A quantum secret sharing method based on lattice cryptography and random bases
By adopting a quantum secret sharing method based on lattice cryptography and random basis, the limitations of key management and resource consumption in existing schemes are solved, dynamic key management and security are achieved, the probability of eavesdropper detection is reduced, and the efficiency and security of the system are improved.
Patent Information
- Application Number
- CN202411566061.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-05
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2044-11-05
AI Technical Summary
Existing quantum secret sharing schemes have limitations in key management, failing to achieve dynamic management. Furthermore, the transmission of decoy particles between participants and the detection of eavesdroppers increase computational and communication costs. The more decoy particles an eavesdropper measures, the greater the probability of error.
A quantum secret sharing method based on lattice cryptography and random basis is adopted. By constructing a quantum secret sharing system, a resegmentable threshold public key encryption technology is introduced to reduce the transmission of decoy particles between participants. A semi-trusted third party is used for eavesdropper detection, and decoy particles with random quantum states are used to improve security.
It improves the dynamic management capability of keys, reduces resource and communication consumption, enhances the flexibility and security of the system, reduces the probability of eavesdropper detection, and strengthens security.
Smart Images

Figure CN119449296B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of quantum cryptography, and in particular relates to a quantum secret sharing method based on lattice cryptography and random bases. Background Art
[0002] Quantum cryptography is an emerging field that combines quantum mechanics with traditional cryptography. Its security is based on fundamental principles of quantum mechanics, such as the quantum superposition principle, the quantum no-cloning theorem, and the quantum uncertainty principle, theoretically achieving unconditional security. With the development of quantum computing technology, traditional encryption algorithms based on classical computing are facing the threat of quantum attacks. As an effective means of resisting quantum attacks, quantum cryptography has become a key research area in the field of information security.
[0003] Quantum Secret Sharing (QSS), a key branch of quantum cryptography, aims to split a secret into multiple parts and distribute them to different participants. The secret can only be recovered when a certain number of participants cooperate. Traditional classical secret sharing schemes suffer from high computational complexity and inflexible key management. Quantum secret sharing, however, leverages the properties of quantum mechanics to enhance security while ensuring that the key is not leaked during the sharing process.
[0004] Although the existing quantum secret sharing schemes have made significant progress in security and efficiency, there are still some shortcomings. Most schemes have certain limitations in key management and cannot achieve dynamic management of keys. In addition, in most quantum secret sharing schemes using decoy particles, single-particle state schemes usually require particles to be transmitted in a circular manner between participants, and eavesdropper detection is required for each transmission. Therefore, participants need to prepare decoy particles. Although these decoy particle states are relatively simple, since each participant and server needs to prepare decoy particles and perform eavesdropping detection with the sender, this significantly increases the computational cost of the scheme and reduces efficiency. Some single-particle state schemes choose to have the server prepare all decoy particles, and participants only use some decoy particles to complete eavesdropper detection together with the server. Although this method reduces resource consumption, it increases the communication cost of the scheme to a certain extent. In addition, in terms of the selection of the quantum state of the decoy particles, the quantum state of the decoy particles in most schemes is usually selected from a fixed set, such as {|0>,|1>,|+>,|->}, or unbiased basis In these schemes, the more decoy particles an eavesdropper measures, the greater the probability of error. Summary of the Invention
[0005] To solve the problems existing in the above-mentioned prior art, the present invention proposes a quantum secret sharing method based on lattice cryptography and random base, which comprises: constructing a quantum secret sharing system, which comprises a secret distributor (Dealer), a secret reconstructor (TP), and n participants; the quantum secret sharing system comprises: a key generation phase, a secret encryption and distribution phase, a quantum secret reconstruction phase, and a key retransmission phase;
[0006] The key generation phase includes: the secret distributor Dealer generates the public key TPK and private key share tsk through the TKeyGen algorithm i And the verification key tvk i ; Dealer selects a hash function to calculate the hash value of the secret and sends the hash value to the secret reconstructor TP;
[0007] The secret encryption and distribution phase includes: Dealer encrypts the secret using the public key to generate ciphertext C; broadcasts the ciphertext to all participants and the secret reconstructor TP;
[0008] The quantum secret reconstruction phase includes: each participant and the secret reconstructor TP decrypt the ciphertext; obtain the decrypted value of the decryption results of t participants and calculate the shadow corresponding to the decrypted value; use unitary operation to embed the shadow and random number into the information particle; the secret recoverer TP measures the extracted information particle, calculates the sum of all shadows, removes the noise term, and obtains the recovered secret; and uses a hash function to verify whether the recovered secret is correct.
[0009] The key resending phase includes: the system re-determines whether the participants have changed. If the participants have changed, the dealer executes the Tsplit algorithm to generate shares for re-dividing and redistributing the key; the dealer re-divides the elements TSK in the private key vector i To generate a new private key share tsk i , and redistributed to participants.
[0010] Beneficial effects of the present invention:
[0011] This invention introduces lattice-based resegmentable threshold public key encryption (RTPKE). RTPKE not only inherits the security of traditional threshold encryption, but also adds the dynamic management capability of keys, enabling the new quantum secret sharing method to flexibly adjust the distribution and use of keys as needed, thereby improving the flexibility and security of the system.
[0012] The decoy particles of the present invention are not used for eavesdropper detection when they are transmitted between participants. Instead, eavesdropper detection is performed by the semi-trusted third party (TP) after they are returned to the TP. This approach effectively reduces the resource consumption and communication consumption of the solution, improving overall efficiency.
[0013] The decoy particles used in this invention are not selected from fixed quantum states, but rather completely random quantum states. Conventional measurements of such random quantum states cannot yield correct results, and the probability of an eavesdropper measuring any decoy particle without being detected is virtually zero. Therefore, the proposed scheme offers significant security advantages over traditional quantum secret sharing schemes. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 is a flow chart of the secret recovery phase of the present invention;
[0015] Figure 2 Schematic diagram of the process of quantum secret recovery in an embodiment of the present invention. DETAILED DESCRIPTION
[0016] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0017] A quantum secret sharing method based on lattice cryptography and random bases comprises: constructing a quantum secret sharing system, the system comprising a secret distributor (Dealer), a secret reconstructor (TP), and n participants; performing quantum secret sharing in the quantum secret sharing system comprises: a key generation phase, a secret encryption and distribution phase, a quantum secret reconstruction phase, and a key retransmission phase.
[0018] The key generation phase includes: the secret distributor Dealer generates the public key TPK and private key share tsk through the TKeyGen algorithm i And the verification key tvk i ; Dealer selects a hash function to calculate the hash value of the secret and sends the hash value to the secret reconstructor TP;
[0019] The secret encryption and distribution phase includes: Dealer encrypts the secret using the public key to generate ciphertext C; broadcasts the ciphertext to all participants and the secret reconstructor TP;
[0020] The quantum secret reconstruction phase includes: each participant and the secret reconstructor TP decrypt the ciphertext; obtain the decrypted value of the decryption results of t participants and calculate the shadow corresponding to the decrypted value; use unitary operation to embed the shadow and random number into the information particle; the secret recoverer TP measures the extracted information particle, calculates the sum of all shadows, removes the noise term, and obtains the recovered secret; and uses a hash function to verify whether the recovered secret is correct.
[0021] The key resending phase includes: the system re-determines whether the participants have changed. If the participants have changed, the dealer executes the Tsplit algorithm to generate shares for re-dividing and redistributing the key; the dealer re-divides the elements TSK in the private key vector i To generate a new private key share tsk i , and redistributed to participants.
[0022] This embodiment provides a quantum secret sharing method based on lattice cryptography and random bases, such as Figure 1 As shown, including but not limited to the following steps:
[0023] S1. Initialization and key generation phase: Dealer generates public key TPK and private key share tsk through TKeyGen algorithm i And the verification key tvk i The public key TPK is used to encrypt the secret S, and the private key share tsk i For Bob i Perform partial decryption, threshold verification key tvk i For Bob i Verify that the partial decryption result is correct. In addition, the Dealer selects a hash function H() to calculate the secret hash value H(S) and sends this hash value to the TP.
[0024] Specifically, the specific implementation process of step S1 is as follows:
[0025] S11. Generate private key vector TSK: Dealer randomly generates a private key vector TSK = (TSK1, TSK2, ..., TSK n ), each TSK i is from the finite field Z q A randomly selected element from a Gaussian distribution Each element of the private key vector TSK is sampled from i It will serve as the basic secret for each participant.
[0026] S12. Construct threshold polynomial f i (x): To ensure that only t or more participants can recover the private key, each private key element TSK i The segmentation is performed in the form of a threshold polynomial. For each TSK i , Dealer generates a polynomial f of degree t-1 i (x)∈Z q [x], and ensure that the value of the polynomial at 0 is TSK i :f i (x) = TSKi +a1x+a2x 2 +…+a t- 1x t-1 , where a1, a2, …, a t-1 is from the finite field Z q The randomly selected coefficients in .
[0027] S13. Calculate the participant's private key share tsk i :Bob i Private key share tsk i are polynomials f1(x),f2(x),…,f n (x) is the value at x=i. The specific calculation is as follows: tsk i =(f1(i),f2(i),…,f n (i)), which means that each participant i receives a share of the private key tsk i is a vector consisting of multiple polynomial values.
[0028] S14. Distribute private key shares: Dealer distributes each participant’s private key share tsk i The private key is sent to the corresponding participants through a secure channel. Participants can only know their own private key share and cannot know the private key share of other participants.
[0029] S15. Generate public key matrix A: Dealer generates a random matrix This matrix is part of the public key and is used in the encryption process.
[0030] S16. Calculate the error vector e: Randomly generate an error vector from the Gaussian distribution Error vectors are used to protect keys and increase security.
[0031] S17. Calculate the public key vector b: The dealer calculates the public key vector b using the following formula: b = eA·TSKmode, where A·TSK is the product of the matrix A and the private key vector TSK. This vector b and the matrix A together constitute the public key TPK.
[0032] S18. Generate public key TPK: The public key consists of matrix A and vector b, that is: TPK = (A, b). The public key will be broadcast to all participants and the final secret recoverer TP for the subsequent encryption process of the secret S.
[0033] S19. Generate verification key: To prevent participants from cheating or submitting incorrect partial decryption results during the partial decryption process, the Dealer will generate a threshold verification key tvk for each participant. i, used to verify each participant’s partial decryption result. For each participant Bob i , the threshold verification key is: The threshold verification key is distributed to participants along with the private key share and is made public to everyone for verifying the correctness of decryption. The dealer eventually broadcasts the public key TPK (including matrix A and vector b) to all participants and the secret restorer TP. i and threshold verification key tvk i Sent to the corresponding participants through a secure channel.
[0034] S2, secret encryption and distribution phase: Dealer uses the public key to encrypt the secret S and generate a ciphertext C. The ciphertext will be broadcast to all participants and the final secret recoverer TP so that the secret can be recovered through the collaboration of t or more participants in the subsequent decryption process.
[0035] Specifically, the detailed process of step S2 includes:
[0036] S21. Select a key pair (sk, vk): The dealer first generates a key pair (sk, vk) for the ciphertext, where sk is the private signing key and sk is the public signing key. This key pair will be used to sign the generated ciphertext in subsequent steps to ensure its integrity and authenticity.
[0037] S22, Select random vectors e1, e2, e3 from Gaussian distribution: Dealer randomly selects two vectors from Gaussian distribution and a scalar e3∈Z q These random vectors and scalars will be used to ensure the randomness and security of the ciphertext.
[0038] S23. Calculate the first part c1 of the ciphertext: Calculate the first part c1 of the ciphertext using the public key matrix A and the random vectors e1 and e2: Where A is the public key matrix, and e1 and e2 are random vectors generated from a Gaussian distribution. This part of the ciphertext ensures randomness during transmission.
[0039] S24. Calculate the second part c2 of the ciphertext: Calculate the second part c2 of the ciphertext using the public key vector b, the random vector e1, the scalar e3, and the secret S: Where b is the public key vector and S is the secret to be encrypted (usually 0 or 1). This formula embeds the secret S into the ciphertext and adds the random vector e1 and error term e3 to ensure the security of the encryption.
[0040] S25. Sign the ciphertext σ: The dealer uses the previously generated private signature key sk to sign the generated ciphertext c1, c2, obtaining the signature σ: σ = Sign(sk, c1, c2). This signature σ ensures that the ciphertext has not been tampered with during transmission. The receiver can verify the integrity of the ciphertext using the signature public key vk.
[0041] S26. Generate ciphertext C: Finally, the dealer generates ciphertext C, whose structure is: C = (c1, c2, vk, σ)
[0042] Where c1 and c2 are the two parts of the ciphertext, vk is the signature public key, and σ is the signature. The dealer broadcasts the generated ciphertext C to all participants and the final secret recoverer TP.
[0043] S3, quantum secret reconstruction stage: This stage is performed by each participant Bob i Together with the secret recoverer TP, t participants will partially decrypt the result μ i The partial decrypted value e in i Extract it and calculate its corresponding shadow. Each participant embeds the shadow and random number into the information particle by performing unitary operation. The secret recoverer TP measures the extracted information particles, calculates the sum of all shadows, removes the noise term, and finally recovers the secret. It then verifies whether the recovered secret is correct through the hash function.
[0044] Specifically, if Figure 2 As shown, the detailed process of step S3 includes:
[0045] S31. Randomly select t participants: TP randomly selects t participants from n participants as participants in quantum secret reconstruction.
[0046] S32, TP prepares information particles and decoy particles: TP first prepares a d-dimensional single particle As information particles, Then construct a privacy coefficient matrix:
[0047]
[0048] In this matrix, the elements of each row satisfy Using the elements in the coefficient matrix as parameters, TP prepares a set of decoy particles It is named as decoy particle sequence V. TP will A new sequence V′ is obtained by random insertion into V, TP records the insertion position and sends V′ to participant Bob1 through the ideal quantum channel.
[0049] S33. Each participant calculates the shadow corresponding to the partial decryption result: After all participants have received the particle, each participant Bob i (i=1,2,…,t) takes out its own private key share, performs partial decryption and verification, and generates a partial decryption result μ i , and then calculate the shadow S corresponding to the decrypted value i The specific steps are as follows:
[0050] (1) Verify the ciphertext signature:
[0051] During the decryption process, the integrity of the ciphertext must first be verified to ensure that the ciphertext has not been tampered with during transmission.
[0052] Bob i Verify the signature σ of the ciphertext (c1, c2) using the signature public key vk contained in the ciphertext:
[0053] Verify(vk,c1,c2,σ)
[0054] If the signature verification fails, the ciphertext is considered invalid and the participant outputs μ i =(i,⊥), indicating partial decryption failure, and subsequent decryption operations are stopped. If signature verification passes, the partial decryption steps continue.
[0055] (2) Partial decryption calculation:
[0056] Each participant uses the public key TPK and his own private key share tsk i =(s i,1 ,s i,2 ,…,s i,n )Through TShareDecryption(TPK,tsk i ,C) algorithm partially decrypts the ciphertext C and generates a partial decryption result μ i The specific steps are as follows:
[0057] First, participant Bob i Calculate the partial decryption value sd i :
[0058] sd i =c2+c1·tsk i modq
[0059] Among them, c1 is the first part of the ciphertext, c2 is the second part of the ciphertext, and tsk i It is participant Bob i The participant's private key share is combined with the ciphertext to generate a partial decrypted value.
[0060] Then, calculate the pseudo-random correction term xi :
[0061] Participant Bob i Generate a pseudo-random correction term x i , used to ensure that some decryption results are random and prevent attackers from inferring the private key content through multiple decryption results.
[0062] Correction term x i By the following pseudo-random function φ KA (c1,c2) generates:
[0063] x i =φ KA (c1,c2)
[0064] Among them, the pseudo-random function φ KA Use the random seed KA held by the participant and the ciphertext c1 and c2 as input to generate a pseudo-random value.
[0065] Finally, calculate the partial decryption result μ i :
[0066] Participant Bob i Combined with the partial decryption value sd i and the pseudo-random correction term x i , calculate the final partial decryption result:
[0067] e i =sd i +x i modq
[0068] The generated partial decryption result μ i for:
[0069]
[0070] Among them, e i It is participant Bob i The partial decrypted value of is the correction term x i The correction term makes the decryption result unpredictable, ensuring security.
[0071] (3) Verify partial decryption results:
[0072] After obtaining the partial decryption results, each participant Bob i You need to verify your partial decryption results through the TShareVerify algorithm Is it correct? Make sure there are no calculation errors in these decryption results.
[0073] The verification process is based on the following equation:
[0074]
[0075] in, is the partially decrypted value e i The exponential form of is the pseudo-random correction term x i The exponential form of c2 is the second part of the ciphertext, r1, r2, ..., r n is the value in the ciphertext c1, It is participant Bob i The individual elements of the verification key.
[0076] If the verification is successful, it means that the participant's partial decryption result is correct, and the decryption result will be used for subsequent secret recovery. Otherwise, it will directly return ⊥, indicating that the decryption failed.
[0077] (4) Calculate the shadow S corresponding to the decrypted value i :
[0078] After completing the partial decryption and verification steps, each participant Bob i Take out your own partial decryption results respectively The partial decrypted value e in i , and calculate the shadow S of the decrypted value i :
[0079] S i =e i ·λ i modq
[0080] Where i = 1, 2, …, t, λ i is the Lagrange interpolation coefficient, defined as:
[0081]
[0082] S34. Bob1 performs a unitary operation to embed the shadow and random number: After receiving the sequence V′, Bob1 first calculates B1=r1+S1, where r1 is a randomly selected integer from the set {0,1,2,…,d-1}, and S1 is the shadow corresponding to Bob1's partial decrypted value e1. Next, Bob1 performs a unitary operation on all particles in V′. Subsequently, Bob1 reorders the particles in the sequence to obtain a new sequence V′1, and Bob1 records the ordering information v1. Finally, Bob1 sends the sequence V′1 to Bob2.
[0083] Furthermore, the specific form of the unitary operation performed by each participant is:
[0084]
[0085] Among them, U α,β For any single-particle state {|t>|t∈(0,1,2,...,d-1)}, the results are as follows:
[0086]
[0087] Furthermore, the properties of the d-dimensional Pauli operator are described as follows:
[0088] For any two Pauli operators U a,b and U p,q (a,b,p,q∈{0,1,2,...,d-1}), if they are applied to the particle|σ> in sequence, the particle transformation process is:
[0089] U a,b U p,q |σ>=ω b·p U a+p,b+q ∣σ>
[0090] S35. Other participants perform similar operations as Bob1: Each of the remaining participants Bob k (k=2,3,4,...,t) all perform similar operations as Bob1 until Bob t A new sequence V′ is obtained t And send it to TP.
[0091] S36, TP obtains sorting information from all participants: confirms sequence V' t And after sending it back to TP, each participant Bob k (k=3,4,...,t) will all sort the information {v k |k=1,2,…,t} is sent to TP through the classical channel. TP then converts the sequence V′ into t The particles in are restored to their original positions, thus obtaining a new sequence VV″. At this time, the order of particles in V″ should be the same as the order of particles in sequence V′.
[0092] S37, TP performs eavesdropping detection: TP extracts the particle V″ based on the recorded initial position of the secret particle TP is then measured using the computational basis {|0>,|1>,...,|d-1>} Obtaining measurement results TP calculation At this time, except for the secret particle, assume that the remaining particles of sequence V″ are {|ψ1>′,|ψ2>′,...,|ψ m >′}. TP performs the Qudit quantum gate on these remaining particles:
[0093] G d (α i(0-sum′) ,α i(1-sum′) ,…,α i(d-1-sum′) )∣ψ i >′,i=1,2,…,m
[0094] Furthermore, the Qudit quantum gate executed by TP is specifically explained as follows:
[0095] G d is a d-dimensional transformation that can map any qudit state to |d-1>:
[0096]
[0097] where {α j |j=0,1,...,d-1} satisfies G d can be broken down into:
[0098]
[0099] And X j (a j ,b j ) is in the form of a matrix:
[0100]
[0101] Where I represents the identity matrix, a j * ,b j * Indicates a j ,b j The conjugate number of .
[0102] The TP now measures all remaining particles using the computational basis {|0>,|1>,...,|d-1>}. If the measurement results for all remaining particles are d-1, the TP continues the protocol. Otherwise, the TP considers the communication unsafe, cancels the communication, and restarts the protocol.
[0103] S38. TP calculates the sum of all shadows: All participants randomly select one participant as a representative to collect random numbers from each participant and calculate the sum of the random numbers:
[0104]
[0105] The representative then sends R to TP. After receiving R, TP calculates the sum of all shadows:
[0106] sum = (sum′ - R) mod d
[0107] At this time, the sum of the shadows corresponding to the t participants obtained by TP is
[0108] S39, remove noise, recover final secret and verify: TP judges and removes noise according to the value range of the sum of shadows, and finally recovers the secret S. If sum is close to 0, the recovered secret is S′=0. If sum is close to The recovered secret is S′ = 1. TP uses the hash function H() to calculate the hash value H(S′) and then verifies that the equation H(S′) = H(S) holds. If so, the secret recovery process is successful; otherwise, it concludes that at least one dishonest participant was involved in the reconstruction process and terminates the execution.
[0109] S4. Participant Change and Key Redistribution Mechanism: In the quantum secret sharing scheme based on lattice cryptography and random base, participant change and key redistribution are a dynamic adjustment mechanism of the system. When the participant set changes (such as new participants joining or existing participants leaving), the dealer executes the Tsplit algorithm to redistribute and redistribute the key shares. The dealer redistributes the elements TSK in the private key vector by redistributing the elements TSK in the private key vector. i To generate a new private key share tsk i , and redistribute it to participants to flexibly adapt to changes in participants.
[0110] Specifically, the detailed process of step S4 includes:
[0111] To ensure that the addition of new participants or the exit of existing participants does not affect the security of the system, the Dealer needs to regenerate the private key share based on TSK through the Tsplit algorithm.
[0112] S41. Generate a new threshold polynomial f′ i (x): Dealer for each private key vector element TSK i Regenerate a new threshold polynomial f′ of degree t-1 i (x), and ensure that the value of the polynomial at 0 is equal to the private key vector element TSK i , that is, f′ i (0) = TSK i This ensures that the newly allocated private key shares are consistent with the original private key vector:
[0113] f′ i (x) = TSK i +a′1x+a′2x 2 +…+a′ t-1 x t-1
[0114] Among them, a′1,a′2,…,a′ t-1 is from the finite field Z q The randomly selected coefficients in .
[0115] S42. Recalculate the private key share tsk′ for existing participants i : For each existing participant Bob i , Dealer calculates the new private key share tsk′ i , which is based on the new threshold polynomial f′ i (x) split:
[0116] tsk′ i =(f′1(i),f′2(i),…,f′ n (i))
[0117] These new private key shares tsk′ i It will be distributed to all current participants, replacing the original private key shares.
[0118] S43. Calculate the private key share tsk′ for the new participant i :When a new participant joins, Dealer uses the regenerated polynomial f′ i (x) Calculate for each new participant Bob j The private key share tsk′ j :
[0119] tsk′ j =(f′1(j),f′2(j),…,f′ n (j))
[0120] These newly calculated private key shares are distributed to newly joined participants.
[0121] S44. Generate a new threshold verification key tvk′ i :Since the private key vector element TSK i The verification keys of all participants need to be regenerated. Dealer generates a new threshold verification key tvk′ for each participant. i , used to verify the partial decryption results of participants in the future decryption:
[0122]
[0123] These new verification keys are used during the decryption process to verify the correctness of each participant's partial decryption results.
[0124] S45. Output the new private key share and threshold verification key: Dealer outputs the new private key share tsk′ iand threshold verification key tvk′ i Distributed to existing and new participants. These private key shares must be transmitted through a secure channel to prevent interception or tampering. Threshold verification key tvk′ i They can be distributed over public channels as they do not affect the security of the private key shares.
[0125] The above embodiments further illustrate the purpose, technical solutions and advantages of the present invention in detail. It should be understood that the above embodiments are only preferred implementation plans of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made to the present invention within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A quantum secret sharing method based on lattice cryptography and random basis, characterized in that: include: Construct a quantum secret sharing system, which includes a secret distributor (Dealer), a secret reconstructor (TP), and n participants. The quantum secret sharing system includes the following stages: key generation, secret encryption and distribution, quantum secret reconstruction, and key retransmission. The key generation phase includes: the secret distributor Dealer generates the public key TPK and private key share tsk through the TKeyGen algorithm i And the verification key tvk i ; Dealer selects a hash function to calculate the hash value of the secret and sends the hash value to the secret reconstructor TP; The secret encryption and distribution phase includes: Dealer encrypts the secret using the public key to generate ciphertext C; broadcasts the ciphertext to all participants and the secret reconstructor TP; The quantum secret reconstruction phase includes: each participant and the secret reconstructor TP decrypt the ciphertext; obtain the decrypted value of the decryption results of t participants and calculate the shadow corresponding to the decrypted value; use unitary operation to embed the shadow and random number into the information particle; the secret reconstructor TP calculates the sum of all shadows by measuring the extracted information particles, removes the noise term, and obtains the recovered secret; and uses a hash function to verify whether the recovered secret is correct. The key resending phase includes: the system re-determines whether the participants have changed. If the participants have changed, the dealer executes the Tsplit algorithm to generate shares for re-dividing and redistributing the key; the dealer re-divides the elements TSK in the private key vector i To generate a new private key share tsk i , and redistributed to participants.
2. A quantum secret sharing method based on lattice cryptography and random base according to claim 1, characterized in that: The specific steps of the key generation phase include: Step 1: Dealer randomly generates a private key vector TSK = (TSK1, TSK2, ..., TSK n ); Step 2: For each private key element TSK i , Dealer generates a polynomial f of degree t-1 i (x); Step 3: According to the polynomial f i (x) Calculate the participant’s private key share tsk i ; Step 4. Dealer sends each participant’s private key share tsk i Send to the corresponding participants through a secure channel; Step 5: Dealer generates a random matrix B; Step 6: Randomly generate an error vector e from Gaussian distribution; Step 7: Calculate the public key vector b based on the error vector; Step 8: Generate the public key TPK based on the random matrix B and the public key vector b; Step 9: For each participant, generate a threshold verification key tvk i ; Dealer broadcasts the public key TPK to all participants and secretly reconstructs TP; the private key share tsk i and threshold verification key tvk i Sent to the corresponding participants through a secure channel.
3. The quantum secret sharing method based on lattice cryptography and random base according to claim 2, characterized in that: Polynomial f i The expression of (x) is: f i (x)=TSK i +a1x+a2x 2 +…+a t-1 x t-1 Among them, a1, a2, …, a t-1 From the finite field Z q The randomly selected coefficients in .
4. The quantum secret sharing method based on lattice cryptography and random base according to claim 2, characterized in that: Private key share tsk i is the polynomial f i (x) The value of x at x=i.
5. The quantum secret sharing method based on lattice cryptography and random base according to claim 1, characterized in that: The secret encryption and distribution phase includes: Step 1: The dealer generates a key pair (sk, vk) for the ciphertext, where sk is the signature private key and vk is the signature public key; Step 2: Dealer randomly selects two vectors e1, e2 and a scalar e3 from Gaussian distribution; Step 3: Calculate the first part c1 of the ciphertext using the public key matrix A and the random vectors e1 and e2. Step 4: Calculate the second part c2 of the ciphertext using the public key vector b, the random vector e1, the scalar e3, and the secret S. Step 5: Dealer uses the previously generated signature private key sk to sign the generated ciphertext c1, c2 to obtain the signature σ; Step 6: Dealer generates ciphertext C, whose structure is: C = (c1, c2, vk, σ); Dealer broadcasts the generated ciphertext C to all participants and the final secret reconstructor TP.
6. The quantum secret sharing method based on lattice cryptography and random base according to claim 5, characterized in that: The first part of the ciphertext c1 is: The second part of the ciphertext c2 is: Where A is the public key matrix, e1 and e2 are random vectors generated from Gaussian distribution, b is the public key vector, S is the secret to be encrypted, e3 is a scalar, q is a large prime number, and mod is the modulo operation. To round down.
7. The quantum secret sharing method based on lattice cryptography and random base according to claim 1, characterized in that: Decrypting ciphertext involves: Step 1: TP randomly selects t participants from n participants as participants in quantum secret reconstruction; Step 2: TP converts a d-dimensional single particle As information particles; construct a privacy coefficient matrix; construct a decoy particle sequence V with the elements in the privacy coefficient matrix; insert the information particles into the decoy particle sequence to obtain a new sequence V′; TP records the insertion position and V ′ Sent to participants via an ideal quantum channel; Step 3: After all participants receive the particles, they verify the ciphertext signature; each participant Bob i (i=1,2,…,t) takes out its own private key share, performs partial decryption and verification, and generates a partial decryption result μ i .
8. The quantum secret sharing method based on lattice cryptography and random base according to claim 1, characterized in that: The shadow and random number are embedded into the information particle using unitary operation: after participant Bod1 receives the sequence V′, he calculates B1=r1+S1, where r1 is an integer randomly selected from the set {0,1,2,…,d-1}, and S1 is the shadow corresponding to Bob1’s partial decryption value e1; participant Bob1 performs unitary operation on all particles in V′ Bob1 reorders the particles in the sequence to obtain a new sequence V′1. Bob1 records the sorting information v1. Bob1 sends the sequence V′1 to Bob2. Other participants perform the same operation as Bob1 until Bob t A new sequence V′ is obtained t And send it to TP.
9. The quantum secret sharing method based on lattice cryptography and random base according to claim 1, characterized in that: The key resend phase includes: Dealer generates a TSK for each private key vector element i Regenerate a new threshold polynomial f′ of degree t-1 i (x), and ensure that the value of the polynomial at 0 is equal to the private key vector element TSK i ; For each existing participant Bob i , Dealer calculates the new private key share tsk′ i ; When a new participant joins, Dealer uses the regenerated polynomial f′ i (x) Calculate for each new participant Bob j The private key share tsk′ j ; Dealer generates a new threshold verification key tvk′ for each participant i , used to verify the partial decryption results of participants in the future; Dealer will use the new private key share tsk′ i and threshold verification keys tvk′i are distributed to existing and newly joined participants.
Citation Information
Patent Citations
Secret key sharing method based on identity-based encryption
CN102064946A
Quantum threshold secret sharing method and system based on Lagrangian unitary operator
CN110266489A