Quantum private comparison protocol for comparing two classical bits through single photon

By using a single-photon quantum private comparison protocol, which utilizes the four quantum states of a single photon and a semi-loyal third party, a quantum private comparison with a quantum bit efficiency of 200% is achieved. This solves the problem of low quantum bit efficiency in existing technologies and provides theoretically unconditional security and efficient data comparison capabilities.

CN120915435APending Publication Date: 2025-11-07ZHEJIANG UNIV OF WATER RESOURCES & ELECTRIC POWER
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511055682.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

The current quantum private comparison protocol has a qubit efficiency of less than 100%, which cannot effectively protect the security of private data.

Method used

Using single photons as quantum resources, a novel quantum private comparison protocol is designed. The four quantum states of a single photon, |0>, |1>, |+>, and |->, represent two classical bits 00, 01, 10, and 11, respectively. A semi-loyal third party is introduced to participate in the comparison, and a comparison with a quantum bit efficiency of 200% is achieved through unitary operations and decoy photon technology.

Benefits of technology

It achieves efficient comparison of whether private data is equal without leaking private data, with a quantum bit efficiency of 200%, and provides theoretically unconditional security through decoy photon technology, resisting external and internal attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure BDA0005524315280000043
    Figure BDA0005524315280000043
  • Figure BDA0005524315280000051
    Figure BDA0005524315280000051
  • Figure BDA0005524315280000084
    Figure BDA0005524315280000084
Patent Text Reader

Abstract

The QPC (Quantum Private Comparison) can finish the comparison work of two pieces of private data under the condition of no leakage; the working efficiency of quantum private comparison can be measured by a parameter called quantum bit efficiency; at present, no matter a full-quantum QPC protocol or a semi-quantum QPC protocol, the quantum bit efficiency of the prior art is not greater than 100%, and the quantum bit efficiency of most existing QPC protocols is far lower than 100%; according to the invention, a QPC protocol with quantum bit efficiency up to 200% is created by using a method of carrying out two-bit classic bit coding on four quantum states of a single photon; analysis shows that the protocol provided by the invention has basic security and correctness of a QPC protocol; compared with the prior art, the method has the advantages that the quantum resources used are simple, the protocol is easy to implement, and the working efficiency is high.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to a method for realizing a quantum private comparison protocol for comparing two classical bits by using one photon as a quantum resource. BACKGROUND

[0002] Quantum cryptography has theoretically unconditional security[1,2]. Quantum private comparison (QPC) is a branch of quantum cryptography, which can protect the privacy of private data while comparing two data to determine whether they are equal. At present, there are various QPC protocols[3-32]. However, the quantum bit efficiency of these protocols is less than 100%.

[0003] The present application uses the method provided in document

[33] to prepare single photons, and designs a new QPC protocol by using only single photons as quantum resources. The present application uses all four quantum states of single photons, i.e. the four quantum states |0>, |1>, |+> and |-> of the polarization degree of the photons represent the classical bits 00, 01, 10 and 11 of two bits respectively. On the basis of this quantum encoding method, a quantum private comparison protocol is realized, and the quantum bit efficiency can be as high as 200%, which is much higher than the prior art.

[0004] Lo

[34] once pointed out that it is impossible to design a secure equality function in a scenario with only two participants. Therefore, an additional third party (TP) is needed to participate in the QPC protocol. According to this research conclusion, the present application will let a semi-honest third party (STP) participate in the following QPC protocol. "Semi-honest" means that the STP itself may steal the private data of the end user, but it will faithfully execute the protocol process, neither be bribed by external eavesdroppers to corrupt and engage in malpractice, nor conspire with any internal user to steal the private data of another user. In this way, there will be three QPC participants in the QPC protocol invented by the present application: two end users and one STP.

[0005] REFERENCES

[0006] [1] Bennett, C. H.; Brassard, G.: Quantum cryptography: public key distribution and coin tossing. In: Proceedings of IEEE International Conference on Computers Systems and Signal Processing, Bangalore, India, 175-179 (1984)

[0007] [2] Shor P. W.; Preskill J.: Simple proof of security of the BB84 quantum key distribution protocol. Phys. Rev. Lett. 85(2), 441-444 (2000)

[0008] [3] Yang, Y. G.; Wen, Q. Y.: An efficient two-party quantum private comparison protocol with decoy photons and two-photon entanglement, J. Phys. A Math. Theor.. 42(5), P055305 (2009)

[0009] [4] Yang, Y. G.; Cao, W. F.; Wen, Q. Y.: Secure quantum private comparison, Phys. Scr.. 80(6), 065002 (2009)

[0010] [5] Lin, J.; Tseng, H. Y.; Hwang, T.: Intercept-resend attacks on Chen et al.’s quantum private comparison protocol and the improvements, Opt. Commun.. 284, 2412-2414 (2011)

[0011] [6] Tseng, H. Y.; Lin, J.; Hwang, T.: New quantum private comparison protocol using EPR pairs, Quantum Inf. Process.. 11 (2), 373-384 (2012)

[0012] [7] Liu, W.; Wang, Y. B.: Quantum private comparison based on GHZ entangled states, Int. J. Theor. Phys.. 51, 3596-3604 (2012)

[0013] [8] Huang, W.; Wen, Q. Y.; Liu, B.; Gao, F.; Sun, Y.: Robust and efficient quantum private comparison of equality with collective detection over collective-noise channels, Sci. China Phys. Mech. Astron.. 56, 1670-1678 (2013)

[0014] [9] Liu, B.; Gao, F.; Jia, H. Y.; Huang, W.; Zhang, W. W.; Wen, Q. Y.: Efficient quantum private comparison employing single photons and collective detection, Quantum Inf. Process. 12 (2), 887-897 (2013)

[0015]

[10] Sun, Z. W.; Yu, J. P.; Wang, P.; Xu, L. L.; Wu, C. H.: Quantum private comparison with a malicious third party, Quantum Inf. Process. 14 (6), 2125-2133 (2015)

[0016]

[11] Xu, L.; Zhao, Z.: High-capacity quantum private comparison protocol with two- photon hyperentangled Bell states in multiple-degree of freedom, Eur. Phys. J. D.. 73, 58 (2019)

[0017]

[12] Ji, Z. X.; Zhang, H. G.; Fan, P. R.: Two-party quantum private comparison protocol with maximally entangled seven-qubit state, Mod. Phys. Lett. A. 34(28), 1-179 (2019)

[0018]

[13] Chang, Y.; Zhang, S. B.; Yan, L. L.; et al.: Device-independent quantum key distribution protocol based on hyper-entanglement, Computers, Materials & Continua. 65(1), 879-896 (2020)

[0019]

[14] Ji, Z.; Fan, P.; Zhang, H.; Wang, H.: Greenberger-Horne-Zeilinger-based quantum private comparison protocol with bit-flipping, Phys. Scr.. 96, 015103 (2020)

[0020]

[15] Lang, Y.-F.: Quantum gate-based quantum private comparison, Int. J. Theor. Phys.. 59, 833-840 (2020)

[0021]

[16] Huang, X.; Zhang, S. B.; Chang, Y.; Hou, M.; Cheng, W.: Efficient quantum private comparison based on entanglement swapping of bell states, Int. J. Theor. Phys.. 60, 3783-3796 (2021)

[0022]

[17] Lang, Y.-F.: Quantum Private Comparison Using Single Bell State, Int. J. Theor. Phys.. 60(11-12), 4030-4036 (2021)

[0023]

[18] Wu, W. Q.; Zhao, Y. X.: Quantum private comparison of size using d-level Bell states with a semi-honest third party, Quantum Inf. Process.. 20, 155 (2021)

[0024]

[19] Tsai, C.-W.; Lin, J.; Chao, H.-C.; Yang, C.-W.: Cryptanalysis and improvement on two party quantum private comparison based on seven-qubit and eight-qubit states, Mod. Phys. Lett. A. 37(19), 2250120 (2022)

[0025]

[20] Fan, P.; Rahman, A. U.; Ji, Z. X.; Ji, X. M.; Hao, Z. Q.; Zhang, H. G.: Two-party quantum private comparison based on eight-qubit entangled state, Mod. Phys. Lett. A. 37(5), 2250026 (2022)

[0026]

[21] Xiao, M.; Ma, C. A.: Fault-tolerant Quantum Private Comparison Protocol, Int. J. Theor. Phys. 61(2), 41 (2022)

[0027]

[22] Sun, Q.: Quantum private comparison with six-particle maximally entangled states, Mod. Phys. Lett. A. 37(23), 2250149 (2022)

[0028]

[23] Lang, Y.-F.: Fast Quantum Private Comparison without Keys and Entanglement, Int. J. Theor. Phys. 61(2), 45 (2022)

[0029]

[24] Kou, T.-Y.; Che, B.-C.; Dou, Z.; et al.: Efficient quantum private comparison protocol utilizing single photons and rotational encryption, Chin. Phys. B. 31(6), 060307 (2022)

[0030]

[25] Hou, M.; Wu, Y.: New Quantum Private Comparison Using Bell States, Entropy. 26, 682 (2024)

[0031]

[26] Huang, X.; Zhang, W.; Zhang, S.: Practical quantum protocols for blind millionaires’ problem based on rotation encryption and swap test, Phys. A Stat. Mech. Its Appl. 637, 129614 (2024)

[0032]

[27] Hou, M.; Wu, Y.: Single-photon-based quantum secure protocol for the socialist millionaires’ problem, Front. Phys.. 12, 1364140 (2024)

[0033]

[28] Boyer, M.; Kenigsberg, D.; Mor, T.: Quantum key distribution with classical Bob, Phys. Rev. Lett.. 99(14), 140501 (2007)

[0034]

[29] Boyer, M.; Gelles, R.; Kenigsberg, D.; Mor, T.: Semiquantum key distribution, Phys. Rev. A.. 79(3), 032341 (2009)

[0035]

[30] Lang, Y.-F.: Semi-quantum private comparison using single photons, Int. J. Theor. Phys.. 57(10), 3048-3055 (2018)

[0036]

[31] Li, Q.; Li, P. s.; Xie, L.; Chen, L. I.; Quan, J. y.: Security analysis and improvement of a semi-quantum private comparison protocol with three-particle G-like states, Quantum Inf. Process.. 21(4), 91 (2022)

[0037]

[32] Gong, L.-H.; et al.: Novel semi-quantum private comparison protocol with Bell states, Laser Phys. Lett.. 21, 055209 (2024)

[0038]

[33] Ding, X.; Guo, Y.-P.,; Xu, M.-C.; et al.: High-efficiency single- photon source above the loss-tolerant threshold for efficient linear optical quantum computing, Nature Photonics. 19, 387-391 (2025)

[0039]

[34] Lo, H. K.: Insecurity of quantum secure computations, Phys. Rev. A. 56(2), 1154-1162 (1997)

[0040]

[35] Long, G. L.; Liu, X. S.: Theoretically efficient high-capacity quantum- key-distribution scheme, Phys. Rev. A. 65, 032302 (2002)

[0041]

[36] Li, C. Y.; Zhou, H. Y.; Wang, Y.; Deng, F. G.: Secure quantum key distribution network with Bell states and local unitary operations, Chin. Phys. Lett. 22(5), 1049-1052 (2005)

[0042]

[37] Li, C. Y.; Li, X. H.; Deng, F. G.; Zhou, P.; Liang, Y. J.; Zhou, H. Y.: Efficient quantum cryptography network without entanglement and quantum memory, Chin. Phys. Lett. 23(11), 2896-2899 (2006) SUMMARY

[0043] In view of the defects of the prior art, i.e., the quantum bit efficiency of the existing quantum private comparison protocol is less than 100%, the present application creates a quantum private comparison protocol with a quantum bit efficiency of 200%.

[0044] The following introduces the pre-knowledge to be used in the present application. The symbols |0> and |1> are used to represent the horizontal and vertical polarization of a photon respectively. In this way, two non-orthogonal polarization degree preparation bases can be marked as Z = { |0>, |1>} and X = { |+>, |->}, where and In the polarization degree, there are four unitary operations, the expressions of which are formula (1), (2), (3) and (4). The four unitary operations can all operate the following four quantum states |0>, |1>, |+> and |->, so as to evolve them into other quantum states, the expressions of the evolution are represented by formula (5), (6), (7) and (8). The two unitary operations of (5) and (6) do not change the measurement base of the photon, while the two unitary operations of (7) and (8) change the measurement base of the photon, that is, the Z measurement base of the photon is changed into the X measurement base and the X measurement base is changed into the Z measurement base. Table 1 lists 16 operation results of the four polarization degree states |0>, |1>, |+> and |-> under the action of the above four unitary operations.

[0045] U 00 = |0><0| + |1><1| (1)

[0046] U 01 = |1><0| - |0><1| (2)

[0047]

[0048] U 00 |0> = |0>, U 00 |1> = |1>, U 00 |+> = |+>, U 00 |-> = |-> (5)

[0049] U 01 |0> = |1>, U 01 |1> = -|0>, U 01 |+> = -|->, U 01 |-> = |+> (6)

[0050] U 10 |0> = |+>, U 10 |1> = |->, U 10 |+> = |0>, U 10 |-> = |1> (7)

[0051] U 11 |0> = |->, U 11 |1> = -|+>, U 11 |+> = -|1>, U 11 |-> = |0> (8)

[0052] Table 1: The effect of the four kinds of polarization degree of unitary operation

[0053] DETAILED DESCRIPTION

[0054] Quantum private comparison (QPC) can compare whether the private data is equal without revealing the specific value of the private data. The quantum bit efficiency of the prior art is less than 100% without involving quantum entanglement. In order to improve the quantum bit efficiency and reduce the implementation cost, the present application invents a quantum private comparison method with a quantum bit efficiency of 200% under the condition of not involving quantum entanglement but only using single photons. The name of the method is quantum private comparison protocol for comparing two classical bits by single photons. The protocol is that two private data comparison parties A and B compare whether the private data is equal under the hosting of a semi-trusted third party (STP). A and B respectively own private data A=a L-1 ...a j ...a1a0and B=b L- 1...b j ...b1b0, where a j ,b j ∈{00,01,10,11}, j∈{0,1,...,L-1}, 2 2L-1 ≤max{A,B}<2 2L ; the specific steps of the protocol are as follows:

[0055] Step 1: STP generates L+D1+D2 single photons, the states of which are randomly selected from the following four quantum states{|0>,|1>,|+>,|->}. Among them, L photons constitute a quantum sequence T=(t L-1 ...t j ...t1t0), where j∈{0,1,...,L-1}, the quantum sequence T will be used to compare the equality of the private data of A and B; and the other D1+D2 photons will be used as decoy photons for two times of eavesdropping behavior checking, the D1+D2 photons are randomly inserted into the quantum sequence T; only STP knows the positions of the L+D1+D2 single photons and their corresponding measurement bases and quantum initial states; if STP uses bit 0 / 1 to represent the measurement bases of quantum states{|0>,|1>} / {|+>,|->}, then the bit sequence representing the measurement basis of T is MT=(mt L-1 ...mt j ...mt1mt0), where mt j∈ {0,1}, j∈ {0,1,...,L-1}; STP sends the L+D1+D2 single photons to Alice through quantum channel in the way of quantum data block

[35] ;

[0056] Step 2: After receiving the L+D1+D2 single photons, STP announces the position and measurement basis of D1 single photons; Alice measures the D1 photons according to the information announced by STP; then Alice tells STP the measurement results of the D1 photons through classical channel in the way of announcement; STP checks whether there is an eavesdropper in the quantum channel from STP to Alice according to the announced measurement results; if the checking result is that the error rate of the D1 photons is lower than the normal threshold, the protocol continues to step 3; otherwise, the protocol terminates this run and then restarts the protocol;

[0057] Step 3: STP announces the related information of the remaining D2 photons, i.e. position, measurement basis and quantum initial state; after obtaining the information, Alice rearranges the order of the D2 photons, and the D2 photons form a new quantum sequence RD2; at this time, only Alice knows the measurement basis and quantum initial state of each photon in the quantum sequence RD2; at the same time, Alice keeps the order of the last remaining L photons unchanged and performs a unitary operation on the L photons After the unitary operation is performed, the quantum sequence T evolves into a new quantum sequence UT; if the unitary operation is U 00 or U 01 , Alice records ma j as 0; otherwise, the unitary operation is U 10 and U 11 , Alice records ma j as 1; in this way, Alice obtains a bit string MA=(ma L- 1...ma j ...ma1ma0), where ma j ∈ {0,1}, j∈ {0,1,...,L-1}; Alice randomly inserts each photon in RD2 into the quantum sequence UT in the original order to form a new quantum sequence RD2+UT, and sends the quantum sequence RD2+UT to Bob through the quantum channel;

[0058] Step 4: When the quantum sequence RD2+UT arrives at Beth, Alice announces the positions of the RD2 photons in the quantum sequence RD2+UT and their measurement bases; Beth measures the RD2 photons according to the information announced by Alice and tells Alice the measurement results through a classical channel in a public way; Alice checks whether there is an eavesdropper in the quantum channel from Alice to Beth according to the measurement results of Beth; if the checking result is normal, the protocol continues and goes to Step 5; otherwise, the current run of the protocol is terminated and the protocol is restarted;

[0059] Step 5: When Beth discards the RD2 photons and recovers the quantum sequence UT, since the unitary operation U 00 and U 01 does not change the measurement bases of the quantum sequence T, the unitary operation U 10 and U 11 changes the measurement bases of T, so Beth first informs Alice and STP to announce the MA and MT respectively; then calculates the expression where mta j ∈{0,1} and j∈{0,1,...,L-1}, is a binary XOR operator; the mta j composes a bit string MTA=(mta L-1 ...mta j ...mta1mta0); and then measures UT using the MTA: if mta j is bit 0 / 1, then Beth measures Ut j using the measurement bases of{|0>,|1>} / {|+>,|->}; if the measurement results |0>,|1>,|+> and |-> are recorded as 00, 01, 10 and 11 respectively, then Beth can obtain a bit sequence TA=(ta L-1 ...ta j ...ta1ta0), where ta j ∈{00,01,10,11} and j∈{0,1,...,L-1}; if STP also records the quantum states |0>,|1>,|+> and |-> in the quantum sequence T as 00, 01, 10 and 11 respectively, then the quantum initial state of the quantum sequence T can be represented as TIS=(tis L- 1...tis j ...tis1tis0), where tis j ∈{00,01,10,11} and j∈{0,1,...,L-1}, and only STP knows the TIS; after obtaining the bit sequence TA, Beth performs a bitwise XOR operation on the TA and the private data B where tabj ∈ {00, 01, 10, 11}, j e {0, 1,..., L - 1}, is a binary XOR operator and publishes the result TAB = (tab L-1 ... tab j ... tab1tab0) ;

[0060] Step 6: When the STP receives the TAB value published by B, it compares the TAB with the TIS in the hand of the STP; if they are equal, the STP publishes that the private data of A and B are equal; otherwise, it publishes that the private data of the two users are not equal.

[0061] Embodiment

[0062] To facilitate the understanding of the above protocol, an example is given below to illustrate the flow of the protocol. Here, we assume that A = 11100001 and B = 10010011. According to the protocol, it can be deduced that L = 4.

[0063] Step 1*: Suppose that T = (t3t2t1t0) = {|->|1>|+>|0>}. Thus, MT = (mt3mt2mt1mt0) = 1010.

[0064] Step 3*: UT = {(Ut3)(Ut2)(Ut1)(Ut0)} = {(U 11 ·|->)(U 10 ·|1>)(U 00 ·|+>)(U 01 ·|0>)} = {|0>|->|+>|1>}. MA = (ma3ma2ma1ma0) = 1100.

[0065] Step 5*: Since B measures Ut3, Ut2, Ut1 and Ut0 with the measurement bases {|0>, |1>}, {|+>, |- >}, {|+>, |- >} and {|0>, |1>} respectively, i.e. measures the quantum sequence {|0>|->|+>|1>}; B obtains TA = (ta3ta2ta1ta0) = 00111001;

[0066] Step 6*: According to T = (t3t2t1t0) = {|->|1>|+>|0>}, the STP knows that TIS = 11011000. Since TIS ≠ TAB = 10101010, the STP announces that the private data of A and B are different.

[0067] In the above example, the private data A = 11100001 of Alice is not equal to the private data B = 10010011 of Bob, which is consistent with the announcement of the STP. Thus, the protocol has the correct function.

[0068] Qubit efficiency

[0069] According to the reference [6], the qubit efficiency is denoted by η, and its definition is shown in equation (9).

[0070]

[0071] where c represents the number of bits of the data to be compared in a comparison stage; and q represents the number of photons used for comparison in a comparison stage, here excluding the number of decoy photons, because the number of decoy photons can be considered as belonging to another independent operation flow. In the protocol, 1 photon t j is used to compare 2 bits of data, i.e. 2 bits of data a j of Alice and 2 bits of data b j of Bob. Thus, q = 1 and c = 2. Therefore, without considering the security check link,

[0072] Correctness analysis

[0073] According to the method of encoding the quantum states |0>, |1>, |+> and |-> by two bits of data 00, 01, 10 and 11 respectively, the effect of the unitary operation of Alice is equivalent to equation (10). Thus, the bitwise XOR operation of the two bits of data of Bob can be rewritten as equation (11).

[0074]

[0075] According to equation (11), if tab j = tis j , it means that which means that a j is equal to b j . If tab j ≠ tis j , we deduce that which tells us that a j ≠ b j . Therefore, the STP can determine whether the private data of Alice and that of Bob are equal by comparing whether the received TAB is the same as the TIS in its hand. Thus, the invented QPC protocol has the correct function.

[0076] Security analysis

[0077] The security of the protocol is analyzed from both external attacks and internal attacks.

[0078] External attack analysis

[0079] In the invented QPC protocol, there are totally 6 steps, among which three steps, i.e., steps 1, 3 and 5, are at risk of security, while the remaining three steps are not at risk of external attack, because decoy photons are used in steps 1 and 3, and quantum measurement results are announced through classical information channel in step 5. All the three communications are vulnerable to attacks from external attackers. As to steps 1 and 3, the quantum sequences L+D1+D2 and RD2+UT contain decoy photons, which can be used to detect whether there is an external attacker. According to references [36, 37], the decoy photon technique can provide theoretically unconditional security for the above photon communications, because the technique is considered as a copy of the method for detecting eavesdropping in the famous BB84 protocol, which is proved to have theoretically unconditional security [2].

[0080] Although the decoy photons D2 are prepared by the STP, they are reordered by Alice, and constitute a new quantum sequence RD2. As long as Alice does not announce the positions and measurement bases of the RD2 photons, no one knows the measurement bases and initial states of the decoy photons RD2 except Alice. Therefore, RD2 can still be used as decoy photons safely. Based on this, the quantum communications in steps 1 and 3 are protected by the decoy photon technique. Therefore, steps 1 and 3 are secure.

[0081] In step 5, because the external attacker knows nothing about TIS, and only the STP knows the value of TIS, according to equation (11), the external attacker is impossible to deduce the secret data of the two users from the TAB encrypted by TIS. In summary, the invented QPC protocol can prevent external attacks.

[0082] Internal attack analysis

[0083] As to internal attacks, there are two cases: the first case is that the STP wants to steal the secret data of the two users; the second case is that the two users steal each other's secret data. Therefore, we only need to analyze the above two cases.

[0084] Case 1: Attack of the STP

[0085] If STP wants to steal the private data of the user, it can only attack the quantum sequence UT. If it does so, it will be detected as an external attacker by Alice, because the quantum sequence UT is secured by the decoy photon technique [36, 37] with the decoy photons RD1 included. Therefore, STP is impossible to succeed in stealing the private data A of Alice. Without the data A, it is even more impossible to deduce the private data B of Bob by using equation (11). Therefore, the protocol is not threatened by the attack of STP.

[0086] Case 2: Mutual attack between users

[0087] First, we analyze the first scenario that Alice steals the private data of Bob. Alice has only one chance to achieve this goal, which is to use the TAB value published by Bob to deduce the private data of Bob. However, since STP is semi-honest, STP is impossible to collude with Alice to steal the private data of Bob. This means that STP is impossible to leak the TIS value in the hand of STP to Alice. In this way, Alice is unable to deduce the private data B of Bob according to equation (11) because she has no knowledge of the TIS value. Therefore, the attack of Alice is impossible to succeed.

[0088] Next, we analyze the second scenario that Bob steals the private data of Alice. To do this, Bob can only use the quantum sequence UT he received himself, and the quantum measurement of the sequence corresponds to the classical information value TA. Since STP is semi-honest, STP is prohibited from colluding with any party in the protocol to steal private data. Therefore, STP is impossible to leak the TIS value it knows to Bob. Since Bob does not know the TIS value, Bob is impossible to deduce the private data A of Alice from TA according to equation (10).

[0089] In summary, the above analysis shows that Alice and Bob are impossible to steal each other's private data.

[0090] Based on the above security analysis of the two internal attacks, we can conclude that the invented QPC protocol is also capable of resisting internal attacks.

[0091] In summary, the protocol can both prevent external attacks and resist internal attacks, and is secure in security.

[0092] Comparison with previous QPC protocols

[0093] In terms of qubit efficiency, the QPC protocol surpasses all existing QPC protocols - its qubit efficiency reaches 200%. In order to more comprehensively evaluate the invented protocol, we compare the QPC protocol with some existing QPC protocols. We compare them from five aspects: quantum resources, quantum entanglement, quantum unitary operations, quantum measurements and qubit efficiency. The comparison results are listed in Table 1. From Table 1, we can see that the QPC protocol of the application has the characteristics of simplicity, easy operation and high qubit efficiency.

[0094] Table 1 Comparison of the QPC protocol of the application with some existing QPC protocols

[0095]

[0096] Compared with the prior art, the qubit efficiency of the QPC protocol of the application is as high as 200%. It is also lower than many existing QPC protocols in terms of implementation difficulty and cost, because it only uses single photons and unitary operations acting on single photons. It can be implemented without obstacles and at low cost with existing conventional quantum technology. Therefore, the application has the creativity, practicality and novelty required by the Patent Law. This is the reason why the patent application can be granted a patent.

Claims

1. Quantum private comparison (QPC) can compare whether the private data is equal without revealing the specific value of the private data; the quantum bit efficiency of the prior art is less than 100% without involving quantum entanglement; in order to improve the quantum bit efficiency and reduce the implementation cost, the present application invents a quantum private comparison method with a quantum bit efficiency of 200% under the condition of not involving quantum entanglement and only using single photons, and the name of the method is quantum private comparison protocol for comparing two classical bits by single photons; the protocol is that two private data comparison parties A and B compare whether the private data is equal under the hosting of a semi-loyal third party STP, A and B respectively own private data A=a L-1 ...a1a0 and B=b L-1 ...b1b0, wherein a j ,b j ∈{00,01,10,11}, j∈{0,1,...,L-1}, 2 2L-1 ≤max{A,B}<2 2L ; the protocol is characterized in that: Step 1: STP generates L+D1+D2 single photons, whose states are randomly chosen from the following four quantum states { |0>, |1>, |+>, |->}, where L photons form a quantum sequence T = (t L-1 ...t j ...t1t0), here j e {0, 1,..., L-1}, the quantum sequence T will be used to compare the equality of Alice's and Bob's private data; while the other D1+D2 photons will be used as decoy photons for two times of eavesdropping behavior check, which are randomly inserted into the quantum sequence T; only STP knows the positions of the L+D1+D2 single photons and their corresponding measurement bases and quantum initial states; if STP uses bit 0 / 1 to represent the measurement bases of quantum states { |0>, |1>} / { |+>, |->}, then the bit sequence representing the measurement bases of T is MT = (mt L-1 ...mt j ...mt1mt0), here mt j e {0, 1}, j e {0, 1,..., L-1}; STP sends the L+D1+D2 single photons to Alice in the form of quantum data blocks through a quantum channel; Step 2: After Bob receives the L+D1+D2 single photons, STP announces the positions and measurement bases of the D1 single photons, and Bob measures the D1 photons according to the information announced by STP. Then Bob tells STP the measurement results of the D1 photons through the classical channel in a public way. STP checks whether there is an eavesdropper in the quantum channel from STP to Bob according to the announced measurement results. If the checking result is that the error rate of the D1 photons is below the normal threshold, the protocol continues to step 3; otherwise, the protocol terminates this run and then restarts the protocol; Step 3: STP publishes the information of the remaining D2 photons, i.e. the position, the measurement basis and the quantum initial state; after obtaining the information, Alice rearranges the order of the D2 photons, and the D2 photons form a new quantum sequence RD2; at this time, only Alice knows the measurement basis and the quantum initial state of each photon in the quantum sequence RD2; meanwhile, Alice keeps the order of the last remaining L photons unchanged and performs a unitary operation on the L photons After the unitary operation is performed, the quantum sequence T evolves into a new quantum sequence UT; if the unitary operation is U 00 or U 01 , Alice records ma j as 0; otherwise, the unitary operation is U 10 and U 11 , Alice records ma j as 1; in this way, Alice obtains a bit string MA = (ma L- 1...ma j ...ma1ma0), where ma j ∈ {0, 1}, j ∈ {0, 1,..., L-1}; Alice randomly inserts each photon in the quantum sequence RD2 into the quantum sequence UT in the original order to form a new quantum sequence RD2+UT, and sends the quantum sequence RD2+UT to Bob through a quantum channel; Step 4: When the quantum sequence RD2+UT reaches Alice, Bob announces the positions of the RD2 photons in the quantum sequence RD2+UT and their measurement bases. Alice measures the RD2 photons according to the information announced by Bob and tells Bob the measurement results through the classical channel in a public way. Bob checks whether there is an eavesdropper in the quantum channel from Bob to Alice according to the measurement results of Alice. If the checking result is normal, the protocol continues to step 5; otherwise, the protocol terminates this run and then restarts the protocol; Step 5: When Bob discards the RD2 photons and recovers the quantum sequence UT, since Alice's unitary operation U 00 and U 01 will not change the measurement basis of the quantum sequence T, Alice first informs Charlie and STP to respectively announce the MA and MT, and then calculates the expression 10 and U 11 will change the measurement basis of T, Alice first informs Charlie and STP to respectively announce the MA and MT, and then calculates the expression where mta j ∈{0,1}, j∈{0,1,...,L-1}, and is the binary XOR operator; the mta j bit string MTA=(mta L-1 ...mta j ...mta1mta0); and then measures UT using the MTA: if mta j is bit 0 / 1, then Bob measures Ut using the measurement basis of {|0>,|1>} / {|+>,|->} j ; if the measurement results |0>,|1>,|+> and |-> are recorded as 00, 01, 10 and 11 respectively, then Bob can obtain the bit sequence TA=(ta L-1 ...ta j ...ta1ta0), where ta j ∈{00,01,10,11}, j∈{0,1,...,L-1}; if STP also records the quantum states |0>,|1>,|+> and |-> in the quantum sequence T as 00, 01, 10 and 11 respectively, then the quantum initial state of the quantum sequence T can be represented as TIS=(tis L-1 ...tis j ...tis1tis0), where tis j ∈{00,01,10,11}, j∈{0,1,...,L-1}, and only STP knows the TIS; after Bob obtains the bit sequence TA, Bob performs a bitwise XOR operation on the TA and the private data B where tab j ∈{00,01,10,11}, j∈{0,1,...,L-1}, is the binary XOR operator, and announces the calculation result TAB=(tab L-1 ...tab j ...tab1tab0). Step 6: After STP receives the TAB value announced by Alice, STP compares whether the TAB and the TIS in the hand of STP are equal. If they are equal, STP announces that the private data of Bob and Alice are equal; otherwise, STP announces that the private data of the two users are not equal.