A third-party quantum summation method with bidirectional authentication mechanism based on cluster states

By adopting a cluster-state-based bidirectional identity authentication mechanism, the problem of loose integration between quantum identity authentication and secure multi-party computation protocol is solved, realizing an efficient and secure quantum summation process and ensuring the authenticity of the identities and data privacy of the communicating parties.

CN121308992BActive Publication Date: 2026-03-13SUZHOU UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-15
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

Existing quantum authentication schemes are not tightly integrated with secure multi-party computation protocols, resulting in high communication risks and high costs.

Method used

A two-way authentication mechanism based on cluster states is adopted. A third party rewrites the four-particle entangled cluster state to generate an initial quantum sequence. The hash function value is used for measurement and encoding. Decoy particles are randomly inserted to detect the bit error rate. Quantum summation is performed after the participant is identified.

Benefits of technology

It improves information density and protocol efficiency, prevents replay attacks, ensures the authenticity of the identities of both communicating parties, eliminates impersonation, prevents eavesdropping through quantum mechanics principles, and enhances security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121308992B_ABST
    Figure CN121308992B_ABST
Patent Text Reader

Abstract

This invention relates to the field of quantum-secure computing and communication technology, and discloses a third-party quantum summation method based on cluster states with a two-way authentication mechanism. First, by pre-sharing secret identity information and a hash function, combined with decoy photon technology, two-way authentication between participants and a third party is achieved in a quantum channel, fundamentally preventing impersonation and man-in-the-middle attacks. After successful authentication, participants randomly perform measurement or reflection operations on their respective particles. This not only generates encrypted private keys with the assistance of a third party, but also allows for joint detection of external eavesdropping and attacks from internal participants based on operation combinations, forming a multi-layered security protection. Ultimately, the third party can only calculate the bitwise modulo-2 sum of each party's private bit strings, but cannot obtain any individual input values. This invention organically integrates authentication and computation, significantly reducing the quantum capability requirements of participants while ensuring unconditional security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of quantum secure computing and communication technology, and in particular to a third-party quantum summation method based on cluster states with a two-way authentication mechanism. Background Technology

[0002] With the advent of the big data era, secure and efficient data aggregation has become an important research direction in the field of privacy computing. Quantum cryptography, as a novel interdisciplinary field, primarily utilizes the fundamental principles of quantum mechanics to establish a new cryptographic system that theoretically guarantees unconditional security. Compared to classical cryptography, quantum cryptography possesses the unique advantage of information theory security; its security does not rely on the assumption of computational complexity but is based on the guarantees of physical laws. Since the pioneering work of Bennett and Brassard in 1984, and with the rapid development of quantum communication technology, quantum cryptography has gradually moved from theoretical exploration to practical applications, giving rise to various application forms such as quantum key distribution (QKD), quantum secure direct communication (QSDC), and quantum secret sharing (QSS). These developments have laid a solid foundation for building future quantum-secure networks.

[0003] Secure multi-party computation (SMC) is an important branch of cryptography that allows multiple participants to collaboratively compute a function without revealing their private data. Proposed by Yao in 1982, SMC allows n participants to jointly compute a function based on their private inputs, guaranteeing the security of each participant's input. Quantum-secure summation is a fundamental problem in SMC, aiming to enable participants to compute the sum of their secret data without revealing the specific value of any individual data. Research in quantum-secure summation has been ongoing both domestically and internationally. In 2002, Heinrich began research on quantum summation and applied it to integration. Later, he also studied quantum Boolean summation under the worst-case average setting. In 2007, Du proposed a quantum secret addition. In 2010, Chen et al. proposed a new and efficient quantum summation protocol that utilizes multi-particle entangled states as information carriers, whereas previous protocols mostly relied on single-particle states. To date, numerous quantum summation protocols have been constructed from different perspectives.

[0004] In distributed quantum networks, the authenticity of the participants' identities is a prerequisite for ensuring protocol security. Without a reliable authentication mechanism, malicious attackers could impersonate legitimate participants to obtain sensitive information or disrupt the correctness of the computation process. Therefore, two-way authentication has become an indispensable component of quantum-safe protocols, ensuring that communicating parties can mutually verify each other's identities. In recent years, researchers have proposed several quantum authentication schemes, including authentication for quantum secure keys, authentication for quantum dialogue, and protocols capable of two-way authentication. However, the integration of existing quantum authentication schemes with secure multi-party computation protocols is not yet tight enough. Most quantum summation protocols lack built-in authentication mechanisms or assume that the participants' identities have been verified externally; this separate design approach may increase protocol complexity and implementation costs, and may also introduce additional security risks. Therefore, organically integrating two-way authentication with quantum summation protocols to form a unified security framework has significant theoretical and practical value. Summary of the Invention

[0005] Therefore, the technical problem to be solved by the present invention is to overcome the problem that the combination of quantum identity authentication scheme and secure multi-party computation protocol in the prior art is not tight enough, resulting in high communication risk and high cost.

[0006] To address the aforementioned technical problems, this invention provides a third-party quantum summation method based on clustered states with a bidirectional authentication mechanism. This method is applied to a quantum channel comprising four participants and one third party. Each of the four participants possesses a private bit string and secret identity information shared with the third party, including:

[0007] A third party uses quantum operations to rewrite the cluster state of four entangled particles, obtaining multiple rewritten states; the i-th particle in each rewritten state is obtained, forming the i-th initial quantum sequence, which is sent to the i-th participant; where 1≤i≤4;

[0008] A third party calculates the first hash function value for each participant based on a preset random number and the secret identity information of each participant; using the first hash function value of each participant, the initial quantum sequence of each participant is measured and encoded to obtain the first optimized quantum sequence of each participant.

[0009] A third party randomly selects decoy particles and inserts them into the initial quantum sequence of each participant to obtain the target quantum sequence of each participant; the decoy particle insertion information and the target quantum sequence of each participant are then sent to the corresponding participant.

[0010] After receiving the target quantum sequence, participants measure the target quantum sequence to obtain the decoy particle measurement results; they then determine whether the bit error rate between each participant's decoy particle measurement results and the decoy particle insertion information exceeds a preset error threshold.

[0011] If the value is greater than the given value, the current communication will be interrupted.

[0012] If the value is not greater than the given value, the participant is asked to reconstruct their corresponding initial quantum sequence. Then, using a preset random number and secret identity information, the participant's second hash function value is calculated. The participant's initial quantum sequence is then measured and encoded using the second hash function value to obtain the participant's second optimized quantum sequence.

[0013] A third party calculates the bit error rate between the first and second optimized quantum sequences of each participant and determines whether the bit error rate is less than a preset error threshold.

[0014] If the value is not less than the minimum, then the participant has not been verified.

[0015] If the value is less than 1, the participant is authenticated. This continues until all participants are detected to be authenticated, at which point the third party performs a quantum summation on all participants.

[0016] Preferably, a third party performs quantum summation on all participants, including:

[0017] Each participant randomly performs a MEASURE or REFLECT operation on each particle in their initial quantum sequence to obtain a reflected particle, which is then fed back to a third party.

[0018] After receiving all the reflected particles, the third party sends confirmation messages to each participant and obtains the operation type performed on each reflected particle from each participant.

[0019] For each participant, based on the type of operation they perform on each reflecting particle, corresponding security checks are performed, including:

[0020] If the participant performs the MEASURE operation on all four reflecting particles, then based on the measurement results of the MEASURE operation, the participant's private key is generated according to the preset encoding rules, and the participant's private bit string is encrypted using the private key and sent to a third party, so that the third party receives the encrypted private bit strings of all participants, performs modulo 2 sum calculation, and obtains the summation result of all participants.

[0021] If the participant performs the REFLECT operation on all four reflecting particles, external eavesdropping detection will be performed;

[0022] If the participant performs the MEASURE operation on two reflecting particles and the REFLECT operation on the other two reflecting particles, then internal eavesdropping detection is performed.

[0023] If any other situation exists besides the one described above, then skip that participant.

[0024] Preferably, the MEASURE operation includes: applying a Hadamard gate operation to the particle to convert the particle from a computational basis to a superposition state; performing a Z-basis measurement on the particle in the superposition state to obtain the corresponding bit value as the measurement result of the MEASURE operation; and the REFLECT operation is to flip the particle using a universal quantum gate operation.

[0025] Preferably, the external eavesdropping detection includes:

[0026] A third party measures the four reflecting particles, obtains the corresponding measurement results, and determines whether the measurement results are the same as the quantum states of the four particles in the initial quantum sequence:

[0027] If they are the same, then there is no external eavesdropping;

[0028] If they are different, communication is terminated.

[0029] Preferably, the internal eavesdropping detection includes:

[0030] For two reflecting particles that have performed the MEASURE operation, obtain the corresponding measurement results of the MEASURE operation, and use them as the first measurement result and the second measurement result;

[0031] For two reflecting particles that have performed the REFLECT operation, a joint measurement is performed on the Bell basis to obtain the Bell measurement results.

[0032] Determine whether the Bell measurement result, the first measurement result, and the second measurement result conform to the records in the preset truth table:

[0033] If the conditions are met, then there is no internal eavesdropping detection.

[0034] If the conditions are not met, communication will be terminated.

[0035] Preferably, a third party uses quantum operations to rewrite the cluster state of the four-particle entanglement to obtain multiple rewritten states, including:

[0036] A third party arbitrarily selects a particle from the four particles in the cluster state to perform quantum operations and obtain the corresponding rewritten state;

[0037] The quantum operations include: CONT gate operations, bit flipping, Hadamard gate operations, or combinations thereof.

[0038] Preferably, the initial quantum sequence of each participant is measured and encoded using the first hash function value of each participant to obtain the first optimized quantum sequence of each participant, including:

[0039] The third party selects the corresponding measurement basis based on the values ​​in the participants' first hash function values ​​and a preset mapping relationship;

[0040] Each particle in the initial quantum sequence is measured using various measurement bases to obtain the measurement results for each particle;

[0041] Based on the preset encoding rules, each measurement result is mapped to a bit value to obtain the participant's first optimized quantum sequence;

[0042] The preset mapping relationship includes: if the value of the first hash function is 0, then the X base is selected as the measurement base; if the value of the first hash function is 1, then the Z base is selected as the measurement base.

[0043] The preset coding rules include: if the measurement result is If the value of the mapped bit is 0, then the value of the mapped bit is 0; if the measurement result is If the mapped bit value is 1, then the value of the mapped bit is 1.

[0044] Preferably, a third party randomly selects decoy particles and inserts them into the initial quantum sequence of each participant to obtain the target quantum sequence of each participant, including:

[0045] A third party inserts a randomly generated decoy particle into a random position in the participant's initial quantum sequence to obtain the participant's target quantum sequence.

[0046] The quantum state of the decoy particles is randomly in... , , or state.

[0047] Preferably, after receiving the target quantum sequence, the participant measures the target quantum sequence to obtain the decoy particle measurement results, including: the participant measures each decoy particle in the target quantum sequence based on the decoy particle insertion information, obtains the bit value corresponding to each decoy particle, and forms the decoy particle measurement results of the target quantum sequence.

[0048] Preferably, the bit error rate between the participant's decoy particle measurement result and the decoy particle insertion information is the ratio of the number of particles with the same position but different values ​​in the decoy particle measurement result and the decoy particle insertion information to the total number of decoy particles in the participant; the bit error rate between the participant's first optimized quantum sequence and the second optimized quantum sequence is the ratio of the number of particles with the same position but different values ​​in the first optimized quantum sequence and the second optimized quantum sequence to the total number of particles in the first optimized quantum sequence.

[0049] Compared with the prior art, the above-described technical solution of the present invention has the following advantages:

[0050] The third-party quantum summation method based on cluster states with a two-way authentication mechanism described in this invention uses four-particle cluster states as quantum resources. These cluster states can simultaneously associate information from four participants, improving information density and protocol efficiency. In the two-way authentication phase, a first hash function value is calculated for each participant based on a preset random number and their secret identity information. Therefore, only a legitimate third party can generate the correct first optimized quantum sequence. Furthermore, due to the introduction of random numbers, the first optimized quantum sequence generated for each authentication is different, effectively preventing replay attacks. The third party verifies the user's identity by comparing the hash sequence calculated by the user; simultaneously, the user verifies the third party's identity by checking whether the third party correctly responds to its submitted sequence, ensuring the absolute authenticity of both parties' identities and eliminating impersonation at the source.

[0051] Furthermore, the security of the entire authentication process relies not only on the hash function, but more importantly, on the quantum mechanical principle based on decoy photon detection. Even if the hash function is cracked in the classical sense, an attacker cannot impersonate the decoy photon through the quantum channel. Any eavesdropper intercepting the quantum state, unaware of the basis randomly chosen by the third party for each decoy photon, will irreversibly perturb the quantum state if they use an incorrect basis for measurement, thus being detected in the bit error rate detection. This embodiment ensures that the quantum channel is not eavesdropped on during transmission by detecting bit error rates in the decoy photons, preventing man-in-the-middle interception and tampering of quantum information.

[0052] In the third-party summation phase, this invention involves each participant randomly performing a MEASURE or REFLECT operation on each particle in their stored quantum sequence, reflecting the result back to the third party. This integrates computational tasks with security monitoring. After receiving all reflected particles and the types of operations performed on each particle, the third party performs joint measurements on the reflected particles, binding local, classically verifiable measurement results with global, quantum mechanical entanglement. By statistically analyzing the bit error rate between the measurement results and the expected results, it determines whether internal or external eavesdropping has occurred, significantly improving the protocol's security. Simultaneously, users' private data remains encrypted throughout; the third party can only obtain the final sum and cannot access any individual user's input, further ensuring security. Attached Figure Description

[0053] To make the content of this invention easier to understand, the invention will be further described in detail below with reference to specific embodiments and accompanying drawings, wherein:

[0054] Figure 1 This is a flowchart illustrating the steps of the third-party quantum summation method with a two-way authentication mechanism based on cluster states provided by this invention. Detailed Implementation

[0055] The present invention will be further described below with reference to the accompanying drawings and specific embodiments, so that those skilled in the art can better understand and implement the present invention. However, the embodiments described are not intended to limit the present invention.

[0056] This invention provides a third-party quantum summation method based on clustered states with a bidirectional authentication mechanism. This method ingeniously combines the ultra-high entanglement properties of quantum clustered states with classical authentication mechanisms to construct a secure, reliable, and efficient third-party summation computation framework. The core advantage of this method lies in its combination of the security of quantum physics with the authentication of classical cryptography. It not only theoretically provides physically based security against future quantum computing attacks, but also improves the feasibility, security, and reliability of the protocol in the real world through practical design (such as the use of clustered states and authentication), providing a powerful solution for future scenarios such as secure cloud computing and privacy data aggregation.

[0057] First, the existing quantum entangled states and logic gates used in this embodiment will be introduced:

[0058] ① Forming Z-base, Formation of X-base; , ;

[0059] ② Pauli-X gate: The X gate is equivalent to the NOT gate in classical logic gates, and it can flip the bits of a qubit, that is... , Its functional expression and matrix form are respectively expressed as follows: , ;

[0060] ③The Hadamard gate, also known as the H-transform, functions as follows: Its operation on a single bit is described as follows: , ;

[0061] ④ The Bell basis is a maximally entangled state composed of two particles, which constitutes a complete orthogonal basis in the four-dimensional Hilbert space, specifically in the form of: , , , ;

[0062] ⑤ The control phase GZ gate has two input qubits: a control qubit and a target qubit. Its function is to control the phase when both the control qubit and the target qubit are in phase. When the phases of these two states are reversed by π, the corresponding matrix form is: ;

[0063] ⑥ The quantum controlled-NOT gate (or CNOT gate) has two input qubits: a control qubit and a target qubit. Its function is to control the input qubit when the control qubit is... When the target qubit remains unchanged, the control qubit remains unchanged. When the target qubit state is flipped, its corresponding matrix form is: .

[0064] Reference Figure 1 The flowchart illustrates the steps of the third-party quantum summation method based on clustered states with a bidirectional authentication mechanism, as shown in this invention. This method is applied to a quantum channel involving four participants and one third party. Each of the four participants has a private bit string and secret identity information shared with the third party. The specific steps include:

[0065] S101: A third party uses quantum operations to rewrite the cluster state of four entangled particles, obtaining multiple rewritten states; obtains the i-th particle in each rewritten state, forms the i-th initial quantum sequence, and sends it to the i-th participant; where 1≤i≤4;

[0066] The quantum operations include: CONT gate operation, bit flip, Hadamard gate or combination operation; a third party arbitrarily selects particles from the four particles of the cluster state to perform quantum operations and obtain the corresponding rewritten state;

[0067] S102: A third party calculates the first hash function value of each participant based on a preset random number and the secret identity information of each participant; using the first hash function value of each participant, the initial quantum sequence of each participant is measured and encoded to obtain the first optimized quantum sequence of each participant;

[0068] Specifically, the third party selects the corresponding measurement basis based on the values ​​in the participant's first hash function value and a preset mapping relationship; uses each measurement basis to measure each particle in the initial quantum sequence to obtain the measurement results of each particle; and maps each measurement result to a bit value based on a preset encoding rule to obtain the participant's first optimized quantum sequence.

[0069] The preset mapping relationship includes: if the value of the first hash function is 0, then the X base is selected as the measurement base; if the value of the first hash function is 1, then the Z base is selected as the measurement base.

[0070] The preset coding rules include: if the measurement result is If the value of the mapped bit is 0, then the value of the mapped bit is 0; if the measurement result is If , then the mapped bit value is 1;

[0071] S103: A third party randomly selects decoy particles and inserts them into the initial quantum sequence of each participant to obtain the target quantum sequence of each participant; the decoy particle insertion information and the target quantum sequence of each participant are sent to the corresponding participant.

[0072] The quantum state of the decoy particles is randomly in... , , or State; A third party inserts a randomly generated decoy particle into a random position in the participant's initial quantum sequence to obtain the participant's target quantum sequence;

[0073] S104: After receiving the target quantum sequence, the participants measure the target quantum sequence to obtain the decoy particle measurement results; determine whether the bit error rate between each participant's decoy particle measurement results and the decoy particle insertion information is greater than a preset error threshold.

[0074] S105: If the value is greater than the given value, then interrupt the current communication.

[0075] S106: If it is not greater than, then after the participant restores its corresponding initial quantum sequence, the second hash function value of the participant is calculated using a preset random number and secret identity information; and the second hash function value is used to measure and encode the participant's initial quantum sequence to obtain the participant's second optimized quantum sequence;

[0076] S107: A third party calculates the bit error rate between the first and second optimized quantum sequences of each participant and determines whether the bit error rate is less than a preset error threshold.

[0077] S107-1: If it is not less than, then the participant has not been authenticated;

[0078] S107-2: If it is less than, then the participant is authenticated. Until all participants are detected to be authenticated, the third party performs quantum summation on all participants.

[0079] The bit error rate between the participant's decoy particle measurement results and the decoy particle insertion information is the ratio of the number of particles with the same position but different values ​​in the decoy particle measurement results and the decoy particle insertion information to the total number of decoy particles in the participant; the bit error rate between the participant's first optimized quantum sequence and the second optimized quantum sequence is the ratio of the number of particles with the same position but different values ​​in the first optimized quantum sequence and the second optimized quantum sequence to the total number of particles in the first optimized quantum sequence.

[0080] Specifically, in the identity authentication process, this embodiment of the invention does not specify a specific algorithm for a particular hash function because the method does not utilize the one-wayness and collision-resistant security of the hash function H(x), but only uses the hash function H(x) to generate a hash that is used for each authentication. Compressed data related to (i∈{A, B, C, D}) and r, and the hash value when choosing different r. They are different. The unconditional security of this method is based on quantum mechanics principles (such as the uncertainty principle and the no-cloning theorem), not on the assumption of the computational complexity of the hash function. The hash function here is merely used as a message compression tool, mapping long inputs to fixed-length short outputs for easier subsequent processing. Even if the hash function itself is broken in classical computation, the entire method remains secure as long as the security assumption of the quantum part holds. Therefore, in practical implementation, any standard cryptographic hash function that meets the output length requirements (n bits and m bits) can be chosen, such as SHA-256 (256 bits output), SHA-512 (512 bits output), or SHA3-256. The choice of specific algorithm is an implementation-level issue and does not affect the theoretical design of the method itself.

[0081] In this embodiment, if all participants are authenticated, the third party performs a quantum summation on all participants, including:

[0082] Each participant randomly performs a MEASURE or REFLECT operation on each particle in their initial quantum sequence to obtain a reflected particle, which is then fed back to a third party.

[0083] After receiving all the reflected particles, the third party sends confirmation messages to each participant and obtains the operation type performed on each reflected particle from each participant.

[0084] For each participant, based on the type of operation they perform on each reflecting particle, corresponding security checks are performed, including:

[0085] If the participant performs the MEASURE operation on all four reflecting particles, then based on the measurement results of the MEASURE operation, the participant's private key is generated according to the preset encoding rules, and the participant's private bit string is encrypted using the private key and sent to a third party, so that the third party receives the encrypted private bit strings of all participants, performs modulo 2 sum calculation, and obtains the summation result of all participants.

[0086] If the participant performs the REFLECT operation on all four reflecting particles, external eavesdropping detection will be performed;

[0087] If the participant performs the MEASURE operation on two reflecting particles and the REFLECT operation on the other two reflecting particles, then internal eavesdropping detection is performed.

[0088] If any other situation exists besides the one described above, then skip that participant.

[0089] The MEASURE operation includes: applying a Hadamard gate operation to the particle to convert the particle from a computational basis to a superposition state; performing a Z-basis measurement on the particle in the superposition state to obtain the corresponding bit value as the measurement result of the MEASURE operation; and the REFLECT operation is to flip the particle using a universal quantum gate operation.

[0090] The external eavesdropping detection includes: a third party measuring the four reflecting particles, obtaining the corresponding measurement results, and determining whether the measurement results are the same as the quantum states of the four particles in the initial quantum sequence; if they are the same, there is no external eavesdropping; if they are not the same, communication is terminated.

[0091] The internal eavesdropping detection includes: acquiring the measurement results of the corresponding MEASURE operation for two reflecting particles performing the MEASURE operation, and using them as the first measurement result and the second measurement result; performing joint measurement on the Bell basis for two reflecting particles performing the REFLECT operation, and acquiring the Bell measurement result; determining whether the Bell measurement result, the first measurement result, and the second measurement result conform to the records in the preset truth table: if they conform, there is no internal eavesdropping detection; if they do not conform, communication is terminated.

[0092] This invention involves four participants and a semi-trusted third party, TP, who assists in calculating the modulo-2 summation of the private bit strings of the four participants. This embodiment leverages the characteristics of cluster states in quantum information to achieve an efficient fusion of data encryption and aggregation processing. Simultaneously, to prevent identity forgery and data tampering by malicious external parties, this embodiment introduces an authentication mechanism, effectively ensuring message integrity and the legitimacy of the sender. Specifically, this embodiment has two execution parts: identity authentication and third-party modulo-2 summation. In the first part, the four participants and the third-party TP undergo identity authentication to eliminate the possibility of malicious attacks before the summation protocol can be successfully executed. In the second part, TP performs modulo-2 summation based on the private bit strings generated by each participant, then verifies the security of the method and analyzes the impact of noise, finally proving the feasibility and reliability of the method.

[0093] This invention eliminates impersonation and man-in-the-middle attacks by introducing identity authentication, a key upgrade compared to many earlier quantum-safe computing methods. This invention can verify the legitimate identities of each participant and the third-party TP (Transfer Provider). This ensures that only authorized users can participate in the computation, effectively preventing malicious third parties from posing as legitimate participants to submit false data or steal results. The core security of this invention is rooted in the fundamental principles of quantum mechanics, rather than the assumption of computational complexity. Any attempt by an eavesdropper to intercept, measure, or copy the quantum carrier (e.g., measuring clustered particles) will inevitably disrupt its fragile entanglement properties. Such perturbations will be detected by legitimate participants through eavesdropping detection steps, thus ensuring the absolute protection of the privacy of the summation input value during transmission. Furthermore, each participant's private data remains encrypted throughout the entire process (whether in quantum state form or classical bit form encrypted after measurement). Only with the third-party TP, after all information is aggregated, can the final sum be decrypted, and it is impossible to trace back individual inputs.

[0094] Based on the above embodiments, this invention ingeniously combines the ultra-high entanglement characteristics of quantum cluster states with classical authentication mechanisms to construct a secure, reliable, and efficient third-party summation computation framework. The core advantage of this method lies in its combination of quantum physical security with classical cryptographic authentication, achieving a 1+1>2 effect. It not only theoretically provides physical laws-based security against future quantum computing attacks, but also improves the feasibility, security, and reliability of the protocol in the real world through practical design (such as using cluster states and authentication), providing a powerful solution for future scenarios such as secure cloud computing and privacy data aggregation. In this embodiment, the third-party quantum summation method based on cluster states with a two-way authentication mechanism provided by this invention is used for summation, including:

[0095] S201: Implementation Preparation;

[0096] S201-1: Based on the quantum state of the four-particle cluster state used in the embodiments of the present invention, rewrite it to obtain multiple rewritten states;

[0097] The quantum state used in this embodiment is represented in its basic form as follows:

[0098] ;

[0099] Where the subscripts 1, 2, 3, and 4 represent each particle in the four-particle entangled state, respectively. To better apply this method, starting from the cluster state and quantum operations, the above cluster state is rewritten to obtain the initial variation, expressed as:

[0100] ;

[0101] Adding quantum gates to the particles in the initial variation, in the following order: CNOT gate (quantum controlled NOT gate): 2 particles (control qubit) → 1 particle (target qubit); X gate: 4 particles; H gate: 2 particles; CNOT gate: 2 particles (control qubit) → 1 particle (target qubit), the resulting first variation is:

[0102] ;

[0103] Adding an X-gate to the 2 particles in the first variation yields the second variation:

[0104] ;

[0105] Adding an X-gate to the 4 particles in the first variation and adding an X-gate to the 4 particles in the second variation yields the following results:

[0106] ;

[0107] ;

[0108] Adding a CNOT gate to particles 1 and 2 in the initial variation: 2 particles → 1 particle, transforms it into the third variation, represented as:

[0109] ;

[0110] Adding a CNOT gate to particles 3 and 4 in the third variation: 3 particles → 4 particles, then adding an H gate to particle 3, and finally adding a CNOT gate again: 2 particles → 1 particle, 3 particles → 4 particles, yields a rewritten state, represented as:

[0111] ;

[0112] Other operations are similar to those described above, yielding other rewritten states for combinations of particles 1, 3, and 2, 4, represented as follows:

[0113] ;

[0114] ;

[0115] ;

[0116] Adding a CNOT gate to particles 1 and 2 in the initial variation: 2 particles → 1 particle, yields the fourth variation, expressed as:

[0117] ;

[0118] At this point, it can be seen that the cluster state of the combination of particles 1 and 4 and particles 2 and 3 in the fourth variation is the same as the cluster state of the combination of particles 1 and 2 and particles 3 and 4, so the quantum operation is also the same.

[0119] Finally, the following rewritten states can be easily obtained:

[0120] ;

[0121] S201-2: Initializing the quantum channel, participants, and third parties;

[0122] Assume the quantum channel is authenticated as a classical channel, and that there are four users: Alice, Bob, Charlie, and David. They are classical and each has a private n-bit string. , , and In this embodiment, n=8, and the private bit strings of the four participants are respectively , , and ;

[0123] Additionally, there exists a third party, TP, who must faithfully execute the protocol. With the TP's involvement, the TP performs bidirectional authentication with the four participants, and upon successful authentication, the TP calculates the modulo-2 sum of their private bit strings. Assuming Alice, Bob, and Charlie possess only finite quantum capabilities, their goal is to obtain the modulo-2 addition of their private bit strings without disclosing their identities. The TP assists them in calculating: ;

[0124] = ;

[0125] In addition, prior to implementation of the method, A, B, C, D and the third party TP also pre-share a secret identity information. (i∈{A、B、C、D}).

[0126] S202: Two-way authentication;

[0127] S202-1: TP prepares 12*n (1+δ) cluster states, each state being randomly selected from... The rewritten state is selected, where δ is a parameter that allows each participant to obtain an n-bit private key for encryption in the final summation protocol, and the particle ( () represent four particles in the cluster state, and TP takes the value of Forming the first initial quantum sequence ,Pick , and The second, third, and fourth initial quantum sequences are formed respectively. , and ;

[0128] S202-2: TP then selects a random number r and publishes it, followed by the use of the shared key. (i∈{A, B, C, D}) and a random number r are used to calculate the value of the first hash function. (i∈{A, B, C, D}), where, according to The value can be used to select the appropriate measurement basis to measure the initial quantum sequence. Particles in (i, j∈{1,2,3,4}), the preset mapping relationship of the measurement basis selected by TP is shown in Table 1;

[0129] Table 1. Preset mapping relationship of the measurement base selected by TP

[0130]

[0131] In this way, TP will obtain a new quantum sequence, namely the first optimized quantum sequence. (i∈{1,2,3,4}), the preset encoding rules for mapping measurement results to bit values ​​are shown in Table 2;

[0132] Table 2 Preset encoding rules for mapping measurement results to bit values

[0133]

[0134] S202-3: Since the authentication process is the same, this section only describes the two-way authentication between TP and Alice. TP prepares a sufficient number of decoy photons. Insert it randomly In the sequence, a new sequence is formed. That is, the target quantum sequence; these decoy photons are randomly in one of four states { , , , Each of these sequences presents a one-in-one probability. Subsequently, TP will target the quantum sequence. Send to Alice;

[0135] S202-4: If it is confirmed that Alice has received the target quantum sequence TP will inform Alice of the decoy particle's position in the sequence and the corresponding measurement basis. Referring to Table 3, to analyze the bit error rate, Alice will compare her measurement results with the information of the decoy particle reserved by TP. If the quantum bit error rate (QBER) is lower than a preset threshold, the communication process continues. Conversely, if the error rate exceeds the given threshold, the current communication is interrupted, and the protocol is re-executed.

[0136] Table 3. Correspondence between Alice's measurement results after knowing the bait's location and classical information.

[0137]

[0138] S202-5: If the protocol continues, Alice will be removed from the sequence. Remove decoy photons Recovery sequence And store it in its own quantum memory. When TP verifies the identities of Bob, Charlie, and David, each of them will eventually restore their identities. , and It is stored in her own quantum memory. Then, Alice will use the random number r published by TP and the pre-shared key... Calculate the second hash function ,in At this point, Alice will also obtain a second optimized quantum sequence. Alice then obtained the quantum sequence and Inform TP.

[0139] S202-6: Final TP comparison and The value of TP is calculated, and the error rate is determined. If the error rate is below a threshold, TP considers Alice's identity to be correct; otherwise, TP considers Alice to be fake. This allows TP to determine whether Alice's identity is correct, and conversely, Alice can also determine whether TP's identity is correct.

[0140] S203: TP and the four participants all perform the two-way identity authentication operation as shown in step S202 to complete the two-way identity authentication and eliminate the possibility of dishonest participants.

[0141] S204: Summation of third parties;

[0142] S204-1: After identity verification, TP has confirmed the correctness of the identities of the four participants. During the verification phase, each participant has separately stored the quantum sequence. , , and Alice, Bob, Charlie, and David then randomly perform either a MEASURE or REFLECT operation on each particle in the sequence. After receiving all the particles, TP sends an "ACK" message to Alice, Bob, Charlie, and David, requesting them to announce the operation they performed. Upon receiving the "ACK" message, Alice (Bob, Charlie, David) announces the location of the particle on which the MEASURE or REFLECT operation was performed via an authenticated classical channel to TP.

[0143] For the MEASURE operation, an H quantum gate is applied to each particle individually, so that each particle is calculated from the ground state ( , Transformation to superposition state ( , Then in Z-base { , In quantum computing, Z-basis measurements, also known as computational basis measurements, are the most common measurement methods and cause the quantum state to collapse to a certain value. or In this way, each quantum state will randomly collapse into , The quantum state is then recorded as the measurement result. The REFLECT operation is a general quantum gate operation, the core idea of ​​which is to flip a component (usually the phase) of the quantum state vector. In this invention, the measurement result is reflected back to a third party TP without interference.

[0144] That is, four participants are required to perform the following operations: apply an H-gate to four quantum particles, in the Z-based { , The following measurement operation is performed on these particles; random qubits (with values ​​of...) are generated. , ), to reflect particles without disturbance (REFLECT operation).

[0145] S204-2: Subsequently, TP, Alice, Bob, Charlie, and David discussed whether there was external eavesdropping or a participant attack, and they took corresponding actions to check for external eavesdropping or participant attacks, or to generate a private key. Their actions are shown in Table 4:

[0146] Table 4 shows the operations each user selected for the particles they received, and the final results.

[0147] Case Alice, Bob, Charlie, and David's actions result Case 1 MMMM Generate private key Case 2 MMRR / MRMR / MRRM / RRMM / RMMR / RMRM Internal eavesdropping Case 3 RRRR external eavesdropping Case 4 other neglect

[0148] ① Detecting participant attacks (internal eavesdropping):

[0149] In cases where two participants choose the REFLECT operation and the other two choose the MEASURE operation, such as Case 2, Alice, Bob, Charlie, David, and TP jointly detect participant attacks. For cluster states falling within Case 2, the participant choosing the MEASURE operation announces its measurement to TP. TP measures two particles belonging to the same cluster state in the Bell basis. TP uses Case 2 to verify entanglement relationships dependent on cluster states. If there are no participant attacks, all measurements should satisfy the relationships shown in Table 5 below. TP calculates the error rate based on these measurements. If the error rate exceeds a threshold, communication is interrupted and restarted.

[0150] Table 5. MEASURE measurement results and Bell joint measurement results

[0151]

[0152] In this embodiment, regarding participant attacks, taking the operation order of four users on each particle as MMRR as an example, it can be seen that if Alice and Bob's measurement results are... Then the Bell measurement results of TP for Charlie's and David's reflected qubits are as follows: or .

[0153] ② Detect external eavesdropping;

[0154] If all four participants choose the REFLECT operation, there will be no risk of internal leakage. Alice, Bob, Charlie, David, and TP will work together to detect external eavesdropping. For example, in Case 3, TP measures four reflecting particles in the cluster state and then compares the measurement results with their corresponding initial states. If there is no external eavesdropping, the measurement results and their corresponding initial states should be the same. They calculate the error rate based on this point. If the error rate exceeds the threshold, they stop communication and start over; otherwise, they continue to the next step.

[0155] S204-3: In the MEASURE operation where Alice, Bob, Charlie, and David all choose to participate, approximately n (1+δ) clustered states are involved, and the first n clustered states will be used to generate the participants' private keys. Let the n clustered states be:

[0156] ( );

[0157] Based on the encoding rules described above, when n is 8, the generated private keys are as follows: , , and ;

[0158] If Alice's (Bob, Charlie, David) measurement results are ,So ,otherwise Next, Alice (Bob, Charlie, David) will calculate... ( , , In this embodiment, =(10011011) =(10001100) =(10101110) = (10010101), then Alice (Bob, Charlie, David) will... ( , , It is sent to TP for final calculation.

[0159] S204-4: TP received , , , Then, calculate R={ };

[0160] According to the coding rules: if Alice's (Bob, Charlie, David) measurement results come from... or ,So ,otherwise Finally, TP announces the result R to all participants, thus completing the summation process.

[0161] Specifically, if Alice's (Bob, Charlie, David) measurement results belong to { },but According to the rules, Right now

[0162] ;

[0163] Specifically, if Alice's (Bob, Charlie, David) measurement results belong to { },but According to the rules, it can be seen that... ,Right now

[0164] ;

[0165] The final calculation result is R = (00111000). Finally, TP announces the result R to all participants. The correctness of the method can be verified based on the result, thus completing the summation process.

[0166] Based on the above embodiments, a security analysis is performed on the third-party quantum summation method with bidirectional authentication mechanism based on cluster states proposed in this embodiment of the invention; this embodiment will prove that the proposed third-party quantum summation method with authentication mechanism based on cluster states is secure against two threats: external attacks and participant attacks.

[0167] Regarding defense against external attacks, it has been proven during the identity authentication phase that external eavesdroppers cannot learn any information from the participants' private input.

[0168] Regarding participant attacks, it will be proven that dishonest participants, including TPs, cannot obtain any information about the inputs of other participants. The proof is as follows:

[0169] In the protocol, the TP is semi-honest, meaning the TP honestly executes the protocol and cannot collude with dishonest participants. Even if the TP allocates quantum resources and knows the measurement results, encoding rules, and... TP also does not know the key. Because the four participants who choose the MEASURE operation randomly send 0 or 1 to TP, although TP can eventually obtain R, TP cannot collude with any dishonest participants. As a result, TP cannot obtain the private input of honest participants.

[0170] In this embodiment, it is assumed that Alice is dishonest and wants to eavesdrop on Bob's results:

[0171] ①Measure-resend Attack:

[0172] Alice can intercept the particles in the initial quantum sequence that TP sends to Bob, and use the Z-basis to measure these particles, obtaining Bob's private key based on the measurement results. Alice then generates new particles in the Z-base and sends them to Bob. These particles have the same polarization as the measurement, but this attack will be detected during the authentication phase.

[0173] ②Collective Attack:

[0174] If Alice launches a collective attack, she only does so if she chooses the MEASURE operation. In this case, if Bob, Charlie, and David all choose the MEASURE operation, Alice attempts to obtain Bob's key using auxiliary qubits, i.e., entangle his auxiliary quantum state with the original quantum system and try to extract useful information from the auxiliary quantum state; otherwise, Alice must pass TP's check. Alice performs the Ue operation on the second optimized quantum sequence that TP sent to Bob in Step 5:

[0175] ;

[0176] ;

[0177] The final result shows that Alice can evade eavesdropping detection, but at the same time she cannot obtain Bob's measurement results, so the collective attack by dishonest participants is invalid for the protocol.

[0178] The third-party quantum summation method based on cluster states with a two-way authentication mechanism described in this invention uses four-particle cluster states as quantum resources. These cluster states can simultaneously associate information from four participants, improving information density and protocol efficiency. In the two-way authentication phase, a first hash function value is calculated for each participant based on a preset random number and their secret identity information. Therefore, only a legitimate third party can generate the correct first optimized quantum sequence. Furthermore, due to the introduction of random numbers, the first optimized quantum sequence generated for each authentication is different, effectively preventing replay attacks. The third party verifies the user's identity by comparing the hash sequence calculated by the user; simultaneously, the user verifies the third party's identity by checking whether the third party correctly responds to its submitted sequence, ensuring the absolute authenticity of both parties' identities and eliminating impersonation at the source. Furthermore, the security of the entire authentication process relies not only on the hash function, but more importantly, on the quantum mechanical principle based on decoy photon detection. Even if the hash function is cracked in the classical sense, an attacker cannot impersonate the decoy photon through the quantum channel. Any eavesdropper intercepting the quantum state, unaware of the basis randomly chosen by the third party for each decoy photon, will irreversibly perturb the quantum state if they use an incorrect basis for measurement, thus being detected in the bit error rate detection. This embodiment ensures that the quantum channel is not eavesdropped on during transmission by detecting bit error rates in the decoy photons, preventing man-in-the-middle interception and tampering of quantum information. In the third-party summation phase, this invention involves each participant randomly performing a MEASURE or REFLECT operation on each particle in their stored quantum sequence, reflecting the result back to the third party. This integrates computational tasks with security monitoring. After receiving all reflected particles and the types of operations performed on each particle, the third party performs joint measurements on the reflected particles, binding local, classically verifiable measurement results with global, quantum mechanical entanglement. By statistically analyzing the bit error rate between the measurement results and the expected results, it determines whether internal or external eavesdropping has occurred, significantly improving the protocol's security. Simultaneously, users' private data remains encrypted throughout; the third party can only obtain the final sum and cannot access any individual user's input, further ensuring security.

[0179] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0180] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0181] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0182] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0183] Obviously, the above embodiments are merely illustrative examples for clear explanation and are not intended to limit the implementation. Those skilled in the art will recognize that other variations or modifications can be made based on the above description. It is neither necessary nor possible to exhaustively list all possible implementations here. However, obvious variations or modifications derived therefrom are still within the scope of protection of this invention.

Claims

1. A third-party quantum summation method based on cluster states with a two-way authentication mechanism, characterized in that, This is applied to a quantum channel involving four participants and one third party, where each participant has a private bit string and secret identity information shared with the third party, including: A third party uses quantum operations to rewrite the cluster state of four entangled particles, obtaining multiple rewritten states; the i-th particle in each rewritten state is obtained, forming the i-th initial quantum sequence, which is sent to the i-th participant; where 1≤i≤4; A third party calculates the first hash function value for each participant based on a preset random number and the secret identity information of each participant; using the first hash function value of each participant, the initial quantum sequence of each participant is measured and encoded to obtain the first optimized quantum sequence of each participant. A third party randomly selects decoy particles and inserts them into the initial quantum sequence of each participant to obtain the target quantum sequence of each participant; the decoy particle insertion information and the target quantum sequence of each participant are then sent to the corresponding participant. After receiving the target quantum sequence, participants measure the target quantum sequence to obtain the decoy particle measurement results; they then determine whether the bit error rate between each participant's decoy particle measurement results and the decoy particle insertion information exceeds a preset error threshold. If the value is greater than the given value, the current communication will be interrupted. If it is not greater than, then after the participant reconstructs its corresponding initial quantum sequence, the second hash function value of the participant is calculated using a preset random number and secret identity information; and the second hash function value is used to measure and encode the initial quantum sequence reconstructed by the participant to obtain the participant's second optimized quantum sequence. A third party calculates the bit error rate between the first and second optimized quantum sequences of each participant and determines whether the bit error rate is less than a preset error threshold. If the value is not less than the minimum, then the participant has not been verified. If the value is less than 1, the participant is authenticated. This continues until all participants are detected to be authenticated, at which point the third party performs a quantum summation on all participants.

2. The third-party quantum summation method with bidirectional authentication mechanism based on cluster states according to claim 1, characterized in that, A third party performs quantum summation on all participants, including: Each participant randomly performs a MEASURE or REFLECT operation on each particle in their initial quantum sequence to obtain a reflected particle, which is then fed back to a third party. After receiving all the reflected particles, the third party sends confirmation messages to each participant and obtains the operation type performed on each reflected particle from each participant. For each participant, based on the type of operation they perform on each reflecting particle, corresponding security checks are performed, including: If the participant performs the MEASURE operation on all four reflecting particles, then based on the measurement results of the MEASURE operation, the participant's private key is generated according to the preset encoding rules, and the participant's private bit string is encrypted using the private key and sent to a third party, so that the third party can receive the encrypted private bit strings of all participants, perform modulo 2 sum calculation, and obtain the summation result of all participants. If the participant performs the REFLECT operation on all four reflective particles, then the participant will be subject to external eavesdropping detection. If the participant performs the MEASURE operation on two reflecting particles and the REFLECT operation on the other two reflecting particles, then internal eavesdropping detection will be performed on the participant. If any other situation exists besides the one described above, then skip that participant.

3. The third-party quantum summation method with bidirectional authentication mechanism based on cluster states according to claim 2, characterized in that, The MEASURE operation includes: applying a Hadamard gate operation to the particle to convert the particle from a computational basis to a superposition state; performing a Z-basis measurement on the particle in the superposition state to obtain the corresponding bit value as the measurement result of the MEASURE operation; and the REFLECT operation is to flip the particle using a universal quantum gate operation.

4. The third-party quantum summation method with bidirectional authentication mechanism based on cluster states according to claim 2, characterized in that, The external eavesdropping detection of the participant includes: A third party measures the four reflecting particles of the participant, obtains the corresponding measurement results, and determines whether the measurement results are the same as the quantum states of the four particles in the initial quantum sequence: If they are the same, then there is no external eavesdropping; If they are different, communication is terminated.

5. The third-party quantum summation method with bidirectional authentication mechanism based on cluster states according to claim 2, characterized in that, The internal eavesdropping detection of the participant includes: For the two reflecting particles that perform the MEASURE operation in this participant, obtain the corresponding MEASURE operation measurement results as the first measurement result and the second measurement result; For the two reflecting particles that perform the REFLECT operation in this participant, a joint measurement is performed under the Bell basis to obtain the Bell measurement results; Determine whether the Bell measurement result, the first measurement result, and the second measurement result conform to the records in the preset truth table: If the conditions are met, then there is no internal eavesdropping detection. If the conditions are not met, communication will be terminated.

6. The third-party quantum summation method with bidirectional authentication mechanism based on cluster states according to claim 1, characterized in that, A third party used quantum operations to rewrite the cluster state of four entangled particles, obtaining multiple rewritten states, including: A third party arbitrarily selects a particle from the four particles in the cluster state to perform quantum operations and obtain the corresponding rewritten state; The quantum operations include: CONT gate operations, bit flipping, Hadamard gate operations, or combinations thereof.

7. The third-party quantum summation method based on cluster states with a two-way authentication mechanism according to claim 1, characterized in that, Using the first hash function value of each participant, the initial quantum sequence of each participant is measured and encoded to obtain the first optimized quantum sequence of each participant, including: The third party selects the corresponding measurement basis based on the values ​​in the participants' first hash function values ​​and a preset mapping relationship; Each particle in the initial quantum sequence is measured using various measurement bases to obtain the measurement results for each particle; Based on the preset encoding rules, each measurement result is mapped to a bit value to obtain the participant's first optimized quantum sequence; The preset mapping relationship includes: if the value of the first hash function is 0, then the X base is selected as the measurement base; if the value of the first hash function is 1, then the Z base is selected as the measurement base. The preset coding rules include: if the measurement result is If the value of the mapped bit is 0, then the value of the mapped bit is 0; if the measurement result is If the mapped bit value is 1, then the value of the mapped bit is 1.

8. The third-party quantum summation method with bidirectional authentication mechanism based on cluster states according to claim 1, characterized in that, A third party randomly selects decoy particles and inserts them into the initial quantum sequences of each participant to obtain the target quantum sequences of each participant, including: A third party inserts a randomly generated decoy particle into a random position in the participant's initial quantum sequence to obtain the participant's target quantum sequence. The quantum state of the decoy particles is randomly in... , , or state.

9. The third-party quantum summation method with bidirectional authentication mechanism based on cluster states according to claim 1, characterized in that, After receiving the target quantum sequence, the participants measure the target quantum sequence to obtain the decoy particle measurement results, including: based on the decoy particle insertion information, the participants measure each decoy particle in the target quantum sequence to obtain the bit value corresponding to each decoy particle, and the decoy particle measurement results of the target quantum sequence are formed.

10. The third-party quantum summation method with bidirectional authentication mechanism based on cluster states according to claim 1, characterized in that, The bit error rate between the participant's decoy particle measurement result and the decoy particle insertion information is the ratio of the number of particles with the same position but different values ​​in the decoy particle measurement result and the decoy particle insertion information to the total number of decoy particles in the participant; the bit error rate between the participant's first optimized quantum sequence and the second optimized quantum sequence is the ratio of the number of particles with the same position but different values ​​in the first optimized quantum sequence and the second optimized quantum sequence to the total number of particles in the first optimized quantum sequence.

Citation Information

Patent Citations

  • Flexible privacy comparison protocol based on five-particle cluster state

    CN105721428A

  • Quantum identity authentication method and application method of quantum identity authentication method in quantum key distribution process

    CN107493168A