A quantum private size comparison protocol resistant to bit leakage
By using a quantum private size comparison protocol with single Bell state and XOR operation to obtain small operations, the problem of bit leakage in the prior art is solved, and the correct size comparison is achieved without leaking private data, which improves security and efficiency.
Patent Information
- Application Number
- CN202310132646.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-20
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2043-02-20
AI Technical Summary
The existing quantum private size comparison protocol will leak one bit in private data during the comparison process, which violates the basic requirements of quantum private comparison.
Using a single Bell state as a quantum resource, through exclusive OR operation and small operation, combined with the interaction between classical channels and quantum channels, a quantum private size comparison protocol that resists bit leakage is designed to ensure that private data does not leak any information during the comparison process.
It achieves correct size comparison without leaking private data, improves the security and efficiency of the protocol, prevents bit leakage, and meets the basic requirements of quantum private comparison.
Smart Images

Figure FDA0005536594370000011 
Figure FDA0005536594370000012 
Figure FDA0005536594370000013
Abstract
Description
Technical Field
[0001] The present invention relates to a quantum private magnitude comparison (QPMC) protocol that does not leak any bit. Background Art
[0002] Quantum Private Comparison (QPC), a branch of quantum cryptography, has garnered significant research attention in recent years. The fundamental principle of QPC is to compare the private data of two users using quantum cryptography without revealing any information about the users' private data. This technology has a wide range of applications, including comparing the wealth of millionaires without disclosing their financial information, e-commerce, anonymous voting, and data mining.
[0003] Existing QPC protocols [1-15] often only compare private data for equality, resulting in either equality or inequality. The quantum private magnitude comparison (QPMC) protocol, on the other hand, can compare private data for magnitude, with results in the following three categories: greater than, equal to, and less than. However, existing QPMC techniques [16, 17] can leak one bit of the private data during the comparison process.
[0004] The reason for leaking a single bit of private data is as follows: The existing technology compares the binary numbers of two private data bits bit by bit, starting with the most significant bit of the private data. A third party, the TP, conducting the comparison, announces the position of the first unequal bit in the two private data. Based on this position, Person A and Person B can determine whose bit is larger, and therefore whose private data is larger. This means that the bit owners, Person A and Person B, can use their own unequal bits to deduce the other party's bit size, since a bit is either 0 or 1. This causes the existing QPMC technology to leak a single bit of private data during the comparison process. Although the leakage of a single bit is not sufficient to compromise the entire private data, it also violates the basic requirement of quantum private comparison, which assumes that the input private data must be kept confidential.
[0005] References:
[0006] [1]Yang, YG, Gao, WF, Wen, QY: Secure quantum private comparison, Phys. Scr.. 80(6), 065002 (2009)
[0007] [2]Liu, B., Gao, F., Jia, H.Y., Huang, W., Zhang, W.W., Wen, Q.Y.:Efficient quantum private comparison employing single photons and collectivedetection, Quantum Inf. Process. 12(2), 887–897 (2013)
[0008] [3]Chen, X.B., Su, Y., Niu, X.X., Yang, Y.X.: Efficient and feasiblequantum private comparison of equality against the collective amplitudedamping noise, Quantum Inf. Process. 13(1), 101–112 (2014)
[0009] [4]Sun, Z.W., Yu, J.P., Wang, P., Xu, L.L., Wu, C.H.: Quantum privatecomparison with a malicious third party, Quantum Inf. Process. 14(6), 2125–2133 (2015)
[0010] [5]Ye, T.Y.: Quantum private comparison via cavity QED, Commun.Theor. Phys.. 67(2), 147–156 (2017)
[0011] [6]Lang, Y.-F.: Semi-quantum private comparison using single photons,Int. J. Theor. Phys.. 57(10), 3048–3055 (2018)
[0012] [7]Ye, T.-Y., Ye, C.-Q.: Measure-resend semi-quantum privatecomparison without entanglement, Int. J. Theor. Phys.. 57(12), 3819–3834(2018)
[0013] [8]Ji, Z.X., Zhang, H.G., Fan, P.R.: Two-party quantum privatecomparison protocol with maximally entangled seven-qubit state, Mod. Phys.Lett. A. 34(28), 1–179(2019)
[0014] [9]Lang, Y.-F.: Quantum gate-based quantum private comparison, Int.J. Theor. Phys.. 59(3), 833–840 (2020)
[0015]
[10] Lang, Y.-F.: Quantum Private Comparison without ClassicalComputation, Int. J. Theor. Phys.. 59(9), 2984–2992 (2020)
[0016]
[11] Huang, X., Zhang, S.B., Chang, Y. et al.: Efficient QuantumPrivate Comparison Based on Entanglement Swapping of Bell States, Int JTheor. Phys.. 60, 3783–3796 (2021)
[0017]
[12] Lang, Y.-F.: Quantum Private Comparison Using Single Bell State,Int. J. Theor. Phys.. 60(11-12), 4030-4036(2021)
[0018]
[13] Lang, Y.-F.: Fast Quantum Private Comparison without Keys andEntanglement, Int. J. Theor. Phys.. 61(2), 45(2022)
[0019]
[14] Chou, W.H., Hwang, T., Gu, J.: Semi-quantum private comparisonprotocol under an almost-dishonest third party,
[0020]
[15] Thapliyala, K., Sharmab, R.D., Pathak, A.: Orthogonal-state-basedand semi-quantum protocols for quantum private comparison in noisyenvironment,
[0021]
[16] Lang, Y.-F.: Quantum Private Magnitude Comparison, Int. J. Theor.Phys.. 61(4), 100 (2022)
[0022]
[17] Zhou, L.-t., Lang, Y.-F., Zhao, Z.-H.: Quantum Private MagnitudeComparison Based on Maximum Operation, Int. J. Theor. Phys.. 62(1), 2(2023)
[0023]
[18] Long, G.L., Liu, X.S.: Theoretically efficient high-capacityquantum-key-distribution scheme. Phys. Rev. A. 65, 032302 (2002)
[0024]
[19] Li, CY, Zhou, HY, Wang, Y., Deng, FG: Secure quantum keydistribution network with Bell states and local unitary operations. Chin.Phys. Lett. 22(5), 1049–1052 (2005)
[0025]
[20] Li, CY, Li, XH, Deng, FG, Zhou, P., Liang, YJ, Zhou,HY: Efficient quantum cryptography network without entanglement and quantummemory. Chin. Phys. Lett. 23(11), 2896–2899 (2006)
[0026]
[21] Shor PW, Preskill J.: Simple proof of security of the BB84quantum key distribution protocol. Phys. Rev. Lett. 85(2), 441–444(2000) Summary of the Invention
[0027] To address the shortcomings of existing technologies, meet the basic requirements of quantum secret comparison, and enhance the security of private data, this present invention proposes a bit-leakage-resistant quantum secret size comparison protocol. This protocol eliminates the leakage of any bit of private data during the quantum secret size comparison process. This protocol utilizes a single Bell state as a quantum resource. This reduces the cost of using this bit-leakage-resistant quantum secret size comparison protocol and improves its efficiency and practicality. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] none. DETAILED DESCRIPTION
[0029] The present invention uses the symbol ⊕ to represent the exclusive OR operation of two bits, that is, if the two bits are x and y, then the expression of the exclusive OR operation of the two bits is x⊕y, where x, y∈{0, 1}, 0⊕0=0, 0⊕1=1, 1⊕0=1, 1⊕1=0.
[0030] The present invention uses the symbol ∩ to represent the minimum operation of two bits, that is, if the two bits are x and y, then the expression of the minimum operation of the two bits is x∩y, where x, y∈{0, 1}, 0∩0=0, 0∩1=0, 1∩0=0, 1∩1=1.
[0031] The working principle of data size comparison is explained below. Comparison refers to comparing the relative sizes of two pieces of data. Logically, when comparing two pieces of data, the comparison should be done bit by bit, from the highest digit to the lowest digit. If the highest digits are already compared, the conclusion can be drawn immediately, and there is no need to compare the lower digits, as they have no impact on the overall result. Only when the highest digits are equal are the lower digits compared. For example, when comparing the two commonly used decimal numbers 501 and 499, the highest digit—the hundreds digit—is compared first. Since the hundreds digit in the former is 5 and the hundreds digit in the latter is 4, and 5 is greater than 4, 501 is greater than 499, so there is no need to compare the tens and units digits. Only when the highest digit—the hundreds digit—is equal is the lowest digit—the tens digit—needed to be compared. This method also applies to comparing two binary numbers.
[0032] Next, we'll explain the process of comparing a bit. Assume a and b are the two bits to be compared. To determine their relative size, we need to perform two operations on them. The first operation is the exclusive OR operation: and , remember the calculation result and The second operation is to take the smaller operation, that is and When the calculation result m is 1, it means a > b; when the calculation result n is 1, it means a < b; when both m and n are 0, it means a = b. After these two operations are completed, we know the magnitude relationship between the two bits, a and b. To more clearly illustrate the above comparison process, we list the two operation results and comparison results of the two bits a and b in the truth table for single-bit binary number size comparison in Table 1.
[0033] Table 1 Truth table for comparing the size of a single-bit binary number
[0034] a / a ⊕ 1 b / b ⊕ 1 m n Size relationship 0 / 1 0 / 1 0 0 a=b 0 / 1 1 / 0 0 1 a<b 1 / 0 0 / 1 1 0 a>b 1 / 0 1 / 0 0 0 a=b
[0035] Existing quantum secret size comparison protocols utilize quantum cryptography to compare the size of private data without leaking the user's private data. While this technology does not leak the user's private data as a whole, it can leak a single bit of the private data during the comparison process. To strictly meet the fundamental requirement of quantum secret comparison—no leakage of any private data—the present invention creates a bit-leakage-resistant quantum secret size comparison protocol. This protocol completely eliminates the bit-leakage issue present in existing technologies.
[0036] The quantum private size comparison protocol against bit leakage is run under the operation of two private data comparison parties A and B, and a third party TP. A and B respectively have private data A=a N-1 ...a1a0 and B=b N-1 ...b1b0, where a j ,b j ∈{0, 1},j∈{0, 1, ..., N-1},2 N-1 ≤max{A, B}<2 N The leftmost bit a N-1 and b N-1 The quantum secret size comparison protocol resistant to bit leakage includes the following six steps.
[0037] Step 1: Third-party TP prepares 4N or Bell state, TP divides these 4N Bell states into 4 groups, each group has N Bell states, and uses the first and second particles of the first group of N Bell states to form quantum sequences A0 and A1 respectively, uses the first and second particles of the second group of N Bell states to form quantum sequences B0 and B1 respectively, uses the first and second particles of the third group of N Bell states to form quantum sequences P0 and P1 respectively, and uses the first and second particles of the fourth group of N Bell states to form quantum sequences P2 and P3 respectively; in order to detect whether there is eavesdropping behavior during quantum communication, TP prepares two groups of decoy photon sequences DA and DB, each of which is randomly selected from { , , , },in and , where Z-based and X-based are used to represent { , }and{ , } measurement basis, TP randomly inserts the decoy photons in DA into the quantum sequence S0 composed of A0, P0 and P2 to form a new quantum sequence SA; TP also randomly inserts the decoy photons in DB into the quantum sequence S1 composed of B0, P1 and P3 to form a new quantum sequence SB; then, the third party TP sends SA and SB to A and B respectively; at the same time, TP uses the Z basis to measure the quantum sequences A1 and B1. If the measurement result is the quantum state and , then the corresponding bits are 0 and 1 respectively, so TP obtains two bit strings A1=(a1 N-1 ...a11a10) and B1=(b1 N-1...b11b10), where a1 j , b1 j ∈{0, 1}, j∈{0, 1, ..., N-1};
[0038] Step 2: After A and B receive SA and SB, respectively, TP announces the position of the decoy photons in SA and SB and their corresponding measurement basis through the classical channel. A and B use the information announced by TP to perform quantum measurements on the decoy photons in their hands and return the measurement results to TP through the classical channel. After receiving the information, TP verifies A and B's measurement results to check whether there is an eavesdropper in the quantum channel. If TP finds that the error rate of A and B's measurement results is within a preset value, they proceed to step 3; otherwise, they start over from step 1.
[0039] Step 3: A and B discard the decoy photons in SA and SB respectively to recover the quantum sequences S0 and S1. Then A uses the Z basis to measure A0, P0 and P2. The measurement results are recorded as A0=(a0 N-1 ...a01a00), P0=(p0 N-1 ...p01p00) and P2=(p2 N-1 ...p21p20), B also uses the Z basis to measure B0, P1 and P3, and the measurement results are recorded as B0=(b0 N- 1...b01b00), P1=(p1 N-1 ...p11p10) and P3=(p3 N-1 ...p31p30), where a0 j , b0 j , p0 j , p1 j , p2 j ,p3 j ∈{0, 1}, j∈{0, 1, ..., N-1}; A and B calculate ra bit by bit respectively j =a j ⊕a0 j ⊕p0 j and rb j =b j ⊕b0 j ⊕p1 j , where ra j , rb j ∈{0, 1},RA=(ra N-1 ...ra1ra0), RB=(rb N-1 ...rb1rb0), j∈{0, 1, ...,N-1}; A and B send the bit strings RA and RB to TP respectively through announcements;
[0040] Step 4: According to p0 j p2 j , A divides all N subscripts, i.e., j=0, 1, ..., N-1, into four groups Gk, where k∈{0, 1, 2, 3}, and first puts subscript N-1 into group G0; if p0 N-2 p2 N-2 = p0 N-1 p2 N-1 , then subscript N-2 is also classified into group G0, otherwise subscript N-2 is classified into group G1; if p0 N-3 p2 N-3 =p0 N-1 p2 N-1 , then subscript N-3 is also included in group G0, if p0 N- 3p2 N-3 =p0 N-2 p2 N-2 , then put the subscript N-3 into group G1, otherwise put the subscript N-3 into group G2; if p0 N-4 p2 N-4 =p0 N- 1p2 N-1 , then subscript N-4 will be included in group G0, if p0 N-4 p2 N-4 =p0 N-2 p2 N-2 , then subscript N-4 is included in group G1, if p0 N-4 p2 N-4 =p0 N-3 p2 N-3 , then subscript N-4 is included in group G2, otherwise subscript N-4 is included in group G3; and so on, all remaining subscripts are included in the four subscript groups G0, G1, G2 or G3; B also groups all subscripts in the same way, because p1 j p3 j =p0 j p2 j , so the grouping results are the same; since p0 in the same group j or p1 j The values of are the same, so the p0 in the same group j or p1 j All are uniformly marked as p0 Gk or p1 Gk ; Party A sends all subscripts and their corresponding group numbers, Gk, to the third party TP through an announcement;
[0041] Step 5: After receiving RA, RB, G0, G1, G2 and G3 information, TP uses the data RA, RB, A1 and B1 to calculate the expression r0 starting from their highest bit. j =(ra j ⊕a1 j ⊕1)∩(rb j ⊕b1 j ) and r1 j =(ra j ⊕a1 j )∩(rb j ⊕b1 j ⊕1) value; once r0 j or r1 j The calculated value is 1, TP ends the calculation, and then uses the subscript j to find the corresponding group number Gk. After finding the group number Gk, use r0 Gk or r1 Gk To replace r0 j or r1 j Go to the announcement r0 Gk =1 or r1 Gk =1, then go to step 6; otherwise, continue to calculate r0 j or r1 j The value of RA, RB, A1 and B1 is calculated until all bits are calculated, and finally r00=0 and r10=0 are obtained. TP declares that the private data of A and B are equal. Here r0 j , r1 j ∈{0, 1},R0=(r0 N-1 ...r01r00), R1=(r1 N-1 ...r11r10), j∈{0, 1, ..., N-1};
[0042] Step 6: A and B according to the announced r0 Gk or r1 Gk You can know their respective p0 Gk and p1 Gk The value of r0; A and B then Gk =1 or r1 Gk =1 and their respective p0 Gk and p1 Gk The value of privately judges the size relationship of the private data of both parties: if r0 Gk =1 and p0 Gk = p1 Gk =0 or r1 Gk =1 and p0 Gk = p1 Gk =1, then A and B can infer that B's private data is greater than A's private data, that is, B > A; if r1Gk =1 and p0 Gk = p1 Gk =0 or r0 Gk =1 and p0 Gk = p1 Gk =1, then A and B can privately know that A's private data is greater than B's private data, that is, A > B.
[0043] To verify the correctness of the quantum secret size comparison protocol that is resistant to bit leakage, the following analysis is conducted. The two equations in the protocol can be rewritten as follows: j =(ra j ⊕a1 j ⊕1)∩(rb j ⊕b1 j )=(a j ⊕a0 j ⊕p0 j ⊕a1 j ⊕1)∩(b j ⊕b0 j ⊕p1 j ⊕b1 j ) and r1 j =(ra j ⊕a1 j )∩(rb j ⊕b1 j ⊕1)=(a j ⊕a0 j ⊕p0 j ⊕a1 j )∩(b j ⊕b0 j ⊕p1 j ⊕b1 j ⊕1). In the above steps, the Bell state generated by TP Once measured, the two particles will collapse into the following two states { , }. Therefore, a0 j =a1 j =0 / 1, b0 j =b1 j =0 / 1, p0 j =p1 j =0 / 1, p2 j =p3 j =0 / 1. So, and .
[0044] According to Table 1, as long as r0 j or r1 j Equal to 1, r0j or r1 j The expression can show that a j and b j The size relationship; if r0 j and r1 j are all 0, then it means a j Equal to b j The grouping of all subscripts in step 4 does not affect a j and b j Because each pair of p0 in each group j and p1 j The values are equal. Therefore, the bit leakage-resistant quantum secret size comparison protocol can correctly perform quantum secret size comparison. The present invention is correct.
[0045] The following analyzes the security of the bit-leakage-resistant quantum secret size comparison protocol of the present invention from the perspectives of external attacks and internal attacks.
[0046] First, we analyze external attacks. In the above steps, except for step 1, there is no opportunity for external attackers to attack. The quantum bits transmitted through the quantum channel in step 1 are very vulnerable to external security attacks, but the SA and SB transmitted in step 1 contain decoy photons and are transmitted in the form of quantum data blocks
[18] . In other words, the present invention uses quantum data block technology and decoy photon technology [19, 20] to ensure the security of quantum communication in step 1. Decoy photon technology has been proven to be unconditionally secure in relevant literature
[21] .
[0047] Since RA is encrypted by A0 and P0 and RB is encrypted by B0 and P1, the private data of the two users are kept confidential in steps 3 and 4. In steps 5 and 6, the announced r0 Gk or r1 Gk The value of r0 cannot help external attackers deduce the user's private data, and only TP knows r0 k and r1 l The calculation result, r0 k and r1 l The value of cannot be leaked and used by external attackers. Because TP is semi-loyal, the data (ra j ⊕a1 j ) and (rb j ⊕b1 j ) cannot be leaked, so (ra j ⊕a1 j ) and (rb j ⊕b1 j) cannot be exploited by an external attacker. As can be seen above, the private data of the two users remains confidential to external attackers. Therefore, the bit-leakage-resistant quantum private size comparison protocol is resistant to external attacks.
[0048] Next, we analyze internal attacks. Internal attacks can be divided into two scenarios. The first scenario is when one comparison participant attempts to obtain the private data of another. The second scenario is when a TP attempts to obtain the private data of both comparison participants.
[0049] The analysis of scenario 1 is as follows. Since Person A and Person B play the same role in the protocol, we only consider the case where Person A attempts to obtain Person B's private data. Since the semi-loyal TP does not collude with any other party, and Person A knows nothing about the secret key B0 used to encrypt the private data B into the ciphertext RB, Person A cannot deduce any information from the published RB. Therefore, Person A cannot learn Person B's private data. In summary, the bit-leakage-resistant quantum secret size comparison protocol is resistant to insider attacks, meaning that one party cannot obtain the private data of another.
[0050] The analysis of the second case is as follows. In the technical solution of the present invention, TP is semi-loyal, it always strictly implements the process of the solution and faithfully generates Bell entangled states. or , and does not collude with external eavesdroppers to steal information. Therefore, it can only steal the private data of the two comparison participants by using A1 and B1. Since the two users' private data A and B are encrypted into ciphertexts RA and RB respectively using secret keys P0 and P1, and because of the quantum properties of Bell entangled states, TP cannot know the one-time values of P0 and P1. Therefore, even if TP knows the values of A1 and B1 and the grouping information of P0 and P2, TP still cannot deduce the two users' private data A and B from the ciphertexts RA and RB. In other words, TP cannot obtain the private data of the two comparison participants.
[0051] From the above security analysis, we conclude as follows: TP can only obtain j or r1 j The calculation result of the specific two bits is a j and b j Unequal information, and as for a j and b jNo one, including TP, knows the size relationship of the two bits. Person A and Person B also don't know which two bits are unequal, let alone the size relationship between the two bits. Regarding the question of "who knows the comparison results of private data," a comparison of the present invention with the prior art [16, 17] is listed in Table 2. From the above description, we can see that the present invention, namely the bit-leakage-resistant quantum secret size comparison protocol, can prevent bit leakage.
[0052] From the above analysis of Case 1 and Case 2, it can be seen that the technical solution of the present invention is also safe against internal attacks.
[0053] Table 2 Differences between the present invention and the prior art
[0054] Comparison results of private data Existing technologies[16, 17] The present invention Announcement Information The subscript of a bit The group number of the group to which the subscript belongs <![CDATA[Two bits a j and b j are not equal]]> Everyone knows Only TP knows <![CDATA[The magnitude relationship between two bits a j and b j > Only A and B know No one knows Two private data A and B are not equal Everyone knows Everyone knows The size relationship between two private data A and B Only A and B know Only A and B know
[0055] While existing quantum secret size comparison techniques do not disclose the user's private data in the overall data, they can leak one bit of the private data to the other party during the comparison process. To meet the fundamental requirement of quantum secret comparison—no disclosure of any private data—the present invention creates a bit-leakage-resistant quantum secret size comparison protocol. This protocol completely eliminates the bit-leakage issue present in existing technologies. This demonstrates not only the practicality of this invention but also its innovative nature. The technical solution of this invention requires creative effort, which also demonstrates the inherent inventiveness of this invention.
Claims
1. A quantum secret size comparison method that is resistant to bit leakage. The method involves two participants, A and B, who are comparing the size of private data. The method is run under the auspices of a third party TP. A and B each have private data A = a N-1 ...a1a0 and B=b N-1 ...b1b0, where a j ,b j ∈{0,1},j∈{0,1,...,N-1},2 N-1 ≤max{A,B}<2 N , the leftmost bit a N-1 and b N-1 The method comprises the following six steps: Step 1: Third-party TP prepares 4N or Bell state, TP divides these 4N Bell states into 4 groups, each group has N Bell states, and uses the first and second particles of the first group of N Bell states to form quantum sequences A0 and A1 respectively, uses the first and second particles of the second group of N Bell states to form quantum sequences B0 and B1 respectively, uses the first and second particles of the third group of N Bell states to form quantum sequences P0 and P1 respectively, and uses the first and second particles of the fourth group of N Bell states to form quantum sequences P2 and P3 respectively; in order to detect whether there is eavesdropping behavior during quantum communication, TP prepares two groups of decoy photon sequences DA and DB, each of which is randomly selected from {|0>,|1>,|+>,|->}, where and Here, the Z basis and X basis are used to represent the measurement basis of {|0>,|1>} and {|+>,|->} respectively. TP randomly inserts the decoy photons in DA into the quantum sequence S0 composed of A0, P0 and P2 to form a new quantum sequence SA; TP also randomly inserts the decoy photons in DB into the quantum sequence S1 composed of B0, P1 and P3 to form a new quantum sequence SB; then, the third party TP sends SA and SB to A and B respectively; at the same time, TP uses the Z basis to measure the quantum sequences A1 and B1. If the measurement results are quantum states |0> and |1>, then the corresponding bits are 0 and 1 respectively. In this way, TP obtains two bit strings A1=(a1 N-1 ...a11a10) and B1=(b1 N-1 ...b11b10), where a1 j ,b1 j ∈{0,1}, j∈{0,1,...,N-1}; Step 2: After A and B receive SA and SB, respectively, TP announces the position of the decoy photons in SA and SB and their corresponding measurement basis through the classical channel. A and B use the information announced by TP to perform quantum measurements on the decoy photons in their hands and return the measurement results to TP through the classical channel. After receiving the information, TP verifies A and B's measurement results to check whether there is an eavesdropper in the quantum channel. If TP finds that the error rate of A and B's measurement results is within a preset value, they proceed to step 3; otherwise, they start over from step 1. Step 3: A and B discard the decoy photons in SA and SB respectively to recover the quantum sequences S0 and S1. Then A measures A0, P0 and P2 using the Z basis. The measurement results are recorded as A0=(a0 N-1 ...a01a00), P0=(p0 N-1 ...p01p00) and P2=(p2 N-1 ...p21p20), B also uses the Z basis to measure B0, P1 and P3, and the measurement results are recorded as B0=(b0 N- 1...b01b00), P1=(p1 N-1 ...p11p10) and P3=(p3 N-1 ...p31p30), where a0 j ,b0 j ,p0 j ,p1 j ,p2 j ,p3 j ∈{0,1},j∈{0,1,...,N-1};A and B calculate ra bit by bit respectively j =a j ⊕a0 j ⊕p0 j and rb j =b j ⊕b0 j ⊕p1 j , where ra j ,rb j ∈{0,1},RA=(ra N-1 ...ra1ra0), RB=(rb N-1 ...rb1rb0), j∈{0,1,...,N-1}; A and B send the bit strings RA and RB to TP respectively through announcements; Step 4: According to p0 j p2 j The value of p0, A divides all N subscripts, i.e. j = 0, 1, ..., N-1, into four groups Gk, where k∈{0, 1, 2, 3}, and first puts subscript N-1 into group G0; if p0 N-2 p2 N-2 =p0 N-1 p2 N-1 , then subscript N-2 is also classified into group G0, otherwise subscript N-2 is classified into group G1; if p0 N-3 p2 N-3 =p0 N-1 p2 N-1 , then subscript N-3 is also included in group G0, if p0 N-3 p2 N-3 =p0 N-2 p2 N-2 , then put the subscript N-3 into group G1, otherwise put the subscript N-3 into group G2; if p0 N-4 p2 N-4 =p0 N-1 p2 N-1 , then subscript N-4 will be included in group G0, if p0 N-4 p2 N-4 =p0 N-2 p2 N-2 , then subscript N-4 is included in group G1, if p0 N-4 p2 N-4 =p0 N-3 p2 N-3 , then subscript N-4 is included in group G2, otherwise subscript N-4 is included in group G3; and so on, all remaining subscripts are included in the four subscript groups G0, G1, G2 or G3; B also groups all subscripts in the same way, because p1 j p3 j =p0 j p2 j , so the grouping results are the same; since p0 in the same group j or p1 j The values of are the same, so the p0 in the same group j or p1 j All are uniformly marked as p0 Gk or p1 Gk ; Party A sends all subscripts and their corresponding group numbers, Gk, to the third party TP through an announcement; Step 5: After receiving RA, RB, G0, G1, G2 and G3 information, TP uses the data RA, RB, A1 and B1 to calculate the expression r0 starting from their highest bit. j =(ra j ⊕a1 j ⊕1)∩(rb j ⊕b1 j ) and r1 j =(ra j ⊕a1 j )∩(rb j ⊕b1 j ⊕1) value; once r0 j or r1 j The calculated value is 1, TP ends the calculation, and then uses the subscript j to find the corresponding group number Gk. After finding the group number Gk, use r0 Gk or r1 Gk To replace r0 j or r1 j Go to the announcement r0 Gk =1 or r1 Gk =1, then go to step 6; otherwise, continue to calculate r0 j or r1 j The value of RA, RB, A1 and B1 is calculated until all bits are calculated, and finally r00 = 0 and r10 = 0 are obtained. TP declares that the private data of A and B are equal. Here r0 j ,r1 j ∈{0,1},R0=(r0 N-1 ...r01r00), R1=(r1 N-1 ...r11r10), j∈{0,1,...,N-1}; Step 6: A and B according to the announced r0 Gk or r1 Gk You can know their respective p0 Gk and p1 Gk The value of r0; A and B then Gk =1 or r1 Gk =1 and their respective p0 Gk and p1 Gk The value of privately judges the size relationship of the private data of both parties: if r0 Gk =1 and p0 Gk =p1 Gk =0 or r1 Gk =1 and p0 Gk =p1 Gk =1, then A and B can infer that B's private data is greater than A's private data, that is, B>A; if r1 Gk =1 and p0 Gk =p1 Gk =0 or r0 Gk =1 and p0 Gk =p1 Gk =1, then A and B can privately know that A's private data is greater than B's private data, that is, A>B; The symbol ⊕ represents an XOR operation of two bits; the symbol ∩ represents a smaller operation of two bits.
Citation Information
Patent Citations
Collective dephasing noise resisting error tolerance channel encryption quantum dialogue protocol
CN104104503A
Bell state-based semi-quantum privacy comparison method which does not require classical communicator to have measurement capability
CN110830241A