Identity authentication methods, systems, devices, and media based on quantum secret sharing

By combining weak coherent state coding and single-photon interferometry with quantum secret sharing technology based on hash functions, the problems of high hardware complexity and high cost in power grid dispatching are solved, the security and reliability of power grid information transmission are realized, the coding implementation is simplified, and the information processing efficiency is improved.

CN120934904BActive Publication Date: 2026-01-06ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511446263.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-11
Publication Date
2026-01-06
Estimated Expiration
2045-10-11

AI Technical Summary

Technical Problem

Existing quantum secret sharing technologies suffer from high hardware complexity, high cost, and stringent technical requirements in power grid dispatching, making it difficult to guarantee the security and reliability of information transmission in the power grid environment.

Method used

Weakly coherent state coding technology is used to generate weakly coherent optical pulses by controlling the quantum secret sharing mechanism between the master station and the factory station through phase and intensity modulation. Combined with single-photon interferometry and hash function, a security key is generated and identity authentication is performed.

Benefits of technology

It simplifies hardware configuration, reduces system complexity and cost, ensures unconditional security, improves the security and reliability of information transmission, simplifies coding implementation, and improves information processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934904B_ABST
    Figure CN120934904B_ABST
Patent Text Reader

Abstract

The present application belongs to the technical field of quantum secure communication, and discloses an identity authentication method, system, device and medium based on quantum secret sharing, to solve the security problem of identity authentication of a control master station in a power grid environment. The method is implemented by one control master station and at least two plant stations, and includes key distribution and identity authentication. The present application constructs a quantum secret sharing mechanism between the control master station and the plant stations, wherein the plant station end only needs to modulate the phase and intensity of weak coherent light pulses to encode information, without complex entangled resources; at the same time, the control master station end only needs to be equipped with a standard single-photon interferometric measurement device to complete the key distribution. This design significantly simplifies the hardware configuration, reduces the system complexity, and ensures unconditional security through strict security analysis.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of quantum secure communication technology, and specifically relates to an identity authentication method, system, device and medium based on quantum secret sharing. Background Technology

[0002] In power systems, the authentication of the control station is crucial, especially in ensuring the safe and stable operation of the power grid. The control station bears the heavy responsibility of dispatching and commanding the entire power grid, involving the effective management and precise control of a vast number of generating units, substations, and loads. Therefore, the authentication mechanism of the control station must possess extremely high reliability and security to cope with the complex situations and potential risks inherent in power grid operation.

[0003] Secret sharing, a key tool in cryptography, works by breaking down secret information into multiple parts and distributing them to different participants. Since a single participant cannot access the complete secret, only through the collaborative efforts of a certain number of participants can it be successfully deciphered, thus ensuring a certain level of security. However, with the rapid development of quantum computing technology, the shortcomings of traditional classical secret sharing schemes are becoming increasingly apparent, facing potential security threats and failing to meet the growing security demands.

[0004] In 1999, Hillery et al. proposed a secret-sharing protocol based on three-particle entangled states (HBB protocol). This protocol guarantees security based on the quantum no-cloning theorem, bringing a completely new security and confidentiality approach to the field of secret sharing. Since then, numerous quantum secret-sharing schemes have emerged. For example, Fu Yao et al. proposed a measurement-device-independent quantum cryptography sharing scheme using post-selected GHZ entangled states (Physical review letters 114(9): 090501.); Chinese invention patent (publication number CN114362945A) proposed a quantum secret-sharing scheme based on entanglement swapping; and Chinese invention patent (publication number CN115549908A) proposed a quantum secret-sharing scheme and system based on phase encoding. However, these existing schemes have problems that cannot be ignored. On the one hand, the technical requirements are extremely demanding, involving complex quantum operations and precise equipment configurations, which not only increases the technical difficulty in the implementation process, but also places extremely high demands on the professional competence of the operators. On the other hand, high technical requirements inevitably lead to high costs, including equipment purchase, maintenance, and personnel training, which significantly reduces the economic feasibility of the solution. These shortcomings severely limit its promotion and further development in practical applications.

[0005] In summary, existing technologies cannot effectively integrate quantum secret sharing technology with power grid dispatching applications, thus failing to guarantee the security of information transmission in the power grid environment and failing to provide solid and reliable technical support for the stable operation of the power system. Summary of the Invention

[0006] Based on the aforementioned shortcomings and deficiencies in the existing technology, one of the objectives of this invention is to at least solve one or more of the aforementioned problems in the existing technology. In other words, one of the objectives of this invention is to provide an identity authentication method, system, device, and medium based on quantum secret sharing that meets one or more of the aforementioned requirements, aiming to solve the security problem of identity authentication of the control master station in the power grid environment and improve the security and reliability of information transmission.

[0007] To achieve the above-mentioned objectives, the present invention adopts the following technical solution.

[0008] In a first aspect, this invention provides an identity authentication method based on quantum secret sharing, implemented by a control master station and at least two substations, including key distribution and identity authentication. The specific steps are as follows: Each substation prepares coherent optical pulses with the same intensity, performs phase modulation and intensity modulation to obtain a coherent state or a vacuum state, attenuates it to the single-photon level using an adjustable optical attenuator, and then sends the weakly coherent optical pulses into an optical fiber channel; the control master station receives the weakly coherent optical pulses from each substation and performs interferometry. If successful, it publishes the measurement result and the corresponding classical bits; otherwise, it publishes the measurement failure; after each substation and the control master station repeat the weakly coherent optical pulse transmission and reception operation multiple times, each substation publishes the state selection of all successful measurement rounds in which at least one party sent a vacuum state, and retains the data from the remaining successful measurement rounds to form its respective sieved key; each substation publishes a portion of the sieved key to calculate key increment. The control station calculates the gain, bit error rate, and phase error rate; it coordinates the master station and each substation to perform error correction and security enhancement on the remaining filtered keys, generating the final security key; the master station sequentially selects a key of a preset length from multiple security keys to construct a hash function, performs hash operation on the identity scheduling information to obtain a digest, and then selects another key of a preset length to encrypt the digest to generate a signature; the master station sends the identity scheduling information and the corresponding signature to a target substation, which, upon receiving the signature, sends a key request to other substations, which respond to the request and send part of their security keys to the target substation; the target substation, based on its local security key and the received security key, reconstructs the decryption key, decrypts the signature to obtain the first digest, calculates the second digest of the identity scheduling information, compares the first digest and the second digest, and if they match, authentication is successful.

[0009] As a preferred embodiment, the power station includes power station A and power station B; the phase modulation is based on a 50 / 50 probability random selection of phase 0 or... Phase modulation is performed; the intensity modulation is to completely cut off the light pulse with a one-third probability to prepare a vacuum state. This allows for the preparation of the first coherent state. The second coherent state and vacuum state The probability of each is one-third.

[0010] As a preferred embodiment, the control master station performs the interferometric measurement using a 50:50 beam splitter and two threshold detectors. When the phase difference between the two optical pulses from station A and station B is 0, and only the first threshold detector responds, the measurement is considered successful and classical bit 0 is recorded. If only the second threshold detector responds, the measurement is considered successful and classic bit 1 is recorded; if neither threshold detector responds or both respond simultaneously, the measurement is considered a failure.

[0011] As a preferred scheme, the rounds corresponding to the data reserved for constructing the sieve key are successful measurement rounds in which both plant A and plant B sent data in a non-vacuum state, including four encoding combinations, the expression of which is: .

[0012] As a preferred embodiment, the key gain is defined as the conditional probability of the master station achieving a successful measurement under a specific combination of non-vacuum states; the bit error rate is calculated by comparing the difference between the transmitted and received key bits, which involves the amplitude parameter of the coherent state.

[0013] As a preferred embodiment, the hash function includes the Toeplitz hash function based on a linear feedback shift register and the generalized division hash function.

[0014] Secondly, this invention provides an identity authentication system based on quantum secret sharing, used to implement the identity authentication method described in the first aspect, comprising a control master station and at least two substations; each substation is used to prepare coherent optical pulses with the same light intensity, and perform phase modulation and intensity modulation to obtain a coherent state or a vacuum state, which is then attenuated to the single-photon level by an adjustable optical attenuator to obtain a weakly coherent optical pulse, which is then sent into an optical fiber channel; the control master station is used to receive the weakly coherent optical pulses from each substation and perform interferometric measurements. If successful, the measurement result and the corresponding classical bit are published; otherwise, the measurement failure is published; after repeated weakly coherent optical pulse transmission and reception operations, each substation and the control master station publish the state selection of all successful measurement rounds in which at least one party has sent a vacuum state, and retain the data of the remaining successful measurement rounds to form their respective sieved keys; each substation publishes a portion of the sieved keys to calculate the secret key. The system calculates key gain, bit error rate, and estimates phase error rate; it coordinates the master station and each substation to perform error correction and security enhancement on the remaining filtered keys, generating the final security key; the master station sequentially selects multiple security key segments of a preset length to construct a hash function, performs hash operation on the identity scheduling information to obtain a digest, and then selects another key segment of a preset length to encrypt the digest, generating a signature; the master station sends the identity scheduling information and corresponding signature to a target substation, which, upon receiving the signature, sends a key request to other substations, which respond to the request and send a portion of their security keys to the target substation; the target substation uses its local security key and the received security key to reconstruct the decryption key, decrypts the signature to obtain a first digest, calculates a second digest of the identity scheduling information, compares the first digest and the second digest, and if they match, authentication is successful.

[0015] As a preferred embodiment, the plant is equipped with a quantum signal transmitting device, which includes a pulsed laser, a phase modulator, an intensity modulator, and a tunable optical attenuator; the control master station is equipped with a quantum measurement device, which includes a 50:50 beam splitter and two threshold detectors.

[0016] Thirdly, the present invention provides an electronic device, the computer device including a memory, a processor and a computer program, wherein when the computer program is executed by the processor, it implements the authentication method as described in the first aspect.

[0017] Fourthly, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the authentication method as described in the first aspect.

[0018] Compared with the prior art, the present invention has the following beneficial effects:

[0019] 1. This invention establishes a quantum secret sharing mechanism between the control master station and the factory station. The factory station only needs to modulate the phase and intensity of weakly coherent optical pulses to encode information, without requiring complex entanglement resources. Simultaneously, the control master station only needs a standard single-photon interferometry measurement device to complete key distribution. This design significantly simplifies hardware configuration, reduces system complexity, and ensures unconditional security through rigorous security analysis.

[0020] 2. By employing weakly coherent state encoding technology, this invention completely eliminates the reliance on quantum entanglement resources found in traditional methods. This not only reduces the difficulty of experimental implementation but also decreases the system's requirement for the preparation of special quantum states, making quantum identity authentication technology easier to deploy and apply in practical environments.

[0021] 3. This invention incorporates the vacuum state into the phase error estimation process, simplifying the coding implementation. Simultaneously, combined with detailed security analysis, it ensures that the system maintains unconditional security even under imperfect conditions, providing a reliable guarantee for quantum communication.

[0022] 4. This invention utilizes a hash function to transform identity scheduling information into a fixed-length digest, significantly improving information processing efficiency. This digest generation method not only compresses the data volume but also maintains the uniqueness and immutability of the information, providing strong support for fast and accurate identity authentication.

[0023] Further or more detailed beneficial effects will be described in conjunction with specific embodiments in the detailed implementation. Attached Figure Description

[0024] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0025] Figure 1 This is a schematic diagram of the key distribution process of the identity authentication method described in the embodiments of the present invention.

[0026] Figure 2 This is a schematic diagram of a key distribution device for the identity authentication method described in an embodiment of the present invention.

[0027] Figure 3 This is a schematic diagram of the identity authentication process of the identity authentication method described in the embodiments of the present invention.

[0028] Figure 4 This is a structural diagram of the electronic device provided in the embodiment of the present invention.

[0029] Icon labels:

[0030] 400. Electronic devices;

[0031] 401. Processor; 402. Communication bus; 403. User interface; 404. Network interface; 405. Memory. Detailed Implementation

[0032] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.

[0033] In the following description, several embodiments of the present invention are provided. Different embodiments can be substituted or combined. Therefore, the present invention can also be considered to include all possible combinations of the same and / or different embodiments described. Thus, if one embodiment includes features A, B, and C, and another embodiment includes features B and D, then the present invention should also be considered to include embodiments containing one or more other possible combinations of A, B, C, and D, even if such embodiments are not explicitly described in the following text.

[0034] The following description provides examples and does not limit the scope, applicability, or examples set forth in the claims. Changes may be made to the function and arrangement of the described elements without departing from the scope of the invention. Various processes or components may be appropriately omitted, substituted, or added to the various examples. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Furthermore, features described with respect to some examples may be combined into other examples.

[0035] To facilitate a better understanding of the embodiments of the present invention, its application scenarios will be explained before providing a detailed explanation of the specific implementation methods.

[0036] The authentication method described in the embodiments of this specification is applied to the secure communication process between the power system control master station and the substation. In these scenarios, the application of the authentication method aims to achieve high-security authentication through quantum technology, prevent third-party access and information tampering, and ensure the accurate execution of power grid dispatching instructions and the stable operation of the power system.

[0037] The following is a brief explanation of the quantum secret sharing, control master station, factory station, interferometry, key gain, bit error rate, phase error rate, and hash function involved in the various embodiments of this specification:

[0038] Quantum secret sharing is a cryptographic technique whose core idea is to divide a secret (such as an encryption key) into multiple parts and distribute them to different participants (such as a control master station and a control plant). The original secret can only be recovered when a specific number of participants cooperate. This technique utilizes fundamental principles of quantum mechanics (such as the quantum no-cloning theorem) to provide higher security than traditional methods.

[0039] The control and dispatching master station is the core node in the power system, responsible for the dispatching and command of the entire power grid. It undertakes the management and control tasks of generating units, substations, and loads. The security of its identity authentication is directly related to the stability and reliability of the power grid operation.

[0040] Power plants and substations are the basic units in a power system, responsible for executing instructions from the control center and carrying out local power production and distribution. In the quantum identity authentication system, power plants and substations, as participants in key distribution and identity verification, work with the control center to achieve secure communication.

[0041] Interferometry is a key technology in quantum communication, which uses beam splitters and detectors to interfere two or more light waves to measure their phase difference or other optical properties. In this invention, the control master station uses interferometry to analyze the phase and intensity of weakly coherent light pulses from the factory station, thereby enabling key distribution and verification.

[0042] Key gain is a metric for key distribution efficiency, representing the ratio of the number of successfully generated and usable key bits to the total number of bits sent under specific conditions (such as channel transmission efficiency and detector performance). High key gain implies a more efficient key distribution process.

[0043] Bit error rate (BER) is a metric for measuring the accuracy of key transmission, representing the probability of bit mismatch between the receiver and sender during key distribution. A low BER is crucial for ensuring key security and communication quality.

[0044] Phase error rate (BER) is a metric specifically used to evaluate phase consistency in quantum key distribution. It represents the probability of phase information errors caused by factors such as photon attenuation and detector noise. Accurate BER estimation is crucial for ensuring unconditional key security.

[0045] A hash function is a mathematical function that maps input information of arbitrary length to a fixed-length digest. In this invention, a hash function is used to transform identity-scheduling information into a fixed-length digest for efficient encryption and verification. Commonly used hash functions include Toeplitz hashing based on a linear feedback shift register and generalized division hashing.

[0046] Example 1:

[0047] This embodiment provides an identity authentication method based on quantum secret sharing, implemented by a control master station and at least two substations, including key distribution and identity authentication. Preferably, in this embodiment, two substations are provided, including substation A and substation B. The specific process of the identity authentication method is as follows.

[0048] The key distribution process is as follows: Figure 1 As shown, the key distribution device can be referred to. Figure 2 The steps include:

[0049] Step S1: Plant A and Plant B prepare coherent optical pulses with the same light intensity, and perform phase modulation and intensity modulation to obtain coherent states. or coherent state or vacuum state Finally, the light is attenuated to the single-photon level by an adjustable optical attenuator and transmitted into the optical fiber channel.

[0050] Specifically, plant A and plant B are equipped with pulsed lasers, phase modulators, intensity modulators, and tunable optical attenuators, respectively. The pulsed lasers generate a fixed intensity... Coherent light. The phase modulator operates with a 1 / 2 probability. Phase modulation, when the phase modulation is 0, corresponds to a classical bit of 0, when the phase modulation is... At that time, the corresponding classical bit is 1. The intensity modulator cuts off the light pulse with a 1 / 3 probability, resulting in a 1 / 3 probability of obtaining a coherent state. coherent state and vacuum state The tunable optical attenuator attenuates the modulated coherent optical pulse to the level of a single photon.

[0051] Step S2: The control station performs interferometric measurements on the weakly coherent optical pulses from plant A and plant B. If the measurement is successful, the measurement result is published; otherwise, the measurement failure is published.

[0052] Specifically, the control master station uses a 50:50 beam splitter and two threshold detectors. Interferometry is performed on weakly coherent optical pulses from plant A and plant B to obtain the phase difference between them. When the phase difference is 0, Response If there is no response, the control master station records its classic bit as 0; when the phase difference is hour, Response If there is no response, the control master station records its classic bit as 1 and marks it as a successful measurement. Due to photon attenuation and the influence of detector dark count, a measurement is considered a failure when both threshold detectors fail to respond or respond simultaneously.

[0053] Step S3: Repeat steps S1 and S2 multiple times, and at least one of the plants, A and B, will announce a vacuum state. The state selection of all successful measurement rounds is used to retain the remaining successful measurement rounds, forming their respective sieve keys.

[0054] Specifically, based on the successful measurements announced by the main control station, both plant A and plant B retain the modulation information at the corresponding time and announce that at least one person has transmitted a vacuum state. State selection, i.e. The remaining state combinations are retained as the sieved key, i.e. .

[0055] Step S4: Plant A and Plant B publish part of the filtered key, which is used to calculate the gain and bit error rate of the final code and estimate the phase error rate.

[0056] Specifically, the gain of the sieved key ,in Indicates that plant A sent Taier Factory Station B Send In this state, the probability of successful measurement by the control master station is expressed as:

[0057]

[0058] In the formula, It is the dark count of the detector. It is channel transmission efficiency. and These are the arguments of the preparation states of plant A and plant B, respectively;

[0059] The expression for the bit error rate of the filtered key is:

[0060] ,

[0061] In the formula, It is a natural constant. yes and The amplitude.

[0062] The phase error rate is estimated by the following formula:

[0063]

[0064] In the formula, it can be seen from the summation symbol that... or ,when hour, and Both are even numbers, when hour, and If all are odd, then and They represent the even photon number probability and the odd photon number probability, respectively. Indicates that plant A sent One photon was sent from station B. The photon timing control master station successfully measured ( Response The probability of not responding. Similarly, because only [the following was prepared] For phase error estimation, this embodiment selects .

[0065] Step S5: Plant A, Plant B and the control master station perform error correction and security amplification on the remaining post-screening secrets to obtain the final security key.

[0066] Specifically, the final security key is estimated using the following formula:

[0067] ,

[0068] In the formula, Represents the error correction coefficient. This represents the binary Shannon entropy function.

[0069] The identity authentication process is as follows: Figure 3 As shown, the steps include:

[0070] Step S6: The control master station sequentially selects two data points with a length of... key and Constructing a hash function Then for length of Identity-Scheduling Information Perform hash calculation to obtain digest Then select a length of key For hash value The signature Sig is obtained by performing a "one-time password" operation.

[0071] Specifically, the hash functions constructed in this embodiment include Toeplitz hashing based on linear feedback shift registers and generalized division hashing.

[0072] Step S7: The control master station sends (M||Sig) to any plant station, such as plant station A. After receiving (M||Sig), plant station A selects three parts of length [missing information]. key , and , and then send ( || || ||M||Sig) is given to plant B, and plant B also selects three parts of length in sequence. key , and And forward it to plant A. Here, || is the cascading symbol.

[0073] Step S8: Plant A uses the key in its hand and the received key Perform modulo 2 operation to obtain ( ), then Decrypting Sig yields the digest. ,use and Construct a hash function and compute a digest Finally, compare the decrypted digests. Summary of local computation If they are equal, the signature of the control station will be accepted; otherwise, it will not be accepted.

[0074] Example 2:

[0075] This embodiment provides an identity authentication system based on quantum secret sharing, used to implement the identity authentication method as described in Embodiment 1, including a control master station and at least two factory stations; each factory station is used to prepare coherent optical pulses with the same light intensity, and perform phase modulation and intensity modulation to obtain a coherent state or a vacuum state, which is attenuated to the single photon level by an adjustable optical attenuator to obtain a weakly coherent optical pulse, which is then sent into the optical fiber channel;

[0076] The control master station receives weak coherent optical pulses from various stations and performs interferometric measurements. If successful, it publishes the measurement results and corresponding classical bits; otherwise, it announces measurement failure. Each station and the control master station, after repeated weak coherent optical pulse transmission and reception operations, publish the state selection for all successful measurement rounds where at least one party transmitted a vacuum state, retaining the data from the remaining successful measurement rounds to form their respective sieved keys. Each station publishes a portion of the sieved keys to calculate key gain, bit error rate, and estimate phase error rate. The control master station and each station perform error correction and security enhancement on the remaining sieved keys to generate the final secure key. The control master station sequentially selects multiple segments from its secure key... A hash function is constructed using a key of preset length to perform a hash operation on the identity scheduling information to obtain a digest. Then, another key of preset length is selected to encrypt the digest, generating a signature. The control master station sends the identity scheduling information and corresponding signature to a target factory station. After receiving the signature, the target factory station sends a key request to other factory stations. The other factory stations respond to the request and send a portion of their security keys to the target factory station. The target factory station uses its local security key and the received security key to reconstruct the decryption key, decrypts the signature to obtain a first digest, calculates a second digest of the identity scheduling information, and compares the first and second digests. If they match, authentication is successful.

[0077] Specifically, the plant is equipped with a quantum signal transmitting device, which includes a pulsed laser, a phase modulator, an intensity modulator, and a tunable optical attenuator; the control station is equipped with a quantum measurement device, which includes a 50:50 beam splitter and two threshold detectors.

[0078] Example 3:

[0079] like Figure 4 As shown, this embodiment provides an electronic device, which may include: at least one processor, at least one network interface, a user interface, a memory, and at least one communication bus.

[0080] The communication bus can be used to enable communication between the various components mentioned above.

[0081] The user interface may include buttons, and optional user interfaces may also include standard wired interfaces and wireless interfaces.

[0082] The network interface may include, but is not limited to, Bluetooth modules, NFC modules, Wi-Fi modules, etc.

[0083] The processor may include one or more processing cores. It connects various parts of the electronic device via various interfaces and lines, executing instructions, programs, code sets, or instruction sets stored in memory, and accessing data stored in memory to perform various functions and process data. Optionally, the processor can be implemented using at least one hardware form of DSP, FPGA, or PLA. The processor may integrate one or more of the following: CPU, GPU, and modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content required for display; and the modem handles wireless communication. It is understood that the modem may also be implemented as a separate chip without being integrated into the processor.

[0084] The memory may include RAM or ROM. Optionally, the memory may include a non-transitory computer-readable medium. The memory can be used to store instructions, programs, code, code sets, or instruction sets. The memory may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-described method embodiments, etc.; the data storage area may store data involved in the above-described method embodiments, etc. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor. The memory, as a computer storage medium, may include an operating system, a network communication module, a user interface module, and an authentication application. The processor can be used to call the authentication application stored in the memory and execute the steps of the authentication methods mentioned in the foregoing embodiments.

[0085] Example 4:

[0086] This embodiment provides a computer-readable storage medium storing instructions that, when executed on a computer or processor, cause the computer or processor to perform the above-described instructions. Figure 1 and Figure 3 One or more steps in the illustrated embodiment. If the constituent modules of the above-described electronic device are implemented as software functional units and sold or used as independent products, they can be stored in the computer-readable storage medium.

[0087] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this specification are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in or transmitted through a computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, Digital Subscriber Line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., Digital Versatile Discs (DVDs)), or semiconductor media (e.g., Solid State Disks (SSDs)).

[0088] Those skilled in the art will understand that all or part of the processes in the method of Embodiment 1 described above can be implemented by a computer program instructing related hardware. This program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the methods described above. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks. Unless otherwise specified, the technical features of this embodiment and the implementation scheme can be combined arbitrarily.

[0089] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the present invention is not limited to the described order of actions, because according to the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.

[0090] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0091] The above description is merely an exemplary embodiment of the present invention and should not be construed as limiting the scope of the invention. Any equivalent changes and modifications made in accordance with the teachings of this invention are still within the scope of this invention. Those skilled in the art will readily conceive of embodiments of the invention upon considering the specification and practicing the disclosure herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not described herein. The specification and embodiments are to be considered exemplary only, and the scope and spirit of the invention are defined by the claims.

Claims

1. A method for identity authentication based on quantum secret sharing, characterized in that, The method is implemented by a control master station and at least two factory stations, and the specific steps are as follows: Each factory station prepares coherent state light pulses with the same light intensity, and performs phase modulation and intensity modulation to obtain coherent state or vacuum state, and then sends the weak coherent light pulses into an optical fiber channel after attenuation to a single photon level by an adjustable optical attenuator; The control master station receives the weak coherent light pulses from each factory station, and performs interference measurement, and if the measurement is successful, the measurement result and the corresponding classical bit are published, otherwise the measurement failure is published; After repeating the weak coherent light pulse sending and receiving operations for multiple times, each factory station publishes the state selection of the successful measurement rounds in which at least one party sends a vacuum state, and retains the data of the remaining successful measurement rounds to form a respective filtered key; Each factory station publishes part of the filtered key to calculate the key gain, the bit error rate and estimate the phase error rate; The control master station and each factory station perform error correction and privacy enhancement on the remaining filtered key to generate a final secure key; The control master station selects multiple segments of the preset length of the secure key to construct a hash function, performs hash operation on the identity scheduling information to obtain a digest, and then selects another segment of the preset length of the key to encrypt the digest to generate a signature; The control master station sends the identity scheduling information and the corresponding signature to a target factory station, and the target factory station receives the information and sends a key request to other factory stations, and the other factory stations respond to the request and send part of the secure key to the target factory station; The target factory station restores the decryption key according to the local secure key and the received secure key, decrypts the signature to obtain a first digest, calculates a second digest of the identity scheduling information, compares the first digest and the second digest, and if they are consistent, the authentication is passed.

2. The identity authentication method based on quantum secret sharing according to claim 1, wherein: The factory stations include a factory station A and a factory station B; said phase modulation is randomly selecting a 0 phase or modulating the phase; The intensity modulation is a complete chopping of the light pulse with a probability of one third to produce the vacuum state , so that the first coherent state , the second coherent state and the vacuum state are produced with a probability of one third each.

3. The identity authentication method based on quantum secret sharing according to claim 2, wherein: The control master station completes the interference measurement by using a 50:50 beam splitter and two threshold detectors; When the phase difference between the two light pulses from the factory station A and the factory station B is 0, and only the first threshold detector responds, it is determined that the measurement is successful and the classical bit 0 is recorded; When the phase difference of the two optical pulses from station A and station B is and only the second threshold detector responds, a successful measurement is determined and a classical bit of 1 is recorded. When neither of the two threshold detectors responds or both of them respond at the same time, it is determined that the measurement fails.

4. The identity authentication method based on quantum secret sharing according to claim 3, wherein: The rounds corresponding to the data retained for forming the filtered key are the successful measurement rounds in which the factory station A and the factory station B both send non-vacuum states, including four encoding combinations, and the expression is 。 5. The identity authentication method based on quantum secret sharing according to claim 4, wherein: The key gain is defined as the conditional probability that the control master station obtains a successful measurement under a specific non-vacuum state combination; The bit error rate is calculated by comparing the difference between the sent and received key bits, and the amplitude parameter of the coherent state is involved.

6. The identity authentication method based on quantum secret sharing according to claim 5, wherein: The hash function includes a Toeplitz hash function based on a linear feedback shift register and a generalized division hash function.

7. A quantum secret sharing based identity authentication system, characterized by, The identity authentication method comprises a regulation master station and at least two factory stations. Each factory station is configured to prepare coherent state light pulses with the same light intensity, and to perform phase modulation and intensity modulation to obtain coherent state or vacuum state, and to attenuate the coherent state or vacuum state to a single photon level through an adjustable optical attenuator to obtain weak coherent light pulses and then send the weak coherent light pulses into an optical fiber channel. The regulation master station is configured to receive the weak coherent light pulses from each factory station, and to perform interference measurement, and if successful, to publish the measurement result and the corresponding classical bit, otherwise to publish a measurement failure. Each factory station and the regulation master station are configured to publish the state selection of successful measurement rounds in which at least one party sends a vacuum state after repeating the weak coherent light pulse transmission and reception operation multiple times, and to retain the data of the remaining successful measurement rounds to form respective filtered keys. Each factory station is configured to publish part of the filtered keys to calculate key gain, bit error rate and estimate phase error rate. The regulation master station and each factory station perform error correction and privacy enhancement on the remaining filtered keys to generate a final secure key. The regulation master station selects multiple keys of a preset length from the secure keys in sequence to construct a hash function, performs hash operation on the identity scheduling information to obtain a digest, and selects another key of a preset length to encrypt the digest to generate a signature. The regulation master station is configured to send the identity scheduling information and the corresponding signature to a target factory station, and the target factory station, after receiving the identity scheduling information and the corresponding signature, sends a key request to other factory stations, and the other factory stations respond to the request and send part of the secure keys to the target factory station. The target factory station is configured to restore a decryption key according to the local secure key and the received secure key, decrypt the signature to obtain a first digest, calculate a second digest of the identity scheduling information, compare the first digest and the second digest, and if they are consistent, the authentication is passed.

8. The identity authentication system based on quantum secret sharing according to claim 7, wherein: the factory station is equipped with a quantum signal emitting device, and the quantum signal emitting device comprises a pulse laser, a phase modulator, an intensity modulator, and an adjustable optical attenuator. The regulation master station is equipped with a quantum measurement device, and the quantum measurement device comprises a 50:50 beam splitter and two threshold detectors. The computer program is executed by a processor to implement the identity authentication method according to any one of claims 1 to 6.

9. A computer device comprising a memory, a processor and a computer program, characterized in that The computer program is executed by a processor to implement the identity authentication method according to any one of claims 1 to 6.

10. A computer-readable storage medium having stored thereon a computer program, characterized in that, ​

Citation Information

Patent Citations

  • Quantum secret sharing method based on entanglement swap

    CN114362945A

  • Quantum secret sharing method and system based on phase coding

    CN115549908A

  • Asymmetric coherent detection quantum conference key negotiation method and system

    CN113037476A

  • Quantum key negotiation method, quantum key negotiation system, quantum digital signature method and quantum digital signature system

    CN114244500A