Authentication utilizing quantum entanglement swapping and key sharing method

A novel protocol using a trusted third party in quantum communication networks authenticates new users and shares encryption keys securely by controlling optical separators and photon signals, addressing vulnerabilities in existing quantum communication systems.

JP2025176853APending Publication Date: 2025-12-05NAT INST OF INFORMATION & COMM TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024083210
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-22
Publication Date
2025-12-05

AI Technical Summary

Technical Problem

Existing quantum communication networks face challenges in authenticating new users and sharing encryption keys securely, particularly in scenarios where Bell measurements can only be performed correctly at specific locations, and are vulnerable to attacks like quantum teleportation.

Method used

A novel protocol using a trusted but not highly competent third party (Tom) to authenticate new users and share encryption keys by controlling optical separators and photon signals in a quantum communication network, employing photon-pair quantum entanglement swapping.

Benefits of technology

Enables secure authentication and key sharing with new users even in scenarios where Bell measurements are only possible correctly, achieving minimal conversion to classical information and enhancing security against attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025176853000001_ABST
    Figure 2025176853000001_ABST
Patent Text Reader

Abstract

To provide an authentication of a person capable of performing accurate measurement and declaration thereof in a quantum communication network of a quantum entanglement swapping node, etc., a method and a system for performing key sharing with the person by an unprecedented protocol.SOLUTION: In a system which performs a quantum communication, an authentication unit 17 controls a light separation section 21, and a first intra-node user 11 and a second intra-node user 13 respectively output a first photon signal and a second photon signal. A third intra-node user 15 detects the first photon signal and the second photon signal which pass the light separation section 21 and notifies the first intra-node user 11 and the second intra-node user 13 of a detection result. The authentication unit 17 notifies the first intra-node user 11 and the second intra-node user 13 of control information of the light separation section. The first intra-node user 11 and the second intra-node user 13 use the detection result and the control information to authenticate the third intra-node user 15.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an authentication and key sharing method using quantum entanglement swapping. [Background technology]

[0002] The goal of position-based cryptography (PBC) is for honest parties to use spatiotemporal locations as authorized entities in cryptographic protocols. In particular, location verification aims to verify that a specific party, known as a prover, possesses a specific location in space and time. PBC has been actively researched in classical settings, and it has been shown that information-theoretic security is impossible to achieve in the standard model (Non-Patent Document 1). However, the same paper provides a secure structure using a constrained retrieval model, a variant of the constrained storage model. Attempts have also been made to overcome this no-go theorem using quantum technology. For example, quantum key distribution and the sharing of co-random numbers using quantum entanglement with EPR pairs are functions not available in classical systems, and security studies using these are currently underway. Kent et al. published a paper on PBC using quantum technology in 2002, describing attacks against quantum structures (Non-Patent Document 2). Malaney also proposed a verification function in the following Non-Patent Document 3.

[0003] Furthermore, Lau and Lo demonstrated the possibility of implementing PBC using causality (Non-Patent Document 4), but Buhrman et al. (Non-Patent Document 6) showed that an attacker capable of quantum teleportation could spoof the EPR pair (Non-Patent Document 5) in advance, proving that information-theoretically secure implementation is impossible. Meanwhile, efforts are continuing to prove the computational security of PBC against currently known attack methods, such as proposing protocols that require exponential EPR pairs, but no progress has been made in improving PBC to achieve information-theoretically secure implementation.

[0004] Japanese Patent No. 5911097 describes a single-photon detector that detects single photons in a quantum key distribution system. In a quantum communication network such as a quantum key distribution system, it is not easy to properly authenticate a new user (terminal). [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Patent No. 5911097 [Non-patent literature]

[0006] [Non-Patent Document 1] N. Chandran, V. Goyal, R. Moriarty, and R. Ostrovsky, in Advances in Cryptology-CRYPTO 2009 (Springer, New York, 2009), pp. 391-407. [Non-patent document 2] A. Kent, WJ Munro, and TP Spiller, Phys. Rev. A 84, 012326 (2011). [Non-patent document 3] RAMalaney, inProceedings of the IEEE Global Telecommunications Conference (GLOBECOM 2010) (IEEE, 2010), pp. 1-6. [Non-patent document 4] H.-K. Lau and H.-K. Lo, Phys. Rev. A 83, 012322 (2011). [Non-patent document 5] Einstein A, Podolsky B and Rosen N 1935 Can quantum-mechanical description of physical reality be considered complete? Phys. Rev. 47 777-80 [Non-patent document 6] H. Buhrman, N. Chandran, S. Fehr, R. Gelles, V. Goyal, R. Ostrovsky, and C. Schaffner, in Advances in Cryptology-CRYPTO 2011 (Springer, New York, 2011), pp. 429-446. Summary of the Invention [Problem to be solved by the invention]

[0007] The object of this invention is to provide a method for authenticating a person who can make an accurate measurement and declare it, and for sharing a key with that person using a novel protocol in a quantum communication network such as a quantum entanglement swapping node. [Means for solving the problem]

[0008] This invention is based on the finding that by providing a reliable but not highly capable authentication unit in a quantum communication network and adjusting the photon signals output from two already authenticated users (terminals), authentication of a new user (terminal) and key sharing in the quantum communication network can be performed using a new protocol.

[0009] The first invention is a method for authenticating a third node user 15 (Charlie) in a network in which a first node user 11 (Alice) and a second node user 13 (Bob) are authenticated. The third intra-node user 15 (Charlie) can receive photon signals (e.g., signals using quantum entangled photons) output from the first intra-node user 11 (Alice) and the second intra-node user 13 (Bob) via the optical separation unit 21. The method then includes the following steps: The authentication unit 17 (Tom) controls the optical separator 21 to be in the first state. The first photon signal and the second photon signal output from the first intra-node user 11 (Alice) and the second intra-node user 13 (Bob), respectively, pass through the optical demultiplexer 21, which is in the first state. The third intra-node user 15 (Charlie) detects the first photon signal and the second photon signal that have passed through the optical separator 21, and obtains the detection result. The user 15 (Charlie) in the third node notifies the user 11 (Alice) in the first node and the user 13 (Bob) in the second node of the detection result (detection result notification step). After the detection result notification step, the authentication unit 17 (Tom) notifies the first intra-node user 11 (Alice) and the second intra-node user 13 (Bob) of control information relating to the control of the optical demultiplexer. The first node user 11 (Alice) and the second node user 13 (Bob) use the detection result and the control information to authenticate the third node user 15 (Charlie). This method relates to the authentication of a party by so-called Bell measurement.

[0010] In a preferred example of the above method, a third intra-node user 15 (Charlie) has a first photon detection unit 31 (e.g., a first arm and detectors a, b) and a second photon detection unit 41 (e.g., a second arm and detectors c, d). The detection result is information about the ground state of a single photon detected by the first photon detecting unit 31 and the second photon detecting unit 41.

[0011] In a preferred example of the above method, the light separating unit 21 includes a half-wave plate (HWP) 23 that changes polarization, and a beam splitter 25 through which light passes after passing through the half-wave plate 23. The authentication unit 17 (Tom) controls the light separating unit 21 by rotating the half-wave plate 23.

[0012] The second invention relates to a method for sharing an encryption key with a third node user 15 (Charlie) in a network in which a first node user 11 (Alice) and a second node user 13 (Bob) are authenticated and share an encryption key.

[0013] The method includes the following steps: Based on the first invention, a user 15 (Charlie) in a third node is authenticated. The authentication unit 17 (Tom) controls the light separating unit 21 to make the light separating unit 21 transparent. The third photon signal and the fourth photon signal output from the first intra-node user 11 (Alice) and the second intra-node user 13 (Bob), respectively, pass through the transparent optical separator 21. The third intra-node user 15 (Charlie) controls the first photon detection unit 31 (first arm and detectors a, b) and the second photon detection unit 41 (second arm and detectors c, d) to measure different bases, and then detects the third photon signal and the fourth photon signal that have passed through the optical separation unit 21 to obtain a second detection result. The first intra-node user 11 (Alice) and the second intra-node user 13 (Bob) measure the third photon signal and the fourth photon signal to obtain their own measurement results. The third node user 15 (Charlie) notifies the first node user 11 (Alice) and the second node user 13 (Bob) of the second detection result (second detection result notification step). After the second detection result notification process, the authentication unit 17 (Tom) notifies the first node user 11 (Alice) and the second node user 13 (Bob) of transparency information, which is information regarding the fact that the optical separation unit 21 has been made transparent. Either or both of the first node user 11 (Alice) and the second node user 13 (Bob) begin sharing a cryptographic key with the third node user 15 (Charlie) based on the self-measurement results, the second detection results, and the transparency information. This method involves three-party QKD technology, and by repeating the same process, it is possible to increase the number of users who can share encryption keys.

[0014] The third invention relates to a system for sharing an encryption key with a user 15 (Charlie) in a third node in a user node where a user 11 (Alice) in a first node and a user 13 (Bob) in a second node are authenticated and share an encryption key. The third intra-node user 15 (Charlie) is capable of receiving the photon signals output from the first intra-node user 11 (Alice) and the second intra-node user 13 (Bob) via the optical separation unit 21. The authentication unit 17 (Tom) can control the optical separator 21 to change the basis of the photon signal that passes through the optical separator. Then, this system employs the method according to the second aspect of the invention to start sharing an encryption key with the third intra-node user 15 (Charlie). [Effects of the Invention]

[0015] This invention provides a method for authenticating a person who can make an accurate measurement and declare it, and for key sharing with that person using a novel protocol in a quantum communication network such as a quantum entanglement swapping node. The novel protocol is, for example, a two-to-one authentication and key sharing protocol using photon-pair quantum entanglement swapping. [Brief explanation of the drawings]

[0016] [Figure 1] FIG. 1 is a block diagram of a system for performing quantum communication. DETAILED DESCRIPTION OF THE INVENTION

[0017] Hereinafter, embodiments of the present invention will be described with reference to the drawings. The present invention is not limited to the embodiments described below, but also includes appropriate modifications of the embodiments below within the scope obvious to those skilled in the art.

[0018] Figure 1 is a block diagram of a system that performs quantum communication. As shown in Figure 1, this system manages a network in which a user 11 (Alice) in a first node and a user 13 (Bob) in a second node are authenticated. Each user represents a user terminal. The terminal may be a computer or a server, and typically has a processor that can implement various functions and execute each process based on program instructions. This system is capable of performing quantum communication. This system can also authenticate new users and share encryption keys.

[0019] Conventional quantum entanglement repeaters have no other role or active function other than making Bell measurements, regardless of whether the repeater terminals are honest or not. On the other hand, Bell measurements cannot be performed correctly anywhere, but rather must be performed in a place where the pulses from Alice and Bob can interfere with each other, and the measurements must be performed correctly. We thought we could actively use this fact to authenticate the third user and then lead to key sharing. In the present invention, this idea can be implemented by using a measuring instrument that simultaneously inputs two photon pulses with a pulse width of 100 ps (2 cm in fiber length) and can observe the interference effect. In ordinary quantum optics experiments that do not assume attacks by malicious users such as Eve, precise control of transmission distance is required. On the other hand, if attacks by Eve are assumed, attacks such as teleportation, tapping, and even quantum memory can be assumed, so ordinary measurements of quantum entanglement alone cannot meet the requirements of PBC (Position-based cryptography). In the authentication method and key agreement method of the present invention, we propose novel protocols and security requirements for authentication and key agreement by using a trusted but not highly competent third party (Tom). In a system where quantum optical interference measurements are possible, the present invention can achieve authentication and encryption key agreement with minimal conversion to classical information. In this case, the present invention makes it possible to share encryption keys with new users even in an implementation where Bell measurements are only possible correctly.

[0020] The first invention is a method for authenticating a third node user 15 (Charlie) in a network in which a first node user 11 (Alice) and a second node user 13 (Bob) are authenticated. The network may be a quantum key decryption (QKD) network. The encryption key may be distributed via the quantum key decryption (QKD) network. The quantum cryptography communication device includes, for example, a transmitter and a receiver. Quantum cryptography communication is performed between these devices using an optical signal (laser light). The first node, second node, and third node may be the same node or different nodes, as long as they are capable of transmitting and receiving information within the same network.

[0021] The computer has an input unit, an output unit, a control unit, a calculation unit, and a memory unit, and each element is connected by a bus or the like to enable information exchange. For example, a control program or various information may be stored in the memory unit. When predetermined information is input from the input unit, the control unit reads the control program stored in the memory unit. Then, the control unit reads the information stored in the memory unit as appropriate and transmits it to the calculation unit. The control unit also transmits the input information to the calculation unit as appropriate. The calculation unit performs calculation processing using the received various information and stores it in the memory unit. The control unit reads the calculation results stored in the memory unit and outputs them from the output unit. In this manner, various processes and steps are performed. The various units and means execute these various processes. The computer may have a processor, and the processor may realize various functions and steps. The computer may be standalone. Some of the functions of the computer may be distributed between a server and a terminal. In this case, it is preferable that the server and the terminal can exchange information via a network such as the Internet or an intranet. The computer may include a processor and a memory coupled to the processor. The memory may store instructions that, when executed by the processor, cause the computer to perform various processes or function as various elements. The computer may be provided with various training data to build a learning model and perform various calculations through machine learning. In this case, the computer may perform various analyses using the learning model created through machine learning and deep learning of AI (artificial intelligence).

[0022] In the example shown in FIG. 1 , Alice 11 (first intra-node user) is a terminal capable of outputting a single photon. For example, Alice 11 is a terminal located at a certain node in a quantum keying (QKD) network. In this example, Alice 11 includes a single-photon source 51, a half-wave plate 53, a beam splitter 55, and photon detectors (e.g., single-photon detectors) 57 and 59. The single photon output from the single-photon source 51 has its polarization plane adjusted (or not adjusted) by the half-wave plate 53 and enters the beam splitter 55. The single photon that enters the beam splitter 55 is then separated according to its polarization plane (base), and enters the single-photon detectors 57 and 59 for detection. A control unit of Alice 11 may be able to rotate the half-wave plate 53, thereby enabling Alice 11 to adjust the bases detected by the single-photon detectors 57 and 59.

[0023] In the example shown in FIG. 1, Bob 13 (a second intra-node user) has a similar configuration to Alice 11, and each element functions in the same way.

[0024] In the example shown in FIG. 1, Charlie 15 (a third intra-node user) has an optical separator 21, a first photon detector 31, and a second photon detector 41. Charlie 15 is a terminal located at the same node on the network as Alice 11. In this example, the optical separator 21 has, for example, a half-wave plate (HWP) 23 and a beam splitter (BS) 25. Also in this example, the first photon detector 31 has the same configuration as Alice 11. That is, in this example, the first photon detector 31 has a half-wave plate 33, a beam splitter 35, a single-photon detector a 37, and a single-photon detector b 39. Also in this example, the second photon detector 41 has a half-wave plate 43, a beam splitter 45, a single-photon detector c 47, and a single-photon detector d 49. Charlie 15 is capable of receiving the photon signals (for example, signals based on quantum entangled photons) output from Alice 11 and Bob 13 via the optical separation unit 21.

[0025] In the example shown in FIG. 1, Tom 17, an authenticated unit, can rotate a half-wave plate (HWP) 23 (or HWPs 33 and 43). Tom 17 is also a terminal on the same network as Alice 11. For example, when Tom 17 rotates the HWP 23, the basis of the single photons split by the beam splitter (BS) 25 changes. Tom 17 can also control the HWP 23 to put the BS 25 into a state (transparent state) in which the single photon passes through as is. Tom 17 is an authenticated terminal on this network. The control units of Alice 11, Bob 13, Charlie 15, and Tom 17 may be a control unit on a single server, or various information may be output to the server and controlled by the control unit of the server.

[0026] Next, an authentication method using the above system will be described. This method is a method for authenticating a third user, Charlie 15, in a network in which Alice 11 and Bob 13 are authenticated. This method includes the following steps:

[0027] The authentication unit 17 (Tom) controls the light separating unit 21 to put it into a first state. The first state also includes a state in which Tom 17 does not control the half-wave plate 23. The control unit of Tom 17 stores control information for the light separating unit 21 in a memory unit as appropriate. Examples of the control information may be the rotation status of the half-wave plate 23 or information about the basis of single photons separated by the light separating unit 21.

[0028] Alice 11 and Bob 13 output a first photon signal and a second photon signal, respectively. In this case, Alice 11 and Bob 13 may independently determine the basis of the first photon signal and the second photon signal. Examples of the basis are H (horizontal), V (vertical), diagonally upper right, and diagonally upper left.

[0029] The first photon signal and the second photon signal output from Alice 11 and Bob 13, respectively, pass through the optical separation unit 21, which is in the first state. An example of the first state is a state in which the first photon signal (photon) output from Alice 11 has its basis changed and reaches the second photon detection unit 41, and the second photon signal output from Bob 13 has its basis changed and reaches the first photon detection unit 31. This example state is a state that is specified by how the basis is changed (or not changed) and which detector the signal reaches (or does not reach).

[0030] Charlie 15 detects the first photon signal and the second photon signal that have passed through the optical separation unit 21 to obtain a detection result. In the example of FIG. 1, Charlie 15 has a first arm having a first photon detection unit 31 and a second arm having a second photon detection unit 41. Charlie 15 normally controls the first photon detection unit 31 and the second photon detection unit 41 so that they measure different bases. Of the photon signals that have passed through the optical separation unit 21, the photon signals directed to the first arm have their polarization plane appropriately adjusted by the half-wave plate 33, and the basis to be separated by BS 35 is controlled. The photon signals are separated by the basis by BS 35 and detected by single-photon detector a 37 or single-photon detector b 39. In this example, the polarization plane of the photon signal directed to the second arm is appropriately adjusted by the half-wave plate 43, the basis to be separated is controlled by the BS 45, and the photon signal is separated by the basis by the BS 45 and detected by the single-photon detector c47 or the single-photon detector d49. Charlie 15 confirms that the first arm or the second arm is firing and randomly selects and measures a basis in each arm. However, different bases are measured in the first arm or the second arm. The control unit of Charlie 15 stores the detection results of the single-photon detector c47 or the single-photon detector d49 in the memory unit. Examples of detection results include receiving a single photon in a certain basis or measuring the entangled state of photons.

[0031] Charlie 15 notifies Alice 11 and Bob 13 of the detection result (detection result notification step). The control unit of Charlie 15 reads the detection result from the storage unit and outputs information about the detection result to Alice 11 and Bob 13 from the output unit.

[0032] Alice 11 and Bob 13 receive information about the detection result from Charlie 15. The input units of Alice 11 and Bob 13 may receive information about the detection result output by Charlie 15, and the control units of Alice 11 and Bob 13 may store the information about the detection result in their respective storage units.

[0033] After the detection result notification process, the authentication unit 17 (Tom) notifies Alice 11 and Bob 13 of control information, which is information related to the control of the optical demultiplexer. The control unit of Tom 17 reads the control information from the storage unit and outputs the read control information from the output unit to Alice 11 and Bob 13.

[0034] Alice 11 and Bob 13 receive the control information output from Tom 17 and store it in a storage unit as appropriate.

[0035] Alice 11 and Bob 13 authenticate Charlie 15 using the detection result and the control information. For example, if the detection result and the control information are each information about a basis of a single photon, Charlie 15 may be formally authenticated if they match. Alternatively, Alice 11 and Bob 13 may use the control information to determine a basis of a single photon that Charlie 15 will likely detect, and authenticate Charlie if the determined basis matches the detection result. This authentication is preferably performed simultaneously (in parallel) by Alice 11 and Bob 13. This method relates to peer authentication by so-called Bell measurement.

[0036] Next, a method for sharing an encryption key will be described. This method is a method for sharing an encryption key with a new user terminal, Charlie 15, in a network in which Alice 11 and Bob 13 are authenticated and have shared an encryption key. This method may use the system described above.

[0037] The method includes the following steps: User 15 (Charlie) in the third node is authenticated based on the method described above.

[0038] Tom 17 (authentication unit) controls the light separating unit 21 to make it transparent. For example, the control unit of Tom 17 may receive a program command to rotate the HWP 23 and control the light separating unit 21 so that the BS 25 transmits light. In the example of FIG. 1, the light from Alice 11 may be transmitted to the second arm (second single-photon detector 41), and the light from Bob 13 may be transmitted to the first arm (first single-photon detector 31). Tom 17 may store transparency information, which is information relating to the fact that the light separating unit 21 has been made transparent, in a storage unit as appropriate.

[0039] Alice 11 and Bob 13 output the third and fourth photon signals, respectively. Charlie 15 does not know that Tom 17 has taken control of the optical splitter 21.

[0040] The third photon signal and the fourth photon signal output from Alice 11 and Bob 13, respectively, pass through the transparent optical separating unit 21.

[0041] Charlie 15 normally controls the first photon detection unit 31 and the second photon detection unit 41 to measure different bases. If the first photon detection unit 31 and the second photon detection unit 41 are configured to measure only the same base, Charlie 15 controls the HWPs 33 and 43 to adjust the first photon detection unit 31 and the second photon detection unit 41 to measure different bases. Then, Charlie 15 detects the third photon signal and the fourth photon signal that have passed through the optical separation unit 21 to obtain a second detection result. The obtained second detection result may be stored in a memory unit as appropriate.

[0042] Alice 11 and Bob 13 measure the third photon signal and the fourth photon signal, respectively, to obtain self-measurement results. Alice 11 and Bob 13 may also measure the photon signals after randomly selecting a basis for measurement. For example, the third photon signal, which is a single photon output from the single-photon source 51 of Alice 11, has its polarization plane adjusted (or not adjusted) by the half-wave plate 53 and enters the beam splitter 55. The third photon signal that enters the beam splitter 55 is then separated according to its polarization plane (basis), enters the single-photon detectors 57 and 59, and is detected. Bob 13 may measure the fourth photon signal in a similar manner. For example, Alice 11 and Bob 13 store the obtained self-measurement results in their respective memories.

[0043] Charlie 15 notifies Alice 11 and Bob 13 of the second detection result (second detection result notification step). For example, the control unit of Charlie 15 may read the second detection result from the storage unit and output it to Alice 11 and Bob 13.

[0044] Alice 11 and Bob 13 receive the second detection result output from Charlie 15. Then, for example, Alice 11 and Bob 13 store the second detection result in a storage unit.

[0045] After the second detection result notification step, Tom 17 notifies Alice 11 and Bob 13 of transparency information, which is information about making the light separating unit 21 transparent. Tom 17 reads out the transparency information from the storage unit and outputs it to Alice 11 and Bob 13.

[0046] Alice 11 and Bob 13 receive the transparency information output from Tom 17 and store it in a storage unit as appropriate.

[0047] Either Alice 11 or Bob 13, or both, perform second-stage authentication of Charlie 15 based on the self-measurement result, the second detection result, and the transparency information, and start sharing an encryption key with Charlie 15 based on the result. For example, if Charlie 15 notifies them that the first arm and the second arm have fired (the second detection result) and Tom 17 notifies them of information about making the optical separator 21 transparent, Alice 11 and Bob 13 can independently start sharing an encryption key with Charlie 15. To start sharing an encryption key, for example, quantum cryptography communication using quantum entanglement, such as the BBM92 protocol, can be performed. In this notification, a common key used for encryption is shared using two photons (photon pairs) in a state called quantum entanglement. When the state of one photon is determined by observation, the state of the other photon is also determined. For example, if Charlie 15 is still found to be legitimate through the second-stage authentication, Alice 11 and Bob 13 can share their shared encryption key with Charlie. In this case, either Alice 11 or Bob 13 or both may output the encryption key to Charlie 15. This method is related to three-party QKD technology, and by repeating the same process, the number of users who can share the encryption key can be increased.

[0048] The third invention relates to a system for sharing an encryption key with Charlie 15 at a user node where Alice 11 and Bob 13 are authenticated and share an encryption key. Charlie 15 is capable of receiving the photon signals output from Alice 11 and Bob 13 via the optical separator 21 . Tom 17 controls the optical separator 21 to change the basis of the photon signal passing through the optical separator. Then, the system employs the method described above to start sharing an encryption key with Charlie 15. The system performs the above steps by having the processor execute instructions based on the program. [Industrial Applicability]

[0049] This method can be used in fields such as quantum secure communications. [Explanation of symbols]

[0050] 11 Alice (user in the first node) 13 Bob (user in the second node) 15 Charlie (user in the third node) 17 Tom (certified unit) 21 Light separation section 23 Half-wave plate 25 Beam Splitter 31 First photon detector 33 Half-wave plate 35 Beam Splitter 37 Single Photon Detectora 39 Single Photon Detector b 41 Second photon detector 43 Half-wave plate 45 Beam Splitter 47 Single Photon Detector c 49 Single Photon Detector 51 Single Photon Source 53 half wavelength 55 Beam Splitter 57, 59 Single photon detector

Claims

1. A method for authenticating a third intra-node user (15) in a network in which a first intra-node user (11) and a second intra-node user (13) are authenticated, comprising: a third intra-node user (15) capable of receiving photon signals output from the first intra-node user (11) and the second intra-node user (13) via an optical separation unit (21); an authentication unit (17) controlling the light separating unit (21) to set it to a first state; a step of passing a first photon signal and a second photon signal outputted from a first intra-node user (11) and a second intra-node user (13), respectively, through the optical separation unit (21) in a first state; a step in which a third intra-node user (15) detects the first photon signal and the second photon signal that have passed through the optical separation unit (21) to obtain a detection result; a detection result notification step in which the third intra-node user (15) notifies the first intra-node user (11) and the second intra-node user (13) of the detection result; a step of the authentication unit (17) notifying the first intra-node user (11) and the second intra-node user (13) of control information, which is information related to the control of the optical separation unit (21), after the detection result notification step; a step in which the first intra-node user (11) and the second intra-node user (13) authenticate the third intra-node user (15) using the detection result and the control information; method.

2. 10. The method of claim 1, The third intra-node user (15) has a first photon detector (31) and a second photon detector (41); The detection result is detection information regarding the ground state of a single photon by the first photon detection unit (31) and the second photon detection unit (41). method.

3. 10. The method of claim 1, The light separating unit (21) has a half-wave plate (23) that changes polarization, and a beam splitter (25) through which light that has passed through the half-wave plate passes, The authentication unit (17) controls the light separation unit (21) by rotating the half-wave plate (23). method.

4. A method for sharing an encryption key with a third intra-node user (15) in a network in which a first intra-node user (11) and a second intra-node user (13) are authenticated and share the encryption key, comprising: authenticating a user (15) in a third node according to the method of claim 2; a step in which the authentication unit (17) controls the light separating unit (21) to make the light separating unit (21) transparent; a step of passing a third photon signal and a fourth photon signal outputted from a first intra-node user (11) and a second intra-node user (13), respectively, through the transparent optical separation unit (21); a step in which a third intra-node user (15) controls the first photon detection unit (31) and the second photon detection unit (41) to measure different bases, and then detects the third photon signal and the fourth photon signal that have passed through the optical separation unit (21), thereby obtaining a second detection result; a first intra-node user (11) and a second intra-node user (13) measuring the third photon signal and the fourth photon signal to obtain self-measurement results; a second detection result notification step in which the third intra-node user (15) notifies the first intra-node user (11) and the second intra-node user (13) of the second detection result; a step in which, after the second detection result notification step, the authentication unit (17) notifies the first intra-node user (11) and the second intra-node user (13) of transparency information, which is information relating to the fact that the optical separation unit (21) has been made transparent; a step in which either or both of the first intra-node user (11) and the second intra-node user (13) start sharing an encryption key with a third intra-node user (15) based on the self-measurement result, the second detection result, and the transparency information; A method comprising:

5. A system for sharing an encryption key with a third node user (15) in a user node in which a first node user (11) and a second node user (13) are authenticated and share the encryption key, comprising: a third intra-node user (15) capable of receiving quantum entangled photon signals output from the first intra-node user (11) and the second intra-node user (13) via an optical separator (21); an authentication unit (17) that controls the optical separation unit (21) to change the basis of a photon signal that passes through the optical separation unit (21); A system that initiates sharing of an encryption key with a user (15) in a third node according to the method of claim 4.

Citation Information

Patent Citations

  • Protecting circuit of speaker system

    JP1984011097A