classical messages to quantum states, and the error rate of the quantum comparison method SWAP-test can be defined as the collision rate of quantum hash functions. The security of quantum one-way functions with classical input and quantum output is primarily guaranteed by the quantum no-cloning principle and the Holevo bound. However, a major problem with this method is that the length of the output quantum state is proportional to the length of the input message, rather than a fixed length. Furthermore, it does not meet the deterministic requirements of classical hash functions. These properties limit its application as a hash function primitive in quantum cryptography.

[0008] (2) Classical Input-Classical Output Quantum Hash Function

[0009] There are two research routes for this type of quantum hash function. One is based on a universal quantum computing method - the quantum walk method, and the other is based on Bose sampling.

[0010] Research on quantum hash functions based on quantum walks primarily focuses on employing different underlying quantum walk methods. These schemes typically only consider controlling different coin operators to construct quantum hash functions, and have not fully explored the effectiveness of other operators. Furthermore, most quantum hash functions based on controlled alternating quantum walks cannot directly generate hash values ​​of arbitrary lengths, such as the NIST-specified 224-bit, 256-bit, 384-bit, and 512-bit hash values, lacking flexibility.

[0011] Quantum hash functions based on Bose sampling use grouped coarse-grained Bose sampling techniques to achieve collision resistance. However, such quantum hash functions can only be efficiently computed over linear optical networks, and their high time complexity makes them difficult to use on classical computers.

[0012] To address these issues, the present invention employs an active quantum walk approach, parameterizing the activity coefficient to control the magnitude of the additional long-range mobility. Different activity coefficients, loop sizes, and initial quantum states can all influence the properties of the active quantum walk. Compared to discrete-time quantum walks, this approach incorporates an additional displacement state at each step of the evolution. This allows for the avoidance of regularity on loops of arbitrary lengths by setting appropriate parameters. This property enhances the security and flexibility of the present invention. Summary of the Invention

[0013] The present invention addresses the shortcomings of existing quantum hash functions based on controllable alternating quantum walks by providing a multi-level secure information integrity authentication method based on active quantum walks. This method constructs a message check code based on this method to achieve a multi-level secure information integrity authentication method. By employing a parameterized control model, this method addresses the lack of flexibility and scalability of previous solutions, enabling the realization of classical input-classical output quantum hash functions with varying security requirements, thereby achieving multi-level secure information integrity authentication.

[0014] The technical solution adopted by the present invention is: a multi-level security information integrity authentication method based on active quantum walks, in which an initial key and classical information are input. The internal operation of each step of the active quantum walk method is to perform a corresponding unitary transformation according to the key, which is controlled by the message bits. Multi-level security information integrity authentication is achieved by constructing a keyed quantum hash function.

[0015] The present invention comprises the following steps:

[0016] Step 1: Initialization of the keyed quantum hash function

[0017] The parameter set of the multi-level security information integrity authentication of the present invention is {N, C, τ1, τ2, a1, a2, a3, l, s}. The specific parameter meanings and setting requirements are as follows: N∈Q, Q is a natural number, which represents the size of the one-dimensional ring, that is, the number of vertices on the ring. The vertices x on the ring are numbered starting from 0 and numbered in lexicographic order; C is a coin operator, which is generally selected as the Grover operator. τ1 and τ2 are the activity coefficients of active quantum walks, which should satisfy represents the floor function; a1, a2, and a3 are the initial quantum states |Ψ> start The amplitude coefficient of each coin state in , where |·> is the Dirac symbol in quantum mechanics, and a1, a2 and a3∈(0,1) satisfy |a1| 2 +|a2| 2 +|a3| 2 =1; parameter l is the probability expansion coefficient, s is the modulus coefficient, both of which are integers greater than 0 and are determined by the security level of the hash function. At the same time, s and l must also meet 10 l >>2 s . The coin operator C and the initial quantum state |Ψ> start The amplitude coefficients a1, a2 and a3 of each coin state are used as the input key.

[0018] Specifically, the initialization steps of the keyed quantum hash function are as follows:

[0019] S1.1 Security level selection

[0020] Select the security level of the keyed quantum hash function, that is, the binary length len of the output hash value, such as 296 bits, 256 bits, etc., and determine the size N of the ring of active quantum walk execution and the appropriate modulus coefficient s based on len so that

[0021] S1.2 Input message preprocessing

[0022] Given a plaintext message M, M is the ASCII code format of classic information such as text or images. First, the plaintext message M is arranged in order according to the ASCII code format, concatenated and converted into a binary string msg. Then padding is performed to obtain a given padding value. The padding length is determined by the actual required security level. The purpose of padding is to avoid the hash value generated by short messages from having regularity. The specific input message padding rules are as follows: If the length of msg is less than The missing digits will be filled with 0.

[0023] S1.3 Input parameter initialization

[0024] The key parameters required for executing the controlled alternating active quantum walk are selected based on the binary length len output by the hash function. The key parameters of the present invention are the two activity coefficients and the coin operator of the controlled alternating active quantum walk method. These three parameters determine the specific evolution process and properties of the controlled alternating active quantum walk method.

[0025] First, determine the coin operator C and activity coefficients τ1 and τ2 of the controlled alternating active quantum walk method. At the same time, the selection of the coin operator and activity coefficient should meet the security requirements to resist the forgery attack on the hash function. The forgery attack on the hash function can be defined as: for a hash function H(·), given an input message msg, a polynomial time adversary can construct another input message msg' such that

[0026] H(msg)=H(msg'), which means a collision of hash functions occurs. In order to achieve a keyed quantum hash function that is resistant to forgery attacks, the two activity coefficients τ1 and τ2 of the controlled alternating active quantum walk method and the coin operator C should satisfy two additional constraints:

[0027] (1) When N is an even number, the two activity coefficients τ1 and τ2 of the controlled alternating active quantum walk are both even numbers. Because if the two activity coefficients τ1 and τ2 of the controlled alternating active quantum walk are both odd numbers, the controlled alternating active quantum walk will exhibit a periodic phenomenon, that is, after executing an odd number of steps, the probability value of the walker at the odd-numbered vertex on the ring is non-zero, while the probability value of the even-numbered vertex is zero. This property will lead to an uneven distribution of hash values ​​and easy collisions. Therefore, when N is an even number, even activity coefficients τ1 and τ2 should be selected. When N is an odd number, the parity of the activity coefficients τ1 and τ2 remains unchanged. The size of the ring in this embodiment is N=37, so the selection of the activity coefficient is not restricted. In this embodiment, when the input message bit is 0, the controlled alternating active quantum walk method performs an active quantum walk with an activity coefficient τ1=0; when the input message bit is 1, the controlled alternating active quantum walk method performs an active quantum walk with an activity coefficient τ2=2.

[0028] (2) The coin operator C of the active quantum walk needs to be carefully selected. First, define the period of the quantum walk, a set in is a set of natural numbers, U is the evolution operator corresponding to the quantum walk on a ring, is an identity matrix. If Then the period T of the quantum walk on the ring is written as Otherwise, for In the case of , the quantum walk on the ring has a period of ∞, which is called an aperiodic quantum walk. In particular, the periodicity of a quantum walk on a ring means that the particle returns to its quantum initial state exactly after a finite number of steps.

[0029] The periodicity of quantum walks will lead to the success of forgery attacks. Specifically, suppose there is a quantum walk method evolution operator U1 (executed when the message bit is 1) executed on a ring with a finite period T. In this case, U1 T |Ψ> start =I|Ψ> start =|Ψ> start , so for a binary message msg = 10…10, any nT,n∈{1,2,3…} message bit string can be inserted into the original message string, and the collision will appear in the following form: Therefore, in order to avoid forgery attacks, the present invention adopts a Grover-type matrix that is not periodic under the condition that the ring size N>3 as the coin operator:

[0030]

[0031] Finally, the initial position state of the walker with the key quantum hash function is selected. Each vertex on the ring is encoded into a quantum state {0>,|1>,…,|N-1>} in the position space. Select the initial quantum state The coefficients of the position state and coin state are selected from {|0>,|1>,…,|N-1}, and the coin state is |c>=a1|0>+a2|1>+a3|2>. In step S1.3, the amplitude coefficients a1, a2, and a3 of each coin state bit of the initial position state of the coin operator C and the walker of the controlled alternating active quantum walk serve as the key of the keyed quantum hash function and are shared by the message compression party and the message verification party.

[0032] Step 2: Perform a controlled alternating active quantum walk method

[0033] The active quantum walk process on the N-length loop occurs in the Hilbert space Among them represents a position space whose orthogonal basis is given by the lexicographically ordered labels of each vertex on an N-length ring, defined as Represents the three-dimensional coin space, defined as The walker starts from the initial quantum state Starting from the ring, a controlled alternating active quantum walk method is performed, and each step of the walk process is controlled bit by bit according to the binary message. Each step starts with tossing a coin, and the walker decides the direction of movement according to the state of the coin. This process is determined by the unitary transformation Description, where I N is the N-dimensional identity matrix, S is the shift operator, defined as follows:

[0034]

[0035] Z N is an integer ring with a module of N, S is controlled by each message bit; C is a coin operator, which can be fixed or controlled by each message bit. This step can finally obtain the final quantum state is the amplitude coefficient of vertex x at coin state c at the end moment.

[0036] Step 3: POVM (symmetric information completeness) measures the probability distribution of the terminal quantum state vertex

[0037] The final quantum state |Ψ> in step 2 is calculated using a set of orthogonal computational bases {|0>,|1>,…,|N-1>} start The position state |x> performs POVM measurement operation and obtains the probability distribution P = (p0, p1, p2, ... p N-1 ),in is the probability value of the walker at each vertex on the ring, x∈z N is the probability value of the walker at each vertex x on the ring.

[0038] Step 4: Execute post-processing method to calculate hash value

[0039] The probability distribution P=(p0,p1,p2,…p N-1 ) is amplified, and for each p in P x Execute post-processing method That is, multiply the probability value of each vertex by 10 l , after rounding down, perform modulo 2 s Then the string h corresponding to each vertex is calculated. x Concatenate in sequence and convert into a new binary string h0‖h1‖h2‖…‖h N-1 , which is the hash value h of the plaintext.

[0040] The advantages of the present invention compared with the prior art are:

[0041] (1) The present invention proposes a novel controllable alternating quantum walk method. By introducing active quantum walks, a parameterized controlled alternating active quantum walk method is realized. The keyed quantum hash function constructed based on this method is controlled by a variable activity coefficient rather than a coin operator. There is an additional connection each time a quantum walk is executed. This novel keyed quantum hash function based on controlled alternating quantum walks can run on a ring of any size without worrying about the occurrence of periodic probability distributions. By adjusting the parameters, hash values ​​that meet different security levels can be generated, which has higher flexibility and practicality.

[0042] (2) The present invention enhances the structure of the hash function based on quantum walks. By introducing more control parameters, the anti-collision performance, sensitivity to plaintext messages, diffusion and confusion, and uniformity of plaintext message images of the hash function are improved. In addition, the introduction of the activity coefficient also enables the hash function to resist forgery attacks. At the same time, the novel quantum walk method adopted by the present invention implements a keyed quantum hash function based on the original controlled alternating quantum walk framework, thereby realizing a multi-level secure information integrity authentication method. There is no change in its security principle. Therefore, the multi-level secure information integrity authentication method based on controlled alternating quantum walks proposed by the present invention inherits the security of the original quantum hash function, and its performance can be evaluated using the same analysis method. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 Flow chart of the method.

[0044] Figure 2 This is the quantum circuit diagram of the incremental cyclic permutation gate.

[0045] Figure 3 This is the quantum circuit diagram of the decrement cyclic permutation gate.

[0046] Figure 4 As an example of the present invention, when the input message bit is 1, the corresponding quantum circuit diagram of the quantum hash function is realized.

[0047] Figure 5 As an example of the present invention, when the input message bit is 0, the corresponding quantum circuit diagram of the quantum hash function is realized.

[0048] Figure 4 and Figure 5 The symbols are explained as follows:

[0049] vertex is the input quantum state in position space;

[0050] coin is the input quantum state of the coin space;

[0051] message is the input quantum state of the message space;

[0052] G is the Grover operator. DETAILED DESCRIPTION

[0053] This paper proposes a multi-level secure information integrity authentication method based on controlled alternating active quantum walks. The main concept is to construct a controlled alternating active quantum walk method based on the active quantum walk method, and then implement a keyed quantum hash function on this basis, thereby realizing a multi-level secure information integrity authentication method. By studying the properties of the active quantum walks, secure parameters are selected to ensure that the keyed quantum hash function has the relevant properties required for a keyed hash function.

[0054] The multi-level secure information integrity authentication method based on controlled alternating active quantum walks proposed in this invention is that the evolution of the entire system occurs in the Hilbert space. Among them Represents the location space, Represents the coin space, and the initial quantum state is The final quantum state is Among them U msg The product of a series of unitary transformations that control the bit-by-bit operation of the binary string with a given value after padding.

[0055] The multi-level security information integrity authentication method proposed in the present invention can be calculated with polynomial time complexity on both classical and quantum computers. When using a classical computer for calculation, it is essentially simulating the evolution of active quantum walks, which includes basic arithmetic and logical operations and only requires O(N) time complexity. When using a quantum computer for calculation, the present invention can only require logarithmic level complexity resources in the quantum computer, requiring only a constant number of cyclic permutation gates and basic element gates, such as Figure 2 and Figure 3 As shown, the cyclic permutation gate is composed of a generalized CNOT gate, which only requires The number of additional auxiliary qubits and The quantum hash function proposed in this invention is unidirectional. During the measurement and post-processing phases of the invention, the quantum measurement operation, modulo operation, and truncation operation are irreversible, resulting in a one-to-many mapping between the output and input of the hash function.

[0056] The following describes embodiments of the present invention in detail with reference to the accompanying drawings. The same or similar reference numerals throughout the drawings represent the same or similar elements or elements having the same or similar functions. The embodiments described below are exemplary and are intended to illustrate the present invention.

[0057] A multi-level secure information integrity authentication method based on controlled alternating active quantum walks according to an embodiment of the present invention comprises the following four steps:

[0058] Step 1: Initialization of the keyed quantum hash function

[0059] First, the security level of the quantum hash function is selected, that is, the binary length len of the output hash value is 296 bits. At this time, the modulus coefficient s and the probability expansion coefficient l are both selected to be 8, so the size of the ring of active quantum walk execution is

[0060] Given an input plaintext message M to be compressed, convert it into ASCII code format and arrange it in sequence and then convert it into binary format msg∈{0,1} * , assuming:

[0061] msg=0110101101011110101100010111011101110110110101111011010101101 010110111001011001101011011;

[0063] Since the length of msg is less than the ring size N, no padding is required.

[0064] The present invention selects a suitable coin operator from the Grover type matrix set so that the active quantum walk on the ring does not have periodicity. At this time, the quantum hash function based on the controlled alternating active quantum walk on the ring has strict security and collision resistance. As a coin operator:

[0065]

[0066] when When , the coin operator C is:

[0067]

[0068] In classical computer simulation, the calculation accuracy is considered to be 10 -14 , the key space size of the initial conditions and control parameters is roughly 2 186 .

[0069] Finally, the parameter set of this embodiment is:

[0070] in is a coin operator, which is fixed in this embodiment. a1, a2, a3 and the parameter θ of the coin operator serve as the initial key of the keyed quantum hash function.

[0071] Step 2: Perform a controlled alternating active quantum walk method

[0072] The message bits are used to control the evolution of each step of the controlled alternating active quantum walk. Specifically, the evolution operator of each step is It is controlled by a given value msg after filling, and bit by bit controls the shift operator S that acts on the active quantum walk at each vertex x.

[0073] Specifically, when the msg bit is 0, the activity coefficient τ1=0 is selected to construct the shift operator:

[0074]

[0075] When the message bit is 1, select τ2 = 2, and the shift operator is:

[0076]

[0077] From the initial quantum state |Ψ> start Initially, the evolution process can be expressed as m i Indicates the i-th bit of msg.

[0078] Step 3: POVM measurement obtains the probability distribution of the terminal quantum state vertex

[0079] After executing step 2, the walker ends up in the quantum state |Ψ> final By using the orthogonal computational basis {|0>,|1>,…,|N-1>} to perform POVM measurement on each vertex |x> on the ring, the corresponding probability distribution P=(p0,p1,p2,…p N-1 ). You can use a simulation program to calculate the probability distribution of the quantum walker at various locations at this time, retaining 8 decimal places to obtain:

[0080]

[0081] Step 4: Execute post-processing method to calculate hash value

[0082] For each p in the probability distribution P obtained in step 3 x Execute post-processing method Multiply the probability value of each vertex by 10 8 , after rounding down, perform modulo 2 8 Modulo operation to get the hash value:

[0083]

[0084] Arrange and concatenate all the characters in order to obtain a 296-bit binary string as the hash value h = h0 ‖ h1 ‖ h2 ‖ ... ‖ h N-1 For simplicity, convert it to a hexadecimal string:

[0085] F2A9C8652F69C31918EB6A9D56B763140835C5241840971B153D3BC6B2D93E439C04C66DD2.

[0086] For the specific quantum circuit implementation of this embodiment, please refer to Figures 2 to 5 ,in Figure 2 and Figure 3 These are the increment recursive permutation gate and the decrement recursive gate, which can implement shift operators by increasing or decreasing the value of the vertex bit string. Figure 4 and Figure 5 Implementation of a partial quantum circuit for a quantum hash function with activity coefficients of 0 and 2 (the activity coefficient corresponding to the input message bit is 0, and the activity coefficient corresponding to the input message bit is 1) and an output hash value of 296 bits. Incr and decr represent the increment cyclic permutation gate and the decrement cyclic gate, respectively.

[0087] The above description is merely an example of a multi-level secure information integrity authentication method based on controlled alternating active quantum walks according to the present invention. It should be noted that these examples are merely used to illustrate the implementation process of the present invention and do not limit the scope of the present invention. Persons skilled in the art will appreciate that improvements, modifications, or equivalent forms of modifications may be made without departing from the principles of the keyed quantum hash function based on controlled alternating active quantum walks according to the present invention. Such improvements, modifications, or equivalent forms of modifications should also be considered within the scope of the claims appended to the multi-level secure information integrity authentication method based on controlled alternating active quantum walks according to the present invention.

Claims

1. A multi-level security information integrity authentication method based on active quantum walks, characterized in that: It contains the following steps: Step 1: Initialization of the keyed quantum hash function According to the security level requirements of the quantum hash function, select the appropriate keyed quantum hash function output length len, the appropriate ring size N, the activity coefficients τ1 and τ2 of the controlled alternating active quantum walk, the coin operator C, and the initial quantum state |Ψ> start The amplitude coefficients a1, a2 and a3 of each coin position and the parameters of the post-processing method: probability expansion coefficient l and modulus coefficient s; Among them, a1, a2, a3 and C are the shared keys of the message compressor and the message verifier; Given a plaintext message M, first arrange the plaintext message M in order according to the ASCII code format, concatenate it and convert it into a binary string msg, and then fill it with the given value; if the length of msg is less than Fill the missing digits with 0; Step 2: Execute the controlled alternating active quantum walk method The controlled alternating active quantum walk method is performed on a ring of size N, and each step of the walk process is controlled bit by bit according to the bit of the binary message msg, that is, the unitary transformation process Where S is a shift operator; when the input bit of the binary string is 0, an active quantum walk method with an activity coefficient of τ1 is used; When the input bit of the binary string is 1, an active quantum walk method with an activity coefficient of τ2 is used; Step 3: POVM measurement obtains the probability distribution of the terminal quantum state vertex The final quantum state |Ψ> in step 2 is calculated using a set of orthogonal computational bases {|0>,|1>,…,|N-1>} start The position state |x> performs POVM measurement operation to obtain the probability distribution P of the quantum walker at each vertex x on the ring, where x∈z N is the probability value of the walker at each vertex x on the ring; Step 4: Execute post-processing method to calculate hash value The probability distribution P=(p0,p1,p2,…p N-1 ) is amplified, and for each p in P x Execute the post-processing method; first multiply the probability value of each vertex by 10 l , after rounding down, perform modulo 2 s The modulo operation is then performed; the strings corresponding to each vertex are concatenated in sequence and converted into a new binary string, and finally an Ns-bit hash value is obtained; the message verifier can only verify the integrity of the message and the identity of the message compressor if it holds the key {a1, a2, a3, C}.

2. The multi-level security information integrity authentication method based on active quantum walks according to claim 1 is characterized in that: In step 1, the value conditions of each parameter in the initialization process of the keyed quantum hash function are: N∈Q, Q is a natural number, its size is determined by len and the appropriate modulus coefficient s, satisfying The activity coefficients τ1, τ2 and the coin operator C of the controlled alternating active quantum walk should satisfy represents the floor function, and C belongs to the Grover type matrix. When N is an even number, even activity coefficients τ1 and τ2 should be selected, while when N is an odd number, the parity of the activity coefficients τ1 and τ2 remains unchanged. The coin operator C is selected from the set of Grover type matrices so that the active quantum walk on the ring does not have periodicity. At this time, the quantum hash function based on the controlled alternating active quantum walk on the ring has strict security and collision resistance. A class of Grover type matrices is as follows: As long as the ring size is not equal to 3, the active quantum walk method is not periodic; Initial quantum state |Ψ> start The amplitude coefficients of each coin state are a1, a2 and a3, "|·>" represents the Dirac symbol representation of the quantum state, a1, a1, a1∈(0,1), satisfying |a1| 2 +|a2| 2 +|a3| 2 =1; the parameter probability expansion coefficient l and modulus coefficient s of the post-processing method are integers greater than 0 and satisfy 10 l >>2 s .

3. The multi-level security information integrity authentication method based on active quantum walks according to claim 1 is characterized in that: The active quantum walk process on the N-length ring in step 2 occurs in the Hilbert space Among them represents a position space whose orthogonal basis is given by the lexicographically ordered labels of each vertex on an N-length ring, defined as Represents the three-dimensional coin space, defined as The walker starts from the initial quantum state Starting from, a controlled alternating active quantum walk method is performed on a ring of size N.

4. The multi-level security information integrity authentication method based on active quantum walks according to claim 1 is characterized in that: In step 2, The unitary transformation of the internal execution process of the keyed quantum hash function is: where m i Represents the i-th bit of msg; the unitary transformation process of each step is Where S is a shift operator, defined as follows: Z N is an integer ring modulo N, S is controlled by each message bit; C is a coin operator, which can be fixed or controlled by each message bit; When the t-th bit of the input message is 0, the unitary transformation U is executed in the t-th step, where the activity coefficient of the shift operator used is τ=τ1, and the unitary transformation U is denoted as U1, and S is denoted as S1; when the t-th bit of the input message is 1, the unitary transformation is executed in the t-th step, where the activity coefficient of the shift operator used is τ=τ2, and the unitary transformation U is denoted as U2, and S is denoted as S2.

5. The multi-level security information integrity authentication method based on active quantum walks according to claim 1 is characterized in that: The final quantum state obtained in step 3 is: in is the amplitude coefficient of vertex x in coin state c at the end moment; the probability that the walker finally reaches each vertex on the ring can be measured by using a set of orthogonal calculation bases {|0>,|1>,…,|N-1>} to perform POVM measurement operations, which is specifically described as: Measuring the final quantum state |Ψ> final The position state |x>, the probability distribution of the quantum walker reaching each vertex x on the ring is P=(p0,p1,p2,…p N-1 ),in x∈z N is the probability value of the walker at each vertex x on the ring.

6. The multi-level security information integrity authentication method based on active quantum walk according to claim 1 is characterized in that: In step 4, a post-processing method is used to obtain a hash value for message integrity, which is specifically described as follows: For P=(p0,p1,p2,…p N-1 ) in each p x Execute post-processing method Multiply the probability value of each vertex by 10 l , after rounding down, perform modulo 2 s Modulo operation, calculate the string h corresponding to each vertex x x , concatenated in sequence and converted into a new binary string h0‖h1‖h2‖…‖h N-1 , and use it as the hash value h of the plaintext.

Citation Information

Patent Citations

  • Biometric fingerprint authentication method based on quantum fuzzy commitment

    CN102750529A

  • Method for realizing information integrity based on continuous quantum walk hash algorithm

    CN112564886A