A quantum encryption device that can be configured with multiple functions

By designing a quantum encryption device that integrates quantum key distribution, quantum private query, quantum secret sharing and quantum digital signature functions, the problem of single functions and difficulty in participation in the existing technology is solved, and efficient and low-cost multifunctional quantum communication is achieved.

CN118101196BActive Publication Date: 2025-05-06NANJING UNIV OF POSTS & TELECOMM
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410423654.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-09
Publication Date
2025-05-06
Estimated Expiration
2044-04-09

AI Technical Summary

Technical Problem

Most existing quantum encryption products can only realize the quantum key distribution QKD with a single function, and cannot achieve the integration of multiple functions and multi-party participation.

Method used

A quantum encryption device that can be configured with multiple functions is designed, integrating the functions of quantum key distribution QKD, quantum private query QPQ, quantum secret sharing QSS and quantum digital signature QDS. Through flexible module design and modulation methods, multi-function coexistence and multi-party participation are achieved.

Benefits of technology

It realizes that a single quantum cryptographic machine supports multiple functions at the same time, improves efficiency, reduces costs, provides stronger privacy protection, confidentiality and security, and does not require polarization calibration during communication, ensuring the stability of the transmission process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118101196B_ABST
    Figure CN118101196B_ABST
Patent Text Reader

Abstract

The present invention proposes a quantum encryption device that can be configured with multiple functions, including a transmitting end and a receiving end; the transmitting end includes a laser, an intensity modulator IM1, an F-M interference ring a, an intensity modulator IM2, a phase modulator PM1, an optical attenuator, a wavelength division multiplexing module and a Sagnac ring a; the receiving end includes a demultiplexing module, a Sagnac ring b, an F-M interference ring b, and a detector; a quantum cryptographic machine is used to realize four functions, which greatly improves efficiency and reduces costs. Among them, quantum key distribution QKD can be used in complex communication scenarios with eavesdropping, quantum secret sharing QSS can provide high confidentiality and security for multi-party secret sharing, quantum private query QPQ can query the database in a distributed environment, providing stronger privacy protection, and quantum digital signature QDS can enhance the verification of message integrity, non-repudiation and non-forgeability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the fields of quantum communication, quantum cryptography and quantum security technology, and in particular relates to a quantum encryption device that can be configured with multiple functions, which is applied to quantum key distribution (QKD), quantum private query (QPQ), quantum secret sharing (QSS) and quantum digital signature (QDS). Background Art

[0002] The background and development history of these four functions will be explained below.

[0003] Quantum key distribution (QKD) is the earliest researched and most mature part of quantum cryptography. In 1900, the concept of "quantum" was proposed, and quantum mechanics was born. In 1984, the BB84 protocol was proposed, and quantum cryptography was officially born. Since then, a series of quantum key distribution (QKD) protocols have been proposed, and quantum key distribution (QKD) has entered a rapid development stage. In 2016, the "Mozi" quantum science experimental satellite was launched. In 2021, the team of the University of Science and Technology of China demonstrated a space-ground integrated quantum communication network based on the satellite.

[0004] The application of quantum encryption is not limited to quantum key distribution QKD. Other more extensive functional applications have also been proposed. Quantum private query is a way of retrieving private information. In 2008, the first quantum private query QPQ protocol was proposed by V.Giovannet, and several variants were proposed later. Quantum private query QPQ allows for simple linear optical implementation, using the momentum (or time slot) of the photon as the address qubit and its polarization as the bus qubit. In 2011, L.Olejnik proposed an improved protocol that is more efficient in terms of communication complexity and number of rounds, while providing clear privacy parameters. In the same year, a new quantum private query QPQ protocol based on the SARG04 protocol was proposed. Since then, different versions of quantum private query QPQ based on quantum key distribution QKD have been proposed one after another.

[0005] In addition, quantum secret sharing QSS can be seen as a direct application of quantum key distribution QKD. Quantum secret sharing QSS is a function that prevents secrets from being too concentrated to achieve risk dispersion. In 1999, Hillery et al. proposed the first quantum secret sharing QSS protocol using the entanglement of GHZ. In 2014, Bell et al. realized quantum secret sharing QSS based on quantum information of graph states. In 2021, a CV-quantum secret sharing QSS protocol based on discrete modulated coherent states was proposed.

[0006] Quantum digital signatures (QDS) are designed to provide information-theoretic security for legitimate users (Alice, Bob, and Charlie). The first quantum digital signature (QDS) protocol was proposed by Gottesman and Chuang in 2001. It requires non-destructive state comparison, long-term quantum storage, and secure quantum channels. Subsequently, in 2016, Wallden et al. proposed the idea and scheme of using quantum key distribution (QKD) protocol to implement quantum digital signatures (QDS), which greatly facilitated the implementation of quantum digital signatures (QDS). In the same year, Amiri et al. proposed a quantum digital signature (QDS) scheme that does not require a secure quantum channel, and gave a general model of decoy state quantum digital signatures (QDS), making quantum digital signatures (QDS) more practical.

[0007] Most of the quantum encryption products on the market currently can only realize a single quantum key distribution QKD function. If multiple functions are required, multiple devices are required, and multi-party participation is not possible. Summary of the invention

[0008] The technical problem to be solved by the present invention is to provide a quantum encryption device that can be configured with multiple functions, including a transmitting end and a receiving end; the transmitting end includes a laser, an intensity modulator IM1, an FM interference ring a, an intensity modulator IM2, a phase modulator PM1, an optical attenuator, a wavelength division multiplexing module and a Sagnac ring a; the laser is used to generate laser light; the intensity modulator IM1 randomly modulates the laser light into three quantum state light pulses, namely, a signal state, a decoy state and a vacuum state; then the light pulse passes through the FM interference ring a to split a light pulse into two light pulses one in front and one behind, and the two light pulses after chopped are chopped by the intensity modulator IM2; the FM interference ring a includes a 50:50 beam splitter and two Faraday rotators;

[0009] The pulse of intensity modulation IM2 passes through phase modulator PM1 for phase modulation, then passes through optical attenuator and wavelength division multiplexing module, and then is sent to the receiving end through Sagnac loop a; the Sagnac loop a includes single polarization phase modulator PM2, polarization beam splitter and Faraday rotator;

[0010] The receiving end includes a wavelength division demultiplexing module, a Sagnac loop b, an FM interference loop b, and a detector;

[0011] The optical pulse received by the receiving end first passes through the demultiplexing module, then is demodulated by the Sagnac loop b, and the pulse is interfered by the FM interferometer loop b, and finally reaches the detector. The Sagnac loop b includes a single polarization phase modulator PM, a polarization beam splitter and a Faraday rotator; the FM interferometer loop b includes a 50:50 beam splitter and two Faraday rotators.

[0012] Furthermore, in the process of realizing quantum key distribution QKD, the transmitting end is Alice and the receiving end is Bob; at Alice, the three amplitudes of the electrical signal input to the intensity modulator IM1 correspond to the signal state, the decoy state and the vacuum state respectively. When the vacuum state is selected, the intensity modulator IM1 uses the maximum attenuation and turns off the laser at the same time. The intensity modulator IM2 always allows both the front and rear pulses to pass. The four amplitudes of the electrical signal input to the phase modulator PM1 at Alice correspond to the four phases of the phase modulator PM1 at the transmitting end, 0, π / 2, π and 3π / 2; the four amplitudes of the electrical signal input to the phase modulator PM at Bob correspond to the four phases of the phase modulator PM at the receiving end, 0, π / 2, π and 3π / 2 respectively.

[0013] Furthermore, based on the quantum key distribution QKD process, the security key rate R is written as:

[0014]

[0015] Among them, f(E μ ) represents the error correction efficiency; H2(x) is the binary entropy function, which is expressed as:

[0016] H2(x)=-xlog2x-(1-x)log2(1-x) (6)

[0017] If the light source uses a weak coherent light source, the gain Q μ and the quantum bit error rate E μ The expression of is given by:

[0018] Q μ =Y0+1-e -ημ , (7)

[0019] E μ Q μ =e0Y0+e Det (1-e -ημ ) (8)

[0020] Among them, e0 is the error probability of background light, Y0 is the dark count rate of the detector, and e Det is the background bit error rate, η is the transmission efficiency between Alice and Bob;

[0021] The relationship between η and the distance L between Alice and Bob is:

[0022] η=η D 10 -αL / 10 (9)

[0023] Among them, η D is the detection efficiency of the single-photon detector, α is the loss coefficient of the optical fiber;

[0024] is the lower bound of the single-photon gain, and its expression is given by:

[0025]

[0026] is the lower bound of the zero photon count rate, and its expression is given by the following formula:

[0027]

[0028] is the upper bound of the single photon bit error rate, and its expression is given by the following formula:

[0029]

[0030] Among them, Y1 L is the lower bound of the single photon count rate, and its expression is given by the following formula:

[0031]

[0032] Furthermore, in the quantum private query QPQ process, the sending end is Alice and the receiving end is Bob; at Alice, the intensity modulator IM1 is used to realize the modulation of the signal state and the decoy state, and the three amplitudes of the electrical signal input to the intensity modulator IM1 correspond to the signal state, the decoy state and the vacuum state respectively; when the vacuum state is selected, IM1 uses the maximum attenuation and turns off the laser at the same time; the intensity modulator IM2 always allows both the front and rear pulses to pass; the four amplitudes of the electrical signal input to PM1 at Alice correspond to the four phases of PM1 at the sending end, 0, π / 2, π and 3π / 2 respectively; the four amplitudes of the electrical signal input to the phase modulator PM at Bob correspond to the four phases of the phase modulator PM at the receiving end, 0, π / 2, π and 3π / 2 respectively.

[0033] Furthermore, the process of executing the SARG04 protocol is as follows: Bob selects k×N bits from the long key, where k is a security metric; divides it into k subsequences of length N, and then takes XOR to dilute the number of bits known by Alice; since Alice needs to know every element in the XOR to get the final result, the probability that Alice knows each bit is (1 / 4) k ; Therefore, Alice knows that the number of bits of the key of length N satisfies the expectation Poisson distribution; if Alice does not receive any key, the key distribution process needs to be re-executed.

[0034] Furthermore, the final query process of quantum private query QPQ is as follows: all outputs of the database held by Bob form a sequence C; if Alice wants to query the jth bit of C, and Alice knows the i-th bit of the final key, Alice submits (ji)modN to Bob; Bob shifts the final key to the right by (ji)modN bits, and then performs a bitwise XOR operation with C to generate a ciphertext; then, Bob discloses the ciphertext to Alice; since Alice knows the j-th bit of the key after the shift and the j-th ciphertext, Alice performs an XOR operation on the i-th key she knows and the j-th ciphertext to understand the j-th database information.

[0035] Furthermore, the quantum secret sharing QSS protocol process based on the quantum encryption device is as follows: Alice and Charlie are both transmitting ends, Alice controls the laser, intensity modulator IM1, FM interference ring a, intensity modulator IM2, phase modulator PM1, optical attenuator, wavelength division multiplexing module, and Charlie controls Sagnac ring a; Alice uses intensity modulator IM1 to realize modulation of signal state and decoy state, and the three amplitudes of the electrical signal input to the intensity modulator IM1 correspond to the signal state, decoy state and vacuum state respectively; when the vacuum state is selected, the intensity modulator IM1 uses maximum attenuation and turns off the laser at the same time; the intensity modulator IM2 always allows the front and rear pulses to pass; the four amplitudes of the electrical signal input to the phase modulator PM1 at the Alice end correspond to the four phases of 0, π / 2, π and 3π / 2 of the phase modulator PM1 at the transmitting end, and the two amplitudes of the electrical signal input to the phase modulator PM2 in the Sagnac ring at the Charlie end are 0 and π / 2 respectively.

[0036] Furthermore, the security key rate R of the quantum secret sharing QSS protocol is written as:

[0037] R=Q μ (1-f e H2(E μ )-H2(E p )) (19)

[0038] Among them, f e represents the error correction efficiency; H2(x) is the binary entropy function, and its expression is:

[0039] H2(x)=-xlog2 x-(1-x)log2(1-x) (20)

[0040] If the light source is a weak coherent light source (WCS), the gain Q μ and the quantum bit error rate E μ The expression of is given by:

[0041] Qμ =(1-p d )[1-(1-2p d ) -2μη ] (twenty one)

[0042] E μ Q μ =e d (1-p d )[1-(1-p d ) -2μη ]+(1-e d ) d (1-p d ) -2μη (twenty two)

[0043] Among them, p d is the dark count rate of the detector, e d is the background bit error rate, η is the transmission efficiency between Alice or Charlie and Bob; L is the distance between Alice or Charlie and Bob, and the relationship between η and distance L is:

[0044] η=η D 10 -αL / 10 (twenty three)

[0045] Among them, η D is the detection efficiency of the single-photon detector, α is the loss coefficient of the optical fiber; E p is the phase error rate, and its expression is given by the following formula:

[0046]

[0047] in, For the base selection {Y a ,X b ,Y c} or {Y a ,Y b ,X c}The corresponding key bit calculates the bit error rate; Δ represents the basis dependence of Alice signal; Δ is 1-2Q μ Δ=<ψ y |ψ x >Calculate.

[0048] Furthermore, in the quantum digital signature QDS protocol process, Alice is the transmitter, and Bob and Charlie are the receivers; the intensity modulator IM1 is used to realize the modulation of the signal state and the decoy state; the three amplitudes of the electrical signal input to the intensity modulator IM1 correspond to the signal state, the decoy state and the vacuum state respectively; when the vacuum state is selected, the intensity modulator IM1 uses the maximum attenuation and turns off the laser at the same time; the intensity modulator IM2 always allows both the front and rear pulses to pass; the four amplitudes of the electrical signal input to PM1 at Alice's end correspond to the four phases of PM1 at the transmitter, 0, π / 2, π and 3π / 2, and the amplitude of PM2 in the Sagnac ring is 0; the four amplitudes of the electrical signal input to PM in the Sagnac ring at Bob and Charlie's ends correspond to the four phases of PM at the receiving end, 0, π / 2, π and 3π / 2.

[0049] Furthermore, the security key rate R of the quantum digital signature QDS protocol is written as:

[0050]

[0051] Among them, f(E μ ) represents the error correction efficiency; H2(x) is the binary entropy function, which is expressed as:

[0052] H2(x)=-xlog2x-(1-x)log2(1-x) (26)

[0053] If the light source uses a weak coherent light source, the gain Q μ The expression of is given by:

[0054]

[0055] Where β = ηC sα∣jγ ,D=1-P d , C sα∣jγ The receiver selects α as the measurement basis pair |φ jγ >The probability of measuring the state and obtaining the bit value s; P d is the dark count rate of the detector, η is the transmission efficiency between Alice and Bob; it is related to the distance L between Alice and Bob as follows:

[0056] η=η D 10 -αL / 10 (28)

[0057] Among them, η D is the detection efficiency of the single-photon detector, α is the loss coefficient of the optical fiber; is the lower bound of the zero photon count rate, and its expression is given by the following formula:

[0058]

[0059] is the upper bound of the single photon bit error rate, and its expression is given by the following formula:

[0060]

[0061] Among them, Y1 L is the lower bound of the single photon count rate, and its expression is given by the following formula:

[0062]

[0063] Beneficial effects: The quantum encryption device of the present invention can be configured with multiple functions, and uses one quantum cryptographic machine to realize four functions, which greatly improves efficiency and reduces costs. Among them, quantum key distribution QKD can be used in complex communication scenarios where eavesdropping exists, quantum secret sharing QSS can provide a high degree of confidentiality and security for multi-party secret sharing, quantum private query QPQ can query the database in a distributed environment, and provide stronger privacy protection, and quantum digital signature QDS can enhance the verification of message integrity, non-repudiation and non-forgeability. In addition, since a single polarization phase modulator is used in the present invention, the receiving end and the transmitting end of our device are polarization-independent, and no polarization calibration is required during the communication process, which ensures the stability of the transmission process. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] Figure 1 It is a schematic diagram of the device of the sending end of the system of the present invention.

[0065] Figure 2 It is a schematic diagram of the device at the receiving end of the system of the present invention. DETAILED DESCRIPTION

[0066] In view of the problem that the current quantum encryption machine has a single encryption function, the present invention proposes a multifunctional cryptographic machine with four functions: quantum key distribution QKD, quantum private query QPQ, quantum secret sharing QSS, and quantum digital signature QDS. These four functions will be described in detail below.

[0067] 1. Quantum Key Distribution QKD Protocol Process and Implementation

[0068] According to the BB84 protocol, the signal sender Alice and the signal receiver Bob implement key distribution according to the following process (before executing the following steps, both parties need to agree on the definition rules of 1 and 0 bits):

[0069] (1) Launch:

[0070] Alice at the transmitting end uses P xThe probability of randomly modulating each weak coherent state pulse to light intensity x, where x∈{μ,ν1,ν2}, μ is the intensity of the signal state, ν1,ν2 represent the intensity of the two decoy states respectively. And with P Z|x Each pulse is randomly prepared on the Z basis with probability P X|x The probability of random preparation on the basis X, where P Z|x +P X|x =1, and then send the modulated pulses to Bob in a certain timing.

[0071] (2) Base selection and measurement:

[0072] The receiving end Bob uses P X and P Z (P Z =1-P X ) with a probability of randomly selecting a basis from the X basis and the Z basis to perform a projection measurement operation on each pulse received by itself. If Bob measures a pulse, he records the corresponding measurement result and announces the position of the pulse. At this point, Alice and Bob obtain the initial bit string (raw key).

[0073] (3) Basis matching: Alice and Bob publish their own preparation and measurement bases for each pulse through public channels. If Alice's preparation base matches Bob's measurement base, the basis matching is recorded as successful. Otherwise, the basis matching fails and both parties discard the data of this measurement. Thus, the sift key is obtained.

[0074] (4) Generate key: Alice and Bob will perform post-processing operations such as error correction and confidentiality amplification on the sift bit string sift key after the base is successfully generated to obtain a secure key.

[0075] When this system executes the BB84 protocol, the intensity modulator IM1 is used to realize the modulation of the signal state and the decoy state. The three amplitudes of the input electrical signal of the intensity modulator IM1 correspond to the signal state, the decoy state and the vacuum state respectively. When the vacuum state is selected, the intensity modulator IM1 uses the maximum attenuation and turns off the laser at the same time. The intensity modulator IM2 always allows both the front and rear pulses to pass. The four amplitudes of the input electrical signal of the phase modulator PM1 at Alice's end correspond to the four phases of the phase modulator PM1 at the transmitting end, 0, π / 2, π and 3π / 2, and the amplitude of the input electrical signal of PM2 is 0; the four amplitudes of the input electrical signal of the phase modulator PM at Bob's end correspond to the four phases of the phase modulator PM at the receiving end, 0, π / 2, π and 3π / 2. Let the phases selected by Alice and Bob be θ A ,θ B , the response probability of the detector can be calculated using the following process.

[0076] First, the optical pulse passes through the FM loop a at Alice's end and is divided into two bin pulses, one before and one after. After passing through the Sagnac loop a at Alice's end, a phase θ is added to the pulse passing through the long arm (l). A ; After passing through the Bob-end Sagnac loop b, the pulse passing through the short arm (s) is added with a phase θ B ; After passing through the FM loop b at Bob's end, each bin pulse is divided into two bin pulses before and after; the specific formula derivation process is as follows:

[0077]

[0078] Considering that only the pulses that pass through the long arm of FM ring a and the short arm of FM ring b at the same time can interfere with the bin pulses that pass through the short arm of FM ring a and the long arm of FM ring b at the same time,

[0079] In other cases, interference cannot occur, and only the interferable terms are retained. The above formula can be simplified to:

[0080]

[0081] The response probabilities of detector D1 and detector D2 are:

[0082]

[0083] Therefore, the relationship between the detector response probability and the PM selection phase of Alice and Bob is shown in Table I:

[0084] Table I Corresponding relationship between PM applied phase size and detector response probability at Alice and Bob

[0085]

[0086] When the detector responds, Alice and Bob compare the bases through the classical channel. If the two parties choose different bases, the result will be abandoned; if the two parties choose the same base, a secure key will be generated after post-processing.

[0087] The security key rate R of the BB84 protocol can be written as:

[0088]

[0089] Among them, f(E μ ) represents the error correction efficiency. H2(x) is the binary entropy function, and its expression is:

[0090] H2(x)=-xlog2x-(1-x)log2(1-x). (6)

[0091] If the light source is a weak coherent light source (WCS), the gain Q μand the quantum bit error rate E μ The expression of is given by:

[0092] Q μ =Y0+1-e -ημ , (7)

[0093] E μ Q μ =e0Y0+e Det (1-e -ημ ) (8)

[0094] Where e0 is the error probability of background light. Since background light is generally considered to be completely random, there is a 0.5 probability of producing a correct and an incorrect detection result, that is, e0 = 0.5. Y0 is the dark count rate of the detector, e Det is the background bit error rate, η is the transmission efficiency between Alice and Bob. Its relationship with the distance L between Alice and Bob is:

[0095] η=η D 10 -αL / 10 . (9)

[0096] Among them, η D is the detection efficiency of the single-photon detector, and α is the loss coefficient of the optical fiber. is the lower bound of the single-photon gain, and its expression is given by:

[0097]

[0098] is the lower bound of the zero photon count rate, and its expression is given by the following formula:

[0099]

[0100] is the upper bound of the single photon bit error rate, and its expression is given by the following formula:

[0101]

[0102] Among them, Y1 L is the lower bound of the single photon count rate, and its expression is given by the following formula:

[0103]

[0104] 2. Quantum Private Query QPQ Protocol Process and Implementation

[0105] Quantum Private Query (QPQ) is used to perform database queries while protecting user privacy. Usually, in traditional database queries, users need to send queries to the server, and the server will return the corresponding results. However, this may expose the content of the user's query, so for sensitive information, this may be unacceptable. Quantum private query uses the technology of quantum encryption and quantum communication to allow users to query data from the database without revealing the content of the query. This technology is of great significance for protecting user privacy and data security, especially in scenarios involving sensitive information, such as medical records, financial transactions, etc. The following is an introduction to the implementation scheme based on this device through the SARG04 protocol. According to the SARG04 protocol, the signal sender Alice and the signal receiver Bob implement key distribution according to the following process (before executing the following steps, both parties need to agree on the definition rules of 1 and 0 bits):

[0106] (1) Transmitting: Alice at the transmitting end sends a signal with P x The probability of randomly modulating each weak coherent state pulse to light intensity x, and using P Z|x Each pulse is randomly prepared on the Z basis with probability P X|x The probability of random preparation on the basis X, where P Z|x +P X|x =1, and then send the modulated pulses to Bob in a certain timing.

[0107] (2) Basis selection and measurement: The receiving end Bob uses P X and P Z (=1-P X ) with a probability of randomly selecting a basis from the X basis and the Z basis to perform a projection measurement operation on each pulse received by itself. If Bob measures a pulse, he records the corresponding measurement result and announces the position of the pulse. At this point, Alice and Bob obtain the initial bit string (raw key).

[0108] (3) Basis: Bob publishes the preparation and measurement basis he uses for each pulse through a public channel. For each quantum bit that Bob has successfully measured, Alice publishes a pair of quantum bits: one quantum bit is the quantum state prepared by Alice herself, and the other pair is a quantum state on a random basis. Therefore, Alice can only publish four pairs, namely {0, π / 2}, {0, 3π / 2}, {π, π / 2}, and {π, 3π / 2}. For example, if Alice prepares π / 2, she can publish {0, π / 2}. Bob infers Alice's original quantum state based on the set that Alice tells Bob the quantum state she sent is in and the measurement result. Only when the measurement result is not in the phase state published by Alice can the quantum state originally sent by Alice be determined. For example, Bob's measurement result is π, and Alice publishes {0, 3π / 2}. Then Bob knows that he chose the wrong basis for measurement and the real quantum state should be 3π / 2. If Bob's measurement result is included in the phase state published by Alice, Bob may have chosen the right basis for measurement, or he may have chosen the wrong basis but the measurement result happens to be consistent with the quantum state randomly selected by Alice. Therefore, in this case, Bob is not sure about the quantum state sent by Alice. This method can well protect the security of users.

[0109] (4) Generate key: In summary, Bob can only determine the quantum state if he chooses the wrong basis for measurement and the measurement result is inconsistent with the quantum state generated by Alice. The probability of this happening is 1 / 4. So far, Alice and Bob have shared a long key, 1 / 4 of which is known by Bob, but Alice cannot determine the number of bits known by Bob. By performing sparse preparation on the long key, a secure key is obtained.

[0110] When this system executes the SARG04 protocol, the intensity modulator IM1 is used to realize the modulation of the signal state and the decoy state. The three amplitudes of the IM1 input electrical signal correspond to the signal state, the decoy state and the vacuum state respectively. When the vacuum state is selected, IM1 uses the maximum attenuation and turns off the laser at the same time. IM2 always allows both the front and rear pulses to pass. The four amplitudes of the PM1 input electrical signal at Alice's end correspond to the four phases of PM1 at the transmitting end, 0, π / 2, π and 3π / 2; the four amplitudes of the PM input electrical signal at Bob's end correspond to the four phases of PM at the receiving end, 0, π / 2, π and 3π / 2. The phases selected by Alice and Bob are θ A ,θ B , the response probability of the detector can be calculated using the following process.

[0111] The operation and calculation methods of the SARG04 protocol are the same as those of the quantum key distribution QKD protocol. The following introduces the sparseness of the SARG04 protocol and the final query process of the quantum private query QPQ.

[0112] Bob selects k×N bits from the long key, where k is a security metric. He divides it into k subsequences of length N, and then takes XOR to dilute the number of bits Alice knows. Since Alice needs to know every element in the XOR to get the final result, the probability that Alice knows each bit is (1 / 4) k In this way, Alice knows that the number of bits of a key of length N satisfies the expectation Poisson distribution. If Alice does not receive any key, she needs to re-execute the previous steps. The probability that the protocol needs to be restarted is The purpose of this step is to reduce the amount of additional information leaked by the database. 3 ~10 6 , when k is 4 to 9, the probability that the protocol needs to restart is P0, which will be controlled at about 5%, and the amount of additional information leaked by the database The value will be controlled in single digits, which can well protect the security of the database.

[0113] The final query process of quantum private query QPQ is as follows: All outputs of the database held by Bob form a sequence C. If Alice wants to query the jth bit of C, and she knows the ith bit of the final key, she can submit (ji)modN to Bob. Bob shifts the final key to the right by (ji)modN bits, and then performs a bitwise XOR operation with C to generate a ciphertext. Then, Bob discloses the ciphertext to Alice. Since Alice knows the jth bit of the key after the shift and the jth ciphertext, she can XOR the i-th key she knows with the j-th ciphertext to understand the j-th database information.

[0114] 3. Quantum Secret Sharing QSS Protocol Process and Implementation

[0115] According to the quantum secret sharing (QSS) protocol, signal senders Alice and Charlie and signal receiver Bob implement key distribution according to the following process:

[0116] (1) Transmitting: Alice at the transmitting end sends a signal with P x The probability of randomly modulating each weak coherent state pulse to light intensity x, where x∈{μ,ν1,ν2}, μ,ν1,ν2 are the intensities of the signal state and the two decoy states respectively. And with P Y|x Each pulse is randomly prepared on the Y basis with probability P X|xThe probability of random preparation on the basis X, where P Y|x +P X|x =1. In the X basis, Alice modulates the phase to 0, and the logic bit is recorded as 0, and the modulation phase is π, and the logic bit is recorded as 1; in the Y basis, Alice modulates the phase to π / 2, and the logic bit is recorded as 1, and the modulation phase is 3π / 2, and the logic bit is recorded as 0. Then the modulated pulse is sent to Charlie in a certain sequence. Charlie randomly selects 0 or π / 2 modulation phase in the X basis or Y basis. When the modulation phase is 0, the logic bit is recorded as 0, and when the modulation phase is π / 2, the logic bit is recorded as 1. Charlie sends the modulated pulse to Bob in a certain sequence.

[0117] (2) Basis selection and measurement: The receiving end Bob uses p x The probability of recording the phase as 0 is 1-p x The probability of recording the phase as π / 2. When the phase is 0, Bob records the basis as X; when the phase is π / 2, Bob records the basis as Y. Then Bob uses a beam splitter to perform interference measurement on the two received pulses. After the measurement is completed, record which detector has a response. If D1 responds, Bob records the logic bit as 0; if D2 responds, Bob records the logic bit as 1; if both detectors respond, the logic bit is randomly recorded as 0 or 1. At this point, Alice and Charlie obtain the initial bit string (raw key).

[0118] (3) Basis: Alice, Bob, and Charlie announce their basis choices, which we denote as Z i (Z∈{X,Y},i∈{a,b,c}). If their basis choice is {X a ,X c ,X b}, {X a ,Y c ,Y b} and {Y a ,Y c ,X b}, their logical bits are filtered to form the original key bits. If their base choice is {Y a ,X c ,X b}, Alice and Charlie's logic bits are screened to form the original key bits, and Bob flips the corresponding logic bits to form the original key bits. The remaining bases are discarded.

[0119] (4) Generate key: When the base is {X a ,X c ,X b} and {X a ,Y c ,Yb}, the original key bits are used to form the security key bits, and part of the original key bits are consumed to analyze the bit error rate When the base is chosen as {Y a ,X c ,Y b} and {Y a ,Y c ,X b}, Alice, Bob, and Charlie disclose their original key bits to constrain the phase error rate E p Alice, Bob, and Charlie perform classical error correction and privacy amplification on the original key bits to extract the final key, whose corresponding basis is chosen as {X a ,X c ,X b} or {X a ,Y c ,Y b}.

[0120] When the system is running, Alice controls the laser, intensity modulator IM1, FM interferometer ring a, intensity modulator IM2, phase modulator PM1, optical attenuator, wavelength division multiplexing module, and Charlie controls Sagnac ring a. Alice uses intensity modulator IM1 to realize the modulation of signal state and decoy state. The three amplitudes of the electrical signal input to IM1 correspond to the signal state, decoy state and vacuum state respectively. When the vacuum state is selected, IM1 uses maximum attenuation and turns off the laser at the same time. IM2 always allows both the front and rear pulses to pass. The four amplitudes of the electrical signal input to the phase modulator PM1 at Alice correspond to the four phases of 0, π / 2, π and 3π / 2 of the phase modulator PM1 at the transmitting end, and the two amplitudes of the electrical signal input to the phase modulator PM2 in the Sagnac ring at Charlie are 0 and π / 2 respectively. The first part of the process of the quantum secret sharing QSS protocol and the quantum key distribution QKD protocol is the same. First, the optical pulse passes through the FM ring a at Alice's end and is divided into two bin pulses, front and rear; PM1 at Alice's end adds a phase θ to the pulse passing through the long arm (l) A , passing through the Charlie end Sagnac loop a, adding a phase θ to the pulse passing through the long arm (l) B ; After passing through the Bob-end Sagnac loop b, the pulse passing through the short arm (s) is added with a phase θ C ;

[0121] Let Si(i∈{a,b,c}) be the classical bit. When the basis is {X a ,X c ,X b}, {X a ,Y c ,Yb} and {Y a ,Y c ,X b}, the phase difference Δφ=(S c -S a )π, then the bit correlation When the base choice is {Y a ,X c ,Y b}, phase difference Δφ=(S c -S a +1)π, but because Bob performs a phase flip, the bit correlation is still Therefore, the bit satisfaction relationship of the three participants is always If any party engages in deception, true and complete information will not be obtained.

[0122] When the detector responds, Alice or Charlie and Bob communicate through the classical channel. a ,X c ,X b} and {X a ,Y c ,Y b}, the original key bits are used to form the secure key bits.

[0123] The security key rate R of the quantum secret sharing QSS protocol can be written as:

[0124] R=Q μ (1-f e H2(E μ )-H2(E p )) (19)

[0125] Among them, f e Represents the error correction efficiency. H2(x) is the binary entropy function, and its expression is:

[0126] H2(x)=-xlog2x-(1-x)log2(1-x). (20)

[0127] If the light source is a weak coherent light source (WCS), the gain Q μ and the quantum bit error rate E μ The expression of is given by:

[0128] Q μ =(1-p d )[1-(1-2p d ) -2μη ], (twenty one)

[0129] E μQ μ =e d (1-p d )[1-(1-p d ) -2μη ]+(1-e d ) d (1-p d ) -2μη (twenty two)

[0130] Among them, p d is the dark count rate of the detector, e d is the background bit error rate, η is the transmission efficiency between Alice (Charlie) and Bob. Its relationship with the distance L between Alice (Charlie) and Bob is:

[0131] η=η D 10 -αL / 10 . (twenty three)

[0132] Among them, η D is the detection efficiency of the single-photon detector, and α is the loss coefficient of the optical fiber. p is the phase error rate, and its expression is given by the following formula:

[0133]

[0134] in, For the base selection {Y a ,X b ,Y c} or {Y a ,Y b ,X c}The bit error rate is calculated by the key bit corresponding to the bit. α represents the basis dependence of Alice's signal. Δ can be obtained from 1-2Q μ Δ=<ψ y |ψ x >Calculate.

[0135] 4. Quantum Digital Signature QDS Protocol Process and Implementation

[0136] According to the quantum digital signature QDS protocol, the sender of the signed message Alice and the receivers of the message Bob and Charlie implement the digital signature according to the following process:

[0137] (1) Distribution phase: Bob or Charlie prepares N totEach pulse is modulated into one of {|0>,|1>,|+>} with equal probability and sent to Alice. Among them, |0> and |+> correspond to the classical bit 0, |1> corresponds to the classical bit 1, and |0> and |1> correspond to the Z basis, and |+> corresponds to the X basis. Alice also chooses the X basis or the Z basis to measure the received pulse with equal probability. When they both choose the Z basis, the corresponding bits are used as the signature key string, but when Alice chooses the X basis, the corresponding bits are used as parameter estimates. Then they select the corresponding bits from N tot The optical pulses select a portion of the key string n with a proportion of d test Estimated bit error rate e AB (e AC ), the rest is used as the signature key pool and is recorded as n pool . To sign possible future messages m = 0 or 1, Alice and Bob (Charlie) sign n pool Select a key string of length L to construct the signature sequence and ( and ),in and Held by Alice, Finally, Bob (Charlie) randomly selects half of the keys and forwards them and their corresponding positions to Charlie (Bob) through a classic authentication channel. We call the retained half of the keys The other half is called At this time, the symmetric keys held by Bob and Charlie are and

[0138]

[0139] (2) Message stage: Alice sends the signature (m, Sig m ) to Bob, where Bob gives his verification key And the received signature Sig m A comparison is performed and the number of mismatches is recorded. The number of mismatches in both parts is less than s α L / 2, then Bob receives the signed message and forwards it to Charlie; otherwise, Bob rejects the message and announces the termination of the protocol. α represents the threshold of authentication required for quantum digital signature QDS security, and 0 α <0.5. Charlie checks the signed message forwarded by Bob in the same way, except that the threshold is s​v , and 0 α v <0.5, if the number of mismatches is still less than s v L / 2, then Charlie receives the message.

[0140] When this system executes the quantum digital signature QDS protocol, the intensity modulator IM1 is used to realize the modulation of the signal state and the decoy state. The three amplitudes of the IM1 input electrical signal correspond to the signal state, the decoy state and the vacuum state respectively. When the vacuum state is selected, IM1 uses the maximum attenuation and turns off the laser at the same time. IM2 always allows both the front and rear pulses to pass. The four amplitudes of the PM1 input electrical signal at Alice's end correspond to the four phases of PM1 at the transmitting end, 0, π / 2, π and 3π / 2, and the PM2 amplitude is 0; the four amplitudes of the PM input electrical signal in the Sagnac ring at Bob or Charlie's end correspond to the four phases of PM1 at the receiving end, 0, π / 2, π and 3π / 2. The phases selected by Alice, Bob or Charlie are θ A ,θ B , the response probability of the detector can be calculated using the following process.

[0141] First, the optical pulse passes through the FM ring a at Alice's end and is divided into two bin pulses, one before and one after. After passing through PM1 at Alice's end, a phase θ is added to the pulse passing through the long arm (l). A ; Passing through the Sagnac loop b at Bob (Charlie) end, adding phase θ to the pulse passing through the short arm (s) B ; After passing through FM loop b at Bob (Charlie) end, each bin pulse is divided into two bin pulses before and after.

[0142] When the detector responds, Bob (Charlie) and Alice compare the bases through the classical channel. If the two parties choose different bases, the result will be abandoned; if the two parties choose the same base, a secure key will be generated after post-processing.

[0143] The security key rate R of the quantum digital signature QDS protocol can be written as:

[0144]

[0145] Among them, f(E μ ) represents the error correction efficiency. H2(x) is the binary entropy function, and its expression is:

[0146] H2(x)=-xlog2x-(1-x)log2(1-x). (26)

[0147] If the light source is a weak coherent light source (WCS), the gain Q μ ​​The expression of is given by:

[0148]

[0149] Where β = ηC sα∣jγ ,D=1-P d , C sα∣jγ The receiver selects α as the measurement basis pair |φ jγ >The probability of measuring the state and obtaining the bit value s; P d is the dark count rate of the detector, and η is the transmission efficiency between Alice and Bob. It is related to the distance L between Alice and Bob as follows:

[0150] η=η D 10 -αL / 10 . (28)

[0151] Among them, η D is the detection efficiency of the single-photon detector, and α is the loss coefficient of the optical fiber. is the lower bound of the zero photon count rate, and its expression is given by the following formula:

[0152]

[0153] is the upper bound of the single photon bit error rate, and its expression is given by the following formula:

[0154]

[0155] Among them, Y1 L is the lower bound of the single photon count rate, and its expression is given by the following formula:

[0156]

Claims

1. A quantum encryption device that can be configured with multiple functions, characterized in that: Includes the sending end and the receiving end; The transmitting end includes a laser, an intensity modulator IM1, an FM interference loop a, an intensity modulator IM2, a phase modulator PM1, an optical attenuator, a wavelength division multiplexing module and a Sagnac loop a; Lasers are used to generate laser light; The intensity modulator IM1 randomly modulates the laser into three quantum state light pulses, namely the signal state, the decoy state and the vacuum state; Then the light pulse passes through FM interference ring a to split the light pulse into two light pulses one in front and one behind. The pulse after passing through the interference ring is chopped by intensity modulator IM2. The pulse of intensity modulation IM2 passes through phase modulator PM1 for phase modulation, then passes through optical attenuator and wavelength division multiplexing module, and then is sent to the receiving end through Sagnac loop a; the Sagnac loop a includes phase modulator PM2; The receiving end includes a wavelength division demultiplexing module, a Sagnac loop b, an FM interference loop b, and a detector; The optical pulse received by the receiving end first passes through the demultiplexing module, then is demodulated by the Sagnac loop b, and the pulse is interfered by the FM interferometer loop b, and finally reaches the detector; Based on the quantum encryption device, the quantum secret sharing QSS protocol process is as follows: Alice and Charlie are both transmitters. Alice controls the laser, intensity modulator IM1, FM interference loop a, intensity modulator IM2, phase modulator PM1, optical attenuator, and wavelength division multiplexing module, and Charlie controls Sagnac loop a. Alice uses intensity modulator IM1 to realize modulation of signal state and decoy state. The three amplitudes of the input electrical signal of intensity modulator IM1 correspond to signal state, decoy state and vacuum state respectively. When the vacuum state is selected, intensity modulator IM1 uses maximum attenuation and turns off the laser at the same time. Intensity modulator IM2 always allows both the front and rear pulses to pass. The four amplitudes of the input electrical signal of phase modulator PM1 at Alice correspond to the four phases of PM1 at the transmitter, 0, π / 2, π and 3π / 2, respectively. The two amplitudes of the input electrical signal of phase modulator PM2 in the Sagnac loop at Charlie correspond to 0 and π / 2 respectively. The security key rate R of the quantum secret sharing QSS protocol is written as: R=Q μ (1-f e H2(E μ )-H2(E p )) (19) Among them, f e represents the error correction efficiency; H2(x) is the binary entropy function, and its expression is: H2(x)=-xlog2x-(1-x)log2(1-x) (20) If the light source uses a weak coherent light source, the gain Q μ and the quantum bit error rate E μ The expression of is given by: Q μ =(1-p d )[1-(1-2p d )e -2μη ] (21) AND μ Q μ =and d (1-p d )[1-(1-p d )And -2μη ]+(1-e d )p d (1-p d )And -2μη (22) Among them, p d is the dark count rate of the detector, e d is the background bit error rate, η is the transmission efficiency between Alice (Charlie) and Bob; L is the distance between Alice or Charlie and Bob, and the relationship between η and distance L is: the=the D 10 -αL / 10 (23) Among them, η D is the detection efficiency of the single-photon detector, α is the loss coefficient of the optical fiber; E p is the phase error rate, and its expression is given by the following formula: in, For the base selection {Y a ,X b ,Y c } or {Y a ,Y b ,X c }The corresponding key bit calculates the bit error rate; Δ represents the basis dependence of Alice signal; Δ is 1-2Q μ Δ=<ψ y |ψ x > Calculate.

2. A quantum encryption device capable of configurable multiple functions according to claim 1, characterized in that: In the process of realizing quantum key distribution QKD, the transmitting end is Alice and the receiving end is Bob; at Alice, the three amplitudes of the electrical signal input to the intensity modulator IM1 correspond to the signal state, the decoy state and the vacuum state respectively. When the vacuum state is selected, the intensity modulator IM1 uses the maximum attenuation and turns off the laser at the same time. The intensity modulator IM2 always allows both the front and rear pulses to pass. The four amplitudes of the electrical signal input to the phase modulator PM1 at Alice correspond to the four phases of the phase modulator PM1 at the transmitting end, 0, π / 2, π and 3π / 2; the four amplitudes of the electrical signal input to the phase modulator PM at Bob correspond to the four phases of the phase modulator PM at the receiving end, 0, π / 2, π and 3π / 2 respectively.

3. A quantum encryption device capable of configurable multiple functions according to claim 2, characterized in that: Based on the quantum key distribution QKD process, the security key rate R is written as: Among them, P μ represents the probability of selecting the signal state, P Z|μ represents the probability of preparing a signal state in the Z basis, P Z represents the probability of selecting the Z basis, f(E μ ) represents the error correction efficiency, H2(x) is the binary entropy function; The expression of H2(x) is: H2(x)=-xlog2x-(1-x)log2(1-x) (6) If the light source uses a weak coherent light source, the gain Q μ and the quantum bit error rate E μ The expression of is given by: Q μ =Y0+1-e -ημ , (7) AND μ Q μ =e0Y0+e Det (1-e -ημ ) (8) Among them, e0 is the error probability of background light, Y0 is the dark count rate of the detector, and e Det is the background bit error rate, η is the transmission efficiency between Alice and Bob; The relationship between η and the distance L between Alice and Bob is: the=the D 10 -αL / 10 (9) Among them, η D is the detection efficiency of the single-photon detector, α is the loss coefficient of the optical fiber; is the lower bound of the single-photon gain, and its expression is given by: μ is the strength of the signal state, ν1 and ν2 represent the strengths of the two decoy states, respectively. represents the first decoy state gain, represents the second decoy state gain, is the lower bound of the zero photon count rate, and its expression is given by the following formula: is the upper bound of the single photon bit error rate, and its expression is given by the following formula: Among them, Y1 L is the lower bound of the single photon count rate, and its expression is given by the following formula:

4. According to claim 1, a quantum encryption device capable of configurable multiple functions, characterized in that: In the quantum private query QPQ process, the sending end is Alice and the receiving end is Bob; at Alice's end, the intensity modulator IM1 is used to realize the modulation of the signal state and the decoy state, and the three amplitudes of the input electrical signal of the intensity modulator IM1 correspond to the signal state, the decoy state and the vacuum state respectively; when the vacuum state is selected, IM1 uses the maximum attenuation and turns off the laser at the same time; the intensity modulator IM2 always allows both the front and rear pulses to pass; the four amplitudes of the input electrical signal of PM1 at Alice's end correspond to the four phases of PM1 at the sending end, 0, π / 2, π and 3π / 2 respectively; the four amplitudes of the input electrical signal of the phase modulator PM at Bob's end correspond to the four phases of the phase modulator PM at the receiving end, 0, π / 2, π and 3π / 2 respectively.

5. A quantum encryption device capable of configurable multiple functions according to claim 4, characterized in that: The process of executing the SARG04 protocol is as follows: Bob selects k×N bits from the long key, where k is a security metric; divides it into k subsequences of length N, and then XORs them to dilute the number of bits known by Alice; Since Alice needs to know every element in the XOR to get the final result, the probability that Alice knows every bit is (1 / 4) k ; Therefore, Alice knows that the number of bits of a key of length N satisfies the expectation Poisson distribution of If Alice does not receive any key, the entire protocol process needs to be re-executed.

6. According to claim 4, a quantum encryption device capable of configurable multiple functions is characterized in that: The final query process of quantum private query QPQ is as follows: All outputs of the database held by Bob form a sequence C; if Alice wants to query the j-th bit of C, and Alice knows the i-th bit of the final key, Alice submits (ji)modN to Bob; Bob shifts the final key to the right by (ji)modN bits, and then performs a bitwise XOR operation with C to generate a ciphertext; then, Bob discloses the ciphertext to Alice; since Alice knows the j-th bit of the shifted key and the j-th ciphertext, Alice performs an XOR operation on the i-th key she knows and the j-th ciphertext, thereby understanding the j-th database information.

7. According to claim 1, a quantum encryption device capable of configurable multiple functions, characterized in that: In the quantum digital signature QDS protocol process, Alice is the transmitter, and Bob and Charlie are the receivers; the intensity modulator IM1 is used to realize the modulation of the signal state and the decoy state; the three amplitudes of the electrical signal input to the intensity modulator IM1 correspond to the signal state, the decoy state and the vacuum state respectively; when the vacuum state is selected, the intensity modulator IM1 uses the maximum attenuation and turns off the laser at the same time; the intensity modulator IM2 always allows both the front and rear pulses to pass; the four amplitudes of the electrical signal input to PM1 at Alice's end correspond to the four phases of PM1 at the transmitter, 0, π / 2, π and 3π / 2, and the amplitude of PM2 in the Sagnac ring is 0; the four amplitudes of the electrical signal input to PM in the Saganac ring at Bob and Charlie's ends correspond to the four phases of PM at the receiving end, 0, π / 2, π and 3π / 2.

8. According to claim 1, a quantum encryption device capable of configurable multiple functions, characterized in that: The security key rate R of the quantum digital signature QDS protocol is written as: Among them, f(E μ ) represents the error correction efficiency; H2(x) is the binary entropy function, which is expressed as: H2(x)=-xlog2x-(1-x)log2(1-x) (26) If the light source uses a weak coherent light source, the gain Q μ The expression of is given by: Where β = ηC sα∣jγ ,D=1-P d , C sα∣jγ The receiver selects α as the measurement basis pair |φ jγ | state and obtain the probability of bit value s; P d is the dark count rate of the detector, η is the transmission efficiency between Alice and Bob; it is related to the distance L between Alice and Bob as follows: the=the D 10 -αL / 10 (28) Among them, η D is the detection efficiency of the single-photon detector, α is the loss coefficient of the optical fiber; Y0 L is the lower bound of the zero photon count rate, and its expression is given by the following formula: is the upper bound of the single photon bit error rate, and its expression is given by the following formula: Among them, Y1 L is the lower bound of the single photon count rate, and its expression is given by the following formula:

Citation Information

Patent Citations

  • Quantum key distribution device capable of configuring multiple protocols

    CN112448815A