Reward reception method, reward payment method, entanglement generation device, user device, entanglement-based quantum key distribution system, entanglement generation method, and secret key generation method

The modified entanglement quantum key distribution scheme addresses the issue of reward interception and inefficient communication by implementing passive modulation and classical data processing, enabling secure and efficient quantum key distribution with reward receipt for the entanglement source.

WO2025225295A1PCT designated stage Publication Date: 2025-10-30MITSUBISHI ELECTRIC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/013320
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-26
Filing Date
2025-04-01
Publication Date
2025-10-30

AI Technical Summary

Technical Problem

Existing entanglement quantum key distribution systems face challenges in ensuring that the entanglement source, which has the highest implementation cost, receives rewards and that these rewards are not intercepted by other parties, as users A and B cannot identify the actual source of the entangled state they receive.

Method used

A modified entanglement quantum key distribution scheme that includes passive modulation and classical data processing, allowing the entanglement generator to send modulated entangled states with random numbers, and reward receipt based on matching evidence keys generated by user devices, ensuring the entanglement source receives rewards and preventing interception.

Benefits of technology

The solution enables information-theoretic security and efficient utilization of quantum communication by allowing selection between different key distributions, reducing waste and improving communication efficiency while ensuring the entanglement source receives rewards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025013320_30102025_PF_FP_ABST
    Figure JP2025013320_30102025_PF_FP_ABST
Patent Text Reader

Abstract

In this reward reception method, which is executed in an entanglement-based quantum key distribution scheme, an entanglement generation device receives, from a first user device, a reward in return for sending a first modulated entangled state if a first evidence key and a second evidence key match when communication is executed between the first user device and a second user device on the basis of a first random number group and the result of measuring the first modulated entangled state. The first evidence key refers to a key generated by the entanglement generation device on the basis of a verification random number, a second random number group, and the result of the second user device measuring a second modulated entangled state. The second evidence key refers to a key generated by the first user device on the basis of a verification random number and the result of the first user device measuring the second modulated entangled state.
Need to check novelty before this filing date? Find Prior Art

Description

Reward receiving method, reward payment method, entanglement generating device, user device, entanglement quantum key distribution system, entanglement generating method, and private key generating method

[0001] The present disclosure relates to a reward receiving method, a reward payment method, an entanglement generating device, a user device, an entanglement quantum key distribution system, an entanglement generating method, and a private key generating method.

[0002] Quantum key distribution (QKD) is a type of quantum technology that enables a pair of users (user A and user B) at two remote locations to share a secret key for use in encryption. Quantum mechanics, one of the laws of physics, guarantees that the secret key will not be leaked, regardless of any new technologies that may emerge in the future. Security guaranteed by quantum mechanics is defined as "information-theoretic security." According to this term, quantum key distribution can be said to be a quantum technology that enables a pair of users at two remote locations to share an information-theoretically secure secret key. Information-theoretic security is often also called "unconditional security." Furthermore, quantum cryptography defines a method of encrypted communication using Vernam's one-time pad using a secret key provided by quantum key distribution. In contrast, the security of modern cryptography, i.e., cryptographic methods already in widespread use today, relies on the assumption that "certain mathematical problems should be unsolvable." Security that relies on this assumption is called computational security. Therefore, modern cryptography can potentially be broken by the emergence of new types of computers or algorithms. In fact, many modern encryption methods have been broken in the past. Quantum cryptography is clearly more secure than modern cryptography in terms of the possibility of encryption being broken. In a typical quantum key distribution (QKD) implementation, communication between user A and user B is performed via a single line. On the other hand, a modified version of QKD is called "entangled quantum key distribution." In "entangled QKD," a third party called the "entanglement source" exists in addition to users A and B, who share a secret key. The entanglement source C sends an "entangled state" to users A and B. By utilizing the entangled state, users A and B can double the communication distance of QKD compared to when the entangled state is not used (see, for example, Non-Patent Document 1). While entanglement sources are often misunderstood as being difficult to implement, they can actually be implemented using current technology. Various implementation reports on entanglement sources have been published since the 2000s.

[0003] Feihu Xu, Xiongfeng Ma, Qiang Zhang, Hoi-Kwong Lo, and Jian-Wei Pan, “Secure quantum key distribution with realistic “Reviews of Modern Physics 92, 025002 (American Physical Society, 2020).

[0004] If we compare the situation described in the background art to a mobile phone, the entangled state is radio waves or a communication line, and C, which provides the entangled state, is a telecommunications carrier. Furthermore, among A, B, and C, the device C (the entanglement source) has the highest implementation cost. The implementation costs of the devices A and B (receivers) are often lower than those of C. In existing technologies, C unilaterally serves A and B, but C has a problem in that it cannot receive rewards from A and B. More precisely, users A and B described in the background art cannot identify the source of the entangled state they receive. Therefore, users A and B may pay rewards to an entanglement source that is different from the actual entanglement source. To address this problem from C's perspective, there is a possibility that the reward for the entangled state generated by C may be intercepted by another party. The present disclosure aims to achieve the following two security functions by making minor modifications to an existing entanglement quantum key distribution scheme. Function A: The entanglement source that provided the appropriate line (entanglement state) gets the fee. Function B: The fee is not stolen by other entanglement sources.

[0005] The reward receiving method according to the present disclosure includes the steps of: an entanglement generator included in an entanglement quantum key distribution system that performs entanglement quantum key distribution sends a first modulated entangled state obtained by modulating a first entangled state using a first random number set consisting of one or more random numbers; and a second modulated entangled state obtained by modulating a second entangled state using a second random number set consisting of one or more random numbers, to a first user device and a second user device included in the entanglement quantum key distribution system; and when communication is performed between the first user device and the second user device based on the first random number set and a result of measuring the first modulated entangled state, if a first evidence key generated by the entanglement generator based on a verification random number, the second random number set, and a result of measuring the second modulated entangled state by the second user device, and a second evidence key generated by the first user device based on the verification random number and a result of measuring the second modulated entangled state by the first user device, match, The entanglement generator receives a reward from the first user device for sending the first modulated entangled state.

[0006] According to the present disclosure, there is realized a reward receiving method in which, when communication is performed between a first user device and a second user device based on a first random number set and a result of measuring the first modulated entangled state, if the first evidence key and the second evidence key match, the entanglement generating device receives a reward from the first user device for sending the first modulated entangled state. The reward receiving method is realized by making a minor modification to an existing entanglement quantum key distribution scheme. Therefore, according to the present disclosure, the above two security functions can be realized by making a minor modification to an existing entanglement quantum key distribution scheme.

[0007] FIG. 1 is a diagram showing an example of the configuration of an entanglement quantum key distribution system 90 according to a first embodiment. FIG. 2 is a diagram showing an example of the hardware configuration of an entanglement generating device 100 according to the first embodiment. FIG. 3 is a diagram explaining an outline of the operation of the entanglement quantum key distribution system 90 according to the first embodiment. FIG. 4 is a diagram explaining the operation of the entanglement quantum key distribution system 90 according to the first embodiment. FIG. 5 is a diagram showing an example of the hardware configuration of an entanglement generating device 100 according to a modification of the first embodiment. FIG. 6 is a diagram explaining the operation of the entanglement quantum key distribution system 90 according to a second embodiment.

[0008] In the description of the embodiments and the drawings, the same elements and corresponding elements are given the same reference numerals. The description of elements given the same reference numerals will be omitted or simplified as appropriate. Arrows in the drawings mainly indicate the flow of data or the flow of processing. Furthermore, "unit" may be read as "circuit," "step," "procedure," "process," or "circuitry" as appropriate.

[0009] Embodiment 1. This embodiment will be described in detail below with reference to the drawings. This embodiment discloses a method for realizing a security function (triple quantum key distribution). This embodiment aims to enable switching between three types of key sharing functions (hereinafter referred to as "AB QKD," "BC QKD," and "CA QKD," respectively): key sharing between user pair AB, user pair BC, and user pair CA. User pair AB is a pair of user A and user B. User pair BC is a pair of user B and entanglement source C. User pair CA is a pair of entanglement source C and user A. More precisely, in this embodiment, even after quantum communication is completed, it is permitted to decide which quantum key distribution to perform among AB QKD, BC QKD, and CA QKD. Then, after quantum communication is completed, different classical data processing is performed on the result of the quantum communication depending on the decision on which quantum key distribution to perform, thereby actually realizing the quantum key distribution. In this specification, user A, user B, and entanglement source C may be simply referred to as "A," "B," and "C," respectively. "User A" may refer to the device used by user A, i.e., the first user device. "User B" may refer to the device used by user B, i.e., the second user device. "User A" may be considered the second user device, and "user B" may be considered the first user device. As a specific example, when BC QKD is selected, A, B, and C perform classical data processing corresponding to BC QKD, and only B and C have the secret key k BC Then, each user other than B and C obtains the secret key k BC In other words, an external eavesdropper will not only know the secret key k, but also A. BC Furthermore, the same applies to the case where AB QKD or CA QKD is selected as the quantum key distribution method. In other words, the following sentences are valid when the symbols A, B, and C are arbitrarily substituted for each other in this example.

[0010] ***Configuration*** In this embodiment, functions for performing passive modulation and classical data processing are added to a device that employs a conventional entanglement quantum key distribution scheme. Because modifications related to this embodiment are easy to make, this embodiment does not impair the advantage of entanglement quantum key distribution, that is, that it can be implemented using current technology.

[0011] 1 shows an example of the configuration of an entanglement quantum key distribution system 90 according to this embodiment. The entanglement quantum key distribution system 90 performs entanglement quantum key distribution and includes an entanglement generating device 100 and two user devices 200. The multiple devices included in the entanglement quantum key distribution system 90 are communicatively connected. The entanglement generating device 100 may also be referred to as "C." The two user devices 200 may also be referred to as "A" and "B," respectively.

[0012] The entanglement generator 100 is an entanglement source and includes a quantum communication unit 110, an information processing unit 120, and a classical communication unit .

[0013] The quantum communication unit 110 has a function of generating an entangled state and a function of performing quantum communication. The quantum communication unit 110 generates a random number set consisting of one or more random numbers, modulates the entangled state using the random number set to generate a modulated entangled state, and sends the modulated entangled state to the first user device and the second user device. The random number set and a measurement result of the modulated entangled state are used to generate a private key for quantum key distribution. At least one of the first user device, the second user device, and the entanglement generating device 100 determines whether the measurement result of the modulated entangled state is used in communication between the first user device and the second user device or in communication between the entanglement generating device 100 and the first user device.

[0014] The information processing unit 120 has a function of performing classical data processing. When it is determined that the measurement result of the modulated entangled state is to be used in communication between the first user device and the second user device, the information processing unit 120 publishes a random number set to the first user device and the second user device. When it is determined that the measurement result of the modulated entangled state is to be used in communication between the entanglement generating device 100 and the first user device, the information processing unit 120 generates a verification random number, publishes the verification random number to the first user device, and generates a private key for quantum key distribution based on the random number set, the verification random number, and the measurement result of the modulated entangled state published by the second user device.

[0015] The classical communication unit 130 has a function of executing classical communication.

[0016] The user device 200 includes a quantum communication unit 210 , an information processing unit 220 , and a classical communication unit 230 .

[0017] The quantum communication unit 210 has a function of receiving and measuring a quantum state. The quantum communication unit 210 measures a modulated entangled state. A specific example of the quantum state is a qubit state.

[0018] The information processing unit 220 is similar to the information processing unit 120. When it is determined that the measurement result of the modulated entangled state is to be used in communication between the user device 200 and the second user device, the information processing unit 220 generates a private key for quantum key distribution based on the measurement result of the modulated entangled state and a set of random numbers made public by the entanglement generating device 100. When it is determined that the measurement result of the modulated entangled state is to be used in communication between the entanglement generating device 100 and the user device 200, the information processing unit 220 generates a private key for quantum key distribution based on the verification random number made public by the entanglement generating device 100 and the measurement result of the modulated entangled state.

[0019] The classical communication unit 230 is similar to the classical communication unit 130 .

[0020] 2 shows an example of the hardware configuration of the entanglement generator 100 according to this embodiment. The entanglement generator 100 is hardware that functions as an entanglement source and is composed of hardware including a computer. The entanglement generator 100 may be composed of multiple computers.

[0021] As shown in the figure, the entanglement generator 100 is a computer that includes hardware such as a processor 11, a memory 12, an auxiliary storage device 13, a quantum communication device 14, and a classical communication device 15. These pieces of hardware are appropriately connected via signal lines 19.

[0022] The processor 11 is an integrated circuit (IC) that performs arithmetic processing and controls the hardware of a computer. Specific examples of the processor 11 include a central processing unit (CPU), a digital signal processor (DSP), or a graphics processing unit (GPU). The entanglement generating device 100 may include multiple processors that replace the processor 11. The multiple processors share the role of the processor 11.

[0023] The memory 12 is typically a volatile storage device, specifically a random access memory (RAM). The memory 12 is also called a primary storage device or a main memory. Data stored in the memory 12 is saved in the secondary storage device 13 as needed.

[0024] The auxiliary storage device 13 is typically a non-volatile storage device, and specific examples thereof include a ROM (Read Only Memory), an HDD (Hard Disk Drive), or a flash memory. Data stored in the auxiliary storage device 13 is loaded into the memory 12 as needed. The memory 12 and the auxiliary storage device 13 may be configured integrally.

[0025] The quantum communication unit 110 is realized by the quantum communication device 14, which generates an entangled state and performs quantum communication.

[0026] The classical communication device 15 is a receiver and a transmitter. A specific example of the classical communication device 15 is a communication chip or a NIC (Network Interface Card).

[0027] The auxiliary storage device 13 stores an entanglement quantum key distribution program. The entanglement quantum key distribution program is a program that causes a computer to realize the functions of each unit included in the entanglement generating device 100. The entanglement quantum key distribution program is loaded into the memory 12 and executed by the processor 11. The functions of each unit included in the entanglement generating device 100 are realized by software.

[0028] Data used when executing the entanglement quantum key distribution program and data obtained by executing the entanglement quantum key distribution program are stored in a storage device as appropriate. Each part of the entanglement generating device 100 uses a storage device as appropriate. Specific examples of the storage device include at least one of the memory 12, the auxiliary storage device 13, a register in the processor 11, and a cache memory in the processor 11. Note that the terms "data" and "information" may have the same meaning. The storage device may be independent of the computer. The functions of the memory 12 and the auxiliary storage device 13 may be realized by other storage devices.

[0029] The entanglement quantum key distribution program may be recorded on a computer-readable non-volatile recording medium. Specific examples of the non-volatile recording medium include an optical disk, a magnetic disk, and a flash memory. The entanglement quantum key distribution program may be provided as a program product.

[0030] The hardware configuration of the user device 200 is similar to that of the entanglement generating device 100, except for the quantum communication unit 110. The quantum communication device 14 included in the user device 200 does not generate or transmit an entangled state, but measures the quantum state (including the entangled state).

[0031] ***Explanation of Operation*** The operating procedures of each device included in the entanglement quantum key distribution system 90 are collectively referred to as an entanglement quantum key distribution method. Also, the programs that realize the operations of each device included in the entanglement quantum key distribution system 90 are collectively referred to as an entanglement quantum key distribution program.

[0032] 3 is a diagram for explaining an outline of the operation of entanglement quantum key distribution. With reference to FIG. 3, an outline of the difference between the operation of this embodiment and the operation of the prior art will be explained.

[0033] (Difference in Step S1) In conventional entanglement quantum key distribution, C always sends one type of entangled state. On the other hand, in this embodiment, random modulation is applied to the entangled state. To be precise, C generates a random number and then sends an entangled state specified by the value of the generated random number. Here, the types of entangled states corresponding to the values ​​of the generated random numbers are different from each other.

[0034] (Difference in Step S2) Step S2 is the same as in conventional entanglement quantum key distribution, that is, A and B each receive half of the entangled state and measure the received entangled state.

[0035] Steps S1 and S2 are sometimes referred to as the "quantum communication phase" (quantum communication phase) because they require the transmission and reception of quantum states. On the other hand, step S3 is a step that does not require the transmission and reception of quantum states at all. That is, step S3 can be realized only by classical data processing, i.e., by existing communications such as the Internet and calculations using existing computers. Therefore, step S3 is sometimes referred to as the "classical data processing phase" (classical communication phase). In the quantum communication phase consisting of steps S1 and S2, the same operations are performed regardless of whether quantum key distribution is performed among AB QKD, CA QKD, and BC QKD. Furthermore, the data obtained by A, B, and C in the quantum communication phase contains information that allows them to fully respond regardless of whether quantum key distribution among AB QKD, CA QKD, or BC QKD is selected. Then, even after the quantum communication phase is completed, each of A, B, and C can select any one of the quantum key distributions, AB QKD, CA QKD, and BC QKD, and can actually execute the selected quantum key distribution by changing the processing in the classical data processing phase depending on the selected quantum key distribution.

[0036] (Difference in step S3) Each of A, B, and C performs classical data processing according to the selected type of quantum key distribution (AB QKD, BC QKD, or CA QKD). As a specific example, if BC QKD is selected as the quantum key distribution, each of A, B, and C performs classical data processing corresponding to BC QKD, and only B and C possess the private key k BC Then, k_BC is known to no one other than B and C. In other words, it is completely unknown to A, let alone an external eavesdropper. The same can be said when AB QKD or CA QKD is selected as the quantum key distribution method. In other words, the statement in the previous paragraph in which the symbols A, B, and C are arbitrarily substituted is also valid. As a result, the operation shown in Figure 4 is realized.

[0037] Fig. 4 is a diagram illustrating the operation of the entanglement quantum key distribution system 90. The operation will be described in detail below with reference to Fig. 4. In the Bennett-Brassard-Mermin 1992 (BBM92) system (Reference 1), which is one method of entanglement quantum key distribution, the process shown in Fig. 3 is performed. In this embodiment, the operation is modified as follows.

[0038] [Reference 1] Charles H. Bennett, Gilles Brassard, and N. David Mermin, “Quantum cryptography without Bell's theorem,” Physical Review Letters 68,557 (American Physical Society, 1992).

[0039] [Quantum Communication Phase] Each of A, B, and C repeats the following steps S1 and S2 n times, where n is any natural number.

[0040] (Step S1: Entangled state transmission by C) This step is a modified version of step S1 in the BBM92 method shown in Fig. 3. In the BBM92 method, C generates a Bell state, which is a type of entangled state, and sends half of the generated Bell state to A and half to B. [Equation 1] shows the Bell state.

[0041]

[0042] Here, we will organize the symbols used in quantum mechanics. Note that due to restrictions on the characters that can be used, notations different from those used in mathematical formulas may be used in this text. In [Mathematical Formula 1], |0> and |1> are orthonormal vectors in a two-dimensional complex vector space. In quantum mechanics, states are represented by vectors. Therefore, vectors are also called states. Furthermore, the two states {|0>, |1>} form a basis, and these two states are also specifically called the Z basis. Furthermore, the two states {|0~>, |1~>} are called the X basis. Here, "0~" means the number 0 with a superscript tilde attached. "1~" is the same as "0~". The meaning of the superscript tilde is as shown in [Mathematical Formula 2].

[0043]

[0044] The symbol of two intersecting lines in a circle represents a tensor product. As a specific example, the first term of [Equation 3] represents that both parts A and B are in the 0 state, and the second term of [Equation 3] represents that both parts A and B are in the 1 state.

[0045]

[0046] |β 00 > AB represents a superposition of two states, the 0 state and the 1 state. When a state cannot be written as a single tensor product, the state is said to be entangled. As a concrete example, each term shown in [Equation 3] can be written as a single tensor product, so it is not entangled. On the other hand, |β 00 > AB cannot be written as a single tensor product, so they are "entangled." In this embodiment, this procedure is modified as follows.

[0047] (Process 1) The quantum communication unit 110 of C is in the state |β 00 > AB Generate.

[0048] (Process 2) The quantum communication unit 110 of C selects values ​​for the random number bits h, x, and z, where h, x, zε{0, 1}.

[0049] (Process 3) When z=1, the quantum communication unit 110 of C performs a phase flip (Z operator) in the Z basis on the A part of the state at hand.

[0050] (Process 4) When x=1, the quantum communication unit 110 of C performs a bit flip (X operator) in the Z basis on the A part of the state at hand.

[0051] (Process 5) When h=1, the quantum communication unit 110 of C performs a transformation (Hadamard transformation, H operator) on the A part of the state at hand to swap the Z basis and the X basis.

[0052] (Process 6) The quantum communication unit 110 of C sends half of the state obtained by executing the above process to each of user A and user B. That is, the quantum communication unit 110 of C sends half of the state |β 00 > AB Instead of sending it as is, state |β 00 > AB In other words, the quantum communication unit 110 of C randomly selects h, x, z∈{0, 1} and sends the entangled state corresponding to the combination of selected values ​​to each of A and B, that is, sends the entangled state shown in [Equation 4]. The entangled state sent is one of eight types of entangled states. The entangled state shown in [Equation 4] corresponds to a modulated entangled state. h, x, and z correspond to each random number that makes up the random number group.

[0053]

[0054] Currently, the entangled state is often implemented using the polarization state of light. As a specific example, it is possible to implement |0> as the vertical polarization state (vibrating in the 0 degree direction) of a single photon, and |1> as the horizontal polarization state (vibrating in the 90 degree direction) of a single photon. In this implementation, the above operations mean the following. Part A and part B each refer to a separate single photon. The first term in [Equation 3] indicates that part A and part B are both in the vertical polarization state. The second term in [Equation 3] indicates that part A and part B are both in the horizontal polarization state. "State |β 00 > AB"Generating" means generating a superposition state of the first term of [Equation 3] and the second term of [Equation 3] by a method such as parametric down-conversion. "Phase flip in the Z basis (Z operator)" means phase inversion of only the horizontal polarization state (switching the sign of the coefficient of the vector component). "Bit flip in the Z basis (X operator)" means rotating by 90 degrees, that is, switching between vertical and horizontal polarization. "Hadamard transform (H operator)" means rotating the polarization direction by 45 degrees by the operation of an element or by rotating a device. In other words, it means changing vertical polarization into either right-diagonal (45-degree) polarization or left-diagonal (135-degree) polarization. "Sending half of the obtained state to user A and half to user B" means sending part A and part B, which are single photons generated and manipulated by quantum communication unit 110 of C, to user A and user B, respectively, via optical fiber or the like.

[0055] (Step S2: Measurement by A and B) This step is the same as the step S2 of the BBM92 method shown in Fig. 3. The quantum communication units 210 of A and B each measure the received state in the same way as in the BBM92 method. That is, A and B each randomly select either the Z basis or the X basis, measure the received state in the selected basis, and express the measurement result as b A , b B ∈{0, 1}. The process of this step is described more specifically as follows.

[0056] The quantum communication unit 210 of A receives the bit h A After randomly selecting ∈{0, 1}, the receiving state is A Measure at the base and compare the results with b A ∈{0, 1}. The quantum communication unit 210 of B records the bit h B After randomly selecting ∈{0, 1}, the receiving state is B Measure at the base and compare the results with b B ∈{0, 1}. Here, the Z basis and the X basis are written as the 0 basis and the 1 basis, respectively. This notation will be used hereafter.

[0057] The data obtained in the above n times of steps S1 and S2 is set to r=(r 1 , ..., r n ) where r is called the "result". i = (h i , x i , z i , h Ai , b Ai , h Bi , b Bi ) where i is an integer between 1 and n.

[0058] The operations up to this point are called the quantum communication phase, meaning that they require the transmission and reception of quantum states. Furthermore, the same operations are performed regardless of whether AB QKD, CA QKD, or BC QKD is used for quantum key distribution.

[0059] When implementing a device using the polarization state of light, the above operations mean the following: "Measurement in Z basis (0 basis)" means determining whether a photon is in a vertically polarized or horizontally polarized state by measurement. In this case, if vertical polarization is measured, the result is b = 0, and if horizontal polarization is measured, b = 1. "Measurement in X basis (1 basis)" means measuring in Z basis (0 basis) after rotating the photon by 45 degrees (Hadamard transform). Similarly, this means determining whether a photon is in a right-diagonal (45 degrees) polarized state or a left-diagonal (135 degrees) polarized state by measurement. In this case, if right-diagonal polarization is measured, the result is b = 0, and if left-diagonal polarization is measured, b = 1.

[0060] [Classical Data Processing Phase] In the following processing, no transmission or reception of quantum states is required. Furthermore, the following processing is classical data processing, i.e., processing that can be realized only through existing communications such as the Internet and processing by existing computers. Therefore, the following processing is referred to as the classical data processing phase. In the classical data processing phase, first, a determination is made as to which quantum key distribution to perform from among AB QKD, CA QKD, and BC QKD. Then, depending on the determination, one of steps S3-AB, S3-CA, and S3-BC shown below is performed. The quantum key distribution to perform is determined based on a discussion between at least two parties, for example, user A, user B, and entangled light source C. These three steps correspond to modified processing equivalent to step S3 of the BBM92 method shown in FIG. 3 .

[0061] (Step S3-AB: Classical Data Processing Phase for AB QKD) When the result r is used in AB QKD, A, B, and C each perform the following classical data processing.

[0062] (Process 1: Preliminary classical data processing) Each device performs the following process for i=1, ..., n. (a) The information processing unit 120 of C performs h i and x i and Z i Each of these will be made public.

[0063] (b) The information processing unit 220 of A receives raw key data h Ai ' and raw key data b Ai Each of the above expressions is calculated using the formula shown in [Formula 5]. Note that the equal signs in each of [Formula 5], [Formula 6], [Formula 7], and [Formula 8] hereinafter all refer to the remainder when divided by the integer 2. In other words, "modulo 2" is abbreviated in these equations.

[0064]

[0065] (Process 2: Final classical data processing) The information processing units 220 of A and B respectively perform h Ai ' and b Ai ' and h Bi and b Bi(i=1,...,n) is regarded as a raw key in the BB84 method (see Reference 2 for a specific example), and the secret key k is obtained by performing error rate estimation and key distillation in the same way as in BB84. AB That is, the information processing units 220 of A and B generate a secret key for quantum key distribution based on the random number set made public by the entanglement generator 100 and the measurement result of the modulated entangled state. In the final classical data processing, an authenticated public communication channel is used for communication between A and B.

[0066] [Reference 2] Masahito Hayashi and Toyohiro Tsurumaru, “Concise and tight security analysis of the Bennett-Brassard 1984 protocol with finite key lengths,” New Journal of Physics 14, 093014 (2012).

[0067] (Step S3-CA: Classical Data Processing Phase for CA QKD) When the result r is used in CA QKD, A, B, and C each perform the following classical data processing.

[0068] (Process 1: Preliminary classical data processing) Each device performs the following process for i=1, ..., n. (a) The information processing unit 220 of B performs h Bi and b Bi Each of these will be made public.

[0069] (b) The information processing unit 120 of C generates the random number bit s i Generate the generated s i After that, the information processing unit 120 of C releases the raw key data h Ci ' and raw key data b Ci The random number bits s are calculated using the formula shown in [Equation 6]. i corresponds to the random number for verification.

[0070]

[0071] (c) The information processing unit 220 of A receives the raw key data h Ai ' and raw key data b Ai ' and are calculated using the formula shown in [Equation 7].

[0072]

[0073] (Process 2: Final classical data processing) Each of the information processing unit 120 of C and the information processing unit 220 of A performs h Ci ' and b Ci ' and h Ai ' and b Ai ' (i = 1, ..., n) is regarded as a raw key of the BB84 system, and the secret key k is obtained by performing error rate estimation and key distillation in the same way as the BB84 system. CA That is, the information processing unit 120 of C generates a private key for quantum key distribution based on the random number set, the verification random number, and the measurement result of the modulated entangled state made public by the second user device. Also, the information processing unit 220 of A generates a private key for quantum key distribution based on the verification random number made public by the entanglement generating device 100 and the measurement result of the modulated entangled state. In the final classical data processing, an authenticated public communication channel is used for communication between CA.

[0074] (Step S3-BC: Classical Data Processing Phase for BC QKD) When the result r is used in BC QKD, each of A, B, and C exchanges all symbols A in the above-mentioned "Classical Data Processing for CA QKD" with symbols B, and performs the preliminary classical data processing in the "Classical Data Processing Phase for CA QKD" by replacing the symbols A with symbols B. Ci The classical data processing is performed by changing the equation of ' to [Equation 8].

[0075]

[0076] ***Description of Effect of First Embodiment*** This embodiment alone can achieve the effect of reducing wasteful quantum communication in quantum key distribution. More details are as follows. Generally, quantum communication has the property that its communication speed is overwhelmingly inferior to that of classical communication. Therefore, practical quantum key distribution systems are operated in a way that does not impair user convenience due to this property. Specifically, in this operation, quantum communication is constantly performed to generate a private key, regardless of whether or not users A and B request encrypted communication, and the generated private key is stored. Then, in this operation, the stored private key is handed over when users A and B actually request encrypted communication. However, this operation has the problem that if users A and B do not perform secure communication such as quantum cryptography communication, all previously performed quantum communication is wasted. On the other hand, in this embodiment, the results of quantum communication unused by users A and B can be diverted to either BC QKD or CA QKD. As a result, according to this embodiment, the utilization rate of quantum communication can be improved in terms of a long-term average value. In other words, according to this embodiment, it is possible to reduce waste in quantum communication.

[0077] Here, the intuitive reason why the present embodiment can actually realize three types of quantum key distribution, AB QKD, BC QKD, and CA QKD, will be described.

[0078] (Reasons for AB QKD) In ​​step S1, the Bell state (|β 00 > AB ) for the A part of the random unitary transformation (H h X x Z z ) A In step S3-AB-processing 1-(a), the random unitary transformation (H h X x Z z ) A The types of random number bits, that is, the random number bits h, x, and z, are made public. Therefore, A can determine the random unitary transformation (H h X x Zz ) A By applying the inverse transformation for the A part to the A part, a random unitary transformation (H h X x Z z ) A Furthermore, the inverse transformation is equivalent to the reinterpretation of the result of the process performed by A in step S3-AB-processing 1-(b). As a result, the situation is such that C does not have "|β 00 > AB ", and A and B each send out "|β 00 > AB This is equivalent to performing BB84 measurement on the generated private key k. AB It can be said that there is information-theoretic security in

[0079] (Reason for CA QKD) First, as can be seen from a simple calculation, in reality, "C is in state |α hxz > AB In step S2, B is sent. hxz > AB By measuring the result h B and b B The situation where "C obtains parameter h B and b B A BB84 state designated by h X x Z z Furthermore, the calculations of C and A in step S3-CA are performed using the random transformation H h X x Z z Therefore, the situation is equivalent to the BB84 protocol between CAs. CA The reason for BC QKD is the same as that for CA QKD.

[0080] ***Other Configurations*** <Modification 1> Fig. 5 shows an example of the hardware configuration of the entanglement generating device 100 according to this modification. The entanglement generating device 100 includes a processing circuit 18 instead of the processor 11, the processor 11 and memory 12, the processor 11 and auxiliary storage device 13, or the processor 11, memory 12, and auxiliary storage device 13. The processing circuit 18 is hardware that realizes at least a portion of the components included in the entanglement generating device 100. The processing circuit 18 may be dedicated hardware, or may be a processor that executes a program stored in the memory 12.

[0081] When the processing circuit 18 is dedicated hardware, the processing circuit 18 may be, for example, a single circuit, a multiple circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof. The entanglement generator 100 may include multiple processing circuits that replace the processing circuit 18. The multiple processing circuits share the role of the processing circuit 18.

[0082] In the entanglement generating device 100, some functions may be realized by dedicated hardware, and the remaining functions may be realized by software or firmware.

[0083] The processing circuitry 18 is realized by, for example, hardware, software, firmware, or a combination thereof. The processor 11, memory 12, auxiliary storage device 13, and processing circuitry 18 are collectively referred to as "processing circuitry." In other words, the functions of the functional components of the entanglement generating device 100 are realized by the processing circuitry. The entanglement generating device 100 according to other embodiments may also have a configuration similar to that of this modification. The user device 200 may also have a processing circuitry 18 similar to that of this modification.

[0084] Second Embodiment The following mainly describes the differences from the above-described embodiment with reference to the drawings.

[0085] ***Description of Configuration*** The configuration of the entanglement quantum key distribution system 90 according to this embodiment is the same as the configuration of the entanglement quantum key distribution system 90 according to embodiment 1. In other words, this embodiment is realized by adding functions for performing passive modulation and classical data processing to a conventional entanglement quantum key distribution device. Note that this modification is easy, and therefore, in this embodiment, the advantage of entanglement quantum key distribution, that is, its ability to be implemented using current technology, is not impaired.

[0086] In this embodiment, a reward receiving method is realized in which the entanglement generating device 100 sends a first modulated entangled state and a second modulated entangled state to a first user device and a second user device, and when communication is performed between the first user device and the second user device based on a first random number set and the first modulated entangled state, if the first evidence key and the second evidence key match, the entanglement generating device 100 receives a reward from the first user device for sending the first modulated entangled state. Also, in this case, a reward payment method is realized in which the first user device pays the entanglement generating device 100 a reward for sending the first modulated entangled state. The first modulated entangled state is an entangled state generated by modulating the first entangled state using a first random number set consisting of one or more random numbers. The second modulated entangled state is an entangled state generated by modulating the second entangled state using a second random number set consisting of one or more random numbers. The first evidence key is a key generated by the entanglement generator 100 based on the verification random number, the second random number set, and a result of measurement of the second modulated entangled state by the second user device. The second evidence key is a key generated by the first user device based on the verification random number and a result of measurement of the second modulated entangled state by the first user device. The reward received by the entanglement generator 100 is also a reward for realizing encrypted communication between A and B.

[0087] The quantum communication unit 110 according to this embodiment generates a first random number set consisting of one or more random numbers, and generates a first modulated entangled state by modulating an entangled state using the first random number set. The quantum communication unit 110 generates a second random number set consisting of one or more random numbers, and generates a second modulated entangled state by modulating the entangled state using the second random number set. The quantum communication unit 110 transmits the first modulated entangled state and the second modulated entangled state to a first user device and a second user device.

[0088] The processing of the information processing unit 120 will be described when the first user device determines that the measurement result of the first modulated entangled state will be used in communication between the entanglement generating device 100 and the first user device, and also determines that the measurement result of the second modulated entangled state will be used in communication between the entanglement generating device 100 and the first user device. First, the information processing unit 120 publishes a first random number set to the first user device. Next, the information processing unit 120 generates a verification random number and publishes the verification random number to the first user device. Next, the information processing unit 120 generates a first secret key based on error rate estimation and key distillation using the second random number set, the verification random number, and the measurement result of the second modulated entangled state published by the second user device. Next, if the second secret key and the first secret key match, the information processing unit 120 receives a reward from the first user device for sending the first modulated entangled state. The second private key is a key generated by the first user device based on error rate estimation and key distillation using the verification random number and the result of measurement of the second modulation entanglement state by the first user device. The first private key corresponds to the first evidence key. The second private key corresponds to the second evidence key.

[0089] 6 is a diagram illustrating an example of the operation of the entanglement quantum key distribution system 90 according to this embodiment. The operation of the entanglement quantum key distribution system 90 according to this embodiment is the same as the operation of the entanglement quantum key distribution system 90 according to the first embodiment, but with the following modifications.

[0090] [Random Assignment Phase] The random assignment phase is added between the quantum communication phase and the classical data processing phase. The information processing unit 220 of A assigns each result of the quantum communication phase to the r AB and r for CA QKD CA To be precise, user A randomly assigns each integer from 1 to n to one of two groups (I AB and I CA ) Therefore, I AB ∪I CA = {1, ..., n} and I AB ∩I CA =φ (φ is an empty set). AB The result r with index i belongs to i The arrangement of these is r AB Also, I CA The result r with index j belongs to j The arrangement of these is r CA Let's say.

[0091] [Classical Data Processing Phase (Modified from the First Embodiment)] The information processing units 220 of A and B respectively process the results r AB By performing step S3-AB on the secret key k AB The information processing unit 120 of C and the information processing unit 220 of A each obtain the result r CA By performing step S3-CA on the private key k CA get.

[0092] [Reward Exchange Phase] The reward exchange phase (information exchange phase) is added after the classical data processing phase. The information processing unit 120 of C sends a secret key k CA If the following conditions are met, the information processing unit 220 of A will pay a reward to C. Note that the k presented by C CA is the first evidence key. CA is the second evidence key. If this condition is met, the first evidence key and the second evidence key are consistent. Condition: "The k presented by C CAis the k calculated by the information processing unit 220 of A. CA It matches up with

[0093] ***Explanation of Effects of Second Embodiment*** According to this embodiment, by making slight modifications to an existing entanglement quantum key distribution scheme, the following two security functions can be realized. Function A: An entanglement source that provides an appropriate line (entangled state) receives a fee for use. Function B: The fee is not stolen by other entanglement sources.

[0094] The reason why the configuration and operation of this embodiment achieve the security functions A and B is as follows. First, it is generally true that "in order for the quantum key distribution protocol to be completed to the end and for the private key to be obtained, the estimated error rate calculated by the "error rate estimation step" within the quantum key distribution protocol must be equal to or less than a threshold value." Furthermore, in this embodiment, "r AB and r CA is selected randomly, the estimated error rates calculated within AB QKD and CA QKD coincide within the range of statistical error. Therefore, in this embodiment, it can be said that "if and only if AB QKD is successful, CA QKD will be successful." Therefore, according to this embodiment, security function A is established. Furthermore, from the nature of quantum key distribution, "the private key k obtained by CA QKD CA It is guaranteed that "is unknown to anyone other than A and C." Therefore, according to this embodiment, security function B is established. In intuitive terms, the above can be expressed as "private key k CA In other words, if someone has a secret key k CA If someone presents a statement, it is guaranteed that "the person in question did indeed generate the entangled state that A and B received."

[0095] Third Embodiment The following mainly describes the differences from the above-described embodiments.

[0096] ***Description of Configuration*** The configuration of the entanglement quantum key distribution system 90 according to this embodiment is the same as the configuration of the entanglement quantum key distribution system 90 according to the second embodiment.

[0097] The information processing unit 120 according to this embodiment does not generate a first secret key, but generates a first sieve key using a second random number set, a verification random number, and a measurement result of the second modulated entangled state published by the second user device. Furthermore, if the second sieve key and the first sieve key match, the information processing unit 120 receives a reward from the first user device for sending the first modulated entangled state. The second sieve key is a key generated by the first user device using the verification random number and a measurement result of the second modulated entangled state by the first user device. The first sieve key corresponds to a first evidence key and plays a role similar to the first secret key in the second embodiment. The second sieve key corresponds to a second evidence key and plays a role similar to the second secret key in the second embodiment.

[0098] Here, the processing of the information processing unit 120 will be described when the first user device determines that the measurement result of the first modulated entangled state will be used in communication between the entanglement generating device 100 and the first user device, and also determines that the measurement result of the second modulated entangled state will be used in communication between the entanglement generating device 100 and the first user device. First, the information processing unit 120 publishes a first random number set to the first user device and the second user device. Next, the information processing unit 120 generates a verification random number and publishes the verification random number to the first user device. Next, the information processing unit 120 generates a first sieve key using the second random number set, the verification random number, and the measurement result of the second modulated entangled state published by the second user device. Next, if the second sieve key and the first sieve key match, the information processing unit 120 receives a reward from the first user device for sending the first modulated entangled state.

[0099] ***Explanation of Operation*** [Classical Data Processing Phase] The classical data processing phase according to this embodiment is a phase in which the result rCA The process for each device is modified as follows: CA However, each device only performs process 1 of step S3-CA, and does not perform process 2 of step S3-CA.

[0100] [Reward Exchange Phase] The reward exchange phase according to this embodiment is as follows.

[0101] (Process 1) The information processing unit 120 of C presents to A a sieve key in CA QKD.

[0102] (Process 2) If the following condition is met, A pays a reward to C. The sieve key presented by C corresponds to the first evidential key. The sieve key calculated by A's information processing unit 220 corresponds to the second evidential key. If this condition is met, the first evidential key and the second evidential key are consistent. Condition: "The error rate between the sieve key presented by C and the sieve key calculated by A's information processing unit 220 in CA QKD is equal to the estimated error rate calculated in AB QKD."

[0103] ***Explanation of Effect of Embodiment 3*** According to this embodiment, in addition to the effect of the above-mentioned embodiment, neither C nor A performs key distillation in step S3-CA. Therefore, according to this embodiment, the load of the classical data processing phase on each of C and A is significantly reduced.

[0104] Also, obviously, from the general construction of quantum key distribution, anyone who can present a sieve key can perform a key distillation algorithm to obtain the private key k CA Therefore, the sieve key is k CA Similarly, this is evidence that the person has created the entangled state. Therefore, the same effect as in the second embodiment can be obtained in this embodiment.

[0105] ***Other Embodiments*** The above-described embodiments can be freely combined, or any of the components of each embodiment can be modified, or any of the components can be omitted from each embodiment. Furthermore, the embodiments are not limited to those shown in embodiments 1 to 3, and various modifications are possible as needed. The procedures described using the drawings, etc. may be modified as appropriate.

[0106] 11 Processor, 12 Memory, 13 Auxiliary storage device, 14 Quantum communication device, 15 Classical communication device, 18 Processing circuit, 19 Signal line, 90 Entanglement quantum key distribution system, 100 Entanglement generator, 110 Quantum communication unit, 120 Information processing unit, 130 Classical communication unit, 200 User device, 210 Quantum communication unit, 220 Information processing unit, 230 Classical communication unit.

Claims

1. When an entanglement generator included in an entanglement quantum key distribution system that performs entanglement quantum key distribution sends a first modulated entangled state obtained by modulating a first entangled state using a first random number set consisting of one or more random numbers, and a second modulated entangled state obtained by modulating a second entangled state using a second random number set consisting of one or more random numbers, to a first user device and a second user device included in the entanglement quantum key distribution system, and communication is performed between the first user device and the second user device based on the first random number set and a result of measuring the first modulated entangled state, if a first evidence key generated by the entanglement generator based on a verification random number, the second random number set, and a result of measuring the second modulated entangled state by the second user device, and a second evidence key generated by the first user device based on the verification random number and a result of measuring the second modulated entangled state by the first user device, match, A reward receiving method in which the entanglement generator receives a reward from the first user device for sending the first modulated entangled state.

2. When an entanglement generator included in an entanglement quantum key distribution system that performs entanglement quantum key distribution sends a first modulated entangled state obtained by modulating a first entangled state using a first random number set consisting of one or more random numbers, and a second modulated entangled state obtained by modulating a second entangled state using a second random number set consisting of one or more random numbers, to a first user device and a second user device included in the entanglement quantum key distribution system, and communication is performed between the first user device and the second user device based on the first random number set and the first modulated entangled state, if a first evidence key generated by the entanglement generator based on a verification random number, the second random number set, and a result of measurement of the second modulated entangled state by the second user device, and a second evidence key generated by the first user device based on the verification random number and a result of measurement of the second modulated entangled state by the first user device, match, A reward payment method in which the first user device pays a reward to the entanglement generator for sending the first modulated entangled state.

3. An entanglement generator included in an entanglement quantum key distribution system that is a system comprising a first user device and a second user device and that performs entanglement quantum key distribution, the entanglement generator comprising: a quantum communication unit that generates a random number group consisting of one or more random numbers, generates a modulated entangled state by modulating an entangled state using the random number group, and sends the modulated entangled state to the first user device and the second user device, wherein the random number group and the measurement result of the modulated entangled state are used to generate a private key in quantum key distribution.

4. The entanglement generating device according to claim 3, wherein at least one of the first user device, the second user device, and the entanglement generating device decides whether to use the measurement result of the modulated entangled state in communication between the first user device and the second user device or in communication between the entanglement generating device and the first user device, and the entanglement generating device further comprises: an information processing unit that, when it is decided that the measurement result of the modulated entangled state will be used in communication between the first user device and the second user device, discloses the random number set to the first user device and the second user device; and, when it is decided that the measurement result of the modulated entangled state will be used in communication between the entanglement generating device and the first user device, generates a verification random number and discloses the verification random number to the first user device, and generates a private key for quantum key distribution based on the random number set, the verification random number, and the measurement result of the modulated entangled state disclosed by the second user device.

5. The quantum communication unit generates a first random number group consisting of one or more random numbers, generates a first modulated entangled state by modulating an entangled state using the first random number group, generates a second random number group consisting of one or more random numbers, generates a second modulated entangled state by modulating the entangled state using the second random number group, and sends the first modulated entangled state and the second modulated entangled state to the first user device and the second user device; when it is determined by the first user device that a result of measuring the first modulated entangled state will be used in communication between the entanglement generator and the first user device and when it is determined by the first user device that a result of measuring the second modulated entangled state will be used in communication between the entanglement generator and the first user device, the information processing unit: discloses the first random number group to the first user device; 5. The entanglement generating device of claim 4, further comprising: generating the verification random number; disclosing the verification random number to the first user device; generating a first secret key based on error rate estimation and key distillation using the second random number group, the verification random number, and a measurement result of the second modulated entangled state disclosed by the second user device; and receiving a reward from the first user device for sending the first modulated entangled state if the first secret key matches the second secret key generated by the first user device based on error rate estimation and key distillation using the verification random number and a measurement result of the second modulated entangled state by the first user device.

6. The quantum communication unit generates a first random number group consisting of one or more random numbers, generates a first modulated entangled state by modulating an entangled state using the first random number group, generates a second random number group consisting of one or more random numbers, generates a second modulated entangled state by modulating the entangled state using the second random number group, and sends the first modulated entangled state and the second modulated entangled state to the first user device and the second user device; when it is determined by the first user device that a result of measuring the first modulated entangled state will be used in communication between the entanglement generator and the first user device and when it is determined by the first user device that a result of measuring the second modulated entangled state will be used in communication between the entanglement generator and the first user device, the information processing unit: publishes the first random number group to the first user device and the second user device; 5. The entanglement generating device of claim 4, further comprising: generating the verification random number; disclosing the verification random number to the first user device; generating a first sieve key using the second random number group, the verification random number, and a measurement result of the second modulated entangled state disclosed by the second user device; and receiving a reward from the first user device for sending the first modulated entangled state if the second sieve key generated by the first user device using the verification random number and a measurement result of the second modulated entangled state by the first user device matches the first sieve key.

7. A system comprising an entanglement quantum key distribution system that performs entanglement quantum key distribution, the system comprising an entanglement generator and a second user device, wherein the user device comprises: the entanglement generator generates a random number group consisting of one or more random numbers, generates a modulated entangled state by modulating an entangled state using the random number group, and sends the modulated entangled state to the user device and the second user device; the random number group and a measurement result of the modulated entangled state are used to generate a private key in quantum key distribution; and when at least one of the user device, the second user device, and the entanglement generator decides whether to use the measurement result of the modulated entangled state in communication between the user device and the second user device or in communication between the entanglement generator and the user device, a quantum communication unit that measures the modulated entangled state; a user device comprising: an information processing unit that, when it is determined that the measurement result of the modulated entangled state will be used in communication between the user device and the second user device, generates a private key for quantum key distribution based on the set of random numbers made public by the entanglement generator and the measurement result of the modulated entangled state; and, when it is determined that the measurement result of the modulated entangled state will be used in communication between the entanglement generator and the user device, generates a private key for quantum key distribution based on the verification random number made public by the entanglement generator and the measurement result of the modulated entangled state.

8. An entanglement quantum key distribution system comprising an entanglement generating device according to any one of claims 3 to 6, and a user device according to claim 7 as the first user device.

9. An entanglement generation method performed by an entanglement generator included in an entanglement quantum key distribution system comprising a first user device and a second user device, the entanglement generator generating a random number set consisting of one or more random numbers, generating a modulated entangled state by modulating an entangled state using the random number set, and sending the modulated entangled state to the first user device and the second user device, wherein the random number set and a measurement result of the modulated entangled state are used to generate a private key in quantum key distribution.

10. A private key generation method executed by a user device included in an entanglement quantum key distribution system that is a system comprising an entanglement generator and a second user device and that performs entanglement quantum key distribution, wherein the entanglement generator generates a random number set consisting of one or more random numbers, generates a modulated entangled state by modulating an entangled state using the random number set, and sends the modulated entangled state to the user device and the second user device, the random number set and a measurement result of the modulated entangled state are used to generate a private key for quantum key distribution, and when at least one of the user device, the second user device, and the entanglement generator decides whether to use the measurement result of the modulated entangled state in communication between the user device and the second user device or in communication between the entanglement generator and the user device, the user device measures the modulated entangled state, A private key generation method for generating a private key for quantum key distribution based on the set of random numbers published by the entanglement generator and the measurement result of the modulated entangled state when it is decided that the measurement result of the modulated entangled state will be used in communication between the user device and the second user device, and for generating a private key for quantum key distribution based on the verification random number published by the entanglement generator and the measurement result of the modulated entangled state when it is decided that the measurement result of the modulated entangled state will be used in communication between the entanglement generator and the user device.

Citation Information

Patent Citations

  • Quantum key distribution system and quantum key creating method

    JP2007318445A