A one-way coded semi-quantum key distribution system and method

By using a one-way coded semi-quantum key distribution method, one-way transmission of photons in quantum channels and quantization of eavesdropping information are realized, solving the security and loss problems of bidirectional systems and improving key generation rate and security.

CN116800410BActive Publication Date: 2026-02-10INNER MONGOLIA UNIV OF TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310316399.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-29
Publication Date
2026-02-10
Estimated Expiration
2043-03-29

AI Technical Summary

Technical Problem

In existing semi-quantum key distribution protocols, the security analysis of bidirectional systems is highly complex, making them vulnerable to Trojan horse attacks. Furthermore, single photons suffer significant losses during bidirectional transmission, affecting key generation rate and security.

Method used

A one-way coding semi-quantum key distribution method is adopted, in which photons are transmitted unidirectionally in the quantum channel, and the returned photons are used to quantize the eavesdropping information. SIFT and CTRL operations are realized by using a Michelson interferometer and an optical switch. The classical method does not require additional information output. The combination of polarization beam splitter and optical delay coil achieves time distinguishability and avoids Trojan horse attacks.

Benefits of technology

It improves the key generation rate, enhances the security and usability of the system, avoids Trojan horse attacks, and strengthens the key generation capability over a certain distance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116800410B_ABST
    Figure CN116800410B_ABST
Patent Text Reader

Abstract

The application aims to provide a one-way code generation semi-quantum key distribution system and method, wherein the coded photons are transmitted in a one-way manner in a channel, and the returned photons are used to quantify the information amount of a eavesdropper, and the security of the protocol is proved based on a collective attack. The one-way loading key is realized by using a Michelson interferometer, the Trojan horse attack problem commonly existing in the existing two-way system is solved, the security of the real system is improved, and the key generation rate is improved under certain distance conditions. The system and method provided by the application have high security and practicability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum secure communication, and more specifically, to a one-way coded semi-quantum key distribution system and method. Background Technology

[0002] Classical communication security relies on algorithmic strength, not physical principles, making it vulnerable to increasingly powerful eavesdroppers. Quantum key distribution (QKD), however, utilizes quantum mechanics principles to share keys, independent of algorithms and computational power, thus achieving secure information transmission. In 2007, Boyer et al. first proposed a semi-quantum key distribution protocol—the BKM07 protocol—which allows one party to possess quantum capabilities while the other possesses classical capabilities, still enabling the sharing of a secure key. The quantum party can prepare and measure qubits using any basis, while the classical party possesses only some physical classical capabilities, limiting its ability to measure and prepare quantum states using only a set of orthogonal bases.

[0003] The initial experimental implementation of the SQKD protocol was extremely difficult, requiring the quantum side to prepare quantum states and the classical side to measure and prepare identical particles to return to the quantum side, which limited the feasibility of SQKD. In 2021, Han et al. optimized the mirror protocol, using an intensity modulator (IM) to implement classical operations (CTRL, SWAP-10, SWAP-01, SWAP-ALL), which can distribute secure keys without preparing identical photons, making it the most experimentally feasible protocol at the current technological level.

[0004] The SQKD protocol typically employs a bidirectional quantum channel. Alice sends a light pulse, which travels through the channel to Bob's classical counterpart. Bob encodes the pulse and sends it back to Alice, completing one information transmission. Because the qubits undergo forward and reverse transmission within the channel, the system's security analysis is highly complex. Compared to unidirectional systems, bidirectional systems are more vulnerable to Trojan horse attacks. Especially when the detector is untrusted, delayed or invisible photons sent by Eve cannot be effectively detected, compromising the security of the physical key. Furthermore, the loss of single photons during bidirectional transmission is a major obstacle to the implementation of the SQKD protocol. Improving security and practicality is the core task of theoretical and experimental research on the SQKD protocol. Summary of the Invention

[0005] The purpose of this invention is to overcome the shortcomings of existing technologies and propose a one-way coded semi-quantum key distribution method. This method allows coded photons to be transmitted unidirectionally in a quantum channel, while the returned photons are used to quantize the amount of information received by an eavesdropper. Security is proven based on collective attack. By using a one-way device to load key information, the method solves the problem that existing protocols rely entirely on bidirectional systems. It improves the key generation rate under certain distance conditions and avoids Trojan horse attacks, exhibiting extremely high security and practicality.

[0006] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0007] A one-way coded semi-quantum key distribution system, in which the quantum side prepares the quantum state and the classical side randomly selects a measurement photon to generate the key, or returns a photon to detect eavesdropping;

[0008] The system includes a quantum side Alice and a classical side Bob, as well as a quantum channel connecting the two. The quantum side Alice consists of a pulsed photon source, an attenuator, a circulator, a beam splitter, a first optical delay coil, a first switchable polarization rotator, a first Faraday mirror, a first single-photon detector, and a second single-photon detector. The classical side Bob consists of an optical switch, a polarization beam splitter, a second optical delay coil, a third single-photon detector, a second switchable polarization rotator, and a second Faraday mirror.

[0009] Alice end: The output port of the pulsed photon source is connected to the input port of the attenuator; the output port of the attenuator is connected to port 1 of the circulator; the circulator's in-phase input port 2 is connected to port d of the beam splitter; the circulator's in-phase output port 3 is connected to the first single-photon detector; the beam splitter's port c is connected to the second single-photon detector; the beam splitter's port a is connected to the input port of the first optical delay coil; the output port of the first optical delay coil is connected to the input port of the first polarization rotator; the output port of the first polarization rotator is connected to the first Faraday mirror; the beam splitter's port b is connected to the input port of the quantum channel; the output port of the quantum channel is connected to the input port of the Bob end optical switch.

[0010] Bob end: The output port 2 of the optical switch is connected to the combination port 1 of the polarization beam splitter and the second optical delay coil; the port 3 of the polarization beam splitter is connected to the third single-photon detector; the output port 3 of the optical switch is connected to the input port of the second polarization rotator; and the output port of the second polarization rotator is connected to the second Faraday mirror.

[0011] Furthermore, the quantum square Alice uses only one set of orthogonal bases to prepare and measure quantum states, and its quantum properties are reflected in the fact that Alice prepares a superposition state of single photons and empty pulses.

[0012] Furthermore, the classic Bob method employs an optical switch to select SIFT and CTRL operations; when the optical switch is turned on, a key is directly generated based on the response of the third detector, thus realizing one-way key loading.

[0013] Furthermore, when the classical side Bob turns on the optical switch and generates the key, since no additional information is output from the classical side, the Trojan horse attack problem that is common in existing bidirectional systems is solved.

[0014] Furthermore, the classical Bob method achieves time distinguishability by using a polarization beam splitter and a second optical delay coil. The classical characteristic is reflected in the fact that only a third detector is used to measure at two different time stamps, without the need to prepare quantum states.

[0015] The present invention also provides a one-way coded semi-quantum key distribution method, which utilizes the above-mentioned one-way coded semi-quantum key distribution system, characterized in that: the photons encoded by the semi-quantum key distribution system are transmitted unidirectionally in the quantum channel, and the returned photons are used to quantize the amount of information of the eavesdropper.

[0016] This invention proposes a semi-quantum key distribution method with one-way key loading. A Michelson interferometer connects the two communicating parties, with the classical party using an optical switch to connect different ports for SIFT and CTRL operations respectively. When the optical switch is open, the classical party measures and decodes all input signals (including Trojan photons from eavesdroppers), achieving one-way key loading. Simultaneously, since no additional information is output from the classical party, the Trojan horse attack problem is solved. A polarization beamsplitter and a second optical delay coil are used for decoding, ensuring that different polarization states arrive at the third detector at different times, achieving time distinguishability. When the optical switch is closed, the light pulse is returned and interferes at the beamsplitter; the interference result limits the amount of information the eavesdropper can transmit. Since the throughput of a quantum channel decreases exponentially with increasing transmission distance, this one-way key loading method improves the key generation rate under certain distance conditions and also enhances the practical security of the system.

[0017] Compared with the prior art, the present invention has the following beneficial effects:

[0018] (1) One-way key loading was implemented, which improved the key generation rate.

[0019] (2) By adopting a one-way key loading method, the problem of Trojan horse attacks that are common in existing two-way systems is solved. Attached Figure Description

[0020] Figure 1 Schematic diagram of one-way coded semi-quantum key distribution principle

[0021] The names corresponding to the reference numerals in the attached figures are as follows:

[0022] 101 - Laser

[0023] 102 - Attenuator

[0024] 103—Circulator

[0025] 104 - Beam Splitter

[0026] 105 – First optical delay coil; 203 – Second optical delay coil

[0027] 106 – First polarization rotator, 205 – Second polarization rotator

[0028] 107 – First Faraday Mirror, 206 – Second Faraday Mirror

[0029] 108 – First single-photon detector, 109 – Second single-photon detector, 204 – Third single-photon detector

[0030] 301—Quantum Channel

[0031] 201 - Optical Switch

[0032] 202—Polarization Beam Splitter

[0033] 103-1, 103-2, 103-3 — Ports of the circulator (103)

[0034] 104-a, 104-b, 104-c, 104-d — Ports of the beam splitter (104)

[0035] 201-1, 201-2, 201-3 — Ports of the optical switch (201)

[0036] 202-1, 202-2, 202-3 — Ports of the polarization beam splitter (202) Detailed Implementation

[0037] The present invention will now be clearly and completely described with reference to the accompanying drawings and specific embodiments:

[0038] In this embodiment, the quantum square Alice uses only one set of orthogonal bases to prepare and measure quantum states. The quantum properties are reflected in the fact that Alice prepares a superposition state of single photons and empty pulses. The pulsed photon source 101 at the Alice end of the quantum square emits a pulse signal with a stable polarization state of |H> or |V> from its output port. After the pulse signal enters the input port of the attenuator 102, the signal intensity is adjusted to the single-photon level. The light pulse enters port 1 of the circulator 104. The circulator 104, when receiving the light pulse, transmits the single-photon level light pulse in the same direction to port d of the beam splitter 104 connected to port 2, and transmits the light pulse returned from the classical square Bob to the first single-photon detector 108 connected to port 3. The beam splitter 104, together with the first Faraday mirror 106 and the second Faraday mirror 205, constitutes a Michelson interferometer, connecting the two communicating parties. The beam splitter 104 splits the received light pulse into two beams, a and b. Pulse a exits through port a of beam splitter 104 and remains at Alice's end. Pulse b exits through port b of beam splitter 104 and reaches Bob's end via quantum channel 301. The state of the system at this point can be represented as:

[0039]

[0040] Where p represents the polarization state of the photon, p∈{H,V}, and |0> represents the vacuum state.

[0041] In this embodiment, the b-pulse enters the classical Bob terminal through the quantum channel 301. Bob processes the received b-pulse through two options via the optical switch 201. One option is to close the optical switch 201 and return it directly to the quantum Alice via the second Faraday mirror 206. This option is defined as Bob's CTRL operation. The other option is to open the optical switch 201 and measure it through the third single-photon detector 204. After the measurement, there is no need to prepare a new light pulse to return to the quantum Alice. This option is defined as Bob's SIFT operation.

[0042] If Bob selects the SIFT operation, then the optical switch 202 is turned on to measure photons. There are two scenarios:

[0043] (1) When the photon is in path a, the light pulse passes through the first optical delay coil 105 and reaches the first polarization rotator 106. The first polarization rotator 106 selects whether to perform a flip operation on the pulse and then reaches the first Faraday mirror 107. After the polarization is rotated by 90°, it is reflected and exits from port d and c with equal probability through the beam splitter 104, triggering the first detector 108 in path d or the second detector 109 in path c respectively.

[0044] (2) When the photon is on path b, the key is directly generated based on the response of the third detector 204. The classical Bob does not need to re-prepare the quantum state and send it to the quantum Alice, thus achieving one-way key loading. The light pulse reaches the optical switch 201 through the quantum channel 301, and then passes through the polarization beam splitter 202 and the second optical delay coil 203 (the horizontal polarization state |H> is emitted from port 3, and the vertical polarization state |V> is emitted from port 2 and returns to the polarization beam splitter 202, emitting from port 3), and is finally detected by the third detector 204. Based on the timestamp t0 or t1 response of the third single-photon detector 204, Bob records his key as 0 or 1 ("0" represents the photon polarization state as |H>; "1" represents the photon polarization state as |V>). Since the classical Bob uses the combination of the polarization beam splitter 202 and the second optical delay coil 203 to achieve time distinguishability, the classical square's requirement for the number of single-photon detectors is reduced, making it a more reasonable classical square design.

[0045] If Bob selects the CTRL operation, the optical switch 202 is turned off, connecting port 1 of the optical switch 202 to port 3. The b pulse, after passing through the second polarization rotator 205 and reaching the second Faraday mirror 206, undergoes a 90° polarization rotation and returns to Alice's end via the same path. During this process, when both communicating parties operate the first and second polarization rotators 106 and 205 simultaneously, the a pulse and b pulse interfere at the beam splitter 104, triggering the second detector 109. Alice, the quantum side, records the responses of the returned photons to the first and second detectors 108 and 109 as parameters for estimating the amount of information from the eavesdropper.

[0046] This embodiment provides a one-way coded semi-quantum key distribution method. Photons encoded using the aforementioned one-way coded semi-quantum key distribution system are transmitted unidirectionally in a quantum channel, and the returned photons are used to quantize the amount of information received by the eavesdropper. The classical Bob uses an optical switch 201 to implement SIFT and CTRL operations. When the classical Bob selects the SIFT operation, all input light is detected by the third detector 204, and no photons are output, thus solving the Trojan horse attack problem commonly found in existing bidirectional systems.

[0047] Based on the security proof ideas of theoretical physicists Peter Shor and John Preskill, quantum key distribution protocols based on state preparation and measurement are equivalent in security to those based on entanglement purification protocols. The following section will prove the security of this scheme under collective attacks based on the entanglement purification protocol, mathematically establishing the relationship between the eavesdropper's information content and experimentally observable parameters. The specific process is as follows:

[0048] Alice prepares N pairs of entangled states. Where A is Alice's auxiliary particle, particle A and mode a always remain within Alice's safe zone, while mode b is transmitted to Bob, and after passing through beam splitter 104, it has...

[0049] After N rounds of communication, Alice's initial state can be represented as:

[0050]

[0051] in |H> Aa =|H> A |0> a ,|V> Aa =|V> A |0> a Where |H> A ,|V> A ,|0> A For the quantum states of the Alice auxiliary particle with horizontal polarization, vertical polarization, and empty pulse, |H> a ,|V> a ,|0> a For the quantum states of a photon with horizontal polarization, vertical polarization, and empty pulse, |H> b ,|V> b ,|0> b Let |0>,|H>,|V> represent the quantum states of a mode b photon with horizontal polarization, vertical polarization, and empty pulse. For simplicity, we will use 0, H, and V to represent |0>,|H>,|V>.

[0052] The security of this scheme will be proven by starting with the general form of a collective attack. A collective attack is defined as a unitary transformation U Eve It acts on the auxiliary state e0 of both the b-mode and the eavesdropper Eve, therefore,

[0053]

[0054] Define the Bob operation as U Bob Including SIFT operation U S and CTRL operation U C Two types, then there is U S H b 0 B =0 b H B U S V b 0 B =0 b V B U S 0 b 0 B =0 b 0B U C H b 0 B =H b 0 B U C V b 0 B =V b 0 B U C 0 b 0 B =0 b 0 B Therefore, in the l-th round of communication, the quantum state of the system when it reaches Bob's end can be represented as:

[0055]

[0056] Where e XY In the context of X, Y = 0, H, V, this represents the arbitrary state of the Eve auxiliary particle during the l-th communication. This corresponds to the case where module b evolves from the initial state X to Y through the channel. In practice, due to the low dark count of the detector, to avoid double counting, we have... In the security proof process of this scheme, only the quantum state of the eavesdropper related to the key rate is considered. The quantum state of the photon returning to Alice's end can be represented as:

[0057]

[0058] When Alice and Bob simultaneously choose to flip or not flip, modes a and b meet and interfere at beam splitter 104. Assume K... e Let K = 0, 1, 2, ... be a set of basis vectors for state e, then we have C K (AB) = e <K|e AB >, A,B=0,H,V. Without Alice and Bob flipping, the reduced density matrices of particles A,B, and modes a,b can be expressed as:

[0059]

[0060] because Then we can get After pulse a passes through BS, there is After pulse b passes through BS, there is For the sake of brevity, define Next, the encoded photons are entangled and purified. When the photons are propagating forward in the quantum channel, the density matrices of Alice and Bob are represented as follows:

[0061]

[0062] The reduced density matrices of paths d and c are expressed as follows:

[0063]

[0064] Among them Λ l Since is a constant, according to formula (6), the detection probabilities of path d and path c can be expressed as follows:

[0065]

[0066] Due to the symmetry of the optical path, the same detection probability distribution formula can be obtained when Alice and Bob flip simultaneously. Considering the possibility of an eavesdropper attack in the channel, it is assumed that all bit errors are introduced by Eve. After passing through the quantum channel, the corresponding quantum state can be transformed into the following four cases: If the initial quantum state changes to state |φ after passing through the channel + > AB Then there are no errors in the channel; if the initial quantum state becomes state |φ after passing through the channel. - > AB ,|ψ + > AB ,|ψ - > AB Therefore, the eavesdropper introduces both phase error and bit error into the channel. Thus, the formula for phase error can be derived as follows: but because achievable let β can be calculated using formula (9). l =16[P l (H A H c )+P l (H A H d )]-η,β′ l =16[P l (V A V c )+P l (V A V d )]-η,ξ l =32P l (H A V c ), ξ′ l =32P l (V A H c ).

[0067] Therefore, phase error The tight boundary can be represented as:

[0068]

[0069] in constant Λ l It can be represented as:

[0070]

[0071] Ultimately, we need to determine the overall phase error e. ph According to Azuma's inequality, when N is sufficiently large, e ph and The difference is infinitesimal, meaning it can be approximated. Similarly let

[0072] therefore,

[0073]

[0074] Assuming there is no eavesdropping attack by Eve and no channel noise, then... P(H A H d )=P(V A V d Since ) = 0, we can get β = β′ = η, ξ = ξ′ = 0. Substituting these into formula (12), we get e. ph If the number of entangled elements is 0, then the eavesdropper's information content is 0, and Alice and Bob share the maximally entangled state.

[0075] The above embodiments are merely one of the preferred embodiments of the present invention and should not be used to limit the scope of protection of the present invention. Any modifications or refinements made to the main design concept and spirit of the present invention that are not of substantial significance, but solve the same technical problem as the present invention, should be included within the scope of protection of the present invention.

Claims

1. A one-way code-generating semi-quantum key distribution system, characterized in that: The quantum method prepares quantum states, while the classical method randomly selects photons to generate keys or returns photons to detect eavesdropping. The system includes a quantum side Alice and a classical side Bob, as well as a quantum channel (301) connecting the two sides. The quantum side Alice is composed of a pulsed photon source (101), an attenuator (102), a circulator (103), a beam splitter (104), a first optical delay coil (105), a first switchable polarization rotator (106), a first Faraday mirror (107), a first single-photon detector (108), and a second single-photon detector (109). The classical side Bob is composed of an optical switch (201), a polarization beam splitter (202), a second optical delay coil (203), a third single-photon detector (204), a second switchable polarization rotator (205), and a second Faraday mirror (206). Alice end: The output port of the pulsed photon source (101) is connected to the input port of the attenuator (102), the output port of the attenuator (102) is connected to port 1 of the circulator (103), the in-phase input port 2 of the circulator (103) is connected to port d of the beam splitter (104), the in-phase output port 3 of the circulator (103) is connected to the first single-photon detector (108), the c port of the beam splitter (104) is connected to the second single-photon detector (109), the a port of the beam splitter (104) is connected to the input port of the first optical delay coil (105), the output port of the first optical delay coil (105) is connected to the input port of the first polarization rotator (106), the output port of the first polarization rotator (106) is connected to the first Faraday mirror (107), the b port of the beam splitter (104) is connected to the input port of the quantum channel (301); the output port of the quantum channel (301) is connected to the input port of the Bob end optical switch (201). Bob end: The output port 2 of the optical switch (201) is connected to the combined port 1 of the polarization beam splitter (202) and the second optical delay coil (203), the port 3 of the polarization beam splitter (202) is connected to the third single-photon detector (204), the output port 3 of the optical switch (201) is connected to the input port of the second polarization rotator (205), and the output port of the second polarization rotator (205) is connected to the second Faraday mirror (206). The classic Bob uses an optical switch to select SIFT and CTRL operations; when the optical switch is open, the key is directly generated based on the response of the third detector, realizing one-way key loading; when the classic Bob opens the optical switch and generates the key, since no additional information is output from the classic side, the Trojan horse attack problem that is common in existing bidirectional systems is solved.

2. The one-way code-generating semi-quantum key distribution system according to claim 1, characterized in that: The quantum square Alice uses only one set of orthogonal bases to prepare and measure quantum states. Its quantum properties are reflected in the fact that Alice prepares a superposition state of single photons and empty pulses.

3. The one-way coded semi-quantum key distribution system according to claim 1, characterized in that: The classical Bob method achieves time distinguishability by using a polarization beam splitter and a second optical delay coil. Its classical characteristic is reflected in the fact that it only uses a third detector to measure at two different time stamps without the need to prepare quantum states.

4. A one-way code-generating semi-quantum key distribution method, utilizing the one-way code-generating semi-quantum key distribution system according to any one of claims 1 to 3, characterized in that: The photons encoded by the semi-quantum key distribution system are transmitted unidirectionally in the quantum channel, and the returned photons are used to quantify the amount of information the eavesdropper has.

Citation Information

Patent Citations

  • Bell state-based two-party quantum key negotiation method and system

    CN110098930A

  • One-way transmission quantum database privacy query method

    CN110929294A