Apparatus and method for performing arbitrator-based message-attached quantum signature by using quantum entanglement without using direct connection channel between transmitter and receiver in communication system

The mediator-based quantum signature method using GHZ or Bell states addresses the challenge of performing quantum signatures without direct connections, enabling secure and reliable communication by mediating quantum entanglement processes.

WO2026054143A1PCT designated stage Publication Date: 2026-03-12LG ELECTRONICS INC
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-09
Publication Date
2026-03-12

AI Technical Summary

Technical Problem

Existing communication systems face challenges in performing quantum signatures without a direct connection path between senders and receivers, necessitating innovative methods to facilitate secure and reliable quantum entanglement-based signature processes.

Method used

A mediator-based quantum signature method using quantum entanglement is employed, where an arbitrator mediates the process by transmitting qubit messages and signature information through quantum channels, utilizing Greenberger-Horne-Zeilinger (GHZ) or Bell states for verification and encryption.

Benefits of technology

Enables effective quantum signature operations even in the absence of a direct path between senders and receivers, ensuring secure and reliable communication through intermediary-mediated quantum entanglement processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024013599_12032026_PF_FP_ABST
    Figure KR2024013599_12032026_PF_FP_ABST
Patent Text Reader

Abstract

The purpose of the present disclosure is to perform an arbitrator-based quantum signature by using a single photon without using a direct connection channel between a transmitter and a receiver in a communication system, and a method, which is performed by a first device, may comprise the steps of: performing an initial access procedure with a base station; establishing a connection with the base station; transmitting capability information to the base station; establishing a quantum channel with a third device for a quantum signature with a second device; and transmitting, to the third device through the quantum channel, request information comprising at least one qubit message encrypted by using a secret symmetric key shared between the first device and the third device, as information for requesting generation of signature information for the quantum signature.
Need to check novelty before this filing date? Find Prior Art

Description

Device and method for performing a mediator-based message-attached quantum signature using quantum entanglement without using a direct connection channel between a sender and a receiver in a communication system

[0001] The present disclosure relates to a communication system, and to a device and method for performing a mediator-based message-attached quantum signature using quantum entanglement without using a direct connection channel between a sender and a receiver in the communication system.

[0002] Wireless access systems are widely deployed to provide various types of communication services, such as voice and data. Typically, wireless access systems are multiple access systems that support communications with multiple users by sharing available system resources (e.g., bandwidth, transmission power). Examples of multiple access systems include code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), orthogonal frequency division multiple access (OFDMA), and single-carrier frequency division multiple access (SC-FDMA).

[0003] In particular, as numerous communication devices demand greater communication capacity, enhanced mobile broadband (eMBB) communication technologies are being proposed, improving upon existing radio access technology (RAT). Furthermore, massive machine type communications (mMTC), which connects multiple devices and objects to provide diverse services anytime and anywhere, as well as communication systems that consider reliability and latency-sensitive services / user equipment (UE), are being proposed. Various technological configurations are being proposed for these solutions.

[0004] The present disclosure relates to a device and method for effectively performing quantum signature in a communication system.

[0005] The present disclosure relates to a device and method for performing quantum signature in a communication system in which there is no direct path between a sender and a receiver.

[0006] The present disclosure relates to a device and method for performing quantum signatures using quantum entanglement without using a direct path between a sender and a receiver in a communication system.

[0007] The present disclosure relates to a device and method for performing quantum signature using an arbitrator without using a direct path in a communication system.

[0008] The present disclosure relates to a device and method for performing a quantum signature scheme with appendix in a communication system in a situation where there is no direct path between a sender and a receiver.

[0009] The present disclosure relates to a device and method for a transmitter in a communication system to transmit qubit messages to an arbitrator to request signature information for quantum signatures.

[0010] The present disclosure relates to a device and method for transmitting request information generated based on a qubit message to an arbitrator for a quantum signature in a communication system to request signature information.

[0011] The present disclosure relates to a device and method for transmitting signature information generated based on quantum information received from a sender to a receiver by an intermediary for quantum signature in a communication system.

[0012] The present disclosure relates to a device and method for performing verification using Greenberger-Horne-Zeilinger (GHZ) state or bell state particles as an intermediary for quantum signature in a communication system.

[0013] The present disclosure relates to a device and method for an arbitrator for quantum signature in a communication system to encrypt and decrypt information for its own verification operation with its own secret key.

[0014] The technical objectives to be achieved in the present disclosure are not limited to those mentioned above, and other technical tasks not mentioned can be considered by a person having ordinary skill in the technical field to which the technical configuration of the present disclosure is applied from the embodiments of the present disclosure described below.

[0015] As an example of the present disclosure, a method performed by a first device in a communication system may include the steps of performing an initial connection procedure with a base station, establishing a connection with the base station, transmitting capability information to the base station, establishing a quantum channel with a third device for quantum entanglement-based quantum signature with a second device, and transmitting request information to the third device through the quantum channel, the request information including at least one qubit message encrypted using a secret symmetric key shared between the first device and the third device, as information for requesting generation of signature information for the quantum signature.

[0016] As an example of the present disclosure, a method performed by a second device in a communication system may include the steps of: receiving signature information from a third device that mediates a quantum signature based on quantum entanglement with a first device; storing a first qubit message received together with the signature information; transmitting to the third device, as first transfer information generated based on the signature information, quantum information generated based on the signature information and the qubit message; receiving, as second transfer information generated based on the first transfer information, quantum information including a result of a first verification performed based on the first transfer information from the third device; and performing a second verification based on the second transfer information.

[0017] As an example of the present disclosure, a method performed by a third device in a communication system may include the steps of: receiving, from the first device, request information including a qubit message encrypted using a first secret symmetric key shared between the first device and the third device as information for requesting generation of signature information for a quantum signature between the first device and the second device, and a plurality of qubit messages; transmitting, to the second device, signature information generated from the request information using a secret key of the third device and a second secret symmetric key shared between the second device and the third device, and at least one qubit message among the qubit messages; receiving, from the second device, first delivery information generated based on the signature information; performing first verification based on the first delivery information; and transmitting, to the second device, second delivery information for second verification of the second device, the second delivery information including verification result information indicating a result of the first verification.

[0018] As an example of the present disclosure, in a communication system, a first device may include a transceiver and a processor coupled to the transceiver, wherein the processor may be configured to perform an initial connection procedure with a base station, establish a connection with the base station, transmit capability information to the base station, establish a quantum channel with a third device for quantum entanglement-based quantum signature with a second device, and transmit request information to the third device through the quantum channel, the request information including at least one qubit message encrypted using a secret symmetric key shared between the first device and the third device as information for requesting generation of signature information for the quantum signature.

[0019] As an example of the present disclosure, in a communication system, a second device may include a transceiver and a processor coupled to the transceiver, wherein the processor may be configured to receive signature information from a third device that mediates a quantum signature based on quantum entanglement with the first device, store a first qubit message received together with the signature information, transmit quantum information generated based on the signature information and the qubit message to the third device as first transfer information generated based on the signature information, receive quantum information from the third device as second transfer information generated based on the first transfer information, including a result of a first verification performed based on the first transfer information, and perform a second verification based on the second transfer information.

[0020] As an example of the present disclosure, in a communication system, a third device may include a transceiver and a processor coupled to the transceiver, wherein the processor may be configured to receive request information and a plurality of qubit messages from the first device, the request information including a qubit message encrypted using a first secret symmetric key shared between the first device and the third device as information for requesting generation of signature information for quantum signature between the first device and the second device, and transmit, to the second device, signature information generated from the request information using a secret key of the third device and a second secret symmetric key shared between the second device and the third device, and at least one qubit message among the qubit messages, receive, from the second device, first transfer information generated based on the signature information, perform first verification based on the first transfer information, and transmit, to the second device, second transfer information including verification result information indicating a result of the first verification, second transfer information for second verification of the second device.

[0021] As an example of the present disclosure, a communication device may include at least one processor, and at least one computer memory coupled to the at least one processor and storing instructions that, when executed by the at least one processor, direct operations, wherein the operations may include performing an initial connection procedure with a base station, establishing a connection with the base station, transmitting capability information to the base station, establishing a quantum channel with a third device for quantum entanglement-based quantum signature with a second device, and transmitting request information to the third device through the quantum channel, the request information including at least one qubit message encrypted using a secret symmetric key shared between the first device and the third device, as information for requesting generation of signature information for the quantum signature.

[0022] As an example of the present disclosure, a non-transitory computer-readable medium storing at least one instruction includes at least one instruction executable by a processor, wherein the at least one instruction can instruct a device to perform an initial connection procedure with a base station, establish a connection with the base station, transmit capability information to the base station, establish a quantum channel with a third device for quantum entanglement-based quantum signature with a second device, and transmit request information to the third device through the quantum channel, the request information including at least one qubit message encrypted using a secret symmetric key shared between the first device and the third device as information for requesting generation of signature information for the quantum signature.

[0023] The above-described aspects of the present disclosure are only some of the preferred embodiments of the present disclosure, and various embodiments reflecting the technical features of the present disclosure can be derived and understood by a person having ordinary skill in the art based on the detailed description of the present disclosure to be described below.

[0024] The following effects may be achieved by embodiments based on the present disclosure.

[0025] According to the present disclosure, quantum signatures can be effectively performed in situations where there is no direct path between a sender and a receiver.

[0026] The effects that can be obtained from the embodiments of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned can be clearly derived and understood by those skilled in the art to which the technical configuration of the present disclosure is applied, from the description of the embodiments of the present disclosure below. In other words, unintended effects resulting from implementing the configuration described in the present disclosure can also be derived from the embodiments of the present disclosure by those skilled in the art.

[0027] The accompanying drawings are intended to aid understanding of the present disclosure and, together with detailed descriptions, may provide embodiments of the present disclosure. However, the technical features of the present disclosure are not limited to specific drawings, and the features disclosed in each drawing may be combined with each other to form new embodiments. Reference numerals in each drawing may indicate structural elements.

[0028] Figure 1 illustrates an example of a communication system applicable to the present disclosure.

[0029] FIG. 2 illustrates an example of a wireless device applicable to the present disclosure.

[0030] FIG. 3 illustrates a method for processing a transmission signal applicable to the present disclosure.

[0031] Figure 4 illustrates a communication procedure between a terminal and a base station applicable to the present disclosure.

[0032] FIG. 5 illustrates an example of a communication structure that can be provided in a 6G (6th generation) system applicable to the present disclosure.

[0033] Figure 6 illustrates an electromagnetic spectrum applicable to the present disclosure.

[0034] Figure 7 illustrates a transmitter structure applicable to the present disclosure.

[0035] Figure 8 illustrates an example of a functional framework for application of artificial intelligence technology applicable to the present disclosure.

[0036] Figure 9 illustrates an example of a procedure for utilizing an artificial intelligence model applicable to the present disclosure.

[0037] Figure 10 illustrates a communication procedure based on AI (artificial intelligence) technology applicable to the present disclosure.

[0038] Figure 11 illustrates the concept of an electronic signature technique based on direct signature.

[0039] Figure 12 illustrates the concept of a mediator-based electronic signature technique.

[0040] Figure 13 illustrates the concept of a quantum signature technique based on an arbitrator using the GHZ (Greenberger-Horne-Zeilinger) state.

[0041] Figure 14 illustrates the concept of a quantum signature technique based on an arbitrator using a bell state.

[0042] Figure 15 illustrates the concept of a single photon-based quantum signature technique.

[0043] FIG. 16a illustrates an initial step of a mediator-based message attachment quantum signature scheme using GHZ states according to one embodiment of the present disclosure.

[0044] FIG. 16b illustrates a quantum signature generation step of a message attachment-based quantum signature technique using a GHZ state according to one embodiment of the present disclosure.

[0045] FIG. 16c and FIG. 16d illustrate verification steps of a mediator-based message attachment quantum signature technique using GHZ states according to one embodiment of the present disclosure.

[0046] FIGS. 17A and 17B illustrate examples of operations of a sender, a receiver, and an arbitrator according to a arbitrator-based message attachment quantum signature technique using GHZ states according to one embodiment of the present disclosure.

[0047] FIG. 18a illustrates an initial step of a mediator-based message attachment quantum signature technique using a bell state according to one embodiment of the present disclosure.

[0048] FIG. 18b illustrates a quantum signature generation step of a message attachment-based quantum signature technique using a bell state according to one embodiment of the present disclosure.

[0049] FIG. 18c and FIG. 18d illustrate verification steps of a message attachment-based quantum signature technique using a bell state according to one embodiment of the present disclosure.

[0050] FIGS. 19A and 19B illustrate examples of operations of a sender, a receiver, and an arbitrator according to a message attachment quantum signature technique based on an arbitrator using a bell state according to one embodiment of the present disclosure.

[0051] FIG. 20 illustrates an example of a procedure in which a sender requests generation of signature information according to a message attachment-based quantum signature technique based on an arbitrator according to one embodiment of the present disclosure.

[0052] FIG. 21 illustrates an example of a procedure in which an arbitrator performs a quantum signature according to an arbitrator-based message attachment quantum signature technique according to one embodiment of the present disclosure.

[0053] FIG. 22 illustrates an example of a procedure for a recipient to perform signing according to a message attachment-based quantum signature technique based on an arbitrator according to one embodiment of the present disclosure.

[0054] FIG. 23 illustrates an example of a quantum key distribution (QKD) technology to which a quantum signature technique is applied according to one embodiment of the present disclosure.

[0055] FIG. 24 illustrates an example of quantum secure direct communication (QSDC) using a quantum signature technique according to one embodiment of the present disclosure.

[0056] Figure 25 illustrates an example of a wireless device applicable to the present disclosure.

[0057] Figure 26 illustrates an example of a portable device applicable to the present disclosure.

[0058] FIG. 27 illustrates an example of a vehicle or autonomous vehicle applicable to the present disclosure.

[0059] Figure 28 illustrates an example of a vehicle applicable to the present disclosure.

[0060] FIG. 29 illustrates an example of an extended reality (XR) device applicable to the present disclosure.

[0061] Figure 30 illustrates an example of a robot applicable to the present disclosure.

[0062] Figure 31 illustrates an example of an AI device applicable to the present disclosure.

[0063] FIG. 32 illustrates an example of a quantum communication device applicable to the present disclosure.

[0064] The following embodiments combine the components and features of the present disclosure in a predetermined form. Each component or feature may be considered optional unless explicitly stated otherwise. Each component or feature may be implemented without being combined with other components or features. Furthermore, some components and / or features may be combined to form embodiments of the present disclosure. The order of operations described in the embodiments of the present disclosure may be changed. Some components or features of one embodiment may be included in another embodiment or may be replaced with corresponding components or features of another embodiment.

[0065] In the description of the drawings, procedures or steps that may obscure the gist of the present disclosure are not described, and procedures or steps that can be understood by a person skilled in the art are also not described.

[0066] Throughout the specification, when a part is said to "comprising" or "including" a component, this does not mean that other components may be included, but rather that other components may be excluded, unless otherwise specifically stated. In addition, terms such as "...part," "...unit," and "module" described in the specification mean a unit that processes at least one function or operation, which may be implemented by hardware, software, or a combination of hardware and software. In addition, the words "a" or "an," "one," "the," and similar related words may be used in the context of describing the present disclosure (especially in the context of the claims below) to include both the singular and the plural, unless otherwise indicated herein or clearly contradicted by context.

[0067] Embodiments of the present disclosure described herein focus on the data transmission and reception relationship between a base station and a mobile station. Here, the base station is understood as a terminal node of a network that directly communicates with the mobile station. Certain operations described herein as being performed by the base station may, in some cases, be performed by an upper node of the base station.

[0068] That is, in a network consisting of multiple network nodes including a base station, various operations performed for communication with a mobile station may be performed by the base station or other network nodes other than the base station. In this case, the term 'base station' may be replaced by terms such as fixed station, Node B, eNB (eNode B), gNB (gNode B), ng-eNB, advanced base station (ABS), or access point.

[0069] Additionally, in the embodiments of the present disclosure, the term terminal may be replaced with terms such as user equipment (UE), mobile station (MS), subscriber station (SS), mobile subscriber station (MSS), mobile terminal, or advanced mobile station (AMS).

[0070] Additionally, a transmitter refers to a fixed and / or mobile node that provides data or voice services, and a receiver refers to a fixed and / or mobile node that receives data or voice services. Therefore, for uplink, a mobile station can be the transmitter, and a base station can be the receiver. Similarly, for downlink, a mobile station can be the receiver, and a base station can be the transmitter.

[0071] Embodiments of the present disclosure may be supported by standard documents disclosed in at least one of wireless access systems, such as IEEE 802.xx system, 3rd Generation Partnership Project (3GPP) system, 3GPP Long Term Evolution (LTE) system, 3GPP 5th generation (5G) NR (New Radio) system and 3GPP2 system, and in particular, embodiments of the present disclosure may be supported by 3GPP TS (technical specification) 38.211, 3GPP TS 38.212, 3GPP TS 38.213, 3GPP TS 38.321 and 3GPP TS 38.331 documents.

[0072] Furthermore, the embodiments of the present disclosure can be applied to other wireless access systems and are not limited to the systems described above. For example, they can be applied to systems implemented after the 3GPP 5G NR system and are not limited to a specific system.

[0073] That is, obvious steps or parts not described in the embodiments of the present disclosure can be explained by referring to the above documents. In addition, all terms disclosed in this document can be explained by the above standard documents.

[0074] Hereinafter, preferred embodiments according to the present disclosure will be described in detail with reference to the accompanying drawings. The detailed description set forth below, together with the accompanying drawings, is intended to illustrate exemplary embodiments of the present disclosure and is not intended to represent the only embodiments in which the technical configurations of the present disclosure may be implemented.

[0075] Additionally, specific terms used in the embodiments of the present disclosure are provided to aid in understanding the present disclosure, and the use of such specific terms may be changed to other forms without departing from the technical spirit of the present disclosure.

[0076] The following technology can be applied to various wireless access systems such as CDMA (code division multiple access), FDMA (frequency division multiple access), TDMA (time division multiple access), OFDMA (orthogonal frequency division multiple access), and SC-FDMA (single carrier frequency division multiple access).

[0077]

[0078] For clarity, the following description is based on 3GPP communication systems (e.g., LTE, NR, etc.), but the technical spirit of the present disclosure is not limited thereto. LTE may refer to technology after 3GPP TS 36.xxx Release 8. Specifically, LTE technology after 3GPP TS 36.xxx Release 10 may be referred to as LTE-A, and LTE technology after 3GPP TS 36.xxx Release 13 may be referred to as LTE-A pro. 3GPP NR may refer to technology after TS 38.xxx Release 15. 3GPP 6G may refer to technology after TS Release 17 and / or Release 18. "xxx" refers to a standard document detail number. LTE / NR / 6G may be collectively referred to as a 3GPP system.

[0079] For background information, terms, abbreviations, etc. used in this disclosure, reference may be made to standard documents published prior to this disclosure. For example, reference may be made to standard documents 36.xxx and 38.xxx.

[0080]

[0081] Communication system applicable to the present disclosure

[0082] Although not limited thereto, the various descriptions, functions, procedures, proposals, methods and / or operational flowcharts of the present disclosure disclosed in this document may be applied to various fields requiring wireless communication / connectivity (e.g., 5G) between devices.

[0083] Hereinafter, more specific examples will be provided with reference to the drawings. In the drawings / descriptions below, the same drawing reference numerals may represent identical or corresponding hardware blocks, software blocks, or functional blocks, unless otherwise described.

[0084] Figure 1 illustrates an example of a communication system applied to the present disclosure.

[0085] Referring to FIG. 1, a communication system (100) applied to the present disclosure includes a wireless device, a base station, and a network. Here, the wireless device refers to a device that performs communication using a wireless access technology (e.g., LTE, LTE-A, LTE-A pro, NR, 5G, 5G-A, 6G) and may be referred to as a communication / wireless / 5G device. Although not limited thereto, the wireless device may include a robot (100a), a vehicle (100b-1, 100b-2), an XR (extended reality) device (100c), a hand-held device (100d), a home appliance (100e), an IoT (Internet of Things) device (100f), and an AI (artificial intelligence) device / server (100g). For example, the vehicle may include a vehicle equipped with a wireless communication function, an autonomous vehicle, a vehicle capable of performing vehicle-to-vehicle communication, etc. Here, the vehicles (100b-1, 100b-2) may include unmanned aerial vehicles (UAVs) (e.g., drones). The XR devices (100c) include augmented reality (AR) / virtual reality (VR) / mixed reality (MR) devices, and may be implemented in the form of head-mounted devices (HMDs), head-up displays (HUDs) installed in vehicles, televisions, smartphones, computers, wearable devices, home appliances, digital signage, vehicles, robots, etc. The portable devices (100d) may include smartphones, smart pads, wearable devices (e.g., smartwatches, smart glasses), computers (e.g., laptops, etc.), etc. The home appliances (100e) may include TVs, refrigerators, washing machines, etc. The IoT devices (100f) may include sensors, smart meters, etc.For example, the base station (120) and the network (130) may also be implemented as wireless devices, and a specific wireless device (120a) may act as a base station / network node to other wireless devices.

[0086] Wireless devices (100a to 100f) can be connected to a network (130) via a base station (120). AI technology can be applied to the wireless devices (100a to 100f), and the wireless devices (100a to 100f) can be connected to an AI server (100g) via a network (130). The network (130) can be configured using a 3G network, a 4G (e.g., LTE) network, a 5G (e.g., NR), or a 6G network. The wireless devices (100a to 100f) can communicate with each other via the base station (120) / network (130), but can also communicate directly (e.g., sidelink communication) without going through the base station (120) / network (130). For example, vehicles (100b-1, 100b-2) can communicate directly (e.g., V2V (vehicle to vehicle) / V2X (vehicle to everything) communication). Additionally, an IoT device (100f) (e.g., a sensor) can communicate directly with another IoT device (e.g., a sensor) or another wireless device (100a to 100f).

[0087] Wireless communication / connection (150a, 150b, 150c) can be established between wireless devices (100a to 100f) / base stations (120), and base stations (120) / base stations (120). Here, the wireless communication / connection can be established through various wireless access technologies such as uplink / downlink communication (150a), sidelink communication (150b) (or D2D communication), and base station-to-base station communication (150c) (e.g., relay, IAB (integrated access backhaul)). Through the wireless communication / connection (150a, 150b, 150c), the wireless device and base station / wireless device, and base stations and base stations can transmit / receive wireless signals to / from each other. For example, the wireless communication / connection (150a, 150b, 150c) can transmit / receive signals through various physical channels. To this end, based on various proposals of the present disclosure, at least some of various configuration information setting processes for transmitting / receiving wireless signals, various signal processing processes (e.g., channel encoding / decoding, modulation / demodulation, resource mapping / demapping, etc.), resource allocation processes, etc. may be performed.

[0088]

[0089] Devices applicable to the present disclosure

[0090] FIG. 2 illustrates an example of a wireless device applicable to the present disclosure.

[0091] Referring to FIG. 2, the wireless device (200) can transmit and receive wireless signals via various wireless access technologies (e.g., LTE, LTE-A, LTE-A pro, NR, 5G, 5G-A, 6G). The wireless device (200) includes at least one processor (202) and at least one memory (204), and may additionally include at least one transceiver (206) and / or at least one antenna (208).

[0092] The processor (202) controls the memory (204) and / or the transceiver (206), and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in this document. For example, the processor (202) may process information in the memory (204) to generate first information / signal, and then transmit a wireless signal including the first information / signal via the transceiver (206). In addition, the processor (202) may receive a wireless signal including second information / signal via the transceiver (206), and then store information obtained from signal processing of the second information / signal in the memory (204). The memory (204) may be connected to the processor (202) and may store various information related to the operation of the processor (202). For example, the memory (204) may store software code including instructions for performing some or all of the processes controlled by the processor (202), or for performing the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed herein. Here, the processor (202) and the memory (204) may be part of a communication modem / circuit / chip designed to implement wireless communication technology. The transceiver (206) may be connected to the processor (202) and may transmit and / or receive wireless signals via at least one antenna (208). The transceiver (206) may include a transmitter and / or a receiver. The transceiver (206) may be used interchangeably with an RF (radio frequency) unit. In the present disclosure, a wireless device may also mean a communication modem / circuit / chip.

[0093] Hereinafter, the hardware elements of the wireless device (200) will be described in more detail. Although not limited thereto, at least one protocol layer may be implemented by at least one processor (202). For example, at least one processor (202) may implement at least one layer (e.g., a functional layer such as physical (PHY), media access control (MAC), radio link control (RLC), packet data convergence protocol (PDCP), radio resource control (RRC), and service data adaptation protocol (SDAP)). At least one processor (202) may generate at least one Protocol Data Unit (PDU) and / or at least one Service Data Unit (SDU) according to the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this document. At least one processor (202) may generate a message, control information, data, or information according to the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this document. At least one processor (202) can generate a signal (e.g., a baseband signal) including a PDU, an SDU, a message, control information, data or information according to the functions, procedures, proposals and / or methods disclosed in this document, and provide the signal to at least one transceiver (206). At least one processor (202) can receive a signal (e.g., a baseband signal) from at least one transceiver (206) and obtain the PDU, SDU, message, control information, data or information according to the descriptions, functions, procedures, proposals, methods and / or operational flowcharts disclosed in this document.

[0094] At least one processor (202) may be referred to as a controller, a microcontroller, a microprocessor, or a microcomputer. The at least one processor (202) may be implemented by hardware, firmware, software, or a combination thereof. For example, at least one application specific integrated circuit (ASIC), at least one digital signal processor (DSP), at least one digital signal processing device (DSPD), at least one programmable logic device (PLD), or at least one field programmable gate array (FPGA) may be included in the at least one processor (202). The descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this document may be implemented using firmware or software, and the firmware or software may be implemented to include modules, procedures, functions, etc. The descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in this document may be included in the at least one processor (202), or may be stored in at least one memory (204) and executed by the at least one processor (202). The descriptions, functions, procedures, suggestions, methods and / or flowcharts disclosed in this document may be implemented using firmware or software in the form of code, instructions and / or sets of instructions.

[0095] At least one memory (204) can be connected to at least one processor (202) and can store various forms of data, signals, messages, information, programs, codes, instructions and / or commands. The at least one memory (204) can be configured as a read only memory (ROM), a random access memory (RAM), an erasable programmable read only memory (EPROM), a flash memory, a hard drive, a register, a cache memory, a computer readable storage medium and / or a combination thereof. The at least one memory (204) can be located internally and / or externally to the at least one processor (202). In addition, the at least one memory (204) can be connected to the at least one processor (202) via various technologies such as a wired or wireless connection.

[0096] At least one transceiver (206) can transmit user data, control information, wireless signals / channels, etc., mentioned in the methods and / or flowcharts of this document to at least one other device. At least one transceiver (206) can receive user data, control information, wireless signals / channels, etc. mentioned in the descriptions, functions, procedures, proposals, methods and / or flowcharts disclosed in this document from at least one other device. For example, at least one transceiver (206) can be connected to at least one processor (202) and can transmit and receive wireless signals. For example, at least one processor (202) can control at least one transceiver (206) to transmit user data, control information, or wireless signals to at least one other device. Furthermore, at least one processor (202) can control at least one transceiver (206) to receive user data, control information, or wireless signals from at least one other device. In addition, at least one transceiver (206) may be connected to at least one antenna (208), and at least one transceiver (206) may be configured to transmit and receive user data, control information, wireless signals / channels, etc. mentioned in the descriptions, functions, procedures, proposals, methods and / or operation flowcharts disclosed in this document through at least one antenna (208). In this document, at least one antenna may be a plurality of physical antennas or a plurality of logical antennas (e.g., antenna ports). At least one transceiver (206) may convert the received wireless signals / channels, etc. from RF band signals to baseband signals in order to process the received user data, control information, wireless signals / channels, etc. using at least one processor (202). At least one transceiver (206) may convert the processed user data, control information, wireless signals / channels, etc. from baseband signals to RF band signals using at least one processor (202).For this purpose, at least one transceiver (206) may include an (analog) oscillator and / or filter.

[0097] The components of the wireless device described with reference to FIG. 2 may be referred to by different terms in terms of functionality. For example, the processor (202) may be referred to as a control unit, the transceiver (206) as a communication unit, and the memory (204) as a storage unit. In some cases, the communication unit may be used to mean at least a portion of the processor (202) and the transceiver (206).

[0098] The structure of the wireless device described with reference to FIG. 2 can be understood as the structure of at least a portion of various devices. For example, the structure of the wireless device illustrated in FIG. 2 can be at least a portion of various devices described with reference to FIG. 1 (e.g., a robot (100a), a vehicle (100b-1, 100b-2), an XR device (100c), a portable device (100d), a home appliance (100e), an IoT device (100f), an AI device / server (100g)). Furthermore, according to various embodiments, in addition to the components illustrated in FIG. 2, the device may further include other components.

[0099] For example, the device may be a portable device such as a smartphone, a smart pad, a wearable device (e.g., a smart watch, smart glasses), or a portable computer (e.g., a laptop, etc.). In this case, the device may further include at least one of a power supply unit that supplies power and includes a wired / wireless charging circuit, a battery, etc., an interface unit that includes at least one port for connection with another device (e.g., an audio input / output port, a video input / output port), and an input / output unit for inputting and outputting image information / signals, audio information / signals, data, and / or information input from a user.

[0100] For example, the device may be a mobile device such as a mobile robot, a vehicle, a train, an aerial vehicle (AV), a ship, etc. In this case, the device may further include at least one of a driving unit including at least one of an engine, a motor, a power train, wheels, brakes, and a steering unit of the device, a power supply unit including a wired / wireless charging circuit, a battery, etc. that supplies power, a sensor unit that senses status information, environmental information, and user information of the device or its surroundings, an autonomous driving unit that performs functions such as path maintenance, speed control, and destination setting, and a position measurement unit that obtains location information of the mobile device through a global positioning system (GPS) and various sensors.

[0101] For example, the device may be an XR device such as an HMD, a head-up display (HUD) installed in a vehicle, a television, a smartphone, a computer, a wearable device, a home appliance, a digital signage, a vehicle, a robot, etc. In this case, the device may further include at least one of a power supply unit that supplies power and includes a wired / wireless charging circuit, a battery, etc., an input / output unit that obtains control information, data, etc. from the outside and outputs the generated XR object, and a sensor unit that senses status information, environmental information, and user information of the device or the surroundings of the device.

[0102] For example, the device may be a robot that can be classified into industrial, medical, household, military, etc. types depending on the purpose or field of use. In this case, the device may further include at least one of a sensor unit that senses status information, environmental information, and user information of the device or its surroundings, and a driving unit that performs various physical actions, such as moving the robot joints.

[0103] For example, the device may be an AI device such as a TV, a projector, a smartphone, a PC, a laptop, a digital broadcasting terminal, a tablet PC, a wearable device, a set-top box (STB), a radio, a washing machine, a refrigerator, digital signage, a robot, a vehicle, etc. In this case, the device may further include at least one of an input unit that acquires various types of data from the outside, an output unit that generates output related to sight, hearing, or touch, a sensor unit that senses status information, environmental information, and user information of the device or its surroundings, and a training unit that trains a model composed of an artificial neural network using learning data.

[0104] The structure of the wireless device illustrated in FIG. 2 may be understood as a part of a RAN node (e.g., a base station, DU, RU, RRH, etc.). That is, the device illustrated in FIG. 2 may be a RAN node. In this case, the device may further include a wired transceiver for front haul and / or back haul communications. However, if the front haul and / or back haul communications are based on wireless communications, at least one transceiver (206) illustrated in FIG. 2 may be used for front haul and / or back haul communications, and a wired transceiver may not be included.

[0105]

[0106] FIG. 3 illustrates a method for processing a transmission signal applicable to the present disclosure. For example, the transmission signal may be processed by a signal processing circuit. At this time, the signal processing circuit (300) may include scramblers (310), modulators (320), a layer mapper (330), a precoder (340), resource mappers (350), and signal generators (360). At this time, for example, the operation / function of FIG. 3 may be performed in the processor (202) and / or the transceiver (206) of FIG. 2. Furthermore, for example, the hardware elements of FIG. 3 may be implemented in the processor (202) and / or the transceiver (206) of FIG. 2. For example, blocks 310 to 360 may be implemented in the processor (202) of FIG. 2. Additionally, blocks 310 to 350 may be implemented in the processor (202) of FIG. 2, and block 360 may be implemented in the transceiver (206) of FIG. 2, and are not limited to the above-described embodiment.

[0107] The codeword can be converted into a wireless signal through the signal processing circuit (300) of FIG. 3. Here, the codeword is an encoded bit sequence of an information block. The information block may include a transport block (e.g., a UL-SCH transport block, a DL-SCH transport block). Here, the information block may include data related to AI (e.g., training data, AI model data, input data, output data, etc.), and the codeword may be an encoded bit sequence corresponding to the data related to AI. The wireless signal may be transmitted through various physical channels (e.g., a PUSCH, a PDSCH). Specifically, the codeword may be converted into a bit sequence scrambled by scramblers (310). The scramble sequence used for scrambling is generated based on an initialization value, and the initialization value may include ID information of the wireless device, etc. The scrambled bit sequence may be modulated into a modulation symbol sequence by modulators (320). Modulation schemes may include pi / 2-BPSK (pi / 2-binary phase shift keying), m-PSK (m-phase shift keying), m-QAM (m-quadrature amplitude modulation), etc.

[0108] A complex modulation symbol sequence can be mapped to at least one transport layer by a layer mapper (330). Here, a transport layer is a logical resource unit for mapping a signal or data transmitted through spatial resources to antenna ports, and one transport layer can correspond to one stream or one antenna port. Each of the complex modulation symbols included in the complex modulation symbol sequence is mapped to at least one transport layer, thereby determining which antenna port it will be transmitted through. The modulation symbols of each transport layer can be mapped to the corresponding antenna port(s) by a precoder (340). The output z of the precoder (340) can be obtained by multiplying the output y of the layer mapper (330) by a precoding matrix W of NХM. Here, N is the number of antenna ports, and M is the number of transport layers. Here, the precoder (340) may perform precoding after performing transform precoding (e.g., discrete Fourier transform (DFT) transform) on complex modulation symbols. Additionally, the precoder (340) may perform precoding without performing transform precoding.

[0109] Resource mappers (350) can map modulation symbols of each antenna port to time-frequency resources. The time-frequency resources may include a plurality of symbols (e.g., CP-OFDMA symbols, DFT-s-OFDMA symbols) in the time domain and a plurality of subcarriers in the frequency domain. Signal generators (360) generate wireless signals from the mapped modulation symbols, and the generated wireless signals can be transmitted to other devices through each antenna. To this end, each of the signal generators (360) may include an inverse fast Fourier transform (IFFT) module, a cyclic prefix (CP) inserter, a digital-to-analog converter (DAC), a frequency uplink converter, etc.

[0110] The signal processing process for a received signal in a wireless device may be configured in reverse order of the signal processing process (310 to 360) of FIG. 3. For example, a wireless device (e.g., 200 of FIG. 2) may receive a wireless signal from the outside through an antenna port / transceiver. The received wireless signal may be converted into a baseband signal through a signal restorer. For this purpose, the signal restorer may include a frequency downlink converter, an analog-to-digital converter (ADC), a CP remover, and a fast Fourier transform (FFT) module. Thereafter, the baseband signal may be restored to a codeword through a resource demapper process, a postcoding process, a demodulation process, and a descrambling process. The codeword may be restored to the original information block through decoding. Therefore, a signal processing circuit (not shown) for a received signal may include a signal restorer, a resource demapper, a postcoder, a demodulator, a descrambler, and a decoder.

[0111] The signal processing circuit (300) described with reference to FIG. 3 is exemplified as including a plurality of scramblers (310), modulators (320), a plurality of resource mappers (350), and a plurality of signal generators (360). However, at least one of the scramblers, modulators, resource mappers, and signal generators may be implemented as a single integrated structure. That is, the number of at least one of the scramblers, modulators, resource mappers, and signal generators may be smaller than the number of layers. Furthermore, at least one of the components exemplified in FIG. 3 may be omitted.

[0112]

[0113] Figure 4 illustrates a communication procedure between a terminal and a base station applicable to the present disclosure. Figure 4 illustrates operations of a terminal (410) and a base station (420) transmitting and / or receiving data and operations performed prior thereto.

[0114] Referring to FIG. 4, in step 401, the terminal (410) and the base station (420) perform synchronization. For example, the terminal (410) performs an initial cell search operation. Specifically, the terminal (410) can detect at least one synchronization signal transmitted from the base station (420) according to a predefined rule. Here, the synchronization signal can include multiple synchronization signals classified according to structure or purpose (e.g., primary synchronization signal, secondary synchronization signal). Through this, the terminal (410) can check the boundary of the frame, subframe, slot, and / or symbol of the base station (420) and obtain information about the base station (420) (e.g., cell identifier).

[0115] In step 403, the terminal (410) obtains system information transmitted from the base station (420). The system information is information related to the properties, characteristics, and / or capabilities of the base station (420) required to access the base station (420) and use the service, and may be classified by content (e.g., whether it is essential for access), transmission structure (e.g., channel used, whether provided on-demand), etc., and may be classified into, for example, a master information block (MIB) and a system information block (SIB). If necessary, the terminal (410) may transmit a signal requesting system information before receiving the system information. The system information may include information related to an AI function. For example, the system information may include at least one of information related to an AI model, information related to training, and information related to inference / prediction, as information required for operations performed based on AI. However, the request and provision of the system information may be performed after a random access procedure described below.

[0116] In step 405, the terminal (410) and the base station (420) perform a random access procedure. The terminal (410) may transmit and / or receive at least one message (e.g., a random access preamble, a random access response (RAR) message, etc.) for the random access procedure based on information related to the random access channel of the base station (420) obtained through system information (e.g., channel position, channel structure, supported preamble structure, etc.). For example, the terminal (410) may transmit a preamble (e.g., MSG1) through the random access channel, receive an RAR message (e.g., MSG2), transmit a message (e.g., MSG3) including information related to the terminal (410) (e.g., identification information) to the base station (420) using scheduling information included in the RAR message, and receive a message (e.g., MSG4) for contention resolution and / or connection establishment. As another example, MSG1 and MSG3 may be sent and received as one message, or MSG2 and MSG4 may be sent and received as one message.

[0117] In step 407, the terminal (410) and the base station (420) perform signaling of control information. Here, the control information may be defined in various layers, such as a layer that controls a connection (e.g., a radio resource control (RRC) layer), a layer that handles mapping between logical channels and transport channels (e.g., a media access control (MAC) layer), and a layer that handles physical channels (e.g., a physical (PHY) layer). For example, the terminal (410) and the base station (420) may perform at least one of signaling for establishing a connection, signaling for determining settings related to communication, and signaling for indicating allocated resources. In addition, the signaling of the control information may be performed to convey information related to an AI function. For example, the information related to an AI function is information necessary for an operation performed based on AI, and may include at least one of information related to an AI model, information related to training, and information related to inference / prediction. More specifically, information related to the AI ​​function signaled in step 407 may be combined and / or linked with information related to the AI ​​function signaled in step 403, and the two may be defined in a hierarchical, mutually complementary, or substitutive structure.

[0118] In step 409, the terminal (410) and the base station (420) transmit and / or receive data. In other words, the terminal (410) and the base station (420) can process, transmit, and / or receive data based on the signaling of the control information. For example, when transmitting data, the terminal (410) or the base station (420) can perform at least one of channel encoding, rate matching, scrambling, constellation mapping, layer mapping, waveform modulation, antenna mapping, and resource mapping on the information bits. Conversely, when receiving data, the terminal (410) or the base station (420) can perform at least one of signal extraction from resources, waveform demodulation for each antenna, signal arrangement considering layer mapping, constellation demapping, descrambling, and channel decoding. Here, the transmitted data is data related to AI, and may include, for example, data for AI-based operations or data generated by AI-based operations.

[0119] Steps 401 to 409 illustrated with reference to FIG. 4 do not necessarily have to be performed in the order illustrated in FIG. 4, and the order of at least some of the steps may vary. Furthermore, at least some of steps 401 to 409 may be combined into a single step or omitted. That is, the steps illustrated in FIG. 4 may be performed in various modified forms.

[0120]

[0121] 6G communication systems and core implementation technologies of 6G systems

[0122] The 5G system defines various operating bands within FR1 (frequency range 1), which covers 410 MHz to 7125 MHz, and FR2 (frequency range 2), which covers 24,250 MHz to 71,000 MHz. Various frequencies are being discussed as operating bands for the subsequent 6G system, and the use of higher frequencies than 5G systems is also being considered for wider bandwidth and higher transmission speeds. One such band is the THz (terahertz) frequency band, which covers approximately 100 GHz to 10 THz. The THz frequency band is a band that has both the transparency of radio waves and the straightness of light waves, and communications using the THz frequency band are expected to play a transitional role from existing radio-centered communications to lightwave-based communications.

[0123] 6G systems utilizing the THz frequency band have the following goals: i) very high data rates per device, ii) a very large number of connected devices, iii) global connectivity, iv) very low latency, v) reduced energy consumption of battery-free IoT devices, vi) ultra-reliable connectivity, and vii) connected intelligence with machine learning capabilities. The vision of the 6G system can be divided into four aspects: “intelligent connectivity,” “deep connectivity,” “holographic connectivity,” and “ubiquitous connectivity,” and the 6G system can be designed to satisfy the requirements as shown in [Table 1] below.

[0124] Per device peak data rate1 TbpsE2E latency1 msMaximum spectral efficiency100 bps / HzMobility supportup to 1000 km / hrSatellite integrationFullyAIFullyAutonomous vehicleFullyXRFullyHaptic CommunicationFully

[0125] At this time, the 6G system may have key factors such as enhanced mobile broadband (eMBB), ultra-reliable low latency communications (URLLC), massive machine type communications (mMTC), AI integrated communication, tactile internet, high throughput, high network capacity, high energy efficiency, low backhaul and access network congestion, and enhanced data security. FIG. 5 illustrates an example of a communication structure that can be provided in a 6G system applicable to the present disclosure. Referring to FIG. 5, the 6G system is expected to have simultaneous wireless communication connectivity that is 50 times higher than that of a 5G wireless communication system. URLLC, a key feature of 5G, is expected to become an even more crucial technology in 6G communications, offering end-to-end latency of less than 1 ms. Furthermore, 6G systems will boast significantly higher volumetric spectral efficiency than the commonly used area spectral efficiency. 6G systems can offer extremely long battery life and advanced battery technologies for energy harvesting, eliminating the need for separate charging for mobile devices in 6G systems. New network characteristics in 6G may include:

[0126] - Satellite integrated network: 6G is expected to integrate with satellites to provide a global mobile network. The integration of terrestrial, satellite, and airborne networks into a single wireless communications system is crucial for 6G.

[0127] Connected Intelligence: Unlike previous generations of communication systems, 6G is revolutionary, upgrading the wireless evolution from "connected objects" to "connected intelligence." AI can be applied at every stage of the communication process (or at every signal processing step, as described below).

[0128] - Seamless integration of wireless information and energy transfer: 6G wireless networks will transfer power to charge the batteries of devices such as smartphones and sensors. Therefore, wireless information and energy transfer (WIET) will be integrated.

[0129] - Ubiquitous super 3D connectivity: Access to networks and core network functions of drones and very low Earth orbit satellites will create super 3D connectivity in 6G ubiquitous.

[0130] Some general requirements for the new network characteristics of 6G, such as the above, may be as follows:

[0131] - Small cell networks: The concept of small cell networks was introduced to improve received signal quality in cellular systems by increasing throughput, energy efficiency, and spectral efficiency. Consequently, small cell networks are essential for 5G and beyond-5G (5GB) communication systems. Accordingly, 6G communication systems also adopt the characteristics of small cell networks.

[0132] Ultra-dense heterogeneous networks: Ultra-dense heterogeneous networks will be another key feature of 6G communication systems. Multi-tier networks comprised of heterogeneous networks improve overall QoS and reduce costs.

[0133] High-capacity backhaul: Backhaul connections are characterized by high-capacity backhaul networks to support high-volume traffic. High-speed fiber optics and free-space optics (FSO) systems may be potential solutions to this problem.

[0134] - Radar technology integrated with mobile technology: High-precision localization (or location-based services) through communications is a key feature of 6G wireless communication systems. Therefore, radar systems will be integrated with 6G networks.

[0135] - Softwarization and virtualization: Softwarization and virtualization are two critical features that form the foundation of the design process for 5GB networks to ensure flexibility, reconfigurability, and programmability. Furthermore, billions of devices can be shared on a shared physical infrastructure.

[0136] To satisfy the above-mentioned characteristics, the core implementation technologies of the 6G system may include artificial intelligence (AI), THz (terahertz) communication, optical wireless technology, FSO backhaul network, massive MIMO technology, blockchain, 3D networking, quantum communication, unmanned aerial vehicles, cell-free communication, wireless information and energy transfer (WIET), integration of sensing and communication, integration of access backhaul networks, holographic beamforming, big data analysis, and large intelligent surface (LIS).

[0137] For example, THz communication can be utilized in 6G systems. THz communication is a communication that utilizes a spectrum in a frequency band between 0.3 THz and 3 THz with a corresponding wavelength in the range of 0.1 mm to 1 mm, as shown in FIG. 6. Referring to FIG. 6, the frequency band of THz waves is located in the middle region between the infrared band and the millimeter wave band, and therefore, THz waves can be understood as radio waves with the shortest wavelength and light waves with the longest wavelength. Therefore, THz waves share some of the characteristics of infrared and microwave waves, and specifically, they can simultaneously have the transparency of electromagnetic waves and the straightness of light waves.

[0138]

[0139] Figure 7 illustrates a transmitter structure applicable to the present disclosure.

[0140] Referring to Figure 7, in order to modulate data into an optical signal, an optical source of a laser can be passed through an optical wave guide to change the phase of the signal, etc. At this time, data is loaded by changing the electrical characteristics through a microwave contact, etc. Therefore, the optical modulator output is formed as a modulated waveform.

[0141] Data may be provided from a data signal generator. Here, the data may include various user data, configuration information, control information, etc. transmitted through a channel. Furthermore, the data may include data related to AI-based operations, such as information for configuring an AI model, input / output data for tasks of the AI ​​model, etc. To this end, components related to AI functions (e.g., an AI processing unit) may be included in the data signal generator or may be linked to the data signal generator.

[0142] An optical / electronic converter (O / E converter) can generate THz pulses by optical rectification using a nonlinear crystal, photoelectric conversion using a photoconductive antenna, or emission from a bunch of relativistic electrons. The THz pulse generated in the above manner can have a length in the range of femtoseconds to picoseconds. The optical / electronic converter (O / E converter) performs down conversion by utilizing the nonlinearity of the device.

[0143] Considering the THz spectrum usage, it is likely that multiple contiguous GHz bands will be used for THz systems, either fixed or for mobile services. For an outdoor scenario, the available bandwidth can be categorized based on an oxygen attenuation of 10^2 dB / km in the spectrum up to 1 THz. Accordingly, a framework in which the available bandwidth is divided into multiple band chunks can be considered. As an example of this framework, if the THz pulse length for a single carrier is set to 50 ps, ​​the bandwidth (BW) becomes approximately 20 GHz.

[0144] Effective down-conversion from the infrared band to the THz band depends on how to utilize the nonlinearity of the optical / electrical converter (O / E converter). In other words, to down-convert to the desired THz band, it is necessary to design an O / E converter with the most ideal non-linearity for transferring to the THz band. If an O / E converter that is not suitable for the target frequency band is used, errors in the amplitude and phase of the pulse are likely to occur.

[0145] A THz transmission and reception system can be implemented using a single optical-to-electrical converter in a single-carrier system. Depending on the channel environment, optical-to-electrical converters may be required as many as the number of carriers in a multi-carrier system. This phenomenon will be particularly noticeable in a multi-carrier system that utilizes multiple broadbands according to the aforementioned spectrum usage plan. In this regard, a frame structure for the multi-carrier system may be considered. A signal down-frequency converted based on an optical-to-electrical converter may be transmitted in a specific resource region (e.g., a specific frame). The frequency region of the specific resource region may include multiple chunks. Each chunk may be composed of at least one component carrier (CC).

[0146]

[0147] 6G systems may introduce AI technology. Efficient resource management and optimization are required to maintain connectivity between various services and devices. AI technology may include technologies that perform data analysis, pattern recognition, and predictive modeling using AI / ML (artificial intelligence / machine learning) models. Here, an AI / ML model can be understood as a set of parameter values ​​and / or weight values ​​related to mathematical formulas or algorithms generated through learning to discover patterns in input data or make predictions. To create such an AI / ML model, an AI / ML model learning process is required, which builds an AI / ML model by learning the relationship between inputs and outputs in a data-driven manner. Various learning algorithms, such as supervised learning, unsupervised learning, and reinforcement learning, can be utilized as learning algorithms. To generate output, a user can input specific data into a trained AI / ML model, and the process of obtaining output data by inputting input data into an AI / ML model can be referred to as AI / ML "inference" or "prediction."

[0148] Network control parameters can be obtained as output through AI / ML inference using trained AI / ML models. Users can utilize the output parameter values ​​to improve network efficiency. For example, AI technology can be utilized in various fields, such as wireless network resource allocation, traffic management, fault prediction, and quality of service (QoS) management. In particular, machine learning can efficiently allocate resources even in dynamically changing network environments based on real-time data. Therefore, AI technology can be utilized to provide hyper-connectivity and ultra-low latency.

[0149] At this time, AI / ML inference can be performed based on a combination of various devices. For example, the UE and the network can jointly perform AI / ML inference, and such an AI / ML model can be referred to as a two-sided AI / ML model or a two-sided model. In this case, the UE can perform the first part of the inference first, and the base station can perform the remaining inference, or vice versa. Alternatively, inference can be performed entirely on the UE, and such an AI / ML model can be referred to as a UE-side AI / ML model or a UE-side model.

[0150] Additionally, life cycle management (LCM) can be performed for AI / ML models. Life cycle management can include model training, model deployment, model inference, model monitoring, and model updates. This may require support for data collection, model training, functional / model identification, model delivery / transfer, model inference operations, functional / model selection / activation / deactivation / fallback, functional / model monitoring, model updates, and UE capabilities.

[0151] For example, AI / ML technology can be operated based on a functional framework such as FIG. 8. FIG. 8 illustrates an example of a functional framework for application of AI / ML technology applicable to the present disclosure. First, a data collection function (810) performs data preparation on input data collected from objects (e.g., UE, RAN node, network node, etc.) to generate training data (801), monitoring data (803), and / or inference data (805) including processed input data. A model training function (820), which receives training data (801) from the data collection function (810), performs training on an AI / ML model using the training data (801) and provides a trained / updated model (813) to a model repository (840). The model repository (840) can store and retain the received trained / updated model (813).

[0152] A management function (830) may be used to control AI / ML model training. The management function (830) may control the operation of the AI / ML model or AI / ML functions, or supervise their performance. To this end, the management function (830) may receive monitoring data (830) from the data collection function (810) and inference output (809) from the inference function (840). The management function (830) manages the data received from the data collection function (810) and the inference function (840) so that the inference task can be performed efficiently. That is, the management function (830) may transmit performance feedback or a retraining request (807) to the model training function (820) to improve the inference task. Here, the performance feedback may be used to indicate a learning goal or as a reward for reinforcement learning. Additionally, the management function (830) can transmit management instructions (811) that instruct the inference function (840) to select AI / ML models or AL / ML-based functions to be used, activate / deactivate them, or switch to non-AI / ML operation.

[0153] The inference function (840) generates an inference output (809) by performing inference and / or prediction using the inference data (805) received by the data collection function (810). Here, the inference output (809) refers to the inference output of the AI / ML model used by the inference function (840), and the details of the inference output may vary depending on the use case. The AI / ML model used by the inference function (840) can be controlled by the management function (830). That is, the management function (830) can transmit a model transfer / forward request signal (815) to request a necessary AI / ML model to the model repository function (850), and the model repository function (850) can transmit the corresponding AI / ML model to the inference function (840) via a model transfer / forward signal (817). Therefore, the inference function (840) can perform inference using the AI / ML model (817) according to the received management instruction (811).

[0154] Additionally, the management function (830) may trigger or perform a designated task / action based on the inference output (809). Accordingly, the management function (830) may trigger a task / action for another entity (e.g., at least one UE, at least one RAN node, at least one network node, etc.) or for itself. Any one of the functions exemplified in FIG. 8 described above may be performed by two or more entities, including the RAN, the network node, the network operator's OAM, or the UE, in collaboration. This may be referred to as a split AI operation.

[0155] Not all of the functions (810 to 850) illustrated in FIG. 8 need to be used to utilize the AI / ML model, and the method of combining them is not limited to a specific method. Accordingly, the functions (810 to 850) may be operated in an integrated manner, or some functions may be omitted. Furthermore, the functions (810 to 850) illustrated in FIG. 8 are not necessarily limited to being implemented as separate devices or apparatuses. For example, some or all of the functions (810 to 850) may be included in the processor (202) of FIG. 2. Furthermore, the model storage function (850) may be included in the memory (204) of FIG. 2.

[0156] FIG. 9 illustrates an example of a procedure for utilizing an AI model applicable to the present disclosure. FIG. 9 illustrates a case where a model training function (820) is included in a network node and a model inference function (840) is included in a RAN node. Referring to FIG. 9, in step 1, RAN node 1 and RAN node 2 transmit input data (e.g., training data) for training an AI model to the network node. Here, RAN node 1 and RAN node 2 may transmit data collected from the UE (e.g., measurements of the UE related to RSRP, RSRQ, SINR of the serving cell and neighboring cells, the UE's position, speed, etc.) together to the network node. In step 2, the network node trains the AI ​​model using the received training data. In step 3, the network node distributes / updates the AI ​​model to RAN node 1 and / or RAN node 2. RAN node 1 and / or RAN node 2 may also continue model training based on the received AI model. In this procedure, it is assumed that the AI ​​model is deployed / updated only to RAN node 1. In step 4, RAN node 1 receives input data (e.g., inference data) for AI model inference from UE and RAN node 2. In step 5, RAN node 1 performs AI model-based inference using the received inference data to generate output data (e.g., prediction or decision). In step 6, if applicable, RAN node 1 may transmit model performance feedback to network nodes. In step 7, RAN node 1, RAN node 2, and UE (or 'RAN node 1 and UE', or 'RAN node 1 and RAN node 2') perform actions based on the output data. For example, in case of load balancing operation, the UE may move from RAN node 1 to RAN node 2. In step 8, RAN node 1 and RAN node 2 transmit feedback information to network nodes.

[0157] Network nodes can manage AI models based on feedback information regarding the AI ​​model's inference results. For example, the network node can perform additional training on the AI ​​model or generate additional information about the AI ​​model (e.g., performance information, accuracy information, etc.). If additional training is performed on the AI ​​model, the network node can distribute the updated AI model to RAN node 1.

[0158] As described with reference to Figure 9, model training can be performed by network nodes, and inference using the model can be performed by RAN node 1. In other words, the model training and inference functions can be distributed. Typically, model training requires significant computational resources because it utilizes large amounts of data and complex algorithms for optimization. In contrast, inference, which uses a trained model to derive conclusions about new data, requires relatively fewer computational resources compared to model training. Therefore, using the procedure of Figure 9, model training can be performed through network nodes when the computational resources of the UE or RAN node are insufficient. Furthermore, security can be ensured for the AI ​​model because the AI ​​model is not disclosed to the UE.

[0159] FIG. 9 illustrates a case where a model training function (820) is included in a network node and a model inference function (840) is included in a RAN node, but the present disclosure is not limited thereto. For example, if the computational resources of the RAN node are sufficient, both the model training function (820) and the model inference function (840) may be included in RAN node 1. In this case, RAN node 1 receives training data for training an AI model from the UE and RAN node 2. RAN node 1 trains the AI ​​model using the received training data. Thereafter, RAN node 1 receives inference data for AI model inference from the UE and RAN node 2. RAN node 1 performs inference based on the AI ​​model using the received inference data to generate output data. Based on the output data, the UE, RAN node 1, and RAN node 2 may perform operations related to communication (e.g., handover, cell change). Thereafter, the UE and RAN node 2 may transmit feedback regarding the operations to RAN node 1. Therefore, RAN node 1 can learn the AI ​​model and update its own AI model using feedback information regarding the AI ​​model's inference results. According to the aforementioned method, signaling with the network is not required for AI model learning and inference, thereby reducing network load and delays until the AI ​​model is trained or inference results are received. Furthermore, since the UE performs inference using the AI ​​model, its personal information is not transmitted to network nodes, etc., thereby enhancing the security of personal information.

[0160] As another example, the model training function (820) may be included in the RAN node, and the model inference function (840) may be included in the UE. The RAN node receives training data for training an AI model from the UE, and trains the AI ​​model using the received training data. The RAN node distributes the trained AI model to the UE. The UE may perform inference based on the received AI model to generate output data. At this time, the data for inference may be received from the RAN node, or the UE may use data acquired on its own. The UE and the RAN node may perform communication-related operations based on the output data generated by inference. Thereafter, the UE may transmit feedback regarding the operation to the RAN node. Therefore, the RAN node may train the AI ​​model and distribute the updated AI model to the UE through feedback information regarding the inference result of the AI ​​model. According to the above-described method, the model training function (820) may be included in the RAN node, and the model inference function (840) may be included in the UE to perform inference, thereby reducing the load on the RAN node. Additionally, if the UE uses data acquired on its own to make inferences, even if the UE loses connection with the RAN node after receiving the AI ​​model, the UE can continue to infer the distributed AI model and perform operations based on the inference results.

[0161] According to the aforementioned framework and procedures, an AI model can be trained and utilized in a communication system. The model training function (820) and the model inference function (840) can be combined in various ways and are not necessarily limited to the case of FIG. 9. In the aforementioned framework and procedures, various types of data, such as input data, training data, and inference data, are introduced, and the specific content of the aforementioned data may vary depending on the task for which the AI ​​model is utilized. For example, information used in various embodiments of the present disclosure described below may be included in the aforementioned data.

[0162]

[0163] Figure 10 illustrates an AI technology-based communication procedure applicable to the present disclosure. The detailed procedures illustrated in Figure 10 can be combined with various embodiments of the present disclosure described below. For example, data generated according to various embodiments of the present disclosure can be used for operations (e.g., configuration, training, inference, and / or data transmission / reception) in at least one of the detailed procedures illustrated in Figure 10. As another example, the results of the inference illustrated in Figure 10 can be used to transmit and / or receive data according to various embodiments of the present disclosure.

[0164] Referring to FIG. 10, in step S1001, at least one of the UE (1010), the RAN node (1020), and the network node (1030) performs an initial access procedure. For example, in this step, at least one of an initial cell search operation, a system information acquisition operation, a random access operation, and a registration operation may be performed. In step S1003, at least one of the UE (1010), the RAN node (1020), and the network node (1030) performs a configuration procedure. Through the configuration procedure, parameters, resources, connections, and / or entities necessary for performing subsequent procedures in layers between the UE (1010) and the RAN node (1020) and / or in at least one layer between the UE (1010) and the network node (1030) may be determined and / or created. In this case, the configuration procedure may be performed based on information, status, and / or characteristics of an AI model used for subsequent training and inference.

[0165] In step S1005, at least one of the UE (1010), the RAN node (1020), and the network node (1030) performs a model training procedure. At least one of the UE (1010), the RAN node (1020), and the network node (1030) may collect training data and perform learning using the training data. For example, the model training procedure may be performed as described with reference to FIG. 9. If an offline-trained model is used, this step may be omitted.

[0166] In step S1007, at least one of the UE (1010), the RAN node (1020), and the network node (1030) performs a task using the trained model. That is, the task may be performed based on the results of inference and / or prediction using the trained model. For example, the task may be a procedure belonging to a communication protocol, and may be a preparatory operation for subsequent data transmission and / or reception, or may be related to data transmission and / or reception, or may be related to data processing (e.g., encoding, decoding, etc.).

[0167] In step S1009, at least one of the UE (1010), the RAN node (1020), and the network node (1030) transmits and / or receives data. At this time, the result of the task performed in step 1007 may be used. In some cases, the task performed in step 1007 may include transmitting and / or receiving data, in which case this step may be omitted as it is part of step 1007.

[0168]

[0169] Specific embodiments of the present disclosure

[0170] The present disclosure relates to a quantum signature technique that can ensure absolute security by utilizing the inherent properties of quantum mechanics. Specifically, the present disclosure relates to a quantum signature technique based on quantum entanglement, which is used to prevent repudiation and spoofing of message information transmitted between a sender and a receiver, and to secure authentication functions. In particular, the present disclosure presents a technology for performing quantum electronic signatures using a trusted third party (TTP) as an arbitrator and an intermediate link between the two parties when a direct channel is not connected between the sender and the receiver. The present disclosure also covers single-photon-based quantum signature techniques, including both message-attached quantum signature methods. Here, message-attached quantum signature refers to a technique in which a sender performs a signature by transmitting a message and signature information generated from the message to the receiver.

[0171] Digital signature techniques fundamentally provide solutions that guarantee message integrity, message authentication, and non-repudiation, excluding confidentiality, among the four goals of information security. Existing authentication techniques cannot address situations where trust is broken between parties exchanging information. Therefore, digital signature techniques are necessary, and they provide third-party verification for dispute resolution, authentication of the origin of message content, and verification of forgery. Generally, signature techniques are categorized into message attachment-type (signature with appendix), which sends the plaintext message and the signature together, and message recovery-type (signature with message recovery), which additionally ensures message confidentiality by transmitting only the signature and recovering the plaintext from the signature. The classic digital signature and quantum digital signatures introduced below can also be configured in two ways.

[0172] First, let's look at the classical electronic signature technique as follows. Existing electronic signature techniques can be broadly divided into direct signature technique and arbitrator-based signature technique. The direct signature technique is as shown in Figure 11. Figure 11 illustrates the concept of an electronic signature technique based on direct signature. Referring to Figure 11, in an environment where only a sender (e.g., Alice) (1110) and a recipient (e.g., Bob) (1120) exist, digital signature is performed based on an asymmetric key, and modeling is performed using a public key cryptographic algorithm and a hash function. The sender (1110) signs the entire message or hash with his private key, and the recipient (1120) decrypts the signature with the sender's (1110) public key. For example, ElGamal signature and discrete logarithm-based public key algorithms are representative electronic signature techniques. However, electronic signature technology based on direct signatures relies on the security of the sender's private key for its validity. Furthermore, the sender can claim that their private key has been lost or stolen, and the sender's private key can actually be stolen. Consequently, this technology requires third-party intervention. Therefore, while direct signature-based electronic signature technology offers the advantage of structural simplicity, it may be difficult to utilize in situations requiring extremely high security.

[0173] To address this, arbitrator-based signature techniques have emerged, and unlike direct signature techniques, they employ arbitrators or TTPs. Figure 12 illustrates the concept of an arbitrator-based digital signature technique. The digital signature technique illustrated in Figure 12 is a model that uses a conventional cryptographic algorithm and an arbitrator (1230), which verifies the validity of the signed message. Therefore, the arbitrator (1230) must maintain neutrality and require a high level of trust. An arbitrator-based digital signature technique can be implemented using a private key, a public key algorithm, etc. While an arbitrator-based digital signature technique offers greater security in terms of information security compared to a direct signature technique, it has the disadvantage of having a more complex configuration due to the use of an arbitrator (1230), and the reliability of the arbitrator (1230) must always be maintained. Figure 12 illustrates a signing process using a quantum signature method using a symmetric key-based cryptosystem and an unconditionally trustworthy arbitrator (1230). First, Alice (1210) creates a message m and generates a hash value H from the message m using her hash function h. Then, Alice (1210) shares the hash value H with the mediator (1230) and the secret key K A and sends the encrypted hash value u to the arbitrator (1230). Then, the arbitrator (1230) decrypts the encrypted hash value u with the same key and encrypts H with a key K that only it has. T and sends the encrypted hash value S to Alice (1210). Alice (1210) sends the signature information S and message m to Bob (1220). Next, Bob (1220) encrypts the signature information S with the secret key K that he and the arbitrator (1230) have. B encrypts the message m, sends the encrypted signature information v to the arbitrator (1230), and stores the message m. The arbitrator (1230) recovers H included in the signature information using its own secret keys, and converts H to KB and sends the result of encryption w to Bob (1220). Based on this, Bob (1220) determines whether the signature has been passed by checking whether H' and H generated from message m match. In other words, the electronic signature technique consists of three steps: an initialization step of sharing a symmetric key, a step of generating signature information from a message, and a step of performing signature verification at Bob (1220) with the help of an arbitrator (1230) after transmitting the signature information.

[0174]

[0175] The following is a review of electronic signature techniques utilizing quantum mechanics. Quantum electronic signature techniques utilize the properties of quantum mechanics to provide unconditional security. Similar to existing electronic signature technologies, they can be categorized into quantum one-time signatures (QTSs), which consist of a quantum one-way function and a combination of private and public keys, and arbitrated quantum signatures (AQSs). Among quantum electronic signature techniques, QTSs follow the Lamport-Diffle one-time signature architecture. The sender uses their private key as input to a quantum one-way function to generate a public key shared between the sender and receiver. Next, the sender transmits the message and the location of the private key mapped to the message as signature information to the receiver. During the verification process, the receiver generates a message using the received signature information and the same quantum one-way function as the sender. The recipient verifies the signature by verifying that the generated message matches the message received from the sender. In other words, quantum one-time signatures, similar to direct signature techniques among existing signature techniques, use only the sender and receiver to perform the signing process.

[0176] On the other hand, arbitrated quantum signatures (AQS) are divided into methods based on quantum entanglement states, such as GHZ states and Bell states, and methods based on single photons. The first AQS was introduced by G. Zeng in 2002 and is a quantum signature technique based on a secret symmetric key and an arbitrator using GHZ states using quantum key distribution technology.

[0177] Figure 13 illustrates the concept of a arbitrator-based quantum signature technique utilizing GHZ states. Figure 13 illustrates the configuration of a arbitrator-based quantum electronic signature technique utilizing GHZ states. The arbitrator-based quantum signature technique utilizing GHZ states proceeds through the stages of preparation, signature generation, and signature verification.

[0178] In the preparation phase, Alice (1310) and the mediator (1330) use a symmetric key , Bob (1320) and the arbitrator (1330) share a symmetric key The arbitrator (1330) can create a GHZ state and distribute the GHZ state upon request from Alice (1310) and Bob (1320).

[0179] In the signature generation step, Alice (1310) generates a quantum message containing N qubits. = + , and the quantum one time pad algorithm and A quantum message having a quantum state other than the quantum state of a quantum message using Next, Alice (1310) converts the quantum message And perform Bell state measurement of GHZ state particle of Alice (1310) and compare the result with 2N qubits. Next, Alice (1310) saves the signature information Generates signature information Is and About can be generated by applying a quantum one-time pad algorithm using . For example, and for Signature information by quantum one-time pad algorithm operation defined as can be generated. At this time, quantum messages contains N qubits and signature information contains 3N qubits.

[0180] Signature information generated by Alice (1310) and multiple quantum messages is transmitted to Bob (1320). Bob (1320) is a quantum message One of them is stored for use in subsequent signature verification. Then, Bob (1320) measures his GHZ state particle along the X-axis, and the measurement result Then, Bob (1320) saves the signature information , at least one remaining quantum message , measurement results cast Encrypt with and the encrypted result is sent to the arbitrator (1330).

[0181] The arbitrator (1330) received cast By decrypting the signature information using and quantum messages Obtain. The arbitrator (1330) obtains the signature information cast By decrypting using and obtain, to By applying a conversion operator based on The arbitrator (1330) determines whether the signature information is forged or not based on whether the two values ​​obtained are the same. determines whether it is 0 or 1. Next, the arbitrator (1330) measures Alice's (1310) measurement value , measurement value of rice (1320) , judgment factor , GHZ state particles not measured in the arbitrator (1330) , signature information cast Encrypt using and the result of encryption Send to Bob (1320).

[0182] Finally, in the signature verification step, Bob (1320) Decryption is performed using and the verification procedure of the signature information is performed in two steps. First, as the first signature verification operation, Bob (1320) includes Factors for determining whether something is counterfeit or not Verifies based on the value of . If, If =0, the signature is forged, and Bob (1320) therefore receives the quantum message and stop the procedure. On the other hand, If =1, it is a component of the signature information. Since this is correct, Bob (1320) proceeds with the second signature verification operation as follows.

[0183] In the second signature verification operation, the unmeasured GHZ state particle of the arbitrator (1330) received from the arbitrator (1330) Regarding, Bob (1320) and By taking an appropriate operator that can be inferred from the correlation between the measurement results and the GHZ state. . Here, the selectable operators are as follows [Table 2].

[0184] Operations required to recover messages ± | - Z - Z ± | ± X - XZ - XZ ± X

[0185] Next, we have previously saved the rice (1320) and previously acquired Verify the correctness of the signature information by checking whether it matches. and If this matches, Bob (1320) judges it as complete correction, and the message Accept. and If this does not match, Bob (1320) sends a message Reject.

[0186] The quantum signature technique based on a mediator using a triplet GHZ state introduced by G. Zeng can also be performed using a two-photon entangled state such as a Bell state. Fig. 14 illustrates the concept of a quantum signature technique based on a mediator using a Bell state. Fig. 14 illustrates the configuration of a technique that performs a signature similar to the procedure described with reference to Fig. 13 in a situation where the entangled quantum state shared by the mediator is replaced from a GHZ state utilizing the entanglement of three photons to a Bell state, which is a two-photon entangled state.

[0187] In the preparation phase, Alice (1410) and the mediator (1430) use a symmetric key , Bob (1420) and the arbitrator (1430) share a symmetric key The mediator (1430) can create an entanglement state and distribute the entanglement state according to the request of Alice (1410) and Bob (1420).

[0188] In the signature generation step, Alice (1410) generates a quantum message containing N qubits. = + , and the quantum one time pad algorithm and A quantum message having a quantum state other than the quantum state of a quantum message using Next, Alice (1410) converts the quantum message And perform the entanglement state measurement of the particle of Alice (1410), and the result is the entanglement state measurement result with the length of 2N qubits. Next, Alice (1410) stores the signature information Generates signature information Is and About can be generated by applying a quantum one-time pad algorithm using . For example, and for Signature information by quantum one-time pad algorithm operation defined as can be generated. At this time, quantum messages contains N qubits and signature information contains 3N qubits.

[0189] Signature information generated by Alice (1410) and multiple quantum messages is transmitted to Bob (1420). Bob (1420) is a quantum message One of them is stored for use in subsequent signature verification. Then, Bob (1420) stores the signature information , at least one remaining quantum message cast Encrypt with and the encrypted result is sent to the arbitrator (1430).

[0190] The arbitrator (1430) received cast By decrypting the signature information using and quantum messages obtains the signature information. The arbitrator (1430) cast By decrypting using and obtain, to By applying a conversion operator based on The arbitrator (1430) determines whether the signature information is forged based on whether the two values ​​obtained are identical. determines whether it is 0 or 1. Next, the arbitrator (1430) measures Alice's (1410) measurement value , judgment factor , signature information cast Encrypt using and the result of encryption Send to Bob (1420).

[0191] Finally, in the signature verification step, Bob (1420) Decryption is performed using and the verification procedure of the signature information is performed in two steps. First, as the first signature verification operation, Bob (1420) includes Factors for determining whether something is counterfeit or not Verifies based on the value of . If, If =0, the signature is forged, and Bob (1420) therefore receives the quantum message and stop the procedure. On the other hand, If =1, it is a component of the signature information. Since this is correct, Bob (1420) proceeds with the second signature verification operation as follows.

[0192] In the second signature verification operation, the unmeasured entangled state particle of the arbitrator (1430) received from the arbitrator (1430) Regarding, Bob (1420) is the result of measuring the bell state. and by taking appropriate operators that can be inferred from the correlation of the entangled state. . Here, the selectable operators are as follows [Table 3].

[0193] Operations required to recover messages ± | - Z ± X - XZ

[0194] Next, we have previously saved the rice (1420) and previously acquired Verify the correctness of the signature information by checking whether it matches. and If this matches, Bob (1420) judges it as complete correction, and the message Accept. and If this does not match, Bob (1420) sends a message Reject.

[0195] Applying a method similar to that shown in Figure 14 can maintain security while reducing the amount of information transmitted compared to GHZ state-based quantum signature techniques. Specifically, referring to Figures 13 and 14, it is confirmed that the number of qubits transmitted between the arbitrator and Bob is reduced from 5N and 7N+1 to 4N and 5N+1.

[0196] The two entanglement-based mediator-based quantum signature techniques described above can be implemented using single photons. Using a single photon eliminates the need for processes like generating an entangled light source and measuring Bell states, making implementation relatively easier and significantly reducing the amount of entangled qubit information transmitted compared to the two previous techniques.

[0197]

[0198] Figure 15 illustrates the concept of a single-photon-based quantum signature technique. Figure 15 illustrates the operations of Alice (1510), Bob (1520), and an arbitrator (1530) according to a single-photon-based quantum signature technique that utilizes a public board instead of an entangled state.

[0199] In the initial phase, Alice (1510), Bob (1520), and the mediator (1530) each share a secret symmetric key they need. Specifically, Alice (1510) and the mediator (1530) share a secret symmetric key , Bob (1520) and the arbitrator (1530) share a secret symmetric key , Alice (1510) and Bob (1520) share a secret symmetric key Share.

[0200] At the signing stage, Alice (1510) sends the message To further ensure the confidentiality of the message, Alice (1510) generates a random number Secret qubit string by encrypting the message using and create, Secret symmetric key from Generated using and secret symmetric key Generated using Signature information based on generates. And, Alice (1510) creates the signature information Send to Bob (1520).

[0201] In the signature verification step, Bob (1520) receives the received signature information From , , is obtained. And, Bob (1520) is obtained from the signature information. and Encrypt and encrypt the result is sent to the arbitrator (1530). The arbitrator (1530) By decrypting and obtains and performs signature verification. Specifically, the arbitrator (1530) By decrypting and obtain, and Compare. And, the arbitrator (1530) and Indicates whether or not the match is It is announced through the public board and is regenerated as information required for verification by Bob (1520). Send to Bob (1520).

[0202] Bob (1520) verifies the message information by decrypting the received information. First, Bob (1520) checks the message information on the public board. Check it out, If the value is 1, the received By decrypting and , and Bob (1520) By decrypting and obtain, and Indicates whether or not the match is The value is announced through a public board. That is, if no inconsistency occurs during the verification process, Bob (1520) announces the verification result through a public channel.

[0203] Verification results If it is determined that there is no problem with the verification result of Bob (1520), Alice (1510) sends to Bob (1520) the random number information required to restore the message. transmits it through a public channel. Finally, Bob (1520) receives the received random information By proceeding with the restoration process for the message information you received based on the original message Restores.

[0204]

[0205] The quantum signature techniques described above can commonly satisfy the following four properties.

[0206] First, it must be impossible for the recipient or attacker to forge the signature after it has been generated.

[0207] Second, the signer must not be able to deny the signature and the signed message, and the recipient must not be able to deny receiving the message and signature.

[0208] Third, each message must be assigned a new signature and must not be separated from that signature.

[0209] Fourth, quantum signatures must contain quantum mechanical properties.

[0210]

[0211] The symbols and terms used in the following description can be defined as follows.

[0212] - : quantum message,

[0213] - : Quantum signature information

[0214] - : Secret symmetric key exchanged between Alice and TTP using QKD

[0215] - : Secret symmetric key exchanged between Bob and TTP using QKD

[0216] - : A secret key that only the arbitrator has. It is used during the arbitrator's verification process and is generated using the arbitrator's random number generator.

[0217] - : The quantum state resulting from applying the quantum one time pad algorithm to the message

[0218] - Alice: Message creator

[0219] - Bob: Signer and message receiver and verifier

[0220] - TTP (Trusted Third Party): A third party trusted by all participants in signing.

[0221] - Quantum one-time pad encryption: , applied to the encryption of information transmitted through quantum channels.

[0222] - Unitary transform:

[0223] - : classical encryption

[0224]

[0225] Existing mediator-based quantum signature techniques only consider cases where a direct connection exists between the sender and receiver. Therefore, it is necessary to consider quantum signature techniques for cases where a direct connection does not exist between the sender and receiver. To achieve this, the role of the mediator cannot be limited to assisting with existing verification; it must be expanded to encompass various functions, such as signature generation and verification, and message delivery.

[0226] In the quantum signature technique based on arbitration using entanglement or single photon states, as described with reference to FIGS. 13, 14, and 15, since a direct channel exists between the sender and receiver, messages and signature information can be directly transmitted from the sender to the receiver, and the receiver can perform a verification procedure by exchanging the received information with the arbitrator. In addition, the arbitrator only performs the role of generating the results and factors necessary for signature verification using the information received from the receiver.

[0227] However, quantum signatures may be necessary in situations where a direct connection path does not exist between the sender and receiver (e.g., when LOS is not secured between the sender and receiver, when the transmission distance between the sender and receiver is long, or when direct information transmission is impossible due to environmental factors). In these cases, a messenger is required to relay the signature-related information between the sender and receiver. In digital information-based signature techniques, signature mechanisms utilizing messengers have been developed, and ISO / IEC 13888, the international standard for classical symmetric key-based non-repudiation techniques, considers non-repudiation mechanisms for both cases where a direct connection path exists between the sender and receiver and where it does not, and proposes a non-repudiation mechanism using a TTP as an intermediary. However, for quantum signatures, only mechanisms exist for cases where a direct connection path exists between the sender and receiver. Therefore, when considering future standardization, the development of quantum signature mechanisms is necessary not only for cases where a direct connection path exists, as in classical signature techniques, but also for cases where a direct connection path does not exist.

[0228] In digital information-based signature techniques, signature mechanisms utilizing intermediaries have also been developed, and ISO / IEC 13888, the international standard for classical symmetric key-based non-repudiation techniques, considers non-repudiation mechanisms for both cases where a direct connection path exists between the sender and receiver, and suggests a non-repudiation mechanism using a TTP as an intermediary. However, for quantum signatures, only a mechanism exists for cases where a direct connection path exists between the sender and receiver. Therefore, when considering future standardization, it is necessary to develop a quantum signature mechanism that can handle not only cases where a direct connection path exists between the sender and receiver, as in classical signature techniques, but also cases where there is no direct connection path.

[0229]

[0230] The present disclosure proposes various embodiments for performing a message-attached quantum signature technique (e.g., a technique in which a sender transmits a message and signature information to a receiver to perform signing) using an entanglement-based mediator that can be applied in a situation in which there is no direct information transmission path between a sender (e.g., Alice) and a receiver (e.g., Bob). Embodiment #1 described below relates to a mediator-based quantum signature technique using a GHZ triplet state, and Embodiment #2 relates to a mediator-based quantum signature technique using a Bell state. The quantum signature procedure proposed in the present disclosure consists of three stages: an initialization stage, a quantum signature generation stage, and a verification stage. According to various embodiments, the mediator (e.g., TTP) in the present disclosure may be a certification agent (CA), the sender may be understood as a mobile terminal (e.g., UE) requesting verification of a signature generated from a message, and the receiver may be understood as a base station, server, or core network entity performing verification.

[0231]

[0232] [Example #1] A Quantum Signature Protocol with Message Attachment Based on Arbitrators Using GHZ State

[0233] Example #1 relates to a mediator-based message-attached quantum signature technique utilizing GHZ states, applicable in cases where there is no direct connection path between the sender and receiver. In this signature technique, TTP holds two of the three particles constituting the GHZ state generated by TTP and distributes one particle to Bob. Specifically, the quantum signature technique according to Example #1 can proceed as follows.

[0234] (1) Initial stage

[0235] Figure 16a illustrates the initial steps of a quantum signature scheme based on an arbitrator-based message attachment using a GHZ state according to an embodiment of the present disclosure. Referring to Figure 16a, in a situation where there is no direct connection channel between Alice (1610) and Bob (1620), Alice (1610) and the arbitrator (1630) exchange a secret symmetric key according to the QKD protocol. Similarly, Bob (1620) and the arbitrator (1630) use the channel connected to each other according to the QKD protocol. . In addition, the arbitrator (1630) shares a secret key to be used in the signature verification process. Generate a secret key is held by the arbitrator (1630) and may not be shared with other devices.

[0236] (2) Quantum signature generation step:

[0237] FIG. 16B illustrates a quantum signature generation step of a message-attached quantum signature technique using a GHZ state arbitrator according to an embodiment of the present disclosure. Referring to FIG. 16B , the quantum signature generation step includes operations S1 to S8. In the proposed technique, since there are no GHZ state particles shared with the sender, the message generated by the sender and additional information generated by encrypting the message are transmitted to the TTP, and a signature is generated based on the message and the additional information, thereby ensuring that the signature was constructed in the TTP from the message generated by the sender.

[0238] Referring to Figure 16b, in operation S1, Alice (1610) first sends a primary message containing n qubits Creates four copies of . Here, In action S2, Alice (1610) Using qubit messages By encrypting one copy of the requested information generates one copy of the qubit message. Then, in operation S3, Alice (1610) sends three copies of the qubit message to the mediator (1630). and one copy of the requested information By sending , we request the generation of signature information.

[0239] In operation S4, the arbitrator (1630) is in GHZ state Among the particles that make up In operation S5, the arbitrator (1630) obtains and Perform BSM using and measure the results In operation S6, in order to ensure that only the arbitrator (1630) can be the subject of signature verification, the arbitrator (1630) A secret key held only by the arbitrator (1630) By encrypting it with , the factor for primary verification generates. That is, the arbitrator (1630) generates information for signature verification of the arbitrator (1630). In operation S7, the arbitrator (1630) generates a signature In operation S8, the arbitrator (1630) signs and two copies of the message Send to Bob (1620).

[0240]

[0241] (3) Verification stage

[0242] FIGS. 16c and 16d illustrate verification steps of a message-attached quantum signature based on an arbitrator using a GHZ state according to one embodiment of the present disclosure. Referring to FIGS. 16c and 16d , the verification step includes operations V1 to V14.

[0243] In action V1, Bob (1620) signs information and two copies of the message Received from the arbitrator (1630), one copy of the two copies is stored for use in message verification. In operation V2, Bob (1620) is the third particle in the GHZ state Received from the arbitrator (1630), By measuring in the X direction, the result is In operation V3, Bob (1620) saves In operation V4, Bob (1620) generates the first transmission information for the first verification. is transmitted to the arbitrator (1630). Here, the first verification means the verification performed by the arbitrator (1630).

[0244] In operation V5, the arbitrator (1630) receives The secret key held by the arbitrator (1630) By decrypting using In operation V6, the arbitrator (1630) generates at least one argument for signature verification. Specifically, the arbitrator (1630) generates signature information By decrypting the first verification factor Decide on, Obtained through The second verification factor is encrypted with a secret key that only the arbitrator (1630) has. Here, the second verification factor can be obtained from the operation S6 described above.

[0245] In operation V7, the arbitrator (1630) performs signature verification by comparing whether the signature verification factors match (e.g., using a swap test), and indicates the result of the signature verification by providing a verification result. creates. For example, On the other hand, is set to, On the other hand, is set to . In this verification process, two unknown quantum states and When performing a swap test for comparison, based on whether the statistical error rate obtained by comparing the quantum state matches of a number of message qubit strings corresponding to the length of n (e.g., a sufficiently large number) exceeds a threshold (e.g., the comparison error rate that occurs when comparing quantum state information of the same n qubit strings, the larger n, the lower the error rate). is set to 0 or 1.

[0246] In operation V8, the arbitrator (1630) is the second particle in the GHZ state In operation V9, the mediator (1630) Measurement results of entangled particles and Using qubit messages It is converted by applying an operator to convert to . For example, the operator is as follows [Table 4].

[0247] The mediator's message Operators required for recovery | Z Z | X XZ XZ X

[0248] In operation V10, the arbitrator (1630) provides the information necessary to determine the verification result of Bob (1620), i.e., the second transmission information for the second verification. In operation V11, the arbitrator (1630) generates the second transmission information required for Bob's (1620) verification decision. In operation V12, Bob (1620) transmits the received information By decrypting In operation V13, Bob (1620) receives the signature verification result received from the arbitrator (1630). It determines whether to pass or reject signature verification using . If, On the other hand, rice (1620) This is judged to be forged. On the other hand, On the other hand, rice (1620) is judged as passing and proceeds to the next step. In operation V14, Bob (1620) verifies the message in Bob (1620) by using the qubit message stored in operation V1. and qubit messages received through the operation V12 process. Message verification is performed by comparing . If, On the other hand, rice (1620) Approves the verification pass. On the other hand, On the other hand, rice (1620) Rejects verification approval.

[0249]

[0250] FIGS. 17A to 17C illustrate examples of operations of a sender, a receiver, and a mediator according to a message attachment quantum signature technique using a mediator-based GHZ state according to an embodiment of the present disclosure. In FIGS. 17A to 17C , Alice (1710) performs the role of a message generator, Bob (1720) performs the role of a verifier, and the mediator (1730) is positioned as an intermediate connection path existing between the sender and the receiver, and performs the roles of generating and verifying a signature and receiving a message generated by the sender. In the flowchart, I denotes an initial stage, S denotes a signature generation stage, and V denotes a signature verification stage, respectively.

[0251]

[0252] [Example #2] A message attachment-based quantum signature technique using a bell state when TTP is used as an intermediate link between the sender and receiver.

[0253] Example #2 relates to a message-attached quantum signature technique based on a mediator utilizing a Bell state, applicable when there is no direct connection path between the sender and receiver. This technique overcomes the problem of existing Bell state-based mediator-attached quantum signature techniques, which operate only when a direct connection path exists between the sender and receiver. In this signature technique, the mediator (e.g., TTP) and Bob each share an entanglement particle. Specifically, the quantum signature technique according to Example #2 can proceed as follows.

[0254] (1) Initial stage:

[0255] Figure 18a illustrates the initial stage of a message attachment-based quantum signature scheme using a bell state according to one embodiment of the present disclosure. Referring to Figure 18a, in a situation where there is no direct connection channel between Alice (1810) and Bob (1820), Alice (1810) and the arbitrator (1830) exchange a secret symmetric key according to the QKD protocol. Similarly, Bob (1820) and the arbitrator (1830) use the channel connected to each other according to the QKD protocol. . In addition, the arbitrator (1830) shares a secret key to be used in the signature verification process. Generate a secret key is held in the arbitrator (1830) and may not be shared with other devices. In this embodiment, the Bell state is a quantum state that utilizes the entanglement relationship between two particles, so the arbitrator (1830) and Bob (1820) share one entangled particle each.

[0256] (2) Quantum signature generation step:

[0257] FIG. 18b illustrates a quantum signature generation step of a message-attached quantum signature technique based on a mediator using a bell state according to an embodiment of the present disclosure. Referring to FIG. 18b, the quantum signature generation step includes operations S1 to S11. In the proposed technique, based on the characteristic that the states of the mediator and the receiver's GHZ state particles used for signature and message verification are determined when performing BSM measurements on the message generated by the sender and the GHZ state particles, it can be guaranteed that the signature was generated from the sender's message.

[0258] Referring to Figure 18b, in operation S1, Alice (1810) first sends a primary message containing n qubits Creates four copies of . Here, In action S2, Alice (1810) Using qubit messages By encrypting one copy of the requested information generates one copy of the qubit message. Then, in operation S3, Alice (1810) sends three copies of the qubit message to the mediator (1830). and one copy of the requested information By sending , we request the generation of signature information.

[0259] In action S4, the arbitrator (1830) and Perform BSM using and measure the results In operation S6, in order to ensure that only the arbitrator (1830) can be the subject of signature verification, the arbitrator (1830) A secret key held only by the arbitrator (1830) By encrypting it as the first factor for primary verification In operation S7, the arbitrator (1830) generates the signature information In operation S8, the arbitrator (1830) signs and two copies of the message Send to Bob (1820).

[0260]

[0261] (3) Quantum signature verification process

[0262] FIG. 18C illustrates a verification step of a quantum signature scheme based on an arbitrator and message recovery using a bell state according to an embodiment of the present disclosure. Referring to FIG. 18C , the verification step includes operations V1 to V13. The signature verification process begins with Bob (1820) receiving a message and a signature from an arbitrator (1830). First, Bob (1820) receives the signature and message from the arbitrator (1830), stores the message, and returns the remainder to the arbitrator (1830). Next, the arbitrator (1830) performs signature verification using the received information and transmits the result and information to be used for message verification by Bob (1820). Finally, Bob (1820) determines whether the signature has passed and verifies the message based on the received information. The details of the quantum signature verification process are as follows.

[0263] In action V1, Bob (1820) signs information and two copies of the message Received from the arbitrator (1830), one copy of two copies is stored for use in message verification. In operation V2, Bob (1820) uses his private key to send the first transmission information for primary verification. In operation V3, Bob (1820) generates the first transmission information is sent to the arbitrator (1830).

[0264] In operation V4, the arbitrator (1830) receives The secret key held by the arbitrator (1830) By decrypting using In operation V5, the arbitrator (1830) generates at least one argument for signature verification. Specifically, the arbitrator (1830) generates signature information By decrypting the first verification factor Decide on, Obtained through The second verification factor is encrypted with a secret key that only the arbitrator (1830) has. Here, the second verification factor can be obtained from the operation S6 described above.

[0265] In operation V6, the arbitrator (1830) performs signature verification by comparing whether the signature verification factors match (e.g., using a swap test), and indicates the result of the signature verification by providing a verification result. creates. For example, On the other hand, is set to, On the other hand, is set to . In this verification process, two unknown quantum states and When performing a swap test for comparison, based on whether the statistical error rate obtained by comparing the quantum state matches of a number of message qubit strings corresponding to the length of n (e.g., a sufficiently large number) exceeds a threshold (e.g., the comparison error rate that occurs when comparing quantum state information of the same n qubit strings, the larger n, the lower the error rate). is set to 0 or 1.

[0266] In operation V7, the arbitrator (1830) provides the information necessary to determine the verification result of Bob (1820), i.e., the second transmission information for the second verification. In operation V8, the arbitrator (1830) generates the second transmission information required for Bob's (1820) verification decision. In operation V9, Bob (1820) transmits the received second transmission information By decrypting In operation V10, Bob (1820) receives the signature verification result from the arbitrator (1830). It determines whether to pass or reject signature verification using . If, On the other hand, rice (1820) This is judged to be forged. On the other hand, On the other hand, rice (1820) It is judged as passing and proceeds to the next step.

[0267] In action V11, Bob (1820) is the second particle in the Bell state. In action V12, Bob (1820) gets The results of the bell state measurement of the arbitrator (1830) who has this relationship Use the message It is converted by applying an operator to convert to . For example, the operator is as follows [Table 5].

[0268] message Operators required for recovery | Z Z |

[0269]

[0270] In operation V13, Bob (1820) stores the message stored in operation V1 for message verification in Bob (1820). and messages received through the Action V12 process Message verification is performed by comparing the two. This operation may include an operation to check whether the information between the two parties matches using the swap test used in the signature verification procedure of the arbitrator (1830). If On the other hand, Bob (1920) Approves the verification pass. On the other hand, On the other hand, rice (1820) Rejects verification approval.

[0271]

[0272] FIGS. 19A to 19C illustrate examples of operations of a sender, a receiver, and a mediator according to a message attachment quantum signature technique using a mediator-based bell state according to an embodiment of the present disclosure. In FIGS. 19A to 19C , Alice (1810) performs the role of a message generator, Bob (1820) performs the role of a verifier, and the mediator (1830) is positioned as an intermediate connection path existing between the sender and the receiver, and performs the roles of generating and verifying a signature and receiving a message generated by the sender. In the flowchart, I denotes an initial stage, S denotes a signature generation stage, and V denotes a signature verification stage, respectively.

[0273]

[0274] FIG. 21 illustrates an example of a procedure in which an arbitrator performs a quantum signature according to a message-attached quantum signature technique based on an arbitrator according to one embodiment of the present disclosure. FIG. 21 illustrates a method performed by a device that arbitrates a quantum signature (e.g., an arbitrator (1630), an arbitrator (1830), or a certification authority server), and the subject of the operation is hereinafter referred to as a third device.

[0275] Referring to FIG. 21, in step S2101, a third device receives request information requesting the generation of quantum signature information from a first device (e.g., Alice (1610), Alice (1810), or a terminal). The request information includes at least one qubit message including qubits and may be received via a quantum channel. In this case, the at least one qubit message may be received in an encrypted state using a first secret symmetric key shared between the third device and the first device. In addition, according to various embodiments, at least one unencrypted qubit message may be received together with the request information.

[0276] In step S2103, the third device transmits signature information generated based on the request information to the second device. That is, the third device can generate a first verification factor by encrypting an encrypted qubit message among the qubit messages received from the first device using the secret key of the third device. In addition, the third device can generate signature information by encrypting the first verification factor using a second secret symmetric key shared between the third device and the second device. At this time, according to various embodiments, the first verification factor can be encrypted alone or together with the qubit message converted by the third device.

[0277] In step S2105, the third device receives first transmission information from the second device. The first transmission information is quantum information generated by the second device based on the signature information transmitted in step S2103, and can be received via a quantum channel. Here, the first transmission information includes quantum information encrypted using a second secret symmetric key.

[0278] In step S2107, the third device performs the first verification based on the first transmission information. The third device can obtain the quantum information elements included in the first transmission information by decrypting the first transmission information. Here, since the protocol is defined so that the first transmission information includes the quantum information elements transmitted from the third device to the second device (e.g., at least one of a qubit message, signature information, and a measurement result of the second device for a GHZ state particle), the third device can obtain the first verification factor by decrypting the signature information, obtain the second verification factor by encrypting the qubit message, and perform the first verification based on the first verification factor and the second verification factor. Through this, the third device can generate verification result information indicating whether the first verification factor and the second verification factor match.

[0279] In step S2109, the third device transmits second transmission information for secondary verification in the second device. The second transmission information may include quantum information corresponding to the first transmission information. Specifically, the third device may generate at least one quantum information element included in the first transmission information, encrypt the at least one quantum information element using a second secret symmetric key to generate second transmission information, and transmit the second transmission information through a quantum channel. For example, the at least one quantum information element may include at least one of verification result information indicating the first verification result, a qubit message restored from a GHZ state particle, and a measurement result of the third device on a Bell state particle.

[0280]

[0281] Figure 22 illustrates an example of a procedure for a recipient to perform a signature according to a message attachment-based quantum signature technique based on an intermediary according to one embodiment of the present disclosure. Figure 22 illustrates a method performed by a device (e.g., Bob (1620), Bob (1820), or a core network entity) that verifies signature information, and the subject of the operation is hereinafter referred to as a second device.

[0282] Referring to FIG. 22, in step S2201, the second device receives signature information from the third device. The signature information is quantum information encrypted using a second secret symmetric key shared between the second device and the third device, and is derived from a qubit message generated by the first device. In one embodiment, the signature information may include a result of sequentially encrypting the qubit message using the first secret symmetric key shared between the first device and the third device, the secret key of the third device, and the second secret symmetric key. At this time, a plurality of qubit messages may be received together with the signature information. In this case, the second device may store at least one received qubit message for subsequent operations.

[0283] In step S2203, the second device transmits the first transmission information generated based on the signature information. The second device may generate the second transmission information by encrypting the signature information using a second secret symmetric key together with at least one other quantum information element. According to various embodiments, the at least one other quantum information element may include at least one of the qubit messages received in step S2201 and at least one of the second device's measurement results for the GHZ state particle.

[0284] In step S2205, the second device receives second transmission information including the result of the first verification performed based on the first transmission information. The second transmission information may include verification result information indicating the result of the first verification performed by the third device and at least one other quantum information element. According to various embodiments, the at least one other quantum information element may include at least one of a qubit message restored from a GHZ state particle and a measurement result of the third device on a Bell state particle.

[0285] In step S2207, the second device performs secondary verification based on the second transmission information. To this end, the second device decrypts the second transmission information using the second secret symmetric key to obtain quantum information elements included in the second transmission information. According to various embodiments, the second device may determine whether the signature is forged based on verification result information among the obtained quantum information elements. Furthermore, according to one embodiment, the second device may determine whether the qubit message passes using the qubit message among the obtained quantum information elements. Furthermore, according to another embodiment, the second device may reconstruct the qubit message from the second particle in the Bell state using the measurement result of the third device for the first particle in the Bell state among the obtained quantum information elements, and determine whether the reconstructed qubit message passes.

[0286]

[0287] The quantum signature technique utilizing quantum entanglement described above can be utilized in various ways. For example, use cases of the quantum signature technique according to various embodiments of the present disclosure are as follows.

[0288] FIG. 23 illustrates an example of a quantum key distribution (QKD) technology applied with a quantum signature technique according to an embodiment of the present disclosure. FIG. 23 illustrates the structure of a quantum cryptography communication system applying QKD, which is being standardized in ETSI and ITU-T SG 13 and 17, and exemplifies a case where quantum signature technology is applied as a technology for authentication, non-repudiation, and anti-forgery of a sender and receiver during the secret key transmission process of QKD. The quantum cryptography communication technology uses QKD technology to quantum-mechanically securely generate a secret symmetric key to be used for encryption and decryption of plaintext, and performs message encryption and decryption using the secret symmetric key. Here, the quantum signature technique according to various embodiments of the present disclosure can be adopted as at least a part of the authentication operation, which is one of the post-processing processes in the overall procedure of QKD. Although existing authentication techniques are limited to user and message authentication, by applying the quantum signature technique according to various embodiments of the present disclosure to the authentication operation, additional functions such as non-repudiation of the sender and receiver, message integrity, and anti-forgery can be secured in addition to existing authentication.

[0289] However, since the existing authentication technique uses the classic Wegman Carter authentication technique, it only uses the public channel, but the quantum signature technique according to the present disclosure uses both the quantum channel and the public channel. In Fig. 23, the quantum signature technique according to the present disclosure can be performed before or after the preprocessing process in the quantum domain (2302) (e.g., the process of generating random quantum information at the sender and completing random measurements at the receiver to generate a raw key). Then, in the public domain (2304), when the signing operation according to the quantum signature technique according to the present disclosure is completed within the authentication operation (2301), a postprocessing process for the raw key information (e.g., the process of obtaining the final secret symmetric key through operations from sifting to privacy amplification) is performed.

[0290]

[0291] Fig. 24 illustrates an example of quantum secure direct communication (QSDC) using a quantum signature technique according to one embodiment of the present disclosure. Fig. 24 illustrates the structure of a QSDC technique that can securely transmit messages directly through a quantum channel based on quantum mechanics without using a secret key, and exemplifies a case where quantum signature technology is applied as a technology for authentication, non-repudiation, and anti-forgery of senders and receivers exchanging messages in QSDC.

[0292] A typical QSDC technique performs object authentication and message authentication for the transmitting and receiving entities through a public channel. When applying the quantum signature technique according to the present disclosure, in the quantum domain (2402), quantum information transmitted through a quantum channel for security verification is measured, and in the classical domain (2404), the quantum signature technique according to the present disclosure can be applied to the authentication operation (2401) before the parameter estimation operation using some of the measured quantum information. In this process, if the quantum signature is passed, operations such as parameter estimation and message encoding are sequentially performed, and the information that has passed the signing process can secure authentication, anti-forgery, non-repudiation, and message integrity.

[0293]

[0294] Existing intermediary-based quantum signature techniques only consider cases where a direct channel exists between the sender and receiver, allowing for the direct exchange of signature and message information between the sender and receiver, with the TTP assisting in receiver verification. However, there may be situations where quantum electronic signatures must be performed even when a direct channel connection between the sender and receiver is not established. Therefore, in this disclosure, we propose a method for performing quantum signatures between the sender and receiver by applying a TTP as an intermediary in situations where a direct channel connection is not established between the sender and receiver. Through this, we demonstrate that it is possible to secure message confidentiality in addition to the authentication / forgery / repudiation prevention functions of electronic signatures.

[0295]

[0296] Below, examples of wireless device utilization to which various embodiments of the present disclosure are applied are described.

[0297] Figure 25 illustrates an example of a wireless device applicable to the present disclosure. The wireless device may be implemented in various forms depending on the use case / service (see Figure 1).

[0298] Referring to FIG. 25, the wireless device (200) corresponds to the wireless device (200) of FIG. 2 and may be composed of various elements, components, units / units, and / or modules. For example, the wireless device (200) may include a communication unit (210), a control unit (220), a memory unit (230), and additional elements (240). The communication unit may include a communication circuit (212) and a transceiver(s) (214). For example, the communication circuit (212) may include one or more processors (202) and / or one or more memories (204) of FIG. 2. For example, the transceiver(s) (214) may include one or more transceivers (206) and / or one or more antennas (208) of FIG. 2. The control unit (220) is electrically connected to the communication unit (210), the memory unit (230), and the additional elements (240) and controls the overall operations of the wireless device. For example, the control unit (220) can control the electrical / mechanical operations of the wireless device based on the program / code / command / information stored in the memory unit (230). In addition, the control unit (220) can transmit information stored in the memory unit (230) to an external device (e.g., another communication device) via a wireless / wired interface through the communication unit (210), or store information received from an external device (e.g., another communication device) via a wireless / wired interface in the memory unit (230).

[0299] The additional element (240) may be configured in various ways depending on the type of the wireless device. For example, the additional element (240) may include at least one of a power unit / battery, an input / output unit (I / O unit), a driving unit, and a computing unit. Although not limited thereto, the wireless device may be implemented in the form of a robot (Fig. 1, 100a), a vehicle (Fig. 1, 100b-1, 100b-2), an XR device (Fig. 1, 100c), a portable device (Fig. 1, 100d), a home appliance (Fig. 1, 100e), an IoT device (Fig. 1, 100f), a digital broadcasting terminal, a hologram device, a public safety device, an MTC device, a medical device, a fintech device (or a financial device), a security device, a climate / environmental device, an AI server / device (Fig. 1, 400), a base station (Fig. 1, 200), a network node, etc. Wireless devices may be mobile or stationary depending on the use / service.

[0300] In FIG. 25, various elements, components, units / parts, and / or modules within the wireless device (200) may be entirely interconnected via a wired interface, or at least some may be wirelessly connected via a communication unit (210). For example, within the wireless device (200), the control unit (220) and the communication unit (210) may be wired, and the control unit (220) and a first unit (e.g., 230, 240) may be wirelessly connected via the communication unit (210). In addition, each element, component, unit / part, and / or module within the wireless device (200) may further include one or more elements. For example, the control unit (220) may be composed of a set of one or more processors. For example, the control unit (220) may be composed of a set of a communication control processor, an application processor, an electronic control unit (ECU), a graphics processing processor, a memory control processor, etc. As another example, the memory unit (130) may be composed of RAM (Random Access Memory), DRAM (Dynamic RAM), ROM (Read Only Memory), flash memory, volatile memory, non-volatile memory, and / or a combination thereof.

[0301] Below, the implementation example of Fig. 25 is described in more detail with reference to the drawings.

[0302] Figure 26 illustrates examples of portable devices applicable to the present disclosure. Portable devices may include smartphones, smart pads, wearable devices (e.g., smartwatches, smartglasses), and portable computers (e.g., laptops, etc.). Portable devices may be referred to as Mobile Stations (MS), User Terminals (UT), Mobile Subscriber Stations (MSS), Subscriber Stations (SS), Advanced Mobile Stations (AMS), or Wireless Terminals (WT).

[0303] Referring to FIG. 26, the portable device (200) may include an antenna unit (208), a communication unit (210), a control unit (220), a memory unit (230), a power supply unit (240a), an interface unit (240b), and an input / output unit (240c). The antenna unit (208) may be configured as a part of the communication unit (210). Blocks 210 to 230 / 240a to 240c of FIG. 26 correspond to blocks 210 to 230 / 240 of FIG. 25, respectively.

[0304] The communication unit (210) can transmit and receive signals (e.g., data, control signals, etc.) with other wireless devices and base stations. The control unit (220) can control components of the mobile device (200) to perform various operations. The control unit (220) can include an AP (Application Processor). The memory unit (230) can store data / parameters / programs / codes / commands required for operating the mobile device (200). In addition, the memory unit (230) can store input / output data / information, etc. The power supply unit (240a) supplies power to the mobile device (200) and can include a wired / wireless charging circuit, a battery, etc. The interface unit (240b) can support connection between the mobile device (200) and other external devices. The interface unit (240b) can include various ports (e.g., audio input / output ports, video input / output ports) for connection with external devices. The input / output unit (240c) can input or output video information / signals, audio information / signals, data, and / or information input from a user. The input / output unit (240c) may include a camera, a microphone, a user input unit, a display unit (240d), a speaker, and / or a haptic module.

[0305] For example, in the case of data communication, the input / output unit (240c) obtains information / signals (e.g., touch, text, voice, image, video) input by the user, and the obtained information / signals can be stored in the memory unit (230). The communication unit (210) converts the information / signals stored in the memory into wireless signals, and can directly transmit the converted wireless signals to other wireless devices or to a base station. In addition, the communication unit (210) can receive wireless signals from other wireless devices or base stations, and then restore the received wireless signals to the original information / signals. The restored information / signals can be stored in the memory unit (230) and then output in various forms (e.g., text, voice, image, video, haptic) through the input / output unit (240c).

[0306] Figure 27 illustrates examples of vehicles or autonomous vehicles applicable to the present disclosure. The vehicles or autonomous vehicles may be implemented as mobile robots, cars, trains, manned / unmanned aerial vehicles (AVs), ships, etc.

[0307] Referring to FIG. 27, a vehicle or autonomous vehicle (200-1) may include an antenna unit (208-1), a communication unit (210-1), a control unit (220-1), a driving unit (240a-1), a power supply unit (240b-1), a sensor unit (240c-1), and an autonomous driving unit (240d-1). The antenna unit (208-1) may be configured as a part of the communication unit (210-1). Blocks 210-1 / 230-1 / 240a-1 to 240d-1 of FIG. 27 correspond to blocks 210 / 230 / 240 of FIG. 25, respectively.

[0308] The communication unit (210-1) can transmit and receive signals (e.g., data, control signals, etc.) with external devices such as other vehicles, base stations (e.g., base stations, roadside base stations (ROS), etc.), and servers. The control unit (220-1) can control elements of the vehicle or autonomous vehicle (200-1) to perform various operations. The control unit (220-1) may include an ECU (Electronic Control Unit). The drive unit (240a-1) can drive the vehicle or autonomous vehicle (200-1) on the ground. The drive unit (240a-1) may include an engine, a motor, a power train, wheels, brakes, a steering device, etc. The power supply unit (240b-1) supplies power to the vehicle or autonomous vehicle (200-1) and may include a wired / wireless charging circuit, a battery, etc. The sensor unit (240c-1) can obtain vehicle status, surrounding environment information, user information, etc. The sensor unit (240c-1) may include an IMU (inertial measurement unit) sensor, a collision sensor, a wheel sensor, a speed sensor, an incline sensor, a weight detection sensor, a heading sensor, a position module, a vehicle forward / backward sensor, a battery sensor, a fuel sensor, a tire sensor, a steering sensor, a temperature sensor, a humidity sensor, an ultrasonic sensor, an illuminance sensor, a pedal position sensor, etc. The autonomous driving unit (240d-1) may implement a technology for maintaining a driving lane, a technology for automatically controlling speed such as adaptive cruise control, a technology for automatically driving along a set path, a technology for automatically setting a path and driving when a destination is set, etc.

[0309] For example, the communication unit (210-1) can receive map data, traffic information data, etc. from an external server. The autonomous driving unit (240d-1) can generate an autonomous driving route and driving plan based on the acquired data. The control unit (220-1) can control the drive unit (240a-1) so that the vehicle or autonomous vehicle (200-1) moves along the autonomous driving route according to the driving plan (e.g., speed / direction control). During autonomous driving, the communication unit (210-1) can irregularly / periodically acquire the latest traffic information data from an external server and can acquire surrounding traffic information data from surrounding vehicles. In addition, during autonomous driving, the sensor unit (240c-1) can acquire vehicle status and surrounding environment information. The autonomous driving unit (240d-1) can update the autonomous driving route and driving plan based on newly acquired data / information. The communication unit (210-1) can transmit information regarding the vehicle location, autonomous driving route, driving plan, etc. to an external server. The external server can predict traffic information data in advance using AI technology, etc. based on information collected from the vehicle or autonomous vehicles, and provide the predicted traffic information data to the vehicle or autonomous vehicles. If the device (220-2) is an autonomous vehicle, it can perform the same procedure as the vehicle or autonomous vehicle (200-1). In addition, if the device (220-2) is a base station or a roadside base station, the device (220-2) can transmit data, control signals, etc. to the vehicle or autonomous vehicle (200-1) through the communication unit (210-2).

[0310] Figure 28 illustrates an example of a vehicle applicable to the present disclosure. The vehicle may also be implemented as a means of transportation, a train, an aircraft, a ship, etc. Referring to Figure 28, the vehicle (200) may include a communication unit (210), a control unit (220), a memory unit (230), an input / output unit (240a), and a position measurement unit (240b). Here, blocks 210 to 230 / 240a to 240b correspond to blocks 210 to 230 / 240 of Figure 25, respectively.

[0311] The communication unit (210) can transmit and receive signals (e.g., data, control signals, etc.) with other vehicles or external devices such as base stations. The control unit (220) can control components of the vehicle (200) to perform various operations. The memory unit (230) can store data / parameters / programs / codes / commands that support various functions of the vehicle (100). The input / output unit (240a) can output AR / VR objects based on information in the memory unit (230). The input / output unit (240a) can include a HUD. The position measurement unit (240b) can obtain position information of the vehicle (200). The position information can include absolute position information of the vehicle (200), position information within a driving line, acceleration information, position information with respect to surrounding vehicles, etc. The position measurement unit (240b) can include GPS and various sensors.

[0312] For example, the communication unit (210) of the vehicle (200) can receive map information, traffic information, etc. from an external server and store them in the memory unit (230). The location measurement unit (240b) can obtain vehicle location information through GPS and various sensors and store the information in the memory unit (230). The control unit (220) can create a virtual object based on the map information, traffic information, and vehicle location information, and the input / output unit (240a) can display the created virtual object on the vehicle window (240a-1, 240a-2). In addition, the control unit (220) can determine whether the vehicle (200) is being driven normally within the driving line based on the vehicle location information. If the vehicle (200) abnormally deviates from the driving line, the control unit (220) can display a warning on the vehicle window through the input / output unit (240a). Additionally, the control unit (220) can broadcast a warning message regarding driving abnormalities to surrounding vehicles through the communication unit (210). Depending on the situation, the control unit (220) can transmit vehicle location information and information regarding driving / vehicle abnormalities to relevant authorities through the communication unit (210).

[0313] Figure 29 illustrates examples of XR devices applicable to the present disclosure. The XR devices may be implemented as HMDs, head-up displays (HUDs) installed in vehicles, televisions, smartphones, computers, wearable devices, home appliances, digital signage, vehicles, robots, and the like.

[0314] Referring to FIG. 29, the XR device (200a) may include a communication unit (210), a control unit (220), a memory unit (230), an input / output unit (240a), a sensor unit (240b), and a power supply unit (240c). Here, blocks 210 to 230 / 240a to 240c of FIG. 29 correspond to blocks 210 to 230 / 240 of FIG. 25, respectively.

[0315] The communication unit (210) can transmit and receive signals (e.g., media data, control signals, etc.) with external devices such as other wireless devices, portable devices, or media servers. The media data can include videos, images, sounds, etc. The control unit (220) can control components of the XR device (200a) to perform various operations. For example, the control unit (220) can be configured to control and / or perform procedures such as video / image acquisition, (video / image) encoding, metadata generation and processing, etc. The memory unit (230) can store data / parameters / programs / codes / commands required for driving the XR device (200a) / generating XR objects. The input / output unit (240a) can obtain control information, data, etc. from the outside, and output the generated XR object. The input / output unit (240a) can include a camera, a microphone, a user input unit, a display unit, a speaker, and / or a haptic module. The sensor unit (240b) can obtain the XR device status, surrounding environment information, user information, etc. The sensor unit (240b) may include a proximity sensor, an illuminance sensor, an acceleration sensor, a magnetic sensor, a gyro sensor, an inertial sensor, an RGB sensor, an IR sensor, a fingerprint recognition sensor, an ultrasonic sensor, a light sensor, a microphone, and / or a radar. The power supply unit (240c) supplies power to the XR device (200a) and may include a wired / wireless charging circuit, a battery, etc.

[0316] For example, the memory unit (230) of the XR device (200a) may include information (e.g., data, etc.) required for creating an XR object (e.g., AR / VR / MR object). The input / output unit (240a) may obtain a command to operate the XR device (200a) from the user, and the control unit (220) may operate the XR device (200a) according to the user's operating command. For example, when the user attempts to watch a movie, news, etc. through the XR device (200a), the control unit (220) may transmit content request information to another device (e.g., a mobile device (200b)) or a media server through the communication unit (230). The communication unit (230) may download / stream content such as movies and news from another device (e.g., a mobile device (200b)) or a media server to the memory unit (230). The control unit (220) controls and / or performs procedures such as video / image acquisition, (video / image) encoding, and metadata generation / processing for content, and can generate / output an XR object based on information about surrounding space or real objects acquired through the input / output unit (240a) / sensor unit (240b).

[0317] In addition, the XR device (200a) is wirelessly connected to the mobile device (200b) through the communication unit (210), and the operation of the XR device (200a) can be controlled by the mobile device (200b). For example, the mobile device (200b) can act as a controller for the XR device (200a). To this end, the XR device (200a) can obtain 3D location information of the mobile device (200b), and then generate and output an XR object corresponding to the mobile device (200b).

[0318] Figure 30 illustrates examples of robots applicable to the present disclosure. Robots can be classified into industrial, medical, household, and military types, depending on their intended use or field.

[0319] Referring to FIG. 30, the robot (200) may include a communication unit (210), a control unit (220), a memory unit (230), an input / output unit (240a), a sensor unit (240b), and a driving unit (240c). Here, blocks 210 to 230 / 240a to 240c of FIG. 30 correspond to blocks 210 to 230 / 240 of FIG. 25, respectively.

[0320] The communication unit (210) can transmit and receive signals (e.g., driving information, control signals, etc.) with external devices such as other wireless devices, other robots, or control servers. The control unit (220) can control components of the robot (200) to perform various operations. The memory unit (230) can store data / parameters / programs / codes / commands that support various functions of the robot (200). The input / output unit (240a) can obtain information from the outside of the robot (200) and output information to the outside of the robot (200). The input / output unit (240a) can include a camera, a microphone, a user input unit, a display unit, a speaker, and / or a haptic module. The sensor unit (240b) can obtain internal information of the robot (200), surrounding environment information, user information, etc. The sensor unit (240b) may include a proximity sensor, an illuminance sensor, an acceleration sensor, a magnetic sensor, a gyro sensor, an inertial sensor, an IR sensor, a fingerprint recognition sensor, an ultrasonic sensor, a light sensor, a microphone, a radar, etc. The driving unit (240c) may perform various physical operations, such as moving the robot joints. In addition, the driving unit (240c) may enable the robot (200) to drive on the ground or fly in the air. The driving unit (240c) may include an actuator, a motor, wheels, brakes, propellers, etc.

[0321] Figure 31 illustrates an example of an AI device applicable to the present disclosure.

[0322] AI devices can be implemented as fixed or mobile devices, such as TVs, projectors, smartphones, PCs, laptops, digital broadcasting terminals, tablet PCs, wearable devices, set-top boxes (STBs), radios, washing machines, refrigerators, digital signage, robots, and vehicles.

[0323] Referring to FIG. 31, the AI ​​device (200) may include a communication unit (210), a control unit (220), a memory unit (230), an input / output unit (240a / 240b), a learning processor unit (240c), and a sensor unit (240d). Blocks 210 to 230 / 240a to 240d of FIG. 31 correspond to blocks 210 to 230 / 140 of FIG. 25, respectively.

[0324] The communication unit (210) can transmit and receive wired and wireless signals (e.g., sensor information, user input, learning models, control signals, etc.) to and from external devices such as other AI devices (e.g., 100a to 100f, 120 of FIG. 1) or AI servers (e.g., 100g of FIG. 1) using wired and wireless communication technology. To this end, the communication unit (210) can transmit information within the memory unit (230) to the external device or transfer a signal received from the external device to the memory unit (230).

[0325] The control unit (220) may determine at least one executable operation of the AI ​​device (200) based on information determined or generated using a data analysis algorithm or a machine learning algorithm. In addition, the control unit (220) may control components of the AI ​​device (200) to perform the determined operation. For example, the control unit (220) may request, search, receive, or utilize data from the learning processor unit (240c) or the memory unit (230), and may control components of the AI ​​device (200) to perform at least one executable operation, a predicted operation, or an operation determined to be desirable. In addition, the control unit (220) may collect history information including the operation contents of the AI ​​device (200) or user feedback on the operation, and store the collected history information in the memory unit (230) or the learning processor unit (240c), or transmit the collected history information to an external device such as an AI server (FIG. 1, 100g). The collected history information may be used to update a learning model.

[0326] The memory unit (230) can store data that supports various functions of the AI ​​device (200). For example, the memory unit (230) can store data obtained from the input unit (240a), data obtained from the communication unit (210), output data of the learning processor unit (240c), and data obtained from the sensing unit (140). In addition, the memory unit (230) can store control information and / or software codes necessary for the operation / execution of the control unit (220).

[0327] The input unit (240a) can obtain various types of data from the outside of the AI ​​device (200). For example, the input unit (220) can obtain learning data for model learning, input data to which the learning model will be applied, etc. The input unit (240a) may include a camera, a microphone, and / or a user input unit. The output unit (240b) may generate output related to vision, hearing, or touch. The output unit (240b) may include a display unit, a speaker, and / or a haptic module, etc. The sensing unit (140d) can obtain at least one of internal information of the AI ​​device (200), information about the surrounding environment of the AI ​​device (200), and user information using various sensors. The sensing unit (140d) may include a proximity sensor, an illuminance sensor, an acceleration sensor, a magnetic sensor, a gyro sensor, an inertial sensor, an RGB sensor, an IR sensor, a fingerprint recognition sensor, an ultrasonic sensor, a light sensor, a microphone, and / or a radar, etc.

[0328] The learning processor unit (240c) can train a model composed of an artificial neural network using learning data. The learning processor unit (240c) can perform AI processing together with the learning processor unit of the AI ​​server (Fig. 1, 100g). The learning processor unit (240c) can process information received from an external device via the communication unit (210) and / or information stored in the memory unit (230). In addition, the output value of the learning processor unit (240c) can be transmitted to an external device via the communication unit (210) and / or stored in the memory unit (230).

[0329] Figure 32 illustrates an example of a quantum communication device applicable to the present disclosure. The quantum communication device can be applied to various devices and can be operated in combination (or merged) with other non-quantum communication wired and / or wireless communication devices. Information in quantum communication can be a concept encompassing both bit information, the basic unit of classical information, and qubit information, the basic unit of quantum information.

[0330] The channel encoder (250) can encode the classical bits to be transmitted into coded bits. The channel encoder (250) can improve the reliability of the classical bits.

[0331]

[0332] *The quantum encoder (260) converts the encoded bits into a qubit basis (or computation basis). Here, the qubit basis is logical information about a quantum state and can be formed based on a physical quantum basis. For example, in the transmitter and receiver, horizontal polarization and vertical polarization can be promised to correspond to the qubit basis |0〉 and |1〉, respectively, as quantum basis.

[0333] Classical information bits 0 or 1 can be converted into qubit basis |0〉 or |1〉 through a channel encoder (250) and a quantum encoder (260). The qubit basis generated at the transmitter can be transmitted to the receiver through a quantum channel.

[0334] The quantum decoder (270) at the receiving end can perform measurements based on a pre-arranged quantum basis and decode the qubit basis transmitted to the receiving end into coded bits. If multiple qubit basis determines the qubit state, a qubit coded deterministically or probabilistically can be obtained depending on the measured qubit basis.

[0335] The channel decoder (280) decodes the coded bits back into classical bits and can obtain the information bits sent by the transmitter.

[0336] The procedures related to the channel encoder (250) and channel decoder (280) indicated by dotted lines in FIG. 32 may be omitted. If the channel encoder (250) and channel decoder (280) are omitted, the qubit state can be transmitted from the quantum process of the transmitter to the receiver via a quantum channel. The received qubit state can be used by the quantum processor for various purposes. For example, to transmit the qubit state generated in the quantum processor, a quantum direct communication method in which the qubit state is converted into a photon and transmitted may be used, or a method in which quantum teleportation is performed based on an entanglement source shared by the transmitter and receiver in advance may be used. Here, quantum direct communication refers to a communication method in which classical message information to be transmitted is safely shared directly through a quantum channel, and quantum teleportation refers to a communication method in which quantum information itself is shared through a quantum entanglement channel.

[0337]

[0338] The proposed methods described above can be implemented independently, but they can also be implemented as a combination (or merge) of some of the proposed methods. Rules can be defined so that the base station notifies the terminal of the applicability of the proposed methods (or information about the rules of the proposed methods) through a predefined signal (e.g., a physical layer signal or a higher layer signal).

[0339] The present disclosure may be embodied in other specific forms without departing from the technical ideas and essential features described herein. Therefore, the above detailed description should not be construed as limiting in all respects but rather as illustrative. The scope of the present disclosure should be determined by a reasonable interpretation of the appended claims, and all modifications within the equivalent scope of the present disclosure are intended to be included within the scope of the present disclosure. Furthermore, claims that are not explicitly cited in the claims may be combined to form an embodiment or incorporated into a new claim through a post-filing amendment.

[0340] The embodiments described herein may be applied to various wireless access systems. Examples of such wireless access systems include the 3rd Generation Partnership Project (3GPP) or 3GPP2 systems.

[0341] The embodiments described herein can be applied not only to the various wireless access systems described above, but also to all technical fields utilizing these various wireless access systems. Furthermore, the proposed method can be applied to mmWave and THz communication systems utilizing ultra-high frequency bands.

[0342] Additionally, the embodiments can be applied to various applications such as autonomous vehicles and drones.

Claims

In a method performed by a first device in a communication system, A step for performing an initial connection procedure with a base station; A step of establishing a connection with the above base station; A step of transmitting capability information to the base station; A step of establishing a quantum channel with a third device for quantum signature based on quantum entanglement with a second device; A method comprising the step of transmitting request information including at least one qubit message encrypted using a secret symmetric key shared between the first device and the third device to the third device through the quantum channel as information for requesting generation of signature information for the quantum signature. In claim 1, A step of generating four identical qubit messages; A method further comprising the step of generating the request information by encrypting one of the four qubit messages using the secret symmetric key. In claim 1, In addition to the above request information, a method further comprising the step of transmitting unencrypted three-qubit messages to a third device. In a method performed by a second device in a communication system, A step of receiving signature information from a third device that mediates a quantum signature based on quantum entanglement with a first device; A step of storing a first qubit message received together with the above signature information; A step of transmitting quantum information generated based on the signature information and the qubit message to the third device as first transmission information generated based on the signature information; A step of receiving quantum information including the result of the first verification performed based on the first transmission information, as second transmission information generated based on the first transmission information, from the third device; and A method comprising a step of performing secondary verification based on the second transmission information. In claim 4, When using the GHZ (Greenberger-Horne-Zeilinger) state, a step of receiving the third particle of the GHZ state; A method further comprising the step of generating the first transmission information by encrypting the measurement result for the third particle of the GHZ state, the signature information and the qubit message using a secret symmetric key shared between the third device and the second device. In claim 5, The steps for performing the above secondary verification are: A step of confirming verification result information indicating the result of the first verification performed by the third device included in the second transmission information; and A method comprising a step of determining whether the first qubit message and the second qubit message included in the second transmission information match. In claim 4, A method further comprising the step of generating the first transmission information by encrypting the signature information and the qubit message using a secret symmetric key shared between the third device and the second device when utilizing a bell state. In claim 7, The steps for performing the above secondary verification are: A step of confirming verification result information indicating the result of the first verification performed by the third device included in the second transmission information; and A step of receiving a second particle of the above bell state; A method comprising the step of determining whether the first qubit message and the second qubit message obtained based on the second particle of the bell state match. In a method performed by a third device in a communication system, A step of receiving request information and a plurality of qubit messages from the first device, the request information including a qubit message encrypted using a first secret symmetric key shared between the first device and the third device, as information for requesting generation of signature information for quantum signature between the first device and the second device; A step of transmitting, to the second device, signature information generated from the request information and at least one qubit message among the qubit messages using the secret key of the third device and the second secret symmetric key shared between the second device and the third device; A step of receiving first transmission information generated based on the above signature information from the second device; A step of performing primary verification based on the above first transmission information; and A method comprising the step of transmitting second transmission information for secondary verification of the second device, the second transmission information including verification result information indicating the result of the first verification, to the second device. In claim 9, The steps for performing the above first verification are: A step of obtaining a first verification factor by decrypting the signature information included in the first transmission information using the first secret symmetric key; A step of determining a second verification factor by encrypting the request information using the secret key of the arbitrator; A method comprising the step of generating the verification result information indicating whether the first verification factor and the second verification factor match. In claim 9, Step of obtaining the first particle in the GHZ (Greenberger-Horne-Zeilinger) state; A step of determining a first measurement result for a first particle of the above GHZ state; A step of obtaining a second measurement result for the third particle in the GHZ state by decrypting the first transmission information using the second secret symmetric key; A step of obtaining a second qubit message from a second particle in the GHZ state using the first measurement result and the second measurement result; A method further comprising the step of generating the second transmission information including the second qubit message and the verification result information. In claim 9, Step of obtaining the first particle in bell state; A step of determining the measurement result for the first particle of the above bell state; A method further comprising the step of generating the second transmission information including the measurement result and the verification result information. In a first device in a communication system, Transmitter and receiver; and comprising a processor coupled to the above transceiver, The above processor, Perform initial connection procedures with the base station, Establish a connection with the above base station, Transmit capability information to the above base station, Establish a quantum channel with a third device for quantum signature based on quantum entanglement with a second device, A first device configured to transmit request information including at least one qubit message encrypted using a secret symmetric key shared between the first device and the third device to the third device through the quantum channel as information for requesting generation of signature information for the quantum signature. In the second device of the communication system, Transmitter and receiver; and comprising a processor coupled to the above transceiver, The above processor, Receive signature information from a third device that mediates a quantum signature based on quantum entanglement with the first device, Store the first qubit message received together with the above signature information, As first transmission information generated based on the above signature information, quantum information generated based on the above signature information and the above qubit message is transmitted to the third device, As second transmission information generated based on the first transmission information, quantum information including the result of the first verification performed based on the first transmission information is received from the third device, A second device configured to perform secondary verification based on the second transmission information. In a third device in a communication system, Transmitter and receiver; and comprising a processor coupled to the above transceiver, The above processor, As information for requesting the generation of signature information for quantum signature between a first device and a second device, request information including a qubit message encrypted using a first secret symmetric key shared between the first device and the third device and a plurality of qubit messages are received from the first device, Transmitting to the second device, the signature information generated from the request information and at least one qubit message among the qubit messages using the secret key of the third device and the second secret symmetric key shared between the second device and the third device, Receive first transmission information generated based on the above signature information from the second device, Perform primary verification based on the above first transmission information, A third device configured to transmit second transmission information for second verification of the second device, the second transmission information including verification result information indicating the result of the first verification, to the second device. In communication devices, At least one processor; At least one computer memory connected to said at least one processor and storing instructions that direct operations when executed by said at least one processor, The above actions are, A step for performing an initial connection procedure with a base station; A step of establishing a connection with the above base station; A step of transmitting capability information to the base station; A step of establishing a quantum channel with a third device for quantum signature based on quantum entanglement with a second device; A communication device comprising a step of transmitting request information including at least one qubit message encrypted using a secret symmetric key shared between the first device and the third device to the third device through the quantum channel as information for requesting generation of signature information for the quantum signature. In a non-transitory computer-readable medium storing at least one instruction, comprising at least one instruction executable by the processor, At least one of the above commands causes the device to: Perform initial connection procedures with the base station, Establish a connection with the above base station, Transmit capability information to the above base station, Establish a quantum channel with a third device for quantum signature based on quantum entanglement with a second device, A computer-readable medium for instructing the third device to transmit request information including at least one qubit message encrypted using a secret symmetric key shared between the first device and the third device through the quantum channel as information for requesting the generation of signature information for the quantum signature.

Citation Information

Patent Citations

  • Public key encryption apparatus

    JP2006121524A

  • Quantum signature method using arbitrator

    KR1020040077152A

  • Quantum signature method using arbitrator and system using same

    KR1020140060022A

  • Quantum signature apparatus for quantum message

    KR1020160120062A

  • Light emitting device, and display apparatus including the same

    KR1020250029748A