A quantum identity authentication and key update method and system
By introducing the 'subsequence-parent sequence' definition and theorem into quantum key distribution and quantum identity authentication, and combining it with multi-step identity authentication and key update methods, the noise interference problem is solved, reliable communication under noisy conditions is realized, and the security and practicality of quantum communication are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
- Filing Date
- 2025-11-11
- Publication Date
- 2026-07-21
AI Technical Summary
Existing quantum key distribution and quantum identity authentication fusion schemes are susceptible to noise interference, affecting communication security and efficiency.
By adopting the definition and theorem based on 'sub-sequence-parent-sequence' and combining QIA and QKD protocols, a multi-step authentication and key update method is used to tolerate channel noise and achieve reliable authentication and key distribution.
Reliable quantum identity authentication and key updates were achieved under noisy conditions, improving the security and efficiency of communication and providing support for the practical application of quantum communication technology.
Smart Images

Figure CN121485918B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of quantum identity authentication and quantum key distribution technology, and more specifically, to a quantum identity authentication and key update method and system. Background Technology
[0002] The security of classical cryptography relies on the computational complexity of mathematically difficult problems. However, the rapid development of quantum computing theory and technology, coupled with the powerful parallel computing capabilities of quantum computers, has provided new avenues for breaking classical cryptographic algorithms, posing a serious challenge to the security of classical cryptography, exemplified by RSA. To address the threat posed by quantum computing to classical cryptography, researchers began studying new cryptographic algorithms capable of resisting quantum attacks, giving rise to quantum cryptography. Quantum cryptography is a new type of cryptography that combines classical cryptography theory with the fundamental principles of quantum mechanics. Unlike classical cryptographic systems, quantum cryptographic systems use quantum states as information carriers and are designed according to physical laws. Their security is guaranteed by the fundamental properties of quantum mechanics and is independent of the attacker's computational power. In 1969, S. Wiesner proposed using quantum physical properties to encrypt information, laying the foundation for quantum cryptography. In 1979, CH Bennett and G. Brassard formally proposed the concept of quantum cryptography, propelling the theoretical development of this field. In 1984, the first quantum key distribution protocol, BB84, was developed. This protocol possesses theoretical unconditional security, fundamentally guaranteeing the security of key distribution. With the introduction of the BB84 protocol, quantum key distribution protocols have received high attention and have made great progress in both theoretical research and engineering implementation. It has now become one of the fastest-growing and most practical quantum information technologies.
[0003] Quantum Key Distribution (QKD) protocols require both communicating parties to establish an interference-resistant channel; otherwise, they are vulnerable to man-in-the-middle attacks, and the identities of both parties can be easily impersonated, thus jeopardizing protocol security. Therefore, incorporating a reliable authentication mechanism into the QKD protocol is crucial for ensuring its security.
[0004] Quantum Identity Authentication (QIA) is more secure than classical authentication protocols in certain scenarios and can resist attacks from quantum computing power. Combining QIA with QKD allows for simultaneous key distribution and authentication in a single communication, reducing the number of communications and improving efficiency. However, there is no universal solution to the problem of updating and expanding QIA authentication keys. In 2019, Liu Bin et al. proposed a QIA protocol based on GV95-QKD, opening a new path for quantum identity verification in orthogonal state-coded QKD systems. However, this protocol has security vulnerabilities; attackers can launch man-in-the-middle attacks after both parties have completed the protocol. In 2020, Fen Hou et al. randomly mixed the GV95-QIA and GV95-QKD processes, proposing an authenticated QKD protocol based on the GV95 protocol, which enhances security. However, various quantum identity authentication schemes, such as the fusion of GV95-QIA and GV95-QKD, face a practical problem: susceptibility to noise interference, thus limiting their practical applications. Therefore, the design of quantum identity authentication and its key expansion methods under noisy conditions is a hot topic and a challenge in the design of practical quantum identity authentication schemes. Summary of the Invention
[0005] The present invention aims to provide a quantum identity authentication and key update method and system to solve the problem that the current QKD and QIA fusion scheme is susceptible to noise interference.
[0006] In a first aspect, the present invention provides a quantum identity authentication and key update method, which is applied to identity authentication before error correction and includes the following steps: (1) Alice and Bob, the two communicating parties, perform the QKD process, retain the signals with the same basis vectors, and record the encoding information J of the same basis vectors; based on the position information of the same basis vectors, Alice discards the bits corresponding to the different positions in the random binary sequence R, and the remaining bits form the encoding sequence R. ^ Bob decodes the measurement results corresponding to the same basis vector positions into the original key sequence M according to the QKD encoding rules. In the absence of noise and eavesdropping, R... ^ Same as M; (2) Alice uses QIA's authentication key K AB The first m digits of K 1m Find the match between J and K. 1m The same sub-columns are numbered, and then a random number is sent to Bob; (3) Bob sends the corresponding bit value of the sub-column of the number in M to Alice according to the number; (4) Alice compares the received bit value with R ^If the error rate of the comparison of the corresponding bit values exceeds the threshold, the authentication key K is discarded. AB If Bob fails to complete Alice's initial authentication, the agreement will be terminated. (5) Similarly, using the methods from steps (2) to (4), Bob, based on K AB Bit K from the (m+1)th bit to the 2mth bit 2m Alice undergoes her first identity verification. (6) If Alice passes Bob's first identity verification in step (5), then Alice will proceed according to K. AB Bit K from the (2m+1)th bit to the 3mth bit 3m Perform a second identity verification on Bob; if this verification also passes, Bob will use K... AB Bit K from the (3m+1)th bit to the 4mth bit 4m Alice undergoes a second identity verification; if all four verifications (two rounds) are successful, the identity verification process is complete; if any one of the four verifications fails, the verification process is terminated.
[0007] Furthermore, the quantum identity authentication and key update method further includes: (7) Alice and Bob continue to perform QKD until the quantum key negotiation is completed; Alice and Bob verify their authentication key K based on the key generated by the quantum key negotiation. AB To expand and update.
[0008] Furthermore, during the authentication process, regardless of whether authentication is successful, the used key should be discarded.
[0009] In a second aspect, the present invention provides a quantum identity authentication and key update system, comprising Alice and Bob, wherein Alice and Bob are used to perform the quantum identity authentication and key update method provided in the first aspect.
[0010] Thirdly, this invention provides a quantum identity authentication and key update method, which is applied to identity authentication after error correction, and includes the following steps: (1) Alice and Bob, the two communicating parties, perform the QKD process, retain the signals with the same basis vectors, record the encoding information J of the same basis vectors, and according to the position information of the same basis vectors, Alice discards the bits corresponding to the different positions in the random binary sequence R, and the remaining bits form the encoding sequence R. ^ Bob decodes the measurement results corresponding to the same basis vector positions into the original key sequence M according to the QKD encoding rules; Alice and Bob use R ^Error correction is performed on M so that Alice and Bob each obtain two identical binary sequences R after the error correction. ^* and M*; (2) Alice uses QIA's authentication key K AB The first m digits of K 1m Find the match between J and K. 1m The same sub-columns are numbered, and then a random number is sent to Bob; (3) Bob sends the corresponding bit value of the sub-column of the number in M to Alice according to the number; (4) Alice compares the received bit value with R ^* If the bit value at the corresponding position is incorrect, the authentication key K is discarded. AB If Bob fails to complete Alice's initial authentication, the agreement will be terminated. (5) Similarly, using the methods from steps (2) to (4), Bob, based on K AB Bit K from the (m+1)th bit to the 2mth bit 2m Alice undergoes her first identity verification. (6) If Alice passes Bob's first identity verification in step (5), then Alice will proceed according to K. AB Bit K from the (2m+1)th bit to the 3mth bit 3m Perform a second identity verification on Bob; if this verification also passes, Bob will use K... AB Bit K from the (3m+1)th bit to the 4mth bit 4m Alice undergoes a second identity verification; if all four verifications (two rounds) are successful, the identity verification process is complete; if any one of the four verifications fails, the verification process is terminated.
[0011] Furthermore, the quantum identity authentication and key update method further includes: (7) Alice and Bob continue to perform QKD until the quantum key negotiation is completed; Alice and Bob verify their authentication key K based on the key generated by the quantum key negotiation. AB To expand and update.
[0012] Furthermore, during the authentication process, regardless of whether authentication is successful, the used key should be discarded.
[0013] Fourthly, the present invention provides a quantum identity authentication and key update system, comprising Alice and Bob, wherein Alice and Bob are used to perform the quantum identity authentication and key update method provided in the third aspect.
[0014] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are: This invention, based on the definition and theorem of "subsequence-parent sequence," provides a quantum identity authentication and key update method. This method can perform QKD functionality while conducting mutual identity authentication and update the authentication key using the key generated by QKD. This invention solves the problem of previous QKD and QIA fusion schemes being susceptible to noise interference, providing support for the application of quantum identity authentication in complex communication scenarios, and has significant theoretical and practical application value. Attached Figure Description
[0015] Figure 1 The flowchart illustrates a quantum identity authentication and key update method applied to pre-error correction identity authentication, as provided in an embodiment of the present invention.
[0016] Figure 2 The flowchart illustrates a quantum identity authentication and key update method applied to post-error correction identity authentication, as provided in an embodiment of the present invention. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0018] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.
[0019] This invention, based on the definition and theorem of "subsequence-parent sequence," provides a quantum identity authentication and key update method and system. Its implementation principle involves organically integrating QIA and QKD protocols using the same encoding method (usually two sets of conjugate basis encodings), and proposes two schemes for different application scenarios. During the QIA process, the sender Alice and the receiver Bob pre-share an n×m-bit classical authentication key K. AB(Here, n≥4), Alice generates a random binary sequence R and encodes a quantum state based on this sequence. In the fusion scheme, Alice and Bob achieve reliable identity authentication, key distribution, and identity authentication key update through multiple steps by performing a QKD process and retaining relevant information. The generalized method for quantum identity authentication and key update proposed in this invention can tolerate channel noise and is more practical than existing schemes, providing new ideas and methods for the further development and application of quantum communication technology.
[0020] The specific definitions and theorems of the above "sub-column - parent column" are as follows: Definition: Let S be an n-bit string. If m bits are randomly selected from the n bits of S in sequence to form an m-bit string s, then S is called the parent string of s, and s is the child string of S.
[0021] Theorem: Given a random n-bit string S and a random m-bit string s, where m can be expressed as a function of n, m = M(n), for sufficiently large n, when the limit of M(n) / n is less than 1 / 2, the probability that s is a substring of S is 1. This theorem can be understood as follows: for two random bit strings S and s, when the length of s is much less than half that of S, at least one substring in S can be found that is identical to s.
[0022] This invention provides a quantum identity authentication and key update method, proposing the following two schemes based on different needs and scenarios: Option 1: This method is applied to authentication before error correction, such as... Figure 1 As shown, it includes the following steps: (1) Alice and Bob, the two communicating parties, perform the QKD process, retain the signals with the same basis vectors, and record the encoding information J of the same basis vectors; based on the position information of the same basis vectors, Alice discards the bits corresponding to the different positions in the random binary sequence R, and the remaining bits form the encoding sequence R. ^ Bob decodes the measurement results corresponding to the same basis vector positions into the original key sequence M (J and M are both binary sequences) according to the QKD encoding rules. In the absence of noise and eavesdropping, R... ^ It should be the same as M.
[0023] (2) Alice uses QIA's authentication key K AB The first m digits of K 1m Find the match between J and K. 1m The same sub-columns are numbered, and then a number is randomly selected and sent to Bob.
[0024] (3) Bob sends the corresponding bit value of the sub-column of the number to Alice in M according to the number.
[0025] (4) Alice compares the received bit value with R ^ If the error rate of the comparison of the corresponding bit values exceeds the threshold, the authentication key K is discarded. AB If Bob fails to complete the first authentication with Alice, the agreement will be terminated; otherwise, Bob will pass Alice's first authentication.
[0026] (5) Similarly, using the methods from steps (2) to (4), Bob, based on K AB Bit K from the (m+1)th bit to the 2mth bit 2m Alice undergoes her first identity verification.
[0027] (6) If Alice passes Bob's first identity verification in step (5), then Alice will proceed according to K. AB Bit K from the (2m+1)th bit to the 3mth bit 3m Perform a second identity verification on Bob; if this verification also passes, Bob will use K... AB Bit K from the (3m+1)th bit to the 4mth bit 4m Alice undergoes a second authentication process. If all four authentication attempts (two rounds total) are successful, the authentication is complete. If any one of the four authentication attempts fails, the authentication process terminates. It is important to note that all keys used during the authentication process, regardless of whether authentication is successful, should be discarded.
[0028] (7) Further, Alice and Bob continue to perform QKD until the quantum key negotiation is completed. Additionally, Alice and Bob can verify their authentication key K based on the key generated through quantum key negotiation. AB To expand and update.
[0029] Taking the BB84-QKD protocol as an example, a specific example is as follows: 1. Shared authentication key Alice and Bob shared the authentication key K before performing QKD. AB ={k1,k2…k nm} (n≥4). The first 4m positions are divided into 4 segments, namely K 1m ={k1,k2…k m}, K 2m ={k m+1 ,k2…k 2m}, K 3m ={k 2m+1 ,k2…k 3m} and K 4m ={k 3m+1 ,k2…k 4m};K 1m and K 3mUsed by Alice to authenticate Bob, K 2m and K 4m This is used for Bob to authenticate Alice. This example assumes K. AB ={01101011}, m=2, then K 1m ={01},K 2m ={10},K 3m ={10},K 4m ={11}.
[0030] 2. BB84-QKD protocol execution: (1) Alice and Bob first execute a QKD protocol using two sets of conjugate basis encoding. For example, in the BB84 protocol, Alice encodes information R by sending photons with specific polarization states, while Bob decodes the information by measuring the polarization states of these photons. Specifically, Alice and Bob use the following four polarization states: horizontal polarization, vertical polarization, left-handed polarization, and right-handed polarization. These four polarizations correspond to two measurement basis vectors: Z basis ({|0 ,|1 }) and X-based ({|+ ,| }).
[0031] (2) Alice and Bob publish the selected basis vector information on the certified public channel, and then obtain the sieved key by retaining the information under the same basis vector. Let J be the encoding information of the same basis vector retained by Alice and Bob. According to the position information of the same basis vector, Alice discards the bits corresponding to different positions in R, and the remaining bits form the encoding sequence R^. Bob decodes the measurement results corresponding to the positions of the same basis vector into the original key sequence M according to the encoding rules of BB84-QKD ("→" or "↗" is interpreted as binary bit 0, and "↑" or "↖" is interpreted as binary bit 1).
[0032] In the absence of noise and eavesdropping, R^ and M should be the same. Assume we eventually obtain R^=M={010110010} and J={010100001}. Generally, the sequence lengths of M and J are much greater than 4m; for ease of understanding, we choose shorter sequences for interpretation.
[0033] (3) Alice performs the first identity verification on Bob: Alice searches for the subsequence K in J{011203140506070819}. 1m={01} are numbered sequentially, and then a random number is sent to Bob. Bob sends the corresponding bit value in M back to Alice for verification. For example, if Alice sends number 3, Bob knows from the rules that the sub-sequence is {0119}, and then Bob sends the corresponding sub-sequence {00} in M to Alice.
[0034] Alice compares subcolumns {00} and R. ^ If the error rate is within a predetermined threshold, proceed to the next step; otherwise, terminate the protocol and discard K. 1m .
[0035] (4) Bob performs the first authentication on Alice: Bob searches for the subsequence K in J{011203140506070819}. 2m ={10} are numbered sequentially, and then one number is randomly sent to Alice. Alice sends the corresponding bit value in R^ back to Bob for verification. For example, if Bob sends number 2, Alice knows from the rules that the subsequence is {1205}, and then Alice sends the corresponding subsequence {11} in R^ to Bob.
[0036] Bob compares the bit values at corresponding positions in subsequence {11} and M. If the error rate is within a predetermined threshold, he proceeds to the next step; otherwise, the protocol is terminated and K is discarded. 1m and K 2m .
[0037] (5) Alice and Bob undergo a second round of identity verification: Referring to steps (3) and (4), Alice and Bob, according to K 3m and K 4m A second round of identity verification will be conducted. Specifically, Alice will verify her identity based on K's identity. 3m Bob is certified, Bob is certified according to K 4m Authenticate Alice.
[0038] (6) If both rounds of identity authentication are successful, Alice and Bob have completed mutual identity authentication. While authenticating each other's identities, Alice and Bob also obtained the bit error rate of the QKD quantum signal transmission process.
[0039] (7) Alice and Bob then continue performing QKD until the quantum key negotiation is completed. Furthermore, Alice and Bob can use the key generated through quantum key negotiation to verify their authentication key K. AB To expand and update.
[0040] Option 2: This method is applied to post-error-correction authentication, such as... Figure 2 As shown, it includes the following steps: (1) Alice and Bob, the two communicating parties, perform the QKD process, retain the signals with the same basis vectors, record the encoding information J of the same basis vectors, and according to the position information of the same basis vectors, Alice discards the bits corresponding to the different positions in the random binary sequence R, and the remaining bits form the encoding sequence R. ^ Bob decodes the measurements corresponding to the same basis vector positions into the original key sequence M (both J and M are binary sequences) according to the QKD encoding rules. Alice and Bob use R... ^ The information is reconciled (corrected) with M so that Alice and Bob each obtain two identical binary sequences R after the error correction. ^* And M*.
[0041] (2) Alice uses QIA's authentication key K AB The first m digits of K 1m Find the match between J and K. 1m The same sub-columns are numbered, and then a number is randomly selected and sent to Bob.
[0042] (3) Bob sends the corresponding bit value of the sub-column of the number to Alice in M according to the number.
[0043] (4) Alice compares the received bit value with R ^* If the bit value at the corresponding position is incorrect, the authentication key K is discarded. AB If Bob fails to complete the first authentication with Alice, the agreement will be terminated; otherwise, Bob will pass Alice's first authentication.
[0044] (5) Similarly, using the methods from steps (2) to (4), Bob, based on K AB Bit K from the (m+1)th bit to the 2mth bit 2m Alice undergoes her first identity verification.
[0045] (6) If Alice passes Bob's first identity verification in step (5), then Alice will proceed according to K. AB Bit K from the (2m+1)th bit to the 3mth bit 3m Perform a second identity verification on Bob; if this verification also passes, Bob will use K... AB Bit K from the (3m+1)th bit to the 4mth bit 4m Alice undergoes a second authentication process. If all four authentication attempts (two rounds total) are successful, the authentication is complete. If any one of the four authentication attempts fails, the authentication process terminates. It is important to note that all keys used during the authentication process, regardless of whether authentication is successful, should be discarded.
[0046] (7) Further, Alice and Bob continue to perform QKD until the quantum key negotiation is completed. Additionally, Alice and Bob can verify their authentication key K based on the key generated through quantum key negotiation. AB To expand and update.
[0047] Taking the BB84-QKD protocol as an example, a specific example is as follows: 1. Shared authentication key Alice and Bob shared the authentication key K before performing QKD. AB ={k1,k2…k nm} (n≥4). The first 4m positions are divided into 4 segments, namely K 1m ={k1,k2…k m}, K 2m ={k m+1 ,k2…k 2m}, K 3m ={k 2m+1 ,k2…k 3m} and K 4m ={k 3m+1 ,k2…k 4m};K 1m and K 3m Used by Alice to authenticate Bob, K 2m and K 4m This is used for Bob to authenticate Alice. This example assumes K. AB ={01101011}, m=2, then K 1m ={01},K 2m ={10},K 3m ={10},K 4m ={11}.
[0048] 2. BB84-QKD Protocol Execution (1) Alice and Bob first execute a QKD protocol using two sets of conjugate basis encoding. For example, in the BB84 protocol, Alice encodes information R by sending photons with specific polarization states, while Bob decodes the information by measuring the polarization states of these photons. Specifically, Alice and Bob use the following four polarization states: horizontal polarization, vertical polarization, left-handed polarization, and right-handed polarization. These four polarizations correspond to two measurement basis vectors: Z basis ({|0 ,|1 }) and X-based ({|+ ,| }).
[0049] (2) Alice and Bob publish the selected basis vector information on the certified public channel, and then obtain the sieved key by retaining the information under the same basis vector. Let J be the encoding information of the same basis vector retained by Alice and Bob. According to the position information of the same basis vector, Alice discards the bits corresponding to different positions in R, and the remaining bits form the encoding sequence R^. Bob decodes the measurement results corresponding to the positions of the same basis vector into the original key sequence M according to the encoding rules of BB84-QKD ("→" or "↗" is interpreted as binary bit 0, and "↑" or "↖" is interpreted as binary bit 1).
[0050] Alice and Bob use R^ and M to reconcile (correct) information, resulting in Alice and Bob obtaining two identical binary sequences R^* and M* respectively after correction. Assume the final result is R^*=M*={010110010} and J={010100001}. Generally, the sequence lengths of M* and J are much greater than 4m; for ease of understanding, shorter sequences are chosen for interpretation.
[0051] (3) Alice performs the first identity verification on Bob: Alice searches for the subsequence K in J{011203140506070819}. 1m ={01} are numbered sequentially, and then a random number is sent to Bob. Bob sends the corresponding bit value in M* back to Alice for verification. For example, if Alice sends number 3, Bob knows from the rules that the subsequence is {0119}, and then Bob sends the corresponding subsequence {00} in M* to Alice.
[0052] Alice compares {00} and R ^* If the corresponding bit value is incorrect, the protocol is terminated and K is discarded. 1m Otherwise, proceed to the next step.
[0053] (4) Bob performs the first round of identity verification on Alice: Bob searches for the subsequence K in J{011203140506070819}. 2m ={10} are numbered sequentially, and then one number is randomly sent to Alice. Alice sends the corresponding bit value in R^ to Bob for verification. For example, if Bob sends number 2, Alice knows from the rules that the sub-sequence is {1205}, and then Alice sends the corresponding sub-sequence {11} in R^* to Bob.
[0054] Bob compares the bit values at corresponding positions in subsequence {11} and M*. If an error is found, the protocol is terminated and K is discarded. 1m and K2m Otherwise, proceed to the next step.
[0055] (5) Alice and Bob conduct a second round of identity verification. Referring to steps (3) and (4), Alice and Bob, according to K 3m and K 4m A second round of identity verification will be conducted. Specifically, Alice will verify her identity based on K's identity. 3m Bob is certified, Bob is certified according to K 4m Authenticate Alice.
[0056] (6) If both rounds of identity authentication are successful, Alice and Bob have completed mutual identity authentication. While authenticating each other's identities, Alice and Bob also obtained the bit error rate of the QKD quantum signal transmission process.
[0057] (7) Alice and Bob then continue performing QKD until the quantum key negotiation is completed. Furthermore, Alice and Bob can use the key generated through quantum key negotiation to verify their authentication key K. AB To expand and update.
[0058] Based on the same technical concept, this invention also provides a quantum key distribution system, including Alice and Bob, who are used to perform the above-described quantum identity authentication and key update methods. The specific working principle can be referred to the description in the foregoing method embodiments, and will not be repeated here.
[0059] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A quantum identity authentication and key update method, characterized in that, This method is applied to pre-error correction authentication and includes the following steps: (1) Alice and Bob, the two communicating parties, perform the QKD process, retain the signals with the same basis vectors, and record the encoding information J of the same basis vectors; based on the position information of the same basis vectors, Alice discards the bits corresponding to the different positions in the random binary sequence R, and the remaining bits form the encoding sequence R. ^ Bob decodes the measurement results corresponding to the same basis vector positions into the original key sequence M according to the QKD encoding rules. In the absence of noise and eavesdropping, R... ^ Same as M; (2) Alice uses QIA's authentication key K AB The first m digits of K 1m Find the match between J and K. 1m The same sub-columns are numbered, and then a random number is sent to Bob; (3) Bob sends the corresponding bit value of the sub-column of the number in M to Alice according to the number; (4) Alice compares the received bit value with R ^ If the error rate of the comparison of the corresponding bit values exceeds the threshold, the authentication key K is discarded. AB If Bob fails to complete Alice's initial authentication, the agreement will be terminated. (5) Similarly, using the methods from steps (2) to (4), Bob, based on K AB Bit K from the (m+1)th bit to the 2mth bit 2m Alice undergoes her first identity verification. (6) If Alice passes Bob's first identity verification in step (5), then Alice will proceed according to K. AB Bit K from the (2m+1)th bit to the 3mth bit 3m Perform a second identity verification on Bob; if this verification also passes, Bob will use K... AB Bit K from the (3m+1)th bit to the 4mth bit 4m Alice undergoes a second identity verification; if all four verifications (two rounds) are successful, the identity verification process is complete; if any one of the four verifications fails, the verification process is terminated.
2. The quantum identity authentication and key update method according to claim 1, characterized in that, Also includes: (7) Alice and Bob continue to perform QKD until the quantum key negotiation is completed; Alice and Bob use the authentication key K between them, generated through quantum key negotiation. AB To expand and update.
3. The quantum identity authentication and key update method according to claim 1, characterized in that, During the authentication process, regardless of whether authentication is successful, the used key should be discarded.
4. A quantum identity authentication and key update system, comprising Alice and Bob, characterized in that, Alice and Bob are used to perform the quantum identity authentication and key update method as described in any one of claims 1-3.
5. A quantum identity authentication and key update method, characterized in that, This method is applied to post-error correction authentication and includes the following steps: (1) Alice and Bob, the two communicating parties, perform the QKD process, retain the signals with the same basis vectors, record the encoding information J of the same basis vectors, and according to the position information of the same basis vectors, Alice discards the bits corresponding to the different positions in the random binary sequence R, and the remaining bits form the encoding sequence R. ^ Bob decodes the measurement results corresponding to the same basis vector positions into the original key sequence M according to the QKD encoding rules; Alice and Bob use R ^ Error correction is performed on M so that Alice and Bob each obtain two identical binary sequences R after the error correction. ^* and M*; (2) Alice uses QIA's authentication key K AB The first m digits of K 1m Find the match between J and K. 1m The same sub-columns are numbered, and then a random number is sent to Bob; (3) Bob sends the corresponding bit value of the sub-column of the number in M to Alice according to the number; (4) Alice compares the received bit value with R ^* If the bit value at the corresponding position is incorrect, the authentication key K is discarded. AB If Bob fails to complete Alice's initial authentication, the agreement will be terminated. (5) Similarly, using the methods from steps (2) to (4), Bob, based on K AB Bit K from the (m+1)th bit to the 2mth bit 2m Alice undergoes her first identity verification. (6) If Alice passes Bob's first identity verification in step (5), then Alice will proceed according to K. AB Bit K from the (2m+1)th bit to the 3mth bit 3m Perform a second identity verification on Bob; if this verification also passes, Bob will use K... AB Bit K from the (3m+1)th bit to the 4mth bit 4m Alice undergoes a second identity verification; if all four verifications (two rounds) are successful, the identity verification process is complete; if any one of the four verifications fails, the verification process is terminated.
6. The quantum identity authentication and key update method according to claim 5, characterized in that, Also includes: (7) Alice and Bob continue to perform QKD until the quantum key negotiation is completed; Alice and Bob use the authentication key K between them, generated through quantum key negotiation. AB To expand and update.
7. The quantum identity authentication and key update method according to claim 5, characterized in that, During the authentication process, regardless of whether authentication is successful, the used key should be discarded.
8. A quantum identity authentication and key update system, comprising Alice and Bob, characterized in that, Alice and Bob are used to perform the quantum identity authentication and key update method as described in any one of claims 5-7.