Fully anonymous quantum conference key negotiation method
Through the entanglement characteristics and cluster state conversion of generalized GHZ states, anonymous quantum key negotiation is realized, which solves the problem of insufficient anonymity and security in quantum conference key negotiation, generates secure conference keys, enhances system compatibility and resists side channel attack capabilities.
Patent Information
- Application Number
- CN202510699993.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-07-18
AI Technical Summary
Existing quantum conference key negotiation technology is difficult to balance anonymity and security, especially in quantum computing environments, anonymous communications are insufficient in security, and lack of system compatibility and resistance to side channel attacks.
The entanglement characteristic of generalized GHZ state is used to realize anonymous quantum key negotiation, lock the initiator node through collision detection, anonymously notify the participant node, and the entanglement characteristic of clustered state is used to construct a generalized GHZ state, combining error correction and privacy amplification to generate a security conference key to ensure that identity information is not leaked.
The entire process anonymous quantum key negotiation is realized to protect the security of participants' identity information, enhance the security and correctness of the key, avoid problems caused by the initial system preparation of multiple entangled states, and improve system compatibility and resistance to side channel attacks.
Smart Images

Figure CN120342606A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of quantum communication, and in particular to a fully anonymous quantum conference key negotiation method. Background Art
[0002] In terms of multi-party quantum key negotiation, a good balance has been achieved between practicality and security, but the compatibility problem between quantum and classical systems needs to be solved. The anonymity requirement brings additional technical challenges to quantum conference key negotiation; in traditional cryptography, anonymous communication usually relies on relay networks and coin-flipping techniques, but these methods may no longer be secure in the quantum computing environment. The research on quantum anonymous communication mainly focuses on three directions at present: quantum hybrid networks draw on the classical coin-flipping idea and use the characteristics of quantum states to achieve more efficient anonymous routing; quantum signature authentication allows participants to prove their legitimacy without revealing their identities; the distributed QKD architecture combines blockchain technology to ensure the decentralization and immutability of the negotiation process. These technologies have their own advantages and disadvantages, and need to be selected and optimized according to specific application scenarios.
[0003] From the perspective of implementation, the anonymous quantum conference key negotiation system needs to solve several key technical problems; at the physical layer, it is necessary to develop high-performance quantum light sources and detectors to improve the coding rate and transmission distance of the system; at the network layer, it is necessary to design efficient quantum relay and routing algorithms to support multi-user concurrent access; at the protocol layer, it is necessary to develop new quantum authentication and key management mechanisms to ensure forward security and backward security; in addition, the actual deployment of the system also needs to consider the compatibility with existing communication infrastructure and the ability to resist various side-channel attacks. Summary of the Invention
[0004] Object of the Invention: In order to overcome the deficiencies in the prior art, the present invention provides a fully anonymous quantum conference key negotiation method, which realizes anonymous quantum key negotiation according to the entanglement characteristics of the generalized GHZ state, and uses its conversion relationship with the cluster state to realize the whole-process anonymous negotiation of keys in combination with the entanglement characteristics of the cluster state.
[0005] Technical Solution: To achieve the above object, a fully anonymous quantum conference key negotiation method of the present invention includes the following steps:
[0006] Step1. Determine whether there is a unique node in the shared node network as the initiator node of key negotiation through collision detection, and lock the initiator node of key negotiation;
[0007] Step2. The initiator node of key negotiation anonymously notifies other nodes to make the corresponding nodes become the participant nodes of key negotiation;
[0008] Step 3. Perform corresponding operations on the particles held by the participant nodes according to the parity of the number of key negotiation participant nodes, and construct a generalized GHZ state among multiple nodes;
[0009] Step 4. All non-participant nodes in the key negotiation measure the particles they hold and perform corresponding operations according to the measurement results to construct a generalized GHZ state among the participant nodes;
[0010] Step 5. Repeat the operations of Step 3 and Step 4 several times to obtain generalized GHZ states among several participant nodes;
[0011] Step 6. Divide the generalized GHZ states among several participant nodes into two groups of generalized GHZ states, and the participant nodes respectively perform eavesdropping detection operations and key generation operations on the generalized GHZ states to generate a secure conference key K shared by multiple parties.
[0012] Further, the shared node network includes n nodes, and each node is denoted as N j (j = 1, 2,..., n); when p nodes out of n nodes participate in the key negotiation, the initiator node participating in the key negotiation is set as P1, and each node participating in the key negotiation is denoted as P i (i = 1, 2,..., p); the n nodes share a multi-particle cluster state, and the multi-particle cluster state is shown in the following formula:
[0013]
[0014] In the formula, the value of m is related to the number of nodes n in the node network; when n is an odd number greater than or equal to 3, m = (n + 1) / 2, and the node N j holds the 1st and 2m-th particles, while all other nodes hold the particles with corresponding serial numbers; when n is an even number greater than 3, m = n / 2 + 1, and the node N j holds three particles, namely the 1st, (2m - 1)-th, and 2m-th particles, while all other nodes hold the particles with corresponding serial numbers.
[0015] Further, in the said Step 1, the collision detection for judging whether there is a unique node in the shared node network as the initiator node of the key negotiation includes the following steps:
[0016] Step 1-1. Judge whether the node N j wants to become the initiator node of the key negotiation through the information sent by the node N j . If so, perform the X operation on the particles with the corresponding serial numbers of the node N j , otherwise perform the I operation on the particles with the corresponding serial numbers of the node N j ;
[0017] Step1-2. All nodes in the shared node network measure the particles they hold using the Z basis to obtain the bit results q of all nodes, and submit the bit results q of all nodes to the central node through an anonymous channel;
[0018] Step1-3. The central node verifies the bit results q of all nodes. When there is a unique d satisfying after several verifications, no collision is detected and there is a unique initiator node P1; otherwise, the key negotiation is aborted.
[0019] Further, in Step2, after there is a unique initiator node P1, the initiator node P1 anonymously notifies other nodes to become participant nodes, including the following steps:
[0020] Step2-1. Each node N j has a bit sequence According to the identity of node N j and the identity relationship between node N j and node N a to determine the distribution of R j Each node N j sends the bit sequence to the corresponding node N b ;
[0021] Step2-2. When node N j is the initiator node P1 and at the same time N a is a participant node in the key negotiation, then When node N j is the initiator node P1 and at the same time N a is a non-participant node in the key negotiation, then When node N j is not the initiator node P1, then the identity of N a cannot be determined, then
[0022] Step2-3. Each node N b receives from other nodes and forms a new sequence R b , and calculates and sends it to the corresponding node N a ;
[0023] Step2-4. Each node N a calculates When t a = 1, then N a is notified that it is a participant in the key negotiation.
[0024] Further, in the said Step3, corresponding operations are performed on the particles of all nodes according to the parity of the number of key negotiation participant nodes; when the number p of key negotiation participant nodes is odd; one node N among all nodes j holds the 1st particle and the 2m-th particle, and other nodes hold the particles with corresponding serial numbers; node N j performs a CNOT operation on the particles it holds, node N j measures the 2m-th particle and announces the measurement result; when the measurement result is |0>, then node N j performs a Z operation on the 1st particle; when the measurement result is |1>, then node N j performs an X operation on the particles with serial numbers (m + 1) and those after it;
[0025] when the number p of key negotiation participant nodes is even; one node N among all nodes j holds the 1st particle, the (2m - 1)-th particle and the 2m-th particle, and other nodes hold the particles with corresponding serial numbers; node N j performs a CNOT operation on the 1st particle and the 2m-th particle it holds, node N j measures the 2m-th particle and announces the measurement result; when the measurement result is |0>, then node N j performs a Z operation on the 1st particle; when the measurement result is |1>, then node N j performs an X operation on the particles with serial numbers (m + 1) and those after it.
[0026] Further, in the said Step4, all key negotiation participant nodes know each other's identities, while other non - participant nodes in key negotiation cannot know the identities of key negotiation participant nodes; all non - participant nodes in key negotiation measure the particles they hold using the X - basis and announce the measurement results, and key negotiation participant nodes randomly announce a bit value;
[0027] When the number of measurement values of (|0> - |1>) in the measurement results announced by non - participant nodes in key negotiation is even, the key negotiation is aborted; when the number of measurement values of (|0> - |1>) in the measurement results announced by non - participant nodes in key negotiation is odd, the key negotiation initiator node P1 performs a Z operation on the particles it holds to construct a generalized GHZ state among key negotiation participant nodes.
[0028] Further, in the said Step6, the generalized GHZ state among several participant nodes is divided into two groups of generalized GHZ states, and participant nodes respectively perform eavesdropping detection operations and key generation operations on the generalized GHZ states;
[0029] When the generalized GHZ state is used for eavesdropping detection, all participant nodes in the key negotiation measure the particles they hold using the X - basis, and announce their respective measurement results; according to the measurement results of all participant nodes in the key negotiation, calculate the error rate of each participant node for error estimation. When the error rate of any one participant node exceeds the set error threshold, the key negotiation is aborted; when the error rate of no participant node exceeds the set error threshold, the key negotiation continues.
[0030] Furthermore, when the generalized GHZ state is used for key generation, it includes the following steps:
[0031] Step3 - 1: All participant nodes in the key negotiation measure the particles they hold using the Z - basis. At this time, an initial key K1 is generated among the participant nodes;
[0032] Step3 - 2: The initiator node P1 of the key negotiation generates error - correction data for the initial key K1 based on a public error - correcting code, encrypts the error - correction data using the one - time pad OTP in the pre - shared key to obtain an error - correction ciphertext, and broadcasts the error - correction ciphertext. All the other nodes each generate a random bit sequence of the same length as the confusion parameter;
[0033] Step3 - 3: After all participant nodes in the key negotiation receive the error - correction ciphertext, they decrypt the error - correction ciphertext using the one - time pad OTP of the pre - shared key, and the participant nodes then correct their respective keys according to the decrypted error - correction code;
[0034] Step3 - 4: All participant nodes in the key negotiation calculate the hash value of their respective corrected keys;
[0035] Step3 - 5: The initiator node P1 of the key negotiation encrypts the hash value calculated from its key using the one - time pad OTP to obtain a hash - value ciphertext, and broadcasts the hash - value ciphertext. The non - participant nodes in the other key negotiations submit random hash - value confusion information;
[0036] Step3 - 6: Other participant nodes in the key negotiation receive the hash - value ciphertext, decrypt it using the one - time pad OTP to obtain the hash value of the initiator node P1. Other participant nodes in the key negotiation compare their respective hash values with the hash value of the initiator node P1. When the comparison results are inconsistent, the key negotiation is aborted; when the comparison results are consistent, the key negotiation continues;
[0037] Step3 - 7: Use a specific hash function to perform privacy compression on the key to generate a multi - party shared secure conference key K.
[0038] Beneficial effects: A fully anonymous quantum conference key negotiation method of the present invention effectively protects the identity information of participants from being leaked during the entire negotiation process; uses anonymous collision detection to protect the identity information security of participants while ensuring a single initiator; uses error correction and privacy amplification to ensure the correctness and complexity of the key, making the key not easily cracked, and increasing the security of the key to a certain extent; realizes the conversion of two different entangled states, avoiding various problems caused by the need to prepare two entangled states simultaneously in the initial system. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 It is a flowchart of a fully anonymous quantum conference key negotiation method;
[0040] Figure 2 It is a state diagram of constructing GHZ state particles by multiple parties' nodes. DETAILED DESCRIPTION OF THE INVENTION
[0041] The present invention will be further described below with reference to the accompanying drawings.
[0042] As Figure 1 shown, a fully anonymous quantum conference key negotiation method includes the following steps:
[0043] Step1. Determine whether there is a unique node in the shared node network as the initiator node for key negotiation through collision detection, and lock the unique initiator node for key negotiation;
[0044] Step2. The initiator node for key negotiation anonymously notifies other nodes to make the corresponding nodes become the participant nodes for key negotiation;
[0045] Step3. Perform corresponding operations on the particles held by the participant nodes according to the parity of the number of participant nodes for key negotiation, convert a multi-particle cluster state shared by all nodes into a generalized GHZ state, construct a generalized GHZ state among multiple parties' nodes to obtain a generalized GHZ state among multiple parties' nodes, and the generalized GHZ state among multiple parties' nodes is for anonymously generating a generalized GHZ state among participant nodes by using the entanglement characteristics of the GHZ state in the subsequent process;
[0046] Step4. Based on the generalized GHZ state among multiple parties' nodes, all non-participant nodes for key negotiation measure the particles they hold and perform corresponding operations according to the measurement results, construct a generalized GHZ state among participant nodes to obtain a generalized GHZ state among participant nodes, and the generalized GHZ state among participant nodes is for generating a key through key negotiation in the subsequent process;
[0047] Step5. Repeat the operations of Step3 and Step4 several times to obtain several generalized GHZ states among participant nodes;
[0048] Step 6. Divide the generalized GHZ states among several participant nodes into two groups of generalized GHZ states, specifically, divide the generalized GHZ states among several participant nodes into two groups of generalized GHZ states for eavesdropping detection and key generation; and the participant nodes respectively perform eavesdropping detection operations and key generation operations on the generalized GHZ states to generate a secure conference key K shared by multiple parties.
[0049] The generalized GHZ state is an extended form of the standard GHZ state. On the basis of maintaining the multi-particle entanglement property, it allows the coefficients of the state to have more general values; the GHZ state, the Greenberger-Horne-Zeilinger state, is a typical multi-particle quantum entanglement state, and the GHZ state describes a highly entangled state among three or more qubits. The difference between the generalized GHZ states among participant nodes and the generalized GHZ states among multiple nodes lies in the different number of particles they contain. The number of particles in the generalized GHZ states among participant nodes is usually less than the number of particles in the generalized GHZ states among multiple nodes.
[0050] The shared node network includes n nodes, and each node is denoted as N j (j = 1, 2,..., n); when p nodes out of n nodes participate in the key negotiation, the initiator node participating in the key negotiation is set as P1, and each node participating in the key negotiation is denoted as P i (i = 1, 2,..., p); the n nodes share a multi-particle cluster state, and the multi-particle cluster state is as follows:
[0051]
[0052] In the formula, the value of m is related to the number of nodes n in the node network; when n is an odd number greater than or equal to 3, m = (n + 1) / 2, and the node N j holds the 1st and 2m-th particles, while all other nodes hold the particles with corresponding serial numbers; when n is an even number greater than 3, m = n / 2 + 1, and the node N j holds three particles, namely the 1st, (2m - 1)-th, and 2m-th particles, while all other nodes hold the particles with corresponding serial numbers. The values of k1 and k2 are respectively 0 or 1. Since the adopted particle state is a two-dimensional particle state, there are only two states, 0 and 1; represents the convolution symbol, and here and respectively represent m k1's or k2's in parallel; for example, when m is 2, the multi-particle cluster state is as follows:
[0053]
[0054] In Step1, when multiple nodes in the shared node network simultaneously wish to become initiators, unnecessary conflicts will occur. Therefore, collision detection is used to determine whether there is a unique node in the shared node network as the initiator node for key negotiation, including the following steps:
[0055] Step1-1: Each node determines whether to become an initiator. By the information sent by node N j judge whether node N j wants to become the key negotiation initiator node. If so, perform the X operation on the corresponding serial number particles of node N j ; otherwise, perform the I operation on the corresponding serial number particles of node N j . Node N j is any one of the n nodes included in the shared node network;
[0056] Step1-2: All nodes in the shared node network measure the particles they hold using the Z basis to obtain the bit results q of all nodes, where q = (0, 1). Submit the bit results q of all nodes to a trusted central node through an anonymous channel; the anonymous channel is a mixed network or a broadcast channel;
[0057] Step1-3: The trusted central node verifies the bit results q of all nodes. When there is a unique d satisfying after several verifications, no collision is detected, and there is a unique initiator node P1. Continue the key negotiation operation; otherwise, abort the key negotiation. Where d can take any value in the interval (1, 2,..., m - 1), is the exclusive OR symbol, representing the addition operation modulo 2; q d represents the measurement result of the particle with sequence d, that is, the bit result of the particle with sequence d.
[0058] In Step2, after there is a unique initiator node P1, it is necessary to notify other nodes to become participants. The initiator node P1 anonymously notifies other nodes to become participant nodes and ensures the anonymity of non-key negotiation nodes to ensure the security of the identity information of the initiator node and participant nodes; including the following steps:
[0059] Step2-1: Each node N j has a bit sequence According to the identity of node N j and the identity relationship between node N j and node N a to determine the distribution of R j . Each node N j sends the bit sequence to the corresponding node N b; where node N j is any node in the shared node network, and node N a is the node with serial number a used to distinguish node N j , node N b is the node with serial number b used to distinguish node N j and node N a ;
[0060] Step2-2, when node N j is the initiator node P1, and at the same time N a is a participant node in the key negotiation, then when node N j is the initiator node P1, and at the same time N a is a non-participant node in the key negotiation, then when node N j is not the initiator node P1, then the identity of N a cannot be determined, then where represents the addition operation modulo 2, represents the modulo 2 cumulative value of the values corresponding to b from 1 to n. When N a is a participant node in the key negotiation, this value is 1; when N a is a non-participant node in the key negotiation, this value is 0;
[0061] Step2-3, each node N b receives from other nodes and forms a new sequence R b , and calculates the value of and sends it to the corresponding node N a ; where is a new array sequence, and the new sequence R b is sent to the node represents the modulo 2 cumulative value of the values corresponding to j from 1 to n; can be a sequence formed by the modulo 2 cumulative values of the j 1s or 0s obtained in Step2-2;
[0062] Step2-4, each node N a calculates the value of . When t a = 1, then N a is notified that it is a participant in the key negotiation; where t a is a specific value, represents the modulo 2 cumulative value of the values corresponding to b from 1 to n; ta It can be the value obtained by modulo-2 accumulation of all values in the sequence obtained in Step2-3 in the sequence.
[0063] As Figure 2 shown, in Step3, corresponding operations are performed on the particles of all nodes according to the parity of the number of key negotiation participant nodes; at the beginning, it is necessary to distinguish the parity of the number of nodes in the shared node network. Since constructing a generalized GHZ state among all nodes does not involve the identity issue during key negotiation, no anonymous operation is required and the identity information of the participant nodes will not be leaked; the parity is divided because the parity of the number of nodes affects the state of the initial cluster state and the distribution method of particles. The initial state and subsequent operations are determined by dividing the parity; by performing corresponding CNOT operations and measurements on some particles, and performing X or Z operations on some particles according to the measurement results, a generalized GHZ state can be generated among all nodes.
[0064] When the number p of key negotiation participant nodes is odd; one node N among all nodes j holds the 1st particle and the 2m-th particle, and other nodes hold the particles with corresponding serial numbers; node N j performs a CNOT operation on the particles it holds, and node N j measures the 2m-th particle and announces the measurement result; when the measurement result is |0>, then node N j performs a Z operation on the 1st particle; when the measurement result is |1>, then node N j performs an X operation on the particles with serial numbers (m + 1) and later; where the 1st particle is the control qubit and the 2m-th particle is the target qubit;
[0065] When the number p of key negotiation participant nodes is even; one node N among all nodes j holds the 1st particle, the (2m - 1)-th particle and the 2m-th particle, and other nodes hold the particles with corresponding serial numbers; node N j performs a CNOT operation on the 1st particle and the 2m-th particle it holds, and node N j measures the 2m-th particle and announces the measurement result; when the measurement result is |0>, then node N j performs a Z operation on the 1st particle; when the measurement result is |1>, then node N j performs an X operation on the particles with serial numbers (m + 1) and later; where the 1st particle is the control qubit and the 2m-th particle is the target qubit.
[0066] In Step 4, the participating nodes in the key negotiation know each other's identities, while the non-participating nodes in other key negotiations cannot know the identities of the participating nodes in the key negotiation; all non-participating nodes in the key negotiation measure the particles they hold using the X basis and announce the measurement results, and the participating nodes in the key negotiation randomly announce a bit value.
[0067] When the number of measurement values of (|0> - |1>) in the measurement results announced by the non-participating nodes in the key negotiation is even, the key negotiation is aborted; when the number of measurement values of (|0> - |1>) in the measurement results announced by the non-participating nodes in the key negotiation is odd, the initiator node P1 of the key negotiation performs a Z operation on the particles it holds to construct a generalized GHZ state among the participating nodes in the key negotiation.
[0068] In Step 5, the above operations are performed multiple times, that is, the operations of Step 3 and Step 4 are repeated L times, so that L generalized GHZ states can be obtained among the participating nodes, and each particle of each generalized GHZ state is held by each participating node.
[0069] In Step 6, the generalized GHZ states among several participating nodes are divided into two groups of generalized GHZ states, specifically, the generalized GHZ states among several participating nodes are divided into two groups of generalized GHZ states for eavesdropping detection and key generation; and the participating nodes perform eavesdropping detection operations and key generation operations on the generalized GHZ states respectively; the generalized GHZ states for eavesdropping detection will be negotiated in advance among the participating nodes, that is, the eavesdropping detection operation is performed first to determine the security of the key negotiation, and then the key generation operation is performed.
[0070] When the generalized GHZ state is used for eavesdropping detection, all participating nodes in the key negotiation measure the particles they hold using the X basis and announce their respective measurement results; according to the measurement results of all participating nodes in the key negotiation, the error rate of each participating node is calculated for error estimation. When the error rate of any participating node exceeds the set error threshold, there may be an eavesdropper, or it may be distortion caused by channel noise during the transmission process, or there may be a dishonest participant or an untrusted node, etc. There is a great insecurity in the key negotiation process, so the key negotiation is aborted; when the error rate of no participating node exceeds the set error threshold, the key negotiation continues.
[0071] To handle the suspension situation caused by the above reasons, a suspension bit needs to be set. When a participant node wishes to suspend the key negotiation, this bit is set to 1. After announcing the measurement result bit, the value of this bit is announced, while other participant nodes simultaneously announce a random bit value. To ensure the anonymity of communication, this suspension bit is announced only in specific environments. For example, in the verification session, after a participant node announces its measurement result bit, it then announces the value 1 of this suspension bit. At the same time, other nodes also need to announce a random value simultaneously to eliminate the particularity of the participant node announcing this suspension bit and play an anonymous role.
[0072] When the generalized GHZ state is used for key generation, the participant nodes measure the generalized GHZ state to obtain the initial key. Then the participant nodes perform error correction and privacy amplification on the initial key to generate a secure conference key K shared by multiple parties, including the following steps:
[0073] Step3-1: All participant nodes in the key negotiation measure the particles they hold using the Z basis. At this time, an initial key K1 is generated among the participant nodes.
[0074] Step3-2: To correct potential errors in the key, the initiator node P1 of the key negotiation generates error correction data for the initial key K1 based on a public error correction code, encrypts the error correction data using the one-time pad OTP in the pre-shared key to obtain the error correction ciphertext, and broadcasts the error correction ciphertext. The rest of all nodes then generate random bit sequences of equal length as confusion parameters.
[0075] Step3-3: After all participant nodes in the key negotiation receive the error correction ciphertext, they decrypt the error correction ciphertext using the one-time pad OTP of the pre-shared key. The participant nodes then correct their respective keys according to the decrypted error correction code. The one-time pad OTP of the pre-shared key is a one-time key pre-stored in the shared node network. There are shared keys in the network itself, but the shared keys in the network itself cannot guarantee their anonymity.
[0076] Step3-4: All participant nodes in the key negotiation calculate the hash value of their respective corrected keys.
[0077] Step3-5: The initiator node P1 of the key negotiation encrypts the hash value calculated from its key using the one-time pad OTP to obtain the hash value ciphertext, and broadcasts the hash value ciphertext. The non-participant nodes in the rest of the key negotiation submit random hash value confusion information.
[0078] Step3-6. Other participant nodes in the key negotiation receive the ciphertext of the hash value and decrypt it through the one-time pad OTP to obtain the hash value of the initiator node P1. The other participant nodes in the key negotiation compare their respective hash values with the hash value of the initiator node P1. When the comparison results are inconsistent, the key negotiation is aborted; when the comparison results are consistent, the key negotiation continues;
[0079] Step3-7. Use a specific hash function to perform privacy compression on the key, eliminate the associated information that the eavesdropper may hold, and generate a secure conference key K shared by multiple parties; the specific hash function is a one-way cryptographic algorithm that maps input data of any length to a fixed-length output. Different hash functions can be selected according to requirements in the protocol.
[0080] In the above, the Z basis is the Z-basis, the computational basis, which is the measurement basis with |0> and |1> as basis vectors. The Z-basis measurement is the most commonly used measurement method in quantum computing, directly reading the classical state of the qubit; the X basis is the X-basis, the Hadamard basis, which is and as basis vectors of the measurement basis. The X-basis measurement is used to detect the projection of the qubit in the X direction, similar to the diagonal measurement in classical cases; the I operation is the identity operation, which does not perform any operation on the qubit and keeps its state unchanged;
[0081]
[0082] The X operation is the Pauli-X gate, the bit-flip gate of the qubit, similar to the NOT gate in classical logic;
[0083]
[0084] The Z operation is the Pauli-Z gate, which is the phase-flip gate of the qubit;
[0085]
[0086] The Y operation is:
[0087]
[0088] After determining the single initiator node and notifying the participant nodes of their identities, each node converts this multi-particle cluster state into a generalized GHZ state. Taking six particles as an example below, the conversion process is shown; the six-particle cluster state is expressed as the following:
[0089]
[0090] Perform a CNOT operation on particle 1 and particle 4, and |000111> is obtained; where particle 1 is the control qubit and particle 4 is the target qubit; the calculation process is as follows:
[0091]
[0092] Measuring particle 4 using the Z basis, it can be known that if the measurement result is |0>, then performing a Z operation on particle 1 can obtain a GHZ state; if the measurement result is |1>, then performing an X operation on particles 5 and 6 can obtain a five-particle generalized GHZ state as shown below:
[0093]
[0094] Embodiment
[0095] In a 15-node network, each node is respectively denoted as N j (j = 1, 2,..., 15); among the 15 nodes, there are 5 nodes P i (i = 1, 2,..., 5) participating in the key negotiation, where P1 is the initiator. During the process, it is first necessary to ensure that there is only one initiator during the negotiation process, so collision detection is required. After determining the single initiator P1, P1 also needs to notify the other participant nodes P j that it has selected to participate in the key negotiation, and ensure anonymity during the notification process to ensure the security of the identity information of the negotiation participants. After the initiator node and the participant nodes determine their identities, they need to use the entanglement characteristics of the generalized GHZ state to achieve anonymous key negotiation. Therefore, it is also necessary to construct a generalized GHZ state among multiple nodes, construct a generalized GHZ state among the participant nodes, and perform subsequent key generation.
[0096] Among them, according to the parity of the number of key negotiation participant nodes, operations are performed on the particles of all nodes. When the number of participant nodes n is odd and is 5, node N1 holds particles 1 and 16, and all other nodes hold the particles with corresponding serial numbers. Node N1 performs a CNOT operation on the particles it holds, where particle 1 is the control qubit and particle 16 is the target qubit. Then node N1 measures particle 16 and announces its measurement result. If the measurement result is |0>, then N1 performs a Z operation on particle 1; if the result is |1>, then particles 9 and subsequent sequence particles perform an X operation.
[0097] All participant nodes in the key negotiation measure the particles they hold using the Z basis. At this time, an initial key K1 is generated between the participant nodes. To correct potential errors in the key, the initiator node P1 of the key negotiation generates error correction data for the initial key K1 based on a public error correction code, encrypts the error correction data using the one-time pad OTP in the pre-shared key to obtain an error correction ciphertext, and broadcasts the error correction ciphertext. All the other nodes each generate a random bit sequence of the same length as the confusion parameter. After all the key negotiation participants receive the error correction ciphertext, they decrypt the error correction ciphertext using the one-time pad OTP of the pre-shared key. The participant nodes then correct their respective keys according to the error correction code obtained by decryption; the one-time pad OTP of the pre-shared key is a one-time key pre-stored in the shared node network. There is a shared key in the network itself in the shared node network, but the shared key existing in the network itself cannot guarantee its anonymity. All the participant nodes in the key negotiation calculate the hash value of their respective corrected keys; the initiator node P1 of the key negotiation encrypts the hash value calculated from its key using the one-time pad OTP to obtain a hash value ciphertext, and broadcasts the hash value ciphertext. The non-participant nodes in the other key negotiations submit random hash value confusion information; the other participant nodes in the key negotiation receive the hash value ciphertext and decrypt it using the one-time pad OTP to obtain the hash value of the initiator node P1. The other participant nodes in the key negotiation compare their respective hash values with the hash value of the initiator node P1. When the comparison results are inconsistent, the key negotiation is aborted; when the comparison results are consistent, the key negotiation continues; a specific hash function is used to perform privacy compression on the key to eliminate the correlation information that the eavesdropper may hold, and a secure conference key K shared by multiple parties is generated; the specific hash function is a one-way cryptographic algorithm that maps input data of any length to an output of a fixed length, and different hash functions can be selected according to requirements in the protocol.
[0098] The above is only a description of the preferred embodiment of the present invention. Those of ordinary skill in the art can make several modifications and optimizations based on the above disclosure without departing from the basic principle content. These improvements and optimizations should be regarded as the protection scope understood by the present invention.
Claims
1. A fully anonymous quantum conference key negotiation method, characterized in that: It includes the following steps: Step 1: Determine whether there is a unique node in the shared node network as the initiator node for key negotiation through collision detection, and lock the initiator node for key negotiation; Step 2: The initiator node for key negotiation anonymously notifies other nodes to make the corresponding nodes become the participant nodes for key negotiation; Step 3: Perform corresponding operations on the particles held by the participant nodes according to the parity of the number of participant nodes for key negotiation, and construct a generalized GHZ state among multiple nodes; Step 4: All non-participant nodes for key negotiation measure the particles they hold and perform corresponding operations according to the measurement results to construct a generalized GHZ state among the participant nodes; Step 5: Repeat the operations of Step 3 and Step 4 several times to obtain generalized GHZ states among several participant nodes; Step 6: Divide the generalized GHZ states among several participant nodes into two groups of generalized GHZ states, and the participant nodes respectively perform eavesdropping detection operations and key generation operations on the generalized GHZ states to generate a secure conference key K shared by multiple parties.
2. The fully anonymous quantum conference key negotiation method according to claim 1, wherein: The shared node network includes n nodes, and each node is denoted as N j (j = 1, 2,..., n); when p nodes out of the n nodes participate in the key negotiation, the initiator node participating in the key negotiation is set as P1, and each node participating in the key negotiation is denoted as P i (i = 1, 2,..., p); the n nodes share a multi-particle cluster state, and the multi-particle cluster state is shown as follows: Wherein, the value of m is related to the number of nodes n in the node network; when n is an odd number greater than or equal to 3, m = (n + 1) / 2, and node N j holds particles numbered 1 and 2m, while all other nodes hold particles with corresponding serial numbers; when n is an even number greater than 3, m = n / 2 + 1, and node N j holds three particles numbered 1, (2m - 1), and 2m, while all other nodes hold particles with corresponding serial numbers.
3. A fully anonymous quantum conference key negotiation method according to claim 1, characterized in that: In the said Step 1, determining whether there is a unique node in the shared node network as the initiator node for key negotiation through collision detection includes the following steps: Step1-1. Determine whether node N should become the key negotiation initiator node based on the information sent by node N j If so, perform the X operation on the serial number particles corresponding to node N j Otherwise, perform the I operation on the serial number particles corresponding to node N j j ; Step 1-2: All nodes in the shared node network measure the particles they hold using the Z basis to obtain the bit results q of all nodes, and submit the bit results q of all nodes to the central node through an anonymous channel; Step1-3. The central node verifies the bit results q of all nodes. When there is a unique d satisfying after several verifications, no collision is detected and there is a unique initiator node P1; otherwise, the key negotiation is aborted.
4. A fully anonymous quantum conference key negotiation method according to claim 1, wherein: In the said Step 2, after there is a unique initiator node P1, the initiator node P1 anonymously notifies other nodes to become participant nodes, including the following steps: Step2-1. Each node N j has a bit sequence According to the identity of node N j and the identity relationship between node N j and node N a to determine the distribution of R j Each node N j sends the bit sequence to the corresponding node N b ; Step2-2. When node N j is the initiator node P1 and at the same time N a is a participant node in the key negotiation, then When node N j is the initiator node P1 and at the same time N a is a non-participant node in the key negotiation, then When node N j is not the initiator node P1, then the identity of N a cannot be determined, then Step2-3. Each node N b receives from other nodes and forms a new sequence R b , and calculates the value of it and sends it to the corresponding node N a ; Step2-4. Each node N a calculates the value of, and when t a = 1, then N a is notified that it is a participant in the key negotiation.
5. A fully anonymous quantum conference key negotiation method according to claim 1, wherein: In the said Step 3, corresponding operations are performed on the particles of all nodes according to the parity of the number of key negotiation participant nodes; when the number p of key negotiation participant nodes is odd; one node N among all nodes j holds particle No. 1 and particle No. 2m, and other nodes hold particles with corresponding serial numbers; node N j performs a CNOT operation on the particles it holds, node N j measures particle No. 2m and announces the measurement result; when the measurement result is |0>, then node N j performs a Z operation on particle No. 1; when the measurement result is |1>, then node N j performs an X operation on particles with serial numbers (m + 1) and subsequent serial numbers; When the number p of participant nodes in key negotiation is an even number; one node N among all nodes j holds the 1st particle, the (2m - 1)th particle and the 2mth particle, and other nodes hold the particles with corresponding serial numbers; node N j performs a CNOT operation on the 1st particle and the 2mth particle, node N j measures the 2mth particle and announces the measurement result; when the measurement result is |0>, then node N j performs a Z operation on the 1st particle; when the measurement result is |1>, then node N j performs an X operation on the particles with serial numbers (m + 1) and subsequent ones.
6. A fully anonymous quantum conference key negotiation method according to claim 5, characterized in that: In the said Step 4, the identities of the participant nodes for key negotiation are known to each other, while the identities of the other non-participant nodes for key negotiation cannot be known; all non-participant nodes for key negotiation measure the particles they hold using the X basis and announce the measurement results, and the participant nodes for key negotiation randomly announce a bit value; When the number of measurement values of (|0> - |1>) in the measurement results announced by the non-participant nodes for key negotiation is even, the key negotiation is aborted; when the number of measurement values of (|0> - |1>) in the measurement results announced by the non-participant nodes for key negotiation is odd, the initiator node P1 for key negotiation performs a Z operation on the particles it holds to construct a generalized GHZ state among the participating nodes for key negotiation.
7. A fully anonymous quantum conference key negotiation method according to claim 1, characterized in that: In the said Step 6, divide the generalized GHZ states among several participant nodes into two groups of generalized GHZ states, and the participant nodes respectively perform eavesdropping detection operations and key generation operations on the generalized GHZ states; When the generalized GHZ state is used for eavesdropping detection, all participant nodes in the key negotiation measure the particles they hold using the X basis and announce their respective measurement results. According to the measurement results of all participant nodes in the key negotiation, the error rate of each participant node is calculated for error estimation. When the error rate of any participant node exceeds the set error threshold, the key negotiation is aborted. When the error rate of no participant node exceeds the set error threshold, the key negotiation continues.
8. A fully anonymous quantum conference key negotiation method according to claim 7, characterized in that: When the generalized GHZ state is used for key generation, it includes the following steps: Step3-1: All participant nodes in the key negotiation measure the particles they hold using the Z basis. At this time, an initial key K1 is generated among the participant nodes. Step3-2: The initiator node P1 of the key negotiation generates error correction data based on the public error correction code for the initial key K1, encrypts the error correction data using the one-time pad OTP in the pre-shared key to obtain the error correction ciphertext, and broadcasts the error correction ciphertext. The rest of the nodes each generate a random bit sequence of the same length as the confusion parameter. Step3-3: After all participant nodes in the key negotiation receive the error correction ciphertext, they decrypt the error correction ciphertext using the one-time pad OTP of the pre-shared key, and the participant nodes then correct their respective keys according to the decrypted error correction code. Step3-4: All participant nodes in the key negotiation calculate the hash value of their respective corrected keys. Step3-5: The initiator node P1 of the key negotiation encrypts the hash value calculated from its key using the one-time pad OTP to obtain the hash value ciphertext, and broadcasts the hash value ciphertext. The non-participant nodes in the rest of the key negotiation submit random hash value confusion information. Step3-6: The other participant nodes in the key negotiation receive the hash value ciphertext and decrypt it using the one-time pad OTP to obtain the hash value of the initiator node P1. The other participant nodes in the key negotiation compare their respective hash values with the hash value of the initiator node P1. When the comparison results are inconsistent, the key negotiation is aborted. When the comparison results are consistent, the key negotiation continues. Step3-7: Use a specific hash function to perform privacy compression on the key to generate a multi-party shared secure conference key K.