Quantum key distribution method and system

By using the HBS algorithm for information authentication in quantum key distribution, the problems of complex key management and insufficient verification flexibility in the prior art are solved, and efficient key distribution and communication authentication are achieved.

CN119995845AActive Publication Date: 2025-05-13BEIJING ELECTRONICS SCI & TECH INST
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202411954965.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-05-13
Estimated Expiration
2044-12-27

AI Technical Summary

Technical Problem

In quantum key distribution (QKD), the existing technology has complex key management in large-scale network application environments such as metropolitan area networks, and the workload of preset keys is huge, which increases management costs and reduces communication efficiency. Data verification is required at each data transmission stage, which limits the flexibility of verification.

Method used

A quantum key distribution method is proposed. In the target authentication stage of the sender and receiver determining the need for information authentication through the HBS algorithm, QKD is realized in the classic channel, avoiding the need for preset keys, reducing management costs, and improving communication efficiency and verification flexibility.

Benefits of technology

It realizes efficient authentication of QKD in classic channels, reduces key management costs, improves communication efficiency, and improves the flexibility of data verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995845A_ABST
    Figure CN119995845A_ABST
Patent Text Reader

Abstract

The invention discloses a quantum key distribution method and system. The method comprises the following steps: determining a target authentication stage in which a sender and a receiver need to perform information authentication; in the target authentication stage, the sender signs first information and a first random number which need to be authenticated by using a corresponding first private key through an HBS algorithm to obtain a first signature result, and sends the first signature result, the first information and the first random number to the receiver; and the receiver verifies the first signature result, the first information and the first random number by using a first public key of the sender through an HBS algorithm, if the verification is passed, it is determined that the sender passes the authentication, otherwise, it is determined that the sender does not pass the authentication, and the quantum key distribution process is ended. According to the invention, under the condition that the sender and the receiver carry out data verification, the verification flexibility is improved, the key does not need to be preset, the management cost is reduced, and the communication efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of quantum communication network and quantum key technology, and in particular to a quantum key distribution method and system. Background Art

[0002] At present, the implementation of quantum key distribution (QKD) can include quantum channels and classical channels. Among them, quantum channels can be used to transmit quantum states, and classical channels can be used to transmit information in the data post-processing process, and quantum channels and classical channels are public channels. However, in QKD, authentication is required in the classical channel to ensure security, that is, the information exchanged in the QKD data post-processing process needs to be authenticated.

[0003] In the prior art, a symmetric key can be preset before authentication to authenticate the classical channel, wherein both parties of authentication use the key to encrypt (sign) and decrypt (verify). However, the above-mentioned method of presetting key pairs has a complex key management relationship in large-scale networking application environments such as metropolitan area networks, and the workload of presetting keys is huge, which increases management costs and reduces communication efficiency. In addition, in the prior art, data verification is required at each data transmission stage in the classical channel, which limits the flexibility of verification. Summary of the invention

[0004] The present invention aims to solve one of the technical problems in the related art at least to a certain extent.

[0005] To this end, the present invention proposes a quantum key distribution method, which can realize the authentication of QKD communication in a classical channel through the HBS algorithm in the target authentication phase where the sender and the receiver determine that information authentication is required. While satisfying the data verification requirements of the sender and the receiver, the flexibility of verification is improved, and at the same time, there is no need to pre-set keys, which reduces management costs and improves communication efficiency.

[0006] Another object of the present invention is to provide a quantum communication network system.

[0007] To achieve the above object, the present invention proposes a quantum key distribution method on one hand, which is implemented in quantum communication devices of both the sender and the receiver participating in the quantum key distribution process, and the method comprises:

[0008] Determine a target authentication stage in which the sender and the receiver need to perform information authentication;

[0009] In the target authentication phase, the sender signs the first information to be authenticated and the first random number using the HBS algorithm using the corresponding first private key to obtain a first signature result, and sends the first signature result, the first information and the first random number to the receiver;

[0010] The receiver uses the first public key of the sender to verify the first signature result, the first information and the first random number through the HBS algorithm. If the verification is successful, the sender is determined to have passed the authentication. Otherwise, the sender is determined to have failed the authentication and the quantum key distribution process is terminated, wherein the first private key and the first public key are generated by the sender through the HBS algorithm.

[0011] The quantum key distribution method of the embodiment of the present invention may also have the following additional technical features:

[0012] In one embodiment of the present invention, the target authentication phase of determining that the sender and the receiver need to perform information authentication includes:

[0013] The sender and the receiver determine the target authentication stage for information authentication through negotiation; or

[0014] The target authentication stage at which the sender and the receiver need to perform information authentication is determined according to a predetermined rule.

[0015] In one embodiment of the present invention, the sender and the receiver determine through negotiation the target authentication phase in which information authentication is required, including:

[0016] The sending party sends a first negotiation message to the receiving party, wherein the first negotiation message includes the candidate authentication stage of the sending party;

[0017] The receiving party determines a target authentication phase based on the candidate authentication phase, and sends a second negotiation message to the sending party, wherein the second negotiation message includes the target authentication phase;

[0018] The sender receives the second negotiation message, and determines the target authentication phase based on the second negotiation message.

[0019] In one embodiment of the present invention, the method further includes:

[0020] In the target phase, after the receiving party determines that the sending party has passed the authentication, the receiving party signs the second information to be authenticated and the second random number using the corresponding second private key through the HBS algorithm to obtain a second signature result, and sends the second signature result, the second information and the second random number to the sending party;

[0021] The sender uses the second public key of the receiver to verify the second signature result, the second information and the second random number through the HBS algorithm. If the verification is successful, the receiver is determined to have passed the authentication and the interaction in the target stage is completed. Otherwise, the receiver is determined to have failed the authentication and the quantum key distribution process is ended, wherein the second private key and the second public key are generated by the receiver through the HBS algorithm.

[0022] In one embodiment of the present invention, the target authentication phase includes at least one of the following phases:

[0023] Mutual authentication and parameter negotiation phase;

[0024] Base screening stage;

[0025] Parameter estimation stage;

[0026] Error correction and verification phase.

[0027] In one embodiment of the present invention, the method further includes:

[0028] The sender generates a first public key and a first private key based on the HBS algorithm, and sends a first digital certificate request to a trusted authentication center, where the first digital certificate request includes the first public key and first identity information;

[0029] The sender receives a first digital certificate sent by the trusted authentication center, wherein the first digital certificate is generated after the trusted authentication center verifies the first identity information, and the first digital certificate includes the first public key and a first certificate signature result, and the first certificate signature result is generated by the trusted authentication center signing the first public key using its private key through the HBS algorithm;

[0030] The receiver generates a second public key and a second private key based on the HBS algorithm, and sends a second digital certificate request to a trusted authentication center, where the second digital certificate request includes the second public key and second identity information;

[0031] The recipient receives a second digital certificate sent by the trusted authentication center, wherein the second digital certificate is generated after the trusted authentication center verifies the second identity information, and the second digital certificate includes the second public key and the second certificate signature result, and the second certificate signature result is generated by the trusted authentication center using its private key to sign the second public key through the HBS algorithm.

[0032] In one embodiment of the present invention, before the receiving party verifies the first signature result, the first information and the first random number by using the first public key of the sender through the HBS algorithm, the method further includes:

[0033] The receiving party receives the first digital certificate sent by the sending party;

[0034] The receiver uses the public key of the trusted certification center to verify the signature result of the first certificate in the first digital certificate through the HBS algorithm, and after the verification is passed, obtains the first public key of the sender in the first digital certificate.

[0035] Another aspect of the present invention provides a quantum key distribution method, which is implemented in a sender quantum communication device participating in a quantum key distribution process, and includes:

[0036] Determine with the recipient the target authentication stage where information authentication is required;

[0037] In the target authentication phase, the first information to be authenticated and the first random number are signed by using the corresponding first private key through the HBS algorithm to obtain a first signature result, and the first signature result, the first information and the first random number are sent to the recipient, wherein the first private key is generated by the HBS algorithm;

[0038] Receiving a second signature result, second information, and second random number sent by the recipient;

[0039] The second signature result, the second information and the second random number are verified by using the second public key of the recipient through the HBS algorithm. If the verification passes, it is determined that the recipient has passed the authentication and the interaction in the target stage is completed, wherein the second public key is generated by the recipient through the HBS algorithm.

[0040] Another aspect of the present invention provides a quantum key distribution method, which is implemented in a receiving quantum communication device participating in a quantum key distribution process, and includes:

[0041] Determine with the sender the target authentication stage where information authentication is required;

[0042] In the target authentication phase, receiving a first signature result, a first message and a first random number sent by the sender;

[0043] The first signature result, the first information and the first random number are verified by using the first public key of the sender through the HBS algorithm. If the verification passes, the second information to be authenticated and the second random number are signed by using the corresponding second private key through the HBS algorithm to obtain a second signature result, and the second signature result, the second information and the second random number are sent to the sender; otherwise, it is determined that the sender has failed the authentication and the quantum key distribution process is terminated, wherein the first public key is generated by the sender through the HBS algorithm and the second private key is generated by the receiver through the HBS algorithm.

[0044] Another aspect of the present invention provides a quantum key distribution device, which is in a sender quantum communication device participating in a quantum key distribution process, and includes:

[0045] A determination module, used to determine with the receiving party the target authentication stage at which information authentication is required;

[0046] a sending module, configured to sign the first information to be authenticated and the first random number using the corresponding first private key through the HBS algorithm to obtain a first signature result, and send the first signature result, the first information and the first random number to the recipient in the target authentication phase, wherein the first private key is generated through the HBS algorithm;

[0047] A receiving module, used to receive the second signature result, the second information and the second random number sent by the receiving party;

[0048] A verification module is used to verify the second signature result, the second information and the second random number by using the second public key of the recipient through the HBS algorithm. If the verification passes, it is determined that the recipient is authenticated and the interaction in the target stage is completed, wherein the second public key is generated by the recipient through the HBS algorithm.

[0049] Another aspect of the present invention provides a quantum key distribution device, which is in a receiving quantum communication device participating in a quantum key distribution process, and includes:

[0050] A confirmation module is used to determine with the sender the target authentication stage at which information authentication is required;

[0051] A receiving module, used for receiving a first signature result, a first message and a first random number sent by the sender in the target authentication phase;

[0052] A verification module is used to verify the first signature result, the first information and the first random number by using the first public key of the sender through the HBS algorithm. If the verification is successful, the second information to be authenticated and the second random number are signed by using the corresponding second private key through the HBS algorithm to obtain a second signature result, and the second signature result, the second information and the second random number are sent to the sender; otherwise, it is determined that the sender has not passed the authentication and the quantum key distribution process is terminated, wherein the first public key is generated by the sender through the HBS algorithm and the second private key is generated by the receiver through the HBS algorithm.

[0053] To achieve the above-mentioned purpose, on the other hand, the present invention proposes a quantum communication network system, which includes: a trusted authentication center and multiple quantum communication devices, and is characterized in that the quantum communication network system realizes mutual authentication of the multiple quantum communication devices through any of the methods described above, thereby realizing the distribution of quantum keys and quantum secure communication between them.

[0054] The quantum key distribution method and system of the embodiments of the present invention can realize the authentication of QKD communication in the classical channel through the HBS algorithm in the target authentication phase where the sender and the receiver determine that information authentication is required. While satisfying the data verification requirements of the sender and the receiver, the flexibility of verification is improved, and there is no need to pre-set keys, which reduces management costs and improves communication efficiency.

[0055] Additional aspects and advantages of the present invention will be given in part in the following description and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] The above and / or additional aspects and advantages of the present invention will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:

[0057] Figure 1 is a flow chart of a quantum key distribution method according to an embodiment of the present invention;

[0058] Figure 2 is an interactive flow chart of a quantum key distribution method according to another embodiment of the present invention;

[0059] Figure 3 is an interactive flow chart of a quantum key distribution method according to another embodiment of the present invention;

[0060] Figure 4 is an interactive flow chart of a quantum key distribution method according to another embodiment of the present invention;

[0061] Figure 5 is a flow chart of a quantum key distribution method according to another embodiment of the present invention;

[0062] Figure 6 is a flow chart of a quantum key distribution method according to another embodiment of the present invention;

[0063] Figure 7 is a flow chart of a quantum key distribution device according to another embodiment of the present invention;

[0064] Figure 8 is a flow chart of a quantum key distribution device according to another embodiment of the present invention. DETAILED DESCRIPTION

[0065] It should be noted that, in the absence of conflict, the embodiments of the present invention and the features in the embodiments can be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0066] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0067] The quantum key distribution method and system proposed according to the embodiments of the present invention are described below with reference to the accompanying drawings.

[0068] Figure 1 It is a flow chart of the quantum key distribution method of an embodiment of the present invention.

[0069] like Figure 1 As shown, the method is implemented in quantum communication devices of both the sender and the receiver participating in the quantum key distribution process, and the method may include:

[0070] Step 101, determine the target authentication phase in which the sender and the receiver need to perform information authentication.

[0071] In one embodiment of the present invention, the above-mentioned sender and receiver need to perform information authentication in a classical channel, wherein there are multiple data transmission stages in the classical channel. Based on this, before the sender and receiver perform information authentication in the classical channel, the target authentication stage in which the sender and receiver need to perform information authentication can be determined.

[0072] Among them, in one embodiment of the present invention, the above-mentioned method for determining the target authentication stage at which the sender and the receiver need to perform information authentication may include: the sender and the receiver determine the target authentication stage at which information authentication needs to be performed through negotiation; or determine the target authentication stage at which the sender and the receiver need to perform information authentication according to predetermined rules.

[0073] Specifically, in one embodiment of the present invention, the method in which the sender and the receiver determine through negotiation the target authentication phase in which information authentication is required may include the following steps:

[0074] Step 1: The sender sends a first negotiation message to the receiver, wherein the first negotiation message includes the candidate authentication stage of the sender;

[0075] Step 2: The receiver determines the target authentication phase based on the candidate authentication phase, and sends a second negotiation message to the sender, wherein the second negotiation message includes the target authentication phase;

[0076] Step 3: The sender receives the second negotiation message and determines the target authentication phase based on the second negotiation message.

[0077] In one embodiment of the present invention, the candidate authentication stage can be understood as a stage that the sender preliminarily determines requires information authentication.

[0078] It is understandable that after the sender sends the first negotiation message to the receiver, the receiver can select the target authentication phase that needs to be authenticated from the candidate authentication phases according to its own needs, and then send a second negotiation message to the sender, which carries the target authentication phase determined by the receiver. After receiving the second negotiation message sent by the receiver, the sender confirms the target authentication phase carried in the second negotiation message as the target authentication phase that needs to be authenticated.

[0079] For example, in one embodiment of the present invention, after the sender sends a first negotiation message to the receiver, if the receiver confirms that the candidate authentication stage carried therein is feasible, the candidate authentication stage in the first negotiation message is determined as the target authentication stage, and a second negotiation message is sent to the sender. When the sender receives the second negotiation message sent by the receiver, it can be determined that the receiver agrees with the candidate authentication stage, so that the candidate authentication stage can be determined as the target authentication stage determined by the final negotiation.

[0080] Among them, in another embodiment of the present invention, the target authentication stage in which the sender and the receiver need to perform information authentication can be determined according to predetermined rules. That is, before the sender and the receiver perform quantum key distribution, the target authentication stage in which information authentication needs to be performed can be pre-set based on experience, so that the sender and the receiver can directly perform information authentication in the target authentication stage.

[0081] And, in one embodiment of the present invention, the target authentication phase may include at least one of the following phases:

[0082] Mutual authentication and parameter negotiation phase;

[0083] Base screening stage;

[0084] Parameter estimation stage;

[0085] Error correction and verification phase.

[0086] It should be noted that, in one embodiment of the present invention, if the above-mentioned target authentication stage includes two stages, the target authentication stage needs to include an error correction verification stage and a parameter estimation stage, so that the receiver and the sender can perform signature verification on all received parameters.

[0087] Step 102, in the target authentication phase, the sender uses the corresponding first private key to sign the first information to be authenticated and the first random number through the HBS algorithm to obtain a first signature result, and sends the first signature result, the first information and the first random number to the receiver.

[0088] In one embodiment of the present invention, after the target authentication phase is determined through the above steps, the sender and the receiver can perform information authentication through the HBS algorithm in the target authentication phase to complete the interaction in the target authentication phase. In one embodiment of the present invention, the HBS algorithm can include an international standard and / or a national standard HBS algorithm.

[0089] Furthermore, in one embodiment of the present invention, before the sender and the receiver interact in the target authentication phase, the method may further include the following steps:

[0090] Step a: The sender generates a first public key and a first private key based on the HBS algorithm, and sends a first digital certificate request to a trusted certification center, where the first digital certificate request includes the first public key and the first identity information;

[0091] Step b, the sender receives a first digital certificate sent by a trusted authentication center, wherein the first digital certificate is generated after the trusted authentication center verifies the first identity information, and the first digital certificate includes a first public key and a first certificate signature result, and the first certificate signature result is generated by the trusted authentication center using its private key to sign the first public key through the HBS algorithm;

[0092] Step c: The recipient generates a second public key and a second private key based on the HBS algorithm, and sends a second digital certificate request to the trusted certification center, where the second digital certificate request includes the second public key and the second identity information;

[0093] In step d, the recipient receives the second digital certificate sent by the trusted certification center, wherein the second digital certificate is generated after the trusted certification center verifies the second identity information, and the second digital certificate includes the second public key and the second certificate signature result, and the second certificate signature result is generated by the trusted certification center using its private key to sign the second public key through the HBS algorithm.

[0094] Wherein, in one embodiment of the present invention, the above-mentioned first identity information may include the IP address, name, and device information of the sender; and the second identity information may include the IP address, name, and device information of the receiver. And, in one embodiment of the present invention, after receiving the first identity information and the second identity information, the trusted authentication center may verify whether the identities of the sender and the receiver meet the security specification requirements of the system through the authentication mechanism, wherein the verification process involves checking the legitimacy of the user and verifying the authenticity of the user's identity, and after the verification is passed, the trusted authentication center uses the HBS algorithm to issue a first digital certificate to the sender and a second digital certificate to the receiver, and the first digital certificate includes a first public key and a first certificate signature result, and the first certificate signature result is generated by the trusted authentication center using its private key to sign the first public key through the HBS algorithm, and the second digital certificate includes a second public key and a second certificate signature result, and the second certificate signature result is generated by the trusted authentication center using its private key to sign the second public key through the HBS algorithm, thereby ensuring the identity credibility in communication.

[0095] Furthermore, in one embodiment of the present invention, when the target authentication phase is different, the first information that needs to be authenticated in the target authentication phase is also different.

[0096] For example, in one embodiment of the present invention, assuming that the target authentication phase includes a mutual authentication certificate and a parameter negotiation phase, the sender uses the corresponding first private key SK B The first random number R is signed by the HBS signature algorithm B The first information that needs to be authenticated B Sign to get the first signature value SIG B0 =Sig HBS (SK B , R B , n B ) and the first digital certificate Cert B With the first random number R B , first signature value SIG B0 、First Information B Send to the receiver.

[0097] In one embodiment of the present invention, the first random number is randomly generated by the sender to prevent replay attacks during data transmission.

[0098] Step 103: The receiver uses the sender's first public key to verify the first signature result, the first information and the first random number through the HBS algorithm. If the verification is successful, the sender is determined to be authenticated. Otherwise, the sender is determined to be unauthenticated and the quantum key distribution process ends.

[0099] In one embodiment of the present invention, in the target authentication phase, after the receiver receives the first signature result, the first information and the first random number sent by the sender, the receiver can verify the received first signature result, the first information and the first random number. If the verification passes, the sender is determined to have passed the authentication. Otherwise, the sender is determined to have failed the authentication and the quantum key distribution process ends.

[0100] Specifically, in one embodiment of the present invention, the first signature result can be verified using the sender's first public key through the HBS algorithm. If the verification passes, the sender is determined to have passed the authentication. Otherwise, the sender is determined to have failed the authentication and the quantum key distribution process ends.

[0101] For example, in one embodiment of the present invention, the above-mentioned receiving party receives the first digital certificate Cert B With the first random number R B , first signature value SIG B0 、First Information B After that, the sender's first digital certificate Cert can be verified using the public key of the publicly available trusted certification center B , and after verification, use the sender's first public key PK B The first signature value of the HBS signature verification algorithm is used. If the verification is successful, the sender is determined to be authenticated. Otherwise, the sender is determined to be unauthenticated and the quantum key distribution process ends.

[0102] Furthermore, in one embodiment of the present invention, before the receiving party verifies the first signature result, the first information and the first random number by using the first public key of the sender through the HBS algorithm, the method may further include the following steps:

[0103] Step 1: The receiver receives the first digital certificate sent by the sender;

[0104] Step 2: The receiver uses the public key of the trusted certification center to verify the signature result of the first certificate in the first digital certificate through the HBS algorithm, and after the verification is passed, obtains the first public key of the sender in the first digital certificate.

[0105] Among them, in one embodiment of the present invention, the identity of the recipient can be authenticated through the above steps, and after the identity authentication is passed, the first public key of the trusted sender in the first digital certificate is obtained, so that the subsequent recipient can use the first public key of the sender for verification.

[0106] It should be noted that, in one embodiment of the present invention, the above steps can be performed in the mutual verification certificate and parameter negotiation stage to authenticate the identity of the sender through the first digital certificate, and after the identity of the sender is authenticated in the mutual verification certificate and parameter negotiation stage, there is no need to repeat the authentication in subsequent stages.

[0107] Furthermore, in one embodiment of the present invention, after determining that the sender has passed the authentication, the above method may further include the following steps:

[0108] Step 104, in the target phase, after the receiving party determines that the sending party has passed the authentication, the receiving party signs the second information to be authenticated and the second random number using the corresponding second private key through the HBS algorithm to obtain a second signature result, and sends the second signature result, the second information and the second random number to the sending party;

[0109] Step 105: The sender uses the second public key of the receiver to verify the second signature result, the second information and the second random number through the HBS algorithm. If the verification is successful, the receiver is determined to have passed the authentication and the interaction in the target stage is completed. Otherwise, the receiver is determined to have failed the authentication and the quantum key distribution process ends.

[0110] Among them, in one embodiment of the present invention, before the sender uses the second public key of the receiver to verify the second signature result, the second information and the second random number through the HBS algorithm, the sender can use the second data certificate of the receiver to authenticate the identity of the receiver, and obtain the trusted second public key of the receiver in the second data after the identity authentication is passed. For the specific content of this part, please refer to the detailed introduction in the above embodiment, and the embodiment of the present disclosure will not be repeated here.

[0111] For the relevant introduction in step 104 to step 105, please refer to the detailed introduction in the above embodiment, and the embodiment of the present disclosure will not be elaborated here.

[0112] For example, in one embodiment of the present invention, assuming that the above target phase includes a mutual authentication certificate and a parameter negotiation phase, after the receiving party determines that the sending party has passed the authentication, the receiving party uses the corresponding second private key SK A The HBS algorithm was used to calculate R B , R A , n A Sign to get the second signature value SIG A0 , and the second digital certificate CertA With the second random number R A , second signature value SIG A0 , second information n A Sent to the sender.

[0113] And, the sender receives the second digital certificate Cert A With the second random number R A , second signature value SIG A0 and the second information n A After that, the public key of the trusted certification center can be used to verify the recipient's second digital certificate Cert A , and after verification, use the recipient's second public key PK A The second signature value of the HBS signature verification algorithm is used. If the verification is successful, the sender is determined to have passed the authentication. Otherwise, the sender is determined to have failed the authentication and the quantum key distribution process ends. Based on this, if the above target stage includes the mutual authentication certificate and parameter negotiation stage, it is necessary to verify the first digital certificate or the second digital certificate first, and after completing the identity authentication of both parties, verify the first signature value or the second signature value to ensure that the transmitted data is secure and not damaged.

[0114] It should be noted that, in one embodiment of the present invention, the security of the HBS algorithm depends on the resistance to second preimage of the underlying hash function (that is, given a hash value Y, it is extremely difficult to find two different inputs X and X' such that H(X) = H(X')). Among them, the hash function is constructed based on simple and time-tested algorithm principles, and its security does not depend on complex mathematical structures, but on the anti-collision property of the hash function. Based on this, the HBS algorithm can provide more stable security guarantees when facing quantum computing, and will not be as susceptible to quantum computing as other PQC algorithms based on mathematical problems (such as lattice cryptography). Therefore, the use of the HBS algorithm does not increase the security dependence of the QKD system. The HBS algorithm has significant advantages in the ability to resist quantum computing attacks, and can more effectively resist potential attacks from future quantum computers. It solves the threat of quantum computing to PQC algorithms based on mathematical problems and the management complexity of symmetric key authentication, and provides higher security, thereby ensuring the reliability and long-term effectiveness of the authentication process, and providing a more solid guarantee for the security of the quantum key distribution network.

[0115] The embodiment of the present invention proposes a quantum key distribution method, which includes: determining the target authentication stage in which the sender and the receiver need to perform information authentication; in the target authentication stage, the sender uses the corresponding first private key to sign the first information and the first random number that need to be authenticated through the HBS algorithm to obtain a first signature result, and sends the first signature result, the first information and the first random number to the receiver; the receiver uses the sender's first public key to verify the first signature result, the first information and the first random number through the HBS algorithm. If the verification is successful, it is determined that the sender has passed the authentication, otherwise, it is determined that the sender has not passed the authentication and the quantum key distribution process is terminated, wherein the first private key and the first public key are generated by the sender through the HBS algorithm. Therefore, the present invention can realize the authentication of QKD communication in the classical channel through the HBS algorithm in the target authentication stage in which the sender and the receiver determine that information authentication is required, and improves the flexibility of verification while satisfying the sender and the receiver for data verification. At the same time, there is no need to pre-set keys, which reduces management costs and improves communication efficiency.

[0116] Based on the above description, Figure 2 This is an interactive flow chart of the quantum key distribution method proposed in an embodiment of the present invention.

[0117] Among them, the quantum communication device deployed on the sender is called Alice, and the quantum communication device deployed on the receiver is called Bob. The target authentication phase includes the mutual verification certificate and parameter negotiation phase, the basis screening phase, the parameter estimation phase, and the error correction verification phase.

[0118] Step 201, Alice sends quantum bits r1 and r0 to Bob through a quantum channel;

[0119] Among them, the first quantum bit r1 is called the "generated basis bit", where the "generated basis bit" is 0, and the "X basis" (+45° and -45° directions) is selected. If the "generated basis bit" is 1, the "Z basis" (0° and 90° directions) is selected to encode each quantum bit.

[0120] And, the second quantum bit r0 is called the "key bit". After the measurement basis is selected, the "key bit" determines which quantum state Alice sends. Among them, when the "X basis" is selected, the key bit is 0, which will make Alice send the "+45°" quantum state, and if the key bit is 1, it will make Alice send the "-45°" quantum state; when the generation basis bit selects the "Z basis", the key bit is 0, which will make Alice send the polarization in the 0° direction, and the key bit is 1, which will make Alice send the polarization in the 90° direction. Table 1 is a quantum bit correspondence table proposed in an embodiment of the present invention.

[0121] Table 1

[0122]

[0123]

[0124] Step 202, after Bob receives the quantum bit sent by Alice, he uses a random number bit r3 as the measurement basis bit;

[0125] The "Measurement Basis Bit" can be used to determine which basis to use for measurement. If the measurement basis bit is 0, "X basis" is selected for measurement; if the measurement basis bit is 1, "Z basis" is selected for measurement.

[0126] Also, during specific measurements, if Bob's measurement basis bits are consistent with Alice's generation basis bits (for example, Alice and Bob both choose "Z basis" or both choose "X basis"), Bob's measurement result will be consistent with the key bits sent by Alice, thereby retaining valid information; if Bob's measurement basis bits are different from Alice's generation basis bits (for example, one chooses "Z basis" and the other chooses "X basis"), the measurement result will be a random value, and both parties will discard the mismatched measurement results in the subsequent basis screening step.

[0127] Furthermore, in the process of quantum communication, all r1 used by Alice form the generating base sequence L1, and all r2 used by Bob form the generating base sequence L2.

[0128] Step 203, Bob generates a random number R B (the first random number in the above embodiment), and create a capability list n according to the device and function library B ;

[0129] Step 204, Bob uses the corresponding private key SK B (the first private key in the above embodiment) is converted to R by the HBS algorithm B With n B Sign to get the first signature value SIG B0 =Sig HBS (SK B , R B , n B )(the first signature value in the above embodiment);

[0130] Step 205, Bob sends the digital certificate Cert B , R B , SIG B0 and n B Send to Alice;

[0131] Step 206, Alice receives Cert B With R B, SIG B0 and n B Then, use the public key of the trusted certification center and the HBS algorithm to verify Bob's certificate Cert B , after successful verification, use Bob's certificate Cert B The public key PK in B Verify the signature SIG with the HBS algorithm B0 ;

[0132] Step 207: After confirming Bob's identity, Alice selects Bob's capability list n. B , determine the functions and related parameters used in the data post-processing process, and generate the corresponding capability list n A , and generate a random number R A (the second random number in the above embodiment);

[0133] Step 208, Alice uses the corresponding private key SK A The HBS algorithm was used to calculate R B , R A , n A Sign to get the second signature value SIG A0 =Sig HBS (SK A , R B , R A , n A );

[0134] Step 209, Alice sends the digital certificate Cert A With R A , SIG A0 、n A Send to Bob;

[0135] Step 210, Bob receives Cert A With R A , SIG A0 、n A Then, use the public key of the publicly available trusted certification center to verify Alice's certificate Cert A , and use Alice's certificate Cert A The public key PK in A (the second public key in the above embodiment) and the HBS algorithm verification signature SIG A0 , after verification, Alice’s identity can be confirmed;

[0136] The mutual authentication and parameter negotiation phase is completed through the above steps 203 to 210.

[0137] Step 211, Bob uses the corresponding private key SK BThe random number R is generated by the HBS algorithm. A Sign with the measurement base sequence L2 to obtain the third signature value SIG B1 =Sig HBS (SK B , R A , L2);

[0138] Step 212, Bob connects L2 with SIG B1 Send to Alice;

[0139] Step 213, Alice receives L2 and SIG B1, Then, use Bob's certificate Cert B The public key PK in B , R A 、L2、SIG B1 And HBS algorithm verifies the third signature value SIG B1 After the verification, Alice obtains the measurement basis sequence L2 used in Bob's quantum transmission process;

[0140] Among them, a signature algorithm is used in the above data transmission process to ensure that L2 is complete and not tampered with.

[0141] Step 214, Alice uses the corresponding private key SK A The random number R is generated by the HBS algorithm. B Sign with the generated base sequence L1 to obtain the fourth signature value SIG A1 =Sig HBS (SK A , R B , L1);

[0142] Step 215, Alice connects L1 and SIG A1 Send to Bob;

[0143] Step 216, Bob receives L1 and SIG A1 Then, use Alice's certificate Cert A The public key PK in A , R B 、L1、SIG A1 And HBS algorithm verifies the fourth signature value SIG A1 After the verification, Bob obtains the base sequence L1 used by Alice in the quantum transmission process;

[0144] The base screening stage is completed through the above steps 211 to 216.

[0145] Among them, a signature algorithm is used in the above data transmission process to ensure that L1 is complete and not tampered with.

[0146] And, Bob filters the bits he receives according to the base sequence L1 provided by Alice, retains the bits that are consistent with Alice's base sequence L1, and forms the corresponding original key Key B Similarly, Alice filters the bits she sends based on the generated base measurement sequence L2 provided by Bob, retains the bits that are consistent with Bob's measurement base sequence L2, and performs base filtering to form the corresponding original key Key A Among them, if the quantum channel of quantum transmission is an ideal channel without transmission errors, then Key A and Key B The quantum channel is exactly the same, but it is not an ideal channel without transmission errors. Based on this, Key A and Key B They are not exactly the same, so a parameter estimation process is required to calculate the transmission bit error rate, and then error correction verification is performed to ensure that both parties obtain exactly the same original key.

[0147] Step 217, Bob generates a random number sequence L B (e.g. [5, 12, 29, ...]), and according to L B In Key B Select the corresponding bits to form a bit string r B ;

[0148] Among them, the random number sequence L B The random number in represents the position of the bit randomly selected from the original key for parameter estimation.

[0149] Step 218, Bob uses the corresponding private key SK B The random number R is generated by the HBS algorithm. A , random number sequence L B With bit string r B Sign to obtain the fifth signature value SIG B2 =Sig HBS (SK B , R A , L B , r B );

[0150] Step 219, Bob will L B With SIG B2 Send to Alice;

[0151] Step 220, Alice receives L B With SIG B2 Then, use Bob's certificate Cert B The public key PK in B , RA , L B 、r B , SIG B1 And HBS algorithm verifies the fifth signature value SIG B2 After verification, Alice obtains the random number sequence L used in Bob’s quantum transmission process. B With bit string r B ;

[0152] Among them, the signature algorithm is used in the above data transmission process to ensure L B With r B Complete and not tampered with.

[0153] And, Alice according to L B In Key A Select the corresponding bits to form a bit string r B ', according to r B 'with r B The bit error rate is calculated. If the bit error rate exceeds the preset threshold, the communication is terminated; if the bit error rate is lower than the preset threshold, the subsequent steps are continued to perform the error correction verification process.

[0154] The parameter estimation phase is completed through the above steps 217 to 220.

[0155] Step 221, Alice uses the original key Key A Delete L B The corresponding bits form a bit string r B ', assuming the remaining key length is N, get the key X N , using error correction code to X N Encode to obtain error correction information Q;

[0156] Step 222, Alice uses the corresponding private key SK A The random number R is generated by the HBS algorithm. B With error correction information Q, key X N Sign to get the sixth signature value SIG A2 =Sig HBS (SK A , R B , Q, X N );

[0157] Step 223, Alice adds Q and SIG A2 Send to Bob;

[0158] Step 224, Bob receives Q and SIG A2 After that, in the original key Key B Delete L B The corresponding bits form a bit string rB , assuming the remaining key length is N, we get the key Y N , using the error correction code and error correction information Q to Y N Perform error correction to obtain X N , using Alice's certificate Cert A The public key PK in A , R B , Q, X N , SIG A1 Use the HBS algorithm to verify the signature value SIG A2 , after verification, Alice and Bob have the same key X N ;

[0159] Among them, error correction verification can be performed through polar code (Polar Code), which is not described in detail in the embodiment of the present disclosure.

[0160] The error correction verification phase is completed through the above steps 221 to 224.

[0161] Step 225, Alice calculates the amount of key exposed during the data processing process, compresses it using the privacy amplification method, and obtains the final key s;

[0162] In step 226, Bob calculates the amount of key exposed during the data processing process, compresses it using the privacy amplification method, and obtains the final key s.

[0163] Among them, in one embodiment of the present invention, the privacy amplification method in step 225 and step 226 is the same as the prior art, and the embodiment of the present disclosure will not be described in detail here.

[0164] Based on the above description, Figure 3 This is an interactive flow chart of the quantum key distribution method proposed in an embodiment of the present invention.

[0165] Among them, the quantum communication device deployed on the sender is called Alice, and the quantum communication device deployed on the receiver is called Bob. The target authentication phase includes the mutual verification certificate and parameter negotiation phase, the parameter estimation phase, and the error correction verification phase.

[0166] Step 301, Alice sends quantum bits r1 and r0 to Bob through the quantum channel;

[0167] Step 302, after Bob receives the quantum bit sent by Alice, he uses a random number bit r3 as the measurement basis bit;

[0168] Step 303, Bob generates a random number R B (the first random number in the above embodiment), and create a capability list n according to the device and function library B ;

[0169] Step 304, Bob uses the corresponding private key SK B (the first private key in the above embodiment) is converted to R by the HBS algorithm B With n B Sign to get the first signature value SIG B0 =Sig HBS (SK B , R B , n B )(the first signature value in the above embodiment);

[0170] Step 305, Bob sends the digital certificate Cert B , R B , SIG B0 and n B Send to Alice;

[0171] Step 306, Alice receives Cert B With R B , SIG B0 and n B Then, use the public key of the trusted certification center and the HBS algorithm to verify Bob's certificate Cert B , after successful verification, use Bob's certificate Cert B The public key PK in B Verify the signature SIG with the HBS algorithm B0 ;

[0172] Step 307: After confirming Bob's identity, Alice selects Bob's capability list n. B , determine the functions and related parameters used in the data post-processing process, and generate the corresponding capability list n A , and generate a random number R A (the second random number in the above embodiment);

[0173] Step 308, Alice uses the corresponding private key SK A The HBS algorithm was used to calculate R B , R A , n A Sign to get the second signature value SIG A0 =Sig HBS (SK A , R B , R A , n A );

[0174] Step 309, Alice sends the digital certificate Cert A With R A , SIGA0 、n A Send to Bob;

[0175] Step 310, Bob receives Cert A With R A , SIG A0 、n A Then, use the public key of the publicly available trusted certification center to verify Alice's certificate Cert A , and use Alice's certificate Cert A The public key PK in A (the second public key in the above embodiment) and the HBS algorithm verification signature SIG A0 , after verification, Alice’s identity can be confirmed;

[0176] The mutual authentication and parameter negotiation phase is completed through the above steps 303 to 310.

[0177] Step 311, Bob sends the measurement base sequence L2 to Alice;

[0178] Step 312, after receiving L2, Alice sends the generated base sequence L1 to Bob;

[0179] The base screening stage is completed through the above steps 311 to 312.

[0180] Step 313, after receiving L1, Bob generates a random number sequence L B (e.g. [5, 12, 29, ...]), and according to L B In Key B Select the corresponding bits to form a bit string r B ;

[0181] Among them, the random number sequence L B The random number in represents the position of the bit randomly selected from the original key for parameter estimation.

[0182] Step 314, Bob uses the corresponding private key SK B The random number R is generated by the HBS algorithm. A , base sequence L2, random number sequence L B With bit string r B Sign to get the third signature value SIG B1 =Sig HBS (SK B , R A , L2, L B , r B );

[0183] Step 315, Bob will L B With SIG B1 Send to Alice;

[0184] Step 316, Alice receives L B With SIG B1 Then, use Bob's certificate Cert B The public key PK in B , R A , L2, L B 、r B , SIG B1 And HBS algorithm verifies the third signature value SIG B1 After verification, Alice obtains the random number sequence L used in Bob’s quantum transmission process. B With bit string r B ;

[0185] The parameter estimation phase is completed through the above steps 313 to 316.

[0186] Step 317, Alice uses the original key Key A Delete L B The corresponding bits form a bit string r B ', assuming the remaining key length is N, get the key X N , using error correction code to X N Encode to obtain error correction information Q;

[0187] Step 318, Alice uses the corresponding private key SK A The random number R is generated by the HBS algorithm. B , base sequence L1, error correction information Q, key X N Sign to obtain the fourth signature value SIG A1 =Sig HBS (SK A , R B , L1, Q, X N );

[0188] Step 319, Alice adds Q and SIG A1 Send to Bob;

[0189] Step 320, Bob receives Q and SIG A1 After that, in the original key Key B Delete L B The corresponding bits form a bit string r B , assuming the remaining key length is N, we get the key Y N , using the error correction code and error correction information Q to Y N Perform error correction to obtain XN , using Alice's certificate Cert A The public key PK in A , R B , L1, Q, X N , SIG A1 The fourth signature value SIG is verified by the HBS algorithm A1 , after verification, Alice and Bob have the same key X N ;

[0190] The error correction verification phase is completed through the above steps 317 to 320.

[0191] Step 321, Alice calculates the amount of key exposed during the data processing process, compresses it using the privacy amplification method, and obtains the final key s;

[0192] In step 322, Bob calculates the amount of key exposed during the data processing process, compresses it using the privacy amplification method, and obtains the final key s.

[0193] Based on the above description, Figure 4 This is an interactive flow chart of the quantum key distribution method proposed in an embodiment of the present invention.

[0194] Among them, the quantum communication device deployed on the sender is called Alice, and the quantum communication device deployed on the receiver is called Bob. The target authentication phase includes the error correction verification phase.

[0195] Step 401, Alice sends quantum bits r1 and r0 to Bob through the quantum channel;

[0196] Step 402, after Bob receives the quantum bit sent by Alice, he uses a random number bit r3 as the measurement basis bit;

[0197] Step 403, Bob generates a random number R B (the first random number in the above embodiment), and create a capability list n according to the device and function library B ;

[0198] Step 404, Bob sends the digital certificate Cert B , R B and n B Send to Alice;

[0199] Step 405, Alice receives Cert B , R B and n B Then, use the public key of the trusted certification center and the HBS algorithm to verify Bob's certificate Cert B ;

[0200] Step 406: After confirming Bob's identity, Alice selects Bob's capability list n. B , determine the functions and related parameters used in the data post-processing process, and generate the corresponding capability list n A , and generate a random number R A (the second random number in the above embodiment);

[0201] Step 407, Alice sends the digital certificate Cert A , R A and n A Send to Bob;

[0202] Step 408, Bob receives the Cert A With R A 、n A Then, use the public key of the publicly available trusted certification center to verify Alice's certificate Cert A , after verification, Alice’s identity can be confirmed;

[0203] The mutual authentication and parameter negotiation phase is completed through steps 403 to 408.

[0204] Step 409, Bob sends the measurement base sequence L2 to Alice;

[0205] Step 410, after receiving L2, Alice sends the generated base sequence L1 to Bob;

[0206] The base screening stage is completed through the above steps 409 to 410.

[0207] Step 411, after receiving L1, Bob generates a random number sequence L B (e.g. [5, 12, 29, ...]), and according to L B In Key B Select the corresponding bits to form a bit string r B ;

[0208] Among them, the random number sequence L B The random number in represents the position of the bit randomly selected from the original key for parameter estimation.

[0209] Step 412, Bob uses the corresponding private key SK B The random number R is generated by the HBS algorithm. A , random number R B 、n B , base sequence L2, random number sequence L B With bit string r BSign to get the first signature value SIG B =Sig HBS (SK B , R A , R B , n B , L2, L B , r B );

[0210] Step 413, Bob will L B With SIG B Send to Alice;

[0211] Step 414, Alice receives L B With SIG B Then, use Bob's certificate Cert B The public key PK in B , R A , R B 、n B , L2, L B 、r B , SIG B Verify the first signature value SIG with the HBS algorithm B After verification, Alice obtains the random number sequence L used in Bob’s quantum transmission process. B With bit string r B ;

[0212] The parameter estimation phase is completed through the above steps 411 to 414.

[0213] Step 415, Alice uses the original key Key A Delete L B The corresponding bits form a bit string r B ', assuming the remaining key length is N, get the key X N , using error correction code to X N Encode to obtain error correction information Q;

[0214] Step 416, Alice uses the corresponding private key SK A The random number R is generated by the HBS algorithm. A , random number R B 、n A , base sequence L1, error correction information Q, key X N Sign to get the second signature value SIG A =Sig HBS (SK A , R A , R B , n A , L1, Q, XN );

[0215] Step 417, Alice adds Q and SIG A Send to Bob;

[0216] Step 418, Bob receives Q and SIG A After that, in the original key Key B Delete L B The corresponding bits form a bit string r B , assuming the remaining key length is N, we get the key Y N , using the error correction code and error correction information Q to Y N Perform error correction to obtain X N , using Alice's certificate Cert A The public key PK in A , R A , R B , n A , L1, Q, X N , SIG A Use HBS algorithm to verify the signature value SIG A , after verification, Alice and Bob have the same key X N ;

[0217] The error correction verification phase is completed through the above steps 415 to 418.

[0218] Step 419, Alice calculates the amount of key exposed during the data processing process, compresses it using the privacy amplification method, and obtains the final key s;

[0219] In step 420, Bob calculates the amount of key exposed during the data processing process, compresses it using the privacy amplification method, and obtains the final key s.

[0220] Figure 5 It is a flow chart of the quantum key distribution method of an embodiment of the present invention.

[0221] like Figure 5 As shown, the method is implemented in a sender quantum communication device participating in a quantum key distribution process, and the method may include the following steps:

[0222] Step 501, determine with the receiving party the target authentication phase in which information authentication is required;

[0223] Step 502: In the target authentication phase, the first information to be authenticated and the first random number are signed by using the corresponding first private key through the HBS algorithm to obtain a first signature result, and the first signature result, the first information and the first random number are sent to the recipient, wherein the first private key is generated by the HBS algorithm;

[0224] Step 503, receiving the second signature result, the second information and the second random number sent by the recipient;

[0225] Step 504, using the second public key of the recipient to verify the second signature result, the second information and the second random number through the HBS algorithm. If the verification succeeds, it is determined that the recipient is authenticated and the interaction in the target stage is completed, wherein the second public key is generated by the recipient through the HBS algorithm.

[0226] Figure 6 It is a flow chart of the quantum key distribution method of an embodiment of the present invention.

[0227] like Figure 6 As shown, the method is implemented in a receiving quantum communication device participating in a quantum key distribution process, and the method may include the following steps:

[0228] Step 601, determine with the sender the target authentication phase that requires information authentication;

[0229] Step 602, in the target authentication phase, receiving the first signature result, the first information and the first random number sent by the sender;

[0230] Step 603: Use the sender's first public key to verify the first signature result, the first information and the first random number through the HBS algorithm. If the verification is successful, use the corresponding second private key to sign the second information to be authenticated and the second random number through the HBS algorithm to obtain the second signature result, and send the second signature result, the second information and the second random number to the sender; otherwise, it is determined that the sender has not passed the authentication and the quantum key distribution process is terminated, wherein the first public key is generated by the sender through the HBS algorithm and the second private key is generated by the receiver through the HBS algorithm.

[0231] Figure 7 It is a schematic diagram of the structure of a quantum key distribution device 10 according to an embodiment of the present invention.

[0232] like Figure 7 As shown, the device is in a sender quantum communication device participating in a quantum key distribution process, and the device may include:

[0233] Determination module 701, used to determine with the receiving party the target authentication stage at which information authentication is required;

[0234] The signature module 702 is used to sign the first information to be authenticated and the first random number using the corresponding first private key through the HBS algorithm to obtain a first signature result, and send the first signature result, the first information and the first random number to the recipient in the target authentication phase, wherein the first private key is generated through the HBS algorithm;

[0235] Receiving module 703, used to receive the second signature result, the second information and the second random number sent by the receiving party;

[0236] The verification module 704 is used to verify the second signature result, the second information and the second random number using the second public key of the recipient through the HBS algorithm. If the verification succeeds, it is determined that the recipient has passed the authentication and the interaction in the target stage is completed, wherein the second public key is generated by the recipient through the HBS algorithm.

[0237] Figure 8 It is a schematic diagram of the structure of a quantum key distribution device 20 according to an embodiment of the present invention.

[0238] like Figure 8 As shown, the device is in a receiving quantum communication device participating in a quantum key distribution process, and the device may include:

[0239] Determination module 801, used to determine with the sender the target authentication stage that needs to perform information authentication;

[0240] The receiving module 802 is used to receive the first signature result, the first information and the first random number sent by the sender in the target authentication phase;

[0241] The verification module 803 is used to verify the first signature result, the first information and the first random number by using the first public key of the sender through the HBS algorithm. If the verification is successful, the second information and the second random number to be authenticated are signed by using the corresponding second private key through the HBS algorithm to obtain the second signature result, and the second signature result, the second information and the second random number are sent to the sender; otherwise, it is determined that the sender has not passed the authentication and the quantum key distribution process is terminated, wherein the first public key is generated by the sender through the HBS algorithm and the second private key is generated by the receiver through the HBS algorithm.

[0242] In order to implement the above embodiment, a quantum communication network system is also provided in this embodiment, which includes: a trusted authentication center and multiple quantum communication devices, and is characterized in that the quantum communication network system realizes mutual authentication of multiple quantum communication devices through the above-mentioned quantum key distribution method, thereby realizing the distribution of quantum keys and quantum secure communication between them.

[0243] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, unless they are contradictory.

[0244] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of the features. In the description of the present invention, the meaning of "plurality" is at least two, such as two, three, etc., unless otherwise clearly and specifically defined.

Claims

1. A quantum key distribution method, characterized in that: The method is implemented in quantum communication devices of both the sender and the receiver participating in the quantum key distribution process, and the method comprises: Determine a target authentication stage in which the sender and the receiver need to perform information authentication; In the target authentication phase, the sender signs the first information to be authenticated and the first random number using the HBS algorithm using the corresponding first private key to obtain a first signature result, and sends the first signature result, the first information and the first random number to the receiver; The receiver uses the first public key of the sender to verify the first signature result, the first information and the first random number through the HBS algorithm. If the verification is successful, the sender is determined to have passed the authentication. Otherwise, the sender is determined to have failed the authentication and the quantum key distribution process is terminated, wherein the first private key and the first public key are generated by the sender through the HBS algorithm.

2. The method according to claim 1, characterized in that The target authentication phase of determining that the sender and the receiver need to perform information authentication includes: The sender and the receiver determine the target authentication stage for information authentication through negotiation; or The target authentication stage at which the sender and the receiver need to perform information authentication is determined according to a predetermined rule.

3. The method according to claim 2, characterized in that The sender and the receiver determine through negotiation the target authentication phase for information authentication, including: The sending party sends a first negotiation message to the receiving party, wherein the first negotiation message includes the candidate authentication stage of the sending party; The receiving party determines a target authentication phase based on the candidate authentication phase, and sends a second negotiation message to the sending party, wherein the second negotiation message includes the target authentication phase; The sender receives the second negotiation message, and determines the target authentication phase based on the second negotiation message.

4. The method according to claim 1, characterized in that: The method further comprises: In the target phase, after the receiving party determines that the sending party has passed the authentication, the receiving party signs the second information to be authenticated and the second random number using the corresponding second private key through the HBS algorithm to obtain a second signature result, and sends the second signature result, the second information and the second random number to the sending party; The sender uses the second public key of the receiver to verify the second signature result, the second information and the second random number through the HBS algorithm. If the verification is successful, the receiver is determined to have passed the authentication and the interaction in the target stage is completed. Otherwise, the receiver is determined to have failed the authentication and the quantum key distribution process is ended, wherein the second private key and the second public key are generated by the receiver through the HBS algorithm.

5. The method according to any one of claims 1 to 4, characterized in that: The target authentication phase includes at least one of the following phases: Mutual authentication and parameter negotiation phase; Base screening stage; Parameter estimation stage; Error correction and verification phase.

6. The method according to claim 1, characterized in that The method further comprises: The sender generates a first public key and a first private key based on the HBS algorithm, and sends a first digital certificate request to a trusted authentication center, where the first digital certificate request includes the first public key and first identity information; The sender receives a first digital certificate sent by the trusted authentication center, wherein the first digital certificate is generated after the trusted authentication center verifies the first identity information, and the first digital certificate includes the first public key and a first certificate signature result, and the first certificate signature result is generated by the trusted authentication center signing the first public key using its private key through the HBS algorithm; The receiver generates a second public key and a second private key based on the HBS algorithm, and sends a second digital certificate request to a trusted authentication center, where the second digital certificate request includes the second public key and second identity information; The recipient receives a second digital certificate sent by the trusted authentication center, wherein the second digital certificate is generated after the trusted authentication center verifies the second identity information, and the second digital certificate includes the second public key and the second certificate signature result, and the second certificate signature result is generated by the trusted authentication center using its private key to sign the second public key through the HBS algorithm.

7. The method according to claim 1, characterized in that Before the receiving party verifies the first signature result, the first information and the first random number by using the first public key of the sending party through the HBS algorithm, the method further includes: The receiving party receives the first digital certificate sent by the sending party; The receiver uses the public key of the trusted certification center to verify the signature result of the first certificate in the first digital certificate through the HBS algorithm, and after the verification is passed, obtains the first public key of the sender in the first digital certificate.

8. A quantum key distribution method, characterized in that: The method is implemented in a sender quantum communication device participating in a quantum key distribution process, and includes: Determine with the recipient the target authentication stage where information authentication is required; In the target authentication phase, the first information to be authenticated and the first random number are signed by using the corresponding first private key through the HBS algorithm to obtain a first signature result, and the first signature result, the first information and the first random number are sent to the recipient, wherein the first private key is generated by the HBS algorithm; Receiving a second signature result, second information, and second random number sent by the recipient; The second signature result, the second information and the second random number are verified by using the second public key of the recipient through the HBS algorithm. If the verification passes, it is determined that the recipient has passed the authentication and the interaction in the target stage is completed, wherein the second public key is generated by the recipient through the HBS algorithm.

9. A quantum key distribution method, characterized in that: The method is implemented in a receiving quantum communication device participating in a quantum key distribution process, and includes: Determine with the sender the target authentication stage where information authentication is required; In the target authentication phase, receiving a first signature result, a first message and a first random number sent by the sender; The first signature result, the first information and the first random number are verified by using the first public key of the sender through the HBS algorithm. If the verification passes, the second information to be authenticated and the second random number are signed by using the corresponding second private key through the HBS algorithm to obtain a second signature result, and the second signature result, the second information and the second random number are sent to the sender; otherwise, it is determined that the sender has failed the authentication and the quantum key distribution process is terminated, wherein the first public key is generated by the sender through the HBS algorithm and the second private key is generated by the receiver through the HBS algorithm.

10. A quantum communication network system, comprising: A trusted authentication center and multiple quantum communication devices, characterized in that the quantum communication network system realizes mutual authentication of the multiple quantum communication devices through the method described in any one of claims 1-7, thereby realizing the distribution of quantum keys and quantum secure communication between them.

Citation Information

Patent Citations

  • Quantum key distribution method and system for authentication based on post-quantum cryptography algorithm

    CN112152817A

  • Authentication method, quantum key distribution method and device and quantum cryptography network

    CN114710266A

  • Quantum group signature method based on quantum short key cryptography

    CN115174066A

  • Smart grid lightweight identity authentication and key agreement method based on elliptic curve

    CN118713882A

  • Light emitting device, and display apparatus including the same

    KR1020250029748A