Apparatus and method for performing message recovery-type quantum signature based on arbitrator by using quantum entanglement without using direct connection channel between transmitter and receiver in communication system

The mediator-based quantum signature method using GHZ or Bell states addresses the challenge of direct path absence by facilitating secure quantum information transmission and verification, enhancing communication reliability.

WO2026071275A1PCT designated stage Publication Date: 2026-04-02LG ELECTRONICS INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-24
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing communication systems face challenges in performing quantum signatures when there is no direct path between a sender and a receiver, necessitating innovative methods to facilitate secure message transmission and verification.

Method used

A mediator-based quantum signature method using quantum entanglement, where an arbitrator mediates the process by employing GHZ or Bell states, enabling secure transmission and verification of quantum information without a direct connection between the sender and receiver.

Benefits of technology

Enables effective quantum signature performance in situations without a direct path, ensuring secure and reliable communication through quantum entanglement-based mediation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024014342_02042026_PF_FP_ABST
    Figure KR2024014342_02042026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure is for performing a message recovery-type quantum signature based on an arbitrator by using quantum entanglement without using a direct connection channel between a transmitter and a receiver in a communication system. The method performed by a first device may comprise the steps of: performing an initial access procedure with a base station; establishing a connection with the base station; transmitting capability information to the base station; establishing a quantum channel with a third device for the sake of a quantum signature with a second device; and transmitting signature initiation information, including at least one quantum information element encrypted using a secret symmetric key shared between the first device and the third device, to the third device through the quantum channel as information for requesting the generation of signature information for the quantum signature.
Need to check novelty before this filing date? Find Prior Art

Description

Apparatus and method for performing mediator-based message recovery type quantum signature using quantum entanglement without using a direct connection channel between a sender and a receiver in a communication system

[0001] The present disclosure relates to a communication system and to an apparatus and method for performing a mediator-based message recovery type quantum signature using quantum entanglement without using a direct connection channel between a sender and a receiver in a communication system.

[0002] Wireless access systems are being widely deployed to provide various types of communication services, such as voice and data. Generally, a wireless access system is a multiple access system capable of supporting communication with multiple users by sharing available system resources (bandwidth, transmission power, etc.). Examples of multiple access systems include CDMA (code division multiple access), FDMA (frequency division multiple access), TDMA (time division multiple access), OFDMA (orthogonal frequency division multiple access), and SC-FDMA (single carrier frequency division multiple access) systems.

[0003] In particular, as many communication devices require large communication capacities, enhanced mobile broadband (eMBB) communication technology is being proposed as an improvement over existing radio access technology (RAT). Furthermore, communication systems are being proposed that consider not only massive machine type communications (mmTC), which connects multiple devices and objects to provide various services anytime and anywhere, but also services and user equipment (UE) that are sensitive to reliability and latency. Various technical configurations are being proposed for this purpose.

[0004] The present disclosure relates to an apparatus and method for effectively performing a quantum signature in a communication system.

[0005] The present disclosure relates to an apparatus and method for performing a quantum signature in a situation where there is no direct path between a sender and a receiver in a communication system.

[0006] The present disclosure relates to an apparatus and method for performing a quantum signature using quantum entanglement without using a direct path between a sender and a receiver in a communication system.

[0007] The present disclosure relates to an apparatus and method for performing a quantum signature using an arbitrator without using a direct path in a communication system.

[0008] The present disclosure relates to an apparatus and method for performing a quantum signature scheme with message recovery in a situation where there is no direct path between a sender and a receiver in a communication system.

[0009] The present disclosure relates to an apparatus and method for a sender for a quantum signature in a communication system to transmit qubit messages to an arbitrator to request signature information.

[0010] The present disclosure relates to an apparatus and method for transmitting request information, generated based on a qubit message, to an arbitrator for a quantum signature in a communication system.

[0011] The present disclosure relates to an apparatus and method for a mediator for a quantum signature in a communication system to transmit to a receiver signature information generated based on quantum information received from a sender.

[0012] The present disclosure relates to an apparatus and method for an arbitrator for a quantum signature in a communication system to perform verification using a GHZ (Greenberger-Horne-Zeilinger) state or a bell state particle.

[0013] The present disclosure relates to an apparatus and method for an arbitrator for a quantum signature in a communication system to encrypt and decrypt information for his verification operation using his secret key.

[0014] The technical objectives to be achieved in this disclosure are not limited to those mentioned above, and other unmentioned technical problems may be considered by those skilled in the art to which the technical configuration of this disclosure applies, based on the embodiments of this disclosure described below.

[0015] As an example of the present disclosure, a method performed by a first device in a communication system may include: performing an initial connection procedure with a base station; establishing a connection with the base station; transmitting capability information to the base station; establishing a quantum channel with a third device for a quantum signature based on quantum entanglement with a second device; and transmitting signature initiation information to the third device through the quantum channel, wherein the signature initiation information includes at least one quantum information element encrypted using a secret symmetric key shared between the first device and the third device, as information for requesting the generation of signature information for the quantum signature. The at least one quantum information element included in the signature initiation information may include a first qubit message and a measurement result for a GHZ (Greenberger-Horne-Zeilinger) state or Bell state particle, or at least one second qubit message and at least one third qubit message generated based on the first qubit message.

[0016] As an example of the present disclosure, a method performed by a second device in a communication system may include: receiving signature information from a third device that mediates a quantum signature based on quantum entanglement with a first device; acquiring a particle in a GHZ (Greenberger-Horne-Zeilinger) state or a Bell state; transmitting to the third device quantum information generated based on the signature information and the particle as first transmission information generated based on the signature information; receiving from the third device quantum information including the results of signature verification and message verification performed based on the first transmission information as second transmission information generated based on the first transmission information; acquiring random number information based on the second transmission information; and recovering a first qubit message from a second qubit message included in the second transmission information based on the random number information.

[0017] As an example of the present disclosure, a method performed by a third device in a communication system may include: receiving from the first device signature initiation information, which includes quantum information elements encrypted using a first secret symmetric key shared between the first device and the third device, as information for requesting the generation of signature information for a quantum signature between the first device and the second device; transmitting to the second device signature information generated from one of the quantum information elements based on at least one of the secret key of the third device, a second secret symmetric key shared between the second device and the third device, and random number information; receiving from the second device first transmission information generated based on the signature information; performing signature verification and message verification based on the first transmission information; transmitting to the second device second transmission information, which includes verification result information indicating the results of the signature verification and message verification; and transmitting to the second device the random number information.

[0018] As an example of the present disclosure, a first device in a communication system comprises a transceiver and a processor coupled to the transceiver, wherein the processor performs an initial connection procedure with a base station, establishes a connection with the base station, transmits capability information to the base station, establishes a quantum channel with a third device for a quantum signature based on quantum entanglement with a second device, and is configured to transmit signature initiation information to the third device through the quantum channel, wherein the signature initiation information includes at least one quantum information element encrypted using a secret symmetric key shared between the first device and the third device, and wherein the at least one quantum information element included in the signature initiation information may include a first qubit message and a measurement result for a GHZ state or Bell state particle, or at least one second qubit message and at least one third qubit message generated based on the first qubit message.

[0019] As an example of the present disclosure, a second device in a communication system comprises a transceiver and a processor coupled to the transceiver, wherein the processor may be configured to receive signature information from a third device that mediates a quantum signature based on quantum entanglement with a first device, acquire a particle in a GHZ (Greenberger-Horne-Zeilinger) state or a Bell state, transmit to the third device quantum information generated based on the signature information and the particle as first transmission information generated based on the signature information, receive from the third device quantum information including the results of signature verification and message verification performed based on the first transmission information as second transmission information generated based on the first transmission information, acquire random number information based on the second transmission information, and recover a first qubit message from a second qubit message included in the second transmission information based on the random number information.

[0020] As an example of the present disclosure, a third device in a communication system comprises a transceiver and a processor coupled to the transceiver, wherein the processor may be configured to receive from the first device signature initiation information, which includes quantum information elements encrypted using a first secret symmetric key shared between the first device and the third device, as information for requesting the generation of signature information for a quantum signature between the first device and the second device, transmit to the second device signature information generated from one of the quantum information elements based on at least one of the secret key of the third device, a second secret symmetric key shared between the second device and the third device, and random number information, receive from the second device first transmission information generated based on the signature information, perform signature verification and message verification based on the first transmission information, transmit to the second device second transmission information including verification result information indicating the results of the signature verification and message verification, and transmit the random number information to the second device.

[0021] As an example of the present disclosure, a communication device comprises at least one processor and at least one computer memory connected to the at least one processor and storing instructions that direct operations as executed by the at least one processor, wherein the operations may include: performing an initial connection procedure with a base station; establishing a connection with the base station; transmitting capability information to the base station; establishing a quantum channel with a third device for a quantum signature based on quantum entanglement with a second device; and transmitting signature initiation information to the third device through the quantum channel, wherein the signature initiation information includes at least one quantum information element encrypted using a secret symmetric key shared between the first device and the third device as information for requesting the generation of signature information for the quantum signature. The at least one quantum information element included in the signature initiation information may include a first qubit message and a measurement result for a particle in a GHZ state or Bell state, or at least one second qubit message and at least one third qubit message generated based on the first qubit message.

[0022] As an example of the present disclosure, a non-transitory computer-readable medium storing at least one instruction comprises said at least one instruction executable by a processor, said at least one instruction there is.

[0023] The embodiments of the present disclosure described above are merely some of the preferred embodiments of the present disclosure, and various embodiments reflecting the technical features of the present disclosure can be derived and understood by those skilled in the art based on the detailed description of the present disclosure set forth below.

[0024] The following effects may be achieved by embodiments based on the present disclosure.

[0025] According to the present disclosure, a quantum signature can be effectively performed in a situation where there is no direct path between a sender and a receiver.

[0026] The effects obtainable from the embodiments of the present disclosure are not limited to those mentioned above, and other unmentioned effects can be clearly derived and understood by a person skilled in the art to which the technical configuration of the present disclosure applies from the description of the embodiments of the present disclosure below. That is, unintended effects resulting from implementing the configuration described in the present disclosure can also be derived by a person skilled in the art from the embodiments of the present disclosure.

[0027] The drawings attached below are intended to aid in understanding the present disclosure and may provide embodiments of the present disclosure together with the detailed description. However, the technical features of the present disclosure are not limited to specific drawings, and features disclosed in each drawing may be combined with one another to form new embodiments. Reference numerals in each drawing may denote structural elements.

[0028] FIG. 1 illustrates an example of a communication system applicable to the present disclosure.

[0029] FIG. 2 illustrates an example of a wireless device applicable to the present disclosure.

[0030] FIG. 3 illustrates a method for processing a transmission signal applicable to the present disclosure.

[0031] FIG. 4 illustrates a communication procedure between a terminal and a base station applicable to the present disclosure.

[0032] FIG. 5 illustrates an example of a communication structure that can be provided in a 6G (6th generation) system applicable to the present disclosure.

[0033] FIG. 6 illustrates an electromagnetic spectrum applicable to the present disclosure.

[0034] FIG. 7 illustrates a transmitter structure applicable to the present disclosure.

[0035] FIG. 8 illustrates an example of a functional framework for the application of artificial intelligence technology applicable to the present disclosure.

[0036] FIG. 9 illustrates an example of a procedure for utilizing an artificial intelligence model applicable to the present disclosure.

[0037] FIG. 10 illustrates a communication procedure based on artificial intelligence (AI) technology applicable to the present disclosure.

[0038] Figure 11 illustrates the concept of an electronic signature technique based on direct signature.

[0039] Figure 12 illustrates the concept of a mediator-based electronic signature technique.

[0040] Figure 13 illustrates the concept of a mediator-based quantum signature technique using the GHZ (Greenberger-Horne-Zeilinger) state.

[0041] Figure 14 illustrates the concept of a mediator-based quantum signature technique using a bell state.

[0042] Figure 15 illustrates the concept of a mediator-based quantum signature technique using a single photon.

[0043] FIG. 16a illustrates an initial step of a method for distributing GHZ state particles only between a mediator and a receiver, as a mediator-based message recovery quantum signature method using a GHZ state according to one embodiment of the present disclosure.

[0044] FIGS. 16b and 16c illustrate a quantum signature generation step in which GHZ state particles are distributed only between a mediator and a receiver, as a mediator-based message recovery type quantum signature technique using a GHZ state according to one embodiment of the present disclosure.

[0045] FIG. 16d illustrates a quantum signature verification and message recovery method using a GHZ state mediator-based message recovery quantum signature technique according to one embodiment of the present disclosure, wherein GHZ state particles are distributed only between a mediator and a receiver.

[0046] FIGS. 17a to 17c illustrate examples of operations of a sender, a receiver, and an arbitrator according to a quantum signature technique that uses a GHZ state and distributes GHZ state particles only between the arbitrator and the receiver, as an arbitrator-based message recovery type quantum signature technique according to one embodiment of the present disclosure.

[0047] FIG. 18a illustrates an initial step of a method for distributing GHZ state particles between a mediator, a sender, and a receiver, as a mediator-based message recovery type quantum signature technique using a GHZ state according to one embodiment of the present disclosure.

[0048] FIGS. 18b and 18c illustrate a quantum signature generation step in a manner that distributes GHZ state particles between a mediator, a sender, and a receiver, as a mediator-based message recovery type quantum signature technique using a GHZ state according to one embodiment of the present disclosure.

[0049] FIG. 18d illustrates a quantum signature verification and message recovery method using a GHZ state mediator-based message recovery quantum signature technique according to one embodiment of the present disclosure, which distributes GHZ state particles between a mediator, a sender, and a receiver.

[0050] FIGS. 19a to 19c illustrate examples of operations of a sender, a receiver, and an arbitrator according to a quantum signature technique that uses a GHZ state and distributes GHZ state particles between an arbitrator, a sender, and a receiver, as an arbitrator-based message recovery type quantum signature technique according to one embodiment of the present disclosure.

[0051] FIG. 20a illustrates an initial step of a method for distributing state particles between a mediator and a receiver, as a mediator-based message recovery type quantum signature technique using a Bell state according to one embodiment of the present disclosure.

[0052] FIGS. 20b and FIGS. 20c illustrate a quantum signature generation step in a manner that distributes state particles between a mediator and a receiver, as a mediator-based message recovery type quantum signature technique using a Bell state according to one embodiment of the present disclosure.

[0053] FIG. 20d illustrates a quantum signature verification and message recovery method using a Bell state mediator-based message recovery quantum signature technique according to one embodiment of the present disclosure, which distributes state particles between a mediator and a receiver.

[0054] FIGS. 21a to 21c illustrate examples of operations of a sender, a receiver, and an arbitrator according to a quantum signature technique that uses a Bell state to recover messages, according to an embodiment of the present disclosure, and a method of distributing state particles between an arbitrator and a receiver.

[0055] FIG. 22a illustrates an initial step of a method for distributing Bell state particles between a sender and a receiver, as a mediator-based message recovery type quantum signature technique using a Bell state according to one embodiment of the present disclosure.

[0056] FIGS. 22b and FIGS. 22c illustrate a quantum signature generation step in a method of distributing Bell state particles between a sender and a receiver, as a mediator-based message recovery type quantum signature technique using a Bell state according to one embodiment of the present disclosure.

[0057] FIG. 22d illustrates a quantum signature verification and message recovery method using a Bell state mediator-based message recovery quantum signature technique according to one embodiment of the present disclosure, which distributes Bell state particles between a sender and a receiver.

[0058] FIGS. 23a to 23c illustrate examples of operations of a sender, a receiver, and an arbitrator according to a quantum signature technique that uses a Bell state to recover messages, according to an embodiment of the present disclosure, and a method of distributing state particles between a sender and a receiver.

[0059] FIG. 24 illustrates an example of a procedure in which a sender requests the generation of signature information according to an arbitrator-based message recovery type quantum signature technique according to one embodiment of the present disclosure.

[0060] FIG. 25 illustrates an example of a procedure in which a mediator performs a quantum signature according to a mediator-based message recovery type quantum signature technique according to one embodiment of the present disclosure.

[0061] FIG. 26 illustrates an example of a procedure in which a recipient proceeds with a signature according to an arbitrator-based message recovery type quantum signature technique according to one embodiment of the present disclosure.

[0062] FIG. 27 illustrates an example of a quantum key distribution (QKD) technology to which a quantum signature technique according to one embodiment of the present disclosure is applied.

[0063] FIG. 28 illustrates an example of quantum secure direct communication (QSDC) to which a quantum signature technique according to one embodiment of the present disclosure is applied.

[0064] FIG. 29 illustrates an example of a wireless device applicable to the present disclosure.

[0065] FIG. 30 illustrates an example of a portable device applicable to the present disclosure.

[0066] FIG. 31 illustrates an example of a vehicle or autonomous vehicle applicable to the present disclosure.

[0067] FIG. 32 illustrates an example of a vehicle applicable to the present disclosure.

[0068] FIG. 33 illustrates an example of an extended reality (XR) device applicable to the present disclosure.

[0069] FIG. 34 illustrates an example of a robot applicable to the present disclosure.

[0070] FIG. 35 illustrates an example of an AI device applicable to the present disclosure.

[0071] FIG. 36 illustrates an example of a quantum communication device applicable to the present disclosure.

[0072] The following embodiments are combinations of the components and features of the present disclosure in a predetermined form. Each component or feature may be considered optional unless otherwise explicitly stated. Each component or feature may be implemented in a form not combined with other components or features. Additionally, some components and / or features may be combined to form embodiments of the present disclosure. The order of operations described in the embodiments of the present disclosure may be changed. Some components or features of any embodiment may be included in other embodiments, or may be replaced with corresponding components or features of other embodiments.

[0073] In the description of the drawings, procedures or steps that could obscure the gist of the present disclosure have not been described, nor have procedures or steps that are understandable to those skilled in the art been described.

[0074] Throughout the specification, when a part is described as "comprising" or "including" a component, this means that, unless specifically stated otherwise, it does not exclude other components but may include additional components. Furthermore, terms such as "...part," "...unit," and "module" as used in the specification refer to a unit that performs at least one function or operation, and this may be implemented in hardware, software, or a combination of hardware and software. Additionally, "one (a or an)," "one," "the," and similar related terms may be used in the context describing the present disclosure (particularly in the context of the following claims) in both singular and plural forms, unless otherwise indicated in the specification or clearly contradicted by the context.

[0075] In this specification, the embodiments of the present disclosure are described with a focus on the data transmission and reception relationship between a base station and a mobile station. Here, the base station refers to a terminal node of a network that communicates directly with a mobile station. Specific operations described in this document as being performed by a base station may, in some cases, be performed by an upper node of the base station.

[0076] That is, in a network consisting of multiple network nodes including a base station, various operations performed for communication with a mobile station may be performed by the base station or other network nodes other than the base station. In this case, 'base station' may be replaced by terms such as fixed station, Node B, eNB (eNode B), gNB (gNode B), ng-eNB, advanced base station (ABS), or access point.

[0077] Additionally, in embodiments of the present disclosure, the term terminal may be replaced with terms such as user equipment (UE), mobile station (MS), subscriber station (SS), mobile subscriber station (MSS), mobile terminal, or advanced mobile station (AMS).

[0078] Furthermore, the transmitting end refers to a fixed and / or mobile node that provides data or voice services, and the receiving end refers to a fixed and / or mobile node that receives data or voice services. Therefore, in the case of the uplink, a mobile station can be the transmitting end and a base station can be the receiving end. Similarly, in the case of the downlink, a mobile station can be the receiving end and a base station can be the transmitting end.

[0079] Embodiments of the present disclosure may be supported by standard documents disclosed in at least one of the wireless access systems, such as IEEE 802.xx systems, 3GPP (3rd Generation Partnership Project) systems, 3GPP LTE (Long Term Evolution) systems, 3GPP 5G (5th generation) NR (New Radio) systems and 3GPP2 systems, and in particular, embodiments of the present disclosure may be supported by 3GPP TS (technical specification) 38.211, 3GPP TS 38.212, 3GPP TS 38.213, 3GPP TS 38.321 and 3GPP TS 38.331 documents.

[0080] In addition, the embodiments of the present disclosure may be applied to other wireless access systems and are not limited to the systems described above. For example, they may be applicable to systems applied after the 3GPP 5G NR system and are not limited to specific systems.

[0081] That is, obvious steps or parts not described in the embodiments of the present disclosure may be described by referring to the aforementioned documents. Additionally, all terms disclosed in this document may be explained by the aforementioned standard documents.

[0082] Hereinafter, preferred embodiments according to the present disclosure will be described in detail with reference to the accompanying drawings. The detailed description disclosed below, together with the accompanying drawings, is intended to describe exemplary embodiments of the present disclosure and is not intended to represent the only embodiment in which the technical configuration of the present disclosure can be implemented.

[0083] Additionally, specific terms used in the embodiments of the present disclosure are provided to aid in understanding the present disclosure, and the use of such specific terms may be modified in other forms without departing from the technical spirit of the present disclosure.

[0084] The following technology can be applied to various wireless access systems such as CDMA (code division multiple access), FDMA (frequency division multiple access), TDMA (time division multiple access), OFDMA (orthogonal frequency division multiple access), and SC-FDMA (single carrier frequency division multiple access).

[0085]

[0086] For the sake of clarity, the following description is based on 3GPP communication systems (e.g., LTE, NR, etc.), but the technical scope of this disclosure is not limited thereto. LTE may refer to technology from 3GPP TS 36.xxx Release 8 onwards. Specifically, LTE technology from 3GPP TS 36.xxx Release 10 onwards is referred to as LTE-A, and LTE technology from 3GPP TS 36.xxx Release 13 onwards may be referred to as LTE-A pro. 3GPP NR may refer to technology from TS 38.xxx Release 15 onwards. 3GPP 6G may refer to technology from TS Release 17 and / or Release 18 onwards. "xxx" indicates a specific standard document number. LTE / NR / 6G may be collectively referred to as 3GPP systems.

[0087] Regarding the background technology, terms, abbreviations, etc. used in this disclosure, reference may be made to standard documents published prior to this disclosure. For example, reference may be made to standard documents 36.xxx and 38.xxx.

[0088]

[0089] Communication systems applicable to the present disclosure

[0090] Although not limited thereto, the various descriptions, functions, procedures, proposals, methods, and / or flowcharts of the disclosure disclosed in this document may be applied to various fields requiring wireless communication / connection (e.g., 5G) between devices.

[0091] Examples are provided in more detail below with reference to the drawings. In the following drawings and descriptions, the same reference numerals may represent the same or corresponding hardware blocks, software blocks, or function blocks unless otherwise described.

[0092] FIG. 1 illustrates an example of a communication system to which the present disclosure applies.

[0093] Referring to FIG. 1, the communication system (100) to which the present disclosure applies includes a wireless device, a base station, and a network. Here, the wireless device refers to a device that performs communication using wireless access technology (e.g., LTE, LTE-A, LTE-A pro, NR, 5G, 5G-A, 6G) and may be referred to as a communication / wireless / 5G device. Although not limited thereto, the wireless device may include a robot (100a), a vehicle (100b-1, 100b-2), an XR (extended reality) device (100c), a hand-held device (100d), a home appliance (100e), an IoT (Internet of Thing) device (100f), and an AI (artificial intelligence) device / server (100g). For example, the vehicle may include a vehicle equipped with wireless communication capabilities, an autonomous vehicle, a vehicle capable of performing inter-vehicle communication, etc. Here, the vehicle (100b-1, 100b-2) may include an unmanned aerial vehicle (UAV) (e.g., a drone). The XR device (100c) includes an augmented reality (AR) / virtual reality (VR) / mixed reality (MR) device and may be implemented in the form of a head-mounted device (HMD), a head-up display (HUD) equipped in a vehicle, a television, a smartphone, a computer, a wearable device, a home appliance, digital signage, a vehicle, a robot, etc. The portable device (100d) may include a smartphone, a smartpad, a wearable device (e.g., a smartwatch, smart glasses), a computer (e.g., a laptop, etc.). The home appliance (100e) may include a TV, a refrigerator, a washing machine, etc. The IoT device (100f) may include a sensor, a smart meter, etc.For example, the base station (120) and network (130) may also be implemented as wireless devices, and a specific wireless device (120a) may act as a base station / network node to other wireless devices.

[0094] Wireless devices (100a to 100f) can be connected to a network (130) through a base station (120). AI technology may be applied to the wireless devices (100a to 100f), and the wireless devices (100a to 100f) can be connected to an AI server (100g) through the network (130). The network (130) can be configured using a 3G network, a 4G (e.g., LTE) network, a 5G (e.g., NR) network, or a 6G network. The wireless devices (100a to 100f) may communicate with each other through the base station (120) / network (130), but may also communicate directly (e.g., sidelink communication) without going through the base station (120) / network (130). For example, vehicles (100b-1, 100b-2) can communicate directly (e.g., V2V (vehicle to vehicle) / V2X (vehicle to everything) communication). Also, an IoT device (100f) (e.g., a sensor) can communicate directly with another IoT device (e.g., a sensor) or other wireless devices (100a to 100f).

[0095] Wireless communication / connection (150a, 150b, 150c) can be established between wireless devices (100a to 100f) / base station (120) and between base station (120) / base station (120). Here, wireless communication / connection can be established through various wireless access technologies such as uplink / downlink communication (150a), sidelink communication (150b) (or D2D communication), and communication between base stations (150c) (e.g., relay, IAB (integrated access backhaul)). Through wireless communication / connection (150a, 150b, 150c), wireless devices and base stations / wireless devices, and base stations and base stations can transmit / receive wireless signals to / from each other. For example, wireless communication / connection (150a, 150b, 150c) can transmit / receive signals through various physical channels. To this end, based on the various proposals of the present disclosure, at least some of the following may be performed: a process for setting various configuration information for transmitting / receiving wireless signals, a process for various signal processing (e.g., channel encoding / decoding, modulation / demodulation, resource mapping / demapping, etc.), a resource allocation process, etc.

[0096]

[0097] Devices applicable to the present disclosure

[0098] FIG. 2 illustrates an example of a wireless device that can be applied to the present disclosure.

[0099] Referring to FIG. 2, the wireless device (200) can transmit and receive wireless signals through various wireless access technologies (e.g., LTE, LTE-A, LTE-A pro, NR, 5G, 5G-A, 6G). The wireless device (200) includes at least one processor (202) and at least one memory (204), and may additionally include at least one transceiver (206) and / or at least one antenna (208).

[0100] The processor (202) controls the memory (204) and / or the transceiver (206) and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or sequences of operation disclosed in this document. For example, the processor (202) may process information within the memory (204) to generate a first information / signal and then transmit a wireless signal containing the first information / signal through the transceiver (206). Additionally, the processor (202) may receive a wireless signal containing a second information / signal through the transceiver (206) and then store information obtained from the signal processing of the second information / signal in the memory (204). The memory (204) may be connected to the processor (202) and may store various information related to the operation of the processor (202). For example, memory (204) may store software code containing instructions for performing some or all of the processes controlled by the processor (202) or for performing the descriptions, functions, procedures, proposals, methods, and / or sequences of operations disclosed in this document. Here, the processor (202) and memory (204) may be part of a communication modem / circuit / chip designed to implement wireless communication technology. A transceiver (206) may be connected to the processor (202) and may transmit and / or receive wireless signals through at least one antenna (208). The transceiver (206) may include a transmitter and / or receiver. The transceiver (206) may be interchangeable with a radio frequency (RF) unit. In this disclosure, a wireless device may mean a communication modem / circuit / chip.

[0101] Hereinafter, hardware elements of the wireless device (200) will be described in more detail. Although not limited thereto, at least one protocol layer may be implemented by at least one processor (202). For example, at least one processor (202) may implement at least one layer (e.g., functional layers such as PHY (physical), MAC (media access control), RLC (radio link control), PDCP (packet data convergence protocol), RRC (radio resource control), and SDAP (service data adaptation protocol). At least one processor (202) may generate at least one PDU (Protocol Data Unit) and / or at least one SDU (service data unit) according to the descriptions, functions, procedures, proposals, methods and / or operation sequences disclosed in this document. At least one processor (202) may generate messages, control information, data, or information according to the descriptions, functions, procedures, proposals, methods and / or operation sequences disclosed in this document. At least one processor (202) may generate a signal (e.g., baseband signal) including a PDU, SDU, message, control information, data, or information according to the functions, procedures, proposals, and / or methods disclosed in this document and provide it to at least one transceiver (206). At least one processor (202) may receive a signal (e.g., baseband signal) from at least one transceiver (206) and may obtain a PDU, SDU, message, control information, data, or information according to the descriptions, functions, procedures, proposals, methods, and / or operation sequences disclosed in this document.

[0102] At least one processor (202) may be referred to as a controller, microcontroller, microprocessor, or microcomputer. At least one processor (202) may be implemented by hardware, firmware, software, or a combination thereof. For example, at least one application-specific integrated circuit (ASIC), at least one digital signal processor (DSP), at least one digital signal processing device (DSPD), at least one programmable logic device (PLD), or at least one field programmable gate array (FPGA) may be included in at least one processor (202). The descriptions, functions, procedures, proposals, methods, and / or operation sequences disclosed in this document may be implemented using firmware or software, and the firmware or software may be implemented to include modules, procedures, functions, etc. Firmware or software configured to perform the descriptions, functions, procedures, proposals, methods, and / or operation sequences disclosed in this document may be included in at least one processor (202) or stored in at least one memory (204) and driven by at least one processor (202). The descriptions, functions, procedures, proposals, methods, and / or flowcharts disclosed in this document may be implemented using firmware or software in the form of code, instructions, and / or sets of instructions.

[0103] At least one memory (204) may be connected to at least one processor (202) and may store various forms of data, signals, messages, information, programs, codes, instructions, and / or commands. At least one memory (204) may be composed of ROM (read-only memory), RAM (random access memory), EPROM (erasable programmable read-only memory), flash memory, hard drive, registers, cache memory, computer read storage media, and / or combinations thereof. At least one memory (204) may be located inside and / or outside of at least one processor (202). Additionally, at least one memory (204) may be connected to at least one processor (202) via various technologies, such as wired or wireless connections.

[0104] At least one transceiver (206) may transmit user data, control information, wireless signals / channels, etc., as mentioned in the methods and / or operation flowcharts, etc. of this document to at least one other device. At least one transceiver (206) may receive user data, control information, wireless signals / channels, etc., as mentioned in the descriptions, functions, procedures, proposals, methods and / or operation flowcharts, etc. disclosed in this document from at least one other device. For example, at least one transceiver (206) may be connected to at least one processor (202) and may transmit and receive wireless signals. For example, at least one processor (202) may control at least one transceiver (206) to transmit user data, control information, or wireless signals to at least one other device. Additionally, at least one processor (202) may control at least one transceiver (206) to receive user data, control information, or wireless signals from at least one other device. Additionally, at least one transceiver (206) may be connected to at least one antenna (208), and at least one transceiver (206) may be configured to transmit and receive user data, control information, wireless signals / channels, etc., as described in the descriptions, functions, procedures, proposals, methods, and / or operation sequence diagrams disclosed in this document through at least one antenna (208). In this document, at least one antenna may be a plurality of physical antennas or a plurality of logical antennas (e.g., antenna ports). At least one transceiver (206) may convert the received wireless signals / channels, etc., from RF band signals to baseband signals in order to process the received user data, control information, wireless signals / channels, etc., using at least one processor (202). At least one transceiver (206) may convert the processed user data, control information, wireless signals / channels, etc., from baseband signals to RF band signals using at least one processor (202).To this end, at least one transceiver (206) may include an (analog) oscillator and / or filter.

[0105] The components of the wireless device described with reference to FIG. 2 may be referred to by other terms in terms of their function. For example, the processor (202) may be referred to as the control unit, the transceiver (206) as the communication unit, and the memory (204) as the storage unit. In some cases, the communication unit may be used to mean at least a part of the processor (202) and the transceiver (206).

[0106] The structure of the wireless device described with reference to FIG. 2 can be understood as the structure of at least part of various devices. For example, the structure of the wireless device exemplified in FIG. 2 may be at least part of the various devices described with reference to FIG. 1 (e.g., robot (100a), vehicle (100b-1, 100b-2), XR device (100c), portable device (100d), home appliance (100e), IoT device (100f), AI device / server (100g)). Furthermore, according to various embodiments, the device may include other components in addition to the components exemplified in FIG. 2.

[0107] For example, the device may be a portable device such as a smartphone, smartpad, wearable device (e.g., smart watch, smart glasses), or portable computer (e.g., laptop, etc.). In this case, the device may further include at least one of a power supply unit that supplies power and includes a wired / wireless charging circuit, a battery, etc., an interface unit that includes at least one port for connection with another device (e.g., audio input / output port, video input / output port), and an input / output unit for inputting and outputting video information / signals, audio information / signals, data, and / or information input by a user.

[0108] For example, the device may be a mobile device such as a mobile robot, vehicle, train, manned / unmanned aerial vehicle (AV), or ship. In this case, the device may further include at least one of a drive unit comprising at least one of an engine, motor, power train, wheel, brake, and steering device of the device; a power supply unit that supplies power and includes a wired / wireless charging circuit, battery, etc.; a sensor unit that senses state information, environmental information, and user information of the device or its surroundings; an autonomous driving unit that performs functions such as path maintenance, speed control, and destination setting; and a position measurement unit that acquires position information of the moving body through a GPS (global positioning system) and various sensors.

[0109] For example, the device may be an XR device such as an HMD, a HUD (head-up display) equipped in a vehicle, a television, a smartphone, a computer, a wearable device, a home appliance, digital signage, a vehicle, a robot, etc. In this case, the device may further include at least one of a power supply unit that supplies power and includes a wired / wireless charging circuit, a battery, etc., an input / output unit that acquires control information, data, etc. from the outside and outputs a generated XR object, and a sensor unit that senses state information, environment information, and user information of the device or the surroundings of the device.

[0110] For example, the device may be a robot that can be classified into industrial, medical, household, military, etc., depending on the purpose or field of use. In this case, the device may further include at least one of a sensor unit that senses state information, environmental information, and user information of the device or its surroundings, and a drive unit that performs various physical actions, such as moving robot joints.

[0111] For example, the device may be an AI device such as a TV, projector, smartphone, PC, laptop, digital broadcasting terminal, tablet PC, wearable device, set-top box (STB), radio, washing machine, refrigerator, digital signage, robot, vehicle, etc. In this case, the device may further include at least one of an input unit that acquires various types of data from the outside, an output unit that generates output related to sight, hearing, or touch, a sensor unit that senses state information, environmental information, and user information of the device or its surroundings, and a training unit that learns a model composed of an artificial neural network using training data.

[0112] The structure of the wireless device illustrated in FIG. 2 can be understood as part of a RAN node (e.g., base station, DU, RU, RRH, etc.). That is, the device illustrated in FIG. 2 may be a RAN node. In this case, the device may further include a wired transceiver for front haul and / or back haul communication. However, if the front haul and / or back haul communication is based on wireless communication, at least one transceiver (206) illustrated in FIG. 2 is used for front haul and / or back haul communication, and the wired transceiver may not be included.

[0113]

[0114] FIG. 3 illustrates a method for processing a transmission signal applicable to the present disclosure. For example, the transmission signal may be processed by a signal processing circuit. In this case, the signal processing circuit (300) may include scramblers (310), modulators (320), a layer mapper (330), a precoder (340), resource mappers (350), and signal generators (360). In this case, for example, the operation / function of FIG. 3 may be performed in the processor (202) and / or transceiver (206) of FIG. 2. Also, for example, the hardware elements of FIG. 3 may be implemented in the processor (202) and / or transceiver (206) of FIG. 2. For example, blocks 310 to 360 may be implemented in the processor (202) of FIG. 2. Additionally, blocks 310 to 350 may be implemented in the processor (202) of FIG. 2, and block 360 may be implemented in the transceiver (206) of FIG. 2, and are not limited to the embodiments described above.

[0115] A codeword can be converted into a wireless signal through the signal processing circuit (300) of FIG. 3. Here, the codeword is an encoded bit sequence of an information block. The information block may include a transmission block (e.g., UL-SCH transmission block, DL-SCH transmission block). Here, the information block may include AI-related data (e.g., training data, AI model data, input data, output data, etc.), and the codeword may be an encoded bit sequence corresponding to the AI-related data. The wireless signal may be transmitted through various physical channels (e.g., PUSCH, PDSCH). Specifically, the codeword may be converted into a scrambled bit sequence by scramblers (310). The scrambled sequence used for scrambling is generated based on an initialization value, which may include ID information of the wireless device, etc. The scrambled bit sequence may be modulated into a modulation symbol sequence by modulators (320). Modulation methods may include pi / 2-BPSK (pi / 2-binary phase shift keying), m-PSK (m-phase shift keying), m-QAM (m-quadrature amplitude modulation), etc.

[0116] A complex modulation symbol sequence can be mapped to at least one transmission layer by a layer mapper (330). Here, a transmission layer is a logical resource unit for mapping signals or data transmitted through spatial resources to antenna ports, and one transmission layer can correspond to one stream or one antenna port. Each complex modulation symbol included in the complex modulation symbol sequence is mapped to at least one transmission layer, thereby determining which antenna port it will be transmitted through. The modulation symbols of each transmission layer can be mapped to the corresponding antenna port(s) by a precoder (340). The output z of the precoder (340) can be obtained by multiplying the output y of the layer mapper (330) by an N-XM precoding matrix W, where N is the number of antenna ports and M is the number of transmission layers. Here, the precoder (340) can perform precoding after performing transform precoding (e.g., a discrete Fourier transform (DFT)) on the complex modulation symbols. Additionally, the precoder (340) can perform precoding without performing transform precoding.

[0117] Resource mappers (350) can map the modulation symbols of each antenna port to time-frequency resources. The time-frequency resources may include multiple symbols (e.g., CP-OFDMA symbols, DFT-s-OFDMA symbols) in the time domain and multiple subcarriers in the frequency domain. Signal generators (360) generate radio signals from the mapped modulation symbols, and the generated radio signals can be transmitted to other devices through each antenna. To this end, each of the signal generators (360) may include an inverse fast Fourier transform (IFFT) module, a cyclic prefix (CP) inserter, a digital-to-analog converter (DAC), a frequency uplink converter, etc.

[0118] The signal processing process for a received signal in a wireless device can be configured as the inverse of the signal processing process (310 to 360) of FIG. 3. For example, a wireless device (e.g., 200 in FIG. 2) can receive a wireless signal from the outside through an antenna port / transceiver. The received wireless signal can be converted into a baseband signal through a signal restorer. To this end, the signal restorer may include a frequency downlink converter, an analog-to-digital converter (ADC), a CP remover, and a fast Fourier transform (FFT) module. Subsequently, the baseband signal can be restored into a codeword through a resource de-mapper process, a postcoding process, a demodulation process, and a de-scrambling process. The codeword can be restored into the original information block through decoding. Accordingly, a signal processing circuit (not shown) for a received signal may include a signal restorer, a resource de-mapper, a postcoder, a demodulator, a de-scrambler, and a decoder.

[0119] The signal processing circuit (300) described with reference to FIG. 3 is illustrated as including a plurality of scramblers (310), modulators (320), a plurality of resource mappers (350), and a plurality of signal generators (360). However, at least one of the scramblers, modulators, resource mappers, and signal generators may be implemented as a single integrated structure. That is, the number of at least one of the scramblers, modulators, resource mappers, and signal generators may be less than the number of layers. Furthermore, at least one of the components illustrated in FIG. 3 may be omitted.

[0120]

[0121] FIG. 4 illustrates a communication procedure between a terminal and a base station applicable to the present disclosure. FIG. 4 illustrates the operation of a terminal (410) and a base station (420) transmitting and / or receiving data, and the operation performed prior to this.

[0122] Referring to FIG. 4, in step 401, the terminal (410) and the base station (420) perform synchronization. For example, the terminal (410) performs an initial cell search operation. Specifically, the terminal (410) can detect at least one synchronization signal transmitted from the base station (420) according to a predefined rule. Here, the synchronization signal may include a plurality of synchronization signals (e.g., primary synchronization signal, secondary synchronization signal) classified according to structure or use. Through this, the terminal (410) can identify the boundaries of the frame, subframe, slot, and / or symbol of the base station (420) and obtain information about the base station (420) (e.g., cell identifier).

[0123] In step 403, the terminal (410) obtains system information transmitted from the base station (420). The system information is information related to the attributes, characteristics, and / or capabilities of the base station (420) required to connect to the base station (420) and use the service, and can be classified according to content (e.g., whether it is essential for connection), transmission structure (e.g., channel used, whether it is provided on-demand), etc., and can be classified, for example, into a master information block (MIB) and a system information block (SIB). If necessary, the terminal (410) may transmit a signal requesting the system information prior to receiving the system information. The system information may include information related to AI functions. For example, the system information is information required for operations performed based on AI, and may include at least one of information related to an AI model, information related to training, and information related to inference / prediction. However, the request and provision of the system information may be performed after the random access procedure described later.

[0124] In step 405, the terminal (410) and the base station (420) perform a random access procedure. The terminal (410) may transmit and / or receive at least one message for the random access procedure (e.g., random access preamble, RAR (random access response) message, etc.) based on information related to the random access channel of the base station (420) obtained through system information (e.g., channel location, channel structure, structure of supported preamble, etc.). For example, the terminal (410) may transmit a preamble (e.g., MSG1) through the random access channel, receive a RAR message (e.g., MSG2), transmit a message (e.g., MSG3) containing information related to the terminal (410) (e.g., identification information) to the base station (420) using scheduling information included in the RAR message, and receive a message (e.g., MSG4) for contention resolution and / or connection establishment. As another example, MSG1 and MSG3 can be transmitted and received as a single message, or MSG2 and MSG4 can be transmitted and received as a single message.

[0125] In step 407, the terminal (410) and the base station (420) perform signaling of control information. Here, the control information may be defined in various layers, such as a layer that controls the connection (e.g., a radio resource control (RRC) layer), a layer that handles mapping between logical channels and transmission channels (e.g., a media access control (MAC) layer), and a layer that handles physical channels (e.g., a physical (PHY) layer). For example, the terminal (410) and the base station (420) may perform at least one of signaling to establish a connection, signaling to determine settings related to communication, and signaling to indicate allocated resources. Additionally, the signaling of control information may be performed to convey information related to AI functions. For example, information related to AI functions is information necessary for operations performed based on AI, and may include at least one of information related to an AI model, information related to training, and information related to inference / prediction. More specifically, the information related to the AI ​​function signaled in step 407 can be combined and / or combined with the information related to the AI ​​function signaled in step 403, and both can be defined as having a hierarchical, mutually complementary, or substitute structure.

[0126] In step 409, the terminal (410) and the base station (420) transmit and / or receive data. That is, the terminal (410) and the base station (420) can process, transmit and / or receive data based on the signaling of control information. For example, when transmitting data, the terminal (410) or the base station (420) may perform at least one of channel encoding, rate matching, scrambling, constellation mapping, layer mapping, waveform modulation, antenna mapping, and resource mapping on the information bits. Conversely, when receiving data, the terminal (410) or the base station (420) may perform at least one of signal extraction from resources, antenna-specific waveform demodulation, signal placement considering layer mapping, constellation demapping, descrambling, and channel decoding. Here, the transmitted data is AI-related data, and may include, for example, data for AI-based operations or data generated by AI-based operations.

[0127] Steps 401 through 409 described with reference to FIG. 4 must not necessarily be performed in the order exemplified in FIG. 4, and the order of at least some of the steps may vary. Additionally, at least some of steps 401 through 409 may be combined into a single step or omitted. That is, the steps exemplified in FIG. 4 may be performed in various modified forms.

[0128]

[0129] 6G communication systems and core implementation technologies of 6G systems

[0130] 5G systems define various operating bands within FR1 (frequency range 1), which includes 410 MHz to 7125 MHz, and FR2 (frequency range 2), which includes 24,250 MHz to 71,000 MHz. Various frequencies are being discussed as operating bands for subsequent 6G systems, and the use of frequencies higher than those of 5G systems is also being considered for wider bandwidth and higher transmission speeds. As one example, the use of the THz (Terahertz) frequency band, which includes approximately 100 GHz to 10 THz, is being discussed. The THz frequency band is a band that possesses both the penetrability of radio waves and the directivity of optical waves, and communication using the THz frequency band is expected to play a transitional role from existing radio-based communication to optical-based communication.

[0131] 6G systems utilizing the THz frequency band as described above aim for: i) very high data rates per device, ii) a very large number of connected devices, iii) global connectivity, iv) very low latency, v) reduced energy consumption of battery-free IoT devices, vi) ultra-reliable connectivity, and vii) connected intelligence with machine learning capabilities. The vision of 6G systems can be four aspects, such as "intelligent connectivity," "deep connectivity," "holographic connectivity," and "ubiquitous connectivity," and 6G systems can be designed to satisfy requirements such as those shown in [Table 1] below.

[0132] Per device peak data rate1 TbpsE2E latency1 msMaximum spectral efficiency100 bps / HzMobility supportup to 1000 km / hrSatellite integrationFullyAIFullyAutonomous vehicleFullyXRFullyHaptic CommunicationFully

[0133] At this time, the 6G system may have key factors such as enhanced mobile broadband (eMBB), ultra-reliable low latency communications (URLC), massive machine type communications (mMTC), AI integrated communication, tactile internet, high throughput, high network capacity, high energy efficiency, low backhaul and access network congestion, and enhanced data security. FIG. 5 illustrates an example of a communication structure that can be provided by a 6G system applicable to the present disclosure. Referring to FIG. 5, the 6G system is expected to have simultaneous wireless communication connectivity 50 times higher than that of a 5G wireless communication system. URLLC, a key feature of 5G, is expected to become an even more dominant technology in 6G communication by providing end-to-end latency of less than 1ms. In this case, 6G systems will have significantly superior volumetric spectral efficiency, unlike the frequently used area-spectral efficiency. Since 6G systems can provide very long battery life and advanced battery technology for energy harvesting, mobile devices in 6G systems may not need to be charged separately. New network characteristics in 6G may be as follows.

[0134] - Satellite Integrated Network: 6G is expected to be integrated with satellites to provide a global mobile population. Integrating terrestrial, satellite, and airborne networks into a single wireless communication system is crucial for 6G.

[0135] - Connected Intelligence: Unlike previous generations of communication systems, 6G is innovative and will update wireless evolution from "connected things" to "connected intelligence." AI can be applied at each stage of the communication process (or at each step of the signal processing described below).

[0136] - Seamless integration of wireless information and energy transfer: 6G wireless networks will transfer power to charge the batteries of devices such as smartphones and sensors. Therefore, wireless information and energy transfer (WIET) will be integrated.

[0137] - Ubiquitous Super 3D Connectivity: Connectivity to the network and core network functions of drones and very low Earth orbit satellites will create Super 3D connectivity in 6G ubiquitous.

[0138] Some general requirements regarding the new network characteristics of 6G mentioned above may be as follows.

[0139] - Small cell networks: The idea of ​​small cell networks was introduced to improve the quality of received signals in cellular systems as a result of increased throughput, energy efficiency, and spectrum efficiency. Consequently, small cell networks are an essential feature of communication systems for 5G and beyond 5G (5GB). Therefore, 6G communication systems also adopt the characteristics of small cell networks.

[0140] - Ultra-dense heterogeneous network: Ultra-dense heterogeneous networks will be another important characteristic of 6G communication systems. Multi-tier networks composed of heterogeneous networks improve overall QoS and reduce costs.

[0141] - High-capacity backhaul: Backhaul connections are characterized as high-capacity backhaul networks to support high-volume traffic. High-speed fiber optics and free-space optics (FSO) systems can be possible solutions to this problem.

[0142] - Radar technology integrated with mobile technology: High-precision localization (or location-based services) through communication is one of the functions of 6G wireless communication systems. Therefore, radar systems will be integrated with 6G networks.

[0143] - Softwarization and virtualization: Softwarization and virtualization are two important features that form the basis of the design process in 5GB networks to ensure flexibility, reconfigurability, and programmability. Additionally, billions of devices can be shared across a shared physical infrastructure.

[0144] To satisfy the aforementioned characteristics, technologies such as artificial intelligence (AI), THz (Terahertz) communication, optical wireless technology, FSO backhaul network, massive MIMO technology, blockchain, 3D networking, quantum communication, unmanned aerial vehicles, cell-free communication, wireless information and energy transfer (WIET), integration of sensing and communication, integration of access backhaul networks, holographic beamforming, big data analysis, and large intelligent surface (LIS) may be adopted as core implementation technologies of the 6G system.

[0145] For example, THz communication can be utilized in 6G systems. THz communication is a communication that uses a spectrum in the frequency band between 0.3 THz and 3 THz with a corresponding wavelength in the range of 0.1 mm to 1 mm as shown in Fig. 6. Referring to Fig. 6, the frequency band of the THz wave is located in the intermediate region between the infrared band and the millimeter wave band; accordingly, the THz wave can be understood as a radio wave with the shortest wavelength and, at the same time, a light wave with the longest wavelength. As a result, the THz wave shares some characteristics of infrared and microwave waves, and specifically, can simultaneously possess the penetrability of electromagnetic waves and the directivity of light waves.

[0146]

[0147] FIG. 7 illustrates a transmitter structure applicable to the present disclosure.

[0148] Referring to Fig. 7, in order to modulate data onto an optical signal, the optical source of a laser can be passed through an optical wave guide to change the phase of the signal. At this time, data is loaded by changing electrical characteristics through a microwave contact, etc. Therefore, the optical modulator output is formed as a modulated waveform.

[0149] Data may be provided by a data signal generator. Here, the data may include various user data, configuration information, control information, etc. transmitted through a channel. Furthermore, the data may include data related to AI-based operations, for example, information for configuring an AI model, input / output data for tasks of an AI model, etc. To this end, components related to AI functions (e.g., an AI processing unit) may be included in the data signal generator or may interact with the data signal generator.

[0150] An O / E converter can generate THz pulses based on optical rectification by a nonlinear crystal, O / E conversion by a photoconductive antenna, emission from a bundle of relativistic electrons, etc. THz pulses generated in such a manner can have a length ranging from femtoseconds to picoseconds. The O / E converter performs down-conversion by utilizing the non-linearity of the device.

[0151] When considering the usage of the THz spectrum, it is highly likely that multiple contiguous GHz bands will be used for fixed or mobile service applications for THz systems. According to outdoor scenario criteria, available bandwidth can be classified based on an oxygen attenuation of 10^2 dB / km in the spectrum up to 1 THz. Accordingly, a framework in which the available bandwidth is composed of multiple band chunks can be considered. As an example of the above framework, if the length of the THz pulse for a single carrier is set to 50 ps, ​​the bandwidth (BW) becomes approximately 20 GHz.

[0152] Effective down-conversion from the infrared band to the THz band depends on how the nonlinearity of the photoelectric converter (O / E converter) is utilized. In other words, to achieve down-conversion to the desired THz band, it is required to design an O / E converter with the most ideal nonlinearity for transferring to that specific band. If an O / E converter that does not match the target frequency band is used, there is a high probability of errors occurring regarding the amplitude and phase of the corresponding pulse.

[0153] In a single-carrier system, a THz transceiver system can be implemented using a single photoelectric converter. Depending on the channel environment, in a multi-carrier system, as many photoelectric converters as there are carriers may be required. This phenomenon will be particularly pronounced in multi-carrier systems utilizing multiple broadbands according to the plans related to the aforementioned spectrum applications. In this regard, a frame structure for the multi-carrier system may be considered. A signal down-frequency converted based on a photoelectric converter can be transmitted in a specific resource region (e.g., a specific frame). The frequency domain of the specific resource region may include multiple chunks. Each chunk may consist of at least one component carrier (CC).

[0154]

[0155] AI technology can be introduced in 6G systems. Efficient resource management and optimization are required to maintain connectivity between various services and devices. AI technology may include techniques capable of performing data analysis, pattern recognition, and predictive modeling using AI / ML (artificial intelligence / machine learning) models. Here, an AI / ML model can be understood as a set of parameter values ​​and / or weight values ​​related to mathematical formulas or algorithms generated through learning, designed to discover patterns in input data or perform predictions. To create such an AI / ML model, an AI / ML model training procedure is required to build the model by learning the relationship between input and output in a data-driven manner. Various learning algorithms, such as supervised learning, unsupervised learning, and reinforcement learning, can be utilized as training algorithms. Users can input specific data into a trained AI / ML model to generate output, and the procedure of obtaining output data by inputting input data into the AI / ML model can be referred to as AI / ML 'inference' or 'prediction'.

[0156] Network control parameters can be obtained as output through AI / ML inference using trained AI / ML models. Users can improve network efficiency by utilizing these output parameter values. For example, AI technology can be applied in various fields, such as wireless network resource allocation, traffic management, fault prediction, and Quality of Service (QoS) management. In particular, machine learning can efficiently allocate resources even in dynamically changing network environments based on real-time data. Therefore, AI technology can be utilized to provide hyper-connectivity and ultra-low latency.

[0157] In this case, AI / ML inference can be performed based on a combination of various devices. For example, the UE and the network can jointly perform AI / ML inference, and such an AI / ML model may be referred to as a two-sided AI / ML model or a two-sided model. In this case, the UE may perform the first part of the inference first, and the base station may perform the remaining inference, and vice versa. As another example, all inference may be performed by the UE, and such an AI / ML model may be referred to as a UE-side AI / ML model or a UE-side model.

[0158] In addition, life cycle management (LCM) for AI / ML models can be performed. Life cycle management may include model training, model deployment, model inference, model monitoring, and model updating. To this end, support may be required for data collection, model training, functionality / model identification, model delivery / transfer, model inference operations, functionality / model selection / enable / disable / fallback, functionality / model monitoring, model updating, and UE capabilities.

[0159] For example, AI / ML technology can be operated based on a functional framework such as FIG. 8. FIG. 8 illustrates an example of a functional framework for the application of AI / ML technology applicable to the present disclosure. First, a data collection function (810) generates training data (801), monitoring data (803), and / or inference data (805) containing processed input data by performing data preparation on input data collected from objects (e.g., UE, RAN node, network node, etc.). A model training function (820), having received the training data (801) from the data collection function (810), performs training on an AI / ML model using the training data (801) and provides the trained / updated model (813) to a model repository (840). The model repository (840) can store and retain the received trained / updated model (813).

[0160] A management function (830) may be used to control AI / ML model training. The management function (830) may control the operation of AI / ML models or AI / ML functions, or supervise their performance. To this end, the management function (830) may receive monitoring data (830) from the data collection function (810) and receive inference output (809) from the inference function (840). The management function (830) performs the role of managing the inference operation so that it can be performed efficiently based on the data received from the data collection function (810) and the inference function (840). That is, the management function (830) may transmit performance feedback or a retraining request (807) to the model training function (820) to improve the inference operation. Here, the performance feedback may be used to direct the learning goal or as a reward for reinforcement learning. Additionally, the management function (830) can provide management instructions (811) that instruct the inference function (840) to select AI / ML models or AI / ML-based functions to use, enable / disable them, or switch to non-AI / ML operations.

[0161] The inference function (840) generates an inference output (809) by performing inference and / or prediction using inference data (805) received by the data collection function (810). Here, the inference output (809) refers to the inference output of the AI / ML model used by the inference function (840), and the details of the inference output may vary depending on the use case. The AI / ML model used by the inference function (840) can be controlled by the management function (830). That is, the management function (830) can transmit a model transmission / delivery request signal (815) to the model repository function (850) to request the necessary AI / ML model, and the model repository function (850) can transmit the corresponding AI / ML model to the inference function (840) via a model transmission / delivery signal (817). Thus, the inference function (840) can perform inference using the AI / ML model (817) according to the received management instructions (811).

[0162] Additionally, the management function (830) can trigger or perform a specified task / action based on the inference output (809). Thus, the management function (830) can trigger a task / action on other objects (e.g., at least one UE, at least one RAN node, at least one network node, etc.) or on itself. Any one of the functions exemplified in FIG. 8 described above may be performed by two or more entities among the RAN, network node, network operator's OAM, or UE in collaboration. This may be referred to as a split AI operation.

[0163] To use an AI / ML model, not all of the functions (810 to 850) illustrated in FIG. 8 must be used, and the method of combining them is not limited to a specific method. Therefore, the functions (810 to 850) may be operated in an integrated manner, or some functions may be omitted. Furthermore, the functions (810 to 850) illustrated in FIG. 8 are not necessarily limited to being implemented as separate devices or apparatuses. For example, some or all of the functions (810 to 850) may be included in the processor (202) of FIG. 2. Additionally, the model storage function (850) may be included in the memory (204) of FIG. 2.

[0164] FIG. 9 illustrates an example of a procedure for utilizing an AI model applicable to the present disclosure. FIG. 9 illustrates a case where a model training function (820) is included in a network node and a model inference function (840) is included in a RAN node. Referring to FIG. 9, in step 1, RAN node 1 and RAN node 2 transmit input data (e.g., training data) for training an AI model to a network node. Here, RAN node 1 and RAN node 2 may also transmit data collected from a UE (e.g., UE measurements related to RSRP, RSRQ, SINR of a serving cell and neighboring cells, UE location, velocity, etc.) to the network node. In step 2, the network node trains the AI ​​model using the received training data. In step 3, the network node distributes / updates the AI ​​model to RAN node 1 and / or RAN node 2. RAN node 1 and / or RAN node 2 may continue to perform model training based on the received AI model. In this procedure, it is assumed that the AI ​​model is deployed / updated only to RAN Node 1. In Step 4, RAN Node 1 receives input data (e.g., inference data) for AI model inference from the UE and RAN Node 2. In Step 5, RAN Node 1 generates output data (e.g., prediction or decision) by performing AI model-based inference using the received inference data. In Step 6, if applicable, RAN Node 1 may transmit model performance feedback to the network nodes. In Step 7, RAN Node 1, RAN Node 2, and the UE (or 'RAN Node 1 and UE', or 'RAN Node 1 and RAN Node 2') perform an action based on the output data. For example, in the case of a load balancing action, the UE may move from RAN Node 1 to RAN Node 2. In Step 8, RAN Node 1 and RAN Node 2 transmit feedback information to the network nodes.

[0165] Network nodes can manage AI models based on feedback information regarding the inference results of AI models. For example, network nodes can perform additional training on AI models or generate additional information about AI models (e.g., performance information, accuracy information, etc.). If additional training is performed on AI models, network nodes can distribute the updated AI models to RAN node 1.

[0166] As explained with reference to Fig. 9, model training can be performed by network nodes, and inference using the model can be performed by RAN node 1. In other words, the model training and inference functions can be distributed. Generally, model training requires a large amount of computational resources because it involves optimization using large amounts of data and complex algorithms. In contrast, inference is a process of drawing conclusions about new data using an already trained model, and therefore requires relatively fewer computational resources compared to model training. Therefore, by using the procedure of Fig. 9, model training can be performed through network nodes if the computational resources of the UE or RAN nodes are insufficient. Additionally, security regarding the AI ​​model can be ensured because the AI ​​model is not exposed to the UE.

[0167] FIG. 9 illustrates a case where the model training function (820) is included in a network node and the model inference function (840) is included in a RAN node, but the present disclosure is not limited thereto. For example, if the computational resources of the RAN node are sufficient, both the model training function (820) and the model inference function (840) may be included in RAN node 1. In this case, RAN node 1 receives training data for training an AI model from the UE and RAN node 2. RAN node 1 trains the AI ​​model using the received training data. Subsequently, RAN node 1 receives inference data for AI model inference from the UE and RAN node 2. RAN node 1 generates output data by performing AI model-based inference using the received inference data. Based on the output data, the UE, RAN node 1, and RAN node 2 can perform communication-related operations (e.g., handover, cell change). Subsequently, the UE and RAN node 2 can transmit feedback regarding the operations to RAN node 1. Therefore, RAN Node 1 can train the AI ​​model and update the AI ​​model it will use through feedback information regarding the inference results of the AI ​​model. According to the aforementioned method, since signaling with the network is not required for AI model training and inference, the network load or the latency to train the AI ​​model or receive inference results can be reduced. Additionally, since the UE performs inference using the AI ​​model, the UE's personal information is not transmitted to network nodes, etc. Consequently, security regarding personal information can be enhanced.

[0168] As another example, the model training function (820) may be included in the RAN node, and the model inference function (840) may be included in the UE. The RAN node receives training data for training an AI model from the UE and trains the AI ​​model using the received training data. The RAN node distributes the trained AI model to the UE. The UE can generate output data by performing inference based on the received AI model. At this time, the data for inference can be received from the RAN node or data acquired by the UE itself can be used. The UE and the RAN node can perform communication-related operations based on the output data generated by inference. Subsequently, the UE can send feedback regarding the operation to the RAN node. Thus, through feedback information regarding the inference results of the AI ​​model, the RAN node can train the AI ​​model and distribute the updated AI model to the UE. According to the method described above, the load on the RAN node can be reduced by having the model training function (820) in the RAN node and the model inference function (840) in the UE perform inference. In addition, if the UE performs inference using data acquired independently, even if the UE loses its connection to the RAN node after receiving the AI ​​model, the UE can continue to perform inference using the received AI model and operate based on the inference results.

[0169] According to the aforementioned framework and procedure, an AI model can be trained and utilized in a communication system. The model training function (820) and the model inference function (840) can be combined in various ways and are not necessarily limited to the case of FIG. 9. In the aforementioned framework and procedure, various data such as input data, training data, and inference data are introduced, and the specific details of the aforementioned data may vary depending on the task in which the AI ​​model is utilized. For example, information used in the various embodiments of the present disclosure described below may be included in the aforementioned data.

[0170]

[0171] FIG. 10 illustrates an AI technology-based communication procedure applicable to the present disclosure. The detailed procedure illustrated in FIG. 10 may be combined with various embodiments of the present disclosure described below. For example, data generated according to various embodiments of the present disclosure may be used for operations (e.g., setup, training, inference, and / or data transmission / reception) in at least one of the detailed procedure illustrated in FIG. 10. As another example, the result of the inference illustrated in FIG. 10 may be used to transmit and / or receive data according to various embodiments of the present disclosure.

[0172] Referring to FIG. 10, in step S1001, at least one of the UE (1010), RAN node (1020), and network node (1030) performs an initial connection procedure. For example, in this step, at least one of an initial cell search operation, a system information acquisition operation, a random access operation, and a registration operation may be performed. In step S1003, at least one of the UE (1010), RAN node (1020), and network node (1030) performs a configuration procedure. Through the configuration procedure, parameters, resources, connections, and / or entities necessary to perform subsequent procedures at layers between the UE (1010) and the RAN node (1020) and / or at least one layer between the UE (1010) and the network node (1030) may be determined and / or created. At this time, the configuration procedure may be performed based on information, status, and / or characteristics of the AI ​​model used for subsequent training and inference.

[0173] In step S1005, at least one of the UE (1010), RAN node (1020), and network node (1030) performs a model training procedure. At least one of the UE (1010), RAN node (1020), and network node (1030) may collect training data and perform training using the training data. For example, the model training procedure may be performed as described with reference to FIG. 9. If an offline trained model is used, this step may be omitted.

[0174] In step S1007, at least one of the UE (1010), RAN node (1020), and network node (1030) performs a task using a trained model. That is, the task may be performed by the result of inference and / or prediction using the trained model. For example, the task may be a procedure belonging to a communication protocol, a preliminary operation for subsequent data transmission and / or reception, related to data transmission and / or reception, or related to data processing (e.g., encoding, decoding, etc.).

[0175] In step S1009, at least one of the UE (1010), RAN node (1020), and network node (1030) transmits and / or receives data. At this time, the result of the task performed in step 1007 may be used. In some cases, the task performed in step 1007 may include the transmission and / or reception of data, in which case this step may be omitted as it is part of step 1007.

[0176]

[0177] Specific embodiments of the present disclosure

[0178] The present disclosure relates to a quantum signature technique capable of ensuring absolute security by utilizing the inherent properties of quantum mechanics. Specifically, the present disclosure relates to an entanglement-based quantum signature technique used to prevent repudiation and spoofing of message information transmitted between a sender and a receiver, and to ensure authentication and confidentiality. In particular, the present disclosure presents a technique for performing quantum electronic signatures by using a trusted third party (TTP) as an intermediary between the two parties, acting as an arbiter, when a direct channel is not connected between the sender and the receiver. Furthermore, the present disclosure covers a message recovery type quantum signature method. Here, a recovery type quantum signature is a signature technique in which the sender transmits only the signature information to the receiver, and the receiver recovers the message from the signature information.

[0179] Digital signature techniques fundamentally provide a solution that guarantees message integrity, message authentication, and non-repudiation—excluding confidentiality—among the four goals of information protection. Existing authentication techniques cannot handle situations where trust between entities exchanging information is broken. Therefore, digital signature techniques are necessary, as they provide functions such as third-party verification for dispute resolution, authentication of the origin of message content, and verification of forgery. Generally, signature techniques are classified into signature with appendix, which sends the plaintext message and signature together, and signature with message recovery, which transmits only the signature to additionally secure message confidentiality and recovers the plaintext from the signature. The existing classic digital signature and quantum digital signature, introduced below, can also be configured in two ways.

[0180] First, let's look at classical digital signature techniques. Existing digital signature techniques can be broadly divided into direct signature techniques and mediator-based signature techniques. A direct signature technique is illustrated in FIG. 11. FIG. 11 illustrates the concept of a digital signature technique based on direct signatures. Referring to FIG. 11, in an environment where only a sender (e.g., Alice) (1110) and a receiver (e.g., Bob) (1120) exist, a digital signature is performed based on an asymmetric key, and modeling is performed using a public key cryptographic algorithm and a hash function. The sender (1110) signs the entire message or hash using a private key, and the receiver (1120) decrypts the signature using the sender's (1110) public key. For example, ElGamal signatures and discrete logarithm-based public key algorithms are representative digital signature techniques. However, digital signature technology based on direct signatures relies on the security of the sender's private key for validity. Since the sender may claim to have lost or had their private key stolen, or the key could actually be stolen, this technology consequently requires the intervention of a third party. Therefore, while direct signature-based technology offers the advantage of structural simplicity, it may be difficult to utilize in situations requiring extremely high security.

[0181] To address this, a mediator-based signature method has emerged, and unlike the direct signature method, a mediator or TTP appears. Fig. 12 illustrates the concept of a mediator-based electronic signature method. The electronic signature method exemplified in Fig. 12 is a model using a conventional cryptographic algorithm and a mediator (1230), and the mediator (1230) performs the role of verifying the validity of the signed message. Therefore, the mediator (1230) must maintain neutrality and requires high trust. The mediator-based electronic signature method can be implemented using a private key, a public key algorithm, etc. Although the mediator-based electronic signature method provides higher security in terms of information security compared to the direct signature method, it has a more complex configuration in that it uses a mediator (1230) and has the disadvantage that the trustworthiness of the mediator (1230) must always be maintained. Fig. 12 exemplifies the signing process of a quantum signature method using a symmetric key-based cryptographic system and an unconditionally trustworthy mediator (1230). First, Alice (1210) generates a message m and generates a hash value H from message m using her hash function h. Then, Alice (1210) shares the hash value H with the secret key K shared with the mediator (1230). A It encrypts the value and transmits the encrypted hash value u to the mediator (1230). Then, the mediator (1230) decrypts the encrypted hash value u using the same key and H using the key K that only he possesses. T It encrypts and sends the encrypted hash value S to Alice (1210). Alice (1210) sends the signature information S and message m to Bob (1220). Next, Bob (1220) sends the signature information S to the secret key K held by himself and the mediator (1230). B Encrypt it, transmit the encrypted signature information v to the mediator (1230), and store the message m. The mediator (1230) uses its secret keys to recover H included in the signature information and KB It is encrypted, and the result of the encryption w is transmitted to Bob (1220). Based on this, Bob (1220) determines whether the signature is passed by checking whether H' and H generated from the message m match. That is, the digital signature technique consists of three steps: an initialization step in which a symmetric key is shared, a step in which signature information is generated from a message, and a step in which signature verification is performed by Bob (1220) with the help of an arbitrator (1230) after transmitting the signature information.

[0182]

[0183] Next, we examine electronic signature techniques based on quantum mechanics. Quantum electronic signature techniques provide unconditional security by utilizing the properties of quantum mechanics. Similar to existing electronic signature technologies, they can be classified into quantum one-time signatures, which consist of a combination of a quantum unidirectional function, a private key, and a public key, and arbitrator-based arbitrated quantum signatures (AQS). Among quantum electronic signature techniques, the quantum one-time signature follows the structure of the Lamport-Diffle one-time signature. The sender generates a public key shared between the sender and receiver by using the private key as the input to the quantum unidirectional function. Next, the sender transmits information regarding the location mapped to the message—either the message or the private key—to the receiver as signature information. During the verification process, the receiver generates a message using the received signature information and the same quantum unidirectional function as the sender, and verifies whether the signature is valid by confirming that the generated message matches the message received from the sender. In other words, similar to the direct signature technique among existing signature methods, the quantum one-time signature proceeds with the signing process using only the sender and the receiver.

[0184] On the other hand, arbitrated quantum signature (AQS) is divided into methods based on quantum entanglement states, such as GHZ states and Bell states, and methods based on single photons. The first AQS was introduced by G. Zeng in 2002 and is a quantum signature technique based on a secret symmetric key using quantum key distribution technology and an arbitrator using GHZ states.

[0185] Figure 13 illustrates the concept of a mediator-based quantum signature technique using GHZ states. Figure 13 illustrates the configuration of a mediator-based quantum electronic signature technique using GHZ states. The mediator-based quantum signature technique using GHZ states proceeds through the steps of preparation, signature generation, and signature verification.

[0186] In the preparation phase, Alice (1310) and the mediator (1330) are symmetric keys Sharing, Bob (1320) and the mediator (1330) are symmetric keys Shares. The mediator (1330) can generate a GHZ state and distribute the GHZ state according to the requests of Alice (1310) and Bob (1320).

[0187] In the signature generation step, Alice (1310) has a quantum message containing N qubits = + Generates, and the quantum one-time pad algorithm and Using the quantum state of a quantum message to a quantum message having a different quantum state It converts to. Next, Alice (1310) converts the quantum message and perform a Bell state measurement of the GHZ state particle of Alice (1310), and the result is 2N qubits Save it as. Next, Alice (1310) has signature information Generates. Signature information Is and About It can be generated by applying a quantum one-time pad algorithm using . For example, and for Signature information by quantum one-time pad algorithm computation defined by can be generated. At this time, a quantum message It includes N qubits, and signature information It contains 3N qubits.

[0188] Signature information generated in Alice (1310) and multiple quantum messages It is transmitted to Bob (1320). Bob (1320) receives the quantum messages One of them is saved for use in subsequent signature verification. Then, Bob (1320) measures his GHZ state particle along the X-axis, and the measurement result Saves. Next, Bob (1320) has signature information , at least one remaining quantum message , measurement results cast Encrypt as, and the encrypted result It transmits to the mediator (1330).

[0189] The mediator (1330) received cast Signature information by decrypting using and quantum messages The mediator (1330) obtains signature information. cast By decoding using Acquire, to By applying a conversion operator based on The mediator (1330) obtains a decision factor indicating whether the signature information is forged, based on whether the two obtained values ​​are identical. Determine whether it is 0 or 1. Next, the mediator (1330) determines Alice's (1310) measurement value , the measured value of rice (1320) , judgment factor , GHZ state particles not measured in the mediator (1330) , signature information cast Encrypt using, and the result of encryption Sends to Bob (1320).

[0190] Finally, in the signature verification step, Bob (1320) Decryption is performed using [it], and the verification procedure of the signature information is carried out in two steps. First, as the first signature verification operation, Bob (1320) [it] includes in the signature information Factors for determining whether it is forged Verify based on the value of. If, If =0, the signature is forged, and accordingly, Bob (1320) has a quantum message Discard and halt the procedure. On the other hand, If =1, the components of the signature information Since this is correct, Bob (1320) proceeds with the following second signature verification operation.

[0191] In the second signature verification operation, the unmeasured GHZ state particle of the mediator (1330) received from the mediator (1330) Regarding this, rice (1320) is and By taking an appropriate operator that can be inferred from the correlation between the measurement results and the GHZ state Generates. Here, the selectable operators are as shown in [Table 2] below.

[0192] Operations required for message recovery + | - Z - Z + | + X - XZ - XZ + X

[0193] Next, the previously stored rice (1320) and previously acquired The correctness of the signature information is verified by checking whether it matches. and If this matches, Bob (1320) determines it to be a complete correction, and the message Accepts. and If this does not match, Bob (1320) is the message Refuses.

[0194] The mediator-based quantum signature technique using triplet GHZ states introduced by G. Zeng can also be performed using two photon entanglement states, such as Bell states. Fig. 14 illustrates the concept of a mediator-based quantum signature technique using Bell states. Fig. 14 exemplifies the configuration of a signature technique similar to the procedure described with reference to Fig. 13, in a situation where the entanglement quantum state shared by the mediator is replaced from a GHZ state using three photon entanglements to a Bell state, which is a two-photon entanglement state.

[0195] In the preparation phase, Alice (1410) and the mediator (1430) are symmetric keys Sharing, Bob (1420) and the mediator (1430) are symmetric keys The mediator (1430) can create an entanglement state and distribute the entanglement state according to the requests of Alice (1410) and Bob (1420).

[0196] In the signature generation step, Alice (1410) has a quantum message containing N qubits = + Generates, and the quantum one-time pad algorithm and Using the quantum state of a quantum message to a quantum message having a different quantum state It converts to. Next, Alice (1410) converts the quantum message and perform a measurement of the particle entanglement state of Alice (1410), and the result is 2N qubits Save it as. Next, Alice (1410) has signature information Generates. Signature information Is and About It can be generated by applying a quantum one-time pad algorithm using . For example, and for Signature information by quantum one-time pad algorithm computation defined by can be generated. At this time, a quantum message It includes N qubits, and signature information It contains 3N qubits.

[0197] Signature information generated in Alice (1410) and multiple quantum messages It is transmitted to Bob (1420). Bob (1420) receives quantum messages One of them is saved for use in subsequent signature verification. Then, Bob (1420) has signature information , at least one remaining quantum message cast Encrypt as, and the encrypted result It transmits to the mediator (1430).

[0198] The mediator (1430) received cast Signature information by decrypting using and quantum messages The mediator (1430) obtains the signature information. cast By decoding using Acquire, to By applying a conversion operator based on The mediator (1430) obtains a decision factor indicating whether the signature information is forged, based on whether the two obtained values ​​are identical. Determine whether it is 0 or 1. Next, the mediator (1430) determines Alice's (1410) measurement value , judgment factor , signature information cast Encrypt using and the result of encryption Sends to Bob (1420).

[0199] Finally, in the signature verification step, Bob (1420) Decryption is performed using [the method], and the verification procedure of the signature information is carried out in two steps. First, as the first signature verification operation, Bob (1420) [is included in the signature information] Factors for determining whether it is forged Verify based on the value of. If, If =0, the signature is forged, and accordingly, Bob (1420) is a quantum message Discard and halt the procedure. On the other hand, If =1, the components of the signature information Since this is correct, Bob (1420) proceeds with the following second signature verification operation.

[0200] In the second signature verification operation, the unmeasured entanglement state particle of the mediator (1430) received from the mediator (1430) Regarding this, rice (1420) is By taking an appropriate operator that can be inferred from the correlation between the measurement results and the entanglement state Generates. Here, the selectable operators are as shown in [Table 3] below.

[0201] Operations required for message recovery + | - Z + X - XZ

[0202] Next, the previously stored rice (1420) and previously acquired The correctness of the signature information is verified by checking whether it matches. and If this matches, Bob (1420) determines it to be a complete correction, and the message Accepts. and If this does not match, Bob (1420) is the message Refuses.

[0203] By applying a method like that shown in Fig. 14, the amount of information transmitted is reduced compared to a GHZ state-based quantum signature technique, while maintaining security. Specifically, referring to Figs. 13 and 14, it is confirmed that the amount of qubits transmitted between the mediator and Bob decreases from 5N and 7N+1 to 4N and 5N+1.

[0204] The two aforementioned mediator-based quantum signature techniques using entanglement can be implemented based on a single photon. When using a single photon, processes such as generating an entangled light source and measuring the Bell state are not required, making implementation relatively easier, and the amount of transmitted entangled qubit information can be significantly reduced compared to the two previous techniques.

[0205]

[0206] FIG. 15 illustrates the concept of a mediator-based quantum signature technique using a single photon. FIG. 15 exemplifies the actions of Alice (1510), Bob (1520), and the mediator (1530) according to a single photon-based quantum signature technique using a public board instead of an entangled state.

[0207] In the initial stage, Alice (1510), Bob (1520), and the Mediator (1530) share the secret symmetric key required by each of them. Specifically, Alice (1510) and the Mediator (1530) have the secret symmetric key They share, and Bob (1520) and the mediator (1530) have a secret symmetric key They share, and Alice (1510) and Bob (1520) have a secret symmetric key Share.

[0208] At the signing stage, Alice (1510) messages Generates. To further ensure the confidentiality of the message, Alice (1510) generates a random number Secret qubit string by encrypting the message using Create, secret symmetric key from Generated using and secret symmetric key Generated using Signature information based on It generates. And, Alice (1510) has signature information Sends to Bob (1520).

[0209] In the signature verification step, Bob (1520) receives the received signature information from , , ...is obtained. And, Bob (1520) is obtained from the signature information and Encrypt and the encryption result It transmits to the mediator (1530). The mediator (1530) By decoding and The mediator (1530) obtains and performs signature verification. Specifically, the mediator (1530) By decoding Acquire, and Compares. And, the mediator (1530) and Indicating whether it matches It is announced through a public board and regenerated as information necessary for the verification of Bob (1520). Sends to Bob (1520).

[0210] Bob (1520) performs verification of message information by decoding the received information. First, Bob (1520) on the public board Check and If the value of is 1, the received By decoding and Acquires. And, Rice (1520) is By decoding Acquire, and Indicating whether it matches The value of is announced through a public board. That is, if no discrepancy occurs during the verification process, Bob (1520) announces the verification result using a public channel.

[0211] Verification results If it is determined that there is no problem with the verification result of Bob (1520) based on this, Alice (1510) gives Bob (1520) the random number information necessary for message recovery. It transmits through a public channel. Finally, Bob (1520) receives the received random number information By proceeding with the restoration process of the message information received based on, the original message Restores.

[0212]

[0213] The aforementioned quantum signature techniques can satisfy the following four characteristics in common.

[0214] First, it must be impossible for the recipient or the attacker to forge the signature after it has been generated.

[0215] Second, the signer must not be able to deny the signature and the signed message, and the recipient must not be able to deny the fact that they received the message and the signature.

[0216] Third, each message must be assigned to a new signature and must not be separated from that signature.

[0217] Fourth, the quantum signature must contain quantum mechanical characteristics.

[0218]

[0219] The symbols and terms used in the following description may be defined as follows.

[0220] - Quantum message,

[0221] - Quantum signature information

[0222] - : Secret symmetric key exchanged via QKD between Alice and TTP

[0223] - : Secret symmetric key exchanged via QKD between Bob and TTP

[0224] - : A secret key possessed only by the arbitrator. It is used during the arbitrator's verification process and is generated using the arbitrator's random number generator.

[0225] - Quantum state resulting from applying the quantum one-time pad algorithm to the message

[0226] - Alice: Message creator

[0227] - Bob: Signature, message recipient, and verifier

[0228] - TTP (Trusted Third Party): A third party trusted by all participants in the signing

[0229] - Quantum one-time pad encryption: , applied to the encryption of information transmitted over quantum channels

[0230] - Unitary transform:

[0231]

[0232] Existing mediator-based quantum signature techniques consider only cases where a direct connection exists between the sender and receiver. Therefore, it is necessary to consider quantum signature techniques for cases where no direct connection exists between the sender and receiver. To this end, the role of the mediator cannot be limited to merely assisting with existing verification; it is required to expand to various functions such as signature generation and verification, and message delivery.

[0233] In the arbitration-based quantum signature technique using entanglement or single-photon states described with reference to FIGS. 13, 14, and 15, since there is a directly connected channel between the sender and the receiver, message and signature information can be directly transmitted from the sender to the receiver, and the receiver can perform a verification procedure by exchanging the received information with the arbitrator. The arbitrator performs only the role of generating results and factors necessary for signature verification using the information received from the receiver.

[0234] However, situations where a direct connection path does not exist between the sender and receiver (e.g., situations where Line of Sight (LOS) is not secured between the sender and receiver, situations where direct information transfer is impossible due to long transmission distances or environmental factors, etc.) may necessitate the performance of a quantum signature. In such cases, a messenger is required to act as an intermediary to facilitate the transfer of signature-related information between the sender and receiver. In digital information-based signature techniques, signature mechanisms utilizing intermediaries have been developed. Furthermore, ISO / IEC 13888, the international standard for classical symmetric key-based non-repudiation techniques, considers non-repudiation mechanisms for both cases where a direct connection path exists and where it does not, and proposes a non-repudiation mechanism using TTPs as intermediaries. However, regarding quantum signatures, only mechanisms for cases where a direct connection path exists exist. Therefore, when considering future standardization, it is necessary to develop quantum signature mechanisms for cases where a direct connection path does not exist, just as with classical signature techniques.

[0235]

[0236] The present disclosure proposes various embodiments for performing an entanglement-based arbitrator-based message recovery quantum signature technique applicable in situations where there is no direct information transmission path between a sender (e.g., Alice) and a receiver (e.g., Bob). Embodiment #1 described below relates to an arbitrator-based quantum signature technique using a GHZ triplet state, and Embodiment #2 relates to an arbitrator-based quantum signature technique using a Bell state. The quantum signature procedure proposed in the present disclosure consists of three stages: an initial stage, a quantum signature generation stage, and a verification stage. Depending on the various embodiments, the arbitrator (e.g., TTP) in the present disclosure may be a certification agent (CA), the sender may be understood as a mobile terminal (e.g., UE) requesting verification of a signature generated from a message, and the receiver may be understood as a base station, server, or core network entity performing the verification.

[0237]

[0238] [Example #1] Mediator-based message recovery type quantum signature protocol using GHZ state

[0239] [Example #1-1] Quantum signature technique with a structure that distributes GHZ state particles only between a mediator and a receiver

[0240] Example #1-1 relates to a mediator-based message recovery quantum signature technique using a GHZ state that can be applied when there is no direct connection path between a sender and a receiver. In the case of a message recovery quantum signature technique, since message information is not exposed during the process of the sender transmitting to the receiver, it is possible to additionally secure the confidentiality of the message in addition to the functions of a conventional quantum signature. In this embodiment, a mediator (e.g., TTP) holds two of the three particles constituting the GHZ state generated by the mediator and distributes one particle to Bob (1620). The quantum signature according to Example #1-1 is performed as follows.

[0241] (1) Initial stage

[0242] FIG. 16a illustrates an initial stage of a method for distributing GHZ state particles only between a mediator and a receiver, in a mediator-based message recovery quantum signature technique using a GHZ state according to one embodiment of the present disclosure. Referring to FIG. 16a, in a situation where there is no direct connection channel between Alice (1610) and Bob (1620), Alice (1610) and the mediator (1630) [use] a first secret symmetric key according to the QKD protocol They share. Similarly, Bob (1620) and the mediator (1630) use a mutually connected channel to obtain a second secret symmetric key according to the QKD protocol. It shares the secret key. In addition, the mediator (1630) uses the secret key in the signature verification process. Generates a secret key It is held by the mediator (1630) and may not be shared with other devices.

[0243] (2) Quantum signature generation step:

[0244] FIGS. 16b and 16c illustrate a quantum signature generation step in which GHZ state particles are distributed only between a mediator and a receiver, as a mediator-based message recovery quantum signature technique using a GHZ state according to one embodiment of the present disclosure. According to Example #1-1, since there are no entangled particles connected to the sender, the sender Alice (1610) transmits a message and additional information related to the message to the mediator (1630), the mediator (1630) generates a signature based on the received information, and it can be guaranteed that the signature was constructed at the mediator (1630) from the message generated by Alice (1610).

[0245] Referring to FIGS. 16b and 16c, in operation S1, the mediator (2030) [represents] a random number Generates. In operation S2, the mediator (1630) generates a random number as the first secret symmetric key Encrypted using Generates. In operation S3, the mediator (1630) gives Alice (1610) encrypted random number information transmits. In operation S4, the sender Alice (1610) decodes By doing so, random number information Acquires. In operation S5, Alice (1610) obtains a primary qubit message containing n qubits. Creates 4 copies of. Here, is. In operation S6, Alice (1610) performs a second qubit message through a unitary conversion operation using a random number. Creates four copies of. In operation S7, Alice (1610) creates a secondary qubit message 3rd qubit message using 1 copy of generates. In operation S8, Alice (1610) generates two pieces of information from the message qubit information to ensure the integrity of the message, namely, the secondary qubit message. and 3rd qubit message Signature initiation information by encrypting Generates. In operation S9, Alice (1610) generates signature start information It transmits to the mediator (1630).

[0246] In operation S10, the mediator (1630) provides signature initiation information Receive and decrypt By doing so, three copies of the secondary qubit message and 3rd qubit message Acquires. In operation S11, the mediator (1630) 1st qubit message through Recovers two copies of. In operation S12, the mediator (1630) creates the GHZ state The first particle of Acquires. In operation S13, the mediator (1630) obtains the first particle and 1st qubit message Perform BSM using and the measurement results Saves.

[0247] In operation S14, the mediator (1630) is a verification factor for verifying the signature of the mediator (1630). Generates. In operation S15, the mediator (1630) generates signature information Generates. In operation S16, the mediator (1630) generates signature information It transmits to Bob (1620). In operation S17, the mediator (1630) transmits the second particle in the GHZ state. Acquires. In operation S18, the mediator (1630) obtains the second particle Perform X-direction measurements, and as a result Saves.

[0248] (3) Quantum signature verification step:

[0249] FIG. 16d illustrates a quantum signature verification and message recovery method using a GHZ state mediator-based message recovery quantum signature technique according to one embodiment of the present disclosure, wherein GHZ state particles are distributed only between a mediator and a receiver.

[0250] Referring to FIG. 16d, in operation V1, Bob (1620) is signature information and the third particle in the GHZ state is received from the mediator (1630). In operation V2, Bob (1620) receives the received information, i.e., and is the second secret symmetric key The first transmission information by encrypting it Generates. In operation V3, Bob (1620) is the first transfer information It transmits to the mediator (1630).

[0251] In operation V4, the mediator (1630) receives the first transmission information. is the second secret symmetric key Decrypt using By doing so, the quantum information elements included in the first transmission information, namely, signature information and the third particle Obtains. In operation V5, obtained through the decoding process at the mediator (1630). Decode By doing so, quantum information elements, namely, qubit messages and validation factors Acquires. In operation V6, the mediator (1630) obtains the third particle cast and 1st qubit message using Restore it. At this time, the restoration rules shown in [Table 4] may be applied.

[0252] rice message Operators required for recovery | Z Z | X XZ XZ X

[0253]

[0254] In operation V7, the mediator (1630) is the signature verification factors and It generates. Specifically, the mediator (1630) generates a primary qubit message Random number for The first signature verification factor through a unitary transformation operation using It generates. And, the mediator (1630) verifies the information By decrypting the 3rd qubit message using the mediator's (1630) secret key Obtain the acquired 3rd qubit message as the 1st secret symmetric key By decrypting, the second signature verification factor Generates. In operation V8, the arbitrator (1630) performs signature verification by comparing whether signature verification factors match (e.g., a swap test) and a signature verification result indicating the result. Generates. In this verification process, when performing a swap test to compare two unknown quantum states, based on whether the statistical error rate obtained through comparisons of quantum state matching corresponding to the length of a message qubit sequence of n (e.g., a sufficiently large number) exceeds a threshold (e.g., the comparison error rate occurring when comparing quantum state information of the same n-qubit sequence; the error rate decreases as n increases), This is set to 0 or 1.

[0255] In operation V9, the mediator (1630) retrieves the primary qubit message recovered in operation S11. Random number for Message validation arguments through unitary conversion operations using Generates. In operation V10, the mediator (1630) performs message verification using message verification parameters, and the message verification result Generates. In operation V11, the mediator (1630) provides second transmission information as information necessary for determining the verification result of Bob (1620). Generates. In operation V12, the mediator (1630) generates the second transmission information Sends to Bob (1620).

[0256] In operation V13, Bob (1620) decodes the factors required for verification judgment. By doing so, the second qubit message , signature verification result and message verification results ...is obtained. In operation V14, Bob (1620) uses the information received from the mediator (1630) to determine whether the signature verification passes. If the signature verification passes, in operation V15, Bob (1620) gives the mediator (1630) random number information for message recovery. Requests. In operation V16, the mediator (1630) gives Bob (1620) random number information The mediator (1630) that received the request for random number information from Bob (1620) is the entity that performed the verification, so if the verification result is all 1, the random number information generated by itself in operation S1 It transmits to Bob (1620). In operation V17, Bob (1620) receives the random number information received from the mediator (1630). 1st qubit message using It recovers the first qubit message. That is, Bob (1620) recovers the first qubit message by performing the inverse transformation of the unitary transformation operation on the second qubit message.

[0257]

[0258] FIGS. 17a through 17c illustrate examples of operations of a sender, a receiver, and an arbitrator according to a quantum signature technique based on a GHZ state and message recovery using an arbitrator-based method, which distributes GHZ state particles only between the arbitrator and the receiver, as an embodiment of the present disclosure. In FIGS. 17a through 17c, Alice (1610) acts as a message creator, Bob (1620) acts as a verifier, and the arbitrator (1630) is positioned as an intermediate connection path existing between the sender and the receiver, performing the roles of signature creation and verification, generating and transmitting random number information to ensure message confidentiality, and receiving the message created by the sender. In the flowchart, I represents the initial stage, S represents the signature creation stage, and V represents the signature verification stage.

[0259]

[0260] [Example #1-2] Quantum signature technique with a structure for distributing GHZ state particles among three participants in a signature

[0261] Example #1-2 relates to a mediator-based message recovery quantum signature technique using a GHZ state that can be applied when there is no direct connection path between a sender and a receiver. In this embodiment, unlike Example #1-1, the mediator (1830) distributes three particles constituting the GHZ state generated in the mediator (1830) one each to Alice (1810), Bob (1820), and the mediator (1830). The quantum signature according to Example #1-2 is performed as follows.

[0262] (1) Initial stage

[0263]

[0264] FIG. 18a illustrates an initial step of a method for distributing GHZ state particles between a mediator, a sender, and a receiver, in a mediator-based message recovery quantum signature method using a GHZ state according to one embodiment of the present disclosure. Referring to FIG. 18a, in a situation where there is no direct connection channel between Alice (1810) and Bob (1820), Alice (1810) and the mediator (1830) [use] a first secret symmetric key according to the QKD protocol They share. Similarly, Bob (1820) and the mediator (1830) use a mutually connected channel to share a second secret symmetric key according to the QKD protocol. It shares the secret key. In addition, the mediator (1830) uses the secret key in the signature verification process. Generates a secret key It is held by the mediator (1830) and may not be shared with other devices. In this embodiment, the mediator (e.g., TTP) holds one of the three particles constituting the GHZ state generated by the mediator and distributes one particle to Alice (1810) and one particle to Bob (1820).

[0265] (2) Quantum signature generation step:

[0266] FIGS. 18b and 18c illustrate a quantum signature generation step in which GHZ state particles are distributed among a mediator, a sender, and a receiver, as a mediator-based message recovery type quantum signature technique using GHZ state according to an embodiment of the present disclosure. According to Example #1-2, when BSM measurement is performed using a message generated by a sender and GHZ state particles, it can be guaranteed that a signature was generated from the sender's message based on the fact that the state of the GHZ state particles of the mediator and the receiver used for signature and message verification is determined. The detailed procedure of the message recovery type quantum signature technique utilizing these characteristics is as follows.

[0267] Referring to FIGS. 18b and 18c, in operation S1, Alice (1810) has a primary qubit message containing n qubits. Creates 4 copies of. Here, is. In operation S2, Alice (1810) receives the first particle in the GHZ state from the mediator (1830). is received. In operation S3, Alice (1810) receives the acquired information, specifically and Perform BSM based on, and the measurement results Saves. In operation S4, Alice (1810) saves the signature start information to ensure message confidentiality. Generates. In operation S5, Alice (1810) gives the signature start information to the mediator (1830). transmits.

[0268] In operation S6, the mediator (1830) receives signature initiation information Receive and decrypt By doing so and Acquires. In operation S7, the mediator (1830) obtains a random number Generate and the first qubit message Random number for Secondary qubit message through unitary conversion operation using Creates two copies of. In operation S8, the mediator (1830) verifies the verification factor for signature verification. Generates. In operation S9, the mediator (1830) encrypts the secondary qubit message and verification factor using the first secret symmetric key to generate signature information. Creates.

[0269] In operation S10, the mediator (1830) is the second particle in the GHZ state Acquires. In operation S11, the mediator (1830) obtains the second particle Measure in the X-axis direction, and the measurement result Saves. In operation S12, the mediator (1630) gives the signature information to Bob (1620). transmits.

[0270] (3) Quantum signature verification step:

[0271] FIG. 18d illustrates a quantum signature verification and message recovery method using a GHZ state mediator-based message recovery quantum signature technique according to one embodiment of the present disclosure, wherein GHZ state particles are distributed between a mediator, a sender, and a receiver. In the signature verification step, a mediator (1830) obtains the parameters required for verification, performs verification, and based on the results, Bob (1820) performs a judgment and then performs message recovery. The detailed process is as follows.

[0272] Referring to FIG. 18d, in operation V1, Bob (1820) is signature information and the third particle in the GHZ state is received from the mediator (1830). In operation V2, Bob (1820) receives the received information, specifically, signature information. and the third particle is the second secret symmetric key The first transmission information by encrypting it Generates. In operation V3, Bob (1820) is the first transfer information It transmits to the mediator (1830).

[0273] In operation V4, the mediator (1830) receives the first transmission information. is the second secret symmetric key Decrypt using By doing so, signature information and the third particle Acquires. In operation V5, the arbitrator (1830) obtains the signature information obtained through decryption. Decode By doing so, the second qubit message and validation factors Acquires. In operation V6, the mediator (1830) obtains the third particle from and 1st qubit message using Restores. The restoration rules for this are as shown in [Table 5] below.

[0274] rice message Operators required for recovery | Z Z | X XZ XZ X

[0275] In operation V7, the mediator (1830) is the signature verification factors and It generates. Specifically, the mediator (1830) generates a primary qubit message Random number for Unitary conversion operation using Through the first signature verification factor It generates. Also, the mediator (1830) verifies information Decrypt using the mediator's (1830) secret key By doing so, the second signature verification factor Generates. In operation V8, the arbitrator (1830) performs verification of the signature, and the signature verification result Generates. In this verification process, when performing a swap test to compare two unknown quantum states, based on whether the statistical error rate obtained through comparisons of quantum state matching corresponding to the length of a message qubit sequence of n (e.g., a sufficiently large number) exceeds a threshold (e.g., the comparison error rate occurring when comparing quantum state information of the same n-qubit sequence; the error rate decreases as n increases), This is set to 0 or 1. In operation V9, the mediator (1830) receives the recovered primary qubit message generated in operation S6. Based on It generates parameters to be used for message verification. That is, the mediator (1830) generates the primary qubit message recovered in operation S6. Random number for Message validation arguments through unitary conversion operations using Generates. In operation V10, the mediator (1830) performs message verification using message verification parameters, and the message verification result Generates. In operation V11, the mediator (1830) provides the second transmission information necessary for determining the verification result of Bob (1820). Generates. Specifically, the mediator (1830) generates second delivery information by encrypting the second qubit message, the signature verification result, and the message verification result using the second secret symmetric key. In operation V12, the mediator (1830) generates the second delivery information Sends to Bob (1820).

[0276] In operation V13, Bob (1820) decodes the second transmission information By doing so, the second qubit message , signature verification result and message verification results ...is obtained. In operation V14, Bob (1820) determines whether the signature verification passes using the signature verification result received from the mediator (1830). If the signature verification passes, in operation V15, Bob (1820) provides the mediator (1830) with random number information for message recovery. Requests. In operation V16, the mediator (1830) gives Bob (1820) random number information The mediator (1830) that received the request for random number information from Bob (1820) is the entity that performed the verification, so if the verification result is all 1, the random number information that it generated in operation S1 It transmits to Bob (1820). In operation V17, Bob (1820) receives the random number information received from the mediator (1830). Message recovery process using ...is performed. That is, Bob (1820) recovers the first qubit message by performing the inverse transformation of the unitary transformation operation on the second qubit message.

[0277]

[0278] FIGS. 19a to 19c illustrate examples of operations of a sender, a receiver, and an arbitrator according to a quantum signature technique that uses a GHZ state and distributes GHZ state particles between an arbitrator, a sender, and a receiver, as an arbitrator-based message recovery type quantum signature technique using a GHZ state according to one embodiment of the present disclosure. In FIGS. 19a to 19c, Alice (1810) performs the role of a message creator, Bob (1820) performs the role of a verifier, and the arbitrator (1830) is located as an intermediate connection path existing between the sender and the receiver and performs the roles of signature creation and verification, generation and transmission of random number information to ensure message confidentiality, and receiving the message created by the sender. In the flowchart, I represents the initial stage, S represents the signature creation stage, and V represents the signature verification stage.

[0279]

[0280]

[0281] [Example #2] Mediator-based message recovery type quantum signature protocol using Bell state

[0282] [Example #2-1] Quantum signature technique with a structure that distributes Bell state particles only between a mediator and a receiver

[0283] Example #2-1 relates to a mediator-based message recovery quantum signature technique using a Bell state that can be applied when there is no direct connection path between a sender and a receiver. In this embodiment, a mediator (2030) (e.g., TTP) holds one of the two particles constituting the Bell state generated by the mediator (2030) and distributes one particle to Bob (2020). The quantum signature according to Example #2-1 is performed as follows.

[0284] (1) Initial stage

[0285] FIG. 20a illustrates an initial step of a method for distributing state particles between a mediator and a receiver, in a mediator-based message recovery quantum signature technique using a Bell state according to one embodiment of the present disclosure. Referring to FIG. 20a, in a situation where there is no direct connection channel between Alice (2010) and Bob (2020), Alice (2010) and the mediator (2030) [use] a first secret symmetric key according to the QKD protocol They share. Similarly, Bob (2020) and the mediator (2030) use a mutually connected channel to share a second secret symmetric key according to the QKD protocol. It shares in advance. Also, the mediator (2030) has a secret key that only he / she possesses. It is generated for use in the signature verification process. Additionally, it is held by the mediator (1630) and may not be shared with other devices (2030), which is a Bell state, an entangled state of two photons. It generates, and the mediator (2030) and Bob (2020) each have one entangled particle.

[0286] (2) Quantum signature generation step:

[0287] FIGS. 20b and FIGS. 20c illustrate a quantum signature generation step in a manner that distributes Bell state particles between a mediator and a receiver, as a mediator-based message recovery quantum signature technique using a Bell state according to one embodiment of the present disclosure. According to Example #2-1, since there are no entangled particles connected to the sender, the sender Alice (2010) transmits a message and additional information related to the message to the mediator (2030), the mediator (2030) generates a signature based on the received information, and it can be guaranteed that the signature was constructed at the mediator (2030) from the message generated by Alice (2010).

[0288] Referring to FIGS. 20b and 20c, in operation S1, the mediator (2030) [represents] a random number Generates. In operation S2, the mediator (2030) generates a random number as the first secret symmetric key Encrypted random number information using Generates. In operation S3, the mediator (2030) gives Alice (2010) encrypted random number information transmits. In operation S4, the sender Alice (2010) decrypts the encrypted random number information. By doing so, random number information Acquires. In operation S5, Alice (2010) obtains a primary qubit message containing n qubits. Creates 4 copies of. Here, is. In operation S6, Alice (2010) performs a second qubit message through a unitary conversion operation using a random number. Creates 4 copies of. In operation S7, Alice (2010) creates a secondary qubit message 3rd qubit message using 1 copy of generates. In operation S8, Alice (2010) generates two pieces of information from the message qubit information to ensure the integrity of the message, namely, the secondary qubit message and 3rd qubit message Signature initiation information by encrypting Generates. In operation S9, Alice (2010) generates signature start information It transmits to the mediator (2030).

[0289] In operation S10, the mediator (2030) provides signature initiation information Receive and decrypt By doing so, three copies of the secondary qubit message and 3rd qubit message Acquires. In operation S11, the mediator (2030) 1st qubit message through Restores two copies of. In operation S12, the mediator (2030) creates the bell state The first particle that makes up Acquires. In operation S13, the mediator (2030) obtains the first particle and 1st qubit message Perform BSM using and the measurement results Saves.

[0290] In operation S14, the mediator (2030) has a verification factor for verifying the signature of the mediator (2030). Generates. In operation S15, the mediator (2030) generates signature information Generates. In operation S16, the mediator (2030) generates signature information Sends to Bob (2020).

[0291] (3) Quantum signature verification step:

[0292] FIG. 20d illustrates a quantum signature verification and message recovery method using a Bell state mediator-based message recovery quantum signature technique according to one embodiment of the present disclosure, which distributes Bell state particles between a mediator and a receiver.

[0293] Referring to FIG. 20d, in operation V1, Bob (2020) is signature information and the second particle in the bell state is received from the mediator (2030). In operation V2, Bob (2020) receives the received information, i.e., and is the second secret symmetric key The first transmission information by encrypting it Generates. In operation V3, Bob (2020) is the first transfer information It transmits to the mediator (2030).

[0294] In operation V4, the mediator (2030) receives the first transmission information. is the second secret symmetric key Decrypt using By doing so, the quantum information elements included in the first transmission information, namely, signature information and the second particle Obtains. In operation V5, obtained through the decoding process at the mediator (2030). Decode By doing so, quantum information elements, namely, qubit messages and validation factors Acquires. In operation V6, the mediator (2030) obtains the second particle cast 1st qubit message using Restore it. At this time, the restoration rules shown in [Table 6] may be applied.

[0295] message Operators required for recovery | Z Z XZ

[0296] In operation V7, the mediator (2030) is the signature verification factors and It generates. Specifically, the mediator (2030) generates a primary qubit message Random number for The first signature verification factor through a unitary transformation operation using It generates. And, the mediator (2030) verifies the information 3rd qubit message by decrypting using the mediator's (2030) secret key Obtain the acquired 3rd qubit message as the 1st secret symmetric key By decrypting, the second signature verification factor Generates. In operation V8, the arbitrator (2030) performs signature verification by comparing whether signature verification factors match (e.g., swap test) and a signature verification result indicating the result. Generates. In this verification process, when performing a swap test to compare two unknown quantum states, based on whether the statistical error rate obtained through comparisons of quantum state matching corresponding to the length of a message qubit sequence of n (e.g., a sufficiently large number) exceeds a threshold (e.g., the comparison error rate occurring when comparing quantum state information of the same n-qubit sequence; the error rate decreases as n increases), This is set to 0 or 1.

[0297] In operation V9, the mediator (2030) retrieves the primary qubit message recovered in operation S11. Random number for Message validation arguments through unitary conversion operations using Generates. In operation V10, the mediator (2030) performs message verification using message verification parameters, and the message verification result Generates. In operation V11, the mediator (2030) provides second transmission information as information necessary for determining the verification result of Bob (2020). Generates. In operation V12, the mediator (2030) generates the second transmission information Sends to Bob (2020).

[0298] In operation V13, Bob (2020) decodes the factors required for verification judgment By doing so, the second qubit message , signature verification result and message verification results ...is obtained. In operation V14, Bob (2020) determines whether the signature verification passes using the information received from the mediator (2030). If the signature verification passes, in operation V15, Bob (2020) provides the mediator (2030) with random number information for message recovery. Requests. In operation V16, the mediator (2030) gives Bob (2020) random number information The mediator (2030) that received the request for random number information from Bob (2020) is the entity that performed the verification, so if the verification result is all 1, the random number information generated by itself in operation S1 It transmits to Bob (2020). In operation V17, Bob (2020) receives the random number information received from the mediator (2030). 1st qubit message using It recovers the first qubit message. That is, Bob (2020) recovers the first qubit message by performing the inverse transformation of the unitary transformation operation on the second qubit message.

[0299]

[0300] FIGS. 21a to 21c illustrate examples of operations of a sender, a receiver, and an arbitrator according to a quantum signature technique that uses a Bell state and distributes state particles between an arbitrator and a receiver, as an arbitrator-based message recovery type quantum signature technique according to an embodiment of the present disclosure. In FIGS. 21a to 21c, Alice (2010) performs the role of a message creator, Bob (2020) performs the role of a verifier, and the arbitrator (2030) is located as an intermediate connection path existing between the sender and the receiver and performs the roles of signature creation and verification, generation and transmission of random number information to ensure message confidentiality, and receiving the message created by the sender. In the flowchart, I represents the initial stage, S represents the signature creation stage, and V represents the signature verification stage, respectively.

[0301]

[0302] [Example #2-2] Quantum signature technique with a structure for distributing Bell state particles between senders and receivers participating in the signature

[0303] Example #2-2 relates to a mediator-based message recovery quantum signature technique using a Bell state that can be applied when there is no direct connection path between the sender and the receiver. In this embodiment, unlike Example #2-1, the mediator (2230) distributes one of the two particles constituting the Bell state generated by the mediator (2230) to Alice (2210) and Bob (2220), respectively. The quantum signature according to Example #2-2 is performed as follows.

[0304] (1) Initial stage

[0305] FIG. 22a illustrates an initial step of a method for distributing Bell state particles between a sender and a receiver, in a mediator-based message recovery quantum signature technique using a Bell state according to an embodiment of the present disclosure. Referring to FIG. 22a, in a situation where there is no direct connection channel between Alice (2210) and Bob (2220), Alice (2210) and the mediator (2230) [use] a first secret symmetric key according to the QKD protocol They share. Similarly, Bob (2220) and the mediator (2230) use a mutually connected channel to share a second secret symmetric key according to the QKD protocol. It shares the secret key. In addition, the mediator (2230) uses the secret key in the signature verification process. Generates a secret key It is held by the mediator (2230) and may not be shared with other devices. In this embodiment, the mediator (e.g., TTP) distributes one of the two particles constituting the bell state generated by the mediator to Alice (2210) and the other particle to Bob (2220).

[0306] (2) Quantum signature generation step:

[0307] FIGS. 22b and 22c illustrate a quantum signature generation step in which Bell state particles are distributed between a sender and a receiver, as a mediator-based message recovery type quantum signature technique using Bell state according to an embodiment of the present disclosure. According to Example #2-2, when BSM measurement is performed using a message generated by a sender and Bell state particles, it can be guaranteed that a signature was generated from the sender's message based on the fact that the state of the Bell state particles of the mediator and the receiver used for signature and message verification is determined. The detailed procedure of the message recovery type quantum signature technique utilizing these characteristics is as follows.

[0308] Referring to FIGS. 22b and 22c, in operation S1, Alice (2210) has a primary qubit message containing n qubits. Creates 4 copies of. Here, is. In operation S2, Alice (2210) receives the first particle in the Bell state from the mediator (2230). is received. In operation S3, Alice (2210) receives the acquired information, specifically and Perform BSM based on, and the measurement results Saves. In operation S4, Alice (2210) saves the signature start information to ensure message confidentiality. Generates. In operation S5, Alice (2210) gives the signature start information to the mediator (2230). transmits.

[0309] In operation S6, the mediator (2230) receives signature initiation information Receive and decrypt By doing so and Acquires. In operation S7, the mediator (2230) obtains a random number Generate and the first qubit message Random number for Secondary qubit message through unitary conversion operation using Creates two copies of. In operation S8, the mediator (2230) verifies the verification factor for signature verification. Generates. In operation S9, the mediator (2230) encrypts the secondary qubit message and verification factor using the first secret symmetric key to generate signature information. Creates.

[0310] In operation S10, the mediator (2230) gives Bob (2220) signature information transmits.

[0311] (3) Quantum signature verification step:

[0312] FIG. 22d illustrates a quantum signature verification and message recovery method using a Bell state mediator-based message recovery quantum signature technique according to one embodiment of the present disclosure, which distributes Bell state particles between a sender and a receiver. In the signature verification step, a mediator (2230) obtains the parameters required for verification, performs verification, and based on the results, Bob (2220) performs a judgment, and the detailed process is as follows.

[0313] Referring to FIG. 22d, in operation V1, Bob (2220) is signature information and the second particle in the bell state is received from the mediator (2230). In operation V2, Bob (2220) receives the received information, specifically, signature information. and the second particle is the second secret symmetric key The first transmission information by encrypting it Generates. In operation V3, Bob (2220) is the first transfer information It transmits to the mediator (2230).

[0314] In operation V4, the mediator (2230) receives the first transmission information. is the second secret symmetric key Decrypt using By doing so, signature information and the second particle Acquires. In operation V5, the mediator (2230) obtains the signature information obtained through decryption. Decode By doing so, the second qubit message and validation factors Acquires. In operation V6, the mediator (2230) obtains the second particle from 1st qubit message using Restores. The restoration rules for this are as shown in [Table 7] below.

[0315] message Operators required for recovery | Z Z XZ

[0316] In operation V7, the mediator (2230) is the signature verification factors and It generates. Specifically, the mediator (2230) generates a primary qubit message Random number for Unitary conversion operation using Through the first signature verification factor It generates. In addition, the mediator (2230) verifies information Decrypt using the secret key of the mediator (2230). By doing so, the second signature verification factor Generates. In operation V8, the arbitrator (2230) performs verification of the signature, and the signature verification result Generates. In this verification process, when performing a swap test to compare two unknown quantum states, based on whether the statistical error rate obtained through comparisons of quantum state matching corresponding to the length of a message qubit sequence of n (e.g., a sufficiently large number) exceeds a threshold (e.g., the comparison error rate occurring when comparing quantum state information of the same n-qubit sequence; the error rate decreases as n increases), This is set to 0 or 1. In operation V9, the mediator (2230) receives the recovered primary qubit message generated in operation S6. Based on It generates parameters to be used for message verification. That is, the mediator (2230) generates the primary qubit message recovered in operation S6. Random number for Message validation arguments through unitary conversion operations using Generates. In operation V10, the mediator (2230) performs message verification using message verification parameters, and the message verification result Generates. In operation V11, the mediator (2230) provides the second transmission information necessary for determining the verification result of Bob (2220). It generates. Specifically, the mediator (2230) generates second transmission information by encrypting the second qubit message, the signature verification result, and the message verification result using the second secret symmetric key. In operation V12, the mediator (2230) generates the second transmission information Sends to Bob (2220).

[0317] In operation V13, Bob (2220) decodes the second transmission information By doing so, the second qubit message , signature verification result and message verification results ...is obtained. In operation V14, Bob (2220) determines whether the signature verification passes using the signature verification result received from the mediator (2230). If the signature verification passes, in operation V15, Bob (2220) provides the mediator (2230) with random number information for message recovery. Requests. In operation V16, the mediator (2230) gives Bob (2220) random number information The mediator (2230) that received the request for random number information from Bob (2220) is the entity that performed the verification, so if the verification result is all 1, the random number information generated by itself in operation S1 It transmits to Bob (2220). In operation V17, Bob (2220) receives the random number information received from the mediator (2230). Message recovery process using ...is performed. That is, Bob (2220) recovers the first qubit message by performing the inverse transformation of the unitary transformation operation on the second qubit message.

[0318]

[0319] FIGS. 23a to 23c illustrate examples of operations of a sender, a receiver, and an arbitrator according to a quantum signature technique that uses a Bell state and distributes state particles between an arbitrator and a receiver, as an arbitrator-based message recovery type quantum signature technique according to one embodiment of the present disclosure. In FIGS. 23a to 23c, Alice (2210) performs the role of a message creator, Bob (2220) performs the role of a verifier, and the arbitrator (2230) is located as an intermediate connection path existing between the sender and the receiver and performs the roles of signature creation and verification, generation and transmission of random number information to ensure message confidentiality, and receiving the message created by the sender. In the flowchart, I represents the initial stage, S represents the signature creation stage, and V represents the signature verification stage, respectively.

[0320]

[0321] FIG. 24 illustrates an example of a procedure in which a sender requests the generation of signature information according to an arbitrator-based message recovery type quantum signature technique according to one embodiment of the present disclosure. FIG. 24 illustrates a method performed by a device requesting the generation of signature information (e.g., Alice (1610), Alice (1810), Alice (2010), Alice (2210), or terminal), and the subject of the operation is referred to as the first device.

[0322] Referring to FIG. 24, in step S2401, the first device performs an initial connection procedure. Specifically, the first device may perform synchronization by detecting a synchronization signal from a base station, receive system information, and perform a random access channel (RACH) procedure. The RACH procedure may include a 4-stage RACH procedure or a 2-stage RACH procedure. In the RACH procedure, the first device may transmit a RACH preamble and receive a random access response (RAR) message.

[0323] In step S2403, the first device establishes a connection. Specifically, the first device establishes a connection with a base station (e.g., an RRC connection) and may establish a connection with at least one core network entity (e.g., a NAS (non-access stratum) connection). Through this, the first device obtains a classic channel with a third device (e.g., an arbitrator device) or obtains the foundational connection required to subsequently establish a classic channel.

[0324] In step S2405, the first device transmits capability information. Prior to transmitting the capability information, the first device may receive a message requesting capability information. The capability information may include information regarding hardware or software capabilities related to the performance of communication by the first device, and information regarding procedures, functions, or features supported by the first device. In this case, according to various embodiments of the present disclosure, the capability information may include information indicating support for enhanced authentication functions using quantum signatures, in particular, mediator-based quantum signatures in situations where there is no direct path.

[0325] In step S2407, the first device establishes a quantum channel. The quantum channel is a channel capable of transmitting quantum information (e.g., qubits) and can be established by synchronizing an optical transmitter and an optical receiver. The quantum channel can take the form of a wireless or wired connection. A quantum channel in the form of a wired connection can be implemented as a wired optical fiber-based channel. For example, the first device may receive configuration information or control information necessary for establishing the quantum channel through a classical channel from a base station, a core network, etc., and establish the quantum channel based on the received configuration information or control information. At this time, if the quantum channel is established to perform a quantum signature procedure with the second device, the first device may share a secret symmetric key with the third device.

[0326] In step S2409, the first device generates signature initiation information and transmits the signature initiation information. Specifically, the first device may generate a plurality of primary qubit messages containing qubits and generate signature initiation information based on the plurality of primary qubit messages. According to one embodiment, the first device may generate signature initiation information by decrypting information obtained from the third device to obtain random number information determined by the third device, generate a secondary qubit message from the primary qubit message using the random number information, generate a tertiary qubit message by encrypting the secondary qubit message, and generate signature initiation information by encrypting at least one secondary qubit message and at least one tertiary qubit message. According to another embodiment, the first device may generate signature initiation information by generating a plurality of primary qubit messages, obtaining a particle in a GHZ state or a Bell state, and encrypting the measurement result for the particle and at least one primary qubit message.

[0327]

[0328] FIG. 25 illustrates an example of a procedure in which a mediator performs a quantum signature according to a mediator-based message recovery quantum signature technique according to one embodiment of the present disclosure. FIG. 25 illustrates a method performed by a device mediating a quantum signature (e.g., a mediator (1630), a mediator (1830), a mediator (2030), a mediator (2230), or a certification authority server), and the subject of the operation is referred to as a third device.

[0329] Referring to FIG. 25, in step S2501, the third device receives signature initiation information requesting the generation of quantum signature information from the first device (e.g., Alice (1610), Alice (1810), or terminal). The signature initiation information includes at least one qubit message containing qubits and may be received via a quantum channel. At this time, the at least one qubit message may be received in an encrypted state using a first secret symmetric key shared between the third device and the first device. Although not illustrated in FIG. 25, according to one embodiment, prior to receiving the signature initiation information, the third device may generate random number information and transmit the random number information encrypted using a first secret symmetric key shared between the first device and the third device to the first device.

[0330] In step S2503, the third device transmits signature information generated based on signature initiation information to the second device. That is, the third device can obtain quantum information elements by decrypting signature initiation information received from the first device, generate signature information based on the obtained quantum information elements, and transmit the signature information to the second device. According to one embodiment, the third device can obtain at least one secondary qubit message and at least one tertiary qubit message from signature initiation information, generate a verification factor by encrypting the tertiary qubit message, and generate signature information by encrypting at least one secondary qubit message and the verification factor using a first secret symmetric key. According to another embodiment, the third device can obtain at least one primary qubit message from signature initiation information, generate at least one secondary qubit message from the primary qubit message using random number information, generate a verification factor by encrypting at least one secondary qubit message, and generate signature information by encrypting at least one secondary qubit message and the verification factor using a first secret symmetric key.

[0331] In step S2505, the third device receives first transmission information from the second device. The first transmission information is quantum information generated by the second device based on the signature information transmitted in step S2503, and can be received through a quantum channel. Here, the first transmission information includes quantum information encrypted using a second secret symmetric key.

[0332] In step S2507, the third device performs signature verification and message verification based on the first transmission information. The third device can obtain quantum information elements included in the first transmission information by decoding the first transmission information. Here, the first transmission information includes quantum information elements (e.g., signature information, GHZ state or Bell state particles) transmitted from the third device to the second device, and the third device can perform signature verification and message verification based on the quantum information elements included in the first transmission information. The second device can generate a first verification result and a second verification result indicating the results of the signature verification and message verification.

[0333] In step S2509, the third device transmits second transmission information including the results of signature verification and message verification. The second transmission information may include the first verification result and the second verification result, and furthermore, may further include at least one secondary qubit message. Here, the secondary qubit message included in the second transmission information may be generated through a unitary conversion operation using random number information from the third device.

[0334] In step S2511, the third device transmits random number information based on a request from the second device. When a request for random number information is received from the second device that has received the second transmission information, the third device may transmit random number information to the second device. The random number information may be used by the second device to recover a secondary qubit message included in the second transmission information.

[0335]

[0336] FIG. 26 illustrates an example of a procedure in which a recipient performs a signature according to an arbitrator-based message recovery type quantum signature technique according to one embodiment of the present disclosure. FIG. 26 illustrates a method performed by a device that verifies signature information (e.g., Bob (1620), Bob (1820), Bob (2020), Bob (2220), or a core network entity), and the subject of the operation is referred to as a second device.

[0337] Referring to FIG. 26, in step S2601, the second device receives signature information from the third device. The signature information is quantum information encrypted using a first secret symmetric key shared between the first device and the third device, and is derived from a qubit message generated by the first device. According to one embodiment, the signature information may include a second qubit message and a verification factor which is the result of encrypting the second qubit message using the secret key of the third device.

[0338] In step S2603, the second device transmits first transmission information generated based on signature information. According to various embodiments, the second device may generate first transmission information by acquiring a GHZ state or Bell state particle and encrypting the acquired particle and signature information using a second secret symmetric key.

[0339] In step S2605, the second device receives second transmission information including results of signature verification and message verification performed based on the first transmission information. The second transmission information may include a first verification result and a second verification result indicating results of signature verification and message verification performed by the third device, and at least one quantum information element. According to various embodiments, the other at least one quantum information element may include a second qubit message generated through a unitary transformation operation using random number information for a first qubit message.

[0340] In step S2607, the second device obtains random number information based on the second transmission information. Specifically, the second device obtains quantum information elements included in the second transmission information, namely the first verification result and the second verification result, by decrypting the second transmission information using the second secret symmetric key. If both the first verification result and the second verification result indicate a successful verification, the second device requests random number information from the third device and can receive the random number information.

[0341] In step S2609, the second device recovers the qubit message based on random number information. That is, the second device can obtain the first qubit message through the inverse transformation of a unitary transformation operation using random number information for the second qubit message included in the second transmission information.

[0342]

[0343] The security of the mediator-based quantum signature technique according to the present disclosure is as follows.

[0344] Impossible to forge: If the attacker Eve attempts to forge the signature, Eve uses the secret symmetric key shared in the initial stage through QKD. and ...must know it. However, due to the perfect secrecy of QKD, key information cannot be viewed. Furthermore, if the signature is forged, the parameters used by the arbitrator for signature verification cannot be correctly generated, making it impossible to pass verification. Meanwhile, even if Bob attempts to forge it, Bob [can] the arbitrator's unique secret key generated by the arbitrator from the random number generator Since it is impossible to know, it is impossible to manipulate the factors used for signature verification. Therefore, it is impossible to forge Bob's signature.

[0345] Message Confidentiality Can Be Ensured: Since the proposed method is a message recovery-type quantum signature technique, it encrypts and transmits the message using a secret symmetric key and random number information during the information transfer process between all signature components. Therefore, message exposure is prevented, thereby ensuring message confidentiality. Specifically, in the path from Alice to the mediator, the secret symmetric key Sends an encrypted message, and the arbitrator and Bob use the arbitrator's random number and the secret symmetric key Since encrypted messages are transmitted, message confidentiality can be ensured.

[0346] Prevention of Sender's Denial of Dispatch: If a situation of sender denial arises where Alice claims she did not send signature information, the denial can be refuted through the following process. According to the proposed technology, the message sent by Alice is encrypted using Alice's private key and sent to the arbitrator; the information is then re-encrypted using the arbitrator's exclusive private key and transmitted via signature; finally, the arbitrator receives the signature information back from Bob and performs signature verification. In this process, the arbitrator's signature verification passing implies that the arbitrator decrypted the verification information using the same private key shared with Alice and used the original information sent by Alice for verification; therefore, if the verification passes, sender denial of dispatch is impossible.

[0347] Non-repudiation of the recipient: If Bob claims he never received a signature, the denial of receipt can be refuted through the following process. According to the proposed technology, an arbitrator [uses] Bob's private key to the information received by Bob. Verification is performed using the information that is encrypted and re-transmitted to the mediator, and the decrypted information. In this process, if the verification passes, it can be seen that Bob received the information, encrypted it with the same secret symmetric key as the mediator, and sent it back to the mediator.

[0348] Prevention of Denial of Service (DOS) Attacks Caused by False Denial by the Recipient: In existing quantum signature techniques, message verification and determination are performed by the recipient. Consequently, if the recipient determines that the signature has failed verification, no one participating in the signing process—excluding the recipient—can accurately determine whether the cause is an actual discrepancy between the two message qubits compared during the verification process or if the recipient is intentionally manipulating the verification results to make a false denial. This vulnerability can be exploited to intercept the received message without passing it through the signature process. However, the proposed technique adopts a method where an arbitrator performs the message verification and sends only the result to the recipient, allowing the recipient to decide whether the verification was passed. Through this approach, if the recipient makes a false denial, the arbitrator can determine whether the recipient is making a false denial based on their own verification results, thereby preventing false denial by the recipient. In addition, to block DOS attacks aimed at message theft through false denial, if the arbitrator determines that the recipient has made a false denial, the arbitrator does not provide random number information capable of decrypting the recipient's encrypted message, thereby blocking the recipient's false denial attack.

[0349] In addition to the aforementioned effects, existing mediator-based quantum signature techniques utilizing entanglement resources such as GHZ states or Bell states could only operate when a direct connection path existed between the sender and the receiver; signature and message information were exchanged directly through this connection path, and the mediator performed only the role of assisting in the receiver's signature verification. However, there may be situations where quantum electronic signatures must be performed even when a direct channel connection between the sender and the receiver is not established. Accordingly, the present disclosure proposes a method for performing entanglement-based quantum signatures between a sender and a receiver by applying the mediator as an intermediary connector in situations where a direct channel connection is not established between the sender and the receiver, and demonstrates that message confidentiality can be secured along with the functions of electronic signatures, such as authentication, forgery, and non-repudiation, even in such a connection environment.

[0350]

[0351] The quantum signature technique using the aforementioned quantum entanglement can be utilized in various ways. For example, use cases of the quantum signature technique according to various embodiments of the present disclosure are as follows.

[0352] FIG. 27 illustrates an example of quantum key distribution (QKD) technology to which a quantum signature technique according to one embodiment of the present disclosure is applied. FIG. 27 illustrates the structure of a quantum cryptographic communication system applying QKD, which is being standardized by ETSI and ITU-T SG 13 and 17, and exemplifies a case where quantum signature technology is applied as a technology for authentication, non-repudiation, and anti-forgery of the sender and receiver during the secret key transmission process of QKD. Quantum cryptographic communication technology generates a secret symmetric key to be used for the encryption and decryption of plaintext in a quantum mechanically secure manner using QKD technology, and performs message encryption and decryption using the secret symmetric key. Here, the quantum signature technique according to various embodiments of the present disclosure may be adopted as at least part of the authentication operation, which is one of the post-processing steps in the overall QKD procedure. While existing authentication techniques are limited to user and message authentication, applying the quantum signature technique according to various embodiments of the present disclosure to the authentication operation can secure additional functions such as non-repudiation of the sender and receiver, message integrity, and anti-forgery, in addition to existing authentication.

[0353] However, since existing authentication methods use the classical Wegman-Carter authentication method, they use only the public channel, whereas the quantum signature method according to the present disclosure uses both the quantum channel and the public channel. In FIG. 27, the quantum signature method according to the present disclosure may be performed before or after a preprocessing process in the quantum domain (2702) (e.g., a process of generating random quantum information at the sender and completing random measurements at the receiver to generate a raw key). Then, in the public domain (2704), when the signature operation according to the quantum signature method according to the present disclosure is completed within the authentication operation (2701), a postprocessing process for the raw key information (e.g., a procedure to obtain a final secret symmetric key through operations ranging from sifting to privacy amplification) is performed.

[0354]

[0355] FIG. 28 illustrates an example of Quantum Secure Direct Communication (QSDC) to which a quantum signature technique according to one embodiment of the present disclosure is applied. FIG. 28 illustrates a structure of a QSDC technique that can securely transmit messages directly over a quantum channel based on quantum mechanics without using a secret key, and exemplifies a case where a quantum signature technique is applied as an authentication, non-repudiation, and anti-forgery technique for a sender and receiver exchanging messages in the QSDC.

[0356] A general QSDC technique performs object authentication and message authentication for the sending and receiving entities through a public channel. When applying the quantum signature technique according to the present disclosure, the quantum information transmitted for security verification through a quantum channel is measured in the quantum domain (2802), and the quantum signature technique according to the present disclosure may be applied to an authentication operation (2801) prior to a parameter estimation operation using some of the measured quantum information in the classical domain (2804). In this process, if the quantum signature is passed, operations such as parameter estimation and message encoding are performed sequentially, and the information that has passed the signature process can secure authentication, anti-forgery, non-repudiation, and message integrity.

[0357]

[0358] Existing arbitrator-based quantum signature techniques have all considered only cases where a direct connection exists between the sender and receiver, allowing for the direct exchange of signature and message information, with the TTP serving to assist in the receiver's verification. However, there may be situations where quantum electronic signatures must be performed even when a direct channel connection between the sender and receiver is not established. Therefore, this disclosure proposes a method for performing quantum signatures between a sender and receiver by applying a TTP as an intermediary in situations where a direct channel is not established, and demonstrates that this enables the securing of message confidentiality in addition to the functions of electronic signatures, such as authentication, forgery, and non-repudiation.

[0359]

[0360] Hereinafter, examples of wireless device applications to which various embodiments of the present disclosure are applied will be described.

[0361] FIG. 29 illustrates an example of a wireless device applicable to the present disclosure. The wireless device may be implemented in various forms depending on the use—example / service (see FIG. 1).

[0362] Referring to FIG. 29, the wireless device (200) corresponds to the wireless device (200) of FIG. 2 and may be composed of various elements, components, units / parts, and / or modules. For example, the wireless device (200) may include a communication unit (210), a control unit (220), a memory unit (230), and additional elements (240). The communication unit may include a communication circuit (212) and transceiver(s) (214). For example, the communication circuit (212) may include one or more processors (202) and / or one or more memories (204) of FIG. 2. For example, the transceiver(s) (214) may include one or more transceivers (206) and / or one or more antennas (208) of FIG. 2. The control unit (220) is electrically connected to the communication unit (210), the memory unit (230), and additional elements (240) and controls the overall operation of the wireless device. For example, the control unit (220) can control the electrical / mechanical operation of the wireless device based on a program / code / command / information stored in the memory unit (230). Additionally, the control unit (220) can transmit information stored in the memory unit (230) to an external entity (e.g., another communication device) via a wireless / wired interface through the communication unit (210), or store information received from an external entity (e.g., another communication device) via a wireless / wired interface through the communication unit (210) in the memory unit (230).

[0363] The additional element (240) may be configured in various ways depending on the type of wireless device. For example, the additional element (240) may include at least one of a power unit / battery, an input / output unit (I / O unit), a driving unit, and a computing unit. Although not limited thereto, the wireless device may be implemented in the form of a robot (Fig. 1, 100a), a vehicle (Fig. 1, 100b-1, 100b-2), an XR device (Fig. 1, 100c), a portable device (Fig. 1, 100d), a home appliance (Fig. 1, 100e), an IoT device (Fig. 1, 100f), a digital broadcasting terminal, a holographic device, a public safety device, an MTC device, a medical device, a fintech device (or financial device), a security device, a climate / environment device, an AI server / device (Fig. 1, 400), a base station (Fig. 1, 200), a network node, etc. Depending on the use—e.g., service—the wireless device may be movable or used in a fixed location.

[0364] In FIG. 29, various elements, components, units / parts, and / or modules within the wireless device (200) may be entirely interconnected via a wired interface, or at least some of them may be wirelessly connected via a communication unit (210). For example, within the wireless device (200), the control unit (220) and the communication unit (210) may be wired, and the control unit (220) and the first unit (e.g., 230, 240) may be wirelessly connected via the communication unit (210). Additionally, each element, component, unit / part, and / or module within the wireless device (200) may include one or more additional elements. For example, the control unit (220) may be composed of one or more sets of processors. For example, the control unit (220) may be composed of a set of a communication control processor, an application processor, an Electronic Control Unit (ECU), a graphics processing processor, a memory control processor, etc. As another example, the memory unit (130) may be composed of RAM (Random Access Memory), DRAM (Dynamic RAM), ROM (Read Only Memory), flash memory, volatile memory, non-volatile memory and / or a combination thereof.

[0365] Hereinafter, an implementation example of FIG. 29 will be described in more detail with reference to the drawings.

[0366] FIG. 30 illustrates an example of a portable device applicable to the present disclosure. The portable device may include a smartphone, a smartpad, a wearable device (e.g., a smartwatch, smart glasses), or a portable computer (e.g., a laptop). The portable device may be referred to as a Mobile Station (MS), a User Terminal (UT), a Mobile Subscriber Station (MSS), a Subscriber Station (SS), an Advanced Mobile Station (AMS), or a Wireless Terminal (WT).

[0367] Referring to FIG. 30, the portable device (200) may include an antenna unit (208), a communication unit (210), a control unit (220), a memory unit (230), a power supply unit (240a), an interface unit (240b), and an input / output unit (240c). The antenna unit (208) may be configured as part of the communication unit (210). Blocks 210 to 230 / 240a to 240c of FIG. 30 correspond to blocks 210 to 230 / 240 of FIG. 29, respectively.

[0368] The communication unit (210) can transmit and receive signals (e.g., data, control signals, etc.) with other wireless devices and base stations. The control unit (220) can control the components of the portable device (200) to perform various operations. The control unit (220) may include an AP (Application Processor). The memory unit (230) can store data / parameters / programs / code / commands required for the operation of the portable device (200). Additionally, the memory unit (230) can store input / output data / information, etc. The power supply unit (240a) supplies power to the portable device (200) and may include wired / wireless charging circuits, batteries, etc. The interface unit (240b) can support the connection between the portable device (200) and other external devices. The interface unit (240b) may include various ports (e.g., audio input / output ports, video input / output ports) for connection with external devices. The input / output unit (240c) can receive or output video information / signals, audio information / signals, data, and / or information input by a user. The input / output unit (240c) may include a camera, a microphone, a user input unit, a display unit (240d), a speaker and / or a haptic module, etc.

[0369] For example, in the case of data communication, the input / output unit (240c) acquires information / signals (e.g., touch, text, voice, image, video) input by the user, and the acquired information / signals can be stored in the memory unit (230). The communication unit (210) converts the information / signals stored in the memory into wireless signals and can directly transmit the converted wireless signals to another wireless device or to a base station. Additionally, the communication unit (210) can receive wireless signals from another wireless device or base station and then restore the received wireless signals to their original information / signals. The restored information / signals can be stored in the memory unit (230) and then output in various forms (e.g., text, voice, image, video, haptic) through the input / output unit (240c).

[0370] FIG. 31 illustrates an example of a vehicle or autonomous vehicle applicable to the present disclosure. The vehicle or autonomous vehicle may be implemented as a mobile robot, a vehicle, a train, an aerial vehicle (AV), a ship, etc.

[0371] Referring to FIG. 31, a vehicle or autonomous vehicle (200-1) may include an antenna unit (208-1), a communication unit (210-1), a control unit (220-1), a driving unit (240a-1), a power supply unit (240b-1), a sensor unit (240c-1), and an autonomous driving unit (240d-1). The antenna unit (208-1) may be configured as part of the communication unit (210-1). Blocks 210-1 / 230-1 / 240a-1 to 240d-1 of FIG. 31 correspond to blocks 210 / 230 / 240 of FIG. 29, respectively.

[0372] The communication unit (210-1) can transmit and receive signals (e.g., data, control signals, etc.) with external devices such as other vehicles, base stations (e.g., base stations, roadside base stations (Road Side Unit), etc.), and servers. The control unit (220-1) can perform various operations by controlling elements of the vehicle or autonomous vehicle (200-1). The control unit (220-1) may include an Electronic Control Unit (ECU). The driving unit (240a-1) can drive the vehicle or autonomous vehicle (200-1) on the ground. The driving unit (240a-1) may include an engine, motor, power train, wheels, brakes, steering device, etc. The power supply unit (240b-1) supplies power to the vehicle or autonomous vehicle (200-1) and may include wired / wireless charging circuits, batteries, etc. The sensor unit (240c-1) can obtain vehicle status, surrounding environment information, user information, etc. The sensor unit (240c-1) may include an IMU (inertial measurement unit) sensor, a collision sensor, a wheel sensor, a speed sensor, an inclination sensor, a weight detection sensor, a heading sensor, a position module, a vehicle forward / reverse sensor, a battery sensor, a fuel sensor, a tire sensor, a steering sensor, a temperature sensor, a humidity sensor, an ultrasonic sensor, an illuminance sensor, a pedal position sensor, etc. The autonomous driving unit (240d-1) may implement technologies such as maintaining the driving lane, technologies for automatically adjusting speed such as adaptive cruise control, technologies for automatically driving along a predetermined path, and technologies for automatically setting a path and driving when a destination is set.

[0373] For example, the communication unit (210-1) can receive map data, traffic information data, etc. from an external server. The autonomous driving unit (240d-1) can generate an autonomous driving path and a driving plan based on the acquired data. The control unit (220-1) can control the drive unit (240a-1) so that the vehicle or the autonomous vehicle (200-1) moves along the autonomous driving path according to the driving plan (e.g., speed / direction control). During autonomous driving, the communication unit (210-1) can acquire the latest traffic information data from an external server non-periodically and can acquire surrounding traffic information data from surrounding vehicles. Additionally, during autonomous driving, the sensor unit (240c-1) can acquire vehicle status and surrounding environment information. The autonomous driving unit (240d-1) can update the autonomous driving path and the driving plan based on the newly acquired data / information. The communication unit (210-1) can transmit information regarding the vehicle location, autonomous driving path, driving plan, etc. to an external server. An external server can predict traffic information data in advance using AI technology, etc., based on information collected from vehicles or autonomous vehicles, and can provide the predicted traffic information data to vehicles or autonomous vehicles. If the device (220-2) is an autonomous vehicle, it can perform the same procedure as the vehicle or autonomous vehicle (200-1). In addition, if the device (220-2) is a base station or a roadside base station, the device (220-2) can transmit data and control signals to the vehicle or autonomous vehicle (200-1) through the communication unit (210-2).

[0374] FIG. 32 illustrates an example of a vehicle applicable to the present disclosure. The vehicle may be implemented as a means of transport, a train, an aircraft, a ship, etc. Referring to FIG. 32, the vehicle (200) may include a communication unit (210), a control unit (220), a memory unit (230), an input / output unit (240a), and a position measurement unit (240b). Here, blocks 210 to 230 / 240a to 240b correspond to blocks 210 to 230 / 240 of FIG. 29, respectively.

[0375] The communication unit (210) can transmit and receive signals (e.g., data, control signals, etc.) with other vehicles or external devices such as base stations. The control unit (220) can control the components of the vehicle (200) to perform various operations. The memory unit (230) can store data / parameters / programs / codes / commands that support various functions of the vehicle (100). The input / output unit (240a) can output AR / VR objects based on information within the memory unit (230). The input / output unit (240a) may include a HUD. The position measurement unit (240b) can acquire position information of the vehicle (200). The position information may include absolute position information of the vehicle (200), position information within the driving line, acceleration information, position information relative to surrounding vehicles, etc. The position measurement unit (240b) may include GPS and various sensors.

[0376] For example, the communication unit (210) of the vehicle (200) can receive map information, traffic information, etc. from an external server and store it in the memory unit (230). The location measurement unit (240b) can acquire vehicle location information through GPS and various sensors and store it in the memory unit (230). The control unit (220) creates a virtual object based on map information, traffic information, and vehicle location information, etc., and the input / output unit (240a) can display the created virtual object on the glass window inside the vehicle (240a-1, 240a-2). In addition, the control unit (220) can determine whether the vehicle (200) is operating normally within the driving line based on the vehicle location information. If the vehicle (200) deviates abnormally from the driving line, the control unit (220) can display a warning on the glass window inside the vehicle through the input / output unit (240a). Additionally, the control unit (220) can broadcast a warning message regarding a driving abnormality to surrounding vehicles through the communication unit (210). Depending on the situation, the control unit (220) can transmit the vehicle's location information and information regarding the driving / vehicle abnormality to relevant authorities through the communication unit (210).

[0377] FIG. 33 illustrates an example of an XR device applicable to the present disclosure. The XR device may be implemented as an HMD, a Head-Up Display (HUD) equipped in a vehicle, a television, a smartphone, a computer, a wearable device, a home appliance, digital signage, a vehicle, a robot, etc.

[0378] Referring to FIG. 33, the XR device (200a) may include a communication unit (210), a control unit (220), a memory unit (230), an input / output unit (240a), a sensor unit (240b), and a power supply unit (240c). Here, blocks 210 to 230 / 240a to 240c of FIG. 33 correspond to blocks 210 to 230 / 240 of FIG. 29, respectively.

[0379] The communication unit (210) can transmit and receive signals (e.g., media data, control signals, etc.) with external devices such as other wireless devices, mobile devices, or media servers. The media data may include video, images, sound, etc. The control unit (220) can control the components of the XR device (200a) to perform various operations. For example, the control unit (220) may be configured to control and / or perform procedures such as video / image acquisition, (video / image) encoding, metadata generation, and processing. The memory unit (230) may store data / parameters / programs / code / commands required for driving the XR device (200a) or creating an XR object. The input / output unit (240a) acquires control information, data, etc. from the outside and can output the created XR object. The input / output unit (240a) may include a camera, microphone, user input unit, display unit, speaker and / or haptic module, etc. The sensor unit (240b) can obtain XR device status, surrounding environment information, user information, etc. The sensor unit (240b) may include a proximity sensor, an illuminance sensor, an accelerometer, a magnetic sensor, a gyroscope, an inertial sensor, an RGB sensor, an IR sensor, a fingerprint recognition sensor, an ultrasonic sensor, a light sensor, a microphone and / or radar, etc. The power supply unit (240c) supplies power to the XR device (200a) and may include a wired / wireless charging circuit, a battery, etc.

[0380] For example, the memory unit (230) of the XR device (200a) may contain information (e.g., data, etc.) necessary for creating an XR object (e.g., AR / VR / MR object). The input / output unit (240a) may receive a command to operate the XR device (200a) from the user, and the control unit (220) may operate the XR device (200a) according to the user's operation command. For example, if the user intends to watch movies, news, etc. through the XR device (200a), the control unit (220) may transmit content signature start information to another device (e.g., mobile device (200b)) or a media server through the communication unit (230). The communication unit (230) may download / stream content such as movies, news, etc. from another device (e.g., mobile device (200b)) or a media server to the memory unit (230). The control unit (220) controls and / or performs procedures such as video / image acquisition, (video / image) encoding, and metadata generation / processing for the content, and can generate / output an XR object based on information about the surrounding space or real object acquired through the input / output unit (240a) / sensor unit (240b).

[0381] Additionally, the XR device (200a) is wirelessly connected to the mobile device (200b) through the communication unit (210), and the operation of the XR device (200a) can be controlled by the mobile device (200b). For example, the mobile device (200b) can act as a controller for the XR device (200a). To this end, the XR device (200a) can acquire three-dimensional position information of the mobile device (200b), and then generate and output an XR object corresponding to the mobile device (200b).

[0382] FIG. 34 illustrates an example of a robot applicable to the present disclosure. Robots may be classified into industrial, medical, domestic, military, etc., depending on the purpose or field of use.

[0383] Referring to FIG. 34, the robot (200) may include a communication unit (210), a control unit (220), a memory unit (230), an input / output unit (240a), a sensor unit (240b), and a driving unit (240c). Here, blocks 210 to 230 / 240a to 240c of FIG. 34 correspond to blocks 210 to 230 / 240 of FIG. 29, respectively.

[0384] The communication unit (210) can transmit and receive signals (e.g., driving information, control signals, etc.) with external devices such as other wireless devices, other robots, or control servers. The control unit (220) can control the components of the robot (200) to perform various operations. The memory unit (230) can store data / parameters / programs / codes / commands that support various functions of the robot (200). The input / output unit (240a) can acquire information from outside the robot (200) and output information to outside the robot (200). The input / output unit (240a) may include a camera, microphone, user input unit, display unit, speaker and / or haptic module, etc. The sensor unit (240b) can obtain internal information of the robot (200), surrounding environment information, user information, etc. The sensor unit (240b) may include a proximity sensor, an illuminance sensor, an accelerometer, a magnetic sensor, a gyroscope, an inertial sensor, an IR sensor, a fingerprint recognition sensor, an ultrasonic sensor, a light sensor, a microphone, a radar, etc. The driving unit (240c) may perform various physical movements, such as moving robot joints. Additionally, the driving unit (240c) may enable the robot (200) to travel on the ground or fly in the air. The driving unit (240c) may include an actuator, a motor, a wheel, a brake, a propeller, etc.

[0385] FIG. 35 illustrates an example of an AI device applicable to the present disclosure.

[0386] AI devices can be implemented as stationary devices or mobile devices, such as TVs, projectors, smartphones, PCs, laptops, digital broadcasting terminals, tablet PCs, wearable devices, set-top boxes (STBs), radios, washing machines, refrigerators, digital signage, robots, vehicles, etc.

[0387] Referring to FIG. 35, the AI ​​device (200) may include a communication unit (210), a control unit (220), a memory unit (230), an input / output unit (240a / 240b), a learning processor unit (240c), and a sensor unit (240d). Blocks 210 to 230 / 240a to 240d of FIG. 35 correspond to blocks 210 to 230 / 140 of FIG. 29, respectively.

[0388] The communication unit (210) can transmit and receive wired and wireless signals (e.g., sensor information, user input, learning model, control signal, etc.) with external devices such as other AI devices (e.g., 100a to 100f, 120 in FIG. 1) or AI servers (e.g., 100g in FIG. 1) using wired and wireless communication technology. To do this, the communication unit (210) can transmit information within the memory unit (230) to an external device or transmit signals received from an external device to the memory unit (230).

[0389] The control unit (220) can determine at least one executable operation of the AI ​​device (200) based on information determined or generated using a data analysis algorithm or a machine learning algorithm. The control unit (220) can perform the determined operation by controlling the components of the AI ​​device (200). For example, the control unit (220) can request, search, receive, or utilize data from the learning processor unit (240c) or the memory unit (230), and can control the components of the AI ​​device (200) to execute a predicted operation or an operation determined to be desirable among at least one executable operation. Additionally, the control unit (220) can collect historical information, including the operation content of the AI ​​device (200) or user feedback regarding the operation, and store it in the memory unit (230) or the learning processor unit (240c), or transmit it to an external device such as an AI server (Fig. 1, 100g). The collected historical information can be used to update the learning model.

[0390] The memory unit (230) can store data that supports various functions of the AI ​​device (200). For example, the memory unit (230) can store data obtained from the input unit (240a), data obtained from the communication unit (210), output data from the learning processor unit (240c), and data obtained from the sensing unit (140). Additionally, the memory unit (230) can store control information and / or software code required for the operation / execution of the control unit (220).

[0391] The input unit (240a) can acquire various types of data from outside the AI ​​device (200). For example, the input unit (220) can acquire training data for model training and input data to which the training model is applied. The input unit (240a) may include a camera, a microphone and / or a user input unit, etc. The output unit (240b) can generate output related to visual, auditory, or tactile senses, etc. The output unit (240b) may include a display unit, a speaker and / or a haptic module, etc. The sensing unit (140d) can obtain at least one of internal information of the AI ​​device (200), surrounding environment information of the AI ​​device (200), and user information using various sensors. The sensing unit (140d) may include a proximity sensor, an illuminance sensor, an accelerometer, a magnetic sensor, a gyroscope, an inertial sensor, an RGB sensor, an IR sensor, a fingerprint recognition sensor, an ultrasonic sensor, a light sensor, a microphone and / or radar, etc.

[0392] The learning processor unit (240c) can train a model composed of an artificial neural network using training data. The learning processor unit (240c) can perform AI processing together with the learning processor unit of the AI ​​server (Fig. 1, 100g). The learning processor unit (240c) can process information received from an external device through the communication unit (210) and / or information stored in the memory unit (230). Additionally, the output value of the learning processor unit (240c) can be transmitted to an external device through the communication unit (210) and / or stored in the memory unit (230).

[0393]

[0394] FIG. 36 illustrates an example of a quantum communication device applicable to the present disclosure. The quantum communication device can be applied to various devices and can be operated in combination (or merged) with other wired and / or wireless communication devices that are not quantum communication devices. Information in quantum communication may be a concept that includes both bit information, which is the basic unit of classical information, and qubit information, which is the basic unit of quantum information.

[0395] The channel encoder (250) can encode the classical bit to be transmitted into a coded bit. The channel encoder (250) can improve the reliability of the classical bit.

[0396] The quantum encoder (260) converts the encoded bits into a qubit basis (or computation basis). Here, the qubit basis is logical information about the quantum state and can be formed based on a physical quantum basis. For example, as quantum bases at the transmitting and receiving ends, horizontal polarization and vertical polarization can be agreed to correspond to the qubit bases |0〉 and |1〉, respectively.

[0397] Through the channel encoder (250) and the quantum encoder (260), classical information bits 0 or 1 can be converted into qubit bases |0〉 or |1〉. The qubit bases generated at the transmitting end can be transmitted to the receiving end through the quantum channel.

[0398] The quantum decoder (270) at the receiving end can perform measurements based on a pre-agreed quantum basis to decode the qubit basis transmitted to the receiving end into a coded bit. If multiple qubit bases determine the qubit state, a qubit coded deterministically or probabilistically can be obtained depending on the measured qubit basis.

[0399] The channel decoder (280) can decode the coded bits back into classical bits and obtain the information bits sent by the transmitting end.

[0400] The procedures related to the channel encoder (250) and channel decoder (280), indicated by dotted lines in FIG. 36, may be omitted. When the channel encoder (250) and channel decoder (280) are omitted, the qubit state from the quantum process at the transmitting end can be transmitted to the receiving end through a quantum channel. The received qubit state can be used for various purposes by the quantum processor. For example, to transmit the qubit state generated by the quantum processor, a quantum direct communication method in which the qubit state is converted into a photon and transmitted may be used, or a method of performing quantum teleportation based on an entanglement source shared in advance between the transmitting and receiving ends may be used. Here, quantum direct communication refers to a communication method in which classical message information to be transmitted is immediately and securely shared through a quantum channel, and quantum teleportation refers to a communication method in which the quantum information itself is shared through a quantum entanglement channel.

[0401]

[0402] The proposed methods described above may be implemented independently, but they may also be implemented in the form of a combination (or merger) of some of the proposed methods. Rules may be defined so that the base station informs the terminal of the application status of the proposed methods (or information regarding the rules of the proposed methods) through a predefined signal (e.g., a physical layer signal or an upper layer signal).

[0403] The present disclosure may be embodied in other specific forms without departing from the technical ideas and essential features described herein. Accordingly, the above detailed description should not be interpreted restrictively in all respects and should be considered illustrative. The scope of the present disclosure shall be determined by a reasonable interpretation of the appended claims, and all modifications within the equivalent scope of the present disclosure are included within the scope of the present disclosure. Furthermore, embodiments may be constructed by combining claims that are not explicitly related in the claims, or new claims may be included by amendments made after filing.

[0404] One embodiment can be applied to various wireless access systems. Examples of various wireless access systems include the 3GPP (3rd Generation Partnership Project) or 3GPP2 system.

[0405] One embodiment can be applied not only to the various wireless access systems mentioned above, but also to all technical fields utilizing the various wireless access systems. Furthermore, the proposed method can be applied to mmWave and THz communication systems utilizing the ultra-high frequency band.

[0406] Additionally, some embodiments may be applied to various applications such as autonomous vehicles and drones.

Claims

1. A method performed by a first device in a communication system, Step of performing an initial connection procedure with the base station; Step of establishing a connection with the above base station; A step of transmitting capability information to the above base station; A step of establishing a quantum channel with a third device for a quantum signature based on quantum entanglement with a second device; The method includes the step of transmitting to the third device through the quantum channel signature initiation information, which includes at least one quantum information element encrypted using a secret symmetric key shared between the first device and the third device, as information for requesting the generation of signature information for the above quantum signature. A method in which at least one quantum information element included in the signature initiation information includes a first qubit message and a measurement result for a GHZ (Greenberger-Horne-Zeilinger) state or Bell state particle, or includes at least one second qubit message and at least one third qubit message generated based on the first qubit message.

2. In Claim 1, Step of generating 4 primary qubit messages; A step of generating four secondary qubit messages through a unitary conversion operation using random number information for the four primary qubit messages; A step of generating a third qubit message by encrypting one of the above four second qubit messages using a secret symmetric key; A method further comprising the step of generating the signature initiation information by encrypting three of the four secondary qubit messages and the third qubit message using the secret symmetric key.

3. In Claim 1, Step of generating 4 primary qubit messages; A step of obtaining measurement results for particles in the GHZ state or bell state; A method further comprising the step of generating the signature initiation information by encrypting three of the four primary qubit messages and the measurement result using a secret symmetric key.

4. In a method performed by a second device in a communication system, A step of receiving signature information from a third device that mediates a quantum signature based on quantum entanglement with a first device; A step of obtaining particles in the GHZ (Greenberger-Horne-Zeilinger) state or the bell state; A step of transmitting to the third device quantum information generated based on the signature information and the particle as first transmission information generated based on the signature information; A step of receiving from the third device quantum information, wherein the second transmission information generated based on the first transmission information comprises the results of signature verification and message verification performed based on the first transmission information; A step of obtaining random number information based on the second transmission information; and A method comprising the step of recovering a first qubit message from a second qubit message included in the second transmission information based on the above random number information.

5. In Claim 4, A method further comprising the step of generating the first transmission information by encrypting the signature information and the particle using a secret symmetric key shared with the third device.

6. In Claim 4, A method further comprising the step of transmitting a request for the random number information to the third device based on the fact that each of the results of the signature verification and message verification indicates the success of the verification.

7. In Claim 4, The step of recovering the first qubit message from the second qubit message is: A method comprising the step of performing an inverse transformation of a unitary transformation operation using the random number information on the above second qubit message.

8. In a method performed by a third device in a communication system, A step of receiving signature initiation information from the first device, comprising quantum information elements encrypted using a first secret symmetric key shared between the first device and the third device, as information for requesting the generation of signature information for a quantum signature between the first device and the second device; A step of transmitting to the second device signature information generated from one of the quantum information elements based on at least one of the secret key of the third device, a second secret symmetric key shared between the second device and the third device, and random number information; A step of receiving first transmission information generated based on the above signature information from the second device; A step of performing signature verification and message verification based on the first transmission information; and A step of transmitting second transmission information to the second device, the second transmission information including verification result information indicating the results of the signature verification and the message verification; and A method comprising the step of transmitting the random number information to the second device.

9. In Claim 8, A method comprising at least one quantum information element including a first qubit message and a measurement result for a GHZ (Greenberger-Horne-Zeilinger) state or Bell state particle, or at least one second qubit message and at least one third qubit message generated based on the first qubit message.

10. In Claim 8, Step of generating the above random number information; A method further comprising the step of transmitting the result of encrypting the above random number information using the above first secret symmetric key to the above first device.

11. In Claim 8, A step of generating a verification factor by encrypting the third qubit message included in the signature initiation information using the secret key of the third device; A method further comprising the step of generating the signature information by encrypting the second qubit message and the verification factor using the first secret symmetric key.

12. In claim 8, A step of generating the second qubit message through a unitary conversion operation using the random number information for the first qubit message included in the signature initiation information; A step of generating a verification factor by encrypting the above second qubit message using the secret key of the third device; and A method further comprising the step of generating the signature information by encrypting the second qubit message and the verification factor using the first secret symmetric key.

13. In claim 8, The step of performing the above signature verification and the above message verification is, A step of obtaining at least one measurement result for at least one GHZ (Greenberger-Horne-Zeilinger) state or bell state particle; A step of recovering a primary qubit message from a GHZ state or Bell state particle included in the first transmission information based on at least one measurement result; A method further comprising the step of performing the signature verification or the message verification based on the first qubit message.

14. In a first device in a communication system, Transmitter / receiver; and It includes a processor coupled to the above-mentioned transmitter and receiver, The above processor is, Perform initial connection procedures with the base station, Establish a connection with the above base station, and Transmit capability information to the above base station, and Establish a quantum channel with the third device for a quantum signature based on quantum entanglement with the second device, and As information for requesting the generation of signature information for the above quantum signature, the signature initiation information including at least one quantum information element encrypted using a secret symmetric key shared between the first device and the third device is configured to be transmitted to the third device through the quantum channel. The first device comprising at least one quantum information element included in the signature initiation information, which includes a first qubit message and a measurement result for a particle in a GHZ state or Bell state, or at least one second qubit message and at least one third qubit message generated based on the first qubit message.

15. In a second device in a communication system, Transmitter / receiver; and It includes a processor coupled to the above-mentioned transmitter and receiver, The above processor is, Receiving signature information from a third device that mediates a quantum signature based on quantum entanglement with a first device, and acquiring a particle in a GHZ (Greenberger-Horne-Zeilinger) state or a Bell state, As first transmission information generated based on the above signature information, quantum information generated based on the above signature information and the particle is transmitted to the third device, and Quantum information is received from the third device as second transmission information generated based on the first transmission information, which includes the results of signature verification and message verification performed based on the first transmission information, and A second device configured to acquire random number information based on the second transmission information and to recover a first qubit message from a second qubit message included in the second transmission information based on the random number information.

16. In a third device in a communication system, Transmitter / receiver; and It includes a processor coupled to the above-mentioned transmitter and receiver, The above processor is, As information for requesting the generation of signature information for a quantum signature between a first device and a second device, signature initiation information including quantum information elements encrypted using a first secret symmetric key shared between the first device and the third device is received from the first device, and Based on at least one of the secret key of the third device, the second secret symmetric key shared between the second device and the third device, and random number information, signature information generated from one of the quantum information elements is transmitted to the second device, and Receives first transmission information generated based on the above signature information from the second device, and performs signature verification and message verification based on the first transmission information, Transmitting second transmission information to the second device, the second transmission information including verification result information indicating the results of the signature verification and the message verification, and A third device configured to transmit the random number information to the second device.

17. In a communication device, At least one processor; It includes at least one computer memory connected to the at least one processor and storing instructions that direct operations as they are executed by the at least one processor, The above operations are, Step of performing an initial connection procedure with the base station; Step of establishing a connection with the above base station; A step of transmitting capability information to the above base station; A step of establishing a quantum channel with a third device for a quantum signature based on quantum entanglement with a second device; The method includes the step of transmitting to the third device through the quantum channel signature initiation information, which includes at least one quantum information element encrypted using a secret symmetric key shared between the first device and the third device, as information for requesting the generation of signature information for the above quantum signature. A communication device comprising at least one quantum information element included in the above signature initiation information, comprising a first qubit message and a measurement result for a GHZ state or Bell state particle, or at least one second qubit message and at least one third qubit message generated based on the first qubit message.

18. In a non-transitory computer-readable medium storing at least one instruction, It includes at least one instruction executable by a processor, The above at least one instruction is, the device, Perform initial connection procedures with the base station, Establish a connection with the above base station, and Transmit capability information to the above base station, and Establish a quantum channel with the third device for a quantum signature based on quantum entanglement with the second device, and As information for requesting the generation of signature information for the above quantum signature, the third device is instructed to transmit signature initiation information, which includes at least one quantum information element encrypted using a secret symmetric key shared between the first device and the third device, to the third device through the quantum channel. The at least one quantum information element included in the above signature initiation information comprises a first qubit message and a measurement result for a particle in a GHZ state or Bell state, or a computer-readable medium comprising at least one second qubit message and at least one third qubit message generated based on the first qubit message.