Method for calculating risk degree of nodes, transmission lines and paths in quantum communication network
By calculating the risk level of network nodes and transmission lines in a quantum communication network and using quantum logic gates for encryption and decryption, the problem that traditional self-checking methods cannot detect eavesdroppers who only copy information is solved, and secure self-checking and dynamic risk monitoring of information in quantum communication networks are achieved.
Patent Information
- Application Number
- CN202310742860.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-21
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2043-06-21
AI Technical Summary
Existing network transmission methods make it difficult to detect situations where eavesdroppers only copy information without changing its content, and traditional self-checking methods cannot effectively detect such situations.
In a quantum communication network, the risk of network nodes and transmission lines is calculated through initialization, error statistics, and dynamic update steps, and information is encrypted and decrypted using quantum logic gates to achieve secure transmission of self-checking information.
It realizes dynamic monitoring of network risks during information transmission, ensures that information is always encrypted during transmission, can accurately detect and offset eavesdropping, and provide security protection for information transmission.
Smart Images

Figure CN119182514B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of secure communication technology, and in particular to a method for calculating the risk of network nodes, transmission lines and transmission paths in a quantum communication network that is particularly suitable for (allowing secure self-checking). Background Art
[0002] In the information age, information security is receiving more and more attention, and the assessment and detection of network security has become an important topic.
[0003] The current network transmission method is based on classical information. When there is an eavesdropper in the network, because the eavesdropper can copy the classical information without changing the information content, the traditional network self-detection method can only target the destroyer who changes the transmission information. It is difficult to detect the eavesdropper who does not change the transmission information but only copies the information. Summary of the Invention
[0004] To address the aforementioned issues in the prior art, the present invention discloses a method for calculating the risk of network nodes, transmission lines, and transmission paths in quantum communication networks, particularly suitable for this purpose. In addition to considering the impact of the overall network layout on the risk of network nodes and transmission lines, this method also proposes dynamic risk considerations based on the information transmission process and the final transmission results. Furthermore, a specific calculation method consistent with networks that allow for security self-checking is provided. This allows for accurate and dynamic monitoring of network risk using the transmission results of self-checking information while simultaneously transmitting normal information, enabling dynamic monitoring of network risk and providing a strong guarantee for planning optimal information transmission paths.
[0005] Specifically, the first aspect of the present invention relates to a risk calculation method for a network node of a quantum communication network, which includes an initialization step, an error statistics step, and a dynamic update step;
[0006] In the initialization step, according to the number P of neighboring network nodes of network node i in the quantum communication network i , calculate the risk r of network node i 0i =ln(1+P i );
[0007] In the error statistics step, the number of errors n related to network node i within the preset time t is counted. i ;
[0008] In the dynamic update step, after the preset time t, according to the number of error reports n i , update the risk r of network node i ti , where: when n i =0, r ti =r 0i *e -λtOtherwise, r ti =r 0i +a*n i 2 , λ and a are preset coefficients.
[0009] Furthermore, in the error statistics step, when a network node on the transmission path receives information transmitted by the previous network node and reports an error based on the classical information therein, the number of errors associated with the previous network node will be increased by 1; when the target network node reports an error based on the received quantum state information, the number of errors associated with each of the intermediate network nodes between the initial network node and the target network node on the transmission path will be increased by 1.
[0010] Furthermore, the classic information includes the initial network node, the target network node, the intermediate network node list, the next network node, the digital signature of the network node and the timestamp, and the network node reports an error when it determines based on the classic information that there is at least one of a transmission path error, the difference between the timestamp and the current time exceeds a preset value, the digital signature does not match, and the classic information format is incorrect.
[0011] Furthermore, the quantum state information is generated based on the coded information, which includes the information to be transmitted, the digital signature and timestamp of the initial network node, and a hash value generated from one or more of the information to be transmitted, the digital signature and timestamp of the initial network node; and the target network node obtains the coded information when measuring the quantum state information and reports an error when the verification of the coded information fails.
[0012] Furthermore, the verification of the encoded information includes one or more of a public comparison of the information to be transmitted, verification of a digital signature of an initial network node, verification of a timestamp, and verification of a hash value.
[0013] Furthermore, information is transmitted between the initial network node and the target network node through the initial transmission process and the retransmission process;
[0014] During the initial transmission process, the initial network node generates original quantum state information based on the information to be transmitted, performs encryption operations on the original quantum state information using quantum logic gates to generate first quantum state information, calculates a minimum-risk transmission path, and transmits the first quantum state information to the target network node along the minimum-risk transmission path; and the target network node performs encryption operations on the first quantum state information using quantum logic gates to generate second quantum state information, calculates a minimum-risk transmission path, and transmits the second quantum state information back to the initial network node along the minimum-risk transmission path.
[0015] During the retransmission process, the initial network node uses a quantum logic gate to decrypt the second quantum state information to generate a third quantum state information, calculates a minimum-risk transmission path, and transmits the third quantum state information to the target network node according to the minimum-risk transmission path; and the target network node uses a quantum logic gate to decrypt the third quantum state information to generate a fourth quantum state information, and measures the fourth quantum state information to obtain the transmitted information.
[0016] The effects of the encryption operation during the initial transmission process and the decryption operation during the retransmission process of the same network node on the quantum state information cancel each other out.
[0017] A second aspect of the present invention relates to a method for calculating the risk of a transmission line between network nodes in a quantum communication network, comprising an initialization step, an error statistics step, and a dynamic update step;
[0018] In the initialization step, according to the line length L of the transmission line ij between two adjacent network nodes in the quantum communication network ij , calculate the risk of transmission line ij μ is the preset coefficient;
[0019] In the error statistics step, the number of errors m related to the transmission line ij within the preset time t is counted. ij ;
[0020] In the dynamic update step, after the preset time t, according to the number of error reports m ij , update the risk r of transmission line ij tij , where: when m ij =0, r tij =r 0ij *e -λt Otherwise, r tij =r 0ij +b*m ij 2 , λ and b are preset coefficients.
[0021] Furthermore, in the error statistics step, when a network node on the transmission path receives information transmitted by the previous network node and reports an error based on the classical information therein, the number of errors reported on the previous transmission line is increased by 1; when the target network node reports an error based on the received quantum state information, the number of errors related to each of all transmission lines on the transmission path is increased by 1.
[0022] Further, the classical information includes an initial network node, a target network node, a list of intermediate network nodes, a next network node, a digital signature of the network node, and a timestamp, and the network node reports an error when at least one of the following conditions is met: a transmission path error is determined based on the classical information, a difference between the timestamp and a current time exceeds a preset value, the digital signature is inconsistent, and the classical information is in an incorrect format.
[0023] Further, the quantum state information is generated based on encoding information, and the encoding information includes the information to be transmitted, a digital signature of the initial network node, and a timestamp, as well as a hash value generated based on one or more of the information to be transmitted, the digital signature of the initial network node, and the timestamp; and the target network node reports an error when the encoding information is obtained by measuring the quantum state information and the verification of the encoding information fails.
[0024] Further, the verification of the encoding information includes one or more of a public comparison of the information to be transmitted, a verification of the digital signature of the initial network node, a verification of the timestamp, and a verification of the hash value.
[0025] Further, the transmission of the information between the initial network node and the target network node is achieved through a primary transmission process and a retransmission process.
[0026] In the primary transmission process, the initial network node generates original quantum state information based on the information to be transmitted, performs an encryption operation on the original quantum state information using a quantum logic gate to generate first quantum state information, calculates a minimum-risk transmission path, and transmits the first quantum state information to the target network node according to the minimum-risk transmission path; and the target network node performs an encryption operation on the first quantum state information using a quantum logic gate to generate second quantum state information, calculates a minimum-risk transmission path, and transmits the second quantum state information back to the initial network node according to the minimum-risk transmission path.
[0027] In the retransmission process, the initial network node performs a decryption operation on the second quantum state information using a quantum logic gate to generate third quantum state information, calculates a minimum-risk transmission path, and transmits the third quantum state information to the target network node according to the minimum-risk transmission path; and the target network node performs a decryption operation on the third quantum state information using a quantum logic gate to generate fourth quantum state information, and measures the fourth quantum state information to obtain the transmitted information.
[0028] The encryption operation of the same network node in the primary transmission process and the decryption operation of the same network node in the retransmission process cancel each other out on the quantum state information.
[0029] A third aspect of the present invention relates to a method for calculating the risk of a transmission path used in a quantum communication network, wherein the risk of the transmission path between an initial network node and a target network node is the sum of the risks of all network nodes on the transmission path and the risks of all transmission lines; and the risk of the network node is calculated using the above-mentioned network node risk calculation method, and the risk of the transmission line is calculated using the above-mentioned transmission line risk calculation method. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] The specific embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.
[0031] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0032] Figure 1 Schematically illustrates a network architecture that allows security self-checking according to the present invention;
[0033] Figure 2 An example of a network node according to the present invention is schematically shown;
[0034] Figure 3 Schematically illustrates the encryption / decryption principle of the quantum encryption / decryption module according to the present invention;
[0035] Figure 4 Schematically shows an example of an analysis module according to the present invention;
[0036] FIG5( a ) schematically shows an example of a self-test information transmission method according to the present invention;
[0037] FIG5( b ) schematically shows the transmission path of a single quantum bit in the self-checking information transmission method according to the present invention. DETAILED DESCRIPTION
[0038] Hereinafter, exemplary embodiments of the present invention will be described in detail with reference to the accompanying drawings. The following embodiments are provided by way of example so as to fully convey the spirit of the present invention to those skilled in the art to which the present invention belongs. Therefore, the present invention is not limited to the embodiments disclosed herein.
[0039] Figure 1The network architecture that allows for secure self-checking according to the present invention is schematically shown, which includes multiple network nodes, such as node 1, ..., node 7. The network nodes are connected via quantum channels and classical channels, so that any two network nodes in the network can directly or indirectly achieve data connection and interact with quantum state information and classical information.
[0040] Figure 2 An example of a network node used in the present invention is shown.
[0041] As shown in the figure, the network node may include a receiving end, a quantum state generation module, a quantum state measurement module, a quantum encryption / decryption module, a control module, an analysis module and a sending end.
[0042] In the network node, the information to be transmitted may first be encoded to form encoded information. As an example, the encoded information may include, in addition to the information to be transmitted, verification data such as the network node's digital signature, a timestamp, and a hash value for verifying the integrity of the information.
[0043] The quantum state generation module is used to generate quantum state information based on the encoded information, which may include multiple quantum bits As an example, the quantum state generation module can be implemented with the help of a quantum state generation device.
[0044] The quantum state measurement module is used to measure quantum state information to obtain coded information, thereby allowing information to be transmitted, i.e., the actual received information, to be obtained from the coded information. As an example, the quantum state measurement module can be implemented using a quantum state measurement device.
[0045] The quantum encryption / decryption module is used to encrypt / decrypt quantum state information. Instead of using traditional (shared) keys for encryption and decryption, it uses quantum logic gates to perform encoded logic operations on quantum state information (qubits), thereby changing the quantum state and achieving encryption or decryption of quantum state information. The use of adjustable quantum logic gates in the quantum encryption / decryption module allows for control of the quantum logic gates to switch between encryption and decryption operations.
[0046] In a preferred example, the quantum logic gates used in the quantum encryption / decryption modules of different network nodes may be different from each other.
[0047] In the present invention, by controlling the quantum logic gate, the encryption operation and decryption operation of the quantum encryption / decryption module of the same network node are made to cancel each other out in terms of the transformation effects on the quantum state.
[0048] Preferably, the quantum logic gate Where, the phase θ j is the quantum logic gate U(θj ) is the adjustment parameter. That is, the phase θ can be controlled j To adjust the quantum logic gate U(θ j ), thereby realizing the switch between encryption and decryption operations. Among them, the quantum logic gate U(θ j )'s phase θ j Can be different from each other.
[0049] In a preferred example, the quantum encryption / decryption module may include a set of quantum logic gates {U(θ j )}, j = 1, .... Therefore, when the quantum state information is input into the quantum encryption / decryption module, the i-th quantum bit in the quantum state information It can be represented by a quantum logic gate {U(θ j )} in the jth quantum logic gate U(θ j ) to perform encoding logic operations The quantum state is changed, thereby realizing the encryption / decryption of the entire quantum state information. Figure 3 As shown, the i=1 quantum bit in the quantum state information The j=1 quantum logic gate U(θ1) is used to calculate i = 2 qubits The j=2 quantum logic gate U(θ2) is used to calculate i = 3 qubits The j=3 quantum logic gate U(θ3) is used to calculate By using quantum logic gates of this specific structure, phase-adjustable single-bit encoding operations can be performed on quantum bits in quantum state information, making the encryption of quantum state information commutative. This can adapt to the ring information transmission structure mentioned below while utilizing the non-replicability of quantum to protect the security of encrypted information.
[0050] In the present invention, the control module is configured to control the quantum logic gates in the quantum encryption / decryption module to achieve switching between encryption operations and decryption operations based on the quantum logic gates.
[0051] Preferably, the control module may include a phase controller for controlling the quantum logic gate U(θ j )’s adjustment parameter phase θ j .
[0052] In a preferred example, the control module can control the quantum logic gate U(θ j ) in phase θ j Next pair of qubits Perform encoding logic operations and encrypt them; when the encrypted quantum bits are expected to be When decrypting, control the quantum logic gate U(θ j )'s phase θ j Reverse to -θ j , using quantum logic gate U(-θ j ) for quantum bits Perform encoding logic operations. Therefore, under this decryption operation, the quantum logic gate U(θ j ) for quantum bits The encryption function restores the quantum bit
[0053] Here, those skilled in the art will appreciate that the quantum operation device for implementing the quantum logic gate can be selected according to the carrier of the quantum bit. When the carrier is pulsed light, the pulsed light can be passed through a polarizer in a specific direction to realize the quantum logic gate U(θ j ) for quantum bits The phase controller can control the quantum logic gate U(θ j ) in the phase parameter θ j .
[0054] Continue to see Figure 2 The receiving end can be used to receive information transmitted by other network nodes, which includes classical information and quantum state information. As an example, the receiving end can be implemented by using a receiving device for quantum state information and classical information.
[0055] When the receiving end receives classical information and quantum state information, it can send the quantum state information to the quantum encryption / decryption module for encryption or decryption operations, and send the classical information to the analysis module.
[0056] The analysis module is used to read, write and analyze classical information, as well as calculate the transmission path of information.
[0057] In the present invention, classic information may include data related to the information transmission process, such as a status identifier and a node list, wherein the status identifier includes an initial transmission status and a retransmission status, and the node list includes information related to the transmission path, such as the initial network node, the target network node, the intermediate network node, and the next network node.
[0058] like Figure 4 As shown, the analysis module may include a reading and writing unit, a processing unit, a risk calculation unit and a path calculation unit.
[0059] The read-write unit is used for reading and writing classical information, such as reading state identification and node list, changing state identification, writing node list data, etc.
[0060] The processing unit is used for determining the operation to be performed according to the classical information read by the read-write module, and providing the digital signature and timestamp of the network node.
[0061] The risk degree calculation unit is used for calculating the risk degree of the network in real time. The risk degree is related to the number of network nodes in the path, the distance between network nodes, the security of the line between network nodes, the confidentiality of each network node, etc., and satisfies the following properties: let R AB be the risk degree between network nodes A and B, and C be another network node, then R AB ≤ R AC + R BC , and the equality holds only when the network node C is on the minimum risk propagation path of the network nodes A and B.
[0062] The path calculation unit is used for calculating the optimal transmission path of the network node according to the risk degree, such as the minimum risk transmission path.
[0063] The sending end can be used to integrate classical information and quantum state information and transmit them together to the next network node. As an example, the sending end can be implemented by means of a classical information transmitter and a quantum state information transmitter.
[0064] In order to better understand the structure and function of each module and unit in the network proposed in the present application, the following will combine Figures 5(a)-5(b) the description of the self-checking information transmission method of the network for allowing safe self-checking, which is especially suitable for the above-mentioned network for allowing safe self-checking.
[0065] As shown in FIG. 5(a), the self-checking information transmission method of the present application takes the transmission of self-checking information from the initial network node A to the target network node B as an example, which includes an initial sending process and a re-sending process.
[0066] During the initial transmission process, after the initial network node A generates original quantum state information based on the information to be transmitted (such as self-test information), it independently uses quantum logic gates to perform encryption operations on the original quantum state information to generate first quantum state information. Based on the risk, it generates a minimum-risk transmission path with respect to the target network node B, and transmits the first quantum state information to the target network node B along this minimum-risk transmission path. After receiving the first quantum state information, the target network node B will also independently use quantum logic gates to perform encryption operations on the first quantum state information to generate second quantum state information. Based on the risk, it generates a minimum-risk transmission path with respect to the initial network node A, and transmits the second quantum state information back to the initial network node A along this minimum-risk transmission path. This ensures that during the initial transmission process, the quantum state information carrying the information to be transmitted is always encrypted.
[0067] During the retransmission process, the initial network node A again independently uses quantum logic gates to decrypt the second quantum state information to generate third quantum state information, and then regenerates a risk-minimizing transmission path for the target network node B based on the risk, and transmits the third quantum state information to the target network node B along this risk-minimizing transmission path. After receiving the third quantum state information, the target network node B also independently uses quantum logic gates to decrypt the third quantum state information to generate fourth quantum state information, and then measures the fourth quantum state information to obtain the plaintext of the received information.
[0068] It can be noted that in the self-test information transmission method of the present invention, the quantum state information first undergoes encryption operations in the initial network node A and the target network node B respectively, and then undergoes decryption operations in the initial network node A and the target network node B respectively, and finally undergoes the same number of encryption and decryption operations in the same network node. Therefore, it is possible to simply control the quantum logic gates used to implement encryption and decryption operations in the network nodes so that the decryption operations and encryption operations performed on the same quantum state information using quantum logic gates in the same network node (for example, the initial network node A, the target network node B) cancel each other out. Therefore, without the network nodes using shared keys, it is possible to ensure that the quantum state information related to the information to be transmitted is always in an encrypted state during the transmission process, and when it is transmitted to the target network node again, it can be automatically restored to plaintext with the help of the decryption operation at the target network node.
[0069] 5(a) , the initial sending process involves states 1 and 2, and the resending process involves states 3 and 4.
[0070] In state 1, the initial network node A calculates the optimal transmission path target to the target network node B with the help of its analysis module.
[0071] In this invention, to assess the confidentiality of a transmission path, the risk between network nodes is used to describe the likelihood of information leakage when two network nodes communicate via the most secure transmission path. Therefore, the analysis module of initial network node A can use, for example, the Dijkstra algorithm to calculate the minimum-risk transmission path from initial network node A to target network node B, thereby enabling information transmission from initial network node A to target network node B based on this minimum-risk transmission path.
[0072] The initial network node A also generates quantum state information related to the information to be transmitted. To this end, the initial network node A can first encode the information to be transmitted to generate coded information, and then use the quantum state generation module to generate original quantum state information based on the coded information.
[0073] In the present invention, in order to enable the target network node B to confirm the authenticity of the received information, the encoded information may include, in addition to the information to be transmitted (text), the digital signature of the initial network node A, a timestamp, and verification data such as a hash value generated from the information to be transmitted, the digital signature, and the timestamp, as shown in the following table:
[0074] Information to be transmitted Digital signature of the initial network node Timestamp Hash value
[0075] Therefore, when the target network node B obtains the coded information transmitted by the initial network node A, it can verify the authenticity and integrity of the information to be transmitted (self-test information) contained in the coded information it obtains through data such as the hash value, the digital signature and timestamp of the initial network node A.
[0076] As mentioned above, to facilitate process control, network nodes can read, write and analyze classical information through their analysis modules, which includes status identification and node lists.
[0077] The state identifier is used to identify the current transmission state of the quantum state information. For example, "initial transmission state" indicates that the current transmission of the quantum state information is in the initial transmission process, and "retransmission state" indicates that the current transmission of the quantum state information is in the retransmission process.
[0078] The node list is used to record data related to the calculated optimal transmission path (transmission path with the lowest risk), such as the initial network node A, the target network node B, the intermediate network node and the next intermediate network node.
[0079] Furthermore, during the initial transmission process, the network node can also use its analysis module to write a timestamp in the classical information, thereby allowing the next network node to determine whether the information transmission between the two network nodes is normal based on the timestamp in the classical information when receiving the quantum state information and classical information.
[0080] For example, in state one involving the initial sending process, the initial network node A, in generating the classical information, identifies the "state identifier" therein as "initial sending state", records the initial network node A, the target network node B, and the intermediate network nodes on the risk degree minimum transmission path other than the initial network node A and the target network node B, and records the next network node about the initial network node A on the risk degree minimum transmission path, for example, "network node C1", at the "next network node" and an additional time stamp.
[0081] In addition, to ensure the security in the information transmission process, the initial network node A also encrypts the original quantum state information to generate the first quantum state information. To this end, the initial network node A can pre-set the quantum logic gate U(θ Aj in its quantum encryption / decryption module by means of the control module, so as to perform an encryption operation on the original quantum state information by means of the quantum encryption / decryption module after generating the original quantum state information, to generate the first quantum state information. Preferably, a set of quantum logic gates {U(θ Aj )} can be used to perform an encoding logic operation on the quantum bits in the original quantum state information, as shown in FIG. 5(b).
[0082] Finally, the first quantum state information (i.e., the original quantum state information encrypted once) and the classical information can be integrated at the sending end and sent to the next network node.
[0083] In state two, after receiving the first quantum state information and the classical information, the target network node B can first read the classical information by means of its analysis module.
[0084] After confirming that it is the target network node of the present information transmission by reading the information of the initial network node A and the target network node B in the classical information, the analysis module can change the state identifier from the initial sending state to the re-sending state, calculate the risk degree minimum transmission path from it to the initial network node A by means of, for example, the Dijkstra algorithm, and send the risk degree minimum transmission path to the sending end as the optimal transmission path from the target network node B to the initial network node A.
[0085] The analysis module of the target network node B can also determine whether the present transmission process is normal by comparing the time stamp in the classical information with the current time, and allow the time stamp to be updated when the difference between the read time stamp and the current time is less than a set value, and write the calculated risk degree minimum transmission path into the classical information.
[0086] Similarly, the target network node B also pre-sets the quantum logic gate U(θ Bj), as shown in Figure 5(b), the quantum encryption / decryption module is used to perform encryption operations on the quantum bits in the first quantum state information to generate Thus, the second quantum state information is obtained, which contains the original state information encrypted twice.
[0087] Finally, the second quantum state information and the classical information can be integrated at the sending end and sent to the initial network node A according to the determined transmission path with the minimum risk.
[0088] At this point, the initial sending process of quantum state information is completed.
[0089] In state three, after receiving the second quantum state information and classical information returned by the target network node B, the initial network node A can use its analysis module to read the classical information.
[0090] After the analysis module reads the classical information and determines that the state identifier is the retransmission state and that the current network node is the initial network node, it can verify the digital signature of the target network node B in the classical information. After the digital signature verification is passed, it uses the Dijkstra algorithm to recalculate its minimum-risk transmission path to the target network node B, and sends it to the sending end as the optimal transmission path to allow the information to be retransmitted from the initial network node A to the target network node B according to the minimum-risk transmission path.
[0091] The analysis module can also verify the timestamp in the classic information, and when the difference between the timestamp and the current time is less than a preset value, encode the classic information to update the timestamp, and write the recalculated minimum risk transmission path from the initial network node A to the target network node B into the classic information, and attach a digital signature at the initial network node A in the classic information.
[0092] In addition, the control module also controls the quantum logic gate in the quantum encryption / decryption module to reverse, for example, the phase parameter θ Aj Take the opposite value, quantum logic gate U(θ Aj ) becomes U(-θ Aj ), as shown in Figure 5(b), the encoding logic operation of the quantum logic gate on the quantum state information is switched to the decryption operation, and the encryption operation and decryption operation of the same network node cancel each other out. For example, U(θ Aj )U(-θ Aj )=I. Therefore, after the decryption operation at the initial network node A, the quantum state information related to the quantum logic gate U(θ Aj ) is decrypted, and the quantum bits in the third quantum state information generated by the decryption operation can be expressed as
[0093] Preferably, after completing the quantum logic gate U(-θ Aj ) After decrypting the quantum state information, the control module can restore the quantum logic gate to its original state U(θ Aj ).
[0094] Finally, the sender integrates the third quantum state information and classical information according to the transmission path with the lowest risk and sends them to the target network node B.
[0095] In state four, after receiving the third quantum state information and the classical information, the target network node B reads the state identifier in the classical information through its analysis module as a resending state.
[0096] At this time, the analysis module can verify the digital signature and timestamp of the initial network node A in the read classical information.
[0097] When the digital signature is verified and the difference between the timestamp and the current time is less than the preset value, the target network node B can use the control module to control the quantum logic gate in the quantum encryption / decryption module to reverse, for example, to make the phase parameter θ Bj Take the opposite value, quantum logic gate U(θ Bj ) becomes I(-θ Bj ), as shown in Figure 5(b), thereby switching the encoding logic operation of the quantum logic gate on the quantum state information to the decryption operation, and the encryption operation and decryption operation of the same network node on the quantum state information cancel each other out. For example, U(θ Bj )-(-θ Bj )=I. Therefore, after the decryption operation at the target network node B, the third quantum state information about the quantum logic gate U(θ Bj ) is decrypted, and the quantum bits in the quantum state information are restored to Therefore, the quantum state information encrypted during the initial transmission process can be restored to its plaintext, that is, the original quantum state information, when it is transmitted again to the target network node B through the retransmission process. This process does not require the participation of a shared key.
[0098] Preferably, after completing the quantum logic gate U(-θ Bj ) After decrypting the quantum state information, the control module can restore the quantum logic gate to its original state U(θ Bj ).
[0099] Afterwards, the target network node B can use the quantum state measurement module to measure the decoded original quantum state information, obtain the encoded information, and parse the plaintext of the received (to be transmitted) information.
[0100] Target network node B can also verify the digital signature of the received coded information to ensure that the information to be transmitted originated from the originating network node A, verify the timestamp in the coded information based on the current time to ensure the normal information transmission process, and verify the hash value in the coded information to ensure the integrity of the received information. At this time, if the verification of the information to be transmitted fails, target network node B can report an error, broadcast the error message, and increase the risk of all network nodes and lines along the transmission path during the next risk settlement.
[0101] Therefore, through the initial sending process and the resending process, the information to be transmitted is encrypted from the initial network node A to the target network node B in the form of a ring transmission. Only the logical operation of the quantum state information can be performed by quantum logic gates without the participation of shared keys, thereby realizing the secure transmission of information (self-test information) between the initial network node A and the target network node B.
[0102] Furthermore, in the self-test information transmission method of the present invention, after measuring the fourth quantum state information to obtain the information to be transmitted, the target network node B can randomly select several bits from the received (to be transmitted) information for public comparison with the initial network node A. If the comparison fails, for example, the error rate exceeds a preset threshold, it indicates that a problem has occurred during the transmission process.
[0103] Furthermore, when a network node receives quantum state information and classical information from the previous network node, and discovers by reading the classical information that it is a node other than the initial network node A and the target network node B, it can determine whether it belongs to an intermediate network node on the recorded minimum risk transmission path based on the received classical information, and whether the received information comes from the previous network node about it on the minimum risk transmission path.
[0104] If it is determined that this network node is on the recorded transmission path with minimum risk, and the received information comes from the previous network node about it on the transmission path with minimum risk, the network node can update the next network node in the classical information based on the recorded transmission path with minimum risk, send the received quantum state information and classical information to the next network node about it, and broadcast it to the initial network node A and the target network node B.
[0105] When it is determined that the network node is not on the recorded transmission path with the lowest risk and / or the received information is not from the previous network node on the transmission path with the lowest risk, the transmission may be terminated and the error may be broadcasted.
[0106] In particular, referring to Fig. 5(a), the operation corresponding to the quantum logic gate selected by the target network node B can be a Hadamard transformation or an Adabm gate. Thus, when the photon prepared by the initial network node A is in the |HV> basis, if the target network node B in state two adopts a Hadamard transformation for encryption, the target network node B in state four is equivalent to measuring in the |HV> basis; if the target network node B in state two adopts an Adabm gate for encryption, the target network node B in state four is equivalent to measuring in the |+-> basis. In this way, the security of the channel of the BB84 protocol can be detected.
[0107] In summary, in the network allowing for secure self-checking and the self-checking information transmission method thereof according to the present application, the use of a ring-shaped information transmission path enables the initial network node and the target network node to perform encryption and decryption without knowing the key (e.g., the phase parameter in the quantum logic gate) used for encryption and decryption, thereby realizing encrypted transmission of information. In addition, in the encryption and decryption operation for encrypted transmission of information, the use of quantum logic gates with a specific structure enables the phase-adjustable single-bit encoding operation to be performed on a group of qubits in sequence, so that the encryption of the quantum state can be performed in a sequence that is interchangeable, thereby protecting the security of the encrypted information by taking advantage of the non-reproducibility of the quantum state while adapting to the ring-shaped information transmission structure. The security of the network is guaranteed by the non-reproducibility and unpredictability of the quantum state. If an eavesdropper wants to know the content of the encrypted quantum information, he or she needs to know the measurement basis, i.e., the phase values of all the nodes that the quantum state has passed through, especially the phase value of the initial network node A, which is equivalent to a direct leakage of information of the initial network node A. In addition, in actual applications, even if the quantum state information received and transmitted by a node is intercepted, because the measurement basis is unknown, the phase value of the quantum logic gate used by the node cannot be obtained by comparing the quantum states, and the detection information cannot be obtained without leaving traces, thereby allowing potential eavesdroppers to be found through this self-checking method.
[0108] In the above description of the quantum communication network and the self-checking information transmission method, the content of determining the information transmission path based on the risk degree of the network is mentioned, and the risk degree-related consideration factors, such as the number of network nodes in the path, the distance between network nodes, the security of the line between network nodes, and the confidentiality of network nodes, are discussed in detail. Although those skilled in the art can think of various specific risk degree calculation schemes based on the above content, the inventors have further created a method for calculating the risk degree of the network nodes, transmission lines, and transmission paths using the self-checking information (i.e., the information to be transmitted) especially suitable for the scenario of transmitting self-checking information between the initial network node and the target network node using the above self-checking information transmission method. Of course, this risk degree calculation method can also be applied to other scenarios.
[0109] The risk calculation method of the present invention may include an initialization step, an error statistics step, and a dynamic update step.
[0110] The initialization step is used to calculate the initial value of the risk of each network node and transmission line (ie, the line between adjacent network nodes) according to the network layout (eg, the network allowing security self-checking of the present invention).
[0111] Specifically, for any network node i in the network, according to the relationship r 0i =ln(1+P i ) Calculate the initial value of its risk r 0i , where P i is the number of adjacent network nodes of network node i in the network.
[0112] For the transmission line ij between any two adjacent network nodes i and j in the network, the relationship Calculate the initial value of its risk r 0ij , where L ij is the line length of the transmission line ij, and μ is a preset coefficient.
[0113] Based on the initial risk values of network nodes and transmission lines, the present invention also dynamically adjusts the risk of each network node and transmission line by counting the occurrence of errors related to each network node and transmission line over a period of time during information transmission, in order to ensure that the obtained risks match the real-time network conditions. Furthermore, the present invention can also broadcast the errors to the entire network.
[0114] According to the present invention, in the error statistics step, when quantum state information is transmitted via the network, classical information such as the information transmission path (i.e., the network nodes and transmission lines through which the information is transmitted) can be recorded simultaneously, so that during the information transmission process, each network node in the path can detect errors in the current information transmission by checking, for example, classical information, or the target network node can detect errors in the information transmission result by checking, for example, quantum state information, and adjust the risk of the corresponding network nodes and transmission lines based on different error types.
[0115] Specifically, as described above in the network and self-test information transmission method, during the information transmission process, quantum state information and classical information can be integrated for transmission. The quantum state information can be generated based on coded information, and the coded information, in addition to the information to be transmitted, can also include verification data such as the digital signature of the initial network node, a timestamp, and a hash value generated from one or more of the information to be transmitted, the digital signature of the initial network node, and the timestamp. The classical information can be used to record data related to the information transmission process and some related verification data, such as the digital signature and timestamp of the initial network node, the target network node, the intermediate network node (list), the next network node, and the network node.
[0116] Therefore, during the information transmission process, when network node i receives the quantum state information and classical information transmitted by the previous network node, since the quantum state information may be in an encrypted state at this time, network node i can read the classical information and, based on the data recorded therein such as the initial network node, target network node, intermediate network node, next network node, digital signature of the network node and timestamp, check whether there are any problems in the transmission process between it and the previous network node, such as transmission path error, the difference between the timestamp and the current time exceeds the preset value, the digital signature does not match, the classical information format error, etc. When such problems occur, the number of error reports related to the previous network node and the number of error reports related to the previous transmission line (i.e., the transmission line from the previous network node to the current network node i) are increased, for example, the number of error reports is increased by 1.
[0117] In addition, when quantum state information is transmitted to a target network node, for example, through an initial transmission process and a retransmission process, the target network node can obtain corresponding encoded information, for example, through a decryption measurement operation, and then publicly compare some bits of the received information to be transmitted with those of the initial network node, verify the digital signature of the initial network node, verify the timestamp, and verify the hash value to check for errors in the information transmission result. If such errors exist, the number of error reports associated with each of all intermediate network nodes and each of all transmission lines between the initial network node and the target network node on the transmission path can be increased, for example, by 1.
[0118] In the present invention, a statistical period t can be pre-set to count the number of error reports n related to each network node i within the period t. i and the number of errors m associated with each transmission line ij ij , so that every statistical period t, with the help of dynamic update steps, according to the number of error reports n i and m ij , and update the risk levels of corresponding network nodes and transmission lines.
[0119] In the dynamic update step, if the number of errors n related to network node i is counted within the current statistical period t i = 0, then the risk of the network node i is updated to r ti =r 0i *e -λt Otherwise, update the risk of network node i to r ti =r 0i +a*n i 2 , where λ and a are preset coefficients.
[0120] If within the current statistical period t, the number of errors related to the transmission line ij is counted m ij = 0, then the risk of the transmission line ij is updated to r tij =r 0ij *e -λt Otherwise, the risk of transmission line ij is updated to r tij =r 0ij +b*m ij 2 , where λ and b are preset coefficients.
[0121] After obtaining the risks of network nodes and transmission lines, the risk of the transmission path from the initial network node to the target network node can be calculated, which is the sum of the risks of all network nodes and all transmission lines on the transmission path.
[0122] In summary, it can be seen that the risk calculation method of the present invention, in addition to considering the impact of the overall network layout on the risk of network nodes and transmission lines, also proposes dynamic considerations of risk based on the information transmission process and the final transmission results, and provides a specific calculation method that is particularly compatible with the quantum communication network of the present invention. This enables the transmission results of self-test information to be used while normal information is being transmitted, to accurately and dynamically grasp the risk of the network, realize dynamic monitoring of network risks, and provide strong guarantees for planning the optimal information transmission path.
[0123] Although the present invention has been described above through specific embodiments in conjunction with the accompanying drawings, it is easy for those skilled in the art to recognize that the above embodiments are merely exemplary and are used to illustrate the principles of the present invention. They do not limit the scope of the present invention. Those skilled in the art can make various combinations, modifications and equivalent substitutions to the above embodiments without departing from the spirit and scope of the present invention.
Claims
1. A method for calculating the risk of a network node in a quantum communication network, comprising an initialization step, an error statistics step, and a dynamic update step; In the initialization step, according to the number of adjacent network nodes of network node i in the quantum communication network , calculate the risk of network node i ; In the error statistics step, the number of errors related to network node i within the preset time t is counted. ; In the dynamic update step, after the preset time t, according to the number of error reports , update the risk of network node i , where: hour, ;otherwise, , and is the preset coefficient; Among them, in the error statistics step, when a network node on the transmission path receives the information transmitted by the previous network node and reports an error based on the classical information therein, the number of error reports related to the previous network node will be increased by 1; when the target network node reports an error based on the received quantum state information, the number of error reports related to each of the intermediate network nodes between the initial network node and the target network node on the transmission path will be increased by 1.
2. The risk calculation method according to claim 1, wherein: Classic information includes the initial network node, target network node, intermediate network node, next network node, digital signature of the network node and timestamp; The network node reports an error when determining based on the classic information that there is at least one of a transmission path error, a difference between the timestamp and the current time exceeds a preset value, a digital signature does not match, and a classic information format error.
3. The risk calculation method according to claim 1, wherein: The quantum state information is generated based on the encoded information, where the encoded information includes the information to be transmitted, the digital signature and the timestamp of the initial network node, and a hash value generated based on one or more of the information to be transmitted, the digital signature and the timestamp of the initial network node; The target network node obtains the coded information by measuring the quantum state information and reports an error when the verification of the coded information fails.
4. The risk calculation method according to claim 3, wherein: Verification of the encoded information includes one or more of a public comparison of the information to be transmitted, verification of the digital signature of the initial network node, verification of the timestamp, and verification of the hash value.
5. The risk calculation method according to claim 1, wherein: The information is transmitted between the initial network node and the target network node through the initial transmission process and the retransmission process; During the initial transmission process, the initial network node generates original quantum state information based on the information to be transmitted, uses quantum logic gates to perform encryption operations on the original quantum state information to generate first quantum state information, calculates the minimum risk transmission path, and transmits the first quantum state information to the target network node according to the minimum risk transmission path; and, the target network node performs an encryption operation on the first quantum state information using a quantum logic gate to generate second quantum state information, calculates a transmission path with the minimum risk, and transmits the second quantum state information back to the initial network node according to the transmission path with the minimum risk; During the retransmission process, the initial network node uses a quantum logic gate to decrypt the second quantum state information to generate a third quantum state information, calculates a minimum-risk transmission path, and transmits the third quantum state information to the target network node according to the minimum-risk transmission path; and the target network node uses a quantum logic gate to decrypt the third quantum state information to generate a fourth quantum state information, and measures the fourth quantum state information to obtain the transmitted information. The effects of the encryption operation during the initial transmission process and the decryption operation during the retransmission process of the same network node on the quantum state information cancel each other out.
6. A method for calculating the risk of transmission lines between network nodes in a quantum communication network, comprising an initialization step, an error statistics step, and a dynamic update step; In the initialization step, according to the line length of the transmission line ij between two adjacent network nodes in the quantum communication network , calculate the risk of transmission line ij , is the preset coefficient; In the error statistics step, the number of errors related to the transmission line ij within the preset time t is counted. ; In the dynamic update step, after the preset time t, according to the number of error reports , update the risk of transmission line ij , where: hour, ,otherwise, , and is the preset coefficient.
7. The risk calculation method according to claim 6, wherein: In the error statistics step, when a network node on the transmission path receives the information transmitted by the previous network node and reports an error based on the classical information therein, the number of errors reported on the previous transmission line is increased by 1; when the target network node reports an error based on the received quantum state information, the number of errors associated with each of all transmission lines on the transmission path between the initial network node and the target network node is increased by 1.
8. The risk calculation method according to claim 7, wherein: The classic information includes the initial network node, the target network node, the intermediate network node, the next network node, the digital signature and the timestamp of the network node, and the network node reports an error when it determines based on the classic information that there is at least one of a transmission path error, the difference between the timestamp and the current time exceeds a preset value, the digital signature does not match, and the classic information format is incorrect.
9. The risk calculation method according to claim 7, wherein: The quantum state information is generated based on the encoded information, where the encoded information includes the information to be transmitted, the digital signature and the timestamp of the initial network node, and a hash value generated based on one or more of the information to be transmitted, the digital signature and the timestamp of the initial network node; The target network node obtains the coded information by measuring the quantum state information and reports an error if the verification of the coded information fails.
10. The risk calculation method according to claim 9, wherein: Verification of the encoded information includes one or more of a public comparison of the information to be transmitted, verification of the digital signature of the initial network node, verification of the timestamp, and verification of the hash value.
11. The risk calculation method according to claim 7, wherein: The information is transmitted between the initial network node and the target network node through the initial transmission process and the retransmission process; During the initial transmission process, the initial network node generates original quantum state information based on the information to be transmitted, uses quantum logic gates to perform encryption operations on the original quantum state information to generate first quantum state information, calculates the minimum risk transmission path, and transmits the first quantum state information to the target network node according to the minimum risk transmission path; and, the target network node performs an encryption operation on the first quantum state information using a quantum logic gate to generate second quantum state information, calculates a transmission path with the minimum risk, and transmits the second quantum state information back to the initial network node according to the transmission path with the minimum risk; During the retransmission process, the initial network node uses a quantum logic gate to decrypt the second quantum state information to generate a third quantum state information, calculates a minimum-risk transmission path, and transmits the third quantum state information to the target network node according to the minimum-risk transmission path; and the target network node uses a quantum logic gate to decrypt the third quantum state information to generate a fourth quantum state information, and measures the fourth quantum state information to obtain the transmitted information. The effects of the encryption operation during the initial transmission process and the decryption operation during the retransmission process of the same network node on the quantum state information cancel each other out.
12. A method for calculating the risk of a transmission path in a quantum communication network, wherein: The risk of the transmission path between the initial network node and the target network node is the sum of the risk of all network nodes on the transmission path and the risk of all transmission lines; and, Calculating the risk of a network node using the risk calculation method according to any one of claims 1 to 5; The risk of the transmission line is calculated using the risk calculation method according to any one of claims 6 to 11.
Citation Information
Patent Citations
Identity authentication methods, devices and system for quantum key distribution process
CN106411521A
Multi-energy flow system anti-monitoring method and device based on quantum secret communication
CN115589328A