Security proof of quantum communication protocols

By introducing fault tolerance limits and attack success limits into quantum communication protocols, the security of quantum channels is evaluated using quantum circuit systems. This solves the security problem of information sharing in quantum communication and realizes a security assessment and protocol termination mechanism, which is applicable to financial, government, and military communications.

CN122122859APending Publication Date: 2026-05-29BUNDESDRUCKEREI GMBH +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BUNDESDRUCKEREI GMBH
Filing Date
2024-10-22
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing quantum communication protocols lack effective security assessment and attack detection mechanisms during information sharing, making it difficult to ensure communication security.

Method used

By defining fault tolerance thresholds and attack success thresholds, quantum circuit systems are used to intercept qubits on a quantum channel, assess the success rate of reception by the receiving node and the success rate of third-party attacks, and terminate the communication protocol when these thresholds are met or not.

Benefits of technology

It enables the security assessment of quantum communication protocols, ensuring the security of information sharing, and is suitable for security-critical applications such as financial transactions, government communications, and military operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122122859A_ABST
    Figure CN122122859A_ABST
Patent Text Reader

Abstract

A method for sharing information between a sender node and a receiver node according to a quantum communication protocol is disclosed. The method comprises determining an attack configuration for accessing a quantum channel by a third party, the attack configuration being defined at least by a quantum circuit system having certain parameters and an attack success bound, the quantum circuit system being configured for intercepting quantum bits on the quantum channel, determining states of the intercepted quantum bits; using the quantum circuit system to measure a first indicator and a second indicator by intercepting at least quantum bits on the quantum channel; determining whether the second indicator satisfies a fault tolerance bound and whether the first indicator satisfies the attack success bound; aborting the communication protocol if the second indicator satisfies the fault tolerance bound and the first indicator satisfies the attack success bound.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data communication, and more particularly to a method for sharing information between nodes according to a quantum communication protocol. Background Technology

[0002] Quantum communication is a field that utilizes the quantum mechanical properties of quantum systems, such as superposition and entanglement, to achieve secure and efficient communication protocols. It offers a wide range of applications, such as quantum key distribution (QKD), which allows two parties to securely exchange encryption keys, where any attempt by a third party to intercept the quantum signal may disturb the quantum state, thus alerting the legitimate user. Another major application of quantum communication is quantum teleportation and quantum cryptography. However, improvements are needed in the use of QKD. Summary of the Invention

[0003] The object of this invention is to provide a method for sharing information using a quantum channel and a data sharing system (including a sending node and a receiving node) according to a quantum communication protocol. This object is achieved through the features of the independent claims.

[0004] The implementation provides a method (security proof method) for sharing information between a sending node and a receiving node using a quantum channel according to a quantum communication protocol that requires or defines a fault tolerance threshold for the receiving node. The method includes: determining an attack configuration for third-party access to the quantum channel, the attack configuration being defined at least by a quantum circuit system with specific parameters and an attack success threshold, the quantum circuit system being configured to intercept qubits on the quantum channel, determine the state of the intercepted qubits, and send the qubits to the receiving node via the quantum channel; defining a first metric representing the success of the attack by the third party and a second metric indicating the success of reception at the receiving node; evaluating the second metric using the receiving node and evaluating the first metric using the quantum circuit system by intercepting at least the qubits on the quantum channel; determining whether the first metric satisfies the attack success threshold and whether the second metric satisfies the fault tolerance threshold; and terminating the communication protocol if the second metric satisfies the fault tolerance threshold and the first metric satisfies the attack success threshold.

[0005] The implementation provides a quantum computing system for sharing information between a sending node and a receiving node according to a quantum communication protocol. The quantum computing system includes a quantum circuit system with specific parameters configured to intercept qubits on a quantum channel, determine the state of the intercepted qubits, and send the qubits to the receiving node via the quantum channel. The quantum computing system is configured to use the receiving node to evaluate a second metric and to use the quantum circuit system to evaluate a first metric by intercepting at least qubits on the quantum channel, wherein the first metric represents the success of an attack using the quantum circuit system, and the second metric indicates the success of reception at the receiving node. It is determined whether the first metric meets an attack success threshold and whether the second metric meets a fault tolerance threshold. If the second metric meets the fault tolerance threshold and the first metric meets the attack success threshold, the communication protocol is terminated.

[0006] It should be understood that one or more of the aforementioned implementation schemes can be combined as long as the combined implementation schemes are not mutually exclusive. Attached Figure Description

[0007] In the following description, embodiments are illustrated in more detail with reference to the accompanying drawings, wherein:

[0008] Figure 1 This is a block diagram of a system according to an embodiment of the subject matter of the present invention.

[0009] Figure 2 This is a flowchart of a method for sharing information between a sending node and a receiving node according to a quantum communication protocol.

[0010] Figure 3A This is a diagram illustrating an exemplary quantum communication system according to an embodiment of the subject matter of the present invention.

[0011] Figure 3B An exemplary quantum circuit system for a third-party quantum computing system is schematically illustrated according to an embodiment of the subject matter of the invention.

[0012] Figure 3C An exemplary quantum circuit system for a third-party quantum computing system is schematically illustrated according to an embodiment of the subject matter of the invention.

[0013] Figure 3D An exemplary quantum circuit system for a third-party quantum computing system is schematically illustrated according to an embodiment of the subject matter of the invention.

[0014] Figure 4A This is a diagram illustrating an exemplary quantum communication system according to an embodiment of the subject matter of the present invention.

[0015] Figure 4BAn exemplary quantum circuit system for a third-party quantum computing system is schematically illustrated according to an embodiment of the subject matter of the invention.

[0016] Figure 5 This is a flowchart of a method for optimizing parameters of a quantum circuit system according to an embodiment of the subject matter of the present invention. Detailed Implementation

[0017] In the following text, similar elements are indicated by the same reference numerals.

[0018] The subject matter of this invention enables two or more remote parties to communicate securely with each other. In particular, the subject matter of this invention can provide an accurate assessment of the level of security of communication via quantum channels.

[0019] Quantum computing enables secure access to information. For this purpose, quantum channels can be used. A quantum channel can be a communication channel capable of transmitting quantum information. Quantum channels can also be used to transmit classical information. An example of quantum information can be information indicating the state of a qubit. The state of a qubit can refer to the computational ground state given a basis. A qubit can be physically realized using a quantum system with two states, where the quantum system can be, for example, a photon or an ion. For example, a quantum channel can be realized using optical fibers or free space. For example, the vertical and horizontal polarization of a photon can be used as a qubit state. For example, the two energy levels of an ion can be used as qubit states. For example, in the case of a qubit represented by a photon, the computational ground state can be a horizontally polarized state and a vertically polarized state, or it can be a diagonally polarized state and an anti-diagonally polarized state.

[0020] Quantum channels can be used to share or provide information. For example, a system comprising a sender node and a receiver node is provided (referred to as a data sharing system or quantum communication system). The sender node may, for example, include a sender quantum computing system, and the receiver node may, for example, include a receiver quantum computing system. The terms "receiver node" and "receiver quantum computing system" are used interchangeably. The terms "sender node" and "sender quantum computing system" are used interchangeably. A data sharing system may include a sender quantum computing system connected to a receiver quantum computing system via a quantum channel. For example, the sender quantum computing system can use the quantum channel to share information with the receiver quantum computing system, and vice versa. For example, the shared information can be encoded in the state of qubits transmitted from the sender quantum computing system to the receiver quantum computing system via the quantum channel.

[0021] Information sharing between a sending quantum computing system and a receiving quantum computing system can be performed according to a quantum communication protocol. A quantum communication protocol can be a rule-based system that allows two or more entities in a communication system to share (e.g., transmit) information. For example, a quantum communication protocol can define the rules, syntax, semantics, and synchronization of communication, as well as possible error recovery methods. In one embodiment, a quantum communication protocol can be used by the sending and receiving quantum computing systems to obtain two identical copies of a bit sequence, wherein the shared information can include at least the bit sequence. For example, the bit sequence can be random and confidential. For example, the sending quantum computing system can prepare qubits in states that respectively represent the bit sequence.

[0022] For example, quantum communication protocols can be based on single qubits or entangled states. Security limits can be used to control the security of information sharing within quantum communication protocols. These limits can be defined, for example, using theoretical methods through theoretical analysis, simulation methods by creating models and performing simulations on the modeled system, or statistical methods by analyzing data and using statistical techniques to identify patterns.

[0023] Security limits can be defined for the reception of qubits at the receiving node. For example, this security limit can be named or referred to as a fault tolerance limit. A fault tolerance limit can refer to a value or a range of values. A fault tolerance limit can refer to a value or a range of values ​​for error rate, reception success rate, or fidelity. For example, a fault tolerance limit can represent the maximum error rate in quantum information transmission, or the minimum success rate of qubit reception that should not be exceeded for secure information sharing; otherwise, information sharing may be classified as insecure. A low error rate can indicate a high degree of accuracy of the transmitted qubits, while a high reception success rate can indicate the ability to reliably detect and measure those qubits. For example, a higher reception success rate can indicate a lower probability of errors occurring during qubit transmission and measurement. Therefore, a higher reception success rate can be associated with a lower error rate. In one embodiment, a fault tolerance limit can represent the error caused by the maximum degree of eavesdropping.

[0024] The subject matter of this invention can also use another security limit to represent eavesdropping. This security limit can be referred to as the attack success limit. The attack success limit can be used to evaluate the security of quantum communication protocols. The attack success limit can indicate the degree of success of a (simulated) attack or eavesdropping by a third party. The attack success limit can refer to a value or a range of values. The attack success limit can refer to a value or a range of values ​​representing fidelity or the degree of success of eavesdropping.

[0025] The subject matter of this invention enables two or more remote parties to communicate securely with each other. In particular, the subject matter of this invention can provide an accurate assessment of the security level of communication via a quantum channel. For this purpose, a third-party quantum computing system (also referred to as a third party) can be provided. The third-party quantum computing system can be configured to connect to a quantum channel between a sending quantum computing system and a receiving quantum computing system. The sending quantum computing system can prepare qubits in their respective ground states and send them to the receiving quantum computing system via the quantum channel. The receiving quantum computing system can be configured to receive the prepared qubits via the quantum channel and measure their states. The third-party quantum computing system can be configured to intercept the prepared qubits on the quantum channel, determine or estimate their states, and send (retransmit) the intercepted qubits to the receiving node via the quantum channel. In one embodiment, the third-party quantum computing system can be configured to intercept the prepared qubits on the quantum channel and determine their states without destroying or altering the states of the intercepted qubits, and then send the qubits to the receiving node. In one embodiment, a third-party quantum computing system can be configured to intercept prepared qubits on a quantum channel, create an approximate copy of the intercepted qubits, send the approximate copy to a receiving node via the quantum channel, and use the approximate copy of the intercepted qubits to estimate the state of the intercepted qubits. The third-party quantum computing system can simulate attacks or eavesdropping on the quantum channel. It can also be used to assess the success of an attack (e.g., the success of eavesdropping on a quantum channel).

[0026] The success of an attack can be assessed using the state of the intercepted qubit, determined by a third-party quantum computing system. The state determined by the third-party quantum computing system can be compared with the prepared state of the intercepted qubit to assess the success of the attack. Once the intercepted qubit reaches the receiving quantum computing system, its state can be measured there, and compared with the prepared state to assess the success of reception at the receiving quantum computing system. The success of the attack can be represented by a first metric. The success of reception can be represented by a second metric. For example, the third-party quantum computing system can be used to assess the first metric. For example, the first metric could be a distance metric, such as fidelity. For example, the third-party quantum computing system can be used to determine the elements of a density matrix, which can be used to calculate the fidelity between the state of the intercepted qubit and the state of the prepared qubit prepared by the sending node. The receiving quantum computing system can be used to assess the success of reception. For example, the receiving quantum computing system can be used to assess the second metric representing the success of reception. For example, the second metric could be a distance metric, such as fidelity. For example, the receiving quantum computing system can be used to determine the elements of the density matrix, which can be used to calculate the fidelity between the state of the received qubit and the state of the prepared qubit prepared by the sending node.

[0027] For example, each of the sending, receiving, and third-party quantum computing systems may include a quantum circuit system. The quantum circuit system can utilize the principles of quantum mechanics to perform quantum computing by manipulating one or more qubits. The quantum circuit system can also utilize the principles of quantum mechanics to perform quantum communication to transmit or receive quantum information. The quantum circuit system can, for example, be a quantum computer. For example, each quantum computing system can be a photonic quantum computer that uses photons to represent qubits, wherein the quantum circuit system may include, for example, components such as a polarization controller, a pulse mode generator, a light source, a plane wave circuit, or any other component capable of enabling the quantum circuit system to perform quantum computing and / or quantum communication. For example, each quantum computing system can be configured to perform classical computing by using a classical computer or by simulating classical computing. The classical computer may or may not be part of each quantum computing system. The classical computer may include hardware such as a processor and memory, and software such as an operating system.

[0028] A third-party quantum computing system can be configured to provide a third-party quantum system. The third-party quantum computing system can be defined based on the attack configuration of a simulated attack. For example, a third-party quantum system can be defined by a set of intercepted, prepared qubits and one or more additional qubits on a quantum channel. For example, a third-party quantum computing system can include a quantum circuit system comprising the intercepted qubits and the set of additional qubits. The quantum circuit system can also be configured to perform a set of one or more quantum operations with specific parameters. The quantum operations can be unitary operations. Applying the set of one or more quantum operations makes it possible to determine or predict the state of the intercepted qubits by measuring one or more additional qubits of the quantum circuit system after applying the set of one or more quantum operations. After applying the set of one or more quantum operations, the intercepted qubits can remain unchanged and can be retransmitted by the quantum circuit system to the receiving node via the quantum channel. For example, a quantum operation can be one or a sequence of operations from a set of defined universal quantum gates, including, for example, rotation operators and controlled-NOT (CNOT) operators.

[0029] For example, a set of one or more quantum operations may be a controlled operation using the intercepted qubit as the control qubit. For example, a controlled operation may be a controlled rotation applied to an additional qubit and using the intercepted qubit as the control qubit. For example, a controlled operation may be a CNOT operation, which acts on two qubits to perform a NOT operation on the additional qubit based on the state of the intercepted qubit. After applying the controlled operation, the intercepted qubit may remain unchanged and may be retransmitted by the quantum circuit system to the receiving node via a quantum channel. After applying the controlled operation, the state of the additional qubit involved in the controlled operation may indicate the state of the intercepted qubit. In another embodiment, the set of quantum operations may include controlled operations in addition to additional quantum operations. Additional quantum operations may be applied to at least a portion of the set of additional qubits. After applying the set of quantum operations, at least one of the additional qubits may be measured, and the measurement result may be used to determine or estimate the state of the intercepted qubit.

[0030] For example, a third-party quantum computing system may include a control device that controls the state of the qubits of a quantum circuit system, such as controlling the quantum circuit system to perform a set of quantum operations. Quantum operations can be applied to at least a portion of the qubits of the quantum circuit system. A quantum operation can be a controlled quantum operation, where the intercepted qubits act as control bits for the quantum operation. For example, specific parameters of the quantum circuit system can be parameters of the quantum operation, such as the rotation angle of a rotation operation. For instance, the state of a qubit can be transformed by rotating it about the x, y, and z axes within a Bloch sphere.

[0031] The value of a first metric can be compared to an attack success threshold (first comparison) to determine whether the value of the first metric meets the attack success threshold. The fact that the value of the first metric meets the attack success threshold means that the attack is successful. For example, the degree of success of the attack meeting the attack success threshold means that the degree of success of the attack is higher than the attack success threshold; for example, the fidelity metric (representing the degree of success of the attack) can be higher than 80%, where 80% can be the attack success threshold. The value of a second metric can be compared to a fault tolerance threshold (second comparison) to determine whether the value of the second metric meets the fault tolerance threshold. The fact that the value of the second metric meets the fault tolerance threshold means that the information reception at the receiving node is successful (e.g., secure). For example, the degree of reception success at the receiving node meeting the fault tolerance threshold means that the degree of reception success at the receiving node is higher than the fault tolerance threshold, where the fault tolerance threshold can be the minimum degree of reception success. In another embodiment, where the fault tolerance threshold is the maximum error rate, if the reception error rate at the receiving node is less than the fault tolerance threshold, then the error rate meets the threshold; for example, the error rate at the receiving node can be less than 10%, where 10% can be the fault tolerance threshold.

[0032] The subject of this invention can determine the security of a quantum communication protocol not only using the second comparison result, but also using both the first and second comparison results simultaneously. For example, if the second metric meets the fault tolerance threshold and the first metric meets the attack success threshold, the quantum communication protocol can be terminated. In another embodiment, if the second metric does not meet the fault tolerance threshold and the first metric meets the attack success threshold, the quantum communication protocol can be terminated. If the second metric meets the fault tolerance threshold and the first metric does not meet the attack success threshold, the quantum communication protocol can remain in place.

[0033] Therefore, the subject matter of this invention enables two or more remote parties to communicate securely with each other; for example, the data sharing system can be a real system (i.e., a non-analog system) for truly sharing information via quantum channels. Such communication is useful in a wide range of applications where security is paramount, such as in financial transactions, government communications, and military operations.

[0034] For example, terminating a quantum communication protocol could include providing warning or error signals to both the sending and receiving quantum computing systems. This signal could indicate that the communication is insecure and that the shared information may be accessible to eavesdroppers.

[0035] In one embodiment, upon receiving a signal, the sending and receiving quantum computing systems can share information by adjusting the quantum communication protocol, repeating the information sharing at another point in time, or ceasing information sharing altogether. In one embodiment, in response to terminating the quantum communication protocol, information can be shared again between the sending and receiving quantum computing systems (e.g., at a later point in time), a first metric and a second metric can be evaluated, and further checks can be performed regarding whether the quantum communication protocol should be terminated. This can be advantageous when the security issue is temporary, for example, it might occur solely due to some temporary misconfiguration. In one embodiment, in response to terminating the quantum communication protocol, the quantum communication protocol can be adjusted, and the security proof method can be repeated using the adjusted quantum communication protocol to share information between the sending and receiving quantum computing systems.

[0036] In one embodiment, information can be shared between a sending quantum computing system and a receiving quantum computing system by at least the sending quantum computing system sending qubits to the receiving quantum computing system. The sending quantum computing system can prepare each qubit in its corresponding computational ground state and then send the prepared qubits to the receiving quantum computing system via a quantum channel. The state of the prepared qubits provides information shared between the sending and receiving quantum computing systems. This embodiment can be advantageous because it enables seamless integration of the subject matter of the invention with existing communication protocols, such as the BB84 protocol. For example, the sending quantum computing system can use a predefined plurality of bases to prepare qubits. For example, to encode or prepare qubits, the sending quantum computing system can select one of the predefined plurality of bases and prepare qubits in their computational ground states using the selected base. Once the receiving quantum computing system receives the prepared qubits on the quantum channel, it can measure the prepared qubits received at the receiving quantum computing system by selecting one of the predefined plurality of bases and using the selected base. This embodiment enables information sharing according to a single-qubit-based protocol.

[0037] In one embodiment, information can be shared between a sending quantum computing system and a receiving quantum computing system by using entanglement. For this purpose, a two-qubit system can be defined for each pair of qubits in the set of qubit pairs, where one qubit of the two-qubit system can be part of the sending quantum computing system and the other qubit can be part of the receiving quantum computing system. The state of the two-qubit system can be an entangled state. For example, the entangled state of the two-qubit system can be any of the Bell states, such as the sending and receiving quantum computing systems each receiving a photon from a polarization-entangled pair.

[0038] The subject of this invention is to utilize the entangled states of a two-qubit system to transmit or share information between a sending quantum computing system and a receiving quantum computing system. Information can be teleported from the sending qubit to the receiving qubit via entanglement. For example, two qubits can be entangled such that when a specific property is measured in one qubit, the opposite state can be instantaneously observed in the entangled qubits.

[0039] Entangled states can be provided as distributed entangled states, such that entangled qubit pairs are located at different locations in the respective sending and receiving quantum computing systems. For example, a distributed entangled state between qubit pairs can be formed by first locally forming the entangled state of the qubit pair at the sending quantum computing system, and then having one of the qubit pairs sent from the sending quantum computing system to the receiving quantum computing system. For example, entangled states can be formed by applying a CNOT operation to the qubit pair. Therefore, to share information between the sending and receiving quantum computing systems, multiple distributed entangled states can be created using qubit pairs separately. According to the subject matter of the invention, the use of entanglement can further ensure information sharing. In one embodiment, the quantum communication protocol can be an entangled QKD protocol, for example, an entangled BB84 variant.

[0040] In one embodiment, the sending and receiving quantum computing systems can also be configured to communicate via a classical public channel, for example, to exchange public data, such as a basis for preparing or measuring qubits. A third-party quantum computing system can be configured to intercept and receive data communicated over the classical public channel. For example, the third-party quantum computing system can use the intercepted information to determine or improve attack configurations and to determine a first metric.

[0041] The subject of this invention can utilize advantageous techniques to provide different (simulated) attack configurations for third-party quantum computing systems, enabling reliable security proofs of quantum communication protocols using quantum channels. For this purpose, offline analysis and quantum simulators can be used to define one or more attack configurations. Offline analysis can be referred to as an attack simulation method. For example, a quantum simulator can be configured to simulate a quantum communication protocol using a model of a real communication system that implements quantum information communication. For example, a quantum simulator can be configured to control parameters for various components and sub-protocols in the system, including the quantum channel and the communicating parties. For example, a quantum simulator can be implemented as a software application.

[0042] In a first optimized embodiment, the attack simulation method can use a quantum simulator to optimize specific parameters of a third-party quantum computing system to improve the attack success rate. The attack simulation method may include: defining a quantum circuit system comprising at least the intercepted qubit and one or more additional qubits, and performing one or more quantum operations with specific parameters, wherein the quantum operations(s) enable the determination of the state of the intercepted qubit, e.g., without affecting the prepared state of the intercepted qubit. The attack simulation method may also include evaluating a first metric using the determined / estimated state of the intercepted qubit. The attack simulation method may be repeated multiple times, wherein different values ​​of the specific parameters are used in each repetition. Repetitions may be performed until a desired target for the first metric is reached, wherein the value of the parameter providing the desired target is provided as the optimal parameter. Alternatively, a predefined number of repetitions may be performed, the resulting first metric values ​​may be compared, and the value of the parameter providing the optimal first metric may be provided as the optimal parameter. Thus, the attack simulation method enables the acquisition of optimized values ​​for specific parameters. These optimized values ​​(and the associated quantum circuit system) can be used by the security proof method of the present invention to prove the security of sharing information between the sending quantum computing system and the receiving quantum computing system.

[0043] In a second optimized embodiment, the attack simulation method can use a quantum simulator to optimize specific parameters of a third-party quantum computing system through machine learning to improve the attack success rate. For this purpose, an objective function can be defined. The attack simulation method can be repeated multiple times, wherein in each repetition, different values ​​of specific parameters are defined based on the evaluated objective function. Repetitions can be performed until the objective function satisfies a convergence criterion. This embodiment allows for the precise determination of the optimal parameters. This can further improve the security proofs of the subject matter according to the invention. The objective function can be defined based on the type of the first metric used.

[0044] In one embodiment, the second metric can be the fidelity between the state of the prepared qubit prepared by the sending node and the measured state of the qubit received at the receiving quantum computing system and measured by the receiving quantum computing system. The state of the prepared qubit can be determined by the density matrix. The state, represented and measured by the receiving quantum computing system, can be expressed by the density matrix. Therefore, the second indicator can be defined as follows: This allows for comparison of the impact of eavesdropping on qubits based on the fidelity of the qubits prepared at the sending node and those obtained at the receiving node.

[0045] In one embodiment, the first indicator ( The first metric can be the fidelity between the state of the intercepted qubit, determined or estimated by a third party, and the state of the prepared qubit, prepared by the sender. Therefore, the first metric can be defined as follows: The following references provide exemplary implementations for evaluating the first and second metrics: Charles H. Bennett, F. Bessette, G. Brassard, L. Salvail and J. Smolin. Experimental quantum cryptography. Journal of cryptology, 5:3-28; and Umesh Vazirani and Thomas Videck. Fully device-independent quantum key distribution. Physical Review Letters, 113(14), Sep 2014.

[0046] For example, if the states are identical, the first index can have a value of 1; if they are orthogonal, the first index can have a value of 0. A third-party quantum computing system can provide a quantum circuit system to maintain its fidelity and the fidelity at the receiver as close to 1 as possible. In this case, an attack might only be noticed with a low probability. For example, in the case where the quantum communication protocol is the BB84 protocol, four different states can be chosen with equal probability. In this case, the average fidelity (e.g., measuring the fidelity for all different states and averaging it over the four different states) can be used as the first and second indices for the third-party quantum computing system and the receiver quantum computing system, respectively.

[0047] A quantum communication protocol can be used by a sending quantum computing system and a receiving quantum computing system to obtain two identical copies of a bit sequence, where the shared information can be the bit sequence itself. For example, the bit sequence can be random and confidential. A third-party quantum computing system can attempt to learn the original bits. During this information-sharing process, each of the three parties can obtain the bit string. These three strings can be interpreted as binary random variables. The degree of dependence between two random variables can be measured based on mutual information. In one embodiment, the first metric may alternatively include the mutual information (interaction information) between the sending node and the third party's binary random variables.

[0048] For example, mutual information can be defined as follows: ,in It can be a random variable associated with a bit at the sending quantum computing system. It can be a random variable associated with a bit at a third-party quantum system, where It is a joint probability. and It is the probability of an individual.

[0049] For example, two random bits b1 and b2 ∈ [0, 1] are used as inputs to a quantum channel, and the output can be an XOR value b1 ⊕ b2. The corresponding probabilities are shown in the table below:

[0050] For example, the input 00 appears with a 1 / 4 probability along with the output 0. Therefore, the value of the interaction information could be 1; for example, 1 bit out of two possible information bits is transmitted through the channel. However, information about the individual bits might not be received because even knowing b1⊕b2, the values ​​of b1 and b2 are still uniformly distributed. However, information about the value of b1⊕b2 could be valuable to an attacker (or eavesdropper) because it might allow the search space in a brute-force search to be limited from four possibilities to two.

[0051] For example, the fidelity of the receiver quantum computing system can be called... Furthermore, the fidelity of third-party quantum computing systems can be called... The objective function of the second optimization embodiment can be defined, for example, as: Where target is fidelity The predetermined target value. The mutual information of a third-party quantum computing system can be called... In this case, the objective function can be defined, for example: .

[0052] A metric determination system can be used to evaluate the first and second metrics. This system may or may not be part of a third-party quantum computing system. The metric determination system can be a classical computer system or a quantum computer system. For example, a metric determination system can use quantum state tomography to construct the density matrix. and (For example, by utilizing a series of measurements performed on different bases), and estimating the fidelity.

[0053] In one embodiment, the quantum communication protocol can be a quantum key distribution (QKD) protocol, where the shared information includes a key. For example, the QKD protocol could be the BB84 protocol or the Eckert protocol E91. The transmitted qubits can be photons prepared in a computational ground state, where the computational ground state can be a horizontally and vertically polarized state, or it can be a diagonally polarized state.

[0054] The subject matter of this invention can further improve the security proof of quantum communication protocols using quantum channels. For this purpose, different structures of quantum circuit systems from third-party quantum computing systems can be used.

[0055] In one embodiment, different quantum circuit systems can be defined, and for each quantum circuit system, it can be used to intercept qubits on a quantum channel and evaluate a first metric. A quantum circuit system with an optimal value for the first metric can be selected and used to perform a security proof method according to the subject matter of the invention. Each quantum circuit system may include intercepted qubits, a defined number of additional qubits, and a set of quantum operations to be performed, including controlled operations and zero or more additional quantum operations. Parameters of the set of quantum operations (e.g., rotation angle) may be specific parameters of the quantum circuit system. For example, the number of additional qubits and additional quantum operations for each quantum circuit system may be randomly selected or may be user-defined.

[0056] In a first circuit embodiment, the quantum circuit system includes an intercepted qubit and one or more qubits. The quantum circuit system is configured to perform a sequence of one or more quantum operations on the qubit to determine the state of the intercepted qubit without destroying the state of the intercepted qubit.

[0057] In the second circuit embodiment, the quantum circuit system includes an intercepted qubit and a target qubit. The target qubit is prepared to be in its initial ground state. Furthermore, a sequence of one or more quantum operations is a single quantum operation that transforms the initial ground state of the target qubit according to the state of the intercepted qubit without destroying the state of the intercepted qubit. The state of the intercepted qubit is determined or estimated using the state of the target qubit measured after the transformation is applied.

[0058] In the third circuit embodiment, the quantum communication protocol can be a QKD protocol, such as the BB84 protocol. According to this quantum communication protocol, the sending quantum computing system can send the basis used to prepare the intercepted qubit to the receiving quantum computing system over a classical public channel. The third-party quantum computing system can be configured to intercept the data communicated over the classical public channel and access the basis used. The third-party quantum computing system can also be configured to store the intercepted qubit, for example, for later operations. Attack simulations can exploit this to control the quantum circuit system, using the stored qubit and information obtained on the basis to perform basis-dependent operations. For this purpose, the quantum circuit system includes the intercepted qubit and the target qubit. The target qubit is prepared to be in an initial ground state. A sequence of one or more quantum operations includes a controlled quantum operation that transforms the initial ground state of the target qubit according to the state of the intercepted qubit, and another quantum operation that transforms the transformed state of the target qubit, taking into account the basis used to prepare the intercepted qubit. The state of the intercepted qubit can be determined or estimated using the state of the target qubit after applying two transformations, without destroying the state of the intercepted qubit.

[0059] In the fourth circuit embodiment, the quantum circuit system includes an intercepted qubit, a first target qubit, and a second target qubit. A sequence of multiple quantum operations includes a controlled quantum operation that enables the determination of the state of the first target qubit based on the state of the intercepted qubit, and a quantum operation that enables the determination of the state of the second target qubit on a specific computational basis. This quantum operation can be applied by the quantum circuit system without destroying the state of the intercepted qubit.

[0060] In the fifth circuit embodiment, the quantum circuit system can be configured to create one or more approximate state copies of the intercepted qubit. This quantum circuit system enables the preparation of states with the highest possible fidelity, while simultaneously preserving as much fidelity as possible at the receiver. The quantum circuit system can include states... The intercepted qubits can be prepared to be in the ground state (e.g., An additional qubit. A quantum circuit system can be configured to respond to input states. A set of one or more quantum operations performed to obtain a state. ,in The state of the intercepted qubit An approximate copy of the state. Approximate copy. It can be received at the receiving quantum computing system, but because it is an approximate copy, the fidelity at the receiving node can still be high. The approximate copy can be used to estimate the first and second indices. The approximate copy... Compared with the original state A comparison is made to estimate the first metric. An approximate copy received at the receiving quantum computing system can be used. Compared with the original state Compare them in order to estimate the second indicator.

[0061] In one embodiment, each quantum circuit system of the above circuit embodiments can also be used to determine a first index and configured to send the intercepted qubits to the receiving node.

[0062] In one embodiment, the security proof method of the present invention can be implemented in a quantum repeater. This enables seamless integration of the subject matter of the invention into existing systems. For example, the quantum computing system of the present invention for realizing information sharing can be included in a quantum repeater.

[0063] Figure 1 This is a diagram of a system 100 according to an embodiment of the subject matter of the present invention. System 100 includes a quantum communication system 110 and an index determination system 105. The quantum communication system 110 includes a sending quantum computing system 101 and a receiving quantum computing system 102, which are configured to exchange or share information through a quantum channel 104. The quantum communication system 110 also includes a third-party quantum computing system 103 configured to intercept qubits on the quantum channel 104, estimate the state of the intercepted qubits (e.g., without destroying the state of the intercepted qubits), and send these qubits to the receiving node 102. For this purpose, the third-party quantum computing system 103 may include a quantum circuit system, which may be... Figures 3B to 3D and Figure 4B An experimental implementation of the circuit is schematically shown. The third-party quantum computing system 103 can be located at any point on the quantum channel 104. For example, the third-party quantum computing system 103 can be located near the receiver node 102, and may or may not be part of the receiver node 102.

[0064] The metric determination system 105 may include a classical computer or a quantum computer and communicates with components of the quantum communication system 110. The metric determination system 105 may be configured to control the operation of a third-party quantum computing system 103. The metric determination system 105 may enable the quantum circuitry system of the third-party quantum computing system 103 to intercept one or more qubits transmitted on the quantum channel 104 and perform corresponding measurements to determine output information capable of determining metrics such as a first metric. The metric determination system 105 may be configured to control the operation of the receiving node 102 to evaluate a second metric.

[0065] Figure 2 This is a flowchart of an exemplary method for sharing information between a sending node and a receiving node according to a quantum communication protocol. For illustrative purposes, Figure 2 The method described in [the document] can be used Figure 1 The system shown can be used to implement this, but is not limited to this implementation. For example, the sending node can be the sending quantum computing system 101, and the receiving node can be the receiving quantum computing system 102.

[0066] In step 201, an attack configuration for third-party access to the quantum channel can be determined. The attack configuration is defined at least by a quantum circuit system with specific parameters and an attack success threshold. The quantum circuit system is configured to intercept qubits on the quantum channel, determine the state of the intercepted qubits, and send the qubits (or an approximate copy thereof) to the receiving node. Figures 3B to 3D An example of an attack configuration is provided.

[0067] In step 203, a first metric representing the degree of success of the third-party attack and a second metric indicating the degree of success of reception at the receiving node can be defined. For example, the first and second metrics can be user-defined metrics; for instance, input providing the definitions of the first and second metrics can be received in step 203. In another embodiment, the first and second metrics can be defined by selecting them from a predefined list of metrics (e.g., randomly).

[0068] In step 205, a quantum circuit system can be used to evaluate the first metric by intercepting at least the qubits on the quantum channel. In step 205, a receiver node can be used to evaluate the second metric.

[0069] In step 207, it can be determined whether the second indicator meets the fault tolerance threshold and whether the first indicator meets the attack success threshold.

[0070] If the second metric meets the fault tolerance threshold and the first metric meets the attack success threshold, the quantum communication protocol can be terminated in step 209. In one embodiment, if the first metric meets the attack success threshold but the second metric does not meet the fault tolerance threshold, the quantum communication protocol can be terminated.

[0071] In one embodiment, if the first metric does not meet the attack success threshold and the second metric meets the fault tolerance threshold, the shared information can be classified as secure and therefore can be used by the sender and receiver.

[0072] Figure 3A This is a diagram illustrating an exemplary quantum communication system according to an embodiment of the subject matter of the present invention. Specifically, the quantum communication system is represented by a quantum circuit 300. Quantum circuit 300 represents qubit q0, which is transmitted from sender (Alice) 301 to receiver (Bob) 302. Qubit q0 can be intercepted by a third-party quantum computing system (Eve) 303 and used as a control qubit for another qubit q1 of quantum circuit 300. Quantum circuit 300 also shows a measurement device for measuring qubits q0 and q1, wherein qubit q0 is measured at receiver 302 and qubit q1 is measured at third-party quantum computing system 303. Third-party quantum computing system 303 may include a quantum circuit system, such as... Figure 3B , Figure 3C or Figure 3D The circuit is shown schematically in the diagram. Figure 3B and Figure 3C Quantum circuit systems can intercept and estimate the state of a qubit without destroying or altering its state; that is, the receiver can receive the qubit prepared by the sender.

[0073] Figure 3B An exemplary quantum circuit system 310 for a third-party quantum computing system is schematically illustrated according to an embodiment of the subject matter of the invention. The quantum circuit system 310 may consist of controlled rotations on Eve's system, while Alice and Bob's systems act as the control system. The quantum circuit system 310 may be configured to perform a rotation along the y-axis on qubit q1 using an angle α, where angle α is a parameter of the quantum circuit system 310. The rotation may use qubit q1 as the target and the intercepted qubit q0 as the control qubit.

[0074] Figure 3CAn exemplary quantum circuit system 311 for a third-party quantum computing system is schematically illustrated according to an embodiment of the subject matter of the invention. Quantum circuit system 311 is an extension of quantum circuit system 310 to a controlled rotation on the Eve system, extended by another operation (but an uncontrolled operation on the Eve system). Quantum circuit system 311 can be configured to perform a first rotation along the y-axis on qubit q1 using angle a and using qubit q0 as the control qubit, and subsequently perform an uncontrolled rotation along the y-axis using angle b, where angles a and b are parameters of quantum circuit system 311.

[0075] Figure 3D An exemplary quantum circuit system 312 for a third-party quantum computing system targeting the BB84 protocol is schematically illustrated according to an embodiment of the subject matter of the invention. The quantum circuit system 312 can be configured to perform use angles A rotation along the y-axis is performed on qubit q1, followed by a CNOT operation using qubit q1 as the control qubit and q0 as the target. The rotation can use qubit q1 as the target and the intercepted qubit q0 as the control qubit. Quantum circuit system 312 can be configured to create an approximate copy of the intercepted qubit. This quantum circuit system 312 enables the preparation of states with the highest possible state quality from the transmitted state, while simultaneously preserving the state quality of the receiver as much as possible. The quantum circuit system can include states... The intercepted qubits and an additional qubit that can be prepared in the ground state |0>. The quantum circuit system can be configured to respond to the input state. A set of one or more quantum operations performed to obtain a state. ,in The state of the intercepted qubit An approximate copy of the state.

[0076] The copied state can be defined in a specific basis, within which the original state of the transferred qubit is defined according to the BB84 protocol. For example, the ground state could be: , , , Each copied state can be compared to the corresponding original state. The first and second indices can be evaluated using partial tracking of the approximate states, enabling comparison of the approximate states at the receiving node and at a third party with the original states of the transmitted qubits. Furthermore, these approximate states, defined in a particular basis, may not be orthogonal to each other and may not be indistinguishable from one another without error. For example, perfect measurements (PGMs) can be used to distinguish these approximate states. To address this, states with associated probabilities can be... density matrix Adding them together yields a matrix. Then calculate The square root of the pseudo-inverse. This can provide operators with positive operator-valued measure (POVM) on the space spanned by these states. If the simulated attack can store an approximate copy of the state until Alice and Bob exchange information about the chosen basis, a third party can perform basis-dependent operations on the stored state. Since Bob and Eve can receive the same state, it is expected that Bob and Eve will also have the same probability of success in identifying the transmitted state. In this case, the measurement can be performed on one of the following two bases: or .

[0077] In one embodiment, if a third party is configured to store the intercepted qubits, the simulated attack can be divided into two parts: the first part involves interactions with Alice and Bob's systems, as well as with the third-party system, which can be stored. After disclosing the chosen basis, the third-party system can perform basis-dependent operations on the stored qubits before measuring them. For example, this can be done using... Figure 4A This is achieved through a circuit.

[0078] Figure 4A This is a diagram illustrating a quantum communication system according to an embodiment of the subject matter of the invention. Specifically, the quantum communication system is represented by a quantum circuit 400. Quantum circuit 400 represents qubit q0, which is transmitted from sender (Alice) 401 to receiver (Bob) 402. Qubit q0 can be intercepted by a third-party quantum computing system (Eve) 403 and used as a control qubit for another qubit q1. Quantum circuit 400 also shows a measurement device for measuring qubits q0 and q1, wherein qubit q0 is measured at receiver 402 and qubit q1 is measured at the third-party quantum computing system 403. The third-party quantum computing system 403 may include, as referenced... Figure 3B or Figure 3C The first quantum circuit system described. Furthermore, the third-party quantum computing system 403 may include... Figure 4B The two second quantum circuit systems shown are each associated with a specific basis (e.g., in the case that the qubit is a photon, the basis may include horizontal and vertical polarization states).

[0079] In this embodiment, the intercepted qubits can be stored or preserved by a third-party quantum computing system. Furthermore, the third-party quantum computing system can access the basis of the state used by the sender to prepare the intercepted qubits; for example, this might be the case in the BB84 protocol, where the basis is sent via a classical public channel and intercepted by the third-party quantum computing system.

[0080] like Figure 4A As shown, quantum circuit 400 can implement a sequence of at least two operations (rotation about the y-axis) on qubit q1, such as operations 403 and 406 implemented by a third-party quantum computing system 403. Qubit q1 is prepared to be in an initial ground state. The sequence of multiple quantum operations includes a quantum operation performed by a first quantum circuit system to transform the initial ground state of qubit q1 according to the state of the intercepted qubit q0. The sequence of multiple quantum operations also includes another quantum operation that transforms the transformed state of qubit q1 in consideration of the basis used to prepare the intercepted qubit q0. This other quantum operation can be performed by one of a second quantum circuit system associated with the basis used to prepare the intercepted qubit q0. This other quantum operation can be referred to as a basis-dependent operation. Figure 4A As shown, this basis-dependent operation 406 can be performed even after Bob's system has measured qubit q0. The state of the intercepted qubit q0 can be determined by a third-party quantum computing system using the state of qubit q1 measured after a sequence of multiple operations has been applied.

[0081] Figure 4B An example of two quantum circuit systems 410 and 411 for a third-party quantum computing system is schematically illustrated according to an embodiment of the subject matter of the invention. Each of the two quantum circuit systems is in Figure 3C The diagram illustrates this. These two quantum circuit systems can be used based on the basis used by Alice's system to prepare the intercepted qubits. Since Alice's system can use two bases, two quantum circuit systems 410 and 411 are provided to be used for these two bases respectively. For this purpose, each of the two quantum circuit systems is configured to perform a controlled operation and a subsequent uncontrolled operation on qubit q1. The controlled operation in both circuits uses the same angle α, while the uncontrolled operation in the two quantum circuit systems uses two different angles b and c.

[0082] Figure 5This is a flowchart of a method for optimizing parameters of a quantum circuit system according to an embodiment of the subject matter of the present invention. In step 501, the parameters can be set to their current values. In step 503, a first metric can be measured using the quantum circuit system. In step 505, it can be determined whether the first metric satisfies a convergence criterion. If the first metric satisfies the convergence criterion, parameter values ​​can be provided in step 507, for example, to... Figure 2 The method is used in this way. If the first metric does not meet the convergence criterion, the method returns to step 501 to set the parameter to another value. For example, the convergence criterion could require the first metric to be within a range of the target value.

Claims

1. A method for sharing information between a sending node (101) and a receiving node (102) using a quantum channel (104) according to a quantum communication protocol, the quantum communication protocol requiring a fault tolerance limit for the receiving node, the method comprising: Determine (201) an attack configuration for access to the quantum channel by a third party, the attack configuration being defined at least by a quantum circuit system (310, 311, 312) with specific parameters and an attack success threshold, the quantum circuit system being configured to intercept qubits on the quantum channel, determine the state of the intercepted qubits, and send the qubits to the receiving node; Definition (203) represents a first indicator of the success of an attack carried out by the third party and a second indicator of the success of reception at the receiving node; The second metric is evaluated using the receiving node and the first metric is evaluated using the quantum circuit system (205) by at least intercepting the qubits on the quantum channel. Determine (207) whether the second indicator meets the fault tolerance threshold and whether the first indicator meets the attack success threshold; If the second indicator meets the fault tolerance threshold and the first indicator meets the attack success threshold, then the (209) communication protocol is terminated.

2. The method according to claim 1, wherein: Repeat the following: The sending node prepares the qubits in the corresponding ground state; The sending node transmits the prepared qubits to the receiving node through the quantum channel to achieve information sharing; The intercepted qubits are the qubits that were prepared.

3. The method according to claim 1, wherein: Repeat the following: An entangled state is formed between the transmitting quantum bit and the receiving quantum bit in the transmitting node; The sending node transmits the receiving qubit to the receiving node through the quantum channel; The intercepted qubits are the receiver's qubits.

4. The method according to any one of the preceding claims, further comprising: The quantum circuit system is optimized using a quantum simulator. The optimization includes repeatedly changing the values ​​of the parameters of the quantum circuit system and evaluating the first index, and repeating the process to obtain a target value for the first index. The specific parameters of the quantum circuit system are provided as optimization parameters associated with the target value of the first index.

5. The method according to any one of the preceding claims, wherein the quantum circuit system includes an intercepted qubit and one or more qubits, the quantum circuit system being configured to perform a sequence of one or more quantum operations on the qubit to determine the state of the intercepted qubit.

6. The method of claim 5, wherein the quantum circuit system comprises an intercepted qubit and a target qubit prepared to be in an initial ground state, wherein the sequence of one or more quantum operations is a single quantum operation that transforms the initial ground state of the target qubit according to the state of the intercepted qubit, wherein the determination of the state of the intercepted qubit is performed using the state of the target qubit measured after the transformation is applied.

7. The method of claim 5, wherein the quantum circuit system comprises an intercepted qubit and a target qubit prepared to be in an initial ground state, wherein the sequence of one or more quantum operations comprises a quantum operation that transforms the initial ground state of the target qubit according to the state of the intercepted qubit, and another quantum operation that transforms the transformed state of the target qubit in consideration of the basis used to prepare the intercepted qubit, wherein the determination of the state of the intercepted qubit is performed using the state of the target qubit measured after the two transformations are applied.

8. The method of claim 5, wherein the quantum circuit system includes an intercepted qubit and a first target qubit and a second target qubit, wherein the sequence of the plurality of quantum operations includes a quantum operation that enables the state of the first target qubit to be determined based on the state of the intercepted qubit and a quantum operation that enables the state of the target qubit to be determined on a particular computational basis.

9. The method according to any one of claims 5 to 8, wherein the quantum operation is a rotational operation about a specific axis.

10. The method according to any one of the preceding claims, wherein the second index is the fidelity between the state of the qubit received at the receiving node and the state of the prepared qubit.

11. The method according to any one of the preceding claims, wherein the first index is the fidelity between the state of the intercepted qubit and the state of the prepared qubit or the mutual information between the sending node and the third party.

12. The method according to any one of the preceding claims, wherein the quantum communication protocol is a quantum key distribution protocol.

13. The method according to any one of the preceding claims, wherein the shared information includes an encryption key, a token, or a secret.

14. The method according to any one of the preceding claims, implemented in a quantum repeater.

15. A quantum computing system (100) for sharing information between a sending node (101) and a receiving node (102) according to a quantum communication protocol, the quantum computing system comprising a quantum circuit system (310, 311, 312) having specific parameters, the quantum circuit system being configured to intercept qubits on a quantum channel (104), determine the state of the intercepted qubits, and send the qubits to the receiving node; the quantum computing system being configured to use the receiving node to evaluate a second metric, and to use the quantum circuit system to evaluate a first metric by intercepting at least qubits on the quantum channel; determining whether the second metric satisfies a fault tolerance threshold and whether the first metric satisfies an attack success threshold; and terminating the communication protocol if the second metric satisfies the fault tolerance threshold and the first metric satisfies the attack success threshold.