Dynamic quantum message authentication method capable of identifying suspension
By introducing a dynamic quantum message authentication method of semi-quantum trusted third-party SQ-TTP, the problems of inefficiency and difficulty in identity recognition in large-scale quantum communication networks are solved, and efficient quantum message transmission and resource conservation are achieved.
Patent Information
- Application Number
- CN202510319522.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-03-18
AI Technical Summary
The existing quantum message authentication scheme that can identify and abort is inefficient in large-scale quantum communication networks, is susceptible to denial of service attacks, and is unable to effectively identify the identity of the participants, resulting in the loss of quantum states.
A semi-quantum trusted third-party SQ-TTP is introduced, and a dynamic quantum message authentication method is adopted. Through three stages of screening honest participants, transmitting quantum messages in parallel, and transmitting messages to the server, quantum resource consumption and improving communication efficiency.
It realizes effective identification of participants in large-scale quantum communication networks, reduces the probability of quantum state loss, improves the efficiency of quantum message transmission, and saves quantum resources.
Smart Images

Figure CN120128331A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of secure multi-party communication and quantum cryptography, and specifically to a dynamic quantum message authentication method capable of identifying abort. Background Art
[0002] Message authentication, as one of the core technologies in the field of cryptography, plays an important role in ensuring the authenticity and integrity of messages during communication. In a traditional computing environment, message authentication schemes relying on symmetric encryption algorithms, hash functions, or public-key cryptography have high security and are widely used in Internet communication, blockchain technology, etc. However, with the rapid development of quantum technology, these traditional message authentication schemes are facing serious security threats. For example, the Shor quantum algorithm can effectively break algorithms such as RSA that rely on difficult problems such as large integer factorization or discrete logarithm solving in polynomial time; the Grover quantum search algorithm can reduce the complexity of brute-force cracking of symmetric cryptography algorithms from exponential O(2 n ) to square root level Similarly, in a quantum computing environment, some classical message authentication technologies will also be unable to effectively guarantee the authenticity and integrity of messages.
[0003] Quantum message authentication (QMA) is an important branch of quantum cryptography. By leveraging quantum properties such as the no-cloning theorem and quantum entanglement, it can effectively prevent eavesdropping and tampering, providing natural security guarantees for the authenticity and integrity of messages in quantum communication. In 2002, Barnum et al. proposed the definition of quantum message authentication (H. Barnum, C. Crepeau, D. Gottesman, A. Smith, and A. Tapp. Authentication of quantum messages. In Proceedings of the 43rd Annual IEEE Symposium on Foundations of Computer Science, pp. 449-458, 2002), and clearly pointed out that authenticating a quantum message must be accompanied by encrypting it to ensure message security. Following this pioneering work, many QMA schemes based on different methods have been proposed. However, most of the existing QMA schemes only perform security detection on a single channel, and their efficiency is very low in large-scale quantum communication networks. Moreover, the communication system is vulnerable to denial-of-service attacks, which can disrupt the entire communication process and cause waste of communication resources. Until 2021, Alon et al. proposed the first secure multi-party quantum message transmission scheme with identifiable abort (B. Alon, H. Chung, K.-M. Chung, M.-Y. Huang, Y. Lee, and Y.-C. Shen. Round efficient secure multi-party quantum computation with identifiable abort. In Advances in Cryptology-CRYPTO 2021, pp. 436-466, 2021). This scheme can timely abort the transmission of insecure channels when the majority of the communicating parties are dishonest, and only terminates the scheme when most of the quantum data has been transmitted or there is no path in the quantum communication network to continue transmission, thus being able to resist denial-of-service attacks during the communication process to improve robustness. However, the trusted third party in this scheme still cannot identify the identities of the participants, and when the message receiver is a malicious participant, there is a high probability of quantum state loss. In addition, in large-scale quantum communication networks, the quantum resources consumed by this scheme increase quadratically with the number of participants, making its communication efficiency and resource utilization difficult to meet actual requirements.
[0004] Therefore, it is of great significance to design a recognizable abortable QMA scheme applicable to large-scale quantum communication networks, reduce quantum resource consumption, and improve the efficiency of quantum message transmission. Summary of the Invention
[0005] Aiming at the deficiencies of existing recognizable abortable QMA schemes, the present invention introduces a semi-quantum trusted third party SQ-TTP to propose a recognizable abortable dynamic quantum message authentication method. Among them, SQ-TTP has classical computing capabilities and quantum measurement capabilities, but does not have complete quantum computing capabilities. This method can not only reduce quantum resources and improve the efficiency of quantum message transmission, but also effectively identify the identities of participants and reduce the probability of quantum state loss.
[0006] The core method of the present invention includes three stages: SQ-TTP screens honest participants, each group transmits quantum messages in parallel, and SQ-TTP and each group of receivers transmit the received messages to the server. The specific process of this method is as follows:
[0007] S1: The stage of SQ-TTP screening honest participants. SQ-TTP determines the number of groups p according to the current number of participants N and the preset number of participants q in each group. Subsequently, SQ-TTP randomly selects r participants (p < r < N) to form a small quantum communication network containing n = r + 1 nodes together. SQ-TTP initializes a complete graph G with n nodes and the set of honest participants The nodes in graph G represent the participants in the network, and the connections between the nodes represent that the transmission channels between the participants are secure. Participant R in the network i encodes the quantum message |ψ> i into |φ> ij = CSS.Enc(|ψ> i ) through the quantum error-correcting code CSS, where 1 ≤ i ≤ r, 1 ≤ j ≤ m, and each encoded qubit is sent to SQ-TTP according to the following steps.
[0008] S1.1: SQ-TTP calculates a transmission path S i from participant R ij to SQ-TTP and broadcasts it. The length of this path is l = n 2 . Define the participants on path S ij as P 1 , …, P l , that is, P 1 represents the sender R i , P 2 , …, P l-1 represents the participants transmitted in sequence on path S ij , and P lRepresents the final recipient SQ-TTP.
[0009] S1.2: SQ-TTP generates (lt + 1) random vectors as the key V 1 ={v 11 , v 12 , …, v 1(lt+1)}, where l is the number of trap registers and t is the number of qubits in each trap register.
[0010] S1.3: SQ-TTP sends the quaternion unitary operator to P 1 , where P 1 acts on the state |φ> after encoding the quantum message 1 and the state |0> of lt trap qubits ij to obtain the encrypted quantum state lt Then δ is sent to the next node P 1 on the transmission path S ij (2 ≤ k ≤ l). k (2 ≤ k ≤ l).
[0011] S1.4: SQ-TTP randomly generates a unitary operator and sends it to P k , where acts on t k =(l - k + 2)t trap qubits, refers to the general linear group composed of all t -order invertible matrices over the field k , G k can be implemented by a sequence of CNOT gates, acts on the first t k +1 qubits, acts on the first t k+1 +1 qubits. Then P k acts W k on the quantum state δ k-1 and measures the qubits in the (l - k + 2)-th trap quantum register. If the measurement results are all 0, then P k sends the authenticated identifier Acc to SQ-TTP, otherwise sends the rejected identifier Rej.
[0012] S1.5: If SQ-TTP receives Acc, then P k continues to send the remaining quantum state after measurement to P k+1, continue to transmit the message according to step S1.4. If SQ-TTP receives Rej, then SQ-TTP deletes the connection line between P k-1 and P k in graph G, and broadcasts the message (abort, P k-1 , P k ). When k = l - 1, the quantum state sent to SQ-TTP by the last participant P k after message authentication is However, since SQ-TTP only has the ability of quantum measurement, it cannot decrypt the quantum state δ by performing the unitary operator k and then measure the trap register for message authentication. To ensure that SQ-TTP can predict the measurement result of the trap register without decrypting the quantum state, the k unitary operator sent by SQ-TTP to the last participant P in k needs to be restricted to a combination of Pauli X gate and Pauli Z gate. When SQ-TTP authenticates the message δ k sent by P k , it directly measures the second trap register, and authenticates the quantum state δ k sent by the last participant P
[0013] S1.6: If graph G becomes disconnected, the honest participants connected to SQ-TTP form a set H. Then SQ-TTP broadcasts the message (abort, H) and terminates the transmission of quantum messages.
[0014] S1.7: SQ-TTP decides whether to end the screening according to the number of honest participants |H| selected. If |H| ≥ p, then SQ-TTP outputs the set H of honest participants and completes the screening phase; otherwise, SQ-TTP dynamically adjusts the grouping parameters according to the current remaining number of participants (N - r), updates the number of participants in each group to q', and continues to screen for honest participants according to step S1.
[0015] S2: The stage of parallel transmission of quantum messages for each group. SQ-TTP designates the honest participants in set H as the receivers of each group. All groups can transmit quantum messages in parallel, and the participants within the group transmit the messages to the receivers designated by SQ-TTP for their groups according to similar steps of S1.1~S1.6. The difference is that SQ-TTP does not need to restrict the construction of the unitary operator sent to the last participant. After the transmission within the group is completed, the designated receiver of each group has the encrypted messages transmitted by all participants within the group.
[0016] S3: The stage where SQ-TTP and each packet receiver transmit the received messages to the server. After the operations in the two stages of S1 and S2, SQ-TTP holds the quantum messages of all the parties in the set H, and the receivers of each packet hold the quantum messages of all the parties within the group. Moreover, the quantum states they hold are in the form of Since SQ-TTP and each packet receiver are honest participants, they can directly perform single-channel quantum message authentication with the server. When the server receives the quantum state, it decrypts the quantum state through the unitary operator sent by SQ-TTP Subsequently, the server measures the last t trap qubits. If all the measurement results are 0, the authentication passes; otherwise, the authentication fails.
[0017] The present invention constructs a new type of quantum message authentication code by using quaternions and the quantum error-correcting code CSS, and on this basis, realizes a dynamic QMA method with recognizable abort. Compared with the prior art, the present invention can better adapt to large-scale quantum communication networks. Its dynamic grouping mechanism and parallel transmission mode can effectively reduce the consumption of quantum resources and improve the efficiency of quantum communication. At the same time, the semi-quantum trusted third party SQ-TTP can identify the identities of the participants, thereby increasing the probability of successful quantum message transmission. In addition, the key used in the transmission process can be recycled by SQ-TTP for continued use after each successful authentication, further saving quantum resources. Brief Description of the Drawings
[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments. The following drawings are only some embodiments of the present invention, so they should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other relevant drawings can also be obtained based on these drawings.
[0019] Figure 1 It is a schematic flowchart of the dynamic quantum message authentication method with recognizable abort of the present invention.
[0020] Figure 2 It is a schematic diagram of the overall quantum circuit formed by three parties on the transmission path of the embodiment of the present invention performing operations in sequence. Detailed Embodiments
[0021] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0022] The process of the dynamic quantum message authentication method that can identify suspension according to the present invention is as follows Figure 1 shown, which mainly includes the following steps:
[0023] S1: SQ-TTP screens honest participant stage. SQ-TTP determines the number of groups according to the current number of participants N and the preset number of participants q in each group to ensure that the number of participants in each group is q±1. Subsequently, SQ-TTP randomly selects r participants (p<r<N) to form a small quantum communication network with n = r + 1 nodes together. SQ-TTP serves as the message receiver of this communication network, initializes a complete graph G with n nodes and a set of honest participants The nodes in graph G represent the participants in the network, and the connections between the nodes represent that the transmission channels between the participants are secure. The participant R in the network i encodes the quantum message |ψ> i into |φ> ij = CSS.Enc(|ψ> i ) through the quantum error correction code CSS, where 1≤i≤r, 1≤j≤m, and sends each encoded quantum bit to SQ-TTP according to the following steps.
[0024] S1.1: SQ-TTP calculates a transmission path S i from the participant R ij to SQ-TTP for transmitting the quantum state |φ> ij using the depth-first search or breadth-first search algorithm according to graph G, and broadcasts this path. To enable at least one honest participant on the transmission path to authenticate the quantum message, set the length of this path to l = n 2 . Define the participants on path S ij as P 1 ,…,P l , that is, P 1 represents the sender R i , P 2 ,…,P l-1 represents the participants transmitted in sequence on path S ij , and P l represents the final receiver SQ-TTP.
[0025] S1.2: SQ-TTP generates (lt + 1) random vectors as the key V 1 = {v 11 ,v 12 ,…,v 1(lt+1)}, where l is the number of trap registers and t is the number of quantum bits in each trap register. The form of each random vector is and satisfy the normalization condition ||v|| 2 =(a 2 +b 2 +c 2 +d 2 ) = 1. Represent the algebraic form of the vector v corresponding to the quaternion using the operators σ 1 = iZ, σ 2 = iY and σ 3 = iX as U v = aI 2 + bσ 1 + cσ 2 + dσ 3 = U (a,b,c,d) , and its matrix form is The inverse of the quaternion is represented as The corresponding matrix form is And satisfy During the message transmission process, each participating party uses the quaternion U v to encrypt the quantum message and uses to decrypt the received quantum state.
[0026] S1.3: SQ-TTP sends the quaternion unitary operator to P 1 , where P 1 acts on the state |φ> 1 after encoding the quantum message and the state of lt trap qubits |0> ij to obtain the encrypted quantum state lt Then δ 1 is sent to the next node P ij on the transmission path S k (2 ≤ k ≤ l).(2 ≤ k ≤ l).
[0027] S1.4: SQ-TTP randomly generates a unitary operator and sends it to P k , where acts on t k =(l - k + 2)t trap qubits, refers to the general linear group composed of all t -order invertible matrices over the field k , G k can be implemented by a sequence of CNOT gates, acts on the first t k + 1 qubits, acts on the first t k+1 + 1 qubits. Then P kApply W k to the quantum state δ k-1 and measure the qubits in the (l - k + 2)-th trap quantum register. If all the measurement results are 0, then P k sends the authenticated identifier Acc to SQ-TTP; otherwise, sends the rejected identifier Rej.
[0028] Specifically, introducing G k is to prevent the sender P 1 from dishonestly preparing lt trap qubits, resulting in the honest participants accusing each other of dishonesty. For example, assume that P 1 is malicious and he only honestly prepares the last t trap qubits. P 2 and P 3 are honest. If the message δ 1 on the transmission path is not subject to a tampering attack, then when P 2 measures the last t trap qubits and all the results are 0, it will wrongly think that P 1 is honest and send the wrong authenticated identifier Acc to SQ-TTP. When P 3 applies W 3 to δ 2 and then measures the t trap qubits, it will get non-zero-all measurement results and thus wrongly think that P 2 is malicious. G k is a linear invertible matrix of t k ×t k and is isomorphic to the matrix in the group generated by the CNOT gate. It can be implemented by a sequence of CNOT gates, and the CNOT gate acting on the trap qubits with all states |0> will not change the measurement results, increasing the probability of identifying the malicious sender.
[0029] S1.5: If SQ-TTP receives Acc, it means that the message transmission path between P k-1 and P k is secure. P k continues to send the remaining measured quantum state to P k+1 , and continues to transmit the message according to step S1.4. If SQ-TTP receives Rej, it means that the message transmission path between P k-1 and P k is insecure, that is, at least one of P k-1 and P k is a malicious participant. At this time, SQ-TTP deletes the connection between P k-1 and P k in graph G, and broadcasts the message (abort, P k-1 , Pk )。When k = l - 1, the last participant P k sends the quantum state to SQ-TTP after message authentication as However, since SQ-TTP only has the ability of quantum measurement, it cannot decrypt the quantum state δ by performing a unitary operator k and then measuring the trap register for message authentication. To ensure that SQ-TTP can predict the measurement result of the trap register without decrypting the quantum state, SQ-TTP sends the unitary operator k to the last participant P in needs to be restricted to a combination of Pauli X gates and Pauli Z gates, specifically U( 1,0,0,0 ) = X 0 Z 0 = I, U( 0,1,0,0 ) = X 0 Z 1 , U (0,0,1,0 ) = X 1 Z 1 and U (0,0,0,1) = X 1 Z 0 in four forms. SQ-TTP directly measures the second trap register when authenticating the message δ k sent by P k . If the trap qubit acts on a Pauli X gate, the correct measurement result should be 1, and 0 in other cases. SQ-TTP authenticates the quantum state δ k sent by the last participant P k according to the consistency between the actual measurement result and the predicted measurement result.
[0030] S1.6: If the graph G becomes disconnected, two subgraphs will be formed. Since SQ-TTP is trusted and the message transmission between honest participants is considered secure, then all the participants connected to SQ-TTP in the graph G are honest participants, and they form the set H. Subsequently, SQ-TTP broadcasts the message (abort, H) and terminates the quantum message transmission.
[0031] S1.7: SQ-TTP decides whether to end the screening according to the number of honest participants |H| screened out. If |H| ≥ p, SQ-TTP outputs the set H of honest participants and completes the screening phase. Otherwise, SQ-TTP dynamically adjusts the grouping parameters according to the current remaining number of participants (H - r), updates the number of participants in each group to q', and continues to screen honest participants according to step S1.
[0032] S2: Stage of parallelly transmitting quantum messages for each group. The SQ-TTP designates the honest participants in the set H as the receivers for each group. All groups can transmit quantum messages in parallel. The participants within a group transmit the messages to the receiver designated by the SQ-TTP for that group according to similar steps as S1.1 to S1.6. The difference is that the SQ-TTP does not need to restrict the construction of the unitary operator sent to the last participant. After the transmission within the group is completed, the designated receiver of each group has the encrypted messages transmitted by all the participants within the group. Figure 2 Fig. shows the schematic diagram of the overall quantum circuit formed by three participants successively performing operations on the transmission path in the embodiment of the present invention. Assume that the three participants on the transmission path are P 1 , P 2 and P 3 . Quantum message |φ> 1 is sent from P 2 to P 3 . The transmission process is described as follows: 11
[0033] (1) P 1 uses the operator sent by the SQ-TTP as the key to encode the quantum message |φ> and generates the quantum state 11 and sends it to P 2 . Among them, 3t trap qubits are respectively stored in three trap quantum registers T 1 , T 2 and T 3 . Each register contains t trap qubits.
[0034] (2) After P 2 receives the quantum state, the SQ-TTP sends the operator as the key to it where G 2 acts on 3t trap qubits, acts on the first 3t + 1 qubits, acts on the first 2t + 1 qubits. Subsequently, P 2 acts W 2 on δ 1 and measures the third trap quantum register T 3 . If the measurement result is all 0, then P 2 sends Acc to the SQ-TTP; otherwise, it sends Rej. The SQ-TTP deletes the connection between P 1 and P 2 from the graph G and broadcasts the message (abort, P 1 , P 2 ). Here, it is assumed that P2 What is sent is Acc, by P 2 To P 3 Continue to send the remaining quantum states after measurement
[0035] (3) Similarly, P 3 After receiving the quantum state, the operator sent by SQ-TTP as the key Act on δ 2 , and measure the second trap quantum register T 2 , and send an authentication identifier to SQ-TTP according to the measurement result. If the authentication is successful, at this time P 3 The quantum state held is
[0036] S3: SQ-TTP and each group recipient transmit the received messages to the server stage. After the operations in the two stages of S1 and S2, SQ-TTP holds the quantum messages of all participating parties in the set H, and the recipients of each group hold the quantum messages of all participating parties within the group, and the quantum states they hold are in the form of Since SQ-TTP and each group recipient are honest participating parties, they can directly perform single-channel quantum message authentication with the server. When the server receives the quantum state, he decrypts the quantum state through the unitary operator sent by SQ-TTP . Subsequently, the server measures the last t trap qubits. If the measurement results are all 0, the authentication passes, otherwise the authentication fails.
[0037] Through the above steps, the present invention realizes a dynamic quantum message authentication method that can identify abort. First, the semi-quantum trusted third party SQ-TTP groups the participating parties in the network and performs quantum message transmission with some participating parties. Subsequently, SQ-TTP screens out the honest participating parties according to the message authentication results and ensures that their number is not less than the number of groups. Then SQ-TTP assigns the screened honest participating parties as the recipients of each group, and each group can transmit in parallel. The participating parties within the group adopt a quantum message transmission method similar to that in the stage of screening honest participating parties to complete their respective quantum message transmissions. After the transmission is completed, SQ-TTP and the recipients of each group transmit the held quantum messages to the server, thus completing the message transmission of the entire quantum communication network. The present invention is applicable to large-scale quantum communication networks. Its dynamic grouping and parallel transmission modes reduce quantum resources while improving the efficiency of quantum message transmission, and external personnel can also identify the identities of malicious participating parties, thus further promoting the practical process of quantum message authentication technology.
[0038] The above-described embodiments are only used to illustrate the principles, features, and advantages of the present invention, and do not limit the scope of the present invention. Without departing from the design concept given by the present invention, those skilled in the art can make various modifications, equivalent replacements, or improvements to it, and these should all be regarded as falling within the protection scope of the present invention.
Claims
1. A dynamic quantum message authentication method capable of identifying abort, characterized in that: It includes the following three stages: S1: The stage where the semi-quantum trusted third party SQ-TTP screens honest participants. SQ-TTP determines the number of groups according to the current number of participants and the preset number of participants in each group. Subsequently, SQ-TTP randomly selects some participants to form a small quantum communication network together. The participants in this network encode the quantum message through the quantum error-correcting code CSS and send the quantum bits to SQ-TTP one by one in a specified manner. SQ-TTP screens out honest participants based on the message authentication result and ensures that the number of them is not less than the number of groups. S2: The stage where each group transmits quantum messages in parallel. SQ-TTP designates the screened honest participants as the receivers of each group. All groups can transmit quantum messages in parallel, and the participants within the group adopt a quantum message transmission method similar to that in step S1 to complete their respective quantum message transmissions. S3: The stage where SQ-TTP and the receivers of each group transmit the received messages to the server. The server decrypts the received messages using the key sent by SQ-TTP, then measures the trap quantum bits, and authenticates the messages according to the measurement results.
2. The method for dynamic quantum message authentication capable of identifying abort according to claim 1, characterized in that: In the stage where SQ-TTP screens honest participants described in step S1: SQ-TTP determines the number of groups based on the current number of participants N and the number of participants in each group q preset by the system Ensure that the number of participants in each group is q±1; Subsequently, SQ-TTP randomly selects r participants (p < r < N) to form a small quantum communication network with n = r + 1 nodes together. SQ-TTP initializes a complete graph G with n nodes and a set of honest parties The nodes in the graph G represent the participants in the network, and the lines between the nodes represent that the transmission channels between the participants are secure. i The quantum message |ψ> i Encoded by quantum error correction code CSS as |ψ> ij =CSS.Enc(|ψ> i ), where 1≤i≤r, 1≤j≤m, and send each encoded quantum bit to SQ-TTP according to the following steps; S1.1: SQ-TTP calculates a path from participant R according to graph G. i Transmission path S to SQ-TTP ij And broadcast, the length of the path is l = n 2 ; Define path S ij The participants on are P1,…,P l , that is, P1 represents the sender R i ,P2,…,P l-1 Representative path S ij The participants who transmit in order, P l Represents the final receiver SQ-TTP; S1.2: SQ-TTP generates (lt+1) random vectors as the key V1={v 11 ,v 12 ,…,v 1(lt+1) }, where l is the number of trap registers, and t is the number of qubits in each trap register; each random vector is in the form of And satisfy the normalization condition ||v|| 2 =(a 2 +b 2 +c 2 +d 2 )=1; the algebraic form of the quaternion corresponding to the vector v is U using the operators σ1=iZ, σ2=iY and σ3=iX v =aI2+bσ1+cσ2+dσ3=U (a,b,c,d) , whose matrix form is The inverse of a quaternion is expressed as The corresponding matrix form is And satisfy During the message transmission process, each participant uses U v Encrypt the quantum message using Decrypt the received quantum state; S1.3: SQ-TTP converts quaternion unitary operators Sent to P1, where P1 applies W1 to the state |φ> after encoding the quantum message ij and lt trap qubit states |0> lt Get encrypted quantum state Then δ1 is sent to the transmission path S ij The next node P on k (2≤k≤l); S1.4: SQ-TTP Randomly Generated Unitary Operators and send it to P k ,in Act on t k =(l-k+2)t trapped qubits, Domain All t k The general linear group of reversible matrices of order G k It can be realized by using CNOT gate sequence, Act on the front k +1 qubit, Act on the front k+1 +1 qubit; then P k W k Acting on the quantum state δ k-1 and measure the quantum bits in the (l-k+2)th trap quantum register; if the measurement results are all 0, then P k Send the authenticated identifier Acc to SQ-TTP, otherwise send the rejected identifier Rej; S1.5: If SQ-TTP receives Acc, then P k Continue to measure the remaining quantum state Send to P k+1 , continue to transmit the message according to step S1.4; if SQ-TTP receives Rej, SQ-TTP deletes P in Figure G k-1 With P k The connection between them and broadcast the message (abort, P k-1 , P k ); When k = l-1, the last participant P k The quantum state sent to SQ-TTP after message authentication is However, since SQ-TTP only has the ability of quantum measurement, it cannot perform unitary operations. Decoding the quantum state δ k Then measure the trap register for message authentication; To ensure that SQ-TTP can predict the measurement result of the trap register without decrypting the quantum state, SQ-TTP sends it to the last participant P k Unitary operator In The combination of Pauli X gate and Pauli Z gate needs to be restricted, specifically U (1,0,0,0) =X 0 Z 0 =I,U (0,1,0,0) =X 0 Z 1 , U (0,0,1,0) =X 1 Z 1 and U (0,0,0,1) =X 1 z 0 Four forms; SQ-TTP is certified by P k Message sentδ k When the second trap register is directly measured, if the trap quantum bit acts on the Pauli X gate, the correct measurement result should be 1, and all other cases are 0; SQ-TTP determines the last participant P according to the consistency between the actual measurement result and the predicted measurement result. k The quantum state δ sent k Conduct certification; S1.6: If the graph G becomes disconnected, the honest participants connected to SQ-TTP form a set H. Subsequently, SQ-TTP broadcasts the message (abort, H) and terminates the transmission of quantum messages. S1.7: SQ-TTP decides whether to end the screening according to the number of screened honest participants |H|. If |H| ≥ p, SQ-TTP outputs the set H of honest participants and completes the screening stage. Otherwise, SQ-TTP dynamically adjusts the grouping parameters according to the current remaining number of participants (N - r), updates the number of participants in each group to q', and continues to screen honest participants according to step S1.
3. The method for dynamic quantum message authentication capable of identifying abort according to claim 1, characterized in that: In the stage where each group transmits quantum messages in parallel described in step S2: SQ-TTP designates the honest participants in the set H as the receivers of each group. All groups can transmit quantum messages in parallel, and the participants in the group transmit the message to the receiver designated by SQ-TTP in the group according to similar steps from S1.1 to S1.
6. The difference is that SQ-TTP does not need to limit the unitary operator sent to the last participant. The structure of After the transmission within the group is completed, the designated receiver of each group has the encrypted messages transmitted by all participants within the group.
4. The method for dynamic quantum message authentication capable of identifying abort according to claim 1, characterized in that: In the stage where SQ-TTP and the receivers of each group transmit the received messages to the server described in step S3: After the two-stage operation of S1 and S2, SQ-TTP holds the quantum messages of all participants in the set μ, and the receivers of each group hold the quantum messages of all participants in the group, and the quantum states they hold are in the form of Since SQ-TTP and each packet receiver are honest participants, they can directly perform single-channel quantum message authentication with the server; when the server receives the quantum state, it uses the unitary operator sent by SQ-TTP to authenticate the quantum state. Decrypt the quantum state; then the server measures the last t trapped quantum bits. If the measurement results are all 0, the authentication is successful, otherwise the authentication fails.
Citation Information
Patent Citations
Quantum security multi-party computing method based on quantum homomorphic encryption
CN113660085A
Quantum digital signature protocol based on chain CNOT gate and rotation operator
CN118199895A
Cited By
Quantum message authentication method and device, equipment and medium
CN121841615A
Trap management device, processor, chip and electronic equipment
CN122152643A