Method and system for two-qubit multi-user quantum key distribution protocol
A three-party quantum key distribution system using two entangled qubits addresses the limitations of existing protocols by ensuring secure communication among multiple users through entanglement verification, enhancing security and integrity.
Patent Information
- Application Number
- JP2023573658
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-05-31
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2041-05-31
AI Technical Summary
Existing quantum key distribution protocols are limited to two-party authentication and are difficult to implement for multiple users, lacking a practical approach for secure communication among three parties using quantum entanglement-based links.
A method and system for three-party quantum key distribution using two entangled qubits, employing quantum entanglement and Bell inequality violation to ensure non-malleable and eavesdrop-proof security, involving the generation and distribution of a shared key among multiple devices through entangled qubit pairs and verification using the Clauser-Horne-Shimony-Holt inequality.
Facilitates secure quantum entanglement-based communication among three parties, ensuring the security and integrity of the shared key distribution by verifying entanglement through the CHSH inequality, thereby enhancing communication security.
Smart Images

Figure 0007746418000112 
Figure 0007746418000113 
Figure 0007746418000114
Abstract
Description
[Technical Field]
[0002] The present invention relates generally to the field of quantum cryptography, and in particular to a method and system for three-party quantum key distribution using two entangled qubits. [Background technology]
[0003] It is generally believed that quantum objects can be utilized to provide communication security that is far improved over conventional non-quantum methods. The BB84 protocol (Bennet, Brassard, Quantum Cryptography: Public key distribution and coin tossing, Proceedings of IEEE International Conference on Computers, Systems and Signal Processing, volume 175, page 8, New York, 1984) is a provable authentication protocol that can enable key distribution from one sender to one receiver, but is limited to two-party authentication and is not well suited for key distribution to multiple parties. Prior art methods for enabling quantum-based security among multiple users of communication devices have, without loss of generality, focused particularly on two aspects:
[0004] First, the prior art has considered several methods that utilize photonic devices to generate multiple entangled particles for multiple users. In Kumavor et al. (Comparison of Four Multi-User Quantum Key Distribution Schemes Over Passive Optical Networks, Journal of Lightwave Technology, Vol. 23, No. 1, January 2005), the authors provide some survey information on recent quantum key distribution (QKD) protocol developments, as well as performance comparisons. The schemes considered in this paper consider an entanglement scenario for two parties: a sender, conventionally called "Alice," and a receiver, conventionally called "Bob."
[0005] In a second respect, the prior art addresses methods for generalizing the BB84 protocol. These methods aim to support QKD for multiple users. Recent prior art in this regard can be seen in the paper by Xue et al. (Efficient multiuser quantum cryptography network based on entanglement, Nature, Sci Rep 7, 45928, 2017). This paper considers a QKD scheme for multiple users based on three or more entangled bits, which is physically difficult to implement.
[0006] In the first perspective, only two parties are considered, while in the second perspective, the system generally relies on a system with three entangled qubits, which is difficult to implement in practice.
[0007] In both respects, the prior art lacks a practical approach for implementing a secure quantum entanglement-based communication link between three parties using a pair of qubits. Accordingly, a method and system are needed that avoids or mitigates one or more limitations of the prior art by facilitating a quantum entanglement-based communication link between three parties and significantly improving communication security between the three parties.
[0008] This background information is provided to identify information believed by the applicant to be of possible relevance to the present invention. No admission is necessarily intended, nor should be construed, that any of the above information constitutes prior art against the present invention. [Prior art documents] [Non-patent literature]
[0009] [Non-Patent Document 1] Bennet, Brassard, Quantum Cryptography: Public key distribution and coin tossing, Proceedings of IEEE International Conference on Computers, Systems and Signal Processing, volume 175, page 8, New York, 1984. [Non-patent document 2] Kumavor et al. (Comparison of Four Multi-User Quantum Key Distribution Schemes Over Passive Optical Networks, Journal of Lightwave Technology, Vol. 23, No. 1, January 2005 [Non-patent document 3] Efficient multiuser quantum cryptography network based on entanglement,Nature,Sci Rep 7,45928,2017 Summary of the Invention [Means for solving the problem]
[0010] In the present invention, quantum entanglement is used to enable three-party quantum key distribution. Embodiments include multi-user (N≧2) based quantum key distribution systems, where the underlying security scheme is based on quantum entanglement and Bell inequality violation, which have been proven to provide the required non-malleable and eavesdrop-proof security properties.
[0011] Aspects of the present disclosure provide a method for an operator O to generate and distribute a multi-user shared key to multiple devices, e.g., receiver A and receiver B. The key is shared between operator O and receiver A and receiver B. Such a method includes sequentially preparing pairs of entangled qubits, each pair of entangled qubits in a state of two-qubit entanglement. Such a method further includes transmitting one entangled qubit from each pair of entangled qubits to receiver A and the other entangled qubit from each pair of entangled qubits to receiver B. Such a method further includes receiving a response from each of receiver A and receiver B, and transmitting a key to each of receiver A and receiver B.
[0012] In some embodiments, the response from each of receiver A and receiver B includes receiving a list of coded bits from receiver A and receiving a list of coded bits from receiver B. For the list of coded bits from receiver A, each bit is measured from the quantum bits sent by operator O, recorded in a list of recorded bits, and encoded in the list of coded bits from receiver A. For the list of coded bits from receiver B, each bit is measured from the quantum bits sent by operator O, recorded in a list of bits, and encoded in the list of coded bits from receiver B.
[0013] In some embodiments, transmitting the key to each of receiver A and receiver B includes verifying a correlation between the list of coded bits from receiver A and the list of coded bits from receiver B. In such methods, verifying the correlation is performed using a quantum entanglement inequality. In some embodiments, the quantum entanglement inequality is the Clauser, Horne, Shimony, Holt (CHSH) inequality.
[0014] In some embodiments, the step of transmitting the key to each of receiver A and receiver B comprises: A list of measured bits for receiver A, and List of coded bits at receiver A The method includes transmitting the list of coded bits from receiver B to receiver A to derive a key according to Such an embodiment may include: A list of measured bits for receiver B, and List of coded bits at receiver B The method further includes transmitting the list of coded bits from receiver A to receiver B to derive a key according to:
[0015] Such a method further includes receiving a derived key for receiver A and a derived key for receiver B over respective authenticated classical channels. Such a method further includes using an entanglement inequality to perform a quantum correlation between the derived key of receiver A and the derived key of receiver B. In such an embodiment, deriving the key includes rejecting pairs of bits that were not entangled according to the entanglement inequality.
[0016] In some embodiments, the method further comprises using the derived key as the verified key if the entanglement between the derived key of receiver A and the derived key of receiver B is sufficient to ensure security.
[0017] In some embodiments, the method further comprises discarding the derived keys and discontinuing communication if the entanglement between the derived keys of receiver A and receiver B is insufficient to ensure security.
[0018] In some embodiments, the method further includes Layer 2 iteration, where operator O of claim 1 is replaced by receiver A of claim 1, receiver A of claim 1 is replaced by user-1, and receiver B of claim 1 is replaced by user-2. In some embodiments, the method further includes Layer 2 iteration, where operator O of claim 1 is replaced by receiver B of claim 1, receiver A of claim 1 is replaced by user-3, and receiver B of claim 1 is replaced by user-4.
[0019] A further aspect of the present disclosure relates to a device including a processor and a non-transitory machine-readable memory executed by the processor for performing the above-described method. Such a device may be operated by an operator O.
[0020] Further aspects of the present disclosure relate to a receiver A device including a processor and a non-transitory machine-readable memory executed by the processor for implementing the above-described method. Similarly, further aspects of the present disclosure relate to a receiver B device including a processor and a non-transitory machine-readable memory executed by the processor for implementing the above-described method.
[0021] A further aspect of the present disclosure relates to a system including an operator O device, a receiver A and a receiver B for implementing the above-mentioned method, each device including a processor and a non-transitory machine-readable memory executed by the processor.
[0022] A further aspect of the present disclosure provides a system for distributing a key. Such a system includes a photon source operative to transmit a sequence of photons and a first beam-splitting device. The first beam-splitting device is configured to sequentially prepare pairs of entangled qubits from the sequence of photons, each pair of entangled qubits being in a state of two-qubit entanglement. The first beam-splitting device is further configured to transmit one entangled qubit from each pair of entangled qubits to the second beam-splitting device and the other entangled qubit to the third beam-splitting device. In such a system, the second and third splitting devices are configured to measure the qubits as bits, record the bits in a list of measured bits, encode the bits in a list of encoded bits, and transmit the list of encoded bits to the first beam-splitting device. In such a system, the first beam-splitting device is operative to receive the list of encoded bits and calculate correlations between the lists of encoded bits using entanglement inequalities.
[0023] Further features and advantages of the present invention will become apparent from the following detailed description taken in conjunction with the accompanying drawings. [Brief explanation of the drawings]
[0024] [Figure 1] FIG. 1 illustrates two calculation bases according to an embodiment. [Figure 2] FIG. 1 illustrates an exemplary implementation for distributing quantum keys, according to one embodiment, where qubits are implemented as photons, the quantum key is a sequence of such photons, and quantum key distribution (QKD) is performed by sending the sequence of photons to a polarizing beam splitter. [Figure 3] FIG. 1 illustrates a method for quantum key distribution, according to an embodiment. [Figure 4] 1 is a quantum computation circuit representing the preparation of Bell states used by operator O, according to one embodiment. [Figure 5] According to an embodiment, the z-axis (i.e.
number
number
number
number
[0025] In contrast to a bit of information, which may be in one of two states labeled as 0 and 1 and may be implemented as a transistor that is either off or on, a quantum bit, typically shortened to "qubit," may be in one of two states labeled as 0 and 1 and is conventionally
number
number
number
number
number
number
number
number
[0026] Qubits cannot be implemented with conventional transistors, but many other physical systems can be designed to realize qubits. One embodiment of a qubit is a single photon, which is a low-intensity light that cannot be further dimmed without being completely turned off. Other physical systems can be used, including atoms, ions, nuclei, specially designed electronic circuits, etc.
[0027] Although an embodiment is not limited to any particular implementation, in any case, the state of the qubit can be divided into two computational basis states:
number
number
number
number
number
number
number
number
number
number
number
number
number
number
number
number
number
number
[0028] 1 illustrates two computational bases according to an embodiment. The first computational base is the computational basis state along the x-axis 110.
number
number
number
number
number
number
number
number
[0029] To represent any state of a single qubit, two states (e.g.,
number
number
number
number
number
number
number
number
number
number
number
number
number
number
number
number
number
number
number
number
number
number
[0030] In one embodiment of a quantum key distribution protocol, the first step may be for a quantum key distribution operator (O) to create an (n,2) qubit system, where n is the key length and 2 is the number of qubits. This system of two qubits may be prepared in a two-qubit state known as a Bell state, which may be expressed as follows:
number
number
number
number
number
number
number
[0031] Quantum entanglement is a physical phenomenon that occurs when pairs or groups of qubits, each of which can be a particle, are created in such a way that the quantum state of each qubit cannot be described independently. Instead, the quantum state must be described for the entire system. Using Bell states as an example, if two qubits qr_0 and qr_1 are not entangled, measuring their states yields four possible states for their collective state:
number
number
[0032] FIG. 2 shows an implementation of a quantum key distribution scheme, according to one embodiment. The source of qubits 205 may be a source of photons or may be network-based. The initial sequence of qubits may include a sequence of qubits that form the quantum key 207. If the qubits are implemented as photons, they may be transmitted to a beam splitter 210, which functions as an operator (O). From each photon, the beam splitter O 210 may generate one entangled state 215 of two qubits and transmit one qubit, qr_0, to receiver A (Alice) 220 and the other qubit, qr_1, to receiver B (Bob) 225. If receivers Alice and Bob are also beam splitters themselves, receivers Alice and Bob can repeat the process of generating further entangled states and distributing them to additional users, e.g., user-1 235, user-2 104, user-3 145, and user-4 150. The distribution from operator O to Alice and Bob can be referred to as Layer 1 distribution 255, and the distribution from Alice and Bob to user-1 235, user-2 204, user-3 245, and user-4 250 can be referred to as Layer 2 distribution. While the example is described using a beam splitter, it should be understood that a polarizing beam splitter can alternatively be used to convert such entanglement between polarization modes into entanglement between spatial modes. The beam splitter may be a beam splitting device comprising a beam splitter, a processor, and a memory.
[0033] 2, each beam splitter can be configured to implement a quantum computation gate or a series of gates on the incident photons, however, in embodiments where qubits are implemented other than with photons, the gates may be elements other than beam splitters.
[0034] Embodiments include methods for implementing gates on qubits, regardless of how the qubits and gates are physically implemented, to distribute quantum keys to multiple users of a quantum communication channel.
[0035] 3 illustrates a method for quantum key distribution, according to an embodiment. An operator O can prepare a pair of entangled qubits qr_0 and qr_1, whose states (i.e., eigenstates) can be in two possible states:
number
number
number
number
number
number
[0036] Receiver A (Alice) can encode each measured qubit qr_0 in a list of classical bits A[] (320), and Bob can similarly encode each measured qubit qr_1 in a list B[] (325). Alice can then send the list of measurement choices a() and the list of encoded measurements A[] to operator O (330), and Bob can similarly send them to operator O (335).
[0037] Operator O can verify whether Alice's encoded measurements A[] are entangled with Bob's encoded measurements B[] by verifying the CHSH inequality using Alice's list of measurement choices a() and Bob's list of measurement choices b() (340). If sufficient entanglement is confirmed by the CHSH inequality, operator O can perform key agreement and derive keys K(O,AB) and K(O,BA) (345). Operator O can then send Alice a string of measurement axes used by Bob signed with the agreed-upon key K(OAB) and send Bob a string of measurement axes used by Alice signed with the agreed-upon key K(OAB) (350). Alice and Bob can then each verify the agreed-upon key K(OAB) by deriving K(O,AB) and K(O,BA), respectively (355).
[0038] In one embodiment, a quantum key distribution system may have two channels: a quantum channel as depicted in FIG. 2, and a classical channel, which may be a conventional communication system such as an optical fiber network. Over the quantum channel, O may send qubit qr_0 to receiver A (Alice) and qubit qr_1, which is entangled with qubit qr_0, to receiver B (Bob). Both qubit qr_0 and qubit qr_1 may be initialized to
number
number
[0039] In notation, the qubit qr_0 is in the initial state
number
number
[0040] Similarly, qubit qr_1 also has an initial state
number
number
[0041] Thus prepared, qubit qr_0 can be processed with a Hadamard gate H given by:
number
[0042] FIG. 4 illustrates a quantum computing circuit illustrating the preparation of Bell states 215, according to an embodiment. Each horizontal single line 405 represents the evolution of a qubit in time, and each double line 410 similarly represents the evolution of a classical bit. The first qubit is qr_0 415 and occupies the first single line. The second qubit is qr_1 420 and occupies the second single line. The double lines are occupied by classical bits cr_0, cr_1, cr_2, and cr_3. Each line is preceded by an identification 425 of the bit and an identification 430 of the initial state of the bit. A Pauli X gate 435 is applied to each of the qubits qr_0 and qr_1, and then a Hadamard gate H 440 is applied to qubit qr_0. At this point, qubit qr_1 can be an input to the same Hadamard gate.
[0043] In one embodiment, once the Bell state is prepared, operator O can transmit the first qubit qr_0 over the quantum channel to receiver A (Alice) 207. Alice's reception can be referred to as Alice's Measurement Preparation 210.
[0044] To perform state measurements on qubit qr_0, receiver A (Alice) may alternatively use different computational bases, i.e.
number
number
number
number
[0045] Figure 5 shows the z-axis (i.e.,
number
[0046] Alternatively, at the site of receiver A (Alice), Alice can see that the x-axis (i.e.
number
number
number
number
[0047] Figure 6 shows a quantum computing circuit that can be used by receiver A (Alice) to measure the state of qubit qr_0 along the x-axis. To do so, a single qubit qr_0 is passed through a Pauli S gate 605 (i.e.,
number
number
[0048] In one embodiment, once the Bell state has been prepared by operator O, operator O can transmit (307) to receiver A (Alice) a sequence of qubits qr_0 each entangled with qubit qr_1, such that qubits qr_0 and qr_1 are in a state of two-qubit entanglement, as well as transmit (309) to receiver B (Bob) a sequence of qubits qr_1 each entangled with qubit qr_0. Bob's reception can be referred to as Bob's measurement preparation 315. Similar to Alice, Bob can alternately and randomly prepare either one of two measurement circuits to measure the qubits along each of the two computational bases. Referring to FIG. 1, one measurement circuit can be configured to measure the qubits along the v-axis (i.e.,
number
number
[0049] The state projection is taken as the w-axis of the vw basis (i.e.,
number
[0050] Figure 7 shows the w-axis of the vw basis (i.e.,
number
[0051] Alternatively, Bob can be positioned along the v-axis of the vw basis (i.e.,
number
[0052] 8 shows a quantum computing circuit that can be used by receiver B (Bob) to measure the state of qubit qr_1 along the v-axis in the vw basis. Measurement 910 of qubit qr_1 420 can be made with respect to classical bit cr_1 920.
[0053] In one embodiment, once Alice prepares for measurements (310), she may measure the received qubits and encode them as either -1 or 1, i.e., {-1, 1}, as a key in the classical bit in response to each qubit measurement (320). Alice may generate the measured qubits as a list A[] and send it to operator O (330).
[0054] Similarly, when Bob prepares for measurement (315), he can measure the received qubits and encode them as either -1 or 1, i.e., {-1, 1}, as a key in the classical bit in response to each qubit measurement (325). Bob can generate the measured qubits as a list B[] and send it to operator O (335).
[0055] In one embodiment, operator O can repeat the process of preparing (305) and sending (307 and 309) two entangled qubits to Alice and Bob, respectively. Alice and Bob can then continue to receive qubits, prepare measurements (310, 315), and encode the qubits with classical bits (220, 225). With the repetition, two strings of qubits are received by Alice and Bob, respectively, each string representing a key, and each qubit in one stream is entangled with a qubit in the other stream, so that Alice and Bob are said to have the same key in a perfectly noiseless quantum channel transmission.
[0056] In one embodiment, once Alice and Bob have received and encoded their respective streams of n bits representing the key, they can send the corresponding streams of classical bits they generated to operator O via the authenticated classical channel (320, 325). Thus, Alice can send a() and A[] to O (330), and Bob can send b() and B[] to O (335).
[0057] In one embodiment, when operator O receives the encoded keys A[] and B[] over the classical channel, operator O can perform a joint measurement of each pair of bits from A[] and B[] to verify (340) whether the qubits originally sent by operator O (305, 307) and the qubits received by Alice and Bob (310 and 315) are entangled. If the simultaneous measurement of the two bits is such that the CHSH inequality is violated, then entanglement between those two bits is confirmed. The CHSH inequality can be expressed as follows: C=||CHSH(A[],B[])||<2
[0058] In one embodiment, once the quantum entanglement between each pair of bits is verified by the CHSH inequalities, the stream of bits can be made to contain only entangled bits. This can ensure that the bit streams from Alice and Bob are the same and contain only entangled bits. Such a technique can be called verification 345, which can be defined as the technique necessary to ensure that Alice's key component and Bob's key component are equal.
[0059] To perform the verification, operator O can send b() signed with KOA to Alice (350) and a() signed with K(OAB) to Bob (350). Alice, who already has a() and A[], can use b() to calculate key K(O,AB), and Bob, who already has b() and B[], can use a() to calculate key K(O,BA). Using b() and a() to derive K(O,AB) and K(O,BA), respectively, completes the key distribution to Alice and Bob. While this final exchange can provide additional protection from eavesdroppers in a classical channel, in another embodiment, operator O can send the common keys directly to Alice and Bob.
[0060] In one embodiment, Alice's measurements may be made along the xz basis, and Bob's measurements may be made along the vw basis, whose axis is at 45° from the axis of the xz basis. There is a possibility of unwanted noise being present in the stream of entangled qubits. To reduce the possibility of noise, the following method can be implemented to generate uniformly distributed measurements.
[0061] In one embodiment, a method for generating uniformly distributed measurements and minimizing transmission noise involves Alice randomly selecting a string of bits and assigning each element a i We can start by preparing a list a() where is either bit 0 or bit 1. This can be shown as follows: a(),a i ={0,1}
[0062] Next, Alice calculates the eigenstates σ i is the xz basis
number
number
number
number
number
[0063] a i If = 0, measurements can be performed along the α plane, and a i If = 1, measurements can be performed along the β plane.
[0064] Each measurement result is i can be recorded in a list A() which is either -1 or 1. A(),A i ={-1,1}
[0065] Element a from list a() and list σ() respectively i and element σ i can be seen as components of the corresponding vectors a and σ. In this way, recording measurements in a list A() can be seen as a tensor operation between vectors a and σ.
number
[0066] Bob can make similar measurements as Alice. Bob can make a i The measurements can be recorded in a corresponding list B() where B is either -1 or 1. B(),B i ={-1,1}
[0067] Similar to Alice, Bob's records can be expressed in terms of tensor operations.
number
[0068] 9 shows two lists of bits received by Alice and Bob and recorded by Alice and Bob, respectively, according to one embodiment. Alice receives a string of bits a() 1100, each of which can be 0 or 1. Alice performs the tensor operation
number
number
[0069] Each bit received by Alice and Bob can be either 0 or 1, which results in four different possibilities: 00, 01, 10, and 11. For each of these possibilities, a tensor operation can be defined, where E is the sum of A and B in the α plane. i is recorded, and B is recorded on the α plane. i When E(0,0) is calculated, A is added to the β plane. i is recorded, and B is recorded on the α plane. i When E(1,0) is calculated, A is added to the α plane. i is recorded, and B is recorded on the β plane. i When E(0,1) is calculated, A is recorded on the β plane. i is recorded, and B is recorded on the β plane. i This is a recording notation in which E(1, 1) is calculated when is recorded.
number
[0070] Once Alice and Bob record their measurements in lists A[] 1105 and B[] 1120, an operator O can use A[] and B[], and a() and b(), to calculate the CHSH correlation C between any two simultaneously received bits. The value of C for a string (i.e., list) of two bits can be calculated using: C=|E(0,0)+E(0,1)|+|E(1,0)-E(1,1)|
[0071] Under locality and reality theory, the CHSH correlations are C ≤ 2, but under nonlocality theory, where quantum entanglement is defined,
number
number
number
[0072] In one embodiment, if entanglement is not confirmed using the CHSH inequalities, it may indicate excessive noise or eavesdropping, and communication may be interrupted.
[0073] In one embodiment, if entanglement between the bit strings sent to Alice and Bob is confirmed (340), operator O can perform key reconciliation 345. Due to the CHSH inequality, key reconciliation can indicate the absence of eavesdropping during transmission. If not, O should abort the multi-user key distribution.
[0074] 10 shows strings of bits received and recorded by Alice and Bob, some of which are rejected due to lack of entanglement, according to an embodiment. From operator O, Alice A can receive a string of qubits, each of which can be measured, to produce a string of classical bits a() 1205, etc. Each bit of the string can be encoded to produce string A[] 1210. The same happens for Bob, who uses the list of received qubits to entangle the qubits received by Alice and measured in a list of classical bits b() 1215, which are then encoded in list B[] 1220.
[0075] In Figure 10, the second bit 1212 of A[] is different from the second bit 1222 of B[]. This indicates that the first pair of qubits they were measured on, measured as the second bit 1207 of a() and the second bit 1217 of b(), are not entangled and therefore can be rejected (1225). Depending on the level of CHSH correlation between Alice's string and Bob's string, a certain number of bits can be rejected. The smaller the CHSH correlation, the greater the number of rejections, which indicates a higher likelihood of eavesdropping or too much noise. The unrejected bits from list A[] form Alice's key K(O,AB) 1225, and the unrejected bits from list B[] form Bob's key K(O,AB) 1230. If they are the same, they form the desired quantum key K(O,AB).
[0076] 11 is a block diagram of an electronic device (ED) 952 shown in a computing and communication environment 950 that may be used to implement the devices and methods disclosed herein. The electronic device 952 typically includes a processor 954, such as a central processing unit (CPU), and may further include a special-purpose processor, such as a graphics processing unit (GPU) or other such processor, memory 956, a network interface 958, and a bus 960 for connecting the components of the ED 952. The ED 952 may also optionally include components such as mass storage 962, a video adapter 964, and an I / O interface 968 (shown with dashed lines). In embodiments, the electronic device may be part of an operator O, the electronic device may be part of a receiver A (Alice), or the electronic device may be part of a receiver B (Bob). In some embodiments, the electronic device portion of receiver A (Alice) is connected to the electronic device portion of operator O and may include a classical communication channel. In some embodiments, the electronic device portion of receiver B (Bob) is connected to the electronic device portion of operator O and may include a classical communication channel.
[0077] The embodiments have been described above in conjunction with the aspects of the invention in which they are implemented. Those skilled in the art will understand that the embodiments may be implemented in conjunction with the aspect used in the description, but may also be implemented with other embodiments of that aspect. When embodiments are mutually exclusive or otherwise incompatible with one another, this will be apparent to those skilled in the art. Some embodiments may be described in connection with one aspect, but may also be applicable to other aspects, as will be apparent to those skilled in the art.
[0078] While the invention has been described with reference to particular features and embodiments thereof, it will be apparent that various modifications and combinations can be made without departing from the invention. The specification and drawings are therefore to be considered merely as illustrative of the invention as defined by the appended claims, and are intended to cover any modifications, variations, combinations, or equivalents that fall within the scope of the invention. [Explanation of symbols]
[0079] 110 x-axis 120 z-axis 130 v axis 140 w-axis Source of 205 qubits 207 Quantum Key 210 Beam Splitter 215 Bell State 220 Receiver A (Alice) 225 Receiver B (Bob) 235 User-1 240 User-2 245 User-3 250 User-4 255 mobile devices 405 Horizontal Single Line 410 Double eyelid line 415 qubit qr_0 420 qubit qr_1 435 Pauli X-gate 440 Hadamard Gate H 510 Hadamard Gate 520 State Measurement 530 Classic Bit cr_0 605 Pauli S Gate 610 Hadamard Gate 615 T-Gate 620 Hadamard Gate 625 measurements 805 Pauli S Gate 810 Hadamard Gate 815 T-Gate 820 Hadamard Gate 825 measurements 830 Classic Bit cr_1 910 measurements 920 Classic Bit cr_1 950 Communication environment 952 Electronic Devices 954 processor 956 memory 958 Network Interface 960 Bus 962 Mass storage device 968 I / O Interface 1100 String a() 1105 List A[] 1110 Tensor Operations 1115 String b() 1120 List B[] 1125 Tensor Operations 1205 String a() 1207 second bit of a() 1210 String A[] 1212 Second bit of A[] 1215 List b() 1217 second bit of b() 1220 List B[] 1222 Second bit of B[] 1225 Key K(O,AB) 1230 Key K(O,AB)
Claims
1. A method for an operator O to generate and deliver a multi-user shared key to a receiver A and a receiver B, comprising: sequentially providing pairs of entangled qubits, each pair of entangled qubits being in a state of two-qubit entanglement; transmitting one entangled qubit from each pair of entangled qubits to receiver A and the other entangled qubit to receiver B; receiving from said receiver A the list of measured bits of receiver A and the list of coded bits of receiver A to derive a derivation key of receiver A; receiving from said receiver B the list of measured bits of receiver B and the list of coded bits of receiver B to derive a derivation key of receiver B; performing a quantum correlation between receiver A's derived key and receiver B's derived key using a quantum entanglement inequality; rejecting pairs of bits that were not entangled according to the quantum entanglement inequality to derive the multi-user shared key; A method comprising:
2. receiving a response from each of receiver A and receiver B; receiving a list of coded bits from receiver A, each bit being measured from a qubit transmitted by operator O, recorded in a list of recorded bits, and encoded in said list of coded bits from receiver A; receiving a list of coded bits from receiver B, each bit measured from a qubit transmitted by operator O, recorded in a list of bits, and encoded in said list of coded bits from receiver B; 2. The method of claim 1, comprising:
3. The step of performing a quantum correlation between the derived key of receiver A and the derived key of receiver B comprises the step of verifying a correlation between the list of coded bits from receiver A and the list of coded bits from receiver B; the step of verifying the correlation is performed using quantum entanglement inequalities; The method of claim 2.
4. The method of claim 3 , wherein the quantum entanglement inequality is a Clauser, Horne, Shimony, Holt (CHSH) inequality.
5. 5. The method of claim 1, further comprising the step of using the derived key as the verified key if entanglement between the derived key of receiver A and the derived key of receiver B is sufficient to ensure security.
6. 5. The method of claim 1, further comprising the step of discarding the derived keys and terminating communication if entanglement between the derived keys of receiver A and receiver B is insufficient to ensure security.
7. further comprising a layer 2 repetition; The operator O in claim 1 is replaced by the receiver A in claim 1; Receiver A in claim 1 is replaced with user 1, Receiver B in claim 1 is replaced by User-2; 7. The method according to any one of claims 1 to 6.
8. further comprising a layer 2 repetition; The operator O in claim 1 is replaced by the receiver B in claim 1; Receiver A in claim 1 is replaced by User-3, Receiver B in claim 1 is replaced by User 4; 7. The method according to any one of claims 1 to 6.
9. a photon source operative to transmit a sequence of photons; a first beam splitting device; 1. A system for distributing keys, comprising: the first beam splitting device is configured to sequentially prepare pairs of entangled qubits from the sequence of photons, each pair of entangled qubits being in a state of two-qubit entanglement, and to transmit one entangled qubit from each pair of entangled qubits to the second beam splitting device and the other entangled qubit from each pair of entangled qubits to the third beam splitting device; the second and third beam splitting devices are configured to measure qubits as bits, record the bits in a list of measured bits, encode the bits in a list of encoded bits, and send the list of encoded bits to the first beam splitting device; the first beam splitting device receiving from the second beam splitting device a list of measured bits of the second beam splitting device and a list of encoded bits of the second beam splitting device to derive a derivation key for the second beam splitting device; receiving from the third beam splitting device a list of measured bits of the third beam splitting device and a list of encoded bits of the third beam splitting device to derive a derivation key for the third beam splitting device; performing a quantum correlation between a derived key of the second beam splitting device and a derived key of the third beam splitting device using a quantum entanglement inequality; and further configured to reject pairs of bits that were not entangled according to the quantum entanglement inequality to derive a key. system.
10. 10. The system of claim 9, wherein the first beam splitting device is configured to verify a correlation between the list of coded bits from the second beam splitting device and the list of coded bits from the third beam splitting device, and verifying the correlation is performed using the quantum entanglement inequality.
11. 11. The system of claim 9 or 10, wherein the first beam splitting device is configured to use a derived key as a matched key if entanglement between the derived key of the second beam splitting device and the derived key of the third beam splitting device is sufficient to ensure security.
12. 11. The system of claim 9 or 10, wherein the first beam splitting device is configured to discard the derived key and discontinue communication if entanglement between the derived key of the second beam splitting device and the derived key of the third beam splitting device is insufficient to ensure security.
13. 13. The system of claim 9, wherein the quantum entanglement inequality is a Clauser, Horne, Shimony, Holt (CHSH) inequality.
14. 9. A device for operation by an operator O to generate and deliver a multi-user shared key to a receiver A and a receiver B, said device comprising a processor operably coupled to a memory, said device being configured to perform the method of any one of claims 1 to 8.
Citation Information
Patent Citations
System for sharing quantum encryption key and method for generating quantum encryption key
JP2007074302A
Quantum state transfer method
JP2007143085A
Multi-terminal quantum key delivery system
JP2016072666A
Apparatus and method for multi-user quantum key distribution
US20180069698A1