Quantum key distribution and quantum secure direct communication method and system

By introducing masking and capacity-enhancing coding into the quantum key distribution protocol, compatibility between quantum key distribution and quantum direct communication is achieved, solving the problems of high channel loss and limited communication distance in existing technologies, and improving communication efficiency and security.

WO2026107948A1PCT designated stage Publication Date: 2026-05-28BEIJING ACAD OF QUANTUM INFORMATION SCI +1
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
BEIJING ACAD OF QUANTUM INFORMATION SCI
Filing Date
2024-12-31
Publication Date
2026-05-28

AI Technical Summary

Technical Problem

Existing quantum key distribution protocols are mainly used to negotiate secure random numbers as keys, which cannot directly transmit information in quantum channels. Furthermore, direct quantum communication requires round trips or multiple transmissions of quantum states, resulting in high channel loss, high system complexity, and limited communication distance and speed.

Method used

This approach integrates common single-transmit/single-receive, dual-path, dual-transmit joint measurement, and entangled QKD protocols with quantum key distribution, enabling direct quantum communication. By reducing channel loss through masking and capacity-enhancing coding, it achieves direct information transmission and allows the receiver to reuse the key masked by random numbers, thus overcoming the limitation of one-time pad in classical encryption.

Benefits of technology

It achieves compatibility between quantum key distribution and quantum direct communication, reduces channel loss, increases communication distance and speed, simplifies system complexity, has the ability to detect eavesdropping, and improves the practicality and security of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024144122_28052026_PF_FP_ABST
    Figure CN2024144122_28052026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a quantum key distribution (QKD) and quantum secure direct communication method. The method is applied to a sender, and comprises: processing plaintext information to be sent, so as to obtain a codeword; encrypting the codeword by means of an encryption key in a key pool, so as to obtain ciphertext; performing encoding processing involving increasing the channel capacity by means of masking on the ciphertext, so as to obtain a codeword which has been subjected to encoding involving increasing the channel capacity by means of masking; using a QKD protocol to process the codeword which has been subjected to encoding involving increasing the channel capacity by means of masking, so as to obtain processing result information, wherein the processing result information enables a receiver to acquire a measurement result on the basis of the QKD protocol; on the basis of the QKD protocol, performing QKD post-processing to acquire a QKD post-processing result; and on the basis of the QKD post-processing result, generating a new key, and storing the new key in the key pool. The present solution can not only complete QKD, but also directly transmit a secret message on a quantum channel, and significantly increases the communication distance and communication speed of quantum secure direct communication.
Need to check novelty before this filing date? Find Prior Art

Description

Methods and systems for quantum key distribution and quantum direct communication Technical Field

[0001] This application relates to the field of quantum communication technology, and in particular to a method and system for quantum key distribution and quantum direct communication. Background Technology

[0002] Quantum communication is a technology that uses the principles of quantum mechanics to transmit information through quantum states, and it has a high degree of security. With the rapid development of quantum computing, the security of asymmetric cryptography based on mathematically complex problems is facing challenges. Quantum communication research has received widespread attention and has developed rapidly, becoming a relatively mature direction in the field of quantum information. It will play an important role in the next generation of secure communication. Quantum communication is mainly divided into branches such as quantum key distribution (QKD), quantum secure direct communication (QSDC), quantum secret sharing, and quantum teleportation. Quantum secure direct communication was proposed in 2000 and has a history of more than 20 years. Its development has gone through four stages. (1) From 2000 to 2005, basic concepts and theories were established. During this stage, typical quantum secure direct communication protocols such as efficient protocols, two-step protocols, DL04 protocols, and high-dimensional protocols were proposed. (2) From 2006 to 2015, the development of protocols and application exploration stage took place. A large number of theoretical protocols were proposed, and the possible uses of quantum secure direct communication were widely explored. (3) 2016-2019: Principle experimental verification and prototype development stage. During this stage, the single-photon-based quantum direct communication scheme and the entanglement-based quantum direct communication protocol were experimentally verified. (4) 2020-present: Product development and practical application advancement. During this stage, the typical performance of the quantum direct communication prototype is 10km@4kbps, enabling real-time secure transmission of text, images, and voice files. Furthermore, 100km quantum direct communication can be achieved using low-loss optical fiber. Summary of the Invention

[0003] The inventors discovered that most existing single-transmitter-single-receiver protocols, dual-path protocols, dual-transmitter joint measurement protocols, and entanglement protocols in the QKD protocol use secure random numbers as keys to complete "quantum key distribution," but cannot directly transmit information in a quantum channel. Quantum direct communication protocols can directly transmit information in a quantum channel, but require round trips or multiple transmissions of quantum states.

[0004] To address the aforementioned issues, this application provides a quantum key distribution and quantum direct communication scheme. On one hand, it integrates common single-transmitter-single-receiver QKD protocols, dual-path QKD protocols, dual-transmitter joint measurement QKD protocols, and entangled QKD protocols with quantum direct communication simultaneously, enabling both quantum key distribution and direct transmission of secret messages through a quantum channel. On the other hand, this application eliminates the need for round-trip quantum state transmission in quantum direct communication, reducing channel loss and system complexity, and significantly improving communication distance and speed. Furthermore, this application utilizes quantum states for simultaneous information transmission and key negotiation, both processes possessing eavesdropping detection capabilities. The key, masked by random numbers, can be reused, overcoming the one-time pad limitation of classical encryption.

[0005] According to a first aspect of this application, a method for quantum key distribution and quantum direct communication is provided, applied to a sender, characterized in that it includes:

[0006] The plaintext information to be sent is processed to obtain the codewords;

[0007] The codeword is encrypted using the encryption key in the key pool to obtain the ciphertext;

[0008] The ciphertext is subjected to masking and enlargement encoding to obtain the masked and enlarged codeword;

[0009] The codeword after masking and enlargement encoding is processed using a quantum key distribution protocol to obtain processing result information, wherein the processing result information enables the receiver to obtain measurement results based on the quantum key distribution protocol;

[0010] According to the quantum key distribution protocol, QKD post-processing is performed to obtain the QKD post-processing result; and a new key is generated based on the QKD post-processing result, and the new key is stored in the key pool.

[0011] According to a second aspect of this application, a method for quantum key distribution and quantum direct communication is provided, applied to a receiver, characterized in that it includes:

[0012] Obtain the measurement results according to the currently used quantum key distribution protocol;

[0013] The codewords corresponding to the plaintext information sent by the sender are obtained through the measurement results;

[0014] Based on the measurement results, QKD post-processing is performed to obtain the QKD post-processing result;

[0015] A new key is generated based on the result of the QKD post-processing, and the new key is stored in the receiver's key pool; and

[0016] The codewords are processed to obtain plaintext information.

[0017] According to a third aspect of this application, a system for quantum key distribution and quantum direct communication is provided, characterized in that it comprises:

[0018] The sending device is configured to perform the method described in the first aspect; and

[0019] A receiving device for performing the method described in the second aspect.

[0020] According to a fourth aspect of this application, an electronic device is provided, comprising:

[0021] Processor; and

[0022] A memory storing computer instructions that, when executed by the processor, cause the processor to perform the methods described in the first and second aspects.

[0023] According to a fifth aspect of this application, a non-transitory computer storage medium is provided, storing a computer program that, when executed by a plurality of processors, causes the processors to perform the methods described in the first and second aspects.

[0024] According to the quantum key distribution and quantum direct communication method and system provided in this application, firstly, quantum direct communication can be achieved without round-trip transmission of quantum states, reducing channel loss and significantly improving communication distance and speed; secondly, this scheme achieves quantum direct communication without the need for quantum state block transmission, thus eliminating the need for quantum storage and improving the practicality of quantum direct communication; thirdly, this scheme simultaneously realizes key negotiation and information transmission, improving the dual-channel secure communication model into a single-channel model and possessing the ability to detect eavesdropping; finally, this scheme can improve common quantum key distribution protocols to be compatible with both quantum key distribution protocols and quantum direct communication protocols, thereby utilizing various quantum information resources such as entangled states and dual-field quantum states to achieve both key distribution and information transmission in a quantum channel. Attached Figure Description

[0025] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings, without exceeding the scope of protection claimed by this application.

[0026] Figure 1 is a schematic diagram of a quantum key distribution and quantum direct communication system based on a single-transmitter, single-receiver QKD protocol according to an embodiment of this application.

[0027] Figure 2 is a schematic diagram of a quantum key distribution and quantum direct communication system based on a dual-path QKD protocol according to an embodiment of this application.

[0028] Figure 3 is a schematic diagram of a quantum key distribution and quantum direct communication system based on a dual-sender joint measurement QKD protocol according to an embodiment of this application.

[0029] Figure 4 is a schematic diagram of a quantum key distribution and quantum direct communication system based on an embodiment of the entangled QKD protocol according to this application.

[0030] Figure 5 is a flowchart of a method for quantum key distribution and quantum direct communication performed by a sender according to an embodiment of this application.

[0031] Figure 6 is a flowchart of a method for quantum key distribution and quantum direct communication performed by the sender according to another embodiment of this application.

[0032] Figure 7 is a flowchart of a method for quantum key distribution and quantum direct communication performed by the sender according to yet another embodiment of this application.

[0033] Figure 8 is a flowchart of a method for quantum key distribution and quantum direct communication performed by a receiver according to an embodiment of this application.

[0034] Figure 9 is a flowchart of a method for quantum key distribution and quantum direct communication performed by a receiver according to another embodiment of this application.

[0035] Figure 10 is a structural diagram of an electronic device provided in this application. Detailed Implementation

[0036] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0037] Figure 1 is a schematic diagram of a quantum key distribution and quantum direct communication system based on a single-transmitter, single-receiver QKD protocol according to an embodiment of this application. The single-transmitter, single-receiver QKD protocol refers to the sender preparing a quantum state and sending it to the receiver, who then measures the quantum state to complete quantum key distribution. Typical protocols include BB84, B92, six-state, SARG04, COW, DPS, RRDPS, three-state, GG02, compressed-state, and so on.

[0038] As shown in Figure 1, the quantum key distribution and quantum direct communication scheme may specifically include the following steps.

[0039] (1) The sender obtains codeword u by performing error correction encoding on the plaintext m to be sent. According to some embodiments, the error correction codes include LDPC codes, Polar codes, etc.

[0040] (2) The sender spreads the codeword u to obtain the codeword v.

[0041] (3) The sender retrieves key k from the key pool and encrypts codeword v to obtain ciphertext s, i.e. Those skilled in the art will understand that if there are not enough keys in the key pool to encrypt the information, the system will first run QKD to generate enough keys to fill the key pool.

[0042] (4) The sender generates a random number R of the same length as s locally, and XORs s and R to obtain the codeword c to be transmitted. For example, This step is called INCUM (increasing the channel capacity using masking) encoding process.

[0043] (5) Based on the specific single-transmit and single-receive QKD protocol used, such as BB84 protocol, SARG04 protocol, COW protocol, DPS protocol, RRDPS protocol, three-state protocol, GG02 protocol, compressed state protocol, etc., the sender prepares the quantum state according to the codeword c and transmits the prepared quantum state to the receiver through the quantum channel.

[0044] (6) The receiver measures the quantum state based on the specific single-transmit single-receive QKD protocol rules used.

[0045] (7) Both communicating parties enter QKD post-processing. The QKD post-processing process includes filtering, error estimation, error correction, and privacy amplification. First, both parties complete filtering and share the raw code. For example, the sender determines a new raw code c1 based on the prior codeword c, the basis vector information for preparing the quantum state, and the measurement basis vector information published by the receiver. Simultaneously, the receiver determines the raw code c1' based on its own measurement basis vector information for measuring the quantum state, the measurement result c', and the basis vector information for preparing the quantum state published by the sender. Compared to c1, c1' has a certain number of errors. If the error rate is below a certain threshold, both communicating parties can supplement their respective key pools with a new key K using the result of QKD post-processing (e.g., represented as a random number), thereby achieving key distribution.

[0046] (8) The receiver publishes the timing positions corresponding to c1', which are called valid probe bits.

[0047] (9) The sender publishes the local random number r used for encryption on these valid probe bits. Due to system losses, the receiver can only receive a portion of the quantum state signal, therefore r comes from R. Except for the valid probe bits, the other timing positions are invalid probe bits. The sender returns the encryption key k2 used on the timing positions of the invalid probe bits to the key pool for use in subsequent communication processes; that is, the key corresponding to the invalid probe bits can be reused. This is because the above encryption key is masked by the local random numbers, and these local random numbers are never published.

[0048] (10) The receiver performs INCUM decoding on c1' to obtain the ciphertext codeword s', i.e.

[0049] (11) The receiver decrypts s' to obtain v', i.e.

[0050] (12) The receiver despreads v' to obtain u'.

[0051] (13) The receiver performs error correction decoding on u' to obtain plaintext m'.

[0052] Figure 2 is a schematic diagram of a quantum key distribution and quantum direct communication system based on a dual-channel QKD protocol according to an embodiment of this application. The dual-channel QKD protocol refers to a system where the receiver first generates a signal and transmits it to the sender, the sender modulates the signal and transmits it back to the receiver, and the receiver finally measures the signal to complete the quantum key distribution. Typical protocols include the ping-pong protocol, the LM05 protocol, and continuous-variable dual-channel protocols, etc.

[0053] As shown in Figure 2, the quantum key distribution and quantum direct communication scheme may specifically include the following steps.

[0054] (1) The receiver prepares a quantum state and sends it to the sender through a quantum channel;

[0055] (2) The sender obtains codeword u by performing error correction encoding on the plaintext m to be sent. According to one embodiment, the error correction code includes LDPC code, Polar code, etc.

[0056] (3) The sender spreads the codeword u to obtain the codeword v.

[0057] (4) The sender retrieves key k from the key pool and encrypts codeword v to obtain ciphertext s, i.e. Those skilled in the art will understand that if there are not enough keys in the key pool to encrypt the information, the system will first run QKD to generate enough keys to fill the key pool.

[0058] (5) The sender generates a random number R of the same length as s locally, and XORs s and R to obtain the codeword c to be transmitted, i.e. This step is called INCUM (increasing the channel capacity using masking) encoding process.

[0059] (6) Based on the specific dual-path QKD protocol used, including ping-pong protocol, LM05 protocol, continuous variable dual-path protocol, etc., the sender modulates the quantum state sent by the receiver to the sender according to the code word c, and sends the modulated quantum state back to the receiver.

[0060] (7) Based on the specific dual-path QKD protocol rules used, the receiver measures the quantum state and obtains a measurement result.

[0061] (8) Both communicating parties perform QKD post-processing. First, the screening is completed, and the two communicating parties share the raw code. Since the quantum state is prepared by the receiver, this type of protocol does not require a basis-matching step. The receiver compares the measurement result with the quantum state originally sent by the receiver and receives the information c1'. The reason for using c1' is because of channel loss. c1' only corresponds to a part of the codeword c1 in c, and c1' contains a certain proportion of errors compared to c1.

[0062] (9) The receiver publishes the timing positions corresponding to c1', which are called valid probe bits.

[0063] (10) The sender determines the corresponding c1 based on these timing positions. The sender and receiver proceed to the subsequent QKD post-processing based on c1 and c1', respectively. The process includes error estimation, error correction, and privacy amplification. If the bit error rate is lower than a certain threshold, the two communicating parties can supplement their respective key pools with new keys K through QKD post-processing, thereby achieving key distribution.

[0064] (11) The sender publishes the local random number r used for encryption on the valid probe bit. Due to system losses, the receiver can only receive a portion of the quantum state signal, therefore from R. The sender returns the encryption key k2 used at the timing position where no probe signal is received to the key pool for use in subsequent communication processes.

[0065] (12) The receiver performs INCUM decoding on c1' to obtain the ciphertext codeword s', i.e.

[0066] (13) The receiver decrypts s' to obtain v', that is...

[0067] (14) The receiver despreads v' to obtain u'.

[0068] (15) The receiver performs error correction decoding on u' to obtain plaintext m'.

[0069] Figure 3 is a schematic diagram of a quantum key distribution and quantum direct communication system based on a dual-sender joint measurement QKD protocol according to an embodiment of this application. The dual-sender joint measurement QKD protocol refers to a process where the sender and receiver prepare quantum state signals, which they then send to an untrusted third party for joint measurement. The measurement results are then published, thus completing quantum key distribution. This protocol can resist attacks by eavesdroppers targeting actual detectors. Typical protocols include MDI QKD, dual-field QKD, transmit-or-not-transmit QKD, pattern-matching QKD, etc.

[0070] As shown in Figure 3, the quantum key distribution and quantum direct communication scheme may specifically include the following steps.

[0071] (1) The sender obtains codeword u by performing error correction encoding on the plaintext m to be sent. According to one embodiment, the error correction code includes LDPC code, Polar code, etc.

[0072] (2) The sender spreads the codeword u to obtain the codeword v.

[0073] (3) The sender retrieves key k from the key pool and encrypts codeword v to obtain ciphertext s, i.e. Those skilled in the art will understand that if there are not enough keys in the key pool to encrypt the information, the system will first run QKD to generate enough keys to fill the key pool.

[0074] (4) The sender generates a random number R of the same length as s locally, and XORs s and R to obtain the codeword c to be transmitted, i.e. This step is called masking and enlarging encoding.

[0075] (5) Based on the specific dual-transmitter joint measurement QKD protocol used, including MDI QKD protocol, dual-field QKD protocol, transmit-or-not-transmit QKD protocol, mode-matching QKD protocol, etc., the sender prepares the quantum state according to the codeword c, and the receiver prepares the quantum state according to a randomly generated string of random numbers c' of the same length as c. During the preparation of the quantum state, the receiver ensures that it is the same as the sender in terms of quantum state encoding dimension, polarization, or phase, and uses the same type of quantum state with the same length. Both parties send their prepared quantum states to an untrusted third party.

[0076] (6) An untrusted third party performs joint measurement on the received quantum state and publishes the measurement results and the corresponding timing position.

[0077] (7) Both communicating parties perform QKD post-processing based on information published by an untrusted third party, their respective quantum state basis vector information, and the transmitted codewords. First, screening is completed, and both communicating parties share the raw code. For example, the sender determines a raw code c1 based on the prior codeword c, the information published by the untrusted third party, and the basis vector information published by the receiver. The receiver determines the raw code c1' based on the prior random number c', the information published by the untrusted third party, and the timing position of the basis vectors published by the sender that is the same as its own. Compared to c1, c1' contains a certain number of errors.

[0078] (8) The sender and receiver perform subsequent QKD post-processing steps based on c1 and c1', respectively. The process includes error estimation, error correction, and privacy amplification. If the bit error rate is lower than a certain threshold, the two communicating parties can supplement their respective key pools with new keys K through QKD post-processing, thereby realizing key distribution.

[0079] (9) The receiver publishes the timing positions corresponding to c1', which are called valid probe bits. The sender publishes the local encrypted random number r at these timing positions. The sender returns the encryption key k2 used on the invalid probe bits to the key pool for use in subsequent communication processes.

[0080] (10) The receiver performs INCUM decoding on c1' to obtain the ciphertext codeword s', i.e.

[0081] (11) The receiver decrypts s' to obtain v', i.e.

[0082] (12) The receiver despreads v' to obtain u'.

[0083] (13) The receiver performs error correction decoding on u' to obtain plaintext m'.

[0084] Figure 4 is a schematic diagram of a quantum key distribution and quantum direct communication system based on an embodiment of the entangled QKD protocol according to this application. Entangled QKD protocols utilize entangled states to achieve quantum key distribution, including the E91 protocol, BBM92 protocol, DI protocol, etc.

[0085] As shown in Figure 4, the quantum key distribution and quantum direct communication scheme may specifically include the following steps.

[0086] (1) The two communicating parties establish quantum entanglement. Specific methods include, but are not limited to: a third party distributing entangled pairs to the sender and receiver, or the sender sending one of the photons of the prepared entangled state to the receiver, or the receiver sending one of the photons of the prepared entangled state to the sender.

[0087] (2) The sender obtains codeword u by performing error correction encoding on the plaintext m to be sent. According to one embodiment, the error correction code includes LDPC code, Polar code, etc.

[0088] (3) The sender spreads the codeword u to obtain the codeword v.

[0089] (4) The sender retrieves key k from the key pool and encrypts codeword v to obtain ciphertext s, i.e. Those skilled in the art will understand that if there are not enough keys in the key pool to encrypt the information, the system will first run QKD to generate enough keys to fill the key pool.

[0090] (5) The sender generates a random number R of the same length as s locally, and XORs s and R to obtain the codeword c to be transmitted, i.e. This step is called masking and enlarging encoding.

[0091] (6) Based on the specific entangled QKD protocol used, including the E91 protocol, BBM92 protocol, DI protocol, etc., the sender and receiver randomly measure the entangled particles they share. For example, after completing the measurement, the sender and receiver obtain results cA and cB respectively. The codewords in c from the sender are compared sequentially with the codewords in cA, and the results in cA that are the same as c and their timing positions are retained in order. The sender publishes these timing positions, and the receiver retains the results at the corresponding timing positions, thus the sender and receiver obtain c and c' respectively. Here, c comes from cA, and c' comes from cB.

[0092] (7) The sender and receiver perform QKD post-processing based on c and c', respectively. The QKD post-processing process includes filtering, error estimation, error correction, and privacy amplification. First, both senders complete raw key filtering. For example, the receiver publishes the measurement basis vectors, and the sender retains the results in c at the same timing positions as the receiver's selected measurement basis vectors, obtaining c1. The sender informs the receiver of these timing positions, and the receiver retains the result c1'. Both senders randomly sample a small subset of c1 and c1' to complete error estimation. If the error rate is lower than a certain threshold, both parties can supplement their respective key pools with new keys K through QKD post-processing, thereby achieving key distribution.

[0093] (8) The receiver copies the raw code obtained from the filtering (corresponding to the result c1' after QKD post-processing filtering) for the recovery of the transmitted information;

[0094] (9) The receiver publishes the locally encrypted random number r at the time position corresponding to c1', where r comes from R. This position is called the valid probe bit. The sender returns the encryption key k2 used for the time positions corresponding to the invalid probe bits to the key pool for use in subsequent communication processes. That is, the sender returns the encryption key k2 used for the time positions other than c1' to the key pool for use in subsequent communication processes.

[0095] (10) The receiver performs INCUM decoding on c1' to obtain the ciphertext codeword s', i.e.

[0096] (11) The receiver decrypts s' to obtain v', i.e.

[0097] (12) The receiver despreads v' to obtain u'.

[0098] (13) The receiver performs error correction decoding on u' to obtain plaintext m'.

[0099] Based on the schemes shown in Figures 1 to 4, according to one aspect of this application, a method for quantum key distribution and quantum direct communication is provided. Figure 5 is a flowchart of the method for quantum key distribution and quantum direct communication performed by a sender according to an embodiment of this application. As shown in Figure 5, the method includes the following steps S501 to S506.

[0100] In step S501, the plaintext information to be sent is processed to obtain codewords.

[0101] According to the embodiments shown in Figures 1 to 4, the sender performs error correction encoding on the plaintext m to be transmitted to obtain codeword u. The sender then spreads codeword u to obtain codeword v.

[0102] Thus, step S501 can specifically include:

[0103] The plaintext information to be sent is subjected to error correction encoding to obtain a first codeword; and

[0104] The first codeword is spread to obtain the second codeword.

[0105] In step S502, the codeword is encrypted using the encryption key in the key pool to obtain ciphertext.

[0106] According to the embodiments shown in Figures 1 to 4, the sender retrieves key k from the key pool to encrypt codeword v, thereby obtaining ciphertext s, i.e. Those skilled in the art will understand that if there are not enough keys in the key pool to encrypt the information, the system will first run QKD to generate enough keys to fill the key pool.

[0107] In step S503, the ciphertext is subjected to masking and enlargement encoding to obtain the masked and enlarged codeword.

[0108] According to the embodiments shown in Figures 1 to 4, the sender generates a random number R of the same length as s locally, and XORs s and R to obtain the codeword c to be transmitted. This step is called masking and enlarging encoding.

[0109] Masking and capacity enhancement can improve the security of information transmission. On the other hand, the encryption key masked by the local random number, which is not published, can be reused, breaking through the one-time pad limitation of classic encryption.

[0110] In step S504, the codeword after masking and augmentation is processed using a quantum key distribution protocol to obtain processing result information, wherein the processing result information enables the receiver to obtain measurement results based on the quantum key distribution protocol.

[0111] According to the embodiment shown in Figure 1, the sender prepares the quantum state based on a specific single-transmit, single-receive QKD protocol, such as BB84, SARG04, COW, DPS, RRDPS, three-state, GG02, compressed-state, etc., according to codeword c, and transmits the prepared quantum state to the receiver through a quantum channel. According to the embodiment shown in Figure 2, the sender modulates the quantum state sent from the receiver to the sender according to codeword c based on a specific dual-path QKD protocol, such as ping-pong, LM05, continuous-variable dual-path, etc., and transmits the modulated quantum state back to the receiver. According to the embodiment shown in Figure 3, based on the specific dual-sender joint measurement QKD protocol used, including the MDI QKD protocol, dual-field QKD protocol, transmit-or-not-transmit QKD protocol, pattern-matching QKD protocol, etc., the sender prepares the quantum state according to the codeword c, and the receiver prepares the quantum state according to a randomly generated string of random numbers c' of the same length as c. During the preparation of the quantum state, the receiver ensures that it is the same as the sender in terms of quantum state encoding dimension, polarization, or phase, and uses the same type of quantum state with the same length. Both parties send their prepared quantum states to an untrusted third party. According to the embodiment shown in Figure 4, based on the specific entanglement QKD protocol used, including the E91 protocol, BBM92 protocol, DI protocol, etc., the sender and receiver randomly measure the entangled particles they share. For example, after completing the measurement, the sender and receiver respectively obtain results cA and cB. The codewords in the sender's c are compared sequentially with the codewords in cA, and the results in cA that are the same as c and their timing positions are retained in order. The sender publishes these timing positions, and the receiver retains the results at the corresponding timing positions, thus obtaining c and c' respectively. Here, c comes from cA, and c' comes from cB.

[0112] According to the embodiment shown in Figure 1, the sender transmits the prepared quantum state to the receiver via a quantum channel. The receiver measures the quantum state according to a single-transmit, single-receive QKD protocol and obtains the measurement result. According to the embodiment shown in Figure 2, the sender transmits the modulated quantum state back to the receiver via a quantum channel. The receiver measures the quantum state according to a dual-path QKD protocol and obtains the measurement result. According to the embodiment shown in Figure 3, the sender and receiver send their respective prepared quantum states to an untrusted third party. The untrusted third party performs joint measurement on the received quantum state and publishes the measurement results and their corresponding timing positions. According to the embodiment shown in Figure 4, based on the entanglement QKD protocol, the sender and receiver randomly measure the particles they hold and obtain the measurement results. The sender determines c and c' based on c, and the receiver determines their respective c' and c' based on their measurement results.

[0113] In step S505, QKD post-processing is performed according to the quantum key distribution protocol to obtain the QKD post-processing result;

[0114] In step S506, a new key is generated based on the result of the QKD post-processing, and the new key is stored in the key pool.

[0115] In the embodiment shown in Figure 1, both communicating parties enter QKD post-processing. They first complete screening and share the raw code. For example, the sender determines a new raw code c1 based on the prior codeword c, the basis vector information for preparing the quantum state, and the measurement basis vector information published by the receiver. Simultaneously, the receiver determines the raw code c1' based on its own measurement basis vector information for measuring the quantum state, the measurement result c', and the basis vector information for preparing the quantum state published by the sender. c1 comes from c, and c1' comes from c'. Compared to c1, c1' has a certain bit error rate. If the bit error rate is below a certain threshold, both communicating parties can supplement their respective key pools with a new key K using the result of QKD post-processing (e.g., represented as a random number). In the implementation shown in Figure 2, the sender and receiver enter QKD post-processing based on c and c1' respectively. This process includes bit error estimation, error correction, and privacy amplification. If the bit error rate is below a certain threshold, both communicating parties can supplement their respective key pools with a new key K using QKD post-processing. In the implementation shown in Figure 3, the sender and receiver perform QKD post-processing based on c and c', respectively. This process includes filtering, error estimation, error correction, and privacy amplification. If the bit error rate is below a certain threshold, both parties can supplement their respective key pools with a new key K through QKD post-processing. In the implementation shown in Figure 4, the sender and receiver perform QKD post-processing based on c and c', respectively. The QKD post-processing process includes filtering, error estimation, error correction, and privacy amplification. If the bit error rate is below a certain threshold, both parties can supplement their respective key pools with a new key K through QKD post-processing.

[0116] Figure 6 is a flowchart of a method for quantum key distribution and quantum direct communication performed by a sender according to another embodiment of this application. Compared with Figure 5, steps S601 to S606 of the method shown in Figure 6 are the same as steps S501 to S506 shown in Figure 5, except that the method shown in Figure 6 further includes step S607.

[0117] In step S607, information about the random number used in the masking and capacity-enhancing encoding process at the corresponding time position is sent to the receiver.

[0118] In the embodiments shown in Figures 1 and 2, the receiver publishes the timing positions of the valid probe bits; the sender publishes the local random number r used for encryption at these timing positions. Due to system losses, the receiver can only receive a portion of the quantum state signal, therefore r comes from R. The sender returns the encryption key k2 used at the timing positions of the invalid probe bits to the key pool for use in subsequent communication processes; that is, the key corresponding to the invalid probe bits can be reused. In the embodiment shown in Figure 3, an untrusted third party performs joint measurements on the received quantum state and publishes the measurement results and the corresponding timing positions; the sender publishes the local encrypted random number r at the timing positions of the valid probe bits, r comes from R. The sender returns the encryption key k2 used at the invalid probe bits to the key pool for use in subsequent communication processes.

[0119] Thus, step S607 can specifically include:

[0120] Obtain the timing positions corresponding to the published valid probe bits; and

[0121] The information of the random number used in the masking and capacity-enhancing encoding process at the specified timing position is sent to the receiver.

[0122] In the embodiment shown in Figure 4, the sender and receiver each perform random measurements on the entangled particles they share. For example, after completing the measurements, the sender and receiver obtain results cA and cB, respectively. The codewords in sender c are compared sequentially with the codewords in cA, and the results in cA that are identical to c and their timing positions are retained in order. The sender publishes these timing positions, and the receiver retains the results at the corresponding timing positions, thus obtaining c and c', respectively. Here, c comes from cA, and c' comes from cB. The sender publishes the locally encrypted random number r at the timing position corresponding to the valid probe bit, where r comes from R. The sender returns the encryption key k2 used for the timing positions corresponding to the invalid probe bits to the key pool for use in subsequent communication processes.

[0123] Thus, step S607 can also specifically include:

[0124] The sender's particle is measured using the quantum key distribution protocol to obtain a first measurement result;

[0125] Obtain the first time sequence position of the first measurement result;

[0126] Obtain the second time-series position with the second measurement result published by the recipient;

[0127] Based on the first timing position and the second timing position, determine the timing positions where both the sender and the receiver have measurement results and are basically corresponding; and

[0128] The information of the random number used in the masking expansion process at the specified timing position is sent to the receiver.

[0129] Figure 7 is a flowchart of a method for quantum key distribution and quantum direct communication performed by the sender according to another embodiment of this application. Compared with Figure 6, steps S701 to S707 of the method shown in Figure 7 are the same as steps S601 to S607 shown in Figure 6, except that the method shown in Figure 7 further includes step S708.

[0130] In step S708, among the encryption keys used to encrypt the codeword, the encryption key that does not correspond to the timing position is returned to the key pool.

[0131] In the embodiments shown in Figures 1 and 2, the sender returns the encryption key k2 used for the timing position corresponding to the invalid probe bit to the key pool for use in subsequent communication processes. In the embodiment shown in Figure 3, the sender returns the encryption key k2 used for the timing position corresponding to the invalid probe bit to the key pool for use in subsequent communication processes. In the embodiment shown in Figure 4, the sender returns the encryption key k2 used for the timing position corresponding to the invalid probe bit to the key pool for use in subsequent communication processes.

[0132] Figure 8 is a flowchart of a method for quantum key distribution and quantum direct communication performed by a receiver according to an embodiment of this application. As shown in Figure 8, the method includes steps S801 to S805.

[0133] In step S801, the measurement result is obtained according to the currently used quantum key distribution protocol.

[0134] In the embodiment shown in Figure 1, the sender prepares a quantum state according to codeword c and transmits the prepared quantum state to the receiver through a quantum channel. The receiver measures the quantum state according to the specific single-transmit, single-receive QKD protocol rules and obtains the measurement result. In the embodiment shown in Figure 2, the sender modulates the quantum state sent by the receiver to the sender according to codeword c and sends the modulated quantum state back to the receiver. The receiver measures the quantum state according to the specific dual-path QKD protocol rules and obtains the measurement result. In the embodiment shown in Figure 3, an untrusted third party performs joint measurement on the received quantum state and publishes the measurement result and the corresponding timing position. The receiver obtains the measurement result. In the embodiment shown in Figure 4, the receiver measures the particle in its possession according to the specific entanglement QKD protocol and obtains the measurement result.

[0135] Thus, step S801 can specifically include:

[0136] According to a single-send, single-receive quantum key distribution protocol, the quantum state generated by the sender is measured, and the measurement result is obtained; or

[0137] According to a dual-path quantum key distribution protocol, the quantum state modulated by the sender is measured to obtain the measurement result; or

[0138] According to the dual-sender joint measurement quantum key distribution protocol, the measurement result obtained by a third party measuring the quantum states from the sender and the receiver is received; or

[0139] According to the entangled quantum key distribution protocol, the particle of the receiver is measured based on the measurement result of the sender, and the measurement result is obtained.

[0140] In step S802, the codeword corresponding to the plaintext information sent by the sender is obtained through the measurement result.

[0141] In the embodiment shown in Figure 1, the receiver filters the measurement results to obtain codeword c1'. In the embodiment shown in Figure 2, the receiver compares the measurement results with the quantum state originally emitted by the receiver to obtain codeword c1'. In the embodiment shown in Figure 3, the receiver filters the measurement results published by an untrusted third party to obtain codeword c1'. In the embodiment shown in Figure 4, the receiver measures the particle in its possession and filters it against the sender's results to obtain codeword c1'. Here, codeword c1' corresponds to the plaintext information sent by the sender. The plaintext information sent by the sender undergoes a series of processing steps (including error correction coding, spreading, encryption, etc.) to obtain codeword c. Compared to c1, c1' contains certain errors, and c1 originates from c.

[0142] In step S803, QKD post-processing is performed based on the measurement results to obtain the QKD post-processing result;

[0143] In step S804, a new key is generated based on the result of the QKD post-processing, and the new key is stored in the key pool of the receiver.

[0144] In the embodiment shown in Figure 1, both communicating parties enter QKD post-processing. The QKD post-processing process includes filtering, error estimation, error correction, and privacy amplification. The receiver performs QKD post-processing based on the measurement results, and the sender determines a new codeword c1 based on the prior codeword c and the measurement basis vectors published by the receiver. The receiver retains the raw code c1' corresponding to c1. If the bit error rate is below a certain threshold, both communicating parties can supplement their respective key pools with a new key K using the result of the QKD post-processing (e.g., represented as a random number). In the implementation shown in Figure 2, the sender and receiver enter QKD post-processing based on c and c1', respectively. The process includes error estimation, error correction, and privacy amplification. If the bit error rate is below a certain threshold, both communicating parties can supplement their respective key pools with a new key K using the QKD post-processing. In the implementation shown in Figure 3, the sender and receiver perform QKD post-processing based on c and c', respectively. The process includes filtering, error estimation, error correction, and privacy amplification. If the bit error rate is below a certain threshold, both communicating parties can supplement their respective key pools with a new key K through QKD post-processing. In the implementation shown in Figure 4, the sender and receiver perform QKD post-processing based on c and c', respectively. The QKD post-processing process includes filtering, bit error estimation, error correction, and privacy amplification. If the bit error rate is below a certain threshold, both communicating parties can supplement their respective key pools with a new key K through QKD post-processing.

[0145] In step S805, the codeword is processed to obtain plaintext information.

[0146] Figure 9 is a flowchart of a method for quantum key distribution and quantum direct communication performed by a receiver according to another embodiment of this application. Compared with Figure 8, steps S901 to S905 of the method shown in Figure 9 are the same as steps S801 to S805 shown in Figure 8, except that the method shown in Figure 9 further includes step 906.

[0147] In step S906, a locally encrypted random number corresponding to the timing position of the valid probe bit in the measurement result is received from the sender.

[0148] In the embodiments shown in Figures 1 and 2, the receiver publishes the timing positions of the valid probe bits; the sender publishes the local random number r used for encryption at these timing positions. In the embodiment shown in Figure 3, an untrusted third party performs joint measurements on the received quantum states and publishes the measurement results and the corresponding timing positions; the sender, based on the timing positions corresponding to the measurement results published by the untrusted third party and the basis pairing results of the sender and receiver, publishes the local encrypted random number r at the timing positions of the valid probe bits. In the embodiment shown in Figure 4, the communicating parties, based on the entangled QKD protocol and codeword c used, complete the filtering to obtain c1'; the receiver publishes the timing position corresponding to c1'; the sender publishes the local encrypted random number r at the corresponding timing position. Due to system losses, the communicating parties can only detect a portion of the entangled states simultaneously, therefore r comes from R.

[0149] In the embodiments shown in Figures 1 to 4, the receiver first performs INCUM decoding on c1' to obtain the ciphertext codeword s', i.e. Secondly, the receiver decrypts s' to obtain v', that is... Then, the receiver despreads v' to obtain u', and finally, the receiver performs error correction decoding on u' to obtain the plaintext m'.

[0150] Thus, step S805 or step S905 can specifically include:

[0151] The codeword is masked and enlarged and decoded according to the local encrypted random number to obtain the masked and enlarged decoded codeword;

[0152] The codeword after the mask is enlarged and decoded is decrypted to obtain the decrypted codeword;

[0153] The despread codeword is then despread to obtain the despread codeword; and

[0154] The despread codewords are then subjected to error correction and decoding to obtain the plaintext information.

[0155] According to the quantum key distribution and quantum direct communication method and system provided in this application, firstly, quantum direct communication can be achieved without round-trip transmission of quantum states, reducing channel loss and significantly improving communication distance and speed; secondly, this scheme achieves quantum direct communication without the need for quantum state block transmission, thus eliminating the need for quantum storage and improving the practicality of quantum direct communication; thirdly, this scheme simultaneously realizes key negotiation and information transmission, improving the dual-channel secure communication model into a single-channel model and possessing the ability to detect eavesdropping; finally, this scheme can improve common quantum key distribution protocols to be compatible with both quantum key distribution protocols and quantum direct communication protocols, thereby utilizing various quantum information resources such as entangled states and dual-field quantum states to achieve both key distribution and information transmission in a quantum channel.

[0156] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0157] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.

[0158] In the several embodiments provided in this application, it should be understood that the disclosed apparatus can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be an electrical connection or other forms.

[0159] Referring to Figure 10, Figure 10 provides an electronic device including a processor and a memory. The memory stores computer instructions, which, when executed by the processor, cause the processor to perform the computer instructions to implement the methods and refinements shown in Figures 5 to 9.

[0160] It should be understood that the above-described device embodiments are merely illustrative, and the device disclosed in this invention can be implemented in other ways. For example, the division of units / modules described in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, integrated into another system, or some features may be ignored or not executed.

[0161] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of the present invention can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.

[0162] If the integrated unit / module is implemented in hardware, the hardware can be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor or chip can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the on-chip cache, off-chip memory, and storage can be any suitable magnetic or magneto-optical storage medium, such as resistive random access memory (RRAM), dynamic random access memory (DRAM), static random access memory (SRAM), enhanced dynamic random access memory (EDRAM), high-bandwidth memory (HBM), hybrid memory cube (HMC), etc.

[0163] If the integrated unit / module is implemented as a software program module and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer electronic device (which may be a personal computer, server, or network electronic device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this disclosure. The aforementioned memory includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0164] This application also provides a non-transient computer storage medium storing a computer program, which, when executed by multiple processors, causes the processors to execute the methods and refinements shown in Figures 5 to 9.

[0165] The embodiments of this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the embodiments above are only for the purpose of helping to understand the method and core ideas of this application. Furthermore, any changes or modifications made by those skilled in the art based on the ideas of this application, and on the specific implementation methods and application scope of this application, are all within the scope of protection of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A method for quantum key distribution and quantum direct communication, applied to the sender, characterized in that, include: The plaintext information to be sent is processed to obtain the codewords; The codeword is encrypted using the encryption key in the key pool to obtain the ciphertext; The ciphertext is subjected to masking and enlargement encoding to obtain the masked and enlarged codeword; The codeword after masking and enlargement encoding is processed using a quantum key distribution protocol to obtain processing result information, wherein the processing result information enables the receiver to obtain measurement results based on the quantum key distribution protocol; According to the quantum key distribution protocol, QKD post-processing is performed to obtain the QKD post-processing result; and A new key is generated based on the result of the QKD post-processing, and the new key is stored in the key pool.

2. The method as described in claim 1, characterized in that, Also includes: Send the information of the random number used in the masking and capacity-enhancing encoding process at the corresponding time position to the receiver.

3. The method as described in claim 2, characterized in that, The step of sending information about the random number used in the masking and capacity-enhancing encoding process at the corresponding time position to the receiver includes: Obtain the timing position of the published valid probe bits; and The information of the random number used in the masking and capacity-enhancing encoding process at the specified timing position is sent to the receiver.

4. The method as described in claim 2, characterized in that, The step of sending information about the random number used in the masking and capacity-enhancing encoding process at the corresponding time position to the receiver includes: The sender's particle is measured using the quantum key distribution protocol to obtain a first measurement result; Obtain the first time sequence position of the first measurement result; Obtain the second time-series position with the second measurement result published by the recipient; Based on the first timing position and the second timing position, determine the timing positions where both the sender and the receiver have measurement results and are basically corresponding; and The information of the random number used in the masking expansion process at the specified timing position is sent to the receiver.

5. The method as described in claims 1 to 4, characterized in that, Also includes: Among the encryption keys used to encrypt the codeword, encryption keys that do not correspond to the timing position are returned to the key pool.

6. The method according to any one of claims 1 to 4, characterized in that, The process of processing the plaintext information to be sent to obtain codewords includes: The plaintext information to be sent is subjected to error correction encoding to obtain a first codeword; and The first codeword is spread to obtain the second codeword.

7. A method for quantum key distribution and quantum direct communication, applied to a receiver, characterized in that, include: Obtain the measurement results according to the currently used quantum key distribution protocol; The codewords corresponding to the plaintext information sent by the sender are obtained through the measurement results; Based on the measurement results, QKD post-processing is performed to obtain the QKD post-processing result; A new key is generated based on the result of the QKD post-processing, and the new key is stored in the key pool of the receiver; as well as The codewords are processed to obtain plaintext information.

8. The method as described in claim 7, characterized in that, Also includes: Receive a locally encrypted random number sent by the sender that corresponds to the timing position of the valid probe bit in the measurement result; The step of processing the codeword to obtain plaintext information includes: The codeword is masked and enlarged and decoded according to the local encrypted random number to obtain the masked and enlarged decoded codeword; The codeword after the mask is enlarged and decoded is decrypted to obtain the decrypted codeword; The despread codeword is then despread to obtain the despread codeword; and The despread codewords are then subjected to error correction and decoding to obtain the plaintext information.

9. The method as described in claim 7 or 8, characterized in that, The process of obtaining measurement results according to the currently adopted quantum key distribution protocol includes: According to a single-send, single-receive quantum key distribution protocol, the quantum state generated by the sender is measured, and the measurement result is obtained; or According to a dual-path quantum key distribution protocol, the quantum state modulated by the sender is measured to obtain the measurement result; or According to the dual-sender joint measurement quantum key distribution protocol, the measurement result obtained by a third party measuring the quantum states from the sender and the receiver is received; or According to the entangled quantum key distribution protocol, the particle of the receiver is measured based on the measurement result of the sender, and the measurement result is obtained.

10. A system for quantum key distribution and quantum direct communication, characterized in that, include: A transmitting device, configured to perform the method as described in any one of claims 1 to 6; as well as A receiving device for performing the method as described in any one of claims 7 to 9.

11. An electronic device, characterized in that, The device includes a memory and a processor, wherein the memory stores a computer program, and the processor, when executing the computer program in the memory, implements the method of any one of claims 1 to 9.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method of any one of claims 1 to 9.