Method for realizing one-out-of-N based on quantum casual transmission and storage medium

By building a binary tree at the sending end and setting a key for each layer, and converting N-select 1 as a binary selection of log2N layer, the problem of excessive resource and time consumption in inadvertent quantum transmission is solved, and efficient and secure quantum communication is achieved.

CN120263408APending Publication Date: 2025-07-04ANHUI GUOKE QUANTUM NETWORK CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510485850.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

When the existing quantum inadvertent transmission protocols process large-scale data, the resource and time consumption in the optical quantum preparation, transmission and measurement links are too high, resulting in low resource utilization efficiency and high processing costs.

Method used

By building a binary tree at the sending end, setting a pair of keys for each layer, and determining the encryption key group according to the location of the message to be sent in the binary tree, the sending end only needs to send a pair of keys through the QOT protocol, and the receiving end selectively obtains the corresponding keys of the path through the d QOT protocol, and converts N to 1 as the binary selection of the log2N layer to avoid the need for large-scale quantum transmission.

Benefits of technology

It significantly reduces resource consumption and processing costs, improves resource utilization efficiency, and achieves efficient and secure quantum inadvertent transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263408A_ABST
    Figure CN120263408A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to the field of quantum communication, and discloses a method for realizing one-out-of-N based on quantum casual transmission and a storage medium. In the method, a sending end generates a sending end binary tree based on a plurality of messages, sets a pair of keys (a left sub-side corresponds to a first key and a right sub-side corresponds to a second key) for each layer, determines a key group according to the position of a message to be sent, encrypts the message, sends the encrypted message to a receiving end, and sends the key pair of each layer; and a receiving end receives the encrypted message to generate a receiving end binary tree, determines a target encrypted message, selects a bit sequence, and determines a decryption key group to decrypt the message in combination with the key pair of the sending end. And the problems of low resource utilization efficiency, overhigh processing cost and the like caused by overhigh resource and time consumption in light quantum preparation, transmission and measurement links are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of quantum communication, and particularly to a method and storage medium for realizing 1-out-of-N selection based on quantum oblivious transfer. Background Art

[0002] Oblivious Transfer (OT) is an application protocol in cryptography, which is used in the interaction process between a message sender and a receiver. Among them, the sender holds a set of data, and the receiver holds an index to select from the sender's data. After the process, the sender does not obtain the data, and the receiver obtains the sender's data corresponding to the index, while maintaining the confidentiality of other inputs of the sender and the confidentiality of the receiver's selection. Currently, the oblivious transfer protocol includes various variant forms, such as 1-out-of-2, 1-out-of-N, etc. Among them, 1-out-of-N means that the receiver selects one piece of information from N pieces of information, and the sender does not know which piece of information the receiver has selected.

[0003] In related technologies, when the sender and the receiver perform 1-out-of-N data interaction, the sender needs to prepare and send a large number of (n*k) optical quanta, and the receiver needs to measure these optical quanta to obtain a corresponding number of qubit sequences. The whole process takes a long time and is difficult to meet the real-time requirements. Especially when dealing with large-scale data, this resource-intensive operation will cause huge time and resource consumption in the preparation, sending, and measurement of optical quanta. Summary of the Invention

[0004] The purpose of the embodiments of the present invention is to provide a method and storage medium for realizing 1-out-of-N selection based on quantum oblivious transfer, so as to solve the problems of low resource utilization efficiency and high processing cost caused by excessive resource and time consumption in the optical quantum preparation, transmission, and measurement links when dealing with large-scale data in related algorithms and protocols.

[0005] To solve the above technical problems, an embodiment of the present invention provides a method for realizing 1-out-of-N selection based on quantum oblivious transfer, which is applied to a sender. The method includes: generating a sender binary tree based on a number of messages, and setting a corresponding pair of keys for each layer of the sender binary tree, where the left sub-edge of each layer corresponds to the first key, and the right sub-edge of each layer corresponds to the second key; sequentially determining a key group for encrypting the message to be sent according to the position of the message to be sent in the sender binary tree, encrypting the message to be sent based on the key group, and sequentially sending the encrypted message to be sent to the receiver; sequentially sending the pair of keys corresponding to each layer to the receiver.

[0006] Embodiments of the present invention also provide a method for realizing 1-out-of-N based on quantum oblivious transfer, which is applied to a receiving end. The method includes: sequentially receiving a plurality of encrypted messages from a sending end, generating a receiving-end binary tree based on the plurality of encrypted messages, and setting a corresponding set of selection bits for each layer of the receiving-end binary tree, where the left sub-edge of each layer corresponds to a first selection bit and the right sub-edge corresponds to a second selection bit; determining a target encrypted message from the plurality of encrypted messages, and determining a selection bit sequence according to the position of the target encrypted message in the receiving-end binary tree; obtaining a plurality of pairs of keys sent by the sending end, determining a key group for decrypting the target encrypted message according to the selection bit sequence and the plurality of pairs of keys, and decrypting the target encrypted message based on the key group.

[0007] Embodiments of the present invention also provide a computer-readable storage medium storing a computer program, which implements the above method for realizing 1-out-of-N based on quantum oblivious transfer when executed by a processor.

[0008] Compared with the related art, in the embodiments of the present invention, by constructing a sending-end binary tree and setting a pair of keys for each layer (the left sub-edge corresponds to the first key and the right sub-edge corresponds to the second key), then according to the position of the message to be sent in the binary tree, the encryption key group is determined in sequence, and the message is encrypted using the key group. Finally, the key pairs of each layer are sent to the receiving end in sequence for the receiving end to decrypt the corresponding encrypted message according to the multiple key pairs. The present invention converts 1-out-of-N into a binary selection of log2N layers, that is, the position of each message is uniquely identified by a d-bit binary path, where d is the number of layers (depth) of the binary tree, N is the number of messages, and "1-out-of-N" is decomposed into d two-way selection operations (selecting the left or right sub-edge for each layer). Instead of directly operating on N*k quantum states, d layers of key pairs are processed. In addition, the sending end only needs to send d pairs of keys (one pair for each layer) through the QOT protocol, and the receiving end selectively obtains the keys corresponding to the path through d QOT protocols (selecting 1 key per round), thus avoiding the large-scale quantum transmission requirements of the traditional scheme where "each message corresponds to a quantum state".

[0009] In addition, the method of generating a sending-end binary tree based on a plurality of messages and setting a corresponding pair of keys for each layer of the sending-end binary tree includes: using the plurality of messages as the leaf nodes of the sending-end binary tree, and the remaining nodes do not store data; for each layer of the sending-end binary tree, based on a key generation rule, generating a first key based on a first random number and generating a second key based on a second random number; setting the first key and the second key as the corresponding pair of keys.

[0010] In addition, generating a first key based on a first random number and a second key based on a second random number according to the key generation rule includes: performing an exclusive OR operation on a key seed with the first random number and the second random number respectively to obtain a first exclusive OR result and a second exclusive OR result; and performing hash iteration on the first exclusive OR result and the second exclusive OR result respectively to obtain the first key and the second key, where the number of iterations is determined by the number of layers of the sender binary tree corresponding to a pair of keys to be generated.

[0011] In addition, determining a key group for encrypting the message to be sent according to the position of the message to be sent in the sender binary tree includes: determining the path from the root node of the sender binary tree to the node corresponding to the message to be sent; sequentially determining the keys corresponding to each layer of branches from the path, and combining the multiple keys in sequence to obtain one key group.

[0012] In addition, encrypting the message to be sent based on the key group includes: encrypting the message to be sent in the order of each key in the key group.

[0013] In addition, sequentially sending a pair of keys corresponding to each layer to the receiver includes: sequentially using a pair of keys corresponding to each layer as data to be selected, and performing a QOT protocol with the receiver to send the data to be selected to the receiver.

[0014] In addition, determining a target encrypted message from the plurality of encrypted messages and determining a selection bit sequence according to the position of the target encrypted message in the receiver binary tree includes: determining the path from the root node of the receiver binary tree to the node corresponding to the target encrypted message; determining a plurality of selection bits according to the multiple edges included in the path, and combining the selection bits in sequence to obtain the selection bit sequence.

[0015] In addition, obtaining multiple pairs of keys sent by the sender, and determining a key group for decrypting the target encrypted message according to the selection bit sequence includes: sequentially performing a QOT protocol with the sender based on the selection bits in the selection bit sequence and the multiple pairs of keys to obtain multiple keys, and combining the multiple keys in sequence according to the key generation rule to obtain the key group. Description of the Drawings

[0016] One or more embodiments are exemplarily illustrated by pictures in the corresponding drawings. These exemplary illustrations do not constitute a limitation on the embodiments. Elements with the same reference numerals in the drawings are represented as similar elements, unless otherwise stated, and the drawings in the figures do not constitute a scale limitation.

[0017] Figure 1It is a flowchart of a method for realizing 1-out-of-N based on quantum oblivious transfer according to an embodiment of the present application;

[0018] Figure 2 It is a schematic structural diagram of a binary tree at the sender end involved in a method for realizing 1-out-of-N based on quantum oblivious transfer according to an embodiment of the present application;

[0019] Figure 3 It is a flowchart of a method for realizing 1-out-of-N based on quantum oblivious transfer according to another embodiment of the present application;

[0020] Figure 4 It is a schematic structural diagram of a binary tree at the receiver end involved in a method for realizing 1-out-of-N based on quantum oblivious transfer according to another embodiment of the present application;

[0021] Figure 5 It is an interaction flowchart between the sender end and the receiver end of a method for realizing 1-out-of-N based on quantum oblivious transfer according to another embodiment of the present application. Detailed implementation manners

[0022] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the embodiments of the present application will be described in detail below with reference to the accompanying drawings. However, those of ordinary skill in the art can understand that in the embodiments of the present application, many technical details are provided to help readers better understand the present application. However, even without these technical details and various changes and modifications based on the following embodiments, the technical solutions required to be protected by the present application can still be implemented. The following division of each embodiment is for convenience of description and should not constitute any limitation on the specific implementation manner of the present application. Each embodiment can be combined and cross-referenced with each other without conflict.

[0023] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products, or devices.

[0024] In view of the problems that a large number of optical quanta need to be prepared and measured in the current Quantum N-to-1 Selection, the efficiency of the whole process is low, and it is difficult to meet the real-time requirements in practical applications, etc., the embodiments of the present application provide a method for realizing N-to-1 selection based on quantum oblivious transfer, which is applied to the sender. The sender is a transmission device based on the quantum transmission mode, specifically the hardware device of the quantum oblivious transfer sender, which is used to execute the function of the sender of quantum information transmission in the QOT (Quantum Oblivious Transfer) protocol, and to implement the method for realizing N-to-1 selection based on quantum oblivious transfer provided by the embodiments of the present application. The method provided by the embodiments of the present application constructs a binary tree of the sender based on N messages, and sets a pair of keys for each layer (the left sub-edge corresponds to the first key, and the right sub-edge corresponds to the second key). Then, according to the position of the message to be sent in the binary tree, the encryption key group is determined in sequence, and the message is encrypted using the key group. Finally, the key pairs of each layer are sent to the receiver in sequence for the receiver to decrypt the corresponding encrypted message according to multiple key pairs. The present invention converts the N-to-1 selection into a binary selection of log2N layers, that is, the position of each message is uniquely identified by a d-bit binary path, where d is the number of layers (depth) of the binary tree, and the calculation formula is N is the number of messages. The "N-to-1 selection" is decomposed into d binary selections (selecting the left or right sub-edge for each layer). Instead of directly operating on N quantum states, d pairs of keys are processed. In addition, the sender only needs to send d pairs of keys (one pair for each layer) through the QOT protocol, and the receiver selectively obtains the keys corresponding to the path through d QOT protocols (selecting 1 key per round), so as to avoid the large-scale quantum transmission requirements of the traditional scheme where "each message corresponds to one quantum state", thus at least solving the problems of low resource utilization efficiency and high processing cost caused by the excessive resource and time consumption in the preparation, transmission, and measurement of optical quanta when dealing with large-scale data in related algorithms and protocols. To facilitate understanding of the method for realizing N-to-1 selection based on quantum oblivious transfer provided by the embodiments of the present application, the following will be described in conjunction with its different implementation processes.

[0025] In some embodiments, the method for realizing N-to-1 selection based on quantum oblivious transfer is applied to the sender, as Figure 1 shown, and includes the following steps.

[0026] Step 101, generate a binary tree of the sender based on a number of messages, and set a corresponding pair of keys for each layer of the binary tree of the sender, where the left sub-edge of each layer corresponds to the first key, and the right sub-edge of each layer corresponds to the second key.

[0027] Step 102: Determine the key group for encrypting the message to be sent according to the position of the message to be sent in the binary tree at the sending end in sequence, encrypt the message to be sent based on the key group, and send the encrypted message to be sent to the receiving end in sequence.

[0028] Step 103: Send a pair of keys corresponding to each layer to the receiving end in sequence.

[0029] In this way, by constructing a binary tree at the sending end and setting a pair of keys for each layer (the left sub-edge corresponds to the first key, and the right sub-edge corresponds to the second key), then according to the position of the message to be sent in the binary tree, determine the encryption key group in sequence, and use the key group to encrypt the message. Finally, send the key pairs of each layer to the receiving end in sequence for the receiving end to decrypt the corresponding encrypted message according to multiple key pairs. The present invention converts the N - to - 1 selection into a binary selection of log2N layers, that is, the position of each message is uniquely identified by a d - bit binary path, and decomposes the "N - to - 1 selection" into d two - to - one operations (select the left or right sub - edge for each layer). Instead of directly operating on N * k quantum states, it processes d layers of key pairs. In addition, the sending end only needs to send d pairs of keys (one pair for each layer) through the QOT protocol, and the receiving end selectively obtains the keys corresponding to the path through d QOT protocols (select one key per round), thus avoiding the large - scale quantum transmission requirements of the traditional scheme where "each message corresponds to a group of quantum states", and at least solving the problems such as low resource utilization efficiency and high processing cost caused by the excessive resource and time consumption in the preparation, transmission, and measurement links of optical quantum when dealing with large - scale data in related algorithms and protocols.

[0030] For better understanding by those skilled in the art Figure 1 of the method for realizing N - to - 1 selection based on quantum oblivious transfer shown below, the following will further illustrate its steps.

[0031] In some examples, for Step 101, the binary tree at the sending end is a full binary tree. Generate the binary tree at the sending end based on several messages, and set a corresponding pair of keys for each layer of the binary tree at the sending end. The generation process can be: use several messages as the leaf nodes of the binary tree at the sending end, and the other nodes do not store data; for each layer of the binary tree at the sending end, generate the first key based on the first random number and generate the second key based on the second random number according to the key generation rule; set the first key and the second key as a corresponding pair of keys.

[0032] Please refer to Figure 2 , Figure 2 which gives a specific implementation of the binary tree at the sending end. The generation rule of the binary tree at the sending end is as follows: First, the sending end calculates the depth d of the tree according to the number of messages, constructs a full binary tree, and the calculation formula is where N is the number of messages, and construct a full binary tree based on this. As Figure 2As shown, for example, when the number of messages is 7, the depth of the tree is 3, forming a three-layer structure: the first layer is the root node, the second layer contains two nodes (the children of the root node), and the third layer contains 8 nodes (one of which is an empty node). For the leaf nodes of the last layer, from left to right, they are numbered 0, 1, 2, …, n - 1 in sequence. Calculate the d-bit binary representation of the number, and if it is less than d bits, pad 0s in front to make it up to d bits. The left side of each layer is marked as 0, and the right side is marked as 1. In addition, a pair of random numbers are generated as salt for each layer, and a pair of keys are generated based on the salt. The leaf nodes of the third layer store the actual message content, where M0 to M6 represent messages. The position of the message in the binary tree can be determined through the path identifier (0 or 1), and then used for operations such as encryption and decryption, or to determine the path and the edges included in the path starting from the leaf node.

[0033] That is to say, there are two ways to set the edges of each layer of the binary tree:

[0034] Way 1: A pair of keys can be generated based on the randomly generated random numbers (or salt) of each layer, and this pair of keys is used as the value of this layer, where the left sub-edge corresponds to the first key and the right sub-edge corresponds to the second key.

[0035] Way 2: A set of random numbers can be set for each layer of this binary tree, where the left sub-edge corresponds to the first value of the random numbers of this layer, and the right sub-edge corresponds to the second value of the random numbers of this layer.

[0036] It should be noted that the "first" and "second" here are only used to distinguish different objects, and do not represent a specific order or priority.

[0037] In some examples, for generating a pair of keys based on the randomly generated random numbers (or salt) of each layer as disclosed in Way 1 and using this pair of keys as the value of this layer, it can be specifically: successively determine the key group for encrypting the message to be sent according to the position of the message to be sent in the binary tree at the sending end, encrypt the message to be sent based on the key group, and send the encrypted message to be sent to the receiving end in sequence; successively send a pair of keys corresponding to each layer to the receiving end.

[0038] Among them, for each layer of the binary tree, an independent key generation logic is executed: according to the preset key generation rule, the first key of this layer is generated using the "first random number"; similarly, based on the key generation rule, the second key of this layer is generated through the "second random number". The "first key" and "second key" generated in the same layer are combined into a pair of keys, and it is stipulated that the left sub-edge of each layer corresponds to the first key and the right sub-edge corresponds to the second key. This hierarchical key pair setting provides a basis for subsequently determining the encryption key group according to the path (left or right branch selection) of the message in the binary tree, enabling the encryption process to combine the structural characteristics of the binary tree and achieve more refined message encryption management.

[0039] In some examples, according to the key generation rule, a first key is generated based on a first random number, and a second key is generated based on a second random number. The process may be as follows: perform exclusive OR operations on the key seed with the first random number and the second random number respectively to obtain a first exclusive OR result and a second exclusive OR result; and perform hash iterations on the first exclusive OR result and the second exclusive OR result respectively to obtain the first key and the second key, where the number of iterations is determined by the number of layers of the binary tree corresponding to the pair of keys to be generated.

[0040] In this way, binary trees with different numbers of layers correspond to different numbers of iterations, making the generation rule of each layer of keys deeply associated with the tree structure. For example, the deeper the layer (such as the third layer), the more iterations, the higher the key complexity, and the encryption strength of the message corresponding to the deeper nodes is enhanced. At the same time, through multiple compression mappings in the hash iteration, the input data is converted into a hash value of a fixed length. The more iterations, the exponentially increasing difficulty of reverse-cracking the key. Combining the characteristics of the binary tree hierarchy, hierarchical key security management is realized, meeting the high requirements of quantum oblivious transfer for key security.

[0041] Among them, the key generation rule is a combination of keys (generated according to the key generation rule) corresponding to the salt values (or called "random numbers") of all edges passed from the root node to a certain leaf node. The key generation rule is as follows.

[0042] The salt value is at a certain layer of the binary tree, and i is used to represent the number of this layer.

[0043] Generate the initial key (i.e., the above exclusive OR result) based on the salt value and the key seed: Among them, key_seed is a preset key seed, which is preset at the sender and the receiver. It is a fixed value, usually a secure random number or a specially processed string, used to provide a basic starting value for key generation. salt is the salt value, which is a random value and is related to the layer where the salt value is located. represents the exclusive OR operation. The exclusive OR operation can compare the binary bits of two values bit by bit, with the same being 0 and the different being 1. By performing the exclusive OR operation on the key seed and the salt value, the randomness of the salt value can be incorporated into the key generation process, increasing the complexity and security of the key. HASH(·) is a hash function that converts the input data (here is the result of ) into a hash value of a fixed length. The hash function has one-wayness, that is, it is difficult to reverse-deduce the original input data from the hash value, which helps to protect the security of the key.

[0044] Then perform hash iteration on the initial key:

[0045] for I from 1 to i:

[0046] key = HASH(key);

[0047] Among them, perform cyclic hash iteration on the initial key, and the number of iterations ranges from 1 to i (i.e., the layer where the salt value is located). In each iteration, use the current key value as the input, perform hash operation again, and reassign the result to key. Through multiple hash iterations, the complexity and security of the key can be further increased, making the key more difficult to be cracked. Assign the key value obtained after the loop ends to the left or right sub-edge of each layer. For example Figure 2 If the message M5 in

[0048] For step 102, in some embodiments, determine the key group used to encrypt the message to be sent according to the position of the message to be sent in the binary tree at the sending end. The process may be as follows: determine the path from the root node of the binary tree at the sending end to the node corresponding to the message to be sent; sequentially determine the keys corresponding to each layer of branches from the path, and combine multiple keys in order to obtain a key group.

[0049] Please continue to refer to Figure 2 , starting from the root node of the binary tree at the sending end of this application, judge the branch direction (left or right) where the message to be sent is located layer by layer. For example Figure 2 If the message M5 in

[0050] For step 102, in some embodiments, encrypt the message to be sent based on the key group. It can be to encrypt the message to be sent in the order of each key in the key group. Based on the above example, the above process may be to encrypt the message to be sent (i.e., M5) based on K01, K10, and K21 in sequence. Here is a possible implementation: How to specifically encrypt the message to be sent can be set according to actual application requirements.

[0051] In step 102, the sending end needs to sequentially send the encrypted message to be sent to the receiving end. In this way, through sequential sending and sequential receiving, it can be ensured that the receiving end can accurately determine the position and path of the target encrypted message in the binary tree, which is convenient for subsequent operations based on the binary tree structure, such as determining the message position, path, etc.

[0052] For the method one, a pair of keys is generated based on the random numbers (or salt values) randomly generated for each layer, and this pair of keys is used as the value of that layer. For step 103, the pair of keys corresponding to each layer is sent to the receiving end in sequence, which can be implemented in the following way. The pair of keys corresponding to each layer is used as the data to be selected in sequence, and the QOT protocol is executed with the receiving end to send the data to be selected to the receiving end.

[0053] Among them, in the QOT protocol, the sender has multiple data (here are the pairs of keys corresponding to each layer), and the receiver can select some of the data to obtain, while the sender does not know which data the receiver has selected; at the same time, the receiver cannot obtain the information of the unselected data. The specific execution process is as follows:

[0054] First, the sender regards the pair of keys corresponding to each layer of the binary tree as the data to be selected. For example, there is a pair of keys {K00, K01} in the first layer of the binary tree, and a pair of keys {K10, K11} in the second layer, and so on. Each pair of keys will be used as an independent data group to be selected. Then, the sender executes the QOT protocol with the receiving end in sequence to send each group of data to be selected (that is, a pair of keys for each layer) to the receiving end. During the execution of the protocol: the receiver can select one key from each pair of keys according to its own needs (such as according to the selection bit sequence), but the sender does not know which key the receiver has selected. The receiver can only obtain the key it has selected and cannot know the information of the other unselected key in the same pair. Finally, through multiple executions of the QOT protocol, the sender sends all the keys corresponding to all layers of the binary tree to the receiving end, and the receiving end can obtain the corresponding keys according to its own selection for subsequent decryption operations of the target encrypted message.

[0055] For method two, a set of random numbers (or salt values) can be set for each layer of the binary tree. Then the sender and the receiver execute the QOT protocol, and three groups of random numbers (salt values) {S00, S01}, {S10, S11}, {S20, S21} are transmitted to the receiving end in sequence. During the execution of the protocol: the receiver can select one random number (or salt value) from each group of random numbers (or salt values) according to its own needs (such as according to the selection bit sequence), but the sender does not know which one the receiver has selected. Further, based on the obtained random number (or salt value), the receiver obtains the key and forms a key group according to the key generation rule (which will be elaborated in detail later in this article and will not be elaborated here).

[0056] In this way, by constructing a binary tree at the sending end, setting a pair of keys for each layer (the left sub-edge corresponds to the first key, and the right sub-edge corresponds to the second key), then determining the encryption key group in sequence according to the position of the message to be sent in the binary tree, encrypting the message using the key group, and finally sending the key pairs of each layer to the receiving end in sequence for the receiving end to decrypt the corresponding encrypted message according to multiple key pairs, the problems of excessive resource consumption and low efficiency in the related art are solved, and at the same time, efficient and secure quantum oblivious transfer is realized.

[0057] Compared with the conventional quantum N-to-1 selection technical solution, for the discrete variable BB84 protocol, assuming that the receiving end detects the optical quantum sent by the sending end, the probability of being completely correct is 50%. For the national cipher SM4 encryption, the required key length is 128 bits. Then for k in the conventional quantum N-to-1 selection, 256 bits can be taken, and the number of optical quanta required is 256. The number of optical quanta required for the method provided in this application to complete one QOT protocol is 2048.

[0058] The method provided in this application has the following advantages compared with the conventional quantum N-to-1 selection technical solution, as shown in the following table.

[0059] Table 1

[0060]

[0061] Another embodiment of this application provides a method for implementing N-to-1 selection based on quantum oblivious transfer, which is applied to the receiving end. The receiving end sequentially receives the encrypted message sequence sent by the sending end, constructs a binary tree structure with these messages as leaf nodes, and assigns selection bits to each layer of the binary tree (the left branch corresponds to 0, and the right branch corresponds to 1). After determining the target encrypted message, extract the path branches from the root node to the target node, and generate a selection bit sequence in the path order. The receiving end obtains multiple pairs of pre-shared keys transmitted by the sending end, and performs a quantum oblivious transfer (QOT) protocol with the sending end according to the selection bit sequence, filters out the valid keys, and combines the key fragments according to the preset rules to generate a key group for decrypting the target encrypted message. Through the hierarchical key management of the binary tree structure and the non-clonability of quantum communication, at least one advantage of this solution is that it can efficiently process large-scale data, significantly reduce the resource overhead of traditional key distribution, and at the same time ensure the communication security at the quantum level. To facilitate understanding of the method for implementing N-to-1 selection based on quantum oblivious transfer provided in the embodiments of this application, the following will be described in combination with its different implementation processes.

[0062] In some embodiments, the method for implementing N-to-1 selection based on quantum oblivious transfer is applied to the receiving end, as Figure 3 shown, and includes the following steps.

[0063] Step 301: Sequentially receive several encrypted messages from the sender, generate a receiver binary tree based on the several encrypted messages, and set a corresponding set of selection bits for each layer of the receiver binary tree. Among them, the left sub-edge of each layer corresponds to the first selection bit, and the right sub-edge corresponds to the second selection bit.

[0064] Step 302: Determine the target encrypted message from the several encrypted messages, and determine the selection bit sequence according to the position of the target encrypted message in the receiver binary tree.

[0065] Step 303: Obtain multiple pairs of keys sent by the sender, determine the key group for decrypting the target encrypted message according to the selection bit sequence and the multiple pairs of keys, and decrypt the target encrypted message based on the key group.

[0066] In this way, the receiver receives messages, constructs a binary tree, sets selection bits, determines the selection bit sequence, obtains the key group based on the selection bit sequence, and decrypts the target encrypted message with the key group. Through the hierarchical design of the binary tree structure, the receiver can efficiently manage a large number of encrypted messages, and through the combination rule of the key group, the receiver can quickly decrypt the target message, improving the overall efficiency.

[0067] For the convenience of those skilled in the art to better understand Figure 3 the method for realizing 1-out-of-N based on quantum oblivious transfer as shown, the following will further explain its steps.

[0068] In some examples, in Step 301, the receiver binary tree is a full binary tree, which is generated based on several sequentially obtained messages. In this way, through sequential sending and sequential receiving, it can be ensured that the receiver accurately determines the position and path of the target encrypted message in the binary tree, facilitating subsequent operations based on the binary tree structure, without the need for additional complex mechanisms to handle message out-of-order problems, reducing the processing overhead, improving the transmission and processing efficiency. At the same time, it is more difficult for attackers to tamper with the message order or insert forged messages, maintaining the integrity and security of message transmission.

[0069] Please refer to Figure 4 , Figure 4 A specific implementation of the receiver binary tree is given. The generation rule of the receiver binary tree is as follows: First, the receiver obtains several encrypted messages sequentially sent by the sender, calculates the depth d of the tree according to the encrypted messages, and constructs a full binary tree. The calculation formula is where n is the number of encrypted messages, and a full binary tree is constructed based on this. For example Figure 4As shown, for example, when the number of messages is 7, the depth of the tree is 3, forming a three-layer structure: the first layer is the root node, the second layer contains two nodes (the children of the root node), and the third layer contains 8 nodes (one of which is an empty node). For the leaf nodes in the last layer, they are numbered 0, 1, 2, …, n - 1 from left to right. Calculate the d-bit binary representation of the number, and fill in 0s in front if it is less than d bits to make it up to d bits. The left side of each layer is marked as 0, and the right side is marked as 1, and 0 or 1 is used as the selection bit.

[0070] In some examples, for step 302, to determine the target encrypted message from several encrypted messages and determine the selection bit sequence according to the position of the target encrypted message in the receiving-end binary tree, the process can be as follows: determine the path from the root node of the receiving-end binary tree to the node corresponding to the target encrypted message; determine multiple selection bits according to the multiple edges included in the path, and combine the selection bits in order to obtain the selection bit sequence.

[0071] Specifically, the receiving end first needs to determine the target encrypted message path: first select the target encrypted message from the received several encrypted messages, and then find the path from the root node to the leaf node corresponding to the target encrypted message in the receiving-end binary tree. For example, if the binary tree has three layers and the target message is in the right branch of the left subtree of the third layer, then the path is "root → left → right". Then, determine the selection bits according to the path. In the binary tree of the receiving end of the present application, the edges of each layer have left and right distinctions, corresponding to different selection bits. Generally, the left sub-edge corresponds to the first selection bit (assumed to be 0), and the right sub-edge corresponds to the second selection bit (assumed to be 1). Along the previously determined path, each time an edge of a layer is passed, a selection bit is determined. For example, if the path is "root → left → right", then the selection bits are 0 and 1 in sequence. Combine the multiple selection bits determined according to the edges of the path in the order of the path passed, and the selection bit sequence is obtained. Taking Figure 4 the encrypted message Y5 in as an example of the target encrypted message, the identifier of the path corresponding to the target encrypted message Y5 is "1 - 0 - 1", corresponding to the selection bit sequence [1, 0, 1].

[0072] In some examples, for step 303, to obtain multiple pairs of keys sent by the sending end and determine the key group for decrypting the target encrypted message according to the selection bit sequence, it can be implemented in the following way: sequentially perform the QOT protocol with the sending end based on the selection bits in the selection bit sequence and the multiple pairs of keys to obtain multiple keys, and combine the multiple keys according to the key generation rule in order to obtain the key group.

[0073] Specifically, the receiving end needs to select a key from each layer of key pairs of the sending end through the QOT protocol based on the selection bit sequence (determined by the path of the target encrypted message in the binary tree), and combine these keys in order to form a key group that is exactly the same as when the sending end encrypts, so as to decrypt the target encrypted message.

[0074] First, the receiving end has received all the encrypted messages from the sending end, constructed a binary tree with the same structure as that of the sending end (the leaf nodes are encrypted messages), and at this time, the target encrypted message has been determined, and the selection bit sequence is obtained through its path in the binary tree (for example, [0, 1, 0], indicating that the left sub-edge is selected in the first layer, the right sub-edge is selected in the second layer, and the left sub-edge is selected in the third layer). The sending end and the receiving end execute the QOT protocol in the order of the binary tree layers, and execute the protocol once for each layer: the sending end provides a pair of keys or a pair of salt values for this layer (the specific providing method and corresponding content have been described in steps 102 to 103, and will not be elaborated here one by one), the receiving end provides the selection bit for this layer, and the receiving end securely obtains a key or a salt value from the pair of keys or a pair of salt values according to the selection bit. The sending end cannot know which key the receiving end has selected, protecting the privacy of the receiving end.

[0075] It should be clear that if several salt values are obtained by the receiving end at this time, keys also need to be generated according to the preset key generation rule and the key seed shared by the sending end and the receiving end. The specific process can refer to the process of generating keys based on salt values in step 102, and will not be elaborated here one by one. After obtaining several keys, multiple keys are combined in order according to the key generation rule to obtain a key group, and the target encrypted message is decrypted based on the key group.

[0076] In this way, the receiving end "filters" out the keys corresponding to the path layer by layer through the QOT protocol, combines them into a key group, ensures that the decryption process strictly matches the encryption process of the sending end, and at the same time uses the security of the quantum protocol to protect privacy and avoid leaking the location of the target message or other key information. This process is the core mechanism for realizing "1-out-of-N" oblivious transfer, and solves the problem of efficient and secure selection under large-scale data.

[0077] This application also presents a two-party interaction process of a method for realizing 1-out-of-N based on quantum oblivious transfer, as Figure 5 shown, Figure 5 which presents the interaction process between the sending end (i.e., Figure 5 "Alice" in Figure 5 and the receiving end (i.e.,

[0078] The first step: Both parties preset the same symmetric key as the key seed key_seed.

[0079] The second step: Alice builds her own full binary tree according to n messages (Mi), then Alice generates encryption keys based on d groups of salt values (random numbers) to encrypt the messages, and sequentially sends the n encrypted messages (Yi) to Bob. Bob sequentially receives the messages (Yi) and determines the target encrypted message he needs.

[0080] Step 3: As QOT-Alice, Alice uses d groups of salt values (random numbers) as the data to be selected; as QOT-Bob, Bob uses d bits as the selection bits and executes the QOT protocol d times.

[0081] Step 4: Bob obtains d salt values and, according to the key generation rule, obtains d keys as decryption keys to decrypt Mi and get the required original message. Then Bob notifies Alice of the processing result.

[0082] Among them, Alice's operations also include: A.0 providing the original data. Alice has n messages (Mi) numbered 0, 1, 2,..., n - 1. A.1 constructing a full binary tree. According to the quantity n, a full binary tree with depth d is constructed. The structure of the tree is used to organize message data or keys (for example, leaf nodes correspond to data, and non-leaf nodes are used for path selection). A.3 preparing QOT salt values. As the sender of the QOT protocol (QOT-Alice), Alice generates d groups of salt values (each group corresponding to one layer of the tree) for subsequent key generation. A.2 encrypting and sending message data. Encrypt the n messages (Yi) and send them to Bob. The encryption key is related to the full binary tree structure or salt values. For Bob's operations, they also include: B.0 selecting the target data. Bob decides to obtain the data numbered i. B.1 constructing the same full binary tree. According to n, construct the same tree structure as Alice to ensure that both parties have the same understanding of the tree. B.3 generating selection bits. As the receiver of the QOT protocol (QOT-Bob), generate d bits (corresponding to the depth d of the tree). Each bit determines whether to select the left sub-edge (labeled 0) or the right sub-edge (labeled 1) at each layer of the tree. The final path points to the target encrypted message Yi. Execute the QOT protocol d times. Through d QOT interactions between the two parties: Alice provides the salt values of each layer (such as the two salt values of the k-th layer). Bob uses the selection bits (0 or 1 of the k-th layer) to obtain the corresponding salt values, but Alice cannot know the selection. B.4 generating decryption keys. Bob uses the d salt values and the pre-set key_seed to generate keys to decrypt the target encrypted data Yi. B.2 receiving and storing data. Receive the encrypted data sent by Alice, but can only decrypt the data he selects himself.

[0083] The above process combines the structured design of the full binary tree and the security guarantee of QOT to achieve efficient and secure data transmission. Alice doesn't need to know Bob's selection, but can ensure the security of the data; Bob can only decrypt the data he selects and cannot obtain other information. The depth of the tree determines the number of protocol interactions and the security complexity, making the whole process efficient and reliable.

[0084] The step division of the above various methods is only for clear description. When implemented, they can be combined into one step or some steps can be split into multiple steps. As long as the same logical relationship is included, they are all within the protection scope of this patent; adding insignificant modifications or introducing insignificant designs to the algorithm or process, but not changing the core design of its algorithm and process are all within the protection scope of this patent.

[0085] Another embodiment of the present invention relates to a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the method embodiments described above are implemented.

[0086] That is, those skilled in the art can understand that all or part of the steps in implementing the methods of the above embodiments can be completed by instructing relevant hardware through a program. The program is stored in a storage medium and includes several instructions to enable a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods of the various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0087] Those of ordinary skill in the art can understand that the above various embodiments are specific embodiments for implementing the present invention. In actual applications, various changes can be made to them in form and details without departing from the spirit and scope of the present invention.

Claims

1. A method for realizing 1-out-of-N selection based on quantum oblivious transfer, applied to a sender, characterized in that, The method includes: Generating a sender binary tree based on a number of messages, and setting a corresponding pair of keys for each layer of the sender binary tree, where the left sub-edge of each layer corresponds to a first key, and the right sub-edge of each layer corresponds to a second key; Sequentially determining a key group for encrypting the message to be sent according to the position of the message to be sent in the sender binary tree, encrypting the message to be sent based on the key group, and sequentially sending the encrypted message to be sent to the receiver; Sequentially sending the pair of keys corresponding to each layer to the receiver.

2. The method for realizing 1-out-of-N selection based on quantum oblivious transfer according to claim 1, wherein The sender binary tree is a full binary tree; The generating a sender binary tree based on a number of messages, and setting a corresponding pair of keys for each layer of the sender binary tree includes: Taking the number of messages as the leaf nodes of the sender binary tree, and the remaining nodes do not store data; For each layer of the sender binary tree, according to the key generation rule, generating a first key based on a first random number, and generating a second key based on a second random number; setting the first key and the second key as the corresponding pair of keys.

3. The method for realizing 1-out-of-N selection based on quantum oblivious transfer according to claim 2, wherein, The generating a first key based on a first random number and generating a second key based on a second random number according to the key generation rule includes: Performing an exclusive OR operation on the key seed with the first random number and the second random number respectively to obtain a first exclusive OR result and a second exclusive OR result; And respectively performing hash iteration on the first exclusive OR result and the second exclusive OR result to obtain a first key and a second key, where the number of iterations is determined by the layer number of the sender binary tree corresponding to the pair of keys to be generated.

4. The method for realizing 1-out-of-N selection based on quantum oblivious transfer according to claim 1, wherein Determining a key group for encrypting the message to be sent according to the position of the message to be sent in the sender binary tree includes: Determining the path from the root node of the sender binary tree to the node corresponding to the message to be sent; Sequentially determining the keys corresponding to each layer of branches from the path, and sequentially combining the multiple keys to obtain a key group.

5. The method for realizing 1-out-of-N selection based on quantum oblivious transfer according to claim 1, wherein The encrypting the message to be sent based on the key group includes: Encrypting the message to be sent in the order of each key in the key group.

6. The method for realizing 1-out-of-N selection based on quantum oblivious transfer according to claim 1, wherein The sequentially sending the pair of keys corresponding to each layer to the receiver includes: Sequentially taking the pair of keys corresponding to each layer as data to be selected, and performing a QOT protocol with the receiver to send the data to be selected to the receiver.

7. A method for realizing 1-out-of-N selection based on quantum oblivious transfer, applied to a receiving end, characterized in that, The method includes: Sequentially receiving a number of encrypted messages from the sender, generating a receiver binary tree based on the number of encrypted messages, and setting a corresponding set of selection bits for each layer of the receiver binary tree, where the left sub-edge of each layer corresponds to a first selection bit, and the right sub-edge of each layer corresponds to a second selection bit; Determining a target encrypted message from the number of encrypted messages, and determining a selection bit sequence according to the position of the target encrypted message in the receiver binary tree; Obtaining multiple pairs of keys sent by the sender, determining a key group for decrypting the target encrypted message according to the selection bit sequence and the multiple pairs of keys, and decrypting the target encrypted message based on the key group.

8. The method for realizing 1-out-of-N selection based on quantum oblivious transfer according to claim 7, characterized in that, Determining a target encrypted message from the plurality of encrypted messages and determining a selection bit sequence according to the position of the target encrypted message in the receiver binary tree includes: Determining a path from the root node of the receiver binary tree to the node corresponding to the target encrypted message; Determining a plurality of selection bits according to a plurality of edges included in the path, and sequentially combining the selection bits to obtain the selection bit sequence.

9. The method for realizing 1-out-of-N selection based on quantum oblivious transfer according to claim 7, wherein Obtaining multiple pairs of keys sent by the sender, and determining a key group for decrypting the target encrypted message according to the selection bit sequence, including: Sequentially performing a QOT protocol with the sender based on the selection bits in the selection bit sequence and the multiple pairs of keys to obtain a plurality of keys, and sequentially combining the plurality of keys according to a key generation rule to obtain the key group.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method for realizing 1-out-of-N based on quantum oblivious transfer according to any one of claims 1 to 6, or the method for realizing 1-out-of-N based on quantum oblivious transfer according to any one of claims 7 to 9.