Methods and systems for quantum key distribution and quantum direct communication
Through improved quantum key distribution and quantum direct communication schemes, combined with masked capacity-enhancing coding processing, direct information transmission and key distribution in quantum channels are realized, solving the problems of high channel loss and system complexity in existing technologies, improving communication distance and speed, and having the ability to perceive eavesdropping.
Patent Information
- Application Number
- CN202411930172.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2024-11-20
- Filing Date
- 2024-12-25
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2044-12-25
AI Technical Summary
Existing quantum key distribution protocols are mainly used to negotiate secure random numbers as keys, and cannot directly transmit information in quantum channels. Quantum direct communication requires round-trip or multiple transmissions of quantum states, resulting in high channel loss and increased system complexity.
The common single-transmitter and single-receiver, dual-path, dual-transmitter joint measurement and entanglement QKD protocols are used for quantum direct communication at the same time as quantum key distribution. The channel loss is reduced through masked capacity coding processing, and secret messages are directly transmitted in the quantum channel to achieve key reuse.
It reduces the channel loss and system complexity of quantum direct communication, improves the communication distance and rate, realizes the reuse of keys and the ability to detect eavesdropping, and breaks through the limitation of one-time one-key in classical encryption.
Smart Images

Figure CN119966612B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of quantum communication technology, and in particular to a method and system for quantum key distribution and quantum direct communication. Background Art
[0002] Quantum communication is a technology that uses the principles of quantum mechanics to complete information transmission through quantum states, and it has a high degree of security. With the rapid development of quantum computing, the security of asymmetric cryptography based on complex mathematical problems is facing challenges. Research on quantum communication has received widespread attention and has developed rapidly, becoming a relatively mature direction in the field of quantum information and will play an important role in the next generation of secure communications. Quantum communication is mainly divided into quantum key distribution (QKD), quantum direct communication (QSDC), quantum secret sharing, and quantum teleportation. Quantum direct communication was proposed in 2000 and has a history of more than 20 years. Its development has gone through four stages. (1) From 2000 to 2005, basic concepts and theories were established. During this stage, typical quantum direct communication protocols such as efficient protocols, two-step protocols, DL04 protocols, and high-dimensional protocols were proposed. (2) From 2006 to 2015, the stage of protocol development and application exploration was established. A large number of theoretical protocols were proposed, and the possible uses of quantum direct communication were widely explored. (3) 2016-2019: Principle experimental verification and prototype development phase. During this phase, the single-photon-based quantum direct communication scheme and the entanglement-based quantum direct communication protocol were experimentally verified. (4) 2020 to date: Product development and practical application have been promoted. During this phase, the typical performance of the quantum direct communication prototype is 10km@4kbps, which can realize the real-time and secure transmission of text, pictures, and voice files, and quantum direct communication of 100km can be achieved using low-loss optical fiber. Summary of the Invention
[0003] The inventors found that most of the existing QKD protocols, single-transmitter single-receiver protocols, two-way protocols, two-transmitter joint measurement protocols, and entanglement protocols are used to negotiate secure random numbers as keys, that is, to complete "quantum key distribution", and cannot directly transmit information in the quantum channel; quantum direct communication protocols can directly transmit information in the quantum channel, but require round-trip or multiple transmissions of quantum states.
[0004] To address the above issues, this application provides a quantum key distribution and quantum direct communication solution. On the one hand, the common single-transmitter single-receiver QKD protocol, dual-channel QKD protocol, dual-transmitter joint measurement QKD protocol, and entangled QKD protocol are combined with quantum direct communication while performing quantum key distribution, so that it can not only complete quantum key distribution but also directly transmit secret messages in the quantum channel. On the other hand, this application eliminates the need for round-trip transmission of quantum states in quantum direct communication, reducing the channel loss and system complexity of quantum direct communication and significantly improving the communication distance and communication rate of quantum direct communication. In addition, this application uses quantum states to simultaneously transmit information and negotiate keys. Both processes have the ability to detect eavesdropping, and the key masked by the random number can be reused, breaking through the limitation of classical encryption's one-time one-pad.
[0005] According to a first aspect of the present application, a method for quantum key distribution and quantum direct communication is provided, which is applied to a sender and is characterized by comprising:
[0006] Process the plaintext information to be sent and obtain the codeword;
[0007] Encrypting the codeword using an encryption key in a key pool to obtain a ciphertext;
[0008] Performing mask-encoding on the ciphertext to obtain a mask-encoded codeword;
[0009] Processing the masked up-encoded codeword using a quantum key distribution protocol to obtain processing result information, wherein the processing result information enables a receiver to obtain a measurement result based on the quantum key distribution protocol;
[0010] Performing QKD post-processing according to the quantum key distribution protocol to obtain a result of the QKD post-processing; and
[0011] A new key is generated according to the result of the QKD post-processing, and the new key is stored in the key pool.
[0012] According to a second aspect of the present application, a method for quantum key distribution and quantum direct communication is provided, which is applied to a receiving party and is characterized by comprising:
[0013] Obtain measurement results according to the currently adopted quantum key distribution protocol;
[0014] Obtaining a codeword corresponding to the plaintext information sent by the sender through the measurement result;
[0015] Performing QKD post-processing according to the measurement result to obtain a QKD post-processing result;
[0016] generating a new key according to the result of the QKD post-processing, and storing the new key in the key pool of the receiver; and
[0017] The codeword is processed to obtain plaintext information.
[0018] According to a third aspect of the present application, a system for quantum key distribution and quantum direct communication is provided, characterized in that it includes:
[0019] A sending device, configured to execute the method according to the first aspect; and
[0020] The receiving device is used to execute the method as described in the second aspect.
[0021] According to a fourth aspect of the present application, an electronic device is provided, including:
[0022] processor; and
[0023] A memory stores computer instructions, which, when executed by the processor, enable the processor to execute the methods described in the first and second aspects.
[0024] According to a fifth aspect of the present application, a non-transitory computer storage medium is provided, storing a computer program. When the computer program is executed by multiple processors, the processors execute the methods described in the first and second aspects.
[0025] According to the method and system for quantum key distribution and quantum direct communication provided in this application, first, quantum direct communication does not require round-trip transmission of quantum states, which reduces channel loss and can significantly improve communication distance and communication rate; second, this scheme does not require quantum state block transmission to achieve quantum direct communication, so there is no need to use quantum storage, which improves the practicality of quantum direct communication; third, this scheme simultaneously realizes key negotiation and information transmission, improves the dual-channel secure communication model into a single-channel model, and has the ability to perceive eavesdropping; finally, this scheme can improve the common quantum key distribution protocol into a compatible quantum key distribution protocol and quantum direct communication protocol, and then utilize various quantum information resources such as entangled states and dual-field quantum states to achieve both key distribution and information transmission in the quantum channel. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without exceeding the scope of protection required by this application.
[0027] Figure 1 This is a schematic diagram of a quantum key distribution and quantum direct communication system based on a single-transmitter-single-receiver QKD protocol according to an embodiment of the present application.
[0028] Figure 2 This is a schematic diagram of a quantum key distribution and quantum direct communication system based on a two-way QKD protocol according to an embodiment of the present application.
[0029] Figure 3 This is a schematic diagram of a quantum key distribution and quantum direct communication system of a dual-transmission joint measurement QKD protocol according to an embodiment of the present application.
[0030] Figure 4 This is a schematic diagram of a quantum key distribution and quantum direct communication system based on an entangled QKD protocol according to an embodiment of the present application.
[0031] Figure 5 This is a flowchart of a method for quantum key distribution and quantum direct communication performed by a sender according to an embodiment of the present application.
[0032] Figure 6 This is a flowchart of a method for quantum key distribution and quantum direct communication performed by a sender according to another embodiment of the present application.
[0033] Figure 7 This is a flowchart of a method for quantum key distribution and quantum direct communication performed by a sender according to another embodiment of the present application.
[0034] Figure 8 This is a flowchart of a method for quantum key distribution and quantum direct communication performed by a receiver according to an embodiment of the present application.
[0035] Figure 9 This is a flowchart of a method for quantum key distribution and quantum direct communication performed by a receiver according to another embodiment of the present application.
[0036] Figure 10 This is a structural diagram of an electronic device provided by this application. DETAILED DESCRIPTION
[0037] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts are within the scope of protection of this application.
[0038] Figure 1This is a schematic diagram of a quantum key distribution and quantum direct communication system based on a single-transmitter, single-receiver QKD protocol according to one embodiment of the present application. A single-transmitter, single-receiver QKD protocol involves a sender preparing a quantum state, sending it to a receiver, and then measuring the quantum state to complete quantum key distribution. Typical protocols include the BB84 protocol, the B92 protocol, the six-state protocol, the SARG04 protocol, the COW protocol, the DPS protocol, the RRDPS protocol, the three-state protocol, the GG02 protocol, and the compressed state protocol.
[0039] like Figure 1 As shown, the quantum key distribution and quantum direct communication schemes may specifically include the following steps.
[0040] (1) The sender performs error correction coding on the plaintext m to be sent to obtain a codeword u. According to some embodiments, the error correction code includes an LDPC code, a Polar code, etc.
[0041] (2) The sender performs spread spectrum processing on the codeword u to obtain the codeword v.
[0042] (3) The sender extracts key k from the key pool and encrypts the codeword v, thereby obtaining the ciphertext s, i.e., s = v ⊕ k. It will be appreciated by those skilled in the art that if there are not enough keys in the key pool to encrypt the message, the system first runs QKD to generate the sufficient keys to fill the key pool.
[0043] (4) The sender locally generates a random number R of the same length as s, and XOR-encrypts s with R to obtain the codeword c to be transmitted, for example, c = s ⊕ R. This step is called masking capacity increasing (INCUM, increasing the channel capacity using masking) encoding processing.
[0044] (5) Based on the specific single-transmitter-single-receiver QKD protocol used, for example, including the BB84 protocol, SARG04 protocol, COW protocol, DPS protocol, RRDPS protocol, three-state protocol, GG02 protocol, compressed state protocol, etc., the sender prepares the quantum state according to the codeword c and transmits the prepared quantum state to the receiver through the quantum channel.
[0045] (6) The receiver measures the quantum state based on the specific single-transmitter-single-receiver QKD protocol rules used.
[0046] (7) The communicating parties enter the QKD post-processing. The QKD post-processing process includes screening, error estimation, error correction and privacy amplification. The two parties first complete the screening and complete the sharing of the naked code. For example, the sender determines a new naked code c1 based on the prior codeword c, the basis vector information of the prepared quantum state and the measurement basis vector information published by the receiver. At the same time, the receiver determines the naked code c1' based on the measurement basis vector information of its own measured quantum state, the measurement result c' and the basis vector information of the prepared quantum state published by the sender. Compared with c1, c1' has a certain error. If the error rate is lower than a certain threshold, the communicating parties can add a new key K to their respective key pools through the results of QKD post-processing (for example, it can be reflected as a random number), thereby realizing key distribution.
[0047] (8) The receiver announces the timing positions corresponding to c1', which are called valid detection bits.
[0048] (9) The sender publishes the local random number r used for encryption at these valid detection bits. Due to system loss, the receiver can only receive part of the quantum state signal, so r comes from R. Except for the valid detection bits, the other time positions are ineffective detection bits. The sender returns the encryption key k2 used at the time positions of the ineffective detection bits to the key pool for use in subsequent communication processes, that is, the key corresponding to the ineffective detection bits can be reused. This is because the above encryption key is masked by the local random number, and these local random numbers are never published.
[0049] (10) The receiver performs INCUM decoding on c1' to obtain the ciphertext codeword s', that is, s'=c1'⊕r.
[0050] (11) The receiver decrypts s' to obtain v', that is,
[0051] (12) The receiver despreads v' to obtain u'.
[0052] (13) The receiver performs error correction decoding on u' to obtain the plaintext m'.
[0053] Figure 2 This is a schematic diagram of a quantum key distribution and quantum direct communication system based on a two-way QKD protocol, according to one embodiment of the present application. A two-way QKD protocol involves the receiver generating a signal and transmitting it to the sender. The sender modulates the signal and transmits it to the receiver, which then measures the signal, ultimately completing quantum key distribution. Typical protocols include the Ping-Pong protocol, the LM05 protocol, and the continuous variable two-way protocol.
[0054] like Figure 2 As shown, the quantum key distribution and quantum direct communication schemes may specifically include the following steps.
[0055] (1) The receiver prepares a quantum state and sends it to the sender through a quantum channel;
[0056] (2) The sender performs error correction coding on the plaintext m to be sent to obtain a codeword u. According to one embodiment, the error correction code includes an LDPC code, a Polar code, and the like.
[0057] (3) The sender performs spread spectrum processing on the codeword u to obtain the codeword v.
[0058] (4) The sender takes the key k from the key pool and encrypts the codeword v to obtain the ciphertext s, that is, It will be understood by those skilled in the art that if there are not enough keys in the key pool to complete the encryption of the information, the system will first run QKD to generate enough keys to fill the key pool.
[0059] (5) The sender generates a random number R with the same length as s locally, and XOR-encrypts s and R to obtain the codeword c to be transmitted, that is, This step is called masked capacity increasing (INCUM, increasing the channel capacity using masking) encoding process.
[0060] (6) Based on the specific two-way QKD protocol used, including the ping-pong protocol, the LM05 protocol, the continuous variable two-way protocol, etc., the sender modulates the quantum state sent by the receiver to the sender according to the codeword c, and transmits the modulated quantum state back to the receiver.
[0061] (7) Based on the specific two-way QKD protocol rules used, the receiver measures the quantum state and obtains a measurement result.
[0062] (8) Both communicating parties perform QKD post-processing. First, the screening is completed, and both communicating parties share the bare code. Because the quantum state is prepared by the receiver, this type of protocol does not require a basis step. The receiver compares the measurement result with the quantum state originally sent by the receiver and receives the information c1'. The reason why it is marked with c1' is because of channel loss. c1' only corresponds to part of the codeword c1 in c, and c1' contains a certain proportion of bit errors compared to c1.
[0063] (9) The receiver announces the timing positions corresponding to c1'. These timing positions are called valid detection bits.
[0064] (10) The sender determines the corresponding c1 based on these time sequence positions. The sender and receiver enter the subsequent QKD post-processing based on c1 and c1' respectively. The process includes error estimation, error correction, and privacy amplification. If the error rate is lower than a certain threshold, the communicating parties can add a new key K to their respective key pools through QKD post-processing, thereby achieving key distribution.
[0065] (11) The sender publishes the local random number r used for encryption at the valid detection position. Due to system loss, the receiver can only receive part of the quantum state signal, so it comes from R. The sender returns the encryption key k2 used at the time position without the detection signal to the key pool for use in subsequent communication processes.
[0066] (12) The receiver performs INCUM decoding on c1' to obtain the ciphertext codeword s', that is, s'=c1'⊕r.
[0067] (13) The receiver decrypts s' and obtains v', that is, v'=s'⊕k1.
[0068] (14) The receiver despreads v' to obtain u'.
[0069] (15) The receiver performs error correction decoding on u' to obtain the plaintext m'.
[0070] Figure 3 This figure is a schematic diagram of a quantum key distribution and quantum direct communication system using a dual-transmit joint measurement QKD protocol according to one embodiment of the present application. The dual-transmit joint measurement QKD protocol involves a sender and receiver preparing quantum state signals, sending them to an untrusted third party for joint measurement, and publishing the measurement results, thereby completing quantum key distribution. This protocol is resistant to eavesdropper attacks against actual detectors. Typical protocols include MDIQKD, dual-field QKD, transmit-or-without-transmit QKD, and pattern matching QKD.
[0071] like Figure 3 As shown, the quantum key distribution and quantum direct communication schemes may specifically include the following steps.
[0072] (1) The sender performs error correction coding on the plaintext m to be sent to obtain a codeword u. According to one embodiment, the error correction code includes an LDPC code, a Polar code, etc.
[0073] (2) The sender performs spread spectrum processing on the codeword u to obtain the codeword v.
[0074] (3) The sender extracts key k from the key pool and encrypts the codeword v, thereby obtaining the ciphertext s, i.e., s = v ⊕ k. It will be appreciated by those skilled in the art that if there are not enough keys in the key pool to encrypt the message, the system first runs QKD to generate the sufficient keys to fill the key pool.
[0075] (4) The sender locally generates a random number R of the same length as s, and XOR-encrypts s and R to obtain the codeword c to be transmitted, that is, c = s ⊕ R. This step is called masked capacity-enhancing coding processing.
[0076] (5) Based on the specific dual-transmission joint measurement QKD protocol used, including the MDIQKD protocol, the dual-field QKD protocol, the transmit or no transmit QKD protocol, the pattern matching QKD protocol, etc., the sender prepares the quantum state according to the codeword c, and the receiver prepares the quantum state according to a randomly generated string of random numbers c' of the same length as c. In the process of preparing the quantum state, the receiver ensures that the quantum state encoding dimension polarization or phase is the same as that of the sender, and uses the same type of quantum state with the same length. Both parties send their prepared quantum states to an untrusted third party.
[0077] (6) An untrusted third party performs a joint measurement on the received quantum state and publishes the measurement results and the corresponding time positions of the measurement results.
[0078] (7) The communicating parties perform QKD post-processing based on the information published by the untrusted third party, the information of their respective quantum state preparation basis vectors, and the codewords sent. First, the screening is completed, and the communicating parties share the bare code. For example, the sender determines a bare code c1 based on the prior codeword c, the information published by the untrusted third party, and the preparation basis vector information published by the receiver. The receiver determines the bare code c1' based on the prior random number c', the information published by the untrusted third party, and the time sequence position published by the sender that is the same as the preparation basis vector. Compared with c1, c1' has a certain bit error.
[0079] (8) The sender and receiver perform subsequent QKD post-processing steps based on c1 and c1', respectively. The process includes error estimation, error correction, and privacy amplification. If the error rate is lower than a certain threshold, the communicating parties can add a new key K to their respective key pools through QKD post-processing, thereby achieving key distribution.
[0080] (9) The receiver publishes the timing positions corresponding to c1'. These positions are called valid detection positions, and the sender publishes the local encrypted random number r at these timing positions. The sender returns the encryption key k2 used for the non-valid detection positions to the key pool for use in subsequent communication processes.
[0081] (10) The receiver performs INCUM decoding on c1' to obtain the ciphertext codeword s', that is,
[0082] (11) The receiver decrypts s' to obtain v', that is,
[0083] (12) The receiver despreads v' to obtain u'.
[0084] (13) The receiver performs error correction decoding on u' to obtain the plaintext m'.
[0085] Figure 4This figure is a schematic diagram of a quantum key distribution and quantum direct communication system using an entangled QKD protocol according to one embodiment of the present application. Entangled QKD protocols utilize entangled states to implement quantum key distribution, including the E91 protocol, the BBM92 protocol, the DI protocol, and others.
[0086] like Figure 4 As shown, the quantum key distribution and quantum direct communication schemes may specifically include the following steps.
[0087] (1) The communicating parties establish quantum entanglement. The specific methods include but are not limited to: a third party distributes entangled pairs to the sender and the receiver, or the sender sends one of the prepared entangled photons to the receiver, or the receiver sends one of the prepared entangled photons to the sender.
[0088] (2) The sender performs error correction coding on the plaintext m to be sent to obtain a codeword u. According to one embodiment, the error correction code includes an LDPC code, a Polar code, and the like.
[0089] (3) The sender performs spread spectrum processing on the codeword u to obtain the codeword v.
[0090] (4) The sender takes the key k from the key pool and encrypts the codeword v to obtain the ciphertext s, that is, It will be understood by those skilled in the art that if there are not enough keys in the key pool to complete the encryption of the information, the system will first run QKD to generate enough keys to fill the key pool.
[0091] (5) The sender generates a random number R with the same length as s locally, and XOR-encrypts s and R to obtain the codeword c to be transmitted, that is, This step is called mask upscaling encoding.
[0092] (6) Based on the specific entangled QKD protocol used, including the E91 protocol, the BBM92 protocol, the DI protocol, etc., the sender and the receiver each perform random measurements on the entangled particles shared in their hands. For example, after completing the measurement, the sender and the receiver obtain the results cA and cB respectively. The codewords in the sender's c are compared with the codewords in cA one by one in order, and the results in cA that are the same as c and their time sequence positions are retained in order. The sender publishes these time sequence positions, and the receiver retains the results at the corresponding time sequence positions. The sender and the receiver thus obtain c and c' respectively. Among them, c comes from cA and c' comes from cB.
[0093] (7) The sender and receiver perform QKD post-processing based on c and c' respectively. The QKD post-processing process includes screening, error estimation, error correction and privacy amplification. First, both parties complete the naked code screening. For example, the receiver publishes the measurement basis vector, and the sender retains the result at the same time position in c as the receiver's measurement basis vector, and obtains c1. The sender informs the receiver of these time positions, and the receiver retains the result c1'. The communicating parties randomly sample a small subset of c1 and c1' to complete the error estimation. If the error rate is lower than a certain threshold, the communicating parties can add a new key K to their respective key pools through QKD post-processing, thereby realizing key distribution.
[0094] (8) The receiver copies a copy of the filtered bare code (corresponding to the result c1' after QKD post-processing filtering) for recovery of the transmitted information;
[0095] (9) The receiver publishes the local encrypted random number r at the time position corresponding to c1', where r comes from R. This position is called a valid detection bit. The sender returns the encryption key k2 used for the time position corresponding to the non-valid detection bit to the key pool for use in subsequent communication processes. In other words, the sender returns the encryption key k2 used for the time position corresponding to the non-valid detection bit to the key pool for use in subsequent communication processes.
[0096] (10) The receiver performs INCUM decoding on c1' to obtain the ciphertext codeword s', that is, s'=c1'⊕r.
[0097] (11) The receiver decrypts s' to obtain v', that is,
[0098] (12) The receiver despreads v' to obtain u'.
[0099] (13) The receiver performs error correction decoding on u' to obtain the plaintext m'.
[0100] exist Figures 1 to 4 Based on the illustrated scheme, according to one aspect of the present application, a method of quantum key distribution and quantum direct communication is provided. Figure 5 FIG. 1 is a flow chart of a method for quantum key distribution and quantum direct communication performed by a sender according to an embodiment of the present application. Figure 5 As shown, the method includes the following steps S501 to S506.
[0101] In step S501, the plaintext information to be sent is processed to obtain a codeword.
[0102] according to Figures 1 to 4 In the embodiment shown, the sender performs error correction coding on the plaintext m to be sent to obtain a codeword u. The sender performs spread spectrum processing on the codeword u to obtain a codeword v.
[0103] Thus, step S501 may specifically include:
[0104] performing error correction coding on the plaintext information to be sent to obtain a first codeword; and
[0105] The first codeword is spread spectrum-spread to obtain a second codeword.
[0106] In step S502, the codeword is encrypted using an encryption key in a key pool to obtain a ciphertext.
[0107] according to Figures 1 to 4 In the embodiment shown, the sender takes the key k from the key pool to encrypt the codeword v, thereby obtaining the ciphertext s, that is, It will be understood by those skilled in the art that if there are not enough keys in the key pool to complete the encryption of the information, the system will first run QKD to generate enough keys to fill the key pool.
[0108] In step S503, the ciphertext is subjected to mask-enhanced encoding to obtain a mask-enhanced encoded codeword.
[0109] according to Figures 1 to 4 In the embodiment shown, the sender generates a random number R of the same length as s locally, and XOR-encrypts s and R to obtain the codeword c to be transmitted, that is, This step is called mask upscaling encoding.
[0110] On the one hand, masked capacity expansion processing can improve the security of information transmission. On the other hand, the encryption key masked by the local random number and not published by the local random number can be reused, breaking through the limitation of one-time one-key in classic encryption.
[0111] In step S504, the codeword after the masked capacity-encoded code is processed using a quantum key distribution protocol to obtain processing result information, wherein the processing result information enables a receiver to obtain a measurement result based on the quantum key distribution protocol.
[0112] according to Figure 1 In the embodiment shown, the sender prepares the quantum state according to the codeword c based on the specific single-transmitter-single-receiver QKD protocol used, for example, including the BB84 protocol, SARG04 protocol, COW protocol, DPS protocol, RRDPS protocol, three-state protocol, GG02 protocol, compressed state protocol, etc., and transmits the prepared quantum state to the receiver through the quantum channel. Figure 2In the embodiment shown, the sender modulates the quantum state sent by the receiver to the sender according to the codeword c based on the specific two-way QKD protocol used, including the ping-pong protocol, LM05 protocol, continuous variable two-way protocol, etc., and transmits the modulated quantum state back to the receiver. Figure 3 The embodiment shown is based on the specific dual-transmission joint measurement QKD protocol used, including the MDIQKD protocol, the dual-field QKD protocol, the transmit or non-transmit QKD protocol, the pattern matching QKD protocol, etc. The sender prepares the quantum state according to the codeword c, and the receiver prepares the quantum state according to a randomly generated string of random numbers c' of the same length as c. In the process of preparing the quantum state, the receiver ensures that the quantum state encoding dimension polarization or phase is the same as that of the sender, and uses the same type of quantum state with the same length. Both parties send the quantum state they prepare to an untrusted third party. According to Figure 4 In the illustrated embodiment, based on the specific entangled QKD protocol used, including the E91 protocol, the BBM92 protocol, the DI protocol, and the like, the sender and the receiver each perform random measurements on the entangled particles shared in their hands. For example, after completing the measurement, the sender and the receiver obtain the results cA and cB, respectively. The codewords in the sender's c are compared one by one with the codewords in cA in order, and the results in cA that are identical to c and their time sequence positions are retained in order. The sender publishes these time sequence positions, and the receiver retains the results at the corresponding time sequence positions, thereby obtaining c and c', respectively. Among them, c comes from cA and c' comes from cB.
[0113] according to Figure 1 In the embodiment shown, the sender transmits the prepared quantum state to the receiver through a quantum channel, and the receiver measures the quantum state according to the single-transmit-single-receive QKD protocol to obtain the measurement result. Figure 2 In the embodiment shown, the sender transmits the modulated quantum state back to the receiver through the quantum channel, and the receiver measures the quantum state according to the two-way QKD protocol to obtain the measurement result. Figure 3 In the embodiment shown, the sender and the receiver send their respective prepared quantum states to an untrusted third party, which then performs a joint measurement on the received quantum states and publishes the measurement results and the corresponding time sequence positions. Figure 4 In the embodiment shown, based on the entanglement QKD protocol, the sender and the receiver randomly measure the particles in their hands to obtain measurement results. The sender determines c and the receiver determines c' based on c and c' based on their respective measurement results.
[0114] In step S505, QKD post-processing is performed according to the quantum key distribution protocol to obtain a result of the QKD post-processing;
[0115] In step S506, a new key is generated according to the result of the QKD post-processing, and the new key is stored in the key pool.
[0116] exist Figure 1 In the embodiment shown, the communicating parties enter the QKD post-processing. Both parties first complete the screening and complete the sharing of the naked code. For example, the sender determines a new naked code c1 based on the prior codeword c, the basis vector information for preparing the quantum state, and the measurement basis vector information published by the receiver. At the same time, the receiver determines the naked code c1' based on the measurement basis vector information of its own measured quantum state, the measurement result c', and the basis vector information for preparing the quantum state published by the sender. c1 comes from c, and c1' comes from c'. Compared with c1, c1' has certain bit errors. If the bit error rate is lower than a certain threshold, the communicating parties can add a new key K to their respective key pools through the results of QKD post-processing (for example, it can be reflected as a random number). In Figure 2 In the implementation shown, the sender and receiver enter QKD post-processing based on c and c1' respectively, which includes error estimation, error correction, and privacy amplification. If the error rate is lower than a certain threshold, the communicating parties can add a new key K to their respective key pools through QKD post-processing. Figure 3 In the implementation shown, the sender and receiver perform QKD post-processing based on c and c' respectively, which includes screening, error estimation, error correction, and privacy amplification. If the error rate is lower than a certain threshold, the communicating parties can add a new key K to their respective key pools through QKD post-processing. Figure 4 In the illustrated implementation, the sender and receiver perform QKD post-processing based on c and c', respectively. This QKD post-processing process includes screening, error estimation, error correction, and privacy amplification. If the bit error rate falls below a certain threshold, both communicating parties can add a new key, K, to their respective key pools through QKD post-processing.
[0117] Figure 6 1 is a flow chart of a method for quantum key distribution and quantum direct communication performed by a sender according to another embodiment of the present application. Figure 5 compared to, Figure 6 The method steps S601 to S606 are Figure 5 Steps S501 to S506 are the same except that: Figure 6 The method shown further includes step S607.
[0118] In step S607, information on the random number used in the masked upscaling coding process at the corresponding time sequence position is sent to the receiving party.
[0119] exist Figure 1 and 2In the embodiment shown, the receiver publishes the timing positions of valid detection bits; the sender publishes the local random number r used for encryption at these timing positions. Due to system loss, the receiver can only receive part of the quantum state signal, so r comes from R. The sender returns the encryption key k2 used at the timing positions of the invalid detection bits to the key pool for use in subsequent communication processes, that is, the key corresponding to the invalid detection bits can be reused. Figure 3 In the illustrated embodiment, an untrusted third party performs a joint measurement of the received quantum state and publishes the measurement result and the corresponding time position. The sender publishes the local encrypted random number r at the time position of the valid detection bit, where r comes from R. The sender returns the encryption key k2 used for the invalid detection bit to the key pool for use in subsequent communication processes.
[0120] Thus, step S607 may specifically include:
[0121] Obtaining the timing position corresponding to the published valid detection bit; and
[0122] Information on the random number used in the masked upscaling coding process at the timing position is sent to the receiving party.
[0123] exist Figure 4 In the embodiment shown, the sender and receiver each perform random measurements on the entangled particles they share. For example, after completing the measurement, the sender and receiver obtain the results cA and cB, respectively. The codewords in the sender's c are compared with the codewords in cA one by one in order, and the results and their time positions in cA that are the same as c are retained in order. The sender publishes these time positions, and the receiver retains the results at the corresponding time positions, so that the sender and receiver obtain c and c', respectively. Among them, c comes from cA and c' comes from cB. The sender publishes the local encrypted random number r at the time position corresponding to the valid detection bit, and r comes from R. The sender returns the encryption key k2 used for the time position corresponding to the invalid detection bit to the key pool for use in subsequent communication processes.
[0124] Thus, step S607 may further specifically include:
[0125] Measuring the sender's particle using the quantum key distribution protocol to obtain a first measurement result;
[0126] Acquire a first time sequence position of the first measurement result;
[0127] Acquire a second time sequence position having a second measurement result published by the receiver;
[0128] Determining, based on the first timing position and the second timing position, a timing position at which both the sender and the receiver have measurement results and correspond to each other; and
[0129] Information on the random number used in the mask capacity expansion process at the timing position is sent to the receiving party.
[0130] Figure 7 1 is a flow chart of a method for quantum key distribution and quantum direct communication performed by a sender according to another embodiment of the present application. Figure 6 compared to, Figure 7 The method steps S701 to S707 are similar to Figure 6 Steps S601 to S607 are the same except that: Figure 7 The method shown further includes step S708.
[0131] In step S708, among the encryption keys used to encrypt the codeword, the encryption key that does not correspond to the time sequence position is returned to the key pool.
[0132] exist Figure 1 Figure 2 In the embodiment shown, the sender returns the encryption key k2 used for the timing position corresponding to the invalid detection bit to the key pool for use in subsequent communication processes. Figure 3 In the embodiment shown, the sender returns the encryption key k2 used for the timing position corresponding to the invalid detection bit to the key pool for use in subsequent communication processes. Figure 4 In the illustrated embodiment, the sender returns the encryption key k2 used for the timing position corresponding to the ineffective detection bit to the key pool for use in subsequent communication processes.
[0133] Figure 8 FIG. 1 is a flow chart of a method for quantum key distribution and quantum direct communication performed by a receiver according to an embodiment of the present application. Figure 8 As shown, the method includes steps S801 to S805.
[0134] In step S801, a measurement result is obtained according to the currently adopted quantum key distribution protocol.
[0135] exist Figure 1 In the embodiment shown, the sender prepares the quantum state according to the codeword c and transmits the prepared quantum state to the receiver through the quantum channel; the receiver measures the quantum state based on the specific single-transmitter-single-receiver QKD protocol rules and obtains the measurement result. Figure 2 In the embodiment shown, the sender modulates the quantum state sent by the receiver to the sender according to the codeword c, and transmits the modulated quantum state back to the receiver; based on the specific two-way QKD protocol rules used, the receiver measures the quantum state and obtains the measurement result. Figure 3In the embodiment shown, the untrusted third party performs a joint measurement on the received quantum state and publishes the measurement result and the time sequence position corresponding to the measurement result, and the receiver obtains the measurement result. Figure 4 In the embodiment shown, the receiver measures the particles in his hand based on the specific entangled QKD protocol used to obtain the measurement results.
[0136] Thus, step S801 may specifically include:
[0137] Measuring the quantum state generated by the sender according to a single-transmitter-single-receiver quantum key distribution protocol to obtain the measurement result; or
[0138] Measuring the quantum state modulated by the sender according to a two-way quantum key distribution protocol to obtain the measurement result; or
[0139] receiving, according to a dual-transmission joint measurement quantum key distribution protocol, the measurement results obtained by a third party measuring the quantum states from the sender and the receiver; or
[0140] According to an entangled quantum key distribution protocol, the particle of the receiver is measured based on the measurement result of the sender to obtain the measurement result.
[0141] In step S802, a codeword corresponding to the plaintext information sent by the sender is obtained through the measurement result.
[0142] exist Figure 1 In the embodiment shown, the receiver performs screening based on the measurement results to obtain the codeword c1'. Figure 2 In the embodiment shown, the receiver compares the measurement result with the quantum state originally sent by the receiver to obtain the codeword c1'. Figure 3 In the embodiment shown, the receiver performs screening based on the measurement results published by the untrusted third party to obtain the codeword c1'. Figure 4 In the illustrated embodiment, the receiver measures the particles in their possession and screens them with the sender to obtain codeword c1'. Codeword c1' corresponds to the plaintext information sent by the sender. The plaintext information sent by the sender undergoes a series of processing (including error correction coding, spread spectrum, encryption, etc.) to obtain codeword c. Compared with c1, c1' contains certain errors, and c1 is derived from c.
[0143] In step S803, QKD post-processing is performed according to the measurement result to obtain a QKD post-processing result;
[0144] In step S804, a new key is generated according to the result of the QKD post-processing, and the new key is stored in the key pool of the receiver.
[0145] exist Figure 1 In the embodiment shown, the communicating parties enter QKD post-processing. The QKD post-processing process includes screening, error estimation, error correction, and privacy amplification. The receiver performs QKD post-processing based on the measurement results. The sender determines a new codeword c1 based on the prior codeword c and the measurement basis vector published by the receiver. The receiver will retain the naked code c1' corresponding to c1. If the bit error rate is lower than a certain threshold, the communicating parties can add a new key K to their respective key pools through the results of QKD post-processing (for example, it can be reflected as a random number). Figure 2 In the implementation shown, the sender and receiver enter QKD post-processing based on c and c1' respectively, which includes error estimation, error correction, and privacy amplification. If the error rate is lower than a certain threshold, the communicating parties can add a new key K to their respective key pools through QKD post-processing. Figure 3 In the implementation shown, the sender and receiver perform QKD post-processing based on c and c' respectively, which includes screening, error estimation, error correction, and privacy amplification. If the error rate is lower than a certain threshold, the communicating parties can add a new key K to their respective key pools through QKD post-processing. Figure 4 In the illustrated implementation, the sender and receiver perform QKD post-processing based on c and c', respectively. This QKD post-processing process includes screening, error estimation, error correction, and privacy amplification. If the bit error rate falls below a certain threshold, both communicating parties can add a new key, K, to their respective key pools through QKD post-processing.
[0146] In step S805, the codeword is processed to obtain plaintext information.
[0147] Figure 9 1 is a flow chart of a method for quantum key distribution and quantum direct communication performed by a receiver according to another embodiment of the present application. Figure 8 compared to, Figure 9 The method steps S901 to S905 are similar to Figure 8 Steps S801 to S805 are the same except that: Figure 9 The illustrated method also includes step 906 .
[0148] In step S906, a local encrypted random number corresponding to the timing position of the valid detection bit in the measurement result is received from the sender.
[0149] exist Figure 1 and 2 In the embodiment shown, the receiver publishes the timing positions of the valid detection bits; the sender publishes the local random numbers r used for encryption at these timing positions. Figure 3In the embodiment shown, an untrusted third party performs a joint measurement on the received quantum state and publishes the measurement result and the corresponding time position of the measurement result; the sender publishes the local encrypted random number r at the time position of the valid detection bit based on the time position corresponding to the measurement result published by the untrusted third party and the basis comparison result between the sender and the receiver. Figure 4 In the illustrated embodiment, the communicating parties complete screening based on the specific entangled QKD protocol and codeword c, obtaining c1'. The receiver publishes the time position corresponding to c1', and the sender publishes the locally encrypted random number r at the corresponding time position. Due to system losses, the communicating parties can only detect a portion of the entangled state simultaneously, so r is derived from R.
[0150] exist Figures 1 to 4 In the embodiment shown, first, the receiver performs INCUM decoding on c1' to obtain the ciphertext codeword s', that is, s'=c1'⊕r; secondly, the receiver decrypts s' to obtain v', that is, Then, the receiver despreads v' to obtain u'. Finally, the receiver performs error correction decoding on u' to obtain the plaintext m'.
[0151] Thus, step S805 or step S905 may specifically include:
[0152] Performing masked capacity-enhancing decoding on the codeword according to the local encrypted random number to obtain a masked capacity-enhancing decoded codeword;
[0153] Decrypting the codeword after the masked capacity-increasing decoding to obtain a decrypted codeword;
[0154] Despreading the decrypted codeword to obtain a despread codeword; and
[0155] Error correction decoding is performed on the despread codeword to obtain plaintext information.
[0156] According to the method and system for quantum key distribution and quantum direct communication provided in this application, first, quantum direct communication does not require round-trip transmission of quantum states, which reduces channel loss and can significantly improve communication distance and communication rate; second, this scheme does not require quantum state block transmission to achieve quantum direct communication, so there is no need to use quantum storage, which improves the practicality of quantum direct communication; third, this scheme simultaneously realizes key negotiation and information transmission, improves the dual-channel secure communication model into a single-channel model, and has the ability to perceive eavesdropping; finally, this scheme can improve the common quantum key distribution protocol into a compatible quantum key distribution protocol and quantum direct communication protocol, and then utilize various quantum information resources such as entangled states and dual-field quantum states to achieve both key distribution and information transmission in the quantum channel.
[0157] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0158] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all optional embodiments, and the actions and modules involved are not necessarily required by this application.
[0159] In the several embodiments provided in this application, it should be understood that the disclosed devices can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical connection or other forms.
[0160] See Figure 10 , Figure 10 An electronic device is provided, comprising a processor and a memory. The memory stores computer instructions, and when the computer instructions are executed by the processor, the processor executes the computer instructions to achieve the following Figures 5 to 9 The method and refinement scheme shown.
[0161] It should be understood that the above-described device embodiments are merely illustrative, and the devices disclosed herein may also be implemented in other ways. For example, the division of units / modules described in the above-described embodiments is merely a logical functional division, and actual implementations may employ alternative divisions. For example, multiple units, modules, or components may be combined or integrated into another system, or some features may be omitted or not implemented.
[0162] In addition, unless otherwise specified, the functional units / modules in the various embodiments of the present invention may be integrated into a single unit / module, each unit / module may exist physically separately, or two or more units / modules may be integrated together. The aforementioned integrated units / modules may be implemented in the form of hardware or software program modules.
[0163] If the integrated unit / module is implemented in hardware, the hardware may be a digital circuit, an analog circuit, or the like. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, and the like. Unless otherwise specified, the processor or chip may be any appropriate hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC. Unless otherwise specified, the on-chip cache, off-chip memory, and storage may be any appropriate magnetic storage medium or magneto-optical storage medium, such as resistive random access memory (RRAM), dynamic random access memory (DRAM), static random access memory (SRAM), enhanced dynamic random access memory (EDRAM), high-bandwidth memory (HBM), hybrid memory cube (HMC), and the like.
[0164] If the integrated unit / module is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a memory, including a number of instructions for enabling a computer electronic device (which can be a personal computer, a server or a network electronic device, etc.) to perform all or part of the steps of the method described in each embodiment of the present disclosure. The aforementioned memory includes: various media that can store program codes, such as a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.
[0165] The present application also provides a non-transitory computer storage medium storing a computer program, which, when executed by multiple processors, causes the processors to execute the following Figures 5 to 9 The method and refinement scheme shown.
[0166] The embodiments of the present application are described in detail above. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only intended to help understand the method and core ideas of the present application. At the same time, changes or modifications made by those skilled in the art based on the ideas of the present application, the specific implementation methods, and the scope of application of the present application, all fall within the scope of protection of the present application. In summary, the contents of this specification should not be construed as limiting the present application.
Claims
1. A method for quantum key distribution and quantum direct communication, applied to a sender, characterized in that: include: Process the plaintext information to be sent and obtain the codeword; Encrypt the codeword using an encryption key in a key pool to obtain a ciphertext; Performing mask-encoding on the ciphertext to obtain a mask-encoded codeword; Using a quantum key distribution protocol to prepare a quantum state according to the codeword after the masked capacity-encoded codeword, obtain a first quantum state preparation result, and send the first quantum state preparation result to an untrusted third party, so that the untrusted third party performs a joint measurement on the first quantum state preparation result to determine the measurement result and the time sequence position corresponding to the measurement result; Determine a first bare code according to the codeword after the masked upscaling encoding, the measurement result and the time sequence position corresponding to the measurement result, and the quantum state preparation basis vector information published by the receiver; Performing QKD post-processing based on the first bare code to obtain a QKD post-processing result; as well as A new key is generated according to the result of the QKD post-processing, and the new key is stored in the key pool.
2. The method according to claim 1, wherein Also includes: Information on the random number used in the masked upscaling coding process at the corresponding used time sequence position is sent to the receiving party.
3. The method according to claim 2, wherein The sending of information of the random number used in the masked upscaling coding process at the corresponding used time sequence position to the receiving party includes: Obtaining the used timing positions of the published valid detection bits; and Information on the random number used in the masked upscaling coding process at the used timing position is sent to the receiving party.
4. The method according to claim 2, wherein The sending of information of the random number used in the masked upscaling coding process at the corresponding used time sequence position to the receiving party includes: Measuring the sender's particle using the quantum key distribution protocol to obtain a first measurement result; Acquire a first time sequence position of the first measurement result; Acquire a second time sequence position having a second measurement result published by the receiver; Determining, based on the first timing position and the second timing position, a corresponding used timing position at which both the sender and the receiver have measurement results; and Sending information on the random number used in the mask capacity increase process at the used timing position to the receiver.
5. The method according to any one of claims 1 to 4, characterized in that Also includes: Among the encryption keys used to encrypt the codeword, the encryption key that does not correspond to the used time sequence position is returned to the key pool.
6. The method according to any one of claims 1 to 4, characterized in that The processing of the plaintext information to be sent to obtain a codeword includes: performing error correction coding on the plaintext information to be sent to obtain a first codeword; and The first codeword is spread spectrum-spread to obtain a second codeword.
7. A method of quantum key distribution and quantum direct communication, applied to a receiving party, characterized in that: include: Generate a random number, wherein the random number is equal in length to the codeword after the masked upscaling encoding by the sender; Prepare a quantum state according to the random number to obtain a second quantum state preparation result; Sending the second quantum state preparation result to an untrusted third party, so that the untrusted third party performs a joint measurement on the second quantum state preparation result to determine the measurement result and the time sequence position corresponding to the measurement result; Determine a second bare code according to the random number, the measurement result, the timing position corresponding to the measurement result, and the timing position published by the sender that is the same as the basis vector prepared by the receiver; performing QKD post-processing according to the second bare code to obtain a QKD post-processing result; generating a new key according to the result of the QKD post-processing, and storing the new key in the key pool of the receiver; and The codeword is processed to obtain plaintext information.
8. The method according to claim 7, wherein Also includes: receiving a local encrypted random number corresponding to a timing position of a valid detection bit in the measurement result, sent by the sender; The processing of the codeword to obtain plaintext information includes: Performing masked capacity-enhancing decoding on the codeword according to the local encrypted random number to obtain a masked capacity-enhancing decoded codeword; Decrypting the codeword after the masked capacity-increasing decoding to obtain a decrypted codeword; Despreading the decrypted codeword to obtain a despread codeword; and Error correction decoding is performed on the despread codeword to obtain plaintext information.
9. A system for quantum key distribution and quantum direct communication, characterized in that: include: A sending device, configured to execute the method according to any one of claims 1 to 6; as well as A receiving device, configured to execute the method according to claim 7 or 8.
10. An electronic device, characterized in that: The method comprises a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the method according to any one of claims 1 to 8 when executing the computer program in the memory.
11. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Quantum direct communication method, device, equipment and system based on single-path transmission
CN114244507A