A continuous variable quantum secret sharing method based on local oscillator
By locally generating vibration light at the legal measurement end and performing phase drift compensation, the security vulnerability of the local vibration light during unsafe channel transmission is solved, and the high security and reliability of the continuous variable quantum secret sharing system is achieved.
Patent Information
- Application Number
- CN202410894541.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-04
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2044-07-04
AI Technical Summary
In the existing continuous variable quantum secret sharing method, local oscillator light is vulnerable to attack when transmitted insecure channels, resulting in security problems. Although existing solutions have been improved, security vulnerabilities have not been completely eliminated.
The method of local generation of vibration light is adopted, and the heterodyne measurement and phase drift compensation technology is used to ensure that the local vibration light does not need to be transmitted through unsafe channels, and phase drift compensation is performed on the legal measurement end, eliminating security loopholes in the attack end manipulation and transmission.
It improves the actual security and reliability of the continuous variable quantum secret sharing system, avoids security threats during local oscillator transmission, and ensures the reliability and security of information sharing.
Smart Images

Figure CN118784223B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of quantum communication, and in particular relates to a continuous variable quantum secret sharing method based on local oscillators. Background Art
[0002] Secret sharing (SS) supports the establishment of secure keys between multiple parties. In a typical (k,n) threshold secret sharing scheme, the secret is divided into n shares, and a participant can only fully reconstruct it if they possess at least any k of the shares. With the rapid development of quantum technology, quantum secret sharing (QSS) has been proposed. Compared with traditional SS, the security of QSS is no longer based on computational complexity but is guaranteed by the principles of quantum mechanics, thereby elevating the security level from computational security to theoretical unconditional security. Among them, continuous variable quantum secret sharing (CVQSS) has the advantages of low detection cost, high theoretical security code rate, ease of integration, and compatibility with classical optical communication networks, making it the most practical type of QSS protocol.
[0003] In the actual implementation of CVQSS, the local oscillator (LO) used for coherent detection is generated by a user laser and then needs to be transmitted to the dealer via an insecure channel. However, the LO exposed in the insecure channel is vulnerable to a series of targeted attacks launched by an attacker, Eve, such as known wavelength attacks, LO calibration attacks, LO fluctuation attacks, clock synchronization jitter attacks, and LO polarization attacks, posing a threat to the actual security of CVQSS. Researchers have studied these attacks and proposed corresponding defense strategies, such as round-trip CVQSS, in which both the LO and quantum signal are generated by the dealer, eliminating the need for LO transmission. Although this solution addresses the security vulnerability of the LO, it requires the transmission of unmodulated quantum states through an insecure quantum channel. In essence, it does not completely eliminate the security vulnerability of the CVQSS system, but rather shifts the vulnerability elsewhere, undoubtedly introducing new practical security issues for CVQSS. Summary of the Invention
[0004] The object of the present invention is to provide a local oscillator-based continuous variable quantum secret sharing method with high reliability and good security.
[0005] The continuous variable quantum secret sharing method based on local local oscillator provided by the present invention comprises the following steps:
[0006] S1. Setting a continuous variable quantum secret sharing system includes a first user terminal, a second user terminal and a legitimate measurement terminal, and obtaining parameter information of the first user terminal, the second user terminal and the legitimate measurement terminal;
[0007] S2. The first user terminal generates a first output quantum state and sends it to the second user terminal;
[0008] S3. The second user terminal generates a second output quantum state, mixes it with the first output quantum state to obtain a mixed quantum state, and sends the mixed quantum state to the legitimate measurement terminal; at the same time, the second user terminal obtains the second user-first user reference phase through heterodyne detection;
[0009] S4. The legitimate measurement end generates local oscillator light and obtains the legitimate measurement by heterodyne measurement - the first user reference phase and heterodyne measurement results;
[0010] S5. The second user terminal performs phase fast drift compensation based on the second user - first user reference phase, and the legitimate measurement terminal performs phase fast drift compensation based on the legitimate measurement - first user reference phase, to obtain the second user correction data and the legitimate measurement terminal correction data;
[0011] S6. Repeat steps S2 to S5 several times; the first user terminal compensates for its own slow phase drift to obtain first user correction data, and the second user terminal compensates for the slow phase drift based on the second user correction data to obtain second user secondary correction data; the first user terminal, the second user terminal, and the legitimate measurement terminal have mastered the corresponding original data set;
[0012] S7. The legitimate measurement terminal randomly selects a subset of the original data set and requires the first user terminal and the second user terminal to disclose the corresponding original data, completes the channel transmittance estimation of the first user terminal and the second user terminal, and then discards the public data;
[0013] S8. The legitimate measurement end selects different subsets from the original data set, establishes connections with the first user end and the second user end, and replaces the subsets. The legitimate measurement end estimates the lower bounds of the key rate between the legitimate measurement end and the first user end, and between the legitimate measurement end and the second user end, thereby obtaining the final key rate.
[0014] S9. Based on the final key rate, the remaining data in the original data set is processed to generate a key between the legitimate measurement terminal and the first user terminal, the legitimate measurement terminal and the second user terminal;
[0015] S10. The legitimate measurement terminal uses the keys shared between the legitimate measurement terminal and the first user terminal, and the legitimate measurement terminal and the second user terminal to encrypt the shared information, and sends the encrypted shared information to the first user terminal and the second user terminal, completing the secret sharing of the shared information between the first user terminal and the second user terminal.
[0016] The first user terminal in step S2 generates a first output quantum state and sends it to the second user terminal, which specifically includes the following steps:
[0017] The laser at the first user end generates a light pulse and splits it into two beams through a 50:50 beam splitter. The first beam is passed through an amplitude modulator, a phase modulator, and a variable optical attenuator to obtain a Gaussian modulated coherent state. The second beam is delayed by half the pulse interval to obtain a reference signal. The Gaussian modulated coherent state and the reference signal are then combined through a beam splitter to obtain the first output quantum state |x1+ip1>, which is sent to the second user end.
[0018] The second user terminal in step S3 generates a second output quantum state, mixes it with the first output quantum state to obtain a mixed quantum state, and sends the mixed quantum state to the legitimate measurement terminal; at the same time, the second user terminal obtains a second user-first user reference phase through heterodyne detection, which specifically includes the following steps:
[0019] The laser at the second user end generates an optical pulse and splits it into two beams via a 50:50 beam splitter. The first beam passes through an amplitude modulator, a phase modulator, and a variable optical attenuator to produce a Gaussian modulated coherent state. The second beam is delayed by half the pulse interval to produce a reference signal. The Gaussian modulated coherent state is coupled to the same spatiotemporal pattern as the first output quantum state |x1+ip1> via a highly asymmetric beam splitter to produce a mixed quantum state. The mixed quantum state includes the first output quantum state |x1+ip1>, the second output quantum state |x2+ip2>, and the first user end reference signal. Finally, the mixed quantum state is sent to the legitimate measurement end.
[0020] At the same time, the second user end reference signal and the first output quantum state |x1+ip1> reflected by the highly asymmetric beam splitter are measured by a heterodyne detector to obtain the second user-first user reference phase between the first user end and the second user end.
[0021] The legitimate measurement end in step S4 generates local oscillator light and obtains the legitimate measurement-first user reference phase and the heterodyne measurement result through heterodyne measurement, which specifically includes the following steps:
[0022] The legitimate measurement end generates local oscillator light locally and splits it into the first local oscillator light and the second local oscillator light through a 50:50 beam splitter. The second local oscillator light is delayed by half the pulse interval through the path to obtain the second delayed local oscillator light.
[0023] The mixed quantum state received by the legal measurement end is divided into two parts by a highly asymmetric beam splitter: the first part uses the first local oscillator light for heterodyne measurement to obtain the heterodyne measurement result {x D ,p D The second part uses the second delayed local oscillator light to perform heterodyne measurement to obtain the legal measurement-first user reference phase of the first user end and the legal measurement end
[0024] The second user terminal in step S5 performs phase fast drift compensation based on the second user-first user reference phase, and the legitimate measurement terminal performs phase fast drift compensation based on the legitimate measurement-first user reference phase, thereby obtaining second user correction data and legitimate measurement terminal correction data, which specifically includes the following steps:
[0025] The second user terminal uses the second user-first user reference phase Perform phase fast drift compensation to obtain the second user correction data {x'2, p'2};
[0026] In specific implementation, the second user correction data {x'2, p'2} is calculated using the following formula:
[0027]
[0028] The legal measurement end uses the legal measurement-first user reference phase Perform phase fast drift compensation to obtain the legal measurement end correction data {x' D ,p' D};
[0029] In specific implementation, the following formula is used to calculate the legal measurement end correction data {x' D ,p' D}:
[0030]
[0031] Where η is the heterodyne detection efficiency; T1 is the channel transmittance of the first user end signal; Φ1 is the quantum signal phase drift of the first user end; Φ2 is the quantum signal phase drift of the second user end; x' N is the modified Gaussian noise x component; p' N is the modified Gaussian noise p component; is the cumulative phase difference between the legitimate measurement end and the first user end; T2 is the channel transmittance of the second user end signal; is the cumulative phase difference between the legitimate measurement end and the second user end.
[0032] Step S6 repeats steps S2 to S5 several times; the first user terminal compensates for its own slow phase drift to obtain first user correction data, and the second user terminal compensates for the slow phase drift based on the second user correction data to obtain second user secondary correction data; the first user terminal, the second user terminal, and the legitimate measurement terminal have corresponding original data sets, specifically including the following steps:
[0033] Repeat steps S2 to S5 several times;
[0034] Legal measurement end discloses some data x' D, the first user end and the second user end respectively calculate x' D Cross-correlation data;
[0035] The following formula is used to calculate the x component and x' of the first user end D Cross-correlation data <x1x' D >:
[0036]
[0037] In the formula <x1x1>is the autocorrelation data of the x component of the first user terminal;
[0038] The following formula is used to calculate the p component and x' of the first user end: D Cross-correlation data:
[0039]
[0040] In the formula <p1p1>is the autocorrelation data of the p component of the first user terminal, and \p1p1>= <x1x1>;
[0041] Get the first user end pair Estimated value of for
[0042] The x component and x' of the second user correction data are calculated using the following formula: D Cross-correlation data <x'2x' D >:
[0043]
[0044] The p component and x' of the second user correction data are calculated using the following formula: D Cross-correlation data <p'2x' D >:
[0045]
[0046] Get the second user terminal Estimated value of for
[0047] The first user terminal, the second user terminal, and the legitimate measurement terminal discard their own public data and the data used for calculation. The first user terminal corrects {x1, p1} using the following formula to obtain the first user corrected data {x′1, p′1}:
[0048]
[0049] The second user uses the following formula to correct {x'2, p'2}, and the second user corrects the data {x″2, p″2} twice:
[0050]
[0051] At this point, the total phase offset of the quantum signal is compensated. The first user end, the second user end and the legal measurement end have the original data set {x′1, p′1} m , {x″2,p″2} m and {x′ D ,p' D } m .
[0052] In step S8, the legitimate measurement end selects different subsets from the original data set, establishes connections with the first user end and the second user end, replaces the subsets, and estimates the lower bounds of the key rate between the legitimate measurement end and the first user end, and between the legitimate measurement end and the second user end, thereby obtaining a final key rate. The steps are as follows:
[0053] The legitimate measurement end selects a subset from the original data set and requires the second user end to disclose the corresponding value; at this time, the legitimate measurement end replaces the subset with x D1 is the x component corresponding to the first user correction data, p D1 is the p component corresponding to the first user's correction data; then, the continuous variable quantum key distribution (CVQKD) security analysis technique is used to estimate the lower bound R1 of the key rate between the legitimate measurement end and the first user end;
[0054] The legitimate measurement end selects a subset from the original data set again and requires the first user end to disclose the corresponding value; at this time, the legitimate measurement end replaces the subset with x D2 is the x component corresponding to the second user's secondary correction data, p D2 is the p component corresponding to the second user's secondary correction data; then, the CVQKD security analysis technique is used to estimate the lower bound R2 of the key rate between the legitimate measurement end and the second user end; the legitimate measurement end, the first user end, and the second user end discard the data that has been disclosed;
[0055] Finally, the legitimate measurement end selects the minimum value between the key rate lower bound R1 and the key rate lower bound R2 as the final key rate R.
[0056] Step S9, in which the remaining data in the original data set is processed according to the final key rate to generate keys between the legitimate measurement terminal and the first user terminal, and between the legitimate measurement terminal and the second user terminal, specifically includes the following steps:
[0057] If the final key rate R is positive, the remaining undisclosed data is processed using the CVQKD post-processing procedure to obtain the key K1 between the legitimate measurement terminal and the first user terminal and the key K2 between the legitimate measurement terminal and the first user terminal respectively;
[0058] If the final key rate R is negative, the key cannot be generated.
[0059] The legitimate measurement terminal in step S10 encrypts the shared information using the keys shared between the legitimate measurement terminal and the first user terminal, and between the legitimate measurement terminal and the second user terminal, and sends the encrypted shared information to the first user terminal and the second user terminal, thereby completing the secret sharing of the shared information between the first user terminal and the second user terminal. The steps specifically include the following:
[0060] The legal measurement end uses the key K1 and the key K2 to encrypt the shared information M into The encrypted shared information E is broadcasted to the first user terminal and the second user terminal, completing the secret sharing of the shared information between the first user terminal and the second user terminal.
[0061] The continuous variable quantum secret sharing method based on local local oscillators provided by the present invention eliminates the need to transmit local oscillator light through insecure channels by locally generating local oscillator light at the legitimate measurement end, avoids the security vulnerability of the attacker manipulating the transmitted local oscillator light, and improves the actual security of the continuous variable quantum secret sharing system. The phase compensation scheme in the method of the present invention ensures the reliability of the method of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] Figure 1 Schematic diagram of the process of the present invention.
[0063] Figure 2 Schematic diagram of phase compensation of the method of the present invention.
[0064] Figure 3 Schematic diagram of (n,n) threshold performance of an embodiment of the method of the present invention. DETAILED DESCRIPTION
[0065] like Figure 1 The figure shows a flow chart of the method of the present invention: The continuous variable quantum secret sharing method based on local local oscillator disclosed in the present invention comprises the following steps:
[0066] The present invention considers the basic (2,2) threshold case, where two remote users (a first user terminal and a second user terminal) are connected sequentially to the legitimate measurement terminal Dealer via an insecure quantum channel;
[0067] S1. Setting a continuous variable quantum secret sharing system includes a first user terminal, a second user terminal and a legitimate measurement terminal, and obtaining parameter information of the first user terminal, the second user terminal and the legitimate measurement terminal;
[0068] S2. The first user terminal generates a first output quantum state and sends it to the second user terminal; specifically comprising the following steps:
[0069] The laser at the first user end generates an optical pulse and splits it into two beams through a 50:50 beam splitter. The first beam passes through an amplitude modulator, a phase modulator, and a variable optical attenuator to produce a Gaussian modulated coherent state. The second beam is delayed by half the pulse interval to produce a reference signal. The Gaussian modulated coherent state and the reference signal are then combined through a beam splitter to produce the first output quantum state |x1+ip1>, which is sent to the second user end.
[0070] S3. The second user terminal generates a second output quantum state, mixes it with the first output quantum state to obtain a mixed quantum state, and sends the mixed quantum state to the legitimate measurement terminal; at the same time, the second user terminal obtains a second user-first user reference phase through heterodyne detection; specifically, the steps include:
[0071] The laser at the second user end generates an optical pulse and splits it into two beams via a 50:50 beam splitter. The first beam passes through an amplitude modulator, a phase modulator, and a variable optical attenuator to produce a Gaussian modulated coherent state. The second beam is delayed by half the pulse interval to produce a reference signal. The Gaussian modulated coherent state is coupled to the same spatiotemporal pattern as the first output quantum state |x1+ip1> via a highly asymmetric beam splitter to produce a mixed quantum state. The mixed quantum state includes the first output quantum state |x1+ip1>, the second output quantum state |x2+ip2>, and the first user end reference signal. Finally, the mixed quantum state is sent to the legitimate measurement end.
[0072] At the same time, the second user end reference signal and the first output quantum state |x1+ip1> reflected by the highly asymmetric beam splitter are measured by a heterodyne detector to obtain the second user-first user reference phase between the first user end and the second user end.
[0073] S4. The legitimate measurement end generates local oscillator light and obtains the legitimate measurement - the first user reference phase and the heterodyne measurement result by heterodyne measurement; specifically comprising the following steps:
[0074] The legitimate measurement end generates local oscillator light locally and splits it into the first local oscillator light and the second local oscillator light through a 50:50 beam splitter. The second local oscillator light is delayed by half the pulse interval through the path to obtain the second delayed local oscillator light.
[0075] The mixed quantum state received by the legal measurement end is divided into two parts by a highly asymmetric beam splitter: the first part uses the first local oscillator light for heterodyne measurement to obtain the heterodyne measurement result {x D ,p D The second part uses the second delayed local oscillator light to perform heterodyne measurement to obtain the legal measurement-first user reference phase of the first user end and the legal measurement end
[0076] S5. The second user terminal performs phase fast drift compensation based on the second user-first user reference phase, and the legitimate measurement terminal performs phase fast drift compensation based on the legitimate measurement-first user reference phase to obtain the second user correction data and the legitimate measurement terminal correction data; specifically comprising the following steps:
[0077] Heterodyne measurement result {x D ,p D }There is a phase drift, which can be expressed as
[0078]
[0079] Where η is the heterodyne detection efficiency; x N and p N is the independent Gaussian noise including unit shot noise, electronic noise and over-noise generated by the attack end; Φ1 and Φ2 are the quantum signal phase drifts of the first user end and the second user end, expressed as in and are the initial phases of the lasers of the first user end, the second user end, and the legitimate measurement end Dealer respectively;
[0080] By introducing these initial phases, the reference phases measured by the second user end and the legitimate measurement end Dealer can be derived as
[0081]
[0082] In the formula is the accumulated phase of the first user terminal reference signal; θ2 delay is the accumulated phase of the second user terminal reference signal; is the accumulated phase of the delayed local oscillator light of the legal measurement end Dealer;
[0083] The phase drift of quantum signal can be rewritten as
[0084]
[0085] In the formula is the cumulative phase difference between the legitimate measurement end and the first user end; is the cumulative phase difference between the legitimate measurement end and the second user end;
[0086] It is not difficult to find that the total phase drift of each user's quantum signal consists of two parts, namely the reference phase difference between the user and the dealer and the cumulative phase difference between the user and the dealer;
[0087] like Figure 2 The figure shows a phase compensation diagram of the method of the present invention. The present step S5 and the next step S6 respectively compensate for the fast and slow phase drifts by using two-step phase rotation.
[0088] The second user terminal uses the second user-first user reference phase Perform phase fast drift compensation to obtain the second user correction data {x'2, p'2};
[0089] When implementing:
[0090] In the first phase rotation step, the second user correction data {x'2, p'2} is calculated using the following formula:
[0091]
[0092] The legal measurement end uses the legal measurement-first user reference phase Perform phase fast drift compensation to obtain the legal measurement end correction data {x' D ,p' D };
[0093] In specific implementation, the following formula is used to calculate the legal measurement end correction data {x' D ,p' D }:
[0094]
[0095] Where η is the heterodyne detection efficiency; T1 is the channel transmittance of the first user end signal; Φ1 is the quantum signal phase drift of the first user end; Φ2 is the quantum signal phase drift of the second user end; x' N is the modified Gaussian noise x component; p' N is the modified Gaussian noise p component; is the cumulative phase difference between the legitimate measurement end and the first user end; T2 is the channel transmittance of the second user end signal; is the cumulative phase difference between the legitimate measurement end and the second user end;
[0096] At this point, the initial phases of the lasers at the second user and the authorized measurement end (Dealer) can be considered identical to the initial phase of the laser at the first user, eliminating the rapid phase drift between different lasers. However, it is clear that there is still a cumulative phase difference between the authorized measurement end (Dealer) and each user.
[0097] S6. Repeat steps S2 to S5 several times; the first user terminal compensates for its own slow phase drift to obtain first user correction data, and the second user terminal compensates for the slow phase drift based on the second user correction data to obtain second user secondary correction data; the first user terminal, the second user terminal, and the legitimate measurement terminal have mastered the corresponding original data sets; specifically, the steps include:
[0098] Repeat steps S2 to S5 several times;
[0099] Legal measurement end discloses some data x' D , the first user end and the second user end respectively calculate x' D Cross-correlation data;
[0100] The following formula is used to calculate the x component and x' of the first user end D Cross-correlation data <x1x' D >:
[0101] Since x1, p1, x2, p2, x' N and p' N are independent of each other, so there are <x1p1> = <x1x2> = <x1p2>= <x1x' N >=0; Therefore, the above formula is simplified to
[0102]
[0103] In the formula <x1x1>is the autocorrelation data of the x component of the first user terminal;
[0104] Similarly, the p component and x' of the first user end are calculated using the following formula: D Cross-correlation data
[0105] In the formula <p1p1>is the autocorrelation data of the p component of the first user terminal, and <p1p1> = <x1x1>;
[0106] Get the first user end pair Estimated value of for
[0107] The x component and x' of the second user correction data are calculated using the following formula: D Cross-correlation data <x'2x' D >:
[0108]
[0109] Therefore, there is
[0110] The p component and x' of the second user correction data are calculated using the following formula: D Cross-correlation data <p'2x' D >:
[0111]
[0112] Therefore, there is
[0113] Get the second user terminal Estimated value of for
[0114] The first user terminal, the second user terminal and the legal measurement terminal discard the data disclosed by each terminal and used for calculation;
[0115] In the second phase rotation step, the first user terminal corrects {x1, p1} using the following formula to obtain the first user corrected data {x′1, p′1}:
[0116]
[0117] The second user uses the following formula to correct {x'2, p'2}, and the second user corrects the data {x″2, p″2} twice:
[0118]
[0119] At this point, the total phase offset of the quantum signal is compensated; the first user end, the second user end and the legal measurement end have mastered the original data set {x′1, p′1} m , {x″2,p″2} m and {x' D ,p' D } m ;
[0120] S7. The legitimate measurement end randomly selects a subset of the original data set and requires the first user end and the second user end to disclose the corresponding original data. It completes the channel transmittance estimation of the first user end and the second user end to obtain {T1, T2}, and then discards the disclosed data.
[0121] S8. The legitimate measurement end selects different subsets from the original data set, establishes connections with the first user end and the second user end, and replaces the subsets. The legitimate measurement end estimates the lower bounds of the key rate between the legitimate measurement end and the first user end, and between the legitimate measurement end and the second user end, thereby obtaining a final key rate. This specifically includes the following steps:
[0122] The legitimate measurement end selects a subset from the original data set and requires the second user end to disclose the corresponding value; at this time, the legitimate measurement end replaces the subset with x D1 is the x component corresponding to the first user correction data, p D1 is the p component corresponding to the first user's corrected data. At this point, a point-to-point CVQKD link is actually established between the legitimate measurement end Dealer and the first user. Then, using classic CVQKD security analysis techniques, the lower bound R1 of the key rate between the legitimate measurement end and the first user is estimated.
[0123] Similarly, the legitimate measurement end selects a subset from the original data set again and requires the first user end to disclose the corresponding value; at this time, the legitimate measurement end replaces the subset with and x D2 is the x component corresponding to the second user's secondary correction data, p D2 is the p component corresponding to the second user's secondary correction data; then, the CVQKD security analysis technique is used to estimate the lower bound R2 of the key rate between the legitimate measurement end and the second user end; the legitimate measurement end, the first user end, and the second user end discard the data that has been disclosed;
[0124] Finally, the legitimate measurement end selects the minimum value of the key rate lower bound R1 and the key rate lower bound R2 as the final key rate R for secret sharing;
[0125] S9. Process the remaining data in the original data set according to the final key rate to generate a key between the legitimate measurement terminal and the first user terminal, and between the legitimate measurement terminal and the second user terminal; specifically comprising the following steps:
[0126] If the final key rate R is positive, the remaining undisclosed data is processed using the CVQKD post-processing procedure to obtain the key K1 between the legitimate measurement terminal and the first user terminal and the key K2 between the legitimate measurement terminal and the first user terminal respectively;
[0127] If the final key rate R is negative, the key cannot be generated;
[0128] S10. The legitimate measurement terminal uses the key between the legitimate measurement terminal and the first user terminal, the legitimate measurement terminal and the second user terminal to encrypt the shared information, and sends the encrypted shared information to the first user terminal and the second user terminal, completing the secret sharing of the shared information between the first user terminal and the second user terminal; specifically comprising the following steps:
[0129] The legal measurement end uses the key K1 and the key K2 to encrypt the shared information M into The encrypted shared information E is broadcasted to the first user terminal and the second user terminal, completing the secret sharing of the shared information between the first user terminal and the second user terminal.
[0130] The performance of the method of the present invention is described below with reference to an embodiment:
[0131] A universal noise model for secret sharing of the method of the present invention is constructed, wherein the variances of quantum signals of the first user end and the second user end are
[0132] When the first user end and the second user end generate quantum signals, due to the limited dynamic range of the actual amplitude modulator, there is not enough extinction ratio to accurately control the modulation variance. The modulation noise can be quantified as
[0133]
[0134] where d dB is the finite dynamics of the amplitude modulator, α S1 and α S2 is the maximum amplitude of the first user end and the second user end signal, respectively It is worth noting that the transmittance of HABS is The channel transmittance of each user can be expressed as Where α is the fiber attenuation coefficient, and l is the fiber length to the legitimate measurement end (dealer). The quantum signal is coupled to the first user-end reference signal via a beam splitter (or a highly asymmetric beam splitter). Because the generation of optical pulses is limited by the extinction ratio, residual photons within the reference signal interval will contaminate the quantum signal. The photon leakage noise can be quantified as:
[0135]
[0136] Where |α R1 | is the amplitude of the reference signal at the first user end; R e is the finite extinction ratio of the amplitude modulator;
[0137] The output voltage of the legal measurement terminal Dealer is quantized by an imperfect analog-to-digital converter (ADC). D ,p D The ADC quantization noise introduced in} is
[0138]
[0139] Where q is the quantization number of the ADC; the phase noise caused by the phase compensation deviation can be expressed as ε phase =ε fast +ε slow , where the compensation noise of the fast phase drift ε fast =ε drift +ε error , compensation noise of slow phase drift ε slow Depends on the compensation error V slow Since the quantum signal and the reference signal are generated by the same laser, V drift =0;ε error It reflects the reference phase measurement error introduced by the heterodyne detection between the second user end and the legal measurement end, which can be calculated as
[0140]
[0141] in is the total noise applied to the first user terminal reference signal, where ε ch is the channel noise of the phase reference, v el is electrical noise;
[0142] After the above analysis, the sum of the channel input noise is ε=ε AM +ε LE +ε ADC +ε error +ε rest , is the noise at the input of the channel in the key rate calculation When we expand the system to the (n,n) threshold case, we can calculate the excess noise introduced by the i-th (i=2, 3, 4, ..., n) user end according to the formula for the excess noise introduced by the second user end in the (2,2) threshold above.
[0143] On this basis, the asymptotic key rate of the secret sharing system of the present invention is evaluated, and the (n,n) threshold performance diagram is shown as follows: Figure 3 shown; through Figure 3 The numerical simulation results show that under the (2,2) threshold, the maximum transmission distance of the system is close to 80km. When the system accommodates more users, its asymptotic performance decreases with the expansion of the user scale. < / p1p1> < / x1x2> < / x1p1>
Claims
1. A continuous variable quantum secret sharing method based on local local oscillator, comprising the following steps: S1. Setting a continuous variable quantum secret sharing system includes a first user terminal, a second user terminal and a legitimate measurement terminal, and obtaining parameter information of the first user terminal, the second user terminal and the legitimate measurement terminal; S2. The first user terminal generates a first output quantum state and sends it to the second user terminal; S3. The second user terminal generates a second output quantum state, mixes it with the first output quantum state to obtain a mixed quantum state, and sends the mixed quantum state to the legitimate measurement terminal; at the same time, the second user terminal obtains the second user-first user reference phase through heterodyne detection; S4. The legitimate measurement end generates local oscillator light and obtains the legitimate measurement by heterodyne measurement - the first user reference phase and heterodyne measurement results; S5. The second user terminal performs phase fast drift compensation based on the second user - first user reference phase, and the legitimate measurement terminal performs phase fast drift compensation based on the legitimate measurement - first user reference phase, to obtain the second user correction data and the legitimate measurement terminal correction data; S6. Repeat steps S2 to S5 several times; the first user terminal compensates for its own slow phase drift to obtain first user correction data, and the second user terminal compensates for the slow phase drift based on the second user correction data to obtain second user secondary correction data; the first user terminal, the second user terminal, and the legitimate measurement terminal have mastered the corresponding original data set; S7. The legitimate measurement terminal randomly selects a subset of the original data set and requires the first user terminal and the second user terminal to disclose the corresponding original data, completes the channel transmittance estimation of the first user terminal and the second user terminal, and then discards the public data; S8. The legitimate measurement end selects different subsets from the original data set, establishes connections with the first user end and the second user end, and replaces the subsets. The legitimate measurement end estimates the lower bounds of the key rate between the legitimate measurement end and the first user end, and between the legitimate measurement end and the second user end, thereby obtaining the final key rate. S9. Based on the final key rate, the remaining data in the original data set is processed to generate a key between the legitimate measurement terminal and the first user terminal, the legitimate measurement terminal and the second user terminal; S10. The legitimate measurement terminal uses the keys shared between the legitimate measurement terminal and the first user terminal, and the legitimate measurement terminal and the second user terminal to encrypt the shared information, and sends the encrypted shared information to the first user terminal and the second user terminal, completing the secret sharing of the shared information between the first user terminal and the second user terminal.
2. The continuous variable quantum secret sharing method based on local local oscillator according to claim 1 is characterized in that The first user terminal in step S2 generates a first output quantum state and sends it to the second user terminal, which specifically includes the following steps: The laser at the first user end generates an optical pulse and splits it into two beams through a 50:50 beam splitter. The first beam is passed through an amplitude modulator, a phase modulator, and a variable optical attenuator to produce a Gaussian modulated coherent state. The second beam is delayed by half the pulse interval to produce a reference signal. The Gaussian modulated coherent state and the reference signal are then combined through a beam splitter to obtain the first output quantum state |x1+ip1>, which is then sent to the second user end.
3. The continuous variable quantum secret sharing method based on local local oscillator according to claim 2, characterized in that The second user terminal in step S3 generates a second output quantum state, mixes it with the first output quantum state to obtain a mixed quantum state, and sends the mixed quantum state to the legitimate measurement terminal; at the same time, the second user terminal obtains a second user-first user reference phase through heterodyne detection, which specifically includes the following steps: The laser at the second user end generates an optical pulse and splits it into two beams via a 50:50 beam splitter. The first beam passes through an amplitude modulator, a phase modulator, and a variable optical attenuator to produce a Gaussian modulated coherent state. The second beam is delayed by half the pulse interval to produce a reference signal. The Gaussian modulated coherent state is coupled to the same spatiotemporal pattern as the first output quantum state |x1+ip1> via a highly asymmetric beam splitter to produce a mixed quantum state. The mixed quantum state includes the first output quantum state |x1+ip1>, the second output quantum state |x2+ip2>, and the first user end reference signal. Finally, the mixed quantum state is sent to the legitimate measurement end. At the same time, the second user end reference signal and the first output quantum state |x1+ip1> reflected by the highly asymmetric beam splitter are measured by a heterodyne detector to obtain the second user-first user reference phase between the first user end and the second user end.
4. The continuous variable quantum secret sharing method based on local local oscillator according to claim 3 is characterized in that The legitimate measurement end in step S4 generates local oscillator light and obtains the legitimate measurement-first user reference phase and the heterodyne measurement result through heterodyne measurement, which specifically includes the following steps: The legitimate measurement end generates local oscillator light locally and splits it into the first local oscillator light and the second local oscillator light through a 50:50 beam splitter. The second local oscillator light is delayed by half the pulse interval through the path to obtain the second delayed local oscillator light. The mixed quantum state received by the legal measurement end is divided into two parts by a highly asymmetric beam splitter: the first part uses the first local oscillator light for heterodyne measurement to obtain the heterodyne measurement result {x D ,p D The second part uses the second delayed local oscillator light to perform heterodyne measurement to obtain the legal measurement-first user reference phase of the first user end and the legal measurement end 5. The continuous variable quantum secret sharing method based on local local oscillator according to claim 4 is characterized in that The second user terminal in step S5 performs phase fast drift compensation based on the second user-first user reference phase, and the legitimate measurement terminal performs phase fast drift compensation based on the legitimate measurement-first user reference phase, thereby obtaining second user correction data and legitimate measurement terminal correction data, which specifically includes the following steps: The second user terminal uses the second user-first user reference phase Perform phase fast drift compensation to obtain the second user correction data {x'2, p'2}; In specific implementation, the second user correction data {x'2, p'2} is calculated using the following formula: The legal measurement end uses the legal measurement-first user reference phase Perform phase fast drift compensation to obtain the legal measurement end correction data {x' D ,p' D }; In specific implementation, the following formula is used to calculate the legal measurement end correction data {x' D ,p' D }: Where η is the heterodyne detection efficiency; T1 is the channel transmittance of the first user end signal; Φ1 is the quantum signal phase drift of the first user end; Φ2 is the quantum signal phase drift of the second user end; x' N is the modified Gaussian noise x component; p' N is the modified Gaussian noise p component; is the cumulative phase difference between the legitimate measurement end and the first user end; T2 is the channel transmittance of the second user end signal; is the cumulative phase difference between the legitimate measurement end and the second user end.
6. The continuous variable quantum secret sharing method based on local local oscillator according to claim 5, characterized in that Step S6 repeats steps S2 to S5 several times; the first user terminal compensates for its own slow phase drift to obtain first user correction data, and the second user terminal compensates for the slow phase drift based on the second user correction data to obtain second user secondary correction data; the first user terminal, the second user terminal, and the legitimate measurement terminal have corresponding original data sets, specifically including the following steps: Repeat steps S2 to S5 several times; Legal measurement end discloses some data x' D , the first user end and the second user end respectively calculate x' D Cross-correlation data; The following formula is used to calculate the x component and x' of the first user end D Cross-correlation data <x1x' D >: In the formula <x1x1> is the autocorrelation data of the x component of the first user terminal; The following formula is used to calculate the p component and x' of the first user end: D Cross-correlation data In the formula <p1p1>is the autocorrelation data of the p component of the first user terminal, and <p1p1> = <x1x1> ;< / x1x1> < / p1p1> Get the first user end pair Estimated value of for The x component and x' of the second user correction data are calculated using the following formula: D Cross-correlation data <x'2x' D >: The p component and x' of the second user correction data are calculated using the following formula: D Cross-correlation data <p'2x' D >: Get the second user terminal Estimated value of for The first user terminal, the second user terminal and the legal measurement terminal discard the data disclosed by each terminal and used for calculation; The first user terminal corrects {x1, p1} using the following formula to obtain the first user corrected data {x′1, p′1}: The second user uses the following formula to correct {x'2, p'2}, and the second user corrects the data {x″2, p″2} twice: At this point, the total phase offset of the quantum signal is compensated; the first user end, the second user end and the legal measurement end have mastered the original data set {x′1, p′1} m , {x″2,p″2} m and {x' D ,p' D } m .
7. The continuous variable quantum secret sharing method based on local local oscillator according to claim 6, characterized in that In step S8, the legitimate measurement end selects different subsets from the original data set, establishes connections with the first user end and the second user end, replaces the subsets, and estimates the lower bounds of the key rate between the legitimate measurement end and the first user end, and between the legitimate measurement end and the second user end, thereby obtaining a final key rate. The steps are as follows: The legitimate measurement end selects a subset from the original data set and requires the second user end to disclose the corresponding value; at this time, the legitimate measurement end replaces the subset with and x D1 is the x component corresponding to the first user correction data, p D1 is the p component corresponding to the first user correction data; Then, the CVQKD security analysis technique is used to estimate the lower bound R1 of the key rate between the legitimate measurement terminal and the first user terminal; The legitimate measurement end selects a subset from the original data set again and requires the first user end to disclose the corresponding value; at this time, the legitimate measurement end replaces the subset with and x D2 is the x component corresponding to the second user's secondary correction data, p D2 is the p component corresponding to the second user's secondary correction data; Then, the CVQKD security analysis technique is used to estimate the lower bound R2 of the key rate between the legitimate measurement end and the second user end; the legitimate measurement end, the first user end, and the second user end discard the data that has been disclosed; Finally, the legitimate measurement end selects the minimum value between the key rate lower bound R1 and the key rate lower bound R2 as the final key rate R.
8. The continuous variable quantum secret sharing method based on local local oscillator according to claim 7, characterized in that Step S9, in which the remaining data in the original data set is processed according to the final key rate to generate keys between the legitimate measurement terminal and the first user terminal, and between the legitimate measurement terminal and the second user terminal, specifically includes the following steps: If the final key rate R is positive, the remaining undisclosed data is processed using the CVQKD post-processing procedure to obtain the key K1 between the legitimate measurement terminal and the first user terminal and the key K2 between the legitimate measurement terminal and the first user terminal respectively; If the final key rate R is negative, the key cannot be generated.
9. The continuous variable quantum secret sharing method based on local local oscillator according to claim 8, characterized in that The legitimate measurement terminal in step S10 encrypts the shared information using the keys shared between the legitimate measurement terminal and the first user terminal, and between the legitimate measurement terminal and the second user terminal, and sends the encrypted shared information to the first user terminal and the second user terminal, thereby completing the secret sharing of the shared information between the first user terminal and the second user terminal. The steps specifically include the following: The legal measurement end uses the key K1 and the key K2 to encrypt the shared information M into The encrypted shared information E is broadcasted to the first user terminal and the second user terminal, completing the secret sharing of the shared information between the first user terminal and the second user terminal.