A quantum key distribution method and system

By using the HBS algorithm for information authentication in quantum key distribution during the target authentication phase determined by the sender and receiver, the problem of key management complexity is solved, the flexibility of verification and communication efficiency are improved, and the management cost is reduced.

CN119995845BActive Publication Date: 2025-10-31BEIJING ELECTRONICS SCI & TECH INST
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411954965.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-10-31
Estimated Expiration
2044-12-27

AI Technical Summary

Technical Problem

In large-scale networking environments such as metropolitan area networks, existing quantum key distribution technologies suffer from complex key management, a large workload for pre-setting keys, reduced communication efficiency, and limited verification flexibility.

Method used

The HBS algorithm is used to perform information authentication in the target authentication stage determined by the sender and receiver. The HBS algorithm realizes the authentication of quantum key distribution in classical channels, avoids the pre-set key, and improves the flexibility of verification and communication efficiency.

Benefits of technology

While satisfying the data verification requirements of both the sender and receiver, the HBS algorithm enables flexible authentication for quantum key distribution, reducing management costs and improving communication efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995845B_ABST
    Figure CN119995845B_ABST
Patent Text Reader

Abstract

This invention discloses a quantum key distribution method and system. The method includes: determining a target authentication stage where the sender and receiver need to authenticate information; in the target authentication stage, the sender uses its corresponding first private key to sign the first information to be authenticated and a first random number using the HBS algorithm to obtain a first signature result, and sends the first signature result, the first information, and the first random number to the receiver; the receiver uses the sender's first public key to verify the first signature result, the first information, and the first random number using the HBS algorithm. If the verification is successful, the sender is deemed to have passed authentication; otherwise, the sender is deemed to have failed authentication and the quantum key distribution process ends. This invention improves the flexibility of verification while satisfying the data verification requirements of the sender and receiver, and eliminates the need for pre-configured keys, reducing management costs and improving communication efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of quantum communication networks and quantum key distribution technology, and in particular to a quantum key distribution method and system. Background Technology

[0002] Currently, quantum key distribution (QKD) implementations can include quantum channels and classical channels. Quantum channels are used to transmit quantum states, while classical channels are used to transmit information during data post-processing. Both quantum and classical channels are public. However, QKD requires authentication within the classical channel to ensure security; that is, information exchanged during QKD data post-processing needs to be authenticated.

[0003] In existing technologies, a symmetric key can be pre-set before authentication to authenticate the classic channel. The authenticating parties use the key for encryption (signing) and decryption (verification). However, in large-scale networking environments such as metropolitan area networks, this pre-set key pair method results in complex key management relationships, a huge workload for pre-setting keys, increased management costs, and reduced communication efficiency. Furthermore, existing technologies require data verification at each data transmission stage in the classic channel, limiting the flexibility of verification. Summary of the Invention

[0004] The present invention aims to at least partially solve one of the technical problems in the related art.

[0005] To address this, the present invention proposes a quantum key distribution method that enables QKD authentication in classical channels during the target authentication phase, where the sender and receiver determine the information authentication required. This method improves the flexibility of authentication while still allowing the sender and receiver to verify data. Furthermore, it eliminates the need for pre-set keys, reducing management costs and increasing communication efficiency.

[0006] Another objective of this invention is to propose a quantum communication network system.

[0007] To achieve the above objectives, the present invention provides a quantum key distribution method, which is implemented in quantum communication devices of both the sender and receiver participating in the quantum key distribution process. The method includes:

[0008] Determine the target authentication stage where the sender and receiver need to perform information authentication;

[0009] In the target authentication phase, the sender uses the corresponding first private key to sign the first information to be authenticated and the first random number using the HBS algorithm to obtain a first signature result, and then sends the first signature result, the first information, and the first random number to the receiver.

[0010] The receiver uses the sender's first public key to verify the first signature result, the first information, and the first random number using the HBS algorithm. If the verification is successful, the sender is deemed to have passed authentication; otherwise, the sender is deemed to have failed authentication and the quantum key distribution process ends. The first private key and the first public key are generated by the sender using the HBS algorithm.

[0011] The quantum key distribution method of this invention may also have the following additional technical features:

[0012] In one embodiment of the present invention, the target authentication stage of determining the information authentication required by the sender and the receiver includes:

[0013] The sender and the receiver determine the target authentication stage that needs to be performed through negotiation; or

[0014] The target authentication stage for information authentication between the sender and the receiver is determined according to predetermined rules.

[0015] In one embodiment of the present invention, the sender and the receiver determine, through negotiation, the target authentication stage that requires information authentication, including:

[0016] The sender sends a first negotiation message to the receiver, wherein the first negotiation message includes the sender's candidate authentication phase;

[0017] The receiver determines the target authentication stage based on the candidate authentication stage and sends a second negotiation message to the sender, wherein the second negotiation message includes the target authentication stage;

[0018] The sender receives the second negotiation message and determines the target authentication stage based on the second negotiation message.

[0019] In one embodiment of the present invention, the method further includes:

[0020] In the target stage, after the receiver determines that the sender has passed the authentication, the receiver uses the corresponding second private key to sign the second information to be authenticated and the second random number using the HBS algorithm to obtain a second signature result, and sends the second signature result, the second information and the second random number to the sender;

[0021] The sender uses the receiver's second public key to verify the second signature result, the second information, and the second random number using the HBS algorithm. If the verification is successful, the receiver is deemed to have passed authentication and the interaction in the target stage is completed. Otherwise, the receiver is deemed to have failed authentication and the quantum key distribution process ends. The second private key and the second public key are generated by the receiver using the HBS algorithm.

[0022] In one embodiment of the present invention, the target authentication phase includes at least one of the following phases:

[0023] Mutual verification certificate and parameter negotiation phase;

[0024] Basic screening stage;

[0025] Parameter estimation stage;

[0026] Error correction and verification phase.

[0027] In one embodiment of the present invention, the method further includes:

[0028] The sender generates a first public key and a first private key based on the HBS algorithm, and sends a first digital certificate request to a trusted authentication center. The first digital certificate request includes the first public key and first identity information.

[0029] The sender receives a first digital certificate sent by the trusted authentication center, wherein the first digital certificate is generated by the trusted authentication center after verifying the first identity information, and the first digital certificate includes the first public key and the first certificate signature result, wherein the first certificate signature result is generated by the trusted authentication center using its private key to sign the first public key using the HBS algorithm;

[0030] The recipient generates a second public key and a second private key based on the HBS algorithm, and sends a second digital certificate request to the trusted authentication center. The second digital certificate request includes the second public key and the second identity information.

[0031] The recipient receives a second digital certificate sent by the trusted authentication center. The second digital certificate is generated by the trusted authentication center after verifying the second identity information. The second digital certificate includes the second public key and the second certificate signature result. The second certificate signature result is generated by the trusted authentication center using its private key to sign the second public key using the HBS algorithm.

[0032] In one embodiment of the present invention, before the receiver verifies the first signature result, the first information, and the first random number using the sender's first public key via the HBS algorithm, the method further includes:

[0033] The receiver receives the first digital certificate sent by the sender.

[0034] The recipient uses the public key of the trusted authentication center to verify the signature result of the first certificate in the first digital certificate through the HBS algorithm, and after the verification is successful, obtains the first public key of the sender in the first digital certificate.

[0035] Another aspect of the present invention proposes a quantum key distribution method, which is implemented in a sending quantum communication device participating in the quantum key distribution process, comprising:

[0036] Determine the target authentication stage with the recipient;

[0037] In the target authentication phase, the first information to be authenticated and the first random number are signed using the HBS algorithm with the corresponding first private key to obtain a first signature result, and the first signature result, the first information and the first random number are sent to the receiver, wherein the first private key is generated by the HBS algorithm;

[0038] Receive the second signature result, second information, and second random number sent by the recipient;

[0039] The second signature result, the second information, and the second random number are verified using the HBS algorithm using the recipient's second public key. If the verification is successful, the recipient is deemed to have passed authentication and completed the interaction in the target stage. The second public key is generated by the recipient using the HBS algorithm.

[0040] Another aspect of the present invention proposes a quantum key distribution method, which is implemented in a receiving quantum communication device participating in the quantum key distribution process, comprising:

[0041] Determine the target authentication stage that requires information authentication with the sender;

[0042] During the target authentication phase, the sender receives a first signature result, first information, and a first random number.

[0043] The first signature result, the first information, and the first random number are verified using the HBS algorithm with the first public key of the sender. If the verification is successful, the second signature result is obtained by signing the second information and the second random number to be authenticated using the corresponding second private key with the HBS algorithm. The second signature result, the second information, and the second random number are then sent to the sender. Otherwise, the sender is deemed to have failed authentication, and the quantum key distribution process ends. The first public key is generated by the sender using the HBS algorithm, and the second private key is generated by the receiver using the HBS algorithm.

[0044] Another aspect of the present invention proposes a quantum key distribution device, which is incorporated in a sending quantum communication device participating in the quantum key distribution process. The device comprises:

[0045] The determination module is used to determine with the recipient the target authentication stage that requires information authentication.

[0046] The sending module is used in the target authentication stage to use the corresponding first private key to sign the first information to be authenticated and the first random number using the HBS algorithm to obtain a first signature result, and to send the first signature result, the first information and the first random number to the receiver, wherein the first private key is generated by the HBS algorithm;

[0047] The receiving module is used to receive the second signature result, the second information, and the second random number sent by the receiver;

[0048] The verification module is used to verify the second signature result, the second information, and the second random number using the recipient's second public key and the HBS algorithm. If the verification is successful, the recipient is determined to have passed authentication and completed the interaction in the target stage. The second public key is generated by the recipient using the HBS algorithm.

[0049] Another aspect of the present invention proposes a quantum key distribution device, which is incorporated in a receiving quantum communication device participating in the quantum key distribution process. The device comprises:

[0050] The confirmation module is used to determine with the sender the target authentication stage that requires information authentication.

[0051] The receiving module is configured to receive, during the target authentication phase, the first signature result, the first information, and the first random number sent by the sender;

[0052] The verification module is used to verify the first signature result, the first information, and the first random number using the HBS algorithm with the sender's first public key. If the verification is successful, the module uses the corresponding second private key to sign the second information and the second random number to be authenticated using the HBS algorithm to obtain a second signature result, and sends the second signature result, the second information, and the second random number to the sender. Otherwise, the module determines that the sender has failed authentication and ends the quantum key distribution process. The first public key is generated by the sender using the HBS algorithm, and the second private key is generated by the receiver using the HBS algorithm.

[0053] To achieve the above objectives, another aspect of the present invention proposes a quantum communication network system, which includes a trusted authentication center and multiple quantum communication devices. The quantum communication network system is characterized in that the multiple quantum communication devices mutually authenticate each other through the method described in any one of the preceding claims, thereby enabling the distribution of quantum keys and quantum secure communication between them.

[0054] The quantum key distribution method and system of this invention can achieve QKD communication authentication in classical channels through the HBS algorithm during the target authentication stage where the sender and receiver determine the information authentication required. This improves the flexibility of authentication while satisfying the data verification requirements of the sender and receiver, and at the same time, it eliminates the need for pre-set keys, reduces management costs, and improves communication efficiency.

[0055] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0056] The above and / or additional aspects and advantages of the present invention will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, wherein:

[0057] Figure 1 This is a flowchart of a quantum key distribution method according to an embodiment of the present invention;

[0058] Figure 2 This is an interactive flowchart of a quantum key distribution method according to another embodiment of the present invention;

[0059] Figure 3 This is an interactive flowchart of a quantum key distribution method according to another embodiment of the present invention;

[0060] Figure 4 This is an interactive flowchart of a quantum key distribution method according to another embodiment of the present invention;

[0061] Figure 5 This is a flowchart of a quantum key distribution method according to another embodiment of the present invention;

[0062] Figure 6 This is a flowchart of a quantum key distribution method according to another embodiment of the present invention;

[0063] Figure 7 This is a flowchart of a quantum key distribution device according to another embodiment of the present invention;

[0064] Figure 8 This is a flowchart of a quantum key distribution device according to another embodiment of the present invention. Detailed Implementation

[0065] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0066] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0067] The quantum key distribution method and system proposed according to embodiments of the present invention are described below with reference to the accompanying drawings.

[0068] Figure 1 This is a flowchart of a quantum key distribution method according to an embodiment of the present invention.

[0069] like Figure 1 As shown, this method is implemented in the quantum communication devices of both the sender and receiver participating in the quantum key distribution process, and the method may include:

[0070] Step 101: Determine the target authentication stage for which the sender and receiver need to perform information authentication.

[0071] In one embodiment of the present invention, the sender and receiver need to perform information authentication in a classic channel. There are multiple data transmission stages in the classic channel. Based on this, the target authentication stage that the sender and receiver need to perform information authentication can be determined before the sender and receiver perform information authentication in the classic channel.

[0072] In one embodiment of the present invention, the method for determining the target authentication stage for information authentication that the sender and receiver need to perform may include: the sender and receiver determining the target authentication stage for information authentication through negotiation; or determining the target authentication stage for information authentication that the sender and receiver need to perform according to predetermined rules.

[0073] Specifically, in one embodiment of the present invention, the method by which the sender and receiver determine the target authentication stage that needs to be performed through negotiation may include the following steps:

[0074] Step 1: The sender sends a first negotiation message to the receiver, wherein the first negotiation message includes the sender's candidate authentication phase;

[0075] Step 2: The receiver determines the target authentication stage based on the candidate authentication stages and sends a second negotiation message to the sender, wherein the second negotiation message includes the target authentication stage;

[0076] Step 3: The sender receives the second negotiation message and determines the target authentication phase based on the second negotiation message.

[0077] In one embodiment of the present invention, the candidate authentication stage can be understood as the stage in which the sender initially determines the information that needs to be authenticated.

[0078] Understandably, after the sender sends the first negotiation message to the receiver, the receiver can select the target authentication stage from the candidate authentication stages according to its own needs, and then send a second negotiation message to the sender, which carries the target authentication stage determined by the receiver. After receiving the second negotiation message from the receiver, the sender confirms the target authentication stage carried in the second negotiation message as the target authentication stage that needs to be authenticated.

[0079] For example, in one embodiment of the present invention, after the sender sends a first negotiation message to the receiver, if the receiver confirms that the candidate authentication stage carried therein is feasible, the sender determines the candidate authentication stage in the first negotiation message as the target authentication stage and sends a second negotiation message to the sender. Upon receiving the second negotiation message sent by the receiver, the sender can determine that the receiver agrees to the candidate authentication stage, and thus can determine the candidate authentication stage as the target authentication stage finally negotiated.

[0080] In another embodiment of the present invention, the target authentication stage that the sender and receiver need to perform information authentication can be determined according to predetermined rules. That is, before the sender and receiver perform quantum key distribution, the target authentication stage that needs to perform information authentication can be preset according to experience, so that the sender and receiver can directly perform information authentication in the target authentication stage.

[0081] Furthermore, in one embodiment of the present invention, the above-mentioned target authentication stage may include at least one of the following stages:

[0082] Mutual verification certificate and parameter negotiation phase;

[0083] Basic screening stage;

[0084] Parameter estimation stage;

[0085] Error correction and verification phase.

[0086] It should be noted that, in one embodiment of the present invention, if the target authentication stage includes two stages, the target authentication stage needs to include an error correction verification stage and a parameter estimation stage, so that the receiver and the sender can perform signature verification on all received parameters.

[0087] Step 102: In the target authentication phase, the sender uses the corresponding first private key to sign the first information to be authenticated and the first random number using the HBS algorithm to obtain the first signature result, and sends the first signature result, the first information, and the first random number to the receiver.

[0088] In one embodiment of the present invention, after determining the target authentication stage through the above steps, the sender and receiver can perform information authentication using the HBS algorithm during the target authentication stage to complete the interaction during the target authentication stage. In one embodiment of the present invention, the HBS algorithm may include HBS algorithms based on international standards and / or national standards.

[0089] Furthermore, in one embodiment of the present invention, before the sender and receiver interact during the target authentication phase, the above method may further include the following steps:

[0090] Step a: The sender generates a first public key and a first private key based on the HBS algorithm, and sends a first digital certificate request to the trusted certification center. The first digital certificate request includes the first public key and the first identity information.

[0091] Step b, the sender receives the first digital certificate sent by the trusted authentication center, wherein the first digital certificate is generated by the trusted authentication center after verifying the first identity information. The first digital certificate includes the first public key and the first certificate signature result. The first certificate signature result is generated by the trusted authentication center using its private key to sign the first public key using the HBS algorithm.

[0092] Step c: The recipient generates a second public key and a second private key based on the HBS algorithm, and sends a second digital certificate request to the trusted certification authority. The second digital certificate request includes the second public key and the second identity information.

[0093] Step d: The recipient receives the second digital certificate sent by the trusted authentication center. The second digital certificate is generated by the trusted authentication center after verifying the second identity information. The second digital certificate includes the second public key and the second certificate signature result. The second certificate signature result is generated by the trusted authentication center using its private key to sign the second public key using the HBS algorithm.

[0094] In one embodiment of the present invention, the first identity information may include the sender's IP address, name, and device information; the second identity information may include the receiver's IP address, name, and device information. Furthermore, in another embodiment of the present invention, after receiving the first and second identity information, the trusted authentication center can verify whether the identities of the sender and receiver comply with the system's security specifications through an authentication mechanism. The verification process involves checking the user's legitimacy and verifying the authenticity of the user's identity. After successful verification, the trusted authentication center issues a first digital certificate to the sender and a second digital certificate to the receiver using the HBS algorithm. The first digital certificate includes a first public key and a first certificate signature result, generated by the trusted authentication center using its private key to sign the first public key using the HBS algorithm. The second digital certificate includes a second public key and a second certificate signature result, generated by the trusted authentication center using its private key to sign the second public key using the HBS algorithm, thereby ensuring the trustworthiness of identities during communication.

[0095] Furthermore, in one embodiment of the present invention, when the target authentication stage is different, the first information that needs to be authenticated in the target authentication stage is also different.

[0096] For example, in one embodiment of the present invention, assuming that the target authentication phase includes a mutual authentication certificate and a parameter negotiation phase, the sender uses the corresponding first private key SK. B The first random number R is processed using the HBS signature algorithm. B With the first information n that needs to be authenticated B Perform the signing to obtain the first signature value SIG B0 =Sig HBS (SK B R B n B ), and will the first digital certificate Cert B With the first random number R B First signature value SIG B0 First information n B Send to the recipient.

[0097] In one embodiment of the present invention, the first random number is randomly generated by the sender to prevent replay attacks during data transmission.

[0098] Step 103: The receiver uses the sender's first public key to verify the first signature result, the first information, and the first random number using the HBS algorithm. If the verification is successful, the sender is deemed to have passed authentication; otherwise, the sender is deemed to have failed authentication and the quantum key distribution process ends.

[0099] In one embodiment of the present invention, during the target authentication phase, after the receiver receives the first signature result, the first information and the first random number sent by the sender, the receiver can verify the received first signature result, the first information and the first random number. If the verification is successful, the sender is determined to have passed authentication; otherwise, the sender is determined to have failed authentication and the current quantum key distribution process ends.

[0100] Specifically, in one embodiment of the present invention, the first signature result can be verified using the HBS algorithm with the sender's first public key. If the verification is successful, the sender is determined to be authenticated; otherwise, the sender is determined to be unauthenticated and the quantum key distribution process ends.

[0101] For example, in one embodiment of the present invention, the recipient receives a first digital certificate Cert. B With the first random number R B First signature value SIG B0 First information n B Then, the sender's first digital certificate, Cert, can be verified using the public key of a publicly obtained trusted certification authority. B And after successful verification, the sender's first public key PK is used. B If the first signature value is verified using the HBS signature verification algorithm, the sender is deemed to be authenticated; otherwise, the sender is deemed to be unauthenticated and the quantum key distribution process ends.

[0102] Furthermore, in one embodiment of the present invention, before the recipient verifies the first signature result, the first information, and the first random number using the sender's first public key via the HBS algorithm, the method may further include the following steps:

[0103] Step 1: The recipient receives the first digital certificate sent by the sender;

[0104] Step 2: The recipient uses the public key of the trusted certification authority to verify the signature result of the first certificate in the first digital certificate using the HBS algorithm, and after successful verification, obtains the sender's first public key in the first digital certificate.

[0105] In one embodiment of the present invention, the recipient's identity can be authenticated through the above steps, and after the identity authentication is successful, the first public key of the trusted sender in the first digital certificate can be obtained so that the recipient can use the first public key of the sender for subsequent verification.

[0106] It should be noted that, in one embodiment of the present invention, the above steps can be performed in the mutual verification certificate and parameter negotiation stage to authenticate the sender's identity through the first digital certificate, and after the sender's identity is successfully authenticated in the mutual verification certificate and parameter negotiation stage, there is no need to perform repeated authentication in subsequent stages.

[0107] Furthermore, in one embodiment of the present invention, after determining that the sender has passed authentication, the above method may further include the following steps:

[0108] Step 104: In the target stage, after the receiver determines that the sender has passed the authentication, the receiver uses the corresponding second private key to sign the second information to be authenticated and the second random number using the HBS algorithm to obtain the second signature result, and sends the second signature result, the second information and the second random number to the sender.

[0109] Step 105: The sender uses the receiver's second public key to verify the second signature result, the second information, and the second random number using the HBS algorithm. If the verification is successful, the receiver is deemed to have passed authentication and the interaction in the target stage is completed. Otherwise, the receiver is deemed to have failed authentication and the quantum key distribution process ends.

[0110] In one embodiment of the present invention, before the sender verifies the second signature result, the second information, and the second random number using the recipient's second public key via the HBS algorithm, the sender can authenticate the recipient's identity using the recipient's second data certificate. After successful authentication, the sender obtains the recipient's trusted second public key from the second data. For details regarding this part, please refer to the detailed description in the above embodiments; this disclosure will not elaborate further.

[0111] For details regarding steps 104 to 105, please refer to the above embodiments for a detailed description. This disclosure will not repeat the details here.

[0112] For example, in one embodiment of the present invention, assuming that the target stage includes a mutual authentication certificate and parameter negotiation stage, after the receiver determines that the sender has passed authentication, the receiver uses the corresponding second private key SK. A R is analyzed using the HBS algorithm. B R A n A Perform the signing to obtain the second signature value SIG A0 and the second digital certificate CertA With the second random number R A Second signature value SIG A0 Second information n A Send to the sender.

[0113] And, the sender receives the second digital certificate Cert. A With the second random number R A Second signature value SIG A0 Second information n A Then, the recipient's second digital certificate, Cert, can be verified using the public key of a trusted certification authority. A And after successful verification, the recipient's second public key PK is used. A If the second signature value is verified using the HBS signature verification algorithm, the sender is deemed to be authenticated; otherwise, the sender is deemed to have failed authentication, and the quantum key distribution process ends. Therefore, if the aforementioned target stage includes a mutual verification certificate and parameter negotiation stage, it is necessary to first verify the first or second digital certificate, and after completing the identity verification of both parties, verify the first or second signature value to ensure the security of transmitted data and prevent its corruption.

[0114] It should be noted that, in one embodiment of the present invention, the security of the HBS algorithm relies on the resistance to second preimages of the underlying hash function (i.e., given a hash value Y, finding two distinct inputs X and X' such that H(X) = H(X') is extremely difficult). The hash function is constructed based on simple and time-tested algorithmic principles; its security does not depend on complex mathematical structures but rather on the collision resistance of the hash function. Therefore, the HBS algorithm provides more robust security against quantum computing and is not as susceptible to its effects as other problem-based PQC algorithms (such as lattice cryptography). Thus, adopting the HBS algorithm does not increase the security dependence of the QKD system. The HBS algorithm has a significant advantage in resisting quantum computing attacks and can more effectively defend against potential attacks from future quantum computers. It solves the threat of quantum computing to problem-based PQC algorithms and the management complexity of symmetric key authentication, providing higher security and ensuring the reliability and long-term effectiveness of the authentication process, thus providing a more solid guarantee for the security of quantum key distribution networks.

[0115] This invention proposes a quantum key distribution method, which includes: determining a target authentication stage where the sender and receiver need to authenticate information; in the target authentication stage, the sender uses its corresponding first private key to sign the first information to be authenticated and a first random number using the HBS algorithm to obtain a first signature result, and sends the first signature result, the first information, and the first random number to the receiver; the receiver uses the sender's first public key to verify the first signature result, the first information, and the first random number using the HBS algorithm. If the verification is successful, the sender is deemed to have passed authentication; otherwise, the sender is deemed to have failed authentication and the quantum key distribution process ends. The first private key and the first public key are generated by the sender using the HBS algorithm. Therefore, this invention can achieve QKD authentication in classical channels during the target authentication stage where the sender and receiver determine the information authentication needs, thereby improving the flexibility of authentication while eliminating the need for pre-set keys, reducing management costs, and improving communication efficiency.

[0116] Based on the above description Figure 2 This is an interactive flowchart of the quantum key distribution method proposed in an embodiment of the present invention.

[0117] The quantum communication device deployed at the sending end is called Alice, and the quantum communication device deployed at the receiving end is called Bob. The target authentication phase includes the mutual verification certificate and parameter negotiation phase, the basis screening phase, the parameter estimation phase, and the error correction verification phase.

[0118] Step 201: Alice sends qubits r1 and r0 to Bob through the quantum channel;

[0119] The first qubit r1 is called the "generated base bit". If the "generated base bit" is 0, the "X base" (+45° and -45° directions) is selected. If the "generated base bit" is 1, the "Z base" (0° and 90° directions) is selected to encode each qubit.

[0120] Furthermore, the second qubit r0 is called the "key bit." After selecting the measurement basis, the "key bit" determines which quantum state Alice sends. Specifically, when the "X basis" is selected, a key bit of 0 will cause Alice to send a quantum state of "+45°," while a key bit of 1 will cause Alice to send a quantum state of "-45°." When the generation basis is selected as "Z basis," a key bit of 0 will cause Alice to send a polarization in the 0° direction, while a key bit of 1 will cause Alice to send a polarization in the 90° direction. Table 1 is a qubit correspondence table proposed in an embodiment of the present invention.

[0121] Table 1

[0122]

[0123]

[0124] Step 202: After Bob receives the qubit sent by Alice, he uses a random number bit r3 as the measurement basis bit.

[0125] The measurement can be performed by selecting the base bit. If the base bit is 0, the measurement is performed using the "X base"; if the base bit is 1, the measurement is performed using the "Z base".

[0126] Furthermore, during the specific measurement, if Bob's measured base bits match Alice's generated base bits (for example, Alice and Bob both chose "Z base" or both chose "X base"), then Bob's measurement result will match the key bits sent by Alice, thus preserving valid information; if Bob's measured base bits differ from Alice's generated base bits (for example, one chose "Z base" while the other chose "X base"), the measurement result will be a random value, and both parties will discard the mismatched measurement results in the subsequent base filtering steps.

[0127] Furthermore, in the quantum communication process, Alice uses all r1 to form the generating basis sequence L1, and Bob uses all r2 to form the generating basis sequence L2.

[0128] Step 203, Bob generates a random number R. B (The first random number in the above embodiments), and create a capability list n based on the device and function library. B ;

[0129] Step 204, Bob uses the corresponding private key SK B (The first private key in the above embodiment) is used to verify R via the HBS algorithm. B With n B Perform the signing to obtain the first signature value SIG B0 =Sig HBS (SK B R B n B (The first signature value in the above embodiments);

[0130] Step 205, Bob will print the digital certificate Cert. B R B SIG B0 and n B Send to Alice;

[0131] Step 206, Alice receives Cert B With R BSIG B0 and n B Then, Bob's certificate Cert is verified using the publicly obtained public key of a trusted certification authority and the HBS algorithm. B After successful verification, use Bob's certificate Cert. B Public key PK B Verify signature using HBS algorithm SIG B0 ;

[0132] Step 207: After confirming Bob's identity, Alice uses Bob's list of abilities... B Determine the functions and related parameters used in the data post-processing procedure, and generate the corresponding capability list n. A And generate random number R A (The second random number in the above embodiments);

[0133] Step 208, Alice uses the corresponding private key SK A R is analyzed using the HBS algorithm. B R A n A Perform the signing to obtain the second signature value SIG A0 =Sig HBS (SK A R B R A n A );

[0134] Step 209, Alice will send the digital certificate Cert. A With R A SIG A0 n A Send to Bob;

[0135] Step 210, Bob receives Cert A With R A SIG A0 n A Then, Alice's certificate Cert is verified using the public key obtained from a publicly trusted certification authority. A and using Alice certificate Cert A Public key PK A (The second public key in the above embodiments) and HBS algorithm verification signature SIG A0 Once verified, Alice's identity can be confirmed.

[0136] Among them, the mutual verification certificate and parameter negotiation stage is completed through the above steps 203 to 210.

[0137] Step 211, Bob uses the corresponding private key SK BRandom number R is generated using the HBS algorithm. A The third signature value SIG is obtained by signing the measurement basis sequence L2. B1 =Sig HBS (SK B R A L2);

[0138] Step 212, Bob connects L2 with SIG B1 Send to Alice;

[0139] Step 213, Alice receives L2 and SIG B1, Then, use Bob's certificate Cert. B Public key PK B R A L2, SIG B1 Verify the third signature value SIG using the HBS algorithm B1 After successful verification, Alice obtained the measurement basis sequence L2 used in Bob's quantum teleportation process;

[0140] In the aforementioned data transmission process, a signature algorithm was used to ensure that L2 was intact and not tampered with.

[0141] Step 214, Alice uses the corresponding private key SK A Random number R is generated using the HBS algorithm. B The fourth signature value SIG is obtained by signing the generating base sequence L1. A1 =Sig HBS (SK A R B L1);

[0142] Step 215, Alice connects L1 and SIG A1 Send to Bob;

[0143] Step 216, Bob receives L1 and SIG A1 Then, use the Alice certificate Cert. A Public key PK A R B L1, SIG A1 Verify the fourth signature value SIG using the HBS algorithm A1 After the verification was successful, Bob obtained the generating basis sequence L1 used by Alice in the quantum teleportation process;

[0144] The basic screening stage is completed through steps 211 to 216 above.

[0145] In the aforementioned data transmission process, a signature algorithm was used to ensure that L1 was intact and had not been tampered with.

[0146] Furthermore, Bob uses the generation base sequence L1 provided by Alice to filter the bits he receives, retaining the bits that match Alice's generation base sequence L1, thus forming the corresponding original key Key. B Similarly, Alice filters the bits she sends based on the generation basis measurement sequence L2 provided by Bob, retaining bits that match Bob's measurement basis sequence L2, and performs basis filtering to form the corresponding original key Key. A If the quantum channel for quantum transmission is an ideal channel with no transmission errors, then Key A and Key B They are exactly the same, but quantum channels are not ideal channels without transmission errors. Based on this, Key A and Key B They are not exactly the same. A parameter estimation process is needed to calculate the transmission error rate, and then error correction verification is performed to ensure that both parties obtain the exact same original key.

[0147] Step 217, Bob generates a random number sequence L. B (e.g., [5, 12, 29, ...]), and according to L B In Key B Select the corresponding bits to form a bit string r B ;

[0148] Among them, the above random number sequence L B The random number represents the position of the bit randomly selected from the original key for parameter estimation.

[0149] Step 218, Bob uses the corresponding private key SK B Random number R is generated using the HBS algorithm. A Random number sequence L B With bit string r B The fifth signature value, SIG, is obtained by performing the signature. B2 =Sig HBS (SK B R A L B r B );

[0150] Step 219, Bob will L B With SIG B2 Send to Alice;

[0151] Step 220, Alice receives L B With SIG B2 Then, use Bob's certificate Cert. B Public key PK B RA L B r B SIG B1 Verify the fifth signature value SIG using the HBS algorithm B2 After successful verification, Alice obtained the random number sequence L used in Bob's quantum teleportation process. B With bit string r B ;

[0152] In the aforementioned data transmission process, a signature algorithm was used to ensure L B With r B It is complete and has not been tampered with.

[0153] And, Alice according to L B In Key A Select the corresponding bits to form a bit string r B ', according to r B 'and r B Calculate the bit error rate. If the bit error rate exceeds a preset threshold, communication is terminated; if the bit error rate is lower than the preset threshold, the subsequent steps continue for error correction and verification.

[0154] The parameter estimation stage is completed through steps 217 to 220 above.

[0155] Step 221, Alice uses the original key Key A Delete L B The corresponding bits form a bit string r B Assuming the remaining key length is N, we obtain the key X. N Use error correction codes for X N Encode the error correction information Q;

[0156] Step 222, Alice uses the corresponding private key SK A Random number R is generated using the HBS algorithm. B With error correction information Q and key X N The sixth signature value, SIG, is obtained by performing the signature. A2 =Sig HBS (SK A R B Q, X N );

[0157] Step 223, Alice sets Q and SIG A2 Send to Bob;

[0158] Step 224, Bob receives Q and SIG A2 Then, in the original key Key B Delete L B The corresponding bits form a bit string rB Assuming the remaining key length is N, the key Y is obtained. N Using error correction codes and error correction information Q to correct Y N Error correction yields X N Using Alice Certificate Cert A Public key PK A R B Q, X N SIG A1 Verify the sixth signature value SIG using the HBS algorithm. A2 After successful verification, Alice and Bob possess the same key X. N ;

[0159] Error correction verification can be performed using polar codes, which will not be elaborated upon in this embodiment.

[0160] The error correction and verification phase is completed through steps 221 to 224 above.

[0161] Step 225: Alice calculates the amount of key exposed during the data processing, compresses it using the privacy amplification method, and obtains the final key s;

[0162] Step 226: Bob calculates the amount of key exposed during the data processing, compresses it using the privacy amplification method, and obtains the final key s.

[0163] In one embodiment of the present invention, the privacy amplification method in steps 225 and 226 is the same as that in the prior art, and will not be described in detail here.

[0164] Based on the above description Figure 3 This is an interactive flowchart of the quantum key distribution method proposed in an embodiment of the present invention.

[0165] The quantum communication device deployed on the sending side is called Alice, and the quantum communication device deployed on the receiving side is called Bob. The target authentication phase includes the mutual verification certificate and parameter negotiation phase, the parameter estimation phase, and the error correction verification phase.

[0166] Step 301: Alice sends qubits r1 and r0 to Bob through the quantum channel;

[0167] Step 302: After Bob receives the qubit sent by Alice, he uses a random number bit r3 as the measurement basis bit.

[0168] Step 303, Bob generates a random number R. B (The first random number in the above embodiments), and create a capability list n based on the device and function library. B ;

[0169] Step 304, Bob uses the corresponding private key SK B (The first private key in the above embodiment) is used to verify R via the HBS algorithm. B With n B Perform the signing to obtain the first signature value SIG B0 =Sig HBS (SK B R B n B (The first signature value in the above embodiments);

[0170] Step 305, Bob will print the digital certificate Cert. B R B SIG B0 and n B Send to Alice;

[0171] Step 306, Alice receives Cert B With R B SIG B0 and n B Then, Bob's certificate Cert is verified using the publicly obtained public key of a trusted certification authority and the HBS algorithm. B After successful verification, use Bob's certificate Cert. B Public key PK B Verify signature using HBS algorithm SIG B0 ;

[0172] Step 307: After confirming Bob's identity, Alice uses Bob's list of abilities... B Determine the functions and related parameters used in the data post-processing procedure, and generate the corresponding capability list n. A And generate random number R A (The second random number in the above embodiments);

[0173] Step 308, Alice uses the corresponding private key SK A R is analyzed using the HBS algorithm. B R A n A Perform the signing to obtain the second signature value SIG A0 =Sig HBS (SK A R B R A n A );

[0174] Step 309, Alice will send the digital certificate Cert. A With R A SIGA0 n A Send to Bob;

[0175] Step 310, Bob receives Cert A With R A SIG A0 n A Then, Alice's certificate Cert is verified using the public key obtained from a publicly trusted certification authority. A and using Alice certificate Cert A Public key PK A (The second public key in the above embodiments) and HBS algorithm verification signature SIG A0 Once verified, Alice's identity can be confirmed.

[0176] Among them, the mutual verification certificate and parameter negotiation stage is completed through the above steps 303 to 310.

[0177] Step 311, Bob sends the measurement basis sequence L2 to Alice;

[0178] Step 312: After receiving L2, Alice sends the generated base sequence L1 to Bob;

[0179] The basic screening stage is completed through steps 311 to 312 above.

[0180] Step 313: After receiving L1, Bob generates a random number sequence L. B (e.g., [5, 12, 29, ...]), and according to L B In Key B Select the corresponding bits to form a bit string r B ;

[0181] Among them, the above random number sequence L B The random number represents the position of the bit randomly selected from the original key for parameter estimation.

[0182] Step 314, Bob uses the corresponding private key SK B Random number R is generated using the HBS algorithm. A , base sequence L2, random number sequence L B With bit string r B The third signature value SIG is obtained by performing the signature. B1 =Sig HBS (SK B R A L2, L B r B );

[0183] Step 315, Bob will L B With SIG B1 Send to Alice;

[0184] Step 316, Alice receives L B With SIG B1 Then, use Bob's certificate Cert. B Public key PK B R A L2, L B r B SIG B1 Verify the third signature value SIG using the HBS algorithm B1 After successful verification, Alice obtained the random number sequence L used in Bob's quantum teleportation process. B With bit string r B ;

[0185] The parameter estimation stage is completed through steps 313 to 316 above.

[0186] Step 317, Alice uses the original key Key A Delete L B The corresponding bits form a bit string r B Assuming the remaining key length is N, we obtain the key X. N Use error correction codes for X N Encode the error correction information Q;

[0187] Step 318, Alice uses the corresponding private key SK A Random number R is generated using the HBS algorithm. B The base sequence L1, the error correction information Q, and the key X N The fourth signature value SIG is obtained by performing the signature. A1 =Sig HBS (SK A R B L1, Q, X N );

[0188] Step 319, Alice sets Q and SIG A1 Send to Bob;

[0189] Step 320, Bob receives Q and SIG A1 Then, in the original key Key B Delete L B The corresponding bits form a bit string r B Assuming the remaining key length is N, the key Y is obtained. N Using error correction codes and error correction information Q to correct Y N Error correction yields XN Using Alice Certificate Cert A Public key PK A R B L1, Q, X N SIG A1 Verify the fourth signature value SIG using the HBS algorithm. A1 After successful verification, Alice and Bob possess the same key X. N ;

[0190] The error correction and verification phase is completed through steps 317 to 320 above.

[0191] Step 321: Alice calculates the amount of key exposed during the data processing, compresses it using the privacy amplification method, and obtains the final key s;

[0192] Step 322: Bob calculates the amount of key exposed during the data processing, compresses it using the privacy amplification method, and obtains the final key s.

[0193] Based on the above description Figure 4 This is an interactive flowchart of the quantum key distribution method proposed in an embodiment of the present invention.

[0194] The quantum communication device deployed at the sending end is called Alice, and the quantum communication device deployed at the receiving end is called Bob. The target authentication phase includes the error correction and verification phase.

[0195] Step 401, Alice sends qubits r1 and r0 to Bob through the quantum channel;

[0196] Step 402: After Bob receives the qubit sent by Alice, he uses a random number bit r3 as the measurement basis bit.

[0197] Step 403, Bob generates a random number R. B (The first random number in the above embodiments), and create a capability list n based on the device and function library. B ;

[0198] Step 404, Bob will send the digital certificate Cert. B R B and n B Send to Alice;

[0199] Step 405, Alice receives Cert B R B and n B Then, Bob's certificate Cert is verified using the publicly obtained public key of a trusted certification authority and the HBS algorithm. B ;

[0200] Step 406: After confirming Bob's identity, Alice uses Bob's list of abilities... B Determine the functions and related parameters used in the data post-processing procedure, and generate the corresponding capability list n. A And generate random number R A (The second random number in the above embodiments);

[0201] Step 407, Alice will send the digital certificate Cert A R A and n A Send to Bob;

[0202] Step 408, Bob receives Cert A With R A n A Then, Alice's certificate Cert is verified using the public key obtained from a publicly trusted certification authority. A Once verified, Alice's identity can be confirmed.

[0203] The mutual verification certificate and parameter negotiation stage is completed through steps 403 to 408.

[0204] Step 409, Bob sends the measurement base sequence L2 to Alice;

[0205] Step 410: After receiving L2, Alice sends the generated base sequence L1 to Bob;

[0206] The basic screening stage is completed through steps 409 to 410.

[0207] Step 411: After receiving L1, Bob generates a random number sequence L. B (e.g., [5, 12, 29, ...]), and according to L B In Key B Select the corresponding bits to form a bit string r B ;

[0208] Among them, the above random number sequence L B The random number represents the position of the bit randomly selected from the original key for parameter estimation.

[0209] Step 412, Bob uses the corresponding private key SK B Random number R is generated using the HBS algorithm. A Random number R B n B , base sequence L2, random number sequence L B With bit string r BPerform the signing to obtain the first signature value SIG B =Sig HBS (SK B R A R B n B L2, L B r B );

[0210] Step 413, Bob will L B With SIG B Send to Alice;

[0211] Step 414, Alice receives L B With SIG B Then, use Bob's certificate Cert. B Public key PK B R A R B n B L2, L B r B SIG B Verify the first signature value SIG using the HBS algorithm B After successful verification, Alice obtained the random number sequence L used in Bob's quantum teleportation process. B With bit string r B ;

[0212] The parameter estimation stage is completed through steps 411 to 414 above.

[0213] Step 415, Alice uses the original key Key A Delete L B The corresponding bits form a bit string r B Assuming the remaining key length is N, we obtain the key X. N Use error correction codes for X N Encode the error correction information Q;

[0214] Step 416, Alice uses the corresponding private key SK A Random number R is generated using the HBS algorithm. A Random number R B n A Base sequence L1, error correction information Q, key X N Perform the signing to obtain the second signature value SIG A =Sig HBS (SK A R A R B n A L1, Q, XN );

[0215] Step 417, Alice sets Q and SIG A Send to Bob;

[0216] Step 418, Bob receives Q and SIG A Then, in the original key Key B Delete L B The corresponding bits form a bit string r B Assuming the remaining key length is N, the key Y is obtained. N Using error correction codes and error correction information Q to correct Y N Error correction yields X N Using Alice Certificate Cert A Public key PK A R A R B n A L1, Q, X N SIG A Verify the signature using the HBS algorithm with the second signature value SIG A After successful verification, Alice and Bob possess the same key X. N ;

[0217] The error correction and verification phase is completed through steps 415 to 418 above.

[0218] Step 419: Alice calculates the amount of key exposed during the data processing, compresses it using the privacy amplification method, and obtains the final key s;

[0219] Step 420: Bob calculates the amount of key exposed during the data processing, compresses it using the privacy amplification method, and obtains the final key s.

[0220] Figure 5 This is a flowchart of a quantum key distribution method according to an embodiment of the present invention.

[0221] like Figure 5 As shown, this method is implemented in a sending quantum communication device participating in the quantum key distribution process, and the method may include the following steps:

[0222] Step 501: Determine the target authentication stage that needs to be performed with the recipient;

[0223] Step 502: In the target authentication phase, the first information to be authenticated and the first random number are signed using the HBS algorithm with the corresponding first private key to obtain the first signature result, and the first signature result, the first information and the first random number are sent to the receiver. The first private key is generated by the HBS algorithm.

[0224] Step 503: Receive the second signature result, second information, and second random number sent by the recipient;

[0225] Step 504: Using the recipient's second public key, the second signature result, the second information, and the second random number are verified using the HBS algorithm. If the verification is successful, the recipient is deemed to have passed authentication, completing the interaction in the target stage. The second public key is generated by the recipient using the HBS algorithm.

[0226] Figure 6 This is a flowchart of a quantum key distribution method according to an embodiment of the present invention.

[0227] like Figure 6 As shown, this method is implemented in a receiver quantum communication device participating in the quantum key distribution process, and the method may include the following steps:

[0228] Step 601: Determine the target authentication stage that needs to be performed with the sender;

[0229] Step 602: In the target authentication phase, receive the first signature result, the first information, and the first random number sent by the sender;

[0230] Step 603: Using the sender's first public key, the first signature result, the first information, and the first random number are verified using the HBS algorithm. If the verification is successful, the second signature result is obtained by using the corresponding second private key to sign the second information and the second random number that need to be authenticated using the HBS algorithm. The second signature result, the second information, and the second random number are then sent to the sender. Otherwise, the sender is deemed to have failed authentication, and the quantum key distribution process ends. Here, the first public key is generated by the sender using the HBS algorithm, and the second private key is generated by the receiver using the HBS algorithm.

[0231] Figure 7 This is a schematic diagram of the structure of the quantum key distribution device 10 according to an embodiment of the present invention.

[0232] like Figure 7 As shown, in the quantum communication device of the sender participating in the quantum key distribution process, the device may include:

[0233] The determination module 701 is used to determine with the recipient the target authentication stage that needs to be performed for information authentication.

[0234] The signature module 702 is used in the target authentication phase to sign the first information to be authenticated and the first random number using the HBS algorithm with the corresponding first private key to obtain a first signature result, and to send the first signature result, the first information and the first random number to the receiver. The first private key is generated by the HBS algorithm.

[0235] The receiving module 703 is used to receive the second signature result, the second information, and the second random number sent by the receiver;

[0236] The verification module 704 is used to verify the second signature result, the second information, and the second random number using the receiver's second public key and the HBS algorithm. If the verification is successful, the receiver is deemed to have passed the authentication and completed the interaction in the target stage. The second public key is generated by the receiver using the HBS algorithm.

[0237] Figure 8 This is a schematic diagram of the structure of the quantum key distribution device 20 according to an embodiment of the present invention.

[0238] like Figure 8 As shown, in the receiver quantum communication device participating in the quantum key distribution process, the device may include:

[0239] The determination module 801 is used to determine with the sender the target authentication stage that needs to be performed for information authentication.

[0240] The receiving module 802 is used to receive the first signature result, the first information, and the first random number sent by the sender during the target authentication phase.

[0241] The verification module 803 is used to verify the first signature result, the first information, and the first random number using the sender's first public key and the HBS algorithm. If the verification is successful, the second signature result is obtained by signing the second information and the second random number to be authenticated using the corresponding second private key and the HBS algorithm. The second signature result, the second information, and the second random number are then sent to the sender. Otherwise, the sender is deemed to have failed authentication, and the quantum key distribution process ends. The first public key is generated by the sender using the HBS algorithm, and the second private key is generated by the receiver using the HBS algorithm.

[0242] To implement the above embodiments, this embodiment also provides a quantum communication network system, which includes a trusted authentication center and multiple quantum communication devices. The quantum communication network system is characterized in that it realizes mutual authentication of multiple quantum communication devices through the quantum key distribution method described above, thereby realizing the distribution of quantum keys and quantum secure communication between them.

[0243] In this specification, the use of terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refers to a specific feature, structure, material, or characteristic described in connection with that embodiment or example, which is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0244] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.

Claims

1. A quantum key distribution method, characterized in that, The method is implemented in quantum communication devices of both the sender and receiver participating in the quantum key distribution process, and the method includes: The sender sends a first negotiation message to the receiver, wherein the first negotiation message includes the sender's candidate authentication phase; The receiver determines the target authentication stage based on the candidate authentication stage and sends a second negotiation message to the sender, wherein the second negotiation message includes the target authentication stage, which is the target authentication stage that requires information authentication in the classic channel; The sender receives the second negotiation message and determines the target authentication stage based on the second negotiation message; In the target authentication phase, the sender uses the corresponding first private key to sign the first information to be authenticated and the first random number using the HBS algorithm to obtain a first signature result, and then sends the first signature result, the first information, and the first random number to the receiver. The receiver uses the sender's first public key to verify the first signature result, the first information, and the first random number using the HBS algorithm. If the verification is successful, the sender is deemed to have passed authentication; otherwise, the sender is deemed to have failed authentication and the quantum key distribution process ends. The first private key and the first public key are generated by the sender using the HBS algorithm. After the sender's identity is successfully authenticated in the target authentication stage, no further authentication is required in subsequent stages.

2. The method according to claim 1, characterized in that, The method further includes: In the target authentication phase, after the receiver determines that the sender has passed the authentication, the receiver uses the corresponding second private key to sign the second information to be authenticated and the second random number using the HBS algorithm to obtain a second signature result, and sends the second signature result, the second information and the second random number to the sender. The sender uses the receiver's second public key to verify the second signature result, the second information, and the second random number using the HBS algorithm. If the verification is successful, the receiver is deemed to have passed authentication, completing the interaction in the target authentication phase. Otherwise, the receiver is deemed to have failed authentication, and the quantum key distribution process ends. The second private key and the second public key are generated by the receiver using the HBS algorithm.

3. The method according to any one of claims 1-2, characterized in that, The target authentication phase includes at least one of the following phases: Mutual verification certificate and parameter negotiation phase; Basic screening stage; Parameter estimation stage; Error correction and verification phase.

4. The method according to claim 1, characterized in that, The method further includes: The sender generates a first public key and a first private key based on the HBS algorithm, and sends a first digital certificate request to a trusted authentication center. The first digital certificate request includes the first public key and first identity information. The sender receives a first digital certificate sent by the trusted authentication center, wherein the first digital certificate is generated by the trusted authentication center after verifying the first identity information, and the first digital certificate includes the first public key and the first certificate signature result, wherein the first certificate signature result is generated by the trusted authentication center using its private key to sign the first public key using the HBS algorithm; The recipient generates a second public key and a second private key based on the HBS algorithm, and sends a second digital certificate request to the trusted authentication center. The second digital certificate request includes the second public key and the second identity information. The recipient receives a second digital certificate sent by the trusted authentication center. The second digital certificate is generated by the trusted authentication center after verifying the second identity information. The second digital certificate includes the second public key and the second certificate signature result. The second certificate signature result is generated by the trusted authentication center using its private key to sign the second public key using the HBS algorithm.

5. The method according to claim 4, characterized in that, Before the receiver verifies the first signature result, the first information, and the first random number using the sender's first public key via the HBS algorithm, the method further includes: The receiver receives the first digital certificate sent by the sender. The recipient uses the public key of the trusted authentication center to verify the signature result of the first certificate in the first digital certificate through the HBS algorithm, and after the verification is successful, obtains the first public key of the sender in the first digital certificate.

6. A quantum key distribution method, characterized in that, The method is implemented in the sending quantum communication device participating in the quantum key distribution process, including: Determine the target authentication stage with the recipient; In the target authentication phase, the first information to be authenticated and the first random number are signed using the HBS algorithm with the corresponding first private key to obtain a first signature result, and the first signature result, the first information and the first random number are sent to the receiver, wherein the first private key is generated by the HBS algorithm; Receive the second signature result, second information, and second random number sent by the recipient; The second signature result, the second information, and the second random number are verified using the HBS algorithm with the second public key of the recipient. If the verification is successful, the recipient is determined to have passed the authentication and the interaction in the target authentication stage is completed. The second public key is generated by the recipient using the HBS algorithm. After the sender's identity is authenticated in the target authentication stage, there is no need to perform repeated authentication in subsequent stages. The target authentication phase, which involves determining with the recipient the information authentication requirements, includes: The sender sends a first negotiation message to the receiver, wherein the first negotiation message includes the sender's candidate authentication phase; The receiver determines the target authentication stage based on the candidate authentication stage and sends a second negotiation message to the sender, wherein the second negotiation message includes the target authentication stage, which is the target authentication stage that requires information authentication in the classic channel; The sender receives the second negotiation message and determines the target authentication phase based on the second negotiation message.

7. A quantum key distribution method, characterized in that, The method is implemented in the receiver's quantum communication device participating in the quantum key distribution process, and includes: Determine the target authentication stage with the sender that requires information authentication; During the target authentication phase, the sender receives a first signature result, first information, and a first random number. The first signature result, the first information, and the first random number are verified using the HBS algorithm with the sender's first public key. If the verification is successful, the second signature result is obtained by signing the second information and the second random number to be authenticated using the corresponding second private key with the HBS algorithm. The second signature result, the second information, and the second random number are then sent to the sender. Otherwise, the sender is deemed to have failed authentication, and the quantum key distribution process ends. The first public key is generated by the sender using the HBS algorithm, and the second private key is generated by the receiver using the HBS algorithm. After the sender's identity is successfully authenticated in the target authentication stage, no further authentication is required in subsequent stages. The target authentication stage, which involves determining with the sender that information authentication is required, includes: The sender sends a first negotiation message to the receiver, wherein the first negotiation message includes the sender's candidate authentication phase; The receiver determines the target authentication stage based on the candidate authentication stage and sends a second negotiation message to the sender, wherein the second negotiation message includes the target authentication stage, which is the target authentication stage that requires information authentication in the classic channel; The sender receives the second negotiation message and determines the target authentication phase based on the second negotiation message.

8. A quantum communication network system, the quantum communication network system comprising: A trusted authentication center and multiple quantum communication devices, characterized in that the quantum communication network system realizes mutual authentication of the multiple quantum communication devices through the method described in any one of claims 1-5, thereby realizing the distribution of quantum keys and quantum secure communication between them.

Citation Information

Patent Citations

  • Quantum key distribution method and system for authentication based on post-quantum cryptography algorithm

    CN112152817A

  • Efficient post-quantum anonymous attestation with signature-based join protocol and unlimited signatures

    US20190319801A1