Quantum fault-tolerant implementation method for S box with ZUC algorithm serial number of 0

By analyzing and designing the sub-components of the S-box S0 of the Zuchong algorithm, the quantum fault tolerance implementation with low T depth is achieved, the problem of lack of efficient methods in the prior art is solved, the efficiency of the quantum implementation circuit is improved and the cost is reduced.

CN120197722AActive Publication Date: 2025-06-24NAT UNIV OF DEFENSE TECH
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510269879.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-06-24
Estimated Expiration
2045-03-07

AI Technical Summary

Technical Problem

There is a lack of efficient methods in the prior art to design quantum fault-tolerant implementations of S-boxes with the Zu Chongzhi algorithm numbered 0, especially under low T depth conditions.

Method used

By analyzing the algebraic structure of the S box S0 of Zu Chong's algorithm, the information of its sub-components P1, P2 and P3 is extracted, and the low-T depth implementation of these sub-components is designed. Combined with sub-components P2 and P3, the low-T depth implementation of this combination is designed, and finally the implementation of sub-components P1, P2 and P3 is combined to obtain the low-T depth implementation of S0.

Benefits of technology

It effectively accelerates the implementation efficiency of the quantum implementation circuit of Zu Chongzhi algorithm, reduces the cost of implementing related quantum circuits, and realizes the low-T depth fault tolerance implementation of Zu Chongzhi algorithm S box S0.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197722A_ABST
    Figure CN120197722A_ABST
Patent Text Reader

Abstract

The invention discloses a quantum fault-tolerant implementation method for an S box with a ZUC algorithm serial number of 0, and the method comprises the steps: S1, analyzing an algebraic structure of the ZUC algorithm S box S0, and extracting the information of subcomponents P1, P2 and P3 of the ZUC algorithm S box S0; s2, designing low T depth implementation of the subcomponent P1; s3, combining the subcomponent P2 and the subcomponent P3, and designing low T depth implementation of the combination; and S4, realizing the combined subcomponents P1, P2 and P3 to obtain low T depth realization of S0. According to the invention, the efficiency of realizing a ZUC algorithm circuit in a quantum application scene is effectively improved, and the cost of realizing a related quantum circuit is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of quantum optimization of the S-box S0 of the Zu Chongzhi algorithm sub-component, and more specifically, to a quantum fault-tolerant implementation method for the S-box numbered 0 of the Zu Chongzhi algorithm. Background Art

[0002] The development of quantum computers poses a serious threat to modern cryptography. For symmetric ciphers, quantum computers can reduce the complexity of brute-force cracking to the square root level through the Grover algorithm. This means that for a 128-bit key, a quantum computer requires approximately 2 64 attempts, while a classical computer requires 2 128 attempts.

[0003] Whether attacking a specific cryptographic algorithm based on the Shor algorithm or the Grover algorithm, the quantum implementation circuit of the algorithm is an important part of launching a quantum attack by means of the above-mentioned quantum algorithms. On the one hand, in current quantum model machines, quantum bits are vulnerable to the influence of the surrounding environment and decoherence occurs, which makes the advantage of quantum computers over classical computers no longer obvious. Therefore, completing the function of the quantum circuit before the occurrence of decoherence poses higher requirements for the running time of the quantum circuit; on the other hand, a quantum circuit is actually a combination of quantum logic gates, and the Clifford+T logic gate set is a quantum fault-tolerant gate. In view of the application requirements of quantum error correction, this logic gate set is widely used in the design of quantum circuits. The running time of a circuit is closely related to the circuit depth, and in the Clifford+T logic gate set, the implementation cost of the T gate is much greater than that of other logic gates in the logic gate set. Therefore, constructing a quantum implementation circuit with a low T-depth for a cryptographic algorithm based on the Clifford+T logic gate set to meet the application requirements of quantum error correction has received wide attention.

[0004] The Zu Chongzhi algorithm is an important symmetric cipher, which is a national cryptographic industry standard and national standard in China, and also an ISO / IEC international standard. It is widely used to protect the confidentiality and integrity of data. Researching the quantum optimization implementation of the Zu Chongzhi algorithm in the post-quantum era has very important strategic significance. Confusion is one of the two basic principles to be followed in the design of symmetric ciphers, and the S-box is commonly used as a sub-component of symmetric ciphers to provide confusion. For the Zu Chongzhi algorithm, its S-box includes S-box S0 and S-box S1, and both are 8-bit S-boxes. However, whether for classical application scenarios or quantum application scenarios, there is no efficient method or tool for designing the optimized implementation of 8-bit S-boxes. At the same time, the S-box S1 of the Zu Chongzhi algorithm is isomorphic to the S-box of the US Advanced Encryption Standard (AES) algorithm, and its efficient implementation can refer to the implementation method of the AES algorithm S-box. In contrast, there is currently no available efficient method for constructing a low T-depth fault-tolerant implementation of the S-box S0 of the ZUC algorithm. Summary of the Invention

[0005] The purpose of the present invention is to provide a quantum fault-tolerant implementation method for the S-box numbered 0 of the Zu Chongzhi algorithm, so as to overcome the defects existing in the prior art.

[0006] In order to achieve the above purpose, the technical solution adopted by the present invention is as follows:

[0007] A quantum fault-tolerant implementation method for the S-box numbered 0 of the Zu Chongzhi algorithm, comprising the following steps:

[0008] S1. Analyze the algebraic structure of the S-box S0 of the Zu Chongzhi algorithm, and extract the information of the sub-components P1, P2, and P3 of the S-box S0 of the Zu Chongzhi algorithm;

[0009] S2. Design a low-T-depth implementation of the sub-component P1;

[0010] S3. Combine the sub-components P2 and P3, and design a low-T-depth implementation of this combination;

[0011] S4. Combine the implementations of the sub-components P1, P2, and P3 to obtain a low-T-depth implementation of S0.

[0012] Further, in the step S1, the S-box S0 of the Zu Chongzhi algorithm is an 8-bit S-box and is composed of three sub-components P1, P2, and P3.

[0013] Further, in the step S2, a quantum AND gate with a T-depth of 1 is used to construct a low-T-depth quantum implementation circuit, specifically including:

[0014] S21. Calculate the information related to the algebraic normal form of the sub-component P1;

[0015] S22. Design an implementation with a better AND gate depth and the number of AND gates according to the information related to the algebraic normal form of the sub-component P1;

[0016] S23. Combine the classical optimized implementation of the sub-component P1 with the quantum implementation cost to convert it into a low-T-depth quantum optimized implementation.

[0017] Further, the step S21 specifically includes:

[0018] Let the input of the S-box S0 of the Zu Chongzhi algorithm be denoted as X = (x0, x1,..., x7), the input of the sub-component P1 be A = X2 = (x4, x5, x6, x7), and the output of P1 be B = (b0, b1, b2, b3), then:

[0019] The expression of b0 is:

[0020] The expression of b1 is:

[0021] The expression of b2 is:

[0022] The expression of b3 is:

[0023] Furthermore, the step S22 specifically includes:

[0024] S221: Denote N as the number of AND gates required to finally implement P1, n as the number of AND gates required in the current implementation, and i as the subscript of the output bit of P1, where i ∈ {0, 1, 2, 3}. Initialize N = 8, n = 0, i = 0;

[0025] S222: If the expression of b i has been processed, then i = i + 1 and transfer to step S223; if the expression of b i has not been processed, directly transfer to step S223;

[0026] S223: Count the occurrence times of each variable in the monomials of degree 2 in the expression of b i , and use the variable with the most occurrences to extract the common factor from the expression of b i . If there are multiple variables with the highest frequency of occurrence, randomly select one. If the extracted variable itself is a monomial in b i , that is, there is an exclusive OR of this variable in the expression of b i , use this variable as the common factor to process this exclusive OR operation, and repeat this step until there are no common factors that can be extracted in the remaining quadratic monomials of b i . Count and update the number of AND gates in the expression of b i and add it to n, i = i + 1, and transfer to step S224;

[0027] S224: If i = 4, then the expressions of b0, b1, b2, and b3 have been processed, and transfer to step S225; otherwise, if i ≤ 3, then the expressions of b0, b1, b2, and b3 have not been processed, and transfer to step S222;

[0028] S225: If N > n, then find a realization scheme with fewer AND gate consumptions, update N = n and transfer to step S226; otherwise, if no realization scheme with fewer AND gate consumptions is found, directly transfer to step S226;

[0029] S226: Let n = 0, i = 0, and transfer to step S222 until a realization scheme with fewer AND gate consumptions cannot be found after repeated attempts, and obtain a realization scheme with an AND gate depth of 1 and relatively optimal AND gate consumption for P1.

[0030] Furthermore, the step S23 specifically includes:

[0031] S231. Use the CNOT gate and the Pauli-X gate to simulate the exclusive OR operation and the negation operation in the expressions of the modified b0, b1, b2, and b3. The expressions are as follows:

[0032]

[0033] S232. For the AND operation in the expressions of the modified b0, b1, b2, and b3, that is Design a parallel implementation scheme using 4 QAND gates.

[0034] S233. Parallelly call 4 QAND gates to simulate 4 AND operations in the expression of the modified P1 under the condition that the T depth is 1:

[0035] QAND(t2, x4, t4, t8), QAND(t1, x7, t5, t9),

[0036] QAND(t3, x5, t6, t 10 ), QAND(t0, x6, t7, t 11 ),

[0037] where the values of t8, t9, t 10 , t 11 are 0, which are the quantum auxiliary bits in the QAND gate and their values remain unchanged before and after calling the QAND gate;

[0038] S234. Calculate the output of P1:

[0039]

[0040] Furthermore, the step S3 specifically includes:

[0041] S31. Calculate the algebraic normal form of the sub-components P2 and P3

[0042] S32. Calculate the algebraic normal form of the combination of the sub-components P2 and P3

[0043] S33. Design a relatively optimal implementation of their AND gate depth and the number of AND gates in stages according to the algebraic normal forms of the sub-components P2 and P3.

[0044] Furthermore, the step S31 specifically includes:

[0045] Let the input of P2 be C = (c0, c1, c2, c3) and the output be D = (d0, d1, d2, d3), then:

[0046] The expression of d0 is:

[0047]

[0048] The expression of d1 is:

[0049]

[0050] The expression of d2 is:

[0051]

[0052] The expression of d3 is:

[0053]

[0054] Let the input of P3 be E = (e0, e1, e2, e3) and the output be F = (f0, f1, f2, f3), then:

[0055] The expression of f0 is as follows:

[0056]

[0057] The expression of f1 is as follows:

[0058]

[0059] The expression of f2 is as follows:

[0060]

[0061] The expression of f3 is as follows:

[0062]

[0063] The specific steps of S32 include:

[0064] Denote the combination of P2 and P3 as P. Assume the input of S-box S0 is X = (x0, x1, …, x7), and the output of P1 is (p0, p1, p2, p3). Then the input of P is Briefly denoted as (q0, q1, …, q7). Denote the output of P as (y0, y1, …, y7). Obtain the expressions of the 8 output variables of P according to the expressions of P2 and P3;

[0065] The expression of y0 is:

[0066]

[0067] The expression of y1 is:

[0068]

[0069] The expression of y2 is:

[0070]

[0071]

[0072] The expression of y3 is:

[0073]

[0074] The expression of y4 is:

[0075]

[0076] The expression of y5 is:

[0077]

[0078] The expression of y6 is:

[0079]

[0080] The expression of y7 is:

[0081]

[0082] Further, the step S33 specifically includes:

[0083] The first stage of processing the output variable algebraic normal form of P includes:

[0084] Step 1: Denote N1 as the number of AND gates required to implement P in the first stage, n as the number of AND gates required in the current implementation, initialize N1 = 28, n = 28, and go to Step 2;

[0085] Step 2: Randomly select n from the 28 AND operations available in the first stage and substitute them into the expressions of the 8 outputs of P, and go to Step 3;

[0086] Step 3: If the algebraic degrees of the modified 8 expressions are not more than 2 for the current n value, go to Step 4; otherwise, if the algebraic degrees of the modified 8 expressions are all more than 2 at the current n value, go to Step 2. If the algebraic degrees of the modified 8 expressions are more than 2 for a long time at the current n value, it means that the n AND operations are likely unable to reduce the algebraic degree of the expression of P to 2, and go to Step 5;

[0087] Step 4: If N1 > n, it means that the implementation scheme of the AND gate is found, update the number of AND gates in the first stage N1 = n, set n = n - 1, and go to Step 2; otherwise, at this time, the number of AND gates has not been optimized, and go to Step 2;

[0088] Step 5: At this time, N1 is the number of AND gates that can reduce the algebraic degree of the output expression of P to 2. Save the N1 AND operations selected in Step 2, and update the 8 output expressions of P to quadratic expressions accordingly.

[0089] The second stage of processing the algebraic normal form of the output variables of P includes:

[0090] First step: Denote N2 as the number of AND gates required to implement P in the second stage, n as the number of AND gates required in the current implementation, and i as the subscript of the output bit of P, that is, i ∈ {0, 1, …, 7}. Initialize N2 = 100, n = 0, i = 0, and go to the second step;

[0091] Second step: If the expression of y i has been processed, i = i + 1 and go to the third step; if the expression of y i has not been processed, directly go to the third step;

[0092] Third step: Count the occurrence times of each variable in the quadratic monomials with algebraic degree 2 in the expression of y i , and use the variable with the most occurrences to extract the common factor from the expression of y i . If there are multiple variables with the highest occurrence frequency, randomly select one. If the extracted variable itself is a monomial in y i , that is, there is an exclusive OR of this variable in the expression of y i , also use this variable as the common factor to process this exclusive OR operation. Repeat this step until there are no common factors that can be extracted from the remaining quadratic monomials of y i . Count and add the number of AND gates in the updated expression of y i to n, i = i + 1, and go to the fourth step;

[0093] Fourth step: If i = 8, the expressions of y0, y1, …, y7 have been processed, go to the fifth step; otherwise, if i ≤ 7, the expressions of y0, y1, …, y7 have not been processed, go to the second step;

[0094] Fifth step: If N2 > n, it proves that a realization scheme with fewer AND gate consumptions is found. Update N2 = n and go to the sixth step; otherwise, if a realization scheme with fewer AND gate consumptions is not found, directly go to the sixth step;

[0095] Sixth step: Let n = 0, i = 0, and go to the second step until a realization scheme with fewer AND gate consumptions cannot be found after repeated attempts, and obtain a better realization scheme for the number of AND gates consumed by P in the second stage.

[0096] Further, the specific steps of step S4 include:

[0097] S41. Convert the low AND gate depth implementation of sub-components P2 and P3 into a quantum-optimized implementation of its low T depth, including using QAND gates to simulate AND gates in the classical implementation, using CNOT gates to simulate XOR operations in the classical implementation, and using Pauli-X gates to simulate inversion operations in the classical implementation;

[0098] S42. Complete the replacement between variables. Assume that the input of P is (q0, q1, …, q7) and the output is (y0, y1, …, y7). Denote the input variables of S-box S0 as X = (x0, x1, …, x7) and the output as S = (s0, s1, …, s7). According to the output of sub-component P1, q4 = x4, q5 = x5, q6 = x6, q7 = x7, and there is only a cyclic shift operation between (y0, y1, …, y7) and (s0, s1, …, s7). It is obtained that (s0, s1, …, s7) is obtained by cyclically shifting (y0, y1, …, y7) 5 bits to the left, i.e., (s0, s1, …, s7) = (y5, y6, y7, y0, y1, y2, y3, y4).

[0099] Compared with the prior art, the advantages of the present invention are as follows: A quantum fault-tolerant implementation method for S-box numbered 0 of the Zu Chongzhi algorithm provided by the present invention effectively improves the implementation efficiency of the quantum implementation circuit of the Zu Chongzhi algorithm and reduces the cost of implementing related quantum circuits. BRIEF DESCRIPTION OF THE DRAWINGS

[0100] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0101] Figure 1 It is a flowchart of the Zu Chongzhi algorithm;

[0102] Figure 2 It is a structural diagram of S-box S0 of the Zu Chongzhi algorithm;

[0103] Figure 3 It is a quantum QAND gate;

[0104] Figure 4 It is a quantum gate;

[0105] Figure 5 It is a low T-depth fault-tolerant implementation framework diagram of S-box S0 of the Zu Chongzhi algorithm of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0106] The preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings, so that the advantages and features of the present invention can be more easily understood by those skilled in the art, thereby making the protection scope of the present invention more clearly defined.

[0107] Refer to Figure 1 As shown, it is the flowchart of the Zu Chongzhi algorithm. The quantum implementation circuit involved in the present invention is for the non-linear transformation S-box ( Figure 1 in the S layer) of the Zu Chongzhi algorithm, and specifically relates to the S0 part in the S-box.

[0108] The method for obtaining the quantum optimized implementation circuit of the present invention is as follows: Analyze the algebraic structure of the S-box S0 of the Zu Chongzhi algorithm, and extract the information of the sub-components P1, P2, and P3 of S0; Design a low-T-depth implementation of the sub-component P1. For this purpose, calculate the information related to the algebraic normal form of P1, design its implementation with a better AND-gate depth and number of AND-gates according to the algebraic normal form of P1, and convert the classical optimized implementation of P1 into its low-T-depth quantum optimized implementation in combination with the quantum implementation cost; Combine P2 and P3 to design a low-T-depth implementation of this combination. For this purpose, calculate the algebraic normal forms of P2 and P3, calculate the algebraic normal form after combining P2 and P3, and design its implementation with a better AND-gate depth and number of AND-gates in stages according to the algebraic normal forms of P2 and P3; Combine the implementations of P1, P2, and P3 to obtain a low-T-depth implementation of S0. This embodiment discloses a quantum fault-tolerant implementation method for the S-box numbered 0 of the Zu Chongzhi algorithm, including the following steps:

[0109] Step S1: Analyze the algebraic structure of the S-box S0 of the Zu Chongzhi algorithm, and extract the information of the sub-components P1, P2, and P3 of the S-box S0 of the Zu Chongzhi algorithm.

[0110] The S-box S0 of the Zu Chongzhi algorithm is an 8-bit S-box and is composed of three sub-components P1, P2, and P3. The specific structure is as Figure 2 shown, where m = 5, and <<< m represents a cyclic left shift of m bits.

[0111] Both P1, P2, and P3 are non-linear transformations with 4-bit inputs and 4-bit outputs. Let x be the input, and the truth tables of P1, P2, and P3 are shown in Table 1.

[0112] Table 1 Truth tables of P1, P2, and P3

[0113] x 0 1 2 3 4 5 6 7 8 9 a b c d e f <![CDATA[P1(x)]]> 9 f 0 e f f 2 a 0 4 0 c 7 5 3 9 <![CDATA[P2(x)]]> 8 d 6 5 7 0 c 4 b 1 e a f 3 9 2 <![CDATA[P3(x)]]> 2 6 a 6 0 d a f 3 3 d 5 0 9 c d

[0114] Step S2: Design a low-T-depth implementation of the sub-component P1.

[0115] To construct a quantum implementation circuit with low T-depth, the most commonly used method currently is to use a quantum AND gate with a T-depth of 1, that is, the QAND gate. The QAND gate is a 4-input logic gate, and it requires the states of 2 of its input bits to be |0>. The circuit diagram of the QAND gate is as shown in Figure 3 and its function can be described as follows:

[0116]

[0117] where a, b ∈ {0, 1}.

[0118] To save qubits, the conjugate of the QAND gate (i.e., the gate) is often used to reset the qubit with the state |a·b> in the output of the QAND gate to |0>. The circuit diagram of the Figure 4 gate is as shown in

[0119]

[0120] where a, b ∈ {0, 1}.

[0121] Note that the basic logic components involved in the QAND gate and the gate, such as the H gate, S gate, T gate (and its conjugate gate), CNOT gate, etc., all belong to quantum fault-tolerant gates. Therefore, the QAND gate and the gate are also applicable to quantum error correction. In addition, the commonly used quantum Pauli-X gate is also a quantum fault-tolerant gate.

[0122] Step S21: Calculate the information related to the algebraic normal form of the sub-component P1.

[0123] When simulating a classical AND gate based on the QAND gate, 2 additional quantum auxiliary bits are required, one for saving the output of the classical AND gate and the other as an auxiliary bit. Therefore, when constructing a quantum implementation by using the QAND gate to simulate the AND gate in a classical circuit, the number of qubits required is closely related to the number of AND gates required to implement the classical circuit. To design a low T-depth implementation of P1 and save qubits, first study the algebraic normal form (i.e., the expression) of P1 and pay attention to the number of AND gates involved.

[0124] Assume that the input of the S-box S0 of the Zu Chongzhi algorithm is denoted as X = (x0, x1, …, x7). Combining Figure 2 it can be known that the input of P1 is A = X2 = (x4, x5, x6, x7). Denote the output of P1 as B = (b0, b1, b2, b3), then b0 can be calculated by the following expression:

[0125]

[0126] As can be seen from the above formula, the calculation of b0 consumes 2 AND gates, several XOR gates and NOT gates, where the AND gates calculate x4·x6 and x6·x7.

[0127] b1 can be calculated by the following expression:

[0128]

[0129] As can be seen from the above formula, the calculation of b1 consumes 2 AND gates and several XOR gates, where the AND gates calculate x5·x6 and x5·x7.

[0130] b2 can be calculated by the following expression:

[0131]

[0132] As can be seen from the above formula, the calculation of b2 consumes 2 AND gates and several XOR gates, where the AND gates calculate x4·x7 and x5·x7.

[0133] b3 can be calculated by the following expression:

[0134]

[0135] As can be seen from the above formula, the calculation of b3 consumes 2 AND gates, several XOR gates and NOT gates, where the AND gates calculate x4·x5 and x4·x6.

[0136] The AND gate can be simulated by the QAND gate, and the process is as described above. The XOR gate can be simulated by the quantum CNOT gate, and the NOT gate can be simulated by the quantum Pauli-X. Let a, b ∈ {0, 1}, and the function of the CNOT gate is to convert the state (|a>, |b>) into That is, to XOR the state of one qubit into another qubit. The function of the Pauli-X gate is to convert the state (|a>) into That is, to invert the state of the qubit. The specific process of simulating the XOR gate by the quantum CNOT gate and the NOT gate by the quantum Pauli-X is as follows:

[0137] For the XOR operation Directly taking the qubits corresponding to a and b as the inputs of the CNOT gate can obtain or where or corresponding to the output of the classical XOR gate.

[0138] For the NOT gate Directly taking the qubit corresponding to a as the input of the Pauli-X gate can obtain This is the output corresponding to the classical NOT gate.

[0139] For simplicity, use an operation in the form of QAND(a, b, c, d) to represent calculating a·b using a QAND gate, and use an operation in the form of QAND_C(a, b, c) to represent resetting the value of c to 0 using a gate, and use an operation in the form of to represent calculating using a CNOT gate and storing it in the qubit corresponding to a, and use an operation in the form of to represent inverting the state of the qubit corresponding to a using a Pauli-X gate.

[0140] S22. Design an implementation with a better AND gate depth and number of AND gates according to the algebraic normal form related information of the sub-component P1.

[0141] From the output expression of P1, it can be seen that the algebraic degrees of b0, b1, b2, and b3 are all 2. Therefore, P1 can be implemented within 1 AND gate depth. Intuitively, the output of P1 can be calculated using 8 AND gates, several XOR gates, and NOT gates, where the 8 AND gates calculate x4·x6, x6·x7, x5·x6, x5·x7, x4·x7, x5·x7, x4·x5, x4·x6 respectively.

[0142] Further processing of the expressions of b0, b1, b2, and b3 may reduce the number of AND gates required to calculate the output of P1, thereby saving the number of qubits. The specific steps are as follows:

[0143] Step 1. Denote N as the number of AND gates required for the final implementation of P1, n as the number of AND gates required in the current implementation, and i as the subscript of the output bit of P1, that is, i ∈ {0, 1, 2, 3}. Initialize N = 8, n = 0, i = 0, and go to Step 2.

[0144] Step 2. If the expression of b i has been processed, i = i + 1 and go to Step 3; if the expression of b i has not been processed, directly go to Step 3.

[0145] Step 3. Count the occurrence times of each variable in the quadratic monomials with algebraic degree 2 in the expression of b i , and extract the common factor from the expression of b i using the variable with the most occurrences. If there are multiple variables with the highest frequency of occurrence, randomly select one. In addition, if the extracted variable itself is a monomial in b i , that is, there is an XOR operation with this variable in the expression of b i , also use this variable as the common factor to process this XOR operation. Repeat this step until there are no common factors that can be extracted in the remaining quadratic monomials of b i After statistical updatei Add the number of AND gates in the expression to n. Let i = i + 1, and go to Step 4.

[0146] Step 4: If i = 4, it means the expressions of b0, b1, b2, and b3 have been processed, and go to Step 5; otherwise, i ≤ 3, which means the expressions of b0, b1, b2, and b3 have not been processed, and go to Step 2.

[0147] Step 5: If N > n, it proves that a realization scheme with fewer AND gate consumptions is found. Update N = n and go to Step 6; otherwise, a realization scheme with fewer AND gate consumptions is not found, and directly go to Step 6.

[0148] Step 6: Let n = 0 and i = 0, and go to Step 2 until a realization scheme with fewer AND gate consumptions cannot be found after multiple repetitions. Obtain a realization scheme of P1 with an AND gate depth of 1 and a relatively optimal number of AND gate consumptions.

[0149] The process of Step 3 is illustrated below using b0 as an example:

[0150] The expression of b0 is as follows:

[0151]

[0152] The monomials of algebraic degree 2 involved are x4·x6 and x6·x7, the variables involved are x4, x6, and x7, and the occurrence times are: 1 time, 2 times, and 1 time in sequence. Therefore, x6 with the most occurrence times is selected as the common factor and the expression of b0 is modified as follows:

[0153]

[0154] Note that in the expression of b0, there is a direct exclusive OR of x6, that is, x6 itself is already a monomial in the expression of b0. Therefore, when x6 is used as the common factor, the common factor extraction process is also performed on this exclusive OR operation as follows:

[0155]

[0156] At this time, the remaining unprocessed monomials in the expression of b0 are 1 and x4, there is no quadratic term, and there is no common factor to be extracted. According to the modified expression, implementing b0 consumes 1 AND gate, that is

[0157] After the above steps, the realization of P1 with 4 AND gates finally obtained is as follows:

[0158]

[0159] S23. Convert the classical optimized implementation of sub-component P1 into its quantum optimized implementation with low T-depth in combination with the quantum implementation cost.

[0160] To convert the implementation of P1 with 4 AND gates into a quantum implementation, QAND gates, CNOT gates, and Pauli-X gates are used to simulate the AND gates, XOR gates, and NOT gates in the classical implementation respectively. At the same time, some auxiliary bits are reset to save the number of qubits. The specific steps are as follows:

[0161] Step 1. Use CNOT gates and Pauli-X gates to simulate the XOR operation and negation operation in the expressions of the modified b0, b1, b2, and b3, that is,

[0162]

[0163] Step 2. For the AND operations in the expressions of the modified b0, b1, b2, and b3, that is, Design a parallel implementation scheme using 4 QAND gates. Note that x4, x5, x6, and x7 appear multiple times in the above four AND operations. Qubits cannot be input into two logic gates simultaneously; on the other hand, using existing qubits to avoid introducing new bits helps save the qubits required by the circuit. A 2-input AND gate has 2 inputs (operands). The above 4 AND gates have a total of 8 inputs, that is, 8 operands. x4, x5, x6, and x7 themselves can be used as the operands of the AND gates. In addition, 4 quantum auxiliary bits (denoted as t0, t1, t2, and t3) are needed to store the other 4 operands of the above 4 AND operations:

[0164]

[0165]

[0166] Step 3. Parallelly call 4 QAND gates to simulate the 4 AND operations in the expression of the modified P1 under the condition that the T-depth is 1:

[0167] QAND(t2, x4, t4, t8), QAND(t1, x7, t5, t9),

[0168] QAND(t3, x5, t6, t 10 ), QAND(t0, x6, t7, t 11 ),

[0169] where t8, t9, t 10 , t 11 have the value of 0, are the quantum auxiliary bits in the QAND gates, and their values remain unchanged before and after calling the QAND gates.

[0170] Step 4. Calculate the output of P1:

[0171]

[0172] Step S3. Combine sub-component P2 and sub-component P3, and design a low-T-depth implementation of this combination. Specifically, it includes:

[0173] Step S31. Calculate the algebraic normal form of sub-components P2 and P3

[0174] After the above steps, the output of P1 in S-box S0 is known at this time. Combining Figure 2 , let the input of P2 be C = (c0, c1, c2, c3), and the output be D = (d0, d1, d2, d3), then:

[0175] The expression of d0 is:

[0176]

[0177] The expression of d1 is:

[0178]

[0179] The expression of d2 is:

[0180]

[0181] The expression of d3 is:

[0182]

[0183] Let the input of P3 be E = (e0, e1, e2, e3), and the output be F = (f0, f1, f2, f3), then:

[0184] The expression of f0 is as follows:

[0185]

[0186] The expression of f1 is as follows:

[0187]

[0188] The expression of f2 is as follows:

[0189]

[0190] The expression of f3 is as follows:

[0191]

[0192] Step S32. Calculate the algebraic normal form of sub-component P2 combined with P3

[0193] Denote the combination of P2 and P3 as P. From Figure 2 it can be seen that assuming the input of S-box S0 is X = (x0, x1, …, x7) and the output of P1 is (p0, p1, p2, p3), then the input of P is briefly denoted as (q0, q1, …, q7). Denote the output of P as (y0, y1, …, y7). According to the expressions of P2 and P3, obtain the expressions of the 8 output variables of P;

[0194] The expression of y0 is:

[0195]

[0196] The expression of y1 is:

[0198]

[0199] The expression of y2 is:

[0200]

[0201] The expression of y3 is:

[0202]

[0203] The expression of y4 is:

[0204]

[0205] The expression of y5 is:

[0206]

[0207] The expression of y6 is:

[0208]

[0209] The expression of y7 is:

[0210]

[0211] Step S33: Design a better implementation of the AND gate depth and the number of AND gates in stages according to the algebraic normal forms of sub-components P2 and P3.

[0212] According to the expressions of y0, y1, …, y7, the algebraic degree of the expressions of the 8 output variables of P does not exceed 4. Therefore, it can be implemented within the depth of 2 AND gates. Taking the monomial q1·q2·q3·q6 in y0 as an example, in the first layer of AND gate depth, it is implemented as: t0 = q1·q2, t1 = q3·q6; in the second layer of AND gate depth, calculating t0·t1 can obtain q1·q2·q3·q6. Expressions with an algebraic degree of 4 can all be implemented within the depth of 2 AND gates in the above manner.

[0213] Therefore, for the implementation of the combination of P2 and P3 (i.e., P), it is divided into two stages: in the first stage, the algebraic degree of the output variables is reduced to 2; in the second stage, an implementation with less consumption of AND gates for expressions with an algebraic degree of 2 is designed.

[0214] Step S331, the first stage of processing the algebraic normal form of the output variables of P, includes:

[0215] In the first stage, the algebraic degree of the expressions of the output variables of P is reduced to 2. The output of the AND operation in the first stage is in the form of q i ·q j , where i, j = 0, 1, …, 7, and i ≠ j. Therefore, there are at most 28 kinds of AND operation outputs that can be utilized in the first stage, namely

[0216] q0·q1, q0·q2, …, q0·q7,

[0217] q1·q2, q1·q3, …, q1·q7,

[0218] q2·q3, q2·q4, …, q2·q7,

[0219] q3·q4, q3·q5, …, q3·q7,

[0220] q4·q5, q4·q6, q4·q7,

[0221] q5·q6, q5·q7,

[0222] q6·q7.

[0223] Step 1: Denote N1 as the number of AND gates required to implement P in the first stage, n as the number of AND gates required in the current implementation, initialize N1 = 28, n = 28, and transfer to Step 2;

[0224] Step 2: Randomly select n from the 28 AND operations available in the first stage and substitute them into the expressions of the 8 outputs of P, and then transfer to Step 3;

[0225] Step 3: If the algebraic degrees of the 8 modified expressions at the current value of n do not exceed 2, go to Step 4; otherwise, if the algebraic degrees of the 8 modified expressions at the current value of n all exceed 2 at this time, go to Step 2. If the algebraic degrees of the 8 modified expressions at the current value of n exceed 2 for a long time, it indicates that the AND operation with n variables will probably not reduce the algebraic degree of the expression of P to 2, then go to Step 5;

[0226] Step 4: If N1 > n, it means that the implementation scheme of the AND gate is found. Update the number of AND gates in the first stage N1 = n, set n = n - 1, and go to Step 2; otherwise, at this time the number of AND gates has not been optimized, then go to Step 2;

[0227] Step 5: At this time, N1 is the number of AND gates that can reduce the algebraic degree of the output expression of P to 2. Save the N1 AND operations selected in Step 2, and update the 8 output expressions of P to quadratic expressions accordingly.

[0228] Step S332: Process the second stage of the algebraic normal form of the output variables of P.

[0229] At the beginning of the second stage, after the first stage, the maximum algebraic degree of the expressions of the output variables of P is 2. Note that the algebraic degree of the expressions of the output variables of P1 is also 2. Therefore, the process of processing the expressions of P in the second stage is the same as the process of processing the expressions of P1 before, only the number of output bits is different. P has 8 outputs, while the number of output bits of P1 is 4. The specific steps of processing the expressions of P are as follows:

[0230] First step: Denote N2 as the number of AND gates required to implement P in the second stage, n marks the number of AND gates required in the current implementation, and i is used to mark the subscript of the output bit of P, that is, i ∈ {0, 1, …, 7}. Initialize N2 = 100, n = 0, i = 0, and go to the second step;

[0231] Second step: If the expression of y i has been processed, i = i + 1 and go to the third step; if the expression of y i has not been processed, directly go to the third step;

[0232] Third step: Count the occurrence times of each variable in the monomials with algebraic degree 2 in the expression of y i , and extract the common factor from the expression of y i using the variable with the most occurrences. If there are multiple variables with the highest occurrence frequency, randomly select one. If the extracted variable itself is a monomial in y i , that is, there is an exclusive OR operation with this variable in the expression of y i , also use this variable as the common factor to process this exclusive OR operation, and repeat this step until y iThere is no common factor that can be extracted from the remaining quadratic monomials, and the number of AND gates in the expression of y after statistical update is added to n, i = i + 1, and then go to the fourth step; i

[0233] Fourth step: If i = 8, the expressions of y0, y1, …, y7 have been processed, then go to the fifth step; otherwise, if i ≤ 7, the expressions of y0, y1, …, y7 have not been processed, then go to the second step;

[0234] Fifth step: If N2 > n, it proves that a realization scheme with fewer AND - gate consumptions is found. Update N2 = n and then go to the sixth step; otherwise, if a realization scheme with fewer AND - gate consumptions is not found, directly go to the sixth step;

[0235] Sixth step: Let n = 0, i = 0, and then go to the second step. Repeat this process until a realization scheme with fewer AND - gate consumptions cannot be found after multiple repetitions, and then obtain a realization scheme with better AND - gate consumption number for the second - stage P.

[0236] Step S4: Combine the realizations of sub - components P1, P2, and P3 to obtain a low - T - depth realization of S0.

[0237] Step S41: Convert the low AND - gate - depth realizations of sub - components P2 and P3 into their low - T - depth quantum - optimized realizations. This process is similar to the process of converting the low AND - gate - depth realization of P1 into its low - T - depth quantum - optimized realization, that is: use QAND gates to simulate AND gates in classical realizations, use CNOT gates to simulate XOR operations in classical realizations, and use Pauli - X gates to simulate negation operations in classical realizations;

[0238] Step S42: Complete the substitution between variables. For example, when dealing with the combination of P2 and P3 (i.e., P), for simplicity, the present invention assumes that the input of P is (q0, q1, …, q7) and the output is (y0, y1, …, y7). From Figure 2 it can be seen that neither (q0, q1, …, q7) nor (y0, y1, …, y7) is the input and output of the S - box S0. Denote the input variables of the S - box S0 as X=(x0, x1, …, x7) and the output as S=(s0, s1, …, s7). Combining Figure 2 , and the output of P1, it is easy to know that q4 = x4, q5 = x5, q6 = x6, q7 = x7, and there is only a cyclic shift operation between (y0, y1, …, y7) and (s0, s1, …, s7). That is to say, (s0, s1, …, s7) can be obtained by cyclically shifting (y0, y1, …, y7) to the left by 5 bits, that is, (s0, s1, …, s7)=(y5, y6, y7, y0, y1, y2, y3, y4). ​

[0239] Using the above steps in this embodiment, a fault-tolerant circuit for the S-box S0 of the Zu Chongzhi algorithm can be implemented within 3 T depths. Since the S-box S0 of the Zu Chongzhi algorithm is an 8-bit S-box, the maximum algebraic degree of its output bits is 7. It can be seen therefrom that the minimum AND gate depth for calculating the output bits of S0 by means of a 2-input classical AND gate is i.e., 3. In this embodiment, a classical implementation with an AND gate depth of 3 is constructed, and then based on this classical implementation and by means of QAND gates to simulate AND gates, a fault-tolerant circuit for S0 is constructed. Therefore, the AND gate depth of the classical implementation constructed by the present invention reaches the theoretical optimum, which also optimizes the T depth of the quantum implementation constructed by the present invention.

[0240] Currently, the T depth of the quantum implementation designed for the sub-component S-box S0 of the Zu Chongzhi algorithm is 7, and the T depth of the quantum implementation scheme of S0 designed by the present invention is only 3. Therefore, from the perspective of circuit depth, the quantum implementation circuit designed by the present invention saves the implementation cost of the sub-component S-box S0 in the non-linear layer of the Zu Chongzhi algorithm. Further, by using the implementation scheme designed by the present invention, the quantum implementation cost of the Zu Chongzhi algorithm can be effectively reduced.

[0241] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, the patent owner can make various deformations or modifications within the scope of the appended claims. As long as it does not exceed the protection scope described in the claims of the present invention, it should be within the protection scope of the present invention.

Claims

1. A quantum fault-tolerant implementation method for an S-box numbered 0 of the Zu Chongzhi algorithm, characterized in that: The following steps are involved: S1, analyze the algebraic structure of Zu Chongzhi's algorithm S-box S0, and extract the information of subcomponents P1, P2 and P3 of Zu Chongzhi's algorithm S-box S0; S2, design a low T depth implementation of subcomponent P1; S3, combining subcomponent P2 and subcomponent P3, designing a low T depth implementation of the combination; S4. Combine the implementations of subcomponents P1, P2, and P3 to obtain a low T-depth implementation of S0.

2. The quantum fault-tolerant implementation method of the S-box with the Zu Chongzhi algorithm number 0 according to claim 1 is characterized in that: The S-box S0 of Zu Chongzhi's algorithm in step S1 is an 8-bit S-box, and is composed of three sub-components P1, P2 and P3.

3. The quantum fault-tolerant implementation method of the S-box with the Zu Chongzhi algorithm number 0 according to claim 1 is characterized in that: In step S2, a quantum AND gate with a T depth of 1 is used to construct a quantum implementation circuit with a low T depth, specifically including: S21, calculate and obtain the algebraic normal form related information of the subcomponent P1; S22, designing an optimal implementation of the AND gate depth and the number of AND gates according to the algebraic normal form related information of the subcomponent P1; S23. Convert the classical optimized implementation of subcomponent P1 into its quantum optimized implementation with low T depth in combination with the quantum implementation cost.

4. The quantum fault-tolerant implementation method of the S-box with the Zu Chongzhi algorithm number 0 according to claim 3 is characterized in that: The step S21 specifically includes: Suppose the input of Zu Chongzhi's algorithm S-box S0 is X = (x0, x1, ..., x7), the input of subcomponent P1 is A = X2 = (x4, x5, x6, x7), and the output of P1 is B = (b0, b1, b2, b3), then: The expression of b0 is: The expression of b1 is: The expression of b2 is: The expression of b3 is:

5. The quantum fault-tolerant implementation method of the S-box with Zu Chongzhi algorithm number 0 according to claim 3 is characterized in that: The step S22 specifically includes: S221, let N be the number of AND gates required to finally implement P1, n is the number of AND gates required in the current implementation, i is used to mark the output bit subscript of P1, i∈{0,1,2,3}, initialize N=8,n=0,i=0; S222, if b i The expression has been processed, i = i + 1 and go to step S223; if b i The expression is not processed, and the process directly proceeds to step S223; S223, Statistics b i The number of occurrences of each variable in the monomial with algebraic degree of 2 in the expression of b is calculated by using the variable with the largest number of occurrences. i The common factor extraction is performed on the expression of b. If there are multiple variables with the highest frequency, one is randomly selected. If the extracted variable itself is b i The monomial in b i The variable exists in the expression of XOR, and the variable is used as a common factor to process the XOR operation. Repeat this step until b i There are no extractable common factors in the remaining quadratic monomials. After statistical update, b i The number of AND gates in the expression is added to n, i=i+1, and the process goes to step S224; S224, if i=4, then the expressions of b0, b1, b2 and b3 have been processed, and the process goes to step S225; otherwise, i≤3, then the expressions of b0, b1, b2 and b3 have not been processed, and the process goes to step S222; S225, if N>n, then find an implementation scheme with less AND gate consumption, update N=n and go to step S226; otherwise, if no implementation scheme with less AND gate consumption is found, directly go to step S226; S226, let n=0, i=0, go to step S222, until an implementation scheme with less AND gate consumption is still not found after multiple repetitions, and obtain an implementation scheme with a P1 AND gate depth of 1 and a better AND gate consumption.

6. The quantum fault-tolerant implementation method of the S-box with the Zu Chongzhi algorithm number 0 according to claim 3 is characterized in that: The step S23 specifically includes: S231. Use CNOT gate and Pauli-X gate to simulate the XOR and negation operations in the modified expressions of b0, b1, b2 and b3. The expressions are as follows: S232, for the AND operation in the modified expressions of b0, b1, b2 and b3, that is, The design uses a parallel implementation of 4 QAND gates. S233, call four QAND gates in parallel to simulate the four AND operations in the expression of the modified P1 under the condition that the T depth is 1: QAND(t2,x4,t4,t8), QAND(t1,x7,t5,t9), <h2 style=";text-align:left;direction:ltr">QAND(t3,x5,t6,t<h2 style=";text-align:left;direction:ltr"> 10 <h2 style=";text-align:left;direction:ltr"> ),QAND(t0,x6,t7,t<h2 style=";text-align:left;direction:ltr"> 11 <h2 style=";text-align:left;direction:ltr"> ), Among them, t8, t9, t 10 ,t 11 The value is 0, which is the quantum auxiliary bit in the QAND gate. Its value remains unchanged before and after calling the QAND gate; S234, calculate the output of P1:

7. The quantum fault-tolerant implementation method of the S-box with the Zu Chongzhi algorithm number 0 according to claim 1 is characterized in that: The step S3 specifically includes: S31, calculate the algebraic normal form of subcomponents P2 and P3 S32, calculate the algebraic normal form of subcomponent P2 combined with P3 S33. Design the implementation with optimal AND gate depth and number in stages according to the algebraic normal forms of subcomponents P2 and P3.

8. The quantum fault-tolerant implementation method of the S-box with the Zu Chongzhi algorithm number 0 according to claim 7 is characterized in that: The step S31 specifically includes: Assume that the input of P2 is C = (c0, c1, c2, c3) and the output is D = (d0, d1, d2, d3), then: The expression of d0 is: The expression of d1 is: The expression of d2 is: The expression for d3 is: Assume that the input of P3 is E = (e0, e1, e2, e3) and the output is F = (f0, f1, f2, f3), then: The expression of f0 is as follows: The expression of f1 is as follows: The expression of f2 is as follows: The expression of f3 is as follows: The step S32 specifically includes: Let the combination of P2 and P3 be P. Assume that the input of S-box S0 is X = (x0, x1, ..., x7), and the output of P1 is (p0, p1, p2, p3). Then the input of P is It is abbreviated as (q0, q1, ..., q7), and the output of P is recorded as (y0, y1, ..., y7). According to the expressions of P2 and P3, the expressions of the 8 output variables of P are obtained; The expression of y0 is: The expression of y1 is: The expression of y2 is: The expression of y3 is: The expression of y4 is: The expression of y5 is: The expression of y6 is: The expression of y7 is:

9. The quantum fault-tolerant implementation method of the S-box with the Zu Chongzhi algorithm number 0 according to claim 7, characterized in that: The step S33 specifically includes: The first stage of processing the algebraic normal form of the output variables of P includes: Step 1: N1 is the number of AND gates required to implement P in the first stage, n is the number of AND gates required in the current implementation, initialize N1=28, n=28, and go to step 2; Step 2: Randomly select n AND operations from the 28 possible AND operations in the first stage and substitute them into the expressions of the 8 outputs of P, and then go to step 3; Step 3: If the algebraic degrees of the 8 modified expressions at the current n value do not exceed 2, proceed to step 4; otherwise, if the algebraic degrees of the 8 modified expressions at the current n value all exceed 2 at this time, proceed to step 2; if the algebraic degrees of the 8 modified expressions at the current n value exceed 2 for a long time, it means that the n AND operations are unlikely to reduce the algebraic degree of the expression of P to 2, proceed to step 5; Step 4: If N1>n, it means that the implementation scheme of the AND gate is found, and the number of AND gates in the first stage is updated to N1=n, and n=n-1 is set, and then go to step 2; otherwise, the number of AND gates is not optimized at this time, and then go to step 2; Step 5. At this time, N1 is the number of AND gates that can reduce the algebraic degree of the output expression of P to 2. Save the N1 AND operations selected in step 2, and update the 8 output expressions of P to quadratic expressions accordingly. The second stage of processing the algebraic normal form of the output variables of P includes: Step 1: Let N2 be the number of AND gates required to implement P in the second stage, n is the number of AND gates required in the current implementation, and i is used to mark the output bit subscript of P, that is, i∈{0,1,…,7}. Initialize N2=100,n=0,i=0, and go to step 2; Step 2: If y i The expression has been processed, i = i + 1 and go to step 3; if y i The expression is not processed and goes directly to the third step; Step 3: Statistics y i The number of occurrences of each variable in the monomial with algebraic degree of 2 in the expression of , using the variable with the largest number of occurrences to calculate y i The common factor extraction is performed on the expression of y. If there are multiple variables with the highest frequency, one is randomly selected. If the extracted variable itself is y i The monomial in , that is, y i The variable exists in the expression of XOR, and the variable is used as a common factor to process the XOR operation. Repeat this step until y i There are no common factors that can be extracted from the remaining quadratic monomials. After the statistical update, y i The number of AND gates in the expression is added to n, i = i + 1, and then go to step 4; Step 4: If i=8, the expressions of y0, y1, ..., y7 have been processed, and the process goes to step 5; otherwise, if i≤7, the expressions of y0, y1, ..., y7 have not been processed, and the process goes to step 2; Step 5: If N2>n, it proves that an implementation scheme with less AND gate consumption has been found, update N2=n and go to step 6; otherwise, no implementation scheme with less AND gate consumption has been found, directly go to step 6; Step 6: Let n=0, i=0 and go to step 2 until an implementation scheme with less AND gate consumption is not found after repeated many times, and then an implementation scheme with better P AND gate consumption in the second stage is obtained.

10. The quantum fault-tolerant implementation method of the S-box with the Zu Chongzhi algorithm number 0 according to claim 1, characterized in that: The step S4 specifically includes: S41, converting the low AND gate depth implementation of subcomponents P2 and P3 into their low T depth quantum optimized implementation, including using QAND gates to simulate AND gates in classical implementations, using CNOT gates to simulate XOR operations in classical implementations, and using Pauli-X gates to simulate negation operations in classical implementations; S42, complete the replacement between variables, assuming that the input of P is (q0, q1, ..., q7), the output is (y0, y1, ..., y7), the input variable of S box S0 is X = (x0, x1, ..., x7), the output is S = (s0, s1, ..., s7), according to the output of subcomponent P1, q4=x4, q5=x5, q6=x6, q7=x7, and there is only a circular shift operation between (y0, y1,…, y7) and (s0, s1,…, s7), and (s0, s1,…, s7) is obtained by circularly shifting (y0, y1,…, y7) to the left by 5 bits, that is, (s0, s1,…, s7)=(y5, y6, y7, y0, y1, y2, y3, y4).

Citation Information

Patent Citations

  • Power consumption attack efficient screening method based on genetic algorithm

    CN113128133A

  • Implementation method of ZUC password security algorithm

    CN114785482A

  • AES algorithm implementation method in quantum storage limited environment

    CN115348003A

  • Method for constructing bidirectional low-delay S box and S box circuit structure

    CN118432805A

  • Apparatus and method for quantum key distribution with enhanced security and reduced trust requirements

    EP3185463A1