Security enhancement method and device based on image transformation, electronic equipment and storage medium
By employing a security enhancement method based on representation transformation, the vulnerability window problem of quantum key distribution systems is solved, achieving full-link security coverage and performance uniformity in quantum communication systems. This method offers strong dynamic defense capabilities while reducing system complexity and cost.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-18
- Publication Date
- 2026-04-07
AI Technical Summary
Existing quantum key distribution systems have vulnerable windows for attack in practical applications, and traditional protection methods have inherent defects such as rigid security strategies, disconnect between security enhancement and system performance, and passive defense mechanisms.
A security enhancement method based on representation transformation is adopted. By initializing and evaluating the stability of the quantum channel, quantum state encoding and fuzzing of the transmitter representation are performed to generate a secure original key. A secondary representation transformation is then performed on the quantum state representing the key. Combined with an account-key separation architecture, ciphertext and decryption parameters are stored to establish a complete audit trail mechanism.
It achieves full-link security coverage for quantum communication systems, has strong dynamic defense capabilities, and perfectly balances system performance and security, reducing complexity and cost, and is able to cope with known and unknown attack methods.
Smart Images

Figure CN121396457B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information security technology, and in particular to security enhancement methods, devices, electronic devices, and storage media based on appearance transformation. Background Technology
[0002] Quantum key distribution (QKD), as an important application of quantum information science, relies on fundamental principles of quantum mechanics for its security, such as the Heisenberg uncertainty principle and the no-cloning theorem. However, despite QKD's theoretically unconditionally secure key distribution, vulnerability windows still exist at the sender and receiver ends of practical systems. Traditional protection methods often employ static, passive defense strategies, which suffer from inherent flaws such as rigid security strategies, a disconnect between security enhancement and system performance, and passive defense mechanisms. Summary of the Invention
[0003] To address the aforementioned technical problems, this invention provides a security enhancement method based on appearance transformation, employing the following technical solution, including the following steps:
[0004] Initialize and assess the stability of the quantum channel;
[0005] Quantum state encoding and fuzzy representation at the transmitting end;
[0006] Quantum state transmission and receiver recovery are performed to securely transmit the ambiguous state to the receiver and recover the original coded state using synchronized transformation parameters;
[0007] Generate a secure original key shared by both the sender and receiver, and perform quantum state recoding for static storage encryption;
[0008] A secondary, independent representational transformation is performed on the quantum state representing the key, and then it is converted into ciphertext to achieve secure static storage of the key locally at the receiving end.
[0009] An architecture that separates ciphertext from encryption is used to store ciphertext and decryption parameters, and a complete audit trail mechanism is established.
[0010] Preferably, the steps of initializing and evaluating the stability of the quantum channel specifically include:
[0011] Verify the legitimacy of the identities of both the sender and receiver, and jointly determine the quantum state representation system used in the session;
[0012] To detect the stability of quantum channels and assess their transmission quality;
[0013] Perform private random number seed synchronization to establish a synchronization starting point for the random sequence required to generate dynamic representation transformation, ensuring that the sending and receiving ends generate the same transformation parameters.
[0014] Preferably, the steps of quantum state encoding and transmitting end appearance ambiguity specifically include:
[0015] According to the QKD protocol, classical key bits are encoded into the physical properties of the quantum carrier to generate a standard initial quantum encoded state;
[0016] The dynamic representation transformation at the transmitting end involves applying a random unitary transformation to the initial coded state, changing its representation under the common basis vectors, and thus achieving representation ambiguity.
[0017] Perform secure synchronization of transformation parameters, and securely inform the receiving end of the index of the currently used transformation parameters to ensure that the receiving end can perform the correct inverse transformation.
[0018] Preferably, the steps of performing quantum state transmission and receiver recovery, securely transmitting the fuzzy state to the receiver, and recovering the original coded state using synchronized transformation parameters specifically include:
[0019] Disguised quantum states Physical transmission via quantum channels;
[0020] Apply the inverse transform of the transmitter's transform to the received ambiguous state to recover the original coded state of the transmitter;
[0021] An evaluation is performed before the recovered state is fed into the measurement module.
[0022] Preferably, the step of generating a secure original key shared by both the sender and receiver, and performing quantum state recoding for static storage encryption, specifically includes:
[0023] The recovered quantum state is measured, and the effective bits for generating the key are selected through open discussion;
[0024] The algorithm corrects for differences in bit strings between the two parties caused by channel noise and potential eavesdropping, compresses the information possessed by the eavesdropper, and generates a shared original key. ;
[0025] The original key in classic form Remap back to the quantum state.
[0026] Preferably, the step of performing a secondary, independent representational transformation on the quantum state representing the key and converting it into ciphertext to achieve secure static storage of the key locally at the receiving end specifically includes:
[0027] Applying a unitary transformation to the recoded quantum state creates an independent layer of encryption for static storage;
[0028] The encrypted quantum information is deterministically converted into classical bits, i.e., ciphertext, for digital storage.
[0029] Classical bits obtained from a series of deterministic measurements Combine the original keys in order to form the final encrypted ciphertext. .
[0030] Preferably, the steps of using an account-secret separation architecture to store ciphertext and decryption parameters, and establishing a complete audit trail mechanism, specifically include:
[0031] The encrypted ciphertext and the transformation parameters required for decryption are physically separated and stored separately.
[0032] Perform storage security and integrity verification;
[0033] Perform audit logging and key lifecycle management.
[0034] To address the aforementioned technical problems, the present invention also provides a security enhancement device based on appearance transformation, which employs the following technical solution, including:
[0035] The evaluation module is used for initializing and evaluating the stability of the quantum channel;
[0036] The appearance fuzzing module is used for quantum state encoding and sending-end appearance fuzzing;
[0037] The recovery module is used for quantum state transmission and receiver recovery, securely transmitting the ambiguous state to the receiver and recovering the original coded state using synchronized transformation parameters;
[0038] The generation module is used to generate a secure original key shared by both the sender and receiver, and to perform quantum state recoding for static storage encryption;
[0039] The representation transformation module is used to perform secondary and independent representation transformations on the quantum state representing the key and convert it into ciphertext, thereby achieving secure static storage of the key locally at the receiving end.
[0040] The storage module is used to store ciphertext and decryption parameters using an account-secret separation architecture, and to establish a complete audit trail mechanism.
[0041] To address the aforementioned technical problems, the present invention also provides an electronic device that employs the technical solution described below, comprising a memory and a processor. The memory stores computer-readable instructions, and the processor, when executing the computer-readable instructions, implements the steps of the aforementioned security enhancement method based on representation transformation.
[0042] To address the aforementioned technical problems, the present invention also provides a computer-readable storage medium, which employs the technical solution described below. The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the aforementioned security enhancement method based on representation transformation.
[0043] Compared with the prior art, the present invention has the following main advantages:
[0044] (1) By introducing a dynamic representation transformation mechanism controlled by private random numbers, the static defense mode of traditional quantum encryption systems has been completely changed; the U of the transport layer Tx U of the transformation and storage layer Store The transformation is updated in real time according to the pseudo-random sequence, which makes the manifestation of the quantum state continuously and rapidly change during channel transmission and static storage, forming a non-stationary defense environment. This dynamic characteristic makes it impossible for attackers to learn the system's behavior pattern through long-term observation. Even if they can intercept the quantum state or access the storage medium, their attack behavior will become ineffective because they cannot obtain the transformation parameters in real time. This elevates the system security from traditional passive protection to a new level of active deterrence.
[0045] (2) By deeply integrating the security enhancement mechanism into the core physical process of quantum state preparation and measurement, a perfect unity of security and system performance is achieved; by reconfiguring the same hardware platform, transmission fuzzing and storage encryption functions are realized simultaneously, avoiding the additional insertion loss and timing delay introduced by traditional external encryption modules; not only maintaining the original high key generation rate and low bit error rate performance of the system, but also significantly reducing the complexity and manufacturing cost of the system through hardware reuse, effectively solving the contradiction between security enhancement and performance degradation in traditional schemes, and laying a solid foundation for the large-scale application of high-security quantum communication technology;
[0046] (3) The constructed dual protection system achieves full-link security coverage from the transmission process to static storage; the dynamic appearance transformation of the transmission layer effectively resists transmission layer threats such as channel eavesdropping and man-in-the-middle attacks, while the secondary encryption and "account-secret separation" mechanism of the storage layer specifically defends against physical attacks and data theft against the receiving end; even if the transmission layer protection is breached, the attacker only obtains the data that has been encrypted again by the storage layer, forming a deep security redundancy; this end-to-end protection architecture can deal with both known and unknown attack methods at the same time, providing security for quantum communication systems. Attached Figure Description
[0047] To more clearly illustrate the solutions in this invention, the accompanying drawings used in the description of the embodiments of this invention will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0048] Figure 1 This is a flowchart of an embodiment of the security enhancement method based on representation transformation of the present invention;
[0049] Figure 2 This is a schematic diagram of a structure of an embodiment of the security enhancement device based on representation transformation of the present invention;
[0050] Figure 3 This is a schematic diagram of another embodiment of the security enhancement device based on appearance transformation of the present invention;
[0051] Figure 4 This is a schematic diagram of internal module information interaction of another embodiment of the security enhancement device based on appearance transformation of the present invention;
[0052] Figure 5 This is a schematic diagram of the structure of an embodiment of the electronic device of the present invention. Detailed Implementation
[0053] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains; the terminology used herein in the specification is for the purpose of describing particular embodiments only and is not intended to limit the invention; the terms "comprising" and "having," and any variations thereof, in the specification, claims, and foregoing drawings are intended to cover non-exclusive inclusion. The terms "first," "second," etc., in the specification, claims, or foregoing drawings are used to distinguish different objects and not to describe a particular order.
[0054] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0055] To enable those skilled in the art to better understand the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings.
[0056] It should be noted that the security enhancement method based on appearance transformation provided in the embodiments of the present invention is generally executed by a server / terminal device, and correspondingly, the security enhancement device based on appearance transformation is generally set in the server / terminal device.
[0057] It should be understood that the number of terminal devices, networks, and servers is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be used.
[0058] Example 1
[0059] Please refer to Figure 1 The flowchart illustrates an embodiment of the security enhancement method based on representation transformation according to the present invention. The security enhancement method based on representation transformation includes the following steps:
[0060] Step S1: Initialize and evaluate the stability of the quantum channel.
[0061] In this embodiment, the electronic device (e.g., a server / terminal device) running on the representation transformation security enhancement method can receive representation transformation security enhancement requests via wired or wireless connection. It should be noted that the aforementioned wireless connection methods may include, but are not limited to, 3G / 4G / 5G connections, WiFi connections, Bluetooth connections, WiMAX connections, Zigbee connections, UWB (ultra wideband) connections, and other currently known or future-developed wireless connection methods.
[0062] In this embodiment, step S1, initializing and evaluating the stability of the quantum channel, may specifically include the following steps:
[0063] S11, confirm the legitimacy of the identities of the sending and receiving ends and jointly determine the quantum state representation system used in the session.
[0064] The secure transmission platform implements two-way authentication based on classical cryptography (such as TLS / SSL protocols and digital certificates) to establish an encrypted classical channel. While the platform does not handle quantum signals, it provides fundamental security services for the entire system, including authentication, channel encryption, and parameter synchronization.
[0065] The parameter negotiation protocol process involves the sending and receiving ends exchanging and confirming the quantum degrees of freedom to be used in this session via a secure channel, such as the polarization basis vectors of photons (e.g., horizontal / vertical polarization). or diagonal basis (or phase basis vector). In practice, this can be accomplished by sending a preset negotiation command.
[0066] Both the sending and receiving devices initialize and store consistent basis vector definitions to ensure consistency in subsequent encoding and measurement.
[0067] The purpose of step S11 is to verify the legitimacy of the identities of both communicating parties and jointly determine the quantum state representation system (i.e., wave function basis vector) used in this session, so as to provide a unified basis for subsequent encoding and transformation.
[0068] S12 detects the stability of the quantum channel and evaluates the transmission quality of the quantum channel.
[0069] The probe state sequence is transmitted by the transmitter (Alice) through a conventional QKD transmission module, which sends a series of known and stable quantum states (such as photons with fixed polarization) to the channel as probe signals.
[0070] Receiver measurement and statistics: The receiver (Bob) uses a single-photon detector (SPD) and a polarization beam splitter (PBS) to measure the received probe state and record the count rate and bit error rate.
[0071] The transmission quality of a quantum channel can be evaluated by calculating parameters such as channel transmission efficiency and qubit error rate.
[0072] The formula for calculating channel transmission loss is: ,in, : Represents channel transmission efficiency, with a value ranging from 0 to 1. The number of photons successfully detected by Bob at the receiver. The total number of photons sent by the Alice terminal.
[0073] The formula for calculating channel transmission loss is used to quantify the degree of attenuation of photons by the channel and is one of the basic indicators for evaluating channel availability.
[0074] The formula for calculating the quantum bit error rate (QBER) is: ,in, The quantum bit error rate reflects the impact of channel noise and potential eavesdropping. The number of erroneous bits found after comparison between the two parties. : The total number of probe states used for comparison.
[0075] The quantum bit error rate (QBER) is a core parameter for determining channel security. If the QBER is lower than the protocol security threshold (such as 11% for the BB84 protocol), the channel is considered usable.
[0076] The purpose of step S12 is to evaluate the transmission quality of the quantum channel, including loss, noise, and bit error rate, and determine whether it meets the threshold requirements for secure key distribution.
[0077] S13, perform private random number seed synchronization, establish a synchronization starting point for the random sequence required to generate dynamic representation transformation, and ensure that the sending and receiving ends generate the same transformation parameters.
[0078] A true random number generator (TRNG) or a quantum random number generator (QRNG) generates a high-entropy initial seed at the Alice end. .
[0079] The secure key encapsulation mechanism utilizes the secure classical channel established in step S11 and employs a symmetric encryption algorithm (such as AES-GCM) to encapsulate the seed key. The encrypted data is then transmitted to Bob at the receiving end.
[0080] Pseudo-random number generator (PRNG) initialization is performed, with both parties using the same cryptographically secure PRNG algorithm (such as DRBG based on hash functions) to... As input, initialize the local shared unitary matrix pool to prepare for the subsequent generation of transformation sequences.
[0081] Step S13 is crucial for achieving error-free recovery.
[0082] The purpose of step S1 is to establish a security foundation for the entire quantum communication session, ensure that the channel quality meets the requirements of subsequent key distribution, and negotiate the basic parameters required for subsequent encryption and decryption.
[0083] Step S2 involves quantum state encoding and blurring the appearance of the transmitting end.
[0084] In this embodiment, step S2, performing quantum state encoding and transmitting end appearance ambiguity, may specifically include the following steps:
[0085] S21. According to the QKD protocol, the classical key bits are encoded into the physical properties of the quantum carrier to generate a standard initial quantum encoded state.
[0086] Single-photon source preparation involves generating laser pulses using a pulsed laser diode, which are then attenuated to the average number of photons by a high-intensity attenuator. At the level of [the target], a single-photon source can be approximately obtained.
[0087] Random bitstreams are generated in real time using a field-programmable gate array (FPGA) or a dedicated random number chip to generate random binary sequences. , as the original key bits.
[0088] Physical modulation and coding are performed, and according to the BB84 protocol, one of two non-orthogonal bases (such as the Z-based base) is randomly selected. Represents 0, Represents 1; X base: Represents 0, (Representative 1) An electro-optic modulator (EOM) or integrated optical phase modulator, under FPGA control, precisely modulates the polarization or phase of each photon to generate an initial quantum state. .For example:
[0089] If Z-base is chosen, bit 0 modulation is Bit 1 modulated as .
[0090] If the X base is chosen, bit 0 modulation is as follows: Bit 1 modulated as .
[0091] S22, Dynamic Representation Transformation at the Transmitter: Apply a random unitary transformation to the initial coded state to change its representation under the common basis vectors, thereby achieving representation ambiguity.
[0092] A programmable representation transformation module is employed, which includes a high-speed liquid crystal waveplate (LCVR) or an electrically controlled birefringent crystal. When different voltages are applied, the high-speed liquid crystal waveplate (LCVR) or the electrically controlled birefringent crystal will produce a controllable optical phase delay, thereby changing the polarization state of the photon (i.e., realizing a unitary transformation).
[0093] Transformation parameter generation and mapping are performed using a locally shared unitary matrix pool of pseudo-random number generators (PRNGs) based on the current time series index. Generate a set of transformation parameters (such as rotation angle) and phase These parameters are converted into the output voltage of a high-precision digital-to-analog converter (DAC). It is applied to a high-speed liquid crystal waveplate (LCVR).
[0094] A shared unitary matrix pool refers to a pseudo-random number generator stored locally on both sides and driven by a master private random number seed. This generator produces a series of unitary transformation parameters, forming a transmission transformation sequence. Synchronization is maintained through a secure transmission platform, ensuring that both sides use the same transformation parameters U at the same time. Tx and its inverse U † Tx .
[0095] The physical implementation of unitary transformation is as follows: LCVR under voltage... Under the drive, it is equivalent to the incident photon state A specific unitary operator was applied. Its mathematical representation is:
[0096] The formula for transforming the appearance at the sending end is: ,in, The initial encoded quantum state is a two-dimensional complex vector. Indexed by time Definite A unitary matrix that satisfies ,in This indicates the conjugate transpose. It is the identity matrix. : Transformed transmission ambiguity state.
[0097] The appearance transformation formula at the sending end is the core encryption operation. It maps a fixed, easily interpretable encoded state to an appearance that is randomized and can only be known by those who possess it. The state, which can only be deciphered by one party, provides proactive, physical-layer-based encryption for the transmission process.
[0098] S23, perform safe synchronization of transformation parameters, and safely inform the receiving end of the index of the currently used transformation parameters to ensure that the receiving end can perform the correct inverse transformation.
[0099] The system extracts and encapsulates parameter indexes, but instead of transmitting complete matrix parameters, it transmits the state index of the PRNG. (A shorter integer). This index is related to... One-to-one correspondence. The index is encapsulated into a data packet after being added with a Message Authentication Code (MAC).
[0100] The encrypted and authenticated index data packets are transmitted to Bob's end in real time via a secure classic channel and a secure transmission platform (or a similar secure socket connection) established in step S1.
[0101] The receiving end parameters are recovered, Bob's security platform decrypts and verifies the data packet, and extracts... The parameters are input into the local synchronous PRNG to reconstruct the same transformation parameters as those on the Alice end, thus obtaining the inverse transformation matrix. .
[0102] The purpose of step S23 is to prevent parameters from being stolen during the synchronization process.
[0103] The purpose of step S2 is to use quantum state encoding and the appearance fuzzing at the transmitting end as the first layer of protection. Before the quantum state enters the public channel, its external appearance is dynamically disguised, so that eavesdroppers cannot directly obtain effective information, thereby protecting the security of the transmission process.
[0104] Step S3 involves quantum state transmission and receiver recovery, securely transmitting the fuzzy state to the receiver, and recovering the original coded state using synchronized transformation parameters.
[0105] In this embodiment, step S3, which involves quantum state transmission and receiver recovery, securely transmitting the fuzzy state to the receiver and recovering the original encoded state using synchronized transformation parameters, may specifically include the following steps:
[0106] S31, the disguised quantum state Physical transmission via quantum channels.
[0107] Commercial single-mode fiber optic cables or free-space optical telescope systems are used as the transmission medium. The channel itself does not provide additional security guarantees.
[0108] Optical pulse timing control is performed using a high-precision clock synchronization system to ensure that the photon detection windows at the transmitting and receiving ends are aligned, thereby reducing information leakage in the time dimension.
[0109] Eavesdropping tolerance design ensures that, because the transmission is in an ambiguous state, any intercept-resend attack or detector blinding attack carried out in the channel will be detected because the attacker is unaware of the eavesdropping process. This introduces a high error rate, which was subsequently discovered in QBER analysis.
[0110] S32, apply the inverse transform of the transmitter's transform to the received ambiguous state to recover the original coded state of the transmitter.
[0111] Symmetrical to the transmitting end, the receiving end's representation conversion module also employs a high-speed liquid crystal waveplate (LCVR). Before the photons arrive, the image conversion has been synchronized... Configure the corresponding inverse transformation voltage.
[0112] The receiver representation transformation module is symmetrical and compatible with the transmitter representation transformation module in terms of hardware configuration, and is located after the quantum channel and before the traditional QKD receiver module. Based on the transformation parameter index synchronized through the secure transmission platform, this module obtains the corresponding U from its local shared unitary matrix pool. Tx And configure its inverse unitary transform U † Tx When the state is ambiguous Upon arrival, the module applies U † Tx To restore the original This is used for measurement by subsequent traditional QKD receiver modules.
[0113] The procedure for applying the inverse unitary transform is as follows: when When the LCVR is applied through the Bob terminal, the device applies a transformation. According to unitarity The operation result is:
[0114] The formula for the inverse representation transformation at the receiving end is: ,in, : The inverse matrix (which is also its conjugate transpose) of . The recovered quantum state is theoretically the same as... Exactly the same.
[0115] Step S32 is the decryption process. It utilizes the invertibility of unitary transformation to restore the information losslessly to the legitimate receiver, while for unsuspecting eavesdroppers... It is incomprehensible.
[0116] Perform real-time dynamic reconfiguration and change parameters With each or batch of photons updated, the LCVR's driving circuitry needs to have a microsecond-level response speed to enable real-time dynamic switching of the transformation.
[0117] S33, an evaluation is performed before the recovered state is sent to the measurement module.
[0118] In this embodiment, the measurement module is a quantum state measurement module. This module is responsible for converting the encrypted quantum information into classical ciphertext. When... During measurement, the eigenvalues of this quantum state are used consistently. Because... It's U Store The transformed state, when measured under its eigenvalues, is a classical bit that is completely different from the original information. This is called the encryption string, which is the ciphertext of the original key bits.
[0119] Sampling measurements and comparisons are performed, and a small portion of the recovered states are periodically extracted (e.g., every 1000 photons). Measurements are performed using a calibrated measurement base.
[0120] The bit error rate is calculated in real time. The measurement results are compared with the known test bit sequence sent by Alice through a secure classical channel to calculate the instantaneous recovery bit error rate. .
[0121] Implement feedback control, if An abnormally high value may indicate a synchronization error, device drift, or active attack. It may trigger an alarm or automatically re-execute part of the initialization process in step S1.
[0122] The purpose of step S33 is to ensure that the recovery process is error-free and to provide feedback on the overall system performance.
[0123] The purpose of step S3 is to prepare for the subsequent standard QKD measurement procedure.
[0124] Step S4: Generate a secure original key shared by both the sender and receiver, and perform quantum state recoding for static storage encryption.
[0125] In this embodiment, step S4, generating a secure original key shared by both the sender and receiver, and performing quantum state recoding for static storage encryption, may specifically include the following steps:
[0126] S41, the recovered quantum state is measured, and the effective bits for generating the key are selected through open discussion.
[0127] To perform conventional QKD receiver measurements, Bob used a polarization beam splitter (PBS) and a single-photon detector (SPD), randomly selecting Z-based or X-based pairs. By performing projection measurements, classical bits are obtained. .
[0128] A basis vector public comparison is performed. Alice and Bob publicly disclose their respective coded and measured basis vectors for each photon via a classical authentication channel, but do not disclose the bit values. Both parties retain the bit sequences whose basis vector choices are consistent.
[0129] A quantum bit error rate (QBER) estimate is performed, estimating the channel QBER from the partially public comparison bits to assess whether eavesdropping is present. If the QBER is within a safe range, proceed.
[0130] The purpose of step S41 is to measure the recovered quantum state and select the effective bits for generating the key through open discussion.
[0131] S42, corrects the differences in bit strings between the two parties caused by channel noise and potential eavesdropping, compresses the information possessed by the eavesdropper, and generates a shared original key. .
[0132] For information coordination (error correction), either an efficient cascade protocol or low-density parity-check (LDPC) code is employed. Both parties exchange parity information via a classical channel to locate and correct erroneous bits, ultimately obtaining a consistent bit string. This process may leak a small amount of information. For the eavesdropper.
[0133] To enhance privacy and eliminate potential eavesdroppers. Bit information is processed using a collision-resistant hash function (such as SHA-3) to convert longer bits into hash values. Compress into a shorter final original key In mathematics, from Bit Extract Bit ,in For security parameters. This ensures that eavesdroppers... The amount of information is exponentially close to zero.
[0134] Key verification is performed; both parties calculate and compare the keys. A short hash value (such as using a message authentication code) ensures that the reconciled keys are completely consistent.
[0135] S43, the original key in classic form Remap back to the quantum state.
[0136] A post-processing quantum coding module is employed, which reuses or is independent of Alice's traditional coding hardware (electro-optic modulator). This module follows a preset, fixed coding rule (e.g., bit 0 corresponds to...). Bit 1 corresponds to ),Will Each classic bit Re-prepared into the corresponding quantum state .
[0137] The post-processing quantum encoding module is consistent with the traditional QKD emission module; it is a quantum state preparation and encoding module. (The original key...) After generation, this module will Each bit in this binary string is re-encoded into a new quantum state according to a preset mapping rule. For example, it controls the modulator at the Bob end, reassembling bit 0 into... The state, bit 1, is reconstructed as state.
[0138] Timing and synchronization control are performed, with the encoding process controlled by the FPGA to ensure that the quantum state generation rate matches the processing capability of the subsequent storage and encryption module.
[0139] The process of generating a sequence of quantum states involves outputting a series of recoded quantum states. ,in yes The length of the quantum state. At this point, the quantum state is merely another physical carrier of the key and has not yet been encrypted.
[0140] The purpose of step S43 is to prepare for subsequent storage encryption based on quantum representation.
[0141] Step S5 involves performing a secondary, independent representational transformation on the quantum state representing the key and converting it into ciphertext, thereby achieving secure static storage of the key locally at the receiving end.
[0142] In this embodiment, step S5, which involves performing a secondary, independent representational transformation on the quantum state representing the key and converting it into ciphertext to achieve secure static storage of the key locally at the receiving end, may specifically include the following steps:
[0143] S51 applies a unitary transformation to the recoded quantum state, creating an independent layer of encryption for static storage.
[0144] Bob runs a separate pseudo-random number generator (PRNG) locally, with its seed... With transport layer Completely independent and never disclosed. This PRNG generates and stores encrypted sequences, outputting transformation parameters (such as...). ).
[0145] The post-processing representation transformation module uses time-division multiplexing of the LCVR hardware at the transmission end. In storage encryption mode, the LCVR... Parameters generated Configured to apply unitary transformation .
[0146] The post-processing representation transformation module refers to the physical execution unit for storage encryption. In practical deployments, to reduce cost and complexity, it can be the same physical hardware as the representation transformation module at the transmission end. Through time-division multiplexing, it switches to storage encryption mode after completing the transmission recovery task. This module uses a storage encryption sequence provided by a private unitary matrix pool, independent of the transmission process, to process the re-encoded quantum state. Apply a completely new unitary transformation U Store Generate encrypted storage state U Store with U Tx Completely unrelated, and its lifecycle is limited to this storage operation.
[0147] Each recoded state It is transformed into an encrypted storage state by sequentially passing through LCVR. The storage encryption transformation formula is: ,in, : The first digit in the stored encrypted sequence Parameters A definite unitary matrix, The encrypted quantum state, its physical manifestation (such as polarization direction) is different from the original key bits. The association was disturb.
[0148] A second layer of channel-independent encryption is introduced. Even if an attacker physically breaches Bob's end and gains access to the quantum signal before storage, the attacker will not be able to detect it. Furthermore, the key cannot be obtained.
[0149] S52 deterministically converts the encrypted quantum information into classical bits, i.e., ciphertext, for digital storage.
[0150] The measurement base of the measurement device (such as a polarization beam splitter (PBS) or a single-photon detector (SPD)) is no longer random, but is forced to switch to... The eigenbase of the defined target representation. For example, if If it is a 45-degree rotation, then the measuring base is fixed. .
[0151] because yes The transformed state, in Measurements taken under the eigenvalue basis will deterministically collapse to a certain eigenstate and output the corresponding classical eigenvalue. (Usually mapped to 0 or 1). This process is non-random.
[0152] The output electrical pulses of the SPD are precisely recorded by the time-to-digital converter (TDC) and time-gated circuitry, and converted into digital bits. .
[0153] S53, classical bits obtained from a series of deterministic measurements Combine the original keys in order to form the final encrypted ciphertext. .
[0154] Microprocessors (such as ARM cores) or FPGAs according to Original index order The measurement results Concatenate into a complete binary string .
[0155] For ciphertext Add a frame header, length information, and cyclic redundancy check (CRC) code, and encapsulate it into a data block to ensure integrity during storage and retrieval.
[0156] In generating ciphertext Then, immediately and completely clear it from memory. , , And all intermediate process data, only the final ciphertext is retained. and parameters used for decryption (or generate) seeds ).
[0157] Step S6: Use an account-secret separation architecture to store ciphertext and decryption parameters, and establish a complete audit trail mechanism.
[0158] In this embodiment, step S6, which uses an account-password separation architecture to store ciphertext and decryption parameters and establishes a complete audit trail mechanism, may specifically include the following steps:
[0159] S61 physically separates and stores the encrypted ciphertext from the transformation parameters required for decryption.
[0160] The encapsulated ciphertext data block Write to encrypted solid-state drives (SEDs) or dedicated secure storage chips. These devices typically feature hardware-level AES encryption and access control.
[0161] A storage transformation sequence will be generated. The key parameter—that is, the PRNG seed. Alternatively, the core parameter index—after secondary encryption (such as using a device-unique key)—is stored within a secure area of a Hardware Security Module (HSM) or Trusted Platform Module (TPM). The HSM provides physical protection against tampering and side-channel attacks.
[0162] The system has separate access permission policies, requiring different authentication credentials to access the encrypted storage device and the decryption parameter storage device, thus achieving management isolation.
[0163] The purpose of step S61 is to significantly increase the difficulty for an attacker to obtain both simultaneously.
[0164] S62 performs storage security and integrity verification.
[0165] Integrity verification is performed by periodically reading ciphertext data blocks using a CRC code or cryptographic hash value appended during storage (such as SHA-256). And recalculate the check value for comparison.
[0166] Perform parameter validity testing in a secure environment using parameters stored in the HSM. This involves attempting to decrypt a piece of test ciphertext to verify whether the decryption process is normal and indirectly verify the integrity of the parameters.
[0167] Perform physical environment monitoring by deploying physical intrusion detection sensors (such as chassis opening and closing detection and light sensors) around the storage devices. Any unauthorized physical access will trigger an alarm and lock the device.
[0168] The purpose of step S62 is to periodically or before use verify whether the stored ciphertext and parameters have been tampered with or damaged.
[0169] S63 performs audit log recording and key lifecycle management.
[0170] All critical operations (such as key generation time, encryption operator ID, storage location, and access attempts) are timestamped and digitally signed, and recorded in an append-only security log, which is also stored in an encrypted manner.
[0171] When the key is needed, the system must retrieve the ciphertext from both the SED and HSM. and parameters Decryption and restoration are completed in memory. Clear it from memory immediately after use. Securely erase the ciphertext in the SED when the key expires or needs to be destroyed. and parameters in HSM The destruction operation is recorded in the audit log.
[0172] Audit logs can be used to generate security reports, meet regulatory compliance requirements such as information security level protection and confidentiality assessment, and provide a basis for post-event analysis of security incidents.
[0173] The purpose of step S63 is to record the entire process of key generation, encryption, storage, use and destruction in an irrefutable manner, so as to achieve traceable security management.
[0174] The beneficial effects of implementing this embodiment are:
[0175] (1) By introducing a dynamic representation transformation mechanism controlled by private random numbers, the static defense mode of traditional quantum encryption systems has been completely changed; the U of the transport layer Tx U of the transformation and storage layer Store The transformation is updated in real time according to the pseudo-random sequence, which makes the manifestation of the quantum state continuously and rapidly change during channel transmission and static storage, forming a non-stationary defense environment. This dynamic characteristic makes it impossible for attackers to learn the system's behavior pattern through long-term observation. Even if they can intercept the quantum state or access the storage medium, their attack behavior will become ineffective because they cannot obtain the transformation parameters in real time. This elevates the system security from traditional passive protection to a new level of active deterrence.
[0176] (2) By deeply integrating the security enhancement mechanism into the core physical process of quantum state preparation and measurement, a perfect unity of security and system performance is achieved; by reconfiguring the same hardware platform, transmission fuzzing and storage encryption functions are realized simultaneously, avoiding the additional insertion loss and timing delay introduced by traditional external encryption modules; not only maintaining the original high key generation rate and low bit error rate performance of the system, but also significantly reducing the complexity and manufacturing cost of the system through hardware reuse, effectively solving the contradiction between security enhancement and performance degradation in traditional schemes, and laying a solid foundation for the large-scale application of high-security quantum communication technology;
[0177] (3) The constructed dual protection system achieves full-link security coverage from the transmission process to static storage; the dynamic appearance transformation of the transmission layer effectively resists transmission layer threats such as channel eavesdropping and man-in-the-middle attacks, while the secondary encryption and "account-secret separation" mechanism of the storage layer specifically defends against physical attacks and data theft against the receiving end; even if the transmission layer protection is breached, the attacker only obtains the data that has been encrypted again by the storage layer, forming a deep security redundancy; this end-to-end protection architecture can deal with both known and unknown attack methods at the same time, providing security for quantum communication systems.
[0178] This invention can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This invention can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This invention can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0179] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by instructing related hardware through computer-readable instructions. These computer-readable instructions can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. The aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, optical disk, or read-only memory (ROM), or random access memory (RAM).
[0180] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0181] Example 2
[0182] Further reference Figure 2 As a response to the above Figure 1 The present invention provides an embodiment of a security enhancement device based on representation transformation, which is similar to the method shown. Figure 1 Corresponding to the method embodiments shown, this device can be specifically applied to various electronic devices.
[0183] like Figure 2 As shown, the security enhancement device 70 based on appearance transformation described in this embodiment includes: an evaluation module 71, an appearance blurring module 72, a recovery module 73, a generation module 74, an appearance transformation module 75, and a storage module 76. Wherein:
[0184] Evaluation module 71 is used to initialize and evaluate the stability of the quantum channel;
[0185] The appearance fuzzing module 72 is used for quantum state encoding and sending-end appearance fuzzing;
[0186] The recovery module 73 is used for quantum state transmission and receiver recovery, securely transmitting the ambiguous state to the receiver and recovering the original coded state using synchronized transformation parameters;
[0187] The generation module 74 is used to generate a secure original key shared by both the sender and receiver, and to perform quantum state recoding for static storage encryption;
[0188] The representation transformation module 75 is used to perform a secondary and independent representation transformation on the quantum state representing the key and convert it into ciphertext to achieve secure static storage of the key at the receiving end.
[0189] Storage module 76 is used to store ciphertext and decryption parameters using an account-secret separation architecture and to establish a complete audit trail mechanism.
[0190] The beneficial effects of implementing this embodiment are: by constructing a dynamic defense system, the proactive security protection capability can be significantly improved; by achieving the unity of security enhancement and system performance, the practicality level can be greatly improved; and an end-to-end security protection system is established to effectively deal with a variety of attack threats.
[0191] Example 3
[0192] Further reference Figure 3 , Figure 3 This is a schematic diagram of another embodiment of the security enhancement device based on representation transformation of the present invention. As a reference to the above... Figure 1 The present invention provides an embodiment of a security enhancement device based on representation transformation, which is similar to the method shown. Figure 1 Corresponding to the method embodiments shown, this device can be specifically applied to various electronic devices.
[0193] like Figure 3 As shown, the security enhancement device based on appearance transformation described in this embodiment includes: a quantum transmission subsystem, a post-processing encryption subsystem, and a transmission encryption subsystem.
[0194] The quantum transport subsystem is the physical basis for realizing quantum key distribution. It is responsible for the preparation, transmission and preliminary measurement of quantum states, and its core modules all adopt QKD hardware devices.
[0195] The quantum transmission subsystem specifically includes a traditional QKD transmitting module, a quantum channel, and a traditional QKD receiving module.
[0196] Traditional QKD emission modules primarily handle quantum state generation and encoding. This is achieved by attenuating the intensity of a series of highly coherent laser pulses to the single-photon level and applying a specific voltage according to the underlying QKD protocol (such as BB84). This precisely modulates a physical degree of freedom (such as polarization or phase) of the photon, thereby encoding each classical bit into a specific physical dimension of the quantum carrier and generating an initial quantum encoded state. .
[0197] A quantum channel is the physical medium for transmitting quantum states; it is a standard single-mode fiber optic channel or a free-space optical channel. This channel is responsible for carrying fuzzy-processed quantum states. It transmits it from the sending end (Alice) to the receiving end (Bob).
[0198] Traditional QKD receiver modules are located at the receiving end and are responsible for processing the recovered original quantum state. Projection measurements are performed. Taking a polarization coding system as an example, its core is a polarization beam splitter, which guides incident photons to different physical paths according to their polarization states, detects and records the arriving photon events, and converts the measurement results of the quantum state into classical electrical pulse signals, providing raw data for subsequent key comparison and encryption.
[0199] The encrypted transmission subsystem is the core of the first layer of protection (transmission security). It is responsible for dynamically disguising quantum states during transmission. Specifically, it includes a transmitter appearance transformation module, a receiver appearance transformation module, a secure transmission platform, and a shared unitary matrix pool.
[0200] The core of the transmitter's representation transformation module is a programmable polarization transformation device (e.g., a high-speed liquid crystal waveplate), located after the traditional QKD transmitter module and before the quantum channel. This module receives real-time instructions (specifically, a digitized voltage control sequence) from a shared unitary matrix pool. Based on these instructions, its drive circuitry generates a high-precision analog voltage, which is applied to the transformation device to control each passing initial quantum encoded state. Apply a specific unitary transformation U Tx This generates a transmission ambiguity state.
[0201] The receiver representation transformation module is symmetrical and compatible with the transmitter module in terms of hardware configuration, located after the quantum channel and before the traditional QKD receiver module. Based on the transformation parameter index synchronized through the secure transmission platform, this module obtains the corresponding U from its local shared unitary matrix pool. Tx And configure its inverse unitary transform U † Tx When the state is ambiguous Upon arrival, the module applies U † Tx To restore the original This is used for measurement by subsequent traditional QKD receiver modules.
[0202] The secure transmission platform is a secure communication and trust platform based on classical cryptography. While it does not handle quantum signals, it provides fundamental security services for the entire system, including authentication, channel encryption, and parameter synchronization.
[0203] The shared unitary matrix pool is a pseudo-random number generator stored locally on both sides and driven by a master private random number seed. This generator produces a series of unitary transformation parameters, forming a transmission transformation sequence. Synchronization is maintained through a secure transmission platform, ensuring that both sides use the same transformation parameters U at the same time. Tx and its inverse U † Tx .
[0204] The post-processing encryption subsystem is the core of the second layer of protection (storage security). It is specifically designed to defend against attacks on the receiver's local side and ensure the static storage security of the final key. Specifically, it includes a post-processing quantum encoding module, a post-processing representation transformation module, a quantum state measurement module, a private unitary matrix pool, and a secure storage medium.
[0205] The post-processing quantum encoding module is consistent with the traditional QKD emission module; it is a quantum state preparation and encoding module. In the original key K... raw After generation, this module will K raw Each bit in this binary string is re-encoded into a new quantum state according to a preset mapping rule. For example, it controls the modulator at the Bob end, reassembling bit 0 into... The state, bit 1, is reconstructed as state.
[0206] The post-processing representation transformation module is the physical execution unit for storage encryption. In actual deployments, to reduce cost and complexity, it is usually the same physical hardware as the representation transformation module at the transmission end. Using time-division multiplexing, it switches to storage encryption mode after completing the transmission recovery task. This module processes the re-encoded quantum state using a storage encryption sequence provided by a private unitary matrix pool, independent of the transmission process. Apply a completely new unitary transformation U Store Generate encrypted storage state U Store with U Tx Completely unrelated, and its lifecycle is limited to this storage operation.
[0207] The quantum state measurement module is responsible for converting the encrypted quantum information into classical ciphertext. When... During measurement, the system consistently uses the eigenvalues of this quantum state for measurement. Because... It's U Store The transformed state, when measured under its eigenvalues, is a classical bit that is completely different from the original information. This is called the encryption string, which is the ciphertext of the original key bits.
[0208] The private unitary matrix pool is a pseudo-random number generator that runs only locally at the receiving end (Bob's end) to generate independent, stored encrypted sequences. These sequences drive the post-processing representation transformation module to generate U... Store Parameters, and these parameters are never transmitted over the network.
[0209] The secure storage medium is a highly secure storage combination employing an account-ciphertext separation architecture. It is used to store the final encrypted ciphertext output by the fuzzy quantum measurement module and the U value generated by the private unitary matrix pool.Store Decrypt the parameters.
[0210] The three subsystems mentioned above ensure the accurate, continuous, and automated execution of the entire encryption process through unified scheduling and coordination.
[0211] Figure 4 This is a schematic diagram of internal module information interaction of another embodiment of the security enhancement device based on appearance transformation of the present invention. For example... Figure 4 As shown, this device is based on the principle of quantum mechanical representation transformation, supported by a secure transmission platform, and uses secure storage media as a tool to construct a full-link, proactive security enhancement system from dynamic transmission of quantum information to static storage of classical keys. It solves the problems of rigidity in traditional communication security strategies, disconnect between security enhancement and system performance, and passive defense mechanisms.
[0212] It should be noted that this device relies on high-performance computing servers, large-capacity storage devices, and high-precision electronically controlled waveplates in terms of hardware.
[0213] The beneficial effects of implementing this embodiment are: by constructing a dynamic defense system, the proactive security protection capability can be significantly improved; by achieving the unity of security enhancement and system performance, the practicality level can be greatly improved; and an end-to-end security protection system is established to effectively deal with a variety of attack threats.
[0214] Example 4
[0215] To address the aforementioned technical problems, embodiments of the present invention also provide an electronic device. Please refer to [link / reference needed]. Figure 5 , Figure 5 This is a basic structural block diagram of the electronic device in this embodiment.
[0216] The aforementioned electronic device 8 includes a memory 81, a processor 82, and a network interface 83 that are interconnected via a system bus. It should be noted that only the electronic device 8 with components 81, 82, and 83 is shown in the figure; however, it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively. Those skilled in the art will understand that the electronic device described here is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.
[0217] The aforementioned electronic devices can be computing devices such as desktop computers, laptops, handheld computers, and cloud servers. These electronic devices can interact with users via keyboards, mice, remote controls, touchpads, or voice-activated devices.
[0218] The aforementioned memory 81 includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the aforementioned memory 81 may be an internal storage unit of the aforementioned electronic device 8, such as the hard disk or memory of the electronic device 8. In other embodiments, the aforementioned memory 81 may also be an external storage device of the aforementioned electronic device 8, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the electronic device 8. Of course, the aforementioned memory 81 may also include both internal storage units and external storage devices of the aforementioned electronic device 8. In this embodiment, the aforementioned memory 81 is typically used to store the operating system and various application software installed on the aforementioned electronic device 8, such as computer-readable instructions based on the appearance transformation security enhancement method. In addition, the aforementioned memory 81 can also be used to temporarily store various types of data that have been output or will be output.
[0219] In some embodiments, the processor 82 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip. The processor 82 is typically used to control the overall operation of the electronic device 8. In this embodiment, the processor 82 is used to execute computer-readable instructions stored in the memory 81 or to process data, for example, to execute the computer-readable instructions based on the appearance transformation security enhancement method.
[0220] The network interface 83 may include a wireless network interface or a wired network interface, which is typically used to establish a communication connection between the electronic device 8 and other electronic devices.
[0221] The beneficial effects of implementing this embodiment are: by constructing a dynamic defense system, the proactive security protection capability can be significantly improved; by achieving the unity of security enhancement and system performance, the practicality level can be greatly improved; and an end-to-end security protection system is established to effectively deal with a variety of attack threats.
[0222] Example 5
[0223] The present invention also provides another embodiment, namely, providing a computer-readable storage medium storing computer-readable instructions that can be executed by at least one processor to cause the at least one processor to perform the steps of the appearance transformation-based security enhancement method as described above.
[0224] The beneficial effects of implementing this embodiment are: by constructing a dynamic defense system, the proactive security protection capability can be significantly improved; by achieving the unity of security enhancement and system performance, the practicality level can be greatly improved; and an end-to-end security protection system is established to effectively deal with a variety of attack threats.
[0225] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods of the various embodiments of the present invention.
[0226] Obviously, the embodiments described above are merely some embodiments of the present invention, not all embodiments. The accompanying drawings show preferred embodiments of the present invention, but do not limit the patent scope of the present invention. The present invention can be implemented in many different forms; rather, these embodiments are provided to provide a more thorough and complete understanding of the disclosure of the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing specific embodiments, or make equivalent substitutions for some of the technical features. Any equivalent structures made using the content of this specification and drawings, directly or indirectly applied to other related technical fields, are similarly within the patent protection scope of this invention.
Claims
1. A security enhancement method based on representation transformation, characterized in that, Includes the following steps: Initialize and assess the stability of the quantum channel; Quantum state encoding and transmitting end appearance fuzzification are performed, where appearance fuzzification refers to changing the appearance of the quantum state through unitary transformation; Quantum state transmission and receiver recovery are performed. The fuzzy state is securely transmitted to the receiver, and the original coded state is recovered using synchronized transformation parameters. The fuzzy state refers to the quantum state after unitary transformation. The synchronized transformation parameters refer to the transformation index synchronized by the transmitter and receiver through a secure channel to generate the same unitary transformation. The recovery of the original coded state is achieved by applying an inverse unitary transformation. Generate a secure original key shared by both the sender and receiver, and perform quantum state recoding for static storage encryption; A secondary, independent representational transformation is performed on the quantum state representing the key, and then it is converted into ciphertext to achieve secure static storage of the key locally at the receiving end. An architecture that separates ciphertext from encryption is used to store ciphertext and decryption parameters, and a complete audit trail mechanism is established.
2. The security enhancement method based on representation transformation according to claim 1, characterized in that, The steps for initializing and evaluating the stability of the quantum channel specifically include: Verify the legitimacy of the identities of both the sender and receiver, and jointly determine the quantum state representation system used in the session; To detect the stability of quantum channels and assess their transmission quality; Perform private random number seed synchronization to establish a synchronization starting point for the random sequence required to generate dynamic representation transformation, ensuring that the sending and receiving ends generate the same transformation parameters.
3. The security enhancement method based on representation transformation according to claim 1, characterized in that, The steps of quantum state encoding and transmitting end appearance blurring specifically include: According to the QKD protocol, classical key bits are encoded into the physical properties of the quantum carrier to generate a standard initial quantum encoded state; The dynamic representation transformation at the transmitting end involves applying a random unitary transformation to the initial coded state, changing its representation under the common basis vectors, and thus achieving representation ambiguity. Perform secure synchronization of transformation parameters, and securely inform the receiving end of the index of the currently used transformation parameters to ensure that the receiving end can perform the correct inverse transformation.
4. The security enhancement method based on representation transformation according to claim 1, characterized in that, The steps of performing quantum state transmission and receiver recovery, securely transmitting the ambiguity state to the receiver, and recovering the original coded state using synchronized transformation parameters, specifically include: Disguised quantum states Physical transmission via quantum channels; Apply the inverse transform of the transmitter's transform to the received ambiguous state to recover the original coded state of the transmitter; An evaluation is performed before the recovered state is fed into the measurement module.
5. The security enhancement method based on representation transformation according to claim 1, characterized in that, The steps of generating a secure original key shared by both the sender and receiver, and performing quantum state recoding for static storage encryption, specifically include: The recovered quantum state is measured, and the effective bits for generating the key are selected through open discussion; The algorithm corrects for differences in bit strings between the two parties caused by channel noise and potential eavesdropping, compresses the information possessed by the eavesdropper, and generates a shared original key. ; The original key in classic form Remap back to the quantum state.
6. The security enhancement method based on representation transformation according to claim 1, characterized in that, The steps of performing a secondary, independent representational transformation on the quantum state representing the key and converting it into ciphertext to achieve secure static storage of the key locally at the receiving end specifically include: Applying a unitary transformation to the recoded quantum state creates an independent layer of encryption for static storage; The encrypted quantum information is deterministically converted into classical bits, i.e., ciphertext, for digital storage. Classical bits obtained from a series of deterministic measurements Combine the original keys in order to form the final encrypted ciphertext. .
7. The security enhancement method based on representation transformation according to any one of claims 1 to 6, characterized in that, The steps of using an account-secret separation architecture to store ciphertext and decryption parameters, and establishing a complete audit trail mechanism, specifically include: The encrypted ciphertext and the transformation parameters required for decryption are physically separated and stored separately. Perform storage security and integrity verification; Perform audit logging and key lifecycle management.
8. A security enhancement device based on appearance transformation, characterized in that, include: The evaluation module is used for initializing and evaluating the stability of the quantum channel; The appearance fuzzing module is used for quantum state encoding and transmitting end appearance fuzzing, where appearance fuzzing refers to changing the appearance of the quantum state through unitary transformation; The recovery module is used for quantum state transmission and receiver recovery. It securely transmits the fuzzy state to the receiver and recovers the original coded state using synchronized transformation parameters. The fuzzy state refers to the quantum state after unitary transformation. The synchronized transformation parameters refer to the transformation index synchronized by the transmitter and receiver through a secure channel to generate the same unitary transformation. The recovery of the original coded state is achieved by applying an inverse unitary transformation. The generation module is used to generate a secure original key shared by both the sender and receiver, and to perform quantum state recoding for static storage encryption; The representation transformation module is used to perform secondary and independent representation transformations on the quantum state representing the key and convert it into ciphertext, thereby achieving secure static storage of the key locally at the receiving end. The storage module is used to store ciphertext and decryption parameters using an account-secret separation architecture, and to establish a complete audit trail mechanism.
9. An electronic device, characterized in that, The method includes a memory and a processor, wherein the memory stores computer-readable instructions, and the processor executes the computer-readable instructions to implement the steps of the representation-based security enhancement method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the security enhancement method based on representation transformation as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Identity authentication method, device and system for quantum key distribution process
CN106470101A
Quantum key distribution method and device, electronic equipment and storage medium
CN117394990A