A secure self-checking method for a quantum communication network
By combining quantum state encryption and ring transmission with a security self-check method that dynamically adjusts the risk level of network nodes and lines, the problem of being unable to detect eavesdroppers in existing technologies is solved, the security and reliability of quantum communication networks are improved, and eavesdroppers can be automatically detected and real-time security protection can be provided.
Patent Information
- Application Number
- CN202310742914.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-21
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2043-06-21
AI Technical Summary
Existing network self-checking methods make it difficult to detect eavesdroppers. Eavesdroppers who only copy information without changing the content of the information cannot effectively ensure the security and reliability of quantum communication networks.
A security self-check method is adopted that combines quantum state encryption and ring transmission with dynamic adjustment of the risk level of network nodes and lines. Quantum state information is encrypted and decrypted through quantum logic gates, and the Dijkstra algorithm is used to calculate the transmission path with the minimum risk. Self-check information transmission and risk monitoring are carried out in combination with classical information.
It has achieved a significant improvement in the security and reliability of quantum communication networks, can automatically detect potential eavesdroppers, ensure that information is always encrypted during transmission, and provide real-time security protection through dynamic risk monitoring.
Smart Images

Figure CN119182515B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of secure communication technology, and in particular to a security self-checking method for a quantum communication network. Background Art
[0002] In the information age, information security is receiving more and more attention, and the assessment and detection of network security has become an important topic.
[0003] The current network transmission method is based on classical information. When there is an eavesdropper in the network, because the eavesdropper can copy the classical information without changing the information content, the traditional network self-detection method can only target the destroyer who changes the transmission information. It is difficult to detect the eavesdropper who does not change the transmission information but only copies the information. Summary of the Invention
[0004] In response to the above-mentioned problems in the prior art, the present invention discloses a security self-checking method for quantum communication networks. Based on the encrypted transmission of self-checking information using quantum state encryption and ring transmission, combined with dynamically adjusted network node and line risk levels, it automatically monitors the risk levels of network nodes and lines in the network, which can greatly ensure the security and reliability of the quantum communication network and allow possible eavesdroppers to be discovered in a timely manner.
[0005] Specifically, the present invention discloses a security self-check method for a quantum communication network, which includes a self-check information transmission step, a risk monitoring step, and a security detection step;
[0006] In the self-test information transmission step, each network node in the quantum communication network serves as an initial network node, periodically and randomly selects another network node as a target network node, and the initial network node sends the self-test information to the target network node through the initial sending process and the resending process;
[0007] During the initial transmission process, the initial network node generates original quantum state information based on self-check information, performs encryption operations on the original quantum state information using quantum logic gates to generate first quantum state information, calculates a minimum-risk transmission path, and transmits the first quantum state information to the target network node along the minimum-risk transmission path; and the target network node performs encryption operations on the first quantum state information using quantum logic gates to generate second quantum state information, calculates a minimum-risk transmission path, and transmits the second quantum state information back to the initial network node along the minimum-risk transmission path.
[0008] During the retransmission process, the initial network node uses a quantum logic gate to decrypt the second quantum state information to generate a third quantum state information, calculates a minimum-risk transmission path, and transmits the third quantum state information to the target network node according to the minimum-risk transmission path; and the target network node uses a quantum logic gate to decrypt the third quantum state information to generate a fourth quantum state information, and measures the fourth quantum state information to obtain self-test information.
[0009] The effects of the encryption operation during the initial transmission and the decryption operation during the retransmission of the same network node on the quantum state information cancel each other out;
[0010] In the risk monitoring step, based on the self-test information received by the target network node, the risk of network nodes and lines on the transmission path between the initial network node and the target network node is adjusted;
[0011] In the security monitoring step, the risks of network nodes and lines in the quantum communication network are settled regularly, and network services are stopped for network nodes or lines whose risks exceed a preset risk threshold.
[0012] Preferably, the quantum logic gates in different network nodes are different from each other; and / or, the corresponding operation of the quantum logic gate selected by the target network node is an identity transformation or a Hadamard gate.
[0013] Preferably, the Dijkstra algorithm is used to calculate the transmission path with the minimum risk.
[0014] Furthermore, the initial network node generates coded information based on the self-check information encoding, and then generates original quantum state information based on the coded information;
[0015] The encoded information includes self-test information, a digital signature and a timestamp of the initial network node A, and a hash value of the self-test information, the digital signature and the timestamp of the initial network node A.
[0016] Furthermore, the network node also sends classical information along with the quantum state information, which includes a state identifier and a node list, the node list including an initial network node, a target network node, an intermediate network node, and a next network node; and,
[0017] The initial network node generates classical information after generating the original quantum state information, where the state is identified as the initial sending state;
[0018] When the target network node reads the state identifier in the classic information as the initial sending state, it changes the state identifier to the resending state and adds a digital signature to the target network node in the node list;
[0019] The initial network node reads the state identifier in the classic information as the resending state, and after verifying the digital signature of the target network node, it adds the digital signature to the initial network node in the node list;
[0020] After the target network node reads the state identifier in the classical information as the resending state and verifies the digital signature of the initial network node, it uses the quantum logic gate to decrypt the third quantum state information to generate the fourth quantum state information, measures the fourth quantum state information to obtain the encoded information, and verifies the digital signature, timestamp and hash value of the initial network node A in the measured encoded information.
[0021] Furthermore, the initial network node also writes a timestamp into the classical information before sending the first quantum state information and the classical information;
[0022] When a network node receives quantum state information and classical information, it compares the timestamp in the classical information with the current time, and allows the timestamp to be updated when the difference between the timestamp and the current time is less than a preset value.
[0023] Furthermore, the network nodes use a set of quantum logic gates {U(θ j )} encrypt or decrypt quantum state information, a set of quantum logic gates {U(θ j )} in the jth quantum logic gate U(θ j ) for the i-th quantum bit in the quantum state information Perform encryption or decryption operations to generate operation results
[0024] Preferably, the quantum logic gate And the quantum logic gate U(θ j ) Phase θ during the initial transmission and retransmission process j Same size, opposite sign.
[0025] Furthermore, if the target network node B fails to verify the digital signature, timestamp and hash value of the initial network node A in the encoded information, the risk of all network nodes and lines in the transmission path will be increased during the next risk settlement.
[0026] Further, when network nodes other than the initial network node and the target network node receive the quantum state information and the classical information, the classical information is read to determine whether it is on the transmission path with the minimum risk, and whether the received information comes from the previous network node on the transmission path with the minimum risk;
[0027] If it is determined that it is on the transmission path with minimum risk and the received information comes from the previous network node on the transmission path with minimum risk, the received quantum state information and classical information will be sent to the next network node on the transmission path with minimum risk; otherwise, the transmission will be terminated and the risk of the previous network node and the risk of the line between it and the previous network node will be increased.
[0028] Optionally, the risk threshold for a line is set according to its length. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The specific embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.
[0030] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0031] Figure 1 Schematically illustrates a network architecture that allows security self-checking according to the present invention;
[0032] Figure 2 An example of a network node according to the present invention is schematically shown;
[0033] Figure 3 Schematically illustrates the encryption / decryption principle of the quantum encryption / decryption module according to the present invention;
[0034] Figure 4 Schematically shows an example of an analysis module according to the present invention;
[0035] FIG5( a ) schematically shows an example of a self-test information transmission method according to the present invention;
[0036] FIG5( b ) schematically shows the transmission path of a single quantum bit in the self-checking information transmission method according to the present invention. DETAILED DESCRIPTION
[0037] Hereinafter, exemplary embodiments of the present invention will be described in detail with reference to the accompanying drawings. The following embodiments are provided by way of example so as to fully convey the spirit of the present invention to those skilled in the art to which the present invention belongs. Therefore, the present invention is not limited to the embodiments disclosed herein.
[0038] Figure 1A schematic diagram of a quantum communication network architecture that allows secure self-checking according to the present invention is shown, which includes multiple network nodes, such as node 1, ..., node 7. Each network node is connected via a quantum channel and a classical channel, so that any two network nodes in the network can directly or indirectly establish a data connection and interact with quantum state information and classical information.
[0039] Figure 2 An example of a network node used in the present invention is shown.
[0040] As shown in the figure, the network node may include a receiving end, a quantum state generation module, a quantum state measurement module, a quantum encryption / decryption module, a control module, an analysis module and a sending end.
[0041] In the network node, the information to be transmitted may first be encoded to form encoded information. As an example, the encoded information may include, in addition to the information to be transmitted, verification data such as the network node's digital signature, a timestamp, and a hash value for verifying the integrity of the information.
[0042] The quantum state generation module is used to generate quantum state information based on the encoded information, which may include multiple quantum bits As an example, the quantum state generation module can be implemented with the help of a quantum state generation device.
[0043] The quantum state measurement module is used to measure quantum state information to obtain coded information, thereby allowing information to be transmitted, i.e., the actual received information, to be obtained from the coded information. As an example, the quantum state measurement module can be implemented using a quantum state measurement device.
[0044] The quantum encryption / decryption module is used to encrypt / decrypt quantum state information. Instead of using traditional (shared) keys for encryption and decryption, it uses quantum logic gates to perform encoded logic operations on quantum state information (qubits), thereby changing the quantum state and achieving encryption or decryption of quantum state information. The use of adjustable quantum logic gates in the quantum encryption / decryption module allows control of the quantum logic gates to switch between encryption and decryption operations.
[0045] In a preferred example, the quantum logic gates used in the quantum encryption / decryption modules of different network nodes may be different from each other.
[0046] In the present invention, by controlling the quantum logic gate, the encryption operation and decryption operation of the quantum encryption / decryption module of the same network node are made to cancel each other out in terms of the transformation effects on the quantum state.
[0047] Preferably, the quantum logic gate Where, the phase θ j is the quantum logic gate U(θj ) is the adjustment parameter. That is, the phase θ can be controlled j To adjust the quantum logic gate U(θ j ), thereby realizing the switch between encryption and decryption operations. Among them, the quantum logic gate U(θ j )'s phase θ j Can be different from each other.
[0048] In a preferred example, the quantum encryption / decryption module may include a set of quantum logic gates {U(θ j )}, j = 1, .... Therefore, when the quantum state information is input into the quantum encryption / decryption module, the i-th quantum bit in the quantum state information It can be represented by a quantum logic gate {U(θ j )} in the jth quantum logic gate U(θ j ) to perform encoding logic operations The quantum state is changed, thereby realizing the encryption / decryption of the entire quantum state information. Figure 3 As shown, the i=1 quantum bit in the quantum state information The j=1 quantum logic gate U(θ1) is used to calculate i = 2 qubits The j=2 quantum logic gate U(θ2) is used to calculate i = 3 qubits The j=3 quantum logic gate U(θ3) is used to calculate By using quantum logic gates of this specific structure, phase-adjustable single-bit encoding operations can be performed on quantum bits in quantum state information, making the encryption of quantum state information commutative. This can adapt to the ring information transmission structure mentioned below while utilizing the non-replicability of quantum to protect the security of encrypted information.
[0049] In the present invention, the control module is configured to control the quantum logic gates in the quantum encryption / decryption module to achieve switching between encryption operations and decryption operations based on the quantum logic gates.
[0050] Preferably, the control module may include a phase controller for controlling the quantum logic gate U(θ j )’s adjustment parameter phase θ j .
[0051] In a preferred example, the control module can control the quantum logic gate U(θ j ) in phase θ j Next pair of qubits Perform encoding logic operations and encrypt them; when the encrypted quantum bits are expected to When decrypting, control the quantum logic gate U(θ j )'s phase θ j Reverse to -θ j , using quantum logic gate U(-θ j ) for quantum bits Perform encoding logic operations. Therefore, under this decryption operation, the quantum logic gate U(θ j ) for quantum bits The encryption function restores the quantum bit
[0052] Here, those skilled in the art will appreciate that the quantum operation device for implementing the quantum logic gate can be selected according to the carrier of the quantum bit. When the carrier is pulsed light, the pulsed light can be passed through a polarizer in a specific direction to realize the quantum logic gate U(θ j ) for quantum bits The phase controller can control the quantum logic gate U(θ j ) in the phase parameter θ j .
[0053] Continue to see Figure 2 The receiving end can be used to receive information transmitted by other network nodes, which includes classical information and quantum state information. As an example, the receiving end can be implemented by using a receiving device for quantum state information and classical information.
[0054] When the receiving end receives classical information and quantum state information, it can send the quantum state information to the quantum encryption / decryption module for encryption or decryption operations, and send the classical information to the analysis module.
[0055] The analysis module is used to read, write and analyze classical information, as well as calculate the transmission path of information.
[0056] In the present invention, classic information may include data related to the information transmission process, such as a status identifier and a node list, wherein the status identifier includes an initial transmission status and a retransmission status, and the node list includes information related to the transmission path, such as the initial network node, the target network node, the intermediate network node, and the next network node.
[0057] like Figure 4 As shown, the analysis module may include a reading and writing unit, a processing unit, a risk calculation unit and a path calculation unit.
[0058] The read / write unit is used to read and write classical information, such as reading status identifiers and node lists, changing status identifiers, and writing node list data.
[0059] The processing unit is used to determine the operation to be performed based on the classical information read by the read-write module, and to provide the digital signature and timestamp of the network node.
[0060] The risk calculation unit is used to calculate the risk of the network in real time. The risk is related to factors such as the number of network nodes, the distance between network nodes, the security of the lines between network nodes, and the confidentiality of each network node, and satisfies the following properties: Let R AB is the risk between network nodes A and B, C is another network node, then R AB ≤R AC +R BC , and the sign is equal if and only if network node C is on the transmission path with the minimum risk between network nodes A and B.
[0061] The path calculation unit is used to calculate the best transmission path between network nodes according to the risk, such as the transmission path with the minimum risk.
[0062] The transmitter can be used to integrate classical information and quantum state information and transmit them together to the next network node. As an example, the transmitter can be implemented using a classical information transmitter and a quantum state information transmitter.
[0063] To better understand the structure and function of each module and unit in the network proposed by the present invention, the following will be combined with Figures 5(a)-5(b) The network self-check information transmission method of the present invention is described, which is particularly suitable for use in the above-mentioned network that allows security self-check.
[0064] As shown in FIG. 5( a ), the self-test information transmission method of the present invention takes the transmission of self-test information from the initial network node A to the target network node B as an example, including an initial transmission process and a retransmission process.
[0065] During the initial transmission process, after the initial network node A generates original quantum state information based on the information to be transmitted (such as self-test information), it independently uses quantum logic gates to perform encryption operations on the original quantum state information to generate first quantum state information. Based on the risk, it generates a minimum-risk transmission path with respect to the target network node B, and transmits the first quantum state information to the target network node B along this minimum-risk transmission path. After receiving the first quantum state information, the target network node B will also independently use quantum logic gates to perform encryption operations on the first quantum state information to generate second quantum state information. Based on the risk, it generates a minimum-risk transmission path with respect to the initial network node A, and transmits the second quantum state information back to the initial network node A along this minimum-risk transmission path. This ensures that during the initial transmission process, the quantum state information carrying the information to be transmitted is always encrypted.
[0066] During the retransmission process, the initial network node A again independently uses quantum logic gates to decrypt the second quantum state information to generate third quantum state information, and then regenerates a risk-minimizing transmission path for the target network node B based on the risk, and transmits the third quantum state information to the target network node B along this risk-minimizing transmission path. After receiving the third quantum state information, the target network node B also independently uses quantum logic gates to decrypt the third quantum state information to generate fourth quantum state information, and then measures the fourth quantum state information to obtain the plaintext of the received information.
[0067] It can be noted that in the self-test information transmission method of the present invention, the quantum state information first undergoes encryption operations in the initial network node A and the target network node B respectively, and then undergoes decryption operations in the initial network node A and the target network node B respectively, and finally undergoes the same number of encryption and decryption operations in the same network node. Therefore, it is possible to simply control the quantum logic gates used to implement encryption and decryption operations in the network nodes so that the decryption operations and encryption operations performed on the same quantum state information using quantum logic gates in the same network node (for example, the initial network node A, the target network node B) cancel each other out. Therefore, without the network nodes using shared keys, it is possible to ensure that the quantum state information related to the information to be transmitted is always in an encrypted state during the transmission process, and when it is transmitted to the target network node again, it can be automatically restored to plaintext with the help of the decryption operation at the target network node.
[0068] 5(a) , the initial sending process involves states 1 and 2, and the resending process involves states 3 and 4.
[0069] In state 1, the initial network node A calculates the optimal transmission path target to the target network node B with the help of its analysis module.
[0070] In this invention, to assess the confidentiality of a transmission path, the risk between network nodes is used to describe the likelihood of information leakage when two network nodes communicate via the most secure transmission path. Therefore, the analysis module of initial network node A can use, for example, the Dijkstra algorithm to calculate the minimum-risk transmission path from initial network node A to target network node B, thereby enabling information transmission from initial network node A to target network node B based on this minimum-risk transmission path.
[0071] The initial network node A also generates quantum state information related to the information to be transmitted. To this end, the initial network node A can first encode the information to be transmitted to generate coded information, and then use the quantum state generation module to generate original quantum state information based on the coded information.
[0072] In the present invention, in order to enable the target network node B to confirm the authenticity of the received information, the encoded information may include, in addition to the information to be transmitted (text), the digital signature of the initial network node A, a timestamp, and verification data such as a hash value generated from the information to be transmitted, the digital signature, and the timestamp, as shown in the following table:
[0073] Information to be transmitted Digital signature of the initial network node Timestamp Hash value
[0074] Therefore, when the target network node B obtains the coded information transmitted by the initial network node A, it can verify the authenticity and integrity of the information to be transmitted (self-test information) contained in the coded information it obtains through data such as the hash value, the digital signature and timestamp of the initial network node A.
[0075] As mentioned above, to facilitate process control, network nodes can read, write and analyze classical information through their analysis modules, which includes status identification and node lists.
[0076] The state identifier is used to identify the current transmission state of the quantum state information. For example, "initial transmission state" indicates that the current transmission of the quantum state information is in the initial transmission process, and "retransmission state" indicates that the current transmission of the quantum state information is in the retransmission process.
[0077] The node list is used to record data related to the calculated optimal transmission path (transmission path with the lowest risk), such as the initial network node A, the target network node B, the intermediate network node and the next intermediate network node.
[0078] Furthermore, during the initial transmission process, the network node can also use its analysis module to write a timestamp in the classical information, thereby allowing the next network node to determine whether the information transmission between the two network nodes is normal based on the timestamp in the classical information when receiving the quantum state information and classical information.
[0079] For example, in state one involving the initial sending process, when the initial network node A generates classic information, it identifies the "state identifier" as the "initial sending state", records the initial network node A, the target network node B, and the intermediate network nodes other than the initial network node A and the target network node B on the transmission path with the minimum risk, and records the next network node related to the initial network node A on the transmission path with the minimum risk at the "next network node", such as "network node C1", and an additional timestamp.
[0080] In addition, to ensure the security of information transmission, the initial network node A will also encrypt the original quantum state information to generate the first quantum state information. To this end, the initial network node A can use the control module to pre-set the quantum logic gate U(θ Aj ), so that after the original quantum state information is generated, the original quantum state information is encrypted with the help of the quantum encryption / decryption module to generate the first quantum state information. Aj )} for the quantum bits in the original quantum state information The encoding logic operation is performed as shown in FIG5(b).
[0081] Finally, the first quantum state information (i.e., the original quantum state information that has been encrypted once) and the classical information can be integrated at the sending end and sent to the next network node.
[0082] In state two, after receiving the first quantum state information and the classical information, the target network node B can first read the classical information through its analysis module.
[0083] After the analysis module confirms that it is the target network node for this information transmission by reading information such as the initial network node A and the target network node B in the classic information, it can change the state identifier from the initial sending state to the resending state, and use, for example, the Dijkstra algorithm to calculate the minimum risk transmission path to the initial network node A, and send the minimum risk transmission path to the sending end as the optimal transmission path from the target network node B to the initial network node A.
[0084] The analysis module of the target network node B can also determine whether the current transmission process is normal by reading the timestamp in the classic information and comparing it with the current time. When it is determined that the difference between the read timestamp and the current time is less than the set value, it is allowed to update the timestamp and write the calculated transmission path with the minimum risk into the classic information.
[0085] Similarly, the target network node B will also use the control module to pre-set the quantum logic gate U(θ Bj), as shown in Figure 5(b), the quantum encryption / decryption module is used to perform encryption operations on the quantum bits in the first quantum state information to generate Thus, the second quantum state information is obtained, which contains the original state information encrypted twice.
[0086] Finally, the second quantum state information and the classical information can be integrated at the sending end and sent to the initial network node A according to the determined transmission path with the minimum risk.
[0087] At this point, the initial sending process of quantum state information is completed.
[0088] In state three, after receiving the second quantum state information and classical information returned by the target network node B, the initial network node A can use its analysis module to read the classical information.
[0089] After the analysis module reads the classical information and determines that the state identifier is the retransmission state and that the current network node is the initial network node, it can verify the digital signature of the target network node B in the classical information. After the digital signature verification is passed, it uses the Dijkstra algorithm to recalculate its minimum-risk transmission path to the target network node B, and sends it to the sending end as the optimal transmission path to allow the information to be retransmitted from the initial network node A to the target network node B according to the minimum-risk transmission path.
[0090] The analysis module can also verify the timestamp in the classic information, and when the difference between the timestamp and the current time is less than a preset value, encode the classic information to update the timestamp, write the recalculated minimum risk transmission path from the initial network node A to the target network node B into the classic information, and attach a digital signature at the initial network node A in the classic information.
[0091] In addition, the control module also controls the quantum logic gate in the quantum encryption / decryption module to reverse, for example, the phase parameter θ Aj Take the opposite value, quantum logic gate U(θ Aj ) becomes U(-θ Aj ), as shown in Figure 5(b), the encoding logic operation of the quantum logic gate on the quantum state information is switched to the decryption operation, and the encryption operation and decryption operation of the same network node cancel each other out. For example, U(θ Aj )U(-θ Aj )=I. Therefore, after the decryption operation at the initial network node A, the quantum state information related to the quantum logic gate U(θ Aj ) is decrypted, and the quantum bits in the third quantum state information generated by the decryption operation can be expressed as
[0092] Preferably, after completing the quantum logic gate U(-θ Aj ) After decrypting the quantum state information, the control module can restore the quantum logic gate to its original state U(θ Aj ).
[0093] Finally, the sender integrates the third quantum state information and classical information according to the transmission path with the lowest risk and sends them to the target network node B.
[0094] In state four, after receiving the third quantum state information and the classical information, the target network node B reads the state identifier in the classical information through its analysis module as a resending state.
[0095] At this time, the analysis module can verify the digital signature and timestamp of the initial network node A in the read classical information. When the digital signature verification is passed and the difference between the timestamp and the current time is less than the preset value, the target network node B can use the control module to control the quantum logic gate in the quantum encryption / decryption module to reverse, for example, to make the phase parameter θ Bj Take the opposite value, quantum logic gate U(θ Bj ) becomes U(-θ Bj ), as shown in Figure 5(b), thereby switching the encoding logic operation of the quantum logic gate on the quantum state information to the decryption operation, and the encryption operation and decryption operation of the same network node on the quantum state information cancel each other out. For example, U(θ Bj )U(-θ Bj )=I. Therefore, after the decryption operation at the target network node B, the third quantum state information about the quantum logic gate U(θ Bj ) is decrypted, and the quantum bits in the quantum state information are restored to Therefore, the quantum state information encrypted during the initial transmission process can be restored to its plaintext, that is, the original quantum state information, when it is transmitted again to the target network node B through the retransmission process. This process does not require the participation of a shared key.
[0096] Preferably, after completing the quantum logic gate U(-θ Bj ) After decrypting the quantum state information, the control module can restore the quantum logic gate to its original state U(θ Bj ).
[0097] Thereafter, the target network node B can use the quantum state measurement module to measure the decoded original quantum state information, obtain the encoded information and parse the plaintext of the received (to be transmitted) information.
[0098] The target network node B can also verify the digital signature in the obtained encoding information to ensure that the received information to be transmitted comes from the initial network node A, verify the timestamp in the encoding information based on the current time to ensure that the information transmission process is normal, and verify the hash value in the encoding information to ensure the integrity of the received information. At this time, if the verification of the information to be transmitted fails, the target network node B can report an error, broadcast error information, and increase the risk degree of all network nodes and lines on the transmission path at the next risk degree settlement.
[0099] Thus, through the initial transmission process and the retransmission process, the information to be transmitted is encrypted from the initial network node A to the target network node B in a ring transmission form, and the secure transmission of the information (self-checking information) between the initial network node A and the target network node B can be achieved only by the logical operation of the quantum state information by means of quantum logic gates without the participation of shared keys.
[0100] Further, in the self-checking information transmission method of the present application, the target network node B can also randomly select a number of bits from the received (to-be-transmitted) information after obtaining the information to be transmitted by measuring the fourth quantum state information, and use the bits for public comparison with the initial network node A. If the comparison fails, for example, the error rate exceeds a preset threshold, it indicates that a problem has occurred in the propagation process.
[0101] Further, when a network node receives quantum state information and classical information from the previous network node, and finds by reading the classical information that it is a node other than the initial network node A and the target network node B, it can determine whether it belongs to an intermediate network node on the recorded risk degree minimum transmission path and whether the received information comes from the previous network node on the risk degree minimum transmission path with respect to it according to the received classical information.
[0102] If it is determined that the network node is on the recorded risk degree minimum transmission path and the received information comes from the previous network node on the risk degree minimum transmission path with respect to it, the network node can update the next network node in the classical information according to the recorded risk degree minimum transmission path, send the received quantum state information and classical information to the next network node with respect to it, and broadcast to the initial network node A and the target network node B.
[0103] When it is determined that the network node is not on the recorded risk degree minimum transmission path and / or the received information does not come from the previous network node on the risk degree minimum transmission path with respect to it, the transmission can be terminated and the error can be broadcast.
[0104] In particular, referring to Figure 5(a), the quantum logic gate selected by target network node B can correspond to either an identity transformation or a Hadamard gate. Therefore, when initial network node A generates photons in the |HV> basis, if target network node B in state two uses an identity transformation for encryption, then in state four, target network node B is equivalent to being measured using the |HV> basis. If target network node B in state two uses a Hadamard gate for encryption, then in state four, target network node B is equivalent to being measured using the |+-> basis. This allows for testing the channel security of the BB84 protocol.
[0105] In summary, in the network that allows secure self-checking and its self-checking information transmission method of the present invention, a ring-shaped information transmission path is adopted to enable the initial network node and the target network node to perform encryption and decryption without knowing each other's encryption and decryption keys (such as phase parameters in quantum logic gates), thereby realizing encrypted transmission of information. In addition, in the encryption and decryption operations for encrypted information transmission, due to the use of quantum logic gates with specific structures, a phase-adjustable single-bit encoding operation can be performed on a group of quantum bits in sequence, so that the encryption of the quantum state can be exchanged in order. While adapting to the ring-shaped information transmission structure, the non-replicability of quantum is used to protect the security of the encrypted information. The security of the network is guaranteed by the non-replicability and unpredictability of the quantum state. If an eavesdropper wants to know the content of the encrypted quantum information, he needs to know the measurement basis, that is, he needs to know the phase values of all the nodes he has passed through. In particular, he needs to know the phase value of the initial network node A, which is equivalent to the direct leakage of the information of the initial network node A. In addition, in practical applications, even if the quantum state information received and transmitted by a node is intercepted, because the measurement basis is unknown, it is impossible to obtain the phase value of the quantum logic gate used by the node through quantum state comparison, and it is impossible to obtain the detection information without leaving a trace, thereby allowing potential eavesdroppers to be found through this self-detection method.
[0106] In the above description of the quantum communication network and the self-checking information transmission method, the content of determining the information transmission path based on the risk of the network is mentioned, and the considerations related to the risk are discussed in detail, such as the risk and the number of network nodes in the path, the distance between network nodes, the security of the lines between network nodes, the confidentiality of network nodes, etc. Although those skilled in the art can think of various specific risk calculation schemes based on the above content, the inventors, through further creative work, also propose a method that is particularly suitable for calculating the risk of network nodes, transmission lines and transmission paths using self-checking information (i.e., information to be transmitted) in the scenario where self-checking information is transmitted between the initial network node and the target network node using the above-mentioned self-checking information transmission method. Of course, this risk calculation method may also be applicable to other scenarios.
[0107] The risk calculation method of the present invention may include an initialization step, an error statistics step, and a dynamic update step.
[0108] The initialization step is used to calculate the initial value of the risk of each network node and transmission line (ie, the line between adjacent network nodes) according to the network layout (eg, the network allowing security self-checking of the present invention).
[0109] Specifically, for any network node i in the network, according to the relationship r 0i =ln(1+P i ) Calculate the initial value of its risk r 0i , where P i is the number of adjacent network nodes of network node i in the network.
[0110] For the transmission line ij between any two adjacent network nodes i and j in the network, the relationship Calculate the initial value r of its risk 0ij , where L ij is the line length of the transmission line ij, and μ is a preset coefficient.
[0111] Based on the initial risk values of network nodes and transmission lines, the present invention also dynamically adjusts the risk of each network node and transmission line by counting the occurrence of errors related to each network node and transmission line over a period of time during information transmission, in order to ensure that the obtained risks match the real-time network conditions. Furthermore, the present invention can also broadcast the errors to the entire network.
[0112] According to the present invention, in the error statistics step, when quantum state information is transmitted via the network, classical information such as the information transmission path (i.e., the network nodes and transmission lines through which the information is transmitted) can be recorded simultaneously, so that during the information transmission process, each network node in the path can detect errors in the current information transmission by checking, for example, classical information, or the target network node can detect errors in the information transmission result by checking, for example, quantum state information, and adjust the risk of the corresponding network nodes and transmission lines based on different error types.
[0113] Specifically, as described above in the network and self-test information transmission method, during the information transmission process, quantum state information and classical information can be integrated for transmission. The quantum state information can be generated based on coded information, and the coded information, in addition to the information to be transmitted, can also include verification data such as the digital signature of the initial network node, a timestamp, and a hash value generated from one or more of the information to be transmitted, the digital signature of the initial network node, and the timestamp. The classical information can be used to record data related to the information transmission process and some related verification data, such as the digital signature and timestamp of the initial network node, the target network node, the intermediate network node (list), the next network node, and the network node.
[0114] Therefore, during the information transmission process, when network node i receives the quantum state information and classical information transmitted by the previous network node, since the quantum state information may be in an encrypted state at this time, network node i can read the classical information and, based on the data recorded therein such as the initial network node, target network node, intermediate network node, next network node, digital signature of the network node and timestamp, check whether there are any problems in the transmission process between it and the previous network node, such as transmission path error, the difference between the timestamp and the current time exceeds the preset value, the digital signature does not match, the classical information format error, etc. When such problems occur, the number of error reports related to the previous network node and the number of error reports related to the previous transmission line (i.e., the transmission line from the previous network node to the current network node i) are increased, for example, the number of error reports is increased by 1.
[0115] In addition, when quantum state information is transmitted to a target network node, for example, through an initial transmission process and a retransmission process, the target network node can obtain corresponding encoded information, for example, through a decryption measurement operation, and then publicly compare some bits of the received information to be transmitted with those of the initial network node, verify the digital signature of the initial network node, verify the timestamp, and verify the hash value to check for errors in the information transmission result. If such errors exist, the number of error reports associated with each of all intermediate network nodes and each of all transmission lines between the initial network node and the target network node on the transmission path can be increased, for example, by 1.
[0116] In the present invention, a statistical period t can be pre-set to count the number of error reports ni related to each network node i and the number of error reports m related to each transmission line ij within the period t. ij , so that every statistical period t, with the help of dynamic update steps, according to the number of error reports ni and m ij , and update the risk levels of corresponding network nodes and transmission lines.
[0117] In the dynamic update step, if the number of errors related to network node i is counted as ni=0 within the current statistical period t, the risk of network node i is updated to r ti =r 0i *e -λt Otherwise, update the risk of network node i to r ti =r 0i +a*ni2, where λ and a are preset coefficients.
[0118] If within the current statistical period t, the number of errors related to the transmission line ij is counted m ij = 0, then the risk of the transmission line ij is updated to r tij =r 0ij *e -λt Otherwise, the risk of transmission line ij is updated to r tij =r 0ij +b*m ij 2 , where λ and b are preset coefficients.
[0119] After obtaining the risks of network nodes and transmission lines, the risk of the transmission path from the initial network node to the target network node can be calculated, which is the sum of the risks of all network nodes and all transmission lines on the transmission path.
[0120] In summary, it can be seen that the risk calculation method of the present invention, in addition to considering the impact of the overall network layout on the risk of network nodes and transmission lines, also proposes dynamic considerations of risk based on the information transmission process and the final transmission results, and provides a specific calculation method that is particularly compatible with the quantum communication network of the present invention. This enables the transmission results of self-test information to be used while normal information is being transmitted, to accurately and dynamically grasp the risk of the network, realize dynamic monitoring of network risks, and provide strong guarantees for planning the optimal information transmission path.
[0121] Based on the above-mentioned quantum communication network architecture, information transmission method and risk calculation method, the present invention further proposes a network security self-test method that uses the non-replicability of quantum bits to transmit self-test information to find potential eavesdroppers. The method can include a self-test information transmission step, a risk monitoring step and a security detection step.
[0122] Specifically, in Figure 1 Taking the network security self-check method of the present invention implemented in the quantum communication network shown as an example, in the self-check information transmission step, each network node can periodically randomly select another network node, and use the self-check information transmission method of the present invention (such as shown in Figure 5(a)) to send self-check information (the so-called "information to be transmitted") to the randomly selected network node.
[0123] Therefore, the network node used to send the self-test information is the initial network node, the randomly selected network node is the target network node, and the initial network node sends the self-test information to the target network node through the initial sending process and the resending process.
[0124] Among them, during the initial transmission process, the initial network node generates original quantum state information based on self-test information, uses quantum logic gates to perform encryption operations on the original quantum state information to generate first quantum state information, calculates the minimum risk transmission path and transmits the first quantum state information to the target network node according to the minimum risk transmission path; and, the target network node uses quantum logic gates to perform encryption operations on the first quantum state information to generate second quantum state information, calculates the minimum risk transmission path and transmits the second quantum state information back to the initial network node according to the minimum risk transmission path.
[0125] During the retransmission process, the initial network node uses quantum logic gates to decrypt the second quantum state information to generate third quantum state information, calculates the transmission path with the minimum risk, and transmits the third quantum state information to the target network node according to the transmission path with the minimum risk; and the target network node uses quantum logic gates to decrypt the third quantum state information to generate fourth quantum state information, and measures the fourth quantum state information to obtain self-test information.
[0126] Furthermore, the effects of the encryption operation during the initial transmission and the decryption operation during the retransmission of the same network node on the quantum state information cancel each other out, thereby ensuring the secure transmission of self-test information.
[0127] In the risk monitoring step, the risk levels of network nodes and lines on the transmission path between the initial network node and the target network node may be adjusted based on the self-test information received by the target network node.
[0128] As an example, in the risk monitoring step, the risk adjustment method disclosed in the above-mentioned self-test information transmission method and / or risk calculation method can be used to change the risk of network nodes and lines on the transmission path accordingly according to different error / problem types, so it will not be repeated here.
[0129] For example, after receiving the self-test information, the target network node can publicly compare the self-test information with the originating network node. If the comparison is incorrect or the target network node does not receive the self-test information, the risk level of the relevant network nodes and lines in the transmission path can be increased.
[0130] In the security monitoring step, the risk settlement of network nodes and lines in the quantum communication network can be performed regularly at intervals, and the security of the network nodes and lines can be monitored based on the settled risk.
[0131] For example, risk thresholds can be pre-set for nodes and lines in a quantum communication network. Therefore, if the risk of a particular node or line exceeds the pre-set risk threshold, network services for that node or line can be suspended to identify potential eavesdroppers.
[0132] As a preferred example, the risk thresholds for different routes may not necessarily be the same. For example, the risk threshold for a route may be related to the length of the route, and preferably a higher risk threshold is set for a route with a longer length.
[0133] With the help of the security self-checking method of the present invention, the quantum communication network can automatically monitor the risk levels of network nodes and lines in the network on the basis of dynamically adjusting the risk levels of network nodes and lines, which can greatly ensure the security and reliability of the quantum communication network and allow possible eavesdroppers to be discovered in a timely manner.
[0134] Although the present invention has been described above through specific embodiments in conjunction with the accompanying drawings, it is easy for those skilled in the art to recognize that the above embodiments are merely exemplary and are used to illustrate the principles of the present invention. They do not limit the scope of the present invention. Those skilled in the art can make various combinations, modifications and equivalent substitutions to the above embodiments without departing from the spirit and scope of the present invention.
Claims
1. A security self-check method for a quantum communication network, comprising a self-check information transmission step, a risk monitoring step, and a security detection step; In the self-test information transmission step, each network node in the quantum communication network serves as an initial network node, randomly selects another network node as a target network node, and the initial network node sends the self-test information to the target network node through the initial sending process and the resending process; During the initial transmission process, the initial network node generates original quantum state information based on self-test information, uses quantum logic gates to perform encryption operations on the original quantum state information to generate first quantum state information, calculates the minimum risk transmission path, and transmits the first quantum state information to the target network node according to the minimum risk transmission path; and, the target network node performs an encryption operation on the first quantum state information using a quantum logic gate to generate second quantum state information, calculates a transmission path with the minimum risk, and transmits the second quantum state information back to the initial network node according to the transmission path with the minimum risk; During the retransmission process, the initial network node uses a quantum logic gate to decrypt the second quantum state information to generate a third quantum state information, calculates a minimum-risk transmission path, and transmits the third quantum state information to the target network node according to the minimum-risk transmission path; and the target network node uses a quantum logic gate to decrypt the third quantum state information to generate a fourth quantum state information, and measures the fourth quantum state information to obtain self-test information. Among them, the effects of the encryption operation during the initial transmission process and the decryption operation during the retransmission process on the quantum state information of the same network node cancel each other out; In the risk monitoring step, based on the self-test information received by the target network node, the risk levels of the network nodes and lines on the transmission path between the initial network node and the target network node are adjusted; In the security monitoring step, the risk levels of network nodes and lines in the quantum communication network are regularly settled, and network services for network nodes and / or lines whose risk levels exceed a risk threshold are stopped; The risk level is calculated using the following steps: For any network node i in the network, Calculate the initial value of its risk ,in, is the number of adjacent network nodes of network node i in the network; For the transmission line ij between any two adjacent network nodes i and j in the network, according to the relationship Calculate the initial value of its risk ,in, is the line length of the transmission line ij, is the preset coefficient; A statistical period t is set in advance, and the number of errors related to each network node i within the period t is counted. and the number of errors associated with each transmission line ij ; If within the current statistical period t, the number of errors related to network node i is counted , then the risk of the network node i is updated to Otherwise, the risk of network node i is updated to ,in, and is the preset coefficient; If within the current statistical period t, the number of errors related to the transmission line ij is counted , then the risk of the transmission line ij is updated to Otherwise, the risk of transmission line ij is updated to ,in, and is the preset coefficient.
2. The safety self-checking method according to claim 1, wherein: The quantum logic gates in different network nodes are different from each other; and / or the corresponding operation of the quantum logic gate selected by the target network node is an identity transformation or a Hadamard gate.
3. The safety self-checking method according to claim 1, wherein: The Dijkstra algorithm is used to calculate the transmission path with the minimum risk.
4. The safety self-checking method according to claim 1, wherein: The initial network node generates coded information based on the self-check information encoding, and then generates the original quantum state information based on the coded information; The encoded information includes self-test information, a digital signature and a timestamp of the initial network node, and a hash value of the self-test information, the digital signature and the timestamp of the initial network node.
5. The safety self-checking method according to claim 4, wherein: The network node also sends classical information along with the quantum state information, which includes a state identifier and a node list, the node list including the initial network node, the target network node, the intermediate network node and the next network node; and, The initial network node generates classical information after generating the original quantum state information, where the state is identified as the initial sending state; When the target network node reads the state identifier in the classic information as the initial sending state, it changes the state identifier to the resending state and adds a digital signature to the target network node in the node list; The initial network node reads the state identifier in the classic information as the resending state, and after verifying the digital signature of the target network node, it adds the digital signature to the initial network node in the node list; After the target network node reads the state identifier in the classical information as the resending state and verifies the digital signature of the initial network node, it uses the quantum logic gate to decrypt the third quantum state information to generate the fourth quantum state information, measures the fourth quantum state information to obtain the encoded information, and verifies the digital signature, timestamp and hash value of the initial network node in the measured encoded information.
6. The safety self-checking method according to claim 5, wherein: The initial network node also writes a timestamp into the classical information before sending the first quantum state information and the classical information; When a network node receives quantum state information and classical information, it compares the timestamp in the classical information with the current time, and allows the timestamp to be updated when the difference between the timestamp and the current time is less than a preset value.
7. The safety self-checking method according to any one of claims 1 to 6, wherein: The network nodes utilize a set of quantum logic gates )} Encrypt or decrypt quantum state information, a set of quantum logic gates )} the jth quantum logic gate ) for the i-th quantum bit in the quantum state information Perform encryption or decryption operations to generate operation results .
8. The safety self-checking method according to claim 7, wherein: Quantum logic gates , and the quantum logic gates of the same network node Phase during initial transmission and retransmission θ j Same size, opposite sign.
9. The safety self-checking method according to claim 5, wherein: If the target network node fails to verify the digital signature, timestamp and hash value of the initial network node in the encoded information, the risk of all network nodes and lines in the transmission path will be increased during the next risk settlement.
10. The safety self-checking method according to claim 5, wherein: When network nodes other than the initial network node and the target network node receive quantum state information and classical information, they read the classical information to determine whether it is on the transmission path with the minimum risk, and whether the received information comes from the previous network node on the transmission path with the minimum risk; If it is determined that it is on the transmission path with minimum risk and the received information comes from the previous network node on the transmission path with minimum risk, the received quantum state information and classical information will be sent to the next network node on the transmission path with minimum risk; otherwise, the transmission will be terminated and the risk of the previous network node and the risk of the line between it and the previous network node will be increased.
11. The safety self-checking method according to claim 1, wherein: Set the risk threshold for the route based on the route length.
Citation Information
Patent Citations
Session key updating method and system applied to dynamic quantum network
CN110740037A
Quantum communication method and communication network based on secure relay
CN112787807A