A quantum-safe multi-party computation method with hybrid topology
By employing a hybrid topology in a quantum-safe multi-party computation system, combining star and ring network topologies, and utilizing decoy particles and entanglement operations to generate authentication keys, the system solves the problems of single point of failure, communication delay, and security in quantum computing systems under large-scale network environments, thus achieving efficient and secure quantum computing.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING ELECTRONICS SCI & TECH INST
- Filing Date
- 2025-08-14
- Publication Date
- 2026-07-17
AI Technical Summary
Existing quantum computing systems suffer from single-point failure risks, high central load pressure, transmission delays, and low computational efficiency in large-scale network environments. Furthermore, their secure multi-party computation mechanisms are complex, resource-intensive, vulnerable to collusion attacks, and lack sufficient security.
A quantum-secure multi-party computation method with a hybrid topology is adopted, which combines star and ring network topologies. The modular addition operation is performed in the subnet through a quantum center, and the authentication key is generated by decoy particles and entanglement operations to realize the modular addition and secure multi-party computation of the user's secret value.
It improves computational efficiency, reduces the load on central nodes, enhances communication security, resists collusion attacks, and is suitable for quantum-safe multi-party computation with large-scale user participation.
Smart Images

Figure CN120811598B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of secure multi-party computation technology, and more specifically to a quantum secure multi-party computation method with a hybrid topology. Background Technology
[0002] Secure Multi-Party Computation (SMPC) is a cryptographic concept first proposed in 1982 by Professor Yao Qizhi, a renowned Chinese computer scientist. This theory primarily studies how multiple users can collaboratively compute a predetermined function and obtain the correct output without the involvement of a trusted third party, without revealing their individual private input information. The core of this cryptographic protocol lies in achieving "privacy-preserving computation," that is, completing collaborative computation tasks while ensuring data privacy and security. Currently, various implementation technologies have been developed in the field of secure multi-party computation, including differential privacy, homomorphic encryption, and garbled circuits. With the rapid development of quantum information technology, traditional secure multi-party computation schemes based on mathematically difficult problems (such as large integer factorization and discrete logarithm problems) are facing severe challenges from quantum computing. Research shows that once a practical general-purpose quantum computer is successfully developed, existing secure multi-party computation protocols based on public-key cryptography will be at risk of being cracked. To address this, Quantum Secure Multi-Party Computation (QSMPC) has emerged. This type of scheme is designed based on the principles of quantum mechanics. Its security no longer depends on the classical assumption of computational complexity, but is based on the fundamental principles of quantum mechanics such as the quantum no-cloning theorem and quantum entanglement, providing a new technological paradigm for privacy-preserving computing in the post-quantum era.
[0003] On the other hand, Semi-Quantum Key Distribution (SQKD) is an innovative hybrid key distribution protocol that cleverly combines classical communication techniques with quantum technology. It is particularly suitable for quantum secure communication scenarios involving classical users who lack full quantum processing capabilities (i.e., "semi-quantum users"). This concept was first formally defined and implemented in the "BKM 2007 protocol" proposed by Boyer, Kenigsberg, and Mor in 2007. Within this protocol framework, quantum user Alice sends a series of random quantum states, while semi-quantum user Bob can choose to directly reflect these quantum states or measure and reconstruct them. Ultimately, both parties disclose partial information through a classical channel to detect potential eavesdropping and generate a shared key. The security of semi-quantum secure communication is rooted in the fundamental principles of quantum mechanics, particularly the non-cloning and measurement collapse properties of quantum states. This means that even if an eavesdropper like Eve intercepts and measures some quantum states, she cannot completely copy and measure them without introducing detectable errors. From an application perspective, semi-quantum secure communication has significant advantages. First, it exhibits good system compatibility, effectively reducing the implementation cost of quantum secure communication. Second, this method allows classical users to participate in quantum secure communication, providing a feasible path for the smooth transition from existing classical communication infrastructure to quantum communication. Finally, by reducing the quantum capability requirements for users, it greatly expands the application scope of quantum secure communication technology, laying an important foundation for the practical application and promotion of quantum communication technology. In recent years, with the rapid development of quantum communication technology, semi-quantum authentication key distribution protocols have made significant progress in both theoretical refinement and experimental implementation, providing a new technological option for building practical quantum communication networks.
[0004] Current quantum computing suffers from the following drawbacks:
[0005] 1. In a large-scale network environment, a quantum computing system with a single topology faces the risk of single point of failure if a star topology is adopted, and there is a problem of high central load pressure; if a ring topology is adopted, there is the risk of transmission delay, and there are problems of low computing efficiency and poor scalability.
[0006] 2. The multi-party computation mechanism for security is complex in design, consumes a lot of resources, and has low computational efficiency.
[0007] 3. The lack of authentication procedures makes it vulnerable to collusion attacks, resulting in insufficient security.
[0008] Therefore, how to achieve more secure and efficient quantum-safe multi-party computation among users with limited quantum capabilities without disclosing users' private secrets is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0009] In view of the above problems, the present invention provides a quantum-safe multi-party computation method with hybrid topology to at least solve some of the technical problems mentioned in the background art.
[0010] To achieve the above objectives, the present invention adopts the following technical solution:
[0011] This invention provides a quantum-safe multi-party computation method with a hybrid topology, applied to a quantum-safe multi-party computation system. The quantum-safe multi-party computation system includes m subnets with a star network topology, each subnet corresponding to a quantum center and multiple users; quantum communication between every two quantum centers is completed based on a ring network topology.
[0012] The quantum-safe multi-party computation method includes:
[0013] Each quantum center performs the modular addition operation of the corresponding user's secret value in its corresponding subnet, and obtains the modular addition result of all user secret values in the corresponding subnet, which is denoted as the subnet secret value modular addition result.
[0014] Based on the subnet secret value modulo addition result, each quantum center continues to participate in the secure multi-party computation protocol between quantum centers to obtain the sum of all user secret values in the quantum secure multi-party computation system.
[0015] Furthermore, each quantum center performs a modular addition operation on the corresponding user's secret value within its corresponding subnet, obtaining the modular addition result of all user's secret values in the corresponding subnet; specifically including:
[0016] Let the i-th quantum center be denoted as TP. i And, i = 1, 2, ..., m; the quantum center TP i The subnet is denoted as TP. i Subnet; Obtain the TP i The public key used by all users in the subnet;
[0017] Quantum Center TP i Send the |+> state sequence containing the decoy particle to TP. i Each user in the subnet; each user selects an operation type to process the received |+> state sequence containing decoy particles and then returns it to the quantum center TP. i By the Quantum Center TP i After performing eavesdropping detection based on the operation type, a TP is generated. i The first-level authentication key for each user in the subnet;
[0018] TP iEach user within the subnet calculates the encrypted information of their own secret value based on their own first-level authentication key and the public key, and publishes the encrypted information to the Quantum Center TP. i ;
[0019] Quantum Center TP i Based on the published encrypted information, obtain and publish TP. i The modulo sum of all user secret values in the subnet is represented as:
[0020]
[0021] Where, sum i Indicates TP i The modulo sum of all user secret values in the subnet; n represents TP i There are n users in the subnet; Indicates TP i User in subnet j Encrypted information; Indicates TP i User in subnet j The first-level authentication key; X j User j The secret value of K; i Indicates TP i The public key used by all users in the subnet; d represents the modulus.
[0022] Furthermore, the quantum center TP i Send the |+> state sequence containing the decoy particle to TP. i Each user in the subnet; each user selects an operation type to process the received qubit sequence and then returns it to the quantum center TP. i By the Quantum Center TP i After performing eavesdropping detection based on the operation type, a TP is generated. i The first-level authentication key for each user in the subnet; specifically including:
[0023] TP i The j-th user in the subnet is denoted as User. j And j = 1, 2, ..., n;
[0024] For TP i n users in the subnet, Quantum Center TP i Prepare the corresponding n sequences Each sequence It contains 2L particles in the |+> state; and prepares 2nL decoy particles randomly in the {|0>,|1>,|+>,|->} state;
[0025] Quantum Center TP i In the corresponding sequence 2L decoy particles are randomly inserted to form a new sequence. and the new sequence Send to the corresponding user. j ;
[0026] User j For the received new sequence After the particles in the quantum perform an R operation or a M operation, they return to the quantum center TP. i The R operation refers to directly processing the received new sequence. Return to the Quantum Center TP i The M-operation refers to the operation on the received new sequence. Each particle in the sequence undergoes a Z-basis measurement, recorded as the user measurement result, and new particles are prepared based on the user measurement results to update the new sequence. The particles in the sequence will be updated. Return to the Quantum Center TP i ;
[0027] Quantum Center TP i Collect TP i The new sequence returned to all users in the subnet At the same time, each user publicly discloses the type of operation they have selected;
[0028] Quantum Center TP i Based on the operation type selected by each user, the corresponding measurement basis pair is selected to return a new sequence. The particles in the quantum center are measured to achieve eavesdropping detection; the measurement results of the quantum center are recorded as the quantum center measurement results;
[0029] After passing the eavesdropping detection, the Quantum Center TP i Notify User j Discard new sequence The 2L decoy particles and the discard sequence User j Select the |+> state particle for the R operation, and then use the remaining measurement result sequence. As the quantum center TP i User in the subnet j The first-level authentication key; where This represents the Lth particle in the remaining sequence of measurement results.
[0030] Furthermore, the Quantum Center TP i and User j For the new sequence The operation process specifically includes:
[0031] (1) When the new sequence When the initial state of the decoy particle is |0>:
[0032] If User j Selecting operation R results in a "none" value for the corresponding user measurement; Quantum Center TP i When Z-basis is selected for measurement, the corresponding quantum center measurement result is |0>;
[0033] If User j Selecting operation M results in a user measurement of |0>; Quantum Center TP i When Z-basis is selected for measurement, the corresponding quantum center measurement result is |0>;
[0034] (2) When the new sequence When the initial state of the decoy particle is |1>:
[0035] If User j Selecting operation R results in a "none" value for the corresponding user measurement; Quantum Center TP i When Z-basis is selected for measurement, the corresponding quantum center measurement result is |1>;
[0036] If User j Selecting operation M results in a user measurement of |1>; Quantum Center TP i When Z-basis is selected for measurement, the corresponding quantum center measurement result is |1>;
[0037] (3) When the new sequence When the initial state of the decoy particle in the equation is |+>:
[0038] If User j Selecting operation R results in a "none" value for the corresponding user measurement; Quantum Center TP i When X basis is selected for measurement, the corresponding quantum center measurement result is |+>;
[0039] If User j Selecting the M operation results in either |0> or |1> for the user's measurement; Quantum Center TP i When Z-basis is selected for measurement, the corresponding quantum center measurement result is |0> or |1>;
[0040] (4) When the new sequence When the initial state of the decoy particle in the equation is |->:
[0041] If User jSelecting operation R results in a "none" value for the corresponding user measurement; Quantum Center TP i When X basis is selected for measurement, the corresponding quantum center measurement result is |->;
[0042] If User j Selecting operation M results in either |0> or |1> for the user measurement; Quantum Center TP i When Z-basis is selected for measurement, the corresponding quantum center measurement result is |0> or |1>.
[0043] Furthermore, based on the modulo addition result of the subnet's secret value, each quantum center continues to participate in the secure multi-party computation protocol between quantum centers to obtain the sum of all user secret values in the quantum secure multi-party computation system; specifically including:
[0044] For i = 1, 2, ..., m-1, by the quantum center TP i Generate specific state sequences and specific state particles;
[0045] Entanglement and sequence distribution operations are performed on adjacent quantum centers at quantum center TP. m The state of summation is obtained at the location;
[0046] A second-layer authentication key is generated for each quantum center based on Z-basis measurements of the generated specific state sequences.
[0047] By combining the subnet secret value modulo addition result, the summation state, and the second-layer authentication key, the sum of all user secret values in the quantum-secure multi-party computation system is obtained.
[0048] Furthermore, for i = 1, 2, ..., m-1, by the quantum center TP i Generate specific state sequences and specific state particles; specifically including:
[0049] (1) Generation of G-Like state sequences from quantum center TP1 in, Let L be the Lth G-Like state particle in sequence S. Each G-Like state particle contains three particles: T, A, and B. Let particle T, particle A, and particle B be separated into separate sequences, represented as follows:
[0050]
[0051] Among them, S T This represents the sequence corresponding to particle T; Represents sequence S T The Lth particle in S; A This represents the sequence corresponding to particle A; Represents sequence S AThe Lth particle in S; B This represents the sequence corresponding to particle B; Represents sequence S B The Lth particle in;
[0052] (2) A particle 1 in the state |0> is generated from the quantum center TP1, denoted as particle |0>1; a quantum Fourier transform is performed on particle |0>1 in the d-dimensional quantum system, and the transformed particle |0>1 is denoted as quantum state ψ1; the quantum state ψ1 contains particle |0>1; the quantum state ψ1 is represented as:
[0053]
[0054] Among them, U QFT denoted by ; |f>1 represents particle 1 in the state |f>; f∈{0,1,…,d-1}, where d represents the dimension;
[0055] (3) A second particle in the state of |0> is generated again from the quantum center TP1, denoted as particle |0>2;
[0056] (4) For i = 2, 3, ..., m-1, by the quantum center TP i Generate a particle i+1 in the state |0>, denoted as particle |0> i+1 ;
[0057] (5) For i = 2, 3, ..., m-1, by the quantum center TP i Generate sequences containing particles in the |+> state. Represented as:
[0058]
[0059] in, Represents a sequence The Lth |+> state particle in the middle.
[0060] Furthermore, the entanglement operation and sequence distribution operation performed on adjacent quantum centers are performed at the quantum center TP. m The state to be summed is obtained at the given point; specifically including:
[0061] (1) For quantum center TP1, perform the first entanglement operation on quantum state ψ1 and particle |0>2 to generate quantum state ψ2, which contains particle 1 and particle 2;
[0062] Quantum center TP1 acts as the sender, and quantum center TP2 acts as the receiver, performing a sequence distribution operation to realize the distribution of sequence S held by quantum center TP1. T The second particle in quantum state ψ2 is sent to quantum center TP2;
[0063] (2) For the quantum center TP i And i = 2, 3, ..., m-1, for the sequence The |+> state particles in the sequence S undergo a second entanglement operation with the G-Like state particles in the G-Like state sequence S; and the |0> state particles undergo a second entanglement operation with the G-Like state particles in the sequence S. i+1 With quantum state ψ i Perform the first entanglement operation to generate the quantum state ψ i+1 ;
[0064] By Quantum Center TP i As the sender, by the Quantum Center TP i+1 As the receiver, it performs sequence distribution operations to realize the quantum center TP i The sequence S held T With quantum state ψ i+1 The i+1 particle was sent to the quantum center TP. i+1 ;
[0065] Ultimate Quantum Center TP m Obtained from the Quantum Center TP m-1 The sent sequence S T With quantum state ψ m The m-th particle in the quantum state ψ is called the quantum state ψ. m To find the summation state.
[0066] Furthermore: the first entanglement operation includes: for the quantum center TP i And i = 1, 2, ..., m-1, using quantum state ψ i Particle i is used as the control bit, and particle i+1 is set to |0> i+1 Target position; perform control and transformation to generate quantum state ψ i+1 The quantum state ψ i+1 It contains i+1 particles; the quantum state ψ i+1 Represented as:
[0067]
[0068] Among them, U Add Indicates control plus transformation; ψ i This indicates that it is produced by the quantum center TP i-1 The generated quantum state; |0>i +1 This indicates that it is produced by the quantum center TP i The generated particle i+1 is in the |0> state; |f> i This indicates that particle i is in the state |f>, and f∈{0,1,…,d-1}, where d represents the dimension of the quantum-safe multi-party computation system;
[0069] The second entanglement operation includes: for the quantum center TP i And i = 2, 3, ..., m-1; let t = 1, 2, ..., L, with the sequence The t-th |+> state particle in As control bits, in sequence S T The t-th particle As the target bit, perform the CNOT operation;
[0070] The sequence distribution operation includes: for i = 1, 2, ..., m-1, by the quantum center TP i As the sender, by the Quantum Center TP i+1 As the recipient;
[0071] Quantum Center TP i The sequence S held T With quantum state ψ i+1 The i+1 particles in the sequence are merged into a transmission sequence;
[0072] By Quantum Center TP i L random particles {|0>,|1>,|+>,|->} are generated as decoy particles, randomly inserted into the transmission sequence to form a new transmission sequence, which is then sent to the quantum center TP. i+1 ;
[0073] When the quantum center TP i+1 Upon receiving the newly transmitted sequence, the quantum center TP i It notifies the location of the decoy particle and its corresponding measurement basis; Quantum Center TP i+1 After correctly measuring all the decoy particles, notify the quantum center TP. i Measurement results;
[0074] Quantum Center TP i According to the Quantum Center TP i+1 The measurement results are compared with the decoy states in the newly sent sequence to calculate the error rate. If the actual error rate is greater than the safety threshold, the protocol is terminated and transmission is restarted; if the actual error rate is lower than the safety threshold, the current sequence distribution communication is considered secure.
[0075] Furthermore: the generation of a second-layer authentication key for each quantum center based on Z-basis measurements of the generated specific state sequence specifically includes:
[0076] The sequence S is formed by the quantum center TP1 A Each particle in the sequence undergoes a Z-basis measurement, and the measurement results are then sequenced. Let it be R0;
[0077] The sequence S is formed by the quantum center TP1 BEach particle in the sequence undergoes a Z-basis measurement, and the measurement results are then sequenced. Let it be R1;
[0078] For i = 2, 3, ..., m-1, by the quantum center TP i For the sequence held Each particle in the sequence undergoes a Z-basis measurement, and the measurement results are then sequenced. Let it be R i ;
[0079] By Quantum Center TP m For the sequence S held T Perform Z-basis measurements on each particle and sequence the measurement results. Let it be R m ;
[0080] Finally, let the measurement result sequence R0 and the measurement result sequence R1 be the second-layer authentication keys of the quantum center TP1; for i = 2, 3, ..., m-1, let the measurement result sequence R... i For the quantum center TP i The second-level authentication key; denoted as the measurement result sequence R m For the quantum center TP m The second layer of authentication key.
[0081] Further, the step of combining the subnet secret value modulo addition result, the summation state, and the second-layer authentication key to obtain the sum of all user secret values in the quantum-secure multi-party computation system includes:
[0082] (1) For i = 1, 2, ..., m, based on the quantum center TP i The corresponding TP i The modulo sum of the secret values of all users in the subnet i By the Quantum Center TP i For the summation state ψ m Particle i in the process executes U i U QFT Transformation processing, where,
[0083] Based on U i U QFT Transformation process to obtain the entire summation state ψ m The transformation formula is expressed as:
[0084]
[0085] Among them, |g i > i This indicates that particle i is in |g i >state, where g i∈{0,1,…,d-1}, and satisfy g1+g2+…+g m =0 mod d, that is
[0086] (2) For i = 1, 2, ..., m, the quantum center TP i For the summation state ψ m exist The base measurement is calculated under the transformation, and the measurement result is denoted as Y. i And by the Quantum Center TP i Y i The second-level authentication key is public; Y i Represented as:
[0087] Y i =(g i +sum i modd
[0088] (3) For quantum center TP1, whether the measurement result of the kth bit in the certified measurement result sequence R0 and the measurement result of the kth bit in the measurement result sequence R1 meets the preset conditions; k = 1, 2, ..., L; if the preset conditions are met, it means that the second layer of authentication key of quantum center TP1 has been verified and the published Y1 is accepted;
[0089] For the quantum center TP i And i = 2, 3, ..., m-1, the authentication measurement result sequence R i Does the measurement result of the k-th position satisfy a preset condition? If the preset condition is satisfied, it represents the quantum center TP. i The second-level authentication key verification is successful, and the publicly disclosed Y... i Accepted;
[0090] For the quantum center TP m Authentication measurement result sequence R m Does the measurement result of the k-th position satisfy a preset condition? If the preset condition is satisfied, it represents the quantum center TP. m The second-level authentication key verification is successful, and the publicly disclosed Y... m Accepted;
[0091] The preset conditions are expressed as follows:
[0092]
[0093] in, This represents the measurement result at the k-th position in the measurement result sequence R0; This represents the measurement result at the k-th position in the measurement result sequence R1; This represents the measurement result at the k-th position in the measurement result sequence R2, where the measurement result sequence R2 is the second-layer authentication key of the quantum center TP2; Represents the measurement result sequence R m The measurement result of the k-th position;
[0094] (4) According to the equation Quantum Center TP after certification i For any i = 1, 2, ..., m, the following calculations can be performed to obtain the modulo addition result of the secret values of all users in the quantum-secure multi-party computation system, and the corresponding TP will be published. i The number of users in the subnet; where the modulo sum of all user secret values, SUM, is represented as:
[0095]
[0096] (5) Any user in the quantum-safe multi-party computation system j By calculating (SUM-mnK) i The sum of all user secret values in the quantum-secure multi-party computation system is obtained by using mod d.
[0097] As can be seen from the above technical solution, compared with the prior art, the present invention discloses a quantum-safe multi-party computation method with hybrid topology, which has the following beneficial effects:
[0098] In this invention, multiple quantum centers can complete the user computing needs within each group online asynchronously and in parallel, which can effectively improve computing efficiency, especially when a large number of users participate in the computing, the advantages are obvious.
[0099] In this invention, communication and computation between quantum centers adopt a ring topology, eliminating the need for an additional center to host computation. This reduces the risk of increased load on computation center nodes in a star topology when the total amount of data involved in computation increases in a large quantum communication network.
[0100] This invention adds a group authentication step and resists various common attacks such as conspiracy attacks, effectively improving communication security.
[0101] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0102] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0103] Figure 1 This is a schematic diagram of a quantum-safe multi-party computation system based on a hybrid topology, provided in an embodiment of the present invention.
[0104] Figure 2 This is a schematic diagram of the quantum-safe multi-party computation method provided in an embodiment of the present invention.
[0105] Figure 3 A schematic diagram illustrating the workflow of subnet computing within a quantum center, provided in an embodiment of the present invention.
[0106] Figure 4 This is a schematic diagram illustrating the workflow of computation between multiple quantum centers provided in an embodiment of the present invention. Detailed Implementation
[0107] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0108] This invention discloses a quantum-safe multi-party computation method with a hybrid topology, applied to a quantum-safe multi-party computation system. The system comprises m subnets with a star-shaped network topology, each subnet corresponding to a quantum center (TP) and multiple users. Quantum communication between any two quantum centers is achieved using a ring-shaped network topology. Each user possesses the same but incomplete quantum capabilities, only able to prepare and measure classical ground states and perform quantum reflection operations. The TP, as the quantum center, possesses complete quantum capabilities, capable of preparing arbitrary quantum states and performing arbitrary quantum unitary operations. Considering the generally limited quantum capabilities of users, communication and computation within each quantum center group are accomplished using a semi-quantum protocol. The quantum center, as a dedicated quantum communication infrastructure, is configured to possess complete quantum computing and storage capabilities and is not limited by quantum communication equipment and technology.
[0109] See the schematic diagram of the quantum-safe multi-party computation system. Figure 1As shown, this structure combines the advantages of star and ring topologies, using flexible structural design to compensate for the shortcomings of a single topology, making it suitable for scenarios with high requirements for reliability, scalability, and performance. The system is divided into multiple star subnets, with each subnet's quantum center connected via a ring backbone to achieve asynchronous parallel computing. New star subnets can be directly connected to the ring backbone without reconstructing the overall network architecture. The core ring layer handles backbone traffic, while the edge star layers connect to end-user devices, enabling traffic layering optimization. The ring backbone uses high-speed fiber optics or high-bandwidth links to ensure efficient transmission of core information. End-user devices connect to the nearest center via star connections, saving cabling and reducing quantum state transmission hops. The resulting quantum-safe multi-party computation system is suitable for large-scale secure multi-party computation, especially large-scale quantum-safe multi-party computation where user terminals have limited quantum capabilities.
[0110] See Figure 2 As shown, the quantum-safe multi-party computation method provided in this embodiment of the invention can realize multi-center parallel asynchronous computation. The method includes:
[0111] 1. Each quantum center performs a modular addition operation on the corresponding user's secret value within its corresponding subnet, and obtains the modular addition result of all user secret values in the corresponding subnet, which is denoted as the subnet secret value modular addition result;
[0112] 2. Based on the subnet secret value modulo addition result, each quantum center continues to participate in the secure multi-party computation protocol between quantum centers to obtain the sum of all user secret values in the quantum secure multi-party computation system.
[0113] Next, the above-mentioned quantum-safe multi-party computation method will be explained in detail.
[0114] 1. Each quantum center performs a modular addition operation on the corresponding user's secret value within its respective subnet, obtaining the modular addition result of all user secret values in the corresponding subnet, denoted as the subnet secret value modular addition result; see also Figure 3 As shown, it specifically includes:
[0115] 1-0: Assume there are m (m≥1) quantum centers TP1,TP2,…,TP in the system. m The number of users in each subnet of each center can be different, and can be n1, n2, ..., n. m To simplify the description of the principle, the following description assumes without loss of generality that the number of users in each subnet is n.
[0116] Let the i-th quantum center be denoted as TP. i And, i = 1, 2, ..., m; the quantum center TP i The subnet is denoted as TP. i Subnet; Obtain TP iThe public key used by all users in the subnet;
[0117] Specifically, TP i In a subnet, n users share a set of binary random secret bit sequences of length L as their public key K in advance through a semi-quantum key distribution protocol via an authoritative key management center. i , for TP i Communication encryption during the first-level summation within the subnet; and for all users on the network, K 1 =…=K m The process will not be detailed here;
[0118] During the execution of the protocol, the Quantum Center TP i (i = 1, 2, ..., m) must follow the protocol steps and cannot collude with any user, but this does not exclude the quantum center TP. i They might attempt to obtain users' secrets by collecting relevant information;
[0119] 1-1: Quantum Center TP i Send the |+> state sequence containing the decoy particle to TP. i Each user in the subnet; each user selects an operation type to process the received |+> state sequence containing decoy particles and then returns it to the quantum center TP. i By the Quantum Center TP i After performing eavesdropping detection based on the operation type, a TP is generated. i The first-level authentication key for each user in the subnet; specifically including:
[0120] 1-1-1: TP i The j-th user in the subnet is denoted as User. j And j = 1, 2, ..., n; User j Possesses Secret Value X j ∈Z d ({Z d ,+} represents d-ary addition to a group, Z d ={0,1,…,d-1}); X j Available binary bit sequences of length L Indicates, that is Where 2 raised to the power of L equals d, that is, d = 2 L ,and n users wish to perform the following steps in a semi-honest TP (Telepathic Transaction) scenario. i Complete the form (X1+X2+...+X) with assistance. n The first-level secret value summation operation mod d is performed without revealing the individual secret values; specifically:
[0121] For TPi n users in the subnet, Quantum Center TP i Prepare the corresponding n sequences Each sequence It contains 2L particles in the |+> state, that is Meanwhile, the Quantum Center TP i Prepare 2nL decoy particles randomly positioned in {|0>,|1>,|+>,|->};
[0122] For each j = 1, 2, ..., n, the quantum center TP i In the corresponding sequence 2L decoy particles are randomly inserted to form a new sequence. (each) The length is 4L), and the new sequence is... Send to the corresponding user. j ;
[0123] 1-1-2: User j For the received new sequence After the particles in the quantum perform an R operation or a M operation, they return to the quantum center TP. i The R operation refers to directly processing the received new sequence. Return to the Quantum Center TP i The M-operation refers to the operation on the received new sequence. Each particle in the sequence undergoes a Z-basis measurement, recorded as the user measurement result, and new particles are prepared based on the user measurement results to update the new sequence. The particles in the sequence will be updated. Return to the Quantum Center TP i ;
[0124] 1-1-3: Quantum Center TP i Collect TP i The new sequence returned to all users in the subnet At the same time, each user publicly discloses the type of operation they have selected; next, the Quantum Center TP i Based on the operation type selected by each user, the corresponding measurement basis pair is selected to return a new sequence. The particles in the quantum center are measured to detect eavesdropping. That is, by checking the accuracy of the measurement results, it is determined whether there is an external attack in the transmission process. If the error rate of the measurement results exceeds a pre-set threshold, the quantum-safe multi-party computation protocol is terminated, and a decision is made on whether to restart the protocol depending on the situation. For ease of explanation in the following text, the measurement results of the quantum center are referred to as the quantum center measurement results.
[0125] In steps 1-1-2 and 1-1-3 above, the quantum center TPi and User j For the new sequence The operation process specifically includes:
[0126] (1) When the new sequence When the initial state of the decoy particle is |0>:
[0127] If User j Selecting operation R results in a "none" value for the corresponding user measurement; Quantum Center TP i When Z-basis is selected for measurement, the corresponding quantum center measurement result is |0>;
[0128] If User j Selecting operation M results in a user measurement of |0>; Quantum Center TP i When Z-basis is selected for measurement, the corresponding quantum center measurement result is |0>;
[0129] (2) When the new sequence When the initial state of the decoy particle is |1>:
[0130] If User j Selecting operation R results in a "none" value for the corresponding user measurement; Quantum Center TP i When Z-basis is selected for measurement, the corresponding quantum center measurement result is |1>;
[0131] If User j Selecting operation M results in a user measurement of |1>; Quantum Center TP i When Z-basis is selected for measurement, the corresponding quantum center measurement result is |1>;
[0132] (3) When the new sequence When the initial state of the decoy particle in the equation is |+>:
[0133] If User j Selecting operation R results in a "none" value for the corresponding user measurement; Quantum Center TP i When X basis is selected for measurement, the corresponding quantum center measurement result is |+>;
[0134] If User j Selecting the M operation results in either |0> or |1> for the user's measurement; Quantum Center TP i When Z-basis is selected for measurement, the corresponding quantum center measurement result is |0> or |1>;
[0135] (4) When the new sequence When the initial state of the decoy particle in the equation is |->:
[0136] If User j Selecting operation R results in a "none" value for the corresponding user measurement; Quantum Center TP i When X basis is selected for measurement, the corresponding quantum center measurement result is |->;
[0137] If User j Selecting operation M results in either |0> or |1> for the user measurement; Quantum Center TP i When Z-basis is selected for measurement, the corresponding quantum center measurement result is |0> or |1>;
[0138] 1-1-4: After passing the eavesdropping detection, the Quantum Center TP i Notify User j Discard new sequence The 2L decoy particles and the discard sequence User j Select the |+> state particles from the R operation (ideally, discard L |+> state particles), and then use the remaining measurement result sequence. As the quantum center TP i User in the subnet j The first-level authentication key; where This represents the Lth particle in the remaining sequence of measurement results.
[0139] 1-2: TP i Each user within the subnet calculates the encrypted information of their own secret value based on their own first-level authentication key and public key, and publishes the encrypted information to the Quantum Center TP. i ;
[0140] TP i User within the subnet j The modulo addition result corresponding to the encrypted information of the secret value is expressed as:
[0141]
[0142] in, Indicates TP i User in subnet j The result of the encryption of the information; X j User j The secret value of K; i Indicates TP i A public key that is used by all users in the subnet; Indicates TP i User in subnet j The first-level authentication key; d represents the modulus;
[0143] 1-3: Quantum Center (TP) i Based on the published encrypted information, obtain and publish TP. i The modulo sum of the secret values of all users in the subnet i and publish it to the corresponding TP. i Subnet users; sum i Represented as:
[0144]
[0145] Where n represents TP i There are n users in the subnet; Indicates TP i User in subnet j Encrypted information; Indicates TP i User in subnet j The first-level authentication key; X j User j The secret value of K; i Indicates TP i The public key used by all users in the subnet; d represents the modulus.
[0146] 1-4: TP i Subnet users at the Quantum Center TP i With the assistance of calculation (sum i -nK i The modulo operation () gives the sum of the secret values of all users in the subnet.
[0147] 2. Based on the subnet's secret value modulo addition result, each quantum center continues to participate in the secure multi-party computation protocol among quantum centers to obtain the sum of all user secret values in the quantum secure multi-party computation system; see [link to relevant documentation]. Figure 4 As shown, it specifically includes:
[0148] 2-0: For i = 1, 2, ..., m-1, by the quantum center TP i Generate specific state sequences and specific state particles; specifically including:
[0149] (1) Generation of G-Like state sequences from quantum center TP1 in, Let L be the Lth G-Like state particle in sequence S. Each G-Like state particle contains three particles: T, A, and B. Let particle T, particle A, and particle B be separated into separate sequences, represented as follows:
[0150]
[0151]
[0152] Among them, S T This represents the sequence corresponding to particle T; Represents sequence S T The Lth particle in S; A This represents the sequence corresponding to particle A; Represents sequence S A The Lth particle in S; B This represents the sequence corresponding to particle B; Represents sequence S B The Lth particle in;
[0153] (2) A particle 1 in the state |0> is generated from the quantum center TP1, denoted as particle |0>1; a quantum Fourier transform is performed on particle |0>1 in the d-dimensional quantum system, and the transformed particle |0>1 is denoted as quantum state ψ1; quantum state ψ1 contains particle |0>1; according to the properties of quantum Fourier transform, quantum state ψ1 is expressed as:
[0154]
[0155] Among them, U QFT The quantum Fourier transform is represented; |F>1 represents particle 1 in the state |f>; f∈{0,1,…,d-1}, where d represents the dimension;
[0156] (3) A second particle in the state of |0> is generated again from the quantum center TP1, denoted as particle |0>2;
[0157] (4) For i = 2, 3, ..., m-1, by the quantum center TP i Generate a particle i+1 in the state |0>, denoted as particle |0> i+1 For example, the quantum center TP2 generates a particle 3 in the state |0>, denoted as particle |0>3;
[0158] (5) For i = 2, 3, ..., m-1, by the quantum center TP i Generate sequences containing particles in the |+> state. Represented as:
[0159]
[0160] in, Represents a sequence The Lth |+> state particle in the middle.
[0161] 2-1: Perform entanglement and sequence distribution operations on adjacent quantum centers, at quantum center TP mThe state to be summed is obtained at the given point; specifically including:
[0162] (1) For quantum center TP1, perform the first entanglement operation on quantum state ψ1 and particle |0>2 to generate quantum state ψ2, which contains particle 1 and particle 2;
[0163] Quantum center TP1 acts as the sender, and quantum center TP2 acts as the receiver, performing a sequence distribution operation to realize the distribution of sequence S held by quantum center TP1. T The second particle in quantum state ψ2 is sent to quantum center TP2;
[0164] (2) For the quantum center TP i And i = 2, 3, ..., m-1, for the sequence The |+> state particles in the sequence S undergo a second entanglement operation with the G-Like state particles in the G-Like state sequence S; and the |0> state particles undergo a second entanglement operation with the G-Like state particles in the sequence S. i+1 With the Quantum Center TP i-1 The generated quantum state ψ i Perform the first entanglement operation to generate the quantum state ψ i+1 ;
[0165] By Quantum Center TP i As the sender, by the Quantum Center TP i+1 As the receiver, it performs sequence distribution operations to realize the quantum center TP i The sequence S held T With quantum state ψ i+1 The i+1 particle was sent to the quantum center TP. i+1 ;
[0166] Ultimate Quantum Center TP m Obtained from the Quantum Center TP m-1 The sent sequence S T With quantum state ψ m The m-th particle in the quantum state ψ is called the quantum state ψ. m For the summation state;
[0167] (3) Specifically, the first entanglement operation, the second entanglement operation, and the sequence distribution operation mentioned above are as follows:
[0168] 1) The first entanglement operation includes: for the quantum center TP i And i = 1, 2, ..., m-1, using quantum state ψ i Particle i is used as the control bit, and particle i+1 is set to |0> i+1 Target position; perform control and transformation to generate quantum state ψ i+1 quantum state ψ i+1 It contains i+1 particles; quantum state ψi+1 Represented as:
[0169]
[0170] Among them, U Add Indicates control plus transformation; ψ i This indicates that it is produced by the quantum center TP i-1 The generated quantum state; |0> i+1 This indicates that it is produced by the quantum center TP i The generated particle i+1 is in the |0> state; |f> i This indicates that particle i is in the state |f>, and f∈{0,1,…,d-1}, where d represents the dimension of the quantum-safe multi-party computation system;
[0171] For example, for quantum center TP1, using particle 1 in quantum state ψ1 as the control position and particle |0>2 as the target position; performing control addition transformation generates quantum state ψ2, which contains particles |0>1 and |0>2; quantum state ψ2 is represented as:
[0172]
[0173] 2) The second entanglement operation includes: for the quantum center TP i And i = 2, 3, ..., m-1; let t = 1, 2, ..., L, with the sequence The t-th |+> state particle in As control bits, in sequence S T The t-th particle As the target bit, perform a CNOT operation (control NOT gate operation);
[0174] 3) Sequence distribution operations include: for i = 1, 2, ..., m-1, the sequence distribution is performed by the quantum center TP. i As the sender, by the Quantum Center TP i+1 As the recipient;
[0175] Quantum Center TP i The sequence S held T With quantum state ψ i+1 The i+1 particles in the sequence are merged into a transmission sequence;
[0176] By Quantum Center TP i L random particles {|0>,|1>,|+>,|->} are generated as decoy particles, randomly inserted into the transmission sequence to form a new transmission sequence, which is then sent to the quantum center TP. i+1 ;
[0177] When the quantum center TP i+1 Upon receiving the newly transmitted sequence, the quantum center TPi It notifies the location of the decoy particle and its corresponding measurement basis; Quantum Center TP i+1 After correctly measuring all the decoy particles, notify the quantum center TP. i Measurement results;
[0178] Quantum Center TP i According to the Quantum Center TP i+1 The measurement results are compared with the decoy states in the newly sent sequence to calculate the error rate. If the actual error rate is greater than the safety threshold, the protocol is terminated and transmission is restarted; if the actual error rate is lower than the safety threshold, the current sequence distribution communication is considered secure.
[0179] 2-2: Based on Z-basis measurements of the generated specific state sequences, a second-layer authentication key is generated for each quantum center; specifically including:
[0180] The sequence S is formed by the quantum center TP1 A Each particle in the sequence undergoes a Z-basis measurement, and the measurement results are then sequenced. Let it be R0;
[0181] The sequence S is formed by the quantum center TP1 B Each particle in the sequence undergoes a Z-basis measurement, and the measurement results are then sequenced. Let it be R1;
[0182] For i = 2, 3, ..., m-1, by the quantum center TP i For the sequence held Each particle in the sequence undergoes a Z-basis measurement, and the measurement results are then sequenced. Let it be R i ;
[0183] By Quantum Center TP m For the sequence S held T Perform Z-basis measurements on each particle and sequence the measurement results. Let it be R m ;
[0184] Finally, let the measurement result sequence R0 and the measurement result sequence R1 be the second-layer authentication keys of the quantum center TP1; for i = 2, 3, ..., m-1, let the measurement result sequence R... i For the quantum center TP i The second-level authentication key; denoted as the measurement result sequence R m For the quantum center TP m The second layer of authentication key.
[0185] 2-3: Combining the subnet secret value modulo addition result, the summation state, and the second-layer authentication key, obtain the sum of all user secret values in the quantum-secure multi-party computation system; specifically including:
[0186] (1) For i = 1, 2, ..., m, based on the quantum center TP i The corresponding TP i The modulo sum of the secret values of all users in the subnet i By the Quantum Center TP i For the summation state ψ m Particle i in the process executes U i U QFT Transformation processing, where,
[0187] Based on U i U QFT Transformation process to obtain the entire summation state ψ m The transformation formula is expressed as:
[0188]
[0189] Among them, |g i > i This indicates that particle i is in |g i >state, where g i ∈{0,1,…,d-1}, and satisfy g1+g2+…+g m =0 mod d, that is
[0190] (2) For i = 1, 2, ..., m, the quantum center TP i For the summation state ψ m exist The base measurement is calculated under the transformation, and the measurement result is denoted as Y. i And by the Quantum Center TP i Y i Its own second-level authentication key is public, and the public form is Y. i ||R i ; where Y i The calculation is expressed as:
[0191] Y i =(g i +sum i modd
[0192] (3) Based on the above information, each quantum center can verify whether its own second-level authentication key meets the preset conditions with the second-level authentication keys of other quantum centers. If the conditions are met, it means that the authentication between the quantum centers is successful, and the publicly disclosed Y... i Accepted; specifically:
[0193] For quantum center TP1, whether the measurement result of the k-th bit in the certified measurement result sequence R0 and the measurement result of the k-th bit in the measurement result sequence R1 meets the preset condition; k = 1, 2, ..., L; if the preset condition is met, it means that the second-level authentication key of quantum center TP1 has been verified and the published Y1 is accepted;
[0194] For the quantum center TP i And i = 2, 3, ..., m-1, the authentication measurement result sequence R i Does the measurement result of the k-th position satisfy a preset condition? If the preset condition is satisfied, it represents the quantum center TP. i The second-level authentication key verification is successful, and the publicly disclosed Y... i Accepted;
[0195] For the quantum center TP m Authentication measurement result sequence R m Does the measurement result of the k-th position satisfy a preset condition? If the preset condition is satisfied, it represents the quantum center TP. m The second-level authentication key verification is successful, and the publicly disclosed Y... m Accepted;
[0196] The above preset conditions are expressed as follows:
[0197]
[0198] in, This represents the measurement result at the k-th position in the measurement result sequence R0; This represents the measurement result at the k-th position in the measurement result sequence R1; This represents the measurement result at the k-th position in the measurement result sequence R2, where the measurement result sequence R2 is the second-layer authentication key of the quantum center TP2; Represents the measurement result sequence R m The measurement result of the k-th bit; that is, the result of XORing all authentication keys bit by bit.
[0199] (4) According to the equation Quantum Center TP after certification i For any i = 1, 2, ..., m, the following calculations can be performed to obtain the modulo summation results of the secret values of all users in the quantum-secure multi-party computation system, and the corresponding TP can be published. i The number of users in the subnet; where the modulo sum of all user secret values, SUM, is represented as:
[0200]
[0201] (5) Any user in a quantum-safe multi-party computation system jAccording to information released by its corresponding quantum center, by calculating (SUM-mnK) i The modulo operation yields the sum of all user secrets in a quantum-safe multi-party computation system.
[0202] At this point, the protocol process for calculating the sum of secret values for all users is complete. During execution, if a subnet adds a requirement, the number of quantum centers TP, m, changes. This can be reassigned as m = m + 1, but it's important to note that this reassignment must be completed before the protocol center summation step. Otherwise, the protocol will no longer accept changes in the number of centers.
[0203] In summary, this invention discloses a quantum-safe multi-party computation method with a hybrid topology, where each quantum center first calculates the sum obtained within the center. i Then, any TP was implemented through a secure multi-party computation protocol between centers. i (i = 1, 2, ..., m) without leaking Under the premise of obtaining The calculation result SUM, any user based on TP i The published information (i = 1, 2, ..., m) can all be used to calculate (SUM - mnK). i ) mod d to get In this process, embodiments of the present invention utilize quantum mechanical properties such as quantum entanglement and quantum no-cloning, based on a hybrid quantum network topology, to achieve secure and efficient quantum-safe multi-party computation between users with limited quantum capabilities, without disclosing users' private secrets. With the continuous development of quantum computing and quantum communication technologies, quantum-safe multi-party computation is expected to be widely applied in fields such as distributed computing, privacy protection, and blockchain, providing crucial support for building secure and reliable quantum interconnected networks.
[0204] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0205] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A quantum-safe multi-party computation method with hybrid topology, characterized in that, The invention is applied to a quantum-safe multi-party computation system, which includes m subnets with a star network topology, each subnet corresponding to a quantum center and multiple users. Quantum communication between each pair of quantum centers is accomplished based on a ring network topology. The quantum-safe multi-party computation method includes: Each quantum center performs the modular addition operation of the corresponding user's secret value in its corresponding subnet, and obtains the modular addition result of all user secret values in the corresponding subnet, which is denoted as the subnet secret value modular addition result. Based on the subnet secret value modulo addition result, each quantum center continues to participate in the secure multi-party computation protocol between quantum centers to obtain the sum of all user secret values in the quantum secure multi-party computation system. Each quantum center performs a modular addition operation on its corresponding user secret value within its respective subnet, obtaining the modular addition result of all user secret values in the corresponding subnet; specifically including: Let the i-th quantum center be denoted as TP. i And, i=1,2,...,m; the quantum center TP i The subnet is denoted as TP. i Subnet; Obtain the TP i The public key used by all users in the subnet; Quantum Center TP i Will contain decoy particles The state sequence is sent to TP i Each user in the subnet; each user selects the operation type for the received data containing decoy particles. The state sequence is processed and returned to the quantum center TP. i By the Quantum Center TP i After performing eavesdropping detection based on the operation type, a TP is generated. i The first-level authentication key for each user in the subnet; TP i Each user within the subnet calculates the encrypted information of their own secret value based on their own first-level authentication key and the public key, and publishes the encrypted information to the Quantum Center TP. i ; Quantum Center TP i Based on the published encrypted information, obtain and publish TP. i The modulo sum of all user secret values in the subnet is represented as: ; Where, sum i Indicates TP i The modulo sum of all user secret values in the subnet; n represents TP i There are n users in the subnet; Indicates TP i User in subnet j Encrypted information; Indicates TP i User in subnet j The first-level authentication key; X j User j The secret value of K; i Indicates TP i The public key used by all users in the subnet; d represents the modulus; Based on the modular addition result of the subnet's secret value, each quantum center continues to participate in the secure multi-party computation protocol among quantum centers to obtain the sum of all user secret values in the quantum secure multi-party computation system; specifically including: For i = 1, 2, ..., m-1, by the quantum center TP i Generate specific state sequences and specific state particles; Entanglement and sequence distribution operations are performed on adjacent quantum centers at quantum center TP. m The state of summation is obtained at the location; A second-layer authentication key is generated for each quantum center based on Z-basis measurements of the generated specific state sequences. By combining the subnet secret value modulo addition result, the summation state, and the second-layer authentication key, the sum of all user secret values in the quantum-secure multi-party computation system is obtained.
2. The quantum-safe multi-party computation method with a hybrid topology according to claim 1, characterized in that, The quantum center TP i Will contain decoy particles The state sequence is sent to TP i Each user in the subnet; each user selects an operation type to process the received qubit sequence and then returns it to the quantum center TP. i By the Quantum Center TP i After performing eavesdropping detection based on the operation type, a TP is generated. i The first-level authentication key for each user in the subnet; Specifically, it includes: TP i The j-th user in the subnet is denoted as User. j And j = 1, 2, ..., n; For TP i n users in the subnet, Quantum Center TP i Prepare the corresponding n sequences Each sequence Contains 2L of Particles in a certain state; and prepare 2nL randomly positioned particles. Deceptive particles; Quantum Center TP i In the corresponding sequence 2L decoy particles are randomly inserted to form a new sequence. and the new sequence Send to the corresponding user. j ; User j For the received new sequence After the particles in the quantum perform an R operation or a M operation, they return to the quantum center TP. i The R operation refers to directly processing the received new sequence. Return to the Quantum Center TP i The M-operation refers to the operation on the received new sequence. Each particle in the sequence undergoes a Z-basis measurement, recorded as the user measurement result, and new particles are prepared based on the user measurement results to update the new sequence. The particles in the sequence will be updated. Return to the Quantum Center TP i ; Quantum Center TP i Collect TP i The new sequence returned to all users in the subnet At the same time, each user publicly discloses the type of operation they have selected; Quantum Center TP i Based on the operation type selected by each user, the corresponding measurement basis pair is selected to return a new sequence. The particles in the quantum center are measured to achieve eavesdropping detection; the measurement results of the quantum center are recorded as the quantum center measurement results; After passing the eavesdropping detection, the Quantum Center TP i Notify User j Discard new sequence The 2L decoy particles and the discard sequence User j Select the R operation State particles, the remaining measurement result sequence As the quantum center TP i User in the subnet j The first-level authentication key; where This represents the Lth particle in the remaining sequence of measurement results.
3. The quantum-safe multi-party computation method with a hybrid topology according to claim 2, characterized in that, Quantum Center TP i and User j For the new sequence The operation process specifically includes: (1) When the new sequence The initial state of the decoy particle in the middle is hour: If User j Selecting operation R results in a "none" value for the corresponding user measurement; Quantum Center TP i Choosing the Z-basis for measurement, the corresponding quantum center measurement result is: ; If User j Selecting the M operation will result in the following user measurement results: Quantum Center TP i Choosing the Z-basis for measurement, the corresponding quantum center measurement result is: ; (2) When the new sequence The initial state of the decoy particle in the middle is hour: If User j Selecting operation R results in a "none" value for the corresponding user measurement; Quantum Center TP i Choosing the Z-basis for measurement, the corresponding quantum center measurement result is: ; If User j Selecting the M operation will result in the following user measurement results: Quantum Center TP i Choosing the Z-basis for measurement, the corresponding quantum center measurement result is: ; (3) When the new sequence The initial state of the decoy particle in the middle is hour: If User j Selecting operation R results in a "none" value for the corresponding user measurement; Quantum Center TP i Choosing the X basis for measurement, the corresponding quantum center measurement result is: ; If User j If the M operation is selected, the user measurement result will be... or Quantum Center TP i Choosing the Z-basis for measurement, the corresponding quantum center measurement result is: or ; (4) When the new sequence The initial state of the decoy particle in the middle is hour: If User j Selecting operation R results in a "none" value for the corresponding user measurement; Quantum Center TP i Choosing the X basis for measurement, the corresponding quantum center measurement result is: ; If User j Selecting the M operation will result in the following user measurement results: or Quantum Center TP i Choosing the Z-basis for measurement, the corresponding quantum center measurement result is: or .
4. The quantum-safe multi-party computation method with a hybrid topology according to claim 1, characterized in that, For i=1,2,…,m-1, the quantum center TP i Generate specific state sequences and specific state particles; specifically including: (1) Generation of G-Like state sequences from quantum center TP1 ,in, Let L be the Lth G-Like state particle in sequence S. Each G-Like state particle contains three particles: T, A, and B. Let particle T, particle A, and particle B be separated into separate sequences, represented as follows: ; Among them, S T This represents the sequence corresponding to particle T; Represents sequence S T The Lth particle in; S A This represents the sequence corresponding to particle A; Represents sequence S A The Lth particle in; S B This represents the sequence corresponding to particle B; Represents sequence S B The Lth particle in; (2) A quantum center TP1 generates a state of The first particle in the state is denoted as particle 1. ; Particles in d-dimensional quantum systems Perform a quantum Fourier transform to transform the particles denoted as quantum state The quantum state Contains particles The quantum state Represented as: ; Among them, U QFT Represents the quantum Fourier transform; Indicates being in Particle No. 1 in the state; d represents the dimension; (3) A quantum center TP1 is generated again to be in a state of The second particle in the state is denoted as particle. ; (4) For i=2,3,…,m-1, by the quantum center TP i Generate a state The i+1th particle in state i is denoted as particle i+1. ; (5) For i=2,3,…,m-1, by the quantum center TP i Generate includes Sequence of state particles ; indicates as: ; in, Represents a sequence The Lth in State particles.
5. A quantum-safe multi-party computation method with a hybrid topology according to claim 4, characterized in that, The entanglement and sequence distribution operations performed on adjacent quantum centers are performed at quantum center TP. m The state to be summed is obtained at the given point; specifically including: (1) For the quantum center TP1, for the quantum state and particles Perform the first entanglement operation to generate a quantum state. The quantum state It contains particle 1 and particle 2; Quantum center TP1 acts as the sender, and quantum center TP2 acts as the receiver, performing a sequence distribution operation to realize the distribution of sequence S held by quantum center TP1. T With quantum state Particle number 2 was sent to the quantum center TP2; (2) For the quantum center TP i And i=2,3,…,m-1, for the sequence In The state particle performs a second entanglement operation with the G-Like state particles in the G-Like state sequence S; and the particle... With quantum state Perform the first entanglement operation to generate a quantum state. ; By Quantum Center TP i As the sender, by the Quantum Center TP i+1 As the receiver, it performs sequence distribution operations to realize the quantum center TP i The sequence S held T With quantum state The i+1 particle was sent to the quantum center TP. i+1 ; Ultimate Quantum Center TP m Obtained from the Quantum Center TP m-1 The sent sequence S T With quantum state The m-th particle in the quantum state is called a quantum state. To find the summation state.
6. The quantum-safe multi-party computation method with a hybrid topology according to claim 5, characterized in that: The first entanglement operation includes: for the quantum center TP i And i=1,2,…,m-1, using quantum states Particle i is used as the control bit, and particle i+1 is... Target bit; perform control and transformation to generate quantum state. The quantum state It contains i+1 particles; the quantum state Represented as: ; in, Indicates control plus transformation; Indicated by the quantum center TP i-1 The generated quantum state; This indicates that it is produced by the quantum center TP i The generated state Particle i+1 in state i; Indicates that particle i is in state, and d represents the dimension of a quantum-safe multi-party computation system; The second entanglement operation includes: for the quantum center TP i And i = 2, 3, ..., m-1; let t = 1, 2, ..., L, with the sequence The t-th state particles As control bits, in sequence S T The t-th particle As the target bit, perform the CNOT operation; The sequence distribution operation includes: for i = 1, 2, ..., m-1, by the quantum center TP i As the sender, by the Quantum Center TP i+1 As the recipient; Quantum Center TP i The sequence S held T With quantum state The i+1 particles in the sequence are merged into a transmission sequence; By Quantum Center TP i Randomly generate L As a decoy particle, it is randomly inserted into the transmission sequence, forming a new transmission sequence, and sent to the quantum center TP. i+1 ; When the quantum center TP i+1 Upon receiving the newly transmitted sequence, the quantum center TP i It notifies the location of the decoy particle and its corresponding measurement basis; Quantum Center TP i+1 After correctly measuring all the decoy particles, notify the quantum center TP. i Measurement results; Quantum Center TP i According to the Quantum Center TP i+1 The measurement results are compared with the decoy states in the newly sent sequence to calculate the error rate. If the actual error rate is greater than the safety threshold, the protocol is terminated and transmission is restarted; if the actual error rate is lower than the safety threshold, the current sequence distribution communication is considered secure.
7. A quantum-safe multi-party computation method with a hybrid topology according to claim 6, characterized in that: The process of generating a second-layer authentication key for each quantum center based on Z-basis measurements of the generated specific-state sequences specifically includes: The sequence S is formed by the quantum center TP1 A Each particle in the sequence undergoes a Z-basis measurement, and the measurement results are then sequenced. Let it be R0; The sequence S is formed by the quantum center TP1 B Each particle in the sequence undergoes a Z-basis measurement, and the measurement results are then sequenced. Let it be R1; For i = 2, 3, ..., m-1, by the quantum center TP i For the sequence held Each particle in the sequence undergoes a Z-basis measurement, and the measurement results are then sequenced. Let it be R i ; By Quantum Center TP m For the sequence S held T Perform Z-basis measurements on each particle and sequence the measurement results. Let it be R m ; Finally, let the measurement result sequence R0 and the measurement result sequence R1 be the second-layer authentication keys of the quantum center TP1; for i=2,3,…,m-1, let the measurement result sequence R... i For the quantum center TP i The second-level authentication key; denoted as the measurement result sequence R m For the quantum center The second layer of authentication key.
8. A quantum-safe multi-party computation method with a hybrid topology according to claim 7, characterized in that, The process of combining the subnet secret value modular addition result, the summation state, and the second-layer authentication key to obtain the sum of all user secret values in the quantum-secure multi-party computation system specifically includes: (1) For i=1,2,…,m, based on the quantum center TP i The corresponding TP i The modulo sum of the secret values of all users in the subnet i By the Quantum Center TP i For summation state Particle i in the process of execution Transformation processing, where, ; based on Transformation process to obtain the entire summation state The transformation formula is expressed as: ; in, Indicates that particle i is in state, in which And satisfy ,Right now ; (2) For i=1,2,…,m, the quantum center TP i For summation state exist The base measurement is calculated under the transformation, and the measurement result is denoted as Y. i And by the Quantum Center TP i Y i The second-level authentication key is public; Y i Represented as: ; (3) For quantum center TP1, does the measurement result of the k-th bit in the authentication measurement result sequence R0 and the measurement result sequence R1 satisfy the preset condition; k=1,2,…,L; if the preset condition is satisfied, it means that the second-level authentication key of quantum center TP1 has been verified and the disclosed key is valid. Accepted; For the quantum center TP i And i=2,3,…,m-1, the authentication measurement result sequence R i Does the measurement result of the k-th position satisfy a preset condition? If the preset condition is satisfied, it represents the quantum center TP. i The second-level authentication key verification passed, and the publicly disclosed key was valid. Accepted; For the quantum center TP m Authentication measurement result sequence R m Does the measurement result of the k-th position satisfy a preset condition? If the preset condition is satisfied, it represents the quantum center TP. m The second-level authentication key verification is successful, and the publicly disclosed Y... m Accepted; The preset conditions are expressed as follows: ; in, This represents the measurement result at the k-th position in the measurement result sequence R0; This represents the measurement result at the k-th position in the measurement result sequence R1; This represents the measurement result at the k-th position in the measurement result sequence R2, where the measurement result sequence R1 is the second-layer authentication key of the quantum center TP2; Represents the measurement result sequence R m The measurement result of the k-th position; (4) According to the equation The Quantum Center TP after completing certification i For any i=1,2,…,m, the following calculations can be performed to obtain the modulo addition result of the secret values of all users in the quantum-secure multi-party computation system, and the corresponding TP will be published. i The number of users in the subnet; where the modulo sum of all user secret values, SUM, is represented as: ; (5) Any user in the quantum-safe multi-party computation system j Through calculation The sum of the secret values of all users in the quantum-safe multi-party computation system is obtained.