Authentication method using pre-shared symmetric key for location selection of authentication information in quantum communication system and apparatus therefor

The method uses a pre-shared symmetric key to select authentication information positions in quantum communication systems, addressing user authentication challenges and improving security by simultaneously estimating QBER, thus ensuring secure and efficient authentication.

CN120322981APending Publication Date: 2025-07-15LG ELECTRONICS INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280102475.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-12-09
Publication Date
2025-07-15

AI Technical Summary

Technical Problem

In existing quantum communication systems, the user authentication process needs to assume that the classical channel and the quantum channel are always connected to the same user, and the user authentication and QBER estimation process are usually performed separately, and it is impossible to effectively detect man-in-the-middle attacks and ensure the security of the quantum channel.

Method used

The method of selecting the authentication information location by pre-shared symmetric keys is adopted. By sending information on the quantum channel and using the pre-shared keys to select the authentication location, combining user authentication and QBER estimation processes, the authentication success or failure is determined by the error rate, ensuring the legality of the sending and receiving entities.

Benefits of technology

It realizes the simultaneous execution of user authentication and QBER estimation in the quantum communication system, improves processing speed, and can effectively detect man-in-the-middle attacks to ensure the security of the quantum channel.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120322981A_ABST
    Figure CN120322981A_ABST
Patent Text Reader

Abstract

The present disclosure provides a method of performing user authentication in a quantum communication system. More specifically, the method comprises: transmitting an information sequence comprising at least one data block to a receiving end on a quantum channel, based on (i) a pre-shared key between the transmitting end and the receiving end and (ii) at least one key generated based on the pre-shared key, determining, from each of the at least one data block, a check sequence for quantum bit error rate (QBER) estimation for determining whether eavesdropping exists on the quantum channel, in which the pre-shared key is used to select a position of a sequence for user authentication among sequences included in a specific data block related to user authentication among the at least one information block; performing user authentication with the receiving end based on a portion of the check sequence determined from each of the at least one data block; and performing a QBER estimation with the receiving end based on i) a result of the user authentication and (ii) a remaining check sequence excluding a portion of the check sequence determined from each of the at least one data block. (i) a user authentication error rate calculated based on a portion of a check sequence for user authentication and determined from each of the at least one data block, and (ii) a QBER estimation error rate calculated based on a remaining check sequence excluding the portion of the check sequence determined from each of the at least one data block is used for the QBER estimation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a quantum communication system, and more particularly, to a method and an apparatus for performing authentication in a quantum communication system. Background Art

[0002] Wireless communication systems are widely deployed to provide various types of communication services, such as voice and data. Generally, a wireless communication system is a multi-access system that can support communication with multiple users by sharing available system resources (bandwidth, transmission power, etc.). Examples of multi-access systems include code division multiple access (CDMA) systems, frequency division multiple access (FDMA) systems, time division multiple access (TDMA) systems, space division multiple access (SDMA) systems, orthogonal frequency division multiple access (OFDMA) systems, single carrier frequency division multiple access (SC-FDMA) systems, and interleaved frequency division multiple access (IDMA) systems. In addition, research on quantum communication is underway, which is a next-generation communication technology that can overcome the limitations of existing information and communication, such as security and ultra-fast computing, by applying quantum mechanical properties to the field of information and communication. Different from existing communication based on binary bit information, quantum communication provides a means of generating, transmitting, processing, and storing information in the form of superposition of 0 and 1. In existing communication technologies, wavelength, amplitude, etc. have been used for information transmission between a transmitting end and a receiving end, while in quantum communication, photons, which are the smallest units of light, are used for information transmission between a transmitting end and a receiving end. Summary of the Invention

[0003] Technical Problem

[0004] An object of the present disclosure is to provide a method and an apparatus for performing user authentication in a quantum communication system.

[0005] Another object of the present disclosure is to provide a method and an apparatus for performing location-based user authentication in a quantum communication system using a pre-shared symmetric key shared between authorized transmitting and receiving entities.

[0006] Another object of the present disclosure is to provide a method and an apparatus for performing user authentication in a quantum communication system based on the user authentication code error rate between a transmitting and a receiving entity.

[0007] Another object of the present disclosure is to provide a method and an apparatus for simultaneously performing a user authentication process and a quantum bit error rate (QBER) estimation process in a quantum communication system.

[0008] The technical objects achieved by the present disclosure are not limited to the technical objects described only by way of example above, and other technical objects not mentioned will be clearly understood by those of ordinary skill in the art to which the present disclosure pertains from the following description.

[0009] Technical solution

[0010] The present disclosure provides a method and apparatus for performing user authentication in a quantum communication system.

[0011] More specifically, the method for performing user authentication by a sending end in a quantum communication system according to the present disclosure includes: performing a random access process with a receiving end, the random access process being used to establish a connection related to a classical channel, the classical channel being related to a quantum channel for user authentication, wherein the random access process includes: sending a random access preamble to the receiving end, receiving a random access response from the receiving end, sending a connection request message to the receiving end based on the random access response; and receiving a contention resolution message from the receiving end; sending an information sequence including at least one data block to the receiving end on the quantum channel, wherein based on (i) a pre-shared key between the sending end and the receiving end and (ii) at least one key generated based on the pre-shared key, a check sequence for determining a quantum bit error rate (QBER) estimate for determining whether there is eavesdropping on the quantum channel is determined from each of the at least one data block, wherein the pre-shared key is used to select a position of a sequence for user authentication among sequences included in a specific data block related to user authentication among the at least one data block; performing user authentication with the receiving end based on a part of the check sequence determined from each of the at least one data block; and performing QBER estimation with the receiving end based on (i) the result of user authentication and (ii) the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block, wherein (i) a user authentication error rate calculated based on the part of the check sequence for user authentication and determined from each of the at least one data block, and (ii) a QBER estimation error rate calculated based on the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block are used for QBER estimation.

[0012] Performing user authentication may include sending a message for user authentication generated based on a part of the check sequence determined from each of the at least one data block to the receiving end.

[0013] Performing user authentication may further include: sending information on which a message for user authentication is based to the receiving end; and receiving measurement basis information from the receiving end, the measurement basis information being used by the receiving end to measure the basis of the sent message for user authentication.

[0014] Performing user authentication may further include: determining user authentication information related to a matching portion between a basis for the sender to generate a message for user authentication from the generated message for user authentication and a basis for the receiver to measure the message for user authentication sent by the sender, based on measurement basis information; and receiving, from the receiver, a user authentication measurement value related to the matching portion between the basis for the sender to generate the message for user authentication and the basis for the receiver to measure the message for user authentication sent by the sender, among measurement values of the messages for user authentication sent by the entire receiver. Determining success or failure of user authentication based on a user authentication error rate, which is calculated based on the difference between (i) the value of the user authentication information and (ii) the user authentication measurement value.

[0015] Performing QBER estimation may include sending, to the receiver, a remaining check sequence excluding a portion of a check sequence determined from each of at least one data block.

[0016] Performing QBER estimation may further include: sending, to the receiver, information used as a basis for generating the remaining check sequence; and receiving, from the receiver, measurement basis information for a basis for the receiver to measure the sent remaining check sequence.

[0017] Performing QBER estimation may further include: determining check sequence information related to a matching portion between a basis for the sender to generate the remaining check sequence from the generated remaining check sequence and a basis for the receiver to measure the remaining check sequence sent by the sender, based on the measurement basis information; and receiving, from the receiver, a check sequence measurement value related to the matching portion between the basis for the sender to generate the remaining check sequence and the basis for the receiver to measure the remaining check sequence sent by the sender, among measurement values of the remaining check sequence sent by the entire receiver.

[0018] At least one key generated based on a pre-shared key may be constructed by repeatedly concatenating the pre-shared key until the sum of (i) the length of the pre-shared key and (ii) the length of at least one key generated based on the pre-shared key is equal to the length of an information sequence including at least one data block.

[0019] At least one key generated based on a pre-shared key may be constructed by repeatedly concatenating the pre-shared key until the sum of (i) the length of the pre-shared key and (ii) the length of at least one key generated based on the pre-shared key is equal to the length of an information sequence including at least one data block. Whenever the pre-shared key is repeatedly concatenated, the repeatedly concatenated pre-shared key may be shifted to the left or right.

[0020] Each of the pre-shared key and at least one key generated based on the pre-shared key can correspond one-to-one to at least one data block.

[0021] A transmitter for performing user authentication in a quantum communication system according to the present disclosure, the transmitter comprising: a transmitter that transmits radio signals; a receiver that receives radio signals; at least one processor; and at least one computer memory operatively connected to the at least one processor and storing instructions for performing operations based on execution by the at least one processor. The operations include: performing a random access procedure with a receiving end, the random access procedure being for establishing a connection related to a classical channel that is related to a quantum channel for user authentication, wherein the random access procedure includes: transmitting a random access preamble to the receiving end; receiving a random access response from the receiving end; transmitting a connection request message to the receiving end based on the random access response; receiving a contention resolution message from the receiving end; transmitting an information sequence including at least one data block to the receiving end on the quantum channel; wherein, based on (i) a pre-shared key between the transmitter and the receiving end and (ii) at least one key generated based on the pre-shared key, a check sequence for determining a quantum bit error rate (QBER) estimate for determining whether there is eavesdropping on the quantum channel is determined from each of the at least one data block, wherein the pre-shared key is used to select the position of the sequence for user authentication among the sequences included in a specific data block related to user authentication among the at least one data blocks; performing user authentication with the receiving end based on a portion of the check sequence determined from each of the at least one data block; and performing QBER estimation with the receiving end based on (i) the result of the user authentication and (ii) the remaining check sequence excluding the portion of the check sequence determined from each of the at least one data block, wherein (i) a user authentication error rate calculated based on the portion of the check sequence for user authentication and determined from each of the at least one data block, and (ii) a QBER estimation error rate calculated based on the remaining check sequence excluding the portion of the check sequence determined from each of the at least one data block are used for QBER estimation.

[0022] A method for a receiving end to perform user authentication in a quantum communication system according to the present disclosure, the method comprising: performing a random access process with a sending end, the random access process being used to establish a connection related to a classical channel, the classical channel being related to a quantum channel for user authentication, wherein the random access process includes: receiving a random access preamble from the sending end; sending a random access response to the sending end; receiving a connection request message from the sending end based on the random access response; and sending a contention resolution message to the sending end; receiving an information sequence including at least one data block from the sending end on the quantum channel, wherein, based on (i) a pre-shared key between the sending end and the receiving end and (ii) at least one key generated based on the pre-shared key, a check sequence for determining a quantum bit error rate (QBER) estimate for determining whether there is eavesdropping on the quantum channel is determined from each of the at least one data block, wherein the pre-shared key is used to select the position of the sequence for user authentication among the sequences included in a specific data block related to user authentication among the at least one data block; performing user authentication with the sending end based on a part of the check sequence determined from each of the at least one data block; and performing a QBER estimate with the receiving end based on (i) the result of the user authentication and (ii) the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block, wherein (i) a user authentication error rate calculated based on the part of the check sequence for user authentication and determined from each of the at least one data block, and (ii) a QBER estimate error rate calculated based on the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block are used for the QBER estimate.

[0023] A receiving end for performing user authentication in a quantum communication system according to the present disclosure, the receiving end comprising: a transmitter that transmits a radio signal; a receiver that receives a radio signal; at least one processor; and at least one computer memory that is operatively connected to the at least one processor and stores instructions for performing operations based on being executed by the at least one processor. The operations include: performing a random access process with a transmitting end, the random access process being for establishing a connection related to a classical channel, the classical channel being related to a quantum channel for user authentication, wherein the random access process includes: receiving a random access preamble from the transmitting end; sending a random access response to the transmitting end; receiving a connection request message from the transmitting end based on the random access response; and sending a contention resolution message to the transmitting end; receiving an information sequence including at least one data block from the transmitting end on the quantum channel; wherein, based on (i) a pre-shared key between the transmitting end and the receiving end and (ii) at least one key generated based on the pre-shared key, a check sequence for determining a quantum bit error rate (QBER) estimate for determining whether there is eavesdropping on the quantum channel is determined from each of the at least one data block, wherein the pre-shared key is used to select a position of a sequence for user authentication among sequences included in a specific data block related to user authentication among the at least one data block; performing user authentication with the transmitting end based on a portion of the check sequence determined from each of the at least one data block; and performing QBER estimation with the receiving end based on (i) the result of the user authentication and (ii) the remaining check sequence excluding the portion of the check sequence determined from each of the at least one data block, wherein (i) a user authentication error rate calculated based on the portion of the check sequence for user authentication and determined from each of the at least one data block, and (ii) a QBER estimation error rate calculated based on the remaining check sequence excluding the portion of the check sequence determined from each of the at least one data block are used for QBER estimation.

[0024] In a non - transitory computer - readable medium (CRM) according to the present disclosure that stores one or more instructions, the one or more instructions executable by one or more processors allow a sending end: to perform a random access process with a receiving end, the random access process being used to establish a connection related to a classical channel, the classical channel being related to a quantum channel for user authentication, wherein the random access process includes: sending a random access preamble to the receiving end, receiving a random access response from the receiving end, sending a connection request message to the receiving end based on the random access response, and receiving a contention resolution message from the receiving end; sending an information sequence including at least one data block to the receiving end over the quantum channel; wherein, based on (i) a pre - shared key between the sending end and the receiving end and (ii) at least one key generated based on the pre - shared key, a check sequence for determining a quantum bit error rate (QBER) estimate for determining whether there is eavesdropping on the quantum channel is determined from each of the at least one data block, wherein the pre - shared key is used to select the position of the sequence for user authentication among the sequences included in a specific data block related to user authentication among the at least one data block; performing user authentication with the receiving end based on a part of the check sequence determined from each of the at least one data block; and performing QBER estimation with the receiving end based on (i) the result of user authentication and (ii) the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block, wherein (i) a user authentication error rate calculated based on the part of the check sequence for user authentication and determined from each of the at least one data block, and (ii) a QBER estimation error rate calculated based on the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block are used for QBER estimation.

[0025] In a device according to the present disclosure that includes one or more memories and one or more processors operatively connected to the one or more memories, the one or more processors enable the device to: perform a random access procedure with a receiving end, the random access procedure being for establishing a connection related to a classical channel, the classical channel being related to a quantum channel for user authentication, wherein the random access procedure includes: sending a random access preamble to the receiving end, receiving a random access response from the receiving end, sending a connection request message to the receiving end based on the random access response, and receiving a contention resolution message from the receiving end; sending an information sequence including at least one data block to the receiving end over the quantum channel; wherein, based on (i) a pre-shared key between the sending end and the receiving end and (ii) at least one key generated based on the pre-shared key, a check sequence for determining a quantum bit error rate (QBER) estimate for determining whether there is eavesdropping on the quantum channel is determined from each of the at least one data block, wherein the pre-shared key is used to select the position of the sequence for user authentication among the sequences included in a specific data block related to user authentication among the at least one data block; performing user authentication with the receiving end based on a part of the check sequence determined from each of the at least one data block; and performing QBER estimation with the receiving end based on (i) the result of the user authentication and (ii) the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block, wherein (i) the user authentication error rate calculated based on the part of the check sequence for user authentication and determined from each of the at least one data block, and (ii) the QBER estimation error rate calculated based on the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block are used for QBER estimation.

[0026] Advantageous Effects

[0027] The present disclosure has the effect of performing user authentication in a quantum communication system.

[0028] The present disclosure has the effect of performing user authentication using information sent over a quantum channel in a quantum communication system.

[0029] The present disclosure has the effect of ensuring security without assuming that the sending end and the receiving end of the classical channel and the quantum channel are the same because user authentication is performed using information sent over a quantum channel in a quantum communication system.

[0030] The present disclosure has the effect that the information used for user authentication in a quantum communication system can be used for QBER estimation.

[0031] The present disclosure has the effect of improving the processing speed of the QBER estimation process in a quantum communication system.

[0032] The advantages achievable in the present disclosure are not limited to the effects described only by way of example above, and other effects and advantages of the present disclosure will be more clearly understood by those skilled in the art to which the present disclosure pertains from the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] The drawings are provided to assist in understanding the present disclosure, and embodiments of the present disclosure may be provided together with the detailed description. However, the technical features of the present disclosure are not limited to specific drawings, and the features disclosed in each drawing may be combined with each other to constitute new embodiments. The reference numerals in each drawing may refer to structural elements.

[0034] Figure 1 An example of a communication system applicable to the present disclosure is shown.

[0035] Figure 2 An example of a wireless device applicable to the present disclosure is shown.

[0036] Figure 3 A method of processing a transmitted signal applicable to the present disclosure is shown.

[0037] Figure 4 Another example of a wireless device applicable to the present disclosure is shown.

[0038] Figure 5 An example of a handheld device applicable to the present disclosure is shown.

[0039] Figure 6 A physical channel applicable to the present disclosure and a signal transmission method using the physical channel are shown.

[0040] Figure 7 A structure of a radio frame applicable to the present disclosure is shown.

[0041] Figure 8 A time slot structure applicable to the present disclosure is shown.

[0042] Figure 9 An example of a communication structure that can be provided in a 6G system applicable to the present disclosure is shown.

[0043] Figure 10 An example of the structure of a quantum communication system is shown.

[0044] Figure 11 An example of a third-party attack that may occur in quantum communication is shown.

[0045] Figure 12 An example of a MAC-based authentication scheme is shown. Figure 13 An example of an authentication method based on Wegman and Carter authentication (WCA) is shown.

[0046] Figure 14Shows an example of a user authentication process via a classical channel.

[0047] Figure 15 Shows an example of a user authentication process that applies the method of selecting the location of authentication information using a pre-shared symmetric key described in the present disclosure.

[0048] Figure 16 Shows an example of a user authentication process that applies the method described in the present disclosure to the authentication process when there is an eavesdropper in the receiver.

[0049] Figure 17 Shows an example of generating an authentication code from a pre-shared symmetric key in a user authentication process that applies the method described in the present disclosure.

[0050] Figure 18 Shows an example of a process of performing authentication by estimating an error rate from authentication codes generated by a transmitter and a receiver of quantum communication.

[0051] Figure 19 Is a flowchart showing an example of performing the user authentication method described in the present disclosure.

[0052] Figure 20 Shows an example of information for authentication and QBER estimation in the method described in the present disclosure.

[0053] Figure 21 Shows a process of selecting information for authentication and QBER estimation from among quantum state string information transmitted on a quantum channel described in the present disclosure.

[0054] Figure 22 Shows an overall flowchart of an authentication scheme and a QBER estimation process that use a pre-shared key described in the present disclosure for authentication information location selection.

[0055] Figure 23 Shows an example of the method of configuring a quantum data block described in the present disclosure.

[0056] Figure 24 Shows an example of performing the QBER estimation method described in the present disclosure.

[0057] Figure 25 Shows an example of performing the authentication method described in the present disclosure.

[0058] Figure 26 Shows an example of performing the user authentication method described in the present disclosure.

[0059] Figure 27 Shows an example of performing the QBER estimation method described in the present disclosure.

[0060] Figure 28An example of applying the user authentication method described in the present disclosure to a QKD method is shown.

[0061] Figure 29 An example of applying the user authentication method described in the present disclosure to the DL04 QSDC quantum communication protocol, which is used to securely send classical information over a single-photon-based quantum channel, is shown.

[0062] Figure 30 An example of performing a user authentication process in which a pre-shared symmetric key is applied to position selection and basis selection is shown.

[0063] Figures 31 to 33 The minimum length of the pre-shared symmetric key required to ensure security for each security strength is shown.

[0064] Figure 34 It is a flowchart showing an example of the user authentication method described in the present disclosure being executed by a sending end.

[0065] Figure 35 It is a flowchart showing an example of the user authentication method described in the present disclosure being executed by a receiving end. Detailed implementation manners

[0066] The embodiments of the present disclosure described below are combinations of elements and features in a specific form of the present disclosure. Unless otherwise mentioned, the elements or features can be considered selective. Each element or feature can be practiced without being combined with other elements or features. In addition, embodiments of the present disclosure can be constructed by combining some of the elements and / or features. The operation sequence described in the embodiments of the present disclosure can be rearranged. Some configurations or elements of any one embodiment can be included in another embodiment and can be replaced by the corresponding configurations or features of another embodiment.

[0067] In the description of the drawings, processes or steps that make the scope of the present disclosure appear unnecessarily ambiguous will be omitted, and processes or steps that can be understood by those skilled in the art will be omitted.

[0068] Throughout the specification, when a part "includes" or "comprises" a certain component, this indicates that other components are not excluded and may be further included, unless otherwise stated. The terms "unit", "-or / er", and "module" described in this specification indicate a unit for processing at least one function or operation, which may be implemented by hardware, software, or a combination thereof. Additionally, the terms "a", "an", "one", "the", etc. in the context of the present disclosure (more specifically, in the context of the appended claims) may include singular and plural representations, unless otherwise stated in the specification or unless the context clearly states otherwise.

[0069] In an embodiment of the present disclosure, the data transmission and reception relationship between a base station (BS) and a mobile station is mainly described. The BS refers to the terminal node of the network that directly communicates with the mobile station. Specific operations described as being performed by the BS may be performed by an upper-layer node of the BS.

[0070] That is, it is obvious that in a network composed of multiple network nodes including the BS, various operations performed for communicating with the mobile station may be performed by the BS or network nodes other than the BS. The term "BS" may be replaced with a fixed station, Node B, evolved Node B (eNode B or eNB), advanced base station (ABS), access point, etc.

[0071] In an embodiment of the present disclosure, the term "terminal" may be replaced with UE, mobile station (MS), subscriber station (SS), mobile subscriber station (MSS), mobile terminal, advanced mobile station (AMS), etc.

[0072] The transmitter is a fixed and / or mobile node that provides data services or voice services, and the receiver is a fixed and / or mobile node that receives data services or voice services. Therefore, on the uplink (UL), the mobile station may act as the transmitter and the BS may act as the receiver. Similarly, on the downlink (DL), the mobile station may act as the receiver and the BS may act as the transmitter.

[0073] Embodiments of the present disclosure may be supported by standard specifications disclosed for at least one of wireless access systems including Institute of Electrical and Electronics Engineers (IEEE) 802.xx systems, 3rd Generation Partnership Project (3GPP) systems, 3GPP Long Term Evolution (LTE) systems, 3GPP 5th Generation (5G) New Radio (NR) systems, and 3GPP2 systems. Specifically, embodiments of the present disclosure may be supported by standard specifications 3GPP TS 36.211, 3GPP TS 36.212, 3GPP TS 36.213, 3GPP TS 36.321, and 3GPP TS 36.331.

[0074] In addition, embodiments of the present disclosure are applicable to other radio access systems and are not limited to the above systems. For example, embodiments of the present disclosure are applicable to systems applied after the 3GPP 5G NR system and are not limited to a specific system.

[0075] That is, steps or parts not described to clarify the technical features of the present disclosure can be supported by those documents. In addition, all terms presented herein can be interpreted through standard documents.

[0076] Embodiments of the present disclosure will now be described in detail with reference to the accompanying drawings. The following detailed description given with reference to the accompanying drawings is intended to explain the exemplary embodiments of the present disclosure and does not show the only embodiments that can be implemented according to the present disclosure.

[0077] The following detailed description includes specific terms to facilitate a thorough understanding of the present disclosure. However, it will be apparent to those skilled in the art that the specific terms can be replaced by other terms without departing from the technical spirit and scope of the present disclosure.

[0078] Embodiments of the present disclosure can be applied to various radio access systems, such as Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-Carrier Frequency Division Multiple Access (SC-FDMA), etc.

[0079] Hereinafter, for the sake of clarifying the following description, the description is based on 3GPP communication systems (e.g., LTE, NR, etc.), but the technical spirit of the present disclosure is not limited thereto. LTE can refer to the technology after 3GPP TS 36.xxx version 8. Specifically, the LTE technology after 3GPP TS 36.xxx version 10 can be referred to as LTE-A, and the LTE technology after 3GPP TS 36.xxx version 13 can be referred to as pre-LTE-A. 3GPP NR can refer to the technology after TS 38.xxx version 15. 3GPP 6G can refer to the technology after TS version 17 and / or version 18. "xxx" can refer to the detailed number of the standard document. LTE / NR / 6G can be collectively referred to as 3GPP systems.

[0080] For the background technology, terms, abbreviations, etc. used in the present disclosure, refer to the matters described in the standard documents published before the present disclosure. For example, reference can be made to the standard documents 36.xxx and 38.xxx.

[0081] Communication systems applicable to the present invention

[0082] Without limitation, the various descriptions, functions, processes, proposals, methods, and / or operation flowcharts of the present disclosure disclosed herein are applicable to various fields that require wireless communication / connection (e.g., 5G).

[0083] Hereinafter, a more detailed description will be given with reference to the accompanying drawings. In the following drawings / description, unless otherwise specified, the same reference numerals may illustrate the same or corresponding hardware blocks, software blocks, or functional blocks.

[0084] Figure 1 An example of a communication system applicable to the present disclosure is shown. Referring to Figure 1 , the communication system 100 applicable to the present disclosure includes a wireless device, a base station, and a network. The wireless device refers to a device used to perform communication using radio access technology (e.g., 5G NR or LTE) and may be referred to as a communication / wireless / 5G device. Without limitation, the wireless device may include a robot 100a, vehicles 100b-1 and 100b-2, an extended reality (XR) device 100c, a handheld device 100d, a household appliance 100e, an Internet of Things (IoT) device 100f, and an artificial intelligence (AI) device / server 100g. For example, the vehicle may include a vehicle with a wireless communication function, an autonomous vehicle, a vehicle capable of performing vehicle-to-vehicle communication, etc. Vehicles 100b-1 and 100b-2 may include unmanned aerial vehicles (UAVs) (e.g., drones). The XR device 100c includes an augmented reality (AR) / virtual reality (VR) / mixed reality (MR) device and may be implemented in the form of a head-mounted device (HMD), a head-up display (HUD) provided in a vehicle, a TV, a smartphone, a computer, a wearable device, a household appliance, a digital sign, a vehicle, or a robot. The handheld device 100d may include a smartphone, a smart tablet, a wearable device (e.g., a smart watch or smart glasses), a computer (e.g., a laptop computer), etc. The household appliance 100e may include a TV, a refrigerator, a washing machine, etc. The IoT device 100f may include sensors, smart meters, etc. For example, the base station 120 and the network 130 may be implemented by wireless devices, and a specific wireless device 120a may operate as a base station / network node for another wireless device.

[0085] Wireless devices 100a to 100f can be connected to network 130 via base station 120. AI technology is applicable to wireless devices 100a to 100f, and wireless devices 100a to 100f can be connected to AI server 100g via network 130. Network 130 can be configured using a 3G network, a 4G (e.g., LTE) network, or a 5G (e.g., NR) network, etc. Wireless devices 100a to 100f can communicate with each other via base station 120 / network 130 or perform direct communication (e.g., sidelink communication) without going through base station 120 / network 130. For example, vehicles 100b-1 and 100b-2 can perform direct communication (e.g., vehicle-to-vehicle (V2V) / vehicle-to-everything (V2X) communication). Additionally, IoT device 100f (e.g., a sensor) can perform direct communication with another IoT device (e.g., a sensor) or other wireless devices 100a to 100f.

[0086] Wireless communications / connections 150a, 150b, and 150c can be established between wireless devices 100a to 100f / base station 120 and base station 120 / base station 120. Here, the wireless communications / connections can be established through various radio access technologies (e.g., 5G NR) such as uplink / downlink communication 150a, sidelink communication 150b (or D2D communication), or communication 150c between base stations (e.g., relay, integrated access backhaul (IAB)). Wireless devices and base stations / wireless devices or base stations and base stations can send / receive radio signals to / from each other via wireless communications / connections 150a, 150b, and 150c. For example, wireless communications / connections 150a, 150b, and 150c can achieve signal transmission / reception through various physical channels. To this end, based on various proposals of the present disclosure, at least some of various configuration information setting processes, various signal processing processes (e.g., channel encoding / decoding, modulation / demodulation, resource mapping / demapping, etc.), resource allocation processes, etc. for radio signal transmission / reception can be performed.

[0087] Communication system applicable to the present disclosure

[0088] Figure 2 Shows an example of a wireless device applicable to the present disclosure.

[0089] Reference Figure 2 , the first wireless device 200a and the second wireless device 200b can send and receive radio signals through various radio access technologies (e.g., LTE or NR). Here, {the first wireless device 200a, the second wireless device 200b} can correspond to Figure 1 {wireless device 100x, base station 120} and / or {wireless device 100x, wireless device 100x}.

[0090] The first wireless device 200a may include one or more processors 202a and one or more memories 204a, and may further include one or more transceivers 206a and / or one or more antennas 208a. The processor 202a may be configured to control the memory 204a and / or the transceiver 206a and implement the descriptions, functions, processes, proposals, methods, and / or operation flowcharts disclosed herein. For example, the processor 202a may process the information in the memory 204a to generate first information / signals, and then transmit radio signals including the first information / signals through the transceiver 206a. Additionally, the processor 202a may receive radio signals including second information / signals through the transceiver 206a, and then store the information obtained from signal processing of the second information / signals in the memory 204a. The memory 204a may be connected to the processor 202a and store various information related to the operation of the processor 202a. For example, the memory 204a may store software code including instructions for executing all or some of the processes controlled by the processor 202a or for implementing the descriptions, functions, processes, proposals, methods, and / or operation flowcharts disclosed herein. Here, the processor 202a and the memory 204a may be part of a communication modem / circuit / chip designed to implement wireless communication technologies (e.g., LTE or NR). The transceiver 206a may be connected to the processor 202a to transmit and / or receive radio signals through one or more antennas 208a. The transceiver 206a may include a transmitter and / or a receiver. The transceiver 206a may be used interchangeably with a radio frequency (RF) unit. In the present disclosure, a wireless device may refer to a communication modem / circuit / chip.

[0091] The second wireless device 200b may include one or more processors 202b and one or more memories 204b, and may further include one or more transceivers 206b and / or one or more antennas 208b. The processor 202b may be configured to control the memory 204b and / or the transceiver 206b and implement the descriptions, functions, processes, proposals, methods, and / or operation flowcharts disclosed herein. For example, the processor 202b may process the information in the memory 204b to generate third information / signals, and then transmit the third information / signals through the transceiver 206b. Additionally, the processor 202b may receive a radio signal including fourth information / signals through the transceiver 206b, and then store the information obtained from the signal processing of the fourth information / signals in the memory 204b. The memory 204b may be connected to the processor 202b to store various information related to the operation of the processor 202b. For example, the memory 204b may store software code including instructions for performing all or some of the processes controlled by the processor 202b or for implementing the descriptions, functions, processes, proposals, methods, and / or operation flowcharts disclosed herein. Here, the processor 202b and the memory 204b may be part of a communication modem / circuit / chip designed to implement wireless communication technologies (e.g., LTE or NR). The transceiver 206b may be connected to the processor 202b to transmit and / or receive radio signals through one or more antennas 208b. The transceiver 206b may include a transmitter and / or a receiver. The transceiver 206b may be used interchangeably with the radio frequency (RF) unit. In the present disclosure, the wireless device may refer to a communication modem / circuit / chip.

[0092] In the following, the hardware components of wireless devices 200a and 200b will be described in more detail. Without limitation, one or more protocol layers may be implemented by one or more processors 202a and 202b. For example, one or more processors 202a and 202b may implement one layer or multiple layers (e.g., functional layers such as PHY (Physical), MAC (Media Access Control), RLC (Radio Link Control), PDCP (Packet Data Convergence Protocol), RRC (Radio Resource Control), SDAP (Service Data Adaptation Protocol)). One or more processors 202a and 202b may generate one or more protocol data units (PDUs) and / or one or more service data units (SDUs) according to the descriptions, functions, processes, proposals, methods, and / or operation flowcharts disclosed herein. One or more processors 202a and 202b may generate messages, control information, data, or information according to the descriptions, functions, processes, proposals, methods, and / or operation flowcharts disclosed herein. One or more processors 202a and 202b may generate PDUs, SDUs, messages, control information, data, or information according to the functions, processes, proposals, and / or methods disclosed herein, and provide the PDUs, SDUs, messages, control information, data, or information to one or more transceivers 206a and 206b. One or more processors 202a and 202b may receive signals (e.g., baseband signals) from one or more transceivers 206a and 206b, and obtain PDUs, SDUs, messages, control information, data, or information according to the descriptions, functions, processes, proposals, methods, and / or operation flowcharts disclosed herein.

[0093] One or more processors 202a and 202b may be referred to as a controller, microcontroller, microprocessor, or microcomputer. One or more processors 202a and 202b may be implemented by hardware, firmware, software, or a combination thereof. For example, one or more application specific integrated circuits (ASICs), one or more digital signal processors (DSPs), one or more digital signal processor devices (DSPDs), programmable logic devices (PLDs), or one or more field programmable gate arrays (FPGAs) may be included in one or more processors 202a and 202b. The descriptions, functions, processes, proposals, methods, and / or operation flowcharts disclosed herein may be implemented using firmware or software, and the firmware or software may be implemented to include modules, processes, functions, etc. The firmware or software configured to execute the descriptions, functions, processes, proposals, methods, and / or operation flowcharts disclosed herein may be included in one or more processors 202a and 202b or stored in one or more memories 204a and 204b to be driven by one or more processors 202a and 202b. The descriptions, functions, processes, proposals, methods, and / or operation flowcharts disclosed herein are implemented using firmware or software in the form of code, commands, and / or command sets.

[0094] One or more memories 204a and 204b may be connected to one or more processors 202a and 202b to store various types of data, signals, messages, information, programs, codes, instructions, and / or commands. One or more memories 204a and 204b may be composed of read only memory (ROM), random access memory (RAM), erasable programmable read only memory (EPROM), flash memory, hard disk drive, registers, cache memory, computer readable storage medium, and / or a combination thereof. One or more memories 204a and 204b may be located inside and / or outside one or more processors 202a and 202b. Additionally, one or more memories 204a and 204b may be connected to one or more processors 202a and 202b through various technologies such as wired or wireless connections.

[0095] One or more transceivers 206a and 206b may transmit user data, control information, radio signals / channels, etc. described in the methods and / or operational flowcharts of the present disclosure to one or more other devices. One or more transceivers 206a and 206b may receive user data, control information, radio signals / channels, etc. described in the methods and / or operational flowcharts of the present disclosure from one or more other devices. For example, one or more transceivers 206a and 206b may be connected to one or more processors 202a and 202b to transmit / receive radio signals. For example, one or more processors 202a and 202b may execute control such that one or more transceivers 206a and 206b transmit user data, control information, or radio signals to one or more other devices. Additionally, one or more processors 202a and 202b may execute control such that one or more transceivers 206a and 206b receive user data, control information, or radio signals from one or more other devices. Additionally, one or more transceivers 206a and 206b may be connected to one or more antennas 208a and 208b, and one or more transceivers 206a and 206b may be configured to transmit / receive user data, control information, radio signals / channels, etc. described in the descriptions, functions, processes, proposals, methods, and / or operational flowcharts disclosed herein via one or more antennas 208a and 208b. In the present disclosure, one or more antennas may be multiple physical antennas or multiple logical antennas (e.g., antenna ports). One or more transceivers 206a and 206b may convert received radio signals / channels, etc. from RF-band signals to baseband signals to facilitate processing of the received user data, control information, radio signals / channels, etc. using one or more processors 202a and 202b. One or more transceivers 206a and 206b may convert user data, control information, radio signals / channels processed using one or more processors 202a and 202b from baseband signals to RF-band signals. To this end, one or more transceivers 206a and 206b may include (analog) oscillators and / or filters.

[0096] Figure 3 A method for processing transmitted signals applicable to the present disclosure is shown. For example, the transmitted signals may be processed by a signal processing circuit. At this time, the signal processing circuit 300 may include a scrambler 310, a modulator 320, a layer mapper 330, a precoder 340, a resource mapper 350, and a signal generator 360. At this time, for example, Figure 3 's operations / functions may be performed by Figure 2 's processors 202a and 202b and / or transceivers 206a and 206b. Additionally, for example, Figure 3 's hardware elements may be in Figure 2Processor 202a and 202b and / or Figure 2 be implemented in transceiver 206a and 206b. For example, blocks 1010 to 1060 may be implemented in Figure 2 Processor 202a and 202b. Additionally, without being limited to the above embodiments, blocks 310 to 350 may be implemented in Figure 2 Processor 202a and 202b, and block 360 may be implemented in Figure 2 Transceiver 206a and 206b.

[0097] The codeword may be converted into a radio signal by Figure 3 signal processing circuit 300. Here, the codeword is a coded bit sequence of an information block. The information block may include a transport block (e.g., UL-SCH transport block or DL-SCH transport block). The radio signal may be sent through Figure 6 various physical channels (e.g., PUSCH and PDSCH). Specifically, the codeword may be converted into a bit sequence scrambled by scrambler 310. The scrambling sequence for scrambling is generated based on an initial value, and the initial value may include ID information of the wireless device, etc. The scrambled bit sequence may be modulated into a modulated symbol sequence by modulator 320. The modulation method may include pi / 2-binary phase shift keying (pi / 2-BPSK), m-phase shift keying (m-PSK), m-quadrature amplitude modulation (m-QAM), etc.

[0098] The complex modulated symbol sequence may be mapped to one or more transmission layers by layer mapper 330. The modulated symbols of each transmission layer may be mapped to corresponding antenna ports (precoding) by precoder 340. The output z of precoder 340 may be obtained by multiplying the output y of layer mapper 330 by an N*M precoding matrix W. Here, N may be the number of antenna ports and M may be the number of transmission layers. Here, precoder 340 may perform precoding after performing transform precoding (e.g., discrete Fourier transform (DFT)) on the complex modulated symbols. Additionally, precoder 340 may perform precoding without performing transform precoding.

[0099] Resource mapper 350 may map the modulated symbols of each antenna port to time-frequency resources. The time-frequency resources may include multiple symbols in the time domain (e.g., CP-OFDMA symbols and DFT-s-OFDMA symbols) and include multiple subcarriers in the frequency domain. Signal generator 360 may generate a radio signal according to the mapped modulated symbols, and the generated radio signal may be sent to another device through each antenna. For this purpose, signal generator 360 may include an inverse fast Fourier transform (IFFT) module, a cyclic prefix (CP) inserter, a digital-to-analog converter (DAC), a frequency upconverter, etc.

[0100] The signal processing process for the received signal in a wireless device can be configured as Figure 3 the inverse process of signal processing processes 310 to 360. For example, a wireless device (e.g., Figure 2 200a or 200b) can receive a radio signal from the outside through an antenna port / transceiver. The received radio signal can be converted into a baseband signal by a signal restorer. For this purpose, the signal restorer can include a frequency downconverter, an analog-to-digital converter (ADC), a CP remover, and a fast Fourier transform (FFT) module. Thereafter, the baseband signal can be restored to a codeword through a resource demapper process, a post-compilation process, a demodulation process, and a descrambling process. The codeword can be restored to the original information block through decoding. Therefore, the signal processing circuit (not shown) for the received signal can include a signal restorer, a resource demapper, a post-compiler, a demodulator, a descrambler, and a decoder.

[0101] Structure of a wireless device applicable to the present disclosure

[0102] Figure 4 Another example of a wireless device applicable to the present disclosure is shown.

[0103] Referring to Figure 4 , the wireless device 400 can correspond to Figure 2 the wireless devices 200a and 200b and includes various elements, components, units / parts, and / or modules. For example, the wireless device 300 can include a communication unit 410, a control unit (controller) 420, a memory unit (memory) 430, and additional components 440. The communication unit can include a communication circuit 412 and a transceiver 414. For example, the communication circuit 412 can include Figure 2 one or more processors 202a and 202b and / or one or more memories 204a and 204b of Figure 2 . For example, the transceiver 414 can include

[0104] The add-on 440 can be configured differently according to the type of wireless device. For example, the add-on 440 can include at least one of a power unit / battery, an input / output unit, a drive unit, or a computing unit. Without being limited thereto, the wireless device 300 can be in the form of a robot ( Figure 1 , 100a), a vehicle ( Figure 1 , 100b-1 and 100b-2), an XR device ( Figure 1 , 100c), a handheld device ( Figure 1 , 100d), a household appliance ( Figure 1 , 100e), an IoT device ( Figure 1 , 100f), a digital broadcast terminal, a holographic device, a public safety device, an MTC device, a medical device, a fintech device (financial device), a security device, a climate / environment device, an AI server / device ( Figure 1 , 140), a base station ( Figure 1 , 120), a network node, etc. According to the usage example / service, the wireless device can be movable or can be used at a fixed location.

[0105] In Figure 4 , various elements, components, units / parts, and / or modules in the wireless device 400 can be connected to each other through a wired interface, or at least some of them can be wirelessly connected through the communication unit 410. For example, in the wireless device 400, the control unit 420 and the communication unit 410 can be connected by wire, and the control unit 420 and the first unit (e.g., 130 or 140) can be wirelessly connected through the communication unit 410. In addition, each element, component, unit / part, and / or module of the wireless device 400 can further include one or more elements. For example, the control unit 420 can be composed of a set of one or more processors. For example, the control unit 420 can be composed of a set of a communication control processor, an application processor, an electronic control unit (ECU), a graphics processing processor, a memory control processor, etc. In another example, the memory unit 430 can be composed of a random access memory (RAM), a dynamic RAM (DRAM), a read-only memory (ROM), a flash memory, a volatile memory, a non-volatile memory, and / or a combination thereof.

[0106] Handheld device applicable to the present disclosure

[0107] Figure 5 Shows an example of a handheld device applicable to the present disclosure.

[0108] Figure 5Shows a handheld device applicable to the present disclosure. The handheld device may include a smartphone, a smart tablet, a wearable device (e.g., a smartwatch or smart glasses), and a handheld computer (e.g., a laptop computer, etc.). The handheld device may be referred to as a mobile station (MS), a user terminal (UT), a mobile subscriber station (MSS), a subscriber station (SS), an advanced mobile station (AMS), or a wireless terminal (WT).

[0109] Referring Figure 5 , the handheld device 400 may include an antenna unit (antenna) 508, a communication unit (transceiver) 510, a control unit (controller) 520, a memory unit (memory) 530, a power supply unit (power supply) 540a, an interface unit (interface) 540b, and an input / output unit 540c. The antenna unit (antenna) 508 may be part of the communication unit 510. Blocks 510 to 530 / 540a to 540c may respectively correspond to Figure 4 blocks 410 to 430 / 440 of

[0110] The communication unit 510 may send signals (e.g., data, control signals, etc.) to other wireless devices or base stations and receive signals from other wireless devices or base stations. The control unit 520 may control the components of the handheld device 500 to perform various operations. The control unit 520 may include an application processor (AP). The memory unit 530 may store the data / parameters / programs / codes / instructions necessary to drive the handheld device 400. Additionally, the memory unit 530 may store input / output data / information, etc. The power supply unit 540a may supply power to the handheld device 500 and includes a wired / wireless charging circuit, a battery, etc. The interface unit 540b may support the connection between the handheld device 500 and another external device. The interface unit 540b may include various ports for connecting to external devices (e.g., audio input / output ports and video input / output ports). The input / output unit 540c may receive or output video information / signals, audio information / signals, data, and / or user input information. The input / output unit 540c may include a camera, a microphone, a user input unit, a display 540d, a speaker, and / or a tactile module.

[0111] For example, in the case of data communication, the input / output unit 540c may obtain user input information / signals (e.g., touch, text, voice, image, or video) from a user and store the user input information / signals in the memory unit 530. The communication unit 510 may convert the information / signals stored in the memory into radio signals and directly transmit the converted radio signals to another wireless device or transmit the converted radio signals to a base station. Additionally, the communication unit 510 may receive radio signals from another wireless device or a base station and then restore the received radio signals to the original information / signals. The restored information / signals may be stored in the memory unit 530 and then output in various forms (e.g., text, voice, image, video, and tactile) through the input / output unit 540c.

[0112] Physical channels and general signal transmission

[0113] In a radio access system, a UE receives information from a base station on the DL and transmits information to the base station on the UL. The information transmitted and received between the UE and the base station includes general data information and various control information. There are many physical channels according to the type / usage of the information transmitted and received between the base station and the UE.

[0114] Figure 6 Illustrates physical channels applicable to the present disclosure and a signal transmission method using the physical channels.

[0115] A UE that is turned on again in the closed state or newly enters a cell performs an initial cell search operation, such as obtaining synchronization with the base station, in step S611. Specifically, the UE performs synchronization with the base station by receiving a primary synchronization channel (P-SCH) and a secondary synchronization channel (S-SCH) from the base station and obtains information such as a cell identifier (ID).

[0116] Thereafter, the UE may receive a physical broadcast channel (PBCH) signal from the base station and obtain in-cell broadcast information. The UE may receive a downlink reference signal (DL RS) in the initial cell search step and check the downlink channel state. In step S612, a UE that has completed the initial cell search may receive a physical downlink control channel (PDCCH) and a physical downlink shared channel (PDSCH) according to the physical downlink control channel information, thereby obtaining more detailed system information.

[0117] Thereafter, the UE may perform a random access procedure such as steps S613 to S616 to complete access to the base station. To this end, the UE may send a preamble through the physical random access channel (PRACH) (S613), and receive a random access response (RAR) for the preamble through the physical downlink control channel and the corresponding physical downlink shared channel (S614). The UE may use the scheduling information in the RAR to send a physical uplink shared channel (PUSCH) (S615), and perform a contention resolution procedure, such as receiving a physical downlink control channel signal and the corresponding physical downlink shared channel signal (S616).

[0118] As a general uplink / downlink signal transmission process, the UE that has performed the above process may perform reception of a physical downlink control channel signal and / or a physical downlink shared channel signal (S617) and transmission of a physical uplink shared channel (PUSCH) signal and / or a physical uplink control channel (PUCCH) signal (S618).

[0119] The control information sent from the UE to the base station is collectively referred to as uplink control information (UCI). UCI includes hybrid automatic repeat request and acknowledgment / negative acknowledgment (HARQ-ACK / NACK), scheduling request (SR), channel quality indication (CQI), precoding matrix indication (PMI), rank indication (RI), beam indication (BI) information, etc. At this time, UCI is generally sent periodically through the PUCCH, but in some embodiments, UCI may be sent through the PUSCH (for example, when sending control information and service data simultaneously). In addition, the UE may send UCI aperiodically through the PUSCH according to the request / command of the network.

[0120] Figure 7 Shows the structure of a radio frame applicable to the present disclosure.

[0121] UL and DL transmissions based on the NR system may be based on the frame shown in Figure 7 At this time, a radio frame has a length of 10 ms and may be defined as two 5-ms half-frames (HFs). A half-frame may be defined as five 1-ms sub-frames (SFs). A sub-frame may be divided into one or more time slots, and the number of time slots in a sub-frame may depend on the subcarrier spacing (SCS). At this time, according to the cyclic prefix (CP), each time slot may include 12 or 14 OFDM(A) symbols. If normal CP is used, each time slot may include 14 symbols. If extended CP is used, each time slot may include 12 symbols. Here, the symbols may include OFDM symbols (or CP-OFDM symbols) and SC-FDMA symbols (or DFT-s-OFDM symbols).

[0122] Table 1 shows the number of symbols per time slot, the number of time slots per frame, and the number of time slots per subframe according to the SCS when using normal CP, and Table 2 shows the number of symbols per time slot, the number of time slots per frame, and the number of time slots per subframe according to the SCS when using extended CP.

[0123] [Table 1]

[0124]

[0125] [Table 2]

[0126]

[0127] In Tables 1 and 2 above, N slot symb can indicate the number of symbols in a time slot, N frame,μ slot can indicate the number of time slots in a frame, while N subframe,μ slot can indicate the number of time slots in a subframe.

[0128] In addition, in the system to which the present disclosure is applicable, OFDM(A) parameter sets (e.g., SCS, CP length, etc.) can be set differently between multiple cells merged into one UE. Therefore, the (absolute time) duration of a time resource (e.g., SF, time slot, or TTI) composed of the same number of symbols (collectively referred to as a time unit (TU) for convenience) can be set differently between the merged cells.

[0129] NR can support multiple parameter sets (or subcarrier spacings (SCS)) for supporting various 5G services. For example, when the SCS is 15 kHz, it supports a wide area in the traditional cellular band, when the SCS is 30 kHz / 60 kHz, it supports dense cities, lower latency, and a wider carrier bandwidth, and when the SCS is 60 kHz or higher, it can support a bandwidth greater than 24.25 GHz to overcome phase noise.

[0130] NR frequency bands are defined as two types (FR1 and FR2) of frequency ranges. FR1 and FR2 can be configured as shown in the following table. In addition, FR2 can refer to millimeter wave (mmW).

[0131] [Table 3]

[0132] Frequency range name Corresponding frequency range Subcarrier spacing FR1 410 MHz – 7125 MHz 15, 30, 60 kHz FR2 24250 MHz – 52600 MHz 60, 120, 240 kHz

[0133] In addition, for example, in the communication system to which the present disclosure is applicable, the above parameter sets can be set differently. For example, the terahertz (THz) band can be used as a band higher than FR2. In the THz band, the SCS can be set to be greater than the SCS of the NR system, and the number of time slots can be set differently, not limited to the above embodiments.

[0134] Figure 8 Fig. shows a time slot structure applicable to the present disclosure.

[0135] One time slot includes multiple symbols in the time domain. For example, in the case of normal CP, one time slot includes seven symbols, and in the case of extended CP, one time slot includes six symbols. A carrier includes multiple subcarriers in the frequency domain. A resource block (RB) can be defined as multiple (e.g., 12) consecutive subcarriers in the frequency domain.

[0136] In addition, a bandwidth part (BWP) is defined as multiple consecutive (P) RBs in the frequency domain and can correspond to one parameter set (e.g., SCS, CP length, etc.).

[0137] A carrier can include at most N (e.g., five) BWPs. Data communication is performed through the activated BWP, and only one BWP can be activated for one UE. In the resource grid, each element is called a resource element (RE), and one complex symbol can be mapped.

[0138] 6G communication system

[0139] The 6G (wireless communication) system has purposes such as: (i) very high data rate for each device, (ii) very large number of connected devices, (iii) global connectivity, (iv) very low latency, (v) reduced energy consumption for battery-free IoT devices, (vi) ultra-reliable connectivity, and (vii) interconnected intelligence with machine learning capabilities. The vision of the 6G system may include four aspects: "intelligent connection", "deep connection", "holographic connection", and "ubiquitous connection", and the 6G system may meet the requirements shown in Table 4 below. That is, Table 4 shows the requirements of the 6G system.

[0140] [Table 4]

[0141] Peak data rate per device 1 Tbps E2E latency 1 ms Maximum spectral efficiency 100 bps / Hz Mobility support Up to 1000 km / h Satellite integration Fully AI Fully Autonomous vehicles Fully XR Fully Tactile communication Fully

[0142] At this time, the 6G system can have key factors such as enhanced mobile broadband (eMBB), ultra-reliable low-latency communication (URLLC), massive machine-type communication (mMTC), artificial intelligence integrated communication, tactile Internet, high throughput, high network capacity, high energy efficiency, low backhaul and access network congestion, and enhanced data security.

[0143] Figure 9 Shows an example of a communication structure that can be provided in a 6G system applicable to the present disclosure.

[0144] Reference Figure 9 , the 6G system will have 50 times higher simultaneous wireless communication connectivity than the 5G wireless communication system. URLLC, a key function of 5G, will become an even more important technology by providing an end-to-end latency of less than 1 millisecond in 6G communication. At this time, different from the frequently used domain spectral efficiency, the 6G system can have better volumetric spectral efficiency. The 6G system can provide advanced battery technology for energy harvesting and a very long battery life, so mobile devices may not need to be charged separately in the 6G system. In addition, in 6G, new network characteristics can be as follows.

[0145] - Satellite integrated network: To provide a global mobile group, 6G will be integrated with satellites. Integrating terrestrial waves, satellites, and public networks into a single wireless communication system may be very important for 6G.

[0146] - Interconnected intelligence: Different from previous generations of wireless communication systems, 6G is innovative, and the wireless evolution may be updated from "connected things" to "connected intelligence". AI can be applied to each step of the communication process (or each signal processing process described below).

[0147] - Seamless integration of wireless information and energy transfer: The 6G wireless network can transfer electricity to charge the batteries of devices such as smartphones and sensors. Therefore, wireless information and energy transfer (WIET) will be integrated.

[0148] - Ubiquitous ultra-three-dimensional connection: Access to the network and core network functions of drones and very low Earth orbit satellites will establish ultra-3D connections in 6G ubiquity.

[0149] Among the new network characteristics of 6G, several general requirements are as follows.

[0150] - Small cell network: The concept of a small cell network is introduced to improve the received signal quality as a result of improving the throughput, energy efficiency, and spectral efficiency of the cellular system. Therefore, the small cell network is an essential feature of 5G and beyond 5G (5GB) communication systems. Therefore, the 6G communication system also adopts the characteristics of the small cell network.

[0151] - Ultra-dense heterogeneous network: The ultra-dense heterogeneous network will be another important feature of the 6G communication system. A multi-tier network composed of heterogeneous networks improves the overall QoS and reduces costs.

[0152] - High-capacity backhaul: The backhaul connection is characterized by a high-capacity backhaul network to support high-capacity services. High-speed optical fibers and free space optical (FSO) systems can be possible solutions to this problem.

[0153] - Radar technology integrated with mobile technology: High-precision positioning through communication (or location-based services) is one of the functions of 6G wireless communication systems. Therefore, radar systems will be integrated with 6G networks.

[0154] - Softwareization and virtualization: Softwareization and virtualization are two important functions that are the basis of the design process in 5G networks to ensure flexibility, reconfigurability, and programmability.

[0155] Quantum communication

[0156] Quantum communication is a next-generation communication technology that can overcome the limitations of existing information and communication, such as security and ultra-fast computing, by applying quantum mechanical properties to the fields of information and communication. Quantum communication provides a means to generate, transmit, process, and store information in a form that cannot be expressed or is difficult to express in the form of 0 and 1, which is based on the binary bit information used in existing communication technologies. In existing communication technologies, wavelengths, amplitudes, etc. have been used for information transmission between the sending end and the receiving end, while in quantum communication, photons, which are the smallest units of light, are used for information transmission between the sending end and the receiving end. In particular, quantum communication can utilize quantum uncertainty, quantum irreversibility, and the non-cloning of the polarization or phase difference of photons (light), and thus quantum communication has the characteristic of realizing communication with perfect security. Quantum communication can also use quantum entanglement to achieve ultra-fast communication under certain conditions.

[0157] This application provides a method and device for user authentication, which is a process of verifying that the entity exchanging information through a quantum channel is a pre-authorized entity in a quantum communication system. More specifically, the present disclosure provides a method and device for determining which information among the initial quantum information will be used as an authentication message for user authentication using a pre-shared symmetric key between the sending end and the receiving end.

[0158] To help understand the method described in the present disclosure, the general content of user authentication is first described.

[0159] Figure 10 An example showing the structure of a quantum communication system.

[0160] As Figure 10As shown, quantum communication technologies (such as quantum key distribution (QKD) and quantum secure direct communication (QSDC)) send information between a transmitter and a receiver 1010 / 1020 by using a quantum channel and a classical channel. The quantum channel converts a secret key or classical message information into quantum state information and then sends it, and the classical channel sends post-processing information of the sent information.

[0161] Among quantum communication technologies, the most widely known QKD protocol can theoretically guarantee the absolute security of the secret key shared on the quantum channel through its no-cloning theorem, which is a property of quantum mechanics. That is to say, if a third party attempts to eavesdrop on the message information sent on the quantum channel by using a part of the information sent on the quantum channel through a quantum bit error rate (QBER) estimation process, an error rate higher than a predetermined rate may occur. Therefore, this can determine whether there is eavesdropping, and thus can guarantee the security of the sent message. In this way, if the transmitter and the receiver are pre-arranged transmitter and receiver, the sent information can be sent securely without being eavesdropped.

[0162] However, in order to guarantee unconditional security in quantum communication technologies such as QKD, an additional process is required to verify whether the entity that securely sends the pre-supposed information is the entity that is committed to exchanging information. This process is called user authentication. User authentication first verifies whether the sending and receiving entities are the originally expected entities by using the information and algorithms pre-agreed between the transmitter and the receiver, and only performs the action of exchanging information between the transmitter and the receiver when the authentication passes.

[0163] As Figure 11As shown, it shows an example of a man-in-the-middle (MITM) attack that may occur in quantum communication. If a third party Eve 1130 exists between Alice 1110 as the sender and Bob 1120 as the receiver, and attempts a man-in-the-middle attack - where Eve 1130 acts as the receiver of Alice 1110 and the sender of Bob 1120, then the QBER estimation results of the information transmission between Alice 1110 and Eve 1130 and the QBER estimation results of the information transmission between Eve 1130 and Bob 1120 cannot verify whether the third party Eve 1130 has performed a man-in-the-middle attack. That is, the third party Eve 1130 can receive the information sent by Alice 1110 through the quantum channel while sending the information randomly generated by Eve 1130 to Bob 1120. Therefore, the QBER estimation process transmitted through the separate verification sequences between Alice 1110 and Eve 1130 and between Eve 1130 and Bob 1120 cannot determine whether there is an eavesdropper. Through a man-in-the-middle attack, the third party Eve 1130 can know the content of all the data sent when relaying data between Alice 1110 and Bob 1120, and can also attempt to forge / modify the data. Therefore, in order to prevent a man-in-the-middle attack, a user authentication process is required to verify that the sender and receiver, who are the entities exchanging information, are authorized users.

[0164] Existing authentication schemes can be divided into hash function-based authentication schemes and information-theoretic security-based authentication schemes, where the hash function-based authentication schemes include encryption strong elements. In hash function-based authentication schemes, the collision probability of the hash function is used as an authentication technique based on computational complexity, and the SHA scheme is a representative hash function-based technique. However, since hash function-based authentication schemes are based on computational complexity, they may face security threats in the future due to the emergence of quantum computers. In addition, in a quantum cryptographic communication system, an authentication scheme using a keyed hash function family that combines a symmetric key and a hash function based on information-theoretic security is applied and used to enhance security, and quantum communication standard organizations (such as the European Telecommunications Standards Institute (ETSI)) have adopted the use of a keyed hash function family as a standard authentication method. The above method uses a hash function called a strictly universal hash as a message authentication code (MAC) algorithm to generate the message authentication code (MAC) to be used in the authentication process, and additionally uses a symmetric key used as a one-time pad (OTP) during the generation process. Since it is unlikely to recover information from the MAC through a reverse process if the symmetric key information is unknown, it is known to have the highest security level.

[0165] Currently, the MAC series authentication scheme is applied as the standard authentication method for quantum information transmission methods such as QKD. Figure 12 An example of a MAC-based authentication scheme is shown.

[0166] MAC is used to verify the integrity of a message and is an authentication scheme based on the fact that it is difficult for a third party who does not know the one-time symmetric key information pre-shared between the sender 1210 and the receiver 1220 to know which MAC algorithm was used when generating the MAC. First, before performing the authentication process, the sender 1210 and the receiver 1220 share the same symmetric key information 1200 as well as the MAC algorithms 1201 and 1203. Thereafter, when the sender 1210 inputs the plaintext message to be used for authentication into the MAC algorithm 1201, which MAC algorithm to use is selected from the value of the pre-shared key 1200. Next, when the plaintext message 1203 is input into the MAC algorithm 1201 selected by the sender 1210, the MAC 1205 is obtained as its output value, and the sender 1210 sends the plaintext message 1203 and the MAC 1205 generated by the sender 1210 through a classical channel so as to generate a MAC at the receiver 1220. The receiver 1220 inputs the received plaintext message 1204 into the MAC algorithm 1202 of the receiver 1220. In this case, since the receiver 1220 has the same pre-shared key as the sender 1210, the receiver 1220 can use the same MAC algorithm 1202 as the sender 1210 to generate a MAC. Finally, the receiver 1220 compares whether the MAC 1205 sent by the sender 1210 matches the MAC generated by the receiver 1220. If the value of the MAC 1205 sent by the sender 1210 matches the value of the MAC generated by the receiver 1220, the authentication passes / succeeds; if the two do not match, the authentication fails.

[0167] In the case of the authentication method using MAC, the pre-shared symmetric key information is not information sent through a classical channel but is only included in the pre-arranged sender and receiver. Therefore, even if a third party who does not know the pre-shared symmetric key information obtains the message information, it is impossible to know which MAC algorithm was applied from the message information obtained by the third party, thus ensuring security. Therefore, it can be understood that the security of the authentication method using MAC is higher as the number of methods for configuring the MAC algorithm increases.

[0168] In the quantum key distribution (QKD) protocol currently applied as a security technology for 4G LTE / 5G, the WCA scheme proposed by Wegman and Carter is adopted and used as the standard authentication technology. A symmetric key generated in the form of one-time pad and strict universal hash class is used, and a tag for authentication is generated using MAC.Figure 13 An example of an authentication scheme based on Wegman and Carter authentication (WCA) is shown.

[0169] Figure 13 The authentication method can be applied to user authentication for verifying whether the sender and the receiver have been changed during message transmission, and to message authentication for verifying whether the content and order of the message information have been changed. In Figure 13 , the sender 1310 uses the pre-shared key 1300 and the MAC algorithm 1301 to generate the tag information 1305 that serves as the MAC from the message information 1303, and a hash function of the strict universal hash class is used as the MAC algorithm. In this case, the pre-shared key information 1300 plays a role in selecting which hash function to use in H (1301 and 1302) at the sender 1310 and the receiver 1320, and the length of the pre-shared key is assigned as bits, where represents the number of hash functions that construct the set of hash functions. The tag information 1305 is represented as , and the message m of the authentication process is obtained from the result obtained by using the hash function selected from the pre-shared key as the input value. Thereafter, the receiver 1320 compares the tag information 1306 of the receiver 1320 obtained from the pre-shared key 1300 and the hash function 1302 of the receiver 1320 with the tag information 1305 received from the sender 1310 using the message 1303 received by the receiver 1320, and determines whether to perform authentication (1208) after verifying whether the two tag information match.

[0170] As described above, the Wegman and Carter authentication scheme uses a hash function as the MAC algorithm. A hash function is a function that receives information of any length and outputs the information as a hash value of a fixed length. It is also called a message digest because the original length of the sentence is reduced to a certain length.

[0171] The hash function can be used as the MAC in the authentication process based on the following three properties.

[0172] One-way: For a given arbitrary output value y, it is computationally infeasible to find the input value x that satisfies y = h(x).

[0173] Second pre-image resistance: For a given input value x, there is h(x), and when h(x) = h(x'), it is computationally infeasible to find another input value x' that satisfies x = / x'.

[0174] Collision resistance: It is computationally infeasible to find two input values x and x' that satisfy the hash value h(x) = h(x').

[0175] Definition of terms

[0176] For ease of explanation, the following symbols / abbreviations / terms may be used interchangeably in this disclosure.

[0177] -QDC: Quantum Direct Communication

[0178] -QSDC: Quantum Secure Direct Communication

[0179] -QBER: Quantum Bit Error Rate

[0180] -QKD: Quantum Key Distribution

[0181] -MIMA: Man-in-the-Middle Attack

[0182] -MAC: Message Authentication Code

[0183] -WCA: Wegman-Carter Authentication

[0184] -OTP: One-Time Pad

[0185] -ITS: Information-Theoretic Security

[0186] The user authentication method described in the present invention can solve the following problems:

[0187] (1) This disclosure can solve the problem that the existing authentication schemes for quantum communication using classical channels require the ideal assumption that the classical channel and the quantum channel are always connected to the same user.

[0188] More specifically, in quantum communication, the quantum channel is used to transmit secret keys or messages, and the classical channel is used to exchange additional information required for additional post-processing procedures such as error correction. Therefore, although user authentication connected to the quantum channel for transmitting actual information is the most important in terms of security, in existing user authentication technologies, when performing user authentication, information for authentication is exchanged between the transmitter and the receiver over the classical channel. Based on the assumption that the users connected via the quantum channel and the classical channel are always the same, this authentication method can be effective. However, if a third party attempts a man-in-the-middle attack only on the quantum channel, the existence of the man-in-the-middle attack cannot be determined by the existing user authentication method using the classical channel. Therefore, the application of a user authentication scheme using the quantum channel is absolutely necessary.

[0189] (2) The present invention can solve the problem that in existing quantum communication user authentication schemes, since the QBER estimation process and the user authentication process are performed separately, it is necessary to separately generate authentication information for user authentication and information for QBER estimation.

[0190] More specifically, the QBER estimation is a method for ensuring the security of an adversarial attack method, where an eavesdropper intercepts information on a quantum channel connecting a transmitter and a receiver to each other, measures the information, and re-transmits quantum information corresponding to the measurement result to the receiver. On the other hand, the authentication process is a method for ensuring the security of an adversarial attack method, where the eavesdropper exchanges individual information with both the transmitter and the receiver.

[0191] Figure 14 An example of a user authentication process via a classical channel is shown.

[0192] As Figure 14 shown, in existing quantum communication schemes, generally, information for user authentication is first sent over a classical channel to verify whether the transmitting and receiving entities 1410 / 1420 are pre-authorized entities. Thereafter, when the authentication of the communication entities 1410 / 1420 is completed, the communication entities 1410 / 1420 verify whether there is information eavesdropping when sending and receiving information over the quantum channel through QBER estimation information called a QBER check sequence. User authentication (1430) is performed by exchanging authentication messages between the communication entities 1410 / 1420 and based on the error rate between the authentication messages. As described above, in existing quantum communication schemes, after generating additional information required for the above two processes in addition to the transmission message, the user authentication process and the QBER estimation process are performed as separate processes.

[0193] Quantum communication technology is a technology that guarantees unconditional security. To this end, it is important to ensure the security of information transmitted over a quantum channel through quantum mechanical properties, and research and development are mainly carried out on this. User authentication of the transmitting and receiving entities that perform quantum communication is as important as ensuring the security of information transmitted over a quantum channel through quantum mechanical properties. Even if the presence of an eavesdropper is identified and information is securely transmitted through quantum mechanical properties such as the no-cloning theorem, if the transmitting and receiving entities are not pre-authorized users, the security of the transmitted information cannot be guaranteed separately from the security of the quantum channel.

[0194] The present disclosure provides a user authentication scheme for verifying whether the transmitting and receiving entities connected over a quantum channel in quantum communication are pre-authorized users. More specifically, the method described in the present disclosure relates to a method of using a pre-shared key used in the user authentication process to select the position of the transmission information (authentication information) to be used for authentication.

[0195] When the method according to the present invention is applied to user authentication, if a third party without a pre-shared key attempts a man-in-the-middle attack, he / she is treated as if he / she were the transmitter or receiver, and there may be a measurement position mismatch at a certain rate in the measurement of the third party. The method described in the present disclosure utilizes the fact that the error rate caused by the measurement position mismatch must be greater than the error rate caused by environmental factors. Further, in the method described in the present disclosure, since the user authentication process and the QBER estimation process are performed based on the error rate, these two processes can be performed simultaneously.

[0196] For the purpose of user authentication in quantum communication, a method of selecting, within the overall generated authentication message, the positions actually used for authentication using a pre-shared key / pre-shared symmetric key is first described.

[0197] An authentication method using a pre-shared symmetric key for user position selection

[0198] The user authentication method described in the present disclosure is a method of estimating the error rate by comparing the measured values at the selected positions, thereby using a pre-captured key to select the positions to be used for authentication and verifying whether the sending and receiving entities are authorized entities. That is, according to the user authentication method proposed in the present disclosure, a pre-shared key is used to select the positions of the information (information bits) actually used for authentication among all the authentication messages generated by the sending end, and the sending and receiving ends can estimate the error rate by comparing only the measured values of the information positions selected by the pre-shared key in all the authentication messages, thereby verifying whether the sending and receiving entities are authorized entities.

[0199] Figure 15 An example of a user authentication process applying the method of selecting the positions of authentication information using the pre-shared symmetric key described in the present disclosure is shown.

[0200] More specifically, Figure 15 An example of a user authentication process via a quantum channel between an authorized transmitter (Alice) 1510 and a receiver (Bob) 1520 is shown. Referring to Figure 15 , since the authorized users 1510 and 1520 have the same pre-shared keys 1531 and 1532, the authorized users 1510 and 1520 can determine which positions among the authentication message information sent over the quantum channel are to be selected and measured based on the values of the pre-shared keys. As described above, since each user can equivalently select the positions of the message information used for authentication based on the values of the pre-shared keys, no error occurs during the authentication process except for the influence of environmental noise such as channel errors.

[0201] Figure 16 An example of a user authentication process applying the method described in the present disclosure to the authentication process when there is an eavesdropper in the receiver is shown.

[0202] More specifically, Figure 16 A user authentication process is shown in which a man-in-the-middle attack is performed via a quantum channel between an authorized transmitter (Alice) 1610 and Eve 1620 instead of an authorized user. Since Eve 1620, who performs the man-in-the-middle attack, does not have a pre-shared key, Eve 1620 has no choice but to randomly select a position for authentication among the positions of the authentication messages sent by the transmitter (Alice) 1610. In this case, if the information about the position to be used for authentication does not match between the transmitter and the receiver (1610 / 1620), a mismatch (error) occurs at a specific k-th position among the information to be used for authentication between the transmitter and the receiver with a probability of 50%. That is, when the information corresponding to a specific k-th position among all authentication information has a value of classical information '0' or '1', and a third party who does not know the position of the information to be used for authentication processes the information with a value of classical information '0' or '1' measured at a random position (j-th position) within the authentication message as the information corresponding to the specific k-th position, the probability that the information corresponding to the specific k-th position matches the information measured at the j-th position is 50%. Therefore, if the information about the position to be used for authentication does not match between the transmitter and the receiver (1610 / 1620), a mismatch (error) will occur at a specific k-th position among the information to be used for authentication between the transmitter and the receiver with a probability of 50%. As described above, the method described in the present disclosure determines whether authentication passes or fails based on an error rate, which is based on the probability (50%) of an error occurring when a receiver who does not know the authentication position information measures the authentication message, which is much higher than the error rate caused by environmental errors (the maximum acceptable error rate limit considering error correction is 11%) occurring during authentication.

[0203] The detailed process of using a pre-shared key to select the position of an authentication message in the user authentication process is as follows.

[0204] (1) Alice (transmitter) and Bob (receiver) share a pre-shared key for user authentication before the start of the quantum communication process. In this case, the length of the pre-shared key is determined based on a security strength standard, and a method for setting the length of the pre-shared key based on the security strength standard is described in the following content related to security analysis.

[0205] (2) Alice (the transmitter) sends sequence information to Bob (the receiver) via a quantum channel. The sequence information includes (i) an authentication message, (ii) the message to be sent (information message), and (iii) information for QBER estimation. In this case, the position of the authentication message can be fixed position information pre-agreed between the transmitter (Alice) and the receiver (Bob). The position of the authentication message does not refer to the position of the actual information used for authentication within the authentication message selected using a pre-shared key, but rather to the position of the authentication message within the sequence information, which includes (i) the authentication message, (ii) the message to be sent (information message), and (iii) information for QBER estimation.

[0206] (3) Bob (the receiver) selects the authentication message from the received sequence information based on the pre-agreed position in (2).

[0207] (4) Alice / Bob (the transmitter / receiver) each uses a pre-shared key 1710 of the same length as the authentication message to select which position within the authentication message 1720 is used for user authentication, as Figure 17 shown. Figure 17 Illustrates an example of generating an authentication code from a pre-shared symmetric key during the user authentication process of applying the method described in the present disclosure.

[0208] In this case, since the pre-shared key is truly random information, the pre-shared key is binary string information, where half of the information is 1 and the other half is 0. Therefore, the value of the authentication message corresponding to the position of 1 in the pre-shared key is output as the code information (1730) for authentication. Although Figure 17 not shown, Bob (the receiver) sends the authentication code generated by Bob (the receiver) to Alice (the transmitter) via a classical channel, and Alice (the transmitter) estimates the error rate by comparing the authentication code generated by Alice (the transmitter) with the authentication code received from Bob (the receiver).

[0209] Refer to Figure 18 for the error rate estimation process description. Figure 18 Illustrates an example of error rate estimation between authentication codes during the user authentication process in quantum communication.

[0210] Refer to Figure 18, the transmitter 1810 and the receiver 1820 generate an authentication code based on the authentication message and the pre-shared key (1.). Next, the transmitter 1810 and the receiver 1820 perform a basic information exchange process via a classical channel (2.). Through the basic information exchange process, only the part that uses the same basis to generate / measure the authentication message / authentication code at a specific information position can be retained among all the authentication messages / authentication codes respectively generated by the transmitter 1810 and the receiver 1820, and the information part using other bases can be removed (3.). Through the basic information exchange process, the part of the authentication message / authentication code with a mismatched basis is removed to generate the final authentication code for authentication. The receiver 1820 sends the generated final authentication code to the transmitter 1810 via the classical channel, and then the error rate is estimated by comparing the final authentication codes of the transmitter 1810 and the receiver 1820 (4.). In this case, if the transmitter 1810 and the receiver 1820 are pre-authorized users, the two users will have selected the authentication message using the same pre-shared key. Therefore, errors greater than or equal to the environmental error rate, such as channel errors, will not occur, and user authentication is successful. On the other hand, if one of the transmitter and the receiver is not an authorized user due to a man-in-the-middle attack, the man-in-the-middle attacker does not have the pre-shared key. Therefore, if the authentication message selection positions are different, an average error of 50% cannot be avoided, and user authentication fails. If the error rate of the authentication information is determined to be less than or equal to the QBER threshold (the maximum allowable rate of errors occurring in the environment), the authentication passes, and then the quantum communication process continues. On the other hand, if the authentication error rate exceeds the QBER threshold, the authentication fails, the quantum communication process is interrupted, and the quantum channel is reconfigured.

[0211] Figure 19 is a flowchart showing an example of executing the user authentication method described in the present disclosure.

[0212] First, a pre-shared symmetric key is shared between the transmitter 1910 and the receiver 1920 (S19010). Thereafter, the transmitter 1910 generates quantum state information and sends the quantum state information to the receiver 1920 via the quantum channel, and the receiver 1920 receives the quantum state information (S19020 and S19030). The quantum state information can be sequence information including (i) an authentication message, (ii) a message to be sent (information message), and (iii) information for QBER estimation. In the quantum state information, the authentication message can be included at a pre-agreed position between the transmitter 1910 and the receiver 1920. Next, the transmitter 1910 and the receiver 1920 select the authentication message from the quantum state information based on the pre-agreed position (S19040), and generate an authentication code using the pre-shared key (S19050).

[0213] Next, the transmitter 1910 and the receiver 1920 perform a basic information exchange process (S19060) via a classical channel. Through the basic information exchange process, only the parts of the authentication messages / authentication codes that use the same basis to generate / measure at specific information positions can be retained in all the authentication messages / authentication codes generated by the transmitter 1910 and the receiver 1920 respectively, and the information parts using other bases can be removed (S19060). The information removal process can be referred to as screening. Next, the receiver 1920 removes the parts of the authentication messages / authentication codes with mismatched bases through the basic information exchange process to generate the final authentication code to be used for authentication, and sends the final authentication code to the transmitter 1910 via the classical channel (S19070). After the receiver 1920 sends the final authentication code to the transmitter 1910 via the classical channel, the transmitter 1910 estimates the error rate by comparing the final authentication code received from the receiver 1920 with the final authentication code generated by the transmitter 1910 (S19080). The error rate estimation process is performed based on whether the QBER threshold is greater than the error rate obtained by comparing the authentication codes (S19090). In this case, if the transmitter 1910 and the receiver 1920 are pre-authorized users, the two users will have selected the authentication messages using the same pre-shared key. Therefore, errors greater than or equal to the environmental error rate, such as channel errors, do not occur, and user authentication is successful (S19103). On the other hand, if one of the transmitter and the receiver is not an authorized user due to a man-in-the-middle attack, the man-in-the-middle attacker does not have the pre-shared key. Therefore, if the authentication message selection positions are different, an average error of 50% cannot be avoided, and user authentication fails (S19101). Although not shown in Figure 19 , if the error rate of the authentication information is determined to be less than or equal to the QBER threshold (the maximum allowable rate of errors occurring in the environment), the authentication passes, and then the quantum communication process continues. On the other hand, if the authentication error rate exceeds the QBER threshold, the authentication fails, the quantum communication process is interrupted, and the quantum channel is reconfigured.

[0214] A method for simultaneously performing the user authentication process and the QBER estimation process is described below.

[0215] Method for simultaneously performing user authentication and QBER estimation process in a user authentication scheme using a pre-shared symmetric key for position selection

[0216] The user authentication process and the QBER estimation process are two of the most important factors required to ensure the security of communication entities and quantum channels from a pre-authorized third party (Eve) in quantum secure communication. In existing quantum communication protocols such as QKD and QSDC, the success or failure of the user authentication process is determined based on whether the authentication codes of the transmitter and receiver match, and the success or failure of the QBER estimation process is determined based on whether the error rate of the QBER check sequence exceeds the QBER threshold. Therefore, the user authentication process and the QBER estimation process are not performed at once, but are performed as separate processes using individual information.

[0217] In the user authentication method described in the present application, different from the existing authentication methods, authentication is determined to pass or fail according to the error rate of the authentication information. Therefore, the user authentication process applying the method described in the present disclosure can be included / incorporated as part of the QBER estimation process for determining whether there is eavesdropping on the quantum channel based on the error rate of the QBER check sequence.

[0218] Two methods for simultaneously performing the user authentication process and the QBER estimation process proposed in the present disclosure are described below.

[0219] Method for simultaneously performing QBER estimation and user authentication while only using a pre-shared key for user authentication Method.

[0220] Figure 20 An example of information for authentication and QBER estimation in the method described in the present disclosure is shown.

[0221] Reference Figure 20 , quantum communication protocols including existing authentication methods use a method of separately generating message information (2020) for user authentication and checking sequence information (2010) for QBER estimation. On the other hand, in the method of user authentication described in the present disclosure that only uses a pre-shared key, the message information (2121) for authentication can be included in the check sequence (2130) for QBER estimation. Therefore, the user authentication process can be first performed using some information (2030) of the QBER check sequence, and in this case, when determining the error rate in QBER estimation, the part that estimates the error rate in the authentication process can be used again. Thereafter, the error rate estimation is performed only using the QBER check sequence that is not used for authentication during QBER estimation. According to this method, compared with the existing method of performing user authentication and QBER estimation using individual information, the processing speed can be improved.

[0222] The method of simultaneously performing QBER estimation and user authentication while only using the pre-shared key for user authentication described in the present invention includes the following processes:

[0223] (1) Alice (transmitter) and Bob (receiver) pre-share a pre-shared key for user authentication before the start of the quantum communication process.

[0224] (2) Alice (transmitter) sends the Figure 21 sequence information shown via a quantum channel to Bob (receiver). Figure 21 shows the process of selecting the information to be used for authentication and QBER estimation among the quantum state string information sent over the quantum channel described in the present disclosure.

[0225] Among the information to be used for QBER estimation, the information having the same length as the pre-shared key is the authentication message information (2121) for authentication, and thus is selected from the fixed positions pre-agreed at the transmitter and receiver ends in the transmission sequence, and the remaining information for QBER estimation is randomly selected from the authentication message information (2121) among all the sequence information.

[0226] (3) The user authentication process is the same as the Figure 19 user authentication method that applies the method of using the pre-shared key to select the position of the authentication message as shown, and thus the detailed description is omitted.

[0227] (4) Next, if the user authentication fails, the quantum channel is reconfigured and the process starts again from the beginning. On the contrary, if the user authentication passes, the QBER estimation process is immediately executed.

[0228] (5) During the QBER estimation process, a process is executed in which the transmitter randomly extracts approximately 10% of the information initially sent via the quantum channel from a random position to generate the information for QBER estimation, and the receiver sends to the transmitter (i) the measurement position of the position where the measurement of the information sent via the quantum channel is initially performed, (ii) the basis information used in the measurement, and (iii) the measurement value, so that the transmitter can estimate the occurrence rate of errors in the extracted QBER check sequence, and a process of estimating the error rate by comparing the QBER check sequence generated by the transmitter with the measurement value of the information received from the receiver, and the above process determines whether there is an eavesdropper on the quantum channel.

[0229] In the method described in the present disclosure, the error rate is estimated by the position of the part to be used for authentication among the QBER check sequences pre-agreed between the transmitter and the receiver ( Figure 21Among them (2121), and the QBER check sequence is selected / extracted from the remaining part of the pre-agreed part for authentication excluded from all quantum state information sent over the quantum channel through random position selection. During the QBER estimation process of applying the method described in the present disclosure, among all the quantum state information sent over the quantum channel, the error rate is estimated by adding (i) the number of error occurrences in the part for user authentication and (ii) the number of error occurrences in the QBER sequence extracted from the part never used for user authentication. If the error rate does not exceed the QBER threshold, it can be guaranteed that there is no eavesdropper on the quantum channel, and thus the subsequent process can be continued. Otherwise, due to the existence of an eavesdropper, the quantum communication process is interrupted and the quantum channel is reconfigured.

[0230] Figure 22 The overall flowchart of the authentication scheme and QBER estimation process showing the position selection for authentication information using the pre-shared key described in the present disclosure.

[0231] Refer to Figure 22 , first, a pre-shared symmetric key (S22010) is shared between the transmitter 2210 and the receiver 2220. Thereafter, the transmitter 2210 generates quantum state information and sends the quantum state information to the receiver 2220 over the quantum channel, and the receiver 2220 receives the quantum state information (S22020 and S22030). The quantum state information may be sequence information including (i) an authentication message, (ii) a message to be sent (information message), and (iii) information for QBER estimation. In the quantum state information, the authentication message may be included at a pre-agreed position between the transmitter 2210 and the receiver 2220. Next, the transmitter 2210 and the receiver 2220 select the authentication message from the quantum state information based on the pre-agreed position (S22040), and generate an authentication code using the pre-shared key (S22050).

[0232] Next, the transmitter 2210 and the receiver 2220 perform a basic information exchange process (S22060) via a classical channel. Through the basic information exchange process, only the portions of the authentication messages / authentication codes that use the same basis for generation / measurement at specific information positions can be retained in all the authentication messages / authentication codes respectively generated by the transmitter 2210 and the receiver 2220, and the information portions that use other bases can be removed (S22060). The information removal process can be referred to as screening. Next, the receiver 2220 removes the portions of the authentication messages / authentication codes with mismatched bases through the basic information exchange process to generate the final authentication code to be used for authentication, and sends the final authentication code to the transmitter 2210 via the classical channel (S22070). After the receiver 2220 sends the final authentication code to the transmitter 2210 via the classical channel, the transmitter 2210 estimates the error rate by comparing the final authentication code received from the receiver 2220 with the final authentication code generated by the transmitter 2210 (S22080). The error rate estimation process is performed based on whether the QBER threshold is greater than the error rate obtained by comparing the authentication codes (S22090). In this case, if the transmitter 2210 and the receiver 2220 are pre-authorized users, the two users will have selected the authentication messages using the same pre-shared key. Therefore, errors greater than or equal to the environmental error rate, such as channel errors, do not occur, and user authentication is successful (S22103). On the other hand, if one of the transmitter and the receiver is not an authorized user due to a man-in-the-middle attack, the man-in-the-middle attacker does not have the pre-shared key. Therefore, if the authentication message selection positions are different, an average error of 50% cannot be avoided, and user authentication fails (S22101). Although not shown in Figure 22 , if the error rate of the authentication information is determined to be less than or equal to the QBER threshold (the maximum allowable rate of errors occurring in the environment), the authentication passes, and then the quantum communication process continues. On the other hand, if the authentication error rate exceeds the QBER threshold, the authentication fails, the quantum communication process is interrupted, and the quantum channel is reconfigured. If the authentication is successful (S22103), the QBER estimation process is performed.

[0233] The transmitter 2210 and the receiver 2220 generate a QBER check sequence by randomly selecting information in a part that does not include the message for authentication from the initially transmitted quantum state information. Thereafter, the receiver 2220 sends the measurement positions and basis information for measurement to the transmitter 2210 and performs a sifting process (S22100 / 22110). Thereafter, the receiver 2220 stores the measurement values and sends the measurement values over the classical channel (S22130). Thereafter, the transmitter 2210 estimates the error rate by comparing the measurement values received from the receiver 2220 with the QBER check sequence information randomly extracted by the transmitter 2210 using the measurement values received from the receiver 2220, the measurement position information, and the basis information for measurement (S22140). In this case, in step S22150 of comparing the error rate with the QBER threshold, the error rate is estimated by adding (i) the number of error occurrences in the part for user authentication and (ii) the number of error occurrences in the QBER sequence extracted from the part never used for user authentication among all the quantum state information sent over the quantum channel, and the error rate is compared with the QBER threshold. If the error rate does not exceed the QBER threshold, it can be ensured that there is no eavesdropper on the quantum channel, so the subsequent process is continued (S22161). Otherwise, since there is an eavesdropper, the quantum communication process is interrupted and the quantum channel is reconfigured (S22163).

[0234] Method for extending a pre-shared key to simultaneously apply it to user authentication and QBER estimation

[0235] This method proposes a method in which the above-mentioned pre-shared key is used not only for user authentication but also for QBER estimation. To establish this method, the length of the pre-shared key must be long enough to select the position of the QBER check sequence from all the information sent over the quantum channel. However, since the pre-shared key is information for user authentication, the length of the pre-shared key is very short compared to the length of all the quantum state information sent over the quantum channel. Therefore, this method proposes a method in which the pre-shared key is extended according to the length of the quantum state information, and then the extended pre-shared key is used to select the position of the QBER check sequence from all the quantum state information. In this case, first, a part of the selected QBER check sequence is used to perform user authentication. If the authentication is passed, the error estimation result of the part of the QBER check sequence for authentication and the result after estimating the error rate of the part not used for authentication are added to perform the QBER estimation process. Therefore, authentication and QBER estimation are performed simultaneously. That is, the error rate obtained from the part of the overall message for user authentication is also reused in the QBER estimation process.

[0236] The user authentication process in this method can be performed in the following order:

[0237] (1) Alice (transmitter) and Bob (receiver) pre-share the presentation key P_1 before quantum communication.

[0238] (2) Alice (transmitter) sends sequence information including the message to be sent to Bob (receiver) and QBER estimation information to Bob (receiver) through a quantum channel.

[0239] (3) Bob (receiver) selects a part (usually about 10%) of the overall received sequence and uses it for QBER estimation and authentication processes. In this method, the positions of the information to be used for QBER estimation are selected using the pre-shared key, and then all the selected parts of the information to be used for QBER estimation are first used for authentication. After that, if the authentication passes, both the information used for authentication and the information not used for authentication among all the information used for QBER estimation are used for the QBER estimation process. On the contrary, if the user authentication fails, the subsequent processes including QBER estimation and post-processing are not performed, and the initial process for quantum communication is restarted.

[0240] (Method for Selecting the Positions of the Sequences for QBER Estimation and User Authentication)

[0241] This method relates to a method for selecting the positions of the sequences for QBER estimation and user authentication, in which the pre-shared key is used not only for the user authentication process but also for the QBER estimation process. The transmitter and receiver divide the overall quantum information sequence including (i) message information and (ii) QBER check information shared through the quantum channel into k blocks based on the length of the pre-shared key, as Figure 23 shown. Figure 23 An example of the method for configuring quantum data blocks described in this disclosure is shown.

[0242] In this case, the length of each of the k divided blocks is the same as the length of the pre-shared key, and the length of the pre-shared key that determines the length of each block is determined by the security strength standard applied as a standard in authentication technology. The higher the security strength, the longer the pre-shared key used. The method for setting the length of the pre-shared key based on the security strength standard is described in detail in the security analysis described below.

[0243] The method for setting the length of the first quantum state information block in the overall quantum information sequence divided into k blocks and the method for selecting the positions of the information for QBER estimation and user authentication are described below.

[0244] In the first quantum state information block (data block) B_1, the transmitter and receiver select the positions of the information to be used for QBER estimation and authentication based on the pre-shared key P_1 they have. Next, refer to Figure 24, in the quantum state information block B_1, select the values corresponding to the positions with value 1 in the pre-trained key P_1 as the information for QBER estimation and authentication (S2410 / S2420). Generally speaking, since the pre-shared key is random information, all information includes half of the information 1 and the other half of the information 0. Therefore, when selecting the positions with the value "1" of the pre-shared key as the QBER estimation information, half of the values of the quantum state information block B_1 are selected. However, since only about 10% of all quantum state information is appropriately used in QBER estimation, the length of the preselected position information should be reduced to 1 / 5. Therefore, when listing in order the positions with 1 in the pre-shared key pre-shared between the transmitter and the receiver, only the positions corresponding to multiples of 5 are selected as the position information for QBER estimation. For example, if the value of the pre-shared key is '1110100100', only the fifth bit string '1' and the tenth bit string '0' are used to select the information to be used for QBER estimation.

[0245] Since the length of the pre-shared key P_1 is much shorter than the length of the overall data sequence, it is impossible to select the positions of the information in the overall data sequence to be used for QBER estimation and authentication only using the information of the pre-shared key. Therefore, the length of the pre-shared key should be extended to be the same as the length of the data sequence. To extend the length of the pre-shared key to be the same as the length of the data sequence, several methods as Figure 25 illustrated can be used. Figure 25 shows an example of executing the authentication method described in the present disclosure.

[0246] First, a method of repeating the same pre-shared key until the length of the data sequence and the length of the pre-shared key are the same can be applied (S2510). Second, whenever the pre-shared key is repeated, the bit values constituting the previous pre-shared key can be shifted right or left (S2520). Finally, when generating the k-th data block, the pre-shared key corresponding to the k-th block can be generated by performing a modulo 2 summation operation on the immediately preceding (k - 1)-th data block (B_k-1) and the immediately preceding pre-shared key (P_k-1).

[0247] The transmitter and the receiver select the same method among the above methods. By doing so, the transmitter and the receiver select a sequence corresponding to about 10% of the overall data sequence as the QBER sequence, and the selected QBER sequence can be selected by the same pre-shared key and pre-shared key extension method.

[0248] (User authentication method)

[0249] This method relates to a user authentication method performed based on a method that uses not only a pre-shared key but also a QBER estimation process in the user authentication process.

[0250] Reference Figure 26 , which shows an example of performing user authentication. By pre-shared key extension, a part of the QBER check sequence selected from all quantum state information sequences (2611 / 2613) is used as the information for user authentication (1.). The position of the QBER check sequence for authentication can be a part of the information at the front of the QBER check sequence, as shown in Figure 26 . However, the information for authentication in the QBER check sequence can be at a position other than the front of the QBER check sequence and does not need to be fixed to a specific position.

[0251] Next, the transmitter and the receiver exchange the basis information (2.) for measuring the quantum state information for authentication through a classical channel, and then only select the positions where the bases match between the transmitter and the receiver to determine whether the authentication passes or fails, and remove the authentication information where the bases do not match (3.). The transmitter and the receiver exchange the values of the authentication messages at the positions where the bases match each other through the classical channel to estimate the error rate (4.). If the transmitter and the receiver are authorized users, the two users select the authentication messages using the same pre-shared key, and thus no error greater than or equal to the environmental error rate, such as a channel error, occurs. On the other hand, if one of the transmitter and the receiver is not an authorized user due to a man-in-the-middle attack, the man-in-the-middle attacker does not have the pre-shared key. Therefore, if the positions for selecting the authentication messages are different, an error of 50% on average cannot be avoided. If the error rate of the authentication information is determined to be less than or equal to the QBER threshold (the maximum allowable rate of errors occurring in the environment), the authentication passes and, in the next step, the QBER estimation process is performed. On the other hand, if the authentication error rate exceeds the QBER threshold, the authentication fails and the quantum communication process is interrupted.

[0252] The process of applying the pre-shared key to position selection and performing user authentication has been described above. This method uses partial QBER estimation information for user authentication and determines whether user authentication passes based on the error rate and the QBER threshold, rather than whether the authentication codes exactly match. Therefore, the result of user authentication can be reused in the QBER estimation process.

[0253] (QBER Estimation Process)

[0254] This method relates to a QBER estimation method, which is performed based on a method of using a pre-shared key not only in the user authentication process but also in the QBER estimation process.

[0255] During the QBER estimation process of this method, the QBER estimation process is performed, including the error rate estimation results used in user authentication. Therefore, the error rate estimation process in the user authentication process can be considered as part of the QBER estimation process. The detailed QBER estimation process is as follows.

[0256] (1) Since some QBER check sequences used for QBER estimation have already been used in the user authentication process, the error occurrence results obtained from the information used in the authentication process are also used in the QBER estimation process.

[0257] (2) Refer to Figure 27 , in order to estimate the error rate of a part of the QBER check sequences not used in user authentication, the transmitter and the receiver exchange the basic information for measuring quantum state information.

[0258] (3) In this case, a part of the QBER check sequences using bases that are not the same between the transmitter and the receiver is removed.

[0259] (4) Only a part of the QBER check sequences using the same base is used for QBER estimation, and the error rate is estimated by comparing the values of the transmitter and the receiver in a part used for QBER estimation.

[0260] (5) Among all the QBER check sequences, the number of QBER check sequences that match between the transmitter and the receiver is used as the denominator for calculating the error rate in QBER estimation, and the sum of the number of authentication information determined to be incorrect in the user authentication process and the number of QBER check sequences with errors among the remaining QBER check sequences is used as the numerator, thereby performing QBER estimation.

[0261] (6) If it is determined that the error rate obtained through QBER estimation does not exceed the QBER threshold, it is ensured that there is no eavesdropper on the quantum channel. Therefore, the transmitter and the receiver perform the quantum communication post-processing process. In the opposite case, the transmitter and the receiver stop the quantum communication.

[0262] Application of a user authentication method based on a pre-shared key in a quantum communication protocol

[0263] Examples of applying the user authentication scheme to various quantum communication protocols are described below. This user authentication scheme uses a pre-shared key to determine the location of the information to be used for user authentication. More specifically, examples of applying the method described in the present disclosure to QKD and QSDC, which are representative quantum communication protocols, are described.

[0264] First, an example of adding the user authentication process proposed in the present disclosure to the secret key sharing process of the QKD protocol, which is a scheme for sharing quantum secret keys, will be described. Next, an example of adding the user authentication process proposed in the present disclosure to the QSDC protocol, which is a scheme for securely transmitting messages directly through a quantum channel, will be described.

[0265] A quantum key distribution (QKD) system including a user authentication method based on a pre-shared key

[0266] Figure 28 An example of applying the user authentication method described in the present disclosure to the QKD method is shown.

[0267] First, the QKD transmitter 2810 generates information for QBER verification and secret key information for ensuring the security of data transmitted on the classical channel, and transmits them through the quantum channel (S28010 / S28020). The receiver 2820 measures the information transmitted on the quantum channel using a random basis (S28030).

[0268] Next, the QKD transmitter 2810 and the receiver 2820 perform a user authentication process to verify whether they are pre-authorized users. The location selection method based on a pre-shared key described in the present application can be applied to this process. In this process, before the user authentication process in Figure 28 (S28040) starts, the pre-shared key is pre-shared and updated.

[0269] Next, the QKD transmitter 2810 and the receiver 2820 select an authentication message from the sub-state information based on a pre-agreed location (S28050), and generate an authentication code using the pre-shared key (S28060).

[0270] Next, the transmitter 2810 and the receiver 2820 perform a basic information exchange process via a classical channel. Through the basic information exchange process, only the parts of the authentication messages / authentication codes that use the same basis for generation / measurement at specific information positions can be retained in all the authentication messages / authentication codes respectively generated by the transmitter 2810 and the receiver 2820, and the information parts using other bases can be removed (S28070). The information removal process may be referred to as screening. Next, the receiver 2820 removes the parts of the authentication messages / authentication codes with mismatched bases through the basic information exchange process to generate the final authentication code to be used for authentication, and sends the final authentication code to the transmitter 2810 via the classical channel (S28080). After the receiver 2820 sends the final authentication code to the transmitter 2810 via the classical channel, the transmitter 2810 estimates the error rate by comparing the final authentication code received from the receiver 2820 with the final authentication code generated by the transmitter 2810 (S28090). The error rate estimation process is performed based on whether the QBER threshold is greater than the error rate obtained by comparing the authentication codes (S28100). In this case, if the transmitter 2810 and the receiver 2820 are pre-authorized users, the two users will have selected the authentication messages using the same pre-shared key. Therefore, errors greater than or equal to the environmental error rate, such as channel errors, do not occur, and user authentication is successful (S28111). On the other hand, if one of the transmitter and the receiver is not an authorized user due to a man-in-the-middle attack, the man-in-the-middle attacker does not have the pre-shared key. Therefore, if the authentication message selection positions are different, an average error of 50% cannot be avoided, and user authentication fails (S28113). If the error rate of the authentication information is determined to be less than or equal to the QBER threshold (the maximum allowable rate of errors occurring in the environment), the authentication passes, and then the quantum communication process continues. On the other hand, if the authentication error rate exceeds the QBER threshold, the authentication fails, the quantum communication process is interrupted, and the quantum channel is reconfigured (S28115). If the authentication is successful (S28103), the QBER estimation process is performed.

[0271] Next, the transmitter 2810 and the receiver 2820 generate a QBER check sequence (S28120) by randomly selecting information in the part other than the message for authentication from the initially transmitted quantum state information or using an extended pre-shared key. Thereafter, the receiver 2820 sends the measurement position and basis information for measurement to the transmitter 2810 and performs a sifting process (S28130). Thereafter, the receiver 2820 stores the measured values and sends the measured values over the classical channel (S28140). Thereafter, the transmitter 2810 estimates the error rate by comparing the measured values received from the receiver 2820 with the QBER check sequence information randomly extracted by the transmitter 2810 using the measured values received from the receiver 2820, the measurement position information, and the basis information for measurement (S28150). In this case, in step S28160 of comparing the error rate with the QBER threshold, the error rate is estimated by adding (i) the number of error occurrences in the part for user authentication and (ii) the number of error occurrences in the QBER sequence extracted from the part never used for user authentication among all the quantum state information sent over the quantum channel, and the error rate is compared with the QBER threshold. If the error rate does not exceed the QBER threshold, it can be ensured that there is no eavesdropper on the quantum channel, so the subsequent process is continued (S28171). Otherwise, since there is an eavesdropper, the quantum communication process is interrupted and the quantum channel is reconfigured (S28173 / S28175).

[0272] If both the user authentication process and the QBER estimation process are successful, a post-processing process of the secret symmetric key for data encryption between the transmitter 2810 and the receiver 2820 is performed. The post-processing process is performed, including QBER estimation, error reconciliation, and privacy amplification processes (S28180 / S28190), so that a secret symmetric key with guaranteed security can be obtained.

[0273] The biggest difference between the method described in the present invention and the existing methods is that there is a QBER estimation process in the post-processing process. In the user authentication of the existing QKD technology, the authentication information is generated separately, and then the user authentication is performed. The QBER estimation information, called the QBER check sequence, is generated separately, and then the error rate is estimated. On the other hand, in the method described in the present invention, the QBER check sequence is reused in the user authentication and QBER estimation processes, and the authentication process and the QBER estimation process are performed simultaneously, which is different from the existing QKD methods.

[0274] Return again Figure 28, whenever secret key information is sent over a quantum channel, a user authentication process is performed to verify the existence of a man-in-the-middle attack, and thus the pre-shared key to be used in the authentication process is updated. To this end, a part of the secret symmetric key generated through a post-processing process is separated and used as an update value for the pre-shared key to be used in the next authentication process (S28180). Thereafter, the remaining secret key is used as the secret key for encrypting / decrypting the data to be sent over the classical channel (S28210).

[0275] Quantum secure direct communication (QSDC) system including a user authentication method based on a pre-shared key

[0276] Figure 29 Shows an example of applying the user authentication method described in this disclosure to the DL04 QSDC quantum communication protocol for securely sending classical information over a quantum channel based on single photons.

[0277] Referring to Figure 29 , in the DL04 QSDC protocol, a user authentication method for applying the pre-shared key described in this disclosure to the selection of the position of authentication information and a method for simultaneously performing QBER estimation and user authentication can be added.

[0278] The DL04 QSDC protocol is a single-photon-based QSDC technology. In the process of generating and measuring the initial information in the DL04 QSDC protocol, the receiver 2920 encodes the random information that does not include message information into an initial quantum state and sends it to the transmitter 2910 over the quantum channel (S29010 / S29020). The transmitter 2910 measures the initial quantum state information received from the receiver 2920, and most of the measured initial information is stored in the quantum memory (S29030). In this case, the remaining initial information is used for QBER estimation and is randomly measured, and the result is stored (S29040).

[0279] Next, in the user authentication process, the transmitter 2910 and the receiver 2920 perform a user authentication process to verify whether they are pre-authorized users. In this process, the pre-shared key should be pre-shared and updated before the start of the user authentication process in Figure 29 (S29050).

[0280] Next, the transmitter 2910 and the receiver 2920 select the positions of the check sequences using the pre-shared key from the quantum state information based on a pre-agreed position, and select the authentication messages to be used for user authentication of the check sequences using the pre-shared key (S29070).

[0281] Next, the transmitter 2910 and the receiver 2920 perform a basic information exchange process via a classical channel. Through the basic information exchange process, only the parts of the authentication messages / authentication codes that use the same basis for generation / measurement at specific information positions can be retained in all the authentication messages / authentication codes generated by the transmitter 2910 and the receiver 2920 respectively, and the information parts using other bases can be removed (S29080). The information removal process can be referred to as screening. Next, the transmitter 2910 removes the parts of the authentication messages / authentication codes with mismatched bases through the basic information exchange process to generate the final authentication code to be used for authentication, and sends the final authentication code to the receiver 2920 via the classical channel (S29090). After the transmitter 2910 sends the final authentication code to the receiver 2920 via the classical channel, the receiver 2920 estimates the error rate by comparing the final authentication code received from the transmitter 2910 with the final authentication code generated by the receiver 2920 (S29100). The error rate estimation process is performed based on whether the QBER threshold is greater than the error rate obtained by comparing the authentication codes (S29100). In this case, if the transmitter 2910 and the receiver 2920 are pre-authorized users, the two users will have selected the authentication messages using the same pre-shared key. Therefore, errors greater than or equal to the environmental error rate, such as channel errors, do not occur, and user authentication is successful (S29111). On the other hand, if one of the transmitter and the receiver is not an authorized user due to a man-in-the-middle attack, the man-in-the-middle attacker does not have the pre-shared key. Therefore, if the authentication message selection positions are different, an average error of 50% cannot be avoided, and user authentication fails (S29113).

[0282] If authentication is successful (S29111), the QBER estimation process is performed. The transmitter 2910 and the receiver 2920 generate a QBER check sequence by randomly selecting information in the parts other than the messages used for authentication from the initially transmitted quantum state information or using an extended pre-shared key (S29120 / S29130). In this case, if the QBER check sequence is generated using the random selection method, the transmitter 2910 sends the positions of the QBER sequence selected to the receiver 2920.

[0283] Next, the transmitter 2910 and the receiver 2920 exchange basic information for measurement and perform a screening process (S29140). Next, the transmitter 2910 encrypts the measurement value using the value of the pre-shared key and sends it to the receiver 2920 over the classical channel (S29150). The receiver 2920 decrypts the encrypted measurement value using the pre-shared key value. Thereafter, the receiver 2920 compares the check sequence values between the transmitter and the receiver to estimate the error rate (S29170), and determines whether there is an eavesdropper by comparing the QBER threshold and the error rate (S29180). In this case, in step S29180 of comparing the error rate with the QBER threshold, the error rate is estimated by adding (i) the number of error occurrences in the part for user authentication and (ii) the number of error occurrences in the QBER sequence extracted from the part that has never been used for user authentication among all the quantum state information sent over the quantum channel, and the error rate is compared with the QBER threshold. If the error rate does not exceed the QBER threshold, it can be ensured that there is no eavesdropper on the quantum channel, so the subsequent process is continued (S29191). Otherwise, since there is an eavesdropper, the quantum communication process is interrupted and the quantum channel is reconfigured (S29193 / S29195).

[0284] If both user authentication and QBER estimation pass, the QBER check sequence is replaced with the pre-shared key to be used in the next user authentication (S19211). Thereafter, the transmitter 2910 encodes the message information into an initial quantum state and sends it to the receiver 2920 (S29220), and the receiver 2920 measures the received information, stores the result, and performs a message recovery process (S29230 / S29240). On the contrary, if user authentication or QBER estimation fails, the communication line can be changed from the existing communication line to another communication line (S29213). When the communication line changes, the pre-shared key used in the next user authentication cannot be replaced with the QBER check sequence. Therefore, the pre-stored backup pre-shared key is used as the new pre-shared key for the next user authentication. Thereafter, the ongoing process is stopped, and the process is executed again from the beginning (S29217).

[0285] In addition, a method of simultaneously using a shared key for position selection of information and basis selection.

[0286] The present disclosure mainly describes a method of using a pre-shared key to select the position of an authentication message code during the user authentication process. However, since the core of user authentication is to prevent users without the pre-shared key from knowing how the authorized sending and receiving entities use the pre-shared key for user authentication, the pre-shared key should not be used only for position selection. Therefore, the pre-shared key can be used by the authorized sending and receiving entities for the basis selection of the authentication message for user authentication. That is, the basis used by the transmitter that sends the authentication message when generating the authentication code and the basis used by the receiver when using the authentication message can be configured to be the same using the pre-shared key. Therefore, when generating the authentication code from the authentication message, the pre-shared key can be sequentially applied to the position selection and basis selection processes. In this way, when the pre-shared key is applied to both the position selection and basis selection processes, the problem in the existing user authentication technology that half of the authentication messages are not used due to the random selection of the basis can be solved. At the same time, since there is no need to share the position and basis information related to the authentication message sent on the classical channel, the throughput of the authentication process can be increased, the processing rate of the authentication process can be increased, and the amount of information leaked on the classical channel can be minimized.

[0287] Figure 30 Illustrate an example of a user authentication process in which a pre-shared symmetric key is used for both position selection and basis selection.

[0288] In Figure 30 Since the pre-shared key is not information exposed to the classical channel, the pre-shared key can be reused in the case of sending a single block of information. First, use the pre-shared key to select the position information to be used as the authentication code among the quantum state authentication messages, and select the quantum state authentication message where the pre-shared key has a value of 0 or 1 as the authentication code, and in this process, halve the original authentication message (S3010). Next, different from the existing quantum communication in which the basis selection for measuring the quantum information for authentication is randomly performed, in the Figure 30 method, half of the pre-shared key used for the above position selection is used for basis selection, and if the value of the pre-shared key is 0, the cross basis is selected, and if it is 1, the diagonal basis is selected, and the measurement of the quantum state information for authentication is performed (S3020). In this case, the pre-shared key can be used in the same direction as in the position selection, or can be applied in the opposite direction. Next, compare the measured authentication codes between the transmitter and the receiver to estimate the error rate, and determine whether the authentication is passed or failed based on the result (S3030). For user authentication using this method, it has the advantages of both using the pre-shared key for position selection and using the pre-shared key for basis selection.

[0289] Effect

[0290] The effects of a location-based user authentication scheme using a pre-shared key proposed in the present disclosure in terms of stability are described below.

[0291] The length of the pre-shared key that can meet the security strength level of the symmetric key currently presented as a standard by NIST can be determined based on the method described in the present disclosure and can be set based on the minimum length of the pre-shared key for which the probability of successful attack may be lower than the security strength. This indicates that the user authentication scheme in the present disclosure can protect against man-in-the-middle attacks with high security based on this value. Considering the noise and other situations that occur in the actual communication environment, an error rate of up to 11% is an acceptable error rate in quantum communication, then the success probability P of the man-in-the-middle attack S can be expressed as shown in Equation 1 below.

[0292] [Equation 1]

[0293]

[0294] In the above equation, the probability of no error occurring can be expressed as the sum of the probability of the case where the measurement positions do not match but the measured values of the transmitter and the receiver are the same and the probability of the case where the measurement positions match. On the other hand, when the measurement positions do not match and the measured values of the transmitter and the receiver are different, the probability of an error occurring .

[0295] The standard number of bits of security strength determined by NIST is classified as 112 or less, 128, 192, and 256. In the case of 256 bits, it represents the maximum security strength known to be able to ensure security until 2030 based on the current level of quantum computers and quantum algorithms. And the fact that the standard number of bits of security strength is 256 bits means that it will take repeated calculations to find the weaknesses of the encryption technology and perform a successful attack.

[0296] Figures 31 to 33 Shows the minimum length of the pre-shared symmetric key required to ensure security for each security strength.

[0297] Figure 31 Shows the minimum length of the pre-shared key that can ensure security at about the 112-bit level, which is the lowest standard security strength, Figure 32 shows the minimum length of the 128-bit pre-shared key, which is the most widely used standard security strength, and Figure 33 shows the length of the pre-shared key that meets 256 bits, which is the highest standard security strength among the current standard technologies. As can be seen from Figures 31 to 33It can be seen that as the security strength increases, the success rate of man-in-the-middle attacks can be reduced to a pre-shared key length lower than the security strength level in each security strength criterion booster, and it can be seen that when using 482 bits or more of security strength bits, the current strongest security strength level can be met according to the technology of the present disclosure.

[0298] Figure 34 FIG. is a flowchart showing an example of a user authentication method described in the present disclosure executed by a sending end.

[0299] First, in S3410, the sending end and the receiving end perform a random access process for establishing a connection related to a classical channel, which is related to a quantum channel for user authentication.

[0300] The random access process includes steps of sending a random access preamble to the receiving end, receiving a random access response from the receiving end, sending a connection request message to the receiving end based on the random access response, and receiving a contention resolution message from the receiving end.

[0301] Next, in S3420, the sending end sends an information sequence including at least one data block to the receiving end on the quantum channel.

[0302] Based on (i) a pre-shared key between the sending end and the receiving end and (ii) at least one key generated based on the pre-shared key, a check sequence for determining a quantum bit error rate (QBER) estimate for determining whether there is eavesdropping on the quantum channel is determined from each of the at least one data block. The pre-shared key is used to select the position of the sequence to be used for user authentication among the sequences included in a specific data block related to user authentication among the at least one data block.

[0303] Next, in S3430, the sending end performs user authentication with the receiving end based on a part of the check sequence determined from each of the at least one data block.

[0304] Finally, in S3440, the sending end performs QBER estimation with the receiving end based on (i) the result of user authentication and (ii) the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block.

[0305] Here, (i) a user authentication error rate calculated based on a part of the check sequence for user authentication and determined from each of the at least one data block, and (ii) a QBER estimation error rate calculated based on the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block are used for QBER estimation.

[0306] The transmitting end includes a transmitter for transmitting radio signals, a receiver for receiving radio signals, at least one processor, and at least one computer memory. The at least one computer memory is operatively connected to the at least one processor and stores instructions that, when executed by the at least one processor, perform operations. The operations include referring to Figure 34 the steps described.

[0307] Referring to Figure 34 the operations described can be stored in a non-transitory computer-readable medium (CRM) that stores one or more instructions. The non-transitory computer-readable medium stores one or more instructions executable by one or more processors, and the one or more instructions allow the transmitting end to perform the operations referred to Figure 34 the description.

[0308] In a device including one or more memories and one or more processors operatively connected to the one or more memories, the one or more processors control the device to perform the operations referred to Figure 34 the description.

[0309] Figure 35 is a flowchart showing an example of a user authentication method performed by a receiving end described in the present disclosure.

[0310] First, in S3510, the receiving end and the transmitting end perform a random access procedure for establishing a connection related to a classical channel, which is related to a quantum channel for user authentication.

[0311] The random access procedure includes steps of receiving a random access preamble from the transmitting end, sending a random access response to the transmitting end, receiving a connection request message from the transmitting end based on the random access response, and sending a contention resolution message to the transmitting end.

[0312] Next, in S3520, the receiving end receives an information sequence including at least one data block from the transmitting end over the quantum channel.

[0313] Based on (i) a pre-shared key between the transmitting end and the receiving end and (ii) at least one key generated based on the pre-shared key, a check sequence for determining a quantum bit error rate (QBER) estimate for determining whether there is eavesdropping on the quantum channel is determined from each of the at least one data block. The pre-shared key is used to select the position of the sequence to be used for user authentication among the sequences included in a specific data block related to user authentication among the at least one data block.

[0314] Next, in S3530, the receiving end performs user authentication with the transmitting end based on a part of the check sequence determined from each of the at least one data block.

[0315] Finally, in S3540, the receiving end performs QBER estimation with the transmitting end based on (i) the result of user authentication and (ii) the remaining check sequence excluding the portions of the check sequences determined from each of the at least one data block.

[0316] Here, (i) the user authentication error rate calculated based on the portion of the check sequence used for user authentication and determined from each of the at least one data block, and (ii) the QBER estimation error rate calculated based on the remaining check sequence excluding the portions of the check sequences determined from each of the at least one data block are used for QBER estimation.

[0317] The receiving end includes a transmitter that transmits radio signals, a receiver that receives radio signals, at least one processor, and at least one computer memory that is operably connected to the at least one processor and stores instructions that, when executed by the at least one processor, perform operations. The operations include referring to Figure 35 the steps described.

[0318] Referring to Figure 35 the operations described can be stored in a non-transitory computer-readable medium (CRM) that stores one or more instructions. The non-transitory computer-readable medium stores one or more instructions executable by one or more processors, and the one or more instructions allow the receiving end to perform the operations referring to Figure 35 the steps described.

[0319] In a device including one or more memories and one or more processors operably connected to the one or more memories, the one or more processors control the device to perform the operations referring to Figure 35 the steps described.

[0320] The embodiments of the present disclosure described above are combinations of elements and features of the present disclosure. Unless otherwise specified, an element or feature can be considered optional. Each element or feature can be practiced without being combined with other elements or features. In addition, embodiments of the present disclosure can be constructed by combining parts of elements and / or features. The order of operations described in the embodiments of the present disclosure can be rearranged. Some configurations of any one embodiment can be included in another embodiment and can be replaced by corresponding configurations of another embodiment. It will be apparent to those skilled in the art that claims that are not explicitly referenced to each other in the appended claims can be presented combinatorially as embodiments of the present disclosure, or can be included as new claims through subsequent modifications after the application is filed.

[0321] Embodiments of the present disclosure can be implemented by various means, for example, hardware, firmware, software, or a combination thereof. In terms of hardware configuration, the method according to an embodiment of the present disclosure can be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, etc.

[0322] In terms of firmware or software configuration, embodiments of the present disclosure can be implemented in the form of modules, procedures, functions, etc. For example, software code can be stored in a memory unit and executed by a processor. The memory can be located inside or outside the processor, and can send data to and receive data from the processor via various known means.

[0323] Those skilled in the art will appreciate that the present disclosure can be implemented in other specific ways different from those described herein without departing from the spirit and basic characteristics of the present disclosure. Therefore, the above embodiments are to be construed as illustrative in all aspects and not restrictive. The scope of the present disclosure should be determined by the appended claims and their legal equivalents, rather than by the above description, and all changes falling within the meaning and equivalent scope of the appended claims should be included therein.

[0324]

Industrial Applicability

[0325] The present disclosure has been described focusing on examples applied to 3GPP LTE / LTE-A and 5G systems, but can be applied to various wireless communication systems in addition to 3GPP LTE / LTE and 5G systems.

Claims

1. A method for a sender to perform user authentication in a quantum communication system, the method comprising: Performing a random access process with a receiver, the random access process being used to establish a connection related to a classical channel, the classical channel being related to a quantum channel for the user authentication; Wherein, the random access process includes: Sending a random access preamble to the receiver; Receiving a random access response from the receiver; Based on the random access response, sending a connection request message to the receiver; and Receiving a contention resolution message from the receiver; Sending an information sequence including at least one data block to the receiver on the quantum channel; Wherein, based on (i) a pre-shared key between the sender and the receiver, and (ii) at least one key generated based on the pre-shared key, a test sequence for quantum bit error rate (QBER) estimation is determined from each of the at least one data block, and the test sequence is used to determine whether there is eavesdropping on the quantum channel; Wherein, the pre-shared key is used to select the position of the sequence for the user authentication from among the sequences included in a specific data block related to the user authentication among the at least one data block; Performing the user authentication with the receiver based on the part of the check sequence determined from each of the at least one data block; and Performing the QBER estimation with the receiver based on (i) the result of the user authentication, and (ii) the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block; Wherein, (i) the user authentication error rate calculated based on the part of the check sequence for the user authentication and determined from each of the at least one data block, and (ii) the QBER estimation error rate calculated based on the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block, are used for the QBER estimation; 2. The method according to claim 1, wherein, Performing the user authentication includes: sending a message for the user authentication generated based on the part of the check sequence determined from each of the at least one data block to the receiver; 3. The method according to claim 2, wherein, Performing the user authentication further includes: Sending information used as the basis for generating the message for the user authentication to the receiver; and Receiving measurement basis information from the receiver, the measurement basis information being used by the receiver to measure the basis of the message for the user authentication sent; 4. The method according to claim 3, wherein, Performing the user authentication further includes: Based on the measurement basis information, determining user authentication information, the user authentication information being related to the matching part between the basis used by the sender to generate the message for the user authentication from the generated message for the user authentication and the basis used by the receiver to measure the message for the user authentication sent by the sender; Receive a user authentication measurement value among measurement values of a message for user authentication for an overall transmission to the receiving end, the user authentication measurement value being related to a matching portion between a basis for generating a message for user authentication at the sending end and a basis for the receiving end to measure the message for user authentication sent by the sending end. Wherein, success or failure of the user authentication is determined based on a user authentication error rate, the user authentication error rate being calculated based on a difference between (i) a value of the user authentication information and (ii) the user authentication measurement value.

5. The method according to claim 1, wherein Performing the QBER estimation includes: sending to the receiving end the remaining check sequence excluding a portion of the check sequence determined from each of the at least one data block.

6. The method according to claim 5, wherein, Performing the QBER estimation further includes: Sending to the receiving end information for a basis for generating the remaining check sequence; Receiving from the receiving end measurement basis information for a basis for the receiving end to measure the sent remaining check sequence.

7. The method according to claim 6, wherein, Performing the QBER estimation further includes: Based on the measurement basis information, determining check sequence information related to a matching portion between a basis for generating a remaining check sequence from the generated remaining check sequence at the sending end and a basis for the receiving end to measure the remaining check sequence sent by the sending end; Receiving from the receiving end a check sequence measurement value among measurement values of the remaining check sequence overall sent by the receiving end, the check sequence measurement value being related to a matching portion between a basis for generating the remaining check sequence at the sending end and a basis for the receiving end to measure the remaining check sequence sent by the sending end.

8. The method according to claim 1, wherein Constructing at least one key generated based on the pre-shared key by repeatedly concatenating the pre-shared key until a sum of (i) a length of the pre-shared key and (ii) a length of the at least one key generated based on the pre-shared key is equal to a length of an information sequence including the at least one data block.

9. The method according to claim 1, wherein Constructing at least one key generated based on the pre-shared key by repeatedly concatenating the pre-shared key until a sum of (i) a length of the pre-shared key and (ii) a length of the at least one key generated based on the pre-shared key is equal to a length of an information sequence including the at least one data block, and wherein, whenever the pre-shared key is repeatedly concatenated, the repeatedly concatenated pre-shared key is shifted left or right.

10. The method according to claim 1, wherein, Each of the pre-shared key and the at least one key generated based on the pre-shared key corresponds one-to-one to the at least one data block.

11. A sending end for performing user authentication in a quantum communication system, the sending end including: A transmitter that transmits radio signals; A receiver that receives the radio signals; At least one processor; And At least one computer memory, the at least one computer memory being operatively connected to the at least one processor and storing instructions, the instructions performing operations when executed by the at least one processor, wherein the operations include: Performing a random access procedure with a receiving end, the random access procedure being for establishing a connection related to a classical channel, the classical channel being related to a quantum channel for the user authentication, wherein the random access procedure includes: Sending a random access preamble to the receiving end; Receiving a random access response from the receiving end; Based on the random access response, sending a connection request message to the receiving end; Receiving a contention resolution message from the receiving end; Sending an information sequence including at least one data block to the receiving end on the quantum channel; wherein, based on (i) a pre-shared key between the sending end and the receiving end, and (ii) at least one key generated based on the pre-shared key, a check sequence for quantum bit error rate (QBER) estimation is determined from each of the at least one data block, the check sequence being for determining whether there is eavesdropping on the quantum channel, wherein the pre-shared key is used to select the position of the sequence for the user authentication among the sequences included in a specific data block related to the user authentication among the at least one data block; Performing the user authentication with the receiving end based on the part of the check sequence determined from each of the at least one data block; and Performing the QBER estimation with the receiving end based on (i) the result of the user authentication, and (ii) the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block, wherein (i) a user authentication error rate calculated based on the part of the check sequence for the user authentication and determined from each of the at least one data block, and (ii) a QBER estimation error rate calculated based on the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block, are used for the QBER estimation.

12. A method for performing user authentication by a receiving end in a quantum communication system, the method including: Performing a random access procedure with a sending end, the random access procedure being for establishing a connection related to a classical channel, the classical channel being related to a quantum channel for the user authentication, wherein the random access procedure includes: Receiving a random access preamble from the sending end; Sending a random access response to the sending end; Based on the random access response, receiving a connection request message from the sending end; and Sending a contention resolution message to the sending end; Receiving an information sequence including at least one data block from the sending end on the quantum channel, Among them, based on (i) a pre-shared key between the sending end and the receiving end, and (ii) at least one key generated based on the pre-shared key, a test sequence for quantum bit error rate (QBER) estimation is determined from each of the at least one data block, and the test sequence is used to determine whether there is eavesdropping on the quantum channel. Among them, the pre-shared key is used to select the position of the sequence for user authentication among the sequences included in a specific data block related to user authentication among the at least one data block. Perform user authentication with the sending end based on the part of the check sequence determined from each of the at least one data block. Perform the QBER estimation with the receiving end based on (i) the result of the user authentication and (ii) the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block. Among them, (i) the user authentication error rate calculated based on the part of the check sequence for user authentication and determined from each of the at least one data block, and (ii) the QBER estimation error rate calculated based on the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block are used for the QBER estimation.

13. A receiving end for performing user authentication in a quantum communication system, the receiving end includes: A transmitter that transmits radio signals. A receiver that receives the radio signals. At least one processor. And At least one computer memory that is operably connected to the at least one processor and stores instructions, and the instructions perform operations based on being executed by the at least one processor. Among them, the operations include: Perform a random access process with the sending end, and the random access process is used to establish a connection related to a classical channel, and the classical channel is related to the quantum channel for user authentication. Among them, the random access process includes: Receive a random access preamble from the sending end. Send a random access response to the sending end. Receive a connection request message from the sending end based on the random access response. And Send a contention resolution message to the sending end. Receive an information sequence including at least one data block from the sending end on the quantum channel. Among them, based on (i) a pre-shared key between the sending end and the receiving end, and (ii) at least one key generated based on the pre-shared key, a test sequence for quantum bit error rate (QBER) estimation is determined from each of the at least one data block, and the test sequence is used to determine whether there is eavesdropping on the quantum channel. Among them, the pre-shared key is used to select the position of the sequence for user authentication among the sequences included in a specific data block related to user authentication among the at least one data block. Perform user authentication with the receiving end based on the portions of the check sequences determined from each of the at least one data block; and Perform QBER estimation with the receiving end based on (i) the result of the user authentication and (ii) the remaining check sequence excluding the portions of the check sequences determined from each of the at least one data block, wherein (i) the user authentication error rate calculated based on the portions of the check sequences for the user authentication and determined from each of the at least one data block, and (ii) the QBER estimation error rate calculated based on the remaining check sequence excluding the portions of the check sequences determined from each of the at least one data block are used for the QBER estimation.

14. A non-transitory computer-readable medium (CRM) storing one or more instructions, Among them, The one or more instructions executable by one or more processors allow a sending end to: Perform a random access procedure with a receiving end, the random access procedure being for establishing a connection associated with a classical channel, the classical channel being associated with a quantum channel for user authentication, wherein the random access procedure includes: Sending a random access preamble to the receiving end; Receiving a random access response from the receiving end; Based on the random access response, sending a connection request message to the receiving end; and Receiving a contention resolution message from the receiving end; Sending an information sequence including at least one data block to the receiving end over the quantum channel; wherein, based on (i) a pre-shared key between the sending end and the receiving end and (ii) at least one key generated based on the pre-shared key, a check sequence for quantum bit error rate (QBER) estimation is determined from each of the at least one data block, the check sequence being for determining whether there is eavesdropping on the quantum channel, wherein the pre-shared key is used to select the position of the sequence for the user authentication among the sequences included in a specific data block related to the user authentication among the at least one data block; Perform user authentication with the receiving end based on the portions of the check sequences determined from each of the at least one data block; and Perform QBER estimation with the receiving end based on (i) the result of the user authentication and (ii) the remaining check sequence excluding the portions of the check sequences determined from each of the at least one data block, wherein (i) the user authentication error rate calculated based on the portions of the check sequences for the user authentication and determined from each of the at least one data block, and (ii) the QBER estimation error rate calculated based on the remaining check sequence excluding the portions of the check sequences determined from each of the at least one data block are used for the QBER estimation.

15. A device including one or more memories and one or more processors operatively connected to the one or more memories, Among them, The one or more processors enable the device to: Perform a random access procedure with a receiving end, the random access procedure being for establishing a connection associated with a classical channel, the classical channel being associated with a quantum channel for user authentication, wherein the random access procedure includes: Sending a random access preamble to the receiving end; Receiving a random access response from the receiving end; Based on the random access response, sending a connection request message to the receiving end; and Receiving a contention resolution message from the receiving end; Sending an information sequence including at least one data block to the receiving end over the quantum channel; wherein, based on (i) a pre-shared key between the sending end and the receiving end, and (ii) at least one key generated based on the pre-shared key, a test sequence for quantum bit error rate (QBER) estimation is determined from each of the at least one data block, the test sequence being for determining whether there is eavesdropping on the quantum channel, wherein the pre-shared key is used to select the position of the sequence for user authentication among the sequences included in a specific data block related to the user authentication among the at least one data block; Performing the user authentication with the receiving end based on the part of the check sequence determined from each of the at least one data block; and Performing the QBER estimation with the receiving end based on (i) the result of the user authentication, and (ii) the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block, wherein (i) the user authentication error rate calculated based on the part of the check sequence for the user authentication and determined from each of the at least one data block, and (ii) the QBER estimation error rate calculated based on the remaining check sequence excluding the part of the check sequence determined from each of the at least one data block, are used for the QBER estimation.