Third-party quantum summation method with bidirectional identity authentication mechanism based on cluster state
By adopting a cluster-state-based two-way identity authentication mechanism, combined with hash functions and quantum operations, the problem of the loose integration between quantum identity authentication and secure multi-party computation protocols is solved, realizing an efficient and secure quantum summation method to ensure the authenticity of the identities of both communicating parties and the security of data.
Patent Information
- Application Number
- CN202511881738.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-15
- Publication Date
- 2026-01-09
- Estimated Expiration
- 2045-12-15
AI Technical Summary
Existing quantum authentication schemes are not tightly integrated with secure multi-party computation protocols, resulting in high communication risks and high costs.
A two-way authentication mechanism based on cluster states is adopted. A third party rewrites the four-particle entangled cluster state to generate an initial quantum sequence. The authentication is performed using a hash function and decoy particles, and security detection is performed by combining MEASURE and REFLECT operations to ensure the authenticity of the identities of the communicating parties and the security of the data.
It improves information density and protocol efficiency, prevents replay attacks, ensures the absolute authenticity of the identities of both communicating parties, eliminates impersonation, greatly enhances protocol security, prevents eavesdropping and tampering, and safeguards the security of private data.
Smart Images

Figure CN121308992A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of quantum secure computing communication, in particular to a third-party quantum summation method based on a cluster state with a bidirectional identity authentication mechanism. BACKGROUND
[0002] With the advent of the big data era, secure and efficient data aggregation has become an important research direction in the field of privacy computing. Quantum cryptography, as a new cross-discipline, mainly uses the basic principles of quantum mechanics to establish a new cryptographic system, which theoretically guarantees unconditional security. Compared with classical cryptography, quantum cryptography has the unique advantage of information-theoretic security, that is, its security does not depend on computational complexity assumptions, but is based on physical laws. Since Bennett and Brassard proposed the pioneering work of quantum cryptography in 1984, with the rapid development of quantum communication technology, quantum cryptography has gradually moved from theoretical exploration to practical application, and various application forms such as quantum key distribution (QKD), quantum secure direct communication (QSDC), and quantum secret sharing (QSS) have emerged. These developments have laid a solid foundation for building future quantum secure networks.
[0003] Secure multi-party computation is an important branch of cryptography, which allows multiple participants to jointly complete a function computation without revealing their private data. Secure multi-party computation was proposed by Yao in 1982, which allows n participants to jointly compute a function of their private inputs and guarantees the security of each participant's private input. Among them, quantum secure summation is a basic problem of secure multi-party computation, which aims to enable participants to calculate the sum of their secret data without revealing the specific value of any single data. From the beginning, research on quantum secure summation has been ongoing both at home and abroad. In 2002, Heinrich began to study quantum summation and applied it to integration. Later, he also studied quantum Boolean summation in the worst average setting. In 2007, Du proposed a quantum secret addition, and in 2010, Chen et al. proposed a new and efficient quantum summation protocol, which uses multi-particle entangled states as information carriers in the protocol, while previous protocols mostly use single particles. So far, a large number of quantum summation protocols have been constructed from different perspectives.
[0004] In a distributed quantum network, the authenticity of the participants' identities is a prerequisite for ensuring the security of the protocol. Without a reliable identity authentication mechanism, malicious attackers may obtain sensitive information or disrupt the correctness of the calculation process by impersonating legitimate participants. Therefore, two-way identity authentication has become an indispensable component in quantum secure protocols, which ensures that both parties of communication can verify the authenticity of each other's identity. In recent years, researchers have proposed some quantum identity authentication schemes, including identity authentication in quantum secure key, identity authentication in quantum dialogue, and protocols that can authenticate both ways. However, the existing quantum identity authentication schemes are not closely integrated with secure multi-party computation protocols. Most quantum summation protocols lack built-in identity authentication mechanisms or assume that the participants' identities have been verified through external means; this separate design approach may increase the complexity and implementation cost of the protocol, and may also introduce additional security risks. Therefore, it is of great theoretical significance and practical value to organically integrate two-way identity authentication with quantum summation protocols to form a unified security framework. SUMMARY
[0005] To this end, the technical problem to be solved by the present application is to overcome the problem that the existing quantum identity authentication scheme is not closely integrated with the secure multi-party computation protocol, resulting in high communication risk and high cost.
[0006] To solve the above technical problems, the present application provides a third-party quantum summation method with a two-way identity authentication mechanism based on a cluster state, applied to a quantum channel including four participants and a third party, each of the four participants having a private bit string and secret identity information shared with the third party, comprising: The third party uses quantum operations to rewrite the four-particle entangled cluster state to obtain multiple rewritten states; the i-th particle in each rewritten state is used to form an i-th initial quantum sequence and sent to the i-th participant; wherein 1≤i≤4; The third party calculates the first hash function value of each participant based on a preset random number and the secret identity information of each participant; and measures and encodes the initial quantum sequence of each participant using the first hash function value of each participant to obtain the first optimized quantum sequence of each participant; The third party randomly selects decoy particles and inserts them into the initial quantum sequence of each participant to obtain the target quantum sequence of each participant; and sends the decoy particle insertion information and the target quantum sequence of each participant to the corresponding participant; After receiving the target quantum sequence, the participant measures the target quantum sequence to obtain the decoy particle measurement result; and determines whether the error rate between the decoy particle measurement result of each participant and the decoy particle insertion information is greater than a preset error threshold: If it is greater, the current communication is interrupted; If not greater than, the participant restores the initial quantum sequence corresponding thereto, calculates a second hash function value of the participant by using the preset random number and the secret identity information, and measures and encodes the initial quantum sequence of the participant by using the second hash function value to obtain a second optimized quantum sequence of the participant; The third party calculates the error code rate between the first optimized quantum sequence and the second optimized quantum sequence of each participant, and judges whether the error code rate is less than a preset error threshold: If not less than, the participant fails in the identity authentication; If less than, the participant passes the identity authentication, and until all the participants are detected to pass the identity authentication, the third party performs quantum summation on all the participants.
[0007] Preferably, the quantum summation on all the participants by the third party comprises: Each participant randomly performs MEASURE operation or REFLECT operation on each particle in the initial quantum sequence to obtain reflected particles and feed back to the third party; After the third party receives all the reflected particles, the third party sends a confirmation message to each participant and obtains the operation type of each reflected particle from each participant; For each participant, based on the type of operation performed on each reflected particle, corresponding security detection is performed, comprising: If the participant performs MEASURE operation on four reflected particles, based on the measurement result of the MEASURE operation, a private key of the participant is generated according to a preset encoding rule, and the private bit string of the participant is encrypted by using the private key and sent to the third party, so that the third party receives all the encrypted private bit strings of the participants, and then performs modulo 2 summation to obtain the summation result of all the participants; If the participant performs REFLECT operation on four reflected particles, external eavesdropping detection is performed; If the participant performs MEASURE operation on two reflected particles and performs REFLECT operation on the other two reflected particles, internal eavesdropping detection is performed; If there is another situation except the above situations, the participant is skipped.
[0008] Preferably, the MEASURE operation comprises: applying Hadamard gate operation to the particle to convert the particle from the computational basis to the superposition state; performing Z basis measurement on the superposition state particle to obtain the corresponding bit value as the measurement result of the MEASURE operation; and the REFLECT operation is to flip the particle by using the general quantum gate operation.
[0009] Preferably, the external eavesdropping detection comprises: The third party measures the four reflecting particles to obtain corresponding measurement results, and determines whether the measurement results are the same as the quantum states of the four particles in the initial quantum sequence: If yes, there is no external eavesdropping; If no, the communication is terminated.
[0010] Preferably, the internal eavesdropping detection comprises: For the two reflecting particles performing the MEASURE operation, obtaining the measurement results of the corresponding MEASURE operation as the first measurement result and the second measurement result; For the two reflecting particles performing the REFLECT operation, performing joint measurement under the Bell basis to obtain the Bell measurement result; Determining whether the Bell measurement result, the first measurement result and the second measurement result conform to the record of the preset truth table: If yes, there is no internal eavesdropping detection; If no, the communication is terminated.
[0011] Preferably, the third party rewrites the four-particle entangled cluster state by quantum operation to obtain a plurality of rewritten states, comprising: The third party performs quantum operation on the particles selected from the four particles of the cluster state to obtain the corresponding rewritten state; The quantum operation comprises CONT gate operation, bit flip, Hadamard gate or combined operation.
[0012] Preferably, the initial quantum sequence of each participant is measured and encoded by using the first hash function value of each participant to obtain the first optimized quantum sequence of each participant, comprising: The third party selects the corresponding measurement basis based on the preset mapping relationship according to each value in the first hash function value of the participant; Each particle in the initial quantum sequence is measured by using each measurement basis to obtain the measurement result of each particle; The first optimized quantum sequence of the participant is obtained by mapping each measurement result to a bit value based on a preset encoding rule; The preset mapping relationship comprises: if the first hash function value is 0, the X basis is selected as the measurement basis; if the first hash function value is 1, the Z basis is selected as the measurement basis; The preset encoding rule comprises: if the measurement result is , the mapped bit value is 0; if the measurement result is , the mapped bit value is 1.
[0013] Preferably, the third party randomly selects decoy particles, inserts the initial quantum sequence of each participant, and obtains the target quantum sequence of each participant, comprising: The third party inserts the decoy particles with random quantum states into the initial quantum sequence of the participant at a random position, and obtains the target quantum sequence of the participant; The quantum state of the decoy particle is randomly in 、 、 or state.
[0014] Preferably, after the participant receives the target quantum sequence, the participant measures the target quantum sequence to obtain the measurement result of the decoy particle, comprising: the participant measures each decoy particle in the target quantum sequence based on the decoy particle insertion information to obtain the bit value corresponding to each decoy particle, and the measurement result of the decoy particle in the target quantum sequence is composed.
[0015] Preferably, the error rate between the decoy particle measurement result of the participant and the decoy particle insertion information is the ratio of the number of particles with the same position but different values in the decoy particle measurement result and the decoy particle insertion information to the total number of decoy particles in the participant; the error rate between the first optimized quantum sequence and the second optimized quantum sequence of the participant is the ratio of the number of particles with the same position but different values in the first optimized quantum sequence and the second optimized quantum sequence to the total number of particles in the first optimized quantum sequence.
[0016] The above technical scheme of the present application has the following beneficial effects compared with the prior art:
[0017] The third-party quantum summation method based on the cluster state with a two-way identity authentication mechanism provided by the present application uses a four-particle cluster state as a quantum resource, and the cluster state can simultaneously associate the information of four participants, thereby improving the information density and the protocol efficiency. In the two-way identity authentication stage, the first hash function value of each participant is calculated based on a preset random number and the secret identity information of each participant, so that only a legitimate third party can generate a correct first optimized quantum sequence. At the same time, since the random number is introduced, the first optimized quantum sequence generated each time is different, thereby effectively preventing a replay attack. The third party verifies the identity of the user by comparing the hash sequence calculated by the user, and the user verifies the identity of the third party by whether the third party can correctly respond to the sequence submitted by the user, thereby ensuring the absolute authenticity of the identities of the two communication parties and eliminating forgery from the source.
[0018] And the security of the whole authentication process not only depends on the hash function, but also depends on the quantum mechanics principle based on decoy photon detection, even if the hash function is cracked in the classical sense, the attacker cannot impersonate through the quantum channel; Any eavesdropper intercepts the quantum state, and due to the unknown basis randomly selected by the third party for each decoy photon, once the eavesdropper measures with the wrong basis, the quantum state will be disturbed irreversibly, so that it is found in the error rate detection. Through the error detection of decoy photons, the embodiment ensures that the quantum channel is not eavesdropped in the transmission stage, and prevents the intermediate person from intercepting and tampering with the quantum information.
[0019] In the third-party summation stage, the present application makes each participant randomly perform MEASURE operation or REFLECT operation on each particle in the quantum sequence saved by himself, and then reflects to the third party to integrate the calculation task and security monitoring; After receiving all the particles reflected back by the users and the operation types of the reflected particles, the third party performs joint measurement on the reflected particles, binds the local, classically verifiable measurement results and the global, quantum mechanical entanglement association together, judges whether there is internal eavesdropping or external eavesdropping by the error rate between the statistical measurement results and the expected results, and greatly improves the security of the protocol. At the same time, the private data of the user always exists in the form of encryption, and the third party can only obtain the final sum, and cannot know any single user's input, further ensuring the security. BRIEF DESCRIPTION OF DRAWINGS
[0020] In order to make the content of the present application more easily understood, the present application will be further described in detail below according to specific embodiments of the present application and in conjunction with the drawings, in which: Figure 1 is a step flow chart of the third-party quantum summation method based on the cluster state with the bidirectional identity authentication mechanism provided by the present application. DETAILED DESCRIPTION
[0021] The present application will be further described below in conjunction with the drawings and specific embodiments, so that those skilled in the art can better understand the present application and implement it, but the embodiments are not as a limitation on the present application.
[0022] The application provides a third-party quantum summation method based on a cluster state and a bidirectional identity authentication mechanism.
[0023] Firstly, the existing quantum entangled state and logic gate used in the embodiment are introduced: forming a Z base, forming an X base; ② Pauli-X gate: the X gate is equivalent to the NOT gate in the classical logic gate, and can perform bit inversion on the quantum bit, that is, ; the function expression and matrix form are respectively represented as: ③ Hadamard gate, also known as H transformation, and its action is represented as: ; the operation expression for a single bit is: ④ Bell base, which is the largest entangled state composed of two particles, which constitutes a complete orthogonal base of a four-dimensional Hilbert space, and the specific form is: ⑤ controlled phase GZ gate, which has two input quantum bits, namely control quantum bit and target quantum bit; its function is to reverse the phase of the two body states by π when the control quantum bit and the target quantum bit are in at the same time, and the corresponding matrix form is: ⑥ quantum controlled non gate (controlled-NOT gate or CNOT gate), which has two input quantum bits, namely control quantum bit and target quantum bit; its function is that when the control quantum bit is , the target quantum bit state is unchanged; when the control quantum bit is , the target quantum bit state is inverted, and the corresponding matrix form is .
[0024] Reference Figure 1 The flowchart illustrates the steps of the third-party quantum summation method based on clustered states with a bidirectional authentication mechanism, as shown in this invention. This method is applied to a quantum channel involving four participants and one third party. Each of the four participants has a private bit string and secret identity information shared with the third party. The specific steps include: S101: A third party uses quantum operations to rewrite the cluster state of four entangled particles, obtaining multiple rewritten states; obtains the i-th particle in each rewritten state, forms the i-th initial quantum sequence, and sends it to the i-th participant; where 1≤i≤4; The quantum operations include: CONT gate operation, bit flip, Hadamard gate or combination operation; a third party arbitrarily selects particles from the four particles of the cluster state to perform quantum operations and obtain the corresponding rewritten state; S102: A third party calculates the first hash function value of each participant based on a preset random number and the secret identity information of each participant; using the first hash function value of each participant, the initial quantum sequence of each participant is measured and encoded to obtain the first optimized quantum sequence of each participant; Specifically, the third party selects the corresponding measurement basis based on the values in the participant's first hash function value and a preset mapping relationship; uses each measurement basis to measure each particle in the initial quantum sequence to obtain the measurement results of each particle; and maps each measurement result to a bit value based on a preset encoding rule to obtain the participant's first optimized quantum sequence. The preset mapping relationship includes: if the value of the first hash function is 0, then the X base is selected as the measurement base; if the value of the first hash function is 1, then the Z base is selected as the measurement base. The preset coding rules include: if the measurement result is If the value of the mapped bit is 0, then the value of the mapped bit is 0; if the measurement result is If , then the mapped bit value is 1; S103: A third party randomly selects decoy particles and inserts them into the initial quantum sequence of each participant to obtain the target quantum sequence of each participant; the decoy particle insertion information and the target quantum sequence of each participant are sent to the corresponding participant. The quantum state of the decoy particles is randomly in... , , or State; A third party inserts a randomly generated decoy particle into a random position in the participant's initial quantum sequence to obtain the participant's target quantum sequence; S104: After the target quantum sequence is received by the participant, the target quantum sequence is measured to obtain the decoy particle measurement result; and whether the error code rate between the decoy particle measurement result of each participant and the decoy particle insertion information is greater than a preset error threshold is judged: S105: If yes, the current communication is interrupted; S106: If no, the participant restores the initial quantum sequence corresponding to the participant, and then calculates the second hash function value of the participant by using the preset random number and the secret identity information; and the initial quantum sequence of the participant is measured and encoded by using the second hash function value to obtain the second optimized quantum sequence of the participant; S107: The third party calculates the error code rate between the first optimized quantum sequence and the second optimized quantum sequence of each participant, and judges whether the error code rate is less than a preset error threshold: S107-1: If no, the participant fails in the identity authentication; S107-2: If yes, the participant passes the identity authentication, and until all the participants are detected to pass the identity authentication, the third party performs quantum summation on all the participants.
[0025] Wherein, the error code rate between the decoy particle measurement result of the participant and the decoy particle insertion information is the ratio of the number of particles with the same position but different values in the decoy particle measurement result and the decoy particle insertion information to the total number of decoy particles in the participant; and the error code rate between the first optimized quantum sequence and the second optimized quantum sequence of the participant is the ratio of the number of particles with the same position but different values in the first optimized quantum sequence and the second optimized quantum sequence to the total number of particles in the first optimized quantum sequence.
[0026] Specifically, in the identity authentication process, the specific algorithm of the specific hash function is not specified, because the security such as the one-wayness and the anti-collision of the hash function H(x) is not utilized, and only the compressed data related to r is generated by using the hash function H(x) each time the authentication is performed. (i∈{A, B, C, D}) and r, and when different r is selected, the hash value The unconditional security of the method is based on the principles of quantum mechanics (such as the uncertainty principle, the no-cloning theorem), rather than on the assumption of the computational complexity of hash functions. Hash functions are only used here as a message compression tool, with the purpose of mapping long inputs to fixed-length short outputs for subsequent processing. Even if the hash function itself is cracked on a classical computer, as long as the security assumption of the quantum part is valid, the entire method is still secure. Therefore, in the specific implementation, any standard encryption hash function that meets the output length requirement (n bits and m bits) can be selected, such as SHA-256 (output 256 bits), SHA-512 (output 512 bits), or SHA3-256, etc. The choice of specific algorithm is an implementation-level issue and does not affect the theoretical design of the method itself.
[0027] In this embodiment, if all participants are authenticated, the third party performs quantum summation on all participants, including: After each participant randomly performs a MEASURE operation or a REFLECT operation on each particle in its initial quantum sequence, it obtains the reflected particles and feeds them back to the third party; After receiving all the reflected particles, the third party sends a confirmation message to each participant and obtains the type of operation performed on each reflected particle from each participant; For each participant, based on the type of operation performed on each reflected particle, corresponding security detection is performed, including: If the participant performs a MEASURE operation on all four reflected particles, based on the measurement results of the MEASURE operation, the participant's private key is generated according to the preset encoding rule, and the participant's private bit string is encrypted using the private key and sent to the third party. After the third party receives all the encrypted private bit strings of the participants, it performs modulo 2 summation to obtain the summation result of all participants; If the participant performs a REFLECT operation on all four reflected particles, external eavesdropping detection is performed; If the participant performs a MEASURE operation on two reflected particles and a REFLECT operation on the other two reflected particles, internal eavesdropping detection is performed; If there is any other situation other than the above, skip this participant.
[0028] The MEASURE operation comprises: applying a Hadamard gate operation to the particle, converting the particle from a computational basis to a superposition state; performing a Z basis measurement on the superposition state particle to obtain a corresponding bit value as a measurement result of the MEASURE operation; and the REFLECT operation is a flip operation on the particle by using a general quantum gate operation.
[0029] The external eavesdropping detection comprises: a third party performing measurement on the four reflected particles to obtain corresponding measurement results, and judging whether the measurement results are the same as the quantum states of the four particles in the initial quantum sequence; if yes, there is no external eavesdropping; if no, the communication is interrupted.
[0030] The internal eavesdropping detection comprises: obtaining measurement results of the MEASURE operation of the two reflected particles as first measurement results and second measurement results; performing joint measurement on the two reflected particles performing the REFLECT operation under a Bell basis to obtain Bell measurement results; and judging whether the Bell measurement results, the first measurement results and the second measurement results conform to a preset truth table; if yes, there is no internal eavesdropping; if no, the communication is interrupted.
[0031] The embodiment of the application relates to four participants and a semi-trusted third party, wherein the third party TP helps to calculate the bitwise modulo 2 sum of the private bit strings of the four participants. The embodiment utilizes the characteristics of cluster states in quantum information, and realizes efficient fusion of data encryption and aggregation processing. Meanwhile, in order to prevent identity forgery and data tampering of an external malicious party, the embodiment introduces an identity verification mechanism, effectively guaranteeing the integrity of the message and the legality of the sender. Specifically, the embodiment has two execution parts, identity authentication and third-party modulo 2 summation; the four participants and the third party TP first pass through identity authentication to exclude the possibility of attack by an external malicious party, and then successfully execute the summation protocol; the TP performs modulo 2 summation according to the private bit string generated by each participant, then verifies the security of the method and analyzes the influence of noise on it, and finally proves the feasibility and reliability of the method.
[0032] The present application prevents forgery and man-in-the-middle attacks by introducing identity authentication, which is a key upgrade compared to many early quantum secure computation methods; the present application can verify the legal identity of each participant and the third party TP; this ensures that only authorized users can participate in the calculation, effectively preventing malicious third parties from disguising as legitimate participants to submit false data or steal results. The core security of the present application is rooted in the basic principles of quantum mechanics, rather than computational complexity assumptions; any attempt by an eavesdropper to intercept, measure or copy a quantum carrier (such as measuring a cluster state particle) will inevitably destroy its fragile entanglement properties; this disturbance will be discovered by the legitimate participants through the eavesdropping detection step, ensuring that the privacy of the sum input values is absolutely protected during transmission. And each participant's private data remains encrypted throughout the process (whether in quantum state form or classical bit form after measurement); only at the third party TP, where all information is aggregated, can the final sum be decrypted, and individual inputs cannot be traced back.
[0033] Based on the above embodiment, the present application ingeniously combines the ultra-high entanglement properties of quantum cluster states with classical identity authentication mechanisms to build a secure, reliable and efficient third-party summation calculation framework. The core advantage of this method is that it combines the security of quantum physics with the identity authentication of classical cryptography, achieving 1+1>2; not only does it provide a physically-based security guarantee against future quantum computing attacks in theory, but it also improves the feasibility, security and reliability of the protocol in real-world applications through practical design (such as using cluster states and identity authentication), providing a powerful solution for future secure cloud computing, privacy data aggregation and other scenarios. In this embodiment, the third-party quantum summation method based on cluster states with a two-way identity authentication mechanism provided by the present application is used to perform summation, including:
[0034] S201: Implementation preparation; S201-1: Based on the quantum state of the four-particle cluster state used in the embodiment of the present application, rewriting is performed to obtain a plurality of rewritten states; The quantum state used in this embodiment is represented in its basic form as: ; Where subscripts 1, 2, 3 and 4 represent each particle of the four-particle entangled state, in order to better apply it to the present method, the above cluster state is rewritten based on the cluster state and quantum operation to obtain an initial change formula, represented as: ; Add a quantum gate to the initial change formula, which is a CNOT gate (quantum controlled non-gate) in turn: 2 particles (control bits) → 1 particle (target bits), X gate: 4 particles, H gate: 2 particles, CNOT gate: 2 particles (control bits) → 1 particle (target bits), and the first change formula is obtained: ; Add an X gate to the 2 particles in the first change formula, and the second change formula is obtained, which is: ; Add an X gate to the 4 particles in the first change formula and an X gate to the 4 particles in the second change formula, respectively: ; ; Add a CNOT gate: 2 particles → 1 particle to the 1, 2 particles in the initial change formula, which can be changed to the third change formula, which is represented as: ; Add a CNOT gate: 3 particles → 4 particles to the 3, 4 particles in the third change formula, add an H gate to the 3 particles, and finally add a CNOT gate: 2 particles → 1 particle, 3 particles → 4 particles, which can obtain a rewritten state, which is represented as: ;
[0035] Other operations are similar to the above, and other rewritten states of 1, 3 and 2, 4 particle combinations can be obtained, which are represented as: ; ; ; Add a CNOT gate: 2 particles → 1 particle to the 1, 2 particles in the initial change formula, which can obtain the fourth change formula, which is represented as: ; At this time, it can be seen that the cluster state of 1, 4 particles and 2, 3 particles in the fourth change formula is the same as the cluster state of 1, 2 particles and 3, 4 particles, and the quantum operation is also the same.
[0036] Finally, the following rewritten states can be easily obtained: ;
[0037] S201-2: Initialize quantum channel, participants and third party; Assume that the quantum channel is authenticated, and assume that there are four users Alice, Bob, Charlie and David, who are classical, and each has a private n-bit string, respectively , , and ; in the present embodiment, n = 8, and the private bit strings of the four participants are respectively , , and ; In addition, there is a third party TP that must faithfully implement the protocol, under the participation of the third party TP, the TP and the four participants perform two-way identity authentication, and after the authentication is passed, the TP calculates the bitwise modulo 2 sum of its private bit string. Assume that Alice, Bob and Charlie only have limited quantum capabilities, and their goal is to obtain the bitwise modulo 2 addition of their private bit strings without disclosure, and the TP helps them to calculate ; = ; In addition, before the method is implemented, A, B, C, D and the third party TP also pre-share a secret identity information (i∈{A, B, C, D}).
[0038] S202: Two-way identity authentication; S202-1: The TP prepares 12*n (1+δ) cluster states, each state is randomly selected from the rewriting state of , where δ is a parameter, so that each participant can obtain an n-bit private key for encryption in the final summation protocol, and the particles (q ) represent the four particles in the cluster state, respectively, and the TP takes to form the first initial quantum sequence , takes , and to form the second, third and fourth initial quantum sequences , and ; S202-2: Then the TP selects a random number r and publishes it, and then calculates the first hash function value (i∈{A, B, C, D}) and the random number r, where, according to the value of , the corresponding measurement basis can be selected to measure the particles in the initial quantum sequence (i, j e {1, 2, 3, 4}), the preset mapping relationship of the measurement bases selected by TP is shown in Table 1; Table 1 Preset mapping relationship of measurement bases selected by TP
[0039] Thus, TP obtains a new quantum sequence, i.e., the first optimized quantum sequence (i e {1, 2, 3, 4}), the preset encoding rule of mapping the measurement results into bit values is shown in Table 2; Table 2 Preset encoding rule of mapping the measurement results into bit values
[0040] S202-3: Since the authentication process is the same, only the two-way authentication between TP and Alice is introduced here. TP prepares a sufficient number of decoy photons , which are randomly inserted into the sequence to form a new sequence , i.e., the target quantum sequence; these decoy photons are randomly in one of the four states , , , , each with a probability of one fourth. Subsequently, TP sends the target quantum sequence to Alice; S202-4: If it is confirmed that Alice receives the target quantum sequence , TP will tell Alice the positions of the decoy particles in the sequence and the corresponding measurement base numbers. Referring to the contents of Table 3, in order to analyze the bit error rate, Alice will compare her measurement results with the information of the decoy particles reserved by TP, and if the quantum bit error rate (QBER) is lower than a preset threshold, the communication process continues. Otherwise, if the error rate exceeds the given threshold, the current communication is interrupted, and the protocol is re-executed.
[0041] Table 3 Correspondence between measurement results and classical information after Alice knows the decoy positions
[0042] S202-5: If the protocol continues, Alice will remove the decoy photons from the sequence to restore the sequence and save it in her own quantum memory. When TP authenticates the identities of Bob, Charlie and David, they will also restore the sequences , and It is stored in her own quantum memory. Then, Alice will use the random number r published by TP and the pre-shared key... Calculate the second hash function ,in At this point, Alice will also obtain a second optimized quantum sequence. Alice then obtained the quantum sequence and Inform TP.
[0043] S202-6: Final TP comparison and The value of TP is calculated, and the error rate is determined. If the error rate is below a threshold, TP considers Alice's identity to be correct; otherwise, TP considers Alice to be fake. This allows TP to determine whether Alice's identity is correct, and conversely, Alice can also determine whether TP's identity is correct.
[0044] S203: TP and the four participants all perform the two-way identity authentication operation as shown in step S202 to complete the two-way identity authentication and eliminate the possibility of dishonest participants.
[0045] S204: Summation of third parties; S204-1: After identity verification, TP has confirmed the correctness of the identities of the four participants. During the verification phase, each participant has separately stored the quantum sequence. , , and Alice, Bob, Charlie, and David then randomly perform either a MEASURE or REFLECT operation on each particle in the sequence. After receiving all the particles, TP sends an "ACK" message to Alice, Bob, Charlie, and David, requesting them to announce the operation they performed. Upon receiving the "ACK" message, Alice (Bob, Charlie, David) announces the location of the particle on which the MEASURE or REFLECT operation was performed via an authenticated classical channel to TP.
[0046] For the MEASURE operation, an H quantum gate is applied to each particle individually, so that each particle is calculated from the ground state ( , Transformation to superposition state ( , Then in Z-base { , In quantum computing, Z-basis measurements, also known as computational basis measurements, are the most common measurement methods and cause the quantum state to collapse to a certain value. or , each quantum state will collapse randomly to , The quantum state, and finally record the measurement result. For the REFLECT operation, it is a general quantum gate operation, the core idea of which is to flip a component (usually the phase) of the quantum state vector, and in the present application, the above measurement result is reflected to the third party TP without disturbance.
[0047] That is, the four participants restrict the execution of the following operations: applying H gate to the four quantum particles, measuring the particles (MEASURE operation) in the Z basis , } generating random quantum bits (whose values are , , and reflecting the particles without disturbance (REFLECT operation).
[0048] S204-2: Then TP, Alice, Bob, Charlie and David discuss whether there is external eavesdropping or participant attack, and they take corresponding actions to check external eavesdropping or participant attack, or generate a private key. Their actions are shown in Table 4: Table 4: Operations selected by each user on the particles they received, and the final results Case Actions by Alice, Bob, Charlie, and David Result Case 1 MMMM Generate private key Case 2 MMRR / MRMR / MRRM / RRMM / RMMR / RMRM Internal eavesdropping Case 3 RRRR External eavesdropping Case 4 Other Ignore
[0049] ①Detect participant attack (internal eavesdropping): For the case where two participants select the REFLECT operation and the other two select the MEASURE operation, for example, case 2, Alice, Bob, Charlie, David and TP jointly detect participant attack. For the cluster state falling into case 2, the participants who select the MEASURE operation announce their measurement results to TP, TP measures two particles belonging to the same cluster state in the Bell basis, and TP uses case 2 to verify the entanglement relationship depending on the cluster state. If there is no participant attack, all measurement results should satisfy the relationship shown in Table 5 below, and TP calculates the error rate according to these measurement results. If the error rate exceeds the threshold, the communication is interrupted and restarted.
[0050] Table 5: MEASURE measurement results and Bell joint measurement results
[0051] In this embodiment, for participant attack, taking the order of operations of the four users on each particle as MMRR as an example, it can be seen that if the measurement results of Alice and Bob are , the Bell measurement results of the reflected qubits of Charlie and David by TP are or .
[0052] ②Detect external eavesdropping; For the case that all four participants choose the REFLECT operation, there is no risk of internal leakage, Alice, Bob, Charlie, David and TP will jointly detect external eavesdropping, for example, case 3, TP measures the four reflected particles in the cluster state, and then compares the measurement results with their corresponding initial states, if there is no external eavesdropping, the measurement results and their corresponding initial states should be the same, they calculate the error rate based on this point, if the error rate exceeds the threshold, they will terminate the communication and start over, otherwise, they will continue to the next step.
[0053] S204-3: In the case that Alice, Bob, Charlie and David all choose the MEASURE operation, about n(1+δ) cluster states are involved, and the first n cluster states will be used to generate the private key of the participants, where n cluster states are respectively: According to the encoding rules in the above method, when n is 8, the generated private keys are , , and ; If the measurement result of Alice (Bob, Charlie, David) is , then , otherwise ; then Alice (Bob, Charlie, David) will calculate , , ; in this embodiment, = (10011011), = (10001100), = (10101110), = (10010101), then Alice (Bob, Charlie, David) will send , , to TP for the final calculation.
[0054] S204-4: TP receives , , , After that, calculate R={ }; According to the encoding rule: if the measurement result of Alice (Bob, Charlie, David) is from or , then , otherwise ; finally, the TP announces the result R to all participants, that is, the summation process is completed.
[0055] Specifically, if the measurement result of Alice (Bob, Charlie, David) belongs to{ }, then According to the rule, it can be seen that , that is ;
[0056] Specifically, if the measurement result of Alice (Bob, Charlie, David) belongs to{ }, then According to the rule, it can be seen that , that is ; The final calculation result R=(00111000) is obtained, and finally the TP announces the result R to all participants, and the correctness of the method can be verified according to the result, that is, the summation process is completed.
[0057] Based on the above embodiment, the security of the third-party quantum summation method based on the cluster state with the two-way identity authentication mechanism proposed in the embodiment of the application is analyzed; this embodiment will prove that the third-party quantum summation method based on the cluster state with the identity authentication mechanism proposed is safe against two threats: external attacks and participant attacks.
[0058] In terms of defending against external attacks, in the identity authentication stage, it has been proved that an external eavesdropper cannot understand any information about the private input of the participants.
[0059] In terms of participant attacks, it will be proved that dishonest participants including the TP cannot obtain any information about the input of other participants. The proof is as follows: In the protocol, the TP is semi-honest, that is, the TP honestly executes the protocol and cannot collude with dishonest participants. Even if the TP allocates quantum resources and knows the measurement result, the encoding rule and , the TP does not know the secret key Since the four participants of the MEASURE operation randomly send 0 or 1 to the TP, although the TP can eventually get R, the TP cannot collude with any dishonest participant. As a result, the TP cannot obtain the private input of the honest participant.
[0060] In this embodiment, it is assumed that Alice is dishonest and wants to eavesdrop on the result of Bob: ① Measure-resend Attack: Alice can intercept the particles in the initial quantum sequence sent by the TP to Bob, and measure these particles using the Z basis to obtain the private key of Bob according to the measurement result Alice then generates new particles in the Z basis and sends them to Bob, and the polarization of these particles is the same as the measurement result, but this attack will be detected in the authentication phase.
[0061] ② Collective Attack: If Alice performs a collective attack, then Alice only performs a collective attack when the MEASURE operation is selected, in which case, if Bob, Charlie and David all select the MEASURE operation, then Alice attempts to use auxiliary quantum bits to obtain the key of Bob, that is, to entangle the auxiliary quantum state with the original quantum system, and try to obtain useful information from the auxiliary quantum state; otherwise, Alice must pass the check of the TP. Alice performs the Ue operation on the second optimized quantum sequence sent by the TP to Bob in Step 5: ; ; The final result shows that Alice can escape the eavesdropping detection, but at the same time she cannot obtain the measurement result of Bob, so the collective attack of the dishonest participant is invalid for the protocol.
[0062] The third-party quantum summation method based on the cluster state and the two-way identity authentication mechanism provided by the application takes four-particle cluster states as quantum resources, and the cluster states can simultaneously associate the information of four participants, thereby improving the information density and the protocol efficiency. In the two-way identity authentication stage, the first hash function value of each participant is calculated based on the preset random number and the secret identity information of each participant, so that only the legitimate third party can generate the correct first optimized quantum sequence. Meanwhile, the first optimized quantum sequence generated each time of authentication is different due to the introduction of the random number, thereby effectively preventing the replay attack. The third party verifies the identity of the user by comparing the hash sequence calculated by the user, and the user verifies the identity of the third party by whether the third party can correctly respond to the sequence submitted by the user, thereby ensuring the absolute authenticity of the identities of the two communication parties and eliminating the forgery from the source. The security of the entire authentication process depends not only on the hash function, but also on the quantum mechanics principle based on the decoy photon detection, so that even if the hash function is cracked in the classical sense, the attacker cannot impersonate through the quantum channel; any eavesdropper will be found in the bit error rate detection when intercepting the quantum state, because the eavesdropper does not know the basis randomly selected by the third party for each decoy photon, and once the eavesdropper measures with the wrong basis, the quantum state will be irreversibly disturbed. The embodiment ensures that the quantum channel is not eavesdropped in the transmission stage by the bit error detection of the decoy photon, and prevents the intermediate person from intercepting and tampering with the quantum information. In the third-party summation stage, each participant randomly performs the MEASURE operation or the REFLECT operation on each particle in the quantum sequence saved by the participant, and then reflects the particle to the third party, so that the calculation task and the security monitoring are integrated. After receiving all the particles reflected by the users and the operation types of the reflected particles, the third party jointly measures the reflected particles, binds the local and classical verifiable measurement results with the global quantum entanglement correlation together, judges whether there is internal eavesdropping or external eavesdropping by the bit error rate between the statistical measurement results and the expected results, and greatly improves the security of the protocol. Meanwhile, the private data of the user always exists in an encrypted form, and the third party can only obtain the final sum but cannot know the input of any single user, thereby further ensuring the security.
[0063] Those skilled in the art will appreciate that embodiments of the application can be supplied as methods, systems, or computer program products. Accordingly, the application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage media, etc.) having computer usable program code embodied in the medium.
[0064] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure One one or more flow or blocks Figure One one or more flow or blocks
[0065] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart block or blocks. Figure One one or more flow or blocks Figure One one or more flow or blocks
[0066] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure One one or more flow or blocks Figure One one or more flow or blocks
[0067] Obviously, the above-described embodiments are only examples and are not intended to limit the present application. Based on the above description, one of ordinary skill in the art can further make other variations and changes to the present application. Here, it is not necessary or possible to enumerate all the embodiments. The obvious variations and changes derived therefrom are still within the scope of the present application.
Claims
1. A third-party quantum summation method based on a cluster state and a bidirectional identity authentication mechanism, characterized in that, The application is applied to a quantum channel including four participants and a third party, the four participants each have a private bit string and secret identity information shared with the third party, and the secret identity information includes: The third party rewrites the four-particle entanglement cluster state by using quantum operation to obtain multiple rewritten states; the first initial quantum sequence is composed of the i-th particle in each rewritten state and is sent to the i-th participant; wherein, 1≤i≤4; The third party calculates the first hash function value of each participant based on the preset random number and the secret identity information of each participant; and measures and encodes the initial quantum sequence of each participant by using the first hash function value of each participant to obtain the first optimized quantum sequence of each participant; The third party randomly selects decoy particles and inserts them into the initial quantum sequence of each participant to obtain the target quantum sequence of each participant; and sends the decoy particle insertion information and the target quantum sequence of each participant to the corresponding participant; After receiving the target quantum sequence, the participant measures the target quantum sequence to obtain the decoy particle measurement result; and judges whether the error rate between the decoy particle measurement result of each participant and the decoy particle insertion information is greater than a preset error threshold: If greater, the current communication is interrupted; If not greater, the participant restores the corresponding initial quantum sequence, calculates the second hash function value of the participant by using the preset random number and the secret identity information, and measures and encodes the initial quantum sequence restored by the participant by using the second hash function value to obtain the second optimized quantum sequence of the participant; The third party calculates the error rate between the first optimized quantum sequence and the second optimized quantum sequence of each participant, and judges whether the error rate is less than a preset error threshold: If not less than, the participant fails the identity verification; If less than, the participant passes the identity verification, and until all participants are detected to pass the identity verification, the third party performs quantum summation on all participants.
2. The cluster state based third party quantum summation method with two-way identity authentication mechanism according to claim 1, characterized in that, The third party performs quantum summation on all participants, including: After each participant randomly performs MEASURE operation or REFLECT operation on each particle in the initial quantum sequence, the participant obtains a reflected particle and feeds back the reflected particle to the third party; After receiving all the reflected particles, the third party sends a confirmation message to each participant and obtains the operation type of each reflected particle from each participant; For each participant, based on the type of operation performed on each reflected particle, corresponding security detection is performed, including: If the participant performs MEASURE operation on the four reflected particles, the participant's private key is generated based on the measurement result of the MEASURE operation according to a preset encoding rule, and the participant's private bit string is encrypted by using the private key and sent to the third party, so that the third party receives all the encrypted private bit strings of the participants and performs modulo 2 summation to obtain the summation result of all the participants; If the participant performs REFLECT operation on the four reflected particles, the participant is detected for external eavesdropping. If the participant performs the MEASURE operation on two reflected particles and the REFLECT operation on the other two reflected particles, internal eavesdropping detection is performed on the participant; If there is another case other than the above, the participant is skipped.
3. The cluster state based third party quantum summation method with two-way identity authentication mechanism according to claim 2, characterized in that, The MEASURE operation comprises: applying a Hadamard gate operation to the particles to convert the particles from a computational basis to a superposition state; performing a Z basis measurement on the particles in the superposition state to obtain corresponding bit values as measurement results of the MEASURE operation; and the REFLECT operation is a flip operation on the particles using a general quantum gate operation.
4. The cluster state based third party quantum summation method with two-way identity authentication mechanism according to claim 2, characterized in that, The external eavesdropping detection on the participant comprises: A third party performs measurement on the four reflected particles of the participant to obtain corresponding measurement results, and judges whether the measurement results are the same as the quantum states of the four particles in the initial quantum sequence: If they are the same, there is no external eavesdropping; If they are not the same, the communication is terminated.
5. The cluster state based third party quantum summation method with two-way identity authentication mechanism according to claim 2, characterized in that, The internal eavesdropping detection on the participant comprises: For the two reflected particles in the participant that perform the MEASURE operation, the measurement results of the corresponding MEASURE operation are obtained as the first measurement result and the second measurement result; For the two reflected particles in the participant that perform the REFLECT operation, joint measurement is performed under the Bell basis to obtain Bell measurement results; Judge whether the Bell measurement results, the first measurement result and the second measurement result conform to the record of the preset truth table: If they conform, there is no internal eavesdropping detection; If they do not conform, the communication is terminated.
6. The cluster state based third party quantum summation method with two-way identity authentication mechanism according to claim 1, characterized in that, The third party rewrites the four-particle entangled cluster state using quantum operations to obtain multiple rewritten states, comprising: The third party selects particles from the four particles of the cluster state to perform quantum operations to obtain corresponding rewritten states; The quantum operation comprises: CONT gate operation, bit flip, Hadamard gate or combination operation.
7. The cluster state based third party quantum summation method with two-way identity authentication mechanism according to claim 1, characterized in that, Using the first hash function value of each participant, the initial quantum sequence of each participant is measured and encoded to obtain the first optimized quantum sequence of each participant, comprising: The third party selects corresponding measurement bases based on the preset mapping relationship according to each value in the first hash function value of the participant; Each particle in the initial quantum sequence is measured using each measurement base to obtain the measurement result of each particle; Based on the preset encoding rule, each measurement result is mapped to a bit value to obtain the first optimized quantum sequence of the participant; Wherein, the preset mapping relationship comprises: if the first hash function value is 0, the X basis is selected as the measurement base; if the first hash function value is 1, the Z basis is selected as the measurement base; The preset encoding rule comprises: if the measurement result is , the mapped bit value is 0; if the measurement result is , the mapped bit value is 1.
8. The cluster state based third party quantum summation method with two-way identity authentication mechanism according to claim 1, characterized in that, The third party randomly selects decoy particles and inserts them into the initial quantum sequence of each participant to obtain the target quantum sequence of each participant, comprising: The third party inserts the quantum state of the decoy particle into the initial quantum sequence of the participant at a random position to obtain the target quantum sequence of the participant; The quantum state of the decoy particle is randomly in , , or state.
9. The cluster state based third party quantum summation method with two-way identity authentication mechanism according to claim 1, characterized in that, After receiving the target quantum sequence, the participant measures the target quantum sequence to obtain decoy particle measurement results, including: the participant measures each decoy particle in the target quantum sequence based on the decoy particle insertion information to obtain a bit value corresponding to each decoy particle, and the bit values constitute the decoy particle measurement results of the target quantum sequence.
10. The cluster state based third party quantum summation method with two-way identity authentication mechanism according to claim 1, characterized in that, The error code rate between the decoy particle measurement results of the participant and the decoy particle insertion information is the ratio of the number of particles with the same position but different values in the decoy particle measurement results and the decoy particle insertion information to the total number of decoy particles in the participant; the error code rate between the first optimized quantum sequence and the second optimized quantum sequence of the participant is the ratio of the number of particles with the same position but different values in the first optimized quantum sequence and the second optimized quantum sequence to the total number of particles in the first optimized quantum sequence.
Citation Information
Patent Citations
Flexible privacy comparison protocol based on five-particle cluster state
CN105721428A
Quantum identity authentication method and application method of quantum identity authentication method in quantum key distribution process
CN107493168A
Multi-party quantum key negotiation method based on four-particle chi state
CN110557250A
Multi-user quantum privacy query method with authentication
CN113114456A
Concealed quantum key distribution method based on bait state
CN118074892A
Cited By
Multi-party multi-data summation method based on d-dimensional cluster state
CN122027123A