Method and apparatus for multi-party information exchange based on ghz state and medium

By using the GHZ state particle exchange method, which utilizes a semi-trusted third party to prepare and measure GHZ state particles, we have achieved comprehensive fairness and security in multi-party information exchange. This solves the first-mover disadvantage in classical protocols and the threat of quantum computing, and provides a new approach to quantum-secure communication.

CN120639196BActive Publication Date: 2026-01-23TIBET UNIVERSITY FOR NATIONALITIES
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511056856.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2026-01-23
Estimated Expiration
2045-07-30

AI Technical Summary

Technical Problem

Existing classical fair exchange protocols are insufficient in terms of security and fairness, making it difficult to completely eliminate first-mover disadvantage and repudiation, and they are threatened by quantum computing. There is an urgent need for new quantum fair exchange protocols to achieve secure and fair exchange of information among multiple parties.

Method used

GHZ-state particles are used for multi-party information exchange. GHZ-state particles are prepared and distributed by a semi-trusted third party. After each party's user terminal applies the bit unitary operator, the measurement results are returned. The results are jointly measured and published, the encoding method is determined, the encoded particles are exchanged, and the hash value is calculated to confirm the successful information exchange.

Benefits of technology

It achieves comprehensive fairness in multi-party information exchange, ensuring equality among participants in terms of identity, information content, and exchange timing. It overcomes the first-mover disadvantage in classical protocols, improves efficiency and traceability, and possesses quantum security and engineering feasibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639196B_ABST
    Figure CN120639196B_ABST
Patent Text Reader

Abstract

The application discloses a multi-party information exchange method and device based on a GHZ state and a medium, and relates to the technical field of quantum communication. The method comprises the following steps: firstly, GHZ state particles are distributed through STTP, a bit unit operator is applied to the particles by a user, STTP jointly measures and publishes the result, and an auxiliary user determines the encoding mode; in the information exchange stage, the STTP prepares GHZ state particles again, the particles are encoded and exchanged according to the plaintext by the user, the operator is applied to the particles again and the particles are returned, the STTP jointly measures and publishes the result, and the user deduces the plaintext of the other party; finally, hash values are calculated and broadcasted by each party, and if the hash values are consistent, it is confirmed that the exchange is successful. The application relies on the non-local entanglement of the GHZ state, guarantees the fairness of the position, content and time, supports the integrated exchange of multiple users, and resists quantum and classical attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum communication technology, and more specifically, to a method, apparatus, and medium for multi-party information exchange based on GHZ states. Background Technology

[0002] With the rapid development of quantum information science, the fields of information security and communication are undergoing unprecedented changes. The fundamental principles of quantum mechanics, especially quantum entanglement and the no-cloning theorem, have laid a solid physical foundation for next-generation secure communication systems, driving rapid progress in cutting-edge technologies such as quantum cryptography and quantum key distribution. These breakthroughs provide entirely new approaches to solving traditional information security challenges and bring unprecedented opportunities for the innovative design of fundamental protocols such as fair exchange.

[0003] Fair exchange protocols, as fundamental security protocols in scenarios such as the digital economy, e-commerce, and financial settlement, aim to ensure the secure and fair exchange of information or digital assets between parties who do not trust each other. To achieve this goal, academia has proposed several classic fair exchange protocol models, including Incremental Release-Fraud (IR-FE), Online Trusted Third Party (Online-TTP-FE), Offline Trusted Third Party (Offline-TTP-FE), and Blockchain-based Fair Exchange (Blockchain-FE). These protocols are continuously being improved in theory and practice, greatly promoting the development of the field of information security. For example, the IR-FE model lowers the trust threshold through sharded sequential exchange, the TTP model introduces a third party to improve fairness, and blockchain solutions utilize smart contracts to achieve automated penalties and transparent execution.

[0004] However, with the continuous improvement of informatization and the booming development of the digital economy, the demand for secure and fair exchange is increasing across all sectors of society. Traditional fair exchange protocols have exposed a series of fundamental challenges in practical applications. First, most existing solutions rely on ex-post punishment mechanisms to deter dishonest behavior, but these mechanisms may fail when the value of the exchanged information significantly exceeds the cost of feasible punishment. Second, classic protocols struggle to completely eliminate the "first-mover disadvantage" dilemma, meaning that in a peer-to-peer exchange, one party must always release valuable information first, making absolute fairness difficult to achieve. Furthermore, with the development of emerging technologies such as quantum computing, classic protocols based on traditional cryptographic assumptions also face the risk of being compromised, and their security urgently needs further improvement.

[0005] In recent years, with the breakthrough of quantum communication and quantum computing technology, researchers have begun to explore the introduction of quantum mechanical properties into fair exchange protocols, trying to use the non-locality of quantum entanglement and the unclonability of measurement to build a physical level fair protection mechanism. Although the related research is still in its infancy, quantum fair exchange protocols show the potential to fundamentally eliminate first-mover disadvantages and denial of service, and are expected to break through the theoretical bottlenecks of the classical paradigm. However, the field still faces problems such as imperfect theoretical models, scarce practical protocols, and great difficulty in technical implementation, and further in-depth research and innovative exploration are urgently needed. SUMMARY

[0006] To solve the above technical problems, the present application provides a multi-party information exchange method and device based on GHZ state and medium.

[0007] To achieve the above purpose, the present application adopts the following technical solutions:

[0008] In a first aspect, the present application provides a multi-party information exchange method based on GHZ state, which comprises:

[0009] A semi-trusted third party prepares multiple pairs of GHZ state particles, and distributes each GHZ state particle to a multi-party user terminal according to the position; each party user terminal applies a bit unit operator to the received GHZ state particle and returns it to the semi-trusted third party, the semi-trusted third party jointly measures and publishes the measurement results to each party user terminal, and each party user terminal determines the encoding mode according to the measurement results;

[0010] The semi-trusted third party again prepares multiple pairs of GHZ state particles and distributes them to each party user terminal, each party user terminal respectively encodes the received GHZ state particles according to the corresponding plaintext information according to the determined encoding mode, exchanges the encoded particles in order, and sends them to the semi-trusted third party after applying the bit unit operator again; the semi-trusted third party jointly measures and publishes the results to each party user terminal, and the user terminal calculates the plaintext of other parties according to the results;

[0011] Each party user terminal calculates the hash value according to its own plaintext and the calculated plaintext of other parties, and broadcasts the hash value to other party user terminals, if the hash values calculated by all user terminals are equal, it is confirmed that the current round of information exchange is successful.

[0012] Further, the GHZ state particle is a multi-particle maximum entangled state, represented as:

[0013]

[0014] In the formula, n represents the number of entangled particles, |GHZ> n represents the GHZ entangled state composed of n particles, |0> and |1> represent the basic quantum state of a single quantum bit, Indicates the tensor product symbol;

[0015] The GHZ state particles include four expressions of the three-particle GHZ state:

[0016]

[0017] In the formula, and These represent four different three-qubit entangled states.

[0018] Furthermore, there are three user terminals: Alice, Bob, and Charlie.

[0019] Furthermore, multiple pairs of GHZ state particles are prepared through a semi-trusted third party, and each GHZ state particle is distributed to multiple user terminals according to its position. Each user terminal applies a bit unitary operator to the received GHZ state particles and returns the result to the semi-trusted third party. The semi-trusted third party jointly measures and publishes the measurement results to each user terminal. Each user terminal determines the encoding method based on the measurement results, including:

[0020] Forty pairs of entangled states were prepared by a semi-trusted third party. The GHZ state particles are extracted in order, and the particles in the first, second and third positions are extracted to form quantum sequences S1, S2 and S3 respectively. These sequences are then sent to users Alice, Bob and Charlie respectively through a quantum channel.

[0021] Users Alice, Bob, and Charlie randomly select bit unitary operators. Each quantum in quantum sequences S1, S2 and S3 is acted upon, and the resulting quantum sequence is returned to a semi-trusted third party.

[0022] A semi-trusted third party extracts particles at the same positions in the resulting quantum sequence, performs joint measurements, and then publishes the measurement results, which are derived from entangled states. Composed of elements in sequence;

[0023] Each user terminal appears in the measurement results The position determines the corresponding bit unitary operator In appearance When there are more than three positions, 3 bits of classic information are determined, and the encoding method for the current round of exchange is determined based on the classic information; if... If there are fewer than three locations, repeat the above steps until the location appears.

[0024] Furthermore, the encoding method is a defined mapping relationship f, expressed as:

[0025] f: f(K, M) = C

[0026] In the formula, f(K, M) represents the process and result of taking elements from the key set K and the plaintext set M as input, performing the mapping operation f, and outputting the ciphertext. C represents the ciphertext set. Let M represent different three-qubit entangled states at GHz, M represent the plaintext set, M = {m1, m2, ..., m8}, where m1, m2, and m8 represent the first, second, up to the eighth plaintext, respectively, and K represent the key set, K = {k1, k2, ..., k8}, where k1, k2, and k8 represent the first, second, up to the eighth key, respectively.

[0027] In the aforementioned encoding method, when the key is unknown, any plaintext has an equal probability of being mapped to any ciphertext, and any ciphertext has an equal probability of corresponding to any plaintext.

[0028] Furthermore, the semi-trusted third party prepares multiple pairs of GHZ-state particles and distributes them to each user terminal. Each user terminal encodes the received GHZ-state particles according to the corresponding plaintext information and a determined encoding method, exchanges the encoded particles in sequence, applies the bit unitary operator again, and sends them to the semi-trusted third party. The semi-trusted third party jointly measures and publishes the results to each user terminal. The user terminals calculate the plaintext from the other parties based on the results, including:

[0029] Forty pairs of entangled states were prepared by a semi-trusted third party. The GHZ state particles are extracted in order, and the particles in the first, second and third positions are extracted to form quantum sequences S1, S2 and S3 respectively. These sequences are then sent to user terminals Alice, Bob and Charlie respectively through a quantum channel.

[0030] On the user terminal Alice, Ua is applied to quantum sequence S1 to obtain quantum sequence S1'; on the user terminal Bob, Ub is applied to quantum sequence S2 to obtain quantum sequence S2'; on the user terminal Charlie, Uc is applied to quantum sequence S3 to obtain quantum sequence S3'; where Ua, Ub, and Uc are the quantum operator sequences of length n1 constructed by user terminals Alice, Bob, and Charlie according to their respective n1 bits of plaintext Pa, Pb, and Pc, and in accordance with the set correspondence.

[0031] Alice sends quantum sequence S1' to Bob; Bob sends quantum sequence S2' to Charlie; Charlie sends quantum sequence S3' to Alice.

[0032] On the user terminal Alice, Ua is applied to quantum sequence S3' to obtain quantum sequence S3"; on the user terminal Bob, Ub is applied to quantum sequence S1' to obtain quantum sequence S1"; on the user terminal Charlie, Uc is applied to quantum sequence S2' to obtain quantum sequence S2"; each user terminal sends its corresponding quantum sequence to a semi-trusted third party.

[0033] A semi-trusted third party extracts particles at the same position from the quantum sequences S1", S2", and S3" for joint measurement, and broadcasts the measurement results (Cabc) to all user terminals in sequence.

[0034] Each user terminal calculates the plaintext of the other party based on its own quantum operator sequence and the published measurement result Cabc; user terminal Alice calculates Pb' and Pc'; user terminal Bob calculates Pa' and Pc"; user terminal Charlie calculates Pa" and Pb"; Pa' and Pc' are the plaintexts of user terminals Bob and Charlie calculated by user terminal Alice, Pa' and Pc" are the plaintexts of user terminals Alice and Charlie calculated by user terminal Bob, and Pa" and Pb" are the plaintexts of user terminals Alice and Bob calculated by user terminal Charlie.

[0035] Furthermore, each user terminal calculates a hash value based on its own plaintext and the plaintext obtained from the other party, and broadcasts the hash value to the other user terminals. If the hash values ​​calculated by all user terminals are equal, the information exchange in the current round is confirmed to be successful, including:

[0036] Each user terminal calculates the hash value using the following formula:

[0037] Ca = HASH(Pa||Pb'||Pc'||sid)

[0038] Cb = HASH(Pa'||Pb||Pc"||sid)

[0039] Cc = HASH(Pa"||Pb"||Pc||sid)

[0040] In the formula, Ca, Cb and Cc are the hash values ​​calculated by users Alice, Bob and Charlie respectively, HASH is the cryptographic hash function, sid is the round number of the current fair exchange, and || is the data concatenation.

[0041] When Ca = Cb = Cc, the information exchange for the current round is confirmed to be successful.

[0042] Furthermore, the method also includes:

[0043] Each time a quantum sequence is transmitted in a quantum channel, both the sender and receiver will use decoy particles to perform an eavesdropping detection.

[0044] Secondly, the present invention provides a multi-party information exchange device based on GHZ state, the device comprising:

[0045] Multiple pairs of GHZ state particles are prepared by a semi-trusted third party, and each GHZ state particle is distributed to multiple user terminals according to its position. Each user terminal applies a bit unitary operator to the received GHZ state particles and returns the result to the semi-trusted third party. The semi-trusted third party jointly measures and publishes the measurement results to each user terminal. Each user terminal determines the encoding method based on the measurement results.

[0046] The semi-trusted third party prepares multiple pairs of GHZ state particles again and distributes them to the user terminals of each party. Each user terminal encodes the received GHZ state particles according to the corresponding plaintext information and the determined encoding method. The encoded particles are exchanged in sequence, and the bit unitary operator is applied again before being sent to the semi-trusted third party. The semi-trusted third party jointly measures and publishes the results to the user terminals of each party. The user terminals calculate and obtain the plaintext of the other parties based on the results.

[0047] Each user terminal calculates a hash value based on its own plaintext and the plaintext obtained from the other party, and broadcasts the hash value to the other user terminals. If the hash values ​​of all user terminals are equal, the information exchange in the current round is confirmed to be successful.

[0048] Thirdly, the present invention provides a readable storage medium storing one or more programs that can be executed by one or more processors to implement the method described above.

[0049] The present invention has at least the following beneficial effects:

[0050] 1. Theoretical Breakthrough and Cryptographic Modeling of GHZ States: This invention systematically elucidates for the first time why the indivisibility and global correlation of GHZ states can naturally achieve fair multi-party exchange, and uses cryptographic language to compare and model the physical characteristics of GHZ states with classical fair exchange protocols. The cooperative collapse mechanism of GHZ states is essentially equivalent to the "atomicity" and "synchronicity" in classical fair exchange, providing a theoretical basis for achieving complete fairness at the physical level.

[0051] 2. Multi-dimensional fairness guarantee: This invention achieves comprehensive fairness in terms of status, content and time among participants, ensuring that all users are completely equal in terms of identity, information content and exchange time, effectively overcoming the first-mover disadvantage and identity asymmetry problems in classic protocols.

[0052] 3. Efficient multi-user integrated exchange and identity verification: This invention supports multi-user integrated information exchange in a single round of operation (e.g., user A can obtain information from users B and C at once, user B obtains information from users A and C, and user C obtains information from users A and B). Furthermore, information ownership verification is naturally achieved through quantum encoding, eliminating the need to embed identifiers in the information, thus improving efficiency and traceability.

[0053] 4. Dedicated Coding and Mathematical Modeling: This invention proposes a dedicated quantum coding method by deriving the characteristics of the three-particle GHZ state, which transforms the problem of fair exchange among multiple parties into a discrimination problem, laying a solid theoretical foundation for the feasibility and verifiability of the protocol.

[0054] 5. Engineering feasibility and experimental verification: This invention has good engineering feasibility and can be directly verified on mainstream quantum platforms such as IBM, which promotes the practical implementation of quantum security protocols.

[0055] 6. Balancing Classical and Quantum Security: The protocol not only systematically analyzes its classical security but also comprehensively explores security safeguards against quantum attacks, including threats such as quantum eavesdropping, interference, and internal collusion, ensuring the protocol's completeness and robustness in a quantum environment.

[0056] In summary, this invention represents a significant breakthrough over traditional multi-party fair exchange schemes in terms of theoretical modeling, methodological design, and engineering implementation, providing a novel approach and technological foundation for quantum-secure communication and information security in the digital economy era. Attached Figure Description

[0057] Figure 1 An application scenario diagram based on existing technology is shown;

[0058] Figure 2 A flowchart of a multi-party information exchange method based on GHZ state according to an embodiment of the present invention is shown;

[0059] Figure 3 A data structure diagram is shown according to an embodiment of the present invention, obtained by selecting different measurement bases for particles at three positions in a three-particle GHZ state;

[0060] Figure 4 An embodiment of the present invention is shown. Figure 3 Data structure diagram obtained from interactive particle sequences;

[0061] Figure 5 A structural diagram of data 1 according to an embodiment of the present invention is shown;

[0062] Figure 6 A structural diagram of data 2 according to an embodiment of the present invention is shown;

[0063] Figure 7A structural diagram of data 3 according to an embodiment of the present invention is shown;

[0064] Figure 8 A structural diagram of data 4 according to an embodiment of the present invention is shown;

[0065] Figure 9 A structural diagram of data 5 according to an embodiment of the present invention is shown;

[0066] Figure 10 A structural diagram of data 6 according to an embodiment of the present invention is shown;

[0067] Figure 11 A structural diagram of data 7 according to an embodiment of the present invention is shown;

[0068] Figure 12 A structural diagram of data 8 according to an embodiment of the present invention is shown;

[0069] Figure 13 A structural diagram of a quantum circuit according to an embodiment of the present invention is shown;

[0070] Figure 14 A diagram showing the theoretical measurement results according to an embodiment of the present invention is provided.

[0071] Figure 15 A graph showing actual measurement results according to an embodiment of the present invention is provided.

[0072] Figure 16 A structural diagram of a multi-party information exchange device based on GHZ state according to an embodiment of the present invention is shown. Detailed Implementation

[0073] To enable those skilled in the art to better understand the technical solutions of the present invention, the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. The embodiments of the present invention will be further described in detail below with reference to the accompanying drawings and specific examples, but this is not intended to limit the present invention. If there is no necessary sequential relationship between the various steps described herein, the order in which they are described as examples should not be considered a limitation. Those skilled in the art should understand that the order can be adjusted, as long as it does not disrupt the logical consistency between them and render the entire process impossible.

[0074] The embodiments of the present invention first introduce the technologies that the present invention may rely on in its implementation.

[0075] 1. Quantum Key Distribution (QKD) – Focuses on eavesdropping detection.

[0076] QKD (Quantum Key Distribution) is the earliest technology to be practically applied in the field of quantum communication, with its core objective being the secure distribution of keys. Its security is based on the quantum no-cloning theorem of quantum mechanics, which effectively detects eavesdropping. Once eavesdropping is detected, the communicating parties can immediately terminate the session, thus ensuring the absolute security of the key.

[0077] 2. Quantum Teleportation (QT) – The Role of the Unitary Matrix.

[0078] Quantum teleportation allows a quantum state to be transferred from a sender to a receiver without directly transmitting qubits. This process relies on pre-shared entangled pairs and unitary matrix operations to precisely recover the quantum state. QT technology provides the foundation for the efficient and secure transfer of quantum information over long distances in quantum networks.

[0079] 3. Quantum Secure Direct Communication (QSDC) – Information Transfer.

[0080] QSDC goes beyond key distribution to achieve direct secure transmission of information. By sending confidential messages directly through quantum channels, and combining technologies such as quantum entanglement and single-photon transmission, it effectively prevents eavesdropping and tampering, achieving end-to-end information security. QSDC is suitable for multi-party scenarios with extremely high communication security requirements.

[0081] 4. Quantum Fair Exchange (QFE) – Information Fairness.

[0082] Quantum-based information exchange (QFE) focuses on fairness in the multi-party information exchange process, ensuring that all parties either receive information or none receive it during protocol execution, preventing unilateral gain or information asymmetry. QFE typically combines quantum entanglement and authentication mechanisms to enhance security and fairness in multi-party collaboration, representing an important development direction for quantum-safe protocols.

[0083] Example 1: A Multi-Party Information Exchange Method Based on GHZ State

[0084] Figure 1 This diagram illustrates an application scenario based on existing technology, such as... Figure 1 As shown, this application scenario includes a semi-trusted third-party STTP and multiple user terminals. The multiple user terminals are connected to each other and to the semi-trusted third-party STTP via signaling. In this embodiment, there are three examples of multiple user terminals: user terminal Alice, user terminal Bob, and user terminal Charlie.

[0085] based on Figure 1 The application scenarios shown are as follows: Figure 2 A flowchart of a multi-party information exchange method based on GHZ state according to an embodiment of the present invention is shown. The present invention provides a multi-party information exchange method based on GHZ state, such as... Figure 2As shown, the method includes the following steps S100-S300.

[0086] S100: Multiple pairs of GHZ state particles are prepared through a semi-trusted third party, and each GHZ state particle is distributed to multiple user terminals according to its position; each user terminal applies a bit unitary operator to the received GHZ state particles and returns the result to the semi-trusted third party; the semi-trusted third party jointly measures and publishes the measurement results to each user terminal; each user terminal determines the encoding method based on the measurement results.

[0087] In this embodiment, the GHZ state, namely the Greenberger-Horne-Zeilinger state, is a multi-particle maximally entangled state, and its form is as follows:

[0088]

[0089] Among them, |GHZ> n This represents a GHZ entangled state consisting of n particles, where |0> and |1> represent the fundamental quantum states of a single qubit. The symbol represents the tensor product, and n represents the number of entangled particles. Its most common form is the three-particle GHZ state; this embodiment uses four of its representations:

[0090]

[0091]

[0092] In the formula, and These represent four different three-qubit entangled states.

[0093] GHZ states possess the following characteristics: maximum entanglement, meaning all particles are nonlocally correlated, and the state of any one particle is closely related to the states of all other particles; symmetry, meaning permutation operations on particles do not alter the form of the GHZ state, making it suitable for multi-user symmetric communication; and measurement sensitivity, meaning that measuring any one particle affects the state of the entire system.

[0094] Single-qubit unitary operators for user-encoded classical information Defined as:

[0095] in, It is a unit operator. It is the Pauli-X operator: And it satisfies two properties:

[0096]

[0097] By selecting different measurement bases for particles at three positions in a three-particle GHZ state, the data obtained are as follows:Figure 3 As shown, the particle sequence was then swapped for further processing, and the resulting data is as follows. Figure 4 As shown.

[0098] In some embodiments, the construction principle of the encoding method is as follows:

[0099] On the user side, Alice, Bob, and Charlie construct quantum operator sequences Ua, Ub, and Uc of length n1 according to their respective n1-bit plaintexts Pa, Pb, and Pc, following the correspondence shown in Table 1.

[0100] Table 1. Correspondence between plaintext and quantum operator sequences

[0101]

[0102] The structures of data 0 to data 7 in Table 1 are as follows: Figures 5 to 12 As shown.

[0103] Let the plaintext set be M = {m1, m2, ..., m8}, where m1, m2, and m8 represent the first, second, and eighth plaintexts, respectively, and the ciphertext set be C = {|φ0>, |φ1>, |φ2>, |φ3>}. These represent different three-qubit entangled states at GHz. The key (encoding method) set is K = {k1, k2, ..., k8}, where k1, k2, and k8 represent the first, second, up to the eighth key, respectively. Each encoding method defines a mapping f: f(K, M) = C. Here, f(K, M) represents the operation process and result of taking elements from the key set K and the plaintext set M as input, performing operations on the mapping f, and outputting the ciphertext.

[0104] This encoding method has three features, namely feature 1, characteristic 2 and characteristic 3.

[0105] Characteristic 1: Uniformity and symmetry.

[0106] It ensures that all plaintext and ciphertext distributions are uniformly distributed, demonstrating good uniformity and symmetry.

[0107] For any plaintext m and any ciphertext c: Where p(C=c∣M=m) represents the probability that the ciphertext is c given that the plaintext is m.

[0108] For any ciphertext c: Where P(C=c) represents the probability that the ciphertext is c without considering other conditions such as plaintext.

[0109] Feature 2: Equal probability mapping between plaintext and ciphertext.

[0110] In the absence of a key, any plaintext has an equal probability of being mapped to any ciphertext. Similarly, any ciphertext has an equal probability of corresponding to any plaintext.

[0111] For any plaintext m and any ciphertext c:

[0112]

[0113] Where p(M=m∣C=c) represents the probability that the plaintext is m given that the ciphertext is c.

[0114] Feature 3: Unique decryption.

[0115] Suppose there are three clients: Alice, Bob, and Charlie, each possessing their own secret information, namely plaintext ma, mb, and mc, and each possessing a key k. After encryption, a unique ciphertext c is generated.

[0116] 1. Ciphertext generation: c = Ek(ma, mb, mc), where Ek represents the encryption function.

[0117] 2. Decryption process: For any party, such as user Alice, given the key k, Alice's plaintext ma, and ciphertext c, the plaintext of the other two parties can be calculated as follows: (mb,mc) = D(k,c,ma); (ma,mc) = D(k,c,mb); (ma,mb) = D(k,c,mc), where D(k,c,ma), D(k,c,mb), and D(k,c,mc) represent the decryption functions of the three users, and ma, mb, and mc represent the plaintext of users Alice, Bob, and Charlie, respectively.

[0118] In some embodiments, each time a quantum sequence is transmitted in a quantum channel, the sender and receiver will use decoy states to perform an eavesdropping detection to prevent potential external eavesdropping.

[0119] The purpose of step S100 is to determine the encoding method. In some embodiments, step S100 can be achieved by the following steps S101-S104.

[0120] S101: STTP preparation of 40 pairs in... The GHZ state particles are extracted bit by bit from the particles at positions 1, 2, and 3 to form quantum sequences S1, S2, and S3, which are then sent to the user terminals Alice, Bob, and Charlie respectively through a quantum channel.

[0121] S102: Alice, Bob, and Charlie are randomly selected on the user side. Each quantum in the quantum sequences S1, S2, and S3 is acted upon and then returned to STTP.

[0122] S103: STTP extracts particles at the same position in a quantum sequence, performs joint measurements, and then publishes the results. The measurement results are... It is composed of elements arranged in sequence.

[0123] S104: The user observed the following in the measurement results Determine the position of what you have in your hands This determined the classic 3-bit information, and based on this information, the encoding method for this exchange was determined. If at least 3 bits are not present... Then repeat steps S101-S104 until it appears.

[0124] S200: The semi-trusted third party prepares multiple pairs of GHZ state particles again and distributes them to the user terminals of each party. Each user terminal encodes the received GHZ state particles according to the corresponding plaintext information and the determined encoding method. The encoded particles are exchanged in sequence, and the bit unitary operator is applied again before being sent to the semi-trusted third party. The semi-trusted third party jointly measures and publishes the results to the user terminals of each party. The user terminals calculate and obtain the plaintext of the other parties based on the results.

[0125] Step S200 achieves fair exchange of user information. In some embodiments, step S200 can achieve fair exchange of user information through the following steps S201-S206:

[0126] Step 1: STTP preparation of multiple pairs in the state The GHZ state particles are extracted bit by bit from the particles at positions 1, 2, and 3 to form quantum sequences S1, S2, and S3, which are then sent to the user terminals Alice, Bob, and Charlie respectively through a quantum channel.

[0127] Step 2: On the user end, Alice, Bob, and Charlie encode their own plaintext information. Alice applies Ua to quantum sequence S1 to obtain quantum sequence S1'; Bob applies Ub to quantum sequence S2 to obtain quantum sequence S2'; and Charlie applies Uc to quantum sequence S3 to obtain quantum sequence S3'.

[0128] Step 3: Alice sends quantum sequence S1' to Bob; Bob sends quantum sequence S2' to Charlie; Charlie sends quantum sequence S3' to Alice.

[0129] Step 4: User Alice applies Ua to quantum sequence S3' to obtain quantum sequence S3"; user Bob applies Ub to quantum sequence S1' to obtain quantum sequence S1"; user Charlie applies Uc to quantum sequence S2' to obtain quantum sequence S2". These are then sent to STTP. Ua, Ub, and Uc represent the n1-bit plaintext Pa, Pb, and Pc sequences constructed by user Alice, user Bob, and user Charlie according to a predefined correspondence.

[0130] Step 5: STTP extracts particles at the same position from the quantum sequences S1", S2" and S3" for joint measurement, and publishes the measurement results (Cabc) sequentially via broadcast.

[0131] Step 6: User terminals Alice, Bob, and Charlie calculate the plaintext of the other parties based on their respective Ui and the published Cabc. Specifically, user terminal Alice calculates Pb' and Pc'; user terminal Bob calculates Pa' and Pc"; user terminal Charlie calculates Pa" and Pb"; Pa' and Pc' are the plaintexts of user terminals Bob and Charlie calculated by user terminal Alice, Pa' and Pc" are the plaintexts of user terminals Alice and Charlie calculated by user terminal Bob, and Pa" and Pb" are the plaintexts of user terminals Alice and Bob calculated by user terminal Charlie.

[0132] S300: Each user terminal calculates a hash value based on its own plaintext and the plaintext obtained from the other party, and broadcasts the hash value to the other user terminals. If the hash values ​​calculated by all user terminals are equal, the information exchange in the current round is confirmed to be successful.

[0133] The purpose of step S300 is to achieve consistency verification. In some embodiments, step S300 achieves consistency verification by means of:

[0134] Each user terminal calculates the hash value using the following formula:

[0135] Ca = HASH(Pa||Pb'||Pc'||sid)

[0136] Cb = HASH(Pa'||Pb||Pc"||sid)

[0137] Cc = HASH(Pa"||Pb"||Pc||sid)

[0138] In the formula, Ca, Cb and Cc are the hash values ​​calculated by users Alice, Bob and Charlie respectively, HASH is the cryptographic hash function, sid is the round number of the current fair exchange, and || is the data concatenation.

[0139] When Ca = Cb = Cc, the information exchange for the current round is confirmed to be successful.

[0140] The feasibility and advancement of this GHZ-based multi-party information exchange method will be analyzed from various perspectives through the following multiple embodiments.

[0141] Example 2: Encoding Method Analysis

[0142] This embodiment analyzes the coding method through probability analysis and effectiveness analysis.

[0143] Probability analysis. There are 3 users, each randomly selecting an operation. The particles are encoded. According to probability theory, this process follows a binomial distribution. (Single acquisition) The probability is p.

[0144]

[0145] If at least 3 of the n² joint measurements occur... If the probability is P(n²), then:

[0146]

[0147] in, Let P(n²) represent the number of combinations. When n = 40, P(n²) > 99.95%.

[0148] Validity analysis. When users randomly select... When three users choose the same... At that time, joint measurement results will inevitably appear When observed At that time, its position in the sequence can also be determined, meaning the user can know the position of the corresponding item in their hand. The specific location, thus further inferring the possession of other users. In turn, they obtained the secret information they possessed.

[0149] When 3 appear At this time, three users can share 3 bits of classic information. Based on this classic information, users can choose the encoding method for this round, preparing for subsequent fair exchange operations.

[0150] Example 3: Validity Analysis

[0151] Given the initial GHZ state:

[0152]

[0153] Apply the operator to each particle separately Obtaining the intermediate state

[0154]

[0155] The operators are applied to each particle again, but this time the order of application has changed. The operators are applied to particle 1. Acting on particle 2 Acting on particle 3 Obtain the final state

[0156]

[0157] Total operator It can be represented as the product of the operators in the second and first steps.

[0158]

[0159] Because operators act on different particles, they are reciprocal, and operators in the tensor product can be rearranged.

[0160]

[0161] Therefore, proving its validity is transformed into a discriminant problem, that is, in Hilbert space, given the initial state... Final state and any operator Can the other two operators be uniquely determined? The solution is expressed as:

[0162]

[0163] Suppose there exist two distinct combinations of operators such that both satisfy the following condition:

[0164] or

[0165] Since joint measurements do not consider global phase, this equation holds.

[0166]

[0167] Consider the following:

[0168]

[0169] Known It is reciprocal, therefore

[0170]

[0171] and

[0172]

[0173] but

[0174]

[0175] This contradicts the assumption, therefore the assumption is invalid, and the solution must be unique.

[0176] Example 4: Fairness Analysis

[0177] This embodiment analyzes the fairness of the method proposed in this invention from the perspectives of status fairness, content fairness, and time fairness.

[0178] Analysis of Status Fairness. In the method proposed in this invention, all users participate with equal roles and responsibilities at every stage of the agreement—including the determination of the encoding method, the exchange of information, and the consistency verification. Throughout the process, no participant has priority or special status. Therefore, the agreement, from a mechanism perspective, guarantees status fairness, ensuring that each user enjoys equal rights and influence throughout the entire process of agreement execution.

[0179] The principle of fairness requires that, assuming all participants are honest and adhere to the exchange, each party should be able to successfully obtain the other party's secret information at the end of the agreement. Conversely, if any participant fails to obtain useful information, then no party can obtain the secret information of others, thus ensuring the fairness of the exchange.

[0180] When the protocol is successfully executed—that is, when all participants honestly follow the protocol—the multi-particle GHZ state, as a maximally entangled state, ensures that the measurement of any single particle instantly affects the states of the remaining particles. According to the protocol design (characteristic 2), no user can obtain the exchanged information of other users before the joint measurement results are published. After the joint measurement results are broadcast (characteristic 3), combined with the aforementioned validity analysis, all users can deduce the secret information of other participants, thus achieving fair information exchange. This fairness is guaranteed by the physical properties of quantum entanglement itself, rather than relying on punitive mechanisms.

[0181] If the protocol fails to be completed, none of the participants will obtain useful information. In this invention, the participants' secret information is embedded in a three-particle entangled state, and no single particle can extract all the secret information (characteristic 2). During protocol execution, the entangled particle carrying the secret information needs to be transmitted to a semi-trusted third party (STTP), but in actual transmission, the protocol may be terminated due to link interruption or channel occupancy. Furthermore, based on the quantum properties of GHZ-state entangled particles, plaintext information cannot be extracted individually, effectively ensuring the requirement of content fairness in quantum fair exchange.

[0182] Temporal Fairness Analysis. Unlike traditional fair exchange protocols that rely on sequential operations to achieve temporal fairness, this invention utilizes quantum entanglement and a broadcast mechanism. The GHZ state ensures that the information of all participants exhibits high nonlocality during measurement; that is, measuring any particle instantly affects the state of other particles. Crucially, due to the encoding design (characteristic 3), no participant can unilaterally decode useful information. A semi-trusted third party (STTP) must be relied upon for synchronous measurement, and the measurement results are simultaneously broadcast to all users. Thus, before the joint measurement results are published, no user can obtain information from others, and the synchronous broadcast transmission of the measurement results ensures that all participants receive information at the same time. This mechanism effectively avoids the temporal unfairness problem caused by different transmission orders in the IR-FE model, eliminating any situation where one party is at a disadvantage due to being the first to send.

[0183] In summary, the GHZ-based multi-party information exchange method can effectively achieve time fairness, ensuring that all participants obtain information at the same time, thus eliminating the unfairness present in traditional information exchange.

[0184] Example 5: Security Analysis

[0185] This embodiment analyzes the security of the method proposed in this invention from several aspects, including leakage, eavesdropping detection, interception measurement attack, man-in-the-middle attack, entanglement attack central node analysis, and false signal attack.

[0186] The leakage is analyzed from two perspectives: information leakage due to encoding method and information leakage due to plaintext.

[0187] Encoding method information leakage

[0188] In this invention, the key collects one bit independently from each of the three participants each time, ultimately obtaining a random bit sequence of length 3. Since the collection process of each bit is completely independent and repeated, we only need to analyze the collection process of a single bit, and the conclusions can be directly generalized to the case of 3 bits.

[0189] Suppose three participants choose bits x1, x2, and x3, where each xi ∈ {0, 1}, i = 1, 2, 3, and all choices follow an independent and identically distributed Bernoulli distribution (with a probability of 0.5). A bit collected in that round is recorded as valid only if all three participants choose the same bit ((0, 0, 0) or (1, 1, 1)); otherwise, it is discarded. We are interested in how an external observer obtains information about this valid bit.

[0190] Before the data collection, the three individuals unanimously chose only two possibilities with equal probability: P(X=(0,0,0))=P(X=(1,1,1))=0.5. Therefore, the prior entropy H(x) of the unanimous choice among the three individuals is:

[0191]

[0192] In the formula, P(Xi) is the probability that the discrete random variable X takes the value Xi, and is the value of the probability mass function (for discrete random variables).

[0193] External observers can only confirm that all three players chose the same option in this round, but cannot distinguish whether it was all 0s or all 1s, that is:

[0194] I(x;C)=0

[0195] In the formula, I(x; C) represents the mutual information between random variable x and random variable C.

[0196] In summary, this invention does not leak information to external observers in the sense of information theory.

[0197] Plaintext information leakage. Because the encoding method is completely confidential to the eavesdropper, each ciphertext could potentially correspond to all eight possible plaintext bit combinations from the eavesdropper's perspective. In this case, the posterior distribution of the plaintext is uniform, and the conditional entropy p(plaintext|ciphertext) = 3H(plaintext|ciphertext) = 3 (bits), reaching maximum information entropy and fully guaranteeing the protocol's security. According to the scheme design, non-participants, including STTP, can only obtain the joint measurement result sequence. Information theory analysis reveals the conditional probability for each case.

[0198] Let the plaintext bit combination be M, and the ciphertext be C. For an eavesdropper, given the ciphertext C, the posterior distribution of the plaintext M is uniform:

[0199]

[0200] Therefore, the conditional entropy H(M|C) of the ciphertext is:

[0201]

[0202] In the formula, P(M i |C) represents the conditional probability, indicating that given ciphertext C, the plaintext M is... i The probability, M i Let i be the i-th plaintext element in the plaintext set.

[0203] Information entropy of plaintext:

[0204]

[0205] I(M;C)=H(A)-H(A|E)=0

[0206] In the formula, H(M) is the information entropy of the plaintext, and P(M) is the information entropy of the plaintext. i ) is plaintext M i The prior probability of occurrence, I(M;C) is the mutual information between plaintext M and ciphertext C, H(A) is the information entropy of variable A, and H(A|E) is the conditional entropy, where E is the conditional variable.

[0207] Therefore, the technical solution adopted in this invention will not lead to information leakage.

[0208] Eavesdropping detection:

[0209] Throughout the operation of the method proposed in this invention, whenever the quantum sequence is transmitted through the quantum channel, decoy particles prepared from Z-based and X-based materials are randomly inserted. These particles are distributed at random positions within the quantum sequence. Since the eavesdropper cannot predict the specific positions and preparation bases of the decoy particles, any eavesdropping on the quantum sequence will inevitably introduce abnormal perturbations. When the user and a trusted third party (STTP) conduct collaborative detection, the bit error rate of the decoy particles will be found to be significantly higher than in the case without eavesdropping, thus effectively identifying the eavesdropping behavior and immediately terminating the protocol. Therefore, the eavesdropper (Eve) cannot obtain any useful information, and the security of the protocol is guaranteed.

[0210] Intercepting measurement attacks:

[0211] Even if an eavesdropper (Eve) persists in stealing a user's secret information despite being detected, they might attempt to directly intercept and measure one or more quantum sequences containing the secret information. However, the superposition property of particles in the GHZ state dictates that Eve cannot obtain meaningful information even using single-particle measurements. If Eve attempts to perform joint measurements on multiple particles, since they do not possess the key and the protocol design ensures the joint measurement results exhibit symmetry (see Feature 1), Eve still cannot deduce valid secret information from the measurement results. Therefore, this invention effectively resists interception measurement attacks and prevents information leakage.

[0212] Man-in-the-middle attack:

[0213] To prevent man-in-the-middle attacks, Eve might attempt to replace the original quantum sequence with entangled particles she prepares herself, thus stealing information from both communicating parties. However, because decoy particles are inserted at random positions in the quantum sequence in this invention, and Eve cannot know the specific positions of these particles or their preparation basis, she can only randomly select a basis for measurement. According to the quantum no-cloning theorem, when Eve selects an incorrect basis to measure the decoy particle, its state collapses, leading to an increase in the decoy particle's bit error rate. Once this bit error rate exceeds a set threshold, STTP and the user can detect the anomaly and terminate communication in time. Therefore, this invention effectively prevents man-in-the-middle attacks and ensures communication security.

[0214] Entanglement attack:

[0215] Suppose Eve introduces her own auxiliary particle |e> to each particle, and performs a joint unitary operation on each pair of particles (denoted as...). This makes the entire system a larger Hilbert space. The matrix representation is as follows:

[0216]

[0217] in a, b, a', b' are complex coefficients that satisfy the normalization condition:

[0218] |a| 2 +|b| 2 =1

[0219] |a'| 2 +|b'| 2 =1

[0220] ab * =(a') * b'

[0221] Where b * Let (a') be the conjugate of the complex number b. * is the conjugate of the complex coefficient a'.

[0222] Eve's operation on the decoy particle can then be written as:

[0223]

[0224] Where |e 00 >,|e 01 >,|e 10 >,|e 11 For the orthogonal states of Eve's auxiliary particles, in order to ensure the probability conservation of the entire system, these orthogonal states of auxiliary particles must satisfy the normalization condition:

[0225]

[0226] Among them, e α,β Let α and β be the quantum states of the Eve auxiliary particle, where α and β are index parameters for the quantum state labeling.

[0227] Based on the derivation, we can obtain:

[0228] |a| 2 =|a'| 2 ,|b| 2 =|b'| 2

[0229] During the eavesdropping detection process, Eve's interference will inevitably introduce errors, therefore the probability that Eve will be detected is:

[0230] P = |b| 2 =1-|a| 2 =|b'| 2 =1-|a'| 2

[0231] When no errors are introduced, the signal particle and Eve's auxiliary particle can only be in a direct product state. A direct product state means there is no correlation between the signal particle and the auxiliary particle, therefore Eve cannot obtain any useful information.

[0232] Central node analysis:

[0233] In this invention, the STTP (semi-trusted third party) is primarily responsible for the preparation of initial entangled particles, detection of eavesdropping in the channel, joint measurement, and result publication. Although the STTP undertakes these crucial steps, it never directly accesses the key or plaintext information throughout the entire process, whether in the key distribution phase or the subsequent information transmission phase.

[0234] Therefore, STTP's role is essentially equivalent to that of an external eavesdropper. Without the key k or the plaintext content, even if it participates in all operations, it cannot obtain any useful information. Based on the foregoing analysis, the scheme ensures that, under the semi-trusted model, the information security of both communicating parties is unaffected by STTP.

[0235] False signal attack:

[0236] In spoofing attacks, STTP may attempt to disrupt information exchange between users by publishing false ciphertext or preparing an incorrect initial state. However, this invention introduces a consistency detection mechanism: all users sequentially concatenate their plaintext information and exchange round number, calculate the hash value, and broadcast it.

[0237] Due to the irreversibility and uniqueness of hash functions, if either party's input is different, the output hash value will inevitably be different. Thus, any spoofing behavior in STTP will cause inconsistent hash values ​​among the parties, allowing for timely detection. Therefore, this invention can effectively resist spoofing attacks and ensure communication reliability.

[0238] Example 6: Performance Analysis

[0239] This embodiment analyzes the performance of the method proposed in this invention from two aspects: transmission efficiency analysis and coding efficiency analysis.

[0240] Transmission efficiency analysis:

[0241] Without considering decoy particles and key transmission, from an information theory perspective, transmission efficiency can be used to measure the information utilization of a quantum cryptography scheme. Transmission efficiency is defined as the ratio of the number of useful information bits actually exchanged between the communicating parties to the total number of bits consumed during communication (including qubits and classical bits). For the method proposed in this invention, the number of useful information bits b... s =2, number of qubits q t =2, classic number of bits b t =2, therefore the transmission efficiency ξ is:

[0242]

[0243] This indicates that under this protocol, for every 4 bits transmitted (including quantum and classical), 2 bits are valid information, demonstrating a high information utilization rate.

[0244] Coding efficiency analysis:

[0245] Encoding efficiency refers to the ratio of the number of useful information bits actually transmitted to the number of qubits consumed in quantum communication. This indicator reflects the efficiency of quantum resource utilization. For the method proposed in this invention, the number of information bits exchanged by the communicating parties, b... s =2, the number of qubits in the communication process is n=2, therefore the coding efficiency is:

[0246]

[0247] This demonstrates that each quantum bit is fully utilized for information transmission, achieving optimal encoding efficiency. In summary, the method proposed in this invention exhibits excellent performance in both transmission and encoding efficiency, and possesses significant practical application value.

[0248] Example 7: Experiment

[0249] Based on the GHZ-based multi-party information exchange method proposed in Example 1, experiments were conducted using an Ibm-Sherbrooke quantum computer. One Ibm-Sherbrooke quantum computer was configured at each of the semi-trusted third party and the multiple user terminals. The Ibm-Sherbrooke quantum computer can be based on, as described in Example 1... Figure 13 The quantum circuit shown is used to conduct a multi-party exchange experiment. Figure 13 In this circuit, q[0], q[1], and q[2] represent three qubits, which are carriers of quantum information and can be in the states of |0>, |1>, or superposition. c3 represents a classical register (3 bits) used to store the measurement results of the qubits (recorded after the quantum state collapses into classical 0 / 1). This quantum circuit can realize GHZ state preparation, unitary operator encoding, joint measurement, and hash consistency verification. Among them, GHZ state preparation can be achieved by H gate 1301, first CNOT gate 1302, and second CNOT gate 1303. First CNOT gate 1302 and second CNOT gate 1303 refer to controlled NOT gates. Unitary operator encoding can be achieved by RX gate 1304 and I gate 1305. Joint measurement and hash consistency verification can be achieved by RZ gate 1306 and measurement gate 1307. H gate 1301 changes q[0] from |0> to a superposition state, preparing for entanglement. q[1] corresponds to the control bit q[0] of the first CNOT gate 1302, the target bit q[1]. If q[0] = |1>, flip the state of q[1]. If q[0] = |0>, q[1] remains unchanged. The control bit q[0] and target bit q[2] of the second CNOT gate 1303 corresponding to q[2] are logically the same as the CNOT of q[1], realizing the entanglement of q[0] and q[2]. The three bits form a GHZ state, that is state.

[0250] based on Figure 13 Experiments were conducted on quantum circuits, and the theoretical predictions and actual results are as follows: Figure 14 and Figure 15 As shown. Figure 14 In the graph, the vertical axis (Probability of the states) represents the probability of a quantum state occurring, ranging from 0 to 100, measuring the likelihood of each computational ground state being observed. The horizontal axis (Computational basis states) lists eight computational ground states, corresponding to all possible states of a three-qubit system (represented by three binary digits 000-111), representing the classical states the quantum system can collapse into. The graph shows that states 011 and 100 have probability values, indicating that after evolution / measurement, the quantum system primarily exhibits these two computational ground states, with other ground states having probabilities close to 0, reflecting the probability distribution characteristics of quantum states under computational basis.

[0251] Figure 15 In the diagram, the horizontal axis is labeled Computational basis states, listing the computational basis states (represented by three binary digits) of a three-qubit system, such as 000, 001, 010, 011, 100, 101, 110, and 111, corresponding to the classical states that the quantum system may collapse into. The vertical axis is labeled Probability, representing the probability of each computational basis state being observed, measuring the likelihood of a quantum state occurring. The diagram includes bars corresponding to the 011 and 100 states, indicating that after evolution / measurement, the quantum system primarily exhibits these two computational basis states, with other basis states having probabilities close to 0, reflecting the probability distribution characteristics of quantum states under computational basis.

[0252] contrast Figure 14 and Figure 15 It can be seen that the probability of the target states (011, 100) in the theoretical graph is concentrated, and the histogram is highly regular, representing the high purity of the ideal quantum state (the quantum state is free of strays and fully conforms to the theoretical design). In the actual graph, the probability of the target state still dominates, but other ground states have a weak distribution, reflecting the purity loss of the actual quantum state. This is because it is difficult for the quantum state to be completely isolated from environmental interference in the experiment, resulting in the diffusion of the probability distribution and the appearance of small results outside the theory. However, the target state is still the main result, which is in line with the theoretical expectation, proving the applicability of the theoretical model in real-world scenarios.

[0253] Example 8: A multi-party information exchange device based on GHZ state

[0254] This invention also provides a multi-party information exchange device based on GHZ state, such as... Figure 16 As shown, the device includes a first terminal 1601 and a plurality of second terminals 1602, wherein the first terminal 1601 serves as a semi-trusted third party and the plurality of second terminals 1602 serve as multiple user terminals.

[0255] Multiple pairs of GHZ state particles are prepared by a semi-trusted third party, and each GHZ state particle is distributed to multiple user terminals according to its position. Each user terminal applies a bit unitary operator to the received GHZ state particles and returns the result to the semi-trusted third party. The semi-trusted third party jointly measures and publishes the measurement results to each user terminal. Each user terminal determines the encoding method based on the measurement results.

[0256] The semi-trusted third party prepares multiple pairs of GHZ state particles again and distributes them to the user terminals of each party. Each user terminal encodes the received GHZ state particles according to the corresponding plaintext information and the determined encoding method. The encoded particles are exchanged in sequence, and the bit unitary operator is applied again before being sent to the semi-trusted third party. The semi-trusted third party jointly measures and publishes the results to the user terminals of each party. The user terminals calculate and obtain the plaintext of the other parties based on the results.

[0257] Each user terminal calculates a hash value based on its own plaintext and the plaintext obtained from the other party, and broadcasts the hash value to the other user terminals. If the hash values ​​of all user terminals are equal, the information exchange in the current round is confirmed to be successful.

[0258] It should be noted that the structures of the various GHZ-based multi-party information exchange devices described in this embodiment belong to the same technical concept as the previously described GHZ-based multi-party information exchange methods, achieving the same beneficial effects through the same principles, and will not be elaborated here.

[0259] Example 9: Readable storage medium

[0260] This invention also provides a readable storage medium storing one or more programs that can be executed by one or more processors to implement the methods described in any of the above embodiments.

[0261] The above embodiments are only used to illustrate the present invention and are not intended to limit the present invention. Those skilled in the art can make various changes and modifications without departing from the spirit and scope of the present invention. Therefore, all equivalent technical solutions also fall within the scope of the present invention, and the patent protection scope of the present invention should be defined by the claims.

Claims

1. A method for multi-party information exchange based on GHZ state, characterized in that, The method includes: Multiple pairs of GHZ state particles are prepared by a semi-trusted third party, and each GHZ state particle is distributed to multiple user terminals according to its position. Each user terminal applies a bit unitary operator to the received GHZ state particles and returns the result to the semi-trusted third party. The semi-trusted third party jointly measures and publishes the measurement results to each user terminal. Each user terminal determines the encoding method based on the measurement results. The semi-trusted third party prepares multiple pairs of GHZ state particles again and distributes them to the user terminals of each party. Each user terminal encodes the received GHZ state particles according to the corresponding plaintext information and the determined encoding method. The encoded particles are exchanged in sequence, and the bit unitary operator is applied again before being sent to the semi-trusted third party. The semi-trusted third party jointly measures and publishes the results to the user terminals of each party. The user terminals calculate and obtain the plaintext of the other parties based on the results. Each user terminal calculates a hash value based on its own plaintext and the plaintext obtained from the other party, and broadcasts the hash value to the other user terminals. If the hash values ​​calculated by all user terminals are equal, the information exchange in the current round is confirmed to be successful. The GHZ state particle is a multi-particle maximally entangled state, represented as: In the formula, n represents the number of entangled particles, |GHZ> n This represents a GHZ entangled state consisting of n particles, where |0> and |1> represent the fundamental quantum states of a single qubit. Indicates the tensor product symbol; The GHZ state particles include four expressions of the three-particle GHZ state: In the formula, and These represent four different three-qubit entangled states; The parties involved consist of three user terminals: Alice, Bob, and Charlie. Multiple pairs of GHZ state particles are prepared through a semi-trusted third party, and each GHZ state particle is distributed to multiple user terminals according to its position. Each user terminal applies a bit unitary operator to the received GHZ state particles and returns the result to the semi-trusted third party. The semi-trusted third party jointly measures and publishes the measurement results to each user terminal. Each user terminal determines the encoding method based on the measurement results, including: Semi-trusted third-party preparation pairs in entangled states The GHZ state particles are extracted in order, and the particles in the first, second and third positions are extracted to form quantum sequences S1, S2 and S3 respectively. These sequences are then sent to user terminals Alice, Bob and Charlie respectively through a quantum channel. Users Alice, Bob, and Charlie randomly select bit unitary operators. Each quantum in quantum sequences S1, S2 and S3 is acted upon, and the resulting quantum sequence is returned to a semi-trusted third party. A semi-trusted third party extracts particles at the same positions in the resulting quantum sequence, performs joint measurements, and then publishes the measurement results, which are derived from entangled states. Composed of elements in sequence; Each user terminal appears in the measurement results The position determines the corresponding bit unitary operator In appearance When there are more than three positions, 3 bits of classic information are determined, and the encoding method for the current round of exchange is determined based on the classic information; if... If there are fewer than three locations, repeat the above steps until the location appears.

2. The multi-party information exchange method based on GHZ state according to claim 1, characterized in that, The encoding method is a defined mapping relationship f, expressed as: f: f(K, M) = C In the formula, f(K, M) represents the process and result of taking elements from the key set K and the plaintext set M as input, performing the mapping operation f, and outputting the ciphertext. C represents the ciphertext set. These represent different three-qubit entangled states at GHz, M represents the plaintext set, M = {m1, m2, ..., m8}, where m1, m2, and m8 represent the first, second, up to the eighth plaintext respectively, and K represents the key set, K = {k1, k2, ..., k8}, where k1, k2, and k8 represent the first, second, up to the eighth key respectively; In the aforementioned encoding method, when the key is unknown, any plaintext has an equal probability of being mapped to any ciphertext, and any ciphertext has an equal probability of corresponding to any plaintext.

3. The multi-party information exchange method based on GHZ state according to claim 2, characterized in that, The semi-trusted third party prepares multiple pairs of GHZ state particles again and distributes them to the user terminals of each party. Each user terminal encodes the received GHZ state particles according to the corresponding plaintext information and the determined encoding method. The encoded particles are exchanged in order, and the bit unitary operator is applied again before being sent to the semi-trusted third party. The semi-trusted third party jointly conducts measurements and publishes the results to all user terminals. The user terminals calculate and obtain the plaintext from other parties based on the results, including: Semi-trusted third-party preparation pairs in entangled states The GHZ state particles are extracted in order, and the particles in the first, second and third positions are extracted to form quantum sequences S1, S2 and S3 respectively. These sequences are then sent to user terminals Alice, Bob and Charlie respectively through a quantum channel. On the user terminal Alice, Ua is applied to quantum sequence S1 to obtain quantum sequence S1'; on the user terminal Bob, Ub is applied to quantum sequence S2 to obtain quantum sequence S2'; on the user terminal Charlie, Uc is applied to quantum sequence S3 to obtain quantum sequence S3'; where Ua, Ub, and Uc are the quantum operator sequences of length n1 constructed by user terminals Alice, Bob, and Charlie according to their respective n1 bits of plaintext Pa, Pb, and Pc, and in accordance with the set correspondence. Alice sends quantum sequence S1' to Bob; Bob sends quantum sequence S2' to Charlie; Charlie sends quantum sequence S3' to Alice. On the user terminal Alice, Ua is applied to quantum sequence S3' to obtain quantum sequence S3"; on the user terminal Bob, Ub is applied to quantum sequence S1' to obtain quantum sequence S1"; on the user terminal Charlie, Uc is applied to quantum sequence S2' to obtain quantum sequence S2"; each user terminal sends its corresponding quantum sequence to a semi-trusted third party. A semi-trusted third party extracts particles at the same position from quantum sequences S1", S2", and S3" for joint measurement, and broadcasts the measurement results (Cabc) to all user terminals in sequence. Each user terminal calculates the plaintext of the other party based on its own quantum operator sequence and the published measurement result Cabc; user terminal Alice calculates Pb' and Pc'; user terminal Bob calculates Pa' and Pc"; user terminal Charlie calculates Pa" and Pb"; Pa' and Pc' are the plaintexts of user terminals Bob and Charlie calculated by user terminal Alice, Pa' and Pc" are the plaintexts of user terminals Alice and Charlie calculated by user terminal Bob, and Pa" and Pb" are the plaintexts of user terminals Alice and Bob calculated by user terminal Charlie.

4. The multi-party information exchange method based on GHZ state according to claim 3, characterized in that, Each user terminal calculates a hash value based on its own plaintext and the plaintext obtained from the other party, and broadcasts the hash value to the other user terminals. If the hash values ​​calculated by all user terminals are equal, the information exchange in the current round is confirmed to be successful, including: Each user terminal calculates the hash value using the following formula: Ca = HASH(Pa||Pb'||Pc'||sid) Cb = HASH(Pa'||Pb||Pc"||sid) Cc = HASH(Pa"||Pb"||Pc||sid) In the formula, Ca, Cb and Cc are the hash values ​​calculated by users Alice, Bob and Charlie respectively, HASH is the cryptographic hash function, sid is the round number of the current fair exchange, and || is the data concatenation. When Ca = Cb = Cc, the information exchange for the current round is confirmed to be successful.

5. The multi-party information exchange method based on GHZ state according to any one of claims 1 to 4, characterized in that, The method further includes: Each time a quantum sequence is transmitted in a quantum channel, both the sender and receiver will use decoy particles to perform an eavesdropping detection.

6. A multi-party information exchange device based on GHZ state, characterized in that, For performing the method as described in any one of claims 1 to 5, the apparatus includes a first terminal and a plurality of second terminals, wherein the first terminal serves as a semi-trusted third party and the plurality of second terminals serve as multiple user terminals; Multiple pairs of GHZ state particles are prepared by a semi-trusted third party, and each GHZ state particle is distributed to multiple user terminals according to its position. Each user terminal applies a bit unitary operator to the received GHZ state particles and returns the result to the semi-trusted third party. The semi-trusted third party jointly measures and publishes the measurement results to each user terminal. Each user terminal determines the encoding method based on the measurement results. The semi-trusted third party prepares multiple pairs of GHZ state particles again and distributes them to the user terminals of each party. Each user terminal encodes the received GHZ state particles according to the corresponding plaintext information and the determined encoding method. The encoded particles are exchanged in order, and the bit unitary operator is applied again before being sent to the semi-trusted third party. The semi-trusted third party jointly conducts the measurement and publishes the results to the user terminals of all parties. The user terminals calculate and obtain the plaintext from the other parties based on the results. Each user terminal calculates a hash value based on its own plaintext and the plaintext obtained from the other party, and broadcasts the hash value to the other user terminals. If the hash values ​​of all user terminals are equal, the information exchange in the current round is confirmed to be successful.

7. A non-transitory computer-readable storage medium storing instructions, characterized in that, When the instructions are executed by the processor, the method according to any one of claims 1 to 5 is performed.

Citation Information

Patent Citations

  • Quantum steganography protocol based on gigahertz (GHZ) state dense coding and entanglement exchange

    CN102801518A

  • Single-state three-party semi-quantum key agreement method based on three-particle GHZ entangled state

    CN114285553A