System and method for randomness extraction and method for executing quantum cryptography

By using a sampling sub-block hashing method, the encryption key is split into sub-blocks and processed independently, which solves the problem of slow hash function speed and enables efficient execution of quantum cryptography protocol on resource-constrained platforms. It is applicable to QKD and QRNG systems.

CN120958772APending Publication Date: 2025-11-14NATIONAL UNIVERSITY OF SINGAPORE
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480026545.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-04-24
Filing Date
2024-04-24
Publication Date
2025-11-14

AI Technical Summary

Technical Problem

Existing quantum cryptography protocols suffer from slow hash function execution speeds when processing large amounts of data, becoming a bottleneck. Furthermore, their high resource utilization limits the application of these systems on low-end FPGAs.

Method used

The sampling sub-block hashing method is adopted. By splitting the encryption key into sub-blocks, determining the lower bound of the entropy of each sub-block, and performing hashing independently, the correlation between the sub-blocks and unsampled bits and other sub-blocks is considered, and the generalized entropy accumulation theorem is used for security analysis.

Benefits of technology

It improves hash processing speed, reduces resource utilization, is suitable for resource-constrained platforms, maintains security and throughput, and is suitable for QKD and QRNG systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120958772A_ABST
    Figure CN120958772A_ABST
Patent Text Reader

Abstract

A system and method for quantum cryptography randomness extraction, and a method for performing quantum cryptography between two or more parties. The system for quantum cryptography randomness extraction comprises a sampling module used for sampling an encryption key to generate one or more sub-blocks; an entropy module to determine a lower limit of entropy in each sub-block, where the determination of the lower limit comprises considering a correlation between each sub-block and the encryption key and / or unsampled bits of other sub-blocks; and the hash module is used for performing hash processing on each sub-block so as to realize random extraction of each sub-block.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention generally relates to systems and methods for extracting randomness in quantum cryptography, and methods for performing quantum cryptography between two or more parties. Background Technology

[0002] Any references to and / or discussion of prior art in this specification should not be construed in any way as an admission that such prior art is well-known or constitutes part of common general knowledge in the art.

[0003] All practical implementations of quantum cryptography protocols have limited resources and are therefore susceptible to statistical fluctuations in data of finite size. These statistical fluctuations must be accounted for to ensure the protocol is theoretically secure. This necessitates a large amount of data being collected. However, large data volumes are detrimental to hash operations, which are a necessary step in quantum key distribution (QKD) and quantum random number generation (QRNG). This is because large data volumes significantly slow down the execution speed of hash functions, and the execution time of hash functions increases superlinearly with the amount of data. For these reasons, hash functions are widely considered the bottleneck in QKD and QRNG implementations.

[0004] More specifically, implemented quantum cryptography protocols operate for finite durations, and therefore have limited resources. Due to statistical fluctuations in finite-size data, randomness extraction from large inputs is necessary in practical implementations of quantum cryptography protocols. For example, in QKD, finite-size analysis requires at least 10... 6 The block size of bits. When considering protocols with weaker assumptions, such as in measurement-device-independent and device-independent settings, the required block size is even larger, approximately 10. 11 Bit.

[0005] Taking device-independent QKD as an example, despite improvements in both theory and experiment, the required block size is still larger than the input size of state-of-the-art Toeplitz hashing implementations on field-programmable gate arrays (FPGAs). This is because hashing becomes increasingly impractical as the input size increases. This can be attributed to two factors: reduced throughput or increased resource requirements. As the input size of a hash algorithm increases, the output speed naturally decreases because more bits need to be processed even to generate just one secure bit. Alternatively, to prevent a decrease in the throughput of the hash algorithm, the FPGA could create a copy of some hardware and execute it in parallel. However, this would lead to a significant increase in resource utilization, thus limiting quantum cryptography systems to high-end FPGAs.

[0006] The embodiments of the present invention are intended to solve at least one of the above-mentioned problems. Summary of the Invention

[0007] According to a first aspect of the present invention, a system for extracting randomness in quantum cryptography is provided, comprising: A sampling module configured to sample the encryption key to generate one or more sub-blocks; An entropy module configured to determine a lower bound of entropy in each sub-block, wherein determining the lower bound includes considering the correlation between each sub-block and the unsampled bits of the encryption key and / or other sub-blocks; and The hash module is configured to hash each sub-block to achieve random extraction of each sub-block.

[0008] According to a second aspect of the present invention, a method for extracting randomness in quantum cryptography is provided, comprising the following steps: The encryption key is sampled to generate one or more sub-blocks; Determine a lower bound on the entropy in each sub-block, wherein determining the lower bound includes considering the correlation between each sub-block and the unsampled bits of the encryption key and / or other sub-blocks; and Each sub-block is hashed to achieve random extraction of each sub-block.

[0009] According to a third aspect of the present invention, a method for performing quantum cryptography between two or more parties is provided, the method comprising: publishing a uniform random variable This indicates which bit of the encryption key was sampled into which sub-block. Attached Figure Description

[0010] Embodiments of the present invention will be better understood and apparent to those skilled in the art from the following written description, which is by way of example only and in conjunction with the accompanying drawings, wherein: Figure 1 A schematic diagram of the sequential model of the Generalized Entropy Accumulation Theorem (GEAT) is shown, where the initial state... After passing through a series of GEAT channels To generate the final state .

[0011] Figure 2 The key rate per transmitted signal versus the number of sampled sub-blocks (i.e.,) is shown with and without the sampled sub-block hashing method according to the example embodiment. The relationship diagram.

[0012] Figure 3 The graph illustrates the relationship between the expected key rate per unit time for randomness extraction when the sampling sub-block hashing method according to the example embodiment is applied and not applied.

[0013] Figure 4AThis shows a comparison between the key rate per transmitted signal and the number of sampled subblocks. The dashed line indicates a target key rate of 0.5 for each signal. "Full" means directly hashing the filtered key; "splitting" means using the sampled subblock hashing method according to the example embodiment; and "small block" means we are running the QKD protocol (…). )wheel times, and for each N S Each block undergoes parameter estimation and hashing.

[0014] Figure 4B This shows a comparison of key rate per unit time with the number of sampled sub-blocks. The dashed line indicates the number of sub-blocks for each split (…). ) method and small block ( This method optimizes the target key rate for each signal. Values ​​and their corresponding throughput. "Full" means directly hashing the filtered keys; "split" means using our sampled sub-block hashing method; "small block" means we run the QKD protocol (…). )wheel Next, and for each Each block undergoes parameter estimation and hash processing.

[0015] Figure 5 The results obtained from the NIST800-22 Statistical Test Suite according to an example embodiment are shown.

[0016] Figure 6A The minimum P-value obtained by testing a 152.56 megabit (Mbits) cascaded output using the National Institute of Standards and Technology (NIST) 800-22 Statistical Test Kit, according to an example embodiment, is shown.

[0017] Figure 6B The minimum scale result obtained by testing a 152.56 megabit cascaded output based on the National Institute of Standards and Technology's 800-22 statistical test suite, according to an example embodiment, is shown.

[0018] Figure 7 A schematic diagram of a system 700 for quantum cryptographic randomness extraction is shown according to an example embodiment.

[0019] Figure 8 A flowchart of a method for extracting randomness in quantum cryptography according to an example embodiment is shown in Figure 800. Detailed Implementation

[0020] General A round agreement, consisting of multiple honest parties (or a single honest party) and an adversary, typically includes the following steps: (1) Data generation. The honest party in In rounds of exchange, classical and quantum information are swapped, and this information may be vulnerable to attack by an adversary. At the end of each round, the honest party receives the original bit string. In which the honest party openly exchanges information The opponent, on the other hand, possesses auxiliary information. Assuming It is generated independently of any storage owned by the honest party (from previous rounds).

[0021] (2) Statistical check. The honest side will allocate the data generated in each round as test rounds ( ) or data generation wheel ( ), and with test probability Regarding the test round, the honest party will disclose information. It includes and calculating statistical data Based on observed statistical data If they do not belong to the event set If so, the agreement is terminated.

[0022] (3) Exchange of Additional Information. The honest party may exchange additional public information, marked as... This information is not generated in a round-by-round manner (e.g., error correction).

[0023] (4) Filtering. Honest users discard uncertain rounds (e.g., due to loss or non-detection) and some test rounds, thus obtaining a shorter filtered bit string. .

[0024] (5) Random extraction. For the filtered bit strings... Perform randomness extraction to obtain the output. ,in It is a hash function randomly selected from the dual universal hash function family.

[0025] At the end of the agreement, the adversary will receive information. as well as and hash function .

[0026] After random extraction, ideally we want the hash output to... Keep it secret from the opponent. Therefore, for example, a stricter minimum entropy chain rule could be used to provide limits on the penalties arising from the announcement.

[0027] To ensure that (1) the quantum cryptography protocol satisfies the finite size effect and (2) the hashing steps remain practical, embodiments of the present invention implement a sampled subblock hashing method to improve current hashing implementations.

[0028] More specifically, in an exemplary embodiment of the invention, the large input data to be subjected to randomness extraction is randomly (by sampling) split into sub-blocks, and a lower bound is provided for the conditional smoothing minimum entropy of each sub-block, noting that the correlation between different sub-blocks is considered in the entropy determination step.

[0029] In one example embodiment, for a single round of sampling, the input data is reduced to a single sampled sub-block, and random extraction is performed on that sub-block, taking into account the correlation between different sampled sub-blocks (in this example embodiment, the correlation between bits randomly sampled into the sub-block and unsampled bits). This contrasts with discarding unsampled bits, which actually introduces a significant entropy loss, as the inventors have recognized.

[0030] In another example embodiment, the input data is sampled into multiple sampled sub-blocks, and randomness extraction is performed independently on each sub-block before all outputs are concatenated. In this example embodiment, the method can take into account the correlation between different sampled sub-blocks. Therefore, this method can perform hash operations on all sub-blocks and concatenate the outputs while still maintaining overall security.

[0031] To demonstrate the performance of the exemplary embodiments of the present invention, a theoretical evaluation was performed on the hashing method according to the exemplary embodiments for protocols that satisfy certain properties and whose security can be analyzed using the latest Generalized Entropy Accumulation Theorem (GEAT). The results show that the hashing method according to the exemplary embodiments introduces only a small (linear) loss in terms of security, while providing a linear improvement in the speed of randomness extraction and maintaining the same number of secure bits. It should be noted that to obtain this lower bound, i.e., the determination of entropy, other methods can be used instead of the Generalized Entropy Accumulation Theorem (GEAT), methods that determine entropy while considering the correlation between a sampled subblock and unsampled bits and / or the correlation between different sampled subblocks, or methods that can be used to determine entropy.

[0032] The exemplary embodiments of this invention utilize the Generalized Entropy Accumulation Theorem (GEAT) [T. Metger, O. Fawzi, D. Sutter, and R. Renner, 63rd IEEE Conference on Foundations of Computer Science (FOCS), 2022 (IEEE Computer Society, Denver, Colorado, USA, 2022), p. 844]. A brief description will be given below using QKD as an example. Assume a QKD protocol can be analyzed using GEAT, and the original string has a certain minimum entropy. (1) in

[0033]

[0034] , in, It is the total number of rounds (or the number of signals exchanged) during the agreement period. It is the minimum trade-off function in GEAT. It is a test statistic. This is the previous state of the GEAT channel. It is a GEAT channel. It is the filtered bit string. It is the set of acceptable statistics that will not trigger protocol termination.

[0035] More specifically, GEAT is used to demonstrate the practicality of the example embodiments, and a brief description of GEAT is provided here. Assume that at the end of a certain protocol, the output quantum state is... This state can be obtained from a certain initial state. (See Figure 1 A series of channels are applied on ) (Referred to as the "GEAT channel") To generate. This usually refers to the output (e.g., the raw key in QKD). This refers to statistical data used to select events (e.g., whether the agreement should be terminated). It is the auxiliary information carried by Alice and Bob. This is Eve's auxiliary information. GEAT outputs... The conditional smoothing minimum entropy provides a fairly strict bound on the output. To supplement information ,Right now Given the condition, entropy is a state. The following assessments were conducted, among which This is a set of events. This limit is very useful because it is directly related to the final key length and security parameters in quantum cryptography protocols.

[0036] GEAT states that if the following two conditions are met, then (2) in , , , , , Among them, variables , and Independent of ,and , and As a certain affine minimum tradeoff function The variance, maximum value, and minimum value. These two conditions are: (1) Non-signaling. This requires Eve to possess any information about... All the auxiliary information should already be included In, rather than stored And will be revealed in subsequent rounds (e.g., to...) More formally, for each GEAT channel There is a channel Make ,in This represents the synthesis operation of the channel.

[0037] (2) Projection reconfigurability. It should be possible to reconfigure the projection by... and Perform projection measurements and apply functions to the results to reconstruct statistical data. More formally, a channel exists. Make .

[0038] The minimum trade-off function is an affine function f(q), where for all , (3) in, ,and As The purification system.

[0039] It is important to note that any protocol that cannot be analyzed using the GEAT framework may still be useful if alternative proof theories can be applied and satisfied. This includes quantum cryptography protocols that typically cannot be reduced to sequential processes following non-signal conditions according to GEAT.

[0040] Based on an example embodiment, consider a sampling method in which each round is performed with a certain probability. Random sampling. In this case, an appropriate GEAT channel can be defined to compute sub-blocks. minimum entropy The method is to issue a notice during the agreement period. And only included in the sampling sub-block In .

[0041] More specifically, the sampled sub-block hashing protocol is used in the example embodiment. This begins with the raw bit string from the encryption key generation module. This is understandable in the field and will not be elaborated upon further. As an example (not a limitation), see the description of the QKD key generation module in the recent review of protocols and implementations in [Feihu Xu, Xiongfeng Ma, Qiang Zhang, Hoi-Kwong Lo, and Jian-Wei Pan, *Review of Modern Physics*, Vol. 92, No. 025002 (2020)], and the review of the QRNG key generation module in the review of protocols and implementations in [Ma, X., Yuan, X., Cao, Z., et al., "Quantum Random Number Generation," *Quantum Information Journal*, Vol. 2, No. 16021 (2016)]. Original bit string It needs to be screened and randomly extracted. For sampling probability, and select The sampled sub-block hashing method according to the example embodiment includes: (1) Sampling. For each round Honesty generates uniform random variables This variable can take the following values: ∈[1, ](Right now, The value range can be from 1 to The probability of each value is In one example embodiment, if , then represents bits Sampling to the In each sub-block, the sub-block is represented as The index of the set Then The value is published to the other honest parties (if necessary).

[0042] (2) Filtering. For each sub-block It can filter to discard uncertain rounds or a portion of test rounds, leaving the filtered sub-blocks. Typically, the length of these bit strings is not fixed. Therefore, to prevent excessively long bit strings from slowing down the Toeplitz hash, in a preferred example embodiment, if any sub-blocks are filtered... Size exceeds predetermined threshold If so, you can choose to abort. In practical applications, the probability of such abort is very small.

[0043] (3) Randomness extraction. If the protocol according to the example embodiment is not terminated, randomness extraction is performed independently on all sub-blocks to produce the output. ,in It is a random hash function independently selected from the dual universal hash function family. For simplicity, each Output length All taken as .

[0044] (4) Concatenation. The final output is represented as follows: It is obtained by concatenating all the individual outputs randomly extracted from each sub-block.

[0045] It is worth noting that when the application performs sampling sub-block hash processing according to the example embodiment, It will be announced separately, and multiple hash functions will be used. Furthermore, attackers can access this information, which has been taken into account in the security assessment of the example embodiments.

[0046] In the example embodiment, when multiple hash strings are concatenated together, the minimum entropy of each sub-block to be computed is... To account for the correlation between sub-blocks, non-sampling rounds are published via appropriate GEAT channels. The minimum entropy value for each sub-block can be calculated. Similarly, it should be noted that to obtain this lower bound, i.e., the determination of entropy, other methods can be used instead of GEAT. These methods determine entropy while considering the correlation between a sampled sub-block and unsampled bits and / or between different sampled sub-blocks, or methods that can be used to determine entropy.

[0047] Typically, to demonstrate the practicality of the example embodiments, we assume that the smooth minimum entropy of each sub-protocol (i.e., each sub-block) is of the form: (4), This form takes into account the correlation between the original sampled bit strings. Since the original protocol applying the sampled sub-block hashing method according to the example embodiment is GEAT analyzable, the GEAT channel Mi can be recorded, and EAT can be applied by defining a minimum trade-off function f(q). To construct the minimum trade-off function of the sampled sub-block hashing method according to the example embodiment applied to the original protocol, the EAT channel can be adjusted to output... (Note that if the first) 𝑖 The wheel was discarded or not included. In the middle, then insert ), and at the same time, information and V i Forwarded to Eve. (Because it only contains bits.) The output is Therefore, entropy and the minimum trade-off function obtain factors. Thus, the modifications in the claims are obtained.

[0048] The security conditions that are of concern are (5) Among them, the bit string can be guaranteed For those with access It is a secret to the opponent. By introducing the form of The intermediate state can be obtained by applying the triangle inequality. (6) Because each output string is calculated according to the sub-block hashing method in the example embodiment. Therefore, the quantum residual hashing lemma [“Residual Hash Techniques for Quantum Side Information” by M. Tomamichel, C. Schaffner, A. Smith, and R. Renner, IEEE Transactions on Information Theory, Vol. 57, p. 5524] and [“Complete Security Proof of Quantum Key Distribution” by M. Tomamichel and A. Leverrier, Quantum Journal, Vol. 1, p. 14 (2017)] can be applied to analyze each sub-block. Therefore, it is possible to set... (7) To achieve the required level of security, where minimum entropy is based on The assessment refers to, except for The set of hash functions used in addition to the above.

[0049] To determine the error, the crucial quantity we need to calculate is the minimum entropy. We can first use data processing inequalities to determine the lower bound of the minimum entropy, because... ,and It can be done Calculations show that (8), The second inequality stems from the fact that: It is independent of all other terms in the minimum entropy.

[0050] In order to use GEAT to analyze minimum entropy, the inequality must be eliminated. The conditional constraints, by definition, cannot be represented as round-by-round generation. Based on the properties of Y, there are many ways to eliminate the conditional constraints using the minimum entropy chain rule. Here, one possible efficient method is described by example if Y is generated from blocks according to the example embodiment. Assume... Based on round only Information generation in, i.e. Therefore, the conditional restrictions can be eliminated using equation (9). (9), in, The second inequality utilizes the property that conditional actions do not increase the minimum entropy, while the third inequality uses... for Data processing inequalities, The last inequality uses the chain rule. However, to maintain consistency, the minimum entropy expansion in the main text will be used in the following analysis (which will incur a penalty). However, it is understandable that generalizing the results to the more effective cases emphasized here is straightforward.

[0051] Now focus on the minimum entropy term. This item can now be analyzed using GEAT, and channels can be defined. ,in, ,and

[0052] (1) Implement EAT channel It will be from Mapped to

[0053] (2) Generate uniform random variables (Step 1 of sample and hash).

[0054] (3) Definition

[0055] (4) Announcement and of i values, that is, these values ​​will be known to the opponent.

[0056] (5) i performs quantum state tracing.

[0057] According to the example embodiment, applying this channel will generate a state at the end of the protocol. And the opponent already knows. To prove that this is a valid EAT channel, the two conditions discussed above—projection reconfigurability and no-signal transmission—must be examined.

[0058] exist , The statistical data generated in and in There is no difference. Furthermore, because... From Generated, including Based on the assumption, the same generation method can be used for analysis. Therefore, utilizing Projection reconfigurability of EAT channels It can create It acts on the extended ,in It's obvious. ,therefore Satisfy projection reconfigurability.

[0059] The proof of no-signal transmission in the example embodiment relies on the following assumptions: the original EAT channel Mi is signalless, and The generation is independent of any storage, i.e., the EAT channel. Due to this independence, the EAT channel can typically be... It is divided into two parts. Part One Responsible for generating Because it is independent of Therefore, only input is accepted. and on form and possible intermediate systems Make modifications. Part Two Including the use Arrival The final output system of the channel. Since the first part does not depend on... Therefore, the non-signal condition will depend only on the second part, i.e., the existence of Make .

[0060] Consider the channel described above. It can be written as a series of channels. ,in The generation and sampling steps of Vi are described. Mapping and The order of these can be interchanged because they do not change the system input to another channel. Therefore, having (10) The second equation describes the output. The fourth equation applies non-signaling attributes, and the last equation is swapped. The order of the trajectories, because and Neither of them apply to . Notice Mapping arrive This shows that the channel It is non-signaling.

[0061] when When considering an effective EAT channel, the minimum trade-off function to be used before applying GEAT can now be considered. In this case, the minimum trade-off function must satisfy... (11), in, ,in, von Neumann entropy can be expressed in different ways. Value expansion simplifies the process. When , When it is a fixed value, the entropy is 0. , and For k > j, since... Fixed as j, and For k>j, it does not include The information, conditional entropy can be simplified to... .because Not in the channel They are used in [the context], therefore they do not provide any [benefits]. Information, and can obtain Furthermore, due to The generation and The generation is entirely determined by the channel. Therefore, the state to be optimized is simplified to Σi(q), thus satisfying the requirement of the minimum trade-off function. (12) Among them, the factor ps is composed of v i The probability of =j is determined. According to the GEAT-analyzable primal protocol, there exists a minimum trade-off function f(q) that determines the lower bound of the right side and does not contain the factor ps. Therefore, f′(q) = psf(q) is an efficient minimum trade-off function.

[0062] By using the minimum trade-off function GEAT combined with the EAT channel Thus, the result in the main text can be derived. Since this result applies to all minimum entropy terms in equation (3), therefore (13) If the smoothing parameter is set to 0 for all rounds , Then the error will be reduced to (14) This invention is illustrated by applying it to the standard BB84 QKD protocol using an example embodiment, wherein the number of rounds in the protocol is... Assuming a phase and bit error rate of 1%, GEAT is used in a series of... Value optimization of key and test baseline probability, Figure 2 This illustrates the key rate per transmitted signal versus the number of sampled sub-blocks (i.e., ...) with and without the application of the sampled sub-block hashing method of the example embodiments. A relationship diagram. Furthermore, Figure 3 The graph shows the relationship between the expected key rate per unit time for randomness extraction, with and without the sampled sub-block hashing method of the example embodiment applied. Figure 2 and Figure 3 As can be seen, using the sampling sub-block hashing method according to the example embodiment results in a small loss of key rate per signal sent, but a significant speed improvement.

[0063] To illustrate the effect of the sampling sub-block hashing method according to another example embodiment, consider N=10. 9 Round and confidential parameters =1×10 -6 The BBM92 protocol. Optimized test probability of direct hashing. The value is 0.0176, rounded to 0.02. This choice... This method addresses scenarios where optimized settings have already been implemented and the goal is to modify post-processing steps to improve throughput. As shown in Figure 4, using the sampled sub-block hashing method according to the example embodiment, the key rate loss per signal transmission is minimal, yet a linear speedup is achieved. Figure 4A As shown, the criticality loss due to sampling is expected and is a result of the sampling penalty. Interestingly, despite this loss, it still has an advantage compared to starting with smaller blocks. This is likely because the analysis using the sampled sub-block hashing method according to the example embodiment... The overall statistics of each round are used to estimate the minimum entropy of each sub-protocol, while the small block scenario only uses the total entropy of each protocol. Round statistics. Furthermore, since the required time is more advantageous for smaller input sizes (based on the obtained clock cycle equation), shorter sub-blocks improve the generation rate despite a loss in key length, such as... Figure 4B As shown.

[0064] A hardware implementation of the method according to the example embodiment is performed using a simulated dataset. The reason for choosing... This is because the loss in extractable key length is minimal, while the execution speed improvement is significant. In this example embodiment, the method is implemented on a Xilinx ZCU111 evaluation board, and the results are shown in the table below. First, Table 1 shows the results of Toeplitz hashing on a large block size using the example BB84 protocol without sampling. As expected, the speed of randomness extraction decreases rapidly as the input size increases. This is because even generating a single bit output requires processing a large number of bits first.

[0065]

[0066] Table 1 Table 2 shows the results of Toeplitz hashing for a larger block size using the method according to the example embodiment of the example BB84 protocol. Comparing Tables 1 and 2 clearly shows that despite the larger input size, the execution speed of randomness extraction using the method of the example embodiment is improved by almost an order of magnitude. This demonstrates that the method of the example embodiment can satisfy the finite size effect without incurring a significant penalty to execution speed.

[0067]

[0068] Table 2 The results in Table 2 apply to a single round of sampling, where the input data is reduced to one sampling sub-block and that sub-block is randomly extracted. In the next setting, according to another example embodiment, consider a cascading method where input data from the BB84 example protocol is sampled into three distinct sub-blocks (e.g., but not limited to), and each sub-block is independently randomly extracted before all outputs are cascaded together. The results are presented in Table 3.

[0069]

[0070] Table 3 Comparing the results in Tables 2 and 3, a further speed improvement is achieved when the method is executed using multiple sub-blocks. This is because the time required for sampling (which only needs to be performed once) is averaged over a larger output size. To further evaluate the implementation of the example embodiment, approximately 55.728 megabits of cascaded output were input into the NIST 800-22 Statistical Test Suite [A. Rukhin, J. Soto, J. Nechvatal, E. Barker, S. Leigh, M. Levenson, D. Banks, A. Heckert, and J. Dray, NIST 800-22 Statistical Test Suite for Random and Pseudo-Random Number Generators in Cryptographic Applications (2010). 39] for uniformity testing. The results are as follows. Figure 5 As shown.

[0071] A p-value greater than 0.0001 indicates that the tested sequence passed the specific homogeneity test. From Figure 5 As can be seen, the cascaded output passed all tests in the test suite. Furthermore, since the theoretical model described above guarantees security, it can be assured that the output is uniform and confidential, and even an adversary cannot know it.

[0072] In another implementation, select again This is because the loss in key length extraction is minimal, while the speed improvement is significant. Using the Xilinx ZCU111 evaluation board as the implementation platform, the results for the BBM 92 example protocol are shown in Table 4. As expected, the speed of randomness extraction decreases linearly as the input size increases. This is because even generating a single bit output requires processing a large number of bits first. By comparing direct hashing (data labeled "Traditional Method" in Table 4) with the example embodiment, the method according to the example embodiment is nearly 20 times faster. This indicates that the example embodiment allows for satisfying the finite size effect without sacrificing too much speed. In particular, for input sizes of 960.40 and 1920 megabits, the traditional Toeplitz hash algorithm requires approximately 413 and 1695 hours, respectively, while our method reduces the time to 20.73 and 84.99 hours, respectively, thus greatly improving the practicality of large-input hashing algorithms.

[0073]

[0074] Table 4 To further evaluate the implementation according to the example embodiment, a cascaded output of 152.56 megabits was input to the National Institute of Standards and Technology (NIST) 800-22 Statistical Test Suite. [A. Rukhin, J. Soto] J. Nechvatal, E. Barker, S. Leigh, M. Levinson. Levenson, D. Banks, A. Heckert, and J. Dray, NIST 800- 22. Statistical Test Suite for Random and Pseudo-random Number Generators in Cryptographic Applications (2010) Uniformity testing was conducted. Figure 6A The table below shows the p-value for each individual test in the test suite. A p-value greater than 10... -4 The P-value indicates that the tested sequence passed that specific homogeneity test. Furthermore, in Figure 6B The table shows the proportion of each individual test result. The proportion results show the percentage of the tested sequence samples that passed that particular test. Figure 5 A ratio greater than 0.9657, indicated by the horizontal line 500 in section B, means the tested sequence passed that specific consistency test. Overall, the cascaded output passed all tests in the test suite. Furthermore, due to the security guarantees provided by the aforementioned theoretical model, it can be reaffirmed that the output is uniform and confidential, unknowable even to adversaries.

[0075] Table 5 lists the resource utilization results for implementing the example embodiments on the ZCU111 evaluation kit. The utilization of the lookup table (LUT), LUTRAM, flip-flops (FF), block RAM (BRAM), and digital signal processing (DSP) modules is low. The low utilization also indicates that the entire project can be adapted to a smaller, lower-cost platform.

[0076]

[0077] Table 5 As described above, the method according to the example embodiment improves hashing speed while also taking into account the requirement for large block sizes due to the finite size effect. The required operations are easy to implement, and the overall security of the process is based on information theory and is maintained. Furthermore, due to low resource utilization, the method according to the example embodiment can also be implemented on resource-constrained platforms.

[0078] Figure 7 A schematic diagram of a system 700 for quantum cryptographic randomness extraction according to an example embodiment is shown. The system includes: a sampling module 702 configured to sample a cryptographic key to generate one or more sub-blocks; an entropy module 704 configured to determine a lower bound of entropy in each sub-block, wherein determining the lower bound includes considering the correlation between each sub-block and unsampled bits of the cryptographic key and / or other sub-blocks; and a hashing module 706 for hashing each sub-block to achieve randomness extraction for each sub-block.

[0079] Encryption keys can include raw keys or filtering keys.

[0080] The sampling module 702 can be configured to sample the encryption key into one or more sampling sub-blocks in a random manner based on a predetermined probability.

[0081] System 700 may include a filtering module 708 for filtering encryption keys or filtering one or more sample sub-blocks.

[0082] The sampling module 702 can be configured to apply a threshold to the bit string length representing each sub-block and to abort the method when the bit string length of any sub-block exceeds a predetermined threshold.

[0083] System 700 may include a splicing module for splicing hashed sub-blocks to generate a key.

[0084] Entropy module 704 can be configured to determine the lower bound based on the generalized entropy accumulation theorem.

[0085] Figure 8 A flowchart of a method for randomness extraction in quantum cryptography according to an example embodiment is shown in step 800. In step 802, the key is sampled to generate one or more sub-blocks. In step 804, a lower bound of the entropy in each sub-block is determined, wherein determining the lower bound includes considering the correlation between each sub-block and the unsampled bits of the key and / or other sub-blocks. In step 806, a hash operation is performed on each sub-block for randomness extraction of each sub-block.

[0086] The encryption key can include the original key or the filtering key.

[0087] The step of sampling the original key into one or more sub-blocks can be performed randomly based on a predetermined probability.

[0088] This method may include filtering encryption keys or filtering one or more sample sub-blocks.

[0089] The method may include applying a threshold to the length of the bit string representing each sub-block, and terminating the method if the length of the bit string of any sub-block exceeds a predetermined threshold.

[0090] This method may include concatenating hashed sub-blocks to generate a key.

[0091] The steps to determine the lower bound can be based on the generalized entropy accumulation theorem.

[0092] In one embodiment, a method for performing quantum cryptography between two or more parties is provided, the method comprising publishing a uniform random variable. This identifies which bit of the encryption key was sampled into which sub-block.

[0093] This method can be used with any of the example embodiments described herein for quantum cryptographic randomness extraction.

[0094] This method may include a method for quantum cryptographic randomness extraction using any of the example embodiments described herein.

[0095] Industrial applications of example embodiments The method according to the example embodiment can be used in all quantum cryptography protocols. The speedup achieved, coupled with considerations for finite-size security, is a highly valuable feature for implementations such as QKD and QRNG. Therefore, the method according to the example embodiment can be used as a general method for randomness extraction in QKD and QRNG systems.

[0096] The method according to the example embodiments is considered particularly useful in measurement-device-independent schemes and device-independent protocols. This is because such protocols require larger block sizes to account for finite size effects, as described herein.

[0097] Furthermore, the chip-based QKD and QRNG system implementations, which have garnered significant industry attention, can also benefit greatly from the methods described in the example embodiments. This is because on-chip system resources are limited, and the finite size effect can lead to a decrease in throughput. The methods described in the example embodiments can address this issue by adding only a few relatively simple operations to resolve the on-chip finite size effect without severely impacting speed.

[0098] Aspects of the systems and methods described herein, such as the sampling module, entropy module, hash module, and splicing module described herein (including in the claims), can be implemented on computing devices, including cloud-based computing devices and / or Internet of Things (IoT) computing devices, as functions programmed into various circuits, including programmable logic devices (PLDs), such as field-programmable gate arrays (FPGAs), programmable array logic (PAL) devices, electrically programmable logic and memory devices, and standard cell-based devices, as well as application-specific integrated circuits (ASICs). Other possibilities for implementing aspects of the system include: microcontrollers with memory (e.g., electrically erasable programmable read-only memory (EEPROM)), embedded microprocessors, firmware, software, etc. Furthermore, aspects of the system can also be embodied in microprocessors with software-based circuit simulation, discrete logic (sequential and combinational), custom devices, fuzzy (neural) logic, quantum devices, and hybrids of any of the above device types. Of course, underlying device technologies can be provided in a variety of component types, such as metal-oxide-semiconductor field-effect transistor (MOSFET) technology (e.g., complementary metal-oxide-semiconductor (CMOS)), bipolar technology (e.g., emitter-coupled logic (ECL)), polymer technology (e.g., silicon conjugated polymer and metal conjugated polymer-metal structures), analog and digital hybrid technology, etc.

[0099] The various functions or processes disclosed herein can be described, based on their behavior, register transfers, logic components, transistors, layout geometry, and / or other characteristics, as data and / or instructions embedded in various computer-readable media. Computer-readable media that may contain such formatted data and / or instructions include, but are not limited to, various forms of non-volatile storage media (e.g., optical, magnetic, or semiconductor storage media) and carrier waves that can be used to transmit such formatted data and / or instructions via wireless, optical, or wired signal media, or any combination thereof. Such data and / or instructions, when received in various circuits (e.g., a computer), can be processed by a processing entity (e.g., one or more processors).

[0100] Those skilled in the art will understand that various modifications and variations can be made to the invention illustrated in the specific embodiments without departing from the spirit or scope of the invention as broadly described herein. Therefore, these embodiments should be considered illustrative rather than restrictive in all respects. Furthermore, the invention includes any combination of features described for different embodiments (including in the summary section), even if such feature or combination of features is not expressly specified in the claims or the detailed description of these embodiments.

[0101] Generally, the terminology used in the claims should not be construed as limiting the systems and methods to the specific embodiments disclosed in the specification and claims, but should be understood to include all processing systems operating under the claims. Therefore, the systems and methods are not limited by this disclosure, but rather their scope is entirely defined by the claims.

[0102] Unless the context explicitly requires otherwise, throughout the specification and claims, the words “comprising,” “including,” and “including” should be understood in an inclusive sense, not an exclusive or exhaustive sense; that is, they should be understood as “including but not limited to.” The use of singular or plural terms also includes the plural or singular, respectively. Furthermore, words such as “here,” “after,” “below,” “above,” and similar terms refer to the entire application, not any specific part of it. When the word “or” is used to refer to a list of two or more items, it covers all of the following interpretations: any item in the list, all items in the list, and any combination of items in the list.

Claims

1. A system for extracting randomness in quantum cryptography, comprising: A sampling module configured to sample an encryption key to generate one or more sub-blocks; An entropy module configured to determine a lower bound of entropy in each sub-block, wherein determining the lower bound includes considering the correlation between each sub-block and the unsampled bits of the encryption key and / or other sub-blocks; as well as A hash module is configured to perform hash processing on each sub-block in order to achieve random extraction of each sub-block.

2. The system according to claim 1, wherein, The encryption key may be the original key or the filtering key.

3. The system according to claim 1 or 2, wherein, The sampling module is configured to sample the encryption key into one or more sampling sub-blocks in a random manner based on a predetermined probability.

4. The system according to any one of the preceding claims, comprising a filtering module configured to filter the encryption key or filter the one or more sampled sub-blocks.

5. The system according to any one of the preceding claims, wherein, The sampling module is configured to apply a threshold to the length of the bit string representing each sub-block, and to abort the method if the bit string length of any sub-block exceeds a predetermined threshold.

6. The system according to any one of the preceding claims, comprising a splicing module configured to splice hashed sub-blocks to generate a key.

7. The system according to any one of the preceding claims, wherein, The entropy module is configured to determine the lower limit based on the generalized entropy accumulation theorem.

8. A method for extracting randomness in quantum cryptography, comprising the following steps: The encryption key is sampled to generate one or more sub-blocks; Determine a lower bound for the entropy in each sub-block, wherein determining the lower bound includes considering the correlation between each sub-block and the unsampled bits of the encryption key and / or other sub-blocks; as well as Each sub-block is hashed to achieve random extraction of each sub-block.

9. The method of claim 8, wherein the encryption key includes the original key or the filtering key.

10. The method according to claim 8 or 9, wherein, The step of sampling the original key into the one or more sub-blocks is performed randomly based on a predetermined probability.

11. The method according to any one of claims 8 to 10, comprising filtering the encryption key or filtering the one or more sampled sub-blocks.

12. The method according to any one of claims 8 to 11, comprising applying a threshold to the length of the bit string representing each sub-block, and suspending the method if the length of the bit string of any sub-block exceeds a predetermined threshold.

13. The method according to any one of claims 8 to 12, comprising concatenating hashed sub-blocks to generate a key.

14. The method according to any one of claims 8 to 13, wherein, The steps for determining the lower limit are based on the generalized entropy accumulation theorem.

15. A method for performing quantum cryptography between two or more parties, the method comprising publishing a uniform random variable This identifies which bit of the encryption key was sampled into which sub-block.

16. The method of claim 15, using the system for quantum cryptographic randomness extraction according to any one of claims 1 to 7.

17. The method of claim 15 or 16, comprising using the method for quantum cryptographic randomness extraction according to any one of claims 8 to 14.