A method for confirming a quantum sealed bidding auction based on blind signature

CN117527253BActive Publication Date: 2026-09-22HAINAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311407684.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-10-27
Publication Date
2026-09-22
Estimated Expiration
2043-10-27

AI Technical Summary

Technical Problem

[0005]总而言之,现有的量子密封投标拍卖方法存在恶意竞价、投标者之间以及投标者和拍卖商之间的合谋等问题

Benefits of technology

[0038]与已有技术相比,本发明的有益效果体现在:

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117527253B_ABST
    Figure CN117527253B_ABST
Patent Text Reader

Abstract

The application discloses a quantum sealed bidding auction post-confirmation method based on blind signature, which comprises an initialization process, a bidding preparation process, a bidding delivery process and a verification process. The application proposes a post-confirmation protocol based on blind signature, and creatively adopts a two-state vector form, which provides a suitable tool for implementing the post-confirmation mechanism to ensure the fairness of the QSA protocol and enhances the fairness of the QSA protocol.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of quantum sealed bidding auctions and quantum blind signatures, specifically to a method for post-auction confirmation of quantum sealed bidding auctions based on blind signatures. Background Technology

[0002] Auctions are an ancient and enduring form of market transaction. Depending on the auction rules, there are various auction formats. For example, in a British auction, bidders start at a starting price and gradually increase their bids until no one is willing to pay a higher price. Another common type of auction is a sealed-bid auction, where all bidders submit their bids simultaneously and anonymously, and the highest bidder wins the item.

[0003] The concept of quantum auctions was first proposed by Piotrowski et al. in 2008. In 2009, Naseri first proposed a quantum sealed-bid auction (QSA) protocol based on a quantum-secure direct communication protocol. However, Naseri's protocol has several security vulnerabilities. For example, Qin et al. discovered that a double CNOT attack could allow malicious bidders to obtain other bidders' private bids undetected. Furthermore, Yang et al. found that in this protocol, malicious bidders could obtain other bidders' private bids by sending false entanglement resources. Therefore, this protocol fails to effectively ensure the fairness of sealed-bid auctions. To defend against these attacks, some scholars have proposed QSA with post-confirmation mechanisms. Nevertheless, it has been found that this protocol does not provide sufficient protection against collusion attacks between malicious bidders and dishonest auctioneers, further threatening the fairness of the auction.

[0004] Subsequently, various novel QSA protocols based on different models and other protocols have been proposed, further enriching the research field of quantum auction protocols. For example, there is the QSA with a secret order, which allows bidders to encode their bids using a secret order and then share the secret information to verify dishonest behavior. Quantum secret sharing protocols are one of the common methods for designing QSA protocols; they distribute bids as shared secret information to other bidders, and then verify dishonest behavior by subsequently recovering the secret information. Furthermore, other quantum cryptographic schemes, such as quantum public-key encryption and quantum key negotiation, have also been used to implement QSA protocols. In addition, researchers are dedicated to studying QSA protocols with various properties and functions to better solve practical problems, such as QSA protocols with privacy protection features. As a protocol that combines security with application requirements, the cryptanalysis and improvement of QSA protocols have also attracted considerable attention.

[0005] In summary, existing quantum sealing bidding and auction methods suffer from problems such as malicious bidding and collusion between bidders and between bidders and auctioneers. Summary of the Invention

[0006] The purpose of this invention is to overcome the shortcomings of the prior art and propose a quantum-sealed post-auction confirmation method for bidders' privacy by utilizing the blind nature of blind signatures.

[0007] This invention provides a method for post-auction confirmation of quantum-sealed bidding based on blind signatures, including an initialization process, a bid preparation process, a bid delivery process, and a verification process: the specific steps of each process are as follows:

[0008] Initialization process:

[0009] Step 1: Set up an auctioneer Alice and t+1 bidders, where Bob... i Let Bob represent the i-th bidder, 1≤i≤t+1; the auctioneer and bidders share a secret key via quantum key distribution, where each bidder Bob... i Shared key K with auctioneer Alice i , i = 1, 2, ..., t+1; t equals the total number of bidders minus 1;

[0010] Step Two: Each bidder, Bob i Prepare t copies of EPR: And each pair of states is and They are The subscripts for the numbers of the first and second particles;

[0011] Step 3: Bob i Retain the second particle and the first particle Transmitted sequentially to the other bidders, Bob j ;

[0012] Bidding preparation process:

[0013] Step 4: After receiving t particles from other bidders, bidder Bob... k Randomly select n particles to form a new set B k Where n is any integer less than t; the remaining tn particles form another group O k ;

[0014] Step 5: Bob k For O k The particles in the middle do not perform any operations and act according to their own bids. Measurement B k Particles in;

[0015] Step Six: Bob k The measurement results are obtained according to step five. And obtain a new sequence

[0016] Bidding and delivery process:

[0017] Step Seven: Bob k Using the shared key K obtained in step one. k Encryption M k and encrypt the obtained Send to the auctioneer;

[0018] Step 8: Bob k The measured particles are returned to the sender along their original paths.

[0019] Step Nine: Auctioneer Deciphers M′ k Where k = 1, ..., t+1, and t+1 bids are received, the winner Bob is announced according to the auction winning rules. * Its decrypted sequence M * ;

[0020] Verification process:

[0021] Step 10: Each bidder, Bob i Choose the appropriate state from the particle sequence you have.

[0022] Step Eleven: Winner Bob * Announce set O * The source of particles in;

[0023] Step Twelve: According to Does it belong to set O? * Bob i According to O * Measure and verify using different measurement standards.

[0024] Furthermore, in step five, Bob k The measurements include the Pauli operator σ. Z σ X The measurement, if Then measure σ Z ,if Then measure σ X ,in, It means Bob k The value of the j-th bit string in the bid; 1≤j≤n.

[0025] Furthermore, step twelve specifically involves:

[0026] if Not belonging to set O * Bob i The observable D has four non-degenerate eigenstates:

[0027]

[0028]

[0029]

[0030]

[0031] Bob i According to M * The matching relationship with the measurement results is verified, and the verification passes if the following rule is met: if the measurement result is |Ψ1> or |Ψ2>, M *′ =00; if the measurement result is |Ψ3> or |Ψ4>, M *′ =01; If the measurement result is |Ψ1> or |Ψ3>, M *′ =10; if the measurement result is |Ψ2> or |Ψ4>, M *′ =11, otherwise, verification fails;

[0032] if Belongs to set O * If the winner did not encode their bid for their particle, then Bob... i Performing a Bell measurement, it has the following four eigenstates:

[0033]

[0034]

[0035]

[0036]

[0037] Bob i Verification is performed based on the measurement results. If the measurement result is |Ψ1>, the verification passes; otherwise, the verification fails.

[0038] Compared with existing technologies, the beneficial effects of this invention are reflected in:

[0039] 1. Adopting a post-confirmation mechanism to resist collusion between auctioneers and bidders, and to prevent collusion between auctioneers and bidders, thereby ensuring the fairness of the auction;

[0040] 2. To ensure the security and confidentiality of bidders' information, blind signature technology is used to protect bidders' privacy;

[0041] 3. Using a binary vector form to implement public verification of the auction ensures the fairness and transparency of the auction process and improves the completeness of the system. Attached Figure Description

[0042] Figure 1 A diagram illustrating the preparation of two EPR pairs for each bidder during the initialization process.

[0043] Figure 2 This is a diagram illustrating how each bidder distributes X particles to other participants during the initialization process.

[0044] Figure 3 A diagram illustrating the process of measuring the received particles for each bidder during the bid preparation and delivery process, and then secretly sending the bid price to the auctioneer.

[0045] Figure 4 This diagram illustrates how each bidder receives their allocated particles and how the auctioneer announces the winning bids during the submission and opening stages. Detailed Implementation

[0046] The design concept of this invention is as follows: taking the commonality between the fairness requirements of the QSA protocol and the blindness of blind signatures as the starting point, a post-confirmation protocol based on blind signatures is proposed for the first time. It creatively adopts a two-state vector form, which provides a suitable tool for implementing the post-confirmation mechanism to ensure the fairness of the QSA protocol and enhances the fairness of the QSA protocol.

[0047] The following is a detailed description of the embodiments.

[0048] This invention is based on a quantum blind signature scheme (SHWL) based on Two State Vector Formalism (TSVF) proposed by Su Qi et al. in 2010, which specifically includes an initialization process, a bid preparation process, a bid delivery process, and a verification process.

[0049] (I) Initialization Process

[0050] After a bidder registers in the auction system, the initialization process begins:

[0051] Step 1: Set up an auctioneer Alice and t+1 bidders, where Bob... i Let Bob represent the i-th bidder, 1 ≤ i ≤ t+1, and the participants in the auction process. First, a secret key is shared through quantum key distribution, where each bidder Bob... i Shared key K with auctioneer Alice i , i = 1, 2, ..., t+1; t equals the total number of bidders minus 1.

[0052] Step Two: Each bidder, Bob i Prepare t pairs of EPR (EPR is a type of Bell state): And each pair of states is They are The subscripts of the first and second particle numbers.

[0053] Step 3: For each EPR state (each EPR state contains two particles), Bob i Retain the second particle and the first particle Transmitted sequentially to the other bidders, Bob j , j = 1, ... t.

[0054] (II) Bidding Preparation Process

[0055] Step 4: After receiving t particles from other bidders, bidder Bob... k Randomly select n particles to form a new set B k (n < t). The remaining tn particles form another group of O. k n represents any n particles that satisfy n < t.

[0056] Step 5: Bob k For O k The particles in the middle do not perform any operations and act according to their own bids m. k = (The bid is represented here in bit string form.) They represent Bob k The value of the first, ..., nth bit string in the bid is measured as B. k The particles in. Specifically, Bob k Perform the following operations:

[0057]

[0058] σ Z σ X Each of these represents a Pauli operator. It means Bob k The value of the j-th bit string in the bid. Measurement σ. Z σ X The reason is that different measurement bases will affect the results in order to conduct subsequent testing and verification.

[0059] Step Six: Bob k The measurement results are obtained according to step five. And obtain a new sequence

[0060] These respectively represent the corresponding steps in step five. The measurement results.

[0061] (II) Bidding and Delivery Process

[0062] Step Seven: Bob k Using the shared key K obtained in step one. k Encrypt the M obtained in step six above. k and encrypt the obtained Send to auctioneer Alice.

[0063] K k Bob k The shared key obtained in step one.

[0064] Step 8: Bob k The measured particles are returned to the sender along their original paths. Therefore, each bidder again holds t pairs of particles |Φ. k >

[0065] Step Nine: Bidding Stage. Auctioneer Deciphers M′ k Where k = 1, ..., t+1, and t+1 bids are received, then the winner Bob is announced. * Its decrypted sequence M * ;

[0066] M * Bob, representing the winner * The sequence can be used by other bidders to verify the results.

[0067] (III) Verification Process

[0068] Step 10: Each bidder, Bobi, selects the corresponding state from the particle sequence he holds.

[0069] Step Eleven: Winner Bob * Announce set O * Where do the particles in the image come from?

[0070] Step Twelve: Bob i According to O * Measurements were performed using different measurement bases:

[0071] if Not belonging to set O * Bob i The observable D has four non-degenerate eigenstates:

[0072]

[0073]

[0074] Bob i According to M * Verify the matching relationship with the measurement results. Verification passes if the following rule is met: if the measurement result is |Ψ1> or |Ψ2>, M *′ =00; If the measurement result is |Ψ3> or |Ψ4>, M *′ =01; If the measurement result is |Ψ1> or |Ψ3>, M *′ =10; if the measurement result is |Ψ2> or |Ψ4>, M *′ =11. Otherwise, verification fails.

[0075] if Belongs to set O * If the winner did not encode their bid for their particle, then Bob... i Performing a Bell measurement, it has the following four eigenstates:

[0076]

[0077]

[0078]

[0079]

[0080] Verification is performed based on the measurement results: if the measurement result is |Ψ1>, then the verification passes. Otherwise, the verification fails.

[0081] To more clearly illustrate the features of the present invention, specific examples are shown in the references. Figure 1-4 As shown in the diagram. In this embodiment, the set formed by the linear combination of the above four eigenstate expressions is called D. The diagram uses three bidders as an example. Alice is the auctioneer, and Bob is the bidder. Figure 1 This shows that each bidder prepares two EPR pairs in the initial stage; Figure 2 This shows that each bidder distributes X particles to other participants in the initial phase; Figure 3 The document describes the particles received by each bidder during the bid preparation and bid delivery phases, as per the agreement, and then secretly sends the bid price to auctioneer Alice. Figure 4 The process describes how each bidder receives their allocated particles and how the auctioneer announces the winning bids during the submission and opening phases.

[0082] A good sealed-bid auction protocol needs to meet not only application requirements but also security requirements. The following detailed analysis of the security aspects of this invention will further illustrate its security features.

[0083] Defend against malicious bidder attacks:

[0084] Suppose there is a bidder Bob v Want to get another bidder Bob k Bob's offer. k Bob, not the winner * Bob v There are three possible strategies, which will be analyzed separately below.

[0085] Case 1: m k The agreement was executed completely and honestly. After joint measurements of D, he was unable to deduce m. k According to Bob v The measurement results are consistent with Bob's. k The corresponding relationship of the bids is explained in step 12 above. Because regardless of the measurement method, m kv There are two possibilities, 0 and 1, and each possibility has a 50% chance. Furthermore, Bob... k Select some of the received particles to randomly encode the bids, so Bob v They didn't even know if his particles were being used.

[0086] Scenario 2: Bob v Use a single particle instead of entangled states. Bob k According to his bid m k Two nonorthogonal bases are used to measure the received particles. Bob v I don't know m k Therefore, it is impossible to determine what the measured state will become. Thus, Bob v Unable to obtain m k .

[0087] Case 3: Bobv uses other entangled states instead. This situation is similar to situation 1.

[0088] Resisting Conspiratorial Attacks:

[0089] There are two types of conspiracy attacks: one is where multiple bidders collude, and the other is Bob. * Conspiring with the auctioneer.

[0090] Scenario 1: Assume u bidders collude to obtain Bob's prize. k The bid. Because the measurement benchmark is unknown, there is no advantage relative to individual cases. Moreover, if Bob... kHe will not declare victory even if he does not win. k Therefore, they do not know that their measurements correspond to m. k The exact location within.

[0091] Scenario 2: Bob * Colluding with the auctioneer. To prevent this attack, a post-confirmation mechanism was used. After the auctioneer announces the winner and the bids, the winner, Bob... * O will be publicly announced * If O * If it's fake, it can be detected using Bell measurements. If m * If it is tampered with, then other bidders can detect it based on their measurements of D. Furthermore, the quantum state used to encode the bid is prepared jointly by all bidders, and throughout the execution of the protocol, |Φ i There is always a particle in Bob's... i In my hands.

Claims

1. A method for post-auction confirmation of quantum-sealed bidding based on blind signatures, characterized in that, The process includes initialization, bid preparation, bid delivery, and verification. The specific steps for each process are as follows: Initialization process: Step 1: Set up an auctioneer and t+1 bidders, where Bob... i Let Bob represent the i-th bidder, 1≤i≤t+1; the auctioneer and bidders share a secret key via quantum key distribution, where each bidder Bob... i Share key K with the auctioneer i , i = 1, 2, ..., t+1; t equals the total number of bidders minus 1; Step Two: Each bidder, Bob i Prepare t copies of EPR: And each pair of states is and They are The subscripts for the numbers of the first and second particles; Step 3: Bob i Retain the second particle and the first particle Transmitted sequentially to the other bidders, Bob j ; Bidding preparation process: Step 4: After receiving t particles from other bidders, bidder Bob... k Randomly select n particles to form a new set B k Where n is any integer less than t; the remaining tn particles form another group O k ; Step 5: Bob k Based on their own bid Measurement B k Particles in; Step Six: Bob k The measurement results are obtained according to step five. And obtain a new sequence Bidding and delivery process: Step Seven: Bob k Using the shared key K obtained in step one. k Encryption M k and the encrypted result Send to the auctioneer; Step 8: Bob k The measured particles are returned to the sender along their original paths. Step Nine: Auctioneer Deciphers M' k Where k = 1, ..., t+1, and t+1 bids are received, then the winner Bob is announced according to the auction winning rules. * Its decrypted sequence M * ; Verification process: Step 10: Each bidder, Bob i Choose the appropriate state from the particle sequence you have. Step Eleven: Winner Bob * Announce set O * The source of particles in; Step Twelve: According to Does it belong to set O? * Bob i According to O * Measure and verify using different measurement standards.

2. The method for post-auction confirmation of quantum-sealed bidding based on blind signatures as described in claim 1, characterized in that, In step five, Bob k The measurements include the Pauli operator σ. Z σ X The measurement, if Then measure σ Z ,if Then measure σ X ,in, It means Bob k The value of the j-th bit string in the bid; 1≤j≤n.

3. The method for post-auction confirmation of quantum sealed bidding based on blind signatures as described in claim 1, characterized in that, Step twelve is as follows: if Belongs to set O * Bob i The observable D has four non-degenerate eigenstates: Bob i According to M * The matching relationship with the measurement results is verified, and the verification passes if the following rule is met: if the measurement result |Ψ1> or |Ψ2>, M *' =00; if the measurement result is |Ψ3> or |Ψ4>, M *' =01; if the measurement result |Ψ1> or |Ψ3>, M *' =10; if the measurement result |Ψ2> or |Ψ4>, M *' =11, otherwise, verification fails; if Belongs to set O * If the winner did not encode their bid for their particle, then Bob... i Performing a Bell measurement, it has the following four eigenstates: Bob i Verification is performed based on the measurement results. If the measurement result is |Ψ1>, the verification passes; otherwise, the verification fails.