Identity authentication method and system without polarized light regulation
By regulating and transmitting the intensity of coherent light sources, the perfect key is generated, and the dependence of traditional quantum identity authentication systems on polarized light regulation is solved, achieving higher security and ease of use.
Patent Information
- Application Number
- CN202510299923.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-06-17
AI Technical Summary
Traditional quantum identity authentication systems rely on polarized light regulation and require complex optical equipment and environments, limiting their application range.
The intensity control and transmission of coherent light sources are adopted to generate a perfect key, which simplifies the system construction and operation process and avoids the dependence on polarized light regulation.
Identity authentication without polarized light regulation is realized, the security and ease of use of the system are improved, and the privacy of the key is ensured, and it cannot be cracked even in the face of powerful quantum computing capabilities.
Smart Images

Figure CN120165849A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of quantum cryptography, and particularly to an identity authentication method and system that do not require polarization light control. Background Art
[0002] Identity authentication technology is one of the core technologies in the field of information security, and its significance is reflected in many aspects: it can effectively prevent identity theft and data leakage, ensuring the security and reliability of information systems; it can protect user privacy and prevent personal information from being misused; it can improve the credibility of information systems and enhance users' trust and dependence on the systems; it can provide security guarantees for various application scenarios, such as financial transactions, online payments, e-government, etc. Identity authentication technology is an important cornerstone for building a secure, reliable, and trustworthy digital world.
[0003] Quantum cryptography is a brand-new method for realizing information security by using the principles of quantum mechanics, which has revolutionary significance for information security. Traditional cryptography is based on the complexity of mathematical problems and its security will no longer be reliable under the threat of quantum computing. However, quantum cryptography is based on physical laws and cannot be cracked even with a powerful quantum computer, providing unconditional security for information. An identity authentication system based on quantum cryptography will bring a higher level of security protection to fields such as financial transactions and confidential communications, promoting the information society towards a more secure and trustworthy future.
[0004] In identity authentication methods and systems based on quantum cryptography, whether it is quantum key distribution or quantum computing, it depends on polarized light as the carrier of quantum states. Polarized light can carry quantum information and read and process information through quantum measurement. However, the implementation of polarized light technology requires relatively complex equipment and environment, such as high-quality polarizers, optical fibers, and optical devices, and also has certain requirements for environmental stability, which limits its application scope. Therefore, exploring other carriers that can effectively carry quantum information and applying them to identity authentication methods and systems based on quantum cryptography to achieve more convenient and efficient identity authentication has become an important research direction in the field of quantum information. Summary of the Invention
[0005] Object of the Invention: To solve the related technical problems raised in the background art, the object of the present invention is to provide an identity authentication method and system that do not require polarization light control. The present invention generates perfect keys by controlling and transmitting the intensity of a coherent light source, simplifies the construction and operation process of the system, making it easier to implement and apply; moreover, it solves the problem that traditional quantum identity authentication systems usually rely on polarization light control and require complex optical equipment and environment; at the same time, this method uses the principles of quantum mechanics to ensure the privacy of the key, and even if an eavesdropper has powerful quantum computing capabilities, it cannot be cracked.
[0006] Technical solution: An identity authentication method without polarization light regulation according to the present invention includes the following steps:
[0007] (1) Encryption key generation: The first user and the second user generate three pairs of keys with a length of l1 using coherent light, which are respectively denoted as key1, key2, and key3; the first user and the second user also have a string of the same password, denoted as R, and the length of R is set to l2, and the value of l1 is less than l2;
[0008] (2) Associated key generation: The verifier and the first user generate a pair of keys with a length of l1 using coherent light, denoted as k1; the verifier and the second user generate a pair of keys with a length of l1 using coherent light, denoted as k2; the verifier calculates where represents the bitwise exclusive OR of two strings of keys;
[0009] (3) Encryption comparison: The first user and the second user use the generated keys to calculate the encrypted information corresponding to their respective passwords R and send it to the verifier for verification; if the verification is consistent, the comparison is successful, and the identity authentication of the first user and the second user passes.
[0010] Further, the specific process of the first user and the second user generating three pairs of keys with a length of l1 using coherent light is as follows:
[0011] 1) Randomly select one party from the first user and the second user, denoted as the coherent light sender, who is responsible for sending coherent light pulses in each time window; the other party is denoted as the coherent light receiver;
[0012] 2) The coherent light sender regards two adjacent time windows as a signal window together, that is: the first time window and the second time window are regarded as the first signal window, the third time window and the fourth time window are regarded as the second signal window,..., the (2k - 1)th time window and the 2kth time window are regarded as the kth signal window;
[0013] For the tth signal window, t ∈ {1, 2,..., k}, the coherent light sender sends an optical pulse |0> s with a probability of p 2t-1 |α> 2t , sends an optical pulse |α> s |0> 2t-1 with a probability of p 2t , sends an optical pulse |α> d1 |α> 2t-1 with a probability of p 2t , sends an optical pulse |0> d2 |0> 2t-1 with a probability of p 2t, where |0> 2t-1 |α> 2t means that a coherent state with optical intensity 0 is sent in the (2t - 1)-th time window, and a coherent state with an average photon number of α is sent in the 2t-th time window. |α> 2t-1 |0> 2t means that a coherent state with an average photon number of α is sent in the (2t - 1)-th time window, and a coherent state with optical intensity 0 is sent in the 2t-th time window. |α> 2t-1 |α> 2t means that coherent states with an average photon number of α are sent in both the (2t - 1)-th time window and the 2t-th time window. |0> 2t-1 |0> 2t means that coherent states with optical intensity 0 are sent in both the (2t - 1)-th time window and the 2t-th time window; the above p s 、 The values of are randomly selected by the coherent optical transmitter and satisfy
[0014] The coherent optical transmitter records the transmission situation of each signal window and the total number N of the signal windows sent. The value of N is randomly selected by the coherent optical transmitter;
[0015] 3) For the optical pulses in each signal window, the coherent optical receiver first injects them into a first beam splitter. One path of the pulses from the first beam splitter is output to a pulse time detector D0, and the time windows when the pulse time detector D0 responds are recorded. The other path of the pulses is output to a second beam splitter. The two outputs of the second beam splitter are propagated through optical fibers of unequal lengths and then injected into a third beam splitter. The two paths of the pulses from the third beam splitter are respectively output to a first interference pulse detector D1 and a second interference pulse detector D2; the coherent optical receiver only records the response situations of the first interference pulse detector D1 and the second interference pulse detector D2 and the corresponding signal windows when the pulses in the same signal window interfere;
[0016] If there are responses from more than two detectors in the same time window, the coherent optical receiver randomly records the response of any one detector and ignores the other responses;
[0017] 4) The coherent optical receiver announces which signal window's optical pulses cause the response of the pulse time detector D0 and which signal window's optical pulses cause the response of the first interference pulse detector D1 and the second interference pulse detector D2;
[0018] 5) For the signal windows corresponding to the response of the pulse time detector D0 and the signal windows corresponding to the response of the first interference pulse detector D1 and the second interference pulse detector D2, the coherent optical transmitter and the coherent optical receiver perform a coding operation to generate a key with a length of l1;
[0019] 6) Repeat the above steps 1) - 5) multiple times until the coherent optical transmitter and the coherent optical receiver generate three pairs of keys with length l1.
[0020] Further, for the signal window corresponding to the response of the pulse time detector D0, and the signal windows corresponding to the responses of the first interference pulse detector D1 and the second interference pulse detector D2, the specific process of the coherent optical transmitter and the coherent optical receiver performing coding operation to generate a key with length l1 is as follows:
[0021] For the signal window corresponding to the response of the pulse time detector D0, the coherent optical transmitter and the coherent optical receiver perform coding in the following manner: (a) The coherent optical transmitter makes a coding judgment in the chronological order of these signal windows: If the optical pulse sent by the signal window is |0> 2t-1 |α> t , then record the bit value 0; if the optical pulse sent by the signal window is |α> 2t-1 |0> t , then record the bit value 1; if other pulses are sent by the signal window, discard them; (b) The coherent optical transmitter announces which signal windows are discarded; (c) For the signal windows that are not discarded, the coherent optical receiver, according to the measurement result of the pulse time detector D0, if it measures that the response is in the latter time window in this signal window, then record the bit value 0; if it measures that the response is in the former time window in this signal window, then record the bit value 1; (d) The coherent optical transmitter and the coherent optical receiver announce the bit values recorded in the 10% of the non-discarded signal windows at the front in chronological order, and compare how many bit values are different. If the number of different bits divided by the total number is greater than or equal to 0.5, then the coherent optical transmitter and the coherent optical receiver discard all the data and re-perform the operation of generating the key; if the number of different bits divided by the total number is less than 0.5, then the coherent optical transmitter and the coherent optical receiver record this value, which is called the bit error rate E b ;
[0022] For the signal windows corresponding to the responses of the first interference pulse detector D1 and the second interference pulse detector D2, the coherent optical transmitter and the coherent optical receiver perform coding in the following manner: (a) The coherent optical transmitter announces the optical pulse states and data sent by these signal windows: N, (b) For the signal windows where the sent optical pulse is |0> 2t-1 |α> 2t , the coherent optical receiver counts the number of response windows of detector D1 among them the number of response windows of detector D2 Calculate the parameter where and respectively represent the gains on detector D1 and the gains on detector D2 when a coherent state with optical intensity 0 is sent in the (2t - 1)-th time window and a coherent state with an average photon number of α is sent in the 2t-th time window; (c) For the signal window of the optical pulse |α> 2t-1 |0> 2t sent by the coherent light receiver, count the number of response windows of detector D1 among them The number of response windows of detector D2 Calculate the parameter where and respectively represent the gains on detector D1 and the gains on detector D2 when a coherent state with an average photon number of α is sent in the (2t - 1)-th time window and a coherent state with optical intensity 0 is sent in the 2t-th time window; (d) For the signal window of the optical pulse |α> 2t-1 |α> 2t sent by the coherent light receiver, count the number of response windows of detector D1 among them The number of response windows of detector D2 Calculate the parameter where and respectively represent the gains on detector D1 and the gains on detector D2 when coherent states with an average photon number of α are sent in both the (2t - 1)-th time window and the 2t-th time window; (e) For the signal window of the optical pulse |0> 2t-1 |0> 2t sent by the coherent light receiver, count the number of response windows of detector D1 among them The number of response windows of detector D2 Calculate the parameter where and represent the gains on detector D1 and the gains on detector D2 when coherent states with optical intensity 0 are sent in both the (2t - 1)-th time window and the 2t-th time window; (f) The coherent light receiver calculates the gain characterized by the phase error rate of detector D1 and the gain characterized by the phase error rate of detector D2
[0023]
[0024]
[0025] where μ = α 2 , N ± = 2(1 ± e -μ );
[0026] Calculate the phase error rate E again p :
[0027]
[0028] Then judge the phase error rate E p , if the phase error rate E p ≥0.5, the coherent optical transmitter and the coherent optical receiver discard all data and re - perform the operation of generating keys; if the phase error rate E p <0.5, the coherent optical transmitter and the coherent optical receiver perform error correction and privacy amplification operations on the key; after the error correction and privacy amplification operations are completed, if the key length is greater than l1, both the coherent optical transmitter and the coherent optical receiver select the first l1 bits of the key as a pair of generated keys, if the key length is less than l1, the coherent optical transmitter and the coherent optical receiver discard all data and re - perform the operation of generating keys.
[0029] Furthermore, the specific process for the first user and the second user to calculate the encrypted information corresponding to the password R they each own using the generated key is as follows:
[0030] A: The first user first generates a binary random number sequence of length l1 using the key key2, that is, each bit of key2 is used as each bit of the binary random number sequence, and then simply adjusts the sequence: if the end of the sequence is 0, change it to 1; the adjusted sequence is expressed as where c0 = 1; then convert this sequence into a polynomial of the following form:
[0031]
[0032] B: The first user verifies whether this polynomial is an irreducible polynomial. If the verification is successful, proceed to the next step; otherwise, the first user and the second user re - generate a new key key2, and then re - perform step A;
[0033] C: The first user represents the sequence as a row vector and represents the key key1 as a column vector X = [key1(1), key1(2),..., key1(l1)] T , where T represents the transpose of the row vector, that is, it represents a column vector, and key1(i) represents the i - th bit of the key key1; then represent the password R to be compared as a column vector where R(i) represents the i - th bit of the password R;
[0034] D: The first user generates l2 column vectors of length l1 according to the following rule
[0035] H1 = [key1(1), key1(2),..., key1(l1)] T
[0036] H2 = [C·H1, key1(1), key1(2),..., key1(l1 - 1)] T
[0037] H3 = [C·H2, C·H1, key1(1), key1(2),..., key1(l1 - 2)] T
[0038] ……
[0039]
[0040] where · represents the multiplication of matrix by matrix; then using l2 column vectors of length l1 construct an l1×l2 matrix H, and each column of matrix H from left to right is
[0041] E: The first user calculates and the result obtained is a column vector of length l1 The first user takes each bit of the column vector and takes the modulo 2 of each bit, that is each bit of mod 2, to obtain a bit string Y of length l1, and the bit string Y is used as the encrypted information corresponding to the password it owns;
[0042] F: The second user performs the same operations in steps A to E above to obtain the encrypted information Y' corresponding to the password it owns.
[0043] Furthermore, the specific process of sending to the verification party for verification is as follows:
[0044] S1: The first user calculates the first verification information and sends the first verification information U1 to the verification party through the authentication channel;
[0045] S2: The second user calculates the second verification information and sends the second verification information U2 to the verification party through the authentication channel;
[0046] S3: The verification party calculates and compares whether it is the same as k3. If they are the same, the comparison is successful, and the identity authentication of the first user and the second user passes; if they are not the same, the comparison is unsuccessful, and the identity authentication of the first user and the second user fails.
[0047] Further, the first user verifying whether the polynomial is an irreducible polynomial means that:
[0048] For all positive integers k less than , the following operations are performed, where [x] represents the floor function of x: Calculate whether holds. If the verification passes for all k, then the polynomial p(x) is an irreducible polynomial of degree n over GF(2); where gcd(f(x), g(x)) represents the greatest common divisor of two polynomials f(x) and g(x), and f(x) and g(x) refer to any two polynomials; that is, if for each positive integer k less than , the calculation result is equal to 1, then the verification is successful, and the next step is carried out.
[0049] The present invention further includes a system for an identity authentication method without polarization light regulation based on the above claims. The system includes a first user, a second user, and a verification party that are pairwise connected;
[0050] The first user is used to generate keys with the second user and the verification party respectively using coherent light, calculate the encrypted information corresponding to the password R it owns through the generated keys, and send it to the verification party for verification;
[0051] The second user is used to generate keys with the first user and the verification party respectively using coherent light, calculate the encrypted information corresponding to the password R it owns through the generated keys, and send it to the verification party for verification;
[0052] The verification party is used to generate keys with the first user and the second user respectively using coherent light, and receive the verification information from the first user and the second user for verification.
[0053] Further, both the first user and the second user include a coherent light transmitting unit and a coherent light measuring unit;
[0054] The coherent light transmitting unit includes a coherent light emitter and an intensity modulator connected in sequence. The coherent light emitter is used to generate high extinction ratio optical pulses with controllable and stable optical intensity; the intensity modulator is used to adjust the optical intensity of the optical pulses to the single photon level;
[0055] The coherent light measurement unit includes a first beam splitter, a pulse time detector, a second beam splitter, a third beam splitter, a first interference pulse detector, and a second interference pulse detector. One output end of the first beam splitter is connected to the pulse time detector, and the other output end is connected to one input end of the second beam splitter. One output end of the second beam splitter is connected to one input end of the third beam splitter through a first optical fiber, and the other output end is connected to the other input end of the third beam splitter through a second optical fiber. The two input ends of the third beam splitter are respectively connected to the first interference pulse detector and the second interference pulse detector.
[0056] Further, the length of the second optical fiber is greater than that of the first optical fiber, and the delay caused by the second optical fiber is the delay of one time window.
[0057] Advantages of the present invention:
[0058] (1) Simplify the complexity of implementing the quantum identity authentication system: Traditional quantum identity authentication systems usually rely on polarization light regulation, which requires complex optical equipment and environment, restricting their application scope. The system proposed by the present invention can generate perfect keys only by using the intensity regulation and transmission of a coherent light source, simplifying the system construction and operation process, making it easier to implement and apply. Using these keys, this system can achieve identity authentication between two users.
[0059] (2) Improve the security of the identity authentication system: The present invention uses the principles of quantum mechanics to ensure the privacy of the keys. Even if an eavesdropper has powerful quantum computing capabilities, they cannot crack them. Therefore, the present invention has unconditional security, raising the security of identity authentication to a new level.
[0060] (3) Expand the application scope of identity authentication: The present invention can be applied to various scenarios requiring secure identity verification, such as financial transactions, online payments, e-government, etc., providing strong support for building a more secure and reliable digital world. Description of the Drawings
[0061] Figure 1 Schematic diagram of the identity authentication system of the present invention that does not require polarization light regulation;
[0062] Figure 2 Schematic diagram of the device for two parties of the present invention to generate keys using coherent light;
[0063] Figure 3 Schematic diagram of selectively recording responses at the interference basis measurement device when two parties of the present invention generate keys using coherent light;
[0064] Figure 4 Schematic diagram of the associated key generation related to the present invention. Detailed Embodiments
[0065] The present invention will be further described below in conjunction with the accompanying drawings and embodiments:
[0066] The present invention proposes an identity authentication method and system that does not require polarization light regulation. By utilizing the intensity regulation of coherent light sources, it gets rid of the dependence on polarization light regulation in traditional quantum identity authentication systems and creates a brand-new identity authentication scheme. Through precise control and transmission of the intensity of coherent light sources, the system can generate keys with perfect privacy. Thanks to the inherent characteristics of quantum mechanics principles, it ensures the unconditional security of the keys. Even in the face of attackers with powerful computing capabilities, the keys cannot be cracked. The identity authentication scheme proposed by the present invention is based on a solid physical foundation and completely gets rid of the security defect of traditional cryptography that relies on computational complexity.
[0067] As Figure 1 shown, the present invention proposes an identity authentication system that does not require polarization light regulation. The system includes a first user 1, a second user 2, and a verifier 3 that are connected to each other in pairs; the first user 1 and the second user 2 need to authenticate each other, and the verifier 3 provides authentication services.
[0068] The first user 1 is used to generate keys with the second user 2 and the verifier 3 respectively using coherent light, calculate the encrypted information corresponding to the password R it owns through the generated keys, and send it to the verifier 3 for verification;
[0069] The second user 2 is used to generate keys with the first user 1 and the verifier 3 respectively using coherent light, calculate the encrypted information corresponding to the password R it owns through the generated keys, and send it to the verifier 3 for verification;
[0070] The verifier 3 is used to generate keys with the first user 1 and the second user 2 respectively using coherent light, and receive the verification information from the first user 1 and the second user 2 for verification.
[0071] Among them, both the first user 1 and the second user 2 include a coherent light sending unit 11 and a coherent light measuring unit 12;
[0072] As Figure 2 shown, the coherent light sending unit 11 includes a coherent light emitter 111 and an intensity modulator 112 that are connected in sequence. The coherent light emitter 111 is used to generate high extinction ratio optical pulses with controllable and stable light intensity; the intensity modulator 112 is used to adjust the light intensity of the optical pulses to the single photon level;
[0073] The coherent light measurement unit 12 includes a first beam splitter 121, a pulse time detector 122, a second beam splitter 123, a third beam splitter 124, a first interference pulse detector 125 and a second interference pulse detector 126. One output end of the first beam splitter 121 is connected to the pulse time detector 122, and the other output end is connected to one input end of the second beam splitter 123. One output end of the second beam splitter 123 is connected to one input end of the third beam splitter 124 through a first optical fiber 127, and the other output end is connected to the other input end of the third beam splitter 124 through a second optical fiber 128. The two input ends of the third beam splitter 124 are respectively connected to the first interference pulse detector 125 and the second interference pulse detector 126. The length of the second optical fiber 128 is greater than that of the first optical fiber 127, and the delay caused by the second optical fiber 128 is the delay of one time window. In this way, before the pulse is incident on the first interference pulse detector 125 and the second interference pulse detector 126, the pulse passes through two optical fibers with unequal lengths, and the second optical fiber 128 has a delay of one time window, thereby causing interference detection for each time window. Of course, the coherent light measurement unit 12 can also be divided into a time-base measurement device and an interference-base measurement device. One output of the first beam splitter 121 is connected to the time-base measurement device, and the other output is connected to the interference-base measurement device. That is to say, the time-base measurement device is the pulse time detector 122, and the interference-base measurement device is the interference detection device composed of the second beam splitter 123, the third beam splitter 124, the first interference pulse detector 125 and the second interference pulse detector 126. The first user 1, the second user 2 and the verification party 3 can also each include a post-processing module. The post-processing module is a computer, which is used to realize the control of each module at this end, as well as classical error correction, error verification and privacy amplification processes to generate the final key, etc.
[0074] The first user 1 and the second user 2 have a string of the same passwords, denoted as R, which can be compared to confirm their identities. However, the first user 1 and the second user 2 do not trust each other before confirming their identities. Directly giving the key may lead to the leakage of the password. This system can complete the comparison of the passwords for identity authentication without leaking the password to either party. This system can generate perfect keys only by using the intensity regulation and transmission of the coherent light source, simplifies the construction and operation process of the system, and makes it easier to implement and apply. Using these keys, this system can realize the identity authentication between two users.
[0075] The present invention also proposes an identity authentication method that does not require polarization light regulation, including the following steps:
[0076] (1) Encryption key generation: The first user 1 and the second user 2 generate three pairs of keys with length l1 using coherent light, denoted as key1, key2, and key3 respectively; the first user 1 and the second user 2 also have a string of the same password, denoted as R, and the length of R is set to l2, where the value of l1 is less than l2, and the specific value is determined by the first user 1 and the second user 2;
[0077] Among them, the specific process of the first user 1 and the second user 2 generating three pairs of keys with length l1 using coherent light is as follows:
[0078] 1) Randomly select one party from the first user 1 and the second user 2, denoted as the coherent light sender, responsible for emitting coherent light pulses in each time window; the other party is denoted as the coherent light receiver;
[0079] 2) The coherent light sender sends coherent light according to the following steps: The coherent light sender regards two adjacent time windows as a signal window together, that is: the first time window and the second time window are regarded as the first signal window, the third time window and the fourth time window are regarded as the second signal window,..., the (2k - 1)th time window and the 2kth time window are regarded as the kth signal window;
[0080] For the tth signal window, t ∈ {1, 2,..., k}, the coherent light sender sends a light pulse |0> s with probability p 2t-1 |α> 2t , sends a light pulse |α> s |0> 2t-1 with probability p 2t , sends a light pulse |α> d1 |α> 2t-1 with probability p 2t , sends a light pulse |0> d2 |0> 2t-1 with probability p 2t , where |0> 2t-1 |α> 2t means sending a coherent state with light intensity 0 in the (2t - 1)th time window and a coherent state with an average number of photons of α in the 2tth time window, |α> 2t-1 |0> 2t means sending a coherent state with an average number of photons of α in the (2t - 1)th time window and a coherent state with light intensity 0 in the 2tth time window, |α> 2t-1 |α> 2t means sending coherent states with an average number of photons of α in both the (2t - 1)th time window and the 2tth time window, |0> 2t-1 |0> 2tIndicates that coherent states with optical intensity 0 are sent in both the (2t - 1)-th time window and the 2t-th time window; the above p s , The values of are randomly selected by the coherent optical transmitter. Since the sum of probabilities should be 1, that is, it satisfies
[0081] The coherent optical transmitter records the sending situation of each signal window and the total number N of the sent signal windows. The value of N is randomly selected by the coherent optical transmitter;
[0082] 3) The coherent optical receiver detects the coherent light according to the following steps: As Figure 2 shown, for the optical pulses of each signal window, the coherent optical receiver first makes them incident on the first beam splitter 121. One path of the pulse output of the first beam splitter 121 is output to the time base measurement device, that is, output to the pulse time detector D0122, and the time window when the pulse time detector D0122 has a response is recorded; the other path of the pulse is output to the interference base measurement device, that is, the optical pulse is output to the second beam splitter 123. The two outputs of the second beam splitter 123 are incident on the third beam splitter 124 after propagating through optical fibers with unequal lengths. The length of one of the optical fibers is a little longer than that of the other, that is, the length of the second optical fiber 128 is greater than the length of the first optical fiber 127, and the delay caused by the second optical fiber 128 is the delay of one time window. After propagating through the optical fiber, it is incident on the third beam splitter 124 again; the two paths of pulses of the third beam splitter 124 are respectively output to the first interference pulse detector D1125 and the second interference pulse detector D2126; before being incident on the detector, the pulse passes through optical fibers with unequal lengths, and there is a delay of one time window in one path, resulting in the detection of each time window, some of which are caused by the interference of pulses in the same signal window, and some of which are caused by the interference of pulses in adjacent signal windows. As Figure 3 shown, when the coherent optical receiver ignores the response of the detector during the interference of pulses in adjacent signal windows, the coherent optical receiver only records the response situations of the first interference pulse detector D1125 and the second interference pulse detector D2126 and the corresponding signal windows when the pulses in the same signal window interfere;
[0083] If there are more than two detectors responding in the same time window, the coherent optical receiver randomly records the response of any one detector and ignores other responses;
[0084] 4) The coherent optical receiver announces which signal window's optical pulses cause the response of the pulse time detector D0, and which signal window's optical pulses cause the response of the first interference pulse detector D1 and the second interference pulse detector D2;
[0085] 5) For the signal window corresponding to the response of the pulse time detector D0, and the signal windows corresponding to the responses of the first interference pulse detector D1 and the second interference pulse detector D2, the coherent optical transmitter and the coherent optical receiver perform a coding operation to generate a key with a length of l1. The specific process is as follows:
[0086] For the signal window corresponding to the response of the pulse time detector D0, the coherent optical transmitter and the coherent optical receiver perform coding in the following manner: (a) The coherent optical transmitter makes a coding judgment in the chronological order of these signal windows: If the optical pulse sent in the signal window is |0> 2t-1 |α> t , then record the bit value 0; if the optical pulse sent in the signal window is |α> 2t-1 |0> t , then record the bit value 1; if other pulses are sent in the signal window, discard them; (b) The coherent optical transmitter announces which signal windows are discarded; (c) For the signal windows that are not discarded, the coherent optical receiver, according to the measurement result of the pulse time detector D0, if it measures that the response is in the latter time window in this signal window, record the bit value 0; if it measures that the response is in the former time window in this signal window, record the bit value 1; (d) The coherent optical transmitter and the coherent optical receiver announce the bit values recorded in the 10% of the non-discarded signal windows at the front in chronological order, and compare how many bit values are different. If the number of different bits divided by the total number is greater than or equal to 0.5, the coherent optical transmitter and the coherent optical receiver discard all the data and re-perform the operation of generating the key; if the number of different bits divided by the total number is less than 0.5, the coherent optical transmitter and the coherent optical receiver record this value, which is called the bit error rate E b ;
[0087] For the signal windows corresponding to the responses of the first interference pulse detector D1 and the second interference pulse detector D2, the coherent optical transmitter and the coherent optical receiver perform coding in the following manner: (a) The coherent optical transmitter announces the state of the optical pulses sent in these signal windows, as well as the data: N, (b) For the signal windows where the sent optical pulse is |0> 2t-1 |α> 2t , the coherent optical receiver counts the number of response windows of detector D1 among them the number of response windows of detector D2 Calculate the parameter where and respectively represent the gains on detector D1 and detector D2 when a coherent state with optical intensity 0 is sent in the (2t - 1)-th time window and a coherent state with an average photon number of α is sent in the 2t-th time window; (c) For the signal window where the coherent light receiver sends an optical pulse of |α> 2t-1 |0> 2t count the number of response windows of detector D1 in it the number of response windows of detector D2 calculate the parameter where and respectively represent the gains on detector D1 and detector D2 when a coherent state with an average photon number of α is sent in the (2t - 1)-th time window and a coherent state with optical intensity 0 is sent in the 2t-th time window; (d) For the signal window where the coherent light receiver sends an optical pulse of |α> 2t-1 |α> 2t count the number of response windows of detector D1 in it the number of response windows of detector D2 calculate the parameter where and respectively represent the gains on detector D1 and detector D2 when coherent states with an average photon number of α are sent in both the (2t - 1)-th time window and the 2t-th time window; (e) For the signal window where the coherent light receiver sends an optical pulse of |0> 2t-1 |0> 2t count the number of response windows of detector D1 in it the number of response windows of detector D2 calculate the parameter where and represent the gains on detector D1 and detector D2 when coherent states with optical intensity 0 are sent in both the (2t - 1)-th time window and the 2t-th time window; (f) The coherent light receiver calculates the gain characterized by the phase error rate of detector D1 and the gain characterized by the phase error rate of detector D2
[0088]
[0089] where μ = α 2 , N ± = 2(1 ± e -μ );
[0090] Then calculate the phase error rate E p :
[0091]
[0092] Then judge the phase error rate E p , if the phase error rate E p ≥0.5, then the coherent optical transmitter and the coherent optical receiver discard all data and regenerate the key; if the phase error rate E p <0.5, then the coherent optical transmitter and the coherent optical receiver perform error correction and privacy amplification operations on the key; after the error correction and privacy amplification operations are completed, if the key length is greater than l1, both the coherent optical transmitter and the coherent optical receiver select the first l1 bits of the key as a pair of generated keys, if the key length is less than l1, the coherent optical transmitter and the coherent optical receiver discard all data and regenerate the key.
[0093] 6) Repeat the above steps 1) - 5) multiple times until the coherent optical transmitter and the coherent optical receiver generate three pairs of keys with a length of l1.
[0094] (2) Associated key generation: The verifier 3 and the first user 1 generate a pair of keys with a length of l1 using coherent light, denoted as k1; the verifier 3 and the second user 2 generate a pair of keys with a length of l1 using coherent light, denoted as k2; as Figure 4 shown, the verifier 3 calculates where represents the bitwise exclusive OR of two strings of keys;
[0095] (3) Encryption comparison: The first user 1 and the second user 2 use the generated keys to calculate the encrypted information corresponding to their respective passwords R and send it to the verifier 3 for verification; if the verification is consistent, the comparison is successful, and the identity authentication of the first user 1 and the second user 2 passes.
[0096] Among them, the specific process of the first user 1 and the second user 2 using the generated keys to calculate the encrypted information corresponding to their respective passwords R is as follows:
[0097] A: The first user 1 first generates a binary random number sequence with a length of l1 using the key key2, that is, each bit of key2 is used as each bit of the binary random number sequence, and then simply adjusts the sequence: if the end of the sequence is 0, it is changed to 1, if the end of the sequence is 1, it remains unchanged; the adjusted sequence is denoted as where c0 = 1; this sequence is regarded as the coefficients of an l1 - order polynomial, where the highest - degree term coefficient is 1, and the remaining term coefficients correspond to the elements in the sequence. In other words, this sequence can be transformed into a polynomial in the following form:
[0098]
[0099] B: The first user 1 verifies whether the polynomial is an irreducible polynomial. If the verification is successful, proceed to the next step; otherwise, the first user 1 and the second user 2 regenerate a new key key2, and then repeat step A. Verifying whether the polynomial is an irreducible polynomial means:
[0100] For all positive integers k less than ([x] represents rounding x downwards) perform the following operations: Calculate whether holds. If the verification passes for all k, then the polynomial p(x) is an irreducible polynomial of degree n over GF(2); where gcd(f(x), g(x)) represents the greatest common divisor of two polynomials f(x) and g(x), and f(x) and g(x) refer to two arbitrary polynomials; that is, if for every positive integer k less than , the calculation result is equal to 1, then the verification is successful, and proceed to the next step.
[0101] C: The first user 1 represents the sequence as a row vector Then represent the key key1 as a column vector X = [key1(1), key1(2),..., key1(l1)] T , where T represents the transpose of the row vector, that is, it represents a column vector, and key1(i) represents the i-th bit of the key key1; then represent the password R to be compared as a column vector where R(i) represents the i-th bit of the password R;
[0102] D: The first user 1 generates l2 column vectors of length l1 according to the following rule
[0103] H1 = [key1(1), key1(2),..., key1(l1)] T
[0104] H2 = [C·H1, key1(1), key1(2),..., key1(l1 - 1)] T
[0105] H3 = [C·H2, C·H1, key1(1), key1(2),..., key1(l1 - 2)] T
[0106] ……
[0107]
[0108] where · represents the multiplication of matrices (the above is the multiplication of a row vector and a column vector, which is a special case of matrix multiplication, and the result is a number); then use these l2 column vectors of length l1 to construct an l1×l2 matrix H, and each column of matrix H from left to right is
[0109] E: The first user 1 calculates The result obtained is a column vector of length l1 The first user 1 takes the modulus of each bit of the column vector with respect to 2, that is each bit of mod 2, to obtain a bit string Y of length l1, and the bit string Y is used as the encrypted information corresponding to the password it owns;
[0110] F: The second user 2 performs the same operations of steps A to E above to obtain the encrypted information Y' corresponding to the password it owns.
[0111] The specific process of sending to the verifier 3 for verification is as follows:
[0112] S1: The first user 1 calculates the first verification information and sends the first verification information U1 to the verifier 3 through the authentication channel;
[0113] S2: The second user 2 calculates the second verification information and sends the second verification information U2 to the verifier 3 through the authentication channel;
[0114] S3: The verifier 3 calculates and compares whether it is the same as k3. If they are the same, it announces that the comparison is successful, and the identity authentication of the first user 1 and the second user 2 passes; if they are not the same, it announces that the comparison is unsuccessful, and the identity authentication of the first user 1 and the second user 2 fails.
[0115] The present invention uses the intensity regulation and transmission of coherent light sources to generate perfect keys, simplifies the construction and operation process of the system, and makes it easier to implement and apply; at the same time, the present invention uses the principles of quantum mechanics to ensure the privacy of the keys. Even if an eavesdropper has powerful quantum computing capabilities, it cannot be cracked; therefore, the present invention has unconditional security and raises the security of identity authentication to a new level.
Claims
1. An identity authentication method that does not require polarized light control, characterized in that: The following steps are involved: (1) Encryption key generation: The first user and the second user use coherent light to generate three pairs of keys of length l1, denoted as key1, key2, and key3 respectively. The first user and the second user also have the same password, denoted as R, the length of R is set to l2, and the value of l1 is less than l2. (2) Generation of associated keys: The authenticator and the first user use coherent light to generate a pair of keys of length l1, denoted as k1; the authenticator and the second user use coherent light to generate a pair of keys of length l1, denoted as k2; the authenticator calculates in Represents the bit-by-bit XOR of two strings of keys; (3) Encryption comparison: The first user and the second user use the generated key to calculate the encrypted information corresponding to their respective passwords R, and send it to the verification party for verification; if the verification is consistent, the comparison is successful, and the identity authentication of the first user and the second user is passed.
2. The identity authentication method according to claim 1, wherein: The specific process of the first user and the second user generating three pairs of keys of length l1 using coherent light is as follows: 1) Randomly select one of the first user and the second user as the coherent light sender, which is responsible for sending coherent light pulses in each time window; the other user is recorded as the coherent light receiver; 2) The coherent optical transmitter regards two adjacent time windows as one signal window, that is, the first time window and the second time window are regarded as the first signal window, the third time window and the fourth time window are regarded as the second signal window, ..., the 2k-1th time window and the 2kth time window are regarded as the kth signal window; For the t-th signal window, t∈{1,2,…,k}, the coherent optical transmitter uses p s The probability of sending a light pulse|0> 2t-1 |α> 2t , with p s The probability of sending a light pulse |α> 2t-1 |0> 2t ,by The probability of sending a light pulse |α> 2t-1 |α> 2t ,by The probability of sending a light pulse|0> 2t-1 |0> 2t , where |0> 2t-1 |α> 2t Indicates that a coherent state with a light intensity of 0 is sent in the 2t-1th time window, and a coherent state with an average number of photons α is sent in the 2tth time window, |α> 2t-1 |0> 2t Indicates that a coherent state with an average number of photons α is sent in the 2t-1 time window, and a coherent state with a light intensity of 0 is sent in the 2t time window, |α> 2t-1 |α> 2t Indicates that a coherent state with an average number of photons α is sent in both the 2t-1 time window and the 2t time window, |0> 2t-1 |0> 2t Indicates that the coherent state with light intensity of 0 is sent in both the 2t-1 time window and the 2t time window; the above p s , The value of is randomly selected by the coherent optical transmitter and satisfies The coherent optical transmitter records the transmission status of each signal window and the total number N of the transmitted signal windows, where the value of N is randomly selected by the coherent optical transmitter; 3) For the optical pulse of each signal window, the coherent light receiver firstly incidents it on the first beam splitter, and one pulse of the first beam splitter is output to the pulse time detector D0, and the time window in which the pulse time detector D0 responds is recorded; the other pulse is output to the second beam splitter, and the two outputs of the second beam splitter are incident to the third beam splitter after propagating through optical fibers of unequal lengths, and the two pulses of the third beam splitter are respectively output to the first interference pulse detector D1 and the second interference pulse detector D2; when the coherent light receiver only records the pulse interference of the same signal window, the response of the first interference pulse detector D1 and the second interference pulse detector D2 and their corresponding signal windows; If more than two detectors respond in the same time window, the coherent light receiver randomly records the response of any one detector and ignores the other responses; 4) The coherent light receiver announces which light pulses in the signal windows cause the response of the pulse time detector D0, and which light pulses in the signal windows cause the response of the first interference pulse detector D1 and the second interference pulse detector D2; 5) For the signal window corresponding to the response of the pulse time detector D0, and the signal window corresponding to the response of the first interference pulse detector D1 and the second interference pulse detector D2, the coherent light transmitter and the coherent light receiver perform a coding operation to generate a key of length l1; 6) Repeat the above steps 1) to 5) multiple times until the coherent optical sender and the coherent optical receiver generate three pairs of keys of length l1.
3. The identity authentication method according to claim 2, wherein: The specific process of the coherent light transmitter and the coherent light receiver performing coding operation on the signal window corresponding to the response of the pulse time detector D0 and the signal window corresponding to the response of the first interference pulse detector D1 and the second interference pulse detector D2 to generate a key of length l1 is as follows: For the signal window corresponding to the response of the pulse time detector D0, the coherent light transmitter and the coherent light receiver perform coding in the following manner: (a) The coherent light transmitter performs coding judgment according to the time sequence of these signal windows: If the optical pulse sent by the signal window is |0> 2t-1 |α> t , then the bit value 0 is recorded; if the light pulse sent by the signal window is |α> 2t-1 |0> t , then record the bit value 1; if the signal window sends other pulses, it is discarded; (b) The coherent optical sender announces which signal windows are discarded; (c) For the signal windows that are not discarded, the coherent optical receiver, based on the measurement results of the pulse time detector D0, if it is measured that the latter time window in the signal window has a response, then record the bit value 0; if it is measured that the former time window in the signal window has a response, then record the bit value 1; (d) The coherent optical sender and the coherent optical receiver announce the bit values recorded in the first 10% of the non-discarded signal windows in chronological order, and compare how many bit values are different. If the number of different bits divided by the total number is greater than or equal to 0.5, the coherent optical sender and the coherent optical receiver discard all data and regenerate the key; if the number of different bits divided by the total number is less than 0.5, the coherent optical sender and the coherent optical receiver record this value, which is called the bit error rate E b ; For the signal windows corresponding to the responses of the first interference pulse detector D1 and the second interference pulse detector D2, the coherent light transmitter and the coherent light receiver perform coding in the following manner: (a) The coherent light transmitter publishes the states of the optical pulses sent in these signal windows, as well as the data: N, (b) The coherent optical receiver is |0> 2t-1 |α> 2t The signal window of the detector D1 is counted. Number of response windows of detector D2 Calculation parameters in and They represent the gain on detector D1 and the gain on detector D2 when the coherent state with a light intensity of 0 is sent in the 2t-1th time window and the coherent state with an average number of photons α is sent in the 2tth time window. (c) The coherent light receiver has |α> 2t-1 |0> 2t The signal window of the detector D1 is counted. Number of response windows of detector D2 Calculation parameters in and They represent the gain on detector D1 and the gain on detector D2 when the coherent state with an average number of photons α is sent in the 2t-1th time window and the coherent state with a light intensity of 0 is sent in the 2tth time window. (d) The coherent light receiver has |α> 2t-1 |α> 2t The signal window of the detector D1 is counted. Number of response windows of detector D2 Calculation parameters in and They represent the gain on detector D1 and the gain on detector D2 in the coherent state with an average number of photons α in both the 2t-1 time window and the 2t time window; (e) The coherent light receiver has |0> 2t-1 |0> 2t The signal window of the detector D1 is counted. Number of response windows of detector D2 Calculation parameters in and represents the gain on detector D1 and the gain on detector D2 in the coherent state where the light intensity is 0 in both the 2t-1 time window and the 2t time window; (f) The coherent light receiver calculates the phase error rate of detector D1 to represent the gain The phase error rate of detector D2 characterizes the gain Where, μ=α 2 ,N ± =2(1±e -μ ); Then calculate the phase error rate E p : Then determine the phase error rate E p , if the phase error rate E p ≥0.5, the coherent optical transmitter and the coherent optical receiver discard all data and regenerate the key; if the phase error rate E p <0.5, the coherent optical sender and the coherent optical receiver perform error correction and privacy amplification operations on the key; after the error correction and privacy amplification operations are completed, if the key length is greater than l1, the coherent optical sender and the coherent optical receiver both select the first l1 bits of the key as a pair of keys to be generated; if the key length is less than l1, the coherent optical sender and the coherent optical receiver discard all data and regenerate the key.
4. The identity authentication method according to claim 1, wherein: The specific process of the first user and the second user using the generated key to calculate the encrypted information corresponding to the password R they each own is: A: The first user first uses the key key2 to generate a binary random number sequence of length l1, that is, each bit of key2 is used as each bit of the binary random number sequence, and then simply adjusts the sequence: if the end of the sequence is 0, it is changed to 1; the adjusted sequence is expressed as Where c0 = 1; then convert the sequence into a polynomial of the following form: B: The first user verifies whether the polynomial is an irreducible polynomial. If the verification is successful, the next step is performed; otherwise, the first user and the second user regenerate a new key key2 and then repeat step A; C: The first user will sequence Represented as a row vector Then the key key1 is represented as a column vector X = [key1(1), key1(2), ..., key1(l1)] T , where T represents the transpose of the row vector, i.e., the column vector, and key1(i) represents the i-th bit of the key key1; then the password R to be compared is represented as a column vector Where R(i) represents the i-th bit of the password R; D: The first user generates l2 column vectors of length l1 according to the following rule H1=[key1(1),key1(2),...,key1(l1)] T H2=[C·H1,key1(1),key1(2),...,key1(l1-1)] T H3=[C·H2,C·H1,key1(1),key1(2),...,key1(l1-2)] T …… where · represents matrix-matrix multiplication; then using l2 column vectors of length l1 Construct a l1×l2 matrix H, where each column from left to right is E: First User Computing The result is a column vector of length l1 The first user will column vector Each bit of the modulo 2 is Mod 2 for each bit of , and get a bit string Y with a length of l1. The bit string Y is used as the encrypted information corresponding to the password you own; F: The second user performs the same operations as above steps A to E and obtains the encrypted information Y corresponding to the password he owns ′ .
5. The identity authentication method according to claim 4, which does not require polarized light control, is characterized in that: The specific process of sending the verification to the verification party is as follows: S1: The first user calculates the first verification information And send the first verification information U1 to the verification party through the authentication channel; S2: The second user calculates the second verification information and sending the second verification information U2 to the verification party through the authentication channel; S3: Verifier Calculation Compare whether they are consistent with k3. If they are consistent, the comparison is successful, and the identity authentication of the first user and the second user is passed; if they are inconsistent, the comparison is unsuccessful, and the identity authentication of the first user and the second user is failed.
6. The identity authentication method according to claim 4, wherein: The first user verifies whether the polynomial is an irreducible polynomial by: For all less than The following operation is performed for a positive integer k, where [x] means rounding x down: Is it true? If it is verified for all k, then the polynomial p(x) is an irreducible polynomial of order n on GF(2); where gcd(f(x), g(x)) represents the greatest common factor of the two polynomials f(x) and g(x), and f(x) and g(x) are two arbitrary polynomials; that is, if for every value less than If the calculated result of any positive integer k is equal to 1, the verification is successful and we proceed to the next step.
7. A system based on the identity authentication method not requiring polarization light control according to any one of claims 1 to 6, characterized in that: The system includes a first user, a second user and a verification party connected in pairs; The first user is used to generate a key with the second user and the verification party respectively by using coherent light, and calculates the encrypted information corresponding to the password R owned by the first user by using the generated key, and sends it to the verification party for verification; The second user is used to generate a key with the first user and the verification party respectively by using coherent light, and calculates the encrypted information corresponding to the password R owned by the second user by using the generated key, and sends it to the verification party for verification; The verification party is used to generate keys with the first user and the second user party respectively by using coherent light, and receive verification information from the first user and the second user for verification.
8. The system according to claim 7, characterized in that: The first user and the second user each include a coherent light transmitting unit and a coherent light measuring unit; The coherent light transmitting unit comprises a coherent light transmitter and an intensity modulator connected in sequence, wherein the coherent light transmitter is used to generate a high extinction ratio light pulse with controllable and stable light intensity; and the intensity modulator is used to adjust the light intensity of the light pulse to a single photon level; The coherent light measurement unit includes a first beam splitter, a pulse time detector, a second beam splitter, a third beam splitter, a first interference pulse detector and a second interference pulse detector. An output end of the first beam splitter is connected to the pulse time detector, and the other output end is connected to an input end of the second beam splitter; an output end of the second beam splitter is connected to an input end of the third beam splitter through a first optical fiber, and the other output end is connected to the other input end of the third beam splitter through a second optical fiber. The two input ends of the third beam splitter are respectively connected to the first interference pulse detector and the second interference pulse detector.
9. The system according to claim 8, characterized in that: The length of the second optical fiber is greater than that of the first optical fiber, and the delay caused by the second optical fiber is a delay of a time window.