Key certificate issuing method, system and device

Through the quantum key distribution technology, the first photon in the photon stream and the second photon in the entangled photon stream are used to modulate the preset code base, and the certificate receiving end performs measurement processing to generate a key certificate, which solves the problem of insufficient security in the prior art and achieves higher security and protection effects.

CN120474715APending Publication Date: 2025-08-12BEIJING HUADA ZHIBAO ELECTRONICS SYST
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510446911.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-10
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

The existing method of issuing key certificates has insufficient security in distributed systems. Attackers can intercept certificate transmission through physical level and crack the encryption algorithm.

Method used

Using quantum key distribution technology, the first photon in the photon stream and the second photon in the entangled photon stream are used to modulate the first photon and the second photon in the entangled photon stream, and the certificate receiving end performs measurement processing to generate a key certificate, verify the identity through quantum communication and generate a key.

Benefits of technology

Improve the security of the key certificate issuance process, preventing attackers from pretending to be identities or intercepting photon flows, and ensuring that the generation and verification process of the key certificate is not cracked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474715A_ABST
    Figure CN120474715A_ABST
Patent Text Reader

Abstract

The invention relates to a key certificate issuing method, system and device. The method comprises: receiving a target photon stream sent by a certificate sending end, the target photon stream being composed of a plurality of first photons and a plurality of second photons, the first photons being photons modulated by the certificate sending end based on a preset coding base, and the second photons being one photon in an entangled state photon pair; performing measurement processing on the target photon flow to obtain a bit value measurement result corresponding to each photon in the target photon flow; obtaining a first bit value measurement result at the first photon arrangement position, and executing identity verification processing for the certificate receiving end based on each first bit value measurement result; and under the condition that the identity verification is passed, obtaining second bit value measurement results not located at the first photon arrangement position from the bit value measurement results, and generating a key certificate based on the second bit value measurement results. By adopting the method, the security of key certificate issuing can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of quantum key distribution, and in particular to a method, system and device for issuing a key certificate. Background Art

[0002] When creating secure authentication media for classic cryptographic systems (including symmetric and public-key cryptography), it is generally necessary to pre-implant a security authentication certificate into the secure authentication media (such as a financial USB shield, secure SIM card, or security module) before initialization. This certificate is then stored in a secure storage area on the secure authentication media. This secure storage area is protected from unauthorized access and tampering. When users need to authenticate their identities and verify data signatures, they use the pre-implanted certificate in the secure authentication media to encrypt, decrypt, and verify data.

[0003] Currently, in distributed systems, certificate centers typically need to establish a secure point-to-point channel with distributed nodes to issue certificates, encrypting the certificates using an encryption algorithm before transmission. However, attackers can intercept certificate transmissions through physical attacks, and the encryption algorithm can also be cracked. Therefore, current key certificate issuance methods still have security issues. Summary of the Invention

[0004] Based on this, it is necessary to provide a key certificate issuance method, system and device to address the above technical issues.

[0005] In a first aspect, the present application provides a key certificate issuance method, which is applied to a certificate receiving end. The method comprises:

[0006] Receive a target photon stream sent by a certificate sending end, where the target photon stream consists of a plurality of first photons and a plurality of second photons, where the first photons are photons modulated by the certificate sending end based on a preset coding basis, and the second photon is one photon of an entangled photon pair;

[0007] Performing measurement processing on the target photon flow to obtain a bit value measurement result corresponding to each photon in the target photon flow;

[0008] Determining a preset first photon arrangement position, obtaining a first bit value measurement result located at the first photon arrangement position from each of the bit value measurement results, and performing identity authentication processing for the certificate receiving end based on each of the first bit value measurement results;

[0009] If the identity authentication is passed, a second bit value measurement result is obtained from each of the bit value measurement results, and a key certificate is generated based on each of the second bit value measurement results; the second bit value measurement result is a measurement result in each of the bit value measurement results except the first bit value measurement result.

[0010] In one embodiment, each of the preset coding bases is a non-orthogonal coding base, the bit value measurement results include invalid measurement results that do not correspond to bit values and valid measurement results that correspond to bit values, and performing identity authentication processing for the certificate receiving end based on each of the first bit value measurement results includes:

[0011] Determining a target first photon arrangement position corresponding to a valid measurement result in each of the first bit value measurement results;

[0012] An identity authentication request is sent to the certificate sending end, where the identity authentication request includes the target first photon arrangement position, and the identity authentication request is used to instruct the certificate sending end to authenticate the certificate receiving end based on the matching of the target first photon arrangement position and the first photon arrangement position.

[0013] In one embodiment, the identity authentication request also includes a first bit value measurement result corresponding to the target first photon arrangement position, and the identity authentication request is also used to instruct the certificate sending end to authenticate the certificate receiving end based on the matching of the first bit value measurement result corresponding to the target first photon arrangement position and the preset coding base corresponding to the target first photon arrangement position.

[0014] In one embodiment, generating a key certificate based on each second bit value measurement result includes:

[0015] receiving a first measurement basis sequence sent by the certificate sending end, where the first measurement basis sequence is a measurement basis sequence used by the certificate sending end to measure each third photon when identity authentication is passed; the third photon is the other photon in the entangled photon pair except the second photon;

[0016] Obtain a second measurement basis sequence corresponding to each second bit value measurement result, determine a target position sequence number based on the first measurement basis sequence and the second measurement basis sequence, and combine the second bit value measurement results corresponding to each target position sequence number to form a key certificate; wherein the target position sequence number has the same measurement basis corresponding to it in the first measurement basis sequence and the second measurement basis sequence.

[0017] In a second aspect, the present application also provides a key certificate issuance method, which is applied to a certificate sending end, comprising:

[0018] Modulating a preset coding basis to obtain a plurality of first photons, generating a plurality of entangled photon pairs, and arranging each of the first photons and a second photon in each of the entangled photon pairs based on a preset arrangement position of the first photons to obtain a target photon stream; the second photon being any one of the entangled photon pairs;

[0019] Sending the target photon flow to a certificate receiving end;

[0020] receiving an identity authentication request sent by the certificate receiving end, and authenticating the certificate receiving end based on the identity authentication request; wherein the identity authentication request is generated based on a first bit value measurement result, the first bit value measurement result being obtained by the certificate receiving end measuring each first target photon located at the first photon arrangement position in the target photon stream after determining the first photon arrangement position;

[0021] If the identity authentication is passed, the third photon in each of the entangled photon pairs is measured and processed to obtain a second bit value measurement result, and a key certificate is generated based on each of the second bit value measurement results; the third photon is the other photon in the entangled photon pair except the second photon.

[0022] In one embodiment, each of the preset coding bases is a non-orthogonal coding base, the identity authentication request carries a target first photon arrangement position, and the preset coding base used when encoding the photons at the target first photon arrangement position can be determined based on the first bit value measurement result corresponding to the target first photon arrangement position and the target measurement basis;

[0023] The authenticating the certificate receiving end based on the identity authentication request includes:

[0024] If the target first photon arrangement position is a subset of the first photon arrangement position, it is determined that the identity authentication is passed; or if the target first photon arrangement position is not a subset of the first photon arrangement position, it is determined that the identity authentication is failed.

[0025] In one embodiment, generating a key certificate based on each second bit value measurement result includes:

[0026] Acquiring a first measurement basis sequence used when performing measurement processing on each of the third photons;

[0027] receiving a second measurement basis sequence sent by the certificate receiving end, where the second measurement basis sequence is a measurement basis sequence used by the certificate receiving end when measuring each photon in the target photon flow that is not located at an arrangement position of the first photons;

[0028] A target position number is determined based on the first measurement basis sequence and the second measurement basis sequence, and second bit value measurement results corresponding to each target position number are combined to form a key certificate; wherein the target position number has the same measurement basis corresponding to it in the first measurement basis sequence and the second measurement basis sequence.

[0029] In a third aspect, the present application also provides a key certificate issuance system, the system comprising a certificate sending end and a certificate receiving end, wherein:

[0030] The certificate sending end is used to obtain multiple first photons based on a preset coding basis modulation, generate multiple entangled photon pairs, arrange each of the first photons and the second photon in each of the entangled photon pairs based on a preset first photon arrangement position, obtain a target photon stream, and send the target photon stream to the certificate receiving end; the second photon is any one photon in the entangled photon pair;

[0031] The certificate receiving end is configured to measure and process the target photon flow to obtain a bit value measurement result corresponding to each photon in the target photon flow, obtain a first bit value measurement result at the arrangement position of the first photon from each of the bit value measurement results, generate an identity authentication request based on each of the first bit value measurement results, and send the identity authentication request to the certificate sending end;

[0032] The certificate sending end is further configured to authenticate the certificate receiving end based on the identity authentication request and send the identity authentication result to the certificate receiving end;

[0033] The certificate receiving end is further configured to obtain, when the identity authentication result indicates that the identity authentication is passed, a second bit value measurement result that is not located at the first photon arrangement position, and generate a key certificate based on each second bit value measurement result;

[0034] The certificate sending end is also used to measure and process the third photon in each of the entangled photon pairs when the identity authentication result indicates that the identity authentication is passed, obtain a third bit value measurement result, and generate a key certificate based on each of the third bit value measurement results; the third photon is the other photon in the entangled photon pair except the second photon.

[0035] In a fourth aspect, the present application further provides a key certificate issuing device, which is applied to a certificate receiving end. The device includes:

[0036] A receiving module is configured to receive a target photon stream sent by a certificate sending end, wherein the target photon stream is composed of a plurality of first photons and a plurality of second photons, wherein the first photons are photons modulated by the certificate sending end based on a preset coding basis, and the second photon is one photon of an entangled photon pair;

[0037] a measurement module, configured to measure the target photon flow to obtain a bit value measurement result corresponding to each photon in the target photon flow;

[0038] a determination module, configured to determine a preset first photon arrangement position, obtain a first bit value measurement result located at the first photon arrangement position from each of the bit value measurement results, and perform identity authentication processing for the certificate receiving end based on each of the first bit value measurement results;

[0039] A generating module is configured to obtain, when identity authentication is passed, a second bit value measurement result from each of the bit value measurement results, and generate a key certificate based on each of the second bit value measurement results; the second bit value measurement result is a measurement result in each of the bit value measurement results other than the first bit value measurement result.

[0040] In one embodiment, each of the preset coding bases is a non-orthogonal coding base, the bit value measurement result includes an invalid measurement result that does not correspond to a bit value and a valid measurement result that corresponds to a bit value, and the determining module is further configured to:

[0041] Determining a target first photon arrangement position corresponding to a valid measurement result in each of the first bit value measurement results;

[0042] An identity authentication request is sent to the certificate sending end, where the identity authentication request includes the target first photon arrangement position, and the identity authentication request is used to instruct the certificate sending end to authenticate the certificate receiving end based on the matching of the target first photon arrangement position and the first photon arrangement position.

[0043] In one embodiment, the identity authentication request also includes a first bit value measurement result corresponding to the target first photon arrangement position, and the identity authentication request is also used to instruct the certificate sending end to authenticate the certificate receiving end based on the matching of the first bit value measurement result corresponding to the target first photon arrangement position and the preset coding base corresponding to the target first photon arrangement position.

[0044] In one embodiment, the generating module is further configured to:

[0045] receiving a first measurement basis sequence sent by the certificate sending end, where the first measurement basis sequence is a measurement basis sequence used by the certificate sending end to measure each third photon when identity authentication is passed; the third photon is the other photon in the entangled photon pair except the second photon;

[0046] Obtain a second measurement basis sequence corresponding to each second bit value measurement result, determine a target position sequence number based on the first measurement basis sequence and the second measurement basis sequence, and combine the second bit value measurement results corresponding to each target position sequence number to form a key certificate; wherein the target position sequence number has the same measurement basis corresponding to it in the first measurement basis sequence and the second measurement basis sequence.

[0047] In a fifth aspect, the present application further provides a key certificate issuing device, which is applied to a certificate sending end. The device includes:

[0048] a first generating module, configured to obtain a plurality of first photons based on a preset coding base modulation, generate a plurality of entangled photon pairs, and arrange each of the first photons and a second photon in each of the entangled photon pairs based on a preset arrangement position of the first photons to obtain a target photon stream; the second photon is any one photon in the entangled photon pair;

[0049] A sending module, configured to send the target photon flow to a certificate receiving end;

[0050] a receiving module, configured to receive an identity authentication request sent by the certificate receiving end, and authenticate the certificate receiving end based on the identity authentication request; the identity authentication request is generated based on a first bit value measurement result, the first bit value measurement result being obtained by the certificate receiving end, after determining the first photon arrangement position, by measuring each first target photon located at the first photon arrangement position in the target photon stream;

[0051] The second generation module is used to measure and process the third photon in each of the entangled photon pairs when the identity authentication is passed, obtain a second bit value measurement result, and generate a key certificate based on each of the second bit value measurement results; the third photon is the other photon in the entangled photon pair except the second photon.

[0052] In one embodiment, each of the preset coding bases is a non-orthogonal coding base, the identity authentication request carries a target first photon arrangement position, and the preset coding base used when encoding the photons at the target first photon arrangement position can be determined based on the first bit value measurement result corresponding to the target first photon arrangement position and the target measurement basis;

[0053] The receiving module is further configured to:

[0054] If the target first photon arrangement position is a subset of the first photon arrangement position, it is determined that the identity authentication is passed; or if the target first photon arrangement position is not a subset of the first photon arrangement position, it is determined that the identity authentication is failed.

[0055] In one embodiment, the generating module is further configured to:

[0056] Acquiring a first measurement basis sequence used when performing measurement processing on each of the third photons;

[0057] receiving a second measurement basis sequence sent by the certificate receiving end, where the second measurement basis sequence is a measurement basis sequence used by the certificate receiving end when measuring each photon in the target photon flow that is not located at an arrangement position of the first photons;

[0058] A target position number is determined based on the first measurement basis sequence and the second measurement basis sequence, and second bit value measurement results corresponding to each target position number are combined to form a key certificate; wherein the target position number has the same measurement basis corresponding to it in the first measurement basis sequence and the second measurement basis sequence.

[0059] In a sixth aspect, the present application further provides a computer device, wherein the computer device comprises a memory and a processor, wherein the memory stores a computer program, and the processor implements any of the above methods when executing the computer program.

[0060] In a seventh aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program implements any of the above methods when executed by a processor.

[0061] In an eighth aspect, the present application further provides a computer program product, comprising a computer program, which implements any of the above methods when executed by a processor.

[0062] The above-mentioned key certificate issuance method, system, and device combine multiple modulated first photons and one photon from an entangled photon pair based on a preset first photon arrangement position to form a target photon stream. After measuring the target photon stream, the certificate receiver determines the preset first photon arrangement position and performs identity authentication based on the measurement result of the first bit value located at the first photon arrangement position. If the identity authentication is successful, the key certificate is generated based on the measurement result of the second bit value not located above the first photon arrangement position. In the presence of an attacker, if the attacker adopts the attack strategy of impersonating the certificate receiver and the certificate sender to communicate, the attacker cannot extract the correct first bit value measurement result to complete the identity authentication because the attacker does not know the agreed first photon arrangement position between the certificate receiver and the certificate sender. If the attacker adopts the strategy of intercepting the target photon stream sent by the certificate sender, the attacker cannot extract the correct second bit value measurement result to generate the key certificate because the attacker does not know the first photon arrangement position. At the same time, due to the characteristics of quantum communication, the attacker's measurement of the target photon stream will affect the polarization direction of the first photon and destroy the entangled state of the second photon, allowing the certificate receiver and the certificate sender to detect the presence of the eavesdropper. Furthermore, because the embodiments of the present application use entangled photon pairs to generate key certificates, the certificate sender will not know the specific identity of the key certificate until the certificate receiver measures the second photon in the entangled photon pair. This also prevents attackers from obtaining the key certificate by attacking the certificate sender. Therefore, the method of the embodiments of the present application can improve the security of the key certificate issuance process. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 A diagram illustrating an application environment of a key certificate issuance method in one embodiment;

[0064] Figure 2 A schematic diagram of a flow chart of a method for issuing a key certificate executed by a certificate receiving end in one embodiment;

[0065] Figure 3 A schematic diagram of the interaction process when a certificate receiving end and a certificate sending end synchronously generate a key certificate in one embodiment;

[0066] Figure 4 A schematic diagram of a flow chart of a method for issuing a key certificate executed by a certificate sending end in one embodiment;

[0067] Figure 5 A schematic diagram of an interactive process of a certificate receiving end and a certificate sending end executing a key certificate issuance method in one embodiment;

[0068] Figure 6 This is a structural block diagram of a key certificate issuing device in one embodiment;

[0069] Figure 7This is a structural block diagram of a key certificate issuing device in one embodiment;

[0070] Figure 8 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0071] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0072] In one embodiment, Figure 1 As shown, a key certificate issuance system is provided, including a certificate sender and a certificate receiver. The certificate sender and the certificate receiver can communicate through traditional channels and quantum channels. The certificate sender is used to generate a target photon stream and send the target photon stream to the certificate receiver through the quantum channel. The target photon stream contains the information required for identity authentication obtained by encoding a single photon, and the information required for generating a key certificate obtained by encoding an entangled photon pair. The certificate receiver parses the information required for identity authentication and authenticates the certificate sender through a traditional channel. If the authentication is successful, the certificate receiver and the certificate sender can respectively measure and process the two photons in the entangled photon pair. Since the measurement results of the two photons in the entangled photon pair are correlated, the certificate receiver and the certificate sender can synchronously generate the same measurement results after the measurement, and respectively save the measurement results in a secure storage area as key certificates.

[0073] like Figure 2 As shown, a key certificate issuance method is provided. This embodiment uses this method to apply Figure 1 Taking the certificate receiving end in as an example, the following steps are included:

[0074] Step 202: Receive the target photon stream sent by the certificate sending end. The target photon stream consists of multiple first photons and multiple second photons. The first photon is a photon modulated by the certificate sending end based on a preset coding basis, and the second photon is a photon in an entangled photon pair.

[0075] In this embodiment of the present application, the certificate sender negotiates certificate issuance with the certificate receiver over a traditional channel. After the negotiation is successful, the certificate sender generates multiple entangled photon pairs and modulates them based on a preset coding basis to generate multiple first photons with specific polarization directions. From each entangled photon pair, one photon is selected as the second photon in the entangled photon pair to be sent to the certificate receiver, while the other photon in the entangled photon pair is retained at the certificate sender. The first photon is used for identity verification, and the second photon is used to generate the key certificate.

[0076] The certificate sender arranges the first and second photons according to a preset first photon arrangement position to generate a target photon stream. The first photon arrangement position refers to the sequence number of each first photon within the target photon stream. The first photon arrangement position can have a certain degree of randomness, making it more difficult for an attacker to determine the first photon arrangement position. After generating the target photon stream, the certificate sender transmits the target photon stream to the certificate receiver via a quantum channel.

[0077] Step 204 : performing measurement processing on the target photon flow to obtain a bit value measurement result corresponding to each photon in the target photon flow.

[0078] In an embodiment of the present application, after the certificate receiving end receives the target photon stream, it randomly selects a measurement basis for each photon in the target photon stream to measure and obtains the bit value measurement result corresponding to each photon in the target photon stream.

[0079] Considering that the target photon stream may be affected by noise during transmission, and to initially detect whether the target photon stream has been eavesdropped on during transmission, quantum error correction can be performed on the target photon stream after the measurement is completed, and the bit error rate of the target photon stream can be calculated. If the bit error rate is greater than a certain threshold, it indicates that the target photon stream may have been eavesdropped on during transmission. The certificate receiver can send a key certificate regeneration request to the certificate sender, causing the certificate sender to re-prepare the target photon stream and resend the target photon stream to the certificate receiver.

[0080] Step 206 , determine a preset first photon arrangement position, obtain a first bit value measurement result located at the first photon arrangement position from each bit value measurement result, and perform identity authentication processing for the certificate receiving end based on each first bit value measurement result.

[0081] In an embodiment of the present application, the certificate sending end and the certificate receiving end can agree on the first photon arrangement position through quantum communication through a quantum channel during the certificate issuance negotiation process. Alternatively, the certificate sending end can encrypt the first photon arrangement position and send it to the certificate receiving end through a traditional channel during the certificate issuance negotiation process. Alternatively, the certificate sending end can also inform the certificate receiving end of the algorithm used to calculate the first photon arrangement position through a traditional channel, and the certificate receiving end can then determine the first photon arrangement position based on the algorithm. The embodiment of the present application does not specifically limit how the certificate receiving end obtains the first photon arrangement position, as long as the transmission of the first photon arrangement position has a certain degree of security.

[0082] After determining the first photon arrangement position, the certificate receiver selects the first bit value measurement result from the various bit value measurement results. These measurement results are used for identity verification. The arrangement position of the photon corresponding to the first bit value measurement result in the target photon stream is the first photon arrangement position.

[0083] After obtaining the first bit value measurement result, the certificate receiver can interact with the certificate sender through a traditional channel and perform identity authentication based on the first bit value measurement result. The purpose of identity authentication includes verifying whether there is an eavesdropper eavesdropping on the target photon stream on the quantum channel and verifying that the certificate receiver is the same certificate receiver as the one used during the certificate issuance negotiation phase.

[0084] The method for performing identity authentication based on the first bit value measurement result may include performing identity authentication based on the accuracy of the first bit value measurement result, performing identity authentication based on the measurement base of the first bit value measurement result, performing identity authentication based on the arrangement position of the first bit value measurement result belonging to a valid measurement result, and so on. The specific method can be determined based on the verification strategy negotiated by the certificate sender and the certificate receiver during the certificate issuance negotiation phase, and the preset coding base type used by the certificate sender.

[0085] The following describes different authentication methods. The principle behind authentication based on the accuracy of first bit value measurement results is that, depending on the protocol used to encode and parse the first photon, the probability of the first bit value measurement result matching the bit value represented by the preset coding base is constant. For example, when encoding and parsing the first photon using the BB84 protocol, the first bit value measurement results should include 50% of the bit values that are consistent with the bit value represented by the preset coding base, and 50% of the bit values that are inconsistent with the bit value represented by the preset coding base. When encoding and parsing the first photon using the E91 protocol, the first bit value measurement results should include 75% of invalid measurement results where the bit value cannot be determined, and 25% of valid measurement results with corresponding bit values, all of which are consistent with the bit value represented by the preset coding base. If the first bit value measurement results do not conform to this pattern, it indicates that an eavesdropper may have eavesdropped on the target photon stream, or that the certificate receiver communicating with the certificate sender does not actually know the exact arrangement of the first photons, indicating that the certificate receiver communicating with the certificate sender is an imposter.

[0086] When using this authentication method, the certificate receiving end can send an authentication request to the certificate sending end, and the authentication request includes the first bit value measurement results and the arrangement position of the photons corresponding to each first bit value measurement result in the target photon stream. The certificate sending end can first determine whether each arrangement position matches the arrangement position of the first photon. If the proportion of the number of mismatching arrangement positions is greater than a certain preset ratio, the authentication can be determined to have failed, the certificate issuance can be abandoned, and an authentication failure response can be returned to the certificate receiving end. If the proportion of the number of mismatching arrangement positions is less than or equal to the preset ratio, the initial authentication can be determined to have succeeded and the next round of verification can be entered.

[0087] The certificate sender can then obtain the preset coding basis used when modulating each photon. For each first bit value measurement result, it determines whether the result is consistent with the bit value represented by the corresponding preset coding basis. If the difference between the matching rate and the preset matching rate determined according to the above rules is less than a preset value, it can be determined that the identity authentication has passed, and an authentication pass response is returned to the certificate receiver. If the difference between the matching rate and the preset matching rate is greater than or equal to the preset value, it is determined that the identity authentication has failed, the certificate issuance is abandoned, and an authentication failure response is returned to the certificate receiver.

[0088] The principle of authentication based on the measurement basis of the first bit value measurement result is that if the measurement basis and the coding basis at the same arrangement position are consistent, the first bit value measurement result of the measurement basis and the corresponding bit value of the coding basis should also be consistent. If the proportion of measurement basis whose first bit value measurement results are inconsistent with the corresponding bit value of the coding basis exceeds a preset ratio among all measurement basis that are consistent with the coding basis, it indicates that there may be an eavesdropper or the certificate recipient is an imposter.

[0089] When using this authentication method, the certificate receiving end can send an authentication request to the certificate sending end, and the authentication request includes the first bit value measurement results, the arrangement position of the photons corresponding to each first bit value measurement result in the target photon stream, and the measurement basis corresponding to each first bit value measurement result. The certificate sending end can first determine whether each arrangement position matches the arrangement position of the first photon. If the proportion of the number of mismatching arrangement positions is greater than a first preset proportion, the authentication can be determined to have failed, the certificate issuance can be abandoned, and an authentication failure response can be returned to the certificate receiving end. If the proportion of the number of mismatching arrangement positions is less than or equal to the first preset proportion, the preliminary authentication can be determined to have succeeded and the next round of determination can be entered.

[0090] The certificate sender can then obtain the preset coding basis used to modulate each photon. For each first bit value measurement result, it determines whether the measurement basis corresponding to the result is consistent with the corresponding preset coding basis. If so, it then continues to determine whether the result is consistent with the bit value represented by the preset coding basis. If, among the measurement bases consistent with the preset coding basis, the proportion of measurement bases whose first bit value measurement results are inconsistent with the bit value represented by the preset coding basis is less than or equal to a second preset proportion, the identity verification is determined to be successful, and an identity verification success response is returned to the certificate receiver. If the proportion is greater than the second preset proportion, the identity verification is determined to have failed, the certificate issuance is aborted, and an identity verification failure response is returned to the certificate receiver. It should be noted that the "first preset proportion" and "second preset proportion" herein are merely used to illustrate that the two preset proportions can be different (or the same), and the specific values of these two preset proportions are not limited in this embodiment of the application.

[0091] Authentication is performed based on the position of the first bit value measurement result that is a valid measurement result. This is applicable to scenarios where the certificate sender and receiver use the E91 protocol to encode and parse the first photon. The E91 protocol uses two non-orthogonal coding bases.

[0092] When using this identity authentication method, the certificate receiving end can first determine the target first photon arrangement position corresponding to the valid measurement result in each first bit value measurement result. The valid measurement result refers to the measurement result of the corresponding bit value in the E91 protocol, and the measurement results other than the valid measurement result are invalid measurement results that do not correspond to the bit value in the E91 protocol. For specific information on how to determine the valid measurement result, please refer to the relevant provisions of the E91 protocol, which will not be described in detail in this embodiment of the application. After obtaining each valid measurement result, the certificate receiving end extracts the target first photon arrangement position of the photon corresponding to the valid measurement result in the target photon stream.

[0093] Furthermore, the certificate receiving end sends an identity authentication request to the certificate sending end, and the identity authentication request includes the target first photon arrangement position. The certificate sending end then authenticates the certificate receiving end based on the matching of the target first photon arrangement position and the first photon arrangement position. The identity authentication method is that if the target first photon arrangement position is a subset of the first photon arrangement position, or if the target first photon arrangement position that does not correspond to the first photon arrangement position accounts for a proportion of less than a first preset proportion in all target first photon arrangement positions, then it is determined that the identity authentication is passed, and an identity authentication pass response is returned to the certificate receiving end. If the target first photon arrangement position is not a subset of the first photon arrangement position, or the proportion of the target first photon arrangement position that does not correspond to the first photon arrangement position is greater than or equal to the first preset proportion, then it is determined that the identity authentication has failed, the certificate issuance is abandoned, and an identity authentication failure response is returned to the certificate receiving end.

[0094] In one embodiment, when using this authentication method, the certificate receiving end may also include a first bit value measurement result corresponding to the target first photon arrangement position in the authentication request, so that the certificate sending end can further authenticate the certificate receiving end based on the matching of the first bit value measurement result corresponding to the target first photon arrangement position and the preset coding base corresponding to the target first photon arrangement position. When encoding and parsing the first photon based on the E91 protocol, valid measurement results must be consistent with the bit value corresponding to the preset coding base. The certificate sending end may determine the proportion of valid measurement results that do not match the bit value corresponding to the preset coding base among all valid measurement results. If this proportion is less than or equal to a second preset proportion, the certificate sending end may determine that the authentication is successful and return an authentication success response to the certificate receiving end. If the proportion is greater than the second preset proportion, the certificate sending end may determine that the authentication has failed, the certificate issuance is aborted, and an authentication failure response is returned to the certificate receiving end. It should be noted that the terms "first preset proportion" and "second preset proportion" are merely used to illustrate that the two preset proportions can be different (or the same). The specific values of these two preset proportions are not limited in this embodiment of the application.

[0095] Step 208: If the identity authentication is passed, obtain a second bit value measurement result from each bit value measurement result, and generate a key certificate based on each second bit value measurement result; the second bit value measurement result is the measurement result of each bit value measurement result except the first bit value measurement result.

[0096] In this embodiment of the present application, if the certificate receiving end receives a response confirming successful authentication, the certificate receiving end obtains the measurement results of the second bit value that is not located at the position of the first photon arrangement. These measurement results are used to generate the key certificate. Simultaneously, the certificate sending end also measures the other photon (hereinafter referred to as the third photon) in each entangled photon pair that remains at the certificate sending end, and generates the key certificate synchronously with the certificate receiving end.

[0097] When measuring the two photons in an entangled photon pair separately, if both measuring parties use the same measurement basis, the measurement results obtained by both parties should be consistent. The certificate sender and certificate receiver can agree on the measurement basis sequence to be used when measuring the second and third photons during the certificate issuance negotiation phase, so that the certificate sender and certificate receiver can use the same measurement basis to measure each second photon and each third photon. Furthermore, the certificate receiver can also send a portion of the second bit value measurement results and the photon arrangement position corresponding to the second bit value measurement results to the certificate sender via a traditional channel, so that the certificate sender can determine whether an eavesdropper has eavesdropped on the target photon stream by verifying whether the second bit value measurement results and the result obtained by the certificate sender when measuring the third photon at the photon arrangement position are the same. If it can be determined that there is no eavesdropper, the certificate sender and certificate receiver combine the second bit value measurement results other than the publicly available second bit value measurement results to form a key certificate.

[0098] Or as Figure 3 As shown, the certificate sender and certificate receiver may not agree on a measurement basis sequence in advance. Instead, after randomly selecting a measurement basis to measure the second and third photons, they exchange measurement basis sequences to determine which second bit value measurement results need to be retained as the key certificate. Specifically, the certificate receiver may generate the key certificate by: receiving a first measurement basis sequence sent by the certificate sender; obtaining a second measurement basis sequence corresponding to each second bit value measurement result; determining a target position sequence based on the first and second measurement basis sequences; and combining the second bit value measurement results corresponding to each target position sequence number to form the key certificate. The certificate sender may also generate the key certificate by: obtaining a first measurement basis sequence used when measuring each third photon; receiving a second measurement basis sequence sent by the certificate receiver; determining a target position sequence based on the first and second measurement basis sequences; and combining the second bit value measurement results corresponding to each target position sequence number to form the key certificate.

[0099] After the certificate sender passes identity verification and randomly selects a measurement basis to measure the third photon, it then sends the first measurement basis sequence used in the measurement to the certificate receiver. The certificate receiver also sends the second measurement basis sequence used when measuring photons that are not located in the arrangement position of the first photon to the certificate sender.

[0100] The certificate receiving end and the certificate sending end respectively compare the first measurement basis sequence and the second measurement basis sequence to determine which position numbers in the sequence correspond to the same measurement basis in the first measurement basis sequence and the second measurement basis sequence. These position numbers are used as target position numbers, and second bit value measurement results corresponding to the target position numbers are determined. The second bit value measurement results are combined to form a key certificate.

[0101] Alternatively, after determining the second bit value measurement results corresponding to the target position numbers, the certificate receiver can select a portion of these second bit value measurement results and send these second bit value measurement results, along with their corresponding target position numbers, to the certificate sender. The certificate sender can verify the consistency between the measurement results corresponding to the third photon at the target position numbers and the second bit value measurement results to determine whether there is an eavesdropper. If there is no eavesdropper, the certificate receiver and certificate sender combine the second bit value measurement results for the target position numbers other than the publicly disclosed target position numbers to form a key certificate.

[0102] After the key certificate is generated, the certificate receiver stores the key certificate in a secure storage area, and can subsequently use the key certificate to communicate with other devices through traditional channels.

[0103] The key certificate issuance method provided by the embodiment of the present application combines a plurality of modulated first photons and one photon of an entangled photon pair to form a target photon stream based on a preset first photon arrangement position. After measuring the target photon stream, the certificate receiving end determines the preset first photon arrangement position and performs identity authentication based on the first bit value measurement result located at the first photon arrangement position. If the identity authentication is successful, a key certificate is generated based on the second bit value measurement result not located above the first photon arrangement position. In the presence of an attacker, if the attacker adopts an attack strategy of impersonating the certificate receiving end and communicating with the certificate sending end, then because the attacker does not know the first photon arrangement position agreed upon by the certificate receiving end and the certificate sending end, the attacker cannot extract the correct first bit value measurement result to complete the identity authentication; if the attacker adopts a strategy of intercepting the target photon stream sent by the certificate sending end, then first, because the attacker does not know the first photon arrangement position, the attacker cannot extract the correct second bit value measurement result to generate the key certificate; at the same time, due to the characteristics of quantum communication, the attacker's measurement of the target photon stream will affect the polarization direction of the first photon and destroy the entangled state of the second photon, causing the certificate receiving end and the certificate sending end to detect the presence of the eavesdropper. Furthermore, because the embodiments of the present application use entangled photon pairs to generate key certificates, the certificate sender will not know the specific identity of the key certificate until the certificate receiver measures the second photon in the entangled photon pair. This also prevents attackers from obtaining the key certificate by attacking the certificate sender. Therefore, the method of the embodiments of the present application can improve the security of the key certificate issuance process.

[0104] In one embodiment, Figure 4 As shown, a key certificate issuance method is provided. In the embodiment of the present application, this method is applied to Figure 1 Taking the certificate sending end in as an example, the following steps are included:

[0105] Step 402: obtain multiple first photons based on preset coding base modulation, generate multiple entangled photon pairs, and arrange each first photon and the second photon in each entangled photon pair based on the preset first photon arrangement position to obtain a target photon stream; the second photon is any one photon in the entangled photon pair.

[0106] In an embodiment of the present application, when the certificate sender needs to issue a key certificate, it needs to generate a preset number of entangled photon pairs according to actual needs, select a photon from the entangled photon pair as the second photon, and arrange the first photons in a preset position. The multiple first photons obtained by modulation based on the preset coding base are inserted into the queue of the second photons to obtain the target photon stream.

[0107] The certificate sender can predetermine the preset length of the key certificate and, based on the key certificate generation method agreed upon by the certificate sender and the certificate receiver, estimate how many of the estimated number of second photons will not become part of the key certificate due to transmission loss, mismatched measurement basis selection, or eavesdropping detection, and then generate entangled photon pairs equal to the sum of the preset length and the estimated number. For example, if the certificate sender and the certificate receiver predetermine the measurement basis sequence used to measure entangled photon pairs and agree to disclose 100 second bit value measurement results to detect the presence of eavesdroppers, it can be determined that, ideally, all second bit value measurement results other than the disclosed second bit value measurement results will become part of the key certificate. Therefore, the certificate sender can calculate the sum of the preset length (e.g., 1024) and 100 (1124), and based on this value, determine an estimated transmission loss ratio (e.g., 10%), ultimately rounding the number of entangled photon pairs to be generated to 1249.

[0108] The certificate sending end can then determine the first photon arrangement position based on the number of entangled photon pairs and notify the certificate receiving end of the first photon arrangement position using the method described in the previous embodiment. After obtaining the first photon arrangement position, the certificate sending end further modulates the first photons to obtain the number of first photon arrangement positions. After arranging one photon from each entangled photon pair to form a queue, the certificate sending end inserts each first photon into the queue according to the first photon arrangement position, thereby obtaining the target photon stream.

[0109] Step 404, sending the target photon stream to the certificate receiving end;

[0110] Step 406: Receive an identity verification request sent by the certificate receiving end, and authenticate the certificate receiving end based on the identity verification request; the identity verification request is generated based on the first bit value measurement result, which is obtained by the certificate receiving end measuring each first target photon located at the first photon arrangement position in the target photon stream after determining the first photon arrangement position;

[0111] Step 408: If the identity authentication is passed, the third photon in each entangled photon pair is measured and processed to obtain a second bit value measurement result, and a key certificate is generated based on each second bit value measurement result; the third photon is the other photon in the entangled photon pair except the second photon.

[0112] Among them, the method of identity authentication and generating key certificates can be referred to the above embodiment, and the embodiment of this application will not be repeated. After generating the key certificate, the certificate sending end stores the key certificate in a secure storage area, and the certificate sending end can subsequently verify the authenticity of the key certificate of the certificate receiving end through the stored key certificate.

[0113] In one embodiment, each preset coding basis is a non-orthogonal coding basis, and the identity authentication request carries the target first photon arrangement position. Based on the first bit value measurement result corresponding to the target first photon arrangement position and the target measurement basis, the preset coding basis used when encoding the photons at the target first photon arrangement position can be determined;

[0114] Authenticate the certificate recipient based on the authentication request, including:

[0115] If the target first photon arrangement position is a subset of the first photon arrangement position, it is determined that the identity authentication is passed; or if the target first photon arrangement position is not a subset of the first photon arrangement position, it is determined that the identity authentication is failed.

[0116] In this embodiment of the present application, if the certificate sending end uses a non-orthogonal coding basis in the E91 protocol when encoding the first photon, the certificate sending end can determine whether the certificate receiving end knows the first photon arrangement position by verifying whether the target first photon arrangement position sent by the certificate receiving end is a subset of the first photon arrangement position, thereby determining whether the identity verification is successful. The specific identity verification steps can be found in the previous embodiment and will not be repeated in this embodiment of the present application.

[0117] In one embodiment, generating a key certificate based on each second bit value measurement result includes:

[0118] obtaining a first measurement basis sequence used when performing measurement processing on each third photon;

[0119] receiving a second measurement basis sequence sent by the certificate receiving end, where the second measurement basis sequence is a measurement basis sequence used by the certificate receiving end when measuring and processing each photon in the target photon stream that is not located at a position where the first photon is arranged;

[0120] A target position serial number is determined based on a first measurement basis sequence and a second measurement basis sequence, and second bit value measurement results corresponding to each target position serial number are combined to form a key certificate; wherein the target position serial number has the same measurement basis corresponding to it in the first measurement basis sequence and the second measurement basis sequence.

[0121] In the embodiment of the present application, when the identity authentication is passed, the certificate sending end measures the third photon left at the certificate sending end. The measurement basis sequence used in the measurement is the first measurement basis sequence. Then the certificate sending end and the certificate receiving end exchange the first measurement basis sequence and the second measurement basis sequence (the second measurement basis sequence is the measurement basis sequence used by the certificate receiving end when measuring each photon that is not located at the arrangement position of the first photon), and obtain the target position serial number by comparing the first measurement basis sequence and the second measurement basis sequence. Then, according to the pre-agreed key certificate generation method, a key certificate is generated based on the measurement result at the target position serial number. For the specific process, please refer to the aforementioned embodiments and Figure 3 As shown, the embodiments of this application are not described again.

[0122] The key certificate issuance method provided by the embodiment of the present application combines a plurality of modulated first photons and one photon of an entangled photon pair to form a target photon stream based on a preset first photon arrangement position. After measuring the target photon stream, the certificate receiving end determines the preset first photon arrangement position and performs identity authentication based on the first bit value measurement result located at the first photon arrangement position. If the identity authentication is successful, a key certificate is generated based on the second bit value measurement result not located above the first photon arrangement position. In the presence of an attacker, if the attacker adopts an attack strategy of impersonating the certificate receiving end and communicating with the certificate sending end, then because the attacker does not know the first photon arrangement position agreed upon by the certificate receiving end and the certificate sending end, the attacker cannot extract the correct first bit value measurement result to complete the identity authentication; if the attacker adopts a strategy of intercepting the target photon stream sent by the certificate sending end, then first, because the attacker does not know the first photon arrangement position, the attacker cannot extract the correct second bit value measurement result to generate the key certificate; at the same time, due to the characteristics of quantum communication, the attacker's measurement of the target photon stream will affect the polarization direction of the first photon and destroy the entangled state of the second photon, causing the certificate receiving end and the certificate sending end to detect the presence of the eavesdropper. Furthermore, because the embodiments of the present application use entangled photon pairs to generate key certificates, the certificate sender will not know the specific identity of the key certificate until the certificate receiver measures the second photon in the entangled photon pair. This also prevents attackers from obtaining the key certificate by attacking the certificate sender. Therefore, the method of the embodiments of the present application can improve the security of the key certificate issuance process.

[0123] In one embodiment, Figure 5 As shown, a key certificate issuance system is provided, which includes a certificate sending end and a certificate receiving end, wherein:

[0124] The certificate sending end is used to obtain multiple first photons based on a preset coding basis modulation, generate multiple entangled photon pairs, arrange each first photon and the second photon in each entangled photon pair based on a preset first photon arrangement position, obtain a target photon stream, and send the target photon stream to the certificate receiving end; the second photon is any photon in the entangled photon pair;

[0125] The certificate receiving end is configured to measure and process the target photon stream to obtain a bit value measurement result corresponding to each photon in the target photon stream, obtain a first bit value measurement result at the first photon arrangement position from each bit value measurement result, generate an identity authentication request based on each first bit value measurement result, and send the identity authentication request to the certificate sending end;

[0126] The certificate sending end is further used to authenticate the certificate receiving end based on the authentication request and send the authentication result to the certificate receiving end;

[0127] The certificate receiving end is further configured to obtain a second bit value measurement result that is not located at the first photon arrangement position when the identity authentication result indicates that the identity authentication is passed, and generate a key certificate based on each second bit value measurement result;

[0128] The certificate sending end is also used to measure and process the third photon in each entangled photon pair when the identity authentication result indicates that the identity authentication is passed, obtain a third bit value measurement result, and generate a key certificate based on each third bit value measurement result; the third photon is the other photon in the entangled photon pair except the second photon.

[0129] Among them, the specific steps performed by the certificate receiving end and the certificate sending end can be found in the aforementioned embodiments, and will not be repeated in the embodiments of this application.

[0130] The key certificate issuance system provided by the embodiment of the present application combines a plurality of modulated first photons and one photon of an entangled photon pair to form a target photon stream based on a preset first photon arrangement position. After measuring the target photon stream, the certificate receiving end determines the preset first photon arrangement position and performs identity authentication based on the first bit value measurement result located at the first photon arrangement position. If the identity authentication is successful, a key certificate is generated based on the second bit value measurement result not located above the first photon arrangement position. When there is an attacker, if the attacker adopts an attack strategy of impersonating the certificate receiving end and communicating with the certificate sending end, then because the attacker does not know the first photon arrangement position agreed upon by the certificate receiving end and the certificate sending end, the attacker cannot extract the correct first bit value measurement result to complete the identity authentication; if the attacker adopts a strategy of intercepting the target photon stream sent by the certificate sending end, then first, because the attacker does not know the first photon arrangement position, the attacker cannot extract the correct second bit value measurement result to generate the key certificate; at the same time, due to the characteristics of quantum communication, the attacker's measurement of the target photon stream will affect the polarization direction of the first photon and destroy the entangled state of the second photon, causing the certificate receiving end and the certificate sending end to detect the presence of the eavesdropper. Furthermore, because the embodiments of the present application use entangled photon pairs to generate key certificates, the certificate sender will not know the specific identity of the key certificate until the certificate receiver measures the second photon in the entangled photon pair. This also prevents attackers from obtaining the key certificate by attacking the certificate sender. Therefore, the method of the embodiments of the present application can improve the security of the key certificate issuance process.

[0131] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0132] Based on the same inventive concept, embodiments of the present application also provide a key certificate issuing device for implementing the key certificate issuing method described above. The implementation solution provided by this device is similar to the implementation solution described in the above method. Therefore, the specific limitations of one or more key certificate issuing device embodiments provided below can be found in the above-mentioned limitations of the key certificate issuing method and will not be repeated here.

[0133] In one embodiment, Figure 6 As shown, a key certificate issuing device 600 is provided, which is applied to a certificate receiving end and includes: a receiving module 602, a measuring module 604, a determining module 606, and a generating module 608, wherein:

[0134] A receiving module 602 is configured to receive a target photon stream sent by a certificate sending end, where the target photon stream consists of a plurality of first photons and a plurality of second photons, where the first photons are photons modulated by the certificate sending end based on a preset coding basis, and the second photon is one photon of an entangled photon pair;

[0135] A measurement module 604 is configured to perform measurement processing on the target photon flow to obtain a bit value measurement result corresponding to each photon in the target photon flow;

[0136] a determination module 606 configured to determine a preset first photon arrangement position, obtain a first bit value measurement result at the first photon arrangement position from each of the bit value measurement results, and perform identity authentication processing for the certificate receiving end based on each of the first bit value measurement results;

[0137] A generation module 608 is configured to, when identity authentication is passed, obtain a second bit value measurement result from each of the bit value measurement results, and generate a key certificate based on each of the second bit value measurement results; the second bit value measurement result is a measurement result in each of the bit value measurement results other than the first bit value measurement result.

[0138] In one embodiment, each of the preset coding bases is a non-orthogonal coding base, the bit value measurement result includes an invalid measurement result that does not correspond to a bit value and a valid measurement result that corresponds to a bit value, and the determining module 606 is further configured to:

[0139] Determining a target first photon arrangement position corresponding to a valid measurement result in each of the first bit value measurement results;

[0140] An identity authentication request is sent to the certificate sending end, where the identity authentication request includes the target first photon arrangement position, and the identity authentication request is used to instruct the certificate sending end to authenticate the certificate receiving end based on the matching of the target first photon arrangement position and the first photon arrangement position.

[0141] In one embodiment, the identity authentication request also includes a first bit value measurement result corresponding to the target first photon arrangement position, and the identity authentication request is also used to instruct the certificate sending end to authenticate the certificate receiving end based on the matching of the first bit value measurement result corresponding to the target first photon arrangement position and the preset coding base corresponding to the target first photon arrangement position.

[0142] In one embodiment, the generating module 608 is further configured to:

[0143] receiving a first measurement basis sequence sent by the certificate sending end, where the first measurement basis sequence is a measurement basis sequence used by the certificate sending end to measure each third photon when identity authentication is passed; the third photon is the other photon in the entangled photon pair except the second photon;

[0144] Obtain a second measurement basis sequence corresponding to each second bit value measurement result, determine a target position sequence number based on the first measurement basis sequence and the second measurement basis sequence, and combine the second bit value measurement results corresponding to each target position sequence number to form a key certificate; wherein the target position sequence number has the same measurement basis corresponding to it in the first measurement basis sequence and the second measurement basis sequence.

[0145] In one embodiment, Figure 7 As shown, a key certificate issuing device 700 is provided, which is applied to a certificate sending end and includes: a first generating module 702, a sending module 704, a receiving module 706, and a second generating module 708, wherein:

[0146] A first generating module 702 is configured to obtain a plurality of first photons based on a preset coding base modulation, generate a plurality of entangled photon pairs, and arrange each of the first photons and a second photon in each of the entangled photon pairs based on a preset arrangement position of the first photons to obtain a target photon stream; the second photon is any one photon in the entangled photon pair;

[0147] A sending module 704 is configured to send the target photon flow to a certificate receiving end;

[0148] a receiving module 706 configured to receive an identity authentication request sent by the certificate receiving end, and authenticate the certificate receiving end based on the identity authentication request; the identity authentication request is generated based on a first bit value measurement result, the first bit value measurement result being obtained by the certificate receiving end, after determining the first photon arrangement position, by measuring each first target photon located at the first photon arrangement position in the target photon stream;

[0149] The second generation module 708 is used to measure and process the third photon in each of the entangled photon pairs when the identity authentication is passed, obtain a second bit value measurement result, and generate a key certificate based on each of the second bit value measurement results; the third photon is the other photon in the entangled photon pair except the second photon.

[0150] In one embodiment, each of the preset coding bases is a non-orthogonal coding base, the identity authentication request carries a target first photon arrangement position, and the preset coding base used when encoding the photons at the target first photon arrangement position can be determined based on the first bit value measurement result corresponding to the target first photon arrangement position and the target measurement basis;

[0151] The receiving module 706 is further configured to:

[0152] If the target first photon arrangement position is a subset of the first photon arrangement position, it is determined that the identity authentication is passed; or if the target first photon arrangement position is not a subset of the first photon arrangement position, it is determined that the identity authentication is failed.

[0153] In one embodiment, the generating module 708 is further configured to:

[0154] Acquiring a first measurement basis sequence used when performing measurement processing on each of the third photons;

[0155] receiving a second measurement basis sequence sent by the certificate receiving end, where the second measurement basis sequence is a measurement basis sequence used by the certificate receiving end when measuring each photon in the target photon flow that is not located at an arrangement position of the first photons;

[0156] A target position number is determined based on the first measurement basis sequence and the second measurement basis sequence, and second bit value measurement results corresponding to each target position number are combined to form a key certificate; wherein the target position number has the same measurement basis corresponding to it in the first measurement basis sequence and the second measurement basis sequence.

[0157] The key certificate issuance device provided in the embodiment of the present application combines a plurality of modulated first photons and one photon of an entangled photon pair based on a preset first photon arrangement position to form a target photon stream. After measuring the target photon stream, the certificate receiving end determines the preset first photon arrangement position and performs identity authentication based on the first bit value measurement result located at the first photon arrangement position. If the identity authentication is successful, the key certificate is generated based on the second bit value measurement result not located above the first photon arrangement position. In the presence of an attacker, if the attacker adopts an attack strategy of impersonating the certificate receiving end and communicating with the certificate sending end, then because the attacker does not know the first photon arrangement position agreed upon by the certificate receiving end and the certificate sending end, the attacker cannot extract the correct first bit value measurement result to complete the identity authentication; if the attacker adopts a strategy of intercepting the target photon stream sent by the certificate sending end, first, because the attacker does not know the first photon arrangement position, the attacker cannot extract the correct second bit value measurement result to generate the key certificate; at the same time, due to the characteristics of quantum communication, the attacker's measurement of the target photon stream will affect the polarization direction of the first photon and destroy the entangled state of the second photon, causing the certificate receiving end and the certificate sending end to detect the presence of the eavesdropper. Furthermore, because the embodiments of the present application use entangled photon pairs to generate key certificates, the certificate sender will not know the specific identity of the key certificate until the certificate receiver measures the second photon in the entangled photon pair. This also prevents attackers from obtaining the key certificate by attacking the certificate sender. Therefore, the method of the embodiments of the present application can improve the security of the key certificate issuance process.

[0158] Each module in the above-mentioned apparatus may be implemented in whole or in part by software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in the form of hardware, or may be stored in a memory in the computer device in the form of software, so that the processor can call and execute the operations corresponding to each module.

[0159] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 8As shown. The computer device includes a processor, memory, and a network interface connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, it implements a key certificate issuance method.

[0160] Those skilled in the art will understand that Figure 8 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0161] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.

[0162] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0163] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.

[0164] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0165] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), data processing logic devices based on quantum computing, and the like.

[0166] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0167] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A key certificate issuance method, characterized in that: The method is applied to a certificate receiving end, and includes: Receive a target photon stream sent by a certificate sending end, where the target photon stream consists of a plurality of first photons and a plurality of second photons, where the first photons are photons modulated by the certificate sending end based on a preset coding basis, and the second photon is one photon of an entangled photon pair; Performing measurement processing on the target photon flow to obtain a bit value measurement result corresponding to each photon in the target photon flow; Determining a preset first photon arrangement position, obtaining a first bit value measurement result located at the first photon arrangement position from each of the bit value measurement results, and performing identity authentication processing for the certificate receiving end based on each of the first bit value measurement results; If the identity authentication is passed, a second bit value measurement result is obtained from each of the bit value measurement results, and a key certificate is generated based on each of the second bit value measurement results; the second bit value measurement result is a measurement result in each of the bit value measurement results except the first bit value measurement result.

2. The method according to claim 1, characterized in that Each of the preset coding bases is a non-orthogonal coding base, the bit value measurement results include invalid measurement results that do not correspond to bit values and valid measurement results that correspond to bit values, and performing identity authentication processing for the certificate receiving end based on each of the first bit value measurement results includes: Determining a target first photon arrangement position corresponding to a valid measurement result in each of the first bit value measurement results; An identity authentication request is sent to the certificate sending end, where the identity authentication request includes the target first photon arrangement position, and the identity authentication request is used to instruct the certificate sending end to authenticate the certificate receiving end based on the matching of the target first photon arrangement position and the first photon arrangement position.

3. The method according to claim 2, characterized in that The identity authentication request also includes a first bit value measurement result corresponding to the target first photon arrangement position, and the identity authentication request is also used to instruct the certificate sending end to authenticate the certificate receiving end based on the matching of the first bit value measurement result corresponding to the target first photon arrangement position and the preset coding base corresponding to the target first photon arrangement position.

4. The method according to claim 1, wherein The generating a key certificate based on each second bit value measurement result includes: receiving a first measurement basis sequence sent by the certificate sending end, where the first measurement basis sequence is a measurement basis sequence used by the certificate sending end to measure each third photon when identity authentication is passed; the third photon is the other photon in the entangled photon pair except the second photon; Obtain a second measurement basis sequence corresponding to each second bit value measurement result, determine a target position sequence number based on the first measurement basis sequence and the second measurement basis sequence, and combine the second bit value measurement results corresponding to each target position sequence number to form a key certificate; wherein the target position sequence number has the same measurement basis corresponding to it in the first measurement basis sequence and the second measurement basis sequence.

5. A key certificate issuance method, characterized in that: The method is applied to a certificate sending end, and includes: Modulating a preset coding basis to obtain a plurality of first photons, generating a plurality of entangled photon pairs, and arranging each of the first photons and a second photon in each of the entangled photon pairs based on a preset arrangement position of the first photons to obtain a target photon stream; the second photon being any one of the entangled photon pairs; Sending the target photon flow to a certificate receiving end; receiving an identity authentication request sent by the certificate receiving end, and authenticating the certificate receiving end based on the identity authentication request; wherein the identity authentication request is generated based on a first bit value measurement result, the first bit value measurement result being obtained by the certificate receiving end measuring each first target photon located at the first photon arrangement position in the target photon stream after determining the first photon arrangement position; If the identity authentication is passed, the third photon in each of the entangled photon pairs is measured and processed to obtain a second bit value measurement result, and a key certificate is generated based on each of the second bit value measurement results; the third photon is the other photon in the entangled photon pair except the second photon.

6. The method according to claim 5, characterized in that Each of the preset coding bases is a non-orthogonal coding base, the identity authentication request carries the target first photon arrangement position, and the preset coding base used when encoding the photons at the target first photon arrangement position can be determined based on the first bit value measurement result corresponding to the target first photon arrangement position and the target measurement basis; The authenticating the certificate receiving end based on the identity authentication request includes: If the target first photon arrangement position is a subset of the first photon arrangement position, it is determined that the identity authentication is passed; or if the target first photon arrangement position is not a subset of the first photon arrangement position, it is determined that the identity authentication is failed.

7. The method according to claim 5, characterized in that The generating a key certificate based on each second bit value measurement result includes: Acquiring a first measurement basis sequence used when performing measurement processing on each of the third photons; receiving a second measurement basis sequence sent by the certificate receiving end, where the second measurement basis sequence is a measurement basis sequence used by the certificate receiving end when measuring each photon in the target photon flow that is not located at an arrangement position of the first photons; A target position number is determined based on the first measurement basis sequence and the second measurement basis sequence, and second bit value measurement results corresponding to each target position number are combined to form a key certificate; wherein the target position number has the same measurement basis corresponding to it in the first measurement basis sequence and the second measurement basis sequence.

8. A key certificate issuance system, characterized in that: The system includes a certificate sending end and a certificate receiving end, wherein: The certificate sending end is used to obtain multiple first photons based on a preset coding basis modulation, generate multiple entangled photon pairs, arrange each of the first photons and the second photon in each of the entangled photon pairs based on a preset first photon arrangement position, obtain a target photon stream, and send the target photon stream to the certificate receiving end; the second photon is any one photon in the entangled photon pair; The certificate receiving end is configured to measure and process the target photon flow to obtain a bit value measurement result corresponding to each photon in the target photon flow, obtain a first bit value measurement result at the arrangement position of the first photon from each of the bit value measurement results, generate an identity authentication request based on each of the first bit value measurement results, and send the identity authentication request to the certificate sending end; The certificate sending end is further configured to authenticate the certificate receiving end based on the identity authentication request and send the identity authentication result to the certificate receiving end; The certificate receiving end is further configured to obtain, when the identity authentication result indicates that the identity authentication is passed, a second bit value measurement result that is not located at the first photon arrangement position, and generate a key certificate based on each second bit value measurement result; The certificate sending end is also used to measure and process the third photon in each of the entangled photon pairs when the identity authentication result indicates that the identity authentication is passed, obtain a third bit value measurement result, and generate a key certificate based on each of the third bit value measurement results; the third photon is the other photon in the entangled photon pair except the second photon.

9. A key certificate issuing device, characterized in that: The device is applied to a certificate receiving end, and includes: A receiving module is configured to receive a target photon stream sent by a certificate sending end, wherein the target photon stream is composed of a plurality of first photons and a plurality of second photons, wherein the first photons are photons modulated by the certificate sending end based on a preset coding basis, and the second photon is one photon of an entangled photon pair; a measurement module, configured to measure the target photon flow to obtain a bit value measurement result corresponding to each photon in the target photon flow; a determination module, configured to determine a preset first photon arrangement position, obtain a first bit value measurement result located at the first photon arrangement position from each of the bit value measurement results, and perform identity authentication processing for the certificate receiving end based on each of the first bit value measurement results; A generating module is configured to obtain, when identity authentication is passed, a second bit value measurement result from each of the bit value measurement results, and generate a key certificate based on each of the second bit value measurement results; the second bit value measurement result is a measurement result in each of the bit value measurement results other than the first bit value measurement result.

10. A key certificate issuing device, characterized in that: The device is applied to a certificate sending end, and includes: a first generating module, configured to obtain a plurality of first photons based on a preset coding base modulation, generate a plurality of entangled photon pairs, and arrange each of the first photons and a second photon in each of the entangled photon pairs based on a preset arrangement position of the first photons to obtain a target photon stream; the second photon is any one photon in the entangled photon pair; A sending module, configured to send the target photon flow to a certificate receiving end; a receiving module, configured to receive an identity authentication request sent by the certificate receiving end, and authenticate the certificate receiving end based on the identity authentication request; the identity authentication request is generated based on a first bit value measurement result, the first bit value measurement result being obtained by the certificate receiving end, after determining the first photon arrangement position, by measuring each first target photon located at the first photon arrangement position in the target photon stream; The second generation module is used to measure and process the third photon in each of the entangled photon pairs when the identity authentication is passed, obtain a second bit value measurement result, and generate a key certificate based on each of the second bit value measurement results; the third photon is the other photon in the entangled photon pair except the second photon.