Method and apparatus for reducing information transmission amount without using quantum memory of receiving unit in quantum signature technique using ghz state

WO2025187852A8PCT designated stage Publication Date: 2025-10-02LG ELECTRONICS INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/002975
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-07
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Existing arbitrator-based quantum signature techniques using GHZ states require excessive transmission of qubit information, necessitating long-term quantum memory storage which is challenging due to the limited durability of quantum memory.

Method used

A method that reduces the amount of quantum information required for verification by using a Hermitian conjugate operation and symmetric keys for encryption, allowing verification without the need for separate quantum memory.

Benefits of technology

Reduces the amount of quantum qubit information needed for verification, eliminating the requirement for separate quantum memory storage and enhancing the feasibility of quantum signature verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024002975_02102025_PF_FP_ABST
    Figure KR2024002975_02102025_PF_FP_ABST
Patent Text Reader

Abstract

A method performed by a second device according to an embodiment of the present specification comprises the steps of: receiving first quantum information and a quantum signature from a first device; transmitting second quantum information to a third device; receiving third quantum information related to verification of the quantum signature from the third device; and performing verification of the quantum signature on the basis of the third quantum information. The third quantum information includes i) a verification factor related to the quantum signature, ii) verification information related to the first quantum information, iii) the first quantum information, and iv) the quantum signature. Encryption related to a second symmetric key for generating the third quantum information is applied to the first quantum information generated on the basis of a Hermitian conjugate operation related to the first symmetric key.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for reducing information transmission volume without using quantum memory of receiver in quantum signature technique using GHZ STATE

[0001] The present specification relates to a method and device for reducing the amount of information transmitted without using quantum memory of a receiver in a quantum signature technique using GHZ state.

[0002] Mobile communication systems were developed to provide voice services while ensuring user activity. However, they have expanded beyond voice to include data services. Currently, explosive growth in traffic is leading to resource shortages and users are demanding faster services, necessitating a more advanced mobile communication system.

[0003] Next-generation mobile communication systems must support explosive data traffic growth, dramatically increasing data rates per user, a vastly increased number of connected devices, ultra-low end-to-end latency, and high energy efficiency. To achieve these goals, various technologies are being studied, including dual connectivity, massive multiple input multiple output (MIMO), in-band full duplex, non-orthogonal multiple access (NOMA), super wideband support, and device networking.

[0004] Digital signature technology provides solutions that guarantee message integrity, message authentication, and non-repudiation, excluding confidentiality, among the four goals of information security. Existing authentication techniques cannot respond when trust between the parties exchanging information is broken. Therefore, digital signature technology is necessary, providing third-party verification for dispute resolution, authentication of the source of message content, and verification of forgery. Existing digital signature techniques can be broadly divided into direct signature techniques and arbitrator-based signature techniques.

[0005] The existing arbitrator-based quantum signature technique using GHZ states requires an excessive amount of transmission qubit information to be exchanged between the three parties: the sender (Alice), the receiver (Bob), and the arbitrator. Bob uses the message qubit used for verification. A message qubit that serves as a comparison target for verification. It needs to be stored for a long time before receiving it, but it is difficult to implement because the storage time of quantum memory is not long.

[0006] The purpose of this specification is to propose a method to solve the above-mentioned problems.

[0007] The technical problems to be achieved in this specification are not limited to the technical problems mentioned above, and other technical problems not mentioned can be clearly understood by a person having ordinary skill in the technical field to which this specification pertains from the description below.

[0008] A method performed by a second device according to one embodiment of the present disclosure comprises the steps of receiving first quantum information and a quantum signature from a first device, transmitting second quantum information to a third device, receiving third quantum information related to verification of the quantum signature from the third device; and performing verification of the quantum signature based on the third quantum information.

[0009] The first quantum information generated based on at least one qubit is received once. The second quantum information includes a measurement result of a second GHZ (Greenberger-Horne-Zeilinger) state particle of the second device, the first quantum information, and the quantum signature.

[0010] The third quantum information comprises i) a verification factor associated with the quantum signature, ii) verification information associated with the first quantum information, iii) the first quantum information, and iv) the quantum signature.

[0011] The encryption associated with the second symmetric key for generating the third quantum information is characterized in that it is applied to the first quantum information generated based on a Hermitian conjugate operation associated with the first symmetric key.

[0012] The above verification information can be generated based on the third GHZ state particles and operators of the third device.

[0013] The above operator may be determined based on the measurement result of the first GHZ state particle of the first device and the measurement result of the second GHZ state particle among the operators related to the states of the third GHZ state particle.

[0014] The quantum signature may be generated based on encryption associated with the first symmetric key. The first symmetric key may be shared between the first device and the third device based on quantum key distribution (QKD).

[0015] The encryption associated with the first symmetric key for generating the quantum signature may be applied to i) first transformation information of the first quantum information based on a quantum one time pad algorithm and ii) the measurement result of the first GHZ state particle.

[0016] The second quantum information may be generated based on encryption associated with the second symmetric key. The second symmetric key may be shared between the second device and the third device based on QKD.

[0017] The third quantum information may be generated based on encryption related to the second symmetric key.

[0018] The above Hermitian conjugate operation can be applied to the first transformation information.

[0019] Based on the value of the above verification factor being 0, the quantum signature can be verified as not forged.

[0020] The value of the verification factor is 1, and based on the difference between the verification information and the first quantum information: the quantum signature can be verified as invalid.

[0021] The value of the verification factor is 1, and based on the verification information and the first quantum information being identical: the quantum signature can be verified as valid.

[0022] The measurement result of the second GHZ state particle, the first quantum information, and the quantum signature can be obtained through decryption of the second quantum information based on the second symmetric key.

[0023] Through decryption of the quantum signature based on the first symmetric key, the measurement result of the particle related to the GHZ state of the first device and the second conversion information of the first quantum information can be obtained.

[0024] The first transformation information of the first quantum information can be obtained by applying the quantum one-time pad algorithm to the first quantum information obtained above.

[0025] The value of the above verification factor may indicate whether the second conversion information and the first conversion information match.

[0026] The above measurement results of the first GHZ state particles may be based on Bell State Measurement (BSM).

[0027] The above measurement results of the second GHZ state particles may be based on X-axis direction measurements.

[0028] A second device according to another embodiment of the present disclosure comprises one or more transceivers, one or more processors, and one or more memories connected to the one or more processors and storing instructions.

[0029] The instructions are characterized in that, based on being executed by the one or more processors, the one or more processors are set to perform all steps according to any one of the methods.

[0030] A device according to another embodiment of the present disclosure comprises one or more memories and one or more processors functionally connected to the one or more memories.

[0031] Said one or more memories are characterized in that they store instructions that set said one or more processors to perform all steps according to any one of said methods based on what is executed by said one or more processors.

[0032] In another embodiment of the present disclosure, one or more non-transitory computer-readable media store instructions.

[0033] The instructions executable by one or more processors are characterized by configuring the one or more processors to perform all steps according to any one of the methods.

[0034] A method performed by a third device according to another embodiment of the present disclosure comprises the steps of receiving second quantum information from a second device, generating third quantum information related to verification of the quantum signature, and transmitting the third quantum information to the second device.

[0035] The second quantum information includes the measurement result of the second GHZ (Greenberger-Horne-Zeilinger) state particle of the second device, the first quantum information, and the quantum signature.

[0036] The third quantum information includes i) a verification factor related to the quantum signature, ii) verification information related to the first quantum information, iii) the first quantum information, and iv) the quantum signature. The encryption related to the second symmetric key for generating the third quantum information is characterized in that it is applied to the first quantum information generated based on a Hermitian conjugate operation related to the first symmetric key.

[0037] A third device according to another embodiment of the present disclosure comprises one or more transceivers, one or more processors, and one or more memories connected to the one or more processors and storing instructions.

[0038] The instructions are characterized in that they are executed by the one or more processors, and the one or more processors are set to perform all steps of the method.

[0039] According to an embodiment of the present specification, all information for verification is transmitted from a third device to a device performing verification (e.g., a second device).

[0040] Therefore, for verification purposes, quantum information ( ) can be reduced, eliminating the need for separate quantum memory to store the quantum signature operation.

[0041] Additionally, the amount of quantum qubit information required to verify mediated quantum signatures can be reduced.

[0042] The effects that can be obtained from this specification are not limited to the effects mentioned above, and other effects that are not mentioned can be clearly understood by a person having ordinary skill in the technical field to which this specification belongs from the description below.

[0043] The accompanying drawings are intended to aid understanding of the present specification and may provide embodiments of the present specification along with detailed descriptions. However, the technical features of the present specification are not limited to specific drawings, and the features disclosed in each drawing may be combined with each other to form new embodiments. Reference numerals in each drawing may indicate structural elements.

[0044] Figure 1 is a drawing showing an example of a communication system applicable to this specification.

[0045] Figure 2 is a drawing showing an example of a wireless device applicable to this specification.

[0046] FIG. 3 is a diagram illustrating a method for processing a transmission signal applicable to the present specification.

[0047] FIG. 4 is a drawing showing another example of a wireless device applicable to this specification.

[0048] FIG. 5 is a drawing showing an example of a mobile device applicable to this specification.

[0049] Figure 6 is a diagram showing physical channels applicable to this specification and a signal transmission method using them.

[0050] Figure 7 is a diagram showing the structure of a wireless frame applicable to this specification.

[0051] Figure 8 is a drawing showing a slot structure applicable to this specification.

[0052] FIG. 9 is a diagram showing an example of a communication structure that can be provided in a 6G system applicable to this specification.

[0053] Figure 10 is a diagram illustrating the configuration of a direct signature technique.

[0054] Figure 11 is a diagram illustrating the configuration of an arbitrator-based signing technique.

[0055] Figure 12 is a diagram illustrating the configuration of a mediator-based quantum signature technique.

[0056] FIG. 13 illustrates the initial steps of an arbitrator-based quantum signature scheme according to an embodiment of the present specification.

[0057] FIG. 14 is a diagram illustrating the overall configuration of an arbitrator-based quantum signature technique according to an embodiment of the present specification.

[0058] Figure 15 shows a flowchart of a quantum signature according to an embodiment of the present specification.

[0059] FIG. 16 is a flowchart illustrating a method performed by a second device according to one embodiment of the present specification.

[0060] FIG. 17 is a flowchart illustrating a method performed by a first device according to another embodiment of the present specification.

[0061] FIG. 18 is a flowchart illustrating a method performed by a third device according to another embodiment of the present specification.

[0062] The following embodiments combine the components and features of this specification in a predetermined form. Each component or feature may be considered optional unless explicitly stated otherwise. Each component or feature may be implemented without being combined with other components or features. Furthermore, some components and / or features may be combined to form embodiments of this specification. The order of operations described in the embodiments of this specification may be changed. Some components or features of one embodiment may be included in another embodiment or may be replaced with corresponding components or features of another embodiment.

[0063] In the description of the drawings, procedures or steps that may obscure the gist of the present specification are not described, and procedures or steps that can be understood by a person skilled in the art are also not described.

[0064] Throughout the specification, when a part is said to "comprising" (or including) a certain component, this does not mean that other components are excluded, but rather that other components can be included, unless specifically stated otherwise. In addition, terms such as "...part," "...unit," and "module" described in the specification mean a unit that processes at least one function or operation, which may be implemented by hardware, software, or a combination of hardware and software. In addition, the words "a" or "an," "one," "the," and similar related words may be used in the context of describing this specification (especially in the context of the claims below) to include both the singular and the plural, unless otherwise indicated herein or clearly contradicted by context.

[0065] The embodiments of this specification have been described with a focus on the data transmission and reception relationship between a base station and a mobile station. Here, the base station is understood as a terminal node of a network that directly communicates with the mobile station. Certain operations described herein as being performed by the base station may, in some cases, be performed by an upper node of the base station.

[0066] That is, in a network consisting of multiple network nodes including a base station, various operations performed for communication with a mobile station may be performed by the base station or other network nodes other than the base station. In this case, the term 'base station' may be replaced by terms such as fixed station, Node B, eNB (eNode B), gNB (gNode B), ng-eNB, advanced base station (ABS), or access point.

[0067] Additionally, in the embodiments of the present specification, the term terminal may be replaced with terms such as user equipment (UE), mobile station (MS), subscriber station (SS), mobile subscriber station (MSS), mobile terminal, or advanced mobile station (AMS).

[0068] Additionally, a transmitter refers to a fixed and / or mobile node that provides data or voice services, and a receiver refers to a fixed and / or mobile node that receives data or voice services. Therefore, for uplink, a mobile station can be the transmitter, and a base station can be the receiver. Similarly, for downlink, a mobile station can be the receiver, and a base station can be the transmitter.

[0069] Embodiments of the present specification may be supported by standard documents disclosed in at least one of wireless access systems, such as IEEE 802.xx system, 3rd Generation Partnership Project (3GPP) system, 3GPP Long Term Evolution (LTE) system, 3GPP 5G (5th generation) NR (New Radio) system and 3GPP2 system, and in particular, embodiments of the present specification may be supported by 3GPP TS (technical specification) 38.211, 3GPP TS 38.212, 3GPP TS 38.213, 3GPP TS 38.321 and 3GPP TS 38.331 documents.

[0070] Furthermore, the embodiments of this specification may be applied to other wireless access systems and are not limited to the aforementioned systems. For example, they may also be applicable to systems implemented after the 3GPP 5G NR system, and are not limited to a specific system.

[0071] That is, obvious steps or parts not described in the embodiments of this specification may be explained by reference to the above documents. In addition, all terms disclosed in this specification may be explained by the above standard documents.

[0072] Hereinafter, preferred embodiments according to the present specification will be described in detail with reference to the accompanying drawings. The detailed description set forth below, together with the accompanying drawings, is intended to illustrate exemplary embodiments of the present specification and is not intended to represent the only embodiments in which the technical components of the present specification may be implemented.

[0073] Additionally, specific terms used in the embodiments of this specification are provided to aid in understanding of this specification, and the use of these specific terms may be changed to other forms without departing from the technical spirit of this specification.

[0074] The following technology can be applied to various wireless access systems such as CDMA (code division multiple access), FDMA (frequency division multiple access), TDMA (time division multiple access), OFDMA (orthogonal frequency division multiple access), and SC-FDMA (single carrier frequency division multiple access).

[0075] In order to make the following description clear, the following description is based on a 3GPP communication system (e.g., LTE, NR, etc.), but the technical idea of ​​the present invention is not limited thereto. LTE may refer to technology after 3GPP TS 36.xxx Release 8. Specifically, LTE technology after 3GPP TS 36.xxx Release 10 may be referred to as LTE-A, and LTE technology after 3GPP TS 36.xxx Release 13 may be referred to as LTE-A pro. 3GPP NR may refer to technology after TS 38.xxx Release 15. 3GPP 6G may refer to technology after TS Release 17 and / or Release 18. "xxx" refers to a standard document detail number. LTE / NR / 6G may be collectively referred to as a 3GPP system.

[0076] For background information, terms, abbreviations, etc. used in this specification, reference may be made to standard documents published prior to the invention of the present invention. For example, reference may be made to the 36.xxx and 38.xxx standard documents.

[0077] Communication systems applicable to this specification

[0078] Although not limited thereto, the various descriptions, functions, procedures, proposals, methods and / or operational flowcharts disclosed herein may be applied to various fields requiring wireless communication / connectivity (e.g., 5G) between devices.

[0079] Hereinafter, more specific examples will be provided with reference to the drawings. In the drawings / descriptions below, the same drawing reference numerals may represent identical or corresponding hardware blocks, software blocks, or functional blocks, unless otherwise described.

[0080] FIG. 1 is a diagram illustrating an example of a communication system applicable to the present specification. Referring to FIG. 1, a communication system (100) applicable to the present specification includes a wireless device, a base station, and a network. Here, a wireless device refers to a device that performs communication using a wireless access technology (e.g., 5G NR, LTE) and may be referred to as a communication / wireless / 5G device. Although not limited thereto, the wireless device may include a robot (100a), a vehicle (100b-1, 100b-2), an XR (extended reality) device (100c), a hand-held device (100d), a home appliance (100e), an IoT (Internet of Things) device (100f), and an AI (artificial intelligence) device / server (100g). For example, the vehicle may include a vehicle equipped with a wireless communication function, an autonomous vehicle, a vehicle capable of performing vehicle-to-vehicle communication, etc. Here, the vehicles (100b-1, 100b-2) may include unmanned aerial vehicles (UAVs) (e.g., drones). The XR devices (100c) include augmented reality (AR) / virtual reality (VR) / mixed reality (MR) devices, and may be implemented in the form of head-mounted devices (HMDs), head-up displays (HUDs) installed in vehicles, televisions, smartphones, computers, wearable devices, home appliances, digital signage, vehicles, robots, etc. The portable devices (100d) may include smartphones, smart pads, wearable devices (e.g., smartwatches, smart glasses), computers (e.g., laptops, etc.), etc. The home appliances (100e) may include TVs, refrigerators, washing machines, etc. The IoT devices (100f) may include sensors, smart meters, etc.For example, the base station (120) and the network (130) may also be implemented as wireless devices, and a specific wireless device (120a) may act as a base station / network node to other wireless devices.

[0081] Wireless devices (100a to 100f) can be connected to a network (130) via a base station (120). AI technology can be applied to the wireless devices (100a to 100f), and the wireless devices (100a to 100f) can be connected to an AI server (100g) via a network (130). The network (130) can be configured using a 3G network, a 4G (e.g., LTE) network, a 5G (e.g., NR) network, etc. The wireless devices (100a to 100f) can communicate with each other via the base station (120) / network (130), but can also communicate directly (e.g., sidelink communication) without going through the base station (120) / network (130). For example, vehicles (100b-1, 100b-2) can communicate directly (e.g., V2V (vehicle to vehicle) / V2X (vehicle to everything) communication). In addition, IoT devices (100f) (e.g., sensors) can communicate directly with other IoT devices (e.g., sensors) or other wireless devices (100a to 100f).

[0082] Wireless communication / connection (150a, 150b, 150c) can be established between wireless devices (100a to 100f) / base stations (120), and base stations (120) / base stations (120). Here, the wireless communication / connection can be established through various wireless access technologies (e.g., 5G NR) such as uplink / downlink communication (150a), sidelink communication (150b) (or D2D communication), and base station-to-base station communication (150c) (e.g., relay, IAB (integrated access backhaul)). Through the wireless communication / connection (150a, 150b, 150c), the wireless device and base station / wireless device, and base stations and base stations can transmit / receive wireless signals to / from each other. For example, the wireless communication / connection (150a, 150b, 150c) can transmit / receive signals through various physical channels. To this end, at least some of the various configuration information setting processes for transmitting / receiving wireless signals, various signal processing processes (e.g., channel encoding / decoding, modulation / demodulation, resource mapping / demapping, etc.), and resource allocation processes may be performed based on various proposals of this specification.

[0083] Communication systems applicable to this specification

[0084] FIG. 2 is a diagram illustrating an example of a wireless device applicable to this specification.

[0085] Referring to FIG. 2, the first wireless device (200a) and the second wireless device (200b) can transmit and receive wireless signals via various wireless access technologies (e.g., LTE, NR). Here, {the first wireless device (200a), the second wireless device (200b)} can correspond to {the wireless device (100x), the base station (120)} and / or {the wireless device (100x), the wireless device (100x)} of FIG. 1.

[0086] A first wireless device (200a) includes one or more processors (202a) and one or more memories (204a), and may further include one or more transceivers (206a) and / or one or more antennas (208a). The processor (202a) controls the memories (204a) and / or the transceivers (206a), and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed herein. For example, the processor (202a) may process information in the memory (204a) to generate first information / signals, and then transmit a wireless signal including the first information / signals via the transceivers (206a). In addition, the processor (202a) may receive a wireless signal including second information / signals via the transceivers (206a), and then store information obtained from signal processing of the second information / signals in the memory (204a). The memory (204a) may be connected to the processor (202a) and may store various information related to the operation of the processor (202a). For example, the memory (204a) may perform some or all of the processes controlled by the processor (202a), or may store software code including instructions for performing the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed herein. Here, the processor (202a) and the memory (204a) may be part of a communication modem / circuit / chip designed to implement wireless communication technology (e.g., LTE, NR). The transceiver (206a) may be connected to the processor (202a) and may transmit and / or receive wireless signals via one or more antennas (208a). The transceiver (206a) may include a transmitter and / or a receiver. The transceiver (206a) may be used interchangeably with an RF (radio frequency) unit. In this specification, wireless device may also mean a communication modem / circuit / chip.

[0087] The second wireless device (200b) includes one or more processors (202b), one or more memories (204b), and may further include one or more transceivers (206b) and / or one or more antennas (208b). The processor (202b) controls the memories (204b) and / or the transceivers (206b), and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed herein. For example, the processor (202b) may process information in the memory (204b) to generate third information / signals, and then transmit a wireless signal including the third information / signals via the transceivers (206b). In addition, the processor (202b) may receive a wireless signal including fourth information / signals via the transceivers (206b), and then store information obtained from signal processing of the fourth information / signals in the memory (204b). The memory (204b) may be connected to the processor (202b) and may store various information related to the operation of the processor (202b). For example, the memory (204b) may perform some or all of the processes controlled by the processor (202b), or may store software code including instructions for performing the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed herein. Here, the processor (202b) and the memory (204b) may be part of a communication modem / circuit / chip designed to implement wireless communication technology (e.g., LTE, NR). The transceiver (206b) may be connected to the processor (202b) and may transmit and / or receive wireless signals via one or more antennas (208b). The transceiver (206b) may include a transmitter and / or a receiver. The transceiver (206b) may be used interchangeably with an RF unit. In this specification, wireless device may also mean a communication modem / circuit / chip.

[0088] Hereinafter, hardware elements of the wireless device (200a, 200b) will be described in more detail. Although not limited thereto, one or more protocol layers may be implemented by one or more processors (202a, 202b). For example, one or more processors (202a, 202b) may implement one or more layers (e.g., functional layers such as physical (PHY), media access control (MAC), radio link control (RLC), packet data convergence protocol (PDCP), radio resource control (RRC), and service data adaptation protocol (SDAP)). One or more processors (202a, 202b) may generate one or more Protocol Data Units (PDUs) and / or one or more Service Data Units (SDUs) according to the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed herein. One or more processors (202a, 202b) may generate messages, control information, data or information according to the descriptions, functions, procedures, proposals, methods and / or operational flowcharts disclosed herein. One or more processors (202a, 202b) may generate signals (e.g., baseband signals) including PDUs, SDUs, messages, control information, data or information according to the functions, procedures, proposals and / or methods disclosed herein and provide the signals to one or more transceivers (206a, 206b). One or more processors (202a, 202b) may receive signals (e.g., baseband signals) from one or more transceivers (206a, 206b) and obtain PDUs, SDUs, messages, control information, data or information according to the descriptions, functions, procedures, proposals, methods and / or operational flowcharts disclosed herein.

[0089] One or more processors (202a, 202b) may be referred to as a controller, a microcontroller, a microprocessor, or a microcomputer. One or more processors (202a, 202b) may be implemented by hardware, firmware, software, or a combination thereof. For example, one or more application specific integrated circuits (ASICs), one or more digital signal processors (DSPs), one or more digital signal processing devices (DSPDs), one or more programmable logic devices (PLDs), or one or more field programmable gate arrays (FPGAs) may be included in one or more processors (202a, 202b). The descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed herein may be implemented using firmware or software, and the firmware or software may be implemented to include modules, procedures, functions, etc. The descriptions, functions, procedures, suggestions, methods and / or operation flowcharts disclosed in this specification may be implemented using firmware or software configured to perform one or more processors (202a, 202b) or stored in one or more memories (204a, 204b) and executed by one or more processors (202a, 202b). The descriptions, functions, procedures, suggestions, methods and / or operation flowcharts disclosed in this specification may be implemented using firmware or software in the form of codes, instructions and / or sets of instructions.

[0090] One or more memories (204a, 204b) may be coupled to one or more processors (202a, 202b) and may store various forms of data, signals, messages, information, programs, codes, instructions, and / or commands. The one or more memories (204a, 204b) may be configured as read only memory (ROM), random access memory (RAM), erasable programmable read only memory (EPROM), flash memory, hard drives, registers, cache memory, computer readable storage media, and / or combinations thereof. The one or more memories (204a, 204b) may be located internally and / or externally to the one or more processors (202a, 202b). Additionally, the one or more memories (204a, 204b) may be coupled to the one or more processors (202a, 202b) via various technologies, such as wired or wireless connections.

[0091] One or more transceivers (206a, 206b) can transmit user data, control information, wireless signals / channels, etc., as mentioned in the methods and / or flowcharts of this specification, to one or more other devices. One or more transceivers (206a, 206b) can receive user data, control information, wireless signals / channels, etc., as mentioned in the descriptions, functions, procedures, proposals, methods and / or flowcharts of this specification, from one or more other devices. For example, one or more transceivers (206a, 206b) can be coupled to one or more processors (202a, 202b) and can transmit and receive wireless signals. For example, one or more processors (202a, 202b) can control one or more transceivers (206a, 206b) to transmit user data, control information, or wireless signals to one or more other devices. Additionally, one or more processors (202a, 202b) may control one or more transceivers (206a, 206b) to receive user data, control information, or wireless signals from one or more other devices. Additionally, one or more transceivers (206a, 206b) may be coupled to one or more antennas (208a, 208b), and one or more transceivers (206a, 206b) may be configured to transmit and receive user data, control information, wireless signals / channels, or the like, as referred to in the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed herein, via one or more antennas (208a, 208b). In the present specification, one or more antennas may be multiple physical antennas or multiple logical antennas (e.g., antenna ports). One or more transceivers (206a, 206b) can convert received user data, control information, wireless signals / channels, etc. from RF band signals to baseband signals in order to process the received user data, control information, wireless signals / channels, etc. using one or more processors (202a, 202b).One or more transceivers (206a, 206b) may convert user data, control information, wireless signals / channels, etc. processed by one or more processors (202a, 202b) from baseband signals to RF band signals. For this purpose, one or more transceivers (206a, 206b) may include an (analog) oscillator and / or filter.

[0092] FIG. 3 is a diagram illustrating a method for processing a transmission signal applied to the present specification. For example, the transmission signal may be processed by a signal processing circuit. At this time, the signal processing circuit (300) may include a scrambler (310), a modulator (320), a layer mapper (330), a precoder (340), a resource mapper (350), and a signal generator (360). At this time, as an example, the operations / functions of FIG. 3 may be performed in the processors (202a, 202b) and / or the transceivers (206a, 206b) of FIG. 2. Furthermore, as an example, the hardware elements of FIG. 3 may be implemented in the processors (202a, 202b) and / or the transceivers (206a, 206b) of FIG. 2. For example, blocks 310 to 350 may be implemented in the processor (202a, 202b) of FIG. 2, and block 360 may be implemented in the transceiver (206a, 206b) of FIG. 2, and are not limited to the above-described embodiments.

[0093] The codeword can be converted into a wireless signal through the signal processing circuit (300) of FIG. 3. Here, the codeword is an encoded bit sequence of an information block. The information block may include a transport block (e.g., a UL-SCH transport block, a DL-SCH transport block). The wireless signal may be transmitted through various physical channels (e.g., a PUSCH, a PDSCH) of FIG. 6. Specifically, the codeword can be converted into a bit sequence scrambled by a scrambler (310). The scramble sequence used for scrambling is generated based on an initialization value, and the initialization value may include ID information of the wireless device, etc. The scrambled bit sequence can be modulated into a modulation symbol sequence by a modulator (320). The modulation scheme may include pi / 2-binary phase shift keying (pi / 2-BPSK), m-phase shift keying (m-PSK), m-quadrature amplitude modulation (m-QAM), etc.

[0094] A complex modulation symbol sequence can be mapped to one or more transmission layers by a layer mapper (330). The modulation symbols of each transmission layer can be mapped to the corresponding antenna port(s) by a precoder (340) (precoding). The output z of the precoder (340) can be obtained by multiplying the output y of the layer mapper (330) by an N*M precoding matrix W. Here, N is the number of antenna ports, and M is the number of transmission layers. Here, the precoder (340) can perform precoding after performing transform precoding (e.g., discrete Fourier transform (DFT) transform) on the complex modulation symbols. In addition, the precoder (340) can perform precoding without performing transform precoding.

[0095] The resource mapper (350) can map modulation symbols of each antenna port to time-frequency resources. The time-frequency resources can include multiple symbols (e.g., CP-OFDMA symbols, DFT-s-OFDMA symbols) in the time domain and multiple subcarriers in the frequency domain. The signal generator (360) generates a wireless signal from the mapped modulation symbols, and the generated wireless signal can be transmitted to another device through each antenna. To this end, the signal generator (360) can include an inverse fast Fourier transform (IFFT) module, a cyclic prefix (CP) inserter, a digital-to-analog converter (DAC), a frequency uplink converter, and the like.

[0096] The signal processing process for receiving signals in a wireless device can be configured in reverse order of the signal processing process (310-360) of FIG. 3. For example, a wireless device (e.g., 200a, 200b of FIG. 2) can receive wireless signals from the outside through an antenna port / transceiver. The received wireless signals can be converted into baseband signals through a signal restorer. For this purpose, the signal restorer can include a frequency downlink converter, an analog-to-digital converter (ADC), a CP remover, and a fast Fourier transform (FFT) module. Thereafter, the baseband signal can be restored to a codeword through a resource demapper process, a postcoding process, a demodulation process, and a descrambling process. The codewords can be restored to the original information blocks through decoding. Accordingly, a signal processing circuit (not shown) for a received signal may include a signal restorer, a resource de-mapper, a postcoder, a demodulator, a de-scrambler, and a decoder.

[0097] Wireless device structure applicable to this specification

[0098] FIG. 4 is a diagram illustrating another example of a wireless device to which the present specification applies.

[0099] Referring to FIG. 4, the wireless device (400) corresponds to the wireless devices (200a, 200b) of FIG. 2 and may be composed of various elements, components, units, and / or modules. For example, the wireless device (400) may include a communication unit (410), a control unit (420), a memory unit (430), and additional elements (440). The communication unit may include a communication circuit (412) and a transceiver(s) (414). For example, the communication circuit (412) may include one or more processors (202a, 202b) and / or one or more memories (204a, 204b) of FIG. 2. For example, the transceiver(s) (414) may include one or more transceivers (206a, 206b) and / or one or more antennas (208a, 208b) of FIG. 2. The control unit (420) is electrically connected to the communication unit (410), the memory unit (430), and the additional elements (440) and controls the overall operation of the wireless device. For example, the control unit (420) may control the electrical / mechanical operation of the wireless device based on the program / code / command / information stored in the memory unit (430). In addition, the control unit (420) may transmit information stored in the memory unit (430) to an external device (e.g., another communication device) via a wireless / wired interface through the communication unit (410), or store information received from an external device (e.g., another communication device) via a wireless / wired interface in the memory unit (430).

[0100] The additional element (440) may be configured in various ways depending on the type of the wireless device. For example, the additional element (440) may include at least one of a power unit / battery, an input / output unit, a driving unit, and a computing unit. Although not limited thereto, the wireless device (400) may be implemented in the form of a robot (Fig. 1, 100a), a vehicle (Fig. 1, 100b-1, 100b-2), an XR device (Fig. 1, 100c), a portable device (Fig. 1, 100d), a home appliance (Fig. 1, 100e), an IoT device (Fig. 1, 100f), a digital broadcasting terminal, a hologram device, a public safety device, an MTC device, a medical device, a fintech device (or a financial device), a security device, a climate / environmental device, an AI server / device (Fig. 1, 140), a base station (Fig. 1, 120), a network node, etc. Wireless devices may be mobile or stationary depending on the use / service.

[0101] In FIG. 4, various elements, components, units / parts, and / or modules within the wireless device (400) may be entirely interconnected via a wired interface, or at least some may be wirelessly connected via a communication unit (410). For example, within the wireless device (400), the control unit (420) and the communication unit (410) may be wired, and the control unit (420) and a first unit (e.g., 430, 440) may be wirelessly connected via the communication unit (410). In addition, each element, component, unit / part, and / or module within the wireless device (400) may further include one or more elements. For example, the control unit (420) may be composed of a set of one or more processors. For example, the control unit (420) may be composed of a set of a communication control processor, an application processor, an electronic control unit (ECU), a graphics processing processor, a memory control processor, etc. As another example, the memory unit (430) may be composed of RAM, DRAM (dynamic RAM), ROM, flash memory, volatile memory, non-volatile memory, and / or a combination thereof.

[0102] Mobile devices to which this specification applies

[0103] FIG. 5 is a drawing illustrating an example of a mobile device to which the present specification applies.

[0104] Figure 5 illustrates an example of a mobile device applicable to the present specification. The mobile device may include a smartphone, a smart pad, a wearable device (e.g., a smart watch, smart glasses), or a portable computer (e.g., a laptop, etc.). The mobile device may be referred to as a mobile station (MS), a user terminal (UT), a mobile subscriber station (MSS), a subscriber station (SS), an advanced mobile station (AMS), or a wireless terminal (WT).

[0105] Referring to FIG. 5, the portable device (500) may include an antenna unit (508), a communication unit (510), a control unit (520), a memory unit (530), a power supply unit (540a), an interface unit (540b), and an input / output unit (540c). The antenna unit (508) may be configured as a part of the communication unit (510). Blocks 510 to 530 / 540a to 540c correspond to blocks 410 to 430 / 440 of FIG. 4, respectively.

[0106] The communication unit (510) can transmit and receive signals (e.g., data, control signals, etc.) with other wireless devices and base stations. The control unit (520) can control components of the portable device (500) to perform various operations. The control unit (520) can include an AP (application processor). The memory unit (530) can store data / parameters / programs / codes / commands required for operating the portable device (500). In addition, the memory unit (530) can store input / output data / information, etc. The power supply unit (540a) supplies power to the portable device (500) and can include a wired / wireless charging circuit, a battery, etc. The interface unit (540b) can support connection between the portable device (500) and other external devices. The interface unit (540b) can include various ports (e.g., audio input / output ports, video input / output ports) for connection with external devices. The input / output unit (540c) can input or output video information / signals, audio information / signals, data, and / or information input from a user. The input / output unit (540c) may include a camera, a microphone, a user input unit, a display unit (540d), a speaker, and / or a haptic module.

[0107] For example, in the case of data communication, the input / output unit (540c) obtains information / signals (e.g., touch, text, voice, image, video) input by the user, and the obtained information / signals can be stored in the memory unit (530). The communication unit (510) can convert the information / signals stored in the memory into wireless signals, and transmit the converted wireless signals directly to other wireless devices or to a base station. In addition, the communication unit (510) can receive wireless signals from other wireless devices or base stations, and then restore the received wireless signals to the original information / signals. The restored information / signals can be stored in the memory unit (530) and then output in various forms (e.g., text, voice, image, video, haptic) through the input / output unit (540c).

[0108] Physical channels and general signal transmission

[0109] In a wireless access system, a terminal can receive information from a base station via the downlink (DL) and transmit it to the base station via the uplink (UL). The information transmitted and received between the base station and the terminal includes general data and various control information, and various physical channels exist depending on the type and purpose of the information being transmitted and received.

[0110] FIG. 6 is a diagram illustrating physical channels applicable to this specification and a signal transmission method using them.

[0111] When a terminal is powered on again from a powered-off state or newly enters a cell, it performs an initial cell search operation, such as synchronizing with the base station, in step S611. To this end, the terminal receives a primary synchronization channel (P-SCH) and a secondary synchronization channel (S-SCH) from the base station to synchronize with the base station and obtain information such as the cell ID.

[0112] After that, the terminal can obtain broadcast information within the cell by receiving a physical broadcast channel (PBCH) signal from the base station. Meanwhile, the terminal can check the downlink channel status by receiving a downlink reference signal (DL RS) in the initial cell search phase. After completing the initial cell search, the terminal can obtain more specific system information by receiving a physical downlink control channel (PDCCH) and a physical downlink shared channel (PDSCH) based on the physical downlink control channel information in step S612.

[0113] Thereafter, the terminal may perform a random access procedure such as steps S613 to S616 to complete connection to the base station. To this end, the terminal may transmit a preamble through a physical random access channel (PRACH) (S613) and receive a random access response (RAR) for the preamble through a physical downlink control channel and a physical downlink shared channel corresponding thereto (S614). The terminal may transmit a physical uplink shared channel (PUSCH) using scheduling information in the RAR (S615) and perform a contention resolution procedure such as receiving a physical downlink control channel signal and a physical downlink shared channel signal corresponding thereto (S616).

[0114] A terminal that has performed the procedure described above can then perform reception of a physical downlink control channel signal and / or a physical downlink shared channel signal (S617) and transmission of a physical uplink shared channel (PUSCH) signal and / or a physical uplink control channel (PUCCH) signal (S618) as a general uplink / downlink signal transmission procedure.

[0115] Control information transmitted from a terminal to a base station is collectively referred to as uplink control information (UCI). UCI includes hybrid automatic repeat and request acknowledgment / negative ACK (HARQ-ACK / NACK), scheduling request (SR), channel quality indication (CQI), precoding matrix indication (PMI), rank indication (RI), and beam indication (BI) information. UCI is generally transmitted periodically through PUCCH, but depending on the embodiment (e.g., when control information and traffic data must be transmitted simultaneously), it may be transmitted through PUSCH. In addition, the terminal may transmit UCI aperiodically through PUSCH upon request / instruction from the network.

[0116] Figure 7 is a diagram illustrating the structure of a wireless frame applicable to this specification.

[0117] Uplink and downlink transmissions based on the NR system can be based on frames such as those in FIG. 7. At this time, one radio frame has a length of 10 ms and can be defined as two 5 ms half-frames (HF). One half-frame can be defined as five 1 ms subframes (SF). One subframe is divided into one or more slots, and the number of slots within a subframe can depend on the subcarrier spacing (SCS). At this time, each slot can contain 12 or 14 OFDM (A) symbols depending on the cyclic prefix (CP). When a normal CP is used, each slot can contain 14 symbols. When an extended CP is used, each slot can contain 12 symbols. Here, the symbol may include an OFDM symbol (or CP-OFDM symbol), an SC-FDMA symbol (or DFT-s-OFDM symbol).

[0118] Table 1 shows the number of symbols per slot, the number of slots per frame, and the number of slots per subframe according to SCS when a general CP is used, and Table 2 shows the number of symbols per slot, the number of slots per frame, and the number of slots per subframe according to SCS when an extended CSP is used.

[0119]

[0120]

[0121] In the above Tables 1 and 2, Nslotsymb may represent the number of symbols in a slot, Nframe,μslot may represent the number of slots in a frame, and Nsubframe,μslot may represent the number of slots in a subframe.

[0122] Additionally, in a system to which the present specification is applicable, OFDM(A) numerologies (e.g., SCS, CP length, etc.) may be set differently between multiple cells merged into a single terminal. Accordingly, the (absolute time) interval of a time resource (e.g., SF, slot, or TTI) (conveniently referred to as TU (time unit)) consisting of the same number of symbols may be set differently between the merged cells.

[0123] NR can support multiple numerologies (or subcarrier spacing (SCS)) to support various 5G services. For example, a 15 kHz SCS supports wide areas in traditional cellular bands; a 30 kHz / 60 kHz SCS supports dense urban areas, lower latency, and wider carrier bandwidth; and a 60 kHz or higher SCS can support bandwidths greater than 24.25 GHz to overcome phase noise.

[0124] The NR frequency band is defined by two types of frequency ranges (FR1 and FR2). FR1 and FR2 can be configured as shown in the table below. FR2 can also refer to millimeter wave (mmW).

[0125]

[0126] Additionally, for example, the numerology described above may be set differently in a communication system to which the present specification is applicable. For example, a terahertz wave (THz) band may be used as a frequency band higher than the FR2 described above. In the THz band, the SCS may be set to be larger than in the NR system, and the number of slots may also be set differently, and the present invention is not limited to the above-described embodiment.

[0127] Figure 8 is a drawing illustrating a slot structure applicable to this specification.

[0128] A single slot contains multiple symbols in the time domain. For example, a slot contains seven symbols in a regular CP, but a slot may contain six symbols in an extended CP. A carrier contains multiple subcarriers in the frequency domain. A Resource Block (RB) can be defined as multiple (e.g., 12) consecutive subcarriers in the frequency domain.

[0129] Additionally, a Bandwidth Part (BWP) is defined as multiple consecutive (P)RBs in the frequency domain, and can correspond to one numerology (e.g., SCS, CP length, etc.).

[0130] A carrier can contain up to N (e.g., 5) BWPs. Data communication is performed through an activated BWP, and only one BWP can be activated per terminal. Each element in the resource grid is referred to as a Resource Element (RE), to which a single complex symbol can be mapped.

[0131] 6G communication system

[0132] The 6G (wireless communication) system aims to achieve (i) very high data rates per device, (ii) a very large number of connected devices, (iii) global connectivity, (iv) very low latency, (v) low energy consumption for battery-free IoT devices, (vi) ultra-reliable connectivity, and (vii) connected intelligence with machine learning capabilities. The vision of the 6G system can be divided into four aspects: "intelligent connectivity," "deep connectivity," "holographic connectivity," and "ubiquitous connectivity," and the 6G system can satisfy the requirements as shown in Table 4 below. In other words, Table 4 is a table showing the requirements of the 6G system.

[0133]

[0134] At this time, the 6G system may have key factors such as enhanced mobile broadband (eMBB), ultra-reliable low latency communications (URLLC), massive machine type communications (mMTC), AI integrated communication, tactile internet, high throughput, high network capacity, high energy efficiency, low backhaul and access network congestion, and enhanced data security.

[0135] FIG. 9 is a diagram illustrating an example of a communication structure that can be provided in a 6G system applicable to this specification.

[0136] Referring to Figure 9, 6G systems are expected to have 50 times higher simultaneous wireless connectivity than 5G wireless systems. URLLC, a key feature of 5G, is expected to become a more prominent technology in 6G communications by providing end-to-end latency of less than 1 ms. Furthermore, 6G systems will have significantly better volumetric spectral efficiency than the commonly used area spectral efficiency. 6G systems can offer extremely long battery life and advanced battery technologies for energy harvesting, eliminating the need for separate charging for mobile devices in 6G systems. Furthermore, new network characteristics in 6G may include:

[0137] - Satellite integrated network: 6G is expected to integrate with satellites to provide a global mobile network. The integration of terrestrial, satellite, and airborne networks into a single wireless communications system could be crucial for 6G.

[0138] Connected Intelligence: Unlike previous generations of wireless communication systems, 6G is revolutionary, upgrading the wireless evolution from "connected objects" to "connected intelligence." AI can be applied at every stage of the communication process (or at every signal processing step, as described below).

[0139] - Seamless integration of wireless information and energy transfer: 6G wireless networks will transfer power to charge the batteries of devices such as smartphones and sensors. Therefore, wireless information and energy transfer (WIET) will be integrated.

[0140] - Ubiquitous super 3-dimension connectivity: Access to networks and core network functions from drones and very low Earth orbit satellites will create super 3-dimension connectivity in 6G ubiquitous.

[0141] Some general requirements for the new network characteristics of 6G, such as the above, may be as follows:

[0142] - Small cell networks: The concept of small cell networks was introduced to improve received signal quality in cellular systems by increasing throughput, energy efficiency, and spectral efficiency. Consequently, small cell networks are essential for 5G and beyond-5G (5GB) communication systems. Accordingly, 6G communication systems also adopt the characteristics of small cell networks.

[0143] Ultra-dense heterogeneous networks: Ultra-dense heterogeneous networks will be another key feature of 6G communication systems. Multi-tier networks comprised of heterogeneous networks improve overall QoS and reduce costs.

[0144] High-capacity backhaul: Backhaul connections are characterized by high-capacity backhaul networks to support high-volume traffic. High-speed fiber optics and free-space optics (FSO) systems may be potential solutions to this problem.

[0145] - Radar technology integrated with mobile technology: High-precision localization (or location-based services) through communications is a key feature of 6G wireless communication systems. Therefore, radar systems will be integrated with 6G networks.

[0146] - Softwarization and virtualization: Softwarization and virtualization are two critical features that form the foundation of the design process for 5GB networks to ensure flexibility, reconfigurability, and programmability. Furthermore, billions of devices can be shared on a shared physical infrastructure.

[0147] The above-mentioned content can be applied in combination with the methods proposed in this specification, which will be described later, or can be supplemented to clarify the technical characteristics of the methods proposed in this specification. The methods described below are distinguished for convenience of explanation, and it is understood that certain components of one method may be substituted for or combined with other methods.

[0148] Below, we examine devices and methods for quantum signature techniques that leverage the unique properties of quantum data. Specifically, in quantum signature techniques for non-repudiation, authentication, and forgery prevention of message information transmitted between senders and receivers, we present an efficient method for reducing the amount of quantum information transmitted between parties during the signing process, without requiring the use of quantum memory by the verifier, Bob, during the verification process.

[0149] Digital signature technology provides a solution that guarantees message integrity, message authentication, and non-repudiation, excluding confidentiality, among the four goals of information security. Existing authentication techniques cannot respond when trust between the parties exchanging information is broken. Therefore, digital signature technology is necessary, providing third-party verification for dispute resolution, authentication of the origin of message content, and verification of forgery.

[0150] 1. Existing electronic signature techniques

[0151] Existing electronic signature techniques can be broadly divided into direct signature techniques and intermediary-based signature techniques. The direct signature technique is described below with reference to Figure 10.

[0152] Figure 10 is a diagram illustrating the configuration of a direct signature technique.

[0153] The direct signature technique, as shown in Figure 10, has a digital signature structure where only the sender and receiver exist, and is primarily modeled using public-key cryptography algorithms and hash functions. In the direct signature technique, the recipient (Bob) is assumed to have the sender's (Alice's) public key. The direct signature technique signs the entire message or hash with the sender's private key and decrypts it with the recipient's public key. ElGamal signatures and discrete logarithm-based public key algorithms are representative electronic signature techniques that follow this method.

[0154] However, the validity of this digital signature technology depends on the security of the sender's private key, and the sender can claim that their private key has been lost or stolen. Indeed, the possibility of the sender's private key being stolen still exists, ultimately requiring third-party intervention. Therefore, while direct signature techniques offer the advantage of structural simplicity, they may be difficult to apply in situations requiring extremely high security.

[0155] To address this, arbitrator-based quantum signature techniques have emerged. Unlike direct signature techniques, they employ an arbitrator. Specifically, this signature technique utilizes a common cryptographic algorithm and an arbitrator, whose role is to verify the validity of the signed message. Therefore, the arbitrator must maintain neutrality and be appropriately trusted, and can be implemented using either a private key or public key algorithm. While this technique offers greater information security than direct signature techniques, it still suffers from the drawbacks of requiring an arbitrator, which necessitates a more complex configuration and the need to maintain the arbitrator's reliability at all times. The configuration of the arbitrator-based quantum signature technique is described below with reference to Figure 11.

[0156] Figure 11 is a diagram illustrating the configuration of an arbitrator-based signature technique. Specifically, Figure 11 illustrates a configuration diagram of a signing process using a quantum signature method that utilizes a symmetric key-based encryption system and an unconditionally trustworthy arbitrator (Trusted Third Party, TTP).

[0157] Referring to Figure 11, Alice generates a message m and generates a hash value H using her hash function h (step 1). Alice shares the hash value H with the mediator using a secret key It is encrypted and sent to the arbitrator (steps 2-3). The arbitrator who receives it then decrypts it with the same key (step 4) and then uses the key that only he has. and sends it back to Alice (steps 5-6). Alice sends the signature information S and the message m to Bob (step 7). Next, Bob uses the received signature information with the private key that he and the arbitrator have. The message is encrypted and sent to the arbitrator, and the message is kept by the arbitrator (steps 8-9). The arbitrator uses his private keys to recover H included in the signature information (steps 10-11), and and sends it back to Bob (step 13). Based on this, Bob generates a message m from his message. and The signature is passed or not by checking whether it matches (steps 14-16).

[0158] The electronic signature technique consists of three steps: an initialization step that shares a symmetric key, a step that generates signature information from a message, and a step that verifies the signature at Bob with the help of an intermediary after transmitting the signature information.

[0159] 2. Quantum electronic signature technique

[0160] Quantum electronic signature techniques utilize the properties of quantum mechanics to ensure unconditional security. Similar to existing electronic signature technologies, they can be categorized into quantum one-time signatures, which consist of a quantum one-way function and a combination of private and public keys, and arbitrated quantum signatures, which rely on an arbitrator. Among quantum electronic signature techniques, quantum one-time signatures follow the Lamport-Diffle one-time signature scheme. A quantum electronic signature technique based on quantum one-time signatures proceeds as follows.

[0161] The transmitter uses the private key as input to a quantum one-way function to generate a public key to be shared by both the transmitter and receiver. Next, the transmitter transmits the message and the location of the private key mapped to the message as signature information to the receiver. The receiver uses the signature information received during the verification process and the same quantum one-way function as the transmitter to generate a message and checks whether the message matches the one received by the transmitter to verify whether the signature has been passed. Like the direct signature technique among existing signature techniques, signing is performed using only the transmitter and receiver.

[0162] On the other hand, arbitrated quantum signatures are a quantum signature technique based on a symmetric key and an arbitrator using GHZ states utilizing quantum key distribution technology. The configuration of an arbitrator-based quantum signature is described below with reference to Figure 12.

[0163] Figure 12 is a diagram illustrating the configuration of a mediator-based quantum signature technique.

[0164] Referring to Figure 12, the arbitrator-based quantum electronic signature technique proceeds through the stages of preparation, signature generation, and signature verification.

[0165] First, in the preparation phase, Alice and the mediator use a symmetric key , Bob and the arbitrator share a symmetric key The arbitrator creates the GHZ state and distributes it upon the request of Alice and Bob.

[0166] Next, in the signature generation step, Alice generates N quantum messages generates. Alice uses the quantum one time pad algorithm Using a message quantum state to another quantum state is converted to Alice's message And Alice's GHZ state particle's Bell state measurement is performed and the results are . After that, Alice signs the information Creates.

[0167] The above process (Step 1) and with quantum one time pad algorithm It is done using. For example, and to Signature information by applying the quantum one time pad algorithm operation defined as can be created.

[0168] Created and is sent to Bob (Step 2).

[0169] Bob sent One of them is stored for use in the signature verification process, and Bob measures his GHZ state particle along the X-axis and calculates the result of that measurement. Save it (Step 3).

[0170] Bob is Wow the rest and cast It is encrypted and sent to the mediator (Step 4).

[0171] The arbitrator received cast Decrypt it with and gets. The mediator cast Decrypt using and save, to If we apply a conversion operator based on Find the two values ​​obtained through this ( , ) Based on whether this is the same, the arbitrator can determine whether the signature information is forged. Determine whether the argument is 0 or 1 (Step 5).

[0172] The arbitrator is Alice's measurement , Bob's measurements , , GHZ state particles not measured in the arbitrator , signature information cast After encrypting it using , it is sent back to Bob (Step 6).

[0173] At the signature verification stage, Bob has the same After decrypting using , the verification process of the signature information is performed in two steps (Step 7). Bob checks the signature information. Whether it is forged or not It is verified through the value of . If If =0, the signature is forged, so Bob can send the message and stop the process. But If =1, then among the components of the signature information Since this implies correctness, Bob proceeds with the second signature verification process.

[0174] In the second signature verification process, Bob first receives the unmeasured GHZ state particle from the arbitrator. From Creates. Specifically, , Based on the measurement results and the correlation of GHZ state, Bob From the state Determines the operator required to generate the . Bob uses that operator. Apply to Creates.

[0175] Bob has already saved and Verify the complete correctness of the signature information by checking whether it matches. Bob and Message only when matches Accept or else message Reject.

[0176] Quantum signatures must satisfy the following four properties:

[0177] 1) It must be impossible for the recipient or attacker to forge the signature after it has been generated.

[0178] 2) The signer must not be able to deny the signature and the signed message, and the recipient must not be able to deny receipt of the message and signature.

[0179] 3) Each message must be assigned a new signature and must not be separated from that signature.

[0180] 4) Quantum signatures must contain quantum mechanical properties.

[0181] The symbols / abbreviations / terms used in this specification are as follows.

[0182] - AQS: Arbitrated quantum signature

[0183] - GHZ state: Greenberger-Horne-Zeilinger state (quantum state in which three particles are entangled)

[0184] - BSM: Bell state measurement

[0185] - : Qubit message

[0186] - : Quantum signature information

[0187] - : Alice's message qubit and the Bell state measurement result of the particle transmitted to Alice from the GHZ state

[0188] - : Measurement results of particles transmitted to Bob in GHZ state

[0189] - : Results of GHZ state particle measurements of the mediator

[0190] - : The quantum state resulting from applying the quantum one time pad algorithm to the message

[0191] - : Verification factor

[0192] - Arbitrator: mediator (helps verify Bob's signature)

[0193] - QKD: Quantum key distribution

[0194] In this specification, the symmetric key shared between Alice and the arbitrator based on QKD is ' ' (or ' ') can be referred to as. In addition, in this specification, the symmetric key shared between Bob and the arbitrator based on QKD is referred to as ' '(or ' ') can be referred to as.

[0195] The technical problems to be solved by this specification are as follows (1) and (2).

[0196] (1) In the existing GHZ state-based quantum signature technique, Bob uses a message qubit for verification. A message qubit that serves as a comparison target for verification using quantum memory. It requires a long storage time until it enters Bob. However, the storage time of quantum memory is not long, making implementation difficult. This is explained in detail below.

[0197] Quantum memories implemented to date struggle to store arbitrary quantum states for long periods of time. From the time Bob receives message information from Alice until actual verification occurs at Bob, the time required for public information to travel back and forth between Bob and the arbitrator is long enough. Therefore, using quantum memory to store qubit messages for long periods of time is difficult. Furthermore, while long optical fiber-based paths could be used to replace quantum memory, even in this case, stored photon information suffers distance loss over long paths, resulting in the loss of a significant portion of the quantum message needed for verification. This makes actual verification difficult.

[0198] (2) In existing GHZ state-based quantum signature techniques, the amount of transmitted qubit information that must be exchanged between the sender, receiver, and arbitrator is extremely large. This can lead to excessive increases in information transmission and computational complexity, increasing the likelihood of public information exposure. This will be further detailed below.

[0199] To transmit an actual N-qubit message, existing signature techniques require the transmission of quantum information of at least 17N qubits. Furthermore, each transmitted piece of information must be encrypted using a public key and a quantum one-time pad algorithm to prevent disclosure. The receiver also needs to revert the information to its pre-encryption state using the receiver's public key and a decryption algorithm. Consequently, information processing requires a significant amount of computation. Furthermore, the greater the amount of public information transmitted through the channel at each stage, the greater the possibility that an attacker can deduce key information and other required information using various combinations of public information. Therefore, it is necessary to minimize the amount of public information exchanged during the signing process.

[0200] Below, we discuss an efficient method to reduce the amount of transmitted information in arbitrator-based quantum signature techniques.

[0201] This specification also presents an easy-to-implement method. Specifically, it presents a method that eliminates the quantum memory required to store the message qubits Bob uses for verification (i.e., the message qubits received from Alice) in existing techniques.

[0202] The entire quantum signature process presented in this specification consists of three stages: an initial setup stage, a quantum signature generation stage, and a verification stage. The detailed process is described below with reference to Figures 14 and 15.

[0203] (1) Initial setup phase

[0204] FIG. 13 illustrates an initial stage of an arbitrator-based quantum signature technique according to an embodiment of the present disclosure. FIG. 14 is a diagram illustrating the overall configuration of an arbitrator-based quantum signature technique according to an embodiment of the present disclosure.

[0205] Referring to Figures 13 and 14, the quantum signature technique considered in this specification is such that the arbitrator generates N GHZ triplet states, which are the number of message qubits, and then shares them with the sender and receiver (Alice and Bob) upon request. The signature is performed using the correlation between the GHZ triplet states. The symmetric key can be shared as follows based on QKD. Alice and the arbitrator use QKD to create a symmetric key. Bob and the arbitrator also share a symmetric key using QKD. Share it.

[0206] (2) Quantum signature generation step

[0207] The quantum signing step (Step 1) is performed by Alice. Alice sends N qubit messages generates a qubit message. Alice Using the quantum one time pad algorithm to create a different type of quantum state is converted to . The above conversion is as shown in the mathematical expression 1 below. When is 0 or 1, Z or X operator This can be done by applying it to .

[0208]

[0209] Alice has her own message qubit information Wow GHZ state Perform BSM of the particles distributed to Alice. The measurement result is determined as one of the four Bell states as shown in Equation 2 below. The measurement result is is saved as .

[0210]

[0211] Alice's signature information creates. Alice Wow qubit message is sent to Bob (Step 2). In this case, in the existing technique, 2 are created and transmitted. According to this example, Bob Since Alice does not store 1 It creates a message and sends it to Bob.

[0212] (3) Verification process

[0213] (3)-A. Process performed by Bob

[0214] Bob measures his GHZ state particle in the X-direction. Save. Is or (Step 3). Mathematical expression 3 below is Alice's measurement result. When , it represents the state of the GHZ particles that Bob and the arbitrator have.

[0215]

[0216] Bob receives information from Alice ( , )and A secret symmetric key that both the user and the arbitrator have After encrypting it using , it is sent to the mediator (Step 4).

[0217]

[0218] (3)-B. Process performed by the arbitrator

[0219] In Step 5, the arbitrator acts as follows:

[0220] The arbitrator received cast By proceeding with the decryption process using , , Get. The mediator cast Decryption is performed by using the component of the signature information , gets. The mediator quantum one time pad algorithm Apply it Save.

[0221] The mediator and The match is verified using an operational process that measures the quantum state, such as a controlled swap operation. The arbitrator and If this matches =1, otherwise Record / save as =0.

[0222] The mediator second Use again can be recovered. This process is the same as the one previously transmitted from Alice. This is a new process that is being applied to reduce the number of cases from two to one. From The process of recovering is performed through a Hermitian conjugate operation process as shown in the following mathematical expression 5.

[0223]

[0224] Table 5 below For the derivation of Here are some examples of operators that should be used.

[0225]

[0226] GHZ state particles transmitted to the arbitrator The state of A process of inference is needed to figure out what the appropriate operator is to transform it into. The arbitrator is and GHZ state particles distributed to oneself using ) estimates the status of the arbitrator. Quantum information in the same form as message qubits The process of converting to is performed. Table 5 above is According to the condition of This is a list of appropriate operators for derivation.

[0227] The arbitrator will provide Bob with the information he needs for the final verification process. is encrypted and sent to Bob (Step 6). The mathematical expression 6 below is the information transmitted from the arbitrator to Bob based on Step 6 ( ) is shown.

[0228]

[0229] (3)-C. Process performed by Bob

[0230] In Step 7, Bob does the following:

[0231] This embodiment adopts a structure in which the arbitrator generates all verification factors used for signature verification and sends them to Bob. Specifically, Bob receives cast By performing the decryption process using , , , . The arguments received as above ( , , , ) Bob performs verification of the quantum signature.

[0232] Bob is Check if it is 0 or 1 First, check whether it is counterfeit or not. If =0, then one of the elements that make up the signature is This means that it was forged. This ultimately means that the signature was forged, so Bob Throw away. If =1 This signifies correctness. However, this verification process alone only verifies some of the signature information, not all of it. Therefore, an additional verification process is required. Bob performs the following additional verification process.

[0233] For further verification, Bob receives from the arbitrator and Use . Back signature information is completely correct, Bob can send a qubit message Accept. However Since the signature information on the back side does not match, Bob Reject.

[0234] Figure 14 is a diagram showing the overall configuration of the arbitrator-based quantum signature technique presented in this specification, as well as the operations performed in the transmitter, receiver, and arbitrator, and the information exchanged between them.

[0235] Step 1 of Figure 14 corresponds to the signature information generation process, and the remaining Steps 2 to 7 correspond to the signature verification process.

[0236] As you can see in the process, step 1 of the two-step signature verification process is the verification factor received from the arbitrator. Bob uses this to make the decision. Therefore, the neutrality and reliability of the arbitrator are absolutely crucial.

[0237] This embodiment has the unique feature of allowing Bob to directly receive all verification factors from the arbitrator and perform verification. There is no need to exchange information (e.g., measurement results) between the arbitrator and Bob to obtain the factors used for verification. Therefore, verification can be performed by exchanging a smaller amount of qubit information than is required for verification in existing techniques.

[0238] Figure 15 illustrates a flowchart of a quantum signature according to an embodiment of the present disclosure. Specifically, Figure 15 illustrates the entire flowchart of the proposed technique described above. Alice generates signature information and a message (S1510-S1514). Bob acts as a verifier (S1515-S1517, S1526-S1531). The arbitrator assists Bob in his verification (S1518-S1525).

[0239] In S1510, Alice has a message qubit Creates.

[0240] In S1511, Alice Quantum transformation of . Specifically, Alice generates a quantum one time pad algorithm based on cast Convert to (see Equation 1).

[0241] At S1512, Alice performs BSM of GHZ state particles and obtains the measurement results ( ) is saved.

[0242] In S1513, Alice uses quantum signature (= ) is created. Specifically, Alice and Quantum signature based on Generates a quantum signature is Alice's symmetric key can be generated based on.

[0243] In S1514, Alice has a message qubit and quantum signatures sends a message qubit to Bob. In other words, Bob sends a message qubit to Alice. and quantum signatures Receive.

[0244] At S1515, Bob performs measurements of GHZ particles and reports the results of the measurements ( ) is saved. The above measurement may be an X-axis measurement.

[0245] In S1516, Bob , and Based on Creates. Specifically, is a symmetric key It can be generated through encryption based on (see Equation 4).

[0246] In S1517, Bob sends it to the arbitrator. In other words, the arbitrator receives the message from Bob. Receive.

[0247] In S1518, the arbitrator Based on , and get. Specifically, , and is a symmetric key can be obtained through decryption based on ( ).

[0248] In S1519, the arbitrator , get. Specifically, , is a symmetric key Through decryption based on can be obtained from ( ).

[0249] In S1520, the arbitrator Find. Specifically silver It can be obtained by applying the quantum one time pad algorithm ( ).

[0250] In S1521, the arbitrator Decide / Save. If, is determined / stored as 1, otherwise is determined / stored as 0.

[0251] In S1522, the arbitrator Restore. Specifically, Is can be restored / obtained based on Hermitian conjugate operations.

[0252] In S1523, the arbitrator is the GHZ state particle of the arbitrator. , and Based on, creates. As a concrete example, the mediator and By using Estimate the state of . The operator is determined based on the state of . is the above operator It can be generated by applying it to .

[0253] In S1524, the arbitrator , , , Based on Creates. Specifically, is a symmetric key It can be generated through encryption based on (see Equation 6).

[0254] In S1525, the arbitrator sends it to Bob. In other words, Bob is sent from the arbitrator. Receive.

[0255] In S1526, Bob Based on , , , get. Specifically, , , , is a symmetric key can be obtained through decryption based on ( ).

[0256] In S1527, Bob Verification is performed based on . If =0, quantum signature is determined to be counterfeit. Bob Discard (S1528). If not =0 ( =1), Bob performs additional verification.

[0257] In S1529, Bob and Verification is performed based on . If not ( ), the signature information does not match, so Bob Reject (S1530). In this case, quantum signature is determined to be non-forged. Bob Accept (S1531).

[0258] This signature technique considers transmitting all information in a quantum state and performing encryption / decryption using a quantum one-time pad algorithm. For example, in the above-described embodiment, the information exchanged between Alice, Bob, and the mediator may be information (quantum information) transmitted and received based on a quantum channel.

[0259] However, the parts presented in Table 6 below can be transmitted as classical information. In other words, the information in Table 6 below can be classical information transmitted and received over a classical channel. If the information in Table 6 below is transmitted as classical information during the encryption / decryption process, existing cryptographic techniques may be applied.

[0260]

[0261] Security Analysis

[0262] Below, we analyze the security of the arbitrator-based quantum signature technique presented in this specification. The two conditions required to ensure security in quantum signatures are the impossibility of signature forgery and non-repudiation of the sender and receiver.

[0263] (1) Impossible to forge

[0264] Bob or Eve (eavesdropper) signs Alice If you forge a secret symmetric key We need to know QKD based on quantum mechanics. Since it is distributed only between Alice and the mediator, it is impossible for Bob or Eve to find out the key information. Through the mediator, the correct Since it is not possible to create the forged Signatures generated based on this cannot pass the verification step.

[0265] Secret symmetric key It can be assumed that Eve is exposed and attempts to forge the signature. Eve Even if we know the correct Alice, we can get the same Bell state measurement result from the new message we generated. cannot be generated. Used in the second verification process. The condition cannot be satisfied. Therefore, forgery of the signature information is impossible.

[0266] (2) Denial prevention

[0267] It can be assumed that Alice never sent the signing information. In this case, non-repudiation is possible as follows: The arbitrator uses a secret key that only Alice and the arbitrator have. The signature information can be decrypted using . The arbitrator can determine that the signature information came from Alice, thus preventing the sender from repudiating the message.

[0268] It can also be assumed that Bob never received the signature. In this case, non-repudiation is possible as follows: To verify a signature, the recipient must receive the signature and use the same secret key. This requires interaction with the intermediary sharing the signature. Once verification is complete, Bob must assume that he has received the signature and transmitted it to the intermediary, thus preventing repudiation by the recipient.

[0269] Expected effect

[0270] In this specification, we propose a quantum signature technique based on Ttiplet GHZ states. This embodiment can be compared with existing methods in terms of the amount of qubit information transmitted between Alice, Bob, and an arbitrator. As shown in Table 7, the qubit transmission amount based on this embodiment (Proposed AQS) can be compared with the qubit transmission amount based on a conventional quantum arbiter-based technique (Conventional AQS with GHZ states). Table 7 compares the transmission amounts based on the transmission of a message with N qubits.

[0271]

[0272] The effect of reducing the amount of qubit information transmitted compared to the existing method occurs in the following areas.

[0273] Alice transmits a message qubit to Bob, eliminating the need for Bob to store the two identical messages that previously required Alice to transmit. Consequently, the number of qubits transmitted along the Alice->Bob path is reduced from 5N to 4N.

[0274] The measurement values ​​are not shared in the information transmitted from the arbitrator to Bob. Therefore, the number of qubits transmitted along the arbitrator->Bob path is reduced from 7N+1 to 5N+1.

[0275] Ultimately, the number of transmitted qubits can be reduced by approximately 17% compared to conventional methods. By reducing the number of transmitted information qubits, quantum signature techniques require all transmitted information to be encrypted / decrypted, which reduces the computational load and improves throughput.

[0276] Existing GHZ-based quantum signature techniques require quantum memory to store the message qubit value, one of the parameters Bob uses for verification. However, this embodiment has the implementation advantage of eliminating the need for quantum memory, as the arbitrator transmits all verification parameters to Bob.

[0277] In terms of implementation, the operations of the first device (Alice) / second device (Bob) / third device (mediator) according to the above-described embodiments can be processed by the devices of FIGS. 1 to 5 described above (e.g., processors (202a, 202b) of FIG. 2).

[0278] In addition, the operations of the first device (Alice) / second device (Bob) / third device (arbitrator) according to the above-described embodiment may be stored in a memory (e.g., 204a, 204b of FIG. 2) in the form of a command / program (e.g., instruction, executable code) for driving at least one processor (e.g., processor (202a, 202b) of FIG. 2).

[0279] The embodiments described below are specifically described with reference to FIGS. 16 to 18 in terms of the operation of the first device, the second device, and the third device (e.g., 200a and 200b in FIG. 2). The methods described below are distinguished only for the convenience of explanation, and it goes without saying that some components of one method may be substituted for some components of another method or may be applied in combination with each other.

[0280] The definitions of the first through third devices are as follows. The first device may refer to Alice or the sender. The second device may refer to Bob or the receiver. The third device may refer to the arbitrator or mediator.

[0281] FIG. 16 is a flowchart illustrating a method performed by a second device according to one embodiment of the present specification.

[0282] Referring to FIG. 16, the method performed by the second device may include a first quantum information and quantum signature receiving step (S1610), a second quantum information transmitting step (S1620), a third quantum information receiving step related to verification of the quantum signature (S1630), and a step of performing verification of the quantum signature (S1640).

[0283] In step S1610, the second device receives first quantum information and a quantum signature from the first device. The first quantum information generated based on at least one qubit may be received once. For example, step S1610 may be based on step S1514 of FIG. 15.

[0284] For example, the first quantum information is as described above. , and the quantum signature described above may mean can mean .

[0285] Specifically, the quantum signature is a first symmetric key (e.g., ) can be generated based on encryption related to the first symmetric key. The first symmetric key can be shared between the first device and the third device based on quantum key distribution (QKD).

[0286] The encryption associated with the first symmetric key for generating the quantum signature comprises: i) first transformation information of the first quantum information based on a quantum one time pad algorithm (e.g., ) and ii) the measurement results of the first GHZ state particles of the first device (e.g. ) can be applied.

[0287] For example, the measurement result of the first GHZ state particle may be based on Bell State Measurement (BSM).

[0288] At S1620, the second device transmits the second quantum information to the third device. For example, S1620 may be based on S1515 to S1517 of FIG. 15.

[0289] The second quantum information may include the measurement result of the second GHZ (Greenberger-Horne-Zeilinger) state particle of the second device, the first quantum information, and the quantum signature. For example, the second quantum information may include the above-described can mean .

[0290] Specifically, the second quantum information is a second symmetric key (e.g., ) can be generated based on encryption related to the second symmetric key. The second symmetric key can be shared between the second device and the third device based on QKD.

[0291] For example, the measurement result of the second GHZ state particle may be based on the X-axis direction measurement.

[0292] At S1630, the second device receives third quantum information related to verification of the quantum signature from the third device. For example, S1630 may be based on S1525 to S1526 of FIG. 15.

[0293] For example, the third quantum information is as described above. can mean .

[0294] In one embodiment, the third quantum information comprises i) a verification factor associated with the quantum signature (e.g., ), ii) verification information related to the first quantum information (e.g. ), iii) the first quantum information (e.g. ) and iv) the quantum signature (e.g. ) may be included. Encryption related to the second symmetric key for generating the third quantum information may be applied to the first quantum information generated based on a Hermitian conjugate operation related to the first symmetric key. Specific details related to the generation of the third quantum information will be described later.

[0295] For example, the verification information may be generated based on the third GHZ state particle and operator of the third device. The operator may be one of the operators (e.g., operators based on Table 5) related to the states of the third GHZ state particle, and the measurement result of the first GHZ state particle of the first device (e.g., ) and the measurement results of the second GHZ state particles (e.g. ) can be determined based on.

[0296] For example, the verification factor may be determined as follows. The verification factor may be determined as follows: the second conversion information (e.g., ) and the first conversion information (e.g. ) can indicate whether or not they match.

[0297] Specifically, the second symmetric key (e.g., ) through decryption of the second quantum information based on the measurement result of the second GHZ state particle (e.g., ), the first quantum information (e.g. ) and the above quantum signature (e.g. ) can be obtained.

[0298] The above first symmetric key (e.g. ) based on the measurement result of the particle related to the GHZ state of the first device (e.g., ) and second transformation information of the first quantum information (e.g. ) can be obtained. By applying the quantum one-time pad algorithm to the first quantum information obtained above, the first transformation information of the first quantum information (e.g., ) can be obtained.

[0299] The value of the verification factor may indicate whether the second conversion information matches the first conversion information. As a specific example, the value of the verification factor may be i) a first value (e.g., 0 or 1) indicating that the second conversion information matches the first conversion information, or ii) a second value (e.g., 1 or 0) indicating that the second conversion information does not match the first conversion information.

[0300] For example, the third quantum information is the second symmetric key (e.g., ) can be generated based on encryption related to .

[0301] Encryption related to the second symmetric key for generating the third quantum information can be applied to the first quantum information generated based on a Hermitian conjugate operation related to the first symmetric key.

[0302] The Hermitian conjugate operation associated with the first symmetric key is performed using the first transformation information (e.g., ) can be applied. That is, the first conversion information (e.g., ) by applying the Hermitian conjugate operation, the first quantum information (e.g., ) can be restored / obtained. In other words, the first quantum information included in the third quantum information (e.g., ) may be the first quantum information obtained / restored based on the Hermitian conjugate operation.

[0303] At S1640, the second device verifies the quantum signature based on the third quantum information. The second device performs the verification in two steps. For example, S1640 may be based on S1526 to S1531 of FIG. 15.

[0304] The second device performs verification based on the value of the verification factor. For example, if the value of the verification factor is 0, the quantum signature can be verified as forged.

[0305] Based on the value of the verification factor being 1, the second device performs an additional verification procedure. For example, based on the value of the verification factor being 1 and the verification information being different from the first quantum information: the quantum signature can be verified as invalid. For example, based on the value of the verification factor being 1 and the verification information being identical to the first quantum information: the quantum signature can be verified as valid.

[0306] An operation based on at least one of S1610 to S1640 described above may be performed based on at least one of S1514 to S1517 and S1526 to S1531 performed by Bob in FIG. 15.

[0307] The operations based on S1610 to S1640 described above can be implemented by the device of FIG. 2. For example, the second device (200a or 200b) can control one or more transceivers (206a or 206b) and / or one or more memories (204a or 204b) to perform the operations based on S1610 to S1640.

[0308] FIG. 17 is a flowchart illustrating a method performed by a first device according to another embodiment of the present specification.

[0309] Referring to FIG. 17, a method performed by a first device according to another embodiment of the present specification includes a first quantum information generation step (S1710), a quantum signature generation step (S1720), and a first quantum information and quantum signature transmission step (S1730).

[0310] In S1710, the first device generates first quantum information. For example, S1710 may be based on S1510 of FIG. 15.

[0311] At S1720, the first device generates a quantum signature. For example, S1720 may be based on S1511 to S1513 of FIG. 15.

[0312] For example, the first quantum information is as described above. , and the quantum signature described above may mean can mean .

[0313] Specifically, the quantum signature is a first symmetric key (e.g., ) can be generated based on encryption related to the first symmetric key. The first symmetric key can be shared between the first device and the third device based on quantum key distribution (QKD).

[0314] The encryption associated with the first symmetric key for generating the quantum signature comprises: i) first transformation information of the first quantum information based on a quantum one time pad algorithm (e.g., ) and ii) the measurement results of the first GHZ state particles of the first device (e.g. ) can be applied.

[0315] For example, the measurement result of the first GHZ state particle may be based on Bell State Measurement (BSM).

[0316] At S1730, the first device transmits the first quantum information and the quantum signature to the second device. For example, S1730 may be based on S1514 of FIG. 15.

[0317] The first quantum information generated based on at least one qubit can be transmitted once. That is, according to the existing method, two was transmitted. In other words, was transmitted twice. According to this embodiment, the second device does not store the first quantum information separately for verification. Therefore, the first quantum information (e.g., ) is transmitted only once.

[0318] An operation based on at least one of S1710 to S1730 described above may be performed based on at least one of S1510 to S1514 performed by Alice in FIG. 15.

[0319] The operations based on S1710 to S1740 described above can be implemented by the device of FIG. 2. For example, the first device (200a or 200b) can control one or more transceivers (206a or 206b) and / or one or more memories (204a or 204b) to perform the operations based on S1710 to S1740.

[0320] FIG. 18 is a flowchart illustrating a method performed by a third device according to another embodiment of the present specification.

[0321] Referring to FIG. 18, a method performed by a third device according to another embodiment of the present specification includes a second quantum information receiving step (S1810), a third quantum information generating step (S1820) related to verification of a quantum signature, and a third quantum information transmitting step (S1830).

[0322] At S1810, the third device receives second quantum information from the second device. For example, the second quantum information includes the measurement result of the second GHZ (Greenberger-Horne-Zeilinger) state particle of the second device, the first quantum information, and the quantum signature. Since S1810 corresponds to S1620 of FIG. 16, a duplicate description will be omitted. For example, S1810 may be based on S1517 of FIG. 15.

[0323] At S1820, the third device generates third quantum information related to the verification of the quantum signature. For example, S1820 may be based on S1518 to S1524 of FIG. 15.

[0324] For example, the third quantum information is as described above. can mean .

[0325] In one embodiment, the third quantum information comprises i) a verification factor associated with the quantum signature (e.g., ), ii) verification information related to the first quantum information (e.g. ), iii) the first quantum information (e.g. ) and iv) the quantum signature (e.g. ) may be included. Encryption related to the second symmetric key for generating the third quantum information may be applied to the first quantum information generated based on a Hermitian conjugate operation related to the first symmetric key. Specific details related to the generation of the third quantum information will be described later.

[0326] For example, the verification information may be generated based on the third GHZ state particle and operator of the third device. The operator may be one of the operators (e.g., operators based on Table 5) related to the states of the third GHZ state particle, and the measurement result of the first GHZ state particle of the first device (e.g., ) and the measurement results of the second GHZ state particles (e.g. ) can be determined based on.

[0327] For example, the verification factor may be determined as follows. The verification factor may be determined as follows: the second conversion information (e.g., ) and the first conversion information (e.g. ) can indicate whether or not they match.

[0328] Specifically, the second symmetric key (e.g., ) through decryption of the second quantum information based on the measurement result of the second GHZ state particle (e.g., ), the first quantum information (e.g. ) and the above quantum signature (e.g. ) can be obtained.

[0329] The above first symmetric key (e.g. ) based on the measurement result of the particle related to the GHZ state of the first device (e.g., ) and second transformation information of the first quantum information (e.g. ) can be obtained. By applying the quantum one-time pad algorithm to the first quantum information obtained above, the first transformation information of the first quantum information (e.g., ) can be obtained.

[0330] The value of the verification factor may indicate whether the second conversion information matches the first conversion information. As a specific example, the value of the verification factor may be i) a first value (e.g., 0 or 1) indicating that the second conversion information matches the first conversion information, or ii) a second value (e.g., 1 or 0) indicating that the second conversion information does not match the first conversion information.

[0331] For example, the third quantum information is the second symmetric key (e.g., ) can be generated based on encryption related to .

[0332] Encryption related to the second symmetric key for generating the third quantum information can be applied to the first quantum information generated based on a Hermitian conjugate operation related to the first symmetric key.

[0333] The Hermitian conjugate operation associated with the first symmetric key is performed using the first transformation information (e.g., ) can be applied. That is, the first conversion information (e.g., ) by applying the Hermitian conjugate operation, the first quantum information (e.g., ) can be restored / obtained. In other words, the first quantum information included in the third quantum information (e.g., ) may be the first quantum information obtained / restored based on the Hermitian conjugate operation.

[0334] At S1830, the third quantum information is transmitted to the second device. For example, S1830 may be based on S1525 of FIG. 15.

[0335] An operation based on at least one of S1810 to S1830 described above may be performed based on at least one of S1517 to S1525 performed by the Arbitrator in FIG. 15.

[0336] The operations based on S1810 to S1830 described above can be implemented by the device of FIG. 2. For example, the third device (200a or 200b) can control one or more transceivers (206a or 206b) and / or one or more memories (204a or 204b) to perform the operations based on S1810 to S1830.

[0337] Here, the wireless communication technology implemented in the wireless device (200a, 200b) of the present specification may include not only LTE, NR, and 6G, but also Narrowband Internet of Things for low-power communication. At this time, for example, NB-IoT technology may be an example of LPWAN (Low Power Wide Area Network) technology, and may be implemented with standards such as LTE Cat NB1 and / or LTE Cat NB2, and is not limited to the above-described names. Additionally or alternatively, the wireless communication technology implemented in the wireless device (200a, 200b) of the present specification may perform communication based on LTE-M technology. At this time, for example, LTE-M technology may be an example of LPWAN technology, and may be called by various names such as eMTC (enhanced Machine Type Communication). For example, LTE-M technology can be implemented by at least one of various standards such as 1) LTE CAT 0, 2) LTE Cat M1, 3) LTE Cat M2, 4) LTE non-BL (non-Bandwidth Limited), 5) LTE-MTC, 6) LTE Machine Type Communication, and / or 7) LTE M, and is not limited to the above-described names. Additionally or alternatively, the wireless communication technology implemented in the wireless device (200a, 200b) of the present specification can include at least one of ZigBee, Bluetooth, and Low Power Wide Area Network (LPWAN) considering low-power communication, and is not limited to the above-described names. For example, ZigBee technology can create personal area networks (PAN) related to small / low-power digital communication based on various standards such as IEEE 802.15.4, and can be called by various names.

[0338] The embodiments described above are combinations of the components and features of the present disclosure in a predetermined form. Each component or feature should be considered optional unless explicitly stated otherwise. Each component or feature may be implemented without being combined with other components or features. Furthermore, it is also possible to combine some components and / or features to form an embodiment of the present disclosure. The order of operations described in the embodiments of the present disclosure may be changed. Some components or features of one embodiment may be included in another embodiment or may be replaced with corresponding components or features of another embodiment. It is self-evident that claims that do not have an explicit citation relationship in the patent claims may be combined to form an embodiment or may be incorporated as a new claim through a post-application amendment.

[0339] Embodiments according to the present specification may be implemented by various means, for example, hardware, firmware, software, or a combination thereof. In the case of hardware implementation, an embodiment of the present invention may be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, etc.

[0340] When implemented via firmware or software, an embodiment of the present specification may be implemented in the form of a module, procedure, function, or the like that performs the functions or operations described above. The software code may be stored in memory and executed by a processor. The memory may be located within or external to the processor and may exchange data with the processor via various known means.

[0341] It will be apparent to those skilled in the art that this specification may be embodied in other specific forms without departing from the essential characteristics thereof. Therefore, the foregoing detailed description should not be construed in any way as limiting but rather as illustrative. The scope of this specification should be determined by a reasonable interpretation of the appended claims, and all changes within the scope of equivalents herein are intended to be included within the scope of this specification.

Claims

1. In a method performed by a second device, A step of receiving first quantum information and a quantum signature from a first device, wherein the first quantum information generated based on at least one qubit is received once; A step of transmitting second quantum information to a third device, wherein the second quantum information includes a measurement result of a second GHZ (Greenberger-Horne-Zeilinger) state particle of the second device, the first quantum information, and the quantum signature; A step of receiving third quantum information related to verification of the quantum signature from the third device; and Including a step of performing verification of the quantum signature based on the third quantum information, The third quantum information comprises i) a verification factor related to the quantum signature, ii) verification information related to the first quantum information, iii) the first quantum information, and iv) the quantum signature, A method characterized in that encryption related to a second symmetric key for generating the third quantum information is applied to the first quantum information generated based on a Hermitian conjugate operation related to the first symmetric key.

2. In paragraph 1, The above verification information is generated based on the third GHZ state particles and operators of the third device, A method characterized in that the operator is determined based on the measurement result of the first GHZ state particle of the first device and the measurement result of the second GHZ state particle among the operators related to the states of the third GHZ state particle.

3. In paragraph 1, The quantum signature is generated based on encryption associated with the first symmetric key, A method characterized in that the first symmetric key is shared between the first device and the third device based on quantum key distribution (QKD).

4. In paragraph 3, A method characterized in that the encryption associated with the first symmetric key for generating the quantum signature is applied to i) first transformation information of the first quantum information based on a quantum one time pad algorithm and ii) the measurement result of the first GHZ state particle.

5. In paragraph 4, The second quantum information is generated based on encryption related to the second symmetric key, A method characterized in that the second symmetric key is shared between the second device and the third device based on QKD.

6. In paragraph 5, A method characterized in that the Hermitian conjugate operation is applied to the first transformation information.

7. In paragraph 1, A method characterized in that the quantum signature is verified as forged based on the value of the verification factor being 0.

8. In paragraph 1, A method characterized in that the quantum signature is verified as invalid based on the value of the verification factor being 1 and the verification information being different from the first quantum information.

9. In paragraph 1, A method characterized in that the quantum signature is verified as valid based on the value of the verification factor being 1 and the verification information being identical to the first quantum information.

10. In paragraph 5, The measurement result of the second GHZ state particle, the first quantum information and the quantum signature are obtained through decryption of the second quantum information based on the second symmetric key, Through decryption of the quantum signature based on the first symmetric key, the measurement result of the particle related to the GHZ state of the first device and the second conversion information of the first quantum information are obtained, The first transformation information of the first quantum information is obtained by applying the quantum one-time pad algorithm to the first quantum information obtained above, A method characterized in that the value of the verification factor indicates whether the second conversion information and the first conversion information match.

11. In paragraph 2, A method characterized in that the measurement result of the first GHZ state particle is based on Bell State Measurement (BSM).

12. In paragraph 1, A method characterized in that the measurement result of the second GHZ state particle is based on the X-axis direction measurement.

13. In the second device, One or more transmitters and receivers; one or more processors; and One or more memories connected to said one or more processors and storing instructions, A second device characterized in that the instructions, based on being executed by the one or more processors, set the one or more processors to perform all steps of the method according to any one of claims 1 to 12.

14. In a device comprising one or more memories and one or more processors functionally connected to the one or more memories, A device characterized in that said one or more memories store instructions that cause said one or more processors to perform all steps of a method according to any one of claims 1 to 12, based on being executed by said one or more processors.

15. In one or more non-transitory computer-readable media storing instructions, One or more non-transitory computer-readable media characterized in that the instructions executable by one or more processors cause the one or more processors to perform all steps of the method according to any one of claims 1 to 12.

16. In a method performed by a third device, A step of receiving second quantum information from a second device, wherein the second quantum information includes a measurement result of a second GHZ (Greenberger-Horne-Zeilinger) state particle of the second device, the first quantum information, and the quantum signature; A step of generating third quantum information related to verification of the quantum signature; and A step of transmitting the third quantum information to the second device; including, The third quantum information includes i) a verification factor related to the quantum signature, ii) verification information related to the first quantum information, iii) the first quantum information, and iv) the quantum signature, A method characterized in that encryption related to a second symmetric key for generating the third quantum information is applied to the first quantum information generated based on a Hermitian conjugate operation related to the first symmetric key.

17. In the third device, One or more transmitters and receivers; one or more processors; and One or more memories connected to said one or more processors and storing instructions, A third device characterized in that the instructions are set to cause the one or more processors to perform all steps of the method according to claim 16, based on the instructions being executed by the one or more processors.