Multi-party quantum key distribution system and method

The multi-party quantum key distribution system addresses the challenge of generating high-quality entangled states by using ultra-weak coherent pulses to securely share keys among multiple nodes, achieving secure key generation without entangled states.

JP2025092159APending Publication Date: 2025-06-19NIPPON TELEGRAPH & TELEPHONE CORP +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2023207869
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-08
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

Existing multi-party quantum key distribution systems face challenges in generating high-quality multi-photon entangled states, which are necessary for secure key sharing among multiple nodes, due to the complexity and low probability of generating such states.

Method used

A multi-party quantum key distribution system that uses ultra-weak coherent pulses with an average photon number of less than 1 photon/pulse and a phase difference of either 0 or π between adjacent pulses, allowing for secure key generation without relying on multi-photon entangled states.

Benefits of technology

This approach enables secure key sharing among multiple nodes in a single signal transmission and reception, ensuring the security of the generated secret key without the need for complex entangled state generation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025092159000001_ABST
    Figure 2025092159000001_ABST
Patent Text Reader

Abstract

To provide a system and a method for distributing a common secret key to three or more parties in single transmission and reception of signals without using a multiphoton quantum entanglement state.SOLUTION: A multi-party quantum key distribution system includes a transmission node that broadcasts phase-modulated very weak coherent pulse strings to a plurality of reception nodes, and a plurality of reception nodes that is connected to the transmission node in a star type topology state. The reception node comprises: an interferometer that branches the transmitted coherent pulse strings, has a delay time equal to the interval between the coherent pulse strings, and has a transmission phase difference of 0; a first photon detector and a second photon detector that detects photons output from the interferometer; and a second control unit that shares information on the photons detected by the photon detectors with the other reception node. The transmission node and the reception nodes generate a secret key bit from a phase difference commonly measured by the reception nodes, of the phase difference between adjacent pulses measured by the reception nodes.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a cryptographic system, and more specifically, to a multi-party quantum key distribution system for delivering a secret key to a plurality of three or more nodes.

Background Art

[0002] As a system for securely supplying a common secret key for encrypting / decrypting communication data to two parties performing cryptographic communication, research and development of quantum cryptography or quantum key distribution (QKD) has been underway. Further, as an extended version of this, research on multi-party QKD for supplying a common secret key to three or more parties has also been underway.

[0003] A direct method of extending two-party QKD to multiple parties is a method in which one central node individually shares a secret key with other terminal nodes by two-party QKD, and the central node encrypts and transmits a common secret key to the terminal nodes using the secret key.

[0004] However, in this method, two-party QKD is performed as the first step, and the procedure for finally obtaining a common secret key is complicated. Therefore, research on multi-party QKD in which multiple nodes obtain a common secret key by a single signal transmission / reception using a special quantum state called quantum entanglement has been underway. Non-Patent Document 1 describes a technique for implementing multi-party QKD using quantum entanglement. Hereinafter, a general quantum key distribution system and a common secret key distribution system using a quantum entanglement state will be briefly described.

[0005] A quantum entanglement state is a quantum state composed of a plurality of quanta (for example, photons) having special correlation characteristics. As a typical example, a two-photon state represented by the following Equation 1 in quantum mechanical notation can be mentioned.

[0006]

Equation

[0007] In Equation 1, |H> represents a one-photon state with horizontal linear polarization, and |V> represents a one-photon state with vertical linear polarization. The subscripts {1, 2} indicate {Photon 1, Photon 2} respectively. Also, |H>1|H>2 represents that both photons have horizontal linear polarization, and |V>1|V>2 represents that both photons have vertical linear polarization.

[0008] The state represented by Equation 1 is a quantum superposition state of |H>1|H>2 and |V>1|V>2. Before observation, it is indefinite whether it is |H>1|H>2 or |V>1|V>2, but when observed, it is observed as one of the two states.

[0009] The state represented by Equation 1 is a two-photon entangled state. As an extended version, an N-photon entangled state represented by the following Equation 2 can be considered.

[0010]

Equation

[0011] In conventional multi-party QKD, such an N-photon entangled state is used to share a common secret key.

[0012] In the known technology, a single central node (for example, a transmitting node) generates an N-photon entangled state as represented by Equation 2 and transmits each photon to N receiving nodes respectively. The receiving nodes measure the transmitted photon states. The measurement result will be either horizontal linear polarization or vertical linear polarization. Due to the correlation characteristics of the entangled state, if the measurement result at one receiving node is horizontal linear polarization, the measurement results of all other receiving nodes will also be horizontal linear polarization; if it is vertical linear polarization, the measurement states of all other receiving nodes will also be vertical linear polarization. That is, the measurement results at all receiving nodes are the same.

[0013] Therefore, if the measurement result is horizontal linear polarization, it is regarded as bit 0, and if it is vertical linear polarization, it is regarded as bit 1. By doing so, the same bit value can be obtained at all receiving nodes. If this entangled state transmission and reception is repeated the necessary number of times, all receiving nodes will obtain the same bit sequence. This is used as the common secret key.

[0014] The security of the secret key shared as described above is guaranteed by being generated from the transmission and reception of quantum entangled states. In order for all receiving nodes to share the secret key, it is necessary for each receiving node to receive and measure one photon each. Here, in order for an external eavesdropper to know the key bit value, the photon being transmitted needs to be stolen and its state measured. However, a photon is the smallest unit of light and cannot be divided further. Therefore, if an eavesdropper steals a photon, that photon will not reach the receiving node and the secret key will not be generated. In other words, if all receiving nodes receive and measure photons and a common secret key is generated, it can be considered that there was no eavesdropping on the transmission signal. Based on such a principle, it can be said that the generated secret key is secure.

Prior Art Documents

Non-Patent Documents

[0015]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0016] In the above prior art, a common secret key is shared by transmitting and receiving a multi-photon entangled state. However, it is not easy to actually generate such a quantum state. Usually, an optical nonlinear phenomenon called parametric down conversion is used to generate an entangled photon state. This is a phenomenon in which one pump photon is converted into a pair of signal photons and idler photons. According to the law of conservation of energy, the converted signal photons and idler photons have quantum correlation characteristics. By utilizing this, first, a plurality of two-photon entangled states are generated, and then they are combined to generate a multi-photon entangled state. However, in order to obtain a high-quality entangled state, it is necessary to construct a complex and highly controlled optical system. In addition, the original photon conversion process is a probabilistic phenomenon, and high-quality entangled states are generated only with a low probability.

Means for Solving the Problem

[0017] The quantum key distribution system according to an embodiment of the present disclosure is a transmitting node that broadcasts a sequence of ultra-weak coherent pulses having an average photon number of less than 1 photon / pulse and a phase difference between adjacent pulses of either 0 or π to a plurality of receiving nodes by a first control unit in order to provide a multi-party quantum key, a plurality of receiving nodes that are connected to the transmitting node in a star topology and receive the transmitted coherent pulse sequence, the receiving device branches the transmitted coherent pulse sequence, an interferometer having a delay time equal to the interval of the coherent pulse sequence and a transmission phase difference of 0, a first photon detector and a second photon detector that detect photons output from the interferometer, and a second control unit that records information related to the photons detected by the first photon detector and the second photon detector in association with either the first photon detector or the second photon detector that detected the photons and shares it with other receiving nodes. The transmitting node and the receiving nodes provide a system that generates secret key bits from the phase differences commonly measured by each receiving node among the phase differences between adjacent pulses measured by the receiving nodes.

[0018] Using a quantum key distribution system according to an embodiment of the present disclosure, in order to provide a multi-party quantum key, a transmitting node generates an ultra-weak coherent pulse train with an average photon number of less than 1 photon / pulse and a phase difference between adjacent pulses being either 0 or π; the transmitting node broadcasts the generated coherent pulse train to a plurality of receiving nodes; detecting the coherent pulse trains branched and superimposed by an interferometer; a plurality of receiving nodes generating bits based on the phase difference of the detected coherent pulse trains; notifying all nodes of the coherent pulse trains; selecting bits by leaving bits generated from the same pulses as other receiving nodes and discarding inconsistent bits; and the transmitting node generating bits based on the phase difference of the detected coherent pulse trains. A method is provided that includes these steps.

Advantages of the Invention

[0019] As described above, according to the present invention, a multi-party quantum key distribution system can be provided that delivers a common secret key to three or more parties in a single signal transmission and reception without using a multi-photon entangled state.

Brief Description of the Drawings

[0020]

Figure 1

Figure 2

Figure 3

Embodiments for Carrying Out the Invention

[0021] Hereinafter, this embodiment will be described in detail with reference to the drawings. In the following description, the same or similar reference numerals indicate the same or similar elements, and repeated description may be omitted.

[0022] (First Embodiment) FIG. 1 shows the configuration of the multi-party quantum key distribution system 100 in the embodiment. As shown in the figure, the multi-party quantum key distribution system 100 is configured with a network topology including a plurality of nodes. As an example, the network topology may be a star topology.

[0023] The multi-party quantum key distribution system 100 shown in FIG. 1 includes one transmitting node 110 and a plurality of receiving nodes, for example, a first receiving node 130 and a second receiving node 150. Further, quantum channels (Quantum Channel: Q.C) 160A and 160B for communicating between the transmitting node and the plurality of receiving nodes are provided. In FIG. 1, among the receiving nodes 130 and 150, the internal configuration of the second receiving node 150 is shown, but the first receiving node 130 has the same configuration as the second receiving node 150.

[0024] The transmitting node 110 includes a coherent pulse light source 111, a phase modulator 113, and an optical attenuator 115. Further, the transmitting node 110 includes a first control unit 117 that controls the coherent pulse light source 111 and the phase modulator 113, and further controls communication with the receiving nodes 130 and 150.

[0025] The coherent pulse light source 111 generates a coherent optical pulse train (hereinafter referred to as "signal light"). As an example, the coherent pulse light source 111 is a laser light source and continuously generates, for example, a rectangular pulse train. According to the laser light source, it is possible to obtain coherent light having good coherence. The generated signal light is output from the output stage of the coherent pulse light source 111 and input to the input stage of the phase modulator 113.

[0026] The phase modulator 113 modulates the phase of the input signal light to a phase of 0 or π. Here, the phase modulated by the phase modulator 113 (i.e., the phase modulation amount) can be used as modulation information for generating a common secret key without being communicated or shared later. The phase-modulated signal light is output from the output stage of the phase modulator 113 and input to the input stage of the optical attenuator 115. The input signal light passes through the optical attenuator 115 and is set so that the average number of photons is less than 1 photon per pulse (e.g., 0.1 photon / pulse), and is broadcast to each receiving node, for example, the first receiving node 130 and the second receiving node 150. Although not shown in FIG. 1, in order to broadcast to a plurality of receiving nodes, optical branching components such as an optical coupler, a half mirror, or a beam splitter may be used.

[0027] The signal light attenuated by the optical attenuator 115 is transmitted to each receiving node 130, 150 via the first quantum channel 160A and the second quantum channel 160B, respectively. The signal light becomes a digital signal according to the pulse and is also referred to as a continuous coherent pulse train 170.

[0028] The receiving nodes 130, 150 have the same configuration. Hereinafter, the configuration of the receiving node 150 will be described instead of the description of the receiving node 130. The receiving node 150 includes a delay Mach-Zehnder interferometer 151, a first photon detector 155A for detecting photons, and a second photon detector 155B. Further, the receiving nodes 130, 150 include a second control unit 157 that records the photons detected by the detectors 155A, 155B in association with these detectors and controls communication with other transmitting and receiving nodes.

[0029] The delay Mach-Zehnder interferometer 151 includes a first half mirror which is a splitter 153A that splits the transmitted continuous coherent pulse train 170, and a second half mirror which is a combiner 153B that combines and interferes the non-delayed pulse train and the delayed pulse train branched by the splitter 153A. The pulse trains incident on the combiner 153B are combined and interfered, and are emitted to two paths. However, in this embodiment, the splitting and combining of the pulse trains are not limited to being performed using half mirrors, and a beam splitter may also be used.

[0030] Also, in the delay Mach-Zehnder interferometer 151, the propagation phase difference between the two paths branched by the splitter 153A is set to 0, and the delay time is equal to the pulse interval in the continuous coherent pulse train 170.

[0031] At the output stage of the delay Mach-Zehnder interferometer 151, a first photon detector 155A and a second photon detector 155B for detecting photons according to the phase difference of the continuous coherent pulse train 170 in which adjacent two pulses interfere with each other are provided in the combiner 153B.

[0032] In such a receiving node 150, the continuous coherent pulse train 170 transmitted from the transmitting node 110 is input to the delay Mach-Zehnder interferometer 151, and is branched into two in the delay Mach-Zehnder interferometer 151, and one of them is time-delayed so as to shift by one pulse. The non-delayed continuous coherent pulse train 170 and the delayed continuous coherent pulse train 170 overlap in the combiner 153B and interfere with each other. As a result, adjacent two pulses interfere with each other, and photons are detected by the photon detectors 155A and 155B according to the phase difference. However, since the average number of photons per pulse of the pulse train is attenuated to less than 1 by the optical attenuator 115, the probability that photons are detected by the photon detectors 155A and 155B at the receiving node 150 is sufficiently low and is random.

[0033] Figure 2 is a table showing the relationship between the adjacent pulse phase difference and the detector that detects photons. Each transmitted pulse is randomly phase - modulated with either 0 or π, and the phase difference between adjacent pulses is measured on the receiving side. The table shown in Figure 2 indicates the numbers of the photon detectors shown in Figure 1 in the left - most column and shows the phase differences of the pulses in the second row. According to the table, for example, when the phase difference between adjacent pulses is 0, photons are detected by the first photon detector 155A, and when the phase difference between adjacent pulses is π, photons are detected by the second photon detector 155B.

[0034] In the last row of the table shown in Figure 2, the receiving node 150 indicates the bits to be generated based on the information of the photon detector that detected the photons. At the receiving node 150, if the measured phase difference between adjacent pulses is 0, the bit is 0, and if it is π, the bit is 1. Then, at the receiving node 150, the information related to the photon and the photon detector that detected this photon are associated, and the value of the bit is recorded in the second control unit 157. For error checking, a part of the bits may be made public to estimate the amount of error. In this case, the public bits are discarded, and the rest are used for generating the secret key.

[0035] The information related to the photon may be, for example, information based on the timing of photon detection. Also, at other receiving nodes, for example, at the first receiving node 130, bits can be generated in the same way, and a table like that in Figure 2 can be generated.

[0036] Next, each receiving node 130, 150 notifies all nodes of the pulses detected by photons using an arbitrary communication channel (not shown), for example, a classical channel. Then, the bits generated from the same pulses as those of other receiving nodes are left, and the inconsistent bits are discarded.

[0037] On the other hand, the transmitting node 110 generates bit 0 if the phase difference applied to the adjacent pulses detected by all receiving nodes is 0, and generates bit 1 if it is π. The bit sequence generated in this way is the same at the transmitting node 110 and all receiving nodes 130, 150. This is used as the common secret key.

[0038] (Second Embodiment) Hereinafter, with reference to FIGS. 1 to 3, a method 300 for sharing a multi-party quantum key using the above-described multi-party quantum key distribution system 100 will be described. FIG. 3 is a flowchart showing a method for sharing a quantum key among a plurality of nodes 110, 130, and 150.

[0039] The transmitting node 110 includes a coherent pulse light source 111, a phase modulator 113, an optical attenuator 115, and a first control unit 117, and the coherent pulse light source 111 generates signal light (step 330). The generated signal light is output from the output stage of the coherent pulse light source 111 and input to the input stage of the phase modulator 113.

[0040] The phase modulator 113 modulates the phase of the input signal light to a phase of 0 or π (step 350). The phase-modulated signal light is output from the output stage of the phase modulator 113 and input to the input stage of the optical attenuator 115. The input signal light is set to have an average photon number of less than 1 photon per pulse (for example, 0.1 photon / pulse) through the optical attenuator 115 (step 370).

[0041] Next, the phase-modulated ultra-weak signal light is broadcast to each receiving node, for example, the first receiving node 130 and the second receiving node 150, as a coherent pulse train 170 via quantum channels 160A and 160B provided between the transmitting node and the plurality of receiving nodes (step 390).

[0042] Each receiving node includes a delay Mach-Zehnder interferometer 151, a first photon detector 155A for detecting photons, and a second photon detector 155B. The delay Mach-Zehnder interferometer 151 branches the input continuous coherent pulse train 170 and overlaps adjacent two pulses (step 313).

[0043] If the phase difference between the above two adjacent pulses is 0, photons are detected by the first photon detector 155A; if it is π, photons are detected by the second photon detector 155B (step 315). However, since the number of photons in the pulse train is very small, photon detection is rare and random in time.

[0044] After that, if the measured phase between adjacent pulses is 0, the receiving nodes 130 and 150 generate bit 0; if it is π, they generate bit 1 (step 317), and record the value of the bit in the second control unit 157 (step 319). For error checking, a part of the bits may be made public to estimate the amount of error. In this case, the public bits are discarded and the rest are used for generating the secret key.

[0045] Next, each receiving node 130, 150 notifies all nodes of the detected photons (step 321), selects bits generated from the same pulses as other receiving nodes, and discards the inconsistent bits (step 323).

[0046] On the other hand, if the phase difference applied to the adjacent pulses detected by all receiving nodes is 0, the transmitting node 110 generates bit 0; if it is π, it generates bit 1 (step 325). Although the step of the transmitting node 110 generating bits is described last, each receiving node may perform this step at the same time as or before step 317 of generating bits.

[0047] The bit sequence generated in this way is the same at the transmitting node and all receiving nodes. This is used as the common secret key.

[0048] The security of the secret key shared by the above system and method is guaranteed by the fact that the number of photons in the coherent pulse train 170 transmitted and received is very small. For an external eavesdropper to know the key bits, a part of the coherent pulse train transmitted from the transmitting node to the receiving node needs to be branched to measure the phase difference between adjacent pulses. However, since the number of photons in the pulse train is very small, it is rare and random to measure the phase difference.

[0049] Although the pulse - to - pulse phase difference in which the private - key bits are generated rarely or accidentally may be measured, the probability is less than 1, and the probability of being eavesdropped by a part - split from the average number of photons of the transmitted pulses can be quantitatively estimated.

[0050] Therefore, by a data compression operation called privacy amplification, the number of key bits that may have been eavesdropped is deleted. Then, the private key after privacy amplification becomes a secure one that has not leaked externally.

[0051] (Additional Considerations) The foregoing description of the embodiments of the present invention has been presented for purposes of illustration and is not intended to be exhaustive or to limit the invention to the precise form disclosed. Those skilled in the art will appreciate that many modifications and variations are possible in light of the above disclosure.

[0052] Finally, the language used herein has been selected primarily for readability and for the purpose of illustration and may not have been selected to describe or limit the subject matter of the invention. Accordingly, the scope of the invention is intended to be limited not by this detailed description but by the appended claims. Thus, the disclosure of the embodiments of the present invention is intended to illustrate, but not to limit, the scope of the invention as set forth in the claims.

Industrial Applicability

[0053] According to the multi - party quantum key distribution system and method described above, without using multi - photon entanglement states, a multi - party quantum key distribution system can be provided that distributes a common private key to three or more parties in a single signal transmission and reception.

Explanation of Signs

[0054] 100 Multi - party quantum key distribution system 110 Transmitting node 111 Coherent pulse light source 113 Phase modulator 115 Optical Attenuator 117 First Control Unit 130 First Receiving Node 150 Second Receiving Node 151 Interferometer 153A Splitter 153B Combiner 155A First Photon Detector 155B Second Photon Detector 157 Second Control Unit 160A First Quantum Channel 160B Second Quantum Channel 170 Coherent Pulse Train

Claims

1. A multi-party quantum key distribution system, comprising: A transmitting node that broadcasts a super-weak coherent pulse train having an average photon number of less than 1 photon / pulse and a phase difference between adjacent pulses of either 0 or π to a plurality of receiving nodes by a first control unit; The plurality of receiving nodes connected to the transmitting node in a star topology and receiving the transmitted coherent pulse train; The receiving node includes: An interferometer that branches the transmitted coherent pulse train, has a delay time equal to the interval of the coherent pulse train, and a transmission phase difference of 0; A first photon detector and a second photon detector that detect photons output from the interferometer; A second control unit that records information related to the photons detected by the first photon detector and the second photon detector in association with either the first photon detector or the second photon detector that detected the photons, and shares the information with other receiving nodes; The transmitting node and the receiving node generate secret key bits from the phase differences commonly measured by each receiving node among the phase differences between adjacent pulses measured by the receiving node. A multi-party quantum key distribution system characterized by the above.

2. The interferometer is a Mach-Zehnder interferometer, and includes a splitter that splits the input coherent pulse train, a non-delayed pulse train among the coherent pulse trains split by the splitter, and a combiner that combines and interferes the non-delayed pulse train with a delayed pulse train having a delay with respect to the non-delayed pulse train. The first photon detector and the second photon detector detect the photons according to the phase difference between the non-delayed pulse train and the delayed pulse train that interfere in the combiner. The multi-party quantum key distribution system according to claim 1.

3. The transmitting node includes a laser light source that emits light for generating the coherent pulse train. The multi-party quantum key distribution system according to claim 1 or 2.

4. A method for delivering a quantum key among multiple parties, comprising: a step in which a transmitting node generates an ultra-weak coherent pulse train having an average photon number of less than 1 photon / pulse and a phase difference between adjacent pulses being either 0 or π; a step in which the transmitting node broadcasts the generated coherent pulse train to a plurality of receiving nodes; a step of detecting the coherent pulse train branched and superimposed by an interferometer; a step in which the plurality of receiving nodes generate bits based on the phase difference of the detected coherent pulse train; a step of notifying all nodes of the detected coherent pulse train; a step of selecting bits, leaving bits generated from the same pulses as those of other receiving nodes and discarding inconsistent bits; a step in which the transmitting node generates bits based on the phase difference of the detected coherent pulse train; and the method includes the above steps.

5. The method according to claim 4, wherein the step in which the transmitting node generates bits is performed simultaneously with or before the step in which the plurality of receiving nodes generate bits.