Reward reception method, reward payment method, entanglement generation device, user device, entanglement quantum key delivery system, entanglement generation method, and private key generation method

A reward receiving method for entanglement generators in quantum key distribution systems addresses the issue of uncompensated entanglement sources and reward theft by using verified modulated entangled states, ensuring fair compensation and security.

JP2025167830APending Publication Date: 2025-11-07MITSUBISHI ELECTRIC CORP +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024072775
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-26
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

In existing quantum key distribution systems, the entanglement source (C) is not compensated for its services, and there is a risk of reward theft by other sources mimicking the entanglement generation.

Method used

Implement a reward receiving method where the entanglement generator sends modulated entangled states with random numbers, and upon verification, receives a reward if the evidence keys match, ensuring proper compensation and preventing reward theft.

Benefits of technology

The method ensures the entanglement source is compensated and prevents reward theft, enhancing security and fairness in quantum key distribution systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025167830000001_ABST
    Figure 2025167830000001_ABST
Patent Text Reader

Abstract

To solve the problem that, in an entanglement quantum key delivery system, an entanglement source which provides an entanglement state desires to obtain fees for providing the entanglement state without intercepted by the other entanglement source.SOLUTION: In a reward reception method which is executed in an entanglement quantum key delivery system, when a communication is executed between a first user device and a second user device based on a result of measuring a first random number group and a first modulation entanglement state, in a case where a first evidence key and a second evidence key are matched, an entanglement generation device receives a reward to sending the first modulation entanglement state from the first user device. The first evidence key is a key which is generated by the entanglement generation device on the basis of a second random number group and a result of the second user device measuring a second modulation entanglement state. The second evidence key is a key which is generated by the first user device on the basis of a random number for confirmation and a result of the first user device measuring the second modulation entanglement state.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a reward receiving method, a reward payment method, an entanglement generating device, a user device, an entanglement quantum key distribution system, an entanglement generating method, and a private key generating method. [Background technology]

[0002] Quantum Key Distribution (QKD) is a type of quantum technology that allows a pair of users (user A and user B) at two remote locations to share a secret key for use in encryption. Quantum mechanics, one of the laws of physics, guarantees that the secret key will not be leaked, regardless of any new technologies that may emerge in the future. Security guaranteed by quantum mechanics in this way is defined as "information-theoretic security." According to this term, quantum key distribution is a quantum technology that allows a pair of users at two remote locations to share an information-theoretically secure private key. Information-theoretic security is often also called "unconditional security." Furthermore, the method of encrypted communication using Vernam's one-time pad with a private key provided by quantum key distribution is defined as quantum cryptography. In contrast, the security of modern cryptography, i.e., the cryptographic methods already in widespread use today, relies on the assumption that "certain mathematical problems should be unsolvable." Security that relies on this assumption is called computational security. Therefore, modern cryptography can be broken by the emergence of new types of computers or algorithms. In fact, many modern cryptography methods have been broken in the past. In terms of the likelihood of the code being broken, quantum cryptography is clearly more secure than modern cryptography. In a typical quantum key distribution embodiment, communication between user A and user B is performed via a single line. On the other hand, there is a modified quantum key distribution embodiment called "entangled quantum key distribution." In "entangled quantum key distribution," in addition to user A and user B who share a secret key, there is a third party called the "entanglement source," C. The entanglement source C sends an "entangled state" to user A and user B. By utilizing the entangled state, user A and user B can double the communication distance of quantum key distribution compared to when the entangled state is not used (for example, non-patent document 1). Although the entanglement source is often misunderstood as being difficult to implement, it can actually be implemented using current technology. There have been various implementation reports on the entanglement source since the 2000s. [Prior art documents] [Non-patent literature]

[0003] [Non-Patent Document 1] Feihu Xu, Xiongfeng Ma, Qiang Zhang, Hoi-Kwong Lo, and Jian-Wei Pan, “Secure quantum key distribution with realistic devices,” Reviews of Modern Physics 92,025002 (American Physical Society, 2020). Summary of the Invention [Problem to be solved by the invention]

[0004] If the situation in the background art is compared to a mobile phone, the entangled state is radio waves or communication lines, and C, which provides the entangled state, is a communication carrier. Furthermore, among A, B, and C, the device with the highest implementation cost is C (the entanglement source). The implementation cost of A and B devices (receivers) is often lower than that of C device. In existing technology, C is unilaterally providing services to A and B, but C has the problem of not being able to receive any reward from A and B. To be more precise, User A and User B in the background art cannot identify the source of the entanglement state they received. Therefore, User A and User B may pay a reward to an entanglement source that is different from the actual entanglement source. If we describe this problem from the perspective of User C, there is a possibility that the reward for the entanglement state generated by User A and User B may be stolen by another user. The purpose of this disclosure is to achieve the following two security features by making minor modifications to existing entanglement quantum key distribution schemes. Function A: The entanglement source that provided the appropriate circuit (entanglement state) gets a fee. Function B: Preventing royalties from being stolen by other sources of entanglement. [Means for solving the problem]

[0005] The reward receiving method according to the present disclosure includes: an entanglement generator included in an entanglement quantum key distribution system that performs entanglement quantum key distribution sends a first modulated entangled state obtained by modulating a first entangled state using a first random number set consisting of one or more random numbers, and a second modulated entangled state obtained by modulating a second entangled state using a second random number set consisting of one or more random numbers, to a first user device and a second user device included in the entanglement quantum key distribution system, and communication is performed between the first user device and the second user device based on the first random number set and a result of measuring the first modulated entangled state, a first evidence key generated by the entanglement generator based on a verification random number, the second random number set, and a result of measurement of the second modulated entanglement state by the second user device; If the verification random number matches a second evidence key generated by the first user device based on the measurement result of the second modulation entanglement state by the first user device, The entanglement generator receives a reward from the first user device for sending the first modulated entangled state. [Effects of the Invention]

[0006] According to the present disclosure, a reward receiving method is realized in which, when communication is performed between a first user device and a second user device based on a first random number set and a result of measuring the first modulated entangled state, if the first evidence key and the second evidence key match, the entanglement generating device receives a reward from the first user device for sending the first modulated entangled state. The reward receiving method is realized by making a slight modification to an existing entanglement quantum key distribution scheme. Therefore, according to the present disclosure, the above two security functions can be realized by making minor modifications to existing entanglement quantum key distribution schemes. [Brief explanation of the drawings]

[0007] [Figure 1] FIG. 1 is a diagram showing an example of the configuration of an entanglement quantum key distribution system 90 according to a first embodiment. [Figure 2] FIG. 1 is a diagram showing an example of the hardware configuration of an entanglement generating device 100 according to a first embodiment. [Figure 3] FIG. 2 is a diagram for explaining an outline of the operation of the entanglement quantum key distribution system 90 according to the first embodiment. [Figure 4] FIG. 2 is a diagram for explaining the operation of the entanglement quantum key distribution system 90 according to the first embodiment. [Figure 5] FIG. 10 is a diagram showing an example of the hardware configuration of an entanglement generating device 100 according to a modification of the first embodiment. [Figure 6] FIG. 10 is a diagram for explaining the operation of the entanglement quantum key distribution system 90 according to the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0008] In the description of the embodiments and the drawings, the same elements and corresponding elements are given the same reference numerals. The description of elements given the same reference numerals will be omitted or simplified as appropriate. Arrows in the drawings mainly indicate the flow of data or the flow of processing. Furthermore, "unit" may be read as "circuit," "step," "procedure," "process," or "circuitry" as appropriate.

[0009] Embodiment 1 Hereinafter, this embodiment will be described in detail with reference to the drawings. In this embodiment, a method for realizing a security function (triple quantum key distribution) is disclosed. In this embodiment, the objective is to enable switching among three types of key sharing functions: key sharing between user-AB, user-BC, and user-CA (hereinafter referred to as “AB QKD,” “BC QKD,” and “CA QKD,” respectively). User-AB is a pair of user A and user B. User-BC is a pair of user B and entanglement source C. User-CA is a pair of entanglement source C and user A. More precisely, in this embodiment, even after quantum communication is completed, it is permitted to decide which quantum key distribution to perform among AB QKD, BC QKD, and CA QKD. Then, after completing quantum communication, the quantum key distribution can be actually realized by performing different classical data processing on the result of the quantum communication depending on which quantum key distribution to perform. Note that in this specification, user A, user B, and entanglement source C may be simply referred to as “A,” “B,” and “C,” respectively. "User A" may refer to the device used by user A, i.e., the first user device. "User B" may refer to the device used by user B, i.e., the second user device. Note that "User A" may be considered the second user device, and "User B" may be considered the first user device. As a concrete example, if BC QKD is chosen, A, B, and C perform classical data processing corresponding to BC QKD, and only B and C possess the secret key k BC Then, each user other than B and C gets the secret key k BCIn other words, not only an external eavesdropper, but also A and the private key k BC Furthermore, if AB QKD or CA QKD is selected as the quantum key distribution method, the same applies as in this example. In other words, the following statement is valid when the symbols A, B, and C are arbitrarily substituted for each other in this example.

[0010] ***Configuration Description*** In this embodiment, a function for performing passive modulation and classical data processing is added to a device that employs a conventional entanglement quantum key distribution scheme. Because the modifications according to this embodiment are easy to make, the advantage of entanglement quantum key distribution, that is, "it can be implemented using current technology," is not lost in this embodiment.

[0011] FIG. 1 shows an example of the configuration of an entanglement quantum key distribution system 90 according to this embodiment. The entanglement quantum key distribution system 90 performs entanglement quantum key distribution, and includes an entanglement generating device 100 and two user devices 200. The multiple devices included in the entanglement quantum key distribution system 90 are communicably connected. The entanglement generating device 100 may be referred to as "C." The two user devices 200 may be referred to as "A" and "B," respectively.

[0012] The entanglement generator 100 is an entanglement source and includes a quantum communication unit 110, an information processing unit 120, and a classical communication unit .

[0013] The quantum communication unit 110 has a function of generating an entangled state and a function of performing quantum communication. The quantum communication unit 110 generates a random number set consisting of one or more random numbers, modulates an entangled state using the random number set to generate a modulated entangled state, and sends the modulated entangled state to the first user device and the second user device. The random number set and a measurement result of the modulated entangled state are used to generate a private key for quantum key distribution. At least one of the first user device, the second user device, and the entanglement generating device 100 determines whether the measurement result of the modulated entangled state is used in communication between the first user device and the second user device or in communication between the entanglement generating device 100 and the first user device.

[0014] The information processing unit 120 has a function of executing classical data processing. When it is determined that the measurement results of the modulation entanglement state are to be used in communication between the first user device and the second user device, the information processing unit 120 makes the random number set public to the first user device and the second user device. When it is decided that the measurement result of the modulated entangled state will be used in communication between the entanglement generating device 100 and the first user device, the information processing unit 120 generates a verification random number, discloses the verification random number to the first user device, and generates a secret key for quantum key distribution based on the set of random numbers, the verification random number, and the measurement result of the modulated entangled state disclosed by the second user device.

[0015] The classical communication unit 130 has a function of executing classical communication.

[0016] The user device 200 includes a quantum communication unit 210, an information processing unit 220, and a classical communication unit 230.

[0017] The quantum communication unit 210 has a function of receiving and measuring a quantum state. The quantum communication unit 210 measures a modulated entangled state. A specific example of the quantum state is a qubit state.

[0018] The information processing unit 220 is similar to the information processing unit 120 . When it is decided that the measurement results of the modulated entangled state will be used in communication between the user device 200 and the second user device, the information processing unit 220 generates a private key for quantum key distribution based on the random number set made public by the entanglement generating device 100 and the measurement results of the modulated entangled state. When it is decided that the measurement result of the modulated entangled state will be used in communication between the entanglement generating device 100 and the user device 200, the information processing unit 220 generates a private key for quantum key distribution based on the verification random number made public by the entanglement generating device 100 and the measurement result of the modulated entangled state.

[0019] The classical communication unit 230 is similar to the classical communication unit 130 .

[0020] 2 shows an example of the hardware configuration of the entanglement generator 100 according to this embodiment. The entanglement generator 100 is hardware that functions as an entanglement source and is composed of hardware including a computer. The entanglement generator 100 may also be composed of multiple computers.

[0021] As shown in the figure, the entanglement generator 100 is a computer equipped with hardware such as a processor 11, a memory 12, an auxiliary storage device 13, a quantum communication device 14, and a classical communication device 15. These pieces of hardware are appropriately connected via signal lines 19.

[0022] The processor 11 is an integrated circuit (IC) that performs arithmetic processing and controls the hardware of the computer. Specific examples of the processor 11 include a central processing unit (CPU), a digital signal processor (DSP), or a graphics processing unit (GPU). The entanglement generator 100 may include multiple processors that replace the processor 11. The multiple processors share the role of the processor 11.

[0023] The memory 12 is typically a volatile storage device, specifically a random access memory (RAM). The memory 12 is also called a primary storage device or a main memory. Data stored in the memory 12 is saved in the secondary storage device 13 as needed.

[0024] The auxiliary storage device 13 is typically a non-volatile storage device, and specific examples thereof include a ROM (Read Only Memory), an HDD (Hard Disk Drive), or a flash memory. Data stored in the auxiliary storage device 13 is loaded into the memory 12 as needed. The memory 12 and the auxiliary storage device 13 may be integrated into one unit.

[0025] The quantum communication unit 110 is realized by the quantum communication device 14, which generates an entangled state and performs quantum communication.

[0026] The classical communication device 15 is a receiver and a transmitter. Specific examples of the classical communication device 15 include a communication chip or a NIC (Network Interface Card).

[0027] The auxiliary storage device 13 stores an entanglement quantum key distribution program. The entanglement quantum key distribution program is a program that causes a computer to realize the functions of each unit included in the entanglement generating device 100. The entanglement quantum key distribution program is loaded into the memory 12 and executed by the processor 11. The functions of each unit included in the entanglement generating device 100 are realized by software.

[0028] Data used when executing the entanglement quantum key distribution program and data obtained by executing the entanglement quantum key distribution program are stored in a storage device as appropriate. Each part of the entanglement generating device 100 uses a storage device as appropriate. Specific examples of the storage device include at least one of the memory 12, the auxiliary storage device 13, a register in the processor 11, and a cache memory in the processor 11. Note that the terms "data" and "information" may have the same meaning. The storage device may be independent of the computer. The functions of the memory 12 and the auxiliary storage device 13 may be realized by other storage devices.

[0029] The entanglement quantum key distribution program may be recorded on a computer-readable non-volatile recording medium. Specific examples of the non-volatile recording medium include an optical disk, a magnetic disk, and a flash memory. The entanglement quantum key distribution program may be provided as a program product.

[0030] The hardware configuration of the user device 200 is similar to that of the entanglement generating device 100, except for the quantum communication unit 110. The quantum communication device 14 included in the user device 200 does not generate or transmit an entangled state, but measures the quantum state (including the entangled state).

[0031] ***Explanation of Operation*** The operating procedures of each device included in the entanglement quantum key distribution system 90 are collectively referred to as an entanglement quantum key distribution method. Also, the programs that realize the operations of each device included in the entanglement quantum key distribution system 90 are collectively referred to as an entanglement quantum key distribution program.

[0032] 3 is a diagram for explaining an outline of the operation of entanglement quantum key distribution. With reference to FIG. 3, an outline of the difference between the operation of this embodiment and the operation of the prior art will be explained.

[0033] (Difference in step S1) In conventional entanglement quantum key distribution, C always sends one type of entangled state. On the other hand, in this embodiment, random modulation is applied to the entangled state. More precisely, C generates a random number and then sends an entangled state specified by the value of the generated random number. Here, the types of entangled states corresponding to the values ​​of the generated random numbers are different from each other.

[0034] (Difference in step S2) Step S2 is the same as conventional entanglement quantum key distribution: A and B each receive half of the entangled state and measure the received entangled state.

[0035] Steps S1 and S2 are sometimes called the "quantum communication phase" in the sense that they are steps that require the transmission and reception of quantum states. On the other hand, step S3 is a step that does not require any transmission or reception of quantum states. In other words, step S3 can be realized only by classical data processing, that is, by existing communications such as the Internet and calculations by existing computers. Therefore, step S3 is sometimes called the "classical data processing phase" (classical communication phase). In the quantum communication phase consisting of steps S1 and S2, the same operations are performed regardless of whether AB QKD, CA QKD, or BC QKD is used for quantum key distribution. Furthermore, the data obtained by A, B, and C in the quantum communication phase contains information that is sufficient to support any of the selected quantum key distribution methods, AB QKD, CA QKD, or BC QKD. Even after the quantum communication phase is over, each of A, B, and C can select any of the quantum key distributions (AB QKD, CA QKD, and BC QKD) and can actually execute the selected quantum key distribution by changing the processing in the classical data processing phase depending on the selected quantum key distribution.

[0036] (Difference in step S3) Each of A, B, and C performs classical data processing according to the selected type of quantum key distribution (AB QKD, BC QKD, or CA QKD). As a specific example, if BC QKD is selected for quantum key distribution, A, B, and C each perform classical data processing corresponding to BC QKD, and only B and C possess the private key k BC And k_BC is unknown to anyone other than B and C. In other words, it is completely unknown to A, as well as to any external eavesdroppers. The same is true when AB QKD or CA QKD is selected as the quantum key distribution method. In other words, the wording in the previous paragraph in which the symbols A, B, and C are arbitrarily substituted is also valid. As a result, the operation shown in FIG. 4 is realized.

[0037] 4 is a diagram illustrating the operation of the entanglement quantum key distribution system 90. Details of the operation will be described below with reference to FIG. In the Bennett-Brassard-Mermin 1992 (BBM92) system (Reference 1), which is one of the entanglement quantum key distribution systems, the process shown in Fig. 3 is carried out. In this embodiment, the operation is modified as follows.

[0038] [Reference 1] Charles H. Bennett, Gilles Brassard, and N. David Mermin, “Quantum cryptography without Bell's theorem,” Physical Review Letters 68,557 (American Physical Society, 1992).

[0039] [Quantum communication phase] Each of A, B, and C repeats the following steps S1 and S2 n times, where n is any natural number.

[0040] (Step S1: Sending entangled state by C) This step is a modified version of step S1 of the BBM92 method shown in FIG. In the BBM92 method, C generates a Bell state, which is a type of entangled state, and sends half of the generated Bell state to A and half to B. [Equation 1] shows the Bell state.

[0041]

number

[0042] Here, we will organize the symbols used in quantum mechanics. Note that due to restrictions on the number of characters that can be used, notations different from those used in mathematical formulas may be used in the text. In [Math 1], |0> and |1> are orthonormal vectors in a two-dimensional complex vector space. In quantum mechanics, states are represented by vectors. Therefore, vectors are also called states. The two states {|0>, |1>} form a basis, and these two states are also specifically called the Z basis. The two states {|0~>, |1~>} are called the X basis. Here, "0~" means the number 0 with a superscript tilde attached. "1~" is the same as "0~". The meaning of the superscript tilde is as shown in [Math 2].

[0043]

number

[0044] The symbol of two intersecting lines in a circle represents a tensor product. For example, the first term of [Equation 3] indicates that parts A and B are both in the 0 state, and the second term of [Equation 3] indicates that parts A and B are both in the 1 state.

[0045]

number

[0046] |β 00 > ABrepresents a superposition of two states, the 0 state and the 1 state. When a state cannot be written as a single tensor product, the state is said to be entangled. As a concrete example, each term shown in [Equation 3] can be written as a single tensor product, so it is not entangled. On the other hand, |β 00 > AB cannot be written as a single tensor product, so they are "entangled." In this embodiment, this procedure is modified as follows.

[0047] (Process 1) The quantum communication unit 110 of C is in the state |β 00 > AB Generate.

[0048] (Process 2) The quantum communication unit 110 of C selects values ​​for each of the random number bits h, x, and z, where h, x, z∈{0, 1}.

[0049] (Process 3) When z=1, the quantum communication unit 110 of C performs a phase flip (Z operator) in the Z basis on the A part of the state at hand.

[0050] (Process 4) When x=1, the quantum communication unit 110 of C performs a bit flip (X operator) in the Z basis on the A part of the state at hand.

[0051] (Process 5) When h=1, the quantum communication unit 110 of C performs a transformation (Hadamard transformation, H operator) on the A part of the state at hand to swap the Z basis and the X basis.

[0052] (Process 6) The quantum communication unit 110 of C sends half of the state obtained by executing the above process to user A and half to user B. That is, the quantum communication unit 110 of C is in the state |β 00 > AB Instead of sending the state |β 00 >AB In other words, the quantum communication unit 110 of C randomly selects h, x, z∈{0, 1} and sends the entangled state corresponding to the combination of selected values ​​to each of A and B, that is, sends the entangled state shown in [Equation 4]. The entangled state sent is one of eight types of entangled states. The entangled state shown in [Equation 4] corresponds to a modulated entangled state. h, x, and z correspond to each random number that makes up the random number set.

[0053]

number

[0054] Currently, the entangled state is often implemented using the polarization state of light. As a specific example, it is possible to implement |0> as the vertical polarization state (oscillation in the 0-degree direction) of a single photon, and |1> as the horizontal polarization state (oscillation in the 90-degree direction) of a single photon. In this implementation, the above operations mean the following: Each of the A and B portions refers to a separate single photon. The first term in [Equation 3] indicates that both parts A and B are in a vertically polarized state. The second term in [Equation 3] indicates that both parts A and B are in a horizontally polarized state. "State | β 00 > AB "Generating" means generating a superposition state of the first term of [Equation 3] and the second term of [Equation 3] by a method such as parametric down-conversion. "Phase flip in the Z basis (Z operator)" means to invert the phase of only the horizontal polarization state (switch the sign of the coefficient of the vector component). "Bit flip in Z basis (X operator)" means rotating by 90 degrees, that is, swapping vertical and horizontal polarization. The "Hadamard transform (H operator)" means rotating the direction of polarization by 45 degrees by the action of an element or by rotating a device. In other words, it means changing vertically polarized light into either right-diagonal (45 degrees) polarization or left-diagonal (135 degrees) polarization. "Sending half of the obtained state to user A and half to user B" means that part A and part B, which are single photons generated and manipulated by quantum communication unit 110 of C, are sent to user A and user B, respectively, via optical fiber or the like.

[0055] (Step S2: Measurement by A and B) This step is the same as the step S2 of the BBM92 method shown in FIG. The quantum communication units 210 of A and B each measure the received state in the same way as in the BBM92 method. That is, A and B each randomly select either the Z basis or the X basis, measure the received state in the selected basis, and express the measurement result as b A ,b B ∈{0,1}. The process of this step is described more specifically as follows:

[0056] The quantum communication unit 210 of A receives the bit h A ∈{0,1} at random, and then set the reception state as h A Measure at the base and measure the result as b A ∈{0,1}. The quantum communication unit 210 of B receives the bit h B ∈{0,1} at random, and then set the reception state as h B Measure at the base and measure the result as b B ∈{0,1}. Here, the Z basis and the X basis are written as the 0 basis and the 1 basis, respectively. This notation will be used hereafter.

[0057] The data obtained in the above n times of steps S1 and S2 is r=(r1,...,r n ) where r is called the "result." i =(hi ,x i ,z i ,h Ai ,b Ai ,h Bi ,b Bi ) where i is an integer between 1 and n.

[0058] The operations up to this point are called the quantum communication phase, as they require the sending and receiving of quantum states. Furthermore, the operations up to this point are the same regardless of whether quantum key distribution is performed using AB QKD, CA QKD, or BC QKD.

[0059] When a device is implemented using the polarization state of light, the above operation means the following. "Measurement in Z basis (0 basis)" means that the measurement determines whether the photon is in a vertically or horizontally polarized state, where the result is b=0 when vertical polarization is measured, and b=1 when horizontal polarization is measured. "Measurement in X basis (1 basis)" means that the photon is rotated 45 degrees (Hadamard transformation) and then measured in Z basis (0 basis). This also means that the measurement determines whether the photon is in a right-angle (45 degrees) or left-angle (135 degrees) polarization state. In this case, if right-angle polarization is measured, the result is b=0, and if left-angle polarization is measured, b=1.

[0060] [Classical data processing phase] The following processing does not require any transmission or reception of quantum states. Furthermore, the following processing is classical data processing, that is, processing that can be realized only through existing communications such as the Internet and processing by existing computers. Therefore, the following processing is called the classical data processing phase. In the classical data processing phase, first, it is decided which quantum key distribution to perform from among AB QKD, CA QKD, and BC QKD. Then, depending on the decision, one of the following steps S3-AB, S3-CA, and S3-BC is performed. As a specific example, which quantum key distribution to perform is decided based on a discussion between at least two parties: user A, user B, and entanglement light source C. Note that these three steps correspond to modified processes equivalent to step S3 of the BBM92 method shown in Figure 3.

[0061] (Step S3-AB: Classical data processing phase for AB QKD) When the result r is used in AB QKD, A, B, and C each perform the following classical data processing.

[0062] (Process 1: Preliminary classical data processing) Each device performs the following process for i=1,...,n. (a) The information processing unit 120 of C is i and x i and z i Each of these will be made public.

[0063] (b) The information processing unit 220 of A receives raw key data h Ai ' and raw key data b Ai Each of the above is calculated using the formula shown in [Number 5]. Note that the equal signs in [Number 5], [Number 6], [Number 7], and [Number 8] below all refer to the remainder when divided by the integer 2. In other words, "modulo 2" is abbreviated in these equations.

[0064]

number

[0065] (Process 2: Final classical data processing) The information processing unit 220 of each of A and B is h Ai ' and b Ai ' and h Bi and b Bi(i=1,...,n) is regarded as a raw key in the BB84 method (see Reference 2 for an example), and the secret key k is obtained by performing error rate estimation and key distillation in the same way as BB84. AB That is, the information processing units 220 of A and B generate a secret key for quantum key distribution based on the random number set made public by the entanglement generator 100 and the measurement result of the modulated entangled state. In the final classical data processing, an authenticated public communication channel is used for communication between A and B.

[0066] [Reference 2] Masahito Hayashi and Toyohiro Tsurumaru, “Concise and tight security analysis of the Bennett-Brassard 1984 protocol with finite key lengths,”New Journal of Physics 14,093014(2012).

[0067] (Step S3-CA: Classical data processing phase for CA QKD) When the result r is used in CA QKD, A, B, and C each perform the following classical data processing.

[0068] (Process 1: Preliminary classical data processing) Each device performs the following process for i=1,...,n. (a) The information processing unit 220 of B is h Bi and b Bi Each of these will be made public.

[0069] (b) The information processing unit 120 of C generates random number bits s i Generate s i After that, the information processing unit 120 of C releases the raw key data h Ci ' and raw key data b Ci ' is calculated using the formula shown in [Equation 6]. i corresponds to the random number for verification.

[0070]

number

[0071] (c) The information processing unit 220 of A receives raw key data h Ai ' and raw key data b Ai ' and are calculated using the formula shown in [Equation 7].

[0072]

number

[0073] (Process 2: Final classical data processing) Each of the information processing unit 120 of C and the information processing unit 220 of A is h Ci ' and b Ci ' and h Ai ' and b Ai '(i=1,...,n) is regarded as a raw key of the BB84 system, and the secret key k is obtained by performing error rate estimation and key distillation in the same way as the BB84 system. CA That is, the information processing unit 120 of C generates a private key for quantum key distribution based on the random number set, the verification random number, and the measurement result of the modulated entangled state made public by the second user device. Also, the information processing unit 220 of A generates a private key for quantum key distribution based on the verification random number made public by the entanglement generating device 100 and the measurement result of the modulated entangled state. In the final classical data processing, an authenticated public communication channel is used for communication between CAs.

[0074] (Step S3-BC: Classical data processing phase for BC QKD) When the result r is used in BC QKD, each of A, B, and C exchanges all symbols A in the "Classical data processing for CA QKD" described above with symbols B, and performs the preliminary classical data processing in the "Classical data processing phase for CA QKD" Ci The classical data processing is performed by changing the equation of ' to [Equation 8].

[0075]

number

[0076] ***Explanation of the effect of the first embodiment*** This embodiment alone can provide the effect of reducing wasteful quantum communication in quantum key distribution. More details are as follows. Generally, quantum communication has the property that its communication speed is overwhelmingly slower than that of classical communication. Therefore, practical quantum key distribution systems are operated in a way that does not impair user convenience due to this property. Specifically, in this operation, quantum communication is constantly performed to generate a private key, regardless of whether or not User A and User B request encrypted communication, and the generated private key is stored. Then, in this operation, the stored private key is handed over when User A and User B actually request encrypted communication. However, this operation has a problem in that if user A and user B do not perform secure communication such as quantum cryptography communication, all of the quantum communication that has been performed in advance will be wasted. On the other hand, in this embodiment, the results of quantum communication that are not used by user A and user B can be diverted to either BC QKD or CA QKD. As a result, according to this embodiment, the utilization rate of quantum communication can be improved in terms of the long-term average value. In other words, according to this embodiment, it is possible to reduce the waste of quantum communication.

[0077] Here, the intuitive reason why the present embodiment can actually realize three types of quantum key distribution, AB QKD, BC QKD, and CA QKD, will be described.

[0078] (AB QKD reasons) In step S1, the Bell state (|β 00 > AB ) for the A part of the random unitary transformation (H h X x Z z ) A is applied. In step S3-AB-processing 1-(a), the random unitary transformation (H h X x Z z ) A The types of random bits, that is, random bit h, random bit x, and random bit z, are made public. Therefore, A is the random unitary transformation (H h X x Z z ) A By applying the inverse transformation of h X x Z z ) A Furthermore, the inverse transformation is equivalent to the interpretation of the result of the processing performed by A in step S3-AB-processing 1-(b). As a result, the situation is such that C is 00 > AB ", and A and B each send out "|β 00 > AB This is equivalent to performing a BB84 measurement on the generated private key k AB It can be said that there is information-theoretic security in

[0079] (CA QKD reasons) First, as can be seen from a simple calculation, in reality, "C is in state |α hxz > AB In step S2, B is sent. hxz > AB By measuring the result h B and b B The situation where "C obtains the parameter h B and b B Generate a BB84 state specified by h X x Z zFurthermore, the calculations of C and A in step S3-CA are performed using the random transformation H h X x Z z This is equivalent to calculating backwards and nullifying the effect of Therefore, the situation is equivalent to the BB84 protocol between CAs. CA It can be said that there is information-theoretic security in The reasons for BC QKD are similar to those for CA QKD.

[0080] ***Other Configurations*** <Variation 1> FIG. 5 shows an example of the hardware configuration of the entanglement generating device 100 according to this modification. The entanglement generator 100 includes a processing circuit 18 in place of the processor 11, the processor 11 and memory 12, the processor 11 and auxiliary storage device 13, or the processor 11, memory 12, and auxiliary storage device 13. The processing circuit 18 is hardware that realizes at least a part of the components of the entanglement generating device 100 . The processing circuitry 18 may be dedicated hardware or may be a processor that executes a program stored in the memory 12 .

[0081] When processing circuitry 18 is dedicated hardware, processing circuitry 18 may be, for example, a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof. The entanglement generator 100 may include multiple processing circuits that replace the processing circuit 18. The multiple processing circuits share the role of the processing circuit 18.

[0082] In the entanglement generator 100, some functions may be realized by dedicated hardware, and the remaining functions may be realized by software or firmware.

[0083] Processing circuitry 18 is illustratively implemented in hardware, software, firmware, or a combination thereof. The processor 11, memory 12, secondary storage device 13, and processing circuit 18 are collectively referred to as "processing circuitry." In other words, the functions of each functional component of entanglement generator 100 are realized by the processing circuitry. The entanglement generating device 100 according to other embodiments may also have the same configuration as this modified example. The user device 200 may include a processing circuit 18 as in this modification.

[0084] Embodiment 2 The following mainly describes the differences from the above-described embodiment with reference to the drawings.

[0085] ***Configuration Description*** The configuration of the entanglement quantum key distribution system 90 according to this embodiment is the same as that of the entanglement quantum key distribution system 90 according to the first embodiment. That is, this embodiment is realized by adding a function to perform passive modulation and classical data processing to a conventional entanglement quantum key distribution device. Note that this modification is easy, and therefore, in this embodiment, the advantage of entanglement quantum key distribution, that is, "it can be implemented using current technology," is not impaired.

[0086] In this embodiment, a reward receiving method is realized in which the entanglement generating device 100 sends a first modulated entangled state and a second modulated entangled state to a first user device and a second user device, and when communication is performed between the first user device and the second user device based on a first random number set and the first modulated entangled state, if the first evidence key and the second evidence key match, the entanglement generating device 100 receives a reward from the first user device for sending the first modulated entangled state. Also, in this case, a reward payment method is realized in which the first user device pays the entanglement generating device 100 a reward for sending the first modulated entangled state. The first modulated entangled state is an entangled state generated by modulating the first entangled state using a first random number set consisting of one or more random numbers. The second modulated entangled state is an entangled state generated by modulating the second entangled state using a second random number set consisting of one or more random numbers. The first evidence key is a key generated by the entanglement generator 100 based on the verification random number, the second random number set, and the result of measurement of the second modulated entangled state by the second user device. The second evidence key is a key generated by the first user device based on the verification random number and the result of measurement of the second modulated entangled state by the first user device. The reward received by the entanglement generator 100 is also a reward for realizing encrypted communication between A and B.

[0087] The quantum communication unit 110 according to this embodiment generates a first random number set consisting of one or more random numbers, and generates a first modulated entangled state by modulating an entangled state using the first random number set. The quantum communication unit 110 generates a second random number set consisting of one or more random numbers, and generates a second modulated entangled state by modulating the entangled state using the second random number set. The quantum communication unit 110 transmits the first modulated entangled state and the second modulated entangled state to a first user device and a second user device.

[0088] The processing of the information processing unit 120 is described below when the first user device determines that the measurement results of the first modulation entangled state will be used in communication between the entanglement generating device 100 and the first user device, and when the first user device determines that the measurement results of the second modulation entangled state will be used in communication between the entanglement generating device 100 and the first user device. First, the information processing unit 120 makes the first random number set public to the first user device. Next, the information processing unit 120 generates a verification random number and makes the verification random number public to the first user device. Next, the information processing unit 120 generates a first secret key based on error rate estimation and key distillation using the second random number set, the verification random number, and the measurement result of the second modulated entangled state made public by the second user device. Next, if the second private key and the first private key match, the information processing unit 120 receives a reward from the first user device for sending the first modulated entangled state. The second private key is a key generated by the first user device based on error rate estimation and key distillation using the verification random number and the result of measuring the second modulated entangled state by the first user device. The first private key corresponds to the first evidence key. The second private key corresponds to the second evidence key.

[0089] ***Explanation of Operation*** 6 is a diagram illustrating an example of the operation of the entanglement quantum key distribution system 90 according to this embodiment. The operation of the entanglement quantum key distribution system 90 according to this embodiment is the same as the operation of the entanglement quantum key distribution system 90 according to the first embodiment, but with the following modifications.

[0090] [Random Allocation Phase] A random assignment phase (random assignment phase) is added between the quantum communication phase and the classical data processing phase. The information processing unit 220 of A converts each result of the quantum communication phase into r AB and r for CA QKD CATo be precise, user A randomly assigns each integer from 1 to n to one of two groups (I AB and I CA ) Therefore, I AB ∪I CA ={1,…,n} and I AB ∩I CA =φ (φ is the empty set). Below, I AB The result r with index i belongs to i The arrangement of these is r AB Also, I CA result r with subscript j belonging to j The arrangement of these is r CA Let's say.

[0091] [Classical data processing phase (modified from embodiment 1)] The information processing unit 220 of each of A and B outputs the result r AB By performing step S3-AB on the secret key k AB get. Each of the information processing unit 120 of C and the information processing unit 220 of A receives the result r CA By performing step S3-CA on the private key k CA get.

[0092] [Reward exchange phase] The reward exchange phase (information exchange phase) is added after the classical data processing phase. The information processing unit 120 of C issues a secret key k CA Present the following. If the following conditions are met, the information processing unit 220 of A will pay a reward to C. Note that the k presented by C CA corresponds to the first evidence key. CA corresponds to the second evidence key. When this condition is met, the first evidence key and the second evidence key match. Condition: "The k presented by C CA is the k calculated by the information processing unit 220 of A. CA It matches up with

[0093] ***Explanation of the effect of the second embodiment*** According to this embodiment, the following two security functions can be realized by making slight modifications to the existing entanglement quantum key distribution scheme. Function A: The entanglement source that provided the appropriate circuit (entanglement state) gets a fee. Function B: Preventing royalties from being stolen by other sources of entanglement.

[0094] The reason why the security functions A and B are achieved by the configuration and operation of this embodiment is as follows. First, it is generally true that "in order for the quantum key distribution protocol to be completed to obtain the private key, the estimated error rate calculated by the 'error rate estimation step' within the quantum key distribution protocol must be below a threshold." Furthermore, in this embodiment, "r AB and r CA is chosen randomly, the estimated error rates calculated within AB QKD and CA QKD agree within the range of statistical error. Therefore, in this embodiment, it can be said that "CA QKD is successful only if AB QKD is successful." Therefore, according to this embodiment, security function A is established. Furthermore, due to the nature of quantum key distribution, the secret key k obtained by CA QKD CA is unknown to anyone other than A and C." Therefore, according to this embodiment, security function B is established. To put the above in intuitive terms, "private key k CA In other words, if someone has a secret key k CA If someone presents a statement, it is guaranteed that "the person in question indeed generated the entangled state that A and B received."

[0095] Embodiment 3 The following mainly describes the differences from the above-described embodiment.

[0096] ***Configuration Description*** The configuration of the entanglement quantum key distribution system 90 according to this embodiment is the same as the configuration of the entanglement quantum key distribution system 90 according to the second embodiment.

[0097] The information processing unit 120 according to this embodiment does not generate a first secret key, but generates a first sieve key using a second random number group, a verification random number, and the measurement result of the second modulated entangled state made public by the second user device. Furthermore, when the second sieve key and the first sieve key match, the information processing unit 120 receives a reward from the first user device for sending the first modulated entangled state. The second sieve key is a key generated by the first user device using the verification random number and the result of the first user device measuring the second modulated entangled state. The first sieve key corresponds to the first evidence key and plays a role similar to the first secret key in the second embodiment. The second sieve key corresponds to the second evidence key and plays a role similar to the second secret key in the second embodiment.

[0098] Here, we will explain the processing of the information processing unit 120 when the first user device decides to use the measurement results of the first modulation entangled state in communication between the entanglement generating device 100 and the first user device, and when the first user device decides to use the measurement results of the second modulation entangled state in communication between the entanglement generating device 100 and the first user device. First, the information processing unit 120 makes the first random number set public to the first user device and the second user device. Next, the information processing unit 120 generates a verification random number and makes the verification random number public to the first user device. Next, the information processing unit 120 generates a first sieve key using the second random number set, the verification random number, and the measurement result of the second modulated entangled state made public by the second user device. Next, if the second sieve key and the first sieve key match, the information processing unit 120 receives a reward from the first user device for sending the first modulated entangled state.

[0099] ***Explanation of Operation*** [Classical data processing phase] The classical data processing phase according to this embodiment is a process of the classical data processing phase according to the second embodiment, in which the result r CA This is a process in which the processing for is changed as follows: Each device produces the result r CA However, each device only performs process 1 of step S3-CA and does not perform process 2 of step S3-CA.

[0100] [Reward exchange phase] The reward exchange phase according to this embodiment is as follows.

[0101] (Process 1) The information processing unit 120 of C presents to A a sieve key in CA QKD.

[0102] (Process 2) If the following conditions are met, A pays a reward to C. The sieve key presented by C corresponds to the first evidence key. The sieve key calculated by A's information processing unit 220 corresponds to the second evidence key. If the conditions are met, the first evidence key and the second evidence key are consistent. Condition: "The error rate between the sieve key presented by C and the sieve key calculated by A's information processing unit 220 in CA QKD is equal to the estimated error rate calculated in AB QKD."

[0103] ***Explanation of the effect of the third embodiment*** According to this embodiment, in addition to the effects of the above-described embodiment, neither C nor A performs key distillation in step S3-CA, which significantly reduces the load on each of C and A in the classical data processing phase.

[0104] Also, obviously, from the general construction of quantum key distribution, anyone who can present a sieve key can run a key distillation algorithm to obtain the private key k CA Therefore, the sieve key is k CA Similarly, this is evidence that the person has created the entangled state. Therefore, the same effect as in the second embodiment can be obtained in this embodiment.

[0105] ***Other embodiments*** The above-described embodiments may be freely combined, or any of the components in each embodiment may be modified, or any of the components in each embodiment may be omitted. Furthermore, the embodiments are not limited to those shown in Embodiments 1 to 3, and various modifications are possible as needed. The procedures explained using the drawings etc. may be modified as appropriate. [Explanation of symbols]

[0106] 11 processor, 12 memory, 13 auxiliary storage device, 14 quantum communication device, 15 classical communication device, 18 processing circuit, 19 signal line, 90 entanglement quantum key distribution system, 100 entanglement generator, 110 quantum communication unit, 120 information processing unit, 130 classical communication unit, 200 user device, 210 quantum communication unit, 220 information processing unit, 230 classical communication unit.

Claims

1. an entanglement generator included in an entanglement quantum key distribution system that performs entanglement quantum key distribution sends a first modulated entangled state obtained by modulating a first entangled state using a first random number set consisting of one or more random numbers, and a second modulated entangled state obtained by modulating a second entangled state using a second random number set consisting of one or more random numbers, to a first user device and a second user device included in the entanglement quantum key distribution system, and communication is performed between the first user device and the second user device based on the first random number set and a result of measuring the first modulated entangled state, a first evidence key generated by the entanglement generator based on a verification random number, the second set of random numbers, and a result of measurement of the second modulated entanglement state by the second user device; If the verification random number matches a second evidence key generated by the first user device based on the result of measuring the second modulation entanglement state by the first user device, A reward receiving method in which the entanglement generator receives a reward from the first user device for sending the first modulated entangled state.

2. an entanglement generator included in an entanglement quantum key distribution system that performs entanglement quantum key distribution sends a first modulated entangled state obtained by modulating a first entangled state using a first random number set consisting of one or more random numbers, and a second modulated entangled state obtained by modulating a second entangled state using a second random number set consisting of one or more random numbers, to a first user device and a second user device included in the entanglement quantum key distribution system, and communication is performed between the first user device and the second user device based on the first random number set and the first modulated entangled state; a first evidence key generated by the entanglement generator based on a verification random number, the second set of random numbers, and a result of measurement of the second modulated entanglement state by the second user device; If the verification random number matches a second evidence key generated by the first user device based on the result of measuring the second modulation entanglement state by the first user device, A reward payment method in which the first user device pays a reward to the entanglement generator for sending the first modulated entangled state.

3. An entanglement generating device is provided in an entanglement quantum key distribution system that is a system that performs entanglement quantum key distribution, the entanglement generating device including a first user device and a second user device, a quantum communication unit that generates a random number group consisting of one or more random numbers, generates a modulated entangled state by modulating an entangled state using the random number group, and transmits the modulated entangled state to the first user device and the second user device; An entanglement generating device comprising: An entanglement generator in which the random number set and the measurement result of the modulated entangled state are used to generate a private key in quantum key distribution.

4. determining whether to use a result of measuring the modulation entanglement state in communication between the first user device and the second user device or in communication between the entanglement generator and the first user device, by at least one of the first user device, the second user device, and the entanglement generator; The entanglement generating device further comprises: When it is determined that a result of measuring the modulation entanglement state is to be used in communication between the first user device and the second user device, the random number set is made public to the first user device and the second user device; an information processing unit that, when it is determined that the measurement result of the modulated entangled state is to be used in communication between the entanglement generating device and the first user device, generates a verification random number, discloses the verification random number to the first user device, and generates a private key for quantum key distribution based on the random number set, the verification random number, and the measurement result of the modulated entangled state disclosed by the second user device. The entanglement generating device of claim 3, comprising:

5. the quantum communication unit generates a first random number group consisting of one or more random numbers, generates a first modulated entangled state by modulating an entangled state using the first random number group, generates a second random number group consisting of one or more random numbers, generates a second modulated entangled state by modulating the entangled state using the second random number group, and sends the first modulated entangled state and the second modulated entangled state to the first user device and the second user device; When the first user device determines that the result of measuring the first modulation entangled state will be used in communication between the entanglement generator and the first user device, and when the first user device determines that the result of measuring the second modulation entangled state will be used in communication between the entanglement generator and the first user device, The information processing unit disclosing the first random number set to the first user device; generating the verification random number, disclosing the verification random number to the first user device, and generating a first secret key based on error rate estimation and key distillation using the second random number set, the verification random number, and the measurement result of the second modulation entanglement state disclosed by the second user device; 5. The entanglement generating device of claim 4, wherein a second secret key generated by the first user device based on error rate estimation and key distillation using the verification random number and the result of the first user device measuring the second modulated entangled state matches the first secret key, and receives a reward from the first user device for sending the first modulated entangled state.

6. the quantum communication unit generates a first random number group consisting of one or more random numbers, generates a first modulated entangled state by modulating an entangled state using the first random number group, generates a second random number group consisting of one or more random numbers, generates a second modulated entangled state by modulating the entangled state using the second random number group, and sends the first modulated entangled state and the second modulated entangled state to the first user device and the second user device; When the first user device determines that the result of measuring the first modulation entangled state will be used in communication between the entanglement generator and the first user device, and when the first user device determines that the result of measuring the second modulation entangled state will be used in communication between the entanglement generator and the first user device, The information processing unit disclosing the first random number group to the first user device and the second user device; generating the verification random number, disclosing the verification random number to the first user device, and generating a first sieve key using the second set of random numbers, the verification random number, and a measurement result of the second modulation entanglement state disclosed by the second user device; 5. The entanglement generating device of claim 4, wherein if a second sieve key generated by the first user device using the verification random number and the result of the first user device measuring the second modulated entangled state matches the first sieve key, the entanglement generating device receives a reward from the first user device for sending the first modulated entangled state.

7. A system including an entanglement generating device and a second user device, the user device being included in an entanglement quantum key distribution system that performs entanglement quantum key distribution, the system including: the entanglement generator generates a random number group consisting of one or more random numbers, modulates an entangled state using the random number group to generate a modulated entangled state, and sends the modulated entangled state to the user device and the second user device; the random number set and the measurement result of the modulated entangled state are used to generate a secret key in quantum key distribution; When it is determined by at least one of the user device, the second user device, and the entanglement generator whether to use the result of measuring the modulated entangled state in communication between the user device and the second user device, or in communication between the entanglement generator and the user device, a quantum communication unit that measures the modulated entangled state; when it is determined that the measurement result of the modulated entangled state is to be used in communication between the user device and the second user device, generating a private key for quantum key distribution based on the random number set published by the entanglement generator and the measurement result of the modulated entangled state; an information processing unit that generates a private key for quantum key distribution based on a verification random number published by the entanglement generator and the measurement result of the modulated entangled state when it is determined that the measurement result of the modulated entangled state is to be used in communication between the entanglement generator and the user device; A user device comprising:

8. A method of manufacturing a vehicle comprising the entanglement generating device according to any one of claims 3 to 6, An entanglement quantum key distribution system comprising the user device according to claim 7 as the first user device.

9. An entanglement generating method performed by an entanglement generating device included in an entanglement quantum key distribution system, the entanglement quantum key distribution system including a first user device and a second user device, the entanglement generating method comprising: the entanglement generator generates a random number set consisting of one or more random numbers, modulates an entangled state using the random number set to generate a modulated entangled state, and sends the modulated entangled state to the first user device and the second user device; The random number set and the measurement result of the modulated entangled state are used in an entanglement generation method for generating a private key in quantum key distribution.

10. A private key generation method executed by a user device included in an entanglement quantum key distribution system, the system including an entanglement generator and a second user device, the system performing entanglement quantum key distribution, the method comprising: the entanglement generator generates a random number group consisting of one or more random numbers, modulates an entangled state using the random number group to generate a modulated entangled state, and sends the modulated entangled state to the user device and the second user device; the random number set and the measurement result of the modulated entangled state are used to generate a secret key in quantum key distribution; When it is determined by at least one of the user device, the second user device, and the entanglement generator whether to use the result of measuring the modulated entangled state in communication between the user device and the second user device, or in communication between the entanglement generator and the user device, The user device: measuring the modulated entangled state; when it is determined that the measurement result of the modulated entangled state is to be used in communication between the user device and the second user device, generating a private key for quantum key distribution based on the random number set published by the entanglement generator and the measurement result of the modulated entangled state; A private key generation method for generating a private key for quantum key distribution based on a verification random number published by the entanglement generator and the measurement result of the modulated entangled state when it is decided to use the measurement result of the modulated entangled state in communication between the entanglement generator and the user device.