A measurement-device-independent continuous-variable quantum secret sharing method
Patent Information
- Application Number
- CN202311820556.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-27
- Publication Date
- 2026-09-08
- Estimated Expiration
- 2043-12-27
AI Technical Summary
然而,在实现过程中,由于实际测量设备的不完美性,可能会出现包括本振光抖动攻击、波长攻击、饱和攻击、偏振攻击等安全性问题,从而严重威胁CVQSS系统的实际安全性;另一方面,这些CVQSS方案对用户排列方式具有限制,需要用户通过同一根光纤进行连接、当有新用户加入时会引入新的过噪声;此外,建立密钥的过程中用户需要多次发送相干态和公布数据,首先,每个用户需要多次发送相干态以建立足够多的相关数据,且当Dealer与各个用户共享密钥时,其他用户均需要公布部分数据,则每个用户均要公布n-1次自己的部分数据供其他用户来生成密钥;上述过程繁琐且公布的数据均需舍去;此外,每增加一个用户均会带来新的过噪声造成系统性能降低
[0062] The measurement-device-independent continuous variable quantum secret sharing method provided by this invention achieves measurement-device-independent continuous variable quantum secret sharing by introducing a third party to perform the measurement and arranging a balanced beam splitter and post-processing steps within the third party; the security and efficiency of this invention are improved.
Smart Images

Figure CN117749374B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of communication security technology, and specifically relates to a measurement device-independent continuous variable quantum secret sharing method. Background Technology
[0002] Secret sharing has important practical applications in cryptography. In a secret sharing protocol, the message sender (Dealer) distributes message M to n users, such that at least k (k≤n) users must cooperate to decipher the message. This is called a (k,n) threshold scheme. For an (n,n) threshold secret sharing protocol, it means that all n participants must cooperate to decipher the Dealer's message.
[0003] If the Dealer shares a separate key K with each user i Given (i = 1, 2, ..., n), and the key length is the same as the message length, an (n, n) threshold secret sharing protocol can be implemented as follows: The Dealer first generates a new key: And then through the expression The message M is encrypted to generate ciphertext E, and then the Dealer announces ciphertext E to all users; ciphertext E can only be decoded by the entire user group when all users cooperate.
[0004] The security of the above scheme relies on the security of the key. Continuous-variable quantum key distribution (CVQKD), based on the fundamental principles of quantum mechanics, can theoretically achieve unconditionally secure key distribution. Therefore, to improve the security of secret sharing, CVQKD can be used to generate keys, extending classical secret sharing to the quantum realm. This secret sharing scheme is called continuous-variable quantum secret sharing (CVQSS). In some CVQSS schemes, to improve key distribution efficiency, the coherent state prepared by the first user is passed sequentially to other users. Each user couples its own prepared coherent state into the same temporal-space mode as the first user's prepared coherent state. Finally, this mode is received and measured by the Dealer. The measurement result is the cumulative amplitude and phase of the coherent states prepared by all users. Through data post-processing, the Dealer can share different keys with each user.
[0005] In these CVQSS schemes, the Dealer is typically considered a legitimate receiver, assumed to be immune to eavesdropping attacks, and is used to receive and probe the quantum states sent by users, ignoring practical security issues related to the measurement equipment. However, in practice, due to the imperfections of actual measurement equipment, security issues such as local oscillator jitter attacks, wavelength attacks, saturation attacks, and polarization attacks may arise, seriously threatening the actual security of the CVQSS system. Furthermore, these CVQSS schemes impose restrictions on user arrangement, requiring users to connect via the same optical fiber; the addition of new users introduces new noise. Additionally, during key generation, users need to send coherent states and publish data multiple times. First, each user needs to send coherent states multiple times to build sufficient relevant data. When the Dealer shares keys with other users, each user needs to publish some data, meaning each user must publish their partial data n-1 times for other users to generate keys. This process is cumbersome, and all published data must be discarded. Moreover, each additional user introduces new noise, degrading system performance.
[0006] In summary, existing CVQSS schemes face numerous challenges in practical applications. These challenges cover security aspects, including attacks on the local oscillator light jitter and wavelength attacks targeting actual measurement equipment. They also involve protocol implementation issues, such as limitations on user arrangement, cumbersome quantum state transmission and data publication processes, and noise introduced by new users leading to system performance degradation. Summary of the Invention
[0007] The purpose of this invention is to provide a measurement device-independent continuous variable quantum secret sharing method that improves security and efficiency.
[0008] The measurement device-independent continuous variable quantum secret sharing method provided by this invention includes the following steps:
[0009] S1. The message sender, Dealer, and n users participate in the preparation process, respectively preparing coherent states;
[0010] S2. Dealer and all users send the coherent state prepared in step S1 to the third party Charlie;
[0011] S3. In step S2, the coherent state sent by the Dealer is processed by several balanced beam splitters (BS) inside Charlie to form a coherent state with the same number of users. Bell measurements (BSM) are then performed with the coherent states input by the users, and the measurement results are broadcast.
[0012] S4.Dealer copies its own coherent state orthogonal component data until the number of copies is the same as the number of users, and uses it to share keys with users;
[0013] S5. For the i-th user User i The key generation process is described, based on the measurement results broadcast in step S3, between the Dealer and the User. i By publishing some of the corresponding data, the corresponding channel transmittance can be estimated.
[0014] S6. Using the measurement results obtained in step S3, Dealer performs data replacement processing to make the data consistent with User's. i The data is correlated, and a secure key rate analysis is used to estimate the lower bound of the secure key rate for the corresponding link.
[0015] S7. Repeat steps S5-S6 to obtain the key rates for all users and select the minimum value as the key rate for the entire secret sharing protocol;
[0016] S8. Using the key rate of the entire secret sharing protocol determined in step S7, when the set conditions are met, the Dealer shares a different key with each user through data post-processing;
[0017] S9. A final security key is generated using the key shared in step S8. The Dealer uses the final security key to encrypt the shared message, thereby realizing the secret sharing protocol.
[0018] Step S1, where the message sender Dealer and n users participate in the preparation process, respectively prepare coherent states, specifically includes:
[0019] The dealer and each user separately prepare coherent states, and all prepared coherent states use the same modulation variance V. s ;
[0020] For coherent states Orthogonal components are defined as follows:
[0021]
[0022] The input mode of the transmitted coherent state is described by the following formula:
[0023]
[0024] in, This indicates that the value has zero mean and zero variance V. s The classical encoded variables of the central Gaussian distribution; Indicates vacuum mode; U represents user; D represents dealer;
[0025] Step S2, which involves the Dealer and all users sending the coherent state prepared in step S1 to the third party Charlie, specifically includes:
[0026] The coherent states prepared by the Dealer and each user in step S1 are sent to a third party, Charlie, through an untrusted quantum channel; assume that the above process is subject to an entanglement cloning attack.
[0027] In step S3, the coherent state sent by the Dealer in step S2 is processed by several balanced beam splitters (BS) within Charlie to form a coherent state with the same number of users. Bell measurements (BSMs) are then performed with the coherent states input by the users, and the measurement results are broadcast. Specifically, this includes:
[0028] Assume the i-th user is User i The coherent states of the Dealer and the coherent states of the Dealer after k BS are processed by BSM. The measurement results under the entangled cloning attack condition are shown below:
[0029]
[0030]
[0031] in, T represents the orthogonal components of the measurement results. D T represents the transmittance of the Dealer-to-Charlie channel; Ui User i Transmittance to the Charlie channel; This represents the orthogonal component of the coherent state sent by the Dealer; User i represents the i-th user. i The orthogonal components of the transmitted coherent state; E1 represents the mode transmitted by the eavesdropper Eve to the Dealer-Charlie channel; E2 represents the mode transmitted by the eavesdropper Eve to the User. i The mode of transmission to the Charlie channel; These are the orthogonal components of E1 and E2, respectively;
[0032] The third party, Charlie, broadcasts the measurement results obtained above to the User. i and Dealer;
[0033] Step S4, where the Dealer copies its own coherent state's orthogonal component data until the number of copies matches the number of users, and uses this data to share keys with users, specifically includes:
[0034] The dealer will use its own coherent orthogonal component data. A copy of n is defined as:
[0035]
[0036] Dealer uses the above data to share a key with n users;
[0037] Step S5 describes the action taken for the i-th user. i The key generation process is described, based on the measurement results broadcast in step S3, between the Dealer and the User. i By publishing some of the corresponding data, the corresponding channel transmittance is estimated, specifically including:
[0038] Dealer and User i By publishing some relevant data and Charlie's measurement results, the corresponding channel transmittance T is estimated. D T Ui , among which, T D T represents the transmittance of the Dealer-to-Charlie channel; Ui User i Transmittance to the Charlie channel;
[0039] The data disclosed above will be discarded after step S5.
[0040] Step S6 describes using the measurement results obtained in step S3. The Dealer then performs data replacement processing to ensure the data matches the User's data. i The data is correlated, and secure key rate analysis is used to estimate the lower bound of the secure key rate for the corresponding link, specifically including:
[0041] According to the measurement results published by Charlie Dealer's data for the i-th copy Perform the replacement process and record it as follows. As shown below:
[0042]
[0043] The results are shown below:
[0044]
[0045]
[0046] but: For User i Estimation of the encoding;
[0047] Estimating the lower bound R of the security key rate using security key rate analysis of MDI-CVQKD i ;
[0048] Step S7 involves repeating steps S5-S6 to obtain the key rates for all users and selecting the minimum value as the key rate for the entire secret sharing protocol. Specifically, this includes:
[0049] For n users, by repeating steps S5-S6 n times, the Dealer can obtain n key rates {R1, R2, ..., R...} n Let R be the minimum value among the n key rates, representing the key rate of the entire QSS protocol. The definition is as follows:
[0050] R = min{R1,R2,…,R} n}
[0051] Step S8, which uses the key rate of the entire secret sharing protocol determined in step S7, enables the Dealer to share a different key with each user through data post-processing when the set conditions are met. Specifically, this includes:
[0052] Using the key rate R determined in step S7, if the key rate is greater than 0, the Dealer can use the remaining unpublished original data to share different keys with each user; if the key rate is less than or equal to 0, the Dealer cannot use the remaining unpublished original data to share different keys with each user, and steps S1-S7 need to be repeated.
[0053] For each link, by generating a key from previously undisclosed related data through reverse negotiation, the Dealer and each user share an independent key; the classic information flows from the Dealer to the user, and the above process can be completed without the user's cooperation.
[0054] Step S9 involves generating a final security key using the key shared in step S8. The Dealer then uses this final security key to encrypt the shared message, thereby implementing the secret sharing protocol. Specifically, this includes:
[0055] Assume the key shared by the Dealer and each user is {K1, K2, ..., K}. n};
[0056] The Dealer first generates a new key, with the key formula shown below:
[0057]
[0058] in, This indicates modulo 2 addition processing;
[0059] Then, the plaintext M is encrypted using K to generate the ciphertext E, as shown in the following formula:
[0060]
[0061] Therefore, only through collaboration among n users can K be determined, thereby decrypting E and obtaining the plaintext M;
[0062] The measurement-device-independent continuous variable quantum secret sharing method provided by this invention achieves measurement-device-independent continuous variable quantum secret sharing by introducing a third party to perform the measurement and arranging a balanced beam splitter and post-processing steps within the third party; the security and efficiency of this invention are improved. Attached Figure Description
[0063] Figure 1 This is a schematic diagram of the method flow of the present invention.
[0064] Figure 2 This is a schematic diagram of the entanglement equivalent model of the method of the present invention when there are only two users.
[0065] Figure 3 This is a schematic diagram of the entanglement equivalent model under general conditions of the method of the present invention.
[0066] Figure 4 This is a schematic diagram illustrating the performance of the method of the present invention. Detailed Implementation
[0067] like Figure 1 The diagram shown is a flowchart of the method of the present invention: The measurement device-independent continuous variable quantum secret sharing method provided by the present invention includes the following steps:
[0068] S1. The message sender (Dealer) and n users participate in the preparation process, each preparing a coherent state; specifically including:
[0069] The dealer and each user separately prepare coherent states, and all prepared coherent states use the same modulation variance V. s ;
[0070] For coherent states Orthogonal components are defined as follows:
[0071]
[0072] The input mode of the transmitted coherent state is described by the following formula:
[0073]
[0074] in, This indicates that the value has zero mean and zero variance V. s The classical encoded variables of the central Gaussian distribution; Indicates vacuum mode; U represents user; D represents dealer;
[0075] S2. Dealer and all users send the coherent state prepared in step S1 to the third party Charlie; specifically including:
[0076] The coherent states prepared by the Dealer and each user in step S1 are sent to a third party, Charlie, through an untrusted quantum channel; assume that the above process is subject to an entanglement cloning attack.
[0077] S3. In step S2, the coherent state sent by the Dealer is processed by several balanced beam splitters (BS) within Charlie to form a coherent state with the same number of users. Bell measurements (BSMs) are then performed with the user-input coherent states, and the measurement results are broadcast. Specifically, this includes:
[0078] Assume the i-th user is User i The coherent states of the Dealer and the coherent states of the Dealer after k BS are processed by BSM. The measurement results under the entangled cloning attack condition are shown below:
[0079]
[0080]
[0081] in, T represents the orthogonal components of the measurement results. D T represents the transmittance of the Dealer-to-Charlie channel; Ui User i Transmittance to the Charlie channel; This represents the orthogonal component of the coherent state sent by the Dealer; User i represents the i-th user. i The orthogonal components of the transmitted coherent state; E1 represents the mode transmitted by the eavesdropper Eve to the Dealer-Charlie channel; E2 represents the mode transmitted by the eavesdropper Eve to the User. i The mode of transmission to the Charlie channel; These are the orthogonal components of E1 and E2, respectively;
[0082] The third party, Charlie, broadcasts the measurement results obtained above to the User. i and Dealer;
[0083] like Figure 2The diagram shows the entanglement equivalent model of the method of the present invention when there are only two users: the coherent state sent by the Dealer is processed by a BS to form two modes, which are then subjected to BSM with the coherent states of the two users respectively. The diagram illustrates the entanglement cloning attack; as shown... Figure 3 The diagram shows a typical entanglement equivalent model of the method of this invention: the coherent state sent by the Dealer forms a 2 after passing through several BSs. t -1 patterns, respectively with 2 t -1 user's coherent state is used for BSM; in Figure 3 It also includes 2 t The situation when the user is present;
[0084] S4.Dealer replicates its own coherent state's orthogonal component data until the number of copies matches the number of users, and then uses this data to share keys with users; specifically, this includes:
[0085] The Dealer will use its own coherent state regularized component data A copy of n is defined as:
[0086]
[0087] Dealer uses the above data to share a key with n users;
[0088] S5. For the i-th user User i The key generation process is described, based on the measurement results broadcast in step S3, between the Dealer and the User. i By publishing some of the corresponding data, the corresponding channel transmittance is estimated; specifically including:
[0089] Dealer and User i By publishing some relevant data and Charlie's measurement results, the corresponding channel transmittance T is estimated. D T Ui , among which, T D T represents the transmittance of the Dealer-to-Charlie channel; Ui User i Transmittance to the Charlie channel;
[0090] The data disclosed above will be discarded after step S5.
[0091] S6. Using the measurement results obtained in step S3, Dealer performs data replacement processing to make the data consistent with User's. i The data is correlated, and a secure key rate analysis is used to estimate the lower bound of the secure key rate for the corresponding link; specifically including:
[0092] According to the measurement results published by Charlie Dealer's data for the i-th copy Perform the replacement process and record it as follows. As shown below:
[0093]
[0094] The results are shown below:
[0095]
[0096]
[0097] but: For User i Estimation of the encoding;
[0098] Estimating the lower bound R of the security key rate using security key rate analysis of MDI-CVQKD i ;
[0099] S7. Repeat steps S5-S6 to obtain the key rates for all users, and select the minimum value as the key rate for the entire secret sharing protocol; specifically including:
[0100] For n users, repeat steps S5-S6 n times, and the message sender can obtain n key rates {R1, R2, ..., R...} n Let R be the minimum value among the n key rates, representing the key rate of the entire QSS protocol. The definition is as follows:
[0101] R = min{R1,R2,…,R} n}
[0102] S8. Using the key rate of the entire secret sharing protocol determined in step S7, when the set conditions are met, data post-processing enables the Dealer to share a different key with each user; specifically including:
[0103] Using the key rate R determined in step S7, if the key rate is greater than 0, the Dealer can use the remaining unpublished original data to share different keys with each user; if the key rate is less than or equal to 0, the Dealer cannot use the remaining unpublished original data to share different keys with each user, and steps S1-S7 need to be repeated.
[0104] For each link, by generating a key from previously undisclosed related data through reverse negotiation, the Dealer and each user share an independent key; the classic information flows from the Dealer to the user, and the above process can be completed without the user's cooperation.
[0105] S9. A final security key is generated using the key shared in step S8. The Dealer uses this final security key to encrypt the shared message, thereby implementing the secret sharing protocol; specifically including:
[0106] Assume the key shared by the Dealer and each user is {K1, K2, ..., K}. n};
[0107] The Dealer first generates a new key, with the key formula shown below:
[0108]
[0109] in, This indicates modulo 2 addition processing;
[0110] Then, the plaintext M is encrypted using K to generate the ciphertext E, as shown in the following formula:
[0111]
[0112] Therefore, only through collaboration among n users can K be determined, thereby decrypting E and obtaining the plaintext M;
[0113] like Figure 4 The figure shows a performance diagram of the method of the present invention: the horizontal axis L in the figure represents the distance from the user to the third party Charlie, the vertical axis represents the key rate, and n represents the number of users.
Claims
1. A measurement device-independent continuous variable quantum secret sharing method, comprising the following steps: S1. The message sender and several users participate in the preparation process, and prepare coherent states respectively; S2. The message sender and all users send the coherent state prepared in step S1 to a third party; S3. In step S2, the coherent state sent by the message sender is transformed into a coherent state with the same number of users through several balanced beam splitters within a third party. Bell measurements are then performed on the coherent states input by the users, and the measurement results are broadcast. S4. The message sender copies its own coherent state orthogonal component data until the number of copies is the same as the number of users, and uses it to share the key with the users; S5. For each user, the key generation process is introduced. Based on the measurement results broadcast in step S3, the message sender and each user estimate the corresponding channel transmittance by publishing the corresponding data. S6. Using the measurement results obtained in step S3, the message sender associates the data with the user's data through data replacement processing, and uses security key rate analysis to estimate the lower bound of the security key rate of the corresponding link. S7. Repeat steps S5-S6 to obtain the key rates for all users and select the minimum value as the key rate for the entire secret sharing protocol; S8. Using the key rate of the entire secret sharing protocol determined in step S7, when the set conditions are met, the message sender shares a different key with each user through data post-processing; S9. A final security key is generated using the key shared in step S8. The message sender uses the final security key to encrypt the shared message, thereby realizing the secret sharing protocol.
2. The measurement device-independent continuous variable quantum secret sharing method according to claim 1, characterized in that... Step S1, in which the message sender and the user participate in the preparation process, respectively prepare coherent states, specifically includes: The message sender and each user prepare coherent states separately, and all prepared coherent states use the same modulation variance V. s ; For coherent states Orthogonal components are defined as follows: The input mode of the transmitted coherent state is described by the following formula: in, This indicates that the value has zero mean and zero variance V. s The classical encoded variables of the central Gaussian distribution; Indicates vacuum mode; U represents user; D represents dealer.
3. The measurement device-independent continuous variable quantum secret sharing method according to claim 2, characterized in that... Step S2, which involves the message sender and all users sending the coherent state prepared in step S1 to a third party, specifically includes: The coherent states prepared by the Dealer and each user in step S1 are sent to a third party, Charlie, through an untrusted quantum channel; assume that the above process is subject to an entanglement cloning attack.
4. The measurement device-independent continuous variable quantum secret sharing method according to claim 3, characterized in that... In step S3, the coherent state sent by the message sender in step S2 is processed by several balanced beam splitters within a third party to form a coherent state with the same number of users. Bell measurements are then performed on each of these coherent states with the user-input coherent states, and the measurement results are broadcast. Specifically, this includes: Assume the i-th user is User i The coherent state of the message sender and the coherent state of the message sender after passing through k balanced beam splitters are subjected to Bell measurement processing. The measurement results under the condition of entanglement cloning attack are shown below: in, T represents the orthogonal components of the measurement results. D T represents the transmittance of the Dealer-to-Charlie channel; Ui User i Transmittance to the Charlie channel; This represents the orthogonal component of the coherent state sent by the Dealer; User i represents the i-th user. i The orthogonal components of the transmitted coherent state; E1 represents the mode transmitted by the eavesdropper Eve to the Dealer-Charlie channel; E2 represents the mode transmitted by the eavesdropper Eve to the User. i The mode of transmission to the Charlie channel; These are the orthogonal components of E1 and E2, respectively; The third party, Charlie, broadcasts the measurement results obtained above to the User. i And the message sender.
5. The measurement device-independent continuous variable quantum secret sharing method according to claim 4, characterized in that... Step S4, where the message sender copies its own coherent state orthogonal component data until the number of copies is the same as the number of users, and uses this data to share a key with the users, specifically includes: The message sender will send its own coherent state regular component data. A copy of n is defined as: The message sender uses the above data to share a key with n users.
6. The measurement device-independent continuous variable quantum secret sharing method according to claim 5, characterized in that... Step S5 describes the key generation process for each user. Based on the measurement results broadcast in step S3, the message sender and each user estimate the corresponding channel transmittance by publishing the corresponding data. Specifically, this includes: Message sender and User i By publishing some relevant data and Charlie's measurement results, the corresponding channel transmittance T is estimated. D T Ui , among which, T D T represents the transmittance from the message sender to the third-party Charlie channel. Ui User i Transmission rate to a third-party Charlie channel; The data disclosed above will be discarded after step S5.
7. The measurement device-independent continuous variable quantum secret sharing method according to claim 6, characterized in that... Step S6, using the measurement results obtained in step S3, involves the message sender associating the data with the user's data through data replacement processing, and estimating the lower bound of the security key rate for the corresponding link using security key rate analysis. Specifically, this includes: According to the measurement results published by Charlie Dealer's data for the i-th copy Perform the replacement process and record it as follows. As shown below: The results are shown below: but: For User i Estimation of the encoding; Estimating the lower bound R of the security key rate using security key rate analysis of MDI-CVQKD i .
8. The measurement device-independent continuous variable quantum secret sharing method according to claim 7, characterized in that... Step S7 involves repeating steps S5-S6 to obtain the key rates for all users and selecting the minimum value as the key rate for the entire secret sharing protocol. Specifically, this includes: For n users, repeat steps S5-S6 n times, and the message sender can obtain n key rates {R1, R2, ..., R...} n Let R be the minimum value among the n key rates, representing the key rate of the entire QSS protocol. The definition is as follows: R=min{R1,R2,…,R n }。 9. The measurement device-independent continuous variable quantum secret sharing method according to claim 8, characterized in that... Step S8, which uses the key rate of the entire secret sharing protocol determined in step S7, enables the message sender to share a different key with each user through data post-processing when the set conditions are met. Specifically, this includes: Using the key rate R determined in step S7, if the key rate is greater than 0, the message sender can use the remaining unpublished original data to share different keys with each user; if the key rate is less than or equal to 0, the message sender cannot use the remaining unpublished original data to share different keys with each user, and steps S1-S7 need to be repeated. For each link, by generating a key from undisclosed related data through reverse negotiation, the Dealer and each user share an independent key; whereby classic information flows from the Dealer to the user, the above process can be completed without the user's cooperation.
10. The measurement device-independent continuous variable quantum secret sharing method according to claim 9, characterized in that... Step S9 involves generating a final security key using the key shared in step S8. The message sender then uses this final security key to encrypt the shared message, thereby implementing the secret sharing protocol. Specifically, this includes: Assume the key shared by the message sender and all users is {K1, K2, ..., K}. n }; The message sender first generates a new key, the key formula of which is shown below: in, This indicates modulo 2 addition processing; Then, the plaintext M is encrypted using K to generate the ciphertext E, as shown in the following formula: Therefore, only through collaboration among n users can K be determined, thereby decrypting E and obtaining the plaintext M.