Quantum key distribution method, device and quantum key distribution system

By improving the post-processing of quantum key distribution, calculating the data correlation and channel state of multiple receivers, the attenuation problem introduced by the optical splitter in the CV-QKD system is solved, the secure key generation rate is improved, the system design is simplified, and quantum key distribution to more user terminals is supported.

CN117544295BActive Publication Date: 2025-11-07HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210917351.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-01
Publication Date
2025-11-07
Estimated Expiration
2042-08-01

AI Technical Summary

Technical Problem

In passive optical network (PON) scenarios, the CV-QKD system suffers from shortened secure transmission distance due to attenuation introduced by the optical splitter, making it unable to effectively support quantum key distribution for multiple user terminals. Existing technologies struggle to improve the secure key generation rate.

Method used

By improving the post-processing of quantum key distribution, calculating the data correlation between multiple receivers, estimating the channel state and performing error correction, the system design is simplified, the attenuation effect of the optical splitter is reduced, and secure key distribution to more user terminals is supported.

Benefits of technology

It improves the key generation rate of security keys for multiple user terminals in PON scenarios, simplifies the system structure, reduces costs and complexity, and supports quantum key distribution for more user terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117544295B_ABST
    Figure CN117544295B_ABST
Patent Text Reader

Abstract

The application provides a quantum key distribution method, device and system, which can improve the security key generation rate of quantum key distribution of multi-user terminals. The method can be applied to a quantum key distribution system with a 1:n structure. The method comprises: a sending terminal receiving a first data sequence from each of n receiving terminals; for any receiving terminal, the sending terminal calculates the security key generation rate between the sending terminal and the receiving terminal according to the first data sequence and a second data sequence of m receiving terminals, the second data sequence comprising part of the original key of the sending terminal; m is an integer greater than 1 and less than or equal to n; the m receiving terminals are included in the n receiving terminals; and the sending terminal performs a security enhancement operation on the error-corrected key obtained by performing an error correction operation on the sending terminal and the receiving terminal to obtain a first final key shared by the sending terminal and the receiving terminal for the secure transmission of information between the sending terminal and the receiving terminal.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of quantum communication, and particularly relates to a quantum key distribution method and device and a quantum key distribution system. BACKGROUND

[0002] With the development of quantum communication technology, quantum key distribution (QKD) has become the most practical quantum secure communication technology at present. QKD can be divided into discrete variable quantum key distribution (DV-QKD) and continuous variable quantum key distribution (CV-QKD) from the dimension of information coding space. DV-QKD usually realizes key distribution by encoding single-photon signals, and in the optical fiber communication band, it needs to work in a low-temperature single-photon detector. CV-QKD usually realizes key distribution by encoding coherent states (such as weak laser). The homodyne detector used by CV-QKD does not need low-temperature control, so CV-QKD is more practical.

[0003] For example, the CV-QKD system has the advantage of a higher secret key rate in a short-distance scenario, and in particular in a short-distance scenario, the system architecture of CV-QKD is very similar to coherent communication, and can greatly reuse the existing communication industry chain. In a short-distance scenario, the most commonly used networking mode of CV-QKD is passive optical network (PON), in which the intermediate node is very simple and only needs an optical splitter (or called beam splitter) without power supply.

[0004] However, in the PON scenario, the optical splitter introduces a large attenuation to a certain user terminal (or terminal). For CV-QKD, it directly reduces the secure transmission distance. The more the number of user terminals, the greater the attenuation introduced by the optical splitter, and the greater the reduction of the secure transmission distance. When the number of user terminals is large enough, even the back-to-back system cannot effectively code. For example, for a CV-QKD system with a maximum secure transmission distance of about 100 kilometers (km), the tolerable equivalent fiber loss is about 20 dB. When the number of user terminals exceeds 100, such as in the case of a 1-to-128 system supporting 128 user terminals, the equivalent transmission distance caused by the splitting loss is greater than the maximum secure transmission distance of the system. At this time, even if the user terminal and the sending end are back-to-back together, the CV-QKD system cannot effectively help the user terminal and the sending end to establish a secure quantum key. Therefore, how to realize quantum key distribution for multiple user terminals in the PON scenario has become a problem to be solved. SUMMARY

[0005] Embodiments of the present application provide a quantum key distribution method, device and system, which can improve the secure key coding rate of quantum key distribution for multiple user terminals in the PON scenario.

[0006] To achieve the above object, the present application adopts the following technical solutions:

[0007] In a first aspect, a quantum key distribution method is provided. The quantum key distribution method is applied to the i-th quantum key distribution of a quantum key distribution system, i is an integer greater than or equal to 1; the quantum key distribution system includes one sending end and n receiving ends, N is an integer greater than 1; the method includes: the sending end receives a first data sequence from each of the n receiving ends; the first data sequence includes part of the original key of the receiving end, the original key of the receiving end being obtained according to the detection data obtained by the receiving end from a probe optical signal, the probe optical signal being obtained by splitting a modulated optical signal by a splitting device, the modulated optical signal being obtained by modulating a first optical signal by the sending end according to a quantum random number; for any receiving end, the sending end calculates a secure key coding rate between the sending end and the receiving end according to the first data sequence and a second data sequence of m receiving ends, wherein the second data sequence includes part of the original key of the sending end; m is an integer greater than 1 and less than or equal to n; the m receiving ends are included in the n receiving ends; the sending end performs a security enhancement operation on an error-corrected key obtained by performing an error correction operation on the sending end and the receiving end to obtain a first final key shared by the sending end and the receiving end; the first final key is used for secure transmission of information between the sending end and the receiving end.

[0008] In the method of the first aspect, in the quantum key distribution system with 1:n structure, in the post-processing of the quantum key distribution, when calculating the secure key rate between the certain receiver and the sender, the other n-1 receivers are not regarded as completely untrusted, but the plurality of receivers (e.g., m receivers including the certain receiver) are regarded as trusted receivers. The plurality of receivers cannot work together with other untrusted users (or eavesdroppers) in the quantum channel to obtain (or eavesdrop) the quantum key information included in the quantum optical signal transmitted in the quantum channel, and cannot work together to obtain the quantum key information included in the quantum optical signal. The data correlation between the receiver and the sender is determined based on the data disclosed by the m receivers to the sender and part of the original key of the sender. The secure key rate between the receiver and the sender is determined according to the determined data correlation. The final key is obtained by performing a security enhancement operation on the error-corrected key shared by the receiver and the sender according to the determined secure key rate. By estimating the data correlation between the certain receiver and the sender from the plurality of receivers, the upper bound of the information that can be obtained by the untrusted users in the channel is more compactly evaluated, so that the influence of the attenuation caused by the beam splitting device is greatly reduced, thereby enabling the quantum key distribution system to support more users.

[0009] In a possible design, the calculation of the secure key rate between the sender and the m receivers based on the first data sequence and the second data sequence of the m receivers includes: calculation of the data correlation between the sender and the m receivers for representing the channel state of the quantum channel of the quantum key distribution system based on the first data sequence and the second data sequence of the m receivers; and calculation of the secure key rate based on the data correlation.

[0010] In the method of the first aspect, in the quantum key distribution system with 1:n structure, in the post-processing of the quantum key distribution, when calculating the secure key rate between the certain receiver and the sender, the other n-1 receivers are not regarded as completely untrusted, but the plurality of receivers (e.g., m receivers including the certain receiver) are regarded as trusted receivers. The plurality of receivers cannot work together with other untrusted users (or eavesdroppers) in the quantum channel to obtain (or eavesdrop) the quantum key information included in the quantum optical signal transmitted in the quantum channel, and cannot work together to obtain the quantum key information included in the quantum optical signal. The data correlation between the receiver and the sender is determined based on the data disclosed by the m receivers to the sender and part of the original key of the sender. The secure key rate between the receiver and the sender is determined according to the determined data correlation. The final key is obtained by performing a security enhancement operation on the error-corrected key shared by the receiver and the sender according to the determined secure key rate. By estimating the data correlation between the certain receiver and the sender from the plurality of receivers, the upper bound of the information that can be obtained by the untrusted users in the channel is more compactly evaluated, so that the influence of the attenuation caused by the beam splitting device is greatly reduced, thereby enabling the quantum key distribution system to support more users.

[0011] That is, the parameter estimation is performed by estimating the data correlation between the sending end and the m receiving ends through the covariance matrix or the characteristic parameter, and the security key generation rate is determined according to the estimated data correlation, so that the security key generation rate is effectively and flexibly calculated and determined, and the system design is simplified.

[0012] In a possible design, the method further includes: performing the following error correction operation between the sending end and the receiving end to obtain the error-corrected key: the sending end receives check information from the receiving end; the check information is obtained by encrypting a second final key, and the second final key is a final key obtained by performing the i-1th quantum key distribution between the sending end and the receiving end in the case that i is greater than 1; the check information includes a syndrome, and the syndrome is calculated by the receiving end according to a third data sequence, and the third data sequence includes remaining data in the original key of the receiving end except the first data sequence; the sending end decrypts the check information according to the second final key to obtain the syndrome; and the sending end performs error correction decoding on a fourth data sequence according to the syndrome to obtain the error-corrected key, where the fourth data sequence includes remaining data in the original key of the sending end except the second data sequence.

[0013] That is, in the data error correction step in the post-processing of the quantum key distribution, the n receiving ends can also achieve the simultaneous key generation of multiple receiving ends by transmitting the syndrome through encryption, which not only ensures that all receiving ends extract the security key at the same time, reduces the use of the time division multiplexing module, and makes the system structure simpler, which is conducive to reducing the system cost and complexity, facilitating the deployment and maintenance of the system. Moreover, the receiving end only needs to send the syndrome to the sending end, and does not need to perform error correction calculation, so that the deployment of the device for error correction with high computing power is performed at the node end, and the computing power distribution is more reasonable.

[0014] In a possible design, in the error correction coding and decoding process between the sending end and the n receiving ends, the n receiving ends are divided into multiple groups, and the channel quality difference of the channels corresponding to different receiving ends in the same group is less than a preset threshold; for different receiving ends in the same group, the error correction coding and decoding scheme between the sending end and different receiving ends in the same group is the same, and the error correction coding and decoding scheme corresponds to a first signal-to-noise ratio, and the first signal-to-noise ratio is the signal-to-noise ratio of the receiving end with the lower signal-to-noise ratio in the group.

[0015] Based on the possible design, according to the signal-to-noise ratio of the channels of the multiple receiving ends, the channels of the multiple receiving ends can be grouped, the channels with similar performance are grouped, the error correction decoding step in the data coordination between the receiving end and the sending end is performed using the error correction coding and decoding scheme corresponding to the poor signal-to-noise ratio, that is, the error correction coding and decoding scheme is designed in groups, and only one or a few groups of error correction coding and decoding schemes can solve the error correction decoding problem in the quantum key distribution process, thereby simplifying the design complexity of the error correction coding and decoding scheme. At the same time, based on the poor signal-to-noise ratio, the other signals in the group are added with trusted noise, the signal-to-noise ratios of all channels in the group are adjusted to be consistent, and by sacrificing a certain code rate performance, the sending end can use a less bit error correction code to complete the error correction coding and decoding of the data, thereby simplifying the design complexity of the error correction coding and decoding scheme and reducing the system cost.

[0016] In a possible design, the light splitting device includes a light splitter and / or a wavelength division multiplexer. The 1:n light splitting is flexibly and effectively implemented through the light splitter and / or the wavelength division multiplexer.

[0017] In a possible design, the quantum key distribution system adds an (n+1)th receiving end, and the method further includes: the sending end sends a reference frame including a synchronization frame, so as to realize data synchronization between the (n+1)th receiving end and the sending end through the synchronization frame.

[0018] In a possible design, in the case that the quantum key distribution system adds an (n+1)th receiving end, the method further includes: the sending end receives side information sent by the (n+1)th receiving end through a classical channel, the side information being used to calculate a final key between the sending end and the (n+1)th receiving end, and the sending end adjusts quantum key distribution timing and / or quantum key distribution resources of n+1 terminals including the (n+1)th receiving end in the quantum key distribution system according to a processing complexity of the side information and a time when the side information arrives at the sending end. In this way, the registration of the new user can be implemented.

[0019] In a possible design, the pre-shared key of the (n+1)th receiving end is a length-L key configured to the (n+1)th terminal when the (n+1)th terminal is manufactured, L is an integer greater than 1; the pre-shared key of the (n+1)th receiving end is a length-L key artificially generated when the (n+1)th terminal is connected to a network; or the pre-shared key of the (n+1)th receiving end is a key obtained after multiple quantum key distributions are performed between the (n+1)th terminal and the sending end, and the length of the pre-shared key of the (n+1)th receiving end is greater than a key length L required by the encryption syndrome.

[0020] In a possible design, the pre-shared key of the n+1th receiving end is a key obtained after multiple quantum key distributions between the n+1th terminal and the sending end, including: determining a final key obtained by performing the following process multiple times as the pre-shared key of the n+1th receiving end: the sending end calculates a secure key rate between the sending end and the n+1th terminal according to part of the original key of the n+1th receiving end and part of the original key of the sending end, performs a security enhancement operation on a post-error correction key obtained by performing an error correction operation on the sending end and the n+1th terminal according to the secure key rate, and obtains a final key shared by the sending end and the n+1th terminal.

[0021] That is, the quantum key distribution method described in the embodiments of the present application and the multiple quantum key distributions between the new user and the sending end are performed until the length of the final key shared between the new user and the sending end meets the key length L required by the encryption check subcode, and the final key obtained by performing the final quantum key distribution is taken as the pre-shared key of the n+1th receiving end.

[0022] In a possible design, in the case that the nth receiving end in the quantum key distribution system is offline, the method further includes: the receiving end obtaining offline time of the nth receiving end, which indicates that the nth receiving end is offline after the kth quantum key distribution, and the receiving end adjusting quantum key distribution timing and / or quantum key distribution resources of the quantum key distribution system after the nth receiving end is offline according to the offline time of the nth receiving end; and performing quantum key distribution between the receiving end and the n+1th receiving end using the adjusted quantum key distribution timing and / or quantum key distribution resources after the kth quantum key distribution is performed. k is an integer greater than 1.

[0023] That is, the quantum key distribution timing and / or quantum key distribution resources of the quantum key distribution system after the nth receiving end is offline are adaptively adjusted based on the offline time of the receiving end, and the quantum key distribution between the receiving end and the n+1th receiving end is performed using the adjusted quantum key distribution timing and / or quantum key distribution resources after the kth quantum key distribution is performed on the offline user, so as to avoid affecting the quantum key distribution of the online user, and meanwhile, improve the utilization rate of the quantum key distribution resources.

[0024] In a second aspect, the present application provides a quantum key distribution device, which can be a sending end or a chip or a system on chip in the sending end, and can also be a functional module in the sending end for implementing the method in the first aspect or any possible design of the first aspect. The quantum key distribution device can implement the functions performed by the sending end in the above aspects or any possible design, and the functions can be implemented by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions. For example, the quantum key distribution device can include a sending unit and a processing unit.

[0025] a receiving unit, configured to receive a first data sequence from each of the n receiving ends; the first data sequence comprises part of data in an original key of the receiving end, the original key of the receiving end being obtained according to probe data obtained by the receiving end from a probe sub-optical signal, the sub-optical signal being obtained by splitting a modulated optical signal by a splitting device, the modulated optical signal being obtained by modulating a first optical signal by the sending end according to the quantum random number.

[0026] a processing unit, configured to, for any receiving end, calculate a secure key generation rate between the sending end and the receiving end according to the first data sequence and a second data sequence of m receiving ends, wherein the second data sequence comprises part of data in an original key of the sending end; m is an integer greater than 1 and less than or equal to n; the m receiving ends are included in the n receiving ends.

[0027] the processing unit is further configured to perform a security enhancement operation on a post-error correction key obtained by performing an error correction operation on the sending end and the receiving end to obtain a first final key shared by the sending end and the receiving end; the first final key is used for secure transmission of information between the sending end and the receiving end.

[0028] Specifically, the execution actions of each unit of the quantum key distribution device can refer to the first aspect or any possible design of the first aspect, and will not be described here.

[0029] In a third aspect, a quantum key distribution device is provided, which can be a chip or a system on chip in a sending end. The quantum key distribution device can implement the functions performed by the sending end in the above aspects or possible designs, which can be implemented by hardware. The quantum key distribution device can implement the functions performed by the network device in the above aspects or possible designs, which can be implemented by hardware. In a possible design, the quantum key distribution device can include a processor and a transceiver, and the processor and the transceiver can support the quantum key distribution device to perform the method described in the above first aspect or any possible design of the first aspect.

[0030] In another possible design, the quantum key distribution device can further include a memory, configured to store computer-executable instructions and data necessary for the quantum key distribution device. When the quantum key distribution device is running, the processor executes the computer-executable instructions stored in the memory, so that the quantum key distribution device performs the quantum key distribution method as described in the above first aspect or any possible design of the first aspect.

[0031] In a fourth aspect, a computer readable storage medium is provided, which can be a readable nonvolatile storage medium, and the computer readable storage medium has stored therein instructions which, when executed on a computer, cause the computer to perform the quantum key distribution method according to the first aspect or any possible design of the first aspect.

[0032] In a fifth aspect, a computer program product is provided, which contains instructions, and the instructions, when executed on a computer, cause the computer to perform the quantum key distribution method according to the first aspect or any possible design of the first aspect.

[0033] In a sixth aspect, a quantum key distribution apparatus is provided, which can be a sender or a chip or a system on chip in the sender, and the quantum key distribution apparatus includes one or more processors and one or more memories. The one or more memories are coupled to the one or more processors, and the one or more memories are configured to store computer program codes, and the computer program codes include computer instructions, and when the one or more processors execute the computer instructions, the sender performs the method according to the first aspect or any possible design of the first aspect.

[0034] The technical effects brought by any design of the second aspect to the sixth aspect can refer to the technical effects brought by the first aspect or any possible design of the first aspect, which will not be repeated here.

[0035] In a seventh aspect, an embodiment of the present application provides a quantum key distribution system, which can include a sender and n receivers, and n is an integer greater than 1. The sender can perform the quantum key distribution method according to the first aspect or any possible design of the first aspect. BRIEF DESCRIPTION OF DRAWINGS

[0036] Figure 1 It is a schematic diagram of a DV-QKD system architecture;

[0037] Figure 2a It is a schematic diagram of a single-channel CV-QKD system architecture Figure 1 ;

[0038] Figure 2b It is a schematic diagram of a single-channel CV-QKD system architecture two;

[0039] Figure 3 It is a schematic diagram of a multi-channel CV-QKD system architecture;

[0040] Figure 4 It is a schematic diagram of a quantum key distribution system architecture based on WDM-PON Figure 1 ;

[0041] Figure 5 A schematic diagram of a quantum key distribution system with 1:n structure provided by an embodiment of the present application Figure 1

[0042] Figure 6a A schematic diagram of a quantum key distribution system with 1:n structure provided by an embodiment of the present application

[0043] Figure 6b A schematic diagram of a quantum key distribution system with 1:n structure provided by an embodiment of the present application Figure 3

[0044] Figure 6c A schematic diagram of a quantum key distribution system with 1:n structure provided by an embodiment of the present application Figure 4

[0045] Figure 6d A schematic diagram of a quantum key distribution system with 1:n structure provided by an embodiment of the present application Figure 5

[0046] Figure 7 A schematic diagram of a quantum key distribution method provided by an embodiment of the present application

[0047] Figure 8 A schematic diagram of a post-processing process in quantum key distribution provided by an embodiment of the present application Figure 1

[0048] Figure 9 A schematic diagram of a post-processing process in quantum key distribution provided by an embodiment of the present application

[0049] Figure 10 A schematic diagram of a quantum key distribution device 100 provided by an embodiment of the present application

[0050] Figure 11 A schematic diagram of a quantum key distribution device 110 provided by an embodiment of the present application

[0051] Figure 12 A schematic diagram of a quantum key distribution system provided by an embodiment of the present application DETAILED DESCRIPTION

[0052] Before describing the embodiments of the present application, some technical terms related to the embodiments of the present application are explained and described:

[0053] ​​​​​Quantum Key Distribution (QKD), the most practical quantum secure communication technology at present, is a communication technology developed on the basis of classical information theory and quantum mechanics, and its function is to achieve unconditional secure distribution of symmetric key on the premise of sharing part of the secure key (or called quantum key). For a one-way QKD system, its implementation is usually through modulating the quantum state of the light signal generated by the light source (such as a laser) according to the quantum random number (or called random key or initial key) at the sending end (or called sending end), transmitting the modulated light signal (which can be called the original key of the sending end) to the receiving end (or called receiving end) through the quantum channel, detecting the signal sent by the sending end to obtain a set of keys (which can be called the original key of the receiving end) at the receiving end, and then the sending end and the receiving end perform post-processing on their respective original keys through the classical channel. The post-processing includes a series of post-processing processes such as measurement basis comparison, data sifting, parameter estimation (PE), data error correction (EC), privacy amplification (PA), etc., so that the sending end and the receiving end finally share a set of secure random keys. The final random key shared by the sending end and the receiving end can be called final key.

[0054] Among them, QKD can be divided into discrete variable quantum key distribution (DV-QKD) and continuous variable quantum key distribution (CV-QKD) in terms of the dimension of information encoding space. These two ways can use different information encoding methods, and according to the difference of specific information encoding method, they can be further divided into different protocols. The following introduces these two ways:

[0055] (1) DV-QKD

[0056] DV-QKD is the earliest QKD method used in PON scenarios. DV-QKD usually realizes quantum key distribution by encoding single photon signals. In the optical communication band, DV-QKD needs to work at a low-temperature single photon detector. Referring to Figure 1 , FIG. 1 is a schematic diagram of DV-QKD, as shown in Figure 1 , DV-QKD has a downlink mode shown in Figure 1 (a) and an uplink mode shown in Figure 1 (b).

[0057] like Figure 1 As shown in (a), in downlink mode, network nodes act as transmitters and user terminals as receivers. A QKD transmitter (or simply transmitting device) is deployed in the network nodes on the network side, and a QKD receiver (or simply receiving device) is deployed on each user terminal side. This QKD receiver can be a single-photon detector. Since DV-QKD transmits quasi-single-photon signals (or single-photon signals), the probability of multiple user terminals (or terminals) simultaneously responding to a single quantum light pulse emitted by the QKD transmitter is very low. Therefore, in downlink mode, one QKD receiver is deployed in each user terminal. The QKD transmitter uses time-division multiplexing to transmit quantum light pulses to multiple user terminals at different times. This prevents overlap when the quantum light pulses arrive at multiple user terminals, allowing them to be distinguished and received by the user terminal's QKD receiver.

[0058] like Figure 1 As shown in (b), in uplink mode, the user terminal acts as the transmitter and the network node acts as the receiver. The QKD transmitters in multiple user terminals transmit quantum optical pulses to the network side using time-division multiplexing. On the network side, a QKD receiver is deployed in the network node to receive and process the quantum optical pulses from multiple user terminals.

[0059] Depend on Figure 1 It is known that in the downlink mode of DV-QKD, each user terminal requires a QKD receiver, such as a single-photon detector. However, single-photon detectors require special environments such as low temperatures, resulting in high costs. Therefore, deploying a single-photon detector for each user leads to a high overall cost for DV-QKD. In the uplink mode of DV-QKD, although the network side only requires one QKD receiver, resulting in lower costs, multiple user terminals need to use time-division multiplexing to send quantum light pulses to the network node. In a scenario with n user terminals, where n is an integer greater than 1, a 1:n combiner is needed to combine the quantum light pulses emitted by a particular user terminal with those emitted by other user terminals before sending them to the network node. However, the combiner has transmission losses; the more user terminals there are and the larger n becomes, the greater the loss of the 1*n combiner, leading to a decrease in the secure transmission distance and lower transmission efficiency. Therefore, the total number of user terminals supported by the uplink mode of DV-QKD is relatively small.

[0060] (2)CV-QKD

[0061] CV-QKD is usually implemented by encoding the quantum state of coherent state (such as weak laser) to achieve quantum key distribution, and the homodyne detector used by CV-QKD does not need to be controlled at low temperature, compared with DV-QKD, CV-QKD is more practical, and the structure and device characteristics of CV-QKD itself also make it have good compatibility with the current wavelength division multiplexing network. The single channel CV-QKD system and the multi-channel CV-QKD system are introduced below:

[0062] Reference Figure 2a , the single channel CV-QKD system architecture schematic diagram is shown in Figure 2a , the sending end uses quantum random number to modulate the quantum state of the optical signal generated by the laser, such as dual polarization quadrature phase shift keying (DPQPSK), and sends the modulated optical signal (or called modulated optical signal) to the beam splitter (BS), and the BS processes and sends it to the attenuator (ATT), and the ATT sends the modulated optical signal to the receiving end through the quantum channel, and the polarization beam splitter (PBS) of the receiving end receives the modulated optical signal, and uses the same base (BS) as the sending end to detect the received modulated optical signal to obtain the initial key of the receiving end, and then the sending end and the receiving end perform data comparison, screening and negotiation on the initial key through the classical channel, and finally the sending end and the receiving end share a set of secure random key.

[0063] The single channel CV-QKD system can be abstracted to get a more general system principle diagram, as shown in Figure 2b , it can be seen from the principle diagram that in a general single channel CV-QKD system, the transmission of optical signal is unidirectional, from the sending end to the receiving end. The sending end mainly includes three modules of light source, modulation and post-processing; the receiving end mainly includes four modules of demodulation, detection, sampling and post-processing. Among them, the two post-processing programs of the sending end and the receiving end need to communicate bidirectionally through the classical channel to complete each post-processing step. Among them, the initial data obtained by the receiving end through some data processing of the balanced receiver output electrical signal is usually called raw key. The raw key still needs to be further processed to get the final secure key. These post-processing steps are as described above, which usually include: measurement base comparison and data screening, parameter estimation, data error correction, security enhancement.

[0064] Reference Figure 3 , the multi-channel CV-QKD system architecture schematic diagram is shown in Figure 3As shown, the sending end (such as a network node) modulates the quantum state of the modulated optical signal (or optical signal) generated by the laser using quantum random numbers, and divides the modulated optical signal B0 into multiple sub-optical signals corresponding to multiple user terminals through a beam splitter, such as Figure 3 B1, B2, … B n , and sends to multiple receiving ends (such as user terminals), each user terminal detects the initial key obtained by detecting the received sub-optical signal, and then the sending end and the receiving end interact through a classical channel, and perform measurement basis comparison, data screening, parameter estimation, data error correction, security enhancement and other post-processing processes, so that the sending end and the receiving end finally share a set of secure random keys.

[0065] When examining the CV-QKD system, two aspects are mainly examined, one is whether the CV-QKD system has a complete security proof, and the other is the performance of the CV-QKD system, mainly the secret key rate under a certain transmission distance. Since QKD cannot be enhanced by ordinary optical amplification, the "signal-to-noise ratio" of the modulated optical signal in the QKD system is decreasing with the increase of the transmission distance. In other words, the secret key rate of QKD is decreasing with the increase of the transmission distance. When the transmission distance is long enough, the secret key rate will be less than the minimum safe key rate threshold (such as 0), that is, when the transmission distance exceeds the transmission distance, the QKD system will not be able to establish a secure quantum key between the sending and receiving ends. The transmission distance at which the secret key rate drops to the minimum safe key rate threshold (such as 0) is usually called the maximum safe transmission distance. Under certain scenarios and requirements, how to reasonably construct the CV-QKD system and protocol to meet both security and sufficient performance is the focus of the research on the CV-QKD system and protocol.

[0066] For example, the CV-QKD system has the advantage of high secure key generation rate at a short distance, especially at a short distance, because it is very similar to coherent communication in system architecture, and can greatly reuse the existing industrial chain in the field of communication. Therefore, in the scenarios of short distance or access such as city area, park area, building, etc., CV-QKD has the potential advantages of high integration and low cost. In such short distance scenarios, the most commonly used networking method is PON, in which the intermediate node is very simple and only needs an optical splitter without power supply. In order to meet the security, in the PON scenario, in the parameter estimation and security analysis method in the existing scheme, when analyzing the secure key generation rate between a certain receiving end and a sending end, it is assumed that other receiving ends are untrusted and are likely to cooperate with untrusted users in the quantum channel. This assumption amplifies the ability of untrusted users, such as untrusted users including other untrusted users in the quantum channel and other receiving ends on the receiving end side except the receiving end, and the secure key generation rate obtained by the untrusted users is the lower bound of the real situation and is secure. It should be noted that the untrusted user described in the present application can refer to a user who obtains quantum key information of other users (or user terminals) for non-benevolent purposes (or referred to as malicious purposes).

[0067] However, under the above analysis assumption, the optical splitter introduces a great attenuation to a certain terminal user, which directly reduces the secure transmission distance. For example, the core of PON is an optical splitter, which divides the input optical signal into n parts. Without loss of generality, it is assumed that the optical splitter divides the signal equally, and the signal power output by the optical splitter is 1 / n of the input signal. When the number of user terminals in the quantum key distribution system increases from n to q, more optical splitters are needed, and the signal power output by the optical splitter becomes 1 / q of the input signal. Obviously, 1 / q < 1 / n, that is, the increase in the number of user terminals directly leads to an increase in the signal power attenuation introduced by the optical splitter, affects the secure key generation rate, reduces the secure transmission distance between the sending end and the receiving end, and reduces the performance of CV-QKD. For practical applications, the distance of each site is usually determined, which limits the maximum number of user terminals that the quantum key distribution system can support.

[0068] As shown above, in the parameter estimation and security analysis methods of existing schemes, the signal attenuation of the optical splitter is related to the number of user terminals, while the signal power received at the receiver is related to the combined effect of the number of user terminals and the transmission distance of the quantum channel. Therefore, the more user terminals there are, the greater the attenuation introduced by the optical splitter, and the less loss is allowed to be introduced by the quantum channel, i.e., the shorter the quantum channel length and the shorter the secure transmission distance. The more user terminals there are, the greater the attenuation introduced by the optical splitter, and the greater the reduction in the secure transmission distance. When the number of user terminals reaches a certain level, even a back-to-back system cannot effectively code. For example, for a system with a maximum secure transmission distance of about 100km, its tolerable equivalent fiber loss is about 20dB. When the number of user terminals exceeds 100, such as the 128 user terminals supported by a 1:128 quantum key distribution system, the transmission distance equivalent to the splitting loss of the optical splitter is already greater than the maximum secure transmission distance of the system. At this time, even if the user terminals and the transmitter are back to back, the CV-QKD system cannot effectively help users and the local station establish a secure quantum key.

[0069] To improve the performance of CV-QKD systems in multi-user scenarios, such as Figure 4 As shown, related technologies implement CV-QKD based on wavelength division multiplexing passive optical network (WDM-PON) structures. This involves the transmitter using multiple quantum random numbers to modulate multiple optical signals of different wavelengths, resulting in multiple modulated optical signals of different wavelengths, which are then emitted. In WDM-PON scenarios, beam splitters are not used; instead, wavelength division multiplexers separate or combine the modulated optical signals of different wavelengths to multiple receivers (e.g., user terminals). Although the loss introduced by WDM beam splitting does not change with the increase in the number of user terminals, which is a significant advantage of WDM-PON, in actual devices, due to limitations in manufacturing processes, the loss does increase with the increase in the number of receivers, although not as significantly as with beam splitters. Furthermore, Figure 4 The WDM-PON shown has the following problems: (1) The transmitter design is relatively complex. For example, in order to detect or transmit modulated optical signals of multiple wavelengths, the transmitter uses a tunable laser and uses time division multiplexing to detect or transmit modulated optical signals of multiple wavelengths. However, time division multiplexing will reduce the transmission efficiency of modulated optical signals of multiple wavelengths. Alternatively, the transmitter uses multiple sets of equipment (such as laser + modulation equipment) in parallel to detect or receive modulated optical signals of multiple wavelengths, which is costly. (2) The transmitter and receiver need to match wavelengths, which will increase the difficulty of network planning or configuration.

[0070] As can be seen from the above, in Figure 3In the illustrated multi-user scenario, although it is assumed that other receiving ends are untrusted when determining the secure key generation rate between a certain receiving end and a sending end, the untrusted users in the quantum channel can cooperate to ensure that the obtained secure key generation rate is the lower bound of the actual situation and is the safest, but the splitting loss of the optical splitter greatly limits the number of user terminals that can be accessed in the quantum key distribution system. In Figure 4 In the illustrated multi-user scenario based on WDM-PON, although the WDM method is used instead of the splitting method of the optical splitter to avoid the splitting loss caused by the optical splitter, the internal deployment of the sending end is complex, and the network planning or configuration difficulty is increased. To solve the above technical problems, the embodiments of the present application provide a quantum key distribution method, which mainly involves improving the post-processing process of the transceiver. The method can be applied to a 1:n quantum key distribution system, where n is the number of receiving ends. Specifically, the method provided by the embodiments of the present application can include:

[0071] After the sending end splits the modulated optical signal into n sub-optical signals through the splitting device and sends them to the n receiving ends, each receiving end in the n receiving ends detects the received sub-optical signal and sends part of the data (which can be referred to as a first data sequence) in the original key obtained by detection to the sending end. For any receiving end, the sending end calculates the secure key generation rate between the receiving end and the sending end according to the first data sequence sent by the m receiving ends and part of the data (which can be referred to as a second data sequence) in the original key of the sending end itself, and then performs a security enhancement operation on the error-corrected key obtained by performing an error correction operation on the sending end and the receiving end to obtain the final key shared by the sending end and the receiving end. Wherein m is an integer greater than 1 and less than or equal to n.

[0072] Thus, when determining the security key rate between a certain receiving end and a sending end, all or part of the other receiving ends except the receiving end are also regarded as trusted, and taking m=n as an example, each receiving end does not cooperate with the non-trusted user in the quantum channel to obtain the quantum key information included in the quantum optical signal transmitted on the quantum channel, and neither do any two receiving ends. Because the other multiple receiving ends will simultaneously participate in the process of generating the quantum key of a certain receiving end, the energy of the sub-optical signal received by the other multiple receiving ends and the receiving end will not be considered to be mastered by the non-trusted user, which to some extent alleviates the attenuation caused by the increase in the number of user terminals and alleviates the problem of the decrease in the maximum safe transmission distance caused by the increase in the number of user terminals. At this time, the upper bound of the information that the non-trusted user in the quantum channel can obtain will have a more compact evaluation result, in other words, the influence of the splitting loss (or attenuation) brought by the optical splitter will be greatly reduced, so that the quantum key distribution system can support more receiving ends (such as user terminals).

[0073] The technical solutions in the present application will be described below with reference to the accompanying drawings.

[0074] The technical solutions of the embodiments of the present application can be applied to scenarios of near-distance access such as metropolitan areas, parks, and buildings, for implementing quantum key distribution from one sending end to n receiving ends, and enabling multiple receiving ends to have simultaneous key generation capability. For the convenience of understanding the embodiments of the present application, a system architecture shown in FIG. 1 is taken as an example to describe the quantum key distribution system applicable to the embodiments of the present application. Figure 5 It should be noted that the network architecture and business scenarios described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that, with the evolution of network architecture and the appearance of new business scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.

[0075] Exemplarily, Figure 5 A quantum key distribution system architecture provided by the embodiments of the present application is shown in FIG. 1. As shown in FIG. 1, the quantum key distribution system includes a sending end 100 and n receiving ends 101-101n. Figure 5As shown, the quantum key distribution system can be a 1:n structure quantum key distribution system, which can include one sending end, n receiving ends (such as receiving end B1 to receiving end Bn), a light splitting device, multiple noisy quantum channels (or simply referred to as quantum channels) that can exist non-trustworthy users, and n classical channels. The sending end can be referred to as a continuous variable quantum key distribution sending end (or referred to as a CV-QKD sending end), and the receiving end can be referred to as a continuous variable quantum key distribution receiving end (or referred to as a CV-QKD receiving end). The parts of the quantum key distribution system are introduced as follows:

[0076] The sending end is configured to load key information through coherent state modulation, and then split the modulated optical signal into n paths through the light splitting device and send it to the n receiving ends. The sending end is a device with wireless transceiving function located at the network side of the quantum key distribution system or a chip or chip system that can be arranged in the device. The sending end can be a network node, including but not limited to: an access point (AP) in a wireless fidelity (WiFi) system, such as a home gateway, a router, a server, a switch, a bridge, an evolved Node B (eNB), a radio network controller (RNC), a Node B (NB), a base station controller (BSC), a base transceiver station (BTS), a home base station (for example, a home evolved Node B, or a home Node B, HNB), a baseband unit (BBU), a wireless relay node, a wireless backhaul node, a transmission and reception point (TRP or transmission point, TP), etc., and can also be a fifth generation (5G) network node, such as a gNB in a new radio (NR) system, or a transmission point (TRP or TP), one or a group of antenna panels (including multiple antenna panels) of a base station in a 5G system, or a network node constituting a gNB or a transmission point, such as a baseband unit (BBU), or a distributed unit (DU), a road side unit (RSU) with base station function, etc. th

[0077] ​The receiving end is configured to measure the key information sent by the sending end in a coherent detection manner, and to simultaneously extract the secure key by encrypting and transmitting the syndrome required for post-processing error correction. Specifically, the receiving end can be a user terminal (or terminal) with wireless transceiving function or a chip or chip system that can be arranged in the terminal. The terminal can also be referred to as an access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device. The terminal in the embodiment of the application can be a mobile phone, a tablet computer (Pad), a computer with wireless transceiving function, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, a vehicle-mounted terminal, an RSU with terminal function, etc. The terminal in the application can also be a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip or a vehicle-mounted unit built into a vehicle as one or more components or units. The vehicle implements the quantum key distribution provided in the application by the built-in vehicle-mounted module, vehicle-mounted component, vehicle-mounted chip or vehicle-mounted unit.

[0078] The light splitting device is configured to receive the modulated signal from the sending end through a quantum channel, split the received modulated optical signal into n sub-optical signals, one sub-optical signal corresponding to one receiving end, and send the sub-optical signals to the n receiving ends through n quantum channels. That is, the light splitting device has a 1-to-n function. Figure 5 The specific design form of the light splitting device shown in the figure can be a one-stage light splitting mode based on a light splitter as shown in Figure 6a The specific design form of the light splitting device shown in the figure can be a one-stage light splitting mode based on a light splitter as shown in Figure 6b The specific design form of the light splitting device shown in the figure can be a one-stage light splitting mode based on a light splitter as shown in Figure 6c The specific design form of the light splitting device shown in the figure can be a one-stage light splitting mode based on a light splitter as shown in Figure 6d The specific design form of the light splitting device shown in the figure can be a one-stage light splitting mode based on a light splitter as shown in

[0079] Referring to Figure 6a Fig. 2 is a schematic diagram of a quantum key distribution system architecture provided in an embodiment of the application.Figure 6a As shown, the beam splitting device in this quantum key distribution system includes a first-stage beam splitter group. This first-stage beam splitter group can include one or more beam splitters (or beam splitters) deployed in parallel, and can have the capability of splitting 1 beam into n beams. For example, suppose the first-stage beam splitter group includes one beam splitter, which has the capability of splitting 1 beam into n beams. Or suppose the first-stage beam splitter group includes k beam splitters, where k is an integer greater than 1, then the total number of beams split by the k beam splitters is equal to or greater than n.

[0080] For example, suppose n = 128, Figure 6a The beam splitting device includes two beam splitters deployed in parallel. The first beam splitter can split 1 beam into 64 beams, and the second beam splitter can also split 1 beam into 64 beams. These two beam splitters can achieve a split of 1 beam into 128 beams.

[0081] It should be noted that the embodiments of this application do not limit the splitting ratio (or beam splitting ratio) of the beam splitter. Optionally, the beam splitter can approximately uniformly divide one signal into multiple signals of equal power, but it is not excluded that a beam splitter with a specially designed splitting ratio can be used to divide one signal into multiple signals of unequal power to suit different quantum channel attenuation conditions.

[0082] Reference Figure 6b The diagram shown illustrates a quantum key distribution system architecture provided in an embodiment of this application. Figure 3 ,like Figure 6b As shown, the beam splitting device in the quantum key distribution system includes a cascaded multi-stage beam splitter group. Each stage of the multi-stage beam splitter group may include one or more beam splitters deployed in parallel. The multiple beam splitter groups together achieve the function of splitting 1 into n. The product of the number of beams split by the multi-stage beam splitters is equal to or greater than n. The number of beams split by each stage beam splitter group is equal to the sum of the number of beams split by all the beam splitters included in that stage beam splitter group.

[0083] For example, suppose n = 128, Figure 6b The beam splitting device includes two-stage beam splitter groups, each of which includes one beam splitter. The first-stage beam splitter can split 1 beam into 4 beams, and the second-stage beam splitter cascaded with the first-stage beam splitter can split 1 beam into 32 beams. Thus, the two-stage beam splitters can achieve a split of 1 beam into 128 beams.

[0084] Reference Figure 6c The diagram shown illustrates a quantum key distribution system architecture provided in an embodiment of this application. Figure 4 ,like Figure 6c As shown, the optical splitting device in this quantum key distribution system includes a wavelength division multiplexer, which can separately transmit n modulated optical signals of different wavelengths that have been multiplexed together to individual receivers. Figure 6cIn the system shown, the sending end generates an optical frequency comb signal with n spectral lines, and a modulation module is used to modulate the optical frequency comb signal with quantum signals. The modulated optical signal is sent to a wavelength division multiplexer through a quantum channel. The wavelength division multiplexer demultiplexes the received modulated optical signal into n sub-optical signals with different wavelengths, and sends the n sub-optical signals to n receiving ends through a quantum channel.

[0085] It should be noted that, in Figure 6c In the system shown, n lasers can be deployed in the sending end to generate an optical frequency comb signal with n spectral lines. Alternatively, a comb laser (also referred to as an optical frequency comb) can be deployed to generate an optical frequency comb signal with n spectral lines.

[0086] Referring to Figure 6d The quantum key distribution system architecture provided by the embodiment of the application is shown in Figure 5 As shown in Figure 6d The light splitting device in the quantum key distribution system includes a wavelength division multiplexer and at least one light splitter in cascade. The wavelength division multiplexer has multiple wavelength-diverse modulated optical signals multiplexed together and sent to the at least one light splitter. The at least one light splitter splits the received modulated optical signals, and finally obtains 1 / n sub-optical signals.

[0087] For example, in the system shown Figure 6d In the system shown, assuming n = 128, the light splitting device includes a wavelength division multiplexer with a 1 / 8 function and a light splitter with a 1 / 16 function in cascade. In this case, the sending end uses a first optical signal with 8 wavelengths to perform a wavelength division multiplexing and modulation scheme on quantum random numbers, and obtains 8 wavelength-diverse modulated optical signals. The 8 modulated optical signals are sent to the wavelength division multiplexer through a quantum channel. The wavelength division multiplexer demultiplexes the 8 modulated optical signals to obtain 8 modulated optical signals. Thereafter, each modulated optical signal is sent to the light splitter with a 1 / 16 function to obtain 16 sub-optical signals. Finally, after the 8 modulated optical signals are split, 128 sub-optical signals are obtained.

[0088] It should be noted that, Figure 6d The above

[0089] The above Figure 6c Or Figure 6dThe 1:n splitting structure shown by the wave division multiplexing technology, the sending end uses the same modulation device, and the same quantum random number is used to modulate multiple different wavelength optical signals to obtain multiple modulated optical signals. Not only can the wave division multiplexing / de-multiplexing structure be used to insert a small loss, but also the same quantum random number can be modulated to different wavelengths by deploying a modulation device at the sending end, so that n receiving ends can be coded at the same time, without Figure 4 The use of multiple modulators to modulate different signals for different wavelengths greatly reduces the complexity of the sending end, making it easier to implement single-point-to-multipoint continuous variable quantum key distribution using wave division multiplexing / de-multiplexing technology.

[0090] The quantum channel can be referred to as a noisy quantum channel. The quantum channel can be built by a standard single-mode optical fiber (such as a spatial quantum channel / space light or an optical fiber). As shown in Figure 5 The quantum channel can include a noisy quantum channel 1-1 and noisy quantum channels 2-1 to 2-n. The noisy quantum channel 1-1 is used to connect the sending end and the splitting device, and the noisy quantum channels 2-1 to 2-n are used to connect the splitting device and the n receiving ends, respectively.

[0091] The classical channel can be a wireless communication channel, which is used to connect the sending end and the n receiving ends for post-processing, such as transmitting side information (or auxiliary information) required in the post-processing process, such as measurement bases, quantization data, and check information containing check subscripts. As shown in Figure 5 The classical channel includes classical channels 1 to n.

[0092] It should be noted that Figure 5- Figure 6d The quantum key distribution system can also include other network devices and / or other user terminals for ease of understanding, which are not shown in Figure 5- Figure 6d In addition, Figure 5- Figure 6d The sending end, receiving end, and optical splitting device in the system shown include a splitter and / or a wavelength division multiplexer, which can use existing mature devices. The modulation method of the sending end, the detection method (such as homodyne detection or heterodyne detection) of the receiving end, and the protocol and type of the quantum key distribution system are not specifically limited. For example, the GG02 protocol or the switchless protocol based on homodyne detection or heterodyne detection of Gaussian modulation, or the discrete protocol based on quadrature phase-shift keying (QPSK) and quadrature amplitude modulation (QAM) modulation, can be used to implement simultaneous coding of quantum key distribution between a single point and multiple points using the method shown in the embodiments of the present application. For Figure 5- Figure 6dThe specific implementation of the type of the quantum key distribution system and the protocol is not specifically limited either, and the on-the-way local oscillator scheme or the local local oscillator scheme can be applied in the embodiments of the present application.

[0093] The quantum key distribution method described in the embodiments of the present application will be introduced below in combination with Figure 5- Figure 6d any quantum key distribution system shown, taking a quantum key distribution system in a 1:n structure as an example. Wherein n is the total number of receiving ends, n is an integer greater than 1, and the specific value of n is not limited. It should be noted that in the embodiments of the present application, the words such as "exemplarily" and "for example" are used to represent as an example, illustration or explanation. Any embodiment or design scheme described as "example" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes, and the word "example" is intended to present the concept in a specific way.

[0094] Figure 7 A flowchart of a quantum key distribution method provided in the embodiments of the present application is shown in FIG. 7, which is used to implement the i-th quantum key distribution of a quantum key distribution system in a 1:n structure, i is an integer greater than or equal to 1. As shown in Figure 7 the figure, the method can include the following steps.

[0095] In step 701, the sending end obtains a modulated light signal (which can be referred to as a second light signal) by modulating a first light signal according to a quantum random number, and sends the modulated light signal to a light splitting device through a quantum channel. Correspondingly, the light splitting device receives the modulated light signal sent by the sending end through the quantum channel.

[0096] Optionally, the sending end also saves the raw key of the sending end. The raw key of the sending end is obtained by mapping a quantum random number. The quantum random number can be referred to as a random key or a raw key, and the length of the quantum random number can be set as needed. The quantum random number can be generated by the sending device itself or generated by other devices and sent to the sending device, and the embodiments of the present application do not limit this.

[0097] The sending end is shown in Figure 5- Figure 6d the figure, which can be one sending end or a functional module in the sending end, and the sending end can be a network node.

[0098] The first light signal can be generated by a light source, which can include a laser or a comb laser. As in the above Figure 6a or Figure 6b , the light source can be one laser, and in Figure 6c or Figure 6d , the light source can include multiple lasers or include one comb laser.

[0099] The modulated light signal is a quantum state of information loaded with a quantum random number, and is obtained by modulating a light signal (such as a first light signal) generated by a light source by the quantum random number. The modulation described in the embodiments of the present application can refer to coherent state modulation, and can use a scheme of cascading an amplitude modulator and a phase modulator, or can use an in-phase-quadrature (IQ) modulator and other modulation schemes to achieve Gaussian modulation, or use one-dimensional modulation, discrete modulation, and other modulation schemes. For example, assuming that the length of the quantum random number is n, the modulated light signal obtained by modulating the first light signal by the quantum random number at the sending end is x A and p A Two regular component data, each component data length is n, the data amount of the original key of the sending end is 2n, and the original key is denoted as D A , then D A = (x1, p1, x2, p2, …, x n , p n ), the two regular component data are alternately stored in sequence, and the subscript of x j , p j represents the jth data, and j is any value in [1, n]. x j , p j are not associated.

[0100] In the embodiments of the present application, the on-the-wire local oscillator scheme or the local local oscillator scheme can be used, which is not limited. In the on-the-wire local oscillator scheme, the sending end can send a reference light signal (or referred to as a local oscillator signal) for modulating reference information at the same time as sending the modulated light signal, and the reference information can be used for frequency offset estimation, phase drift, and the like, so that the receiving end demodulates the received light signal according to the on-the-wire sent reference light signal to obtain the reference information. For example, the sending end can use time division multiplexing, polarization multiplexing, and other multiplexing technologies to realize simultaneous transmission (or referred to as on-the-wire transmission) of the reference light signal and the modulated light signal. Specifically, the time division multiplexing, polarization multiplexing, and other multiplexing technologies can refer to the prior art, and will not be described here. In the local local oscillator scheme, the sending end does not need to send the reference light signal together with the modulated light signal to the sending end, but generates the same reference light signal as the sending end locally, and demodulates the received light signal by using the locally generated reference light signal to obtain the reference information.

[0101] It should be noted that the quantum channel described in the embodiments of the present application not only has noise, but also can have non-trustworthy users. At this time, the signal transmitted through the quantum channel will have a certain attenuation (or referred to as energy attenuation / information quantity attenuation), and the signal received by the receiving end of the quantum channel is the signal attenuated from the signal sent by the sending end of the quantum channel. For example, the modulated light signal received by the light splitting device in step 701 is an attenuated modulated light signal. This is uniformly described below and will not be described again.

[0102] In step 702, the light splitting device performs light splitting processing on the received modulated light signal to obtain n sub light signals, and sends the n sub light signals to n receiving ends through n quantum channels respectively. Correspondingly, each receiving end receives the sub light signal from the light splitting device through the quantum channel.

[0103] Referring to Figure 5 , step 702 can be understood as follows: after the modulated light signal is sent to the light splitting device with a 1 / n function through the quantum channel 1-1 which can have non-trustworthy users, the light splitting device performs 1 / n light splitting processing on the received modulated light signal to obtain n sub light signals, and transmits the n sub light signals to n receiving ends through n quantum channels (such as quantum channel 2-1, quantum channel 2-2, …, quantum channel 2-n) corresponding to the n receiving ends which can have non-trustworthy users, as shown in Figure 5 , one sub light signal is transmitted on one quantum channel.

[0104] The specific design form of the light splitting device is referred to in Figure 6a- Figure 6d , and will not be described again.

[0105] In step 703, each receiving end demodulates the received sub light signal and detects the demodulated signal to obtain detection data, and obtains the original key of the receiving end according to the detection data. Optionally, the receiving end saves its own original key.

[0106] The above demodulation can refer to recovering the information contained in the quantum random number by using the first light signal to perform coherent state modulation on the received sub light signal. The detection method described in step 703 is not limited, and can include homodyne detection or heterodyne detection. The specific detection methods of homodyne detection and heterodyne detection can refer to the prior art, and will not be described again.

[0107] For example, after the n receiving ends demodulate the received sub light signal to obtain demodulated signals, the n receiving ends detect the demodulated signals to obtain detection data and save the detection data

[0108] Step 704, each receiving end interacts with the sending end through a classical channel to perform a post-processing process, and a set of final keys shared by both the receiving end and the sending end is obtained. Thus, the i-th quantum key distribution process ends, and n sets of final keys (or security keys) independent of each other are respectively generated between the sending end and the n receiving ends.

[0109] In the post-processing process performed through the classical channel, in order to ensure the security and integrity of information transmission, the receiving end also needs to add a secure message authentication step in the post-processing process performed through the classical channel and the sending end. The secure message authentication can indicate that the plaintext transmission is not tampered with, and the integrity of the plaintext transmission is ensured. Specifically, the secure message authentication step can refer to the prior art, such as the sending end encrypting the side information to be sent to the receiving end by using the key / private key or performing digital signature, sending the encrypted information and / or digital signature to the receiving end through the classical channel, and the receiving end decrypting the received information by using the symmetric key of the key / private key to obtain the information sent by the sending end, and verifying whether the digital signature is correct as needed.

[0110] Specifically, step 704 can include steps 7041-7044 as shown in Figure 8 .

[0111] Step 7041, the sending end and the receiving end perform measurement basis comparison and data screening, so that the sending end and the receiving end share a set of continuous variables with mutual correlation.

[0112] The measurement basis comparison and data screening process can refer to the prior art. For example, after the receiving end detects the demodulated sub-optical signal to obtain detection data, in order to ensure the correlation of the data between the sending end and the receiving end, the sending end and the receiving end need to retain the data under the same base and discard the data under different bases. At this time, the receiving end sends the measurement bases used for detection to the sending end, so that the sending end screens out the same data as the detection data of the receiving end from the original key saved by the sending end according to the received measurement bases.

[0113] For example, as shown in Figure 9 , assuming that the modulated optical signal of the sending end is D A =(x1, p1, x2, p2, …, x n , p n ), for each receiving end using homodyne detection, it randomly selects one of the two regular components for measurement each time, and after n measurements, each receiving end can detect data with a length of n, wherein part of the data is measured under the x regular component, and part of the data is measured under the p regular component. That is, the data x jp j Only one can be detected by the receiving end (50% of the possibility is x j , 50% of the possibility is p j , n receiving ends perform the detection process to obtain detection data Further, in order to ensure the correlation of data between the sending end and the receiving end, the sending end and the receiving end need to retain the data under the same base and discard the data under different bases, so the sending end and the n receiving ends need to perform the following operations: the n receiving ends respectively disclose their measurement bases to the sending end through a classical channel, and the sending end obtains the original key D A The key data with the same measurement base is retained, and thus n groups of data corresponding to the n sending ends are obtained: At this point, the sending end and the n receiving ends respectively share a group of continuous variables with mutual correlation:

[0114] It should be noted that the above action of sending the measurement base through the classical channel is an optional action, which can be determined according to the protocol used by the quantum key distribution system described in the present application. In some protocols (such as the GG02 protocol), the measurement base needs to be sent, while in some protocols, the measurement base does not need to be sent, such as in the no-switching protocol, the receiving end uses a heterodyne detector, which will simultaneously detect the detection data related to two groups of regular data x and p, and does not need to send the measurement base to the sending end, and this step 7041 can also be omitted. When the receiving end adopts the homodyne detection mode, this step 7041 needs to be performed and cannot be omitted.

[0115] Step 7042, each receiving end of the n receiving ends sends a first data sequence to the sending end. Correspondingly, the sending end receives the first data sequence from each receiving end of the n receiving ends. For any receiving end, the sending end calculates the security key rate between the sending end and the receiving end according to the first data sequence and the second data sequence of the m receiving ends, m being an integer greater than 1 and less than or equal to n.

[0116] Wherein, step 7042 can be referred to as a parameter estimation process in the post-processing process.

[0117] The first data sequence is part of the original key of the receiving end, for example, the first data sequence can be randomly sampled from the original key of the receiving end according to the random number S. The original key of the receiving end is obtained according to the detection data obtained by the receiving end from the probe sub-light signal, for example, the receiving end can directly use the detection data obtained by detection as the original key of the receiving end, or use part of the detection data as the original key of the receiving end. The sub-light signal is obtained by splitting the modulated light signal by the light splitting device, and the modulated light signal is obtained by modulating the first light signal according to the quantum random number by the sending end. For related description of the sub-light signal and the modulated light signal, refer to the description of steps 701 and 702 above, which will not be repeated here.

[0118] The second data sequence is part of the original key of the sending end. For example, in the case of performing step S7041, the second data sequence is obtained by randomly sampling the continuous variable having mutual correlation with the receiving end from the original key of the sending end according to the random number S. The continuous variable can be data selected from the original key of the sending end and having the same base as the receiving end. Or in the case of not performing step S7041, the second data sequence is obtained by randomly sampling the original key of the sending end according to the random number S. The length of the second data sequence is the same as the length of the first data sequence.

[0119] The value of the random number S described in the embodiments of the present application can be set as needed and is not limited. For example, the sending end and the receiving end randomly sample data at the first, third, fifth, etc. S odd positions in their respective original keys. For example, the sending end randomly samples data at the first, third, fifth, etc. S odd positions in its original key, and the receiving end randomly samples data at the first, third, eighth, etc. S even positions in its original key. In addition, the random number S can be set by the sending end and the set random number S is informed to the receiving end, that is, the sending end is responsible for selecting the position of random sampling and sending to all receiving ends. The sending end does not need to perform random sampling for different receiving ends, which can reduce the use of computing resources of the sending end and is conducive to cost control. Or it can also be set by the receiving end and the set random number is informed to the sending end, which is not limited.

[0120] Since the prior information of the quantum channel in the quantum key distribution system is unknown, the quantum channel characteristic must be estimated through the parameter estimation step, which can be used to represent the channel state of the quantum channel of the quantum key distribution system, such as can be used to represent the upper limit of the amount of information that can be obtained by the non-trustworthy user on the quantum channel. Optionally, there are two kinds of parameter estimation, one is to estimate the data correlation between the sending end and the receiving end, such as to estimate the covariance matrix of the transceiver, and the other is to estimate the characteristic parameters of the quantum channel, such as the equivalent transmittance T and / or the equivalent noise ε of the quantum channel. After the data correlation or the quantum channel characteristic is estimated through the parameter estimation step, the secure key generation rate between the sending end and the receiving end can be calculated. Which parameter estimation method is used also relates to the security analysis method, which is specified by the protocol. According to the two parameter estimation methods, the secure key generation rate between the sending end and the receiving end is calculated according to the first data sequence and the second data sequence of the N receiving ends in step S7042, which can include any of the following two methods:

[0121] Method one, estimate the data correlation between the transceiver, and calculate the secure key generation rate between the transceiver according to the data correlation. For example: the sending end calculates the data correlation between the sending end and the receiving end according to the first data sequence and the second data sequence of the m receiving ends, which is used to represent the channel state of the quantum channel of the quantum key distribution system; and the secure key generation rate between the sending end and the receiving end is calculated according to the data correlation.

[0122] Specifically, calculating the data correlation between the sending end and the n receiving ends can include: calculating the variance of the m receiving ends and the covariance between the m sending ends and the receiving ends according to the first data sequence and the second data sequence of the m receiving ends, and obtaining the covariance matrix between the sending end and the receiving end according to the variance of the m receiving ends and the covariance between the m sending ends and the receiving ends, that is, using the covariance matrix to represent the data correlation between the sending end and the receiving end. Further, the secure key generation rate between the sending end and the receiving end is calculated according to the covariance matrix.

[0123] Specifically, the secure key generation rate between the sending end and the receiving end is calculated according to the covariance matrix, which can include: using the variance of the m receiving ends and the covariance between the m sending ends and the receiving ends to calculate the estimation of the quantum key by each of the m receiving ends, and using the constructed covariance matrix to calculate the estimation of the quantum key by the non-trustworthy user when the non-trustworthy user's ability is maximized, and determining the secure key generation rate according to the estimation of the quantum key by each of the m receiving ends and the estimation of the quantum key by the non-trustworthy user.

[0124] wherein the value of m can be set according to requirements. In one example, m is directly set as m=n, and in this case, the covariance matrix is a covariance matrix estimation of n+1 modes, that is, in calculating the security key generation rate of a certain receiving end, n receiving ends are all regarded as trusted (not combined with non-trusted users in the quantum channel, and the receiving ends are not combined with each other), the covariance matrix between the n receiving ends and the sending end is used to represent the data correlation between the receiving end and the sending end, the data correlation between the receiving end and the sending end is increased, the equivalent signal attenuation between all receiving ends as a whole and the sending end is reduced, and the security key generation rate between the receiving end and the sending end is improved. In another example, in order to prevent non-trusted users from attacking part of the receiving end inside the quantum key distribution system in an extreme case, m can be set to be less than n in actual implementation, the number of trusted receiving ends is reduced to achieve more stringent evaluation of the security key generation rate, so as to improve the security in the extreme case, that is, by reducing a certain security key generation rate, it is ensured that even if non-trusted users obtain part of the quantum key information of the receiving end of part of the users, the security code rate evaluated for other users is still safe. For example, when calculating the security key generation rate of a certain receiving end, r receiving ends are randomly removed from the remaining n-1 receiving ends, r is an integer greater than or equal to 1 and less than (n-1), and only the first data sequence of the remaining (n-r) receiving ends is used to participate in the calculation of the security key generation rate of the receiving end. At this time, m=n-r, and the r receiving ends removed at random are equivalent to regarding the r receiving ends as non-trusted parties that have been attacked, which is roughly equivalent to adding r / n non-trusted attenuation. It should be noted that in the actual system, the actual loss of the r receiving ends is determined. For example, when r=n / 2, 3dB non-trusted attenuation is added, which can ensure that even if half of the users' receiving end quantum key information is obtained by non-trusted users, the security of the receiving end of other users in the quantum key distribution system is not affected.

[0125] For example, in the case of each receiving end using heterodyne detection, since the key screening in step 7041 does not need to be performed, the sending end only retains the data D A As described in step 7041, the data D A includes two sets of regular data; the sending end randomly samples the original key D A to obtain the second data sequence Est A for parameter estimation; thereafter, the sending end discloses the random number S to the n receiving ends through the classical channel 1 to the classical channel n, and each receiving end randomly samples the original key according to the random number S to obtain the corresponding first data sequence (or measurement data) , and sends the first data sequence to the sending end through the classical channel 1 to the classical channel n; the sending end calculates the covariance matrix of the first data sequence and the second data sequence according to the formula The sending end and the receiving ends B1, B2, …, Bn can be obtained. n The respective variances γ1, γ2, …, γn A and the covariances therebetween. Since the calculation of the variances in the present application does not involve the data interaction between different receiving ends, the covariances matrix can be calculated by using all the data to reduce the influence of statistical fluctuation. Therefore, the covariance matrix of the n+1 modes can be estimated according to the respective variances of the sending end and the n receiving ends and the covariances therebetween as shown below. Then, the security key generation rate between the sending end and the receiving ends can be calculated according to the covariance matrix.

[0126]

[0127] It should be noted that, in the present application, when the security key generation rate between the sending end and the receiving ends is calculated according to the covariance matrix between the sending end and the receiving ends, the security key generation rate between the sending end and the receiving ends can be directly calculated according to the covariance matrix, or some elements in the covariance matrix can be modified / updated, and the security key generation rate between the sending end and the receiving ends can be calculated according to the modified / updated covariance matrix. For example, the values of some elements in the covariance matrix are reduced, and the security key generation rate is reduced by reducing the data correlation between the sending end and the receiving ends, so that even if a non-trusted user obtains part of the quantum key information of the receiving end of a part of the users, the receiving end of the other users is still safe, and a more stringent evaluation of the security key generation rate is achieved to improve the security in extreme cases.

[0128] Specifically, which elements in the covariance matrix are modified / updated can be set according to the needs, and is not limited.

[0129] Mode two, estimating the characteristic parameters (such as the equivalent transmittance T and / or the equivalent noise ε of the quantum channel) of the quantum channel, and determining the security key generation rate between the sending end and the receiving ends according to the characteristic parameters of the quantum channel.

[0130] For example: the characteristic parameters are calculated according to the first data sequence and the second data sequence of the m receiving ends, wherein the characteristic parameters include the equivalent noise and / or the equivalent transmittance, the equivalent noise is used to represent various types of noise in a statistical form, and the equivalent transmittance is used to represent the signal transmittance of the quantum channel of the quantum key distribution system and / or the preset node combination in the quantum key distribution system as a whole; the security key generation rate between the sending end and the receiving ends is obtained by looking up a comparison table according to the characteristic parameters; wherein the comparison table includes the corresponding relationship between the characteristic parameters and the security key generation rate.

[0131] ​​The preset node can be all or part of components of the quantum key distribution system, such as a partial receiving end and a light splitting device. The correspondence table can be preconfigured, for example, in the sending end.

[0132] It should be noted that in the embodiments of the present application, the security key rate calculated in step S7042 can be directly used in the subsequent processing process, such as directly used in step S7044. Alternatively, the security key rate calculated in step S7042 can be used in the subsequent processing process after being processed by weighting, such as multiplied by a weighting factor less than 1 and then used in the subsequent processing process. The weighting factor can be set as needed, and the weighting factor can be an empirical value. The weighting factor and the security key rate can be stored correspondingly, so that the weighting factor can be obtained by looking up the table. In this way, by reducing a certain security key rate, it is ensured that even if a non-trustworthy user obtains part of the quantum key information of the receiving end of part of the users, the receiving end of the other users is still secure, and more stringent evaluation of the security key rate is achieved to improve the security in extreme cases. The present application does not limit which way to use the security key rate calculated in step S7042, such as directly used in step S7044.

[0133] In step 7043, the sending end and the receiving end perform error correction operation to obtain a corrected key.

[0134] In step 7043, the sending end and the receiving end perform error correction operation to obtain a corrected key. The process can include: the sending end and the receiving end convert the continuous variable into a discrete form through negotiation algorithm, and then complete the error correction decoding by exchanging the negotiation information in discrete form, so that the sending end and the receiving end obtain the same binary bit data, i.e. the corrected key. The error correction decoding process can include: the sending end receives the encrypted check information from the receiving end, the check information is encrypted by the second final key in the case that i is greater than 1, the second final key is the final key obtained by the sending end and the receiving end in the i-1th quantum key distribution, the check information is encrypted by the preset key in the case that i=1, the preset key can be preconfigured, and the check information includes a syndrome, the syndrome is calculated by the receiving end according to a third data sequence, and the third data sequence includes the remaining data in the original key of the receiving end except the first data sequence; the sending end decrypts the check information to obtain the syndrome, and the sending end performs error correction decoding on a fourth data sequence according to the syndrome to obtain the corrected key; the fourth data sequence includes the remaining data in the original key of the sending end except the second data sequence.

[0135] It should be noted that this application does not limit the execution order of steps 7042 and 7043 above. Step 7042 can be executed first, followed by step 7043, or the error correction operation shown in step 7043 can be executed first, followed by the parameter estimation shown in step 7042. In the method of performing error correction first and then parameter estimation, there is no need for the step of random sampling for parameter estimation. Instead, each receiver first performs error correction with the transmitter, and then the transmitter recovers the data from each receiver, calculates the complete covariance matrix locally, and then calculates the security key coding rate corresponding to each receiver.

[0136] For example, such as Figure 9 As shown, n receivers first use a negotiation algorithm to convert their continuous variables into error-correctable discrete forms through quantization or rotation operations, and then transmit side information to the transmitter through a classical channel. After receiving the side information from the n receivers, the transmitter performs corresponding quantization or rotation operations on the n data sets it holds to obtain discrete data associated with the n receivers. Taking multidimensional negotiation as an example, each of the n receivers uses a true random number generator to generate a bit string of length d that follows a uniform distribution. And convert it into spherical code on a d-dimensional unit sphere. Subsequently, n receiving ends each transmit their data. Normalized mapping to spherical code Obtain discrete data Simultaneously, each receiver calculates its data-to-spherical code mapping relationship M1, M2, ..., M n Each of these data is transmitted to the sending end via classical channels 1 to n; after receiving the above data, the sending end transmits its data D. A Make n copies, using the mapping relationship M1, M2, ..., M n For n copies of D′ A By performing the operations separately, discrete information corresponding to n receiving ends is finally obtained, i.e.

[0137] Next, the two sides perform the error correction and decoding steps in data coordination, whereby the n receivers select appropriate error correction codes and, based on the selected error correction codes, decode their respective discretized discrete information. Perform error-correcting code checksum calculations (or checksum calculations) to obtain the respective checksums Syn1, Syn2, ..., Syn. nTaking low-density parity-check (LDPC) codes as an example, the checksum is the product of the check matrix corresponding to the error correction code and the discrete information. For example, if the checksum is represented as a column vector T, the check matrix is ​​C, and the discrete information is Y, then the checksum T = CY. The checksum is then encrypted and sent to the sender through a classical channel, using a one-time pad encryption scheme. For instance, in the i-th quantum key distribution, i > 1, the sender and n receivers use the key management system to retrieve the final key generated in the previous key distribution process, which has the same length as the checksum in the current round. Then, using one-time key technology, respectively utilizing The encrypted checksum yields the verification information: The sender then transmits verification information carrying an encrypted checksum to the transmitter via a classic channel. The transmitter receives the verification information carrying the encrypted checksum. Then, it is first decrypted to obtain the original checksum, i.e. Based on this, error correction decoding is performed on the parser using error correction codes, and the decoded data is then processed. The binary bit data is adjusted to be consistent with that of each receiver. After removing the information loss caused by error correction decoding failure, the final transmitter and n receivers share n sets of binary data, denoted as the error-corrected key: Y1, Y2, ..., Y n .

[0138] Optionally, in a quantum key distribution system, the loss and noise of the channels (e.g., quantum channels, classical channels) between the transmitter and different receivers may be different. This results in different signal-to-noise ratios (SNRs) of the signals received by different receivers from the transmitter through their corresponding channels. Consequently, different receivers and transmitters may need to employ different error correction encoding / decoding schemes (or error correction coding / decoding strategies), such as using LDPC error correction codes with different code rates for different receivers. In multi-user scenarios, different error correction encoding / decoding schemes need to be designed for multiple different receivers, which increases the design complexity of the error correction encoding / decoding scheme. To reduce the design complexity of the error correction encoding / decoding scheme, in the embodiments of this application:

[0139] The n receivers are divided into multiple groups, and the channel quality difference between different receivers within the same group is less than a preset threshold. For each group, the error correction encoding and decoding scheme between the transmitter and different receivers within the same group is the same; that is, a common error correction encoding and decoding scheme is designed for each group. Optionally, the error correction encoding and decoding scheme corresponding to the same group corresponds to a first signal-to-noise ratio (SNR), which is the SNR of the receiver with the lowest SNR within the group, such as the lowest SNR.

[0140] The preset threshold value can be set as needed and is not limited. The channel quality difference of the channels corresponding to different receiving ends being less than the preset threshold value can indicate that the channel quality of the channels corresponding to the different receiving ends is close, and the channel performance is close.

[0141] The corresponding relationship between the error correction coding scheme and the signal-to-noise ratio can be preconfigured. For each group, the lower signal-to-noise ratio (such as the lowest signal-to-noise ratio) corresponding to the group is determined first. Based on the determined signal-to-noise ratio, the preconfigured corresponding relationship between the error correction coding scheme and the signal-to-noise ratio is searched. The error correction coding scheme corresponding to the signal-to-noise ratio in the corresponding relationship is taken as the error correction coding scheme of the group.

[0142] In this way, the channels of the multiple receiving ends can be grouped according to the signal-to-noise ratios of the channels of the multiple receiving ends. Channels with similar performance are grouped. The error correction coding scheme corresponding to the signal-to-noise ratio with poor performance is used as a reference. The error correction decoding step in the data coordination between the receiving end and the sending end is performed using the error correction coding scheme corresponding to the signal-to-noise ratio with poor performance. That is, the error correction coding scheme is designed in groups. Only one or a few groups of error correction coding schemes can solve the error correction decoding problem in the quantum key distribution process, simplifying the design complexity of the error correction coding scheme. At the same time, the signal-to-noise ratios of all channels in the group are adjusted to be consistent by adding trusted noise to other signals in the group based on the signal-to-noise ratio with poor performance. By sacrificing a certain code rate performance, the sending end can use a smaller bit error correction code to complete the error correction coding of the data, simplifying the design complexity of the error correction coding scheme and reducing the system cost.

[0143] Step 7044, for any receiving end, the sending end performs a security enhancement operation on the error-corrected key obtained by performing the error correction operation between the sending end and the receiving end in step 7043 according to the code rate of the security key calculated in step 7042, to obtain a first final key shared by the sending end and the receiving end. The first final key is used for secure transmission of information between the sending end and the receiving end. The first final key can also be referred to as a first security key.

[0144] Step 7044 can be referred to as security enhancement or security enhancement in post-processing or private key amplification process.

[0145] Specifically, step 7044 can include multiplying the error-corrected key shared by the sending end and the receiving end with a universal hash function to obtain the first final key shared by the sending end and the receiving end. In this way, the length of the error-corrected key shared by the sending end and the receiving end can be amplified, and the information obtained by the untrusted user from the error-corrected key shared by the sending end and the receiving end can be compressed. When the code length of the key shared by the sending end and the receiving end after the security enhancement operation is long enough, the information obtained by the untrusted user is almost zero, improving the security of the entire system.

[0146] The general hash function can be a Toeplitz matrix. The general hash function can be constructed based on the security key generation rate. Specifically, the method for constructing the general hash function based on the security key generation rate is based on existing technology and will not be elaborated further.

[0147] For example, such as Figure 9 As shown, the sending end calculates the security key generation rates R1, R2, ..., R between itself and each receiving end. n Then, according to R1, R2, ..., R n Construct n Toeplitz matrices T1, T2, ..., T of suitable size. n The sender and the n receivers then transmit the n sets of error-corrected keys Y1, Y2, ..., Y to each of the n corresponding receivers. n With T1, T2, ..., T n Multiplying them together yields the final keys K1, K2, ..., K. n .

[0148] The security enhancement operation G described in step 7044 removes information already possessed by untrusted users by shortening the key length and discarding some data. The principle of information removal is related to a third party's estimate of the quantum key. One implementation method is to construct an m×n Toeplitz matrix T and multiply it by the column vector composed of the original key, where n is the length of the original key and m is the length of the secure key. The relationship between this and the secure key generation rate calculated based on system parameters is m = R×n. The secure key generation rate R refers to the average number of secure bits per bit transmitted, which can be determined based on the untrusted user's estimate of the quantum key K. E And it is calculated from the original key K0, that is, R = H(K0) - H(K). E ), where H(K0) and H(K) E ) represents K0 and K E The amount of secret information contained therein. When H(K0) remains constant, H(K) E The larger the value of H(K), the lower the bitrate, and the higher the amount of information that needs to be compressed. Through the above operations, all estimates of K0 are less than H(K). E Third-party known information will be removed. In this case, considering the scenario described in the embodiments of this application, when the channel attenuation reaches a certain level, the amount of information that an untrusted user can obtain will be greater than the amount of information between the receivers, i.e., H(K) E )>max{H(K B1 ),H(K B2 ),…,H(K Bn-1 Therefore, according to R = H(K0) - H(K) E)performing security enhancement operation, the association between the key information of each receiving end can be removed while eliminating the non-trusted user known information.

[0149] Based on Figure 8 In the method shown, for a quantum key distribution system with 1:n structure, in the post-processing process of performing quantum key distribution, when calculating the security key rate between a receiving end and a sending end, instead of regarding the other n-1 receiving ends as completely untrusted, the multiple receiving ends (such as m receiving ends including the receiving end) in the n receiving ends are regarded as trusted receiving ends. The multiple receiving ends will not cooperate with the non-trusted user in the quantum channel to obtain the quantum key information included in the quantum optical signal transmitted on the quantum channel, and will not cooperate with each other to obtain the quantum key information included in the quantum optical signal transmitted on the quantum channel. Based on the data disclosed by the m receiving ends to the sending end and part of the original key of the sending end, the data association between the receiving end and the sending end is determined, the security key rate between the receiving end and the sending end is determined according to the determined data association, and then the final key is obtained by performing security enhancement operation on the error-corrected key shared by the receiving end and the sending end according to the determined security key rate. Compared with the prior art, when analyzing the security key rate between a receiving end and a sending end, it is assumed that the other n-1 receiving ends are untrusted and can cooperate with the non-trusted user in the quantum channel, which leads to that the splitting loss of PON will seriously affect the system performance (such as in the case of equal division of the splitter, which is equivalent to introducing a transmittance of 1 / n), which limits the maximum number of users that can be supported by the quantum key distribution system. In the Figure 8 In the scheme shown, the data association between a receiving end and a sending end is estimated by multiple receiving ends, the upper bound of the information that can be obtained by the non-trusted user in the channel will have a more compact evaluation result, the influence of the attenuation caused by the splitting device will be greatly reduced, so that the quantum key distribution system can support more users.

[0150] In addition, Figure 8In the shown scheme, in the data error correction step (such as step 7043) in the post-processing process, the n receivers can also achieve simultaneous decoding of multiple receivers by encrypted transmission of the syndrome, and the security analysis of simultaneous extraction of the key by all receivers after encrypted transmission of the syndrome required in the post-processing error correction link can be performed, thereby ensuring the security of simultaneous decoding of multiple users. The scheme for achieving simultaneous decoding of multiple receivers by encrypted transmission of the syndrome described in the present application not only ensures that all receivers simultaneously extract a secure key, reduces the use of time division multiplexing modules, simplifies the system structure, and is conducive to reducing system cost and complexity, facilitating system deployment and maintenance. Moreover, the receiver only needs to send the syndrome to the sender, and does not need to perform error correction calculation. The device for error correction with high computing power is deployed at the node end, and the computing power allocation is more reasonable.

[0151] Further, the embodiments of the present application also provide schemes in the expansion and contraction scenarios. The expansion can refer to adding new users in the quantum key distribution system, that is, new users access the quantum key distribution system. The contraction can refer to the off-network of users in the quantum key distribution system, and the off-network users no longer participate in the quantum key distribution of the quantum key distribution system. The following introduces the technical solutions of the synchronization, registration and key pre-sharing of the new users in the expansion scenario and the contraction scenario:

[0152] Taking the addition of the n+1th receiver in the quantum key distribution system in the expansion scenario as an example, the synchronization process of the new user includes:

[0153] The sender sends a reference frame; wherein the reference frame includes a synchronization frame, and the synchronization frame is used to realize data synchronization between the n+1th receiver and the sender. Correspondingly, the n+1th receiver receives the reference frame, obtains the synchronization frame from the reference frame, and obtains data synchronization according to the synchronization frame.

[0154] For example, at the beginning of each quantum key distribution, the sender will first send a string of the same, classical synchronization frame signals (or called synchronization frames) to the n receivers through the light splitting device, and the first quantum data after the synchronization frame is the data header; when the n+1th receiver accesses, it continuously monitors the synchronization frame signal, and when it confirms that the synchronization frame signal is received, it retains the subsequent probe data; in principle, it is equivalent to continuously waiting until the current round of key distribution ends after the new user accesses, and formally accessing the network in the next round of key distribution by identifying the reference frame, so as to minimize the influence on other users in the system.

[0155] Taking the addition of the n+1th receiver in the quantum key distribution system in the expansion scenario as an example, the registration process of the new user includes:

[0156] The sending end receives side information sent by the n+1th receiving end; and the sending end adjusts quantum key distribution timing and / or quantum key distribution resources of n+1 terminals including the n+1th receiving end in the quantum key distribution system according to processing complexity of the side information and time when the side information arrives at the sending end.

[0157] The side information is used to calculate final keys between the sending end and the n+1th receiving end, for example, the side information can include information sent by the n+1th receiving end to the sending end through a classical channel in a post-processing process.

[0158] It should be noted that if the n+1th receiving end joins the quantum key distribution system in the ith quantum key distribution process, the sending end can first perform the ith quantum key distribution process of the original n receiving ends, perform quantum key distribution with the i+1th receiving end, and receive side information sent by the n+1th receiving end. According to the side information of the n+1th receiving end, the i+1th quantum key distribution timing and / or quantum key distribution resources are adjusted. In this way, when a new user registers to the quantum key distribution network, it can be ensured that the existing users will not be affected, and the influence of the number of new user terminals on the existing computing resources can be avoided as much as possible, thereby reducing the interference of the new user on the existing users when the new user registers to the network.

[0159] Next, taking error correction coding as an example, the process of the n+1th receiving end registering to the quantum key distribution system is described.

[0160] First, after the n+1th receiving end completes data synchronization, when the sending end receives the check information (Syn new ) carrying the check subscripts of the first round of key distribution of the n+1th receiving end, the sending end records the time when Syn new arrives at the sending end, and stores Syn new and the time when Syn new arrives at the sending end. Thereafter, the existing error correction information processing flow is continued to process the error correction information until the error correction information processing of the current round of the existing n receiving ends is completed, and then Syn new is processed and the processing complexity when the error correction is analyzed. The complexity of error correction decoding can be evaluated by the signal-to-noise ratio. Thereafter, according to the time when Syn new arrives at the sending end and the processing complexity, the sending end re-plans an optimal error correction information processing flow of n+1 receiving ends including the new user; and finally, from the next round of error correction data processing, the sending end performs error correction information processing according to the optimal error correction information processing flow of the refreshed n+1 receiving ends.

[0161] Similarly, for other side information, when a new user accesses, the arrival time sequence of the new user's corresponding data is first recorded and stored, and thereafter the system still processes the key information of other existing users according to the original process to reduce the interference of the new user to other users in the current round; when the data processing of other users is completed, the system processes the new user terminal quantity data and analyzes the data complexity; thereafter, the system refreshes the system data processing process according to the arrival time sequence and complexity of the new user terminal quantity data, and constructs an n+1 user optimization network data processing strategy containing the new user; finally, starting from the next round, the network system executes data processing and resource scheduling according to the n+1 user optimization network data processing strategy, realizing the registration of the new user into the network.

[0162] For example, the sending end adjusts the quantum key distribution time sequence and / or quantum key distribution resources of n+1 terminals including the n+1 receiving end in the quantum key distribution system according to the processing complexity of the side information and the time when the side information arrives at the sending end, which can include: allocating part of the complex data to low-performance computing devices for processing, thereby speeding up the overall data processing process. Avoiding the problem of complex data congestion caused by using high-performance computing to process complex data, which reduces the network data processing efficiency.

[0163] In the present application, in order to enable multiple receiving ends to generate secure keys simultaneously, the receiving end is required to use part of the key generated in the last round of key distribution to encrypt the syndrome required in the transmission error correction process. For new users, the first problem is to pre-share a set of keys with the sending end to encrypt the syndrome of the new user in the first round of key distribution in this scheme. Unlike the pre-shared key used for message authentication in general QKD protocols, the length of this key is very large. Taking the addition of the n+1 receiving end in the quantum key distribution system in the expansion scenario as an example, the key pre-sharing of the new user includes:

[0164] (1) When the new user is added to the network, pre-charge. Specifically, it includes the following two ways:

[0165] 1.1, the pre-shared key of the n+1 receiving end is the length L key configured to the n+1 terminal when the n+1 terminal is manufactured; L is an integer greater than 1.

[0166] For example, the equipment manufacturer has pre-charged the sending end with preset keys that can be used to interface with n+1 receiving end users when the sending end is manufactured. The n+1 groups of preset keys are different from each other and correspond to a predicted receiving end number respectively. And the manufacturer retains a copy of the key. When a receiving end new user is added to the network, first determine its assigned receiving end number, find the reserved key of the corresponding sending end, and charge it according to the information retained by the sending end.

[0167] Mode two 1.2, the pre-shared key of the n+1 receiving end is a key with length L generated by manual when the n+1 terminal enters the network. L is an integer greater than 1.

[0168] For example, when the n+1 receiving end is added to the network, the corresponding receiving end number is first confirmed, and then a random key with the required length is generated, and the sending end and the receiving end are manually filled respectively.

[0169] (2) The pre-shared key of the n+1 receiving end is the key obtained after the n+1 terminal and the sending end perform multiple quantum key distribution. The length of the pre-shared key of the n+1 receiving end is greater than the key length L required for encryption check. That is, the sending end determines the final key obtained by performing the following process multiple times as the pre-shared key of the n+1 receiving end: the sending end calculates the security key rate between the sending end and the n+1 terminal according to part of the data in the original key of the n+1 receiving end and part of the data in the original key of the sending end, and performs security enhancement operation on the error-corrected key obtained by performing error correction operation on the sending end and the n+1 terminal to obtain the final key shared by the sending end and the n+1 terminal.

[0170] For example, after the n+1 receiving end system accesses the quantum key distribution system, it first collects several rounds of data and evaluates the signal-to-noise ratio to determine the key length L for encryption when sending error correction check. At this time, the n+1 receiving end does not generate a key. The system sets a period of time to generate a key for the n+1 terminal to generate an encryption check, and the n+1 terminal does not formally join the network until it accumulates a key with a length of L1 bits. L1 >= L. This period of time can be called expansion preparation time. In order to avoid the expansion preparation time being too long and affecting other users, it can be divided into M time periods to complete, and each time period and the normal operation time of the system are alternately performed, so that the key generation rate of other users only decreases to a certain extent, and there is no long-term interruption.

[0171] In the capacity expansion preparation time, the n+1th receiving end performs the following process: (1) the n+1th receiving end sends the measured data samples to the sending end; other users still send the measured data samples (even all) to the sending end; the sending end calculates the security key generation rate between the n+1th receiving end and the sending end by counting the covariance matrix. (2) The n+1th receiving end transmits the syndrome directly to the sending end without encryption. Because other users do not generate keys during the capacity expansion preparation time, the syndrome of the n+1th receiving end is not encrypted and does not affect other users. The effect of this unencrypted syndrome on the n+1th receiving end itself security key generation rate has been considered in the calculation of the security key generation rate. The security understanding of this part is similar to the ordinary single-path QKD protocol, which is a common method in the industry. Its security key generation rate should be similar to the normal operation of the 1:n network proposed in this patent. (3) The sending end completes error correction according to the syndrome, and the sending end and the new receiving end complete security enhancement and other steps to generate a key for encrypting the syndrome, with a length of L0. After repeating the above processes (1) to (3), a long enough key is accumulated, such as the total length of the key obtained after the last execution of (1) to (3) is greater than the key length required for encrypting the syndrome. This key can be used as the key required for encrypting the syndrome in the first quantum key distribution of the n+1th receiving end after accessing the quantum key distribution system in the formal working stage.

[0172] The above-mentioned key supplement method for new registered users can also be used for key supplement when an existing registered user's key is greatly reduced due to unexpected circumstances, making it impossible to support encrypted syndrome.

[0173] The following describes the capacity reduction scenario with the nth receiving end as an example:

[0174] The receiving end obtains the off-network time of the nth receiving end, which indicates that the nth receiving end has been off-network after the kth quantum key distribution, where k is an integer greater than 1. The receiving end adjusts the quantum key distribution timing and / or quantum key distribution resources after the nth receiving end is off-network according to the off-network time of the nth receiving end; and performs quantum key distribution between the receiving end and the nth receiving end using the adjusted quantum key distribution timing and / or quantum key distribution resources after the kth quantum key distribution is performed.

[0175] For example, before the nth receiving end exits the network, the user is required to disclose the exit time to the sending end in advance through a classical channel, that is, to inform the sending end that the nth receiving end starts the exit process after the quantum key distribution for the first time and no longer receives data and performs data processing with the sending end. During this period, the sending end formulates a data processing strategy and a security analysis scheme after the nth receiving end exits the network, but maintains the existing scheme before the nth receiving end starts to exit. When the nth receiving end completes the last round of quantum key distribution, in the next round of quantum key distribution, the sending end starts the pre-formulated new scheme and excludes the nth receiving end from the nth receiving end in this round.

[0176] The above Figure 5- Figure 9 The quantum key distribution provided by the embodiments of the present application is described in detail. The scheme provided by the embodiments of the present application is mainly introduced from the perspective of interaction between nodes. It can be understood that each node, such as the sending end, the receiving end, etc., contains the corresponding hardware structure and / or software module for executing each function in order to achieve the above functions. Those skilled in the art should easily realize that, in combination with the algorithm steps of each example described in the embodiments disclosed herein, the present application can be realized in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driven hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0177] The embodiments of the present application can group the functional modules of the terminal, network device, etc. according to the above method examples, for example, each functional module can be grouped according to each function, or two or more functions can be integrated in one processing module. The above integrated module can be realized in the form of hardware or in the form of a software functional module. It should be noted that the grouping of modules in the embodiments of the present application is illustrative, and is only a logical grouping, and actual implementation can have another grouping manner.

[0178] Figure 10 A structural diagram of a quantum key distribution apparatus 100 is shown, which can be a sending end, or a chip or system on chip in the sending end, and the quantum key distribution apparatus 100 can be used to execute the functions of the sending end involved in the above embodiments. As a realizable manner, Figure 10 The quantum key distribution apparatus 100 shown includes a receiving unit 1001 and a processing unit 1002.

[0179] The receiving unit 1001 is used to receive a first data sequence from each of the n receiving ends; the first data sequence includes a portion of the original key of the receiving end, the original key of the receiving end is obtained based on the detection data obtained by the receiving end from detecting the sub-optical signal, the sub-optical signal is obtained by splitting the modulated optical signal by a beam splitter, and the modulated optical signal is obtained by the transmitting end modulating the first optical signal according to the quantum random number.

[0180] Processing unit 1002 is configured to, for any receiving end, calculate the security key generation rate between the sending end and the receiving end based on a first data sequence and a second data sequence from m receiving ends, wherein the second data sequence includes a portion of the original key from the sending end; m is an integer greater than 1 and less than or equal to n; and the m receiving ends are included among the n receiving ends.

[0181] The processing unit 1002 is further configured to perform a security enhancement operation on the error-corrected key obtained by the dual error correction operation performed by the sending end and the receiving end according to the security key coding rate, so as to obtain a first final key shared by the sending end and the receiving end; the first final key is used for secure transmission of information between the sending end and the receiving end.

[0182] Specifically, the execution actions of each unit of the quantum key distribution device 100 can be referred to Figure 7- Figure 9 The sending method shown here has the same function as the sending method described above, and therefore can achieve the same effect.

[0183] As another feasible approach Figure 11 The quantum key distribution device 110 shown may include a processor 1101 and a transceiver 1102. Further, the quantum key distribution device 110 may also include a memory 1103, output devices, and input devices. Input devices are keyboards, mice, microphones, or joysticks, etc., and output devices are displays, speakers, etc. These components are connected via communication lines. The processor 1101 is used to control and manage the operation of the quantum key distribution device 110. For example, the processor 1101 may integrate the functions of the processing unit 1002, such as executing steps 703 and 704 as described above. The transceiver 1102 may integrate the functions of the receiving unit 1001 and can be used to support the quantum key distribution device 110 in executing step 701 and communicating with other network entities, such as communication with the receiving end.

[0184] The processor 1101 can be a central processing unit (CPU), a general-purpose processor, a network processor (NP), a digital signal processor (DSP), a microprocessor, a microcontroller, a programmable logic device (PLD), or any combination thereof. The processor 1101 can also be other devices with processing capabilities, such as a circuit, a device, or a software module.

[0185] The transceiver 1102 is configured to communicate with other devices or other communication networks. The other communication networks can be an Ethernet, a radio access network (RAN), a wireless local area network (WLAN), and the like. The transceiver 1102 can be a radio frequency module, a transceiver, or any device capable of implementing communication. In this embodiment of this application, the transceiver 1102 is taken as a radio frequency module for example, and the radio frequency module can include an antenna, a radio frequency circuit, and the like. The radio frequency circuit can include a radio frequency integrated chip, a power amplifier, and the like.

[0186] The memory 1103 is configured to store instructions. The instructions can be a computer program.

[0187] The memory 1103 can be a read-only memory (ROM) or other types of static storage devices that can store static information and / or instructions, or a random access memory (RAM) or other types of dynamic storage devices that can store information and / or instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disk storage, a magneto-optical disk, a magnetic disk storage, or other magnetic storage devices, or a disk storage including a compact disk, a laser disk, an optical disk, a digital versatile disk (DVD), a Blu-ray disk, and the like.

[0188] It should be noted that the memory 1103 can exist independently of the processor 1101, or can be integrated with the processor 1101. The memory 1103 can be used to store instructions or program codes or some data, etc. The memory 1103 can be located in the quantum key distribution device 110, or can be located outside the quantum key distribution device 110, which is not limited. The processor 1101 is used to execute the instructions stored in the memory 1103 to implement the wake-up signal sending method provided by the embodiments described below. In an example, the processor 1101 can include one or more CPUs, such as CPU0 and CPU1. As an optional implementation manner, the quantum key distribution device 110 includes multiple processors, and can further include a processor 1104.

[0189] It should be noted that the quantum key distribution device 110 can be a desktop computer, a laptop computer, a network server, a mobile phone, a tablet computer, a wireless terminal, an embedded device, a chip system, or a device with a similar structure. In addition, the quantum key distribution device 110 can be a device with a different structure. Figure 11 The constituent structures shown in the embodiments of the present application do not constitute a limitation on the communication device, and the communication device can include more or fewer components than those shown, or combine certain components, or different component arrangements. Figure 11 The constituent structures shown in the embodiments of the present application do not constitute a limitation on the communication device, and the communication device can include more or fewer components than those shown, or combine certain components, or different component arrangements. Figure 11 The constituent structures shown in the embodiments of the present application do not constitute a limitation on the communication device, and the communication device can include more or fewer components than those shown, or combine certain components, or different component arrangements.

[0190] In the embodiments of the present application, the chip system can be composed of a chip, or can include a chip and other discrete devices.

[0191] Figure 12 A structural diagram of a quantum key distribution system provided by the embodiments of the present application is shown in FIG. 12. The quantum key distribution system can include a sending end 120, a light splitting device 121, and n receiving ends. N is an integer greater than 1. The function of the sending end 120 is the same as that of the quantum key distribution device 100 or the quantum key distribution device 110, which is not described herein. Figure 12

[0192] ​The embodiments of the present application further provide a computer readable storage medium. All or part of the processes in the above method embodiments can be instructed by a computer program to relevant hardware to complete, the program can be stored in the above computer readable storage medium, and the program can include the processes of the above method embodiments when executed. The computer readable storage medium can be the terminal of any of the preceding embodiments, such as an internal storage unit of a data sending terminal and / or a data receiving terminal, for example, a hard disk or a memory of the terminal. The above computer readable storage medium can also be an external storage device of the terminal, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the terminal. Further, the above computer readable storage medium can include both the internal storage unit and the external storage device of the terminal. The above computer readable storage medium is used to store the above computer program and other programs and data required by the terminal. The above computer readable storage medium can also be used to temporarily store data that has been output or will be output.

[0193] It should be noted that the terms "first" and "second" and the like in the specification, claims and drawings of the present application are used to distinguish different objects, and are not used to describe a particular order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units is not limited to the listed steps or units, but can optionally include steps or units not listed, or can optionally include other steps or units inherent to the process, method, product or device.

[0194] It should be understood that in the present application, "at least one" means one or more, "multiple" means two or more, "at least two" means two or three and more, and "and / or" is used to describe the association relationship of the associated objects, which means that there can be three relationships, for example, "A and / or B" can mean that there are three cases of only A, only B and A and B at the same time, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects. "At least one of the following" or similar expressions means any combination of these items, including any combination of single or multiple items. For example, at least one of a, b or c can mean a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b and c can be single or multiple.

[0195] It should be understood that, in the embodiments of the present application, "B corresponding to A" means that B is associated with A. For example, B can be determined according to A. It should also be understood that determining B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information. In addition, "connection" appearing in the embodiments of the present application means direct connection or indirect connection and various connection modes to achieve communication between devices, which is not limited in the embodiments of the present application.

[0196] "Transmit" appearing in the embodiments of the present application means bidirectional transmission containing sending and / or receiving actions, unless otherwise specified. Specifically, "transmit" in the embodiments of the present application contains sending of data, receiving of data, or sending of data and receiving of data. Or, data transmission herein includes uplink and / or downlink data transmission. Data can include channels and / or signals, uplink data transmission is uplink channel and / or uplink signal transmission, and downlink data transmission is downlink channel and / or downlink signal transmission. "Network" and "system" appearing in the embodiments of the present application express the same concept, and the quantum key distribution system is a communication network.

[0197] Through the description of the above embodiments, those skilled in the art can clearly understand that, for the convenience and brevity of description, only the grouping of the above functional modules is exemplified, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is grouped into different functional modules to complete all or part of the functions described above.

[0198] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented by other manners. For example, the device embodiments described above are only schematic, for example, the grouping of the modules or units is only a logical function grouping, and actual implementation can have another grouping manner, for example, a plurality of units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the shown or discussed ones can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0199] The units described as separate components can or can not be physically separate, and the components shown as units can be one physical unit or multiple physical units, that is, can be located in one place or can be distributed to multiple different places. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiments of the present application.

[0200] In addition, each function unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software function unit.

[0201] When the integrated unit is realized in the form of a software function unit and sold or used as an independent product, the integrated unit can be stored in a readable storage medium. Based on such an understanding, the technical solutions of the embodiments of the present application can be embodied in the form of a software product in essence or the part of the prior art that contributes to the technical solutions or the whole or part of the technical solutions. The software product is stored in a storage medium, and includes a plurality of instructions for causing an apparatus, such as a single-chip microcomputer, a chip, or a processor, to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various storage program codes, such as a U disk, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.

Claims

1. A quantum key distribution method, characterized by, The quantum key distribution method is applied to the i-th quantum key distribution of a quantum key distribution system, where i is an integer greater than or equal to 1; the quantum key distribution system includes one sending end and n receiving ends, where n is an integer greater than 1; the method includes: The sending end receives a first data sequence from each of the n receiving ends; the first data sequence includes part of the original key of the receiving end, and the original key of the receiving end is obtained according to the detection data obtained by the receiving end detecting a sub-light signal, the sub-light signal being obtained by splitting a modulated light signal by a light splitting device, and the modulated light signal being obtained by modulating a first light signal by the sending end according to a quantum random number; For any receiving end, the sending end calculates a secure key generation rate between the sending end and the receiving end according to the first data sequence and the second data sequence of m receiving ends, where the second data sequence includes part of the original key of the sending end; m is an integer greater than 1 and less than or equal to n; the m receiving ends are included in the n receiving ends; The sending end performs a security enhancement operation on the error-corrected key obtained by performing an error correction operation on the sending end and the receiving end to obtain a first final key shared by the sending end and the receiving end; the first final key is used for secure transmission of information between the sending end and the receiving end.

2. The method of claim 1, wherein, The calculation of the secure key generation rate between the sending end and the receiving end according to the first data sequence and the second data sequence of the m receiving ends includes: According to the first data sequence and the second data sequence of the m receiving ends, the data correlation between the sending end and the m receiving ends is calculated; the data correlation is used to represent the channel state of the quantum channel of the quantum key distribution system; The secure key generation rate is calculated according to the data correlation.

3. The method of claim 2, wherein, The calculation of the data correlation between the sending end and the m receiving ends includes: According to the first data sequence and the second data sequence of the m receiving ends, a covariance matrix is calculated.

4. The method of claim 1, wherein, The calculation of the secure key generation rate between the sending end and the receiving end according to the first data sequence and the second data sequence of the m receiving ends includes: According to the first data sequence and the second data sequence of the m receiving ends, a characteristic parameter is calculated, where the characteristic parameter includes equivalent noise and / or equivalent transmittance, the equivalent noise being used to represent various types of noise in a statistical form, and the equivalent transmittance being used to represent the signal transmittance of the quantum channel of the quantum key distribution system and / or a preset node combination in the quantum key distribution system as a whole; According to the characteristic parameter, a comparison relationship table is looked up to obtain the secure key generation rate between the sending end and the receiving end; the comparison relationship table includes the corresponding relationship between the characteristic parameter and the secure key generation rate.

5. The method according to any one of claims 1 to 4, characterized in that, The method further includes: The sending end and the receiving end perform the following error correction operation to obtain an error-corrected key: The sending end receives check information from the receiving end; the check information is encrypted by a second final key, in the case that i is greater than 1, the second final key is a final key obtained by performing the i-1th quantum key distribution between the sending end and the receiving end, and the check information includes a syndrome, which is calculated by the receiving end according to a third data sequence, and the third data sequence includes the remaining data in the original key of the receiving end except the first data sequence; The sending end decrypts the check information according to the second final key to obtain the syndrome; The sending end performs error correction decoding on a fourth data sequence according to the syndrome to obtain the error-corrected key; wherein the fourth data sequence includes the remaining data in the original key of the sending end except the second data sequence.

6. The method of claim 5, wherein, The n receiving ends are divided into multiple groups, and the channel quality difference of the channels corresponding to different receiving ends in the same group is less than a preset threshold; For different receiving ends in the same group, the error correction coding and decoding scheme between the sending end and different receiving ends in the same group is the same, and the error correction coding and decoding scheme corresponds to a first signal-to-noise ratio, and the first signal-to-noise ratio is the signal-to-noise ratio of the receiving end with the lower signal-to-noise ratio in the group.

7. The method of any one of claims 1-6, wherein: The light splitting device includes a light splitter and / or a wavelength division multiplexing module.

8. The method according to any one of claims 1 to 7, characterized in that, The quantum key distribution system adds an n+1th receiving end; the method further includes: The sending end sends a reference frame; wherein the reference frame includes a synchronization frame, and the synchronization frame is used to realize data synchronization between the n+1th receiving end and the sending end.

9. The method of claim 8, wherein, The method further includes: The sending end receives side information sent by the n+1th receiving end; the side information is used to calculate a final key between the sending end and the n+1th receiving end; The sending end adjusts the quantum key distribution timing and / or quantum key distribution resources of n+1 terminals including the n+1th receiving end in the quantum key distribution system according to the processing complexity of the side information and the time when the side information arrives at the sending end.

10. The method of claim 8 or 9, wherein: The pre-shared key of the n+1th receiving end is a key with a length of L configured to the n+1th terminal when the n+1th terminal is factory shipped; L is an integer greater than 1; or The pre-shared key of the n+1th receiving end is a key with a length of L artificially generated when the n+1th terminal is networked; or The pre-shared key of the n+1th receiving end is a key obtained after multiple quantum key distributions between the n+1th terminal and the sending end, and the length of the pre-shared key of the n+1th receiving end is greater than the key length L required for encrypting the syndrome.

11. The method of claim 10, wherein, The pre-shared key of the n+1th receiving end is a key obtained after multiple quantum key distributions between the n+1th terminal and the sending end, including: The final key obtained by executing the following process multiple times is determined as the pre-shared key of the n+1th receiving end: The sending end calculates a security key generation rate between the sending end and the n+1th terminal according to part of data in the original key of the n+1th receiving end and part of data in the original key of the sending end, performs a security enhancement operation on a post-error correction key obtained by performing an error correction operation between the sending end and the n+1th terminal according to the security key generation rate, and obtains a final key shared by the sending end and the n+1th terminal.

12. The method according to any one of claims 1 to 11, characterized in that, The nth receiving end in the quantum key distribution system is offline, and the method further comprises: The receiving end obtains an offline time of the nth receiving end, and the offline time is used to indicate that the nth receiving end is offline after the kth quantum key distribution, and the k is an integer greater than 1; The receiving end adjusts the quantum key distribution time sequence and / or quantum key distribution resource of the quantum key distribution system after the nth receiving end is offline according to the offline time of the nth receiving end; After the kth quantum key distribution is performed, quantum key distribution is performed between the receiving end and the receiving end by using the adjusted quantum key distribution time sequence and / or quantum key distribution resource.

13. A quantum key distribution device, characterized in that, The quantum key distribution device comprises: A receiving unit is configured to receive a first data sequence from each of the n receiving ends; the first data sequence comprises part of data in the original key of the receiving end, and the original key of the receiving end is obtained according to detection data obtained by the receiving end detecting a sub-light signal, wherein the sub-light signal is obtained by splitting a modulated light signal by a light splitting device, and the modulated light signal is obtained by modulating a first light signal by the sending end according to a quantum random number; A processing unit is configured to, for any receiving end, calculate a security key generation rate between the sending end and the receiving end according to the first data sequence of the m receiving ends and a second data sequence, wherein the second data sequence comprises part of data in the original key of the sending end; the m is an integer greater than 1 and less than or equal to the n; and the m receiving ends are included in the n receiving ends; According to the security key generation rate, a security enhancement operation is performed on a post-error correction key obtained by performing an error correction operation between the sending end and the receiving end, and a first final key shared by the sending end and the receiving end is obtained; the first final key is used for secure transmission of information between the sending end and the receiving end.

14. A quantum key distribution system, characterized by, The quantum key distribution system comprises a sending end and n receiving ends; the n is an integer greater than 1; The sending end is configured to receive a first data sequence from each of the n receiving ends; the first data sequence comprises part of data in the original key of the receiving end, and the original key of the receiving end is obtained according to detection data obtained by the receiving end detecting a sub-light signal, wherein the sub-light signal is obtained by splitting a modulated light signal by a light splitting device, and the modulated light signal is obtained by modulating a first light signal by the sending end according to a quantum random number; For any receiving end, a security key rate between the sending end and the receiving end is calculated according to a first data sequence of the m receiving ends and a second data sequence, wherein the second data sequence comprises part of data in an original key of the sending end; the m is an integer greater than 1 and less than or equal to the n; the m receiving ends are included in the n receiving ends; A security enhancement operation is performed on a post-error correction key obtained by performing an error correction operation on the sending end and the receiving end to obtain a first final key shared by the sending end and the receiving end; the first final key is used for secure transmission of information between the sending end and the receiving end.

15. A communications device, characterized by The communication device comprises a processor and a transceiver, and the processor and the transceiver are used to support the communication device to perform the method according to any one of claims 1-12.

16. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions, and when the computer instructions are run on a computer, the computer executes the method according to any one of claims 1-12.

17. A computer program product, characterised in that, The computer program product comprises computer instructions, and when the computer instructions are run on a computer, the computer executes the method according to any one of claims 1-12.

18. A chip, characterized by The chip is coupled with a memory, and is used to read and execute program instructions stored in the memory to implement the method according to any one of claims 1-12.

Citation Information

Patent Citations

  • Post-processing method for discrete modulation continuous variable quantum key distribution

    CN108306733A

  • QTTH system based on multi-core optical fiber mode division multiplexing, and transmission method

    CN109600221A