Access authentication method and device for quantum direct communication network

CN118432813BActive Publication Date: 2026-08-21BEIJING ACAD OF QUANTUM INFORMATION SCI +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410525893.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-28
Publication Date
2026-08-21
Estimated Expiration
2044-04-28

AI Technical Summary

Technical Problem

[0004]本申请提出一种用于量子直接通信网络的接入认证方法、电子设备和计算机可读存储介质,以解决量子直接通信网络中缺少基于数字证书的接入认证问题

Benefits of technology

[0016]根据本申请的一些实施例,参与通信的量子通信设备双方通过将数字证书的签名信息在量子直接通信网络中传输,得到了对方的量子通信设备验签公钥,从而实现了通信双方的接入认证。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118432813B_ABST
    Figure CN118432813B_ABST
Patent Text Reader

Abstract

The application provides an access authentication method for a quantum direct communication network, an electronic device and a computer readable storage medium. The access authentication method comprises the following steps: in response to a user's access authentication request for a first quantum communication device, the first quantum communication device sends a first digital certificate to a second quantum communication device, so that the second quantum communication device obtains a first quantum communication device signature public key through the first digital certificate; the first quantum communication device signs first transmission data by using a first quantum communication device signature private key of the first quantum communication device, and obtains a first transmission data signature; and the first quantum communication device directly sends the first transmission data and the first transmission data signature to the second quantum communication device, so that the second quantum communication device can verify the first transmission data signature by using the first quantum communication device signature public key, and access authentication of the first quantum communication device is realized. According to the embodiment, access authentication of both communication parties is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of quantum direct communication, and more specifically, to an access authentication method, electronic device, and computer-readable storage medium for quantum direct communication networks. Background Technology

[0002] Based on the fundamental principles of quantum mechanics, quantum communication provides security for information exchange. Relying on quantum entanglement as a core resource, several quantum communication paradigms with information-theoretic security have been established, including quantum key distribution (QKD) and quantum secure direct communication (QSDC). Quantum secure direct communication encodes information directly into quantum states and transmits it securely and reliably in quantum channels, representing a new paradigm for quantum secure communication. Constructing large-scale quantum secure direct communication networks is of great significance; however, existing quantum secure direct communication networks lack efficient and secure access authentication schemes based on digital certificates.

[0003] Quantum direct communication enables secure and reliable information transmission in quantum channels susceptible to eavesdropping and noise, and possesses high security capacity. Access authentication is fundamental to ensuring the security of communication networks; however, current quantum direct communication networks still lack a secure and efficient digital certificate-based access authentication scheme. Summary of the Invention

[0004] This application proposes an access authentication method, electronic device, and computer-readable storage medium for quantum direct communication networks to address the lack of digital certificate-based access authentication in quantum direct communication networks.

[0005] According to one aspect of this application, an access authentication method for a quantum direct communication network is proposed. The quantum direct communication network includes a first quantum communication device and a second quantum communication device. The first quantum communication device stores a first digital certificate, which includes a first quantum communication device signature verification public key. The access authentication method is used on the first quantum communication device and includes: in response to a user's access authentication request for the first quantum communication device, the first quantum communication device sends the first digital certificate to the second quantum communication device, enabling the second quantum communication device to obtain the first quantum communication device signature verification public key through the first digital certificate; the first quantum communication device signs first transmitted data using its first quantum communication device signature private key to obtain a first transmitted data signature; the first quantum communication device directly sends the first transmitted data and the first transmitted data signature to the second quantum communication device, enabling the second quantum communication device to verify the first transmitted data signature using the first quantum communication device signature verification public key to authenticate access to the first quantum communication device.

[0006] According to some embodiments, the quantum direct communication network further includes a digital certificate issuing device. Before the first quantum communication device sends the first digital certificate to the second quantum communication device so that the second quantum communication device can obtain the signature public key of the first quantum communication device through the first digital certificate, the access authentication method further includes: the first quantum communication device requesting the digital certificate issuing device to obtain the first digital certificate.

[0007] According to some embodiments, before the first quantum communication device signs the first transmitted data using its signature private key to obtain the first transmitted data signature, the method further includes: the first quantum communication device sending a single-photon qubit to the second quantum communication device so that the second quantum communication device can confirm the first quantum communication device.

[0008] According to some embodiments, before the first quantum communication device signs the first transmitted data using its signature private key to obtain the first transmitted data signature, the method further includes: the first quantum communication device receiving a single-photon qubit sent by the second quantum communication device to confirm the second quantum communication device.

[0009] According to some embodiments, before the first quantum communication device requests the digital certificate issuing device to obtain the first digital certificate, the method further includes: the first quantum communication device receiving the issuing device verification public key from the digital certificate issuing device.

[0010] According to some embodiments, the access authentication method further includes: the first quantum communication device receiving a second digital certificate from the second quantum communication device, wherein the second digital certificate includes a second quantum communication device verification public key of the second quantum communication device; the first quantum communication device using the issuing device verification public key to verify the second digital certificate; and the first quantum communication device determining whether to perform access authentication for the second quantum communication device based on the verification result.

[0011] According to some embodiments, the access authentication method further includes: after the signature verification is successful, obtaining the signature verification public key of the second quantum communication device using the second digital certificate; the first quantum communication device receiving the second transmission data and the second transmission data signature sent by the second quantum communication device; the first quantum communication device using the signature verification public key of the second quantum communication device to verify the signature of the second transmission data in order to perform access authentication for the second quantum communication device.

[0012] According to some embodiments, after receiving a single-photon qubit from the second quantum communication device to confirm the second quantum communication device, and before the first quantum communication device directly sends the first transmission data and the first transmission data signature to the second quantum communication device, the access authentication method further includes: the first quantum communication device calculating the bit error rate of the received single-photon qubit.

[0013] According to one aspect of this application, a quantum communication device is proposed that enables access authentication in a quantum direct communication network, the quantum direct communication network including the first quantum communication device and a peer quantum communication device. The first quantum communication device stores a first digital certificate, which includes a first quantum communication device verification public key. The quantum communication device includes: a first sending unit, configured to send the first digital certificate to the peer quantum communication device in response to a user's access authentication request, so that the peer quantum communication device obtains the quantum communication device verification public key through the first digital certificate; a transmission data signing unit, configured to sign first transmission data using the first quantum communication device signing private key to obtain a first transmission data signature; and a second sending unit, configured to directly send the first transmission data and the first transmission data signature to the peer quantum communication device, so that the peer quantum communication device can verify the first transmission data signature using the first quantum communication device verification public key to authenticate access to the quantum communication device.

[0014] According to one aspect of this application, an electronic device is provided, comprising: a processor; and a memory storing a computer program that, when executed by the processor, causes the processor to perform an editing method as described in any of the preceding embodiments.

[0015] According to one aspect of this application, a non-transitory computer-readable storage medium is proposed, on which computer-readable instructions are stored, which, when executed by a processor, cause the processor to perform an editing method as described in any of the preceding embodiments.

[0016] According to some embodiments of this application, the two quantum communication devices participating in the communication obtain the other party's quantum communication device verification public key by transmitting the signature information of the digital certificate in the quantum direct communication network, thereby realizing access authentication for both parties.

[0017] It should be understood that the above general description and the following detailed description are merely exemplary and do not limit this application. Attached Figure Description

[0018] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. The above and other objectives, features, and advantages of this application will become more apparent by referring to the accompanying drawings and describing exemplary embodiments in detail.

[0019] Figure 1a A schematic diagram of a quantum communication device for obtaining a digital certificate is shown according to an example embodiment of this application.

[0020] Figure 1b A flowchart illustrating a method for obtaining a digital certificate using a quantum communication device according to an example embodiment of this application is shown.

[0021] Figure 2 A flowchart of an access authentication method for a quantum direct communication network according to an example embodiment of this application is shown.

[0022] Figure 3 A schematic diagram of an access authentication process for a quantum communication device according to an example embodiment of this application is shown.

[0023] Figure 4 A device block diagram of a quantum communication device according to an example embodiment of this application is shown.

[0024] Figure 5 An electronic device is shown according to an exemplary embodiment of this application. Detailed Implementation

[0025] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the embodiments set forth herein; rather, they are provided so that this application will be thorough and complete, and will fully convey the concept of the exemplary embodiments to those skilled in the art. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted.

[0026] The described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. Numerous specific details are provided in the following description to give a full understanding of embodiments of this disclosure. However, those skilled in the art will recognize that the technical solutions of this disclosure can be practiced without one or more of these specific details, or other methods, components, materials, apparatus, or operations may be employed. In these cases, well-known structures, methods, apparatuses, implementations, materials, or operations will not be shown or described in detail.

[0027] The flowcharts shown in the accompanying drawings are merely illustrative and do not necessarily include all content and operations / steps, nor do they necessarily have to be performed in the described order. For example, some operations / steps can be broken down, while others can be combined or partially combined; therefore, the actual execution order may change depending on the specific circumstances.

[0028] The terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or apparatuses.

[0029] As mentioned earlier, quantum direct communication can securely and reliably transmit information in quantum channels that are susceptible to eavesdropping and noise, and it also possesses high security capacity. However, access authentication, as the foundation for ensuring the security of communication networks, still lacks a secure and efficient access authentication scheme.

[0030] In classic communication networks, authentication methods are mostly based on public keys or digital certificates. Public key authentication requires prior knowledge of the other party's public key. From the perspectives of security, ease of use, and manageability, a trusted third party is needed to distribute the public key, and an authoritative institution is required for arbitration in case of problems. Therefore, in practical network environments, digital certificates are mostly used to distribute public keys. However, in current quantum direct communication networks, there is currently a lack of an efficient and secure access authentication scheme based on digital certificates.

[0031] According to embodiments of this application, the two quantum communication devices participating in the communication obtain each other's quantum communication device verification public key by transmitting the signature information of digital certificates in a quantum direct communication network. This provides security features such as bidirectional mutual recognition, data confidentiality and integrity, non-forgeability, and non-repudiation. By using quantum direct communication to transmit signature information, the key establishment mechanism in the access authentication process of classical communication networks is replaced; only a digital signature algorithm is needed, without the need for key encapsulation or key negotiation algorithms. Furthermore, legitimate communication can be initiated directly without requesting a digital certificate issuing device during the validity period of the digital certificate. After the digital certificate expires, the user needs to apply for a new certificate from the digital certificate issuing device.

[0032] The specific embodiments according to this application will now be described in detail with reference to the accompanying drawings.

[0033] Figure 1a This diagram illustrates a structure for obtaining a digital certificate using a quantum communication device according to an example embodiment of this application. Figure 1b A flowchart illustrating a method for obtaining a digital certificate using a quantum communication device according to an example embodiment of this application is shown below. Figure 1a and Figure 1b This application provides a detailed description of the process by which a quantum communication device obtains a digital certificate according to an example embodiment.

[0034] like Figure 1a The quantum communication network shown includes a digital certificate issuing device and a first quantum communication device (such as...). Figure 1a Alice terminal shown) and second quantum communication device (such as Figure 1a (The Bob end shown).

[0035] like Figure 1b As shown, in step S101, in response to the user's request for a digital certificate for the quantum communication device, the digital certificate issuing device sends the issuing device verification public key to the quantum communication device.

[0036] According to an embodiment of this application, before step S101, the digital certificate issuing device generates a signing private key and a verification public key using a post-quantum cryptographic digital signature algorithm.

[0037] In step S103, the quantum communication device generates a signing private key and a verification public key.

[0038] In a specific embodiment, the first quantum communication device and the second quantum communication device, the communication participants, generate their respective public-private key pairs using a post-quantum cryptographic digital signature algorithm, including the quantum communication device's signature private key. Verification of public keys for quantum communication devices In this context, A / B represents the first quantum communication device or the second quantum communication device.

[0039] In step S105, the quantum communication device sends the generated quantum communication device verification public key to the digital certificate issuing device.

[0040] In step S107, the digital certificate issuing device uses the quantum communication device to verify the public key, generates a digital certificate, and sends it to the quantum communication device.

[0041] In a specific embodiment, the first and second quantum communication devices of the communication participants respectively use their quantum communication device verification public keys. The public key is sent to the digital certificate issuing device. The digital certificate issuing device then uses quantum communication equipment to verify the signature. Generate the corresponding digital certificate.

[0042] According to some embodiments, a digital certificate includes the user's identity, the public key for verification of quantum communication devices, the validity period, and / or the name of the issuing authority.

[0043] In other embodiments, the digital certificate issuing device uses its signing private key to sign the information in the digital certificate; this process can be abbreviated as follows:

[0044] Because the digital certificate includes the verification public key for the quantum communication device, both parties can communicate directly using the quantum direct communication network during the certificate's validity period, without the digital certificate issuing device's involvement. Only after the digital certificate expires does the quantum communication device need to apply for a new digital certificate from the certificate authority.

[0045] Figure 2 A flowchart illustrating an access authentication method for a quantum direct communication network according to an example embodiment of this application is shown, such as... Figure 2 The access authentication method shown includes steps S201, S203, and S205.

[0046] According to an embodiment of this application, a quantum direct communication network includes a first quantum communication device and a second quantum communication device. The first quantum communication device stores a first digital certificate, which includes a first quantum communication device verification public key and an expiration time.

[0047] In step S201, in response to the user's access authentication request for the first quantum communication device, the first quantum communication device sends the first digital certificate to the second quantum communication device, so that the second quantum communication device can obtain the verification public key of the first quantum communication device through the first digital certificate.

[0048] To ensure the validity of the first digital certificate used, according to an embodiment of this application, before step S203, the first quantum communication device also needs to verify the validity of the digital certificate. For example, the validity of the first digital certificate is determined based on the validity period stored in the first digital certificate. And after the first digital certificate expires, before step S201, the first quantum communication device requests to obtain the first digital certificate from the digital certificate issuing device.

[0049] According to an embodiment of this application, while the first quantum communication device requests a first digital certificate from the digital certificate issuing device, the second quantum communication device, which is connected to the first quantum communication device, also requests a second digital certificate from the digital certificate issuing device.

[0050] The process by which the first quantum communication device requests the first digital certificate from the digital certificate issuing device is as follows: Figure 1a and Figure 1b The process described is the same and will not be repeated here.

[0051] In a specific embodiment, in step S201, the first quantum communication device sends the first digital certificate and a communication request to the second quantum communication device within the validity period of the first digital certificate. Simultaneously, the second quantum communication device also sends the second digital certificate and a communication request to the first quantum communication device within the validity period of the second digital certificate.

[0052] Since the first digital certificate includes the first quantum communication device's verification public key, and as... Figure 1a and Figure 1b The digital certificate issuing device signs the information in the digital certificate using its private key and then saves the verification public key of the first quantum communication device into the first digital certificate. Therefore, after receiving the first digital certificate, the second quantum communication device uses the verification public key received in step S101 from the digital certificate issuing device to verify the first quantum communication device's verification public key in the first digital certificate. If the verification passes, subsequent steps are executed; if the verification fails, the first quantum communication device's verification public key is obtained. Simultaneously, the first quantum communication device obtains the second quantum communication device's verification public key through the second digital certificate.

[0053] In step S203, the first quantum communication device uses its first quantum communication device signature private key to sign the first transmitted data, thereby obtaining the first transmitted data signature.

[0054] According to an embodiment of this application, before step S203, the quantum communication devices participating in quantum communication need to mutually recognize each other.

[0055] For example, a first quantum communication device sends a single-photon qubit to a second quantum communication device to acknowledge the first device's identity. Simultaneously, it receives single-photon qubits from the second device to acknowledge its own identity.

[0056] In some embodiments, the quantum communication devices participating in the communication need to calculate the bit error rate of the received single-photon qubits, and perform subsequent steps when the calculated bit error rate is lower than a preset bit error rate threshold.

[0057] In step S205, the first quantum communication device directly sends the first transmission data and the first transmission data signature to the second quantum communication device, so that the second quantum communication device can use the signature verification public key of the first quantum communication device to verify the first transmission data signature, thereby authenticating access to the first quantum communication device.

[0058] According to an embodiment of this application, while executing step S205, the system receives the second transmission data and the second transmission data signature sent by the second quantum communication device; and verifies the second transmission data signature using the signature verification public key of the second quantum communication device to perform access authentication for the second quantum communication device.

[0059] according to Figure 2 In the illustrated embodiment, the two quantum communication devices involved in the communication obtain each other's quantum communication device verification public key by transmitting the signature information of digital certificates in the quantum direct communication network, thereby achieving identity authentication between the two parties. Compared with digital certificates in classical communication networks, digital certificates in quantum direct communication networks only require the use of digital signature algorithms and do not require the use of key encapsulation or key negotiation algorithms.

[0060] According to some embodiments, legitimate communication can be initiated directly without requesting a digital certificate from the digital certificate issuing device during the certificate's validity period. After the digital certificate expires, it is only necessary to apply for a new digital certificate from the digital certificate issuing device.

[0061] Figure 3 This diagram illustrates an access authentication process for a quantum communication device according to an example embodiment of this application. According to the embodiment of this application, in... Figure 3 Prior to the access authentication shown, both communicating parties obtained their respective digital certificates from the digital certificate issuing device. The following example illustrates this. Figure 3 For example, an access authentication process for a quantum communication device according to an example embodiment of this application will be illustrated.

[0062] like Figure 3 As shown, the quantum communication network includes a digital certificate issuing device and a first quantum communication device (such as...). Figure 3Alice terminal shown) and second quantum communication device (such as Figure 3 (The Bob end shown).

[0063] In step S301, the two communication methods exchange digital certificates.

[0064] For example, during the validity period of its digital certificate, Alice will share its digital certificate and communication requests (DC). A ,R A ) is sent to Bob. Simultaneously, Bob will send the digital certificate and communication request (DC) within the validity period of his digital certificate. B ,R B Send it to Alice.

[0065] In step S303, the two communicating parties perform bidirectional mutual recognition.

[0066] For example, Alice verifies the signature of a public key using the issuing device of a digital certificate issuing device (e.g., a Certificate Authority, or CA). For the received digital certificate DC B Verification was performed to confirm Bob's quantum communication device's public key for signature verification. The validity of the public key was then verified. Alice then prepared a series of single-photon qubits and sent them to Bob. Simultaneously, Bob verified the public key using the issuing device of the digital certificate issuing device. For the received digital certificate DC A Perform signature verification to confirm the signature verification public key of Alice's quantum communication device. The effectiveness of this was then verified. Bob subsequently prepared a series of single-photon qubits and sent them to Alice, thus achieving bidirectional mutual recognition.

[0067] In step S305, the two communicating parties calculate the bit error rate of the qubits.

[0068] For example, Alice and Bob compare the bit error rate of the qubits using a classical channel. When the bit error rate of the qubits is lower than a preset security threshold, they proceed with the next steps.

[0069] In step S307, both communicating parties perform access authentication.

[0070] For example, Alice (Bob) will transmit information M A(B) and the signature of the transmitted information The remaining qubits are encoded and sent to Bob (Alice), and this process is abbreviated as... QSDC stands for Quantum Direct Communication Network. It transmits information M. A(B)This could be a string of random numbers or a communication response. Alice and Bob decode the signature information from the received qubits. Finally, Alice and Bob verify the signature using each other's quantum communication device's public key, thus successfully achieving access authentication.

[0071] After completing access authentication, Alice and Bob continue to execute the quantum direct communication protocol, securely and reliably transmitting information within the quantum direct communication network. Thanks to QSDC technology, which transmits information directly in quantum states, compared to access authentication schemes in classical secure communication networks, this step involves securely transmitting the transmitted information and its signature encoding directly in quantum states through the quantum direct communication network. Furthermore, in this embodiment, both parties only need to obtain the other party's quantum communication device's signature verification public key.

[0072] According to embodiments of this application, efficient and secure access authentication for quantum direct communication networks is achieved based on digital certificates, possessing security features such as two-way mutual recognition, data confidentiality and integrity, non-forgeability, and non-repudiation.

[0073] For example, in this embodiment of the application, the signature of the quantum communication device is verified by the public key of the quantum communication device. Both parties in the communication can verify the legitimacy of the other party, thereby achieving two-way mutual recognition.

[0074] For example, in this embodiment of the application, the security of transmitted information is guaranteed by the fundamental principles of quantum mechanics. The sender signs the encrypted information using their private key, and the receiver verifies the signature using their public key. If the message is tampered with, the verification will fail, thus ensuring the confidentiality and integrity of the transmitted data.

[0075] For example, each participant in the communication generates a signature using their respective private key for a post-quantum cryptographic digital signature algorithm, and the signature is verified by the receiving party. Only legitimate parties can generate valid signatures, therefore any attacker without the corresponding private key cannot forge a valid signature. Furthermore, each participant cannot deny that they have sent the signature to the receiving party. Therefore, the embodiments of this application possess unforgeability and non-repudiation.

[0076] The above description primarily focuses on the methodological aspects of the embodiments of this application. Those skilled in the art should readily recognize that, based on the operations or steps described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Those skilled in the art can implement the described functionality in different ways for each specific operation or method, and such implementations should not be considered beyond the scope of this application.

[0077] The apparatus embodiments of this application are described below. For details not described in the apparatus embodiments of this application, please refer to the method embodiments of this application.

[0078] Figure 4 A device block diagram of a quantum communication device according to an example embodiment of this application is shown. According to the embodiment of this application, Figure 4 The quantum communication device shown is capable of access authentication in quantum direct communication networks.

[0079] In a specific embodiment, the quantum direct communication network includes a quantum communication device and a peer quantum communication device. The first quantum communication device stores a first digital certificate, which includes the first quantum communication device's verification public key.

[0080] like Figure 4 As shown, the quantum communication device includes a first sending unit 401, a transmission data signature unit 403, and a second sending unit 405. The first sending unit 401, in response to a user's access authentication request to the quantum communication device, sends a first digital certificate to the other quantum communication device, enabling the other quantum communication device to obtain the quantum communication device's verification public key through the first digital certificate. The transmission data signature unit 403, using the first quantum communication device's signature private key, signs the first transmission data to obtain a first transmission data signature. The second sending unit 405, directly sending the first transmission data and the first transmission data signature to the other quantum communication device, allows the other quantum communication device to verify the first transmission data signature using the first quantum communication device's signature public key for access authentication.

[0081] Figure 5 An electronic device according to an exemplary embodiment of this application is shown. Reference is made below. Figure 5 To describe an electronic device 200 according to this embodiment of the present application. Figure 5 The electronic device 200 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0082] like Figure 5 As shown, the electronic device 200 is presented in the form of a general-purpose computing device. The components of the electronic device 200 may include, but are not limited to: at least one processing unit 210, at least one storage unit 220, a bus 230 connecting different system components (including storage unit 220 and processing unit 210), a display unit 240, etc.

[0083] The storage unit stores program code, which can be executed by the processing unit 210 to perform the methods described in this specification according to various exemplary embodiments of this application. For example, the processing unit 210 can perform the method shown in FIG1.

[0084] Storage unit 220 may include readable media in the form of volatile storage units, such as random access memory (RAM) 2201 and / or cache memory 2202, and may further include read-only memory (ROM) 2203.

[0085] Storage unit 220 may also include a program / utility 2204 having a set (at least one) program module 2205, such program module 2205 including but not limited to: operating system, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.

[0086] Bus 230 can represent one or more of several types of bus structures, including a memory cell bus or memory cell controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the various bus structures.

[0087] Electronic device 200 can also communicate with one or more external devices 300 (e.g., keyboard, pointing device, Bluetooth device, etc.), and with one or more devices that enable a user to interact with electronic device 200, and / or with any device that enables electronic device 200 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 250. Furthermore, electronic device 200 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 260. Network adapter 260 can communicate with other modules of electronic device 200 via bus 230. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 200, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0088] Through the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. The technical solutions according to the embodiments of this application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, or network device, etc.) to execute the methods described above according to the embodiments of this application.

[0089] Software products may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example,, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: electrical connections with one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0090] Computer-readable storage media may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable storage medium may also be any readable medium other than a readable storage medium that can transmit, propagate, or transfer a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0091] Program code for performing the operations of this application can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, and conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0092] The aforementioned computer-readable medium carries one or more programs, which, when executed by a device, cause the computer-readable medium to perform the aforementioned functions.

[0093] Those skilled in the art will understand that the above modules can be distributed in the device as described in the embodiments, or they can be modified accordingly and placed in one or more devices that are unique to this embodiment. The modules in the above embodiments can be combined into one module, or they can be further divided into multiple sub-modules.

[0094] According to an embodiment of this application, a computer program is proposed, including a computer program or instructions, which, when executed by a processor, can perform the methods described above.

[0095] The embodiments of this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the embodiments above are only for the purpose of helping to understand the method and core ideas of this application. Furthermore, any changes or modifications made by those skilled in the art based on the ideas of this application, and on the specific implementation methods and application scope of this application, are all within the scope of protection of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. An access authentication method for quantum direct communication networks, characterized in that, The quantum direct communication network includes a first quantum communication device and a second quantum communication device. The first quantum communication device stores a first digital certificate, which includes a first quantum communication device signature verification public key. The access authentication method is used on the first quantum communication device and includes: In response to a user's access authentication request for the first quantum communication device, the first quantum communication device sends the first digital certificate to the second quantum communication device, so that the second quantum communication device can obtain the signature verification public key of the first quantum communication device through the first digital certificate; The first quantum communication device uses its signature private key to sign the first transmitted data, thereby obtaining a signature of the first transmitted data. The first quantum communication device encodes the first transmission data and the first transmission data signature in a quantum state and sends them directly to the second quantum communication device through the quantum direct communication network, so that the second quantum communication device can use the signature verification public key of the first quantum communication device to verify the first transmission data signature and perform access authentication for the first quantum communication device. The quantum direct communication network also includes a digital certificate issuance device; wherein... The digital certificate issuing device uses a post-quantum cryptography digital signature algorithm to generate a private key for signing and a public key for verifying signatures. In response to a user's request for digital certificates for the first quantum communication device and the second quantum communication device, the digital certificate issuing device sends its verification public key to the first quantum communication device and the second quantum communication device. The first quantum communication device and the second quantum communication device generate their respective signature private keys and signature verification public keys; The first quantum communication device and the second quantum communication device send the signature verification public key to the digital certificate issuing device; The digital certificate issuing device uses the signature verification public key to generate a digital certificate and sends it to the first quantum communication device and the second quantum communication device.

2. The access authentication method according to claim 1, characterized in that, Before the first quantum communication device signs the first transmitted data using its signature private key to obtain the first transmitted data signature, the process further includes: The first quantum communication device sends a single-photon qubit to the second quantum communication device so that the second quantum communication device can confirm the first quantum communication device.

3. The access authentication method according to claim 1, characterized in that, Before the first quantum communication device signs the first transmitted data using its signature private key to obtain the first transmitted data signature, the process further includes: The first quantum communication device receives a single-photon qubit sent from the second quantum communication device to confirm the second quantum communication device.

4. The access authentication method according to claim 1, characterized in that, Also includes: The first quantum communication device receives a second digital certificate from the second quantum communication device, wherein the second digital certificate includes the second quantum communication device verification public key of the second quantum communication device; The first quantum communication device uses the issuing device's signature verification public key to verify the second digital certificate; The first quantum communication device determines whether to perform access authentication for the second quantum communication device based on the verification result.

5. The access authentication method according to claim 4, characterized in that, Also includes: After the signature verification is successful, the signature verification public key of the second quantum communication device is obtained using the second digital certificate; The first quantum communication device receives the second transmission data and the second transmission data signature sent by the second quantum communication device; The first quantum communication device uses the signature verification public key of the second quantum communication device to verify the signature of the second transmitted data in order to authenticate access to the second quantum communication device.

6. The access authentication method according to claim 3, characterized in that, After receiving a single-photon qubit from the second quantum communication device to confirm the second quantum communication device, and before the first quantum communication device directly sends the first transmitted data and the first transmitted data signature to the second quantum communication device, the method further includes: The first quantum communication device calculates the bit error rate of the received single-photon qubit.

7. A quantum communication device capable of access authentication in a quantum direct communication network, characterized in that, The quantum direct communication network includes the quantum communication device and a peer quantum communication device. The quantum communication device stores a first digital certificate, which includes the quantum communication device's signature verification public key. The quantum communication device includes: The first sending unit is configured to send the first digital certificate to the other quantum communication device in response to a user's access authentication request for the quantum communication device, so that the other quantum communication device can obtain the quantum communication device's signature verification public key through the first digital certificate. A data transmission signature unit is used to sign the first transmitted data using the quantum communication device signature private key of the quantum communication device to obtain a first transmitted data signature; The second sending unit is used to encode the first transmission data and the first transmission data signature in a quantum state and send them directly to the other quantum communication device through the quantum direct communication network, so that the other quantum communication device can use the quantum communication device signature verification public key to verify the first transmission data signature and perform access authentication for the quantum communication device. The quantum direct communication network also includes a digital certificate issuance device; wherein... The digital certificate issuing device uses a post-quantum cryptography digital signature algorithm to generate a private key for signing and a public key for verifying signatures. In response to a user's request for digital certificates for the quantum communication device and the other quantum communication device, the digital certificate issuing device sends its verification public key to the quantum communication device and the other quantum communication device. The quantum communication device and the other quantum communication device generate their respective signature private keys and signature verification public keys; The quantum communication device and the counterpart quantum communication device send the signature verification public key to the digital certificate issuing device; The digital certificate issuing device uses the signature verification public key to generate a digital certificate and sends it to the quantum communication device and the other quantum communication device.

8. An electronic device, characterized in that, include: A memory and a processor; wherein the memory stores one or more computer instructions, wherein the one or more computer instructions, when executed by the processor, implement the access authentication method as described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, It stores a computer program that, when executed, implements the access authentication method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Multi-party quantum identity authentication method based on multi-party quantum secure direct communication

    CN116015482A

  • Quantum security block chain communication method based on quantum direct communication and optical network

    CN116886281A